This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Malawarebytes Will Not Load, Some Streaming Too [Closed]

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Uninstall/Reinstall Google Chrome

First save all your bookmarks/favourites.

  • open Chrome, click on the 3 bars in the top right hand corner, select Bookmarks and then Bookmarks Manager
  • click on Organise and then select Export Bookmarks to HTML file, then choose Desktop to save it
  • again, click on the three bars in the top right hand corner and select Settings
  • in the list of Settings under “Sign in” click on Disconnect your Google Account
  • in the text of the next window click on “Google Dashboard” then, at the “Chrome sync” screen, click on Stop and Clear at the bottom
  • a box will open and ask for confirmation, click on OK (wait for this to complete before doing the next step)
  • when confirmation appears close that page and then click on Disconnect account
  • shut Google Chrome, click on Start > Control Panel > Programs and Features (or Add/Remove Programs in XP) and uninstall Google Chrome. Select Everything for removal if asked.

Reboot the system and then reinstall Google Chrome from here

Repeat the process to reinstate your bookmarks by going to Bookmarks > Bookmarks Manager > Organise and select Import Bookmarks.

 

 

===============================================

 

Can you try running Zoek again after doing that.

 

Important: Disable your AntiVirus and AntiSpyware programs, so they do not interfere with the running of Zoek.exe.

  • on Windows Vista, 7/8, right-click Zoek.exe and select: Run as Administrator
  • give it a few seconds to appear
  • copy/paste the entire script inside the codebox below into the input field of Zoek:
    createsrpoint;
    autoclean;
    emptyalltemp;
    ipconfig /flushdns;b
    
    
  • close any open programs.
  • click the Run script button, and wait. It takes a few minutes to run.
  • when the tool finishes, the zoek-results.log is opened in Notepad: the log can also be found on the systemdrive, normally C:\
  • if a reboot is needed, the log will be opened after the reboot.

Satchfan

 

Good morning Satchfan.

I am unable to save bookmarks (no great loss) as I cannot get Google Chrome to open at all.

I next tried to remove the program from 'add and remove' and got a window asking me to first shut off all Chrome windows first.

There aren't any running that I can see!

Thanks for hanging in there with me.

Thanks for hanging in there with me.

 

No problem - we'll sort this!!!

Let’s try forcing the uninstall.

Download Revo Uninstaller
 

  • double click the installation file on the desktop to run the installer
  • let it install to the default location
  • double click the new Revo Uninstaller Icon on the desktop to start the program.

You will now see a list of installed programs that Revo Uninstaller can remove.
 

  • locate Google Chrome
  • right-click the icon then choose Uninstall
  • click Yes to the warning and choose the Uninstall Mode
  • choose the Advanced option and then click Next
  • this will launch the programs built in uninstaller. Be patient it can take several seconds
  • once the uninstaller is done click Next
  • Revo Uninstaller will now scan for leftover information. Be patient it can take several seconds.
  • once this scan is done click Next
  • you will then be presented of the leftover entries found by Revo Uninstaller
  • look at ALL of the entries to ensure they relate to the uninstall
  • next, click Select All > Delete to remove the entries
  • click Next
  • if there are any program file folders left over you will be presented with a list to be removed
  • again look at ALL of the entries to ensure they are related to the uninstall
  • click Select All > Delete to remove the entries
  • click Finish to go back to the uninstall list
  • when you have removed it, close the program.

Satchfan

 

Update: I was able to get rid of Chrome in safe mode before work.

I tried to run Zoek but, no luck in either safe or regular mode.

Do you want me to reinstall Chrome as above?

Do you want me to reinstall Chrome as above?

 

Not for the moment.

Please run these in the order requested.

Run TDSSKiller

Please download TDSSKiller.zip

  • extract it to your desktop
  • double click TDSSKiller.exe
  • press Start Scan
    • only if Malicious objects are found then ensure Cure is selected. Do not change it to Delete or Quarantine as it may delete infected files that are required for Windows to operate properly.
    • then click Continue > Reboot now
  • copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\) called TDSSKiller_*** (*** denotes version & date)

======================================================

Download and run ComboFix

Download ComboFix from the following location:

Link

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • see this Link  for programs that need to be disabled and instruction on how to disable them.
  • remember to re-enable them when we're done.
  • double click on ComboFix.exe & follow the prompts.
  • as part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal.  It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue its malware removal procedures.

    [external image: RcAuto1.gif]
     

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    [external image: whatnext.jpg]
     

    Click on Yes, to continue scanning for malware.

Note: Do not mouse-click combofix's window while it is running. That may cause it to stall.

When finished, it will produce a log.   Please include the ComboFix.txt in your next reply. It can be found at C:\ComboFix.txt

Please also remember to include the TDSSKiller log

Thanks

Satchfan

I tried running TDSS as instructed and got the same results….a window asking me if I wanted to run the program. I click on run and then nothing happens.

 

I also tried to boot into safe mode to try and after 5 attempts it only gets so far before reverting back to the normal mode and then it will boot.

Can you create a new account with Administrator privileges and see if any of the programs will run when you are logged in to that account.

No luck there either.

 

This is probably a stupid idea but…would it make a difference if I burned a disc of the files you want me to run on another computer then, run it from the CD drive on my computer?

 

Just a thought this morning as the coffee is brewed.

Got you on the account.

I have created a new one and made it an administor.

Still can't get programs to run.

I don't get any messages other than the title of the window 'Open File Security Warning' and

It appears from the warning that you mentioned that Windows settings may be the problem here and not malware.

I’m not an expert in Windows and therefore the instructions may not be 100% but this may be worth trying to get these programs running:

  • press the Windows Key+R
  • type gpedit.msc and click OK, (if prompted for an administrator password or for confirmation, type the password, or provide confirmation}
  • go to User Configuration > Administrative Templates > Windows Components > Attachment Manager and see these two policies:


    Default risk level for file attachments
    Inclusion list for low file types

     

  • change the settings to “Enabled”
  • reboot your computer.

Please try running any of the tools again.

Satchfan


 

 

OK, I got to the step of Windows Components but, there is nothing on the list after clicking it that says Attachment Manager. Must be called something else.

:wall:  Let's try another way.

 

  • right-click ComboFix and select Properties
  • on the "General" tab, click Unblock

When opening a moderate risk file, the warning dialog will include the option "Always ask before opening this file". Clearing this option will remove the zone-marking for ComboFix.

 

Let me know how that goes. :)

Combo fix will open right up. I was waiting to for permission to run that.

OK…ran it and I did need to install the Recovery Console.

Here is the log!

 

ComboFix 15-07-18.01 - Dad 07/18/2015  19:06:57.1.1 - x86

Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.3038.2616 [GMT -4:00]

Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe

AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}

.

.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\documents and settings\All Users\Application Data\TEMP

c:\documents and settings\Dad\Application Data\Roaming

c:\documents and settings\Dad\Application Data\Roaming\HoldemManager\config\FTPRushTables.xml

c:\documents and settings\Dad\WINDOWS

c:\windows\$msi31uninstall_kb893803v2$

c:\windows\$msi31uninstall_kb893803v2$\msi.dll

c:\windows\$msi31uninstall_kb893803v2$\msiexec.exe

c:\windows\$msi31uninstall_kb893803v2$\msihnd.dll

c:\windows\$msi31uninstall_kb893803v2$\msimsg.dll

c:\windows\$msi31uninstall_kb893803v2$\msisip.dll

c:\windows\$msi31uninstall_kb893803v2$\reg00013

c:\windows\$msi31uninstall_kb893803v2$\reg00014

c:\windows\$msi31uninstall_kb893803v2$\reg00015

c:\windows\$msi31uninstall_kb893803v2$\reg00016

c:\windows\$msi31uninstall_kb893803v2$\reg00017

c:\windows\$msi31uninstall_kb893803v2$\reg00018

c:\windows\$msi31uninstall_kb893803v2$\reg00019

c:\windows\$msi31uninstall_kb893803v2$\reg00020

c:\windows\$msi31uninstall_kb893803v2$\reg00021

c:\windows\$msi31uninstall_kb893803v2$\reg00022

c:\windows\$msi31uninstall_kb893803v2$\reg00023

c:\windows\$msi31uninstall_kb893803v2$\reg00024

c:\windows\$msi31uninstall_kb893803v2$\reg00025

c:\windows\$msi31uninstall_kb893803v2$\reg00026

c:\windows\$msi31uninstall_kb893803v2$\reg00027

c:\windows\$msi31uninstall_kb893803v2$\reg00028

c:\windows\$msi31uninstall_kb893803v2$\reg00029

c:\windows\$msi31uninstall_kb893803v2$\reg00030

c:\windows\$msi31uninstall_kb893803v2$\reg00031

c:\windows\$msi31uninstall_kb893803v2$\reg00032

c:\windows\$msi31uninstall_kb893803v2$\reg00033

c:\windows\$msi31uninstall_kb893803v2$\reg00034

c:\windows\$msi31uninstall_kb893803v2$\reg00035

c:\windows\$msi31uninstall_kb893803v2$\reg00036

c:\windows\$msi31uninstall_kb893803v2$\reg00037

c:\windows\$msi31uninstall_kb893803v2$\reg00038

c:\windows\$msi31uninstall_kb893803v2$\reg00039

c:\windows\$msi31uninstall_kb893803v2$\reg00040

c:\windows\$msi31uninstall_kb893803v2$\reg00041

c:\windows\$msi31uninstall_kb893803v2$\reg00042

c:\windows\$msi31uninstall_kb893803v2$\reg00043

c:\windows\$msi31uninstall_kb893803v2$\reg00044

c:\windows\$msi31uninstall_kb893803v2$\reg00045

c:\windows\$msi31uninstall_kb893803v2$\reg00046

c:\windows\$msi31uninstall_kb893803v2$\reg00047

c:\windows\$msi31uninstall_kb893803v2$\reg00048

c:\windows\$msi31uninstall_kb893803v2$\reg00051

c:\windows\$msi31uninstall_kb893803v2$\reg00052

c:\windows\$msi31uninstall_kb893803v2$\reg00053

c:\windows\$msi31uninstall_kb893803v2$\reg00054

c:\windows\$msi31uninstall_kb893803v2$\reg00055

c:\windows\$msi31uninstall_kb893803v2$\reg00056

c:\windows\$msi31uninstall_kb893803v2$\reg00057

c:\windows\$msi31uninstall_kb893803v2$\reg00058

c:\windows\$msi31uninstall_kb893803v2$\reg00059

c:\windows\$msi31uninstall_kb893803v2$\reg00060

c:\windows\$msi31uninstall_kb893803v2$\reg00061

c:\windows\$msi31uninstall_kb893803v2$\reg00062

c:\windows\$msi31uninstall_kb893803v2$\reg00063

c:\windows\$msi31uninstall_kb893803v2$\reg00064

c:\windows\$msi31uninstall_kb893803v2$\reg00065

c:\windows\$msi31uninstall_kb893803v2$\reg00066

c:\windows\$msi31uninstall_kb893803v2$\reg00067

c:\windows\$msi31uninstall_kb893803v2$\reg00068

c:\windows\$msi31uninstall_kb893803v2$\reg00069

c:\windows\$msi31uninstall_kb893803v2$\reg00070

c:\windows\$msi31uninstall_kb893803v2$\reg00071

c:\windows\$msi31uninstall_kb893803v2$\reg00072

c:\windows\$msi31uninstall_kb893803v2$\reg00073

c:\windows\$msi31uninstall_kb893803v2$\reg00074

c:\windows\$msi31uninstall_kb893803v2$\reg00075

c:\windows\$msi31uninstall_kb893803v2$\reg00076

c:\windows\$msi31uninstall_kb893803v2$\reg00077

c:\windows\$msi31uninstall_kb893803v2$\reg00078

c:\windows\$msi31uninstall_kb893803v2$\reg00079

c:\windows\$msi31uninstall_kb893803v2$\reg00080

c:\windows\$msi31uninstall_kb893803v2$\reg00081

c:\windows\$msi31uninstall_kb893803v2$\reg00082

c:\windows\$msi31uninstall_kb893803v2$\reg00083

c:\windows\$msi31uninstall_kb893803v2$\reg00084

c:\windows\$msi31uninstall_kb893803v2$\reg00085

c:\windows\$msi31uninstall_kb893803v2$\reg00086

c:\windows\$msi31uninstall_kb893803v2$\reg00087

c:\windows\$msi31uninstall_kb893803v2$\reg00088

c:\windows\$msi31uninstall_kb893803v2$\reg00089

c:\windows\$msi31uninstall_kb893803v2$\reg00090

c:\windows\$msi31uninstall_kb893803v2$\reg00091

c:\windows\$msi31uninstall_kb893803v2$\reg00092

c:\windows\$msi31uninstall_kb893803v2$\reg00093

c:\windows\$msi31uninstall_kb893803v2$\reg00094

c:\windows\$msi31uninstall_kb893803v2$\reg00095

c:\windows\$msi31uninstall_kb893803v2$\reg00096

c:\windows\$msi31uninstall_kb893803v2$\reg00097

c:\windows\$msi31uninstall_kb893803v2$\reg00098

c:\windows\$msi31uninstall_kb893803v2$\reg00099

c:\windows\$msi31uninstall_kb893803v2$\reg00100

c:\windows\$msi31uninstall_kb893803v2$\reg00101

c:\windows\$msi31uninstall_kb893803v2$\reg00102

c:\windows\$msi31uninstall_kb893803v2$\reg00103

c:\windows\$msi31uninstall_kb893803v2$\reg00104

c:\windows\$msi31uninstall_kb893803v2$\reg00105

c:\windows\$msi31uninstall_kb893803v2$\reg00106

c:\windows\$msi31uninstall_kb893803v2$\reg00107

c:\windows\$msi31uninstall_kb893803v2$\reg00108

c:\windows\$msi31uninstall_kb893803v2$\reg00109

c:\windows\$msi31uninstall_kb893803v2$\reg00110

c:\windows\$msi31uninstall_kb893803v2$\reg00111

c:\windows\$msi31uninstall_kb893803v2$\reg00112

c:\windows\$msi31uninstall_kb893803v2$\reg00113

c:\windows\$msi31uninstall_kb893803v2$\reg00114

c:\windows\$msi31uninstall_kb893803v2$\reg00115

c:\windows\$msi31uninstall_kb893803v2$\reg00116

c:\windows\$msi31uninstall_kb893803v2$\spuninst\spuninst.exe

c:\windows\$msi31uninstall_kb893803v2$\spuninst\spuninst.inf

c:\windows\$msi31uninstall_kb893803v2$\spuninst\spuninst.txt

c:\windows\$msi31uninstall_kb893803v2$\spuninst\updspapi.dll

c:\windows\EventSystem.log

c:\windows\msdownld.tmp

c:\windows\system32\config\systemprofile\Application Data\SearchProtect

c:\windows\system32\Packet.dll

c:\windows\system32\pthreadVC.dll

c:\windows\system32\wpcap.dll

c:\windows\XSxS

.

.

(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

——-\Legacy_DEFAULTTABSEARCH

——-\Service_NPF

.

.

(((((((((((((((((((((((((   Files Created from 2015-06-18 to 2015-07-18  )))))))))))))))))))))))))))))))

.

.

2015-07-17 22:46 . 2015-07-17 22:46   ——–   d–h–w-               c:\windows\system32\GroupPolicy

2015-07-17 17:47 . 2015-07-17 17:47   ——–   d—–w-                c:\documents and settings\Peleki

2015-07-16 19:33 . 2015-07-16 19:33   ——–   d—–w-                c:\program files\VS Revo Group

2015-07-15 00:49 . 2015-07-15 00:49   ——–   d—–w-                C:\zoek_backup

2015-07-12 02:46 . 2015-07-12 02:46   ——–   d—–w-                c:\documents and settings\Dad\Local Settings\Application Data\Dropbox

2015-07-12 02:46 . 2015-07-12 02:46   ——–   d–h–w-               c:\windows\PIF

2015-07-12 02:46 . 2015-07-12 02:46   ——–   d—–w-                c:\program files\Common Files\Microsoft

2015-07-10 16:40 . 2015-07-10 16:40   ——–   d—–w-                c:\program files\360

2015-07-10 02:12 . 2015-07-15 17:12   18524336             —-a-w-                c:\windows\system32\FlashPlayerInstaller.exe

2015-07-10 01:25 . 2015-07-10 01:25   ——–   d—–w-                c:\windows\system32\wbem\Repository

2015-07-10 01:20 . 2015-07-10 01:22   ——–   d—–w-                c:\program files\Malwarebytes Anti-Malware

2015-07-10 00:58 . 2015-07-10 01:20   ——–   d—–w-                c:\documents and settings\LocalService\Application Data\tor

2015-07-08 19:47 . 2015-07-10 01:30   ——–   d—–w-                c:\documents and settings\LocalService\Local Settings\Application Data\Identities

2015-07-08 18:27 . 2015-07-10 01:20   ——–   d–h–w-               c:\documents and settings\All Users\Application Data\{F87DCEF6-04DD-4A4E-8B0F-729ABCA4B397}

2015-06-28 19:38 . 2015-07-10 01:21   ——–   d—–w-                c:\program files\Dell Support Center

2015-06-28 19:38 . 2015-06-28 19:38   ——–   d—–w-                c:\program files\Dell

.

.

.

((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2015-07-15 17:12 . 2012-08-05 11:08   778416  —-a-w-                c:\windows\system32\FlashPlayerApp.exe

2015-07-15 17:12 . 2011-08-14 11:58   142512  —-a-w-                c:\windows\system32\FlashPlayerCPLApp.cpl

2015-06-17 05:01 . 2015-06-17 05:01   1202856                —-a-w-                c:\windows\system32\FM20.DLL

2015-05-04 08:25 . 2014-10-15 00:38   114904  —-a-w-                c:\windows\system32\drivers\MBAMSwissArmy.sys

.

.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt1]

@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]

2015-06-26 18:30        151576  —-a-w-                c:\documents and settings\Dad\Application Data\Dropbox\bin\DropboxExt.26.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt2]

@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]

2015-06-26 18:30        151576  —-a-w-                c:\documents and settings\Dad\Application Data\Dropbox\bin\DropboxExt.26.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt3]

@="{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}]

2015-06-26 18:30        151576  —-a-w-                c:\documents and settings\Dad\Application Data\Dropbox\bin\DropboxExt.26.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt4]

@="{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}]

2015-06-26 18:30        151576  —-a-w-                c:\documents and settings\Dad\Application Data\Dropbox\bin\DropboxExt.26.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt5]

@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]

2015-06-26 18:30        151576  —-a-w-                c:\documents and settings\Dad\Application Data\Dropbox\bin\DropboxExt.26.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt6]

@="{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}]

2015-06-26 18:30        151576  —-a-w-                c:\documents and settings\Dad\Application Data\Dropbox\bin\DropboxExt.26.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt7]

@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]

2015-06-26 18:30        151576  —-a-w-                c:\documents and settings\Dad\Application Data\Dropbox\bin\DropboxExt.26.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt8]

@="{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}]

2015-06-26 18:30        151576  —-a-w-                c:\documents and settings\Dad\Application Data\Dropbox\bin\DropboxExt.26.dll

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Skype"="c:\program files\Skype\Phone\Skype.exe" [2015-04-17 31280256]

"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-08-09 1961984]

"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"TkBellExe"="c:\program files\real\realplayer\update\realsched.exe" [2013-09-04 295512]

"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2015-04-07 157480]

.

c:\documents and settings\Caitlin.PETE-05F6D62355\Start Menu\Programs\Startup\

OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE /tsr [2009-2-26 97680]

.

c:\documents and settings\Dad\Start Menu\Programs\Startup\

Dropbox.lnk - c:\documents and settings\Dad\Application Data\Dropbox\bin\Dropbox.exe /systemstartup [2015-5-4 43871968]

OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE /tsr [2009-2-26 97680]

.

c:\documents and settings\All Users\Start Menu\Programs\Startup\

NETGEAR WNDA3100v2 Genie.lnk - c:\program files\NETGEAR\WNDA3100v2\WNDA3100v2.exe [2014-11-15 8385240]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"MIDI1"=vscapi.dll

"WAVE1"=vscapi.dll

.

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]

BootExecute                REG_MULTI_SZ                autocheck autochk *\0sprestrt

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

@="Driver"

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

@="Service"

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

"c:\\Documents and Settings\\Dad\\Application Data\\Dropbox\\bin\\Dropbox.exe"=

"c:\\Program Files\\iTunes\\iTunes.exe"=

"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

"c:\\Program Files\\Juicy Stakes 2.0\\PokerClient.exe"=

"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"5432:TCP"= 5432:TCP:postgres

.

R2 mbamchameleon;mbamchameleon;c:\windows\system32\drivers\mbamchameleon.sys [10/14/2014 8:38 PM 54360]

R2 postgresql-8.4;PostgreSQL Server 8.4;C:/Program Files/PostgreSQL/8.4/bin/pg_ctl.exe runservice -N "postgresql-8.4" -D "C:/Program Files/PostgreSQL/8.4/data" -w –> C:/Program Files/PostgreSQL/8.4/bin/pg_ctl.exe runservice -N postgresql-8.4 [?]

R2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;c:\program files\RealNetworks\RealDownloader\rndlresolversvc.exe [8/14/2013 3:19 PM 39056]

R3 BCMH43XX;Broadcom 802.11 USB Network Adapter Driver;c:\windows\system32\drivers\bcmwlhigh5.sys [11/14/2014 11:36 PM 1034240]

R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [10/14/2014 8:38 PM 23256]

R3 vsc32;Virtual Sound Canvas 3.2;c:\windows\system32\drivers\vsc.sys [3/29/2011 6:27 PM 951284]

S1 BAPIDRV;BAPIDRV;c:\windows\system32\DRIVERS\BAPIDRV.sys –> c:\windows\system32\DRIVERS\BAPIDRV.sys [?]

S2 MBAMScheduler;MBAMScheduler;c:\program files\Malwarebytes Anti-Malware\mbamscheduler.exe [10/14/2014 8:38 PM 1871160]

S2 MBAMService;MBAMService;c:\program files\Malwarebytes Anti-Malware\mbamservice.exe [10/14/2014 8:38 PM 969016]

S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2/18/2015 8:11 PM 315488]

S2 WSWNDA3100v2;WSWNDA3100v2;c:\program files\NETGEAR\WNDA3100v2\WifiSvc.exe [11/15/2014 1:26 PM 307928]

S3 wlags51b;Wireless LAN USB Driver;c:\windows\system32\drivers\wlags51b.sys [3/20/2011 7:23 PM 177664]

S4 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [8/27/2013 3:57 PM 93072]

.

Contents of the 'Scheduled Tasks' folder

.

2015-07-17 c:\windows\Tasks\Adobe Flash Player Updater.job

- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-05 17:12]

.

2015-07-16 c:\windows\Tasks\AppleSoftwareUpdate.job

- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 22:57]

.

2015-07-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2015-07-16 20:59]

.

2015-07-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2015-07-16 20:59]

.

2015-07-18 c:\windows\Tasks\Microsoft Windows XP End of Service Notification Logon.job

- c:\windows\system32\xp_eos.exe [2014-03-26 01:59]

.

2015-06-08 c:\windows\Tasks\Microsoft Windows XP End of Service Notification Monthly.job

- c:\windows\system32\xp_eos.exe [2014-03-26 01:59]

.

2015-07-10 c:\windows\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-1844237615-515967899-725345543-1005.job

- c:\program files\RealNetworks\RealDownloader\recordingmanager.exe [2013-08-14 19:19]

.

2015-07-18 c:\windows\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-1844237615-515967899-725345543-1005.job

- c:\program files\RealNetworks\RealDownloader\realupgrade.exe [2013-08-14 19:19]

.

2015-07-17 c:\windows\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-1844237615-515967899-725345543-1005.job

- c:\program files\RealNetworks\RealDownloader\realupgrade.exe [2013-08-14 19:19]

.

2015-07-18 c:\windows\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1844237615-515967899-725345543-1004.job

- c:\program files\Real\RealUpgrade\realupgrade.exe [2013-08-14 21:13]

.

2015-07-18 c:\windows\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1844237615-515967899-725345543-1005.job

- c:\program files\Real\RealUpgrade\realupgrade.exe [2013-08-14 21:13]

.

2015-07-17 c:\windows\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1844237615-515967899-725345543-1004.job

- c:\program files\Real\RealUpgrade\realupgrade.exe [2013-08-14 21:13]

.

2015-07-18 c:\windows\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1844237615-515967899-725345543-1005.job

- c:\program files\Real\RealUpgrade\realupgrade.exe [2013-08-14 21:13]

.

2015-07-18 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1844237615-515967899-725345543-1004.job

- c:\program files\Real\RealUpgrade\realupgrade.exe [2013-08-14 21:13]

.

2015-07-18 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1844237615-515967899-725345543-1005.job

- c:\program files\Real\RealUpgrade\realupgrade.exe [2013-08-14 21:13]

.

2015-07-13 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1844237615-515967899-725345543-1004.job

- c:\program files\Real\RealUpgrade\realupgrade.exe [2013-08-14 21:13]

.

2015-07-17 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1844237615-515967899-725345543-1005.job

- c:\program files\Real\RealUpgrade\realupgrade.exe [2013-08-14 21:13]

.

2015-07-18 c:\windows\Tasks\User_Feed_Synchronization-{C1600535-C1FD-474A-9F2E-A1BAED631CC7}.job

- c:\windows\system32\msfeedssync.exe [2009-03-08 09:31]

.

2015-07-18 c:\windows\Tasks\User_Feed_Synchronization-{DFAC5F52-F896-4C64-B364-5AA672E62C68}.job

- c:\windows\system32\msfeedssync.exe [2009-03-08 09:31]

.

.

——- Supplementary Scan ——-

.

uStart Page = hxxp://www.google.com

Trusted Zone: dell.com

TCP: DhcpNameServer = [removed] [removed]

FF - ProfilePath - c:\documents and settings\Dad\Application Data\Mozilla\Firefox\Profiles\ndwc8g77.default-1413647459921\

FF - prefs.js: browser.search.defaulturl -

FF - prefs.js: browser.search.selectedEngine - Yahoo

FF - prefs.js: browser.startup.homepage - about:home

.

.

——- File Associations ——-

.

.txt=

.

- - - - ORPHANS REMOVED - - - -

.

Toolbar-10 - (no file)

Toolbar-Locked - (no file)

HKCU-Run-CPN Notifier - c:\program files\Juicy Stakes 2.0\PokerNotifier.exe

HKCU-Run-GoogleChromeAutoLaunch_700504192C3EF5F701D834ADBDF37978 - c:\program files\Google\Chrome\Application\chrome.exe

SafeBoot-WudfPf

SafeBoot-WudfRd

HKLM_ActiveSetup-{8A69D345-D564-463c-AFF1-A69D9E530F96} - c:\program files\Google\Chrome\Application\43.0.2357.134\Installer\chrmstp.exe

.

.

.

**************************************************************************

.

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2015-07-18 19:20

Windows 5.1.2600 Service Pack 3 NTFS

.

scanning hidden processes … 

.

scanning hidden autostart entries …

.

scanning hidden files … 

.

scan completed successfully

hidden files: 0

.

**************************************************************************

.

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\postgresql-8.4]

"ImagePath"="C:/Program Files/PostgreSQL/8.4/bin/pg_ctl.exe runservice -N \"postgresql-8.4\" -D \"C:/Program Files/PostgreSQL/8.4/data\" -w"

.

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\postgresql-8.4]

"ImagePath"="C:/Program Files/PostgreSQL/8.4/bin/pg_ctl.exe runservice -N \"postgresql-8.4\" -D \"C:/Program Files/PostgreSQL/8.4/data\" -w"

.

——————— LOCKED REGISTRY KEYS ———————

.

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_18_0_0_209_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]

@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_18_0_0_209_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]

@Denied: (A 2) (Everyone)

@="IFlashBroker6"

.

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\software\Microsoft\Cryptography\RNG*]

"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,

   bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\

"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,

   bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\

"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,

   bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\

"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,

   bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\

"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,

   bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\

"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,

   bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\

"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,

   bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\

"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,

   bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\

"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,

   bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\

"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,

   bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\

.

——————— DLLs Loaded Under Running Processes ———————

.

- - - - - - - > 'explorer.exe'(2460)

c:\windows\system32\WININET.dll

c:\documents and settings\Dad\Application Data\Dropbox\bin\DropboxExt.26.dll

c:\windows\system32\ieframe.dll

c:\windows\system32\webcheck.dll

c:\windows\system32\WPDShServiceObj.dll

c:\windows\system32\PortableDeviceTypes.dll

c:\windows\system32\PortableDeviceApi.dll

.

———————— Other Running Processes ————————

.

c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

c:\program files\Bonjour\mDNSResponder.exe

c:\program files\Flip Video\FlipShare\FlipShareService.exe

c:\program files\PostgreSQL\8.4\bin\pg_ctl.exe

c:\program files\PostgreSQL\8.4\bin\postgres.exe

c:\program files\PostgreSQL\8.4\bin\postgres.exe

c:\program files\PostgreSQL\8.4\bin\postgres.exe

c:\program files\PostgreSQL\8.4\bin\postgres.exe

c:\program files\PostgreSQL\8.4\bin\postgres.exe

c:\windows\system32\wbem\unsecapp.exe

c:\windows\system32\wscntfy.exe

c:\documents and settings\Dad\Application Data\Dropbox\bin\Dropbox.exe

c:\program files\iPod\bin\iPodService.exe

.

**************************************************************************

.

Completion time: 2015-07-18  19:26:07 - machine was rebooted

ComboFix-quarantined-files.txt  2015-07-18 23:26

.

Pre-Run: 911,480,377,344 bytes free

Post-Run: 911,521,587,200 bytes free

.

- - End Of File - - 749728446FB31DB833D6B1C15CD31382

8F558EB6672622401DA993E1E865C861

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI