This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Avast Boot Time Scan Found Java Trojans [Solved]

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My Internet was running slow with occasional resets of flash TV videos from my cable service. My bi-weekly Avast logs were always clean, but when I decided to run a Avast Boot Time Scan, it found two Java Trojans:

Java:Malware-gen
and
Java:Agent:DAW

Both were moved to the Chest, but I then ran a Hijackthis log and wish to confirm there are no remnants:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:54:45 PM, on 4/18/2013
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16476)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files (x86)\Logitech\Vid HD\Vid.exe
C:\Program Files (x86)\Samsung\Kies\Kies.exe
C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe
C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Cordless USB Phone\Vtech Cordless Phone Suite.exe
C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe
C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
C:\Program Files (x86)\CyberLink\InstantBurn\Win2K\IBurn.exe
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe
C:\Program Files (x86)\CyberLink\Shared Files\brs.exe
C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files (x86)\MSN Toolbar\Platform\5.0.1423.0\mswinext.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSMSNLoader32.exe
C:\Users\Sungkua\Downloads\TestThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…;m=aspire_m3201
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…;m=aspire_m3201
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…;m=aspire_m3201
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 217.15.117.86:3128
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - (no file)
O2 - BHO: Fantapper - {8A86D350-37AB-410A-8531-7D1363F317B3} - C:\Program Files (x86)\Brand Affinity Technologies\Fantapper Player\\IEInstaller.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Bing Bar BHO - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\5.0.1423.0\npwinext.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: @C:\Program Files (x86)\MSN Toolbar\Platform\5.0.1423.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\5.0.1423.0\npwinext.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O4 - HKLM\..\Run: [PCMMediaSharing] "C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe"
O4 - HKLM\..\Run: [BkupTray] "C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe"
O4 - HKLM\..\Run: [Acer Product Registration] "C:\Program Files (x86)\Acer\Acer Registration\ACE1.exe" /startup
O4 - HKLM\..\Run: [Acer Assist Launcher] "C:\Program Files (x86)\Acer\Acer Assist\launcher.exe"
O4 - HKLM\..\Run: [InstantBurn] C:\PROGRA~2\CYBERL~1\INSTAN~1\Win2K\IBurn.exe
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
O4 - HKLM\..\Run: [RemoteControl9] "C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe"
O4 - HKLM\..\Run: [BDRegion] "C:\Program Files (x86)\Cyberlink\Shared files\brs.exe"
O4 - HKLM\..\Run: [UpdatePPShortCut] "C:\Program Files (x86)\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\PowerProducer" UpdateWithCreateOnce "Software\CyberLink\PowerProducer\5.0"
O4 - HKLM\..\Run: [UpdatePSTShortCut] "C:\Program Files (x86)\CyberLink\Blu-ray Disc Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Blu-ray Disc Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
O4 - HKLM\..\Run: [LWS] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [Bing Bar] "C:\Program Files (x86)\MSN Toolbar\Platform\5.0.1423.0\mswinext.exe"
O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [KiesTrayAgent] "C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Logitech Vid] "C:\Program Files (x86)\Logitech\Vid HD\Vid.exe" -bootmode
O4 - HKCU\..\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload
O4 - HKCU\..\Run: [KiesAirMessage] C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup
O4 - HKCU\..\Run: [] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [Google Update] "C:\Users\Sungkua\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: usb7100 Startup.lnk = C:\Program Files (x86)\Cordless USB Phone\Vtech Cordless Phone Suite.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O9 - Extra button: Fantapper - {AB745E88-1BAD-4B80-A83E-7C964EAC9804} - C:\Program Files (x86)\Brand Affinity Technologies\Fantapper Player\\IEInstaller.dll (HKCU)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://xfinitytv.comcast.net
O15 - Trusted Zone: http://*.netflix.com
O15 - Trusted Zone: http://download.windowsupdate.com
O16 - DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} (Bitdefender QuickScan Control) - http://quickscan.bitdefender.com/qsax/qsax.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.fcd.maricopa.gov/Maps/gismaps/p…mgaxctrl6.5.cab
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=724
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Unknown owner - C:\Windows\system32\agr64svc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\Windows\SysWOW64\bgsvcgen.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
O23 - Service: CyberLink Product - 2010/08/15 22:17:00 (CLKMSVC10_9EC60124) - CyberLink - C:\Program Files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
O23 - Service: FreemakeVideoCapture - Unknown owner - C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe (file missing)
O23 - Service: Fantapper Player Update Service (FTSvc) - Brand Affinity Technologies - C:\Program Files (x86)\Brand Affinity Technologies\Fantapper Player\FantapperUpdateService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice_tmp.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: VMC NetFlix Download Manager (NetFlixDownloadManager) - Unknown owner - C:\Program Files\Luttmann\vmcNetFlix\NetFlixDownloadManager.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Palm Novacom (NovacomD) - Palm - C:\Program Files\Palm, Inc\novacomd\amd64\novacomd.exe
O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: UMVPFSrv - Logitech Inc. - C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files (x86)\RealVNC\VNC4\WinVNC4.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 17481 bytes
I will need a deeper diagnostic scan to ensure nothing remains on your machine, please run the following:

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT

Please download aswMBR to your desktop.
  • Double click the aswMBR.exe icon to run it
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click the Scan button to start the scan
  • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well
Thank you for your help Here are the files you requested. One possible important note, when I ran the aswMBR.exe file, It never asked if I wanted to update the virus definitions, it just got to the screen where I could start the scan. The interface did show some virus definition listed though. Let me know if I need to run it again.
Please run the following

Refer to the ComboFix User's Guide

  • Download ComboFix from the following location:

    Link

    * IMPORTANT !!! Place ComboFix.exe on your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.
    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


    ———————————————————————————————
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.

