There are a few strange things happening here that make no sense so I’d like you to run a couple more scans.
Run DDS
Please download DDS by sUBs from one of the following links and save it to your desktop.
DDS.pif
DDS.com
disable any script blocking protection (How to Disable your Security Programs ) double click DDS icon to run the tool (may take up to 3 minutes to run) when done, DDS.txt will open. after a few moments, attach.txt will open in a second window. save both reports to your desktop. Post the contents of the DDS.txt and Attach.txt reports in your next reply
===================================================
Run CKScanner
Download
CKScanner by
askey127 from
here &
save it to your Desktop .
doubleclick CKScanner.exe then click Search For Files when the cursor hourglass disappears, click Save List To File a message box will verify the file saved double-click the CKFiles.txt icon on your desktop then copy/paste the contents in your next reply
Satchfan
G'day, will be here as long as it takes.
Remember I am on a 2nd machine and using a flash drive to transport these URLs for the scans. My infected machine only gives me a white screen even if I key the URL in the command window or make it my homepage. I save to flash drive then copy it to desktop on the infected PC and run from there.
Long way around but that works, logs are below. Many thx.
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 7/25/2012 7:23:07 PM
System Uptime: 4/10/2013 6:39:29 AM (2 hours ago)
.
Motherboard: Gateway | | VG50_HC_HR
Processor: Intel® Pentium® CPU B950 @ 2.10GHz | U3E1 | 798/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 448 GiB total, 400.049 GiB free.
D: is CDROM ()
F: is Removable
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP47: 3/7/2013 7:36:22 AM - Scheduled Checkpoint
RP48: 3/13/2013 6:54:11 PM - Windows Update
RP49: 3/21/2013 12:19:54 PM - Scheduled Checkpoint
RP50: 3/21/2013 7:08:28 PM - Windows Update
RP51: 3/29/2013 7:06:05 AM - Scheduled Checkpoint
RP52: 4/5/2013 4:45:41 PM - Windows Update
RP53: 4/6/2013 9:00:49 AM - Removed Norton Online Backup
RP54: 4/6/2013 9:01:58 AM - Removed Norton Online Backup
RP55: 4/6/2013 9:02:19 AM - Removed Norton Online Backup
RP56: 4/6/2013 9:04:36 AM - Removed Norton Online Backup
RP57: 4/6/2013 1:59:53 PM - OTL Restore Point - 4/6/2013 1:59:52 PM
RP58: 4/7/2013 8:42:45 PM - Windows Update
RP59: 4/8/2013 2:29:05 PM - Removed AVG 2012
RP60: 4/8/2013 2:30:50 PM - Removed AVG 2012
RP61: 4/8/2013 2:32:41 PM - Removed AVG 2012
.
==== Installed Programs ======================
.
clear.fi SDK- Movie 2
clear.fi SDK - MVP 2
Adobe AIR
Adobe Flash Player 11 ActiveX 64-bit
Adobe Reader X (10.1.4) MUI
Agatha Christie - Death on the Nile
Avira Free Antivirus
Backup Manager V3
Bejeweled 3
Broadcom Card Reader Driver Installer
Broadcom NetLink Controller
Chronicles of Albian
Chuzzle Deluxe
clear.fi Media
clear.fi Photo
Cradle of Rome 2
CyberLink MediaEspresso
D3DX10
Dora's World Adventure
eBay Worldwide
ETDWare PS/2-X64 10.6.9.9_WHQL
Evernote v. 4.5.2
FastStone Image Viewer 4.6
FATE
Final Drive: Nitro
Fooz Kids
Fooz Kids Platform
Galerie de photos Windows Live
Galería fotográfica de Windows Live
Gateway Games
Gateway MyBackup
Gateway Power Management
Gateway Recovery Management
Gateway Registration
Gateway ScreenSaver
Gateway Social Networks
Gateway Updater
GoToMeeting 5.4.0.1083
Governor of Poker 2 Premium Edition
Identity Card
Intel® Control Center
Intel® Management Engine Components
Intel® OpenCL CPU Runtime
Intel® Processor Graphics
Intel® Rapid Storage Technology
Intel® Trusted Connect Service Client
Jewel Match 3
Jewel Quest Mysteries: The Seventh Gate Collector's Edition
Junk Mail filter update
Launch Manager
magicJack
Malwarebytes Anti-Malware version 1.62.0.1300
Mesh Runtime
Microsoft .NET Framework 4 Client Profile
Microsoft Application Error Reporting
Microsoft Office 2010
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
MSVCRT
MSVCRT_amd64
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Nero Control Center 10
Nero ControlCenter 10 Help (CHM)
Nero Core Components 10
Nero DiscSpeed 10
Nero DiscSpeed 10 Help (CHM)
Nero Express 10
Nero Express 10 Help (CHM)
Nero Multimedia Suite 10 Essentials
Nero StartSmart 10
Nero StartSmart 10 Help (CHM)
Nero Update
OpenOffice.org 3.1
Penguins!
