My action center tells me to remove this virus. Avira is not working properly. Other than that, I've had no symptoms.
Report pasted as instructed and second report attached.
.
DDS (Ver_11-03-05.01) - NTFS_AMD64
Run by [removed] at 16:17:03.62 on Thu 05/30/2013
Internet Explorer: 9.0.8112.16421
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.6050.3760 [GMT -4:00]
.
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:windowssystem32wininit.exe
C:windowssystem32lsm.exe
C:windowssystem32svchost.exe -k DcomLaunch
C:windowssystem32svchost.exe -k RPCSS
C:windowsSystem32svchost.exe -k LocalServiceNetworkRestricted
C:windowsSystem32svchost.exe -k LocalSystemNetworkRestricted
C:windowssystem32svchost.exe -k LocalService
C:windowssystem32svchost.exe -k netsvcs
C:Program FilesIDTWDMSTacSV64.exe
C:windowssystem32svchost.exe -k NetworkService
C:windowssystem32WLANExt.exe
C:windowssystem32conhost.exe
C:windowsSystem32spoolsv.exe
C:windowssystem32svchost.exe -k LocalServiceNoNetwork
C:Program Files (x86)Common FilesAdobeARM1.0armsvc.exe
C:Program FilesIDTWDMAESTSr64.exe
C:Program FilesIntelBluetoothHSBTHSAmpPalService.exe
C:Program Files (x86)Common FilesAppleMobile Device SupportAppleMobileDeviceService.exe
C:Program Files (x86)IntelBluetoothdevmonsrv.exe
C:Program FilesBonjourmDNSResponder.exe
C:windowssystem32svchost.exe -k bthsvcs
C:Program FilesIntelBluetoothHSBTHSSecurityMgr.exe
C:Program FilesIntelWiFibinEvtEng.exe
C:windowssystem32svchost.exe -k LocalServiceAndNoImpersonation
C:ProgramDataFreemakeFreemakeUtilsServiceFreemakeUtilsService.exe
C:Program Files (x86)DellDell Datasafe OnlineNOBuAgent.exe
C:Program FilesCommon FilesIntelWirelessCommonRegSrvc.exe
C:Program Files (x86)Dell DataSafe Local Backupsftservice.EXE
C:windowssystem32svchost.exe -k imgsvc
C:Program FilesCommon FilesMicrosoft SharedWindows LiveWLIDSVC.EXE
C:Program Files (x86)IntelBluetoothobexsrv.exe
C:Program FilesCommon FilesMicrosoft SharedWindows LiveWLIDSvcM.exe
C:windowssystem32svchost.exe -k NetworkServiceNetworkRestricted
C:windowsSystem32WUDFHost.exe
C:windowssystem32wbemunsecapp.exe
C:windowssystem32wbemwmiprvse.exe
C:windowssystem32wbemwmiprvse.exe
C:windowssystem32taskhost.exe
C:windowssystem32Dwm.exe
C:Program Files (x86)Dell DataSafe Local BackupTOASTER.EXE
C:windowsExplorer.EXE
C:Program Files (x86)Dell DataSafe Local BackupCOMPONENTSSCHEDULERSTSERVICE.EXE
C:Program Files (x86)Dell DataSafe Local BackupComponentsDSUpdateDSUpd.exe
C:WindowsSystem32igfxtray.exe
C:WindowsSystem32igfxpers.exe
C:Program FilesIDTWDMsttray64.exe
C:Program FilesDellTPadApoint.exe
C:Program FilesDellQuickSetquickset.exe
C:Program FilesCommon FilesIntelWirelessCommoniFrmewrk.exe
C:WindowsSystem32rundll32.exe
C:UsersMadoAppDataLocalAkamainetsession_win.exe
C:Program Files (x86)SkypePhoneSkype.exe
C:Program Files (x86)IntelIntel® Rapid Storage TechnologyIAStorIcon.exe
C:Program Files (x86)NeroSyncUPNeroLauncher.exe
C:Program FilesDellTPadApMsgFwd.exe
C:windowssystem32SearchIndexer.exe
C:Program Files (x86)OpenOffice.org 3programsoffice.exe
C:Program FilesDellTPadApntex.exe
C:windowssystem32conhost.exe
C:Program FilesDellTPadHidFind.exe
C:windowssystem32wbemunsecapp.exe
C:Program Files (x86)Common FilesAdobeARM1.0AdobeARM.exe
