This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

'TR\ATRAPS.Gen2' [Solved]

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi. I have scanned my computer with Avira and it has quarantined the virus it found. I now have an avira pop up which comes up every minute or so telling me that access to the file 'C:\Program\Files\Google\Desktop\…\80000032@' containing the virus TR\ATRAPS.Gen2 was blocked. If I press the button which says Remove then it launches a scanner. Can you help please to see if It is still infected or done any damage. I have attatched a hijack log. Many thanks. Sue.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:20:37, on 16/09/2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\ADAiO2MUI.exe
C:\Program Files\DriverUpdate\DriverUpdate.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trusteer\Rapport\bin\RapportService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\home\My Documents\Downloads\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://shell.windows.com/fileassoc/0409/xm…dir.asp?Ext=DAT
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ADAiO2StatusMonitor] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\ADAiO2MUI.exe
O4 - HKLM\..\Run: [Conime] %windir%\system32\conime.exe
O4 - HKCU\..\Run: [DriverUpdate] "C:\Program Files\DriverUpdate\DriverUpdate.exe" -boot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\home\Local Settings\Application Data\Google\Desktop\Install\{ddf32af7-cb56-24de-0bab-feab1b5137ae}\???\???\???\{ddf32af7-cb56-24de-0bab-feab1b5137ae}\GoogleUpdate.exe" >
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.club-vaio.sony-europe.com
O15 - Trusted Zone: *.Sony-europe.com
O15 - Trusted Zone: *.Sonystyle-europe.com
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - https://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1277842996358
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1277845074437
O16 - DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-31-0.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Rapport Management Service (RapportMgmtService) - Trusteer Ltd. - C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe

–
End of file - 6419 bytes
Hi there,
my name is Marius and I will assist you with your malware related problems.

Before we move on, please read the following points carefully.
  • First, read my instructions completely. If there is anything that you do not understand kindly ask before proceeding.
  • Perform everything in the correct order. Sometimes one step requires the previous one.
  • If you have any problems while following my instructions, Stop there and tell me the exact nature of your problem.
  • Do not run any other scans without instruction or add/remove software unless I tell you to do so. This would change the output of our tools and could be confusing for me.
  • Post all logfiles as a reply rather than as an attachment unless I specifically ask you. If you can not post all logfiles in one reply, feel free to use more posts.
  • If I don't hear from you within 3 days from this initial or any subsequent post, then this thread will be closed.
  • Stay with me. I will give you some advice about prevention after the cleanup process. Absence of symptoms does not always mean the computer is clean.
  • My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.


Combofix

Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT- Save ComboFix.exe to your Desktop

====================================================


Disable your AntiVirus and AntiSpyware applications as they will interfere with our tools and the removal. If you are unsure how to do this, please refer to our sticky topic How to disable your security applications