Plants vs. Zombies - Game of the Year
Polar Bowler
Polar Golfer
Qualcomm Atheros WiFi Driver Installation
Realtek High Definition Audio Driver
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)
Skype™ 5.10
Torchlight
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update Installer for WildTangent Games App
Video Web Camera
Virtual Villagers 5 - New Believers
Visual Studio 2008 x64 Redistributables
Welcome Center
WildTangent Games App
Windows Live
Windows Live Communications Platform
Windows Live Essentials
Windows Live Galeria de Fotos
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Language Selector
Windows Live Mail
Windows Live Mesh
Windows Live Messenger
Windows Live MIME IFilter
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live Remote Client
Windows Live Remote Client Resources
Windows Live Remote Service
Windows Live Remote Service Resources
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
Zuma's Revenge
.
==== Event Viewer Messages From Past Week ========
.
4/9/2013 6:23:11 AM, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
4/9/2013 6:21:35 AM, Error: Application Popup [1060] - \??\C:\ComboFix\catchme.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
4/8/2013 3:41:10 PM, Error: Schannel [36888] - The following fatal alert was generated: 40. The internal error state is 107.
4/8/2013 3:41:10 PM, Error: Schannel [36874] - An SSL 3.0 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed.
.
==== End Of File ===========================
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.16521
Run by [removed] at 8:36:31 on 2013-04-10
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3932.2631 [GMT -4:00]
.
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
C:\Program Files (x86)\Launch Manager\dsiwmis.exe
C:\Program Files\Gateway\Gateway Power Management\ePowerSvc.exe
C:\Program Files (x86)\Launch Manager\LMutilps32.exe
C:\Program Files (x86)\Gateway\Registration\GREGsvc.exe
C:\Program Files\Intel\iCLS Client\HeciServer.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe
C:\Program Files (x86)\NTI\Gateway MyBackup\IScheduleSvc.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files (x86)\Atheros\Ath_WlanAgent.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Elantech\ETDCtrl.exe
C:\Program Files\Gateway\Gateway Power Management\ePowerTray.exe
C:\Windows\system32\igfxext.exe
C:\Program Files (x86)\NTI\Gateway MyBackup\BackupManagerTray.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Launch Manager\LManager.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
C:\Program Files (x86)\Launch Manager\LMworker.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Gateway\Gateway Power Management\ePowerEvent.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Elantech\ETDCtrlHelper.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe
C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\Nero\Update\NASvc.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
C:\Windows\System32\WUDFHost.exe
\\?\C:\Windows\system32\wbem\WMIADAP.EXE
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.download.bleepingcomputer.com/sUBs/dds.com
mWinlogon: Userinit = userinit.exe
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} -
BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
mRun: [BackupManagerTray] "C:\Program Files (x86)\NTI\Gateway MyBackup\BackupManagerTray.exe" -h -k
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe
mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
mRun: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
uPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: NoDrives = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
TCP: NameServer = 192.168.1.1 68.238.112.12
TCP: Interfaces\{4423B56C-33B8-4BD7-A66E-B52E302F9417} : DHCPNameServer = 192.168.1.250
TCP: Interfaces\{C692ADA5-4D81-4D69-AB21-0888554351A7} : DHCPNameServer = 192.168.1.1 [removed]
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck -
x64-BHO: {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} -
x64-BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-Run: [ETDCtrl] C:\Program Files (x86)\Elantech\ETDCtrl.exe
x64-Run: [Power Management] C:\Program Files\Gateway\Gateway Power Management\ePowerTray.exe
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} -
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} -
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck -
.
============= SERVICES / DRIVERS ===============
.
R1 avkmgr;avkmgr;C:\Windows\System32\drivers\avkmgr.sys [2013-4-6 28600]
R2 AntiVirSchedulerService;Avira Scheduler;C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2013-4-6 86752]
R2 AntiVirService;Avira Real-Time Protection;C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2013-4-6 110816]
R2 avgntflt;avgntflt;C:\Windows\System32\drivers\avgntflt.sys [2013-4-6 100712]
R2 DsiWMIService;Dritek WMI Service;C:\Program Files (x86)\Launch Manager\dsiwmis.exe [2012-3-19 355920]
R2 ePowerSvc;ePower Service;C:\Program Files\Gateway\Gateway Power Management\ePowerSvc.exe [2012-4-17 871296]
R2 GREGService;GREGService;C:\Program Files (x86)\Gateway\Registration\GREGsvc.exe [2011-5-29 36456]
R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2012-3-19 13592]
R2 Intel® Capability Licensing Service Interface;Intel® Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-2-3 628448]
R2 jhi_service;Intel® Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe [2012-4-17 161560]
R2 Live Updater Service;Live Updater Service;C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe [2012-3-19 255376]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-8-2 655944]
R2 NAUpdate;Nero Update;C:\Program Files (x86)\Nero\Update\NASvc.exe [2011-7-22 690472]
R2 NTI IScheduleSvc;NTI IScheduleSvc;C:\Program Files (x86)\NTI\Gateway MyBackup\IScheduleSvc.exe [2012-1-5 256536]
R2 UNS;Intel® Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2012-4-17 363800]
R2 ZAtheros Wlan Agent;ZAtheros Wlan Agent;C:\Program Files (x86)\Atheros\Ath_WlanAgent.exe [2012-4-17 72864]
R3 b57xdbd;Broadcom xD Picture Bus Driver Service;C:\Windows\System32\drivers\b57xdbd.sys [2011-11-4 68648]
R3 b57xdmp;Broadcom xD Picture vstorp client drv;C:\Windows\System32\drivers\b57xdmp.sys [2011-11-4 19496]
R3 bScsiMSa;bScsiMSa;C:\Windows\System32\drivers\bScsiMSa.sys [2011-9-2 51752]
R3 bScsiSDa;bScsiSDa;C:\Windows\System32\drivers\bScsiSDa.sys [2012-2-9 78888]
R3 ETD;ELAN PS/2 Port Input Device;C:\Windows\System32\drivers\ETD.sys [2012-3-14 238384]
R3 IntcDAud;Intel® Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2012-3-19 331264]
R3 k57nd60a;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;C:\Windows\System32\drivers\k57nd60a.sys [2012-1-19 435240]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2012-8-2 24904]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-7-13 160944]
S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-20 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-20 31232]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-7-27 1255736]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2013-04-10 10:38:30 ——– d—–w- C:\Users\-\AppData\Local\Programs
2013-04-09 20:10:29 ——– d-sh–w- C:\$RECYCLE.BIN
2013-04-09 18:59:43 ——– d-s—w- C:\ComboFix
2013-04-09 15:02:25 ——– d—–w- C:\_OTL
2013-04-09 12:37:09 ——– d—–w- C:\Users\-\AppData\Local\ElevatedDiagnostics
2013-04-09 10:02:35 98816 —-a-w- C:\Windows\sed.exe
2013-04-09 10:02:35 256000 —-a-w- C:\Windows\PEV.exe
2013-04-09 10:02:35 208896 —-a-w- C:\Windows\MBR.exe
2013-04-09 09:34:17 9311288 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{A2FD5937-05A6-4DC8-ACB8-4E619AB3B40D}\mpengine.dll
2013-04-08 18:30:05 ——– d—–w- C:\Users\-\AppData\Roaming\TuneUp Software
2013-04-07 17:02:10 ——– d—–w- C:\Windows\ERUNT
2013-04-07 17:01:52 ——– d—–w- C:\JRT
2013-04-06 13:12:20 ——– d—–w- C:\Users\-\AppData\Roaming\Avira
2013-04-06 13:09:12 28600 —-a-w- C:\Windows\System32\drivers\avkmgr.sys
2013-04-06 13:09:12 100712 —-a-w- C:\Windows\System32\drivers\avgntflt.sys
2013-04-06 13:09:08 ——– d—–w- C:\ProgramData\Avira
2013-04-06 13:09:08 ——– d—–w- C:\Program Files (x86)\Avira
2013-03-21 10:12:32 19968 —-a-w- C:\Windows\System32\drivers\usb8023.sys
2013-03-14 19:23:45 ——– d—–w- C:\Users\-\AppData\Roaming\OpenOffice.org
2013-03-14 19:20:40 ——– d—–w- C:\Program Files (x86)\JRE
2013-03-14 19:20:37 ——– d—–w- C:\Program Files (x86)\OpenOffice.org 3
.
