Dreamx Posted November 17, 2011 ID:495629 Share Posted November 17, 2011 I allowed my brother to use my old PC. He gave it back to me because he couldn't do anything on it. I need help cleaning it up, my normal methods arn't working.Here is the ComboFix log after I ran it.ComboFix 11-11-16.02 - ~Devon~ 11/17/2011 0:39.2.1 - x86Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1279.800 [GMT -5:00]Running from: c:\documents and settings\~Devon~\Desktop\Combo-Fix.exeAV: avast! antivirus 4.8.0 [VPS 000000-0] *Disabled/Outdated* {7591DB91-41F0-48A3-B128-1A293FD8233D}..((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))..c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exec:\program files\QuickTime\qttask .exec:\program files\QuickTime\qttask .exec:\windows\TEMP\ter1mw32.dll.---- Previous Run -------.c:\documents and settings\~Devon~\Application Data\dwm.exec:\documents and settings\~Devon~\Application Data\Microsoft\conhost.exec:\documents and settings\~Devon~\Application Data\PriceGong\Data\1.xmlc:\documents and settings\~Devon~\Application Data\PriceGong\Data\a.xmlc:\documents and settings\~Devon~\Application Data\PriceGong\Data\b.xmlc:\documents and settings\~Devon~\Application Data\PriceGong\Data\c.xmlc:\documents and settings\~Devon~\Application Data\PriceGong\Data\d.xmlc:\documents and settings\~Devon~\Application Data\PriceGong\Data\e.xmlc:\documents and settings\~Devon~\Application Data\PriceGong\Data\f.xmlc:\documents and settings\~Devon~\Application Data\PriceGong\Data\g.xmlc:\documents and settings\~Devon~\Application Data\PriceGong\Data\h.xmlc:\documents and settings\~Devon~\Application Data\PriceGong\Data\i.xmlc:\documents and settings\~Devon~\Application Data\PriceGong\Data\J.xmlc:\documents and settings\~Devon~\Application Data\PriceGong\Data\k.xmlc:\documents and settings\~Devon~\Application Data\PriceGong\Data\l.xmlc:\documents and settings\~Devon~\Application Data\PriceGong\Data\m.xmlc:\documents and settings\~Devon~\Application Data\PriceGong\Data\mru.xmlc:\documents and settings\~Devon~\Application Data\PriceGong\Data\n.xmlc:\documents and settings\~Devon~\Application Data\PriceGong\Data\o.xmlc:\documents and settings\~Devon~\Application Data\PriceGong\Data\p.xmlc:\documents and settings\~Devon~\Application Data\PriceGong\Data\q.xmlc:\documents and settings\~Devon~\Application Data\PriceGong\Data\r.xmlc:\documents and settings\~Devon~\Application Data\PriceGong\Data\s.xmlc:\documents and settings\~Devon~\Application Data\PriceGong\Data\t.xmlc:\documents and settings\~Devon~\Application Data\PriceGong\Data\u.xmlc:\documents and settings\~Devon~\Application Data\PriceGong\Data\v.xmlc:\documents and settings\~Devon~\Application Data\PriceGong\Data\w.xmlc:\documents and settings\~Devon~\Application Data\PriceGong\Data\x.xmlc:\documents and settings\~Devon~\Application Data\PriceGong\Data\y.xmlc:\documents and settings\~Devon~\Application Data\PriceGong\Data\z.xmlc:\documents and settings\~Devon~\Local Settings\Application Data\{213AD529-E6CF-43D4-990B-78917EEEDFE4}\chrome.manifestc:\documents and settings\~Devon~\Local Settings\Application Data\{213AD529-E6CF-43D4-990B-78917EEEDFE4}\chrome\content\_cfg.jsc:\documents and settings\~Devon~\Local Settings\Application Data\{213AD529-E6CF-43D4-990B-78917EEEDFE4}\chrome\content\overlay.xulc:\documents and settings\~Devon~\Local Settings\Application Data\{213AD529-E6CF-43D4-990B-78917EEEDFE4}\install.rdfc:\documents and settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setup.dllc:\documents and settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dllc:\documents and settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.datc:\documents and settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.exec:\documents and settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.icoc:\documents and settings\NetworkService\Local Settings\Application Data\pgyxxwv.exec:\program files\DealScout\dealscout.dllc:\program files\iTunes\iTunesHelper.exec:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome.manifestc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\content\constants.jsc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\content\convertvideo.jsc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\content\convertvideodlg.jsc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\content\convertvideodlg.xulc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\content\events.jsc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\content\savetomp3popup.jsc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\content\savetomp3popup.xulc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\content\tbcore.jsc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\content\toolbar.xulc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\content\weather.jsc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\content\weatherLoc.jsc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\content\weatherLoc.xulc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\arrow-grey.pngc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\arrow_partner.pngc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\arrow_small.pngc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\bg.jpgc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\buttons\arrow.pngc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\buttons\arrow_big.pngc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\buttons\btn_close.pngc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\buttons\dailyhotdeals.pngc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\buttons\divider.pngc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\buttons\facebook.pngc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\buttons\games.pngc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\buttons\icon-RSS.pngc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\buttons\news.pngc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\buttons\plainbutton.pngc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\buttons\savemp3.pngc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\buttons\savemp3_disabled.pngc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\buttons\savemp3popup-musicicon.pngc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\buttons\savemp3popup.pngc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\buttons\saveyoutubevideos.pngc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\buttons\screensaver.pngc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\buttons\search.pngc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\buttons\searchbar-grey-250.pngc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\buttons\searchbox.pngc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\buttons\separator_line.pngc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\buttons\shopping.pngc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\buttons\Thumbs.dbc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\buttons\watermark.pngc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\buttons\youtube.pngc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\feeditem.pngc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\logo.pngc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\news_refresh.pngc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\popupSearchMp3.cssc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\popupWindow.cssc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\SaveMp3_bg_hover.pngc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\SaveMp3_bg_normal.pngc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\savetomp3PopUp.cssc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\Thumbs.dbc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\toolbar.cssc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\weather\chance_of_rain.pngc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\weather\chance_of_snow.pngc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\weather\chance_of_storm.pngc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\weather\chance_of_tstorm.pngc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\weather\cloudy.pngc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\weather\flurries.pngc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\weather\hazy.pngc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\weather\mist.pngc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\weather\mostly_cloudy.pngc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\weather\mostly_sunny.pngc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\weather\rain.pngc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\weather\sleet.pngc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\weather\snow.pngc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\weather\storm.pngc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\weather\sunny.pngc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\weather\Thumbs.dbc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\weather\thunderstorm.pngc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\weather\weatherbug.pngc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\chrome\skin\weather\windy.pngc:\program files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com\install.rdfc:\program files\Mozilla Firefox\Plugins\npclntax_HBLiteSA.dllc:\program files\Mp3Tube Toolbar\ffmpeg.exec:\program files\Mp3Tube Toolbar\Mp3TubeSvc.exec:\program files\Mp3Tube Toolbar\mp3Tubetb.dllc:\program files\Mp3Tube Toolbar\Mp3TubeVideoToMp3.exec:\program files\Mp3Tube Toolbar\ShowMsg.exec:\program files\Mp3Tube Toolbar\uninstall.exec:\program files\QuickTime\qttask.exec:\program files\Search Toolbar\icon.icoc:\program files\Search Toolbar\SearchToolbar.dllc:\program files\Search Toolbar\SearchToolbarUninstall.exec:\program files\Search Toolbar\SearchToolbarUpdater.exec:\windows\$xntuninstall643$\ppjxq.dllc:\windows\$xntuninstall643$\rhlqh.dllc:\windows\bdodler2.dllc:\windows\Downloaded Program Files\IDropPTB.dllc:\windows\kb913800.exeE:\Autorun.inf..((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))..-------\Legacy_TERMSERVICES-------\Service_TermServices..((((((((((((((((((((((((( Files Created from 2011-10-17 to 2011-11-17 )))))))))))))))))))))))))))))))..2011-11-17 05:34 . 2011-11-17 05:34 37888 ----a-w- c:\windows\system32\mwusbw32.dll2011-11-17 05:34 . 2011-11-17 05:34 161792 ----a-w- c:\windows\system32\vmusbw32.dll2011-11-17 03:52 . 2011-11-17 03:52 -------- d-----w- c:\documents and settings\~Devon~\Application Data\U3...(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))..<pre>c:\program files\Adobe\Reader 9.0\Reader\Reader_sl .exec:\program files\Common Files\Adobe\ARM\1.0\AdobeARM .exec:\program files\Common Files\Java\Java Update\jusched .exec:\program files\Common Files\Microsoft Shared\DW\dwtrig20 .exec:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exec:\program files\iTunes\iTunesHelper .exec:\program files\Lexmark X1100 Series\lxbkbmgr .exec:\program files\Messenger\msmsgs .exec:\program files\QuickTime\qttask .exec:\program files\QuickTime\qttask .exe</pre>.((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))..*Note* empty entries & legit default entries are not shown REGEDIT4.[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-08-26 39432]"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [N/A]"Microsoft Works Update Detection"="c:\program files\Microsoft Works\WkDetect.exe" [N/A]"Octoshape Streaming Services"="c:\documents and settings\~Devon~\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" [N/A]"FreeRandomPasswordGenerator"="c:\program files\FreeRandomPasswordGenerator\password.exe" [N/A].[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"QuickTime Task"="c:\program files\QuickTime\qttask .exe -atboottime" [X]"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-06-21 155648]"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-06-21 126976]"Lexmark X1100 Series"="c:\program files\Lexmark X1100 Series\lxbkbmgr.exe" [2011-08-06 39428]"WorksFUD"="c:\program files\Microsoft Works\wkfud.exe" [N/A]"Microsoft Works Portfolio"="c:\program files\Microsoft Works\WksSb.exe" [N/A]"Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [N/A]"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [N/A]"ErrorTeck"="c:\program files\ErrorTeck\ErrorTeck.exe" [N/A]"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-08-06 39428]"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [N/A]"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-08-06 39428]"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-08-06 39428]"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]"nwiz"="nwiz.exe" [2008-10-07 1630208]"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016]"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [N/A].[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360].[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]"nltide3"="rundll32 advpack.dll" [N/A]"RunNarrator"="Narrator.exe" [2008-04-14 53760]"FlashPlayerUpdate"="c:\windows\system32\Macromed\Flash\FlashUtil10k_ActiveX.exe" [2010-09-24 232912].c:\documents and settings\~Devon~\Start Menu\Programs\Startup\CurseClientStartup.ccip [2010-10-9 0].c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360].[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2009-03-20 77824].[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]2010-03-25 22:32 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL.[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mwusbw32]2011-11-17 05:34 37888 ----a-w- c:\windows\system32\mwusbw32.dll.[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vmwusb]2011-11-17 05:34 37888 ----a-w- c:\windows\system32\mwusbw32.dll.[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]"%windir%\\system32\\sessmgr.exe"="c:\\Program Files\\Bonjour\\mDNSResponder.exe"="c:\\Program Files\\FrostWire\\FrostWire.exe"="c:\\Program Files\\iTunes\\iTunes.exe"="c:\\Program Files\\BitTorrent\\BitTorrent.exe"="c:\\Program Files\\directx\\DirectX\\dplaysvr.exe"="c:\\Program Files\\PlayOnline\\SquareEnix\\PlayOnlineViewer\\pol.exe"="c:\\Documents and Settings\\~Devon~\\Local Settings\\Apps\\2.0\\RMVXK979.AQB\\5MXJNACE.BY5\\curs..tion_eee711038731a406_0004.0000_efb506202a7c3b08\\CurseClient.exe"=.R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [4/13/2009 12:58 PM 114768]R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [10/10/2006 11:53 AM 12872]R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2/27/2007 10:39 AM 67656]R1 SSHDRV85;SSHDRV85;c:\windows\system32\drivers\SSHDRV85.sys [6/28/2009 9:49 PM 78848]R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [4/13/2009 12:58 PM 20560]S1 bckd;bckd;c:\windows\system32\drivers\bckd.sys --> c:\windows\system32\drivers\bckd.sys [?]S2 bckwfs;Blue Coat K9 Web Protection;c:\program files\Blue Coat K9 Web Protection\k9filter.exe --> c:\program files\Blue Coat K9 Web Protection\k9filter.exe [?]S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 1:16 PM 130384]S2 gupdate1c9d4e5577abf52;Google Update Service (gupdate1c9d4e5577abf52);c:\program files\Google\Update\GoogleUpdate.exe [5/14/2009 5:43 PM 133104]S3 ADM8511;ADMtek ADM8511/AN986 USB To Fast Ethernet Converter;c:\windows\system32\drivers\ADM8511.SYS [2/19/2008 4:16 PM 20160]S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2/16/2006 3:51 PM 12872]S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 1:16 PM 753504].--- Other Services/Drivers In Memory ---.*NewlyCreated* - VMUSB.[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]vmwareusb REG_MULTI_SZ vmusb.Contents of the 'Scheduled Tasks' folder.2011-10-09 c:\windows\Tasks\At1.job- c:\program files\HP\HP Deskjet 3050 J610 series\Bin\HPCustPartic.exe [2010-06-14 21:07].2011-10-10 c:\windows\Tasks\At2.job- c:\program files\HP\HP Deskjet 3050 J610 series\Bin\HPCustPartic.exe [2010-06-14 21:07].2011-10-09 c:\windows\Tasks\At3.job- c:\program files\HP\HP Deskjet 3050 J610 series\Bin\HPCustPartic.exe [2010-06-14 21:07].2011-10-09 c:\windows\Tasks\At4.job- c:\program files\HP\HP Deskjet 3050 J610 series\Bin\HPCustPartic.exe [2010-06-14 21:07].2011-11-17 c:\windows\Tasks\Google Software Updater.job- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-05-14 23:40].2011-11-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-14 22:42].2011-10-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-14 22:42].2011-10-09 c:\windows\Tasks\hpwebreg_CN0AM292JD05HX.job- c:\program files\HP\HP Deskjet 3050 J610 series\Bin\hpwebreg.exe [2010-06-14 21:10]..------- Supplementary Scan -------.uStart Page = hxxp://www.myspace.com/TCP: DhcpNameServer = 192.168.2.1DPF: {3DE051B7-CE1E-4149-A39E-3037F29068E1} - hxxps://secure.adrentech.com/PCConfigtool/PCConfigTool.CABFF - ProfilePath - c:\documents and settings\~Devon~\Application Data\Mozilla\Firefox\Profiles\mudqtl66.default\FF - prefs.js: browser.startup.homepage - hxxp://mp3tubetoolbar.com/?tmp=toolbar_Mp3Tube_homepage&prt=pinballtbfour04ff&clid=3cf193f1bd7542879f2dc9a9f2fb6f43&subid=FF - prefs.js: network.proxy.http - 127.0.0.1FF - prefs.js: network.proxy.http_port - 60283FF - prefs.js: network.proxy.type - 1FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtensionFF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ffFF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}FF - user.js: keyword.URL - hxxp://mp3tubetoolbar.com/?tmp=nemo_results_removelink2&q=FF - user.js: keyword.enabled - 1.- - - - ORPHANS REMOVED - - - -.URLSearchHooks-{5E72625C-99E3-4644-BFF0-315AA91294FA} - (no file)BHO-{26A7CA19-7D58-411D-B2DA-F1B0324CBFFC} - c:\program files\Gamers Unite! Snag Bar\Toolbar.dllBHO-{7b13ec3e-999a-4b70-b9cb-2617b8323822} - c:\program files\Zynga\tbZyng.dllToolbar-Locked - (no file)Toolbar-{25515A79-C1C7-4B97-97F8-31A711694487} - c:\program files\Gamers Unite! Snag Bar\Toolbar.dllToolbar-{7b13ec3e-999a-4b70-b9cb-2617b8323822} - c:\program files\Zynga\tbZyng.dllWebBrowser-{25515A79-C1C7-4B97-97F8-31A711694487} - c:\program files\Gamers Unite! Snag Bar\Toolbar.dllWebBrowser-{7B13EC3E-999A-4B70-B9CB-2617B8323822} - c:\program files\Zynga\tbZyng.dllNotify-termsvces - ter1mw32.dllAddRemove-AVS Update Manager_is1 - c:\program files\AVS4YOU\AVSUpdateManager\unins000.exeAddRemove-AVS4YOU Software Navigator_is1 - c:\program files\AVS4YOU\AVSSoftwareNavigator\unins000.exeAddRemove-AVS4YOU Video Converter 6_is1 - c:\program files\AVS4YOU\AVSVideoConverter6\unins000.exeAddRemove-Blue Coat K9 Web Protection - c:\program files\Blue Coat K9 Web Protection\uninst.exeAddRemove-Freemake Video Converter_is1 - c:\program files\Freemake\Freemake Video Converter\Uninstall\unins000.exeAddRemove-Freemake Video Downloader_is1 - c:\program files\Freemake\Freemake Video Downloader\Uninstall\unins000.exeAddRemove-Google Chrome - c:\program files\Google\Chrome\Application\7.0.517.44\Installer\setup.exeAddRemove-IspAssistant-Mp3Tube - c:\program files\Mp3Tube Toolbar\uninstall.exeAddRemove-Pro Media Director_is1 - c:\program files\Pelican Performance\Pro Media Director\unins000.exeAddRemove-SystemRequirementsLab - c:\program files\SystemRequirementsLab\Uninstall.exeAddRemove-Octoshape add-in for Adobe Flash Player - c:\documents and settings\~Devon~\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exeAddRemove-Octoshape Streaming Services - c:\documents and settings\~Devon~\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe...**************************************************************************.catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.netRootkit scan 2011-11-17 00:58Windows 5.1.2600 Service Pack 3 NTFS.scanning hidden processes ... .scanning hidden autostart entries ... .scanning hidden files ... .scan completed successfullyhidden files: 0.**************************************************************************.Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.netWindows 5.1.2600 Disk: ST380215A rev.3.AAD -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4 .device: opened successfullyuser: MBR read successfullyerror: Read A device attached to the system is not functioning.kernel: MBR read successfullydetected disk devices:detected hooks:\Driver\atapi DriverStartIo -> 0x8A47E31Buser & kernel MBR OK .**************************************************************************.--------------------- DLLs Loaded Under Running Processes ---------------------.- - - - - - - > 'winlogon.exe'(624)c:\windows\system32\WININET.dllc:\program files\SUPERAntiSpyware\SASWINLO.DLLc:\windows\system32\ter1mw32.dll.- - - - - - - > 'lsass.exe'(684)c:\windows\system32\WININET.dll.Completion time: 2011-11-17 01:07:19ComboFix-quarantined-files.txt 2011-11-17 06:07.Pre-Run: 9,744,814,080 bytes freePost-Run: 9,691,168,768 bytes free.- - End Of File - - F12ED2D38D9528D5C3F38A2F2D38056C Link to post Share on other sites More sharing options...
Maniac Posted November 18, 2011 ID:496005 Share Posted November 18, 2011 Hello Dreamx! My name is Maniac and I will be glad to help you solve your malware problem.Please note:I recommend you to keep the instructions I will be giving you so that they are available to you at any time. You can save them in a text file or print them.Make sure you read all of the instructions and fixes thoroughly before continuing with them.Follow my instructions strictly and don’t hesitate to stop and ask me if you have any questions.Post your log files, don't attach them. Every log file should be copy/paste in your next reply.Please do not use ComboFix without supervision from a trained helper. It is very powerful tool and could cause such a mess. Please read this article:http://www.bleepingcomputer.com/forums/topic273628.htmlNow, manually delete your copy of ComboFix and then follow the intructions here to download and run it:www.bleepingcomputer.com/combofix/how-to-use-combofix#useWhen you are ready please post the log file with content of Add or Remove Programs.txt which is located at C:\Qoobox directory. Link to post Share on other sites More sharing options...
LDTate Posted November 25, 2011 ID:498162 Share Posted November 25, 2011 Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread. Other members who need assistance please start your own topic in a new thread. Thanks! Link to post Share on other sites More sharing options...
Recommended Posts