====================================================


Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply for further review.
Thank you for the prompt reply and help. Combofix log below.
ComboFix 13-09-17.01 - home 17/09/2013 16:35:44.4.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.1536.1116 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Avira Desktop *Enabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\docume~1\home\LOCALS~1\APPLIC~1\Google\Desktop\Install
c:\docume~1\home\LOCALS~1\APPLIC~1\Google\Desktop\Install\{ddf32af7-cb56-24de-0bab-feab1b5137ae}\C3C1~1\01C8~1\CFFE~1\{ddf32af7-cb56-24de-0bab-feab1b5137ae}\@
c:\docume~1\home\LOCALS~1\APPLIC~1\Google\Desktop\Install\{ddf32af7-cb56-24de-0bab-feab1b5137ae}\C3C1~1\01C8~1\CFFE~1\{ddf32af7-cb56-24de-0bab-feab1b5137ae}\GoogleUpdate.exe
c:\documents and settings\home\Recent\Thumbs.db
c:\program files\Google\Desktop\Install\{ddf32af7-cb56-24de-0bab-feab1b5137ae}\0103~1\0103~1\CFFE~1\{ddf32af7-cb56-24de-0bab-feab1b5137ae}\@
c:\program files\Google\Desktop\Install\{ddf32af7-cb56-24de-0bab-feab1b5137ae}\0103~1\0103~1\CFFE~1\{ddf32af7-cb56-24de-0bab-feab1b5137ae}\GoogleUpdate.exe
c:\program files\Google\Desktop\Install\{ddf32af7-cb56-24de-0bab-feab1b5137ae}\0103~1\0103~1\CFFE~1\{ddf32af7-cb56-24de-0bab-feab1b5137ae}\L\00000004.@
c:\program files\Google\Desktop\Install\{ddf32af7-cb56-24de-0bab-feab1b5137ae}\0103~1\0103~1\CFFE~1\{ddf32af7-cb56-24de-0bab-feab1b5137ae}\L\201d3dde
c:\program files\Google\Desktop\Install\{ddf32af7-cb56-24de-0bab-feab1b5137ae}\0103~1\0103~1\CFFE~1\{ddf32af7-cb56-24de-0bab-feab1b5137ae}\L\76603ac3
c:\program files\Google\Desktop\Install\{ddf32af7-cb56-24de-0bab-feab1b5137ae}\0103~1\0103~1\CFFE~1\{ddf32af7-cb56-24de-0bab-feab1b5137ae}\U\00000004.@
c:\program files\Google\Desktop\Install\{ddf32af7-cb56-24de-0bab-feab1b5137ae}\0103~1\0103~1\CFFE~1\{ddf32af7-cb56-24de-0bab-feab1b5137ae}\U\00000008.@
c:\program files\Google\Desktop\Install\{ddf32af7-cb56-24de-0bab-feab1b5137ae}\0103~1\0103~1\CFFE~1\{ddf32af7-cb56-24de-0bab-feab1b5137ae}\U\000000cb.@
c:\program files\Google\Desktop\Install\{ddf32af7-cb56-24de-0bab-feab1b5137ae}\0103~1\0103~1\CFFE~1\{ddf32af7-cb56-24de-0bab-feab1b5137ae}\U\80000000.@
c:\program files\Google\Desktop\Install\{ddf32af7-cb56-24de-0bab-feab1b5137ae}\0103~1\0103~1\CFFE~1\{ddf32af7-cb56-24de-0bab-feab1b5137ae}\U\80000032.@
.
.
((((((((((((((((((((((((( Files Created from 2013-08-17 to 2013-09-17 )))))))))))))))))))))))))))))))
.
.
2013-09-17 14:54 . 2013-09-17 14:54 ——– d—–w- c:\windows\LastGood
2013-09-16 06:58 . 2013-09-16 06:58 ——– d—–w- c:\windows\system32\LogFiles
2013-08-29 12:01 . 2008-04-14 00:12 221184 —-a-w- c:\windows\system32\wmpns.dll
2013-08-29 11:46 . 2013-08-29 12:26 ——– d—–w- c:\documents and settings\home\Local Settings\Application Data\WMTools Downloaded Files
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-09-11 12:53 . 2012-07-14 19:44 692616 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-09-11 12:53 . 2011-06-09 14:08 71048 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-09-06 07:25 . 2013-02-24 12:17 88840 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2013-08-29 11:47 . 2013-02-24 12:17 136672 —-a-w- c:\windows\system32\drivers\avipbb.sys
2013-08-09 01:56 . 2002-03-29 16:00 386560 —-a-w- c:\windows\system32\themeui.dll
2013-08-08 06:05 . 2002-03-29 16:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2013-08-08 06:05 . 2002-03-29 16:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2013-08-08 06:05 . 2001-12-03 21:55 920064 —-a-w- c:\windows\system32\wininet.dll
2013-08-08 06:05 . 2002-03-29 16:00 18944 —-a-w- c:\windows\system32\corpol.dll
2013-08-08 01:27 . 2002-03-29 16:00 1877760 —-a-w- c:\windows\system32\win32k.sys
2013-08-08 00:02 . 2010-07-18 11:54 385024 —-a-w- c:\windows\system32\html.iec
2013-08-05 21:52 . 2013-08-05 21:52 102448 —-a-w- c:\windows\system32\drivers\RapportKELL.sys
2013-08-05 13:30 . 2002-03-29 16:00 1289728 —-a-w- c:\windows\system32\ole32.dll
2013-07-31 14:11 . 2002-03-29 16:00 810496 —-a-w- c:\windows\system32\wmvdmod.dll
2013-07-10 10:37 . 2002-03-29 16:00 406016 —-a-w- c:\windows\system32\usp10.dll
2013-07-04 02:59 . 2002-03-29 16:00 2193536 —-a-w- c:\windows\system32\ntoskrnl.exe
2013-07-04 02:08 . 2001-08-17 13:48 2070144 —-a-w- c:\windows\system32\ntkrnlpa.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SKIcoBackuped]
@="{7E5951A0-8683-432A-9483-5F43168D6A8C}"
[HKEY_CLASSES_ROOT\CLSID\{7E5951A0-8683-432A-9483-5F43168D6A8C}]
2011-09-28 09:30 3219632 —-a-w- c:\program files\VirginMedia\V Stuff Backup\AGSIconOverlay.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SKIcoSelected]
@="{15054241-49B4-4FA6-B4C7-A0071F118110}"
[HKEY_CLASSES_ROOT\CLSID\{15054241-49B4-4FA6-B4C7-A0071F118110}]
2011-09-28 09:30 3219632 —-a-w- c:\program files\VirginMedia\V Stuff Backup\AGSIconOverlay.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DriverUpdate"="c:\program files\DriverUpdate\DriverUpdate.exe" [2013-06-22 34220352]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2013-08-29 347192]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"ADAiO2StatusMonitor"="c:\windows\System32\spool\DRIVERS\W32X86\3\ADAiO2MUI.exe" [2010-10-18 2362880]
"Conime"="c:\windows\system32\conime.exe" [2008-04-14 27648]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HsdService]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ServicepointService]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.exe.lnk]
backup=c:\windows\pss\Adobe Gamma Loader.exe.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hpoddt01.exe.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\hpoddt01.exe.lnk
backup=c:\windows\pss\hpoddt01.exe.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^VAIO Action Setup (Server).lnk]
backup=c:\windows\pss\VAIO Action Setup (Server).lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ADAiO2StatusMonitor]
2010-10-18 11:41 2362880 —-a-w- c:\windows\system32\spool\drivers\w32x86\3\ADAiO2MUI.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2013-04-04 21:06 958576 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced System Protector]
2012-04-26 14:54 5924224 —-a-w- c:\program files\Advanced System Protector\AdvancedSystemProtector.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcSoft Connection Service]
2010-03-18 11:19 207360 —-a-w- c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avgnt]
2013-08-29 11:47 347192 —-a-w- c:\program files\Avira\AntiVir Desktop\avgnt.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Backup & Storage]
2011-09-28 09:31 12465840 —-a-w- c:\program files\VirginMedia\V Stuff Backup\Backup & Storage.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
2008-04-14 00:12 110592 ——w- c:\windows\system32\bthprops.cpl
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Camera Detector]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Conime]
2008-04-14 00:12 27648 —-a-w- c:\windows\system32\conime.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 —-a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DHSClient.exe]
2011-03-23 13:12 2032952 —-a-w- c:\program files\Virgin Media\Digital Home Support\DHSClient.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriverUpdate]
2013-06-22 14:30 34220352 —-a-w- c:\program files\DriverUpdate\DriverUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus C66 Series]
2004-01-13 02:00 99840 —-a-w- c:\windows\system32\spool\drivers\w32x86\3\E_S4I2S1.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LTSMMSG]
2002-03-29 14:07 32768 —-a-w- c:\windows\LTSMMSG.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Monitor]
2007-12-10 15:55 323584 —-a-w- c:\windows\PixArt\PAC207\Monitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ——w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2006-10-22 11:22 7700480 —-a-w- c:\windows\system32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2006-10-22 11:22 86016 —-a-w- c:\windows\system32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2006-10-22 11:22 1622016 —-a-w- c:\windows\system32\nwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PAC207_Monitor]
2007-12-10 15:55 323584 —-a-w- c:\windows\PixArt\PAC207\Monitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ServiceManager.exe]
2011-03-25 12:34 4371768 —-a-w- c:\program files\Virgin Media\Service Manager\ServiceManager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2012-07-13 12:33 17418928 —-a-r- c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2011-06-09 13:06 254696 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SPTISRV"=3 (0x3)
"SkypeUpdate"=2 (0x2)
"ServicepointService"=2 (0x2)
"RapportMgmtService"=2 (0x2)
"NVSvc"=2 (0x2)
"MozillaMaintenance"=3 (0x3)
"MatSvc"=3 (0x3)
"JavaQuickStarterService"=2 (0x2)
"idsvc"=3 (0x3)
"HsdService"=2 (0x2)
"AntiVirService"=2 (0x2)
"AntiVirSchedulerService"=2 (0x2)
"Advent AIO Network Discovery Service"=2 (0x2)
"AdobeFlashPlayerUpdateSvc"=3 (0x3)
"ACDaemon"=2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
R0 RapportKELL;RapportKELL;c:\windows\system32\drivers\RapportKELL.sys [05/08/2013 22:52 102448]
R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [24/02/2013 13:17 37352]
R1 RapportCerberus_53984;RapportCerberus_53984;c:\documents and settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportCerberus\53984\RapportCerberus32_53984.sys [30/05/2013 11:26 317424]
R1 RapportEI;RapportEI;c:\program files\Trusteer\Rapport\bin\RapportEI.sys [05/08/2013 22:52 103152]
R1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [05/08/2013 22:52 174320]
R2 AntiVirSchedulerService;Avira Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [24/02/2013 13:17 84024]
R2 RapportMgmtService;Rapport Management Service;c:\program files\Trusteer\Rapport\bin\RapportMgmtService.exe [05/08/2013 22:52 1124632]
R3 LucentSoftModem;Lucent Technologies Soft Modem;c:\windows\system32\drivers\LTSM.sys [29/03/2002 15:34 807917]
R3 SiS7012;Service for AC'97 Sample Driver (WDM);c:\windows\system32\drivers\sis7012.sys [28/03/2002 11:08 175232]
S3 Imx5123;Imx5123;c:\windows\system32\drivers\Imx5123.sys [30/07/2013 13:00 79232]
S3 PAC207;PC Camer@;c:\windows\system32\drivers\PFC027.SYS [13/12/2010 18:00 618112]
S4 Advent AIO Network Discovery Service;Advent AIO Network Discovery Service;c:\program files\Advent\AIO\Center\ADAIOHostService.exe [14/10/2011 14:59 361904]
S4 HsdService;HsdService;c:\program files\Virgin Media\Digital Home Support\HsdService.exe [13/05/2013 13:39 1406264]
S4 MatSvc;Microsoft Automated Troubleshooting Service;c:\program files\Microsoft Fix it Center\Matsvc.exe [13/06/2011 22:09 267568]
S4 ServicepointService;ServicepointService;c:\program files\Virgin Media\Service Manager\ServicepointService.exe [13/05/2013 13:38 689464]
S4 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [13/07/2012 13:28 160944]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-08 03:32 128512 —-a-w- c:\windows\system32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder
.
2013-09-17 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-14 12:53]
.
2013-09-17 c:\windows\Tasks\User_Feed_Synchronization-{05259640-3FC6-4058-8291-C66DFD0DC59C}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 03:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
uInternet Connection Wizard,ShellNext = hxxp://shell.windows.com/fileassoc/0409/xml/redir.asp?Ext=DAT
uInternet Settings,ProxyOverride = 127.0.0.1
uSearchAssistant =
Trusted Zone: ebay.co.uk\www
Trusted Zone: Sony-europe.com
Trusted Zone: Sonystyle-europe.com
TCP: DhcpNameServer = [removed] [removed]
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\home\Application Data\Mozilla\Firefox\Profiles\o6sey9ak.default-1378978358171\
.
- - - - ORPHANS REMOVED - - - -
.
HKCU-Run-Google Update - (no file)
HKU-Default-Run-RoboForm - c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
MSConfigStartUp-RoboForm - c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-09-17 16:46
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,00,67,63,81,6e,8d,a0,47,bb,bf,ee,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,00,67,63,81,6e,8d,a0,47,bb,bf,ee,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_8_800_168_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_8_800_168_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2013-09-17 16:51:03
ComboFix-quarantined-files.txt 2013-09-17 15:51
ComboFix2.txt 2012-01-14 18:10
.
Pre-Run: 1,477,459,968 bytes free
Post-Run: 2,115,235,840 bytes free
.
- - End Of File - - F25F1F3159141A421C5BE234FF28A0F0
8F558EB6672622401DA993E1E865C861
Combofix scripting

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Download the attached CFScript.txt and save it to the location where Combofix is.


[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.



Full System Scan with Malwarebytes Antimalware

  • If not existing, please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.

If the program is already installed:
  • Run Malwarebytes Antimalware
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform fullscan, place a checkmark on all hard drives, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location.
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Post that log back here.

Attachments:

Thanks Marius. Both logs below as requested. When preparing the log report in combofix a registry error report came up. It said 'cannot export RegRuns00: Error writing the file. There may be a disk or file system error'

ComboFix 13-09-17.01 - home 18/09/2013 11:41:32.5.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.1536.1073 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\home\Desktop\CFScript.txt
AV: Avira Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Advanced System Protector
c:\program files\Advanced System Protector\AdvancedSystemProtector.exe
c:\program files\Advanced System Protector\AdvancedSystemProtector.exe.config
c:\program files\Advanced System Protector\AppResource.dll
c:\program files\Advanced System Protector\asp.ico
c:\program files\Advanced System Protector\AspManager.exe
c:\program files\Advanced System Protector\aspsys.dll
c:\program files\Advanced System Protector\categories.ini
c:\program files\Advanced System Protector\Chinese_asp_ZH-CN.ini
c:\program files\Advanced System Protector\clamunpack\clamscan.exe
c:\program files\Advanced System Protector\clamunpack\libclamav.dll
c:\program files\Advanced System Protector\clamunpack\readme.txt
c:\program files\Advanced System Protector\Communication.dll
c:\program files\Advanced System Protector\danish_asp_DA.ini
c:\program files\Advanced System Protector\dutch_asp_NL.ini
c:\program files\Advanced System Protector\eng_asp_en.ini
c:\program files\Advanced System Protector\Finnish_asp_FI.ini
c:\program files\Advanced System Protector\french_asp_FR.ini
c:\program files\Advanced System Protector\german_asp_DE.ini
c:\program files\Advanced System Protector\Interop.IWshRuntimeLibrary.dll
c:\program files\Advanced System Protector\italian_asp_IT.ini
c:\program files\Advanced System Protector\japanese_asp_JA.ini
c:\program files\Advanced System Protector\Microsoft.Win32.TaskScheduler.DLL
c:\program files\Advanced System Protector\norwegian_asp_NO.ini
c:\program files\Advanced System Protector\portuguese_asp_PT-BR.ini
c:\program files\Advanced System Protector\russian_asp_ru.ini
c:\program files\Advanced System Protector\scandll.dll
c:\program files\Advanced System Protector\spanish_asp_ES.ini
c:\program files\Advanced System Protector\swedish_asp_SV.ini
c:\program files\Advanced System Protector\System.Core.dll
c:\program files\Advanced System Protector\System.Data.SQLite.dll
c:\program files\Advanced System Protector\unins000.dat
c:\program files\Advanced System Protector\unins000.exe
c:\program files\Advanced System Protector\unins000.msg
c:\program files\Advanced System Protector\unrar.dll
c:\program files\Advanced System Protector\Xceed.Compression.dll
c:\program files\Advanced System Protector\Xceed.Compression.Formats.dll
c:\program files\Advanced System Protector\Xceed.FileSystem.dll
c:\program files\Advanced System Protector\Xceed.Zip.dll
.
.
((((((((((((((((((((((((( Files Created from 2013-08-18 to 2013-09-18 )))))))))))))))))))))))))))))))
.
.
2013-09-18 09:54 . 2013-09-18 09:54 ——– d—–w- c:\windows\LastGood
2013-09-16 06:58 . 2013-09-16 06:58 ——– d—–w- c:\windows\system32\LogFiles
2013-08-29 12:01 . 2008-04-14 00:12 221184 —-a-w- c:\windows\system32\wmpns.dll
2013-08-29 11:46 . 2013-08-29 12:26 ——– d—–w- c:\documents and settings\home\Local Settings\Application Data\WMTools Downloaded Files
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-09-18 09:53 . 2013-08-08 12:16 13464 —-a-w- c:\windows\system32\drivers\SWDUMon.sys
2013-09-11 12:53 . 2012-07-14 19:44 692616 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-09-11 12:53 . 2011-06-09 14:08 71048 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-09-06 07:25 . 2013-02-24 12:17 88840 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2013-08-29 11:47 . 2013-02-24 12:17 136672 —-a-w- c:\windows\system32\drivers\avipbb.sys
2013-08-09 01:56 . 2002-03-29 16:00 386560 —-a-w- c:\windows\system32\themeui.dll
2013-08-08 06:05 . 2002-03-29 16:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2013-08-08 06:05 . 2002-03-29 16:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2013-08-08 06:05 . 2001-12-03 21:55 920064 —-a-w- c:\windows\system32\wininet.dll
2013-08-08 06:05 . 2002-03-29 16:00 18944 —-a-w- c:\windows\system32\corpol.dll
2013-08-08 01:27 . 2002-03-29 16:00 1877760 —-a-w- c:\windows\system32\win32k.sys
2013-08-08 00:02 . 2010-07-18 11:54 385024 —-a-w- c:\windows\system32\html.iec
2013-08-05 21:52 . 2013-08-05 21:52 102448 —-a-w- c:\windows\system32\drivers\RapportKELL.sys
2013-08-05 13:30 . 2002-03-29 16:00 1289728 —-a-w- c:\windows\system32\ole32.dll
2013-07-31 14:11 . 2002-03-29 16:00 810496 —-a-w- c:\windows\system32\wmvdmod.dll
2013-07-10 10:37 . 2002-03-29 16:00 406016 —-a-w- c:\windows\system32\usp10.dll
2013-07-04 02:59 . 2002-03-29 16:00 2193536 —-a-w- c:\windows\system32\ntoskrnl.exe
2013-07-04 02:08 . 2001-08-17 13:48 2070144 —-a-w- c:\windows\system32\ntkrnlpa.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SKIcoBackuped]
@="{7E5951A0-8683-432A-9483-5F43168D6A8C}"
[HKEY_CLASSES_ROOT\CLSID\{7E5951A0-8683-432A-9483-5F43168D6A8C}]
2011-09-28 09:30 3219632 —-a-w- c:\program files\VirginMedia\V Stuff Backup\AGSIconOverlay.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SKIcoSelected]
@="{15054241-49B4-4FA6-B4C7-A0071F118110}"
[HKEY_CLASSES_ROOT\CLSID\{15054241-49B4-4FA6-B4C7-A0071F118110}]
2011-09-28 09:30 3219632 —-a-w- c:\program files\VirginMedia\V Stuff Backup\AGSIconOverlay.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DriverUpdate"="c:\program files\DriverUpdate\DriverUpdate.exe" [2013-06-22 34220352]
"Google Update"="" [BU]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2013-08-29 347192]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"ADAiO2StatusMonitor"="c:\windows\System32\spool\DRIVERS\W32X86\3\ADAiO2MUI.exe" [2010-10-18 2362880]
"Conime"="c:\windows\system32\conime.exe" [2008-04-14 27648]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HsdService]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ServicepointService]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.exe.lnk]
backup=c:\windows\pss\Adobe Gamma Loader.exe.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hpoddt01.exe.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\hpoddt01.exe.lnk
backup=c:\windows\pss\hpoddt01.exe.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^VAIO Action Setup (Server).lnk]
backup=c:\windows\pss\VAIO Action Setup (Server).lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ADAiO2StatusMonitor]
2010-10-18 11:41 2362880 —-a-w- c:\windows\system32\spool\drivers\w32x86\3\ADAiO2MUI.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2013-04-04 21:06 958576 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcSoft Connection Service]
2010-03-18 11:19 207360 —-a-w- c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avgnt]
2013-08-29 11:47 347192 —-a-w- c:\program files\Avira\AntiVir Desktop\avgnt.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Backup & Storage]
2011-09-28 09:31 12465840 —-a-w- c:\program files\VirginMedia\V Stuff Backup\Backup & Storage.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
2008-04-14 00:12 110592 ——w- c:\windows\system32\bthprops.cpl
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Camera Detector]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Conime]
2008-04-14 00:12 27648 —-a-w- c:\windows\system32\conime.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 —-a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DHSClient.exe]
2011-03-23 13:12 2032952 —-a-w- c:\program files\Virgin Media\Digital Home Support\DHSClient.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriverUpdate]
2013-06-22 14:30 34220352 —-a-w- c:\program files\DriverUpdate\DriverUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus C66 Series]
2004-01-13 02:00 99840 —-a-w- c:\windows\system32\spool\drivers\w32x86\3\E_S4I2S1.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LTSMMSG]
2002-03-29 14:07 32768 —-a-w- c:\windows\LTSMMSG.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Monitor]
2007-12-10 15:55 323584 —-a-w- c:\windows\PixArt\PAC207\Monitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ——w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2006-10-22 11:22 7700480 —-a-w- c:\windows\system32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2006-10-22 11:22 86016 —-a-w- c:\windows\system32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2006-10-22 11:22 1622016 —-a-w- c:\windows\system32\nwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PAC207_Monitor]
2007-12-10 15:55 323584 —-a-w- c:\windows\PixArt\PAC207\Monitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ServiceManager.exe]
2011-03-25 12:34 4371768 —-a-w- c:\program files\Virgin Media\Service Manager\ServiceManager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2012-07-13 12:33 17418928 —-a-r- c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2011-06-09 13:06 254696 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SPTISRV"=3 (0x3)
"SkypeUpdate"=2 (0x2)
"ServicepointService"=2 (0x2)
"RapportMgmtService"=2 (0x2)
"NVSvc"=2 (0x2)
"MozillaMaintenance"=3 (0x3)
"MatSvc"=3 (0x3)
"JavaQuickStarterService"=2 (0x2)
"idsvc"=3 (0x3)
"HsdService"=2 (0x2)
"AntiVirService"=2 (0x2)
"AntiVirSchedulerService"=2 (0x2)
"Advent AIO Network Discovery Service"=2 (0x2)
"AdobeFlashPlayerUpdateSvc"=3 (0x3)
"ACDaemon"=2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
.
R0 RapportKELL;RapportKELL;c:\windows\system32\drivers\RapportKELL.sys [05/08/2013 22:52 102448]
R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [24/02/2013 13:17 37352]
R1 RapportCerberus_53984;RapportCerberus_53984;c:\documents and settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportCerberus\53984\RapportCerberus32_53984.sys [30/05/2013 11:26 317424]
R1 RapportEI;RapportEI;c:\program files\Trusteer\Rapport\bin\RapportEI.sys [05/08/2013 22:52 103152]
R1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [05/08/2013 22:52 174320]
R2 AntiVirSchedulerService;Avira Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [24/02/2013 13:17 84024]