==================== Find3M ====================
.
2013-03-12 05:10:56 282744 ——w- C:\Windows\System32\MpSigStub.exe
2013-02-12 05:45:24 135168 —-a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
2013-02-12 05:45:22 350208 —-a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
2013-02-12 05:45:22 308736 —-a-w- C:\Windows\apppatch\AppPatch64\AcGenral.dll
2013-02-12 05:45:22 111104 —-a-w- C:\Windows\apppatch\AppPatch64\acspecfc.dll
2013-02-12 04:48:31 474112 —-a-w- C:\Windows\apppatch\AcSpecfc.dll
2013-02-12 04:48:26 2176512 —-a-w- C:\Windows\apppatch\AcGenral.dll
2013-01-13 21:17:03 9728 —ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-01-13 21:17:02 2560 —ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-01-13 21:16:42 10752 —ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-01-13 21:12:46 3584 —ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-01-13 21:11:21 4096 —ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-01-13 21:11:08 5632 —ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-01-13 21:11:07 5632 —ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-01-13 21:11:07 3072 —ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
2013-01-13 21:11:07 3072 —ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-01-13 20:35:31 9728 —ha-w- C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-01-13 20:35:31 2560 —ha-w- C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-01-13 20:35:18 10752 —ha-w- C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-01-13 20:32:07 3584 —ha-w- C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-01-13 20:31:48 4096 —ha-w- C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-01-13 20:31:41 5632 —ha-w- C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-01-13 20:31:40 5632 —ha-w- C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-01-13 20:31:40 3072 —ha-w- C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
2013-01-13 20:31:40 3072 —ha-w- C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-01-13 20:31:00 1247744 —-a-w- C:\Windows\SysWow64\DWrite.dll
2013-01-13 20:22:22 1988096 —-a-w- C:\Windows\SysWow64\d3d10warp.dll
2013-01-13 20:20:31 293376 —-a-w- C:\Windows\SysWow64\dxgi.dll
2013-01-13 20:09:00 249856 —-a-w- C:\Windows\SysWow64\d3d10_1core.dll
2013-01-13 20:08:43 220160 —-a-w- C:\Windows\SysWow64\d3d10core.dll
2013-01-13 20:08:35 1504768 —-a-w- C:\Windows\SysWow64\d3d11.dll
2013-01-13 19:59:04 1643520 —-a-w- C:\Windows\System32\DWrite.dll
2013-01-13 19:58:28 1175552 —-a-w- C:\Windows\System32\FntCache.dll
2013-01-13 19:54:01 604160 —-a-w- C:\Windows\SysWow64\d3d10level9.dll
2013-01-13 19:53:58 207872 —-a-w- C:\Windows\SysWow64\WindowsCodecsExt.dll
2013-01-13 19:53:14 187392 —-a-w- C:\Windows\SysWow64\UIAnimation.dll
2013-01-13 19:51:30 2565120 —-a-w- C:\Windows\System32\d3d10warp.dll
2013-01-13 19:49:17 363008 —-a-w- C:\Windows\System32\dxgi.dll
2013-01-13 19:48:47 161792 —-a-w- C:\Windows\SysWow64\d3d10_1.dll
2013-01-13 19:46:25 1080832 —-a-w- C:\Windows\SysWow64\d3d10.dll
2013-01-13 19:43:21 1230336 —-a-w- C:\Windows\SysWow64\WindowsCodecs.dll
2013-01-13 19:38:39 333312 —-a-w- C:\Windows\System32\d3d10_1core.dll
2013-01-13 19:38:32 1887232 —-a-w- C:\Windows\System32\d3d11.dll
2013-01-13 19:38:21 296960 —-a-w- C:\Windows\System32\d3d10core.dll
2013-01-13 19:37:57 3419136 —-a-w- C:\Windows\SysWow64\d2d1.dll
2013-01-13 19:25:04 245248 —-a-w- C:\Windows\System32\WindowsCodecsExt.dll
2013-01-13 19:24:33 648192 —-a-w- C:\Windows\System32\d3d10level9.dll
2013-01-13 19:24:30 221184 —-a-w- C:\Windows\System32\UIAnimation.dll
2013-01-13 19:20:42 194560 —-a-w- C:\Windows\System32\d3d10_1.dll
2013-01-13 19:20:04 1238528 —-a-w- C:\Windows\System32\d3d10.dll
2013-01-13 19:15:40 1424384 —-a-w- C:\Windows\System32\WindowsCodecs.dll
2013-01-13 19:10:36 3928064 —-a-w- C:\Windows\System32\d2d1.dll
2013-01-13 19:02:06 417792 —-a-w- C:\Windows\SysWow64\WMPhoto.dll
2013-01-13 18:34:58 364544 —-a-w- C:\Windows\SysWow64\XpsGdiConverter.dll
2013-01-13 18:32:43 465920 —-a-w- C:\Windows\System32\WMPhoto.dll
2013-01-13 18:09:52 522752 —-a-w- C:\Windows\System32\XpsGdiConverter.dll
2013-01-13 17:26:42 1158144 —-a-w- C:\Windows\SysWow64\XpsPrint.dll
2013-01-13 17:05:09 1682432 —-a-w- C:\Windows\System32\XpsPrint.dll
.
