Jump to content

/search.certified-toolbar.com Hijack


harlee

Recommended Posts

  • Staff

Please run the following:

  • Please download aswMBR.exe and save it to your desktop.
  • Double click aswMBR.exe to start the tool.
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click Scan
    • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
    • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.

NEXT

Please download Junkware Removal Tool to your desktop.

  • Shutdown your antivirus to avoid any conflicts.
  • Right-mouse click JRT.exe and select Run as administrator
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message

NEXT

Download AdwCleaner from here and save it to your desktop.

  • Run AdwCleaner and select Delete
  • Once done it will ask to reboot, allow the reboot
  • On reboot a log will be produced, please attach the content of the log to your next reply

Link to post
Share on other sites

  • Staff

we have more mork to do, removing malware usually takes several rounds with a number of different tools, so please stick with me.

the aswMBR scan doesn't appear to have completed if you could please run it again (it takes a while to load the definitions)

Please run the following:

Refer to the ComboFix User's Guide

  1. Download ComboFix from the following location:
    Link
    * IMPORTANT !!! Place ComboFix.exe on your Desktop
  2. Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.
    You can get help on disabling your protection programs here
  3. Double click on ComboFix.exe & follow the prompts.
  4. Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  5. When finished, it shall produce a log for you. Post that log in your next reply
    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.
    ---------------------------------------------------------------------------------------------
  6. Ensure your AntiVirus and AntiSpyware applications are re-enabled.
    ---------------------------------------------------------------------------------------------

NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.

Link to post
Share on other sites

  • Staff

Please run the following:

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <-- very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.

NEXT

Go here to run an online scanner from ESET.

  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish

Link to post
Share on other sites

Malwarebytes Anti-Malware (PRO) 1.70.0.1100

www.malwarebytes.org

Database version: v2013.01.17.03

Windows 7 Service Pack 1 x64 NTFS

Internet Explorer 9.0.8112.16421

Lee :: LEE-PC [administrator]

Protection: Enabled

1/17/2013 5:24:47 AM

mbam-log-2013-01-17 (05-24-47).txt

Scan type: Quick scan

Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM

Scan options disabled: P2P

Objects scanned: 229882

Time elapsed: 1 minute(s), 18 second(s)

Memory Processes Detected: 0

(No malicious items detected)

Memory Modules Detected: 0

(No malicious items detected)

Registry Keys Detected: 0

(No malicious items detected)

Registry Values Detected: 0

(No malicious items detected)

Registry Data Items Detected: 0

(No malicious items detected)

Folders Detected: 0

(No malicious items detected)

Files Detected: 0

(No malicious items detected)

(end)

C:\Users\Lee\Documents\Home\Nar-Anon\Guest Book\gbook16\gbook.php PHP/Obfuscated.F application

C:\Users\Lee\Documents\Home\Nar-Anon\Guest Book\gbook16.zip PHP/Obfuscated.F application

C:\Users\Lee\Documents\Videos\Videos\Movie\MOONRISE KINGDOM.html.exe Win32/BundleInstaller application

J:\Documents\Documents\Home\Nar-Anon\Guest Book\gbook16\gbook.php PHP/Obfuscated.F application

J:\Documents\Documents\Home\Nar-Anon\Guest Book\gbook16.zip PHP/Obfuscated.F application

J:\Documents\Documents (2)\Home\Nar-Anon\Guest Book\gbook16\gbook.php PHP/Obfuscated.F application

J:\Documents\Documents (2)\Home\Nar-Anon\Guest Book\gbook16.zip PHP/Obfuscated.F application

J:\Documents\Documents (2)\Videos\Videos\Movie\MOONRISE KINGDOM.html.exe Win32/BundleInstaller application

J:\Videos\Videos\Movie\MOONRISE KINGDOM.html.exe Win32/BundleInstaller application

Link to post
Share on other sites

I ran a free trail of a program called Stopzilla before I can to the form. It detected a trojan virus and also two ad.yieldmanager.com!

I would not use this program because they wanted me to purchase the product and I already have a virus scanner!

Why did this work and no other program is picking them up?

Link to post
Share on other sites

  • Staff

it may have only detected cookies,

please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".

Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:

Press the WinKey + R to open a run box, type Notepad > click OK.

This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')


File::
C:\Users\Lee\Documents\Videos\Videos\Movie\MOONRISE KINGDOM.html.exe
J:\Documents\Documents (2)\Videos\Videos\Movie\MOONRISE KINGDOM.html.exe
J:\Videos\Videos\Movie\MOONRISE KINGDOM.html.exe

ClearJavaCache::

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:

1.Click File;

2.Click Save As... Change the directory to your desktop;

3.Change the Save as type to "All Files";

4.Type in the file name: CFScript

5.Click Save ...

CFScriptB-4.gif

  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix may request an update; please allow it.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

NEXT

Please advise how the computer is running now and if there are any outstanding issues

Link to post
Share on other sites

ComboFix 13-01-17.03 - Lee 01/17/2013 20:47:42.2.4 - x64

Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3959.2579 [GMT -3.5:30]

Running from: c:\users\Lee\Desktop\ComboFix.exe

Command switches used :: c:\users\Lee\Desktop\CFScript.txt

SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

.

((((((((((((((((((((((((( Files Created from 2012-12-18 to 2013-01-18 )))))))))))))))))))))))))))))))

.

.

2013-01-18 00:20 . 2013-01-18 00:20 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp

2013-01-18 00:20 . 2013-01-18 00:20 -------- d-----w- c:\users\Default\AppData\Local\temp

2013-01-17 08:59 . 2013-01-17 08:59 -------- d-----w- c:\program files (x86)\ESET

2013-01-16 02:59 . 2013-01-16 02:59 -------- d-----w- c:\windows\ERUNT

2013-01-16 02:59 . 2013-01-16 02:59 -------- d-----w- C:\JRT

2013-01-15 21:45 . 2013-01-15 21:45 -------- d-----w- c:\programdata\Anvisoft

2013-01-15 21:45 . 2013-01-15 21:45 -------- d-----w- c:\program files (x86)\anvisoft

2013-01-15 20:40 . 2012-11-19 09:01 9125352 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{05B16D9A-2E3E-4D7D-9FC3-B558BD02AEBE}\mpengine.dll

2013-01-15 15:58 . 2013-01-15 15:58 -------- d-----w- c:\program files\Enigma Software Group

2013-01-15 15:58 . 2013-01-15 15:58 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard

2013-01-15 14:30 . 2013-01-03 10:48 15360 ----a-w- c:\windows\Launcher.exe

2013-01-15 02:14 . 2013-01-15 02:14 -------- d--h--w- c:\windows\AxInstSV

2013-01-09 08:43 . 2012-11-09 05:45 750592 ----a-w- c:\windows\system32\win32spl.dll

2013-01-09 08:43 . 2012-11-09 04:43 492032 ----a-w- c:\windows\SysWow64\win32spl.dll

2012-12-28 22:50 . 2012-12-28 22:50 -------- d--h--w- c:\programdata\CanonBJ

2012-12-28 22:50 . 2009-07-14 01:40 84992 ----a-w- c:\windows\system32\Spool\prtprocs\x64\CNBPP4.DLL

2012-12-22 06:30 . 2012-12-16 17:11 46080 ----a-w- c:\windows\system32\atmlib.dll

2012-12-22 06:30 . 2012-12-16 14:13 34304 ----a-w- c:\windows\SysWow64\atmlib.dll

2012-12-22 06:30 . 2012-12-16 14:45 367616 ----a-w- c:\windows\system32\atmfd.dll

2012-12-22 06:30 . 2012-12-16 14:13 295424 ----a-w- c:\windows\SysWow64\atmfd.dll

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2013-01-17 00:00 . 2012-11-23 20:52 74248 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2013-01-17 00:00 . 2012-11-23 20:52 697864 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe

2013-01-10 06:32 . 2012-11-24 23:20 67599240 ----a-w- c:\windows\system32\MRT.exe

2012-12-14 20:19 . 2012-11-24 00:25 24176 ----a-w- c:\windows\system32\drivers\mbam.sys

2012-12-03 02:26 . 2012-12-03 02:26 821736 ----a-w- c:\windows\SysWow64\npDeployJava1.dll

2012-12-03 02:26 . 2012-12-03 02:26 746984 ----a-w- c:\windows\SysWow64\deployJava1.dll

2012-12-03 02:26 . 2012-12-03 02:26 95208 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll

2012-11-30 04:45 . 2013-01-09 08:42 44032 ----a-w- c:\windows\apppatch\acwow64.dll

2012-11-25 00:59 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll

2012-11-25 00:59 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll

2012-11-22 06:16 . 2012-11-22 06:16 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe

2012-11-22 06:16 . 2012-11-22 06:16 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe

2012-11-22 06:16 . 2012-11-22 06:16 89088 ----a-w- c:\windows\system32\ie4uinit.exe

2012-11-22 06:16 . 2012-11-22 06:16 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll

2012-11-22 06:16 . 2012-11-22 06:16 85504 ----a-w- c:\windows\system32\iesetup.dll

2012-11-22 06:16 . 2012-11-22 06:16 82432 ----a-w- c:\windows\system32\icardie.dll

2012-11-22 06:16 . 2012-11-22 06:16 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe

2012-11-22 06:16 . 2012-11-22 06:16 76800 ----a-w- c:\windows\system32\tdc.ocx

2012-11-22 06:16 . 2012-11-22 06:16 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe

2012-11-22 06:16 . 2012-11-22 06:16 74752 ----a-w- c:\windows\SysWow64\iesetup.dll

2012-11-22 06:16 . 2012-11-22 06:16 65024 ----a-w- c:\windows\system32\pngfilt.dll

2012-11-22 06:16 . 2012-11-22 06:16 63488 ----a-w- c:\windows\SysWow64\tdc.ocx

2012-11-22 06:16 . 2012-11-22 06:16 55296 ----a-w- c:\windows\system32\msfeedsbs.dll

2012-11-22 06:16 . 2012-11-22 06:16 534528 ----a-w- c:\windows\system32\ieapfltr.dll

2012-11-22 06:16 . 2012-11-22 06:16 49664 ----a-w- c:\windows\system32\imgutil.dll

2012-11-22 06:16 . 2012-11-22 06:16 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll

2012-11-22 06:16 . 2012-11-22 06:16 48640 ----a-w- c:\windows\system32\mshtmler.dll

2012-11-22 06:16 . 2012-11-22 06:16 452608 ----a-w- c:\windows\system32\dxtmsft.dll

2012-11-22 06:16 . 2012-11-22 06:16 448512 ----a-w- c:\windows\system32\html.iec

2012-11-22 06:16 . 2012-11-22 06:16 403248 ----a-w- c:\windows\system32\iedkcs32.dll

2012-11-22 06:16 . 2012-11-22 06:16 39936 ----a-w- c:\windows\system32\iernonce.dll

2012-11-22 06:16 . 2012-11-22 06:16 3695416 ----a-w- c:\windows\system32\ieapfltr.dat

2012-11-22 06:16 . 2012-11-22 06:16 367104 ----a-w- c:\windows\SysWow64\html.iec

2012-11-22 06:16 . 2012-11-22 06:16 35840 ----a-w- c:\windows\SysWow64\imgutil.dll

2012-11-22 06:16 . 2012-11-22 06:16 30720 ----a-w- c:\windows\system32\licmgr10.dll

2012-11-22 06:16 . 2012-11-22 06:16 282112 ----a-w- c:\windows\system32\dxtrans.dll

2012-11-22 06:16 . 2012-11-22 06:16 267776 ----a-w- c:\windows\system32\ieaksie.dll

2012-11-22 06:16 . 2012-11-22 06:16 249344 ----a-w- c:\windows\system32\webcheck.dll

2012-11-22 06:16 . 2012-11-22 06:16 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll

2012-11-22 06:16 . 2012-11-22 06:16 222208 ----a-w- c:\windows\system32\msls31.dll

2012-11-22 06:16 . 2012-11-22 06:16 197120 ----a-w- c:\windows\system32\msrating.dll

2012-11-22 06:16 . 2012-11-22 06:16 165888 ----a-w- c:\windows\system32\iexpress.exe

2012-11-22 06:16 . 2012-11-22 06:16 163840 ----a-w- c:\windows\system32\ieakui.dll

2012-11-22 06:16 . 2012-11-22 06:16 161792 ----a-w- c:\windows\SysWow64\msls31.dll

2012-11-22 06:16 . 2012-11-22 06:16 160256 ----a-w- c:\windows\system32\wextract.exe

2012-11-22 06:16 . 2012-11-22 06:16 160256 ----a-w- c:\windows\system32\ieakeng.dll

2012-11-22 06:16 . 2012-11-22 06:16 152064 ----a-w- c:\windows\SysWow64\wextract.exe

2012-11-22 06:16 . 2012-11-22 06:16 150528 ----a-w- c:\windows\SysWow64\iexpress.exe

2012-11-22 06:16 . 2012-11-22 06:16 149504 ----a-w- c:\windows\system32\occache.dll

2012-11-22 06:16 . 2012-11-22 06:16 145920 ----a-w- c:\windows\system32\iepeers.dll

2012-11-22 06:16 . 2012-11-22 06:16 135168 ----a-w- c:\windows\system32\IEAdvpack.dll

2012-11-22 06:16 . 2012-11-22 06:16 12288 ----a-w- c:\windows\system32\mshta.exe

2012-11-22 06:16 . 2012-11-22 06:16 11776 ----a-w- c:\windows\SysWow64\mshta.exe

2012-11-22 06:16 . 2012-11-22 06:16 114176 ----a-w- c:\windows\system32\admparse.dll

2012-11-22 06:16 . 2012-11-22 06:16 111616 ----a-w- c:\windows\system32\iesysprep.dll

2012-11-22 06:16 . 2012-11-22 06:16 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll

2012-11-22 06:16 . 2012-11-22 06:16 10752 ----a-w- c:\windows\system32\msfeedssync.exe

2012-11-22 06:16 . 2012-11-22 06:16 103936 ----a-w- c:\windows\system32\inseng.dll

2012-11-22 06:16 . 2012-11-22 06:16 101888 ----a-w- c:\windows\SysWow64\admparse.dll

2012-11-22 06:05 . 2012-11-22 06:05 45056 ----a-r- c:\users\Lee\AppData\Roaming\Microsoft\Installer\{42929F0F-CE14-47AF-9FC7-FF297A603021}\NewShortcut1_42929F0FCE1447AF9FC7FF297A603021_1.exe

2012-11-14 07:06 . 2012-12-14 06:30 17811968 ----a-w- c:\windows\system32\mshtml.dll

Link to post
Share on other sites

Sorry I did not copy all!

http://search.certified-toolbar.com/?si=41460&shortcut=true&tid=3204 is still in control of my browser,microsoft word and outlook!

I am really thinking about formating the harddrive!

ComboFix 13-01-17.03 - Lee 01/17/2013 20:47:42.2.4 - x64

Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3959.2579 [GMT -3.5:30]

Running from: c:\users\Lee\Desktop\ComboFix.exe

Command switches used :: c:\users\Lee\Desktop\CFScript.txt

SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

.

((((((((((((((((((((((((( Files Created from 2012-12-18 to 2013-01-18 )))))))))))))))))))))))))))))))

.

.

2013-01-18 00:20 . 2013-01-18 00:20 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp

2013-01-18 00:20 . 2013-01-18 00:20 -------- d-----w- c:\users\Default\AppData\Local\temp

2013-01-17 08:59 . 2013-01-17 08:59 -------- d-----w- c:\program files (x86)\ESET

2013-01-16 02:59 . 2013-01-16 02:59 -------- d-----w- c:\windows\ERUNT

2013-01-16 02:59 . 2013-01-16 02:59 -------- d-----w- C:\JRT

2013-01-15 21:45 . 2013-01-15 21:45 -------- d-----w- c:\programdata\Anvisoft

2013-01-15 21:45 . 2013-01-15 21:45 -------- d-----w- c:\program files (x86)\anvisoft

2013-01-15 20:40 . 2012-11-19 09:01 9125352 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{05B16D9A-2E3E-4D7D-9FC3-B558BD02AEBE}\mpengine.dll

2013-01-15 15:58 . 2013-01-15 15:58 -------- d-----w- c:\program files\Enigma Software Group

2013-01-15 15:58 . 2013-01-15 15:58 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard

2013-01-15 14:30 . 2013-01-03 10:48 15360 ----a-w- c:\windows\Launcher.exe

2013-01-15 02:14 . 2013-01-15 02:14 -------- d--h--w- c:\windows\AxInstSV

2013-01-09 08:43 . 2012-11-09 05:45 750592 ----a-w- c:\windows\system32\win32spl.dll

2013-01-09 08:43 . 2012-11-09 04:43 492032 ----a-w- c:\windows\SysWow64\win32spl.dll

2012-12-28 22:50 . 2012-12-28 22:50 -------- d--h--w- c:\programdata\CanonBJ

2012-12-28 22:50 . 2009-07-14 01:40 84992 ----a-w- c:\windows\system32\Spool\prtprocs\x64\CNBPP4.DLL

2012-12-22 06:30 . 2012-12-16 17:11 46080 ----a-w- c:\windows\system32\atmlib.dll

2012-12-22 06:30 . 2012-12-16 14:13 34304 ----a-w- c:\windows\SysWow64\atmlib.dll

2012-12-22 06:30 . 2012-12-16 14:45 367616 ----a-w- c:\windows\system32\atmfd.dll

2012-12-22 06:30 . 2012-12-16 14:13 295424 ----a-w- c:\windows\SysWow64\atmfd.dll

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2013-01-17 00:00 . 2012-11-23 20:52 74248 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2013-01-17 00:00 . 2012-11-23 20:52 697864 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe

2013-01-10 06:32 . 2012-11-24 23:20 67599240 ----a-w- c:\windows\system32\MRT.exe

2012-12-14 20:19 . 2012-11-24 00:25 24176 ----a-w- c:\windows\system32\drivers\mbam.sys

2012-12-03 02:26 . 2012-12-03 02:26 821736 ----a-w- c:\windows\SysWow64\npDeployJava1.dll

2012-12-03 02:26 . 2012-12-03 02:26 746984 ----a-w- c:\windows\SysWow64\deployJava1.dll

2012-12-03 02:26 . 2012-12-03 02:26 95208 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll

2012-11-30 04:45 . 2013-01-09 08:42 44032 ----a-w- c:\windows\apppatch\acwow64.dll

2012-11-25 00:59 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll

2012-11-25 00:59 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll

2012-11-22 06:16 . 2012-11-22 06:16 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe

2012-11-22 06:16 . 2012-11-22 06:16 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe

2012-11-22 06:16 . 2012-11-22 06:16 89088 ----a-w- c:\windows\system32\ie4uinit.exe

2012-11-22 06:16 . 2012-11-22 06:16 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll

2012-11-22 06:16 . 2012-11-22 06:16 85504 ----a-w- c:\windows\system32\iesetup.dll

2012-11-22 06:16 . 2012-11-22 06:16 82432 ----a-w- c:\windows\system32\icardie.dll

2012-11-22 06:16 . 2012-11-22 06:16 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe

2012-11-22 06:16 . 2012-11-22 06:16 76800 ----a-w- c:\windows\system32\tdc.ocx

2012-11-22 06:16 . 2012-11-22 06:16 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe

2012-11-22 06:16 . 2012-11-22 06:16 74752 ----a-w- c:\windows\SysWow64\iesetup.dll

2012-11-22 06:16 . 2012-11-22 06:16 65024 ----a-w- c:\windows\system32\pngfilt.dll

2012-11-22 06:16 . 2012-11-22 06:16 63488 ----a-w- c:\windows\SysWow64\tdc.ocx

2012-11-22 06:16 . 2012-11-22 06:16 55296 ----a-w- c:\windows\system32\msfeedsbs.dll

2012-11-22 06:16 . 2012-11-22 06:16 534528 ----a-w- c:\windows\system32\ieapfltr.dll

2012-11-22 06:16 . 2012-11-22 06:16 49664 ----a-w- c:\windows\system32\imgutil.dll

2012-11-22 06:16 . 2012-11-22 06:16 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll

2012-11-22 06:16 . 2012-11-22 06:16 48640 ----a-w- c:\windows\system32\mshtmler.dll

2012-11-22 06:16 . 2012-11-22 06:16 452608 ----a-w- c:\windows\system32\dxtmsft.dll

2012-11-22 06:16 . 2012-11-22 06:16 448512 ----a-w- c:\windows\system32\html.iec

2012-11-22 06:16 . 2012-11-22 06:16 403248 ----a-w- c:\windows\system32\iedkcs32.dll

2012-11-22 06:16 . 2012-11-22 06:16 39936 ----a-w- c:\windows\system32\iernonce.dll

2012-11-22 06:16 . 2012-11-22 06:16 3695416 ----a-w- c:\windows\system32\ieapfltr.dat

2012-11-22 06:16 . 2012-11-22 06:16 367104 ----a-w- c:\windows\SysWow64\html.iec

2012-11-22 06:16 . 2012-11-22 06:16 35840 ----a-w- c:\windows\SysWow64\imgutil.dll

2012-11-22 06:16 . 2012-11-22 06:16 30720 ----a-w- c:\windows\system32\licmgr10.dll

2012-11-22 06:16 . 2012-11-22 06:16 282112 ----a-w- c:\windows\system32\dxtrans.dll

2012-11-22 06:16 . 2012-11-22 06:16 267776 ----a-w- c:\windows\system32\ieaksie.dll

2012-11-22 06:16 . 2012-11-22 06:16 249344 ----a-w- c:\windows\system32\webcheck.dll

2012-11-22 06:16 . 2012-11-22 06:16 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll

2012-11-22 06:16 . 2012-11-22 06:16 222208 ----a-w- c:\windows\system32\msls31.dll

2012-11-22 06:16 . 2012-11-22 06:16 197120 ----a-w- c:\windows\system32\msrating.dll

2012-11-22 06:16 . 2012-11-22 06:16 165888 ----a-w- c:\windows\system32\iexpress.exe

2012-11-22 06:16 . 2012-11-22 06:16 163840 ----a-w- c:\windows\system32\ieakui.dll

2012-11-22 06:16 . 2012-11-22 06:16 161792 ----a-w- c:\windows\SysWow64\msls31.dll

2012-11-22 06:16 . 2012-11-22 06:16 160256 ----a-w- c:\windows\system32\wextract.exe

2012-11-22 06:16 . 2012-11-22 06:16 160256 ----a-w- c:\windows\system32\ieakeng.dll

2012-11-22 06:16 . 2012-11-22 06:16 152064 ----a-w- c:\windows\SysWow64\wextract.exe

2012-11-22 06:16 . 2012-11-22 06:16 150528 ----a-w- c:\windows\SysWow64\iexpress.exe

2012-11-22 06:16 . 2012-11-22 06:16 149504 ----a-w- c:\windows\system32\occache.dll

2012-11-22 06:16 . 2012-11-22 06:16 145920 ----a-w- c:\windows\system32\iepeers.dll

2012-11-22 06:16 . 2012-11-22 06:16 135168 ----a-w- c:\windows\system32\IEAdvpack.dll

2012-11-22 06:16 . 2012-11-22 06:16 12288 ----a-w- c:\windows\system32\mshta.exe

2012-11-22 06:16 . 2012-11-22 06:16 11776 ----a-w- c:\windows\SysWow64\mshta.exe

2012-11-22 06:16 . 2012-11-22 06:16 114176 ----a-w- c:\windows\system32\admparse.dll

2012-11-22 06:16 . 2012-11-22 06:16 111616 ----a-w- c:\windows\system32\iesysprep.dll

2012-11-22 06:16 . 2012-11-22 06:16 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll

2012-11-22 06:16 . 2012-11-22 06:16 10752 ----a-w- c:\windows\system32\msfeedssync.exe

2012-11-22 06:16 . 2012-11-22 06:16 103936 ----a-w- c:\windows\system32\inseng.dll

2012-11-22 06:16 . 2012-11-22 06:16 101888 ----a-w- c:\windows\SysWow64\admparse.dll

2012-11-22 06:05 . 2012-11-22 06:05 45056 ----a-r- c:\users\Lee\AppData\Roaming\Microsoft\Installer\{42929F0F-CE14-47AF-9FC7-FF297A603021}\NewShortcut1_42929F0FCE1447AF9FC7FF297A603021_1.exe

2012-11-14 07:06 . 2012-12-14 06:30 17811968 ----a-w- c:\windows\system32\mshtml.dll

2012-11-14 06:32 . 2012-12-14 06:30 10925568 ----a-w- c:\windows\system32\ieframe.dll

2012-11-14 06:11 . 2012-12-14 06:30 2312704 ----a-w- c:\windows\system32\jscript9.dll

2012-11-14 06:04 . 2012-12-14 06:30 1346048 ----a-w- c:\windows\system32\urlmon.dll

2012-11-14 06:04 . 2012-12-14 06:30 1392128 ----a-w- c:\windows\system32\wininet.dll

2012-11-14 06:02 . 2012-12-14 06:30 1494528 ----a-w- c:\windows\system32\inetcpl.cpl

2012-11-14 06:02 . 2012-12-14 06:30 237056 ----a-w- c:\windows\system32\url.dll

2012-11-14 05:59 . 2012-12-14 06:30 85504 ----a-w- c:\windows\system32\jsproxy.dll

2012-11-14 05:58 . 2012-12-14 06:30 816640 ----a-w- c:\windows\system32\jscript.dll

2012-11-14 05:57 . 2012-12-14 06:30 599040 ----a-w- c:\windows\system32\vbscript.dll

2012-11-14 05:57 . 2012-12-14 06:30 173056 ----a-w- c:\windows\system32\ieUnatt.exe

2012-11-14 05:55 . 2012-12-14 06:30 2144768 ----a-w- c:\windows\system32\iertutil.dll

2012-11-14 05:55 . 2012-12-14 06:30 729088 ----a-w- c:\windows\system32\msfeeds.dll

2012-11-14 05:53 . 2012-12-14 06:30 96768 ----a-w- c:\windows\system32\mshtmled.dll

2012-11-14 05:52 . 2012-12-14 06:30 2382848 ----a-w- c:\windows\system32\mshtml.tlb

2012-11-14 05:46 . 2012-12-14 06:30 248320 ----a-w- c:\windows\system32\ieui.dll

2012-11-14 02:09 . 2012-12-14 06:30 1800704 ----a-w- c:\windows\SysWow64\jscript9.dll

2012-11-14 01:58 . 2012-12-14 06:30 1427968 ----a-w- c:\windows\SysWow64\inetcpl.cpl

2012-11-14 01:57 . 2012-12-14 06:30 1129472 ----a-w- c:\windows\SysWow64\wininet.dll

2012-11-14 01:49 . 2012-12-14 06:30 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe

2012-11-14 01:48 . 2012-12-14 06:30 420864 ----a-w- c:\windows\SysWow64\vbscript.dll

2012-11-14 01:44 . 2012-12-14 06:30 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb

2012-11-09 05:45 . 2012-12-13 11:56 2048 ----a-w- c:\windows\system32\tzres.dll

2012-11-09 04:42 . 2012-12-13 11:56 2048 ----a-w- c:\windows\SysWow64\tzres.dll

2012-11-02 05:59 . 2012-12-13 11:55 478208 ----a-w- c:\windows\system32\dpnet.dll

2012-11-02 05:11 . 2012-12-13 11:55 376832 ----a-w- c:\windows\SysWow64\dpnet.dll

2012-11-01 18:25 . 2012-11-01 18:25 42248 ----a-w- c:\windows\system32\drivers\hssdrv6.sys

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 0 (0x0)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableLUA"= 0 (0x0)

"EnableUIADesktopToggle"= 0 (0x0)

"PromptOnSecureDesktop"= 0 (0x0)

.

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]

R2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-12-14 398184]

R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-12-14 682344]

R2 sbapifs;sbapifs;c:\windows\system32\DRIVERS\sbapifs.sys [x]

R3 esgiguard;esgiguard;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [x]

R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-12-14 24176]

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-11-23 1255736]

S1 asdnet;asdnet;c:\program files (x86)\anvisoft\Anvi AD Blocker\sys\amd64\asdnet.sys [2012-09-07 19280]

S2 ADBlockerSrv;AD Blocker Service;c:\program files (x86)\anvisoft\Anvi AD Blocker\ADBlockerSrv.exe [2013-01-09 280648]

S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-02 382824]

S3 HECIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]

S3 k57nd60a;Broadcom NetLink Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [2009-08-06 320040]

.

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]

2013-01-13 09:16 1606760 ----a-w- c:\program files (x86)\Google\Chrome\Application\24.0.1312.52\Installer\setup.exe

.

Contents of the 'Scheduled Tasks' folder

.

2013-01-17 c:\windows\Tasks\Adobe Flash Player Updater.job

- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-11-23 00:00]

.

2013-01-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-11-22 06:28]

.

2013-01-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-11-22 06:28]

.

.

--------- X64 Entries -----------

.

.

------- Supplementary Scan -------

.

uLocal Page = c:\windows\system32\blank.htm

uStart Page = hxxp://www.newfoundlandlive.com/

uDefault_Search_URL = hxxp://www.google.com

mDefault_Search_URL = hxxp://www.google.com

mStart Page = hxxp://www.google.com

mLocal Page = c:\windows\SysWOW64\blank.htm

mSearch Page = hxxp://www.google.com

mSearch Bar = hxxp://www.google.com

IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\OFFICE11\EXCEL.EXE/3000

TCP: DhcpNameServer = 192.168.2.1 192.168.2.1

.

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_146_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_146_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

@="0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

@="ShockwaveFlash.ShockwaveFlash.11"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="ShockwaveFlash.ShockwaveFlash"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

@="FlashFactory.FlashFactory.1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="FlashFactory.FlashFactory"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

Completion time: 2013-01-17 20:51:42

ComboFix-quarantined-files.txt 2013-01-18 00:21

ComboFix2.txt 2013-01-16 21:45

.

Pre-Run: 345,356,251,136 bytes free

Post-Run: 345,307,209,728 bytes free

.

- - End Of File - - F0AEEF228C0E681EC4D69A391CAF6A6F

Link to post
Share on other sites

  • Staff

give this a try

Please download Malwarebytes Anti-Rootkit and save it to your desktop.

  • Be sure to print out and follow the instructions provided on that same page for performing a scan.
  • Caution: This is a beta version so also read the disclaimer and back up all your data before using.
  • When the scan completes, click on the Cleanup button to remove any threats found and reboot the computer if prompted to do so.
  • Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
  • If there are problems with Internet access, Windows Update, Windows Firewall or other system issues, run the fixdamage tool located in the folder Malwarebytes Anti-Rootkit was run from and reboot your computer.
  • Two files (mbar-log-YYYY-MM-DD, system-log.txt) will be created and saved within that same folder.
  • Copy and paste the contents of these two log files in your next reply.

Note: Further documentation can be found in the ReadMe.rtf file which is located in the Malwarebytes Anti-Rootkit folder.

Link to post
Share on other sites

Only one file was created!

Malwarebytes Anti-Rootkit BETA 1.01.0.1016

www.malwarebytes.org

Database version: v2013.01.18.01

Windows 7 Service Pack 1 x64 NTFS

Internet Explorer 9.0.8112.16421

Lee :: LEE-PC [limited]

1/17/2013 10:54:11 PM

mbar-log-2013-01-17 (22-54-11).txt

Scan type: Quick scan

Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P

Scan options disabled:

Objects scanned: 28223

Time elapsed: 4 minute(s), 18 second(s)

Memory Processes Detected: 0

(No malicious items detected)

Memory Modules Detected: 0

(No malicious items detected)

Registry Keys Detected: 0

(No malicious items detected)

Registry Values Detected: 0

(No malicious items detected)

Registry Data Items Detected: 0

(No malicious items detected)

Folders Detected: 0

(No malicious items detected)

Files Detected: 0

(No malicious items detected)

(end)

Link to post
Share on other sites

  • Staff

make sure the search certified toolbar is not set as your homepage

Open IE -> Tools -> Internet Option -> General tab.

Enter Google (or page of your choice) to make it the default start page

also check to make sure search certified toolbar is not listed in your Programs and Features

if it is there > remove it

let me know what you find

Link to post
Share on other sites

I ran it a second time and this time it created two files! See below!

Malwarebytes Anti-Rootkit BETA 1.01.0.1016

www.malwarebytes.org

Database version: v2013.01.18.01

Windows 7 Service Pack 1 x64 NTFS

Internet Explorer 9.0.8112.16421

Lee :: LEE-PC [administrator]

1/17/2013 11:00:18 PM

mbar-log-2013-01-17 (23-00-18).txt

Scan type: Quick scan

Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P

Scan options disabled:

Objects scanned: 25261

Time elapsed: 58 second(s) [aborted]

Memory Processes Detected: 0

(No malicious items detected)

Memory Modules Detected: 0

(No malicious items detected)

Registry Keys Detected: 0

(No malicious items detected)

Registry Values Detected: 0

(No malicious items detected)

Registry Data Items Detected: 0

(No malicious items detected)

Folders Detected: 0

(No malicious items detected)

Files Detected: 0

(No malicious items detected)

(end)

Malwarebytes Anti-Rootkit BETA 1.01.0.1016

www.malwarebytes.org

Database version: v2013.01.18.01

Windows 7 Service Pack 1 x64 NTFS

Internet Explorer 9.0.8112.16421

Lee :: LEE-PC [administrator]

1/17/2013 11:04:09 PM

mbar-log-2013-01-17 (23-04-09).txt

Scan type: Quick scan

Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P

Scan options disabled:

Objects scanned: 28195

Time elapsed: 3 minute(s), 38 second(s)

Memory Processes Detected: 0

(No malicious items detected)

Memory Modules Detected: 0

(No malicious items detected)

Registry Keys Detected: 0

(No malicious items detected)

Registry Values Detected: 0

(No malicious items detected)

Registry Data Items Detected: 0

(No malicious items detected)

Folders Detected: 0

(No malicious items detected)

Files Detected: 0

(No malicious items detected)

(end)

Link to post
Share on other sites

  • Staff

here is some info on that toolbar

http://www.ehow.com/how_7408337_remove-discuss-toolbar.html

please re-run the Junkware removal tool and post the new log

then run the following:

Download OTL to your Desktop

  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Select All Users
  • Under the Custom Scan box paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    services.exe
    /md5stop
    %systemroot%\*. /rp /s
    %systemdrive%\$Recycle.Bin|@;true;true;true /fp
    DRIVES
    CREATERESTOREPOINT
    BASESERVICES
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Post both logs

Link to post
Share on other sites

  • 3 weeks later...

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.