R2 RapportMgmtService;Rapport Management Service;c:\program files\Trusteer\Rapport\bin\RapportMgmtService.exe [05/08/2013 22:52 1124632]
R3 LucentSoftModem;Lucent Technologies Soft Modem;c:\windows\system32\drivers\LTSM.sys [29/03/2002 15:34 807917]
R3 SiS7012;Service for AC'97 Sample Driver (WDM);c:\windows\system32\drivers\sis7012.sys [28/03/2002 11:08 175232]
S3 Imx5123;Imx5123;c:\windows\system32\drivers\Imx5123.sys [30/07/2013 13:00 79232]
S3 PAC207;PC Camer@;c:\windows\system32\drivers\PFC027.SYS [13/12/2010 18:00 618112]
S3 SWDUMon;SWDUMon;c:\windows\system32\drivers\SWDUMon.sys [08/08/2013 13:16 13464]
S4 Advent AIO Network Discovery Service;Advent AIO Network Discovery Service;c:\program files\Advent\AIO\Center\ADAIOHostService.exe [14/10/2011 14:59 361904]
S4 HsdService;HsdService;c:\program files\Virgin Media\Digital Home Support\HsdService.exe [13/05/2013 13:39 1406264]
S4 MatSvc;Microsoft Automated Troubleshooting Service;c:\program files\Microsoft Fix it Center\Matsvc.exe [13/06/2011 22:09 267568]
S4 ServicepointService;ServicepointService;c:\program files\Virgin Media\Service Manager\ServicepointService.exe [13/05/2013 13:38 689464]
S4 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [13/07/2012 13:28 160944]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-08 03:32 128512 —-a-w- c:\windows\system32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder
.
2013-09-18 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-14 12:53]
.
2013-09-18 c:\windows\Tasks\User_Feed_Synchronization-{05259640-3FC6-4058-8291-C66DFD0DC59C}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 03:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
uInternet Connection Wizard,ShellNext = hxxp://shell.windows.com/fileassoc/0409/xml/redir.asp?Ext=DAT
uInternet Settings,ProxyOverride = 127.0.0.1
uSearchAssistant =
Trusted Zone: ebay.co.uk\www
Trusted Zone: Sony-europe.com
Trusted Zone: Sonystyle-europe.com
TCP: DhcpNameServer = [removed] [removed]
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\home\Application Data\Mozilla\Firefox\Profiles\o6sey9ak.default-1378978358171\
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-00212D92-C5D8-4ff4-AE50-B20F0F85C40A_Systweak_Ad~B9F029BF_is1 - c:\program files\Advanced System Protector\unins000.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-09-18 11:52
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_8_800_168_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_8_800_168_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2013-09-18 12:00:50
ComboFix-quarantined-files.txt 2013-09-18 11:00
ComboFix2.txt 2013-09-17 15:51
ComboFix3.txt 2012-01-14 18:10
.
Pre-Run: 2,079,023,104 bytes free
Post-Run: 2,012,794,880 bytes free
.
- - End Of File - - BD16283B27EB3D6D9ACB454B38E45E37
8F558EB6672622401DA993E1E865C861
Antimalware bytes log here. Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Database version: v2013.09.18.06 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 home :: YOUR-0XV8V0OEAP [administrator] 18/09/2013 12:10:10 mbam-log-2013-09-18 (12-10-10).txt Scan type: Full scan (C:\|D:\|) Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 247214 Time elapsed: 1 hour(s), 33 minute(s), 28 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 8 C:\Documents and Settings\All Users\Application Data\Systweak\Advanced System Protector (PUP.Optional.AdvancedSystemProtector.A) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\Systweak\Advanced System Protector\2.1.1.71 (PUP.Optional.AdvancedSystemProtector.A) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\Systweak\Advanced System Protector\signatures (PUP.Optional.AdvancedSystemProtector.A) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\Systweak\Advanced System Protector\updates (PUP.Optional.AdvancedSystemProtector.A) -> Quarantined and deleted successfully. C:\Documents and Settings\home\Application Data\Systweak\Advanced System Protector (PUP.Optional.AdvancedSystemProtector.A) -> Quarantined and deleted successfully. C:\Documents and Settings\home\Application Data\Systweak\Advanced System Protector\2.1.1.71 (PUP.Optional.AdvancedSystemProtector.A) -> Quarantined and deleted successfully. C:\Documents and Settings\home\Application Data\Systweak\Advanced System Protector\Logs (PUP.Optional.AdvancedSystemProtector.A) -> Quarantined and deleted successfully. C:\Documents and Settings\home\Application Data\Systweak\Advanced System Protector\Temp (PUP.Optional.AdvancedSystemProtector.A) -> Quarantined and deleted successfully. Files Detected: 33 C:\Documents and Settings\home\My Documents\Downloads\ANTIMALWARE.exe (PUP.Optional.iBryte) -> Quarantined and deleted successfully. C:\Documents and Settings\home\My Documents\Downloads\iL9Setup-r514-t-bf.exe (PUP.Optional.Bandoo) -> Quarantined and deleted successfully. C:\Documents and Settings\home\My Documents\Downloads\WeatherSetup.exe (PUP.Optional.Inbox) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\C\DOCUME~1\home\LOCALS~1\APPLIC~1\Google\Desktop\Install\{ddf32af7-cb56-24de-0bab-feab1b5137ae}\C3C1~1\01C8~1\CFFE~1\{ddf32af7-cb56-24de-0bab-feab1b5137ae}\GoogleUpdate.exe.vir (Trojan.Agent.EDAP) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\C\Program Files\Google\Desktop\Install\{ddf32af7-cb56-24de-0bab-feab1b5137ae}\0103~1\0103~1\CFFE~1\{ddf32af7-cb56-24de-0bab-feab1b5137ae}\GoogleUpdate.exe.vir (Trojan.Agent.EDAP) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\C\Program Files\Google\Desktop\Install\{ddf32af7-cb56-24de-0bab-feab1b5137ae}\0103~1\0103~1\CFFE~1\{ddf32af7-cb56-24de-0bab-feab1b5137ae}\U\00000004.@.vir (Rootkit.Zaccess) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\C\Program Files\Google\Desktop\Install\{ddf32af7-cb56-24de-0bab-feab1b5137ae}\0103~1\0103~1\CFFE~1\{ddf32af7-cb56-24de-0bab-feab1b5137ae}\U\000000cb.@.vir (Rootkit.0Access) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\C\Program Files\Google\Desktop\Install\{ddf32af7-cb56-24de-0bab-feab1b5137ae}\0103~1\0103~1\CFFE~1\{ddf32af7-cb56-24de-0bab-feab1b5137ae}\U\80000000.@.vir (Trojan.0Access) -> Quarantined and deleted successfully. C:\WINDOWS\assembly\GAC\Desktop.ini (Rootkit.0access) -> Quarantined and deleted successfully. C:\WINDOWS\system32\roboot.exe (PUP.Optional.PCPerformer.A) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\Systweak\Advanced System Protector\log.xslt (PUP.Optional.AdvancedSystemProtector.A) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\Systweak\Advanced System Protector\signatures\completedatabase.db (PUP.Optional.AdvancedSystemProtector.A) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\Systweak\Advanced System Protector\signatures\Cookies.bin (PUP.Optional.AdvancedSystemProtector.A) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\Systweak\Advanced System Protector\signatures\DigSign.bin (PUP.Optional.AdvancedSystemProtector.A) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\Systweak\Advanced System Protector\signatures\FilePaths.bin (PUP.Optional.AdvancedSystemProtector.A) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\Systweak\Advanced System Protector\signatures\FileSignature.bin (PUP.Optional.AdvancedSystemProtector.A) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\Systweak\Advanced System Protector\signatures\Folders.bin (PUP.Optional.AdvancedSystemProtector.A) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\Systweak\Advanced System Protector\signatures\Md5.bin (PUP.Optional.AdvancedSystemProtector.A) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\Systweak\Advanced System Protector\signatures\Registry.bin (PUP.Optional.AdvancedSystemProtector.A) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\Systweak\Advanced System Protector\signatures\SetupSign.bin (PUP.Optional.AdvancedSystemProtector.A) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\Systweak\Advanced System Protector\signatures\StrSetupSign.bin (PUP.Optional.AdvancedSystemProtector.A) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\Systweak\Advanced System Protector\updates\914completedatabase.zip (PUP.Optional.AdvancedSystemProtector.A) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\Systweak\Advanced System Protector\updates\915update.zip (PUP.Optional.AdvancedSystemProtector.A) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\Systweak\Advanced System Protector\updates\916update.zip (PUP.Optional.AdvancedSystemProtector.A) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\Systweak\Advanced System Protector\updates\917update.zip (PUP.Optional.AdvancedSystemProtector.A) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\Systweak\Advanced System Protector\updates\918update.zip (PUP.Optional.AdvancedSystemProtector.A) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\Systweak\Advanced System Protector\updates\919update.zip (PUP.Optional.AdvancedSystemProtector.A) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\Systweak\Advanced System Protector\updates\920update.zip (PUP.Optional.AdvancedSystemProtector.A) -> Quarantined and deleted successfully. C:\Documents and Settings\home\Application Data\Systweak\Advanced System Protector\QDetail.db (PUP.Optional.AdvancedSystemProtector.A) -> Quarantined and deleted successfully. C:\Documents and Settings\home\Application Data\Systweak\Advanced System Protector\Settings.db (PUP.Optional.AdvancedSystemProtector.A) -> Quarantined and deleted successfully. C:\Documents and Settings\home\Application Data\Systweak\Advanced System Protector\Update.ini (PUP.Optional.AdvancedSystemProtector.A) -> Quarantined and deleted successfully. C:\Documents and Settings\home\Application Data\Systweak\Advanced System Protector\2.1.1.71\ASPLog.txt (PUP.Optional.AdvancedSystemProtector.A) -> Quarantined and deleted successfully. C:\Documents and Settings\home\Application Data\Systweak\Advanced System Protector\Logs\log_29-04-12_01-44-50.xml (PUP.Optional.AdvancedSystemProtector.A) -> Quarantined and deleted successfully. (end)
Scan with ESET Online Scan

Please go to here to run the online scannner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked
  • Click on Advanced Settings and ensure these options are ticked:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Click Scan
  • Wait for the scan to finish
  • If any threats were found, click the 'List of found threats' , then click Export to text file….
  • Save it to your desktop, then please copy and paste that log as a reply to this topic.




Scan with Farbar´s Service Scanner

Please download Farbar Service Scanner and run it on the computer with the issue.
  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center
    • Windows Update
    • Windows Defender
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.
Thanks Marius. Farbar Log below. I did the eset scan and saved the threats to desktop but they are not there and I can't find the file. Any idea where to look or will I have to do the scan again? Sue. Farbar Service Scanner Version: 13-09-2013 Ran by [removed] (administrator) on 19-09-2013 at 11:52:45 Running from "C:\Documents and Settings\home\Desktop" Microsoft Windows XP Home Edition Service Pack 3 (X86) Boot Mode: Normal **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. LAN connected. Google IP is accessible. Google.com is accessible. Yahoo.com is accessible. Windows Firewall: ============= Firewall Disabled Policy: ================== "HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\\EnableFirewall" registry value does not exist. System Restore: ============ System Restore Disabled Policy: ======================== Security Center: ============ Windows Update: ============ Windows Autoupdate Disabled Policy: ============================ Other Services: ============== Checking ServiceDll of RemoteAccess: ATTENTION!=====> Unable to open RemoteAccess registry key. The service key does not exist. File Check: ======== C:\WINDOWS\system32\dhcpcsvc.dll => MD5 is legit C:\WINDOWS\system32\Drivers\afd.sys => MD5 is legit C:\WINDOWS\system32\Drivers\netbt.sys => MD5 is legit C:\WINDOWS\system32\Drivers\tcpip.sys => MD5 is legit C:\WINDOWS\system32\Drivers\ipsec.sys => MD5 is legit C:\WINDOWS\system32\dnsrslvr.dll => MD5 is legit C:\WINDOWS\system32\ipnathlp.dll => MD5 is legit C:\WINDOWS\system32\netman.dll => MD5 is legit C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit C:\WINDOWS\system32\srsvc.dll => MD5 is legit C:\WINDOWS\system32\Drivers\sr.sys => MD5 is legit C:\WINDOWS\system32\wscsvc.dll => MD5 is legit C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit C:\WINDOWS\system32\wuauserv.dll => MD5 is legit C:\WINDOWS\system32\qmgr.dll => MD5 is legit C:\WINDOWS\system32\es.dll => MD5 is legit C:\WINDOWS\system32\cryptsvc.dll => MD5 is legit C:\WINDOWS\system32\svchost.exe => MD5 is legit C:\WINDOWS\system32\rpcss.dll => MD5 is legit C:\WINDOWS\system32\services.exe => MD5 is legit Extra List: ======= Gpc(6) IPSec(4) NetBT(5) PSched(7) RFCOMM(8) Tcpip(3) 0x080000000400000001000000020000000300000005000000060000000700000008000000 IpSec Tag value is correct. **** End of log ****
Thanks. ESET log here. ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=076f17d1d8014147b4cd95e07b7b29a7 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2012-01-11 02:56:49 # local_time=2012-01-11 02:56:49 (+0000, GMT Standard Time) # country="United Kingdom" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 0 0 0 0 # compatibility_mode=1797 16775125 100 93 150642 62819404 173994 0 # compatibility_mode=8192 67108863 100 0 4173 4173 0 0 # scanned=78588 # found=82 # cleaned=0 # scan_time=7359 C:\Documents and Settings\home\Application Data\Sun\Java\Deployment\cache\6.0\15\ee7ed4f-16f700dc Java/Agent.EA trojan (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\home\Application Data\Sun\Java\Deployment\cache\6.0\56\378fcb78-383c61e5 Java/Exploit.CVE-2011-3544.T trojan (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\home\Application Data\Sun\Java\Deployment\cache\6.0\62\2d7ffebe-5cb74fe1 Java/Exploit.CVE-2011-3544.Q trojan (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\home\My Documents\Downloads\backups\backup-20120109-134544-292.dll a variant of Win32/Toolbar.MyWebSearch.K application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\home\My Documents\Downloads\backups\backup-20120109-134544-394.dll Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\F3CJPEG.DLL.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\F3DTACTL.DLL.vir Win32/Adware.FunWeb application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\F3HISTSW.DLL.vir Win32/Adware.FunWeb application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\F3HKSTUB.DLL.vir Win32/Toolbar.MyWebSearch.G application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\F3HTMLMU.DLL.vir Win32/Toolbar.MyWebSearch.B application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\F3HTtpct.dll.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\F3IMSTUB.DLL.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\F3POPSWT.DLL.vir Win32/Adware.FunWeb application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\F3PSSAVR.SCR.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\F3REGHK.DLL.vir Win32/Toolbar.MyWebSearch.G application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\F3REPROX.DLL.vir Win32/Toolbar.MyWebSearch.D application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\F3RESTUB.DLL.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\F3SCHMON.EXE.vir Win32/Adware.FunWeb application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\F3SCrctr.dll.vir Win32/Toolbar.MyWebSearch.P application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\F3WPHOOK.DLL.vir Win32/FunWeb application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\M3AUXSTB.DLL.vir Win32/Toolbar.MyWebSearch.H application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\M3DLGHK.DLL.vir a variant of Win32/Toolbar.MyWebSearch.I application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\M3HTML.DLL.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\M3IDLE.DLL.vir Win32/Toolbar.MyWebSearch.P application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\M3IMPIPE.EXE.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\M3MSg.dll.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\M3OUtlcn.dll.vir Win32/Toolbar.MyWebSearch.J application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\M3PLUGIN.DLL.vir a variant of Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\M3SKIN.DLL.vir Win32/Toolbar.MyWebSearch.P application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\M3SKPLAY.EXE.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\M3SLSRCH.EXE.vir Win32/Toolbar.MyWebSearch.J application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\M3SRCHMN.EXE.vir Win32/Toolbar.MyWebSearch.I application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\M3TPINST.DLL.vir a variant of Win32/Toolbar.MyWebSearch.I application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\M3UNPAT.DLL.vir a variant of Win32/Toolbar.MyWebSearch.I application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\MWSMLBTN.DLL.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\MWSOEMON.EXE.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\MWSOEPLG.DLL.vir Win32/Toolbar.MyWebSearch.J application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\MWSOESTB.DLL.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\MWSSVC.EXE.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\MWSUABTN.DLL.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\NPMYWEBS.DLL.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\system32\f3PSSavr.scr.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{A951DEE8-8E0B-4CA4-BD50-B25E9F3900C9}\RP129\A0296034.DLL Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{A951DEE8-8E0B-4CA4-BD50-B25E9F3900C9}\RP129\A0296035.DLL a variant of Win32/Toolbar.MyWebSearch.K application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{A951DEE8-8E0B-4CA4-BD50-B25E9F3900C9}\RP130\A0300255.DLL Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{A951DEE8-8E0B-4CA4-BD50-B25E9F3900C9}\RP130\A0300264.DLL Win32/Adware.FunWeb application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{A951DEE8-8E0B-4CA4-BD50-B25E9F3900C9}\RP130\A0300270.DLL Win32/Adware.FunWeb application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{A951DEE8-8E0B-4CA4-BD50-B25E9F3900C9}\RP130\A0300282.DLL Win32/Toolbar.MyWebSearch.G application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{A951DEE8-8E0B-4CA4-BD50-B25E9F3900C9}\RP130\A0300290.DLL Win32/Toolbar.MyWebSearch.B application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{A951DEE8-8E0B-4CA4-BD50-B25E9F3900C9}\RP130\A0300298.DLL Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{A951DEE8-8E0B-4CA4-BD50-B25E9F3900C9}\RP130\A0300307.DLL Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{A951DEE8-8E0B-4CA4-BD50-B25E9F3900C9}\RP130\A0300315.DLL Win32/Adware.FunWeb application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{A951DEE8-8E0B-4CA4-BD50-B25E9F3900C9}\RP130\A0300321.SCR Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{A951DEE8-8E0B-4CA4-BD50-B25E9F3900C9}\RP130\A0300330.DLL Win32/Toolbar.MyWebSearch.G application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{A951DEE8-8E0B-4CA4-BD50-B25E9F3900C9}\RP130\A0300336.DLL Win32/Toolbar.MyWebSearch.D application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{A951DEE8-8E0B-4CA4-BD50-B25E9F3900C9}\RP130\A0300344.DLL Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{A951DEE8-8E0B-4CA4-BD50-B25E9F3900C9}\RP130\A0300350.EXE Win32/Adware.FunWeb application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{A951DEE8-8E0B-4CA4-BD50-B25E9F3900C9}\RP130\A0300359.DLL Win32/Toolbar.MyWebSearch.P application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{A951DEE8-8E0B-4CA4-BD50-B25E9F3900C9}\RP130\A0300375.DLL Win32/FunWeb application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{A951DEE8-8E0B-4CA4-BD50-B25E9F3900C9}\RP130\A0300389.DLL Win32/Toolbar.MyWebSearch.H application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{A951DEE8-8E0B-4CA4-BD50-B25E9F3900C9}\RP130\A0300396.DLL a variant of Win32/Toolbar.MyWebSearch.I application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{A951DEE8-8E0B-4CA4-BD50-B25E9F3900C9}\RP130\A0300418.DLL Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{A951DEE8-8E0B-4CA4-BD50-B25E9F3900C9}\RP130\A0300426.DLL Win32/Toolbar.MyWebSearch.P application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{A951DEE8-8E0B-4CA4-BD50-B25E9F3900C9}\RP130\A0300433.EXE Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{A951DEE8-8E0B-4CA4-BD50-B25E9F3900C9}\RP130\A0300447.DLL Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{A951DEE8-8E0B-4CA4-BD50-B25E9F3900C9}\RP130\A0300457.DLL Win32/Toolbar.MyWebSearch.J application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{A951DEE8-8E0B-4CA4-BD50-B25E9F3900C9}\RP130\A0300471.DLL a variant of Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{A951DEE8-8E0B-4CA4-BD50-B25E9F3900C9}\RP130\A0300480.DLL Win32/Toolbar.MyWebSearch.P application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{A951DEE8-8E0B-4CA4-BD50-B25E9F3900C9}\RP130\A0300486.EXE Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{A951DEE8-8E0B-4CA4-BD50-B25E9F3900C9}\RP130\A0300494.EXE Win32/Toolbar.MyWebSearch.J application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{A951DEE8-8E0B-4CA4-BD50-B25E9F3900C9}\RP130\A0300501.EXE Win32/Toolbar.MyWebSearch.I application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{A951DEE8-8E0B-4CA4-BD50-B25E9F3900C9}\RP130\A0300509.DLL a variant of Win32/Toolbar.MyWebSearch.I application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{A951DEE8-8E0B-4CA4-BD50-B25E9F3900C9}\RP130\A0300516.DLL a variant of Win32/Toolbar.MyWebSearch.I application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{A951DEE8-8E0B-4CA4-BD50-B25E9F3900C9}\RP130\A0300524.DLL Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{A951DEE8-8E0B-4CA4-BD50-B25E9F3900C9}\RP130\A0300531.EXE Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{A951DEE8-8E0B-4CA4-BD50-B25E9F3900C9}\RP130\A0300538.DLL Win32/Toolbar.MyWebSearch.J application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{A951DEE8-8E0B-4CA4-BD50-B25E9F3900C9}\RP130\A0300549.DLL Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{A951DEE8-8E0B-4CA4-BD50-B25E9F3900C9}\RP130\A0300556.EXE Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{A951DEE8-8E0B-4CA4-BD50-B25E9F3900C9}\RP130\A0300563.DLL Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{A951DEE8-8E0B-4CA4-BD50-B25E9F3900C9}\RP130\A0300570.DLL Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{A951DEE8-8E0B-4CA4-BD50-B25E9F3900C9}\RP130\A0300620.scr Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I ${Memory} a variant of Win32/Ramnit.A virus 00000000000000000000000000000000 I ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=076f17d1d8014147b4cd95e07b7b29a7 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2012-01-13 03:38:45 # local_time=2012-01-13 03:38:45 (+0000, GMT Standard Time) # country="United Kingdom" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 0 0 0 0 # compatibility_mode=1797 16775141 100 93 329518 62998280 170425 0 # compatibility_mode=8192 67108863 100 0 183049 183049 0 0 # scanned=58519 # found=41 # cleaned=0 # scan_time=3798 C:\Documents and Settings\home\Application Data\Sun\Java\Deployment\cache\6.0\19\18421313-71a6a175 Java/Exploit.CVE-2011-3544.T trojan (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\home\Application Data\Sun\Java\Deployment\cache\6.0\32\79269c20-65ceef83 Java/Agent.EA trojan (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Documents and Settings\home\My Documents\Downloads\backups\backup-20120109-134544-292.dll.vir a variant of Win32/Toolbar.MyWebSearch.K application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Documents and Settings\home\My Documents\Downloads\backups\backup-20120109-134544-394.dll.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\F3CJPEG.DLL.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\F3DTACTL.DLL.vir Win32/Adware.FunWeb application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\F3HISTSW.DLL.vir Win32/Adware.FunWeb application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\F3HKSTUB.DLL.vir Win32/Toolbar.MyWebSearch.G application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\F3HTMLMU.DLL.vir Win32/Toolbar.MyWebSearch.B application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\F3HTtpct.dll.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\F3IMSTUB.DLL.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\F3POPSWT.DLL.vir Win32/Adware.FunWeb application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\F3PSSAVR.SCR.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\F3REGHK.DLL.vir Win32/Toolbar.MyWebSearch.G application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\F3REPROX.DLL.vir Win32/Toolbar.MyWebSearch.D application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\F3RESTUB.DLL.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\F3SCHMON.EXE.vir Win32/Adware.FunWeb application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\F3SCrctr.dll.vir Win32/Toolbar.MyWebSearch.P application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\M3AUXSTB.DLL.vir Win32/Toolbar.MyWebSearch.H application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\M3DLGHK.DLL.vir a variant of Win32/Toolbar.MyWebSearch.I application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\M3HTML.DLL.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\M3IDLE.DLL.vir Win32/Toolbar.MyWebSearch.P application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\M3IMPIPE.EXE.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\M3MSg.dll.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\M3OUtlcn.dll.vir Win32/Toolbar.MyWebSearch.J application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\M3PLUGIN.DLL.vir a variant of Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\M3SKIN.DLL.vir Win32/Toolbar.MyWebSearch.P application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\M3SKPLAY.EXE.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\M3SLSRCH.EXE.vir Win32/Toolbar.MyWebSearch.J application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\M3SRCHMN.EXE.vir Win32/Toolbar.MyWebSearch.I application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\M3TPINST.DLL.vir a variant of Win32/Toolbar.MyWebSearch.I application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\M3UNPAT.DLL.vir a variant of Win32/Toolbar.MyWebSearch.I application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\MWSMLBTN.DLL.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\MWSOEMON.EXE.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\MWSOEPLG.DLL.vir Win32/Toolbar.MyWebSearch.J application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\MWSOESTB.DLL.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\MWSSVC.EXE.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\MWSUABTN.DLL.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\NPMYWEBS.DLL.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\system32\f3PSSavr.scr.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I ${Memory} a variant of Win32/Ramnit.A virus 00000000000000000000000000000000 I ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=076f17d1d8014147b4cd95e07b7b29a7 # engine=15183 # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2013-09-19 09:50:54 # local_time=2013-09-19 10:50:54 (+0000, GMT Daylight Time) # country="United Kingdom" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=1799 16775165 100 97 7708 150251959 3864 0 # scanned=64228 # found=11 # cleaned=0 # scan_time=3352 sh=0987158367148BF0FB0DB7B300EC078680184D89 ft=1 fh=6ba3030d7ec6e642 vn="a variant of Win32/Bundled.Toolbar.Ask application" ac=I fn="C:\Documents and Settings\home\My Documents\Downloads\cpu-z_1.60.1-setup-en.exe" sh=69FC4041109DC3454368D8DF25B0B3E27998AF6C ft=1 fh=945c89aecf418521 vn="a variant of Win32/OpenInstall application" ac=I fn="C:\Documents and Settings\home\My Documents\Downloads\QuickTimeAlternativeQT7basedv322.exe" sh=71435DDB11E00D0243380C4902324853FE4ECE8F ft=1 fh=12b0cd2dde452d65 vn="a variant of Win32/Bundled.Toolbar.Ask application" ac=I fn="C:\Program Files\Avira\AntiVir Desktop\apnic.dll" sh=1A3F14C0A66F9AF050D1F34FBACBAADC31751A07 ft=1 fh=2704a03a0f47b728 vn="a variant of Win32/Bundled.Toolbar.Ask application" ac=I fn="C:\Program Files\Avira\AntiVir Desktop\apntoolbarinstaller.exe" sh=4B553651EF610C0614F8393D6C25ABA0A8F09ECA ft=1 fh=92ef1bb072edf568 vn="a variant of Win32/Bundled.Toolbar.Ask.D application" ac=I fn="C:\Program Files\Avira\AntiVir Desktop\Offercast_AVIRAV7_.exe" sh=12A33C7D2B534C5BE4E89DA3A4E91D3D707E55F8 ft=1 fh=dca82166c282d63b vn="a variant of MSIL/AdvancedSystemProtector.B application" ac=I fn="C:\Qoobox\Quarantine\C\Program Files\Advanced System Protector\AdvancedSystemProtector.exe.vir" sh=55D85BF669277946BDE31877E69593EC470E5A6C ft=1 fh=529001832cd10951 vn="a variant of MSIL/AdvancedSystemProtector.B application" ac=I fn="C:\Qoobox\Quarantine\C\Program Files\Advanced System Protector\AspManager.exe.vir" sh=2587B2A16644839CBF08F2943FA21CC0C8DD6E5D ft=1 fh=1aeb32f3d5992c2a vn="Win32/Conedex.T trojan" ac=I fn="C:\Qoobox\Quarantine\C\Program Files\Google\Desktop\Install\{ddf32af7-cb56-24de-0bab-feab1b5137ae}\0103~1\0103~1\CFFE~1\{ddf32af7-cb56-24de-0bab-feab1b5137ae}\U\00000008.@.vir" sh=9213188F45F2849F423DC95FDABF1C22154F0EA3 ft=1 fh=b7dc201118461418 vn="probably a variant of Win32/Sirefef.FV trojan" ac=I fn="C:\Qoobox\Quarantine\C\Program Files\Google\Desktop\Install\{ddf32af7-cb56-24de-0bab-feab1b5137ae}\0103~1\0103~1\CFFE~1\{ddf32af7-cb56-24de-0bab-feab1b5137ae}\U\80000032.@.vir" sh=12A33C7D2B534C5BE4E89DA3A4E91D3D707E55F8 ft=1 fh=dca82166c282d63b vn="a variant of MSIL/AdvancedSystemProtector.B application" ac=I fn="C:\System Volume Information\_restore{A951DEE8-8E0B-4CA4-BD50-B25E9F3900C9}\RP1\A0000147.exe" sh=55D85BF669277946BDE31877E69593EC470E5A6C ft=1 fh=529001832cd10951 vn="a variant of MSIL/AdvancedSystemProtector.B application" ac=I fn="C:\System Volume Information\_restore{A951DEE8-8E0B-4CA4-BD50-B25E9F3900C9}\RP1\A0000151.exe" ESETSmartInstaller@High as downloader log: all ok
New FSS scan here also. Farbar Service Scanner Version: 13-09-2013 Ran by [removed] (administrator) on 19-09-2013 at 12:52:55 Running from "C:\Documents and Settings\home\Desktop" Microsoft Windows XP Home Edition Service Pack 3 (X86) Boot Mode: Normal **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. LAN connected. Google IP is accessible. Google.com is accessible. Yahoo.com is accessible. Windows Firewall: ============= netman Service is not running. Checking service configuration: The start type of netman service is OK. The ImagePath of netman service is OK. The ServiceDll of netman service is OK. Firewall Disabled Policy: ================== "HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\\EnableFirewall" registry value does not exist. System Restore: ============ System Restore Disabled Policy: ======================== Security Center: ============ Windows Update: ============ BITS Service is not running. Checking service configuration: The start type of BITS service is set to Demand. The default start type is Auto. The ImagePath of BITS service is OK. Windows Autoupdate Disabled Policy: ============================ Other Services: ============== File Check: ======== C:\WINDOWS\system32\dhcpcsvc.dll => MD5 is legit C:\WINDOWS\system32\Drivers\afd.sys => MD5 is legit C:\WINDOWS\system32\Drivers\netbt.sys => MD5 is legit C:\WINDOWS\system32\Drivers\tcpip.sys => MD5 is legit C:\WINDOWS\system32\Drivers\ipsec.sys => MD5 is legit C:\WINDOWS\system32\dnsrslvr.dll => MD5 is legit C:\WINDOWS\system32\ipnathlp.dll => MD5 is legit C:\WINDOWS\system32\netman.dll => MD5 is legit C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit C:\WINDOWS\system32\srsvc.dll => MD5 is legit C:\WINDOWS\system32\Drivers\sr.sys => MD5 is legit C:\WINDOWS\system32\wscsvc.dll => MD5 is legit C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit C:\WINDOWS\system32\wuauserv.dll => MD5 is legit C:\WINDOWS\system32\qmgr.dll => MD5 is legit C:\WINDOWS\system32\es.dll => MD5 is legit C:\WINDOWS\system32\cryptsvc.dll => MD5 is legit C:\WINDOWS\system32\svchost.exe => MD5 is legit C:\WINDOWS\system32\rpcss.dll => MD5 is legit C:\WINDOWS\system32\services.exe => MD5 is legit Extra List: ======= Gpc(6) IPSec(4) NetBT(5) PSched(7) RFCOMM(8) Tcpip(3) 0x080000000400000001000000020000000300000005000000060000000700000008000000 IpSec Tag value is correct. **** End of log ****
Combofix scripting

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Download the attached CFScript.txt and save it to the location where Combofix is.


[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

Attachments:

Combofix new log here. The same Registry error came up. The Avira pop up has gone. Computer is fairly quick but the browser is very slow to launch. Sue.

ComboFix 13-09-19.01 - home 19/09/2013 13:34:35.6.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.1536.1095 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\home\Desktop\CFScript.txt
AV: Avira Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
FILE ::
"c:\documents and settings\home\My Documents\Downloads\backups\backup-20120109-134544-292.dll"
"c:\documents and settings\home\My Documents\Downloads\backups\backup-20120109-134544-394.dll"
.
.
((((((((((((((((((((((((( Files Created from 2013-08-19 to 2013-09-19 )))))))))))))))))))))))))))))))
.
.
2013-09-19 11:54 . 2013-09-19 11:54 ——– d—–w- c:\windows\LastGood
2013-09-18 11:08 . 2013-09-18 11:08 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2013-09-18 11:08 . 2013-04-04 13:50 22856 —-a-w- c:\windows\system32\drivers\mbam.sys
2013-09-16 06:58 . 2013-09-16 06:58 ——– d—–w- c:\windows\system32\LogFiles
2013-09-10 22:18 . 2013-09-10 22:18 97008 —-a-w- c:\windows\system32\drivers\RapportKELL.sys
2013-08-29 12:01 . 2008-04-14 00:12 221184 —-a-w- c:\windows\system32\wmpns.dll
2013-08-29 11:46 . 2013-08-29 12:26 ——– d—–w- c:\documents and settings\home\Local Settings\Application Data\WMTools Downloaded Files
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-09-19 11:53 . 2013-08-08 12:16 13464 —-a-w- c:\windows\system32\drivers\SWDUMon.sys
2013-09-11 12:53 . 2012-07-14 19:44 692616 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-09-11 12:53 . 2011-06-09 14:08 71048 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-09-06 07:25 . 2013-02-24 12:17 88840 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2013-08-29 11:47 . 2013-02-24 12:17 136672 —-a-w- c:\windows\system32\drivers\avipbb.sys
2013-08-09 01:56 . 2002-03-29 16:00 386560 —-a-w- c:\windows\system32\themeui.dll
2013-08-08 06:05 . 2002-03-29 16:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2013-08-08 06:05 . 2002-03-29 16:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2013-08-08 06:05 . 2001-12-03 21:55 920064 —-a-w- c:\windows\system32\wininet.dll
2013-08-08 06:05 . 2002-03-29 16:00 18944 —-a-w- c:\windows\system32\corpol.dll
2013-08-08 01:27 . 2002-03-29 16:00 1877760 —-a-w- c:\windows\system32\win32k.sys
2013-08-08 00:02 . 2010-07-18 11:54 385024 —-a-w- c:\windows\system32\html.iec
2013-08-05 13:30 . 2002-03-29 16:00 1289728 —-a-w- c:\windows\system32\ole32.dll
2013-07-31 14:11 . 2002-03-29 16:00 810496 —-a-w- c:\windows\system32\wmvdmod.dll
2013-07-10 10:37 . 2002-03-29 16:00 406016 —-a-w- c:\windows\system32\usp10.dll
2013-07-04 02:59 . 2002-03-29 16:00 2193536 —-a-w- c:\windows\system32\ntoskrnl.exe
2013-07-04 02:08 . 2001-08-17 13:48 2070144 —-a-w- c:\windows\system32\ntkrnlpa.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SKIcoBackuped]
@="{7E5951A0-8683-432A-9483-5F43168D6A8C}"
[HKEY_CLASSES_ROOT\CLSID\{7E5951A0-8683-432A-9483-5F43168D6A8C}]
2011-09-28 09:30 3219632 —-a-w- c:\program files\VirginMedia\V Stuff Backup\AGSIconOverlay.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SKIcoSelected]
@="{15054241-49B4-4FA6-B4C7-A0071F118110}"
[HKEY_CLASSES_ROOT\CLSID\{15054241-49B4-4FA6-B4C7-A0071F118110}]
2011-09-28 09:30 3219632 —-a-w- c:\program files\VirginMedia\V Stuff Backup\AGSIconOverlay.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DriverUpdate"="c:\program files\DriverUpdate\DriverUpdate.exe" [2013-06-22 34220352]
"Google Update"="" [BU]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2013-08-29 347192]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"ADAiO2StatusMonitor"="c:\windows\System32\spool\DRIVERS\W32X86\3\ADAiO2MUI.exe" [2010-10-18 2362880]
"Conime"="c:\windows\system32\conime.exe" [2008-04-14 27648]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HsdService]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ServicepointService]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.exe.lnk]
backup=c:\windows\pss\Adobe Gamma Loader.exe.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hpoddt01.exe.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\hpoddt01.exe.lnk
backup=c:\windows\pss\hpoddt01.exe.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^VAIO Action Setup (Server).lnk]
backup=c:\windows\pss\VAIO Action Setup (Server).lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ADAiO2StatusMonitor]
2010-10-18 11:41 2362880 —-a-w- c:\windows\system32\spool\drivers\w32x86\3\ADAiO2MUI.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2013-04-04 21:06 958576 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcSoft Connection Service]
2010-03-18 11:19 207360 —-a-w- c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avgnt]
2013-08-29 11:47 347192 —-a-w- c:\program files\Avira\AntiVir Desktop\avgnt.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Backup & Storage]
2011-09-28 09:31 12465840 —-a-w- c:\program files\VirginMedia\V Stuff Backup\Backup & Storage.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
2008-04-14 00:12 110592 ——w- c:\windows\system32\bthprops.cpl
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Camera Detector]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Conime]
2008-04-14 00:12 27648 —-a-w- c:\windows\system32\conime.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 —-a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DHSClient.exe]
2011-03-23 13:12 2032952 —-a-w- c:\program files\Virgin Media\Digital Home Support\DHSClient.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriverUpdate]
2013-06-22 14:30 34220352 —-a-w- c:\program files\DriverUpdate\DriverUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus C66 Series]
2004-01-13 02:00 99840 —-a-w- c:\windows\system32\spool\drivers\w32x86\3\E_S4I2S1.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LTSMMSG]
2002-03-29 14:07 32768 —-a-w- c:\windows\LTSMMSG.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Monitor]
2007-12-10 15:55 323584 —-a-w- c:\windows\PixArt\PAC207\Monitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ——w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2006-10-22 11:22 7700480 —-a-w- c:\windows\system32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2006-10-22 11:22 86016 —-a-w- c:\windows\system32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2006-10-22 11:22 1622016 —-a-w- c:\windows\system32\nwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PAC207_Monitor]
2007-12-10 15:55 323584 —-a-w- c:\windows\PixArt\PAC207\Monitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ServiceManager.exe]
2011-03-25 12:34 4371768 —-a-w- c:\program files\Virgin Media\Service Manager\ServiceManager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2012-07-13 12:33 17418928 —-a-r- c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2011-06-09 13:06 254696 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SPTISRV"=3 (0x3)
"SkypeUpdate"=2 (0x2)
"ServicepointService"=2 (0x2)
"RapportMgmtService"=2 (0x2)
"NVSvc"=2 (0x2)
"MozillaMaintenance"=3 (0x3)
"MatSvc"=3 (0x3)
"JavaQuickStarterService"=2 (0x2)
"idsvc"=3 (0x3)
"HsdService"=2 (0x2)
"AntiVirService"=2 (0x2)
"AntiVirSchedulerService"=2 (0x2)
"Advent AIO Network Discovery Service"=2 (0x2)
"AdobeFlashPlayerUpdateSvc"=3 (0x3)
"ACDaemon"=2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
.
R0 RapportKELL;RapportKELL;c:\windows\system32\drivers\RapportKELL.sys [10/09/2013 23:18 97008]
R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [24/02/2013 13:17 37352]
R1 RapportCerberus_56758;RapportCerberus_56758;c:\documents and settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus32_56758.sys [18/09/2013 18:59 330960]
R1 RapportEI;RapportEI;c:\program files\Trusteer\Rapport\bin\RapportEI.sys [10/09/2013 23:18 148688]
R1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [10/09/2013 23:18 222416]
R2 AntiVirSchedulerService;Avira Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [24/02/2013 13:17 84024]
R2 RapportMgmtService;Rapport Management Service;c:\program files\Trusteer\Rapport\bin\RapportMgmtService.exe [10/09/2013 23:18 1435928]
R3 LucentSoftModem;Lucent Technologies Soft Modem;c:\windows\system32\drivers\LTSM.sys [29/03/2002 15:34 807917]
R3 SiS7012;Service for AC'97 Sample Driver (WDM);c:\windows\system32\drivers\sis7012.sys [28/03/2002 11:08 175232]
S3 Imx5123;Imx5123;c:\windows\system32\drivers\Imx5123.sys [30/07/2013 13:00 79232]
S3 PAC207;PC Camer@;c:\windows\system32\drivers\PFC027.SYS [13/12/2010 18:00 618112]
S3 SWDUMon;SWDUMon;c:\windows\system32\drivers\SWDUMon.sys [08/08/2013 13:16 13464]
S4 Advent AIO Network Discovery Service;Advent AIO Network Discovery Service;c:\program files\Advent\AIO\Center\ADAIOHostService.exe [14/10/2011 14:59 361904]
S4 HsdService;HsdService;c:\program files\Virgin Media\Digital Home Support\HsdService.exe [13/05/2013 13:39 1406264]
S4 MatSvc;Microsoft Automated Troubleshooting Service;c:\program files\Microsoft Fix it Center\Matsvc.exe [13/06/2011 22:09 267568]
S4 ServicepointService;ServicepointService;c:\program files\Virgin Media\Service Manager\ServicepointService.exe [13/05/2013 13:38 689464]
S4 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [13/07/2012 13:28 160944]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-08 03:32 128512 —-a-w- c:\windows\system32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder
.
2013-09-19 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-14 12:53]
.
2013-09-19 c:\windows\Tasks\User_Feed_Synchronization-{05259640-3FC6-4058-8291-C66DFD0DC59C}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 03:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
uInternet Connection Wizard,ShellNext = hxxp://shell.windows.com/fileassoc/0409/xml/redir.asp?Ext=DAT
uInternet Settings,ProxyOverride = 127.0.0.1
uSearchAssistant =
Trusted Zone: ebay.co.uk\www
Trusted Zone: Sony-europe.com
Trusted Zone: Sonystyle-europe.com
TCP: DhcpNameServer = [removed] [removed]
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\home\Application Data\Mozilla\Firefox\Profiles\o6sey9ak.default-1378978358171\
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-09-19 13:48
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_8_800_168_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_8_800_168_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(1928)
c:\windows\system32\WININET.dll
c:\program files\VirginMedia\V Stuff Backup\AGSIconOverlay.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
Completion time: 2013-09-19 13:59:34
ComboFix-quarantined-files.txt 2013-09-19 12:59
ComboFix2.txt 2013-09-18 11:00
ComboFix3.txt 2013-09-17 15:51
ComboFix4.txt 2012-01-14 18:10
.
Pre-Run: 1,749,544,960 bytes free
Post-Run: 1,740,410,880 bytes free
.
- - End Of File - - 9F4E547970FE7C6C86042191FF4A514F
8F558EB6672622401DA993E1E865C861
Then we can do the cleanup - if you are facing any issues, report that immediately.

Delete junk with adwCleaner


Please download AdwCleaner to your desktop.


  • Run adwcleaner.exe
  • Hit Scan and wait for the scan to finish.
  • Confirm the message but don´t uncheck anything.
  • Hit Delete
  • When the run is finished, it will open up a text file
  • Please post its contents within your next reply
  • You´ll find the log file at C:\AdwCleaner[S1].txt also

SecurityCheck

Please download SecurityCheck: LINK1 LINK2

  • Save it to your desktop, start it and follow the instructions in the window.
  • After the scan finished the (checkup.txt) will open. Copy its content to your thread.
Thanks. No issues other than my firefox browser takes about 5 mins to launch.

Adware log here:

# AdwCleaner v3.004 - Report created 19/09/2013 at 16:22:10
# Updated 15/09/2013 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : home - YOUR-0XV8V0OEAP
# Running from : C:\Documents and Settings\home\Desktop\adwcleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\Documents and Settings\All Users\Application Data\Systweak
Folder Deleted : C:\Documents and Settings\All Users\Start Menu\Programs\Advanced System Protector
Folder Deleted : C:\Documents and Settings\home\Application Data\Systweak

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{08858AF6-42AD-4914-95D2-AC3AB0DC8E28}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{67FA02C4-AB30-4E77-A640-78EE8EC8673B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{799391D3-EB86-4BAC-9BD3-CBFEA58A0E15}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{819FFE22-35C7-4925-8CDA-4E0E2DB94302}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D858DAFC-9573-4811-B323-7011A3AA7E61}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{01947140-417F-46B6-8751-A3A2B8345E1A}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{07B18EAA-A523-4961-B6BB-170DE4475CCA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{07B18EAC-A523-4961-B6BB-170DE4475CCA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1093995A-BA37-41D2-836E-091067C4AD17}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{120927BF-1700-43BC-810F-FAB92549B390}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{17DE5E5E-BFE3-4E83-8E1F-8755795359EC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1F52A5FA-A705-4415-B975-88503B291728}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{247A115F-06C2-4FB3-967D-2D62D3CF4F0A}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2E3537FC-CF2F-4F56-AF54-5A6A3DD375CC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3E53E2CB-86DB-4A4A-8BD9-FFEB7A64DF82}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3E720451-B472-4954-B7AA-33069EB53906}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3E720453-B472-4954-B7AA-33069EB53906}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{63D0ED2B-B45B-4458-8B3B-60C69BBBD83C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{63D0ED2D-B45B-4458-8B3B-60C69BBBD83C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{72EE7F04-15BD-4845-A005-D6711144D86A}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{7473D291-B7BB-4F24-AE82-7E2CE94BB6A9}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{7473D293-B7BB-4F24-AE82-7E2CE94BB6A9}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{7473D295-B7BB-4F24-AE82-7E2CE94BB6A9}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{7473D297-B7BB-4F24-AE82-7E2CE94BB6A9}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{819FFE21-35C7-4925-8CDA-4E0E2DB94302}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8E9CF769-3D3B-40EB-9E2D-76E7A205E4D2}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{90449521-D834-4703-BB4E-D3AA44042FF8}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{991AAC62-B100-47CE-8B75-253965244F69}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A626CDBD-3D13-4F78-B819-440A28D7E8FC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BBABDC90-F3D5-4801-863A-EE6AE529862D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D6FF3684-AD3B-48EB-BBB4-B9E6C5A355C1}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DE38C398-B328-4F4C-A3AD-1B5E4ED93477}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25E}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E79DFBC9-5697-4FBD-94E5-5B2A9C7C1612}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E79DFBCB-5697-4FBD-94E5-5B2A9C7C1612}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EB9E5C1C-B1F9-4C2B-BE8A-27D6446FDAF8}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F87D7FB5-9DC5-4C8C-B998-D8DFE02E2978}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{819FFE20-35C7-4925-8CDA-4E0E2DB94302}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{8FFDF636-0D87-4B33-B9E9-79A53F6E1DAE}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{08858AF6-42AD-4914-95D2-AC3AB0DC8E28}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{EF99BD32-C1FB-11D2-892F-0090271D4F88}]
Key Deleted : HKCU\Software\ParetoLogic
Key Deleted : HKCU\Software\systweak
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKLM\Software\systweak
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{CD95D125-2992-4858-B3EF-5F6FB52FBAD6}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{CD95D125-2992-4858-B3EF-5F6FB52FBAD6}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\00212D92-C5D8-4ff4-AE50-B20F0F85C40A_Systweak_Ad~B9F029BF_is1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\mywebsearch bar uninstall

***** [ Browsers ] *****

-\\ Internet Explorer v8.0.6001.18702


-\\ Mozilla Firefox v23.0.1 (en-GB)

[ File : C:\Documents and Settings\home\Application Data\Mozilla\Firefox\Profiles\o6sey9ak.default-1378978358171\prefs.js ]


-\\ Google Chrome v

[ File : C:\Documents and Settings\home\Local Settings\Application Data\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [7651 octets] - [19/09/2013 16:01:23]
AdwCleaner[S0].txt - [7630 octets] - [19/09/2013 16:22:10]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [7690 octets] ##########



Security check log here:

Results of screen317's Security Check version 0.99.73
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
Avira Free Antivirus
ESET Online Scanner v3
Avira successfully updated!
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware version 1.75.0.1300
Java™ 6 Update 30
Java version out of Date!
Adobe Flash Player 11.8.800.94
Adobe Reader XI
Mozilla Firefox (23.0.1)
````````Process Check: objlist.exe by Laurent````````
Avira Antivir avgnt.exe
Avira Antivir avguard.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:: 14% Defragment your hard drive soon! (Do NOT defrag if SSD!)
````````````````````End of Log``````````````````````

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI