Jump to content

random audio ads without an open browser


Recommended Posts

i am running windows 7 on an hp laptop, and i keep getting random audio ads, and sometimes just songs playing, without having a browser open. i tried running malwarebytes, and a couple of items needed to be quarantined, but this did not resolve the issue.

please help!

.

DDS (Ver_2011-08-26.01) - NTFSx86

Internet Explorer: 7.0.6000.16711 BrowserJavaVersion: 1.6.0_33

Run by Betti at 18:54:20 on 2012-07-09

Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.3070.1948 [GMT -7:00]

.

.

============== Running Processes ===============

.

C:\Windows\system32\wininit.exe

C:\Windows\system32\lsm.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\system32\nvvsvc.exe

C:\Windows\system32\svchost.exe -k rpcss

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\SLsvc.exe

C:\Windows\system32\svchost.exe -k LocalService

C:\Windows\system32\svchost.exe -k NetworkService

C:\Windows\system32\WUDFHost.exe

C:\Windows\System32\spoolsv.exe

C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe

C:\Windows\system32\nvvsvc.exe

C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe

C:\Windows\system32\Dwm.exe

C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork

C:\Program Files\Flip Video\FlipShare\FlipShareService.exe

C:\Program Files\Flip Video\FlipShareServer\FlipShareServer.exe

C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe

C:\Users\Betti\AppData\Local\Temp\DAT259A.tmp.exe

C:\Windows\System32\svchost.exe -k HPZ12

C:\Windows\System32\svchost.exe -k HPZ12

C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe

C:\Program Files\Common Files\Intuit\DataProtect\QBIDPService.exe

C:\Program Files\CyberLink\Shared Files\RichVideo.exe

C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe

C:\Windows\system32\svchost.exe -k imgsvc

C:\Windows\System32\svchost.exe -k WerSvcGroup

C:\Windows\system32\SearchIndexer.exe

C:\Windows\system32\taskeng.exe

C:\Windows\Explorer.EXE

C:\Program Files\Synaptics\SynTP\SynTPStart.exe

C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe

C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe

C:\Program Files\NVIDIA Corporation\Display\nvtray.exe

C:\Windows\system32\wbem\unsecapp.exe

C:\Windows\System32\ICO.EXE

C:\Windows\system32\wbem\wmiprvse.exe

C:\Windows\system32\taskeng.exe

C:\Windows\RtHDVCpl.exe

C:\Program Files\Common Files\Java\Java Update\jusched.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Windows\ehome\ehtray.exe

C:\Program Files\Windows Media Player\wmpnscfg.exe

C:\Program Files\Skype\Phone\Skype.exe

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

C:\Windows\ehome\ehmsas.exe

C:\Windows\System32\Pelmiced.exe

C:\Program Files\Common Files\AOL\1204479927\ee\aolsoftware.exe

c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe

C:\Program Files\AOL 9.0\waol.exe

C:\Program Files\AOL 9.0\shellmon.exe

C:\Program Files\Internet Explorer\iexplore.exe

.

============== Pseudo HJT Report ===============

.

mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop

mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop

uInternet Settings,ProxyOverride = *.local

BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll

BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File

BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No File

BHO: Java Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll

BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll

BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll

BHO: IeMonitorBho Class: {bf00e119-21a3-4fd1-b178-3b8537e75c92} - c:\program files\megaupload\mega manager\MegaIEMn.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll

TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File

{555d4d79-4bd2-4094-a395-cfc534424a05}

uRun: [sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun

uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe

uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe

uRun: [skype] "c:\program files\skype\phone\Skype.exe" /minimized /regrun

uRun: [AOL Fast Start] "c:\program files\aol 9.0\AOL.EXE" -b

mRun: [synTPStart] c:\program files\synaptics\syntp\SynTPStart.exe

mRun: [sMSERIAL] c:\program files\motorola\smserial\sm56hlpr.exe

mRun: [iAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe

mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe

mRun: [Mouse Suite 98 Daemon] ICO.EXE

mRun: [CanonSolutionMenu] c:\program files\canon\solutionmenu\CNSLMAIN.exe /logon

mRun: [RtHDVCpl] RtHDVCpl.exe

mRun: [sunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"

mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray

mPolicies-system: EnableLUA = 0 (0x0)

IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000

IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll

IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office11\REFIEBAR.DLL

DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/8/b/d/8bd77752-5704-4d68-a152-f7252adaa4f2/LegitCheckControl.cab

DPF: {1DB93715-3B60-43EE-93E6-279BB3E1DF76} - hxxp://64.93.28.242:1100/cab/OCXChecker_6110.cab

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab

DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab

DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab

TCP: DhcpNameServer = 209.18.47.61 209.18.47.62

TCP: Interfaces\{B7FF2B18-DBC5-42BE-8CF5-2AEB8A7CB7AD} : DhcpNameServer = 209.18.47.61 209.18.47.62

Handler: intu-help-qb4 - {ACE22922-D07C-4860-B51B-8CF472FEC2CB} - c:\program files\intuit\quickbooks 2011\HelpAsyncPluggableProtocol.dll

Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - c:\windows\system32\mscoree.dll

Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll

Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL

.

================= FIREFOX ===================

.

FF - ProfilePath - c:\users\betti\appdata\roaming\mozilla\firefox\profiles\3aqckf95.default\

FF - prefs.js: browser.search.selectedEngine - Startpage (SSL)

FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157

FF - prefs.js: network.proxy.type - 0

FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll

FF - plugin: c:\program files\java\jre6\bin\plugin2\npdeployJava1.dll

FF - plugin: c:\program files\java\jre6\bin\plugin2\npjp2.dll

FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll

FF - plugin: c:\users\betti\appdata\local\facebook\messenger\2.1.4570.0\npFbDesktopPlugin.dll

FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_3_300_262.dll

FF - plugin: c:\windows\system32\npdeployJava1.dll

FF - plugin: c:\windows\system32\npmproxy.dll

.

============= SERVICES / DRIVERS ===============

.

R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2012-4-3 63928]

R2 FlipShareServer;FlipShare Server;c:\program files\flip video\flipshareserver\FlipShareServer.exe [2011-5-6 1085440]

R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2010-9-3 654408]

R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\nvidia corporation\nvidia update core\daemonu.exe [2012-7-7 1262400]

R2 QBVSS;QBIDPService;c:\program files\common files\intuit\dataprotect\QBIDPService.exe [2010-9-17 1251840]

R2 Skype C2C Service;Skype C2C Service;c:\programdata\skype\toolbars\skype c2c service\c2c_service.exe [2012-6-19 3048136]

R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-9-3 22344]

S2 mdlewanhlma;mdlewanhlma;c:\users\betti\appdata\local\temp\DAT259A.tmp.exe [2012-7-6 44544]

S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-6-5 160944]

S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2012-4-25 113120]

.

=============== Created Last 30 ================

.

2012-07-09 22:59:36 140832 ----a-w- c:\windows\system32\drivers\str.sys

2012-07-07 14:46:10 62272 ----a-w- c:\windows\system32\nvshext.dll

2012-07-07 14:46:09 2561344 ----a-w- c:\windows\system32\nvsvcr.dll

2012-07-07 14:44:22 61248 ----a-w- c:\windows\system32\OpenCL.dll

2012-07-07 14:44:13 -------- d-----w- c:\programdata\NVIDIA Corporation

2012-07-07 14:38:20 8105280 ----a-w- c:\windows\system32\nvwgf2um.dll

2012-07-07 14:38:19 19607872 ----a-w- c:\windows\system32\nvoglv32.dll

2012-07-07 14:38:18 883008 ----a-w- c:\windows\system32\nvgenco32.dll

2012-07-07 14:38:18 11354944 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys

2012-07-07 14:38:17 1000768 ----a-w- c:\windows\system32\nvdispco32.dll

2012-07-07 14:38:16 5982528 ----a-w- c:\windows\system32\nvcuda.dll

2012-07-07 14:38:16 2524992 ----a-w- c:\windows\system32\nvcuvid.dll

2012-07-07 14:38:16 2445120 ----a-w- c:\windows\system32\nvcuvenc.dll

2012-07-07 14:38:10 17551680 ----a-w- c:\windows\system32\nvcompiler.dll

2012-07-07 14:37:25 -------- d-----w- c:\program files\NVIDIA Corporation

2012-07-07 14:36:45 -------- d-----w- C:\NVIDIA

2012-07-06 09:00:19 6762896 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{1173d4f0-9bfa-46dc-bee8-1d4c43f70784}\mpengine.dll

2012-06-20 00:35:14 4967624 ----a-w- c:\program files\mozilla firefox\extensions\{82af8dca-6de9-405d-bd5e-43525bdad38a}\components\SkypeFfComponent.dll

2012-06-16 07:44:25 476936 ----a-w- c:\windows\system32\npdeployJava1.dll

2012-06-11 04:29:28 -------- d-----w- c:\users\betti\appdata\local\Macromedia

.

==================== Find3M ====================

.

2012-07-03 23:28:45 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2012-07-03 23:28:45 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe

2012-06-16 07:43:24 472840 ----a-w- c:\windows\system32\deployJava1.dll

2012-05-21 03:55:47 319456 ----a-w- c:\windows\DIFxAPI.dll

2012-05-15 10:26:00 2368832 ----a-w- c:\windows\system32\nvapi.dll

2012-05-15 10:26:00 15322432 ----a-w- c:\windows\system32\nvd3dum.dll

2012-05-15 09:28:49 645440 ----a-w- c:\windows\system32\nvvsvc.exe

2012-05-15 09:28:49 108352 ----a-w- c:\windows\system32\nvmctray.dll

2012-05-15 09:28:48 3931456 ----a-w- c:\windows\system32\nvcpl.dll

2012-05-15 09:27:28 2759488 ----a-w- c:\windows\system32\nvsvc.dll

2012-05-02 06:55:08 360448 ----a-w- c:\windows\system32\awrdscdc.ax

.

============= FINISH: 18:55:12.59 ===============

.

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.

IF REQUESTED, ZIP IT UP & ATTACH IT

.

DDS (Ver_2011-08-26.01)

.

Microsoft® Windows Vista™ Home Premium

Boot Device: \Device\HarddiskVolume1

Install Date: 2/24/2008 6:05:28 AM

System Uptime: 7/9/2012 6:28:34 PM (0 hours ago)

.

Motherboard: Quanta | | 30D2

Processor: Intel® Core2 Duo CPU T5450 @ 1.66GHz | U2E1 | 1667/667mhz

.

==== Disk Partitions =========================

.

C: is FIXED (NTFS) - 221 GiB total, 80.159 GiB free.

D: is FIXED (NTFS) - 12 GiB total, 1.869 GiB free.

E: is CDROM ()

.

==== Disabled Device Manager Items =============

.

Class GUID: {6bdd1fc6-810f-11d0-bec7-08002be2092f}

Description: Canon MX860 ser Network

Device ID: ROOT\CANON_IJ_NETWORK\0000

Manufacturer: Canon

Name: Canon MX860 ser Network

PNP Device ID: ROOT\CANON_IJ_NETWORK\0000

Service: StillCam

.

==== System Restore Points ===================

.

.

==== Installed Programs ======================

.

32 Bit HP CIO Components Installer

Activation Assistant for the 2007 Microsoft Office suites

ActiveCheck component for HP Active Support Library

Adobe AIR

Adobe Anchor Service CS4

Adobe Bridge CS4

Adobe CMaps CS4

Adobe Color - Photoshop Specific CS4

Adobe Color EU Extra Settings CS4

Adobe Color JA Extra Settings CS4

Adobe Color NA Recommended Settings CS4

Adobe Color Video Profiles CS CS4

Adobe CSI CS4

Adobe Default Language CS4

Adobe Device Central CS4

Adobe Drive CS4

Adobe ExtendScript Toolkit CS4

Adobe Extension Manager CS4

Adobe Flash Player 11 ActiveX

Adobe Flash Player 11 Plugin

Adobe Fonts All

Adobe Linguistics CS4

Adobe Media Player

Adobe Output Module

Adobe PDF Library Files CS4

Adobe Photoshop CS4

Adobe Photoshop CS4 Support

Adobe Reader X (10.1.3)

Adobe Search for Help

Adobe Service Manager Extension

Adobe Setup

Adobe Shockwave Player

Adobe Shockwave Player 11.5

Adobe Type Support CS4

Adobe Update Manager CS4

Adobe WinSoft Linguistics Plugin

Adobe XMP Panels CS4

AdobeColorCommonSetCMYK

AdobeColorCommonSetRGB

Age of Empires III

Age of Empires III - The WarChiefs

AIM 6

AOL Uninstaller (Choose which Products to Remove)

Apple Application Support

Apple Mobile Device Support

Apple Software Update

Ashampoo Burning Studio 6 FREE v.6.80

Audible Download Manager

BestPractice (remove only)

Bonjour

BufferChm

Canon MP Navigator EX 2.1

Canon MX860 series MP Drivers

Canon My Printer

Canon Utilities Solution Menu

CCleaner

Compatibility Pack for the 2007 Office system

Connect

DesignPro 5

Deus Ex

DJ ToneXpress v4.7.5

Driver Detective

Drivers Install For Linksys Easylink Advisor

DVD Suite

EA Link

ESU for Microsoft Vista

Facebook Messenger 2.1.4570.0

Facebook Video Calling 1.2.0.159

Fax

FlipShare

FormatFactory 2.95

Guitar Pro 5.2

HandBrake 0.9.6

Hauppauge MCE XP/Vista Software Encoder (2.0.25149)

Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)

HP Active Support Library

HP Doc Viewer

HP User Guides 0087

HPAsset component for HP Active Support Library

HPNetworkAssistant

Intel® Matrix Storage Manager

iTunes

Java Auto Updater

Java 6 Update 33

Java 6 Update 4

Java 6 Update 7

kuler

LabelPrint

Linksys EasyLink Advisor 1.6 (0032)

Malwarebytes Anti-Malware version 1.61.0.1400

Mega Manager

Microsoft .NET Framework 3.5 SP1

Microsoft Age of Empires II

Microsoft Application Error Reporting

Microsoft Choice Guard

Microsoft Office 2003 Primary Interop Assemblies

Microsoft Office 2007 Primary Interop Assemblies

Microsoft Office Excel MUI (English) 2007

Microsoft Office Home and Student 2007

Microsoft Office OneNote MUI (English) 2007

Microsoft Office PowerPoint MUI (English) 2007

Microsoft Office PowerPoint Viewer 2007 (English)

Microsoft Office Professional Edition 2003

Microsoft Office Proof (English) 2007

Microsoft Office Proof (French) 2007

Microsoft Office Proof (Spanish) 2007

Microsoft Office Proofing (English) 2007

Microsoft Office Shared MUI (English) 2007

Microsoft Office Shared Setup Metadata MUI (English) 2007

Microsoft Office Word MUI (English) 2007

Microsoft Visual C++ 2005 Redistributable

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

Microsoft Visual Studio 2005 Tools for Office Runtime

Microsoft Works

Motorola SM56 Data Fax Modem

Mouse Suite

Mozilla Firefox 13.0.1 (x86 en-US)

Mozilla Maintenance Service

MSCU for Microsoft Vista

MSVCRT

MSXML 4.0 SP2 (KB936181)

MSXML 4.0 SP2 (KB941833)

MSXML 4.0 SP2 Parser and SDK

muvee autoProducer 6.1

NVIDIA Control Panel 301.42

NVIDIA Graphics Driver 301.42

NVIDIA Install Application

NVIDIA PhysX

NVIDIA PhysX System Software 9.12.0213

NVIDIA Update 1.8.15

NVIDIA Update Components

OpenOffice.org 2.4

PDF Settings CS4

PhotoNow!

Photoshop Camera Raw

Power Tab Editor 1.7

Power2Go

PowerDirector

Project64 1.6

QuickBooks

QuickBooks Pro 2011

QuickTime

Realtek 8169, 8168, 8101E and 8102E Ethernet Network Card Driver for Windows Vista

Realtek High Definition Audio Driver

Ricochet Lost Worlds

RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01

RTC Client API v1.2

Skype Click to Call

Skype™ 5.9

SoulSeek 157 NS 13e

Starcraft

Suite Shared Configuration CS4

Synaptics Pointing Device Driver

TELL ME MORE

The Sims™ Life Stories

Transcribe! 7.50

UnloadSupport

Update for Office 2007 (KB934528)

Viewpoint Media Player

VLC media player 1.0.5

WeatherBug Gadget

Winamp

Windows Live Call

Windows Live Communications Platform

Windows Live Essentials

Windows Live Messenger

Windows Live Sign-in Assistant

Windows Live Upload Tool

Windows Media Player Firefox Plugin

WinRAR archiver

YouTube Free Downloader

.

==== Event Viewer Messages From Past Week ========

.

7/9/2012 12:40:18 PM, Error: Service Control Manager [7034] - The Skype C2C Service service terminated unexpectedly. It has done this 1 time(s).

7/6/2012 4:26:40 PM, Error: Microsoft-Windows-WMPNSS-Service [14325] - Service 'WMPNetworkSvc' did not start correctly because QueryService encountered error '0x80070424'. In Windows Media Player, turn off media sharing, and then turn it back on.

7/6/2012 4:24:41 PM, Error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: The specified service does not exist as an installed service.

7/6/2012 4:24:41 PM, Error: Service Control Manager [7003] - The IPsec Policy Agent service depends the following service: BFE. This service might not be installed.

7/6/2012 4:24:41 PM, Error: Service Control Manager [7003] - The IKE and AuthIP IPsec Keying Modules service depends the following service: BFE. This service might not be installed.

7/6/2012 4:24:30 PM, Error: Print [19] - The print spooler failed to share printer Send To OneNote 2007 with shared resource name Send To OneNote 2007. Error 1753. The printer cannot be used by others on the network.

7/6/2012 10:35:28 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the mdlewanhlma service to connect.

7/5/2012 7:29:37 PM, Error: Service Control Manager [7000] - The Parallel port driver service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

.

==== End Of File ===========================

Link to post
Share on other sites

  • Staff

Hi and welcome to Malwarebytes.

Please update MBAM, run a Quick Scan, and post its log.

Next, please visit this webpage for instructions for running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

  • When the tool is finished, it will produce a report for you.
  • Please post the contents of C:\ComboFix.txt along with a new DDS log so we may continue cleaning the system.

Link to post
Share on other sites

for some reason i am unable to get combofix to work properly, after multiple attempts. after i click run and accept, it briefly runs the program and then disappears, and nothing further happens. the auto scan never actually gets going. i am not sure what i am doing wrong or what to do to fix this.

this is the mwbam log:

Malwarebytes Anti-Malware (Trial) 1.61.0.1400

www.malwarebytes.org

Database version: v2012.07.10.02

Windows Vista x86 NTFS

Internet Explorer 7.0.6000.16711

Betti :: HOPI [administrator]

Protection: Enabled

7/9/2012 8:16:40 PM

mbam-log-2012-07-09 (20-36-46).txt

Scan type: Quick scan

Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM

Scan options disabled: P2P

Objects scanned: 255468

Time elapsed: 7 minute(s), 23 second(s)

Memory Processes Detected: 1

C:\Users\Betti\AppData\Local\Temp\DAT259A.tmp.exe (Trojan.Phex.THAGen1) -> 2068 -> No action taken.

Memory Modules Detected: 0

(No malicious items detected)

Registry Keys Detected: 3

HKLM\SYSTEM\CurrentControlSet\Services\mdlewanhlma (Trojan.Phex.THAGen1) -> No action taken.

HKCR\Interface\{66666666-6666-6666-6666-660066226658} (Adware.GamePlayLab) -> No action taken.

HKCR\TypeLib\{44444444-4444-4444-4444-440044224458} (Adware.GamePlayLab) -> No action taken.

Registry Values Detected: 0

(No malicious items detected)

Registry Data Items Detected: 0

(No malicious items detected)

Folders Detected: 0

(No malicious items detected)

Files Detected: 3

C:\Users\Betti\AppData\Local\Temp\DAT259A.tmp.exe (Trojan.Phex.THAGen1) -> No action taken.

C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U\800000cb.@ (Rootkit.0Access) -> No action taken.

C:\Windows\System32\drivers\str.sys (Rootkit.Agent) -> No action taken.

(end)

Link to post
Share on other sites

  • Staff

Run another Quick Scan and remove everything found.

Delete your copy of ComboFix. Grab a fresh copy and save it to your Desktop, but do not run it yet. Before you download it, rename it to sega.com

Please reboot to Safe Mode (tap the F8 key just before Windows starts to load and select the Safe Mode option from the menu).

Click Start --> Run, and enter this command exactly as shown:

"%userprofile%\desktop\sega.com" /killall

See if it will run successfully now. Stop it after half an hour of no activity.

Link to post
Share on other sites

wow, i just tried to do another quick scan, and when i click on the mbam icon on my desktop, it says 'Run time error 5: invalid procedure call or argument". also, i was unable to start my computer before and needed to do a start system restore.

i'm assuming i should uninstall mbam and reinstall and do the quick scan? i will give that a try and then do all the other things you suggested.

Link to post
Share on other sites

finally!!! i had to try to use combofix 4 times in safe mode before something would happen:

ComboFix 12-07-10.01 - Betti 07/10/2012 12:26:15.1.2 - x86 MINIMAL

Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.3070.2509 [GMT -7:00]

Running from: c:\users\Betti\Desktop\sega.com

Command switches used :: /killall

* Created a new restore point

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\users\Betti\AppData\Roaming\Mozilla\Firefox\Profiles\3aqckf95.default\extensions\crossriderapp2258@crossrider.com

c:\users\Betti\AppData\Roaming\Mozilla\Firefox\Profiles\3aqckf95.default\extensions\crossriderapp2258@crossrider.com\chrome.manifest

c:\users\Betti\AppData\Roaming\Mozilla\Firefox\Profiles\3aqckf95.default\extensions\crossriderapp2258@crossrider.com\chrome\content\background.html

c:\users\Betti\AppData\Roaming\Mozilla\Firefox\Profiles\3aqckf95.default\extensions\crossriderapp2258@crossrider.com\chrome\content\browser.xul

c:\users\Betti\AppData\Roaming\Mozilla\Firefox\Profiles\3aqckf95.default\extensions\crossriderapp2258@crossrider.com\chrome\content\crossrider.js

c:\users\Betti\AppData\Roaming\Mozilla\Firefox\Profiles\3aqckf95.default\extensions\crossriderapp2258@crossrider.com\chrome\content\crossriderapi.js

c:\users\Betti\AppData\Roaming\Mozilla\Firefox\Profiles\3aqckf95.default\extensions\crossriderapp2258@crossrider.com\chrome\content\dialog.js

c:\users\Betti\AppData\Roaming\Mozilla\Firefox\Profiles\3aqckf95.default\extensions\crossriderapp2258@crossrider.com\chrome\content\options.js

c:\users\Betti\AppData\Roaming\Mozilla\Firefox\Profiles\3aqckf95.default\extensions\crossriderapp2258@crossrider.com\chrome\content\options.xul

c:\users\Betti\AppData\Roaming\Mozilla\Firefox\Profiles\3aqckf95.default\extensions\crossriderapp2258@crossrider.com\chrome\content\search_dialog.xul

c:\users\Betti\AppData\Roaming\Mozilla\Firefox\Profiles\3aqckf95.default\extensions\crossriderapp2258@crossrider.com\chrome\content\update.html

c:\users\Betti\AppData\Roaming\Mozilla\Firefox\Profiles\3aqckf95.default\extensions\crossriderapp2258@crossrider.com\defaults\preferences\prefs.js

c:\users\Betti\AppData\Roaming\Mozilla\Firefox\Profiles\3aqckf95.default\extensions\crossriderapp2258@crossrider.com\install.rdf

c:\users\Betti\AppData\Roaming\Mozilla\Firefox\Profiles\3aqckf95.default\extensions\crossriderapp2258@crossrider.com\locale\en-US\translations.dtd

c:\users\Betti\AppData\Roaming\Mozilla\Firefox\Profiles\3aqckf95.default\extensions\crossriderapp2258@crossrider.com\skin\button1.png

c:\users\Betti\AppData\Roaming\Mozilla\Firefox\Profiles\3aqckf95.default\extensions\crossriderapp2258@crossrider.com\skin\button2.png

c:\users\Betti\AppData\Roaming\Mozilla\Firefox\Profiles\3aqckf95.default\extensions\crossriderapp2258@crossrider.com\skin\button3.png

c:\users\Betti\AppData\Roaming\Mozilla\Firefox\Profiles\3aqckf95.default\extensions\crossriderapp2258@crossrider.com\skin\button4.png

c:\users\Betti\AppData\Roaming\Mozilla\Firefox\Profiles\3aqckf95.default\extensions\crossriderapp2258@crossrider.com\skin\button5.png

c:\users\Betti\AppData\Roaming\Mozilla\Firefox\Profiles\3aqckf95.default\extensions\crossriderapp2258@crossrider.com\skin\crossrider_statusbar.png

c:\users\Betti\AppData\Roaming\Mozilla\Firefox\Profiles\3aqckf95.default\extensions\crossriderapp2258@crossrider.com\skin\icon128.png

c:\users\Betti\AppData\Roaming\Mozilla\Firefox\Profiles\3aqckf95.default\extensions\crossriderapp2258@crossrider.com\skin\icon16.png

c:\users\Betti\AppData\Roaming\Mozilla\Firefox\Profiles\3aqckf95.default\extensions\crossriderapp2258@crossrider.com\skin\icon24.png

c:\users\Betti\AppData\Roaming\Mozilla\Firefox\Profiles\3aqckf95.default\extensions\crossriderapp2258@crossrider.com\skin\icon48.png

c:\users\Betti\AppData\Roaming\Mozilla\Firefox\Profiles\3aqckf95.default\extensions\crossriderapp2258@crossrider.com\skin\panelarrow-up.png

c:\users\Betti\AppData\Roaming\Mozilla\Firefox\Profiles\3aqckf95.default\extensions\crossriderapp2258@crossrider.com\skin\popup.css

c:\users\Betti\AppData\Roaming\Mozilla\Firefox\Profiles\3aqckf95.default\extensions\crossriderapp2258@crossrider.com\skin\popup.html

c:\users\Betti\AppData\Roaming\Mozilla\Firefox\Profiles\3aqckf95.default\extensions\crossriderapp2258@crossrider.com\skin\popup_binding.xml

c:\users\Betti\AppData\Roaming\Mozilla\Firefox\Profiles\3aqckf95.default\extensions\crossriderapp2258@crossrider.com\skin\skin.css

c:\users\Betti\AppData\Roaming\Mozilla\Firefox\Profiles\3aqckf95.default\extensions\crossriderapp2258@crossrider.com\skin\update.css

c:\windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\@

c:\windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\n

c:\windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U\00000001.@

c:\windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U\80000000.@

c:\windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U\800000cb.@

c:\windows\system32\AutoRun.inf

c:\windows\system32\DEBUG.log

c:\windows\system32\HPBDO.0

c:\windows\system32\HPPPM.0

c:\windows\system32\HPWHEEL.0

c:\windows\system32\ICO.0

c:\windows\system32\ICONSPY.0

c:\windows\system32\KBL.LOG

c:\windows\system32\MFC71.0

c:\windows\system32\MSVCR71.0

c:\windows\system32\NOTIFIER.0

c:\windows\system32\PELCOMM.0

c:\windows\system32\PELHOOKS.0

c:\windows\system32\PELMICED.0

c:\windows\system32\PELRESS.0

c:\windows\system32\PELSCRLL.0

c:\windows\system32\PELSETUP.0

c:\windows\system32\PELUTIL.0

c:\windows\system32\PELZOOM.0

c:\windows\system32\PMARIA.0

c:\windows\system32\PMIBM.0

c:\windows\system32\PMPoPo.0

c:\windows\system32\PMPOPO2.0

c:\windows\system32\PMTilt3.0

c:\windows\system32\PMUNINNT.0

c:\windows\system32\PMUNINST.0

c:\windows\system32\XMOUSE.0

.

Infected copy of c:\windows\system32\services.exe was found and disinfected

Restored copy from - c:\32788r22fwjfw\HarddiskVolumeShadowCopy8_!Windows!System32!services.exe

.

.

((((((((((((((((((((((((( Files Created from 2012-06-10 to 2012-07-10 )))))))))))))))))))))))))))))))

.

.

2012-07-10 19:42 . 2012-07-10 19:44 -------- d-----w- c:\users\Betti\AppData\Local\temp

2012-07-10 19:42 . 2012-07-10 19:42 -------- d-----w- c:\users\Guest\AppData\Local\temp

2012-07-10 19:42 . 2012-07-10 19:42 -------- d-----w- c:\users\Default\AppData\Local\temp

2012-07-10 19:11 . 2012-07-10 19:11 -------- d-----w- C:\sega

2012-07-10 18:28 . 2012-07-10 18:28 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2012-07-10 18:28 . 2012-04-04 22:56 22344 ----a-w- c:\windows\system32\drivers\mbam.sys

2012-07-10 08:13 . 2012-07-10 19:11 -------- d-----w- C:\ComboFix

2012-07-07 14:46 . 2012-07-10 09:22 -------- d-----w- c:\users\UpdatusUser

2012-07-07 14:46 . 2012-05-15 09:28 62272 ----a-w- c:\windows\system32\nvshext.dll

2012-07-07 14:36 . 2012-07-07 14:36 -------- d-----w- C:\NVIDIA

2012-07-06 09:00 . 2012-05-31 03:41 6762896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1173D4F0-9BFA-46DC-BEE8-1D4C43F70784}\mpengine.dll

2012-06-20 00:35 . 2012-06-20 00:35 4967624 ----a-w- c:\program files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll

2012-06-16 07:44 . 2012-06-16 07:43 476936 ----a-w- c:\windows\system32\npdeployJava1.dll

2012-06-11 04:29 . 2012-06-11 04:29 -------- d-----w- c:\users\Betti\AppData\Local\Macromedia

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2012-07-03 23:28 . 2012-03-31 07:30 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe

2012-07-03 23:28 . 2011-10-12 07:11 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2012-06-16 07:43 . 2010-07-17 04:58 472840 ----a-w- c:\windows\system32\deployJava1.dll

2012-05-21 03:55 . 2008-02-24 14:14 319456 ----a-w- c:\windows\DIFxAPI.dll

2012-05-15 10:26 . 2007-09-19 20:05 2368832 ----a-w- c:\windows\system32\nvapi.dll

2012-05-15 10:26 . 2007-09-19 20:05 15322432 ----a-w- c:\windows\system32\nvd3dum.dll

2012-05-15 09:28 . 2008-02-27 11:48 645440 ----a-w- c:\windows\system32\nvvsvc.exe

2012-05-15 09:28 . 2007-09-19 20:05 108352 ----a-w- c:\windows\system32\nvmctray.dll

2012-05-15 09:28 . 2007-09-19 20:05 3931456 ----a-w- c:\windows\system32\nvcpl.dll

2012-05-15 09:27 . 2007-09-19 20:05 2759488 ----a-w- c:\windows\system32\nvsvc.dll

2012-05-02 06:55 . 2009-10-03 01:46 360448 ----a-w- c:\windows\system32\awrdscdc.ax

2012-06-17 07:40 . 2012-03-18 07:19 85472 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-03-03 1232896]

"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]

"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]

"Skype"="c:\program files\Skype\Phone\Skype.exe" [2012-06-05 17344176]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 102400]

"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2007-01-17 634880]

"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-04-16 178712]

"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-06-16 75008]

"Mouse Suite 98 Daemon"="ICO.EXE" [2006-11-03 49152]

"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2009-09-04 767312]

"RtHDVCpl"="RtHDVCpl.exe" [2008-01-15 4874240]

"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]

"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"EnableLUA"= 0 (0x0)

.

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Audible Download Manager.lnk]

path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Audible Download Manager.lnk

backup=c:\windows\pss\Audible Download Manager.lnk.CommonStartup

backupExtension=.CommonStartup

.

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Intuit Data Protect.lnk]

path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Intuit Data Protect.lnk

backup=c:\windows\pss\Intuit Data Protect.lnk.CommonStartup

backupExtension=.CommonStartup

.

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]

path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk

backup=c:\windows\pss\QuickBooks Update Agent.lnk.CommonStartup

backupExtension=.CommonStartup

.

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^QuickBooks_Standard_21.lnk]

path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\QuickBooks_Standard_21.lnk

backup=c:\windows\pss\QuickBooks_Standard_21.lnk.CommonStartup

backupExtension=.CommonStartup

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]

2012-04-04 05:53 843712 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS4ServiceManager]

2008-08-14 14:58 611712 ----a-w- c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Fast Start]

2006-11-10 12:12 50736 ----a-w- c:\program files\AOL 9.0\aol.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]

2012-02-21 04:28 59240 ----a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]

2011-07-19 19:53 2567272 ----a-w- c:\program files\Canon\MyPrinter\BJMYPRT.EXE

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EasyLinkAdvisor]

2007-03-15 23:16 454784 ----a-w- c:\program files\Linksys EasyLink Advisor\LinksysAgent.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update]

2012-06-30 16:04 137536 ----atw- c:\users\Betti\AppData\Local\Facebook\Update\FacebookUpdate.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]

2006-09-26 00:52 50736 ----a-w- c:\program files\Common Files\AOL\1204479927\ee\aolsoftware.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Intuit SyncManager]

2010-09-27 19:26 1443080 ----a-w- c:\program files\Common Files\Intuit\Sync\IntuitSyncManager.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]

2012-03-27 12:09 421736 ----a-w- c:\program files\iTunes\iTunesHelper.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]

2011-10-24 21:28 421888 ----a-w- c:\program files\QuickTime\QTTask.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]

2008-08-03 23:02 36352 ----a-w- c:\program files\Winamp\winampa.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]

"DisableMonitoring"=dword:00000001

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

"DisableMonitoring"=dword:00000001

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]

"DisableMonitoring"=dword:00000001

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2984360966-779318858-4001959606-1000]

"EnableNotificationsRef"=dword:00000001

.

S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x]

.

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

hpdevmgmt REG_MULTI_SZ hpqcxs08

.

Contents of the 'Scheduled Tasks' folder

.

2012-07-10 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2984360966-779318858-4001959606-1000Core.job

- c:\users\Betti\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-03-27 16:04]

.

2012-07-10 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2984360966-779318858-4001959606-1000UA.job

- c:\users\Betti\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-03-27 16:04]

.

2012-07-10 c:\windows\Tasks\User_Feed_Synchronization-{90087F7C-9422-4068-8A5B-8344BF7C1E36}.job

- c:\windows\system32\msfeedssync.exe [2006-11-02 09:45]

.

.

------- Supplementary Scan -------

.

mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop

uInternet Settings,ProxyOverride = *.local

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000

TCP: DhcpNameServer = 209.18.47.61 209.18.47.62

DPF: {1DB93715-3B60-43EE-93E6-279BB3E1DF76} - hxxp://64.93.28.242:1100/cab/OCXChecker_6110.cab

FF - ProfilePath - c:\users\Betti\AppData\Roaming\Mozilla\Firefox\Profiles\3aqckf95.default\

FF - prefs.js: browser.search.selectedEngine - Startpage (SSL)

FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157

FF - prefs.js: network.proxy.type - 0

.

- - - - ORPHANS REMOVED - - - -

.

MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe

.

.

.

**************************************************************************

scanning hidden processes ...

.

scanning hidden autostart entries ...

.

scanning hidden files ...

.

scan completed successfully

hidden files:

.

**************************************************************************

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

"MSCurrentCountry"=dword:000000b5

.

--------------------- DLLs Loaded Under Running Processes ---------------------

.

- - - - - - - > 'lsass.exe'(696)

c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll

.

------------------------ Other Running Processes ------------------------

.

c:\windows\system32\nvvsvc.exe

c:\program files\NVIDIA Corporation\Display\nvxdsync.exe

c:\windows\system32\nvvsvc.exe

c:\program files\Common Files\AOL\ACS\AOLAcsd.exe

c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

c:\program files\Bonjour\mDNSResponder.exe

c:\program files\Flip Video\FlipShare\FlipShareService.exe

c:\program files\Flip Video\FlipShareServer\FlipShareServer.exe

c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe

c:\program files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe

c:\program files\Common Files\Intuit\DataProtect\QBIDPService.exe

c:\program files\CyberLink\Shared Files\RichVideo.exe

c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe

c:\windows\System32\ICO.EXE

c:\program files\Synaptics\SynTP\SynTPEnh.exe

c:\windows\RtHDVCpl.exe

c:\program files\NVIDIA Corporation\Display\nvtray.exe

c:\windows\ehome\ehmsas.exe

c:\windows\system32\wbem\unsecapp.exe

c:\program files\Hewlett-Packard\HP Health Check\hphc_service.exe

c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe

c:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe

.

**************************************************************************

.

Completion time: 2012-07-10 12:54:41 - machine was rebooted

ComboFix-quarantined-files.txt 2012-07-10 19:54

.

Pre-Run: 89,395,703,808 bytes free

Post-Run: 88,056,672,256 bytes free

.

- - End Of File - - 3384CFFF3CAC2D0A615AA94D76EE6251

.

DDS (Ver_2011-08-26.01) - NTFSx86

Internet Explorer: 7.0.6000.16711 BrowserJavaVersion: 1.6.0_33

Run by Betti at 12:58:43 on 2012-07-10

Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.3070.1725 [GMT -7:00]

.

.

============== Running Processes ===============

.

C:\Windows\system32\wininit.exe

C:\Windows\system32\lsm.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\system32\nvvsvc.exe

C:\Windows\system32\svchost.exe -k rpcss

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\SLsvc.exe

C:\Windows\system32\svchost.exe -k LocalService

C:\Windows\system32\svchost.exe -k NetworkService

C:\Windows\System32\spoolsv.exe

C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe

C:\Windows\system32\nvvsvc.exe

C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe

C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\Program Files\Flip Video\FlipShare\FlipShareService.exe

C:\Program Files\Flip Video\FlipShareServer\FlipShareServer.exe

C:\Windows\system32\Dwm.exe

C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe

C:\Windows\System32\svchost.exe -k HPZ12

C:\Windows\System32\svchost.exe -k HPZ12

C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe

C:\Program Files\Common Files\Intuit\DataProtect\QBIDPService.exe

C:\Program Files\CyberLink\Shared Files\RichVideo.exe

C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe

C:\Windows\system32\svchost.exe -k imgsvc

C:\Windows\System32\svchost.exe -k WerSvcGroup

C:\Windows\system32\SearchIndexer.exe

C:\Program Files\Synaptics\SynTP\SynTPStart.exe

C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe

C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe

C:\Windows\System32\ICO.EXE

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

C:\Windows\RtHDVCpl.exe

C:\Program Files\Common Files\Java\Java Update\jusched.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe

C:\Program Files\NVIDIA Corporation\Display\nvtray.exe

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Windows\ehome\ehtray.exe

C:\Program Files\Windows Media Player\wmpnscfg.exe

C:\Windows\ehome\ehmsas.exe

C:\Program Files\Skype\Phone\Skype.exe

C:\Windows\system32\wbem\unsecapp.exe

C:\Windows\system32\taskeng.exe

C:\Windows\system32\taskeng.exe

C:\Windows\system32\wbem\wmiprvse.exe

c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe

C:\Windows\Explorer.exe

C:\Windows\system32\notepad.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Windows\system32\SearchProtocolHost.exe

C:\Windows\system32\SearchFilterHost.exe

.

============== Pseudo HJT Report ===============

.

mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop

uInternet Settings,ProxyOverride = *.local

BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll

BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File

BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No File

BHO: Java Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll

BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll

BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll

BHO: IeMonitorBho Class: {bf00e119-21a3-4fd1-b178-3b8537e75c92} - c:\program files\megaupload\mega manager\MegaIEMn.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll

TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File

{555d4d79-4bd2-4094-a395-cfc534424a05}

uRun: [sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun

uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe

uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe

uRun: [skype] "c:\program files\skype\phone\Skype.exe" /minimized /regrun

mRun: [synTPStart] c:\program files\synaptics\syntp\SynTPStart.exe

mRun: [sMSERIAL] c:\program files\motorola\smserial\sm56hlpr.exe

mRun: [iAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe

mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe

mRun: [Mouse Suite 98 Daemon] ICO.EXE

mRun: [CanonSolutionMenu] c:\program files\canon\solutionmenu\CNSLMAIN.exe /logon

mRun: [RtHDVCpl] RtHDVCpl.exe

mRun: [sunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"

mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray

mPolicies-system: EnableLUA = 0 (0x0)

IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000

IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll

IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office11\REFIEBAR.DLL

DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/8/b/d/8bd77752-5704-4d68-a152-f7252adaa4f2/LegitCheckControl.cab

DPF: {1DB93715-3B60-43EE-93E6-279BB3E1DF76} - hxxp://64.93.28.242:1100/cab/OCXChecker_6110.cab

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab

DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab

DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab

TCP: DhcpNameServer = 209.18.47.61 209.18.47.62

TCP: Interfaces\{B7FF2B18-DBC5-42BE-8CF5-2AEB8A7CB7AD} : DhcpNameServer = 209.18.47.61 209.18.47.62

Handler: intu-help-qb4 - {ACE22922-D07C-4860-B51B-8CF472FEC2CB} - c:\program files\intuit\quickbooks 2011\HelpAsyncPluggableProtocol.dll

Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - c:\windows\system32\mscoree.dll

Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll

Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL

.

================= FIREFOX ===================

.

FF - ProfilePath - c:\users\betti\appdata\roaming\mozilla\firefox\profiles\3aqckf95.default\

FF - prefs.js: browser.search.selectedEngine - Startpage (SSL)

FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157

FF - prefs.js: network.proxy.type - 0

.

============= SERVICES / DRIVERS ===============

.

R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2012-4-3 63928]

R2 FlipShareServer;FlipShare Server;c:\program files\flip video\flipshareserver\FlipShareServer.exe [2011-5-6 1085440]

R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2012-7-10 654408]

R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\nvidia corporation\nvidia update core\daemonu.exe [2012-7-7 1262400]

R2 QBVSS;QBIDPService;c:\program files\common files\intuit\dataprotect\QBIDPService.exe [2010-9-17 1251840]

R2 Skype C2C Service;Skype C2C Service;c:\programdata\skype\toolbars\skype c2c service\c2c_service.exe [2012-6-19 3048136]

R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-7-10 22344]

S2 mdlewanhlma;mdlewanhlma;"c:\users\betti\appdata\local\temp\dat259a.tmp.exe" --service --> c:\users\betti\appdata\local\temp\DAT259A.tmp.exe [?]

S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-6-5 160944]

S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2012-4-25 113120]

.

=============== Created Last 30 ================

.

2012-07-10 19:54:43 -------- d-----w- c:\users\betti\appdata\local\temp

2012-07-10 19:53:56 -------- d-sh--w- C:\$RECYCLE.BIN

2012-07-10 19:23:27 98816 ----a-w- c:\windows\sed.exe

2012-07-10 19:23:27 518144 ----a-w- c:\windows\SWREG.exe

2012-07-10 19:23:27 256000 ----a-w- c:\windows\PEV.exe

2012-07-10 19:23:27 208896 ----a-w- c:\windows\MBR.exe

2012-07-10 19:11:56 -------- d-----w- C:\sega

2012-07-10 18:28:38 22344 ----a-w- c:\windows\system32\drivers\mbam.sys

2012-07-10 18:28:38 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2012-07-10 08:13:58 -------- d-----w- C:\ComboFix

2012-07-07 14:46:10 62272 ----a-w- c:\windows\system32\nvshext.dll

2012-07-07 14:46:09 2561344 ----a-w- c:\windows\system32\nvsvcr.dll

2012-07-07 14:44:22 61248 ----a-w- c:\windows\system32\OpenCL.dll

2012-07-07 14:44:13 -------- d-----w- c:\programdata\NVIDIA Corporation

2012-07-07 14:38:20 8105280 ----a-w- c:\windows\system32\nvwgf2um.dll

2012-07-07 14:38:19 19607872 ----a-w- c:\windows\system32\nvoglv32.dll

2012-07-07 14:38:18 883008 ----a-w- c:\windows\system32\nvgenco32.dll

2012-07-07 14:38:18 11354944 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys

2012-07-07 14:38:17 1000768 ----a-w- c:\windows\system32\nvdispco32.dll

2012-07-07 14:38:16 5982528 ----a-w- c:\windows\system32\nvcuda.dll

2012-07-07 14:38:16 2524992 ----a-w- c:\windows\system32\nvcuvid.dll

2012-07-07 14:38:16 2445120 ----a-w- c:\windows\system32\nvcuvenc.dll

2012-07-07 14:38:10 17551680 ----a-w- c:\windows\system32\nvcompiler.dll

2012-07-07 14:37:25 -------- d-----w- c:\program files\NVIDIA Corporation

2012-07-07 14:36:45 -------- d-----w- C:\NVIDIA

2012-07-06 09:00:19 6762896 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{1173d4f0-9bfa-46dc-bee8-1d4c43f70784}\mpengine.dll

2012-06-20 00:35:14 4967624 ----a-w- c:\program files\mozilla firefox\extensions\{82af8dca-6de9-405d-bd5e-43525bdad38a}\components\SkypeFfComponent.dll

2012-06-16 07:44:25 476936 ----a-w- c:\windows\system32\npdeployJava1.dll

2012-06-11 04:29:28 -------- d-----w- c:\users\betti\appdata\local\Macromedia

.

==================== Find3M ====================

.

2012-07-03 23:28:45 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2012-07-03 23:28:45 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe

2012-06-16 07:43:24 472840 ----a-w- c:\windows\system32\deployJava1.dll

2012-05-21 03:55:47 319456 ----a-w- c:\windows\DIFxAPI.dll

2012-05-15 10:26:00 2368832 ----a-w- c:\windows\system32\nvapi.dll

2012-05-15 10:26:00 15322432 ----a-w- c:\windows\system32\nvd3dum.dll

2012-05-15 09:28:49 645440 ----a-w- c:\windows\system32\nvvsvc.exe

2012-05-15 09:28:49 108352 ----a-w- c:\windows\system32\nvmctray.dll

2012-05-15 09:28:48 3931456 ----a-w- c:\windows\system32\nvcpl.dll

2012-05-15 09:27:28 2759488 ----a-w- c:\windows\system32\nvsvc.dll

2012-05-02 06:55:08 360448 ----a-w- c:\windows\system32\awrdscdc.ax

.

============= FINISH: 12:59:03.65 ===============

Link to post
Share on other sites

it didn't generate a separate log file, so i copied and pasted into notebook. hope that's okay.

SHA256: ef477df61734368e41b3a5f280fa47e1e876f959cfe840a32dddd5f536dabb8d SHA1: fad452bf645ccb5ad3bbf7da86f570d13dd3b847 MD5: fcc7c432fbf465c38fd5d940580ef9b7 File size: 134.3 KB ( 137536 bytes ) File name: FacebookUpdate.exe File type: Win32 EXE Tags: peexe signed Detection ratio: 0 / 42 Analysis date: 2012-07-10 18:10:17 UTC ( 2 hours, 7 minutes ago )

5

6

More details

Antivirus Result Update AhnLab-V3 - 20120705 AntiVir - 20120705 Antiy-AVL - 20120705 Avast - 20120705 AVG - 20120705 BitDefender - 20120705 ByteHero - 20120704 CAT-QuickHeal - 20120705 ClamAV - 20120705 Commtouch - 20120705 Comodo - 20120705 DrWeb - 20120706 Emsisoft - 20120705 eSafe - 20120705 F-Prot - 20120705 F-Secure - 20120706 Fortinet - 20120705 GData - 20120705 Ikarus - 20120705 Jiangmin - 20120705 K7AntiVirus - 20120705 Kaspersky - 20120705 McAfee - 20120706 McAfee-GW-Edition - 20120705 Microsoft - 20120705 NOD32 - 20120705 Norman - 20120705 nProtect - 20120706 Panda - 20120705 PCTools - 20120705 Rising - 20120705 Sophos - 20120705 SUPERAntiSpyware - 20120705 Symantec - 20120706 TheHacker - 20120704 TotalDefense - 20120705 TrendMicro - 20120706 TrendMicro-HouseCall - 20120705 VBA32 - 20120705 VIPRE - 20120705 ViRobot - 20120705 VirusBuster - 20120705

SHA256: 8d8d1ada6c2502902b650fea0030004fca66951a9cb85bd44bd757b678749a5d SHA1: bbae31ada17c43eddfc67d65562a8d8ead7dfb34 MD5: 25f9a960544444ba3ce2ad4cb5bb1401 File size: 12.0 KB ( 12288 bytes ) File name: msfeedssync.exe File type: Win32 EXE Tags: nsrl Detection ratio: 0 / 42 Analysis date: 2011-04-11 18:44:34 UTC ( 1 year, 3 months ago )

0

0

More details

Antivirus Result Update AhnLab-V3 - 20110411 AntiVir - 20110411 Antiy-AVL - 20110411 Avast - 20110411 Avast5 - 20110411 AVG - 20110411 BitDefender - 20110411 CAT-QuickHeal - 20110411 ClamAV - 20110411 Commtouch - 20110406 Comodo - 20110411 DrWeb - 20110411 Emsisoft - 20110411 eSafe - 20110410 eTrust-Vet - 20110411 F-Prot - 20110411 F-Secure - 20110411 Fortinet - 20110409 GData - 20110411 Ikarus - 20110411 Jiangmin - 20110409 K7AntiVirus - 20110411 Kaspersky - 20110411 McAfee - 20110411 McAfee-GW-Edition - 20110411 Microsoft - 20110411 NOD32 - 20110411 Norman - 20110411 Panda - 20110411 PCTools - 20110411 Prevx - 20110411 Rising - 20110411 Sophos - 20110411 SUPERAntiSpyware - 20110410 Symantec - 20110411 TheHacker - 20110411 TrendMicro - 20110411 TrendMicro-HouseCall - 20110411 VBA32 - 20110411 VIPRE - 20110411 ViRobot - 20110411 VirusBuster - 20110411

virustotal-facebookupdate.txt

virus total-msfeedssync.txt

Link to post
Share on other sites

  • Staff

Hi,

Next, please run a free online scan with the ESET Online Scanner

Note: You will need to use Internet Explorer for this scan.

  1. Tick the box next to YES, I accept the Terms of Use.
  2. Click Start
  3. When asked, allow the ActiveX control to install
  4. Click Start
  5. Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  6. Click Scan
    Wait for the scan to finish
  7. Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  8. Copy and paste that log as a reply to this topic

Next, download my Security Check from here or here.

  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

Let me know how things are running now and what issues remain.

Link to post
Share on other sites

i haven't heard any random sounds for at least a few hours now, so it is looking promising. the eset scan found 8 problems, which i gave permission to quarantine.

ESETSmartInstaller@High as CAB hook log:

OnlineScanner.ocx - registred OK

# version=7

# iexplore.exe=7.00.6000.16386 (vista_rtm.061101-2205)

# OnlineScanner.ocx=1.0.0.6583

# api_version=3.0.2

# EOSSerial=a6ad5501611fce45b0091520bc42af71

# end=finished

# remove_checked=true

# archives_checked=false

# unwanted_checked=true

# unsafe_checked=false

# antistealth_checked=true

# utc_time=2012-07-11 04:00:57

# local_time=2012-07-10 09:00:57 (-0800, Pacific Daylight Time)

# country="United States"

# lang=1033

# osver=6.0.6000 NT

# compatibility_mode=5892 16776574 100 100 0 178579030 0 0

# compatibility_mode=8192 67108863 100 0 0 0 0 0

# scanned=427370

# found=8

# cleaned=8

# scan_time=7756

C:\Program Files\FoxTabFLVPlayer\FLVPlayer.exe a variant of Win32/InstallCore.A application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\Program Files\FoxTabFLVPlayer\Uninstall\Uninstall.exe a variant of Win32/Kryptik.JPT trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\Qoobox\Quarantine\C\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U\80000000.@.vir a variant of Win32/Sirefef.FA trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\Qoobox\Quarantine\C\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U\800000cb.@.vir probably a variant of Win32/Agent.TEO trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\Users\Betti\Downloads\cnet2_ashampoo_burning_studio_6_free_6_80_4312_exe.exe a variant of Win32/InstallCore.D application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3N4U50PZ\mx_nan_a[1].htm HTML/Iframe.B.Gen virus (deleted - quarantined) 00000000000000000000000000000000 C

C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NJ7J83G8\firstload_com[1].htm HTML/ScrInject.B.Gen virus (deleted - quarantined) 00000000000000000000000000000000 C

C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RD3ZWQS3\mx_nan_a[1].htm HTML/Iframe.B.Gen virus (deleted - quarantined) 00000000000000000000000000000000 C

Results of screen317's Security Check version 0.99.42

Windows Vista x86 (UAC is disabled!)

Out of date service pack!!

Internet Explorer 7 Out of date!

``````````````Antivirus/Firewall Check:``````````````

WMI entry may not exist for antivirus; attempting automatic update.

`````````Anti-malware/Other Utilities Check:`````````

Malwarebytes Anti-Malware version 1.61.0.1400

CCleaner

Java 6 Update 33

Java 6 Update 4

Java 6 Update 7

Java version out of Date!

Adobe Flash Player 11.3.300.262

Adobe Reader X (10.1.3)

Mozilla Firefox (13.0.1)

````````Process Check: objlist.exe by Laurent````````

Malwarebytes Anti-Malware mbamservice.exe

Malwarebytes Anti-Malware mbamgui.exe

`````````````````System Health check`````````````````

Total Fragmentation on Drive C: 0 %

````````````````````End of Log``````````````````````

Link to post
Share on other sites

  • Staff

Hi,

Run TFC by OldTimer to clear temporary files:

  • Please download TFC from here and save it to your desktop.
  • Close any open programs and Internet browsers.
  • Double click TFC.exe to run it and once it opens click on the Start button on the lower left of the program to allow it to begin cleaning.
  • Please be patient as clearing out temp files may take a while.
  • Once it completes you may be prompted to restart your computer, please do so.
  • Once it's finished you may delete TFC.exe from your Desktop or save it for later use for the cleaning of temporary files.

Navigate to Start --> Run, and type Combofix /uninstall in the box that appears. Click OK afterward. Notice the space between the X and the /uninstall

This uninstalls all of ComboFix's components.

Delete SecurityCheck.

After that, navigate to Start --> Control Panel --> Add or Remove Programs, and uninstall the following program (if present):

Java™ 6 Update 33

Java™ 6 Update 4

Java™ 6 Update 7

Restart your computer.

Get the latest version of Java.

Reboot.

Run Windows Update and install all available updates, including SP2 and Internet Explorer 8. Let me know if you have any issues updating.

Let me know what issues remain.

Link to post
Share on other sites

updates just don't seem to work. i am trying to follow the windows help for the error code i received, and it is telling me to right click on the background intelligent transfer service (bits) in the services window, but that category is not in the list, and i cannot find it by doing a search either.

Link to post
Share on other sites

i am just not being allowed to install any updates, no matter what i try. either i get an error message, or it tells me 'some updates were not installed' 'not needed: xx updates'. i tried to uncheck everything in the list and install updates one at a time, but this has not worked either.

Link to post
Share on other sites

  • Staff

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.