============= FINISH: 8:36:55.78 ===============
CKScanner 2.1 - Additional Security Risks - These are not necessarily bad
scanner sequence 3.RP.11.XENAXT
—– EOF —–
Can you boot the infected computer in safe mode?
Yes, had a hunch that was coming. Am already started in safe mode.
Open ComboFix
Please do the following :
close any open browsers. close/disable all anti virus and anti malware programs so that they do not interfere with the running of ComboFix. open notepad and copy/paste the text in the codebox below into it:
Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
Save this as
"CFScript.txt" , and as Type: All Files (*.*) in the same location as ComboFix.exe
[external image: Posted Image]
Referring to the picture above, drag CFScript into ComboFix.exe
When finished, it produces a log at
C:\ComboFix.txt . Post the contents of Combofix.txt in your next reply.
Try starting in normal mode and let me know how it goes.
Thanks
Satchfan
Several seconds into scan this popped up:
Warning!
Error saving file
C:\Windows\erdnt\Hiv-backup\BCD!
Continue with next file?
[RegCreateKeyEx:5 - Access is denied]
Need your advice here . . . will await your reply
Let's try it this way:
Run MiniRegTool
Please download
MiniRegTool and unzip it.
run the tool copy and paste the following into the edit box:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
check Import radio button press Go Please post the log
(Result.txt) in your reply.
Try starting the computer normally
Satchfan
Copied that statement into the edit window.
There is no "import" radio button on screen.
I clicked Go and nothing is happening. Closed and re-opened MiniRegTool, repeated process, nothing moving.
Maybe the open Warning! popup has things locked?
Very persistent so let's try another way.
Note: If you have MalwareBytes Anti-Malware 1.6 or higher installed and are using the Pro version or trial version, please temporarily disable it for the duration of this fix as it may interfere with the successfully execution of the script below.
Run OTL double click on the icon to run it. copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL
:Services
:OTL
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
:Commands
[purity]
[emptytemp]
[Reboot]
click the Run Fix button at the top let the program run unhindered, reboot when it is done please post the OTL fix log
OK, am ready to go but this reminder:
- ComboFix is still open
- the warning popup is still open wanting a yes/no on continuing the registry backup
Still a go?
OTL log file below.
All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
========== REGISTRY ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\"Userinit"|"C:\\WINDOWS\\system32\\userinit.exe," /E : value set successfully!
========== COMMANDS ==========
[EMPTYTEMP]
User: -
->Temp folder emptied: 244017 bytes
->Temporary Internet Files folder emptied: 351378 bytes
->Flash cache emptied: 291 bytes
User: Administrator
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Public
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 4061 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 1.00 mb
OTL by OldTimer - Version 3.2.69.0 log created on 04102013_131151
Files\Folders moved on Reboot…
C:\Users\-\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Users\-\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.
PendingFileRenameOperations files…
Registry entries deleted on Reboot…
Windows opens fine on the infected PC.
It appears we are back to the previous problem of homepage opening up and visible, but going anywhere from there…it results in a white screen.
It appears we are back to the previous problem of homepage opening up and visible, but going anywhere from there…it results in a white screen.
Is this only in Internet Explorer?
Yes. Other programs resident on the hard drive or external drives work fine