C:Program Files (x86)Dell StageDell StageAccuWeatheraccuweather.exe
C:Program Files (x86)AviraAntiVir Desktopavgnt.exe
C:UsersMadoAppDataLocalAkamainetsession_win.exe
C:Program Files (x86)OpenOffice.org 3programsoffice.bin
C:Program Files (x86)iTunesiTunesHelper.exe
C:Program Files (x86)IntelBluetoothmediasrv.exe
C:Program FilesiPodbiniPodService.exe
C:Program FilesWindows Media Playerwmpnetwk.exe
C:Program Files (x86)IntelBluetoothBTPlayerCtrl.exe
C:windowssystem32SearchProtocolHost.exe
C:windowsSystem32svchost.exe -k LocalServicePeerNet
C:Program Files (x86)IntelIntel® Rapid Storage TechnologyIAStorDataMgrSvc.exe
C:Program Files (x86)IntelIntel® Management Engine ComponentsLMSLMS.exe
C:windowssystem32DllHost.exe
C:Program Files (x86)NeroUpdateNASvc.exe
C:windowssystem32sppsvc.exe
C:windowssystem32taskeng.exe
C:Program Files (x86)Common FilesJavaJava Updatejusched.exe
C:windowsSystem32svchost.exe -k secsvcs
C:Program Files (x86)Mozilla Firefoxfirefox.exe
C:Program Files (x86)IntelIntel® Management Engine ComponentsUNSUNS.exe
C:Program Files (x86)Mozilla Firefoxplugin-container.exe
C:windowsSysWOW64MacromedFlashFlashPlayerPlugin_11_7_700_202.exe
C:windowsSysWOW64MacromedFlashFlashPlayerPlugin_11_7_700_202.exe
C:windowssystem32taskeng.exe
C:windowssystem32SearchFilterHost.exe
C:Program Files (x86)Common FilesJavaJava Updatejucheck.exe
C:windowssystem32taskhost.exe
C:windowssystem32DllHost.exe
C:windowssystem32DllHost.exe
C:UsersMadoDownloadsdds.scr
C:windowssystem32conhost.exe
.
============== Pseudo HJT Report ===============
.
uInternet Settings,ProxyOverride = ;*.local
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:Program Files (x86)Common FilesAdobeAcrobatActiveXAcroIEHelperShim.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:Program Files (x86)Common FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:Program Files (x86)Javajre6binjp2ssv.dll
uRun: [Akamai NetSession Interface] "C:UsersMadoAppDataLocalAkamainetsession_win.exe"
uRun: [Skype] "C:Program Files (x86)SkypePhoneSkype.exe" /minimized /regrun
mRun: [IAStorIcon] C:Program Files (x86)IntelIntel® Rapid Storage TechnologyIAStorIcon.exe
mRun: [NeroLauncher] C:Program Files (x86)NeroSyncUPNeroLauncher.exe 900
mRun: [Dell DataSafe Online] C:Program Files (x86)DellDell Datasafe OnlineNOBuClient.exe
mRun: [Adobe Reader Speed Launcher] "C:Program Files (x86)AdobeReader 10.0ReaderReader_sl.exe"
mRun: [Adobe ARM] "C:Program Files (x86)Common FilesAdobeARM1.0AdobeARM.exe"
mRun: [AccuWeatherWidget] "C:Program Files (x86)Dell StageDell StageAccuWeatheraccuweather.exe" "C:Program Files (x86)Dell StageDell StageAccuWeatherstart.umj" –startup
mRun: [avgnt] "C:Program Files (x86)AviraAntiVir Desktopavgnt.exe" /min
mRun: [APSDaemon] "C:Program Files (x86)Common FilesAppleApple Application SupportAPSDaemon.exe"
mRun: [iTunesHelper] "C:Program Files (x86)iTunesiTunesHelper.exe"
mRunOnce: [Launcher] C:Program Files (x86)Dell DataSafe Local BackupComponentsSchedulerLauncher.exe
StartupFolder: C:UsersMadoAppDataRoamingMICROS~1WindowsSTARTM~1ProgramsStartupOPENOF~1.LNK - C:Program Files (x86)OpenOffice.org 3programquickstart.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:Program Files (x86)Windows LiveWriterWriterBrowserExtension.dll
LSP: C:Program Files (x86)AviraAntiVir Desktopavsda.dll
DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} - hxxp://ccfiles.creative.com/Web/softwareupdate/su/ocx/15102/CTSUEng.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/121022/CTPID.cab
Handler: cozi - {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - C:Program Files (x86)Cozi ExpressCoziProtocolHandler.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:PROGRA~2COMMON~1SkypeSKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:Program Files (x86)Windows LivePhoto GalleryAlbumDownloadProtocolHandler.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program FilesCommon FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll
BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:Program FilesJavajre6binjp2ssv.dll
mRun-x64: [IgfxTray] C:Windowssystem32igfxtray.exe
mRun-x64: [HotKeysCmds] C:Windowssystem32hkcmd.exe
mRun-x64: [Persistence] C:Windowssystem32igfxpers.exe
mRun-x64: [SysTrayApp] C:Program FilesIDTWDMsttray64.exe
mRun-x64: [Apoint] C:Program FilesDellTPadApoint.exe
mRun-x64: [QuickSet] C:Program FilesDellQuickSetQuickSet.exe
mRun-x64: [IntelTBRunOnce] wscript.exe //b //nologo "C:Program FilesIntelTurboBoostRunTBGadgetOnce.vbs"
mRun-x64: [IntelPAN] "C:Program FilesCommon FilesIntelWirelessCommoniFrmewrk.exe" /tf Intel PAN Tray
mRun-x64: [BTMTrayAgent] rundll32.exe "C:Program Files (x86)IntelBluetoothbtmshell.dll",TrayApp
mRun-x64: [DellStage] "C:Program Files (x86)Dell StageDell Stagestage_primary.exe" "C:Program Files (x86)Dell StageDell Stagestart.umj" –startup
.
================= FIREFOX ===================
.
FF - ProfilePath - C:UsersMadoAppDataRoamingMozillaFirefoxProfiles1mby5nem.default
FF - prefs.js: browser.startup.homepage - hxxp://www.mail.yahoo.com
FF - plugin: C:Program Files (x86)AdobeReader 10.0ReaderAIRnppdf32.dll
FF - plugin: C:Program Files (x86)Javajre6binnew_pluginnpdeployJava1.dll
FF - plugin: c:Program Files (x86)Microsoft Silverlight5.1.20125.0npctrlui.dll
FF - plugin: C:Program Files (x86)WildTangent GamesAppBrowserIntegrationRegistered\0NP_wtapp.dll
FF - plugin: C:Program Files (x86)Windows LivePhoto GalleryNPWLPG.dll
FF - plugin: C:windowsSysWOW64MacromedFlashNPSWF32_11_7_700_202.dll
.
============= SERVICES / DRIVERS ===============
.
R1 avkmgr;avkmgr;C:WindowsSystem32driversavkmgr.sys [2013-3-21 28600]
R1 vwififlt;Virtual WiFi Filter Driver;C:WindowsSystem32driversvwififlt.sys [2009-7-13 59904]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:Program Files (x86)Common FilesAdobeARM1.0armsvc.exe [2012-7-27 63960]
R2 AESTFilters;Andrea ST Filters Service;C:Program FilesIDTWDMAESTSr64.exe [2012-1-14 89600]
R2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service;C:Program FilesIntelBluetoothHSBTHSAmpPalService.exe [2011-9-15 1166848]
R2 avgntflt;avgntflt;C:WindowsSystem32driversavgntflt.sys [2013-3-21 100712]
R2 Bluetooth Device Monitor;Bluetooth Device Monitor;C:Program Files (x86)IntelBluetoothdevmonsrv.exe [2011-5-19 921664]
R2 Bluetooth OBEX Service;Bluetooth OBEX Service;C:Program Files (x86)IntelBluetoothobexsrv.exe [2011-5-19 995392]
R2 BTHSSecurityMgr;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Security Service;C:Program FilesIntelBluetoothHSBTHSSecurityMgr.exe [2011-6-3 134928]