    ———————————————————————————————

NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.
Here is the log you requested. There must be some things still causing infections since combofix did delete some files and this morning before I ran the scan, my computer had been turned off. I was going to run combfix in safe mode but read that you are not to do this. Unfortunately, I forgot to run hijackthis to see if there were any registry settings for one time program running. Finally, I noticed I forgot to turn of Windows Defender when running combofix. Let me know if this will be an issue for an accurate log. I will wait for your review of the data: ComboFix 13-04-20.02 - Sungkua 04/21/2013 8:35.1.2 - x64 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.4094.1999 [GMT -7:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . C:\Install.exe c:\windows\SysWow64\muzapp.exe c:\windows\SysWow64\Packet.dll c:\windows\SysWow64\pthreadVC.dll c:\windows\SysWow64\wpcap.dll J:\install.exe . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . . ——-\Legacy_NPF ——-\Service_npf ——-\Service_FTSvc . . ((((((((((((((((((((((((( Files Created from 2013-03-21 to 2013-04-21 ))))))))))))))))))))))))))))))) . . 2013-04-21 15:47 . 2013-04-21 15:47 ——– d—–w- c:\users\UpdatusUser\AppData\Local\temp 2013-04-21 15:47 . 2013-04-21 15:47 ——– d—–w- c:\users\Mcx2\AppData\Local\temp 2013-04-19 18:20 . 2013-04-19 18:20 ——– d—–w- c:\program files\WOT 2013-04-19 18:20 . 2013-04-19 18:20 ——– d—–w- c:\program files (x86)\WOT 2013-04-19 09:41 . 2013-04-20 08:51 76232 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{85BCD467-1E8F-461F-8AA5-338BD085EEBC}\offreg.dll 2013-04-19 09:26 . 2013-04-10 03:46 9317456 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{85BCD467-1E8F-461F-8AA5-338BD085EEBC}\mpengine.dll 2013-04-12 17:11 . 2013-04-12 17:12 ——– d—–w- C:\Program Backups 2013-04-12 11:39 . 2013-04-10 06:58 26520 —-a-w- c:\program files (x86)\Mozilla Firefox\plugin-hang-ui.exe 2013-04-12 11:12 . 2013-04-12 11:16 ——– d—–w- c:\users\Sungkua\AppData\Roaming\QuickScan 2013-04-12 04:55 . 2013-04-12 04:54 95648 —-a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2013-04-10 10:03 . 2013-02-22 06:21 1346560 —-a-w- c:\windows\system32\urlmon.dll 2013-04-10 04:39 . 2013-02-21 04:26 3138048 —-a-w- c:\windows\system32\mstscax.dll 2013-04-10 04:39 . 2013-02-21 04:26 44032 —-a-w- c:\windows\system32\tsgqec.dll 2013-04-10 04:39 . 2013-02-21 04:26 158208 —-a-w- c:\windows\system32\aaclient.dll 2013-04-10 04:39 . 2013-02-21 03:52 36864 —-a-w- c:\windows\SysWow64\tsgqec.dll 2013-04-10 04:39 . 2013-02-21 03:52 2691072 —-a-w- c:\windows\SysWow64\mstscax.dll 2013-04-10 04:39 . 2013-02-21 03:52 131072 —-a-w- c:\windows\SysWow64\aaclient.dll 2013-04-10 04:39 . 2013-03-03 19:13 1513320 —-a-w- c:\windows\system32\drivers\ntfs.sys 2013-04-10 04:39 . 2013-03-11 13:33 4691304 —-a-w- c:\windows\system32\ntoskrnl.exe 2013-04-10 04:39 . 2013-03-09 04:16 85504 —-a-w- c:\windows\system32\csrsrv.dll 2013-04-10 04:39 . 2013-03-09 01:48 75264 —-a-w- c:\windows\system32\smss.exe 2013-04-10 04:39 . 2013-03-05 01:57 2774016 —-a-w- c:\windows\system32\win32k.sys 2013-04-10 04:39 . 2013-03-08 04:18 451072 —-a-w- c:\windows\system32\winsrv.dll 2013-04-10 01:18 . 2013-04-10 01:18 ——– d—–w- c:\program files (x86)\Common Files\Skype 2013-03-30 00:30 . 2013-03-30 00:29 310688 —-a-w- c:\windows\system32\javaws.exe 2013-03-30 00:30 . 2013-03-30 00:29 108448 —-a-w- c:\windows\system32\WindowsAccessBridge-64.dll 2013-03-30 00:30 . 2013-03-30 00:29 188832 —-a-w- c:\windows\system32\javaw.exe 2013-03-30 00:30 . 2013-03-30 00:29 188320 —-a-w- c:\windows\system32\java.exe . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-04-12 11:45 . 2012-04-12 05:00 691592 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-04-12 11:45 . 2011-05-22 15:50 71048 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-04-12 04:54 . 2012-07-17 04:42 861088 —-a-w- c:\windows\SysWow64\npdeployJava1.dll 2013-04-12 04:54 . 2010-08-16 01:47 782240 —-a-w- c:\windows\SysWow64\deployJava1.dll 2013-04-10 10:07 . 2006-11-02 12:35 72702784 —-a-w- c:\windows\system32\mrt.exe 2013-04-04 21:50 . 2011-10-02 16:58 25928 —-a-w- c:\windows\system32\drivers\mbam.sys 2013-03-30 00:29 . 2012-10-11 05:19 963488 —-a-w- c:\windows\system32\deployJava1.dll 2013-03-30 00:29 . 2012-10-11 05:19 1085344 —-a-w- c:\windows\system32\npDeployJava1.dll 2013-03-12 08:10 . 2009-10-19 02:46 282744 ——w- c:\windows\system32\MpSigStub.exe 2013-03-06 23:33 . 2013-03-20 06:14 178624 —-a-w- c:\windows\system32\drivers\aswVmm.sys 2013-03-06 23:33 . 2013-03-20 06:14 65336 —-a-w- c:\windows\system32\drivers\aswRvrt.sys 2013-03-06 23:33 . 2011-05-08 16:53 1025808 —-a-w- c:\windows\system32\drivers\aswSnx.sys 2013-03-06 23:33 . 2010-09-05 05:24 377920 —-a-w- c:\windows\system32\drivers\aswSP.sys 2013-03-06 23:33 . 2010-09-05 05:24 68920 —-a-w- c:\windows\system32\drivers\aswTdi.sys 2013-03-06 23:33 . 2010-09-05 05:24 33400 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys 2013-03-06 23:33 . 2010-09-05 05:24 59144 —-a-w- c:\windows\system32\drivers\aswRdr.sys 2013-03-06 23:33 . 2010-09-05 05:23 80816 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys 2013-03-06 23:32 . 2010-09-05 05:22 41664 —-a-w- c:\windows\avastSS.scr 2013-03-06 23:32 . 2011-01-26 02:05 287840 —-a-w- c:\windows\system32\aswBoot.exe 2013-02-12 02:18 . 2013-03-21 18:08 19456 —-a-w- c:\windows\system32\drivers\usb8023.sys 2013-02-10 03:25 . 2013-02-19 03:14 6267240 —-a-w- c:\windows\SysWow64\nvopencl.dll 2013-02-10 03:25 . 2013-02-19 03:14 15275744 —-a-w- c:\windows\system32\nvwgf2umx.dll 2013-02-10 03:25 . 2013-02-19 03:14 7569184 —-a-w- c:\windows\system32\nvopencl.dll 2013-02-10 03:25 . 2013-02-19 03:14 26947360 —-a-w- c:\windows\system32\nvoglv64.dll 2013-02-10 03:25 . 2013-02-19 03:14 20534560 —-a-w- c:\windows\SysWow64\nvoglv32.dll 2013-02-10 03:25 . 2013-02-19 03:14 11040544 —-a-w- c:\windows\system32\drivers\nvlddmkm.sys 2013-02-10 03:25 . 2013-02-19 03:14 7964680 —-a-w- c:\windows\SysWow64\nvcuda.dll 2013-02-10 03:25 . 2013-02-19 03:14 2911008 —-a-w- c:\windows\system32\nvcuvid.dll 2013-02-10 03:25 . 2013-02-19 03:14 2726176 —-a-w- c:\windows\SysWow64\nvcuvid.dll 2013-02-10 03:25 . 2013-02-19 03:14 2350368 —-a-w- c:\windows\system32\nvcuvenc.dll 2013-02-10 03:25 . 2013-02-19 03:14 1990944 —-a-w- c:\windows\SysWow64\nvcuvenc.dll 2013-02-10 03:25 . 2013-02-19 03:14 1807136 —-a-w- c:\windows\system32\nvdispco6420294.dll 2013-02-10 03:25 . 2013-02-19 03:14 1510176 —-a-w- c:\windows\system32\nvdispgenco6420162.dll 2013-02-10 03:25 . 2013-02-19 03:14 9422672 —-a-w- c:\windows\system32\nvcuda.dll 2013-02-10 03:25 . 2013-02-19 03:14 25256736 —-a-w- c:\windows\system32\nvcompiler.dll 2013-02-10 03:25 . 2013-02-19 03:14 17560352 —-a-w- c:\windows\SysWow64\nvcompiler.dll 2013-02-10 03:25 . 2013-01-13 00:02 12862400 —-a-w- c:\windows\SysWow64\nvwgf2um.dll 2013-02-10 03:25 . 2013-01-13 00:02 2854344 —-a-w- c:\windows\system32\nvapi64.dll 2013-02-10 03:25 . 2013-01-13 00:02 2528840 —-a-w- c:\windows\SysWow64\nvapi.dll 2013-02-10 03:25 . 2013-01-13 00:02 17987192 —-a-w- c:\windows\system32\nvd3dumx.dll 2013-02-10 03:25 . 2013-01-13 00:02 15038296 —-a-w- c:\windows\SysWow64\nvd3dum.dll 2013-02-10 01:04 . 2013-01-13 00:04 6393120 —-a-w- c:\windows\system32\nvcpl.dll 2013-02-10 01:04 . 2013-01-13 00:04 3472672 —-a-w- c:\windows\system32\nvsvc64.dll 2013-02-10 01:04 . 2013-01-13 00:04 63776 —-a-w- c:\windows\system32\nvshext.dll 2013-02-10 01:04 . 2013-01-13 00:04 877856 —-a-w- c:\windows\system32\nvvsvc.exe 2013-02-10 01:04 . 2013-01-13 00:04 237856 —-a-w- c:\windows\system32\nvmctray.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{8A86D350-37AB-410A-8531-7D1363F317B3}] 2011-12-12 09:53 65896 —-a-w- c:\program files (x86)\Brand Affinity Technologies\Fantapper Player\IEInstaller.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP] @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}] 2008-07-30 00:52 121392 —-a-w- c:\program files (x86)\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 138240] "SpybotSD TeaTimer"="c:\program files (x86)\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] "Logitech Vid"="c:\program files (x86)\Logitech\Vid HD\Vid.exe" [2011-01-13 6129496] "KiesPreload"="c:\program files (x86)\Samsung\Kies\Kies.exe" [2012-12-21 1476104] "KiesAirMessage"="c:\program files (x86)\Samsung\Kies\KiesAirMessage.exe" [2012-12-18 578560] "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-03-01 18642024] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "PCMMediaSharing"="c:\program files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe" [2008-05-21 204908] "BkupTray"="c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" [2008-04-26 28672] "Acer Product Registration"="c:\program files (x86)\Acer\Acer Registration\ACE1.exe" [2007-11-26 3387392] "Acer Assist Launcher"="c:\program files (x86)\Acer\Acer Assist\launcher.exe" [2007-11-19 1261568] "InstantBurn"="c:\progra~2\CYBERL~1\INSTAN~1\Win2K\IBurn.exe" [2010-04-20 697640] "CLMLServer"="c:\program files (x86)\CyberLink\Power2Go\CLMLSvc.exe" [2009-11-02 103720] "RemoteControl9"="c:\program files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe" [2009-07-06 87336] "BDRegion"="c:\program files (x86)\Cyberlink\Shared files\brs.exe" [2010-05-14 75048] "UpdatePPShortCut"="c:\program files (x86)\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504] "UpdatePSTShortCut"="c:\program files (x86)\CyberLink\Blu-ray Disc Suite\MUITransfer\MUIStartMenu.exe" [2010-05-29 222504] "LWS"="c:\program files (x86)\Logitech\LWS\Webcam Software\LWS.exe" [2011-08-12 205336] "avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2013-03-06 4767304] "Bing Bar"="c:\program files (x86)\MSN Toolbar\Platform\5.0.1423.0\mswinext.exe" [2010-03-24 243544] "Microsoft Default Manager"="c:\program files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-11-12 288088] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-12-12 152544] "KiesTrayAgent"="c:\program files (x86)\Samsung\Kies\KiesTrayAgent.exe" [2012-12-21 310280] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ usb7100 Startup.lnk - c:\program files (x86)\Cordless USB Phone\Vtech Cordless Phone Suite.exe [2010-9-22 608768] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc] @="Service" . — Other Services/Drivers In Memory — . *NewlyCreated* - WS2IFSL *Deregistered* - CLKMDRV10_9EC60124 . HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs Themes . Contents of the 'Scheduled Tasks' folder . 2013-04-21 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-12 00:06] . 2013-04-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-350625352-3121310031-1665620277-1000Core.job - c:\users\Sungkua\AppData\Local\Google\Update\GoogleUpdate.exe [2013-04-10 00:25] . 2013-04-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-350625352-3121310031-1665620277-1000UA.job - c:\users\Sungkua\AppData\Local\Google\Update\GoogleUpdate.exe [2013-04-10 00:25] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2013-03-06 23:32 133840 —-a-w- c:\program files\Alwil Software\Avast5\ashShA64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP] @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}] 2008-07-30 00:53 50736 —-a-w- c:\program files (x86)\Acer\Empowering Technology\eDataSecurity\x64\PSDProtect.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Acer Empowering Technology Monitor"="c:\program files\Acer\Empowering Technology\SysMonitor.exe" [2008-06-02 319488] "EmpoweringTechnology"="c:\program files\Acer\Empowering Technology\Framework.Launcher.exe" [2008-06-02 319488] "eDataSecurity Loader"="c:\program files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDSloader.exe" [2008-07-30 561200] "CmPCIaudio"="c:\windows\Syswow64\CmiCnfg3.dll" [2008-10-29 7700480] "Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 660360] "EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2011-10-07 1744152] "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-08-01 2417032] . ——- Supplementary Scan ——- . uStart Page = about:blank uLocal Page = c:\windows\system32\blank.htm mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=1&o=vp64&d=0309&m=aspire_m3201 mDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=1&o=vp64&d=0309&m=aspire_m3201 mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyServer = 217.15.117.86:3128 uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html Trusted Zone: comcast.net\xfinitytv Trusted Zone: microsoft.com\*.update Trusted Zone: microsoft.com\update Trusted Zone: microsoft.com\www.update Trusted Zone: netflix.com Trusted Zone: windowsupdate.com\download TCP: DhcpNameServer = 192.168.1.1 FF - ProfilePath - c:\users\Sungkua\AppData\Roaming\Mozilla\Firefox\Profiles\y8g7xt6i.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - prefs.js: network.proxy.ftp - 217.15.117.86 FF - prefs.js: network.proxy.ftp_port - 3128 FF - prefs.js: network.proxy.http - [removed] FF - prefs.js: network.proxy.http_port - 3128 FF - prefs.js: network.proxy.socks - [removed] FF - prefs.js: network.proxy.socks_port - 3128 FF - prefs.js: network.proxy.ssl - [removed] FF - prefs.js: network.proxy.ssl_port - 3128 FF - prefs.js: network.proxy.type - 0 FF - ExtSQL: 2013-04-12 04:40; {CAFEEFAC-0016-0000-0043-ABCDEFFEDCBA}; c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0043-ABCDEFFEDCBA} FF - ExtSQL: 2013-04-18 14:09; {73a6fe31-595d-460b-a920-fcc0f8843232}; c:\users\Sungkua\AppData\Roaming\Mozilla\Firefox\Profiles\y8g7xt6i.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi FF - ExtSQL: 2013-04-19 11:19; {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}; c:\users\Sungkua\AppData\Roaming\Mozilla\Firefox\Profiles\y8g7xt6i.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} . - - - - ORPHANS REMOVED - - - - . Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file) Wow6432Node-HKLM-Run-eRecoveryService - (no file) SafeBoot-WudfPf SafeBoot-WudfRd WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file) HKLM-Run-LogMeIn GUI - c:\program files (x86)\LogMeIn\x64\LogMeInSystray.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_169_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_169_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_169_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_169_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_169.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_169.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_169.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_169.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}] @Denied: (A 2) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0] @="Shockwave Flash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}] @Denied: (A 2) (Everyone) @="" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0] @="FlashBroker" . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows CE Services] "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\ . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . ———————— Other Running Processes ———————— . c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe c:\program files\Alwil Software\Avast5\AvastSvc.exe c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\windows\SysWOW64\bgsvcgen.exe c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe c:\program files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe c:\program files (x86)\CyberLink\Shared Files\RichVideo.exe c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe c:\program files (x86)\RealVNC\VNC4\WinVNC4.exe c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe c:\program files (x86)\CyberLink\InstantBurn\Win2K\IBurn.exe c:\program files\Alwil Software\Avast5\AvastUI.exe c:\program files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSMSNLoader32.exe . ************************************************************************** . Completion time: 2013-04-21 09:05:17 - machine was rebooted ComboFix-quarantined-files.txt 2013-04-21 16:05 . Pre-Run: 83,765,059,584 bytes free Post-Run: 84,073,598,976 bytes free . - - End Of File - - 3793981FF68FDBB14D18929DA1FC1349
We still have a little more work to do, please run the following:

