This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Win32/Small.CA virus? [Closed]

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My action center tells me to remove this virus. Avira is not working properly. Other than that, I've had no symptoms. Report pasted as instructed and second report attached. . DDS (Ver_11-03-05.01) - NTFS_AMD64 Run by [removed] at 16:17:03.62 on Thu 05/30/2013 Internet Explorer: 9.0.8112.16421 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.6050.3760 [GMT -4:00] . AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:windowssystem32wininit.exe C:windowssystem32lsm.exe C:windowssystem32svchost.exe -k DcomLaunch C:windowssystem32svchost.exe -k RPCSS C:windowsSystem32svchost.exe -k LocalServiceNetworkRestricted C:windowsSystem32svchost.exe -k LocalSystemNetworkRestricted C:windowssystem32svchost.exe -k LocalService C:windowssystem32svchost.exe -k netsvcs C:Program FilesIDTWDMSTacSV64.exe C:windowssystem32svchost.exe -k NetworkService C:windowssystem32WLANExt.exe C:windowssystem32conhost.exe C:windowsSystem32spoolsv.exe C:windowssystem32svchost.exe -k LocalServiceNoNetwork C:Program Files (x86)Common FilesAdobeARM1.0armsvc.exe C:Program FilesIDTWDMAESTSr64.exe C:Program FilesIntelBluetoothHSBTHSAmpPalService.exe C:Program Files (x86)Common FilesAppleMobile Device SupportAppleMobileDeviceService.exe C:Program Files (x86)IntelBluetoothdevmonsrv.exe C:Program FilesBonjourmDNSResponder.exe C:windowssystem32svchost.exe -k bthsvcs C:Program FilesIntelBluetoothHSBTHSSecurityMgr.exe C:Program FilesIntelWiFibinEvtEng.exe C:windowssystem32svchost.exe -k LocalServiceAndNoImpersonation C:ProgramDataFreemakeFreemakeUtilsServiceFreemakeUtilsService.exe C:Program Files (x86)DellDell Datasafe OnlineNOBuAgent.exe C:Program FilesCommon FilesIntelWirelessCommonRegSrvc.exe C:Program Files (x86)Dell DataSafe Local Backupsftservice.EXE C:windowssystem32svchost.exe -k imgsvc C:Program FilesCommon FilesMicrosoft SharedWindows LiveWLIDSVC.EXE C:Program Files (x86)IntelBluetoothobexsrv.exe C:Program FilesCommon FilesMicrosoft SharedWindows LiveWLIDSvcM.exe C:windowssystem32svchost.exe -k NetworkServiceNetworkRestricted C:windowsSystem32WUDFHost.exe C:windowssystem32wbemunsecapp.exe C:windowssystem32wbemwmiprvse.exe C:windowssystem32wbemwmiprvse.exe C:windowssystem32taskhost.exe C:windowssystem32Dwm.exe C:Program Files (x86)Dell DataSafe Local BackupTOASTER.EXE C:windowsExplorer.EXE C:Program Files (x86)Dell DataSafe Local BackupCOMPONENTSSCHEDULERSTSERVICE.EXE C:Program Files (x86)Dell DataSafe Local BackupComponentsDSUpdateDSUpd.exe C:WindowsSystem32igfxtray.exe C:WindowsSystem32igfxpers.exe C:Program FilesIDTWDMsttray64.exe C:Program FilesDellTPadApoint.exe C:Program FilesDellQuickSetquickset.exe C:Program FilesCommon FilesIntelWirelessCommoniFrmewrk.exe C:WindowsSystem32rundll32.exe C:UsersMadoAppDataLocalAkamainetsession_win.exe C:Program Files (x86)SkypePhoneSkype.exe C:Program Files (x86)IntelIntel® Rapid Storage TechnologyIAStorIcon.exe C:Program Files (x86)NeroSyncUPNeroLauncher.exe C:Program FilesDellTPadApMsgFwd.exe C:windowssystem32SearchIndexer.exe C:Program Files (x86)OpenOffice.org 3programsoffice.exe C:Program FilesDellTPadApntex.exe C:windowssystem32conhost.exe C:Program FilesDellTPadHidFind.exe C:windowssystem32wbemunsecapp.exe C:Program Files (x86)Common FilesAdobeARM1.0AdobeARM.exe C:Program Files (x86)Dell StageDell StageAccuWeatheraccuweather.exe C:Program Files (x86)AviraAntiVir Desktopavgnt.exe C:UsersMadoAppDataLocalAkamainetsession_win.exe C:Program Files (x86)OpenOffice.org 3programsoffice.bin C:Program Files (x86)iTunesiTunesHelper.exe C:Program Files (x86)IntelBluetoothmediasrv.exe C:Program FilesiPodbiniPodService.exe C:Program FilesWindows Media Playerwmpnetwk.exe C:Program Files (x86)IntelBluetoothBTPlayerCtrl.exe C:windowssystem32SearchProtocolHost.exe C:windowsSystem32svchost.exe -k LocalServicePeerNet C:Program Files (x86)IntelIntel® Rapid Storage TechnologyIAStorDataMgrSvc.exe C:Program Files (x86)IntelIntel® Management Engine ComponentsLMSLMS.exe C:windowssystem32DllHost.exe C:Program Files (x86)NeroUpdateNASvc.exe C:windowssystem32sppsvc.exe C:windowssystem32taskeng.exe C:Program Files (x86)Common FilesJavaJava Updatejusched.exe C:windowsSystem32svchost.exe -k secsvcs C:Program Files (x86)Mozilla Firefoxfirefox.exe C:Program Files (x86)IntelIntel® Management Engine ComponentsUNSUNS.exe C:Program Files (x86)Mozilla Firefoxplugin-container.exe C:windowsSysWOW64MacromedFlashFlashPlayerPlugin_11_7_700_202.exe C:windowsSysWOW64MacromedFlashFlashPlayerPlugin_11_7_700_202.exe C:windowssystem32taskeng.exe C:windowssystem32SearchFilterHost.exe C:Program Files (x86)Common FilesJavaJava Updatejucheck.exe C:windowssystem32taskhost.exe C:windowssystem32DllHost.exe C:windowssystem32DllHost.exe C:UsersMadoDownloadsdds.scr C:windowssystem32conhost.exe . ============== Pseudo HJT Report =============== . uInternet Settings,ProxyOverride = ;*.local mWinlogon: Userinit=userinit.exe BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:Program Files (x86)Common FilesAdobeAcrobatActiveXAcroIEHelperShim.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:Program Files (x86)Common FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:Program Files (x86)Javajre6binjp2ssv.dll uRun: [Akamai NetSession Interface] "C:UsersMadoAppDataLocalAkamainetsession_win.exe" uRun: [Skype] "C:Program Files (x86)SkypePhoneSkype.exe" /minimized /regrun mRun: [IAStorIcon] C:Program Files (x86)IntelIntel® Rapid Storage TechnologyIAStorIcon.exe mRun: [NeroLauncher] C:Program Files (x86)NeroSyncUPNeroLauncher.exe 900 mRun: [Dell DataSafe Online] C:Program Files (x86)DellDell Datasafe OnlineNOBuClient.exe mRun: [Adobe Reader Speed Launcher] "C:Program Files (x86)AdobeReader 10.0ReaderReader_sl.exe" mRun: [Adobe ARM] "C:Program Files (x86)Common FilesAdobeARM1.0AdobeARM.exe" mRun: [AccuWeatherWidget] "C:Program Files (x86)Dell StageDell StageAccuWeatheraccuweather.exe" "C:Program Files (x86)Dell StageDell StageAccuWeatherstart.umj" –startup mRun: [avgnt] "C:Program Files (x86)AviraAntiVir Desktopavgnt.exe" /min mRun: [APSDaemon] "C:Program Files (x86)Common FilesAppleApple Application SupportAPSDaemon.exe" mRun: [iTunesHelper] "C:Program Files (x86)iTunesiTunesHelper.exe" mRunOnce: [Launcher] C:Program Files (x86)Dell DataSafe Local BackupComponentsSchedulerLauncher.exe StartupFolder: C:UsersMadoAppDataRoamingMICROS~1WindowsSTARTM~1ProgramsStartupOPENOF~1.LNK - C:Program Files (x86)OpenOffice.org 3programquickstart.exe mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:Program Files (x86)Windows LiveWriterWriterBrowserExtension.dll LSP: C:Program Files (x86)AviraAntiVir Desktopavsda.dll DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} - hxxp://ccfiles.creative.com/Web/softwareupdate/su/ocx/15102/CTSUEng.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/121022/CTPID.cab Handler: cozi - {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - C:Program Files (x86)Cozi ExpressCoziProtocolHandler.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:PROGRA~2COMMON~1SkypeSKYPE4~1.DLL Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:Program Files (x86)Windows LivePhoto GalleryAlbumDownloadProtocolHandler.dll BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program FilesCommon FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:Program FilesJavajre6binjp2ssv.dll mRun-x64: [IgfxTray] C:Windowssystem32igfxtray.exe mRun-x64: [HotKeysCmds] C:Windowssystem32hkcmd.exe mRun-x64: [Persistence] C:Windowssystem32igfxpers.exe mRun-x64: [SysTrayApp] C:Program FilesIDTWDMsttray64.exe mRun-x64: [Apoint] C:Program FilesDellTPadApoint.exe mRun-x64: [QuickSet] C:Program FilesDellQuickSetQuickSet.exe mRun-x64: [IntelTBRunOnce] wscript.exe //b //nologo "C:Program FilesIntelTurboBoostRunTBGadgetOnce.vbs" mRun-x64: [IntelPAN] "C:Program FilesCommon FilesIntelWirelessCommoniFrmewrk.exe" /tf Intel PAN Tray mRun-x64: [BTMTrayAgent] rundll32.exe "C:Program Files (x86)IntelBluetoothbtmshell.dll",TrayApp mRun-x64: [DellStage] "C:Program Files (x86)Dell StageDell Stagestage_primary.exe" "C:Program Files (x86)Dell StageDell Stagestart.umj" –startup . ================= FIREFOX =================== . FF - ProfilePath - C:UsersMadoAppDataRoamingMozillaFirefoxProfiles1mby5nem.default FF - prefs.js: browser.startup.homepage - hxxp://www.mail.yahoo.com FF - plugin: C:Program Files (x86)AdobeReader 10.0ReaderAIRnppdf32.dll FF - plugin: C:Program Files (x86)Javajre6binnew_pluginnpdeployJava1.dll FF - plugin: c:Program Files (x86)Microsoft Silverlight5.1.20125.0npctrlui.dll FF - plugin: C:Program Files (x86)WildTangent GamesAppBrowserIntegrationRegistered\0NP_wtapp.dll FF - plugin: C:Program Files (x86)Windows LivePhoto GalleryNPWLPG.dll FF - plugin: C:windowsSysWOW64MacromedFlashNPSWF32_11_7_700_202.dll . ============= SERVICES / DRIVERS =============== . R1 avkmgr;avkmgr;C:WindowsSystem32driversavkmgr.sys [2013-3-21 28600] R1 vwififlt;Virtual WiFi Filter Driver;C:WindowsSystem32driversvwififlt.sys [2009-7-13 59904] R2 AdobeARMservice;Adobe Acrobat Update Service;C:Program Files (x86)Common FilesAdobeARM1.0armsvc.exe [2012-7-27 63960] R2 AESTFilters;Andrea ST Filters Service;C:Program FilesIDTWDMAESTSr64.exe [2012-1-14 89600] R2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service;C:Program FilesIntelBluetoothHSBTHSAmpPalService.exe [2011-9-15 1166848] R2 avgntflt;avgntflt;C:WindowsSystem32driversavgntflt.sys [2013-3-21 100712] R2 Bluetooth Device Monitor;Bluetooth Device Monitor;C:Program Files (x86)IntelBluetoothdevmonsrv.exe [2011-5-19 921664] R2 Bluetooth OBEX Service;Bluetooth OBEX Service;C:Program Files (x86)IntelBluetoothobexsrv.exe [2011-5-19 995392] R2 BTHSSecurityMgr;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Security Service;C:Program FilesIntelBluetoothHSBTHSSecurityMgr.exe [2011-6-3 134928] R2 Freemake Improver;Freemake Improver;C:ProgramDataFreemakeFreemakeUtilsServiceFreemakeUtilsService.exe [2013-1-22 100864] R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:Program Files (x86)IntelIntel® Rapid Storage TechnologyIAStorDataMgrSvc.exe [2012-1-14 13336] R2 NAUpdate;Nero Update;C:Program Files (x86)NeroUpdateNASvc.exe [2011-11-25 687400] R2 NOBU;Dell DataSafe Online;C:Program Files (x86)DellDell Datasafe OnlineNOBuAgent.exe [2010-8-25 2823000] R2 SftService;SoftThinks Agent Service;C:Program Files (x86)Dell DataSafe Local BackupSftService.exe [2012-1-14 1692480] R2 TurboB;Turbo Boost UI Monitor driver;C:WindowsSystem32driversTurboB.sys [2010-11-29 16120] R2 UNS;Intel® Management and Security Application User Notification Service;C:Program Files (x86)IntelIntel® Management Engine ComponentsUNSUNS.exe [2012-1-14 2655768] R3 AMPPAL;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Virtual Adapter;C:WindowsSystem32driversAmpPal.sys [2011-9-15 299008] R3 Bluetooth Media Service;Bluetooth Media Service;C:Program Files (x86)IntelBluetoothmediasrv.exe [2011-5-19 1335360] R3 btmaudio;Intel Bluetooth Audio Service;C:WindowsSystem32driversbtmaud.sys [2011-5-19 51712] R3 btmaux;Intel Bluetooth Auxiliary Service;C:WindowsSystem32driversbtmaux.sys [2011-5-19 53248] R3 btmhsf;btmhsf;C:WindowsSystem32driversbtmhsf.sys [2011-7-19 282624] R3 CtClsFlt;Creative Camera Class Upper Filter Driver;C:WindowsSystem32driversCtClsFlt.sys [2012-1-14 176096] R3 iBtFltCoex;iBtFltCoex;C:WindowsSystem32driversiBtFltCoex.sys [2011-7-19 59904] R3 IntcDAud;Intel® Display Audio;C:WindowsSystem32driversIntcDAud.sys [2012-1-14 317440] R3 iwdbus;IWD Bus Enumerator;C:WindowsSystem32driversiwdbus.sys [2011-6-21 25496] R3 MEIx64;Intel® Management Engine Interface;C:WindowsSystem32driversHECIx64.sys [2012-1-14 56344] R3 NETwNs64;___ Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:WindowsSystem32driversNETwNs64.sys [2011-9-18 8604672] R3 RTL8167;Realtek 8167 NT Driver;C:WindowsSystem32driversRt64win7.sys [2012-1-14 406632] R3 tihub3;TI USB3 Hub Service;C:WindowsSystem32driverstihub3.sys [2011-7-20 136000] R3 tixhci;TI XHCI Service;C:WindowsSystem32driverstixhci.sys [2011-7-20 406336] R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:WindowsSystem32driversvwifimp.sys [2009-7-13 17920] S2 AntiVirMailService;Avira Mail Protection;C:Program Files (x86)AviraAntiVir Desktopavmailc.exe [2012-11-27 371768] S2 AntiVirSchedulerService;Avira Scheduler;C:Program Files (x86)AviraAntiVir Desktopsched.exe [2012-11-27 86752] S2 AntiVirService;Avira Real-Time Protection;C:Program Files (x86)AviraAntiVir Desktopavguard.exe [2012-11-27 110816] S2 AntiVirWebService;Avira Web Protection;C:Program Files (x86)AviraAntiVir Desktopavwebgrd.exe [2012-11-27 562744] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:WindowsMicrosoft.NETFrameworkv4.0.30319mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:WindowsMicrosoft.NETFramework64v4.0.30319mscorsvw.exe [2010-3-18 138576] S2 DellDigitalDelivery;Dell Digital Delivery Service;C:Program Files (x86)Dell Digital DeliveryDeliveryService.exe [2011-10-26 162816] S2 SkypeUpdate;Skype Updater;C:Program Files (x86)SkypeUpdaterUpdater.exe [2013-2-28 161384] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:WindowsSysWOW64MacromedFlashFlashPlayerUpdateService.exe [2012-7-10 256904] S3 AMPPALP;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Protocol;C:WindowsSystem32driversAmpPal.sys [2011-9-15 299008] S3 GamesAppService;GamesAppService;C:Program Files (x86)WildTangent GamesAppGamesAppService.exe [2010-10-12 206072] S3 intaud_WaveExtensible;Intel WiDi Audio Device;C:WindowsSystem32driversintelaud.sys [2011-6-21 34200] S3 MozillaMaintenance;Mozilla Maintenance Service;C:Program Files (x86)Mozilla Maintenance Servicemaintenanceservice.exe [2012-11-26 117144] S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:Program FilesIntelWiFibinPanDhcpDns.exe [2011-9-15 340240] S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:WindowsSystem32driversRtsUStor.sys [2012-1-14 250984] S3 TsUsbFlt;TsUsbFlt;C:WindowsSystem32driversTsUsbFlt.sys [2010-11-20 59392] S3 TsUsbGD;Remote Desktop Generic USB Device;C:WindowsSystem32driversTsUsbGD.sys [2010-11-20 31232] S3 TurboBoost;Intel® Turbo Boost Technology Monitor 2.0;C:Program FilesIntelTurboBoostTurboBoost.exe [2010-11-29 149504] S3 USBAAPL64;Apple Mobile USB Driver;C:WindowsSystem32driversusbaapl64.sys [2012-12-13 54784] S3 WatAdminSvc;Windows Activation Technologies Service;C:WindowsSystem32WatWatAdminSvc.exe [2012-5-8 1255736] S4 wlcrasvc;Windows Live Mesh remote connections service;C:Program FilesWindows LiveMeshwlcrasvc.exe [2010-9-22 57184] . =============== Created Last 30 ================ . 2013-05-26 18:55:05 76232 —-a-w- C:PROGRA~3MicrosoftWindows DefenderDefinition Updates{7CE3AC30-5CB6-45B5-B3F4-0A9C99C0472E}offreg.dll 2013-05-26 18:51:34 8199504 —-a-w- C:PROGRA~3MicrosoftWindows DefenderDefinition UpdatesBackupmpengine.dll 2013-05-26 18:51:30 9460464 —-a-w- C:PROGRA~3MicrosoftWindows DefenderDefinition Updates{7CE3AC30-5CB6-45B5-B3F4-0A9C99C0472E}mpengine.dll 2013-05-25 20:57:26 ——– d—–w- C:UsersMadoAppDataRoamingMalwarebytes 2013-05-25 20:57:17 25928 —-a-w- C:windowsSystem32driversmbam.sys 2013-05-25 20:57:17 ——– d—–w- C:Program Files (x86)Malwarebytes' Anti-Malware 2013-05-25 20:57:17 ——– d—–w- C:PROGRA~3Malwarebytes 2013-05-23 20:13:26 ——– d—–w- C:PROGRA~3PC-Doctor for Windows 2013-05-23 20:12:57 ——– d—–w- C:Program FilesMy Dell 2013-05-20 01:50:34 ——– d—–w- C:Program FilesiPod 2013-05-20 01:50:33 ——– d—–w- C:Program FilesiTunes 2013-05-20 01:50:33 ——– d—–w- C:Program Files (x86)iTunes 2013-05-20 01:50:33 ——– d—–w- C:PROGRA~334BE82C4-E596-4e99-A191-52C6199EBF69 2013-05-09 11:48:20 ——– d-sh–w- C:found.000 . ==================== Find3M ==================== . 2013-05-15 19:15:23 71048 —-a-w- C:windowsSysWow64FlashPlayerCPLApp.cpl 2013-05-15 19:15:23 692104 —-a-w- C:windowsSysWow64FlashPlayerApp.exe 2013-04-12 14:45:08 1656680 —-a-w- C:windowsSystem32driversntfs.sys 2013-03-21 15:17:49 28600 —-a-w- C:windowsSystem32driversavkmgr.sys 2013-03-21 15:17:49 100712 —-a-w- C:windowsSystem32driversavgntflt.sys 2013-03-19 06:04:06 5550424 —-a-w- C:windowsSystem32ntoskrnl.exe 2013-03-19 05:46:56 43520 —-a-w- C:windowsSystem32csrsrv.dll 2013-03-19 05:04:13 3968856 —-a-w- C:windowsSysWow64ntkrnlpa.exe 2013-03-19 05:04:10 3913560 —-a-w- C:windowsSysWow64ntoskrnl.exe 2013-03-19 04:47:50 6656 —-a-w- C:windowsSysWow64apisetschema.dll 2013-03-19 03:06:33 112640 —-a-w- C:windowsSystem32smss.exe . ============= FINISH: 16:17:30.30 ===============

Attachments:

Hi and Welcome!!

My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:

  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • If you happen to have a flash drive/thumb drive please have that ready in the event that we need to use it.
  • Please be sure to subscribe to the topic if you have not already done so.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your operating system and losing all your programs and data.


Having said that…. [external image: Posted Image] Let's get going!!
———-

Sorry for any delay….do you still need help?
[external image: Posted Image] Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • If you are asked to update the Avast Virus database please allow it to do so.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-

[external image: Posted Image] AdwCleaner

Please download AdwCleaner by Xplode onto your desktop.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Search.
  • A logfile will automatically open after the scan has finished.
  • Please post the contents of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[R1].txt as well.
———-
Ok let's try this instead…

[external image: Posted Image] Please download TDSSKiller
  • Double click TDSSKiller.exe
  • Press Start Scan but do nothing else as we are just looking for what is there.
  • If Malicious objects are found, select Skip by changing the Cure dropdown in the upper right.
  • Attach the log in your next reply
  • A copy of the log will be saved automatically to the root of the drive (typically C:\)
ComboFix

Download Combofix from either of the links below, and save it to your desktop.
Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**
If you get a message saying "Illegal operation attempted on a registry key that has been marked for deletion", please restart your computer.


——————————————————————–

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

——————————————————————–

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
ComboFix 13-06-08.02 - Mado 06/10/2013 16:13:05.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.6050.3171 [GMT -4:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe c:\programdata\PCDr\6261\AddOnDownloaded\1e512ef2-01fb-49fb-b09b-71de0eac4612.dll c:\programdata\PCDr\6261\AddOnDownloaded\27ada864-54d8-46c9-a6e3-8334fa39b525.dll c:\programdata\PCDr\6261\AddOnDownloaded\2eccd5d6-e118-4f76-97b6-ba56fb6c597a.dll c:\programdata\PCDr\6261\AddOnDownloaded\3e0b29b2-9809-4050-abfc-ef8aff73ceab.dll c:\programdata\PCDr\6261\AddOnDownloaded\5f2ce3e8-3c56-40bb-86d6-a1a41867000b.dll c:\programdata\PCDr\6261\AddOnDownloaded\b69d9551-76e9-4872-95f8-075916f82d74.dll c:\programdata\Roaming . . ((((((((((((((((((((((((( Files Created from 2013-05-10 to 2013-06-10 ))))))))))))))))))))))))))))))) . . 2013-06-10 20:20 . 2013-06-10 20:20 ——– d—–w- c:\users\Guest\AppData\Local\temp 2013-06-10 20:20 . 2013-06-10 20:20 ——– d—–w- c:\users\Default\AppData\Local\temp 2013-06-10 15:56 . 2013-06-10 15:56 76232 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{80A89764-C249-466B-8C5C-582789FF2124}\offreg.dll 2013-06-10 15:55 . 2013-05-14 05:48 9460464 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{80A89764-C249-466B-8C5C-582789FF2124}\mpengine.dll 2013-06-08 22:17 . 2013-06-08 22:17 ——– d—–w- c:\program files\iPod 2013-06-08 22:17 . 2013-06-08 22:18 ——– d—–w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-06-08 22:17 . 2013-06-08 22:18 ——– d—–w- c:\program files\iTunes 2013-06-08 22:17 . 2013-06-08 22:18 ——– d—–w- c:\program files (x86)\iTunes 2013-05-25 20:57 . 2013-05-25 20:57 ——– d—–w- c:\users\Mado\AppData\Roaming\Malwarebytes 2013-05-25 20:57 . 2013-05-25 20:57 ——– d—–w- c:\program files (x86)\Malwarebytes' Anti-Malware 2013-05-25 20:57 . 2013-05-25 20:57 ——– d—–w- c:\programdata\Malwarebytes 2013-05-25 20:57 . 2013-04-04 18:50 25928 —-a-w- c:\windows\system32\drivers\mbam.sys 2013-05-23 20:13 . 2013-05-23 20:13 ——– d—–w- c:\programdata\PC-Doctor for Windows 2013-05-23 20:12 . 2013-05-28 17:38 ——– d—–w- c:\program files\My Dell . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-05-30 20:09 . 2010-06-24 17:33 22240 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2013-05-15 19:15 . 2012-07-11 01:32 692104 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-05-15 19:15 . 2012-01-14 17:30 71048 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-04-12 14:45 . 2013-04-23 21:17 1656680 —-a-w- c:\windows\system32\drivers\ntfs.sys 2013-04-12 07:04 . 2012-11-26 19:25 72702784 —-a-w- c:\windows\system32\MRT.exe 2013-03-21 15:17 . 2013-03-21 15:18 28600 —-a-w- c:\windows\system32\drivers\avkmgr.sys 2013-03-21 15:17 . 2013-03-21 15:18 130016 —-a-w- c:\windows\system32\drivers\avipbb.sys 2013-03-21 15:17 . 2013-03-21 15:18 100712 —-a-w- c:\windows\system32\drivers\avgntflt.sys 2013-03-19 06:04 . 2013-04-10 22:49 5550424 —-a-w- c:\windows\system32\ntoskrnl.exe 2013-03-19 05:46 . 2013-04-10 22:49 43520 —-a-w- c:\windows\system32\csrsrv.dll 2013-03-19 05:04 . 2013-04-10 22:49 3968856 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe 2013-03-19 05:04 . 2013-04-10 22:49 3913560 —-a-w- c:\windows\SysWow64\ntoskrnl.exe 2013-03-19 04:47 . 2013-04-10 22:49 6656 —-a-w- c:\windows\SysWow64\apisetschema.dll 2013-03-19 03:06 . 2013-04-10 22:49 112640 —-a-w- c:\windows\system32\smss.exe . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Akamai NetSession Interface"="c:\users\Mado\AppData\Local\Akamai\netsession_win.exe" [2013-01-26 4480768] "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-04-19 18678376] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" [2010-11-06 283160] "NeroLauncher"="c:\program files (x86)\Nero\SyncUP\NeroLauncher.exe" [2012-08-21 67496] "Dell DataSafe Online"="c:\program files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe" [2010-08-26 1117528] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2012-07-27 35768] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008] "AccuWeatherWidget"="c:\program files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe" [2012-02-01 968048] "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2013-05-07 345312] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-22 59720] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-05-31 152392] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] "Launcher"="c:\program files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe" [2011-08-01 165184] . c:\users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OpenOffice.org 3.4.1.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [N/A] . c:\users\Mado\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OpenOffice.org 3.4.1.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [N/A] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "mixer3"=wdmaud.drv . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" . R2 AntiVirMailService;Avira Mail Protection;c:\program files (x86)\Avira\AntiVir Desktop\avmailc.exe;c:\program files (x86)\Avira\AntiVir Desktop\avmailc.exe [x] R2 AntiVirSchedulerService;Avira Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x] R2 AntiVirWebService;Avira Web Protection;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [x] R2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe [x] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 DellDigitalDelivery;Dell Digital Delivery Service;c:\program files (x86)\Dell Digital Delivery\DeliveryService.exe;c:\program files (x86)\Dell Digital Delivery\DeliveryService.exe [x] R2 Freemake Improver;Freemake Improver;c:\programdata\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe;c:\programdata\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R3 AMPPALP;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Protocol;c:\windows\system32\DRIVERS\amppal.sys;c:\windows\SYSNATIVE\DRIVERS\amppal.sys [x] R3 Bluetooth Media Service;Bluetooth Media Service;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe [x] R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [x] R3 intaud_WaveExtensible;Intel WiDi Audio Device;c:\windows\system32\drivers\intelaud.sys;c:\windows\SYSNATIVE\drivers\intelaud.sys [x] R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [x] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 TurboBoost;Intel® Turbo Boost Technology Monitor 2.0;c:\program files\Intel\TurboBoost\TurboBoost.exe;c:\program files\Intel\TurboBoost\TurboBoost.exe [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x] S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x] S2 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\AESTSr64.exe;c:\program files\IDT\WDM\AESTSr64.exe [x] S2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [x] S2 Bluetooth Device Monitor;Bluetooth Device Monitor;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe [x] S2 BTHSSecurityMgr;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [x] S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [x] S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe;c:\program files (x86)\Nero\Update\NASvc.exe [x] S2 NOBU;Dell DataSafe Online;c:\program files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe SERVICE;c:\program files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe SERVICE [x] S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [x] S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys;c:\windows\SYSNATIVE\DRIVERS\TurboB.sys [x] S2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [x] S3 AMPPAL;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Virtual Adapter;c:\windows\system32\DRIVERS\AMPPAL.sys;c:\windows\SYSNATIVE\DRIVERS\AMPPAL.sys [x] S3 btmaudio;Intel Bluetooth Audio Service;c:\windows\system32\drivers\btmaud.sys;c:\windows\SYSNATIVE\drivers\btmaud.sys [x] S3 btmaux;Intel Bluetooth Auxiliary Service;c:\windows\system32\DRIVERS\btmaux.sys;c:\windows\SYSNATIVE\DRIVERS\btmaux.sys [x] S3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys;c:\windows\SYSNATIVE\DRIVERS\btmhsf.sys [x] S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys;c:\windows\SYSNATIVE\DRIVERS\CtClsFlt.sys [x] S3 iBtFltCoex;iBtFltCoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys;c:\windows\SYSNATIVE\DRIVERS\iBtFltCoex.sys [x] S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x] S3 iwdbus;IWD Bus Enumerator;c:\windows\system32\DRIVERS\iwdbus.sys;c:\windows\SYSNATIVE\DRIVERS\iwdbus.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] S3 tihub3;TI USB3 Hub Service;c:\windows\system32\DRIVERS\tihub3.sys;c:\windows\SYSNATIVE\DRIVERS\tihub3.sys [x] S3 tixhci;TI XHCI Service;c:\windows\system32\DRIVERS\tixhci.sys;c:\windows\SYSNATIVE\DRIVERS\tixhci.sys [x] . . Contents of the 'Scheduled Tasks' folder . 2013-06-10 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-11 19:15] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-04-20 168216] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-04-20 392472] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-04-20 416024] "SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2011-01-25 525312] "Apoint"="c:\program files\DellTPad\Apoint.exe" [2011-04-12 609144] "IntelTBRunOnce"="wscript.exe" [2009-07-14 168960] "IntelPAN"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2011-09-16 1935120] "BTMTrayAgent"="c:\program files (x86)\Intel\Bluetooth\btmshell.dll" [2011-05-19 10365952] "DellStage"="c:\program files (x86)\Dell Stage\Dell Stage\stage_primary.exe" [2012-02-01 2195824] . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = ;*.local LSP: c:\program files (x86)\Avira\AntiVir Desktop\avsda.dll TCP: DhcpNameServer = [removed] [removed] [removed] FF - ProfilePath - c:\users\Mado\AppData\Roaming\Mozilla\Firefox\Profiles\1mby5nem.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.mail.yahoo.com . - - - - ORPHANS REMOVED - - - - . AddRemove-WT089446 - c:\program files (x86)\WildTangent\Dell Games\Wedding Dash - Ready . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2013-06-10 16:21:52 ComboFix-quarantined-files.txt 2013-06-10 20:21 . Pre-Run: 485,089,566,720 bytes free Post-Run: 487,184,416,768 bytes free . - - End Of File - - 3CD07188E533DBAAFBDE0A196A21F130 D41D8CD98F00B204E9800998ECF8427E

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI