Jump to content

FBI "Computer Crime and Intellectual Property" ransomware - help


Recommended Posts

Hi All, This is a determined piece of malware. I am infected and presented intiially with the FBI screen after logging on. This is the variant asking for $300 Moneypak. I intially tried Hitmanpro and on its second scan showed and quarantined an executable in my documents folder, 7a8205fe.exe. After rebooting and logging on i now stop at a failing command window trying to execute that exe. I am able to execute commands from this window but some like Explorer yield the Malware screen. Next, I ran Malwarebytes but it found nothing. After reading this forum I downloaded and ran FRST from the command window and here are the results:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 14-05-2013

Ran by David (administrator) on 15-05-2013 11:32:36

Running from L:\

Windows 7 Ultimate Service Pack 1 (X86) OS Language: English(US)

Internet Explorer Version 9

Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe

(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe

(Trusteer Ltd.) C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe

(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe

(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe

(Amazon.com) C:\Program Files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe

(American Power Conversion Corporation) C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe

(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

(Microsoft Corporation) C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe

(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe

(InterVideo Inc.) C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe

(Carbonite, Inc. (www.carbonite.com)) C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe

() C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe

(Juniper Networks) C:\Program Files\Juniper Networks\Common Files\dsNcService.exe

() c:\hp\HPEZBTN\HPBtnSrv.exe

(Verizon) C:\Program Files\Verizon\IHA_MessageCenter\Bin\Verizon_IHAMessageCenter.exe

(InterVideo) C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe

(Hewlett-Packard Company) c:\Program Files\Common Files\LightScribe\LSSrvc.exe

(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe

(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe

(Microsoft Corporation) C:\Program Files\Microsoft LifeCam\MSCamS32.exe

() C:\Windows\system32\PSIService.exe

(Secunia) C:\Program Files\Secunia\PSI\PSIA.exe

(Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe

(Splashtop Inc.) C:\Program Files\Splashtop\Splashtop Remote\Server\SRService.exe

(SupportSoft, Inc.) C:\Program Files\VERIZONDM\bin\sprtsvc.exe

(Microsoft Corporation) c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe

(Microsoft Corporation) c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe

(Splashtop Inc.) C:\Program Files\Splashtop\Splashtop Software Updater\SSUService.exe

(SupportSoft, Inc.) C:\Program Files\VERIZONDM\bin\tgsrvc.exe

(Viewpoint Corporation) C:\Program Files\Viewpoint\Common\ViewpointService.exe

(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

(Amazon.com) C:\Program Files\Amazon\Amazon Unbox Video\ADVWindowsClientService.exe

(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

(Microsoft Corporation) c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe

(Secunia) C:\Program Files\Secunia\PSI\sua.exe

(Hewlett-Packard) c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe

(Intuit Inc.) C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe

(Intuit Inc.) C:\Program Files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe

(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe

(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe

(Microsoft Corporation) C:\Windows\system32\cmd.exe

(Splashtop Inc.) C:\Program Files\Splashtop\Splashtop Remote\Server\SRServer.exe

(Splashtop Inc.) C:\Program Files\Splashtop\Splashtop Remote\Server\SRFeature.exe

(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe

(Trusteer Ltd.) C:\Program Files\Trusteer\Rapport\bin\RapportService.exe

(Farbar) L:\FRST.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [AmazonGSDownloaderTray] C:\Program Files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderTray.exe [246272 2009-02-02] (Amazon.com)

HKLM\...\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [47392 2010-03-16] (Apple Inc.)

HKLM\...\Run: [CamserviceDP] C:\Program Files\Hercules\Dualpix Infinite\Camservice.exe /startup [345384 2008-09-26] (Guillemot Corporation S.A.)

HKLM\...\Run: [Corel Photo Downloader] "C:\Program Files\Corel\Corel MediaOne\Corel Photo Downloader.exe" -startup [483144 2007-08-17] (Corel, Inc.)

HKLM\...\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [30040 2009-02-26] (Microsoft Corporation)

HKLM\...\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [75008 2008-06-16] (Hewlett-Packard)

HKLM\...\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe [65536 2007-04-18] (Hewlett-Packard Company)

HKLM\...\Run: [KBD] C:\HP\KBD\KbdStub.EXE [65536 2006-12-08] ()

HKLM\...\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe" [118640 2009-07-24] (Microsoft Corporation)

HKLM\...\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [118784 2007-02-15] (OsdMaestro)

HKLM\...\Run: [RtHDVCpl] RtHDVCpl.exe [x]

HKLM\...\Run: [uVS11 Preload] C:\Program Files\Ulead Systems\Ulead VideoStudio 11\uvPL.exe [341232 2007-07-23] (InterVideo Digital Technology Corporation)

HKLM\...\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe" [158448 2010-01-07] (Microsoft Corporation)

HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [946352 2012-12-03] (Adobe Systems Incorporated)

HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59720 2013-01-28] (Apple Inc.)

HKLM\...\Run: [VERIZONDM] "C:\Program Files\VERIZONDM\bin\sprtcmd.exe" /P VERIZONDM [206120 2011-12-01] (SupportSoft, Inc.)

HKLM\...\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49208 2010-06-09] (Hewlett-Packard)

HKLM\...\Run: [] [x]

HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [947152 2013-01-27] (Microsoft Corporation)

HKLM\...\Run: [navservice] "C:\Program Files\Navionics World\NavService.exe" [40960 2012-04-29] ()

HKLM\...\Run: [Carbonite Backup] C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe [1065032 2012-09-13] (Carbonite, Inc.)

HKLM\...\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2012-10-25] (Apple Inc.)

HKLM\...\Run: [DivXMediaServer] C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [450560 2012-11-13] ()

HKLM\...\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW [1263512 2012-11-01] ()

HKLM\...\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [152392 2013-02-20] (Apple Inc.)

HKLM\...\Runonce: [*WerKernelReporting] %SYSTEMROOT%\SYSTEM32\WerFault.exe -k -rq [x]

HKLM\...\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent [532040 2013-04-04] (Malwarebytes Corporation)

HKCU\...\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun [1174016 2010-11-20] (Microsoft Corporation)

HKCU\...\Run: [Aim] "C:\Program Files\AIM\aim.exe" /d locale=en-US [4331392 2012-05-30] (AOL Inc.)

HKCU\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [144384 2010-11-20] (Microsoft Corporation)

HKCU\...\Run: [HPADVISOR] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe view=DOCKVIEW,SYSTRAY [1644088 2009-08-05] (Hewlett-Packard)

HKCU\...\Run: [iSUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler [213936 2006-03-20] (Macrovision Corporation)

HKCU\...\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden [451872 2007-07-18] (Hewlett-Packard Company)

HKCU\...\Run: [TivoServer] C:\Program Files\TiVo\Desktop\TiVoServer.exe /service /registry /auto:TivoServer [2264336 2010-08-24] (TiVo Inc.)

HKCU\...\Run: [TivoTransfer] C:\Program Files\TiVo\Desktop\TiVoTransfer.exe [608528 2010-08-24] (TiVo Inc.)

HKCU\...\Run: [TivoNotify] C:\Program Files\TiVo\Desktop\TiVoNotify.exe /service /registry /auto:TivoNotify [437520 2010-08-24] (TiVo Inc.)

HKCU\...\Run: [TranscodingService] C:\Program Files\TiVo\Desktop\Plus\\TranscodingService.exe [856336 2010-08-24] (TiVo Inc.)

HKCU\...\Run: [Facebook Update] "C:\Users\David\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver [138096 2012-07-11] (Facebook Inc.)

HKCU\...\Run: [Verizon Media Manager] C:\Program Files\Verizon\Verizon Media Manager\Release\Verizon Media Manager.exe 0 [1523712 2012-10-10] ()

HKCU\...\Winlogon: [shell] cmd.exe [302592 2010-11-20] (Microsoft Corporation) <==== ATTENTION

HKU\IUSR_NMPR\...\RunOnce: [WAB Migrate] %ProgramFiles%\Windows Mail\wab.exe /Upgrade [ 2010-11-20] (Microsoft Corporation)

HKU\IUSR_NMPR\...\RunOnce: [DPAPIKeyMig] %SystemRoot%\system32\dpapimig.exe -quiet [ 2009-07-13] (Microsoft Corporation)

HKU\Mcx1\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [ 2010-11-20] (Microsoft Corporation)

HKU\Mcx1\...\Run: [HPADVISOR] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autoRun [ 2009-08-05] (Hewlett-Packard)

HKU\Mcx1\...\RunOnce: [WAB Migrate] %ProgramFiles%\Windows Mail\wab.exe /Upgrade [ 2010-11-20] (Microsoft Corporation)

HKU\Mcx1\...\RunOnce: [DPAPIKeyMig] %SystemRoot%\system32\dpapimig.exe -quiet [ 2009-07-13] (Microsoft Corporation)

Startup: C:\ProgramData\Start Menu\Programs\Startup\Amazon Unbox.lnk

ShortcutTarget: Amazon Unbox.lnk -> C:\Program Files\Amazon\Amazon Unbox Video\ADVWindowsClientSystemTray.exe (Amazon.com)

Startup: C:\ProgramData\Start Menu\Programs\Startup\APC UPS Status.lnk

ShortcutTarget: APC UPS Status.lnk -> C:\Program Files\APC\APC PowerChute Personal Edition\Display.exe (American Power Conversion Corporation)

Startup: C:\ProgramData\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk

ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.0.318\SSScheduler.exe (McAfee, Inc.)

Startup: C:\ProgramData\Start Menu\Programs\Startup\Secunia PSI Tray.lnk

ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files\Secunia\PSI\psi_tray.exe (Secunia)

Startup: C:\ProgramData\Start Menu\Programs\Startup\Snapfish Media Detector.lnk

ShortcutTarget: Snapfish Media Detector.lnk -> C:\Program Files\Snapfish Picture Mover\SnapfishMediaDetector.exe ()

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www22.verizon.com/Foryourhome/MyAccount/Unprotected/UserManagement/Login/Login.aspx

HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.google.com/ig?hl=en

http://www.facebook.com/home.php?sk=lf#!

http://aprs.fi/?call=K1YQZ

http://riyachting.com/

http://my.boatus.com//memberpage.asp?pageid=

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=74&bd=Pavilion&pf=desktop

HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=74&bd=Pavilion&pf=desktop

HKLM SearchScopes: DefaultScope {92484F68-4810-4D30-B9C9-5588B2E09779} URL = http://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=hp-pvdt

SearchScopes: HKLM - {92484F68-4810-4D30-B9C9-5588B2E09779} URL = http://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=hp-pvdt

SearchScopes: HKLM - {A67AC368-D438-42E5-92E5-FE1EC2715FCF} URL = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpd

SearchScopes: HKLM - {C3D61A17-A11F-43DF-AAAE-9C343A1C66B6} URL = http://search.live.com/results.aspx?q={searchTerms}&entrypoint={referrer:source?}&FORM=HVDUS7

SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =

SearchScopes: HKCU - {92484F68-4810-4D30-B9C9-5588B2E09779} URL = http://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=hp-pvdt

SearchScopes: HKCU - {A67AC368-D438-42E5-92E5-FE1EC2715FCF} URL = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpd

SearchScopes: HKCU - {C3D61A17-A11F-43DF-AAAE-9C343A1C66B6} URL = http://search.live.com/results.aspx?q={searchTerms}&entrypoint={referrer:source?}&FORM=HVDUS7

BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)

BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.)

BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)

BHO: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)

BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)

BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)

BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)

BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

BHO: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)

BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)

Toolbar: HKLM - Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)

Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

Toolbar: HKCU -&Links - {F2CF5485-4E02-4F68-819C-B92DE9277049} - C:\Windows\System32\ieframe.dll (Microsoft Corporation)

PDF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab

PDF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab

PDF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab

PDF: {115B1886-2AE0-4259-9FE4-E32A5DEE5451} http://www.wowweesupport.com/download/rovio/WebSee_4.0.cab

PDF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab

PDF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/8/b/d/8bd77752-5704-4d68-a152-f7252adaa4f2/LegitCheckControl.cab

PDF: {49232000-16E4-426C-A231-62846947304B} https://wimpro2.cce.hp.com/ChatEntry/downloads/sysinfo.cab

PDF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} http://cdn.smugmug.com/photos/activex/ImageUploader5-5.5.1.0-082608.cab

PDF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab

PDF: {71D413D7-38C5-4035-8548-976522CF11D5} http://www.crucial.com/controls/cpcVistaBeta.cab

PDF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab

PDF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab

PDF: {8D9563A9-8D5F-459B-87F2-BA842255CB9A} https://sslvpn.amica.com/InternalSite/WhlCompMgr.cab

PDF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab

PDF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab

PDF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab

PDF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://sslvpn.amica.com/dana-cached/sc/JuniperSetupClient.cab

PDF: {F5131C24-E56D-11CF-B78A-444553540000} http://activex.microsoft.com/controls/iptdweb/ikcntrls.cab

Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)

Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)

Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)

Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)

Winsock: Catalog5 01 C:\PROGRA~1\WHALEC~1\CLIENT~1\31265D~1.0\WhlNSP.dll File Not found ()

Winsock: Catalog5 10 C:\Program Files\Bonjour\mdnsNSP.dll [20992] (Microsoft Corporation)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:

========

FF ProfilePath: C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\s0lwqsxt.default

FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_202.dll ()

FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.)

FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()

FF Plugin: @canon.com/EPPEX - C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)

FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)

FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)

FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)

FF Plugin: @google.com/npPicasa2,version=2.0.0 - C:\Program Files\Picasa2\npPicasa2.dll No File

FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)

FF Plugin: @java.com/DTPlugin,version=10.17.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)

FF Plugin: @java.com/JavaPlugin,version=10.17.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)

FF Plugin: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.)

FF Plugin: @microsoft.com/GENUINE - disabled No File

FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)

FF Plugin: @microsoft.com/VirtualEarth3D,version=4.0 - C:\Program Files\Virtual Earth 3D\ ()

FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)

FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)

FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)

FF Plugin: @movenetworks.com/Quantum Media Player - C:\Users\David\AppData\Roaming\Move Networks\plugins\npqmp071701000002.dll (Move Networks)

FF Plugin: @nvidia.com/3DVision - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)

FF Plugin: @nvidia.com/3DVisionStreaming - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)

FF Plugin: @pack.google.com/Google Updater;version=14 - C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)

FF Plugin: @real.com/RhapsodyPlayerEngine,version=1.0 - C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll (RealNetworks, Inc.)

FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)

FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)

FF Plugin: @viewpoint.com/VMP - C:\Program Files\Viewpoint\Viewpoint Media Player\npViewpoint.dll ()

FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF Extension: Google Toolbar for Firefox - C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\s0lwqsxt.default\Extensions\{3112ca9c-de6d-4884-a869-9855de68056c}

FF Extension: No Name - C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\s0lwqsxt.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi

Chrome:

=======

CHR HomePage: hxxp://www.google.com/

CHR RestoreOnStartup: "hxxp://www.google.com/"

CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}

CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}

CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\26.0.1410.64\PepperFlash\pepflashplayer.dll ()

CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer

CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\26.0.1410.64\ppGoogleNaClPluginChrome.dll ()

CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\26.0.1410.64\pdf.dll ()

CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)

CHR Plugin: (downloadUpdater) - C:\Program Files\Mozilla Firefox\plugins\npdnu.dll (AOL LLC)

CHR Plugin: (downloadUpdater2) - C:\Program Files\Mozilla Firefox\plugins\npdnupdater2.dll (AOL LLC)

CHR Plugin: (Navionics NavIn) - C:\Program Files\Mozilla Firefox\plugins\npNavIn.dll (Navionics)

CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.)

CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.)

CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.)

CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.)

CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.)

CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll (Apple Inc.)

CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll (Apple Inc.)

CHR Plugin: (MetaStream 3 Plugin) - C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll ()

CHR Plugin: (AmazonMP3DownloaderPlugin) - C:\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101752.dll (Amazon.com, Inc.)

CHR Plugin: (CANON iMAGE GATEWAY Album Plugin Utility for IJ) - C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)

CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)

CHR Plugin: (DivX Plus Web Player) - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)

CHR Plugin: (Google Earth Plugin) - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)

CHR Plugin: (Google Updater) - C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)

CHR Plugin: (Picasa) - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)

CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File

CHR Plugin: (Java Platform SE 7 U17) - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)

CHR Plugin: (Silverlight Plug-In) - C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)

CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)

CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)

CHR Plugin: (RealNetworks Rhapsody Player Engine) - C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll (RealNetworks, Inc.)

CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)

CHR Plugin: (iTunes Application Detector) - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()

CHR Plugin: (Unity Player) - C:\Users\David\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

CHR Plugin: (Facebook Video Calling Plugin) - C:\Users\David\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)

CHR Plugin: (Move Streaming Media Player) - C:\Users\David\AppData\Roaming\Move Networks\plugins\npqmp071701000002.dll (Move Networks)

CHR Plugin: (Move Streaming Media Player) - C:\Users\David\AppData\Roaming\Move Networks\plugins\npqmp071701000008.dll (Move Networks)

CHR Plugin: (Windows Presentation Foundation) - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)

CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw_1200112.dll No File

CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll No File

CHR Plugin: (Java Deployment Toolkit 7.0.170.2) - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)

CHR Extension: (Google Docs) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0

CHR Extension: (Google Drive) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0

CHR Extension: (YouTube) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0

CHR Extension: (Google Search) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0

CHR Extension: (Skype Click to Call) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.7.0.12055_0

CHR Extension: (DivX Plus Web Player HTML5 \u003Cvideo\u003E) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0

CHR Extension: (Gmail) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0

========================== Services (Whitelisted) =================

R2 ADVService; C:\Program Files\Amazon\Amazon Unbox Video\ADVWindowsClientService.exe [25704 2010-03-04] (Amazon.com)

S3 AlertService; C:\Program Files\Intel\IntelDH\CCU\AlertService.exe [188416 2006-09-11] (Intel® Corporation)

R2 Amazon Download Agent; C:\Program Files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe [317440 2009-02-02] (Amazon.com)

R2 APC UPS Service; C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe [689408 2007-07-19] (American Power Conversion Corporation)

R2 Capture Device Service; C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe [198168 2007-03-06] (InterVideo Inc.)

R2 CarboniteService; C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe [4646472 2012-09-13] (Carbonite, Inc. (www.carbonite.com))

S3 DMService; C:\Windows\Downloaded Program Files\DMService.exe [423576 2008-04-05] (Whale Communications, a Microsoft subsidiary)

R2 DQLWinService; C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe [208896 2006-09-03] ()

R2 dsNcService; C:\Program Files\Juniper Networks\Common Files\dsNcService.exe [670792 2011-09-08] (Juniper Networks)

S2 gupdate1c9e8a748642a0; C:\Program Files\Google\Update\GoogleUpdate.exe [133104 2009-06-08] (Google Inc.)

R2 HP Health Check Service; c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [94208 2008-06-16] (Hewlett-Packard)

R2 HPBtnSrv; c:\hp\HPEZBTN\HPBtnSrv.exe [198240 2007-05-29] ()

R2 IHA_MessageCenter; C:\Program Files\Verizon\IHA_MessageCenter\Bin\Verizon_IHAMessageCenter.exe [352248 2012-08-03] (Verizon)

S2 IntelDHSvcConf; C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe [29696 2006-05-10] (Intel® Corporation)

S3 ISSM; C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe [75264 2006-09-11] (Intel® Corporation)

S3 M1 Server; C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe [26624 2006-09-01] ()

R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)

R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)

S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.0.318\McCHSvc.exe [235216 2013-02-05] (McAfee, Inc.)

S3 MCLServiceATL; C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe [167936 2006-09-11] (Intel® Corporation)

R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [20456 2013-01-27] (Microsoft Corporation)

R3 MSSQL$MSSMLBIZ; c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [29293408 2010-12-10] (Microsoft Corporation)

R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [295232 2013-01-27] (Microsoft Corporation)

S2 ProtexisLicensing; C:\Windows\system32\PSIService.exe [177704 2007-06-05] ()

S3 Remote UI Service; C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe [544256 2006-09-11] (Intel® Corporation)

R2 Secunia PSI Agent; C:\Program Files\Secunia\PSI\PSIA.exe [994360 2011-10-14] (Secunia)

R2 Secunia Update Agent; C:\Program Files\Secunia\PSI\sua.exe [399416 2011-10-14] (Secunia)

R2 Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3289208 2013-04-15] (Skype Technologies S.A.)

R2 SplashtopRemoteService; C:\Program Files\Splashtop\Splashtop Remote\Server\SRService.exe [548264 2012-06-15] (Splashtop Inc.)

R2 sprtsvc_verizondm; C:\Program Files\VERIZONDM\bin\sprtsvc.exe [206120 2011-12-01] (SupportSoft, Inc.)

R2 SSUService; C:\Program Files\Splashtop\Splashtop Software Updater\SSUService.exe [370504 2012-03-15] (Splashtop Inc.)

R2 tgsrvc_verizondm; C:\Program Files\VERIZONDM\bin\tgsrvc.exe [185640 2011-12-01] (SupportSoft, Inc.)

S4 TivoBeacon2; C:\Program Files\TiVo\Desktop\TiVoBeacon.exe [1104656 2010-08-24] (TiVo Inc.)

R2 Viewpoint Manager Service; C:\Program Files\Viewpoint\Common\ViewpointService.exe [24652 2007-01-04] (Viewpoint Corporation)

S3 whliocsv; C:\Program Files\Whale Communications\Client Components\3.1.0\whliocsv.exe [134808 2007-08-29] (Whale Communications, a Microsoft subsidiary)

S3 ZuneWlanCfgSvc; C:\Windows\system32\ZuneWlanCfgSvc.exe [447216 2010-01-07] (Microsoft Corporation)

S3 WPFFontCache_v0400; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [x]

==================== Drivers (Whitelisted) ====================

S3 akshasp; C:\Windows\System32\DRIVERS\akshasp.sys [238208 2012-06-15] (Aladdin Knowledge Systems Ltd.)

S3 aksusb; C:\Windows\System32\DRIVERS\aksusb.sys [289152 2012-06-15] (SafeNet Inc.)

R3 camfilt2; C:\Windows\System32\Drivers\camfilt2.sys [94208 2008-08-13] (Guillemot Corporation)

R3 dsNcAdpt; C:\Windows\System32\DRIVERS\dsNcAdpt.sys [26624 2011-09-08] (Juniper Networks)

S3 FLMckUsb; C:\Windows\System32\DRIVERS\ATTchDrv.sys [84360 2006-12-22] (AuthenTec, Inc.)

R2 hardlock; C:\Windows\system32\drivers\hardlock.sys [596424 2011-08-10] (SafeNet Inc.)

R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)

R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [195296 2013-01-20] (Microsoft Corporation)

R1 MpKsl2b78e5a3; C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{DD13E2B1-CC7A-41DC-BC6E-ED190D87612F}\MpKsl2b78e5a3.sys [29904 2013-05-15] (Microsoft Corporation)

R1 MpKsl9820d9ad; C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{DD13E2B1-CC7A-41DC-BC6E-ED190D87612F}\MpKsl9820d9ad.sys [29904 2013-05-15] (Microsoft Corporation)

R1 NEOFLTR_710_19243; C:\Windows\system32\Drivers\NEOFLTR_710_19243.SYS [85064 2011-09-08] (Juniper Networks)

R3 PSI; C:\Windows\System32\DRIVERS\psi_mf.sys [15544 2010-09-01] (Secunia)

R1 RapportCerberus_51755; C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus32_51755.sys [317112 2013-04-22] ()

R1 RapportEI; C:\Program Files\Trusteer\Rapport\bin\RapportEI.sys [103120 2013-04-30] (Trusteer Ltd.)

R1 RapportPG; C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys [174320 2013-04-30] (Trusteer Ltd.)

R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [9602944 2008-08-13] ()

S3 xcbdaNtscV; C:\Windows\System32\DRIVERS\xcbdaV.sys [157568 2009-07-13] (ViXS Systems Inc.)

S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x]

S3 tsusbhub; system32\drivers\tsusbhub.sys [x]

S3 VGPU; System32\drivers\rdvgkmd.sys [x]

==================== NetSvcs (Whitelisted) ===================

==================== One Month Created Files and Folders ========

2013-05-15 11:28 - 2013-05-15 11:28 - 00000000 ____D C:\FRST

2013-05-15 03:33 - 2013-04-04 18:11 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll

2013-05-15 03:33 - 2013-04-04 18:02 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl

2013-05-15 03:33 - 2013-04-04 18:02 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll

2013-05-15 03:33 - 2013-04-04 18:02 - 01104384 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll

2013-05-15 03:33 - 2013-04-04 18:01 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll

2013-05-15 03:33 - 2013-04-04 17:59 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll

2013-05-15 03:33 - 2013-04-04 17:58 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll

2013-05-15 03:33 - 2013-04-04 17:58 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe

2013-05-15 03:33 - 2013-04-04 17:57 - 00420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll

2013-05-15 03:33 - 2013-04-04 17:56 - 00607744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll

2013-05-15 03:33 - 2013-04-04 17:55 - 01796096 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll

2013-05-15 03:33 - 2013-04-04 17:54 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll

2013-05-15 03:33 - 2013-04-04 17:50 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll

2013-05-15 03:32 - 2013-04-04 18:09 - 09738752 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll

2013-05-15 03:28 - 2013-05-05 15:25 - 12324864 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll

2013-05-15 03:28 - 2013-05-05 15:12 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb

2013-05-15 00:13 - 2013-04-10 01:18 - 00728424 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys

2013-05-15 00:13 - 2013-04-10 01:18 - 00218984 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgmms1.sys

2013-05-15 00:13 - 2013-04-09 23:14 - 02347520 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys

2013-05-15 00:13 - 2013-03-19 00:53 - 00186368 ____A (Microsoft Corporation) C:\Windows\System32\wwansvc.dll

2013-05-15 00:13 - 2013-03-18 23:33 - 00040960 ____A (Microsoft Corporation) C:\Windows\System32\wwanprotdim.dll

2013-05-15 00:13 - 2013-02-27 01:05 - 00101720 ____A (Microsoft Corporation) C:\Windows\System32\consent.exe

2013-05-15 00:13 - 2013-02-27 00:55 - 12872704 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll

2013-05-15 00:13 - 2013-02-27 00:55 - 00180224 ____A (Microsoft Corporation) C:\Windows\System32\shdocvw.dll

2013-05-15 00:13 - 2013-02-27 00:49 - 01796096 ____A (Microsoft Corporation) C:\Windows\System32\authui.dll

2013-05-15 00:13 - 2013-02-27 00:49 - 00047104 ____A (Microsoft Corporation) C:\Windows\System32\appinfo.dll

2013-05-14 21:46 - 2013-05-14 21:46 - 00001065 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk

2013-05-14 21:46 - 2013-05-14 21:46 - 00000000 ____D C:\Users\David\AppData\Roaming\Malwarebytes

2013-05-14 21:46 - 2013-05-14 21:46 - 00000000 ____D C:\ProgramData\Malwarebytes

2013-05-14 21:46 - 2013-05-14 21:46 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware

2013-05-14 21:46 - 2013-04-04 14:50 - 00022856 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys

2013-05-14 20:36 - 2013-05-14 20:36 - 00000742 ____A C:\Windows\System32\.crusader

2013-05-14 19:37 - 2013-05-14 19:37 - 00000000 ____D C:\Program Files\HitmanPro

2013-05-14 18:37 - 2013-05-14 20:36 - 00000000 ____D C:\ProgramData\HitmanPro

2013-05-14 18:37 - 2013-05-14 18:37 - 00153328 ____A C:\Windows\Minidump\051413-59389-01.dmp

2013-05-14 18:37 - 2013-05-14 18:37 - 00000000 ____D C:\Windows\Minidump

2013-05-14 18:36 - 2013-05-14 18:36 - 307725991 ____A C:\Windows\MEMORY.DMP

2013-05-14 16:40 - 2013-05-14 16:40 - 00404828 ____A C:\Users\David\AppData\Roaming\2433f433

2013-05-14 16:40 - 2013-05-14 16:40 - 00404817 ____A C:\ProgramData\2433f433

2013-05-14 16:40 - 2013-05-14 16:40 - 00404812 ____A C:\Users\David\AppData\Local\2433f433

2013-05-14 16:40 - 2013-05-14 16:40 - 00025088 ____A C:\Users\David\Documents\7a8205fe.dll

2013-04-30 01:28 - 2013-04-30 01:28 - 00102448 ____A (Trusteer Ltd.) C:\Windows\System32\Drivers\RapportKELL.sys

2013-04-29 15:20 - 2013-04-29 15:20 - 00000000 ____D C:\Users\David\AppData\Local\Macromedia

2013-04-29 14:41 - 2013-05-03 21:33 - 00002006 ____A C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk

2013-04-29 14:41 - 2013-05-03 21:32 - 00000000 ____D C:\Program Files\McAfee Security Scan

2013-04-29 14:41 - 2013-04-29 14:41 - 00000000 ____D C:\ProgramData\McAfee Security Scan

2013-04-24 02:15 - 2013-04-12 09:45 - 01211752 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ntfs.sys

==================== One Month Modified Files and Folders ========

2013-05-15 11:28 - 2013-05-15 11:28 - 00000000 ____D C:\FRST

2013-05-15 11:26 - 2009-06-26 23:08 - 00000882 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job

2013-05-15 11:18 - 2012-03-31 12:57 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job

2013-05-15 11:03 - 2009-06-26 23:08 - 00000886 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job

2013-05-15 10:33 - 2010-11-13 00:25 - 00009712 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0

2013-05-15 10:33 - 2010-11-13 00:25 - 00009712 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0

2013-05-15 10:31 - 2010-11-13 01:28 - 01657301 ____A C:\Windows\WindowsUpdate.log

2013-05-15 10:25 - 2009-07-14 00:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT

2013-05-15 10:25 - 2009-07-14 00:39 - 04808094 ____A C:\Windows\setupact.log

2013-05-15 10:25 - 2008-01-24 19:33 - 00000000 ____D C:\ProgramData\NVIDIA

2013-05-15 08:52 - 2011-09-22 23:41 - 00000928 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1269665831-4724830-4121108689-1001UA.job

2013-05-15 06:18 - 2012-03-31 12:57 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe

2013-05-15 06:18 - 2011-08-19 21:14 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl

2013-05-15 05:18 - 2009-07-13 22:37 - 00000000 ____D C:\Windows\rescache

2013-05-15 04:03 - 2009-07-13 22:37 - 00000000 ____D C:\Windows\Microsoft.NET

2013-05-15 03:52 - 2009-07-14 00:33 - 00507136 ____A C:\Windows\System32\FNTCACHE.DAT

2013-05-15 03:34 - 2008-04-07 20:56 - 00000000 ____D C:\ProgramData\Microsoft Help

2013-05-15 03:30 - 2010-11-13 01:39 - 00835398 ____A C:\Windows\System32\PerfStringBackup.INI

2013-05-15 03:02 - 2011-06-16 22:27 - 72607752 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe

2013-05-14 21:46 - 2013-05-14 21:46 - 00001065 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk

2013-05-14 21:46 - 2013-05-14 21:46 - 00000000 ____D C:\Users\David\AppData\Roaming\Malwarebytes

2013-05-14 21:46 - 2013-05-14 21:46 - 00000000 ____D C:\ProgramData\Malwarebytes

2013-05-14 21:46 - 2013-05-14 21:46 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware

2013-05-14 20:36 - 2013-05-14 20:36 - 00000742 ____A C:\Windows\System32\.crusader

2013-05-14 20:36 - 2013-05-14 18:37 - 00000000 ____D C:\ProgramData\HitmanPro

2013-05-14 19:37 - 2013-05-14 19:37 - 00000000 ____D C:\Program Files\HitmanPro

2013-05-14 18:37 - 2013-05-14 18:37 - 00153328 ____A C:\Windows\Minidump\051413-59389-01.dmp

2013-05-14 18:37 - 2013-05-14 18:37 - 00000000 ____D C:\Windows\Minidump

2013-05-14 18:36 - 2013-05-14 18:36 - 307725991 ____A C:\Windows\MEMORY.DMP

2013-05-14 17:53 - 2011-09-22 23:41 - 00000906 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1269665831-4724830-4121108689-1001Core.job

2013-05-14 16:40 - 2013-05-14 16:40 - 00404828 ____A C:\Users\David\AppData\Roaming\2433f433

2013-05-14 16:40 - 2013-05-14 16:40 - 00404817 ____A C:\ProgramData\2433f433

2013-05-14 16:40 - 2013-05-14 16:40 - 00404812 ____A C:\Users\David\AppData\Local\2433f433

2013-05-14 16:40 - 2013-05-14 16:40 - 00025088 ____A C:\Users\David\Documents\7a8205fe.dll

2013-05-14 14:53 - 2009-06-08 22:03 - 00000868 ____A C:\Windows\Tasks\Google Software Updater.job

2013-05-12 16:18 - 2012-12-11 16:21 - 00000000 ____D C:\Users\David\AppData\Roaming\Dropbox

2013-05-09 14:27 - 2009-10-15 14:44 - 00000052 ____A C:\Windows\System32\DOErrors.log

2013-05-05 15:25 - 2013-05-15 03:28 - 12324864 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll

2013-05-05 15:12 - 2013-05-15 03:28 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb

2013-05-03 21:33 - 2013-04-29 14:41 - 00002006 ____A C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk

2013-05-03 21:32 - 2013-04-29 14:41 - 00000000 ____D C:\Program Files\McAfee Security Scan

2013-05-02 11:28 - 2010-08-13 00:45 - 00238872 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe

2013-04-30 01:28 - 2013-04-30 01:28 - 00102448 ____A (Trusteer Ltd.) C:\Windows\System32\Drivers\RapportKELL.sys

2013-04-29 15:20 - 2013-04-29 15:20 - 00000000 ____D C:\Users\David\AppData\Local\Macromedia

2013-04-29 14:41 - 2013-04-29 14:41 - 00000000 ____D C:\ProgramData\McAfee Security Scan

2013-04-29 14:41 - 2008-01-24 19:45 - 00000000 ____D C:\ProgramData\Adobe

2013-04-29 14:15 - 2009-03-23 22:14 - 00000000 ____D C:\Program Files\Big Kahuna Reef

2013-04-29 13:53 - 2013-04-02 15:20 - 00000000 ____D C:\Program Files\Mozilla Firefox

2013-04-29 13:53 - 2012-04-02 22:14 - 00000000 ___RD C:\Program Files\Skype

2013-04-29 13:53 - 2008-05-05 21:36 - 00000000 ____D C:\ProgramData\Skype

2013-04-29 13:50 - 2012-12-11 16:24 - 00000000 ___RD C:\Users\David\Dropbox

2013-04-22 13:35 - 2010-11-13 01:02 - 00093000 ____A C:\Windows\PFRO.log

==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit

C:\Windows\System32\winlogon.exe => MD5 is legit

C:\Windows\System32\wininit.exe => MD5 is legit

C:\Windows\System32\svchost.exe => MD5 is legit

C:\Windows\System32\services.exe => MD5 is legit

C:\Windows\System32\User32.dll => MD5 is legit

C:\Windows\System32\userinit.exe => MD5 is legit

C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

Last Boot: 2013-05-14 00:43

==================== End Of Log ============================

there is also an additional txt file if needed.

Thanks in advance for any assistance you can provide, dave

Link to post
Share on other sites

Hello vhe9606 and :welcome:! My name is Maniac and I will be glad to help you solve your malware problem.

Please note:

  • If you are a paying customer, you have the privilege to contact the help desk at Consumer Support. If you choose this option to get help, please let me know.
  • I recommend you to keep the instructions I will be giving you so that they are available to you at any time. You can save them in a text file or print them.
  • Make sure you read all of the instructions and fixes thoroughly before continuing with them.
  • Follow my instructions strictly and don’t hesitate to stop and ask me if you have any questions.
  • Post your log files, don't attach them. Every log file should be copy/pasted in your next reply.
  • Do not perform any kind of scanning and fixing without my instructions. If you want to proceed on your own, please let me know.

Open Notepad (Start => All Programs => Accessories => Notepad). Please copy the entire contents of the code box below. (To do this highlight the contents of the box, right click on it and select copy. Right-click in the open Notepad and select Paste). Save it on the flashdrive as fixlist.txt

C:\Users\David\AppData\Roaming\2433f433

C:\ProgramData\2433f433

C:\Users\David\AppData\Local\2433f433

C:\Users\David\Documents\7a8205fe.dll

NOTICE: This script was written specifically for this user, for use on this particular machine. Running this on another machine may cause damage to your operating system

Now please enter System Recovery Options then select Command Prompt

Run FRST (or FRST64 if you have the 64bit version) and press the Fix button just once and wait.

The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.

Reboot Normally.

Link to post
Share on other sites

Hello Maniac, You are the man! Followed your instructions, log to follow. Once done I rebooted and then logged on. As before the ascreen remained blank with a failed command window open that had tried to execute the moved 7a8205fe.exe. This time I brought up task manager and executed Explorer which loaded the normal desktop. I must still have the cmd to execute the malware in the startup process somewhere. Here's the log:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 14-05-2013

Ran by SYSTEM at 2013-05-15 17:32:20 Run:1

Running from M:\

Boot Mode: Recovery

==============================================

C:\Users\David\AppData\Roaming\2433f433 => Moved successfully.

C:\ProgramData\2433f433 => Moved successfully.

C:\Users\David\AppData\Local\2433f433 => Moved successfully.

C:\Users\David\Documents\7a8205fe.dll => Moved successfully.

==== End of Fixlog ====

thanks for your continued efforts!, dave

Link to post
Share on other sites

Hi Maniac,

A quick update. I was poking arround in my registry and found serveral instances of the exe that is trying to be executed at logon time. Most of them are in CLSID entries like this one :HKEY_USERS\S-1-5-21-1269665831-4724830-4121108689-1001\Software\Classes\CLSID\{89391514-9641-2045-4368-059355495537}\InProcServer32} with a default data value of C:\Users\David\Documents\7a8205fe.dll. One of the hits was in HKEY_USERS\S-1-5-21-1269665831-4724830-4121108689-1001\Software\Microsoft\Command Processor with an autorun value of C:\Users\David\Documents\7a8205fe.dll so I blanked it out and now when I reboot and logon it stops on a blank screen with a CMD window and prompt, no longer trying to autorun the executable. Something is still running the command prompt halting the logon although using task manager to start Explorer seems to bring everything up fine. And of course there are those other CLSID entries.

I will await your input - dave

Link to post
Share on other sites

Please do not take any action while working together.

Note: Please do not run this tool without special supervision and instructions of someone authorized to do so. Otherwise, you could end up with serious problems. For more details, read this article: ComboFix usage, Questions, Help? - Look here

Please visit this webpage for download links, and instructions for running the tool:

http://www.bleepingc...to-use-combofix

* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Please post the C:\ComboFix.txt in your next reply for further review.

Note: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.

Link to post
Share on other sites

Hello Maniac,

Here is the ComboFix.txt:

ComboFix 13-05-16.02 - David 05/16/2013 15:39:06.1.4 - x86

Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.3071.1593 [GMT -4:00]

Running from: c:\users\David\Desktop\ComboFix.exe

AV: Microsoft Security Essentials *Disabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5}

SP: Microsoft Security Essentials *Disabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\users\David\AppData\Roaming\Microsoft\Network\Connections\Pbk\_hiddenPbk

c:\users\David\AppData\Roaming\Microsoft\Network\Connections\Pbk\_hiddenPbk\rasphone.pbk

c:\users\David\Documents\~WRL0001.tmp

.

.

((((((((((((((((((((((((( Files Created from 2013-04-16 to 2013-05-16 )))))))))))))))))))))))))))))))

.

.

2013-05-16 19:51 . 2013-05-16 19:54 -------- d-----w- c:\users\David\AppData\Local\temp

2013-05-16 19:51 . 2013-05-16 19:51 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp

2013-05-16 19:51 . 2013-05-16 19:51 -------- d-----w- c:\users\Mcx1\AppData\Local\temp

2013-05-16 19:51 . 2013-05-16 19:51 -------- d-----w- c:\users\IUSR_NMPR\AppData\Local\temp

2013-05-16 19:51 . 2013-05-16 19:51 -------- d-----w- c:\users\Default\AppData\Local\temp

2013-05-16 19:02 . 2013-05-16 19:02 43600 ----a-w- c:\windows\system32\drivers\iugpaakq.sys

2013-05-16 14:23 . 2013-05-16 14:23 60872 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{196A5639-8D5E-4973-A5B9-219028984806}\offreg.dll

2013-05-16 14:23 . 2013-05-16 14:23 29904 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{196A5639-8D5E-4973-A5B9-219028984806}\MpKsl6a8a6ab4.sys

2013-05-16 14:19 . 2013-05-13 06:19 7016152 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{196A5639-8D5E-4973-A5B9-219028984806}\mpengine.dll

2013-05-15 21:52 . 2013-05-13 06:19 7016152 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll

2013-05-15 15:28 . 2013-05-15 15:28 -------- d-----w- C:\FRST

2013-05-15 07:28 . 2013-05-05 19:12 2382848 ----a-w- c:\windows\system32\mshtml.tlb

2013-05-15 04:13 . 2013-03-19 04:53 186368 ----a-w- c:\windows\system32\wwansvc.dll

2013-05-15 04:13 . 2013-03-19 03:33 40960 ----a-w- c:\windows\system32\wwanprotdim.dll

2013-05-15 04:13 . 2013-04-10 03:14 2347520 ----a-w- c:\windows\system32\win32k.sys

2013-05-15 04:13 . 2013-04-10 05:18 728424 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys

2013-05-15 04:13 . 2013-04-10 05:18 218984 ----a-w- c:\windows\system32\drivers\dxgmms1.sys

2013-05-15 04:13 . 2013-02-27 05:05 101720 ----a-w- c:\windows\system32\consent.exe

2013-05-15 04:13 . 2013-02-27 04:49 1796096 ----a-w- c:\windows\system32\authui.dll

2013-05-15 04:13 . 2013-02-27 04:49 47104 ----a-w- c:\windows\system32\appinfo.dll

2013-05-15 01:46 . 2013-05-15 01:46 -------- d-----w- c:\users\David\AppData\Roaming\Malwarebytes

2013-05-15 01:46 . 2013-05-15 01:46 -------- d-----w- c:\programdata\Malwarebytes

2013-05-15 01:46 . 2013-05-15 01:46 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2013-05-15 01:46 . 2013-04-04 18:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys

2013-05-15 01:45 . 2013-05-15 01:45 -------- d-----w- c:\users\David\AppData\Local\Programs

2013-05-14 23:37 . 2013-05-14 23:37 -------- d-----w- c:\program files\HitmanPro

2013-05-14 22:37 . 2013-05-15 00:36 -------- d-----w- c:\programdata\HitmanPro

2013-04-30 05:28 . 2013-04-30 05:28 102448 ----a-w- c:\windows\system32\drivers\RapportKELL.sys

2013-04-29 19:20 . 2013-04-29 19:20 -------- d-----w- c:\users\David\AppData\Local\Macromedia

2013-04-29 18:41 . 2013-04-29 18:41 -------- d-----w- c:\programdata\McAfee Security Scan

2013-04-29 18:41 . 2013-05-04 01:32 -------- d-----w- c:\program files\McAfee Security Scan

2013-04-24 06:15 . 2013-04-12 13:45 1211752 ----a-w- c:\windows\system32\drivers\ntfs.sys

2013-04-23 18:09 . 2013-04-23 18:08 706640 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{0FB24BE0-A4AE-4318-8FD9-AB86B2F5673C}\gapaengine.dll

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2013-05-15 14:16 . 2010-06-24 16:33 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll

2013-05-15 10:18 . 2012-03-31 16:57 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe

2013-05-15 10:18 . 2011-08-20 01:14 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2013-05-02 15:28 . 2010-08-13 04:45 238872 ------w- c:\windows\system32\MpSigStub.exe

2013-04-13 04:45 . 2013-05-15 04:13 474624 ----a-w- c:\windows\apppatch\AcSpecfc.dll

2013-04-13 04:45 . 2013-05-15 04:13 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll

2013-04-11 15:43 . 2013-04-11 15:43 94112 ----a-w- c:\windows\system32\WindowsAccessBridge.dll

2013-04-11 15:43 . 2012-06-18 13:44 861088 ----a-w- c:\windows\system32\npdeployJava1.dll

2013-04-11 15:43 . 2012-02-04 06:15 782240 ----a-w- c:\windows\system32\deployJava1.dll

2013-04-02 14:09 . 2013-04-02 14:09 4550656 ----a-w- c:\windows\system32\GPhotos.scr

2013-03-19 05:04 . 2013-04-10 08:53 3968856 ----a-w- c:\windows\system32\ntkrnlpa.exe

2013-03-19 05:04 . 2013-04-10 08:53 3913560 ----a-w- c:\windows\system32\ntoskrnl.exe

2013-03-19 04:48 . 2013-04-10 08:53 38912 ----a-w- c:\windows\system32\csrsrv.dll

2013-03-19 02:49 . 2013-04-10 08:53 69632 ----a-w- c:\windows\system32\smss.exe

2013-02-26 04:22 . 2013-02-26 04:22 1985824 ----a-w- c:\windows\system32\nvcuvenc.dll

2013-02-26 04:22 . 2012-10-11 02:14 1017120 ----a-w- c:\windows\system32\nvdispco32.dll

2013-02-26 04:22 . 2013-02-26 04:22 6262608 ----a-w- c:\windows\system32\nvopencl.dll

2013-02-26 04:22 . 2012-10-11 02:14 892704 ----a-w- c:\windows\system32\nvdispgenco32.dll

2013-02-26 04:22 . 2009-07-15 05:54 2505144 ----a-w- c:\windows\system32\nvapi.dll

2013-02-26 04:22 . 2009-07-13 22:09 12641992 ----a-w- c:\windows\system32\nvwgf2um.dll

2013-02-26 04:22 . 2009-06-10 21:19 15129960 ----a-w- c:\windows\system32\nvd3dum.dll

2013-02-26 04:22 . 2013-02-26 04:22 7932256 ----a-w- c:\windows\system32\nvcuda.dll

2013-02-26 04:22 . 2013-02-26 04:22 17560352 ----a-w- c:\windows\system32\nvcompiler.dll

2013-02-26 04:22 . 2013-02-26 04:22 20449056 ----a-w- c:\windows\system32\nvoglv32.dll

2013-02-26 04:22 . 2013-02-26 04:22 8939296 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys

2013-02-26 04:22 . 2013-02-26 04:22 2720544 ----a-w- c:\windows\system32\nvcuvid.dll

2013-05-15 16:10 . 2013-05-15 16:09 262552 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Partial]

@="{E300CD91-100F-4E67-9AF3-1384A6124015}"

[HKEY_CLASSES_ROOT\CLSID\{E300CD91-100F-4E67-9AF3-1384A6124015}]

2012-09-14 01:14 1014856 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Yellow]

@="{5E529433-B50E-4bef-A63B-16A6B71B071A}"

[HKEY_CLASSES_ROOT\CLSID\{5E529433-B50E-4bef-A63B-16A6B71B071A}]

2012-09-14 01:14 1014856 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]

@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]

2012-11-13 23:32 129272 ----a-w- c:\users\David\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]

@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]

2012-11-13 23:32 129272 ----a-w- c:\users\David\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]

@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]

2012-11-13 23:32 129272 ----a-w- c:\users\David\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]

"Aim"="c:\program files\AIM\aim.exe" [2012-05-30 4331392]

"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2010-11-20 144384]

"HPADVISOR"="c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2009-08-05 1644088]

"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-03-20 213936]

"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-07-19 451872]

"TivoServer"="c:\program files\TiVo\Desktop\TiVoServer.exe" [2010-08-24 2264336]

"TivoTransfer"="c:\program files\TiVo\Desktop\TiVoTransfer.exe" [2010-08-24 608528]

"TivoNotify"="c:\program files\TiVo\Desktop\TiVoNotify.exe" [2010-08-24 437520]

"TranscodingService"="c:\program files\TiVo\Desktop\Plus\\TranscodingService.exe" [2010-08-24 856336]

"Facebook Update"="c:\users\David\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2012-07-11 138096]

"Verizon Media Manager"="c:\program files\Verizon\Verizon Media Manager\Release\Verizon Media Manager.exe" [2012-10-10 1523712]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"AmazonGSDownloaderTray"="c:\program files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderTray.exe" [2009-02-02 246272]

"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-03-17 47392]

"CamserviceDP"="c:\program files\Hercules\Dualpix Infinite\Camservice.exe" [2008-09-26 345384]

"Corel Photo Downloader"="c:\program files\Corel\Corel MediaOne\Corel Photo Downloader.exe" [2007-08-17 483144]

"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]

"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-06-16 75008]

"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 65536]

"KBD"="c:\hp\KBD\KbdStub.EXE" [2006-12-08 65536]

"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2009-07-24 118640]

"OsdMaestro"="c:\program files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 118784]

"RtHDVCpl"="RtHDVCpl.exe" [2008-01-15 4874240]

"UVS11 Preload"="c:\program files\Ulead Systems\Ulead VideoStudio 11\uvPL.exe" [2007-07-23 341232]

"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2010-01-07 158448]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]

"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-01-28 59720]

"VERIZONDM"="c:\program files\VERIZONDM\bin\sprtcmd.exe" [2011-12-01 206120]

"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2010-06-10 49208]

"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-01-27 947152]

"navservice"="c:\program files\Navionics World\NavService.exe" [2012-04-29 40960]

"Carbonite Backup"="c:\program files\Carbonite\Carbonite Backup\CarboniteUI.exe" [2012-09-14 1065032]

"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2012-10-25 421888]

"DivXMediaServer"="c:\program files\DivX\DivX Media Server\DivXMediaServer.exe" [2012-11-13 450560]

"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2012-11-01 1263512]

"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2013-02-20 152392]

.

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

Amazon Unbox.lnk - c:\program files\Amazon\Amazon Unbox Video\ADVWindowsClientSystemTray.exe [2010-3-4 97384]

APC UPS Status.lnk - c:\program files\APC\APC PowerChute Personal Edition\Display.exe [2009-1-12 267520]

McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.0.318\SSScheduler.exe [2013-2-5 272248]

Secunia PSI Tray.lnk - c:\program files\Secunia\PSI\psi_tray.exe [2011-10-14 291896]

Snapfish Media Detector.lnk - c:\program files\Snapfish Picture Mover\SnapfishMediaDetector.exe [2007-5-7 1273856]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 5 (0x5)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]

@=""

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys]

@=""

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37Crusader]

@=""

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37CrusaderBoot]

@=""

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

@="Service"

.

R1 iugpaakq;iugpaakq;c:\windows\system32\drivers\iugpaakq.sys [x]

R2 Amazon Download Agent;Amazon Download Agent;c:\program files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe [x]

R2 gupdate1c9e8a748642a0;Google Update Service (gupdate1c9e8a748642a0);c:\program files\Google\Update\GoogleUpdate.exe [x]

R2 IntelDHSvcConf;Intel DH Service;c:\program files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe [x]

R2 IntuitUpdateServiceV4;Intuit Update Service v4;c:\program files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe [x]

R2 MBAMScheduler;MBAMScheduler;c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe [x]

R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [x]

R2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [x]

R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [x]

R3 DMService;Whale Component Manager;c:\windows\Downloaded Program Files\DMService.exe [x]

R3 FLMckUsb;AuthenTec TruePrint USB Driver for AES 3400, 3500, and 4000 Fingerprint Sensors;c:\windows\system32\DRIVERS\ATTchDrv.sys [x]

R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]

R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]

R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [x]

R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]

R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]

R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]

R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]

R3 whliocsv;Whale Network Connector Client;c:\program files\Whale Communications\Client Components\3.1.0\whliocsv.exe [x]

R3 xcbdaNtscV;ViXS Tuner Card (NTSC) - V;c:\windows\system32\DRIVERS\xcbdaV.sys [x]

R4 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\3.0.318\McCHSvc.exe [x]

R4 TivoBeacon2;TiVo Beacon Service;c:\program files\TiVo\Desktop\TiVoBeacon.exe [x]

S0 RapportKELL;RapportKELL;c:\windows\System32\Drivers\RapportKELL.sys [x]

S1 MpKsl6a8a6ab4;MpKsl6a8a6ab4;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{196A5639-8D5E-4973-A5B9-219028984806}\MpKsl6a8a6ab4.sys [x]

S1 NEOFLTR_710_19243;Juniper Networks TDI Filter Driver (NEOFLTR_710_19243);c:\windows\system32\Drivers\NEOFLTR_710_19243.SYS [x]

S1 RapportCerberus_51755;RapportCerberus_51755;c:\programdata\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus32_51755.sys [x]

S1 RapportEI;RapportEI;c:\program files\Trusteer\Rapport\bin\RapportEI.sys [x]

S1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [x]

S2 DQLWinService;DQLWinService;c:\program files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe [x]

S2 HPBtnSrv;HP Chasis Button Service;c:\hp\HPEZBTN\HPBtnSrv.exe [x]

S2 IHA_MessageCenter;IHA_MessageCenter;c:\program files\Verizon\IHA_MessageCenter\Bin\Verizon_IHAMessageCenter.exe [x]

S2 RapportMgmtService;Rapport Management Service;c:\program files\Trusteer\Rapport\bin\RapportMgmtService.exe [x]

S2 Secunia PSI Agent;Secunia PSI Agent;c:\program files\Secunia\PSI\PSIA.exe [x]

S2 Secunia Update Agent;Secunia Update Agent;c:\program files\Secunia\PSI\sua.exe [x]

S2 SplashtopRemoteService;Splashtop® Remote Service;c:\program files\Splashtop\Splashtop Remote\Server\SRService.exe [x]

S2 sprtsvc_verizondm;SupportSoft Sprocket Service (verizondm);c:\program files\VERIZONDM\bin\sprtsvc.exe [x]

S2 SSUService;Splashtop Software Updater Service;c:\program files\Splashtop\Splashtop Software Updater\SSUService.exe [x]

S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]

S2 tgsrvc_verizondm;SupportSoft Repair Service (verizondm);c:\program files\VERIZONDM\bin\tgsrvc.exe [x]

S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [x]

S3 camfilt2;camfilt2;c:\windows\system32\Drivers\camfilt2.sys [x]

S3 netr73;USB Wireless 802.11 b/g Adaptor Driver for Vista;c:\windows\system32\DRIVERS\netr73.sys [x]

S3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [x]

S3 VST_DPV;VST_DPV;c:\windows\system32\DRIVERS\VSTDPV3.SYS [x]

S3 VSTHWBS2;VSTHWBS2;c:\windows\system32\DRIVERS\VSTBS23.SYS [x]

.

.

--- Other Services/Drivers In Memory ---

.

*NewlyCreated* - MPKSL1A0619D6

*NewlyCreated* - MPKSL6A8A6AB4

*Deregistered* - MpKsl1a0619d6

*Deregistered* - NEOFLTR_650_14951

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS fdrespub AppIDSvc QWAVE wcncsvc Mcx2Svc SensrSvc

.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService

FontCache

.

.

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]

2013-04-11 17:59 1642448 ----a-w- c:\program files\Google\Chrome\Application\26.0.1410.64\Installer\chrmstp.exe

.

Contents of the 'Scheduled Tasks' folder

.

2013-05-16 c:\windows\Tasks\Adobe Flash Player Updater.job

- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-08 10:18]

.

2013-05-15 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1269665831-4724830-4121108689-1001Core.job

- c:\users\David\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-09-23 21:47]

.

2013-05-16 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1269665831-4724830-4121108689-1001UA.job

- c:\users\David\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-09-23 21:47]

.

2013-05-16 c:\windows\Tasks\Google Software Updater.job

- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-05-06 20:12]

.

2013-05-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-09 02:07]

.

2013-05-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-09 02:07]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www22.verizon.com/Foryourhome/MyAccount/Unprotected/UserManagement/Login/Login.aspx

mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=74&bd=Pavilion&pf=desktop

uInternet Settings,ProxyOverride = *.local

IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000

Trusted Zone: amazon.com\www

TCP: DhcpNameServer = 192.168.1.1

DPF: {115B1886-2AE0-4259-9FE4-E32A5DEE5451} - hxxp://www.wowweesupport.com/download/rovio/WebSee_4.0.cab

DPF: {71D413D7-38C5-4035-8548-976522CF11D5} - hxxp://www.crucial.com/controls/cpcVistaBeta.cab

FF - ProfilePath - c:\users\David\AppData\Roaming\Mozilla\Firefox\Profiles\s0lwqsxt.default\

FF - ExtSQL: !HIDDEN! 2010-11-12 23:40; {3112ca9c-de6d-4884-a869-9855de68056c}; c:\programdata\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c}

FF - ExtSQL: !HIDDEN! 2010-11-12 23:41; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension

FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false

.

- - - - ORPHANS REMOVED - - - -

.

ShellIconOverlayIdentifiers-{95A27763-F62A-4114-9072-E81D87DE3B68} - c:\users\David\Documents\7a8205fe.dll

HKU-Default-RunOnce-FlashPlayerUpdate - c:\windows\system32\Macromed\Flash\FlashUtil32_11_3_300_271_ActiveX.exe

AddRemove-CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200C14F1 - c:\program files\CONEXANT\CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200C14F1\UIU32m.exe

.

.

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]

@Denied: (2) (LocalSystem)

"{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc,

1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7

"{3049C3E9-B461-4BC5-8870-4C09146192CA}"=hex:51,66,7a,6c,4c,1d,38,12,87,c0,5a,

34,53,fa,ab,0e,f7,66,0f,49,11,3f,d6,de

"{72853161-30C5-4D22-B7F9-0BBC1D38A37E}"=hex:51,66,7a,6c,4c,1d,38,12,0f,32,96,

76,f7,7e,4c,08,c8,ef,48,fc,18,66,e7,6a

"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,

94,30,02,d1,0f,f1,da,12,24,73,56,27,d2

"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,

df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd

"{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}"=hex:51,66,7a,6c,4c,1d,38,12,8f,19,47,

2e,c4,15,0b,03,d7,b5,8c,e9,62,70,06,85

"{FF059E31-CC5A-4E2E-BF3B-96E929D65503}"=hex:51,66,7a,6c,4c,1d,38,12,5f,9d,16,

fb,68,82,40,0b,c0,2d,d5,a9,2c,88,11,17

.

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]

@Denied: (2) (LocalSystem)

"Timestamp"=hex:31,15,d1,74,6e,bf,cc,01

.

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]

@Denied: (2) (LocalSystem)

"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,

d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,b6,2e,8b,c1,7b,24,75,4a,bc,cb,3b,\

"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,

d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,b6,2e,8b,c1,7b,24,75,4a,bc,cb,3b,\

.

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="IE.AssocFile.HTM"

.

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="IE.AssocFile.HTM"

.

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mht\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="IE.AssocFile.MHT"

.

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mhtml\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="IE.AssocFile.MHT"

.

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.partial\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="IE.AssocFile.PARTIAL"

.

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.svg\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="IE.AssocFile.SVG"

.

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.url\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="IE.AssocFile.URL"

.

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.website\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="IE.AssocFile.WEBSITE"

.

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="IE.AssocFile.XHT"

.

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="IE.AssocFile.XHT"

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

Completion time: 2013-05-16 15:56:17

ComboFix-quarantined-files.txt 2013-05-16 19:56

.

Pre-Run: 247,970,365,440 bytes free

Post-Run: 249,474,576,384 bytes free

.

- - End Of File - - F173D783B71148EC2797D359BEF56CC6

Link to post
Share on other sites

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

Driver::

iugpaakq

File::

c:\windows\system32\drivers\iugpaakq.sys

JavaClearCache::

Save this as CFScript.txt, in the same location as ComboFix.exe

CFScriptB-4.gif

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

Link to post
Share on other sites

Hello Maniac,

CombFix.txt:

ComboFix 13-05-16.02 - David 05/16/2013 17:16:31.2.4 - x86

Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.3071.1479 [GMT -4:00]

Running from: c:\users\David\Desktop\ComboFix.exe

Command switches used :: c:\users\David\Desktop\CFScript.txt

AV: Microsoft Security Essentials *Disabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5}

SP: Microsoft Security Essentials *Disabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

FILE ::

"c:\windows\system32\drivers\iugpaakq.sys"

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\users\David\AppData\Roaming\Microsoft\Network\Connections\Pbk\_hiddenPbk

c:\users\David\AppData\Roaming\Microsoft\Network\Connections\Pbk\_hiddenPbk\rasphone.pbk

.

.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

-------\Service_iugpaakq

.

.

((((((((((((((((((((((((( Files Created from 2013-04-16 to 2013-05-16 )))))))))))))))))))))))))))))))

.

.

2013-05-16 21:28 . 2013-05-16 21:47 -------- d-----w- c:\users\David\AppData\Local\temp

2013-05-16 21:28 . 2013-05-16 21:34 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp

2013-05-16 21:28 . 2013-05-16 21:28 -------- d-----w- c:\users\Mcx1\AppData\Local\temp

2013-05-16 21:28 . 2013-05-16 21:28 -------- d-----w- c:\users\IUSR_NMPR\AppData\Local\temp

2013-05-16 14:23 . 2013-05-16 14:23 60872 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{196A5639-8D5E-4973-A5B9-219028984806}\offreg.dll

2013-05-16 14:23 . 2013-05-16 14:23 29904 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{196A5639-8D5E-4973-A5B9-219028984806}\MpKsl6a8a6ab4.sys

2013-05-16 14:19 . 2013-05-13 06:19 7016152 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{196A5639-8D5E-4973-A5B9-219028984806}\mpengine.dll

2013-05-15 21:52 . 2013-05-13 06:19 7016152 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll

2013-05-15 15:28 . 2013-05-15 15:28 -------- d-----w- C:\FRST

2013-05-15 07:28 . 2013-05-05 19:12 2382848 ----a-w- c:\windows\system32\mshtml.tlb

2013-05-15 04:13 . 2013-03-19 04:53 186368 ----a-w- c:\windows\system32\wwansvc.dll

2013-05-15 04:13 . 2013-03-19 03:33 40960 ----a-w- c:\windows\system32\wwanprotdim.dll

2013-05-15 04:13 . 2013-04-10 03:14 2347520 ----a-w- c:\windows\system32\win32k.sys

2013-05-15 04:13 . 2013-04-10 05:18 728424 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys

2013-05-15 04:13 . 2013-04-10 05:18 218984 ----a-w- c:\windows\system32\drivers\dxgmms1.sys

2013-05-15 04:13 . 2013-02-27 05:05 101720 ----a-w- c:\windows\system32\consent.exe

2013-05-15 04:13 . 2013-02-27 04:49 1796096 ----a-w- c:\windows\system32\authui.dll

2013-05-15 04:13 . 2013-02-27 04:49 47104 ----a-w- c:\windows\system32\appinfo.dll

2013-05-15 01:46 . 2013-05-15 01:46 -------- d-----w- c:\users\David\AppData\Roaming\Malwarebytes

2013-05-15 01:46 . 2013-05-15 01:46 -------- d-----w- c:\programdata\Malwarebytes

2013-05-15 01:46 . 2013-05-15 01:46 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2013-05-15 01:46 . 2013-04-04 18:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys

2013-05-15 01:45 . 2013-05-15 01:45 -------- d-----w- c:\users\David\AppData\Local\Programs

2013-05-14 23:37 . 2013-05-14 23:37 -------- d-----w- c:\program files\HitmanPro

2013-05-14 22:37 . 2013-05-15 00:36 -------- d-----w- c:\programdata\HitmanPro

2013-04-30 05:28 . 2013-04-30 05:28 102448 ----a-w- c:\windows\system32\drivers\RapportKELL.sys

2013-04-29 19:20 . 2013-04-29 19:20 -------- d-----w- c:\users\David\AppData\Local\Macromedia

2013-04-29 18:41 . 2013-04-29 18:41 -------- d-----w- c:\programdata\McAfee Security Scan

2013-04-29 18:41 . 2013-05-04 01:32 -------- d-----w- c:\program files\McAfee Security Scan

2013-04-24 06:15 . 2013-04-12 13:45 1211752 ----a-w- c:\windows\system32\drivers\ntfs.sys

2013-04-23 18:09 . 2013-04-23 18:08 706640 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{0FB24BE0-A4AE-4318-8FD9-AB86B2F5673C}\gapaengine.dll

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2013-05-15 14:16 . 2010-06-24 16:33 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll

2013-05-15 10:18 . 2012-03-31 16:57 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe

2013-05-15 10:18 . 2011-08-20 01:14 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2013-05-02 15:28 . 2010-08-13 04:45 238872 ------w- c:\windows\system32\MpSigStub.exe

2013-04-13 04:45 . 2013-05-15 04:13 474624 ----a-w- c:\windows\apppatch\AcSpecfc.dll

2013-04-13 04:45 . 2013-05-15 04:13 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll

2013-04-11 15:43 . 2013-04-11 15:43 94112 ----a-w- c:\windows\system32\WindowsAccessBridge.dll

2013-04-11 15:43 . 2012-06-18 13:44 861088 ----a-w- c:\windows\system32\npdeployJava1.dll

2013-04-11 15:43 . 2012-02-04 06:15 782240 ----a-w- c:\windows\system32\deployJava1.dll

2013-04-02 14:09 . 2013-04-02 14:09 4550656 ----a-w- c:\windows\system32\GPhotos.scr

2013-03-19 05:04 . 2013-04-10 08:53 3968856 ----a-w- c:\windows\system32\ntkrnlpa.exe

2013-03-19 05:04 . 2013-04-10 08:53 3913560 ----a-w- c:\windows\system32\ntoskrnl.exe

2013-03-19 04:48 . 2013-04-10 08:53 38912 ----a-w- c:\windows\system32\csrsrv.dll

2013-03-19 02:49 . 2013-04-10 08:53 69632 ----a-w- c:\windows\system32\smss.exe

2013-02-26 04:22 . 2013-02-26 04:22 1985824 ----a-w- c:\windows\system32\nvcuvenc.dll

2013-02-26 04:22 . 2012-10-11 02:14 1017120 ----a-w- c:\windows\system32\nvdispco32.dll

2013-02-26 04:22 . 2013-02-26 04:22 6262608 ----a-w- c:\windows\system32\nvopencl.dll

2013-02-26 04:22 . 2012-10-11 02:14 892704 ----a-w- c:\windows\system32\nvdispgenco32.dll

2013-02-26 04:22 . 2009-07-15 05:54 2505144 ----a-w- c:\windows\system32\nvapi.dll

2013-02-26 04:22 . 2009-07-13 22:09 12641992 ----a-w- c:\windows\system32\nvwgf2um.dll

2013-02-26 04:22 . 2009-06-10 21:19 15129960 ----a-w- c:\windows\system32\nvd3dum.dll

2013-02-26 04:22 . 2013-02-26 04:22 7932256 ----a-w- c:\windows\system32\nvcuda.dll

2013-02-26 04:22 . 2013-02-26 04:22 17560352 ----a-w- c:\windows\system32\nvcompiler.dll

2013-02-26 04:22 . 2013-02-26 04:22 20449056 ----a-w- c:\windows\system32\nvoglv32.dll

2013-02-26 04:22 . 2013-02-26 04:22 8939296 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys

2013-02-26 04:22 . 2013-02-26 04:22 2720544 ----a-w- c:\windows\system32\nvcuvid.dll

2013-05-15 16:10 . 2013-05-15 16:09 262552 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Partial]

@="{E300CD91-100F-4E67-9AF3-1384A6124015}"

[HKEY_CLASSES_ROOT\CLSID\{E300CD91-100F-4E67-9AF3-1384A6124015}]

2012-09-14 01:14 1014856 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Yellow]

@="{5E529433-B50E-4bef-A63B-16A6B71B071A}"

[HKEY_CLASSES_ROOT\CLSID\{5E529433-B50E-4bef-A63B-16A6B71B071A}]

2012-09-14 01:14 1014856 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]

@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]

2012-11-13 23:32 129272 ----a-w- c:\users\David\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]

@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]

2012-11-13 23:32 129272 ----a-w- c:\users\David\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]

@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]

2012-11-13 23:32 129272 ----a-w- c:\users\David\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]

"Aim"="c:\program files\AIM\aim.exe" [2012-05-30 4331392]

"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2010-11-20 144384]

"HPADVISOR"="c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2009-08-05 1644088]

"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-03-20 213936]

"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-07-19 451872]

"TivoServer"="c:\program files\TiVo\Desktop\TiVoServer.exe" [2010-08-24 2264336]

"TivoTransfer"="c:\program files\TiVo\Desktop\TiVoTransfer.exe" [2010-08-24 608528]

"TivoNotify"="c:\program files\TiVo\Desktop\TiVoNotify.exe" [2010-08-24 437520]

"TranscodingService"="c:\program files\TiVo\Desktop\Plus\\TranscodingService.exe" [2010-08-24 856336]

"Facebook Update"="c:\users\David\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2012-07-11 138096]

"Verizon Media Manager"="c:\program files\Verizon\Verizon Media Manager\Release\Verizon Media Manager.exe" [2012-10-10 1523712]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"AmazonGSDownloaderTray"="c:\program files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderTray.exe" [2009-02-02 246272]

"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-03-17 47392]

"CamserviceDP"="c:\program files\Hercules\Dualpix Infinite\Camservice.exe" [2008-09-26 345384]

"Corel Photo Downloader"="c:\program files\Corel\Corel MediaOne\Corel Photo Downloader.exe" [2007-08-17 483144]

"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]

"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-06-16 75008]

"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 65536]

"KBD"="c:\hp\KBD\KbdStub.EXE" [2006-12-08 65536]

"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2009-07-24 118640]

"OsdMaestro"="c:\program files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 118784]

"RtHDVCpl"="RtHDVCpl.exe" [2008-01-15 4874240]

"UVS11 Preload"="c:\program files\Ulead Systems\Ulead VideoStudio 11\uvPL.exe" [2007-07-23 341232]

"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2010-01-07 158448]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]

"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-01-28 59720]

"VERIZONDM"="c:\program files\VERIZONDM\bin\sprtcmd.exe" [2011-12-01 206120]

"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2010-06-10 49208]

"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-01-27 947152]

"navservice"="c:\program files\Navionics World\NavService.exe" [2012-04-29 40960]

"Carbonite Backup"="c:\program files\Carbonite\Carbonite Backup\CarboniteUI.exe" [2012-09-14 1065032]

"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2012-10-25 421888]

"DivXMediaServer"="c:\program files\DivX\DivX Media Server\DivXMediaServer.exe" [2012-11-13 450560]

"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2012-11-01 1263512]

"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2013-02-20 152392]

.

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

Amazon Unbox.lnk - c:\program files\Amazon\Amazon Unbox Video\ADVWindowsClientSystemTray.exe [2010-3-4 97384]

APC UPS Status.lnk - c:\program files\APC\APC PowerChute Personal Edition\Display.exe [2009-1-12 267520]

McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.0.318\SSScheduler.exe [2013-2-5 272248]

Secunia PSI Tray.lnk - c:\program files\Secunia\PSI\psi_tray.exe [2011-10-14 291896]

Snapfish Media Detector.lnk - c:\program files\Snapfish Picture Mover\SnapfishMediaDetector.exe [2007-5-7 1273856]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 5 (0x5)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]

@=""

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys]

@=""

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37Crusader]

@=""

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37CrusaderBoot]

@=""

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

@="Service"

.

R2 gupdate1c9e8a748642a0;Google Update Service (gupdate1c9e8a748642a0);c:\program files\Google\Update\GoogleUpdate.exe [x]

R2 IntelDHSvcConf;Intel DH Service;c:\program files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe [x]

R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [x]

R3 DMService;Whale Component Manager;c:\windows\Downloaded Program Files\DMService.exe [x]

R3 FLMckUsb;AuthenTec TruePrint USB Driver for AES 3400, 3500, and 4000 Fingerprint Sensors;c:\windows\system32\DRIVERS\ATTchDrv.sys [x]

R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]

R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [x]

R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]

R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]

R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]

R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]

R3 whliocsv;Whale Network Connector Client;c:\program files\Whale Communications\Client Components\3.1.0\whliocsv.exe [x]

R3 xcbdaNtscV;ViXS Tuner Card (NTSC) - V;c:\windows\system32\DRIVERS\xcbdaV.sys [x]

R4 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\3.0.318\McCHSvc.exe [x]

R4 TivoBeacon2;TiVo Beacon Service;c:\program files\TiVo\Desktop\TiVoBeacon.exe [x]

S0 RapportKELL;RapportKELL;c:\windows\System32\Drivers\RapportKELL.sys [x]

S1 MpKsl6a8a6ab4;MpKsl6a8a6ab4;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{196A5639-8D5E-4973-A5B9-219028984806}\MpKsl6a8a6ab4.sys [x]

S1 NEOFLTR_710_19243;Juniper Networks TDI Filter Driver (NEOFLTR_710_19243);c:\windows\system32\Drivers\NEOFLTR_710_19243.SYS [x]

S1 RapportCerberus_51755;RapportCerberus_51755;c:\programdata\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus32_51755.sys [x]

S1 RapportEI;RapportEI;c:\program files\Trusteer\Rapport\bin\RapportEI.sys [x]

S1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [x]

S2 Amazon Download Agent;Amazon Download Agent;c:\program files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe [x]

S2 DQLWinService;DQLWinService;c:\program files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe [x]

S2 HPBtnSrv;HP Chasis Button Service;c:\hp\HPEZBTN\HPBtnSrv.exe [x]

S2 IHA_MessageCenter;IHA_MessageCenter;c:\program files\Verizon\IHA_MessageCenter\Bin\Verizon_IHAMessageCenter.exe [x]

S2 IntuitUpdateServiceV4;Intuit Update Service v4;c:\program files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe [x]

S2 MBAMScheduler;MBAMScheduler;c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe [x]

S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [x]

S2 RapportMgmtService;Rapport Management Service;c:\program files\Trusteer\Rapport\bin\RapportMgmtService.exe [x]

S2 Secunia PSI Agent;Secunia PSI Agent;c:\program files\Secunia\PSI\PSIA.exe [x]

S2 Secunia Update Agent;Secunia Update Agent;c:\program files\Secunia\PSI\sua.exe [x]

S2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [x]

S2 SplashtopRemoteService;Splashtop® Remote Service;c:\program files\Splashtop\Splashtop Remote\Server\SRService.exe [x]

S2 sprtsvc_verizondm;SupportSoft Sprocket Service (verizondm);c:\program files\VERIZONDM\bin\sprtsvc.exe [x]

S2 SSUService;Splashtop Software Updater Service;c:\program files\Splashtop\Splashtop Software Updater\SSUService.exe [x]

S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]

S2 tgsrvc_verizondm;SupportSoft Repair Service (verizondm);c:\program files\VERIZONDM\bin\tgsrvc.exe [x]

S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [x]

S3 camfilt2;camfilt2;c:\windows\system32\Drivers\camfilt2.sys [x]

S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]

S3 netr73;USB Wireless 802.11 b/g Adaptor Driver for Vista;c:\windows\system32\DRIVERS\netr73.sys [x]

S3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [x]

S3 VST_DPV;VST_DPV;c:\windows\system32\DRIVERS\VSTDPV3.SYS [x]

S3 VSTHWBS2;VSTHWBS2;c:\windows\system32\DRIVERS\VSTBS23.SYS [x]

.

.

--- Other Services/Drivers In Memory ---

.

*NewlyCreated* - WS2IFSL

*Deregistered* - NEOFLTR_650_14951

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS fdrespub AppIDSvc QWAVE wcncsvc Mcx2Svc SensrSvc

.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService

FontCache

.

.

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]

2013-04-11 17:59 1642448 ----a-w- c:\program files\Google\Chrome\Application\26.0.1410.64\Installer\chrmstp.exe

.

Contents of the 'Scheduled Tasks' folder

.

2013-05-16 c:\windows\Tasks\Adobe Flash Player Updater.job

- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-08 10:18]

.

2013-05-15 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1269665831-4724830-4121108689-1001Core.job

- c:\users\David\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-09-23 21:47]

.

2013-05-16 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1269665831-4724830-4121108689-1001UA.job

- c:\users\David\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-09-23 21:47]

.

2013-05-16 c:\windows\Tasks\Google Software Updater.job

- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-05-06 20:12]

.

2013-05-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-09 02:07]

.

2013-05-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-09 02:07]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www22.verizon.com/Foryourhome/MyAccount/Unprotected/UserManagement/Login/Login.aspx

mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=74&bd=Pavilion&pf=desktop

uInternet Settings,ProxyOverride = *.local

IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000

Trusted Zone: amazon.com\www

TCP: DhcpNameServer = 192.168.1.1

DPF: {115B1886-2AE0-4259-9FE4-E32A5DEE5451} - hxxp://www.wowweesupport.com/download/rovio/WebSee_4.0.cab

DPF: {71D413D7-38C5-4035-8548-976522CF11D5} - hxxp://www.crucial.com/controls/cpcVistaBeta.cab

FF - ProfilePath - c:\users\David\AppData\Roaming\Mozilla\Firefox\Profiles\s0lwqsxt.default\

FF - ExtSQL: !HIDDEN! 2010-11-12 23:40; {3112ca9c-de6d-4884-a869-9855de68056c}; c:\programdata\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c}

FF - ExtSQL: !HIDDEN! 2010-11-12 23:41; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension

FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false

.

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]

@Denied: (2) (LocalSystem)

"{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc,

1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7

"{3049C3E9-B461-4BC5-8870-4C09146192CA}"=hex:51,66,7a,6c,4c,1d,38,12,87,c0,5a,

34,53,fa,ab,0e,f7,66,0f,49,11,3f,d6,de

"{72853161-30C5-4D22-B7F9-0BBC1D38A37E}"=hex:51,66,7a,6c,4c,1d,38,12,0f,32,96,

76,f7,7e,4c,08,c8,ef,48,fc,18,66,e7,6a

"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,

94,30,02,d1,0f,f1,da,12,24,73,56,27,d2

"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,

df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd

"{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}"=hex:51,66,7a,6c,4c,1d,38,12,8f,19,47,

2e,c4,15,0b,03,d7,b5,8c,e9,62,70,06,85

"{FF059E31-CC5A-4E2E-BF3B-96E929D65503}"=hex:51,66,7a,6c,4c,1d,38,12,5f,9d,16,

fb,68,82,40,0b,c0,2d,d5,a9,2c,88,11,17

.

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]

@Denied: (2) (LocalSystem)

"Timestamp"=hex:31,15,d1,74,6e,bf,cc,01

.

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]

@Denied: (2) (LocalSystem)

"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,

d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,b6,2e,8b,c1,7b,24,75,4a,bc,cb,3b,\

"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,

d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,b6,2e,8b,c1,7b,24,75,4a,bc,cb,3b,\

.

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="IE.AssocFile.HTM"

.

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="IE.AssocFile.HTM"

.

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mht\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="IE.AssocFile.MHT"

.

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mhtml\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="IE.AssocFile.MHT"

.

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.partial\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="IE.AssocFile.PARTIAL"

.

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.svg\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="IE.AssocFile.SVG"

.

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.url\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="IE.AssocFile.URL"

.

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.website\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="IE.AssocFile.WEBSITE"

.

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="IE.AssocFile.XHT"

.

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="IE.AssocFile.XHT"

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

--------------------- DLLs Loaded Under Running Processes ---------------------

.

- - - - - - - > 'Explorer.exe'(5208)

c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll

c:\users\David\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll

.

------------------------ Other Running Processes ------------------------

.

c:\windows\system32\nvvsvc.exe

c:\program files\Microsoft Security Client\MsMpEng.exe

c:\program files\NVIDIA Corporation\Display\nvxdsync.exe

c:\windows\system32\nvvsvc.exe

c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe

c:\program files\APC\APC PowerChute Personal Edition\mainserv.exe

c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe

c:\program files\Bonjour\mDNSResponder.exe

c:\program files\Common Files\InterVideo\DeviceService\DevSvc.exe

c:\program files\Carbonite\Carbonite Backup\carboniteservice.exe

c:\program files\Juniper Networks\Common Files\dsNcService.exe

c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe

c:\program files\Common Files\LightScribe\LSSrvc.exe

c:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe

c:\program files\Microsoft LifeCam\MSCamS32.exe

c:\windows\system32\PSIService.exe

c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe

c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe

c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

c:\program files\Amazon\Amazon Unbox Video\ADVWindowsClientService.exe

c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe

c:\windows\System32\WUDFHost.exe

c:\program files\Hewlett-Packard\HP Health Check\hphc_service.exe

c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe

c:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe

c:\program files\Windows Media Player\wmpnetwk.exe

c:\windows\system32\taskhost.exe

c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe

c:\program files\Splashtop\Splashtop Remote\Server\SRServer.exe

c:\program files\Splashtop\Splashtop Remote\Server\SRFeature.exe

c:\windows\system32\conhost.exe

c:\program files\Splashtop\Splashtop Remote\Server\DataProxy.exe

c:\windows\system32\conhost.exe

c:\program files\NVIDIA Corporation\Display\nvtray.exe

c:\windows\system32\DllHost.exe

.

**************************************************************************

.

Completion time: 2013-05-16 17:51:37 - machine was rebooted

ComboFix-quarantined-files.txt 2013-05-16 21:51

ComboFix2.txt 2013-05-16 19:56

.

Pre-Run: 249,372,893,184 bytes free

Post-Run: 249,835,413,504 bytes free

.

- - End Of File - - 574D41792E787D886F22A165DC211D96

Regards, dave

Link to post
Share on other sites

Please scan your machine with ESET OnlineScan

  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the esetonlinebtn.png button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on esetsmartinstaller_enu.exe to download the ESET Smart Installer.
      Save it to your Desktop.
    • Double click on the esetsmartinstaller_enu.png to download the ESET Smart Installer. icon on your Desktop.

    [*]Check "YES, I accept the Terms of Use."

    [*]Click the Start button.

    [*]Accept any security warnings from your browser.

    [*]Under Scan Settings, check "Scan Archives" and "Remove found threats"

    [*]Click Advanced settings and select the following:

    • Scan potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology

    [*]ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.

    [*]When the scan completes, click List Threats

    [*]Click Export, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.

    [*]Click the Back button.

    [*]Click the Finish button.

Link to post
Share on other sites

Maniac,

This took most the night to run, but it did and here's the results:

C:\FRST\Quarantine\7a8205fe.dll a variant of Win32/Kryptik.BBAO trojan cleaned by deleting - quarantined

C:\Program Files\FoxTabVideoConverter\VideoConverter.exe a variant of Win32/SweetIM.B application cleaned by deleting - quarantined

C:\Users\David\Documents\downloads\VideoConverter\VideoConverterSetup.exe a variant of Win32/SweetIM.B application cleaned by deleting - quarantined

F:\carbonite restore\Toni\Desktop\aim\Install_AIM.exe Win32/Adware.WBug.A application cleaned by deleting - quarantined

F:\Local Disk\Documents and Settings\David\David\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-6b13a7e7-4fb08c46.zip probably a variant of Win32/Agent.JHBSDMY trojan cleaned by deleting - quarantined

F:\Local Disk\Documents and Settings\Toni.MAINPC\Desktop\aim\Install_AIM.exe Win32/Adware.WBug.A application cleaned by deleting - quarantined

G:\Documents and Settings\David\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-6b13a7e7-4fb08c46.zip probably a variant of Win32/Agent.JHBSDMY trojan cleaned by deleting - quarantined

G:\Documents and Settings\David\tonihold\Desktop\aim\Install_AIM.exe Win32/Adware.WBug.A application cleaned by deleting - quarantined

G:\Documents and Settings\Toni.MAINPC\Desktop\aim\Install_AIM.exe Win32/Adware.WBug.A application cleaned by deleting - quarantined

G:\Program Files\AIM\Sysfiles\WxBug.EXE Win32/Adware.WBug.A application cleaned by deleting - quarantined

M:\carbonite restore\Toni\Desktop\aim\Install_AIM.exe Win32/Adware.WBug.A application cleaned by deleting - quarantined

M:\DadLaptop\backup\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7U04AC12\upgrade[1].cab multiple threats deleted - quarantined

M:\DadLaptop\backup\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7U04AC12\upgrade[2].cab multiple threats deleted - quarantined

M:\DadLaptop\backup\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GZVMJSTG\upgrade[1].cab multiple threats deleted - quarantined

M:\DadLaptop\backup\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GZVMJSTG\upgrade[2].cab multiple threats deleted - quarantined

M:\DadLaptop\backup\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GZVMJSTG\upgrade[3].cab multiple threats deleted - quarantined

M:\DadLaptop\backup\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GZVMJSTG\upgrade[4].cab multiple threats deleted - quarantined

M:\DadLaptop\backup\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\L2DZJCEV\upgrade[1].cab multiple threats deleted - quarantined

M:\DadLaptop\backup\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\L2DZJCEV\upgrade[2].cab multiple threats deleted - quarantined

M:\DadLaptop\backup\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SF2N43G0\upgrade[1].cab Win32/Adware.OneStep application deleted - quarantined

M:\DadLaptop\backup\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SF2N43G0\upgrade[2].cab multiple threats deleted - quarantined

M:\DadLaptop\backup\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SF2N43G0\upgrade[3].cab multiple threats deleted - quarantined

M:\DadLaptop\backup\Dixmith\Documents\PERSONAL\CouponPrinter.exe probably a variant of Win32/Adware.Softomate.AD application cleaned by deleting - quarantined

M:\DadLaptop\backup\Dixmith\Downloads\regtool.exe a variant of Win32/Adware.ErrorRepair application cleaned by deleting - quarantined

M:\DadLaptop\backup\Dixmith\Downloads\setup.exe a variant of Win32/Adware.ErrorRepair application cleaned by deleting - quarantined

M:\DadLaptop\backup\Dixmith\Downloads\WeatherBugSetup.msi a variant of Win32/Bundled.Toolbar.Ask.A application deleted - quarantined

M:\DadLaptop\backup\Dixmith\Pictures\Pictures Downloaded from AOL\regtool.exe a variant of Win32/Adware.ErrorRepair application cleaned by deleting - quarantined

M:\DadLaptop\backup\laptop C\SQ004829V03\$RECYCLE.BIN\S-1-5-21-737594619-1414829202-3786626943-1000\$RF748FP.tmp multiple threats cleaned by deleting - quarantined

M:\DadLaptop\backup\laptop C\SQ004829V03\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7U04AC12\upgrade[1].cab multiple threats deleted - quarantined

M:\DadLaptop\backup\laptop C\SQ004829V03\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7U04AC12\upgrade[2].cab multiple threats deleted - quarantined

M:\DadLaptop\backup\laptop C\SQ004829V03\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GZVMJSTG\upgrade[1].cab multiple threats deleted - quarantined

M:\DadLaptop\backup\laptop C\SQ004829V03\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GZVMJSTG\upgrade[2].cab multiple threats deleted - quarantined

M:\DadLaptop\backup\laptop C\SQ004829V03\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GZVMJSTG\upgrade[3].cab multiple threats deleted - quarantined

M:\DadLaptop\backup\laptop C\SQ004829V03\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GZVMJSTG\upgrade[4].cab multiple threats deleted - quarantined

M:\DadLaptop\backup\laptop C\SQ004829V03\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\L2DZJCEV\upgrade[1].cab multiple threats deleted - quarantined

M:\DadLaptop\backup\laptop C\SQ004829V03\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\L2DZJCEV\upgrade[2].cab multiple threats deleted - quarantined

M:\DadLaptop\backup\laptop C\SQ004829V03\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SF2N43G0\upgrade[1].cab Win32/Adware.OneStep application deleted - quarantined

M:\DadLaptop\backup\laptop C\SQ004829V03\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SF2N43G0\upgrade[2].cab multiple threats deleted - quarantined

M:\DadLaptop\backup\laptop C\SQ004829V03\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SF2N43G0\upgrade[3].cab multiple threats deleted - quarantined

M:\DadLaptop\backup\laptop C\users\All Users\Microsoft\Windows\Start Menu\Programs\Hotbar\About Hotbar.lnk LNK/URL.B trojan cleaned by deleting - quarantined

M:\DadLaptop\backup\laptop C\users\All Users\Microsoft\Windows\Start Menu\Programs\Hotbar\Hotbar Customer Support Center.lnk LNK/URL.B trojan cleaned by deleting - quarantined

M:\DadLaptop\backup\laptop C\users\All Users\Microsoft\Windows\Start Menu\Programs\Hotbar\Hotbar Games!.lnk LNK/URL.B trojan cleaned by deleting - quarantined

M:\DadLaptop\backup\laptop C\users\All Users\Microsoft\Windows\Start Menu\Programs\Hotbar\Hotbar Videos!.lnk LNK/URL.B trojan cleaned by deleting - quarantined

M:\DadLaptop\backup\Program Files\AWS\WeatherBug\Local\askToolbarInstaller-1.5.0.0.exe a variant of Win32/Bundled.Toolbar.Ask.A application cleaned by deleting - quarantined

M:\DadLaptop\backup\Program Files\Downloaded Installers\{33E52066-2FD2-4942-9A8B-FDDEC8BA0A32}\setup.msi a variant of Win32/Adware.ErrorRepair application deleted - quarantined

M:\DadLaptop\backup\Program Files\Hotbar\bin\11.0.78.0\HotbarSADF.exe Win32/Adware.HotBar.E application cleaned by deleting - quarantined

M:\DadLaptop\backup\Program Files\Hotbar\bin\11.0.78.0\HotbarUninstaller.exe multiple threats cleaned by deleting - quarantined

M:\DadLaptop\backup\Program Files\Reg Tool\Reg Tool.exe a variant of Win32/Adware.ErrorRepair application cleaned by deleting - quarantined

M:\DadLaptop\backup\Program Files\ShoppingReport\Uninst.exe Win32/Adware.ShopperReports application cleaned by deleting - quarantined

M:\DadLaptop\backup\ProgramData\Microsoft\Windows\Start Menu\Programs\Hotbar\About Hotbar.lnk LNK/URL.B trojan cleaned by deleting - quarantined

M:\DadLaptop\backup\ProgramData\Microsoft\Windows\Start Menu\Programs\Hotbar\Hotbar Customer Support Center.lnk LNK/URL.B trojan cleaned by deleting - quarantined

M:\DadLaptop\backup\ProgramData\Microsoft\Windows\Start Menu\Programs\Hotbar\Hotbar Games!.lnk LNK/URL.B trojan cleaned by deleting - quarantined

M:\DadLaptop\backup\ProgramData\Microsoft\Windows\Start Menu\Programs\Hotbar\Hotbar Videos!.lnk LNK/URL.B trojan cleaned by deleting - quarantined

Regards, dave

Link to post
Share on other sites

Step 1

javaicon.gif Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older versions of Java components and upgrade the application.

Upgrading Java :

Please download JavaRa to your desktop and unzip it to its own folder

  • Run JavaRa.exe, then click Remove JRE.
  • Run the built-in uninstallers for all copies of java listed
  • Click the Next button
  • Click the Next button again
  • Click the Java Manual Download link
  • A browser window will open with the Java download page
  • Click the Windows Offline (32-bit) or Windows Offline (64-bit) link to download Java (based on your browser type)
  • Run the installer
  • Close JavaRa

Step 2

Download TFC to your desktop

  • Open the file and close any other windows.
  • It will close all programs itself when run, make sure to let it run uninterrupted.
  • Click the Start button to begin the process. The program should not take long to finish its job
  • Once its finished it should reboot your machine, if not, do this yourself to ensure a complete clean

Step 3

Download AVPTool from Here to your desktop

Run the programme you have just downloaded to your desktop (it will be randomly named)

Click the cog in the upper right

AVPfront.gif

Select down to and including your main drive, once done select the Automatic scan tab and press Start Scan

avpsettings.gif

Allow AVP to delete all infections found

Once it has finished select report tab (last tab)

Select Detected threads report from the left and press Save button

Save it to your desktop and post it in your next reply.

Link to post
Share on other sites

Hello Maniac,

That took a while, 36 hr for Kaspersky, here's the report:

Status: Deleted (events: 7)

5/18/2013 8:29:21 PM Deleted unknown threat UDS:DangerousObject.Multi.Generic M:\DadLaptop\backup\Dixmith\Documents\Legal Docs\authorizations.dlb High

5/18/2013 8:29:36 PM Deleted adware not-a-virus:AdWare.Win32.HotBar.dh M:\DadLaptop\backup\Program Files\Hotbar\bin\11.0.78.0\LaunchHelp.dll Medium

5/18/2013 8:29:35 PM Deleted adware not-a-virus:AdWare.Win32.HotBar.dh M:\DadLaptop\backup\Program Files\Hotbar\bin\11.0.78.0\Weather.exe Medium

5/18/2013 8:29:46 PM Deleted adware not-a-virus:AdWare.Win32.HotBar.dh M:\DadLaptop\backup\Program Files\Hotbar\bin\11.0.78.0\WeSkin.dll Medium

5/18/2013 8:35:31 PM Deleted Trojan program Trojan-FakeAV.MSIL.PCMightyMax.d M:\DadLaptop\backup\Program Files\PC MightyMax 2009\pcmm2009.exe High

5/18/2013 8:35:31 PM Deleted Trojan program Trojan-FakeAV.MSIL.PCMightyMax.a M:\DadLaptop\backup\Program Files\PC MightyMax 2009\Core.dll High

5/18/2013 8:36:17 PM Deleted Trojan program Trojan-FakeAV.Win32.RegTool.a M:\DadLaptop\backup\Program Files\Reg Tool\Reg Tool.url High

regards, - Dave

Link to post
Share on other sites

If you would like one last scan:

Please download DrWeb-CureIt and save it to your Desktop. Do NOT perform a scan yet

  • Double-click on drweb-cureit.exe to start the program.
    An Express Scan of your PC notice will appear.
  • Under Start the Express Scan Now, Click OK to start the scan.
    This is a short scan that will scan the files currently running in memory.
    If something is found, click the Yes button when it asks you if you want to cure it.
  • Once the short scan has finished, Click Options > Change settings
  • Choose the Scan tab and UNcheck Heuristic analysis
  • Back at the main window, click Custom Scan, then Select drives (a red dot will show which drives have been chosen).
  • Then click the Start/Stop Scanning button (green arrow on the right, and the scan will start.
  • When finished, a message will be displayed at the bottom advising if any viruses were found.
  • Click Yes to all if it asks if you want to cure/move the file.
  • When the scan has finished, look if you can see the icon next to the files found.
    If so, click it, then click the next icon right below and select Move incurable.
    (This will move it to the C:\Documents and Settings\userprofile\DoctorWeb\Quarantine folder if it can't be cured)
  • Next, in the Dr.Web CureIt menu on top, click file and choose save report list.
  • Save the DrWeb.csv report to your Desktop.
  • Exit Dr.Web Cureit when you have finished.
  • Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web in your next reply. (You can use Notepad to open the DrWeb.cvs report)

Link to post
Share on other sites

Hello Maniac,

Dr Web doesn’t provide all the options you specified. I ran the Express Scan and a custom scan with most options selected. There was no reporting function although I did find a cureit.log in the Doctor Web folder. The entire log is over 10Mb and I have unable to include all the text. Here are the bottom contents of this log:

Total 1252644944604 bytes in 765201 files scanned (2312189 objects)

Total 764907 files (2311854 objects) are clean

Total 27 files are infected

Total 10 files (16 objects) are suspicious

Total 166 files are raised error condition

Scan time is 06:11:33.740

-----------------------------------------------------------------------------

Start curing

-----------------------------------------------------------------------------

c:\program files\verizondm\bin\sprtsync.dll - quarantined, reboot required

c:\program files\verizondm\bin\sprtupdate.dll - quarantined, reboot required

G:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1058\A0044868.exe - deleted

G:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1058\A0044884.exe - deleted

G:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1058\A0044902.exe - deleted

G:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1058\A0044941.exe - deleted

G:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1058\A0044995.exe - deleted

G:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1058\A0045017.exe - deleted

G:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1058\A0045039.exe - deleted

G:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1058\A0045061.exe - deleted

G:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1058\A0045089.rbf - deleted

C:\Program Files\HP Games\Cake Mania\SlgClientServicesRedists.exe - quarantined

C:\Program Files\HP Games\Super Granny 3\SlgClientServicesRedists.exe - quarantined

C:\Program Files\Online Services\Aolca\comps\acs\acssetup.exe - quarantined

C:\Program Files\Online Services\Netscape_ca\Setup.exe - quarantined

C:\Users\David\AppData\Local\Citrix\GoToMyPC\gotomypc_540.exe - incurable, quarantined

C:\Windows\VzInHomeAgentInstaller.msi - quarantined

C:\Windows\Installer\7e5d23.msi - quarantined

C:\Windows\Installer\MSIA85C.tmp - incurable, quarantined

D:\PRELOAD\74NAv3PrA418.wim - quarantined

D:\PRELOAD\74NAv3PrA424.wim - quarantined

D:\PRELOAD\74NAv3PrA426.wim - quarantined

D:\hp\apps\APP23288\src\install\English\games\cakemania-setup.exe - quarantined

D:\hp\apps\APP23288\src\install\English\games\supergranny3-setup.exe - quarantined

D:\hp\apps\APP23288\src\install\Spanish\games\cakemania-setup.exe - quarantined

D:\hp\apps\APP23288\src\install\Spanish\games\grannyinparadise-setup.exe - quarantined

D:\hp\apps\APP23288\src\install\Spanish\games\glyph-setup.exe - quarantined

F:\Local Disk\DRIVERS\NETWORK\ONBOARD\SETUP.EXE - incurable, quarantined

F:\Local Disk\Documents and Settings\All Users\Application Data\AOL Downloads\triton_suite_install_6.0.28.3\ocpinst.exe - quarantined

F:\Local Disk\Documents and Settings\Dave\Local Settings\Temporary Internet Files\Content.IE5\60KG8T7T\2[1].htm - quarantined

F:\Local Disk\Documents and Settings\Dave\Local Settings\Temporary Internet Files\Content.IE5\60KG8T7T\1[1].htm - quarantined

F:\Local Disk\I386\GTDownDE_87.ocx - quarantined

M:\DadLaptop\backup\Dixmith\Pictures\Pictures Downloaded from AOL\bin_2024-9_b8.exe - deleted

M:\DadLaptop\backup\Program Files\PC MightyMax 2009\DiagnosticReporter.exe - quarantined

M:\DadLaptop\backup\laptop C\SQ004829V03\$RECYCLE.BIN\S-1-5-21-737594619-1414829202-3786626943-1000\$R35BJK6 - quarantined

M:\DadLaptop\backup\laptop C\SQ004829V03\$RECYCLE.BIN\S-1-5-21-737594619-1414829202-3786626943-1000\$RLTFP46 - quarantined

M:\DadLaptop\backup\laptop C\SQ004829V03\$RECYCLE.BIN\S-1-5-21-737594619-1414829202-3786626943-1000\$RSGHMMG - quarantined

Total 1252644944604 bytes in 765201 files scanned (2312189 objects)

Total 764907 files (2311854 objects) are clean

Total 27 files are infected

Total 10 files (16 objects) are suspicious

Total 37 files (39 objects) are neutralized

Total 166 files are raised error condition

Scan time is 06:11:33.740

=============================================================================

Dr.Web Scanner SE for Windows v8.1.0.04290

© Doctor Web, Ltd., 1992-2013

Scan session started 2013/05/20 00:42:38

Module location : C:\Users\David\AppData\Local\Temp\21E05DC0-E88AD120-5307740-C08D4F40\

=============================================================================

OPTION [Automatic Apply Actions] NO

OPTION [Turn Off Computer After Scan] NO

OPTION [use Sound Alerts] NO

OPTION [block Network] NO

OPTION [Protect Process] NO

OPTION [Protect Raw Disk] NO

Using language: "English"

Available instances: 12

Instances used: 12

Platform: Windows 7 Ultimate x86 (Build 7601), Service Pack 1

API Version: 2.2

Scanning Engine version: 8.1.0.3280

Virus Finding Engine version: 7.0.4.9250

Total 113 virus bases are loaded from C:\Users\David\AppData\Local\Temp\21E05DC0-E88AD120-5307740-C08D4F40

fcz11ue7 7.0 a8eee56066244a280075c01158f991ef2afb80a6 2013/05/19 06:40:32 4428 records - OK

3jizr7hf 7.0 215c2d42a54f5188e8159bfd122292450d16f29b 2011/07/25 10:20:03 2 records - OK

f86ztsxc 7.0 bd2e0b2a1ba2d31fb9e806ad1ca6f329bf3c39df 2013/05/18 15:06:59 39002 records - OK

gip7gh9c 7.0 9b481fbfbe1f564a84f21552da1d30d24e7b01db 2013/05/12 23:07:01 34270 records - OK

ufx66741 7.0 1bf754dd720727b5d6803e081c16ff7f4ba7b40b 2013/05/05 23:08:46 41611 records - OK

m36anpvd 7.0 4e883c92513c2d991968fb3e4f27910a63d9a2df 2013/04/28 23:06:36 36105 records - OK

3efhfk16 7.0 b047d178295ecde53c3cf1c34e4361004569fa33 2013/04/21 23:07:26 31319 records - OK

5f81di8a 7.0 9207e55a924e4aa989dfde4d8d219cf5cc200ce2 2013/04/14 23:07:56 28216 records - OK

wi4aqxcj 7.0 78855cfb9fbc063889c5405a577fe73188f08789 2013/04/07 23:05:35 23589 records - OK

dmx6z6br 7.0 cec6d34c79d50608520e81b90a23d91f39df0b27 2013/03/31 23:07:37 26946 records - OK

f6jfgaf0 7.0 fd3c78d78ea4dae4e252a7f7d76db22e1a679be9 2013/03/24 23:05:37 34778 records - OK

0mac5kum 7.0 268e71b1123ab5e60fd2f38d269fe5f3d22b3697 2013/03/17 23:06:19 11271 records - OK

w0f8py8d 7.0 d196879775b0dc0ee8286f2e4def9adedb5b88df 2013/03/10 23:05:36 12046 records - OK

v7l3wvuf 7.0 0db61d4e3235481da8493523538ced712db362c2 2013/03/03 22:05:18 21747 records - OK

q2vq7q0u 7.0 65f99faf227b51883c9f1c854a3f76806b60affb 2013/02/24 22:06:28 11540 records - OK

vr74xf8x 7.0 17bd7383b9c4b214c5c9029171db8ae1455984a0 2013/02/17 22:06:38 15568 records - OK

pye0musb 7.0 cbe8774953ae403e49370d552b522a5839aa9fdb 2013/02/10 22:06:00 18805 records - OK

uyd1vta2 7.0 fb6865c02a3680338e4ee0603579107227313b2b 2013/02/03 22:06:01 32488 records - OK

72brepq8 7.0 95fcd2e24cd9b2ec2610656ffa70b8bf46e86a8b 2013/01/27 22:04:52 15470 records - OK

rt89rkm6 7.0 3d710b3dd4580a7eca8c74d2c886d48f5b8b5172 2013/01/20 22:06:27 30093 records - OK

0pyxna2q 7.0 bddde0b5426b7e5bebd61e1239ca529c87ae6e36 2013/01/13 22:04:41 16158 records - OK

m7iet1wc 7.0 bc40bd9330301e8d7796f489d03357fb711b3121 2013/01/06 22:04:45 19597 records - OK

ub9h2xvu 7.0 805b6089c867549c75f843eac96b759c3f8d101f 2012/12/30 22:05:41 18184 records - OK

hynvuqia 7.0 c12a817c1f95bb9fd8238ef0d5f68868a8d95686 2012/12/23 22:05:33 30183 records - OK

3nrnmc15 7.0 33def496782eb5b7b1cc93fdb036a1b62fa6a2fd 2012/12/16 22:06:21 25519 records - OK

zrlf6q5r 7.0 422abae03c588822f412aa9aae50578a1d61737e 2012/12/09 22:05:04 20358 records - OK

1wuari6s 7.0 a4f0d0ecad4fb6e0afdb1925f4e0b7863b9d03fa 2012/12/02 22:06:19 20133 records - OK

z0s027pi 7.0 86daa918ee3de1e4c1e5dea6f9b5f63544cf8814 2012/11/25 22:05:22 27311 records - OK

rp8xy5g8 7.0 6556881c748e1f894eb9c7943ebae67017e1aec2 2012/11/18 22:06:09 29434 records - OK

heuc97db 7.0 559141ef34f9e6226bb58560e9b52e4cc5165150 2012/11/11 22:06:22 26900 records - OK

n1c7awr8 7.0 cc55013e63ff89319ec772e34d77056c7108cd3b 2012/11/04 22:05:22 25164 records - OK

i7ount4x 7.0 f477dc247d9b562bb64fd4f46a7dcbdf7124eb60 2012/10/28 23:06:37 30226 records - OK

9cklddwj 7.0 abaf5f7fda7308fcf7573b193bbf2116723e9802 2012/10/21 23:04:37 16441 records - OK

8khqradl 7.0 5adc85528fb49e201d4bc61eca580d6839cc4a4c 2012/10/14 23:05:04 26289 records - OK

6txrrg0t 7.0 da8cf3fbd81206bb3d8103347a439f920a74bbe2 2012/10/07 23:05:51 27278 records - OK

m4dgzpzs 7.0 5988744d3cb357f1a013427d466e2d79ab5f8907 2012/09/30 23:05:11 17444 records - OK

tbj5y51k 7.0 d4a0dabf4a4df0f79805c6ccdc025f796765e786 2012/09/23 23:06:30 21205 records - OK

qq236djr 7.0 82ed005784d9e258213070a0cd8bfceff345018d 2012/09/16 23:05:43 11686 records - OK

evu4bfvc 7.0 a95ae63004b8d857c2db055f4e47c15bfc97f626 2012/09/09 23:04:34 12677 records - OK

gmoid10g 7.0 c39bf233d25242ae9ed8cf204b9b788c8f45ab79 2012/09/02 23:05:28 10118 records - OK

kts9qdr7 7.0 d37b5484b009947b7cdd3837dafe8148615401c2 2012/08/26 23:05:26 12602 records - OK

cl6xj2fb 7.0 41bf1347794ab7060dec7aaecc1d1d95cf6fecb5 2012/08/19 23:04:05 18298 records - OK

jnbqlwau 7.0 1a997511e5892aaeb69b3db70e06676af36382e3 2012/08/12 23:05:19 17126 records - OK

22ljgmpn 7.0 f7226c59914e3683e538e668c3b664af3232654d 2012/08/05 23:03:53 20539 records - OK

u2xa8fad 7.0 4035c8d3b617bf935a317a8c57efaa8e835a61f4 2012/07/29 23:05:26 19330 records - OK

m3vityih 7.0 09b55bc000f184ed426f1d8b9665669346fe5e71 2012/07/22 23:05:34 19692 records - OK

umj3puyr 7.0 f746c097f298e94faa9db94e6f64ef9fd4a7b010 2012/07/15 23:05:43 14727 records - OK

k21n0d8f 7.0 792a6a25a17e764390440cd4c2c6ca5a97ab162f 2012/07/08 23:04:33 19485 records - OK

wacfdbsh 7.0 ca9905c39e3d93428a4db65a192debe9fbd7acf7 2012/07/01 23:04:55 22898 records - OK

i4s1lpde 7.0 dc29c610b866c66ba5327e7830452b2460149a35 2012/06/24 23:05:17 20551 records - OK

7o3tcl93 7.0 c28739bea153508d12942ac9a61abd475d0a0404 2012/06/17 23:03:35 9661 records - OK

fo6pb363 7.0 e5b5835a7c512120c5348e31483a4caa2a845d28 2012/06/10 23:04:32 23632 records - OK

jwiwft35 7.0 61853ce89026ef0ebbd80174f1b7dd5d25bbc63a 2012/06/03 23:04:41 12423 records - OK

cm85ybkc 7.0 4e6c9897e153b47ca97b7da48ceed23e555a7761 2012/05/27 23:04:26 15493 records - OK

viwwth92 7.0 35f4c105cecd8ec1fd01714abebf30f8f3efb96e 2012/05/20 23:03:29 13065 records - OK

s7dgmjsx 7.0 3522aa84677411aa7d67796bb05ea3ab62f02a71 2012/05/13 23:04:24 16238 records - OK

h56wl4e2 7.0 7597333540eda537bd42c0a17d4a6526ad247a2e 2012/05/06 23:04:33 11570 records - OK

rm2agkix 7.0 867814380363bc6ad605acf4b96e02c54dbd60f7 2012/04/29 23:03:28 15478 records - OK

ttkbaylx 7.0 3c04f402d91a19039cb9c223c435dc4ea1bb3da4 2012/04/22 23:05:05 11881 records - OK

ql9o1iqu 7.0 8d0220a2a50b367e61a51d3b29c2659cde41bb7f 2012/04/15 23:03:29 13578 records - OK

5a99p0zh 7.0 b79dc6f5832ad390108d1880694ec538e8b34bb0 2012/04/08 23:05:02 14292 records - OK

j6us22jl 7.0 8ff7cc095c43c2154275b7a54a89bf365e8daf4a 2012/04/01 23:03:24 14084 records - OK

w889zepq 7.0 9502a428b32be4ad08556134e271c9ba03195398 2012/03/25 23:04:43 19126 records - OK

jluthjxs 7.0 28c2fabbc645aff41baac12b911a8499ea163536 2012/03/18 23:03:23 14920 records - OK

p3phfg3r 7.0 86de597ff06e58206f94263f2eef33cb41b2530c 2012/03/11 23:03:25 19017 records - OK

k5zs7vyc 7.0 5bd1d666e7c9ca70c34e591dc6c55314ce4b11af 2012/03/04 22:04:32 19691 records - OK

0v0iftgj 7.0 15a9d10c451d2fcf124700f29f557d9bf338e671 2012/02/26 22:03:21 23605 records - OK

fqlyl1o6 7.0 5647d941e5358105ca6558dce78873f06c48d5dc 2012/02/19 22:03:45 19067 records - OK

o79yx8b1 7.0 c9b2600cb665ce34e0ccd0f19e0a88cd44437f51 2012/02/12 22:04:49 19019 records - OK

5x9nsqu5 7.0 9df2e129e78a9d9ab491186da1329c1dd1190e17 2012/02/05 22:05:25 28028 records - OK

lb6n00w1 7.0 b69b9504a51b8777b8e95a4680dc8ac1d8d8c25d 2012/01/29 22:08:41 29444 records - OK

sm35hh2h 7.0 3d7431bdee1a22d6329e017f348db7760f2645ac 2012/01/23 03:22:13 19353 records - OK

kqmxn9ez 7.0 e04570f78fb00d758abdf77c534a460980e102c0 2012/01/15 22:12:31 20747 records - OK

t1rc0kr5 7.0 2de2479b112c4416e2375343f57ca789b042aecc 2012/01/08 22:04:30 28052 records - OK

ifrcjhc6 7.0 c4bd9612ff1f71d8bd23b4f1bc114eed1ae2ee6b 2012/01/01 22:04:40 12183 records - OK

q3bq86q0 7.0 28b1d218ade8f05fdc8550c7456ac3b74f705208 2011/12/25 22:03:33 19984 records - OK

laftfgz9 7.0 539e41e8f3d97a6f347600c7cef903d9f34e0518 2011/12/18 22:08:45 22627 records - OK

3kg9lj1p 7.0 f8e81968965f555bce0d02fc9933fee840b97aaf 2011/12/12 15:20:22 49580 records - OK

nwbp7wjd 7.0 14751e0f442bba3efc08ee12d82a2815c61cfeb6 2011/12/04 03:00:00 45195 records - OK

gjf6shpv 7.0 1a1e6cb9b3096a2cbba2c31d05e11914c0357d52 2011/12/04 02:00:00 165532 records - OK

i5hef6e3 7.0 0f948a7d416c556bfc8a8be2c2c39f998fee6d9e 2011/12/04 01:00:00 170820 records - OK

hmul8k4s 7.0 9357c3cc73a4a374346a678f197daa22496c7ae5 2011/12/04 00:00:00 171279 records - OK

voqfy37g 7.0 ae56b06b3d6f1e13c5f10cce4ed68f2cccbf3298 2011/12/03 23:00:00 170253 records - OK

5rz8i9vc 7.0 fdaab5c1079d02c94f20d07c39d638cad79d8771 2011/12/03 22:00:00 170291 records - OK

hileya3t 7.0 b59d8841e65d7670b2aae7f2b65734269f6c4fe3 2011/12/03 21:00:00 170501 records - OK

2cued0br 7.0 3946b1d195434cf7a70d144da71c87559475c58f 2011/12/03 20:00:00 353582 records - OK

fa3gcliq 7.0 8df4695f74ea5949551df6044720694e204b13d7 2011/12/03 19:00:00 852776 records - OK

foptuhfa 7.0 dc583d89c11a1706a583bba189f8bfae141834f4 2013/05/19 06:41:02 797 records - OK

3fkyknzt 7.0 0cb77ee7a3e6545553585eb6df267a86d4fecbe4 2013/04/21 23:14:29 1680 records - OK

zuc3d2cq 7.0 6cb68b8fab821702ef054f864ff44917414e50fa 2013/02/03 22:13:43 2078 records - OK

3iuejahx 7.0 cfbe9cf43615f7856e4c35f0fc02e2baf12e39e7 2012/12/16 22:14:14 1725 records - OK

507tnouk 7.0 047694e79b1a8d295f27ea9c6565062404f84a57 2012/11/11 22:12:52 2050 records - OK

70ney8kt 7.0 f3413603f4ee1c88018a78c1f6faf2abeb8fa8c1 2012/09/23 23:13:14 1456 records - OK

r0qh4uul 7.0 8871f579eeb7e5e7b70c6dd898afd27391d7daf4 2012/06/24 23:12:36 1421 records - OK

sr9sqb0h 7.0 3ee43130fe7fec4b367a791892a444d0a791b29b 2012/03/25 23:12:30 1385 records - OK

isci1z88 7.0 fddc5d687537580c7166dbf117d591593bc62261 2012/01/22 23:56:09 1653 records - OK

5c48i2k1 7.0 c04782be4165f041fb28b2b51889bbe3755f5c81 2013/05/19 06:40:50 1369 records - OK

vlwlae05 7.0 bd9fd948b79e07c8676018e17a43ee81f5335e36 2013/04/21 23:24:10 1641 records - OK

fcupgacj 7.0 c7f70566b9bae9fd3f5a8d0b56d961f890a55508 2013/03/17 23:23:44 1742 records - OK

iswpjxd0 7.0 8893c0d254eb40c78b5c78ea17fbc3be60ea6304 2013/01/20 22:24:33 2016 records - OK

85hr3e9t 7.0 cdf3a9d2dcab57f90c378d9eefacbfd358a42699 2012/12/09 22:23:23 1620 records - OK

egrj83y9 7.0 c0726ba000e840272f0810b89051e6daa8799084 2012/11/04 22:23:16 1658 records - OK

v20aidea 7.0 216611859de0125bf130d6324d43c9115cb05def 2012/10/07 23:23:20 1465 records - OK

a5wwznna 7.0 264c14ad60c4423ec292f5f8b182e4448504dfa9 2012/09/09 23:23:14 1588 records - OK

gw66rmd6 7.0 33197bfe9efefa9db33725d240757103c625b601 2012/07/22 23:22:36 1702 records - OK

dqk2pt44 7.0 74d8e114edb84b95bc09d5a2a36191d15a61e2cb 2012/06/10 23:22:36 1659 records - OK

cu5w8q7z 7.0 79ca8239f310688d2b9c314fa3d738a34985cce3 2012/04/29 23:22:34 1670 records - OK

xvg4mgwo 7.0 aac27e986e3731e5260cb76f5b14558e36660dec 2012/03/11 23:22:28 1729 records - OK

rjwr4eb2 7.0 fa5c96b8be693a20c2a295e3545419e6f117fdc4 2012/01/29 22:23:00 1523 records - OK

vlk0catx 7.0 e9b21e0a3578ef2e2067f4876309671ddc78f65f 2011/12/18 22:22:29 1805 records - OK

eixd7fzv 7.0 8f7a8f6f55130f6becc5331ab38dc2108746b8aa 2011/12/03 18:00:00 26456 records - OK

4cxql2w0 7.0 e6d52b11d2f7d405ccd31347da3b6fde69825168 2011/12/03 17:00:00 74279 records - OK

rfsf42hl 7.0 e20ffde4bbc58e0585b0b3b2f324bc91272c2360 2011/12/03 16:00:00 1 record - OK

Total records count: 4031082

Anti-rootkit module version (API 5.01 / 5.01)

Using C:\Users\David\AppData\Local\Temp\21E05DC0-E88AD120-5307740-C08D4F40\8oix977f.key as Dr.Web ® Key file

This Dr.Web ® Key is for 1 computer (A User)

Link to post
Share on other sites

Hi Maniac,

Everything is running well, thank you very much. Are there any prophylactic measures that can prevent this sort of infection. I run and keep uptodate Anti-virus/ anti-malware software as well keep my OS patches uptodate. Thank you again, definitely deserve a PayPal visit!

Regards,

dave S

Link to post
Share on other sites

Thank you Dave! :)

Some good tips for preventing:

users.telenet.be/bluepatchy/miekiemoes/prevention.html

  • Download OTC to your desktop and run it
  • Click Yes to beginning the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. Choose Yes.

Please uninstall ESET Online Scanner and manually delete JavaRa, TFC, Dr.Web CureIt and Kaspersky AVP.

Safe surfing! :)

Link to post
Share on other sites

Glad we could help. :)

If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.