Please download Junkware Removal Tool to your desktop.
  • Shutdown your antivirus to avoid any conflicts.
  • Right-mouse click JRT.exe and select Run as administrator
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message


NEXT


Download AdwCleaner from here and save it to your desktop.
  • Run AdwCleaner and select Delete
  • Once done it will ask to reboot, allow the reboot
  • On reboot a log will be produced, please attach the content of the log to your next reply


NEXT

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Go here to run an online scanner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish
Thank you again, Catbyte. Here are the logs you requested. Both MalwareBytes and Eset Online Scanner ended with no findings. Thus, I couldn't save the Eset log, but the MalwareBytes did allow me. I noticed from the previous combofix log there were multiple instances of an IP of 217.15.117.86 and port 3128. My research shows this to be a Zimbabwe IP address, but it appears port 3128 is a required port to have open. Would you recommend I restrict that octet (217.15.117) with my firewall? Currently, I'm using Microsoft's since I was tired of working with ZoneAlarm. Finally, if this is the last instruction reply you have, can you advise me about the security of some of my internet passwords that I did use on this machine? I've attached the Junkware and AdwCleaner logs to my reply. Here is the copy and paste of the no findings for MalwareBytes: Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Database version: v2013.04.21.07 Windows Vista Service Pack 2 x64 NTFS Internet Explorer 9.0.8112.16421 Sungkua :: SUNGKUA-PC [administrator] 4/21/2013 3:54:18 PM mbam-log-2013-04-21 (15-54-18).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 293665 Time elapsed: 4 minute(s), 48 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)
you cannot block access to a website using Windows Firewall, but you can add the restriction to Firefox

http://www.wikihow.com/Restrict-Web-Browsing-Using-Firefox

As a precaution, you should change all your on-line passwords from a machine that has never been infected.


We can close that port for now, if something you use legitimately needs it, it will open it again

Please run the following:


  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Press the WinKey + R to open a run box, type Notepad > click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

File::
c:\program files (x86)\Brand Affinity Technologies\Fantapper Player\IEInstaller.dll

Registry::
[-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{8A86D350-37AB-410A-8531-7D1363F317B3}]

FireFox::
FF - ProfilePath - c:\users\Sungkua\AppData\Roaming\Mozilla\Firefox\Profiles\y8g7xt6i.default\
FF - prefs.js: network.proxy.ftp - 217.15.117.86
FF - prefs.js: network.proxy.ftp_port - 3128
FF - prefs.js: network.proxy.http - [removed]
FF - prefs.js: network.proxy.http_port - 3128
FF - prefs.js: network.proxy.socks - [removed]
FF - prefs.js: network.proxy.socks_port - 3128
FF - prefs.js: network.proxy.ssl - [removed]
FF - prefs.js: network.proxy.ssl_port - 3128

DDS::
uInternet Settings,ProxyServer = 217.15.117.86:3128

ClearJavaCache::

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix may request an update; please allow it.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.



Please let me know how the computer is running now and if there are any outstanding issues
Thanks Catbyte, From what I can tell, the flash videos are working more regularly. I will try them out over the following few days to see if I can replicate the problem before I first posted. If it starts to happen again, I'll run another dds scan and see if there are similar hits before I start a new post. I may also decide to create a ubuntu linux HTPC box and do away with Vista. Suggestions? Here is the combofix log after the CFScript fix: ComboFix 13-04-22.01 - Sungkua 04/22/2013 8:45.2.2 - x64 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.4094.2045 [GMT -7:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\Sungkua\Desktop\CFScript.txt AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . FILE :: "c:\program files (x86)\Brand Affinity Technologies\Fantapper Player\IEInstaller.dll" . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files (x86)\Brand Affinity Technologies\Fantapper Player\IEInstaller.dll . . ((((((((((((((((((((((((( Files Created from 2013-03-22 to 2013-04-22 ))))))))))))))))))))))))))))))) . . 2013-04-22 15:57 . 2013-04-22 15:57 ——– d—–w- c:\users\UpdatusUser\AppData\Local\temp 2013-04-22 15:57 . 2013-04-22 15:57 ——– d—–w- c:\users\Mcx2\AppData\Local\temp 2013-04-22 15:57 . 2013-04-22 15:57 ——– d—–w- c:\users\Mcx1\AppData\Local\temp 2013-04-22 15:57 . 2013-04-22 15:57 ——– d—–w- c:\users\Default\AppData\Local\temp 2013-04-22 04:08 . 2013-04-22 04:09 ——– d—–w- C:\Testing 2013-04-21 22:33 . 2013-04-21 22:33 ——– d—–w- c:\windows\ERUNT 2013-04-21 22:33 . 2013-04-21 22:33 ——– d—–w- C:\JRT 2013-04-19 18:20 . 2013-04-19 18:20 ——– d—–w- c:\program files\WOT 2013-04-19 18:20 . 2013-04-19 18:20 ——– d—–w- c:\program files (x86)\WOT 2013-04-19 09:41 . 2013-04-20 08:51 76232 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{85BCD467-1E8F-461F-8AA5-338BD085EEBC}\offreg.dll 2013-04-19 09:26 . 2013-04-10 03:46 9317456 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{85BCD467-1E8F-461F-8AA5-338BD085EEBC}\mpengine.dll 2013-04-12 17:11 . 2013-04-12 17:12 ——– d—–w- C:\Program Backups 2013-04-12 11:39 . 2013-04-10 06:58 26520 —-a-w- c:\program files (x86)\Mozilla Firefox\plugin-hang-ui.exe 2013-04-12 11:12 . 2013-04-12 11:16 ——– d—–w- c:\users\Sungkua\AppData\Roaming\QuickScan 2013-04-12 04:55 . 2013-04-12 04:54 95648 —-a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2013-04-10 10:03 . 2013-02-22 06:21 1346560 —-a-w- c:\windows\system32\urlmon.dll 2013-04-10 04:39 . 2013-02-21 04:26 3138048 —-a-w- c:\windows\system32\mstscax.dll 2013-04-10 04:39 . 2013-02-21 04:26 44032 —-a-w- c:\windows\system32\tsgqec.dll 2013-04-10 04:39 . 2013-02-21 04:26 158208 —-a-w- c:\windows\system32\aaclient.dll 2013-04-10 04:39 . 2013-02-21 03:52 36864 —-a-w- c:\windows\SysWow64\tsgqec.dll 2013-04-10 04:39 . 2013-02-21 03:52 2691072 —-a-w- c:\windows\SysWow64\mstscax.dll 2013-04-10 04:39 . 2013-02-21 03:52 131072 —-a-w- c:\windows\SysWow64\aaclient.dll 2013-04-10 04:39 . 2013-03-03 19:13 1513320 —-a-w- c:\windows\system32\drivers\ntfs.sys 2013-04-10 04:39 . 2013-03-11 13:33 4691304 —-a-w- c:\windows\system32\ntoskrnl.exe 2013-04-10 04:39 . 2013-03-09 04:16 85504 —-a-w- c:\windows\system32\csrsrv.dll 2013-04-10 04:39 . 2013-03-09 01:48 75264 —-a-w- c:\windows\system32\smss.exe 2013-04-10 04:39 . 2013-03-05 01:57 2774016 —-a-w- c:\windows\system32\win32k.sys 2013-04-10 04:39 . 2013-03-08 04:18 451072 —-a-w- c:\windows\system32\winsrv.dll 2013-04-10 01:18 . 2013-04-10 01:18 ——– d—–w- c:\program files (x86)\Common Files\Skype 2013-03-30 00:30 . 2013-03-30 00:29 310688 —-a-w- c:\windows\system32\javaws.exe 2013-03-30 00:30 . 2013-03-30 00:29 108448 —-a-w- c:\windows\system32\WindowsAccessBridge-64.dll 2013-03-30 00:30 . 2013-03-30 00:29 188832 —-a-w- c:\windows\system32\javaw.exe 2013-03-30 00:30 . 2013-03-30 00:29 188320 —-a-w- c:\windows\system32\java.exe . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-04-12 11:45 . 2012-04-12 05:00 691592 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-04-12 11:45 . 2011-05-22 15:50 71048 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-04-12 04:54 . 