R2 Freemake Improver;Freemake Improver;C:ProgramDataFreemakeFreemakeUtilsServiceFreemakeUtilsService.exe [2013-1-22 100864]
R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:Program Files (x86)IntelIntel® Rapid Storage TechnologyIAStorDataMgrSvc.exe [2012-1-14 13336]
R2 NAUpdate;Nero Update;C:Program Files (x86)NeroUpdateNASvc.exe [2011-11-25 687400]
R2 NOBU;Dell DataSafe Online;C:Program Files (x86)DellDell Datasafe OnlineNOBuAgent.exe [2010-8-25 2823000]
R2 SftService;SoftThinks Agent Service;C:Program Files (x86)Dell DataSafe Local BackupSftService.exe [2012-1-14 1692480]
R2 TurboB;Turbo Boost UI Monitor driver;C:WindowsSystem32driversTurboB.sys [2010-11-29 16120]
R2 UNS;Intel® Management and Security Application User Notification Service;C:Program Files (x86)IntelIntel® Management Engine ComponentsUNSUNS.exe [2012-1-14 2655768]
R3 AMPPAL;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Virtual Adapter;C:WindowsSystem32driversAmpPal.sys [2011-9-15 299008]
R3 Bluetooth Media Service;Bluetooth Media Service;C:Program Files (x86)IntelBluetoothmediasrv.exe [2011-5-19 1335360]
R3 btmaudio;Intel Bluetooth Audio Service;C:WindowsSystem32driversbtmaud.sys [2011-5-19 51712]
R3 btmaux;Intel Bluetooth Auxiliary Service;C:WindowsSystem32driversbtmaux.sys [2011-5-19 53248]
R3 btmhsf;btmhsf;C:WindowsSystem32driversbtmhsf.sys [2011-7-19 282624]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;C:WindowsSystem32driversCtClsFlt.sys [2012-1-14 176096]
R3 iBtFltCoex;iBtFltCoex;C:WindowsSystem32driversiBtFltCoex.sys [2011-7-19 59904]
R3 IntcDAud;Intel® Display Audio;C:WindowsSystem32driversIntcDAud.sys [2012-1-14 317440]
R3 iwdbus;IWD Bus Enumerator;C:WindowsSystem32driversiwdbus.sys [2011-6-21 25496]
R3 MEIx64;Intel® Management Engine Interface;C:WindowsSystem32driversHECIx64.sys [2012-1-14 56344]
R3 NETwNs64;___ Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:WindowsSystem32driversNETwNs64.sys [2011-9-18 8604672]
R3 RTL8167;Realtek 8167 NT Driver;C:WindowsSystem32driversRt64win7.sys [2012-1-14 406632]
R3 tihub3;TI USB3 Hub Service;C:WindowsSystem32driverstihub3.sys [2011-7-20 136000]
R3 tixhci;TI XHCI Service;C:WindowsSystem32driverstixhci.sys [2011-7-20 406336]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:WindowsSystem32driversvwifimp.sys [2009-7-13 17920]
S2 AntiVirMailService;Avira Mail Protection;C:Program Files (x86)AviraAntiVir Desktopavmailc.exe [2012-11-27 371768]
S2 AntiVirSchedulerService;Avira Scheduler;C:Program Files (x86)AviraAntiVir Desktopsched.exe [2012-11-27 86752]
S2 AntiVirService;Avira Real-Time Protection;C:Program Files (x86)AviraAntiVir Desktopavguard.exe [2012-11-27 110816]
S2 AntiVirWebService;Avira Web Protection;C:Program Files (x86)AviraAntiVir Desktopavwebgrd.exe [2012-11-27 562744]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:WindowsMicrosoft.NETFrameworkv4.0.30319mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:WindowsMicrosoft.NETFramework64v4.0.30319mscorsvw.exe [2010-3-18 138576]
S2 DellDigitalDelivery;Dell Digital Delivery Service;C:Program Files (x86)Dell Digital DeliveryDeliveryService.exe [2011-10-26 162816]
S2 SkypeUpdate;Skype Updater;C:Program Files (x86)SkypeUpdaterUpdater.exe [2013-2-28 161384]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:WindowsSysWOW64MacromedFlashFlashPlayerUpdateService.exe [2012-7-10 256904]
S3 AMPPALP;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Protocol;C:WindowsSystem32driversAmpPal.sys [2011-9-15 299008]
S3 GamesAppService;GamesAppService;C:Program Files (x86)WildTangent GamesAppGamesAppService.exe [2010-10-12 206072]
S3 intaud_WaveExtensible;Intel WiDi Audio Device;C:WindowsSystem32driversintelaud.sys [2011-6-21 34200]
S3 MozillaMaintenance;Mozilla Maintenance Service;C:Program Files (x86)Mozilla Maintenance Servicemaintenanceservice.exe [2012-11-26 117144]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:Program FilesIntelWiFibinPanDhcpDns.exe [2011-9-15 340240]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:WindowsSystem32driversRtsUStor.sys [2012-1-14 250984]
S3 TsUsbFlt;TsUsbFlt;C:WindowsSystem32driversTsUsbFlt.sys [2010-11-20 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:WindowsSystem32driversTsUsbGD.sys [2010-11-20 31232]
S3 TurboBoost;Intel® Turbo Boost Technology Monitor 2.0;C:Program FilesIntelTurboBoostTurboBoost.exe [2010-11-29 149504]
S3 USBAAPL64;Apple Mobile USB Driver;C:WindowsSystem32driversusbaapl64.sys [2012-12-13 54784]
S3 WatAdminSvc;Windows Activation Technologies Service;C:WindowsSystem32WatWatAdminSvc.exe [2012-5-8 1255736]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:Program FilesWindows LiveMeshwlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2013-05-26 18:55:05 76232 —-a-w- C:PROGRA~3MicrosoftWindows DefenderDefinition Updates{7CE3AC30-5CB6-45B5-B3F4-0A9C99C0472E}offreg.dll
2013-05-26 18:51:34 8199504 —-a-w- C:PROGRA~3MicrosoftWindows DefenderDefinition UpdatesBackupmpengine.dll
2013-05-26 18:51:30 9460464 —-a-w- C:PROGRA~3MicrosoftWindows DefenderDefinition Updates{7CE3AC30-5CB6-45B5-B3F4-0A9C99C0472E}mpengine.dll
2013-05-25 20:57:26 ——– d—–w- C:UsersMadoAppDataRoamingMalwarebytes
2013-05-25 20:57:17 25928 —-a-w- C:windowsSystem32driversmbam.sys
2013-05-25 20:57:17 ——– d—–w- C:Program Files (x86)Malwarebytes' Anti-Malware
2013-05-25 20:57:17 ——– d—–w- C:PROGRA~3Malwarebytes
2013-05-23 20:13:26 ——– d—–w- C:PROGRA~3PC-Doctor for Windows
2013-05-23 20:12:57 ——– d—–w- C:Program FilesMy Dell
2013-05-20 01:50:34 ——– d—–w- C:Program FilesiPod
2013-05-20 01:50:33 ——– d—–w- C:Program FilesiTunes
2013-05-20 01:50:33 ——– d—–w- C:Program Files (x86)iTunes
2013-05-20 01:50:33 ——– d—–w- C:PROGRA~334BE82C4-E596-4e99-A191-52C6199EBF69
2013-05-09 11:48:20 ——– d-sh–w- C:found.000
.
==================== Find3M ====================
.
2013-05-15 19:15:23 71048 —-a-w- C:windowsSysWow64FlashPlayerCPLApp.cpl
2013-05-15 19:15:23 692104 —-a-w- C:windowsSysWow64FlashPlayerApp.exe
2013-04-12 14:45:08 1656680 —-a-w- C:windowsSystem32driversntfs.sys
2013-03-21 15:17:49 28600 —-a-w- C:windowsSystem32driversavkmgr.sys
2013-03-21 15:17:49 100712 —-a-w- C:windowsSystem32driversavgntflt.sys
2013-03-19 06:04:06 5550424 —-a-w- C:windowsSystem32ntoskrnl.exe
2013-03-19 05:46:56 43520 —-a-w- C:windowsSystem32csrsrv.dll
2013-03-19 05:04:13 3968856 —-a-w- C:windowsSysWow64ntkrnlpa.exe
2013-03-19 05:04:10 3913560 —-a-w- C:windowsSysWow64ntoskrnl.exe
2013-03-19 04:47:50 6656 —-a-w- C:windowsSysWow64apisetschema.dll
2013-03-19 03:06:33 112640 —-a-w- C:windowsSystem32smss.exe
.
============= FINISH: 16:17:30.30 ===============
Hi and Welcome!!
My name is
Jeff . I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
The fixes are specific to your problem and should only be used for the issues on this machine. It's often worth reading through these instructions and printing them for ease of reference. If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry. Please reply to this thread. Do not start a new topic. If you happen to have a flash drive/thumb drive please have that ready in the event that we need to use it. Please be sure to subscribe to the topic if you have not already done so.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your operating system and losing all your programs and data.
Having said that….
[external image: Posted Image] Let's get going !!
———-
Sorry for any delay….do you still need help?
[external image: Posted Image] Please download
aswMBR to your desktop.
Double click the aswMBR icon to run it. Click the Scan button to start scan. If you are asked to update the Avast Virus database please allow it to do so. When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.
[external image: Posted Image]
Click the image to enlarge it
———-
[external image: Posted Image] AdwCleaner
Please download
AdwCleaner by Xplode onto your desktop.
Double click on AdwCleaner.exe to run the tool. Click on Search . A logfile will automatically open after the scan has finished. Please post the contents of that logfile with your next reply. You can find the logfile at C:\AdwCleaner[R1].txt as well. ———-
Says aswMBR is not a valid win32 file
Ok let's try this instead…
[external image: Posted Image] Please download
TDSSKiller
Double click TDSSKiller.exe Press Start Scan but do nothing else as we are just looking for what is there. If Malicious objects are found, select Skip by changing the Cure dropdown in the upper right. Attach the log in your next reply
A copy of the log will be saved automatically to the root of the drive (typically C:\)
ComboFix
Download
Combofix from either of the links below, and save it to your desktop.
Link 1
Link 2
**Note: It is important that it is saved directly to your desktop**
If you get a message saying "Illegal operation attempted on a registry key that has been marked for deletion ", please restart your computer.
——————————————————————–
IMPORTANT -
Disable your AntiVirus and AntiSpyware applications , usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–
Right-Click and Run as Administrator on
ComboFix.exe & follow the prompts.
When finished, it will produce a report for you. Please post the C:\ComboFix.txt for further review.
ComboFix 13-06-08.02 - Mado 06/10/2013 16:13:05.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.6050.3171 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe
c:\programdata\PCDr\6261\AddOnDownloaded\1e512ef2-01fb-49fb-b09b-71de0eac4612.dll
c:\programdata\PCDr\6261\AddOnDownloaded\27ada864-54d8-46c9-a6e3-8334fa39b525.dll
c:\programdata\PCDr\6261\AddOnDownloaded\2eccd5d6-e118-4f76-97b6-ba56fb6c597a.dll
c:\programdata\PCDr\6261\AddOnDownloaded\3e0b29b2-9809-4050-abfc-ef8aff73ceab.dll
c:\programdata\PCDr\6261\AddOnDownloaded\5f2ce3e8-3c56-40bb-86d6-a1a41867000b.dll
c:\programdata\PCDr\6261\AddOnDownloaded\b69d9551-76e9-4872-95f8-075916f82d74.dll
c:\programdata\Roaming
.
.
((((((((((((((((((((((((( Files Created from 2013-05-10 to 2013-06-10 )))))))))))))))))))))))))))))))
.
.
2013-06-10 20:20 . 2013-06-10 20:20 ——– d—–w- c:\users\Guest\AppData\Local\temp
2013-06-10 20:20 . 2013-06-10 20:20 ——– d—–w- c:\users\Default\AppData\Local\temp
2013-06-10 15:56 . 2013-06-10 15:56 76232 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{80A89764-C249-466B-8C5C-582789FF2124}\offreg.dll
2013-06-10 15:55 . 2013-05-14 05:48 9460464 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{80A89764-C249-466B-8C5C-582789FF2124}\mpengine.dll
2013-06-08 22:17 . 2013-06-08 22:17 ——– d—–w- c:\program files\iPod
2013-06-08 22:17 . 2013-06-08 22:18 ——– d—–w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-06-08 22:17 . 2013-06-08 22:18 ——– d—–w- c:\program files\iTunes
2013-06-08 22:17 . 2013-06-08 22:18 ——– d—–w- c:\program files (x86)\iTunes
2013-05-25 20:57 . 2013-05-25 20:57 ——– d—–w- c:\users\Mado\AppData\Roaming\Malwarebytes
2013-05-25 20:57 . 2013-05-25 20:57 ——– d—–w- c:\program files (x86)\Malwarebytes' Anti-Malware
2013-05-25 20:57 . 2013-05-25 20:57 ——– d—–w- c:\programdata\Malwarebytes
2013-05-25 20:57 . 2013-04-04 18:50 25928 —-a-w- c:\windows\system32\drivers\mbam.sys
2013-05-23 20:13 . 2013-05-23 20:13 ——– d—–w- c:\programdata\PC-Doctor for Windows
2013-05-23 20:12 . 2013-05-28 17:38 ——– d—–w- c:\program files\My Dell
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-05-30 20:09 . 2010-06-24 17:33 22240 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-05-15 19:15 . 2012-07-11 01:32 692104 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-05-15 19:15 . 2012-01-14 17:30 71048 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-04-12 14:45 . 2013-04-23 21:17 1656680 —-a-w- c:\windows\system32\drivers\ntfs.sys
2013-04-12 07:04 . 2012-11-26 19:25 72702784 —-a-w- c:\windows\system32\MRT.exe
2013-03-21 15:17 . 2013-03-21 15:18 28600 —-a-w- c:\windows\system32\drivers\avkmgr.sys
2013-03-21 15:17 . 2013-03-21 15:18 130016 —-a-w- c:\windows\system32\drivers\avipbb.sys
2013-03-21 15:17 . 2013-03-21 15:18 100712 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2013-03-19 06:04 . 2013-04-10 22:49 5550424 —-a-w- c:\windows\system32\ntoskrnl.exe
2013-03-19 05:46 . 2013-04-10 22:49 43520 —-a-w- c:\windows\system32\csrsrv.dll
2013-03-19 05:04 . 2013-04-10 22:49 3968856 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe
2013-03-19 05:04 . 2013-04-10 22:49 3913560 —-a-w- c:\windows\SysWow64\ntoskrnl.exe
2013-03-19 04:47 . 2013-04-10 22:49 6656 —-a-w- c:\windows\SysWow64\apisetschema.dll
2013-03-19 03:06 . 2013-04-10 22:49 112640 —-a-w- c:\windows\system32\smss.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Akamai NetSession Interface"="c:\users\Mado\AppData\Local\Akamai\netsession_win.exe" [2013-01-26 4480768]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-04-19 18678376]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" [2010-11-06 283160]
"NeroLauncher"="c:\program files (x86)\Nero\SyncUP\NeroLauncher.exe" [2012-08-21 67496]
"Dell DataSafe Online"="c:\program files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe" [2010-08-26 1117528]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2012-07-27 35768]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"AccuWeatherWidget"="c:\program files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe" [2012-02-01 968048]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2013-05-07 345312]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-22 59720]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-05-31 152392]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\program files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe" [2011-08-01 165184]
.
c:\users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.4.1.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [N/A]
.
c:\users\Mado\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.4.1.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [N/A]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer3"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
R2 AntiVirMailService;Avira Mail Protection;c:\program files (x86)\Avira\AntiVir Desktop\avmailc.exe;c:\program files (x86)\Avira\AntiVir Desktop\avmailc.exe [x]
R2 AntiVirSchedulerService;Avira Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x]
R2 AntiVirWebService;Avira Web Protection;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [x]
R2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 DellDigitalDelivery;Dell Digital Delivery Service;c:\program files (x86)\Dell Digital Delivery\DeliveryService.exe;c:\program files (x86)\Dell Digital Delivery\DeliveryService.exe [x]
R2 Freemake Improver;Freemake Improver;c:\programdata\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe;c:\programdata\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 AMPPALP;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Protocol;c:\windows\system32\DRIVERS\amppal.sys;c:\windows\SYSNATIVE\DRIVERS\amppal.sys [x]
R3 Bluetooth Media Service;Bluetooth Media Service;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe [x]
R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [x]
R3 intaud_WaveExtensible;Intel WiDi Audio Device;c:\windows\system32\drivers\intelaud.sys;c:\windows\SYSNATIVE\drivers\intelaud.sys [x]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [x]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 TurboBoost;Intel® Turbo Boost Technology Monitor 2.0;c:\program files\Intel\TurboBoost\TurboBoost.exe;c:\program files\Intel\TurboBoost\TurboBoost.exe [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x]
S2 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\AESTSr64.exe;c:\program files\IDT\WDM\AESTSr64.exe [x]
S2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [x]
S2 Bluetooth Device Monitor;Bluetooth Device Monitor;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe [x]
S2 BTHSSecurityMgr;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [x]
S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe;c:\program files (x86)\Nero\Update\NASvc.exe [x]
S2 NOBU;Dell DataSafe Online;c:\program files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe SERVICE;c:\program files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe SERVICE [x]
S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [x]
S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys;c:\windows\SYSNATIVE\DRIVERS\TurboB.sys [x]
S2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [x]
S3 AMPPAL;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Virtual Adapter;c:\windows\system32\DRIVERS\AMPPAL.sys;c:\windows\SYSNATIVE\DRIVERS\AMPPAL.sys [x]
S3 btmaudio;Intel Bluetooth Audio Service;c:\windows\system32\drivers\btmaud.sys;c:\windows\SYSNATIVE\drivers\btmaud.sys [x]
S3 btmaux;Intel Bluetooth Auxiliary Service;c:\windows\system32\DRIVERS\btmaux.sys;c:\windows\SYSNATIVE\DRIVERS\btmaux.sys [x]
S3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys;c:\windows\SYSNATIVE\DRIVERS\btmhsf.sys [x]
S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys;c:\windows\SYSNATIVE\DRIVERS\CtClsFlt.sys [x]
S3 iBtFltCoex;iBtFltCoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys;c:\windows\SYSNATIVE\DRIVERS\iBtFltCoex.sys [x]
S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 iwdbus;IWD Bus Enumerator;c:\windows\system32\DRIVERS\iwdbus.sys;c:\windows\SYSNATIVE\DRIVERS\iwdbus.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 tihub3;TI USB3 Hub Service;c:\windows\system32\DRIVERS\tihub3.sys;c:\windows\SYSNATIVE\DRIVERS\tihub3.sys [x]
S3 tixhci;TI XHCI Service;c:\windows\system32\DRIVERS\tixhci.sys;c:\windows\SYSNATIVE\DRIVERS\tixhci.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
2013-06-10 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-11 19:15]
.
.
——— X64 Entries ———–
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-04-20 168216]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-04-20 392472]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-04-20 416024]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2011-01-25 525312]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2011-04-12 609144]
"IntelTBRunOnce"="wscript.exe" [2009-07-14 168960]
"IntelPAN"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2011-09-16 1935120]
"BTMTrayAgent"="c:\program files (x86)\Intel\Bluetooth\btmshell.dll" [2011-05-19 10365952]
"DellStage"="c:\program files (x86)\Dell Stage\Dell Stage\stage_primary.exe" [2012-02-01 2195824]
.
——- Supplementary Scan ——-
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = ;*.local
LSP: c:\program files (x86)\Avira\AntiVir Desktop\avsda.dll
TCP: DhcpNameServer = [removed] [removed] [removed]
FF - ProfilePath - c:\users\Mado\AppData\Roaming\Mozilla\Firefox\Profiles\1mby5nem.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.mail.yahoo.com
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-WT089446 - c:\program files (x86)\WildTangent\Dell Games\Wedding Dash - Ready
.
.
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2013-06-10 16:21:52
ComboFix-quarantined-files.txt 2013-06-10 20:21
.
Pre-Run: 485,089,566,720 bytes free
Post-Run: 487,184,416,768 bytes free
.
- - End Of File - - 3CD07188E533DBAAFBDE0A196A21F130
D41D8CD98F00B204E9800998ECF8427E
Just out of curiosity, did Avira tell you what file particularly it was that is infected?
Due to inactivity this topic will be closed.
If you need help please start a new thread.
New members follow the instructions here
http://forums.whatthetech.com/you_Infected_t106388.html and start a new topic
At the request of the OP, this topic has been reopened.