2012-07-17 04:42 861088 —-a-w- c:\windows\SysWow64\npdeployJava1.dll 2013-04-12 04:54 . 2010-08-16 01:47 782240 —-a-w- c:\windows\SysWow64\deployJava1.dll 2013-04-10 10:07 . 2006-11-02 12:35 72702784 —-a-w- c:\windows\system32\mrt.exe 2013-04-04 21:50 . 2011-10-02 16:58 25928 —-a-w- c:\windows\system32\drivers\mbam.sys 2013-03-30 00:29 . 2012-10-11 05:19 963488 —-a-w- c:\windows\system32\deployJava1.dll 2013-03-30 00:29 . 2012-10-11 05:19 1085344 —-a-w- c:\windows\system32\npDeployJava1.dll 2013-03-12 08:10 . 2009-10-19 02:46 282744 ——w- c:\windows\system32\MpSigStub.exe 2013-03-06 23:33 . 2013-03-20 06:14 178624 —-a-w- c:\windows\system32\drivers\aswVmm.sys 2013-03-06 23:33 . 2013-03-20 06:14 65336 —-a-w- c:\windows\system32\drivers\aswRvrt.sys 2013-03-06 23:33 . 2011-05-08 16:53 1025808 —-a-w- c:\windows\system32\drivers\aswSnx.sys 2013-03-06 23:33 . 2010-09-05 05:24 377920 —-a-w- c:\windows\system32\drivers\aswSP.sys 2013-03-06 23:33 . 2010-09-05 05:24 68920 —-a-w- c:\windows\system32\drivers\aswTdi.sys 2013-03-06 23:33 . 2010-09-05 05:24 33400 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys 2013-03-06 23:33 . 2010-09-05 05:24 59144 —-a-w- c:\windows\system32\drivers\aswRdr.sys 2013-03-06 23:33 . 2010-09-05 05:23 80816 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys 2013-03-06 23:32 . 2010-09-05 05:22 41664 —-a-w- c:\windows\avastSS.scr 2013-03-06 23:32 . 2011-01-26 02:05 287840 —-a-w- c:\windows\system32\aswBoot.exe 2013-02-12 02:18 . 2013-03-21 18:08 19456 —-a-w- c:\windows\system32\drivers\usb8023.sys 2013-02-10 03:25 . 2013-02-19 03:14 6267240 —-a-w- c:\windows\SysWow64\nvopencl.dll 2013-02-10 03:25 . 2013-02-19 03:14 15275744 —-a-w- c:\windows\system32\nvwgf2umx.dll 2013-02-10 03:25 . 2013-02-19 03:14 7569184 —-a-w- c:\windows\system32\nvopencl.dll 2013-02-10 03:25 . 2013-02-19 03:14 26947360 —-a-w- c:\windows\system32\nvoglv64.dll 2013-02-10 03:25 . 2013-02-19 03:14 20534560 —-a-w- c:\windows\SysWow64\nvoglv32.dll 2013-02-10 03:25 . 2013-02-19 03:14 11040544 —-a-w- c:\windows\system32\drivers\nvlddmkm.sys 2013-02-10 03:25 . 2013-02-19 03:14 7964680 —-a-w- c:\windows\SysWow64\nvcuda.dll 2013-02-10 03:25 . 2013-02-19 03:14 2911008 —-a-w- c:\windows\system32\nvcuvid.dll 2013-02-10 03:25 . 2013-02-19 03:14 2726176 —-a-w- c:\windows\SysWow64\nvcuvid.dll 2013-02-10 03:25 . 2013-02-19 03:14 2350368 —-a-w- c:\windows\system32\nvcuvenc.dll 2013-02-10 03:25 . 2013-02-19 03:14 1990944 —-a-w- c:\windows\SysWow64\nvcuvenc.dll 2013-02-10 03:25 . 2013-02-19 03:14 1807136 —-a-w- c:\windows\system32\nvdispco6420294.dll 2013-02-10 03:25 . 2013-02-19 03:14 1510176 —-a-w- c:\windows\system32\nvdispgenco6420162.dll 2013-02-10 03:25 . 2013-02-19 03:14 9422672 —-a-w- c:\windows\system32\nvcuda.dll 2013-02-10 03:25 . 2013-02-19 03:14 25256736 —-a-w- c:\windows\system32\nvcompiler.dll 2013-02-10 03:25 . 2013-02-19 03:14 17560352 —-a-w- c:\windows\SysWow64\nvcompiler.dll 2013-02-10 03:25 . 2013-01-13 00:02 12862400 —-a-w- c:\windows\SysWow64\nvwgf2um.dll 2013-02-10 03:25 . 2013-01-13 00:02 2854344 —-a-w- c:\windows\system32\nvapi64.dll 2013-02-10 03:25 . 2013-01-13 00:02 2528840 —-a-w- c:\windows\SysWow64\nvapi.dll 2013-02-10 03:25 . 2013-01-13 00:02 17987192 —-a-w- c:\windows\system32\nvd3dumx.dll 2013-02-10 03:25 . 2013-01-13 00:02 15038296 —-a-w- c:\windows\SysWow64\nvd3dum.dll 2013-02-10 01:04 . 2013-01-13 00:04 6393120 —-a-w- c:\windows\system32\nvcpl.dll 2013-02-10 01:04 . 2013-01-13 00:04 3472672 —-a-w- c:\windows\system32\nvsvc64.dll 2013-02-10 01:04 . 2013-01-13 00:04 63776 —-a-w- c:\windows\system32\nvshext.dll 2013-02-10 01:04 . 2013-01-13 00:04 877856 —-a-w- c:\windows\system32\nvvsvc.exe 2013-02-10 01:04 . 2013-01-13 00:04 237856 —-a-w- c:\windows\system32\nvmctray.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP] @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}] 2008-07-30 00:52 121392 —-a-w- c:\program files (x86)\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 138240] "SpybotSD TeaTimer"="c:\program files (x86)\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] "Logitech Vid"="c:\program files (x86)\Logitech\Vid HD\Vid.exe" [2011-01-13 6129496] "KiesPreload"="c:\program files (x86)\Samsung\Kies\Kies.exe" [2012-12-21 1476104] "KiesAirMessage"="c:\program files (x86)\Samsung\Kies\KiesAirMessage.exe" [2012-12-18 578560] "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-03-01 18642024] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "PCMMediaSharing"="c:\program files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe" [2008-05-21 204908] "BkupTray"="c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" [2008-04-26 28672] "Acer Product Registration"="c:\program files (x86)\Acer\Acer Registration\ACE1.exe" [2007-11-26 3387392] "Acer Assist Launcher"="c:\program files (x86)\Acer\Acer Assist\launcher.exe" [2007-11-19 1261568] "InstantBurn"="c:\progra~2\CYBERL~1\INSTAN~1\Win2K\IBurn.exe" [2010-04-20 697640] "CLMLServer"="c:\program files (x86)\CyberLink\Power2Go\CLMLSvc.exe" [2009-11-02 103720] "RemoteControl9"="c:\program files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe" [2009-07-06 87336] "BDRegion"="c:\program files (x86)\Cyberlink\Shared files\brs.exe" [2010-05-14 75048] "UpdatePPShortCut"="c:\program files (x86)\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504] "UpdatePSTShortCut"="c:\program files (x86)\CyberLink\Blu-ray Disc Suite\MUITransfer\MUIStartMenu.exe" [2010-05-29 222504] "LWS"="c:\program files (x86)\Logitech\LWS\Webcam Software\LWS.exe" [2011-08-12 205336] "avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2013-03-06 4767304] "Bing Bar"="c:\program files (x86)\MSN Toolbar\Platform\5.0.1423.0\mswinext.exe" [2010-03-24 243544] "Microsoft Default Manager"="c:\program files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-11-12 288088] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-12-12 152544] "KiesTrayAgent"="c:\program files (x86)\Samsung\Kies\KiesTrayAgent.exe" [2012-12-21 310280] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ usb7100 Startup.lnk - c:\program files (x86)\Cordless USB Phone\Vtech Cordless Phone Suite.exe [2010-9-22 608768] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc] @="Service" . — Other Services/Drivers In Memory — . *NewlyCreated* - WINDEFEND *Deregistered* - CLKMDRV10_9EC60124 . HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs Themes . Contents of the 'Scheduled Tasks' folder . 2013-04-22 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-12 00:06] . 2013-04-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-350625352-3121310031-1665620277-1000Core.job - c:\users\Sungkua\AppData\Local\Google\Update\GoogleUpdate.exe [2013-04-10 00:25] . 2013-04-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-350625352-3121310031-1665620277-1000UA.job - c:\users\Sungkua\AppData\Local\Google\Update\GoogleUpdate.exe [2013-04-10 00:25] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2013-03-06 23:32 133840 —-a-w- c:\program files\Alwil Software\Avast5\ashShA64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP] @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}] 2008-07-30 00:53 50736 —-a-w- c:\program files (x86)\Acer\Empowering Technology\eDataSecurity\x64\PSDProtect.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Acer Empowering Technology Monitor"="c:\program files\Acer\Empowering Technology\SysMonitor.exe" [2008-06-02 319488] "EmpoweringTechnology"="c:\program files\Acer\Empowering Technology\Framework.Launcher.exe" [2008-06-02 319488] "eDataSecurity Loader"="c:\program files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDSloader.exe" [2008-07-30 561200] "CmPCIaudio"="c:\windows\Syswow64\CmiCnfg3.dll" [2008-10-29 7700480] "Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 660360] "EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2011-10-07 1744152] "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-08-01 2417032] "LogMeIn GUI"="c:\program files (x86)\LogMeIn\x64\LogMeInSystray.exe" [BU] . ——- Supplementary Scan ——- . uStart Page = about:blank uLocal Page = c:\windows\system32\blank.htm mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=1&o=vp64&d=0309&m=aspire_m3201 mDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=1&o=vp64&d=0309&m=aspire_m3201 mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html Trusted Zone: comcast.net\xfinitytv Trusted Zone: microsoft.com\*.update Trusted Zone: microsoft.com\update Trusted Zone: microsoft.com\www.update Trusted Zone: netflix.com Trusted Zone: windowsupdate.com\download TCP: DhcpNameServer = 192.168.1.1 FF - ProfilePath - c:\users\Sungkua\AppData\Roaming\Mozilla\Firefox\Profiles\y8g7xt6i.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - prefs.js: network.proxy.type - 0 FF - ExtSQL: 2013-04-12 04:40; {CAFEEFAC-0016-0000-0043-ABCDEFFEDCBA}; c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0043-ABCDEFFEDCBA} FF - ExtSQL: 2013-04-18 14:09; {73a6fe31-595d-460b-a920-fcc0f8843232}; c:\users\Sungkua\AppData\Roaming\Mozilla\Firefox\Profiles\y8g7xt6i.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi FF - ExtSQL: 2013-04-19 11:19; {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}; c:\users\Sungkua\AppData\Roaming\Mozilla\Firefox\Profiles\y8g7xt6i.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} . - - - - ORPHANS REMOVED - - - - . BHO-{8A86D350-37AB-410A-8531-7D1363F317B3} - c:\program files (x86)\Brand Affinity Technologies\Fantapper Player\\IEInstaller.dll Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file) . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_169_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_169_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_169_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_169_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_169.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_169.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_169.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_169.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}] @Denied: (A 2) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0] @="Shockwave Flash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}] @Denied: (A 2) (Everyone) @="" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0] @="FlashBroker" . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows CE Services] "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\ . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . Completion time: 2013-04-22 09:01:01 ComboFix-quarantined-files.txt 2013-04-22 16:01 ComboFix2.txt 2013-04-21 16:05 . Pre-Run: 91,147,878,400 bytes free Post-Run: 91,077,541,888 bytes free . - - End Of File - - E7E7DB0DB4F468A14A06F7357DF0CBBB
Please run the following:

Visit ADOBE and download the latest version of Acrobat Reader (version XI)
Having the latest updates ensures there are no security vulnerabilities in your system.
Decline any additional installs that may be offered.

NEXT

[external image: Posted Image]
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
  • Download the latest version of Java Runtime Environment (JRE) 7 and Save it to your Desktop.
  • Scroll down to where it says Java SE 7u21
  • Click the Download button under JRE to the right.
  • Read the License Agreement then select Accept License Agreement
  • Click on the link to download Windows x86 Offline and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add or Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-7u21-windows-i586.exe to install the newest version.
  • Decline any additional installs that may be offered.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
  • On the General tab, under Temporary Internet Files, click the Settings button.
  • Next, click on the Delete Files button
  • There are three options in the window to clear the cache - Leave these two Checked
    Trace and Log Files
    Cached Applications and Applets
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.


Please advise how the computer is running now and if there are any outstanding issues
Thank you CatByte, I wasn't able to download the Acrobat XI initially, since I specified Windows VISTA as my OS. Adobe doesn't list XI as being compatible with VISTA, but I did google some details and found out that VISTA 64Bit Home Premium with SP2 has been successful in using XI, so I changed the OS request to Windows 7 and was able to download and update to XI. The upgrade for Java 7 went without a hitch and I decided to uninstall Java 6 even though I had the current update. The temporary files were deleted as instructed. I've now had over a day to play with my videos online and have found it more stable. There are occasional stalls, but the videos now continue after a short wait. In the past it would reset back to resume, reset back to the beginning or not play until I refreshed the page. One side note. I did find that the Windows Firewall for VISTA does allow for IP blocking and other restrictions by using the control panel under the Windows Start Button search for, "Windows Firewall with Advanced Security". I added both an inbound and outbound rule for the Zimbabwe IP initially found in the DDS log. Now that I have somewhat better control of the system, I feel comfortable where it is - unless you feel there is anything else that needs to be addressed. Kind Regards,
Hi CatByte, Well, I guess I spoke too soon. I turned back on my scheduling of AVAST and ran a new scan. About two hours into it, I happened to look at the result screen, and it showed that there was one infection while still only at 1%. I haven't stopped the scan to see what the infection is, but will wait for it to complete and follow up with the virus finding(s) and a DDS log.
Got back from class and the scan finished with just the one infection. It specified a Trojan WIn32:Banker-KDL, but said it was in the memory block of firefox.exe. After looking up additional information on AVAST Memory virus positives, I found out that you shouldn't have a memory scan done along with the regular scheduled scans since it produces false positives. I would be okay with this answer, but during the full scan, I did see some strange error messages come up which made me decide to turn off my router before going to class. There were two script error messages that said that a script was not responding in Chrome and I could choose between stopping the script or waiting for it to respond. My concern is that I do not have Chrome installed on my computer so I was confused why this program was being specified. Just in case you feel it's necessary, here are the two DDS logs if you feel further investigation is necessary. I will be turning off my computer and using my clean notebook to wait for your reply before turning the computer back on
without seeing the report, I'd say it's likely identifying something in the broswer history, empty your browser history to clear that detection.

please run the following:

•Download RogueKiller and save it to your desktop.
•Quit all other programs
•Start RogueKiller.exe
•Wait until the Prescan has finished …
•Click on Scan
•Wait for the end of the scan
•Click on Report when the scan has finished, copy/paste the content of the notepad into your next reply
Thanks CatByte,

Here is the report:

RogueKiller V8.5.4 _x64_ [Mar 18 2013] by Tigzy
mail : tigzyRKgmailcom
Feedback : http://www.geekstogo.com/forum/files/file/413-roguekiller/
Website : http://tigzy.geekstogo.com/roguekiller.php
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows Vista (6.0.6002 Service Pack 2) 64 bits version
Started in : Normal mode
User : Sungkua [Admin rights]
Mode : Scan – Date : 04/25/2013 08:21:46
| ARK || FAK || MBR |

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 5 ¤¤¤
[RUN][BLACKLISTDLL] HKLM\[…]\Run : CmPCIaudio (C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\CmiCnfg3.dll,CMICtrlWnd) -> FOUND
[HJPOL] HKLM\[…]\System : DisableRegistryTools (0) -> FOUND
[HJPOL] HKLM\[…]\Wow6432Node\System : DisableRegistryTools (0) -> FOUND
[HJ DESK] HKLM\[…]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [NOT LOADED] ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
–> C:\Windows\system32\drivers\etc\hosts

127.0.0.1 localhost


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: WDC WD64 00AACS-00G8B0 SCSI Disk Device +++++
— User —
[MBR] f86a234057a5c571d0b5ede57e2004c2
[BSP] b6e19e955e5199a5151519f207796a4b : Empty MBR Code
Partition table:
0 - [XXXXXX] UNKNOWN (0xee) [VISIBLE] Offset (sectors): 1 | Size: 200 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 409640 | Size: 610280 Mo
User = LL1 … OK!
Error reading LL2 MBR!

+++++ PhysicalDrive1: WDC WD64 00AAKS-22A7B2 SCSI Disk Device +++++
— User —
[MBR] cc93ce1e9b4790d53a11a8489b28837d
[BSP] 37c4d96bc87fffbc9fb8f4b8dd00bd72 : Acer MBR Code
Partition table:
0 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 63 | Size: 15005 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 30734336 | Size: 238170 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 518506496 | Size: 357302 Mo
User = LL1 … OK!
Error reading LL2 MBR!

Finished : << RKreport[1]_S_04252013_02d0821.txt >>
RKreport[1]_S_04252013_02d0821.txt

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI