Jump to content

ComboFix >> Windows Installer Won't Run


Recommended Posts

Thanks for being here for this kind of troubleshooting. Working on a friend's laptop.

It was very slow, and Vista would not update to SP1. Ran MBAM in safe mode and found malware files, then ran ComboFix. Rebooted after that, and attempted to install TuneUp Utilities. At that point, got an error message that Windows Installer could not be accessed.

Relevant Log Files below - MBAM, ComboFix, and DDS.

MBAM

Malwarebytes Anti-Malware (Trial) 1.75.0.1300

www.malwarebytes.org

Database version: v2013.05.27.07

Windows Vista x86 NTFS (Safe Mode/Networking)

Internet Explorer 7.0.6000.17037

Mad Fad :: MADFAD-PC [administrator]

Protection: Disabled

5/27/2013 5:14:08 PM

mbam-log-2013-05-27 (17-14-08).txt

Scan type: Full scan (C:\|D:\|E:\|)

Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM

Scan options disabled: P2P

Objects scanned: 390173

Time elapsed: 1 hour(s), 10 minute(s), 28 second(s)

Memory Processes Detected: 0

(No malicious items detected)

Memory Modules Detected: 0

(No malicious items detected)

Registry Keys Detected: 2

HKCR\AppID\GamevanceText.DLL (Adware.GameVance) -> Quarantined and deleted successfully.

HKCU\Software\AppDataLow\gvtl (Adware.GameVance) -> Quarantined and deleted successfully.

Registry Values Detected: 1

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|VwOrOo (Trojan.Agent.CPL) -> Data: rundll32.exe shell32.dll,Control_RunDLL "C:\ProgramData\r4Bmi7waQJy9\gnm64yj0sIc5L7fB\1Fcu1csu5lCT\mWIpDSfo.dat", -> Quarantined and deleted successfully.

Registry Data Items Detected: 0

(No malicious items detected)

Folders Detected: 0

(No malicious items detected)

Files Detected: 6

C:\ProgramData\r4Bmi7waQJy9\gnm64yj0sIc5L7fB\1Fcu1csu5lCT\mWIpDSfo.dat (Trojan.Agent.CPL) -> Quarantined and deleted successfully.

C:\ProgramData\N3JvdBTbsOBQ.cpl (Trojan.BanLoad) -> Quarantined and deleted successfully.

C:\Users\Mad Fad\AppData\Local\VirtualStore\ProgramData\Gatmo2Ob12Yb\LNIkrbFKQMf1jbq\AZNPDApZzgXp0\verj2L6HTwzz9\nyvgU3dXIynhm\yORIpPqgz.dat (Trojan.Agent.CPL) -> Quarantined and deleted successfully.

C:\Users\Mad Fad\AppData\Local\VirtualStore\ProgramData\ke2rHens1vGSjShW\ZiAI9lEXPtyA2y\6FiOr2aSTe8ujHP\a1WKZ8YZ0tMvDRn\rgjNL4YgoeGVAr\c99YqN.dat (Trojan.Agent.CPL) -> Quarantined and deleted successfully.

C:\Users\Mad Fad\AppData\Local\VirtualStore\ProgramData\r4Bmi7waQJy9\gnm64yj0sIc5L7fB\1Fcu1csu5lCT\mWIpDSfo.dat (Trojan.Agent.CPL) -> Quarantined and deleted successfully.

C:\ProgramData\jupdate.exe (Trojan.Agent) -> Quarantined and deleted successfully.

(end)

ComboFix

ComboFix 13-05-27.02 - Mad Fad 05/27/2013 22:16:46.1.2 - x86 NETWORK

Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.1982.1495 [GMT -4:00]

Running from: c:\users\Mad Fad\Downloads\ComboFix.exe

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\program files\Common Files\Uninstall

c:\programdata\5hWcTrW0KEO.ico

c:\programdata\e7310cafebc550d4108bb4ab0ec38a1e5b33f1e3

c:\programdata\EDUtt04cjXg0.ico

c:\programdata\expCFJrX5p.ico

c:\programdata\g5vpNioNA.ico

c:\programdata\IFzuuDcSPB.ico

c:\programdata\KvAQf23w57P.ico

c:\programdata\ntuser.dat

c:\programdata\R0EwWApQ.ico

c:\programdata\ScDBcQwvTNci.ico

c:\programdata\SPL37A4.tmp

c:\programdata\SPL4A99.tmp

c:\programdata\SPL5984.tmp

c:\programdata\SPL6078.tmp

c:\programdata\SPL9212.tmp

c:\programdata\SPLA88E.tmp

c:\programdata\SPLB08B.tmp

c:\programdata\SPLE917.tmp

c:\programdata\SPLFB51.tmp

c:\programdata\VLd8PeCXl.ico

c:\users\Mad Fad\~WRL0001.tmp

c:\users\Mad Fad\AppData\Roaming\BabMaint.exe

c:\users\Mad Fad\Documents\~WRL0005.tmp

c:\users\Mad Fad\Firefox_Setup_20.0.exe

c:\users\Mad Fad\SoftonicDownloader_for_photomerge.exe

c:\users\Mad Fad\TLP_Moods.exe

c:\windows\system32\KBL.LOG

c:\windows\system32\SET26B9.tmp

c:\windows\system32\SET3CDA.tmp

c:\windows\system32\SET3E85.tmp

c:\windows\system32\SET43C1.tmp

c:\windows\system32\SET455B.tmp

c:\windows\system32\SETA43A.tmp

c:\windows\system32\SETB8D3.tmp

c:\windows\system32\SETB9CB.tmp

.

.

((((((((((((((((((((((((( Files Created from 2013-04-28 to 2013-05-28 )))))))))))))))))))))))))))))))

.

.

2013-05-27 21:12 . 2013-05-27 21:12 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2013-05-27 21:12 . 2013-04-04 18:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys

2013-05-27 20:47 . 2013-05-27 20:47 -------- d-----w- c:\progra~2\85829C~1

2013-05-27 19:23 . 2009-07-14 01:19 38480 ----a-w- c:\windows\system32\drivers\WdfLdr.sys

2013-05-27 19:23 . 2009-07-14 01:19 445008 ----a-w- c:\windows\system32\drivers\Wdf01000.sys

2013-05-27 19:17 . 2013-05-27 19:17 -------- d-----w- c:\windows\system32\searchplugins

2013-05-27 19:17 . 2013-05-27 19:17 -------- d-----w- c:\windows\system32\Extensions

2013-05-27 19:04 . 2013-05-27 19:04 -------- d-----w- c:\progra~2\85C39C~1

2013-05-27 18:34 . 2013-05-27 18:34 -------- d-----w- c:\progra~2\8520-1~4

2013-05-27 16:58 . 2013-05-27 16:58 -------- d-----w- c:\progra~2\!!8520~1

2013-05-27 16:50 . 2013-05-27 16:50 -------- d-----w- c:\progra~2\8520-1~3

2013-05-27 14:40 . 2013-05-14 05:49 7016152 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8088063B-AFF1-4A39-95AE-4D303913C9AE}\mpengine.dll

2013-05-23 03:31 . 2013-05-23 03:31 -------- d-----w- c:\progra~2\8520-1~2

2013-05-12 16:34 . 2013-05-09 08:59 29816 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys

2013-05-12 16:34 . 2013-05-09 08:59 368944 ----a-w- c:\windows\system32\drivers\aswSP.sys

2013-05-12 16:34 . 2013-05-09 08:59 49760 ----a-w- c:\windows\system32\drivers\aswRdr.sys

2013-05-12 16:34 . 2013-05-09 08:59 765736 ----a-w- c:\windows\system32\drivers\aswSnx.sys

2013-05-12 16:34 . 2013-05-09 08:59 56080 ----a-w- c:\windows\system32\drivers\aswTdi.sys

2013-05-12 16:34 . 2013-05-09 08:59 174664 ----a-w- c:\windows\system32\drivers\aswVmm.sys

2013-05-12 16:34 . 2013-05-09 08:59 49376 ----a-w- c:\windows\system32\drivers\aswRvrt.sys

2013-05-12 16:34 . 2013-05-09 08:59 66336 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys

2013-05-12 16:34 . 2013-05-09 08:58 229648 ----a-w- c:\windows\system32\aswBoot.exe

2013-05-12 16:33 . 2013-05-09 08:58 41664 ----a-w- c:\windows\avastSS.scr

2013-05-12 16:31 . 2013-05-12 16:31 -------- d-----w- c:\program files\AVAST Software

2013-05-12 16:30 . 2013-05-12 16:31 -------- d-----w- c:\programdata\AVAST Software

2013-05-12 16:09 . 2013-05-12 16:09 -------- d-----w- c:\progra~2\PD1C3~1

2013-05-12 16:09 . 2013-05-12 16:09 -------- d-----w- c:\progra~2\8520-1~1

2013-05-11 13:50 . 2013-05-11 13:50 -------- d-sh--w- c:\programdata\r4Bmi7waQJy9

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2013-05-23 03:28 . 2013-04-20 13:29 37664 ----a-w- c:\windows\system32\drivers\avgtpx86.sys

2013-05-02 06:06 . 2010-12-04 23:22 238872 ------w- c:\windows\system32\MpSigStub.exe

2013-03-06 03:46 . 2013-03-06 03:46 71024 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2013-03-06 03:46 . 2013-03-06 03:46 691568 ----a-w- c:\windows\system32\FlashPlayerApp.exe

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]

2013-05-23 03:28 1991344 ----a-w- c:\program files\AVG SafeGuard toolbar\15.2.0.5\AVG SafeGuard toolbar_toolbar.dll

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files\AVG SafeGuard toolbar\15.2.0.5\AVG SafeGuard toolbar_toolbar.dll" [2013-05-23 1991344]

.

[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]

[HKEY_CLASSES_ROOT\AVG SafeGuard toolbar.PugiObj.1]

[HKEY_CLASSES_ROOT\AVG SafeGuard toolbar.PugiObj]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]

@="{472083B0-C522-11CF-8763-00608CC02F24}"

[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]

2013-05-09 08:58 121968 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]

@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]

2012-11-13 23:32 129272 ----a-w- c:\users\Mad Fad\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]

@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]

2012-11-13 23:32 129272 ----a-w- c:\users\Mad Fad\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]

@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]

2012-11-13 23:32 129272 ----a-w- c:\users\Mad Fad\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-02-11 1232896]

"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-08-23 455968]

"HPAdvisor"="c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2007-10-02 1783136]

"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]

"Yontoo Desktop"="c:\users\Mad Fad\AppData\Roaming\Yontoo\YontooDesktop.exe" [2013-04-17 42784]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 102400]

"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-10-01 181544]

"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-09-19 202032]

"OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-09-04 554320]

"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-08-17 218408]

"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-23 80896]

"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-11 49152]

"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-09-13 480560]

"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-08 311296]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]

"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-01-17 185872]

"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2013-04-04 887432]

"Nikon Message Center 2"="c:\program files\Nikon\Nikon Message Center 2\NkMC2.exe" [2010-05-25 619008]

"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-01-28 59720]

"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2012-10-25 421888]

"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2013-02-18 152392]

"vProt"="c:\program files\AVG SafeGuard toolbar\vprot.exe" [2013-05-23 1226928]

"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-05-09 4858968]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-24 13601312]

"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-06-24 92704]

"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2011-10-14 2299176]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

"Malwarebytes Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2013-04-04 532040]

.

c:\users\Mad Fad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Dropbox.lnk - c:\users\Mad Fad\AppData\Roaming\Dropbox\bin\Dropbox.exe [2013-3-12 29106336]

OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

.

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-1-2 210520]

McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.0.318\SSScheduler.exe [2013-2-5 272248]

Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]

"AppInit_DLLs"=c:\progra~2\browse~1\261249~1.132\{c16c1~1\browse~1.dll

.

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]

BootExecute REG_MULTI_SZ autocheck autochk /r \??\C:\0autocheck autochk *

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]

"DisableMonitoring"=dword:00000001

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

"DisableMonitoring"=dword:00000001

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]

"DisableMonitoring"=dword:00000001

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

.

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]

2007-08-23 22:34 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe

.

Contents of the 'Scheduled Tasks' folder

.

2013-05-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1178580412-3150187080-1603977272-1000Core.job

- c:\users\Mad Fad\AppData\Local\Google\Update\GoogleUpdate.exe [2009-12-05 22:18]

.

2013-05-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1178580412-3150187080-1603977272-1000UA.job

- c:\users\Mad Fad\AppData\Local\Google\Update\GoogleUpdate.exe [2009-12-05 22:18]

.

2013-05-27 c:\windows\Tasks\User_Feed_Synchronization-{D38B8088-739A-4735-9EB6-2B7ECD876F8E}.job

- c:\windows\system32\msfeedssync.exe [2006-11-02 09:45]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.google.com/

mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop

uInternet Settings,ProxyOverride = *.local

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000

TCP: DhcpNameServer = 192.168.1.1

Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\15.2.0\ViProtocol.dll

.

- - - - ORPHANS REMOVED - - - -

.

HKLM-Run-HP Health Check Scheduler - [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe

HKLM-Run-lxddmon.exe - c:\program files\Lexmark 2500 Series\lxddmon.exe

HKLM-Run-lxddamon - c:\program files\Lexmark 2500 Series\lxddamon.exe

HKLM-Run-SunJavaUpdateSched - c:\program files\Java\jre7\bin\jusched.exe

.

.

.

**************************************************************************

.

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2013-05-27 22:28

Windows 6.0.6000 NTFS

.

scanning hidden processes ...

.

scanning hidden autostart entries ...

.

scanning hidden files ...

.

scan completed successfully

hidden files: 0

.

**************************************************************************

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

.

--------------------- DLLs Loaded Under Running Processes ---------------------

.

- - - - - - - > 'Explorer.exe'(1896)

c:\program files\Hewlett-Packard\HP Advisor\Pillars\Market\MLDeskBand.dll

.

Completion time: 2013-05-27 22:30:48

ComboFix-quarantined-files.txt 2013-05-28 02:30

.

Pre-Run: 146,892,460,032 bytes free

Post-Run: 148,622,766,080 bytes free

.

- - End Of File - - A0200E24FD74DDF67777FC0860DECD90

DDS

DDS (Ver_2012-11-20.01) - NTFS_x86 NETWORK

Internet Explorer: 7.0.6000.17037 BrowserJavaVersion: 10.7.2

Run by Mad Fad at 7:49:30 on 2013-05-28

Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.1982.1267 [GMT -4:00]

.

.

============== Running Processes ================

.

C:\Windows\system32\wininit.exe

C:\Windows\system32\lsm.exe

C:\Windows\Explorer.EXE

C:\Windows\helppane.exe

C:\Windows\system32\wbem\unsecapp.exe

C:\Windows\system32\wbem\wmiprvse.exe

C:\Users\Mad Fad\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\Mad Fad\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\Mad Fad\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\Mad Fad\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\Mad Fad\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Windows\system32\wbem\wmiprvse.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\system32\svchost.exe -k rpcss

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k NetworkService

C:\Windows\system32\svchost.exe -k LocalService

C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

.

============== Pseudo HJT Report ===============

.

uStart Page = hxxp://www.google.com/

mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop

BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - <orphaned>

BHO: Adobe PDF Reader Link Helper: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll

BHO: MSS+ Identifier: {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -

BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll

BHO: SSVHelper Class: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll

BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll

BHO: AVG SafeGuard toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - c:\program files\avg safeguard toolbar\15.2.0.5\AVG SafeGuard toolbar_toolbar.dll

BHO: Wajam: {A7A6995D-6EE1-4FD1-A258-49395D5BF99C} - c:\program files\wajam\ie\priam_bho.dll

BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll

TB: AVG SafeGuard toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - c:\program files\avg safeguard toolbar\15.2.0.5\AVG SafeGuard toolbar_toolbar.dll

TB: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll

uRun: [sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun

uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden

uRun: [HPAdvisor] c:\program files\hewlett-packard\hp advisor\HPAdvisor.exe autoRun

uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe

uRun: [Yontoo Desktop] "c:\users\mad fad\appdata\roaming\yontoo\YontooDesktop.exe"

mRun: [synTPStart] c:\program files\synaptics\syntp\SynTPStart.exe

mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe"

mRun: [QlbCtrl] c:\program files\hewlett-packard\hp quick launch buttons\QlbCtrl.exe /Start

mRun: [OnScreenDisplay] c:\program files\hewlett-packard\hp quicktouch\HPKBDAPP.exe

mRun: [uCam_Menu] "c:\program files\cyberlink\youcam\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\youcam" update "software\cyberlink\youcam\1.0"

mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe

mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe

mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe

mRun: [WAWifiMessage] c:\program files\hewlett-packard\hp wireless assistant\WiFiMsg.exe

mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"

mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot

mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript

mRun: [Nikon Message Center 2] c:\program files\nikon\nikon message center 2\NkMC2.exe -s

mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"

mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime

mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"

mRun: [vProt] "c:\program files\avg safeguard toolbar\vprot.exe"

mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui

mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup

mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit

mRun: [synTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe

mRunOnce: [Malwarebytes Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent

StartupFolder: c:\users\madfad~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\dropbox.lnk - c:\users\mad fad\appdata\roaming\dropbox\bin\Dropbox.exe

StartupFolder: c:\users\madfad~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE

StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe

StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\3.0.318\SSScheduler.exe

StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE

uPolicies-Explorer: NoDrives = dword:0

mPolicies-Explorer: NoDrives = dword:0

IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000

IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office12\ONBttnIE.dll

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}

DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab

TCP: NameServer = 192.168.1.1

TCP: Interfaces\{924D4EAF-CC8A-4222-831E-68F8B6F5E82F} : DHCPNameServer = 192.168.1.1

Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL

Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll

Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\common files\avg secure search\viprotocolinstaller\15.2.0\ViProtocol.dll

AppInit_DLLs= c:\progra~2\browse~1\261249~1.132\{c16c1~1\browse~1.dll

LSA: Security Packages = kerberos msv1_0 schannel wdigest tspkg

mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"

.

============= SERVICES / DRIVERS ===============

.

R1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx86.sys [2013-4-20 37664]

S0 aswRvrt;aswRvrt;c:\windows\system32\drivers\aswRvrt.sys [2013-5-12 49376]

S0 aswVmm;aswVmm;c:\windows\system32\drivers\aswVmm.sys [2013-5-12 174664]

S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2013-5-12 765736]

S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2013-5-12 368944]

S2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2013-5-12 29816]

S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2013-5-12 66336]

S2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2013-5-12 46808]

S2 BrowserProtect;BrowserProtect;c:\programdata\browserprotect\2.6.1249.132\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe [2013-4-26 2787280]

S2 MBAMScheduler;MBAMScheduler;c:\program files\malwarebytes' anti-malware\mbamscheduler.exe [2013-5-27 418376]

S2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2013-5-27 701512]

S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-7-13 160944]

S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-2-11 24652]

S2 vToolbarUpdater15.2.0;vToolbarUpdater15.2.0;c:\program files\common files\avg secure search\vtoolbarupdater\15.2.0\ToolbarUpdater.exe [2013-5-22 1015984]

S2 WajamUpdater;WajamUpdater;c:\program files\wajam\updater\WajamUpdater.exe [2013-4-4 109064]

S2 Yontoo Desktop Updater;Yontoo Desktop Updater;c:\program files\yontoo\Y2Desktop.Updater.exe [2013-4-26 23552]

S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2013-5-27 22856]

S3 McComponentHostService;McAfee Security Scan Component Host Service;"c:\program files\mcafee security scan\3.0.318\mcchsvc.exe" --> c:\program files\mcafee security scan\3.0.318\McCHSvc.exe [?]

.

=============== Created Last 30 ================

.

2013-05-28 02:42:00 -------- d-sh--w- c:\programdata\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}

2013-05-28 02:30:50 -------- d-----w- c:\users\mad fad\appdata\local\temp

2013-05-28 02:29:57 -------- d-sh--w- C:\$RECYCLE.BIN

2013-05-28 02:13:44 98816 ----a-w- c:\windows\sed.exe

2013-05-28 02:13:44 256000 ----a-w- c:\windows\PEV.exe

2013-05-28 02:13:44 208896 ----a-w- c:\windows\MBR.exe

2013-05-27 21:12:38 22856 ----a-w- c:\windows\system32\drivers\mbam.sys

2013-05-27 21:12:38 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2013-05-27 20:50:56 -------- d-----w- c:\windows\pss

2013-05-27 20:47:36 -------- d-----w- c:\programdata\????8520-1533-40C5-AD09-953C574F14BCÄ???

2013-05-27 19:23:20 38480 ----a-w- c:\windows\system32\drivers\WdfLdr.sys

2013-05-27 19:23:19 445008 ----a-w- c:\windows\system32\drivers\Wdf01000.sys

2013-05-27 19:17:14 -------- d-----w- c:\windows\system32\searchplugins

2013-05-27 19:17:14 -------- d-----w- c:\windows\system32\Extensions

2013-05-27 19:04:55 -------- d-----w- c:\programdata\????8520-1533-40C5-AD09-953C574F14BCÄ???

2013-05-27 18:34:03 -------- d-----w- c:\programdata\????8520-1533-40C5-AD09-953C574F14BCÄ???

2013-05-27 16:58:35 -------- d-----w- c:\programdata\?!?!8520-1533-40C5-AD09-953C574F14BCÄ!?!

2013-05-27 16:50:00 -------- d-----w- c:\programdata\????8520-1533-40C5-AD09-953C574F14BCÄ???

2013-05-27 14:40:25 7016152 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{8088063b-aff1-4a39-95ae-4d303913c9ae}\mpengine.dll

2013-05-23 03:31:48 -------- d-----w- c:\programdata\????8520-1533-40C5-AD09-953C574F14BCÄ???

2013-05-12 16:34:39 765736 ----a-w- c:\windows\system32\drivers\aswSnx.sys

2013-05-12 16:34:37 174664 ----a-w- c:\windows\system32\drivers\aswVmm.sys

2013-05-12 16:34:33 49376 ----a-w- c:\windows\system32\drivers\aswRvrt.sys

2013-05-12 16:34:29 66336 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys

2013-05-12 16:33:29 41664 ----a-w- c:\windows\avastSS.scr

2013-05-12 16:31:09 -------- d-----w- c:\program files\AVAST Software

2013-05-12 16:30:03 -------- d-----w- c:\programdata\AVAST Software

2013-05-12 16:09:09 -------- d-----w- c:\programdata\?ù?ù????????????????????p???????

2013-05-12 16:09:08 -------- d-----w- c:\programdata\????8520-1533-40C5-AD09-953C574F14BCÄ???

2013-05-11 13:50:09 -------- d-sh--w- c:\programdata\r4Bmi7waQJy9

.

==================== Find3M ====================

.

2013-05-23 03:28:38 37664 ----a-w- c:\windows\system32\drivers\avgtpx86.sys

2013-05-02 06:06:08 238872 ------w- c:\windows\system32\MpSigStub.exe

2013-03-06 03:46:28 71024 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2013-03-06 03:46:28 691568 ----a-w- c:\windows\system32\FlashPlayerApp.exe

.

============= FINISH: 7:51:46.28 ===============

Link to post
Share on other sites

Hello Luna_McSniffles and :welcome:! My name is Maniac and I will be glad to help you solve your malware problem.

Please note:

  • If you are a paying customer, you have the privilege to contact the help desk at Consumer Support. If you choose this option to get help, please let me know.
  • I recommend you to keep the instructions I will be giving you so that they are available to you at any time. You can save them in a text file or print them.
  • Make sure you read all of the instructions and fixes thoroughly before continuing with them.
  • Follow my instructions strictly and don’t hesitate to stop and ask me if you have any questions.
  • Post your log files, don't attach them. Every log file should be copy/pasted in your next reply.
  • Do not perform any kind of scanning and fixing without my instructions. If you want to proceed on your own, please let me know.

Please do not run ComboFix without special supervision and instructions of someone authorized to do so. Otherwise, you could end up with serious problems. For more details, read this article: ComboFix usage, Questions, Help? - Look here

Next, post the content of Attach.txt (generated from DDS).

Link to post
Share on other sites

Step 1

Please uninstall the following applications:

Viewpoint Media Player

Wajam

Yontoo 2.052

Step 2

Please download Junkware Removal Tool to your desktop.

  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.

Step 3

  • Launch Malwarebytes' Anti-Malware
  • Go to Update tab and select Check for Updates. If an update is found, it will download and install the latest version.
  • Go to Scanner tab and select Perform Quick Scan, then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer,please do so immediately.

Step 4

Please download AdwCleaner from here and save it on your Desktop.

  1. Right-click on adwcleaner.exe and select Run As Administrator to launch the application.
  2. Now click on the Search tab.
  3. Please post the contents of the log-file created in your next post.

Note: The log can also be located at C:\ >> AdwCleaner[XX].txt >> XX <-- Denotes the number of times the application has been ran, so in this should be something like R1.

In your next reply, post the following log files:

  • Junkware Removal Tool log
  • Malwarebytes' Anti-Malware log
  • AdwCleaner log

Link to post
Share on other sites

Junkware found a bad module, which required rebooting.

MBAM found no errors, and seemingly did not generate a log.

ADW

Log contents below.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Junkware Removal Tool (JRT) by Thisisu

Version: 4.9.4 (05.06.2013:1)

OS: Windows Vista Home Premium x86

Ran by Mad Fad on Tue 05/28/2013 at 13:40:50.06

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

~~~ Services

~~~ Registry Values

Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\\Start Page

Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope

~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\escort.escortiepane

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\escort.escortiepane.1

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\babylon

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\babylontoolbar

Failed to delete: [Registry Key] HKEY_CURRENT_USER\Software\datamngr_toolbar

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\softonic

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\windows\currentversion\ext\bprotectsettings

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\appid\escort.dll

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\appid\escortapp.dll

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\appid\escorteng.dll

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\appid\escortlbr.dll

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\appid\esrv.exe

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\appid\scripthelper.exe

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\appid\viprotocol.dll

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\delta.deltaappcore

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\delta.deltaappcore.1

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\esrv.deltaesrvc

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\esrv.deltaesrvc.1

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\prod.cap

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\protocols\handler\viprotocol

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\scripthelper.scripthelperapi

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\scripthelper.scripthelperapi.1

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\viprotocol.viprotocolole

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\viprotocol.viprotocolole.1

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{66F00777-E2CA-4B62-B7A4-84C1ECB19796}

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{d0508e03-1e5b-4c84-9fd6-6117bdb1490e}

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{443789B7-F39C-4b5c-9287-DA72D38F4FE6}

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{66F00777-E2CA-4B62-B7A4-84C1ECB19796}

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{CF739809-1C6C-47C0-85B9-569DBB141420}

~~~ Files

Successfully deleted: [File] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ebay.lnk"

Successfully deleted: [File] "C:\end"

~~~ Folders

Successfully deleted: [Folder] "C:\ProgramData\babylon"

Successfully deleted: [Folder] "C:\ProgramData\browserprotect"

Successfully deleted: [Folder] "C:\ProgramData\tarma installer"

Successfully deleted: [Folder] "C:\ProgramData\viewpoint"

Successfully deleted: [Folder] "C:\Users\Mad Fad\AppData\Roaming\babsolution"

Successfully deleted: [Folder] "C:\Users\Mad Fad\AppData\Roaming\babylon"

Successfully deleted: [Folder] "C:\Users\Mad Fad\AppData\Roaming\delta"

Successfully deleted: [Folder] "C:\Users\Mad Fad\appdata\locallow\babylontoolbar"

Successfully deleted: [Folder] "C:\Users\Mad Fad\appdata\locallow\delta"

Successfully deleted: [Folder] "C:\Program Files\delta"

Successfully deleted: [Folder] "C:\Program Files\tencent"

Successfully deleted: [Folder] "C:\Program Files\viewpoint"

Successfully deleted: [Folder] "C:\Users\Mad Fad\AppData\Roaming\microsoft\windows\start menu\programs\BrowserProtect"

~~~ Event Viewer Logs were cleared

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Scan was completed on Tue 05/28/2013 at 13:45:06.66

End of JRT log

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

# AdwCleaner v2.301 - Logfile created 05/28/2013 at 15:44:29

# Updated 16/05/2013 by Xplode

# Operating system : Windows Vista Home Premium (32 bits)

# User : Mad Fad - MADFAD-PC

# Boot Mode : Normal

# Running from : C:\Users\Mad Fad\Desktop\adwcleaner.exe

# Option [search]

***** [services] *****

***** [Files / Folders] *****

File Found : C:\Program Files\Mozilla FireFox\Components\AskSearch.js

File Found : C:\Users\Mad Fad\AppData\Local\Google\Chrome\User Data\Default\bProtector Web Data

File Found : C:\Users\Mad Fad\AppData\Local\Google\Chrome\User Data\Default\bprotectorpreferences

File Found : C:\Users\Mad Fad\AppData\Roaming\Mozilla\Firefox\Profiles\bgpdlo4n.default\bprotector_extensions.sqlite

File Found : C:\Users\Mad Fad\AppData\Roaming\Mozilla\Firefox\Profiles\bgpdlo4n.default\bprotector_prefs.js

File Found : C:\Users\Mad Fad\AppData\Roaming\Mozilla\Firefox\Profiles\bgpdlo4n.default\searchplugins\delta.xml

Folder Found : C:\Program Files\Common Files\AVG Secure Search

Folder Found : C:\Users\Mad Fad\AppData\Roaming\Mozilla\Firefox\Profiles\bgpdlo4n.default\extensions\ffxtlbr@delta.com

***** [Registry] *****

Key Found : HKCU\Software\5955dadeb239e815

Key Found : HKCU\Software\DataMngr_Toolbar

Key Found : HKCU\Software\Delta

Key Found : HKCU\Software\InstallCore

Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}

Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Delta

Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Delta Chrome Toolbar

Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}

Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}

Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0702A2B6-13AA-4090-9E01-BCDC85DD933F}

Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}

Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{201F27D4-3704-41D6-89C1-AA35E39143ED}

Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B}

Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3041D03E-FD4B-44E0-B742-2D9B88305F98}

Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}

Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{98889811-442D-49DD-99D7-DC866BE87DBC}

Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}

Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}

Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}

Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}

Key Found : HKCU\Software\TENCENT

Key Found : HKCU\Software\YahooPartnerToolbar

Key Found : HKLM\SOFTWARE\5955dadeb239e815

Key Found : HKLM\Software\AVG Security Toolbar

Key Found : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}

Key Found : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}

Key Found : HKLM\SOFTWARE\Classes\AppID\{39CB8175-E224-4446-8746-00566302DF8D}

Key Found : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}

Key Found : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}

Key Found : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}

Key Found : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}

Key Found : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}

Key Found : HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}

Key Found : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}

Key Found : HKLM\SOFTWARE\Classes\CLSID\{261DD098-8A3E-43D4-87AA-63324FA897D8}

Key Found : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}

Key Found : HKLM\SOFTWARE\Classes\CLSID\{4FCB4630-2A1C-4AA1-B422-345E8DC8A6DE}

Key Found : HKLM\SOFTWARE\Classes\CLSID\{761F6A83-F007-49E4-8EAC-CDB6808EF06F}

Key Found : HKLM\SOFTWARE\Classes\CLSID\{76C45B18-A29E-43EA-AAF8-AF55C2E1AE17}

Key Found : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}

Key Found : HKLM\SOFTWARE\Classes\CLSID\{86838207-681D-469D-9511-D0DCC6F19F9B}

Key Found : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}

Key Found : HKLM\SOFTWARE\Classes\CLSID\{96EF404C-24C7-43D0-9096-4CCC8BB7CCAC}

Key Found : HKLM\SOFTWARE\Classes\CLSID\{97720195-206A-42AE-8E65-260B9BA5589F}

Key Found : HKLM\SOFTWARE\Classes\CLSID\{97D69524-BB57-4185-9C7F-5F05593B771A}

Key Found : HKLM\SOFTWARE\Classes\CLSID\{986F7A5A-9676-47E1-8642-F41F8C3FCF82}

Key Found : HKLM\SOFTWARE\Classes\CLSID\{B18788A4-92BD-440E-A4D1-380C36531119}

Key Found : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}

Key Found : HKLM\SOFTWARE\Classes\CLSID\{E97A663B-81A6-49C5-A6D3-BCB05BA1DE26}

Key Found : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}

Key Found : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}

Key Found : HKLM\SOFTWARE\Classes\Interface\{1231839B-064E-4788-B865-465A1B5266FD}

Key Found : HKLM\SOFTWARE\Classes\Interface\{2DAC2231-CC35-482B-97C5-CED1D4185080}

Key Found : HKLM\SOFTWARE\Classes\Interface\{3F1CD84C-04A3-4EA0-9EA1-7D134FD66C82}

Key Found : HKLM\SOFTWARE\Classes\Interface\{3F83A9CA-B5F0-44EC-9357-35BB3E84B07F}

Key Found : HKLM\SOFTWARE\Classes\Interface\{47E520EA-CAD2-4F51-8F30-613B3A1C33EB}

Key Found : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}

Key Found : HKLM\SOFTWARE\Classes\Interface\{57C91446-8D81-4156-A70E-624551442DE9}

Key Found : HKLM\SOFTWARE\Classes\Interface\{70AFB7B2-9FB5-4A70-905B-0E9576142E1D}

Key Found : HKLM\SOFTWARE\Classes\Interface\{7AD65FD1-79E0-406D-B03C-DD7C14726D69}

Key Found : HKLM\SOFTWARE\Classes\Interface\{97DD820D-2E20-40AD-B01E-6730B2FCE630}

Key Found : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}

Key Found : HKLM\SOFTWARE\Classes\Interface\{B177446D-54A4-4869-BABC-8566110B4BE0}

Key Found : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}

Key Found : HKLM\SOFTWARE\Classes\Interface\{D9D1DFC5-502D-43E4-B1BB-4D0B7841489A}

Key Found : HKLM\SOFTWARE\Classes\Interface\{E0B07188-A528-4F9E-B2F7-C7FDE8680AE4}

Key Found : HKLM\SOFTWARE\Classes\Interface\{F05B12E1-ADE8-4485-B45B-898748B53C37}

Key Found : HKLM\SOFTWARE\Classes\TypeLib\{39CB8175-E224-4446-8746-00566302DF8D}

Key Found : HKLM\SOFTWARE\Classes\TypeLib\{4599D05A-D545-4069-BB42-5895B4EAE05B}

Key Found : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}

Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}

Key Found : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}

Key Found : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}

Key Found : HKLM\Software\Delta

Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{348C2DF3-1191-4C3E-92A6-B3A89A9D9C85}

Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}

Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}

Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}

Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{03F998B2-0E00-11D3-A498-00104B6EB52E}

Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}

Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}

Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}

Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}

Key Found : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\063A857434EDED11A893800002C0A966

Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}

Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Delta

Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Delta Chrome Toolbar

Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Viewpoint Manager

Key Found : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin

Key Found : HKLM\Software\TENCENT

Key Found : HKLM\Software\Viewpoint

Key Found : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WajamUpdater

Value Found : HKCU\Software\Microsoft\Internet Explorer\Main [bprotector start page]

Value Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope]

Value Found : HKCU\Software\Mozilla\Firefox\Extensions [{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}]

Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}]

Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]

Value Found : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar]

***** [internet Browsers] *****

-\\ Internet Explorer v7.0.6000.17037

[HKCU\Software\Microsoft\Internet Explorer\Main - bProtector Start Page] = hxxp://www2.delta-search.com/?affID=121846&babsrc=HP_ss&mntrId=2C47001E68085C02

[HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - bProtectTabs] = hxxp://www2.delta-search.com/?affID=121846&babsrc=NT_ss&mntrId=2C47001E68085C02

-\\ Mozilla Firefox v [unable to get version]

File : C:\Users\Mad Fad\AppData\Roaming\Mozilla\Firefox\Profiles\bgpdlo4n.default\prefs.js

Found : user_pref("browser.search.defaultenginename", "AVG Secure Search");

Found : user_pref("browser.search.selectedEngine", "AVG Secure Search");

-\\ Google Chrome v27.0.1453.94

File : C:\Users\Mad Fad\AppData\Local\Google\Chrome\User Data\Default\Preferences

Found [l.29] : keyword = "babylon.com",

Found [l.33] : search_url = "hxxp://www2.delta-search.com/?q={searchTerms}&affID=121846&babsrc=SP_ss&mntrId=2C47001E68085C02",

*************************

AdwCleaner[R1].txt - [10642 octets] - [28/05/2013 15:44:29]

########## EOF - C:\AdwCleaner[R1].txt - [10703 octets] ##########

Link to post
Share on other sites

  1. Please re-run AdwCleaner
  2. Click on Delete button.
  3. Confirm each time with OK.
  4. Your computer will be rebooted automatically. A text file will open after the restart. Please post the content of that logfile in your reply.

Note: You can find the logfile at C:\AdwCleaner[sn].txt as well - n is the order number.

Link to post
Share on other sites

Ok, here you go. What's next, and does this look to be progressing well?

Key will be getting the Vista updates in place once the Windows Installer is working again (haven't re-tried that yet).

Thanks

# AdwCleaner v2.301 - Logfile created 05/29/2013 at 06:28:38

# Updated 16/05/2013 by Xplode

# Operating system : Windows Vista Home Premium (32 bits)

# User : Mad Fad - MADFAD-PC

# Boot Mode : Normal

# Running from : C:\Users\Mad Fad\Desktop\adwcleaner.exe

# Option [Delete]

***** [services] *****

***** [Files / Folders] *****

Deleted on reboot : C:\Program Files\Common Files\AVG Secure Search

File Deleted : C:\Program Files\Mozilla FireFox\Components\AskSearch.js

File Deleted : C:\Users\Mad Fad\AppData\Local\Google\Chrome\User Data\Default\bProtector Web Data

File Deleted : C:\Users\Mad Fad\AppData\Local\Google\Chrome\User Data\Default\bprotectorpreferences

File Deleted : C:\Users\Mad Fad\AppData\Roaming\Mozilla\Firefox\Profiles\bgpdlo4n.default\bprotector_extensions.sqlite

File Deleted : C:\Users\Mad Fad\AppData\Roaming\Mozilla\Firefox\Profiles\bgpdlo4n.default\bprotector_prefs.js

File Deleted : C:\Users\Mad Fad\AppData\Roaming\Mozilla\Firefox\Profiles\bgpdlo4n.default\searchplugins\delta.xml

Folder Deleted : C:\Users\Mad Fad\AppData\Roaming\Mozilla\Firefox\Profiles\bgpdlo4n.default\extensions\ffxtlbr@delta.com

***** [Registry] *****

Key Deleted : HKCU\Software\5955dadeb239e815

Key Deleted : HKCU\Software\DataMngr_Toolbar

Key Deleted : HKCU\Software\Delta

Key Deleted : HKCU\Software\InstallCore

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Delta

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Delta Chrome Toolbar

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0702A2B6-13AA-4090-9E01-BCDC85DD933F}

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{201F27D4-3704-41D6-89C1-AA35E39143ED}

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B}

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3041D03E-FD4B-44E0-B742-2D9B88305F98}

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{98889811-442D-49DD-99D7-DC866BE87DBC}

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}

Key Deleted : HKCU\Software\TENCENT

Key Deleted : HKCU\Software\YahooPartnerToolbar

Key Deleted : HKLM\SOFTWARE\5955dadeb239e815

Key Deleted : HKLM\Software\AVG Security Toolbar

Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}

Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}

Key Deleted : HKLM\SOFTWARE\Classes\AppID\{39CB8175-E224-4446-8746-00566302DF8D}

Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}

Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}

Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}

Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}

Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}

Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}

Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{261DD098-8A3E-43D4-87AA-63324FA897D8}

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4FCB4630-2A1C-4AA1-B422-345E8DC8A6DE}

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{761F6A83-F007-49E4-8EAC-CDB6808EF06F}

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{76C45B18-A29E-43EA-AAF8-AF55C2E1AE17}

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{86838207-681D-469D-9511-D0DCC6F19F9B}

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{96EF404C-24C7-43D0-9096-4CCC8BB7CCAC}

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{97720195-206A-42AE-8E65-260B9BA5589F}

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{97D69524-BB57-4185-9C7F-5F05593B771A}

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{986F7A5A-9676-47E1-8642-F41F8C3FCF82}

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B18788A4-92BD-440E-A4D1-380C36531119}

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E97A663B-81A6-49C5-A6D3-BCB05BA1DE26}

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1231839B-064E-4788-B865-465A1B5266FD}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2DAC2231-CC35-482B-97C5-CED1D4185080}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3F1CD84C-04A3-4EA0-9EA1-7D134FD66C82}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3F83A9CA-B5F0-44EC-9357-35BB3E84B07F}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{47E520EA-CAD2-4F51-8F30-613B3A1C33EB}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{57C91446-8D81-4156-A70E-624551442DE9}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{70AFB7B2-9FB5-4A70-905B-0E9576142E1D}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{7AD65FD1-79E0-406D-B03C-DD7C14726D69}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{97DD820D-2E20-40AD-B01E-6730B2FCE630}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B177446D-54A4-4869-BABC-8566110B4BE0}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D9D1DFC5-502D-43E4-B1BB-4D0B7841489A}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E0B07188-A528-4F9E-B2F7-C7FDE8680AE4}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F05B12E1-ADE8-4485-B45B-898748B53C37}

Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{39CB8175-E224-4446-8746-00566302DF8D}

Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4599D05A-D545-4069-BB42-5895B4EAE05B}

Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}

Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}

Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}

Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}

Key Deleted : HKLM\Software\Delta

Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{348C2DF3-1191-4C3E-92A6-B3A89A9D9C85}

Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}

Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}

Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}

Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{03F998B2-0E00-11D3-A498-00104B6EB52E}

Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}

Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}

Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}

Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}

Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\063A857434EDED11A893800002C0A966

Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}

Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Delta

Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Delta Chrome Toolbar

Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Viewpoint Manager

Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin

Key Deleted : HKLM\Software\TENCENT

Key Deleted : HKLM\Software\Viewpoint

Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WajamUpdater

Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [bprotector start page]

Value Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope]

Value Deleted : HKCU\Software\Mozilla\Firefox\Extensions [{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}]

Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}]

Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]

Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar]

***** [internet Browsers] *****

-\\ Internet Explorer v7.0.6000.17037

Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - bProtectTabs] = hxxp://www2.delta-search.com/?affID=121846&babsrc=NT_ss&mntrId=2C47001E68085C02 --> hxxp://www.google.com

-\\ Mozilla Firefox v [unable to get version]

File : C:\Users\Mad Fad\AppData\Roaming\Mozilla\Firefox\Profiles\bgpdlo4n.default\prefs.js

C:\Users\Mad Fad\AppData\Roaming\Mozilla\Firefox\Profiles\bgpdlo4n.default\user.js ... Deleted !

Deleted : user_pref("browser.search.defaultenginename", "AVG Secure Search");

Deleted : user_pref("browser.search.selectedEngine", "AVG Secure Search");

-\\ Google Chrome v27.0.1453.94

File : C:\Users\Mad Fad\AppData\Local\Google\Chrome\User Data\Default\Preferences

Deleted [l.34] : keyword = "babylon.com",

Deleted [l.38] : search_url = "hxxp://www2.delta-search.com/?q={searchTerms}&affID=121846&babsrc=SP_ss&mntrId=[...]

*************************

AdwCleaner[R1].txt - [10773 octets] - [28/05/2013 15:44:29]

AdwCleaner[s1].txt - [10894 octets] - [29/05/2013 06:28:38]

########## EOF - C:\AdwCleaner[s1].txt - [10955 octets] ##########

Link to post
Share on other sites

Step 1

  • Launch Malwarebytes' Anti-Malware
  • Go to Update tab and select Check for Updates. If an update is found, it will download and install the latest version.
  • Go to Scanner tab and select Perform Quick Scan, then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer,please do so immediately.

Step 2

  • Download on the desktop RogueKiller
  • Quit all programs
  • Start RogueKiller.exe
  • Wait until Prescan has finished ...
  • Click on Scan. Click on Report and copy/paste the content of the notepad in your next reply.

In your next reply, post the following log files:

  • Malwarebytes' Anti-Malware log
  • RogueKiller log

Link to post
Share on other sites

Here you go:

Malwarebytes Anti-Malware (Trial) 1.75.0.1300

www.malwarebytes.org

Database version: v2013.05.29.04

Windows Vista x86 NTFS

Internet Explorer 7.0.6000.17037

Mad Fad :: MADFAD-PC [administrator]

Protection: Enabled

5/29/2013 9:55:47 AM

mbam-log-2013-05-29 (09-55-47).txt

Scan type: Full scan (C:\|D:\|E:\|)

Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM

Scan options disabled: P2P

Objects scanned: 374157

Time elapsed: 2 hour(s), 34 minute(s), 3 second(s)

Memory Processes Detected: 0

(No malicious items detected)

Memory Modules Detected: 0

(No malicious items detected)

Registry Keys Detected: 0

(No malicious items detected)

Registry Values Detected: 0

(No malicious items detected)

Registry Data Items Detected: 0

(No malicious items detected)

Folders Detected: 0

(No malicious items detected)

Files Detected: 0

(No malicious items detected)

(end)

RogueKiller V8.5.4 [Mar 18 2013] by Tigzy

mail : tigzyRK<at>gmail<dot>com

Feedback : http://www.geekstogo.com/forum/files/file/413-roguekiller/

Website : http://tigzy.geekstogo.com/roguekiller.php

Blog : http://tigzyrk.blogspot.com/

Operating System : Windows Vista (6.0.6000 ) 32 bits version

Started in : Normal mode

User : Mad Fad [Admin rights]

Mode : Scan -- Date : 05/29/2013 13:15:55

| ARK || FAK || MBR |

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 6 ¤¤¤

[TASK][sUSP PATH] EPUpdater : C:\Users\MADFAD~1\AppData\Roaming\BABSOL~1\Shared\BabMaint.exe [x] -> FOUND

[HJPOL] HKCU\[...]\System : DisableTaskMgr (0) -> FOUND

[HJPOL] HKCU\[...]\System : DisableRegistryTools (0) -> FOUND

[HJPOL] HKLM\[...]\System : DisableRegistryTools (0) -> FOUND

[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND

[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [LOADED] ¤¤¤

¤¤¤ HOSTS File: ¤¤¤

--> C:\Windows\system32\drivers\etc\hosts

127.0.0.1 localhost

¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: WDC WD2500BEVS-60UST0 ATA Device +++++

--- User ---

[MBR] ede058bdf452fdc9beca1c99d11acaba

[bSP] 1c18e065a470aef3f4ccaa97422a5411 : MBR Code unknown

Partition table:

0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 226251 Mo

1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 463362795 | Size: 12221 Mo

User = LL1 ... OK!

User = LL2 ... OK!

Finished : << RKreport[1]_S_05292013_02d1315.txt >>

RKreport[1]_S_05292013_02d1315.txt

Link to post
Share on other sites

Please manually delete your ComboFix copy. Then:

Note: Please do not run this tool without special supervision and instructions of someone authorized to do so. Otherwise, you could end up with serious problems. For more details, read this article: ComboFix usage, Questions, Help? - Look here

Please visit this webpage for download links, and instructions for running the tool:

http://www.bleepingc...to-use-combofix

* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Please post the C:\ComboFix.txt in your next reply for further review.

Note: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.

Link to post
Share on other sites

Here you go, Maniac.

ComboFix 13-05-30.01 - Mad Fad 05/29/2013 21:56:04.1.2 - x86

Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.1982.1176 [GMT -4:00]

Running from: c:\users\Mad Fad\Downloads\ComboFix.exe

.

.

((((((((((((((((((((((((( Files Created from 2013-04-28 to 2013-05-30 )))))))))))))))))))))))))))))))

.

.

2013-05-30 02:06 . 2013-05-30 02:06 -------- d-----w- c:\users\Mad Fad\AppData\Local\temp

2013-05-30 02:06 . 2013-05-30 02:06 -------- d-----w- c:\users\Default\AppData\Local\temp

2013-05-29 10:28 . 2013-05-29 10:29 115 ----a-w- c:\windows\DeleteOnReboot.bat

2013-05-28 17:49 . 2013-05-14 05:49 7016152 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{15C99DC4-3574-4ED9-A77C-23A18B603B2C}\mpengine.dll

2013-05-28 17:29 . 2013-05-28 17:29 -------- d-----w- c:\windows\ERUNT

2013-05-28 17:28 . 2013-05-28 17:40 -------- d-----w- C:\JRT

2013-05-28 02:42 . 2013-05-28 02:42 -------- d-sh--w- c:\programdata\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}

2013-05-27 21:12 . 2013-05-27 21:12 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2013-05-27 21:12 . 2013-04-04 18:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys

2013-05-27 20:47 . 2013-05-27 20:47 -------- d-----w- c:\progra~2\85829C~1

2013-05-27 19:23 . 2009-07-14 01:19 38480 ----a-w- c:\windows\system32\drivers\WdfLdr.sys

2013-05-27 19:23 . 2009-07-14 01:19 445008 ----a-w- c:\windows\system32\drivers\Wdf01000.sys

2013-05-27 19:17 . 2013-05-27 19:17 -------- d-----w- c:\windows\system32\searchplugins

2013-05-27 19:17 . 2013-05-27 19:17 -------- d-----w- c:\windows\system32\Extensions

2013-05-27 19:04 . 2013-05-27 19:04 -------- d-----w- c:\progra~2\85C39C~1

2013-05-27 18:34 . 2013-05-27 18:34 -------- d-----w- c:\progra~2\8520-1~4

2013-05-27 16:58 . 2013-05-27 16:58 -------- d-----w- c:\progra~2\!!8520~1

2013-05-27 16:50 . 2013-05-27 16:50 -------- d-----w- c:\progra~2\8520-1~3

2013-05-23 03:31 . 2013-05-23 03:31 -------- d-----w- c:\progra~2\8520-1~2

2013-05-12 16:34 . 2013-05-09 08:59 29816 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys

2013-05-12 16:34 . 2013-05-09 08:59 368944 ----a-w- c:\windows\system32\drivers\aswSP.sys

2013-05-12 16:34 . 2013-05-09 08:59 49760 ----a-w- c:\windows\system32\drivers\aswRdr.sys

2013-05-12 16:34 . 2013-05-09 08:59 765736 ----a-w- c:\windows\system32\drivers\aswSnx.sys

2013-05-12 16:34 . 2013-05-09 08:59 56080 ----a-w- c:\windows\system32\drivers\aswTdi.sys

2013-05-12 16:34 . 2013-05-09 08:59 174664 ----a-w- c:\windows\system32\drivers\aswVmm.sys

2013-05-12 16:34 . 2013-05-09 08:59 49376 ----a-w- c:\windows\system32\drivers\aswRvrt.sys

2013-05-12 16:34 . 2013-05-09 08:59 66336 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys

2013-05-12 16:34 . 2013-05-09 08:58 229648 ----a-w- c:\windows\system32\aswBoot.exe

2013-05-12 16:33 . 2013-05-09 08:58 41664 ----a-w- c:\windows\avastSS.scr

2013-05-12 16:31 . 2013-05-12 16:31 -------- d-----w- c:\program files\AVAST Software

2013-05-12 16:30 . 2013-05-12 16:31 -------- d-----w- c:\programdata\AVAST Software

2013-05-12 16:09 . 2013-05-12 16:09 -------- d-----w- c:\progra~2\PD1C3~1

2013-05-12 16:09 . 2013-05-12 16:09 -------- d-----w- c:\progra~2\8520-1~1

2013-05-11 13:50 . 2013-05-11 13:50 -------- d-sh--w- c:\programdata\r4Bmi7waQJy9

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2013-05-23 03:28 . 2013-04-20 13:29 37664 ----a-w- c:\windows\system32\drivers\avgtpx86.sys

2013-05-02 06:06 . 2010-12-04 23:22 238872 ------w- c:\windows\system32\MpSigStub.exe

2013-03-06 03:46 . 2013-03-06 03:46 71024 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2013-03-06 03:46 . 2013-03-06 03:46 691568 ----a-w- c:\windows\system32\FlashPlayerApp.exe

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]

@="{472083B0-C522-11CF-8763-00608CC02F24}"

[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]

2013-05-09 08:58 121968 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]

@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]

2012-11-13 23:32 129272 ----a-w- c:\users\Mad Fad\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]

@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]

2012-11-13 23:32 129272 ----a-w- c:\users\Mad Fad\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]

@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]

2012-11-13 23:32 129272 ----a-w- c:\users\Mad Fad\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-08-23 455968]

"HPAdvisor"="c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2007-10-02 1783136]

"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 102400]

"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-10-01 181544]

"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-09-19 202032]

"OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-09-04 554320]

"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-08-17 218408]

"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-23 80896]

"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-11 49152]

"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-09-13 480560]

"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-08 311296]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]

"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-01-17 185872]

"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2013-04-04 887432]

"Nikon Message Center 2"="c:\program files\Nikon\Nikon Message Center 2\NkMC2.exe" [2010-05-25 619008]

"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-01-28 59720]

"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2012-10-25 421888]

"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2013-02-18 152392]

"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-05-09 4858968]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-24 13601312]

"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-06-24 92704]

"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2011-10-14 2299176]

.

c:\users\Mad Fad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Dropbox.lnk - c:\users\Mad Fad\AppData\Roaming\Dropbox\bin\Dropbox.exe [2013-3-12 29106336]

OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

.

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-1-2 210520]

McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.0.318\SSScheduler.exe [N/A]

Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

.

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]

BootExecute REG_MULTI_SZ autocheck autochk /r \??\C:\0autocheck autochk *

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]

"DisableMonitoring"=dword:00000001

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

"DisableMonitoring"=dword:00000001

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]

"DisableMonitoring"=dword:00000001

.

--- Other Services/Drivers In Memory ---

.

*NewlyCreated* - TRUESIGHT

*Deregistered* - TrueSight

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

.

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]

2007-08-23 22:34 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe

.

Contents of the 'Scheduled Tasks' folder

.

2013-05-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1178580412-3150187080-1603977272-1000Core.job

- c:\users\Mad Fad\AppData\Local\Google\Update\GoogleUpdate.exe [2009-12-05 22:18]

.

2013-05-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1178580412-3150187080-1603977272-1000UA.job

- c:\users\Mad Fad\AppData\Local\Google\Update\GoogleUpdate.exe [2009-12-05 22:18]

.

2013-05-29 c:\windows\Tasks\User_Feed_Synchronization-{D38B8088-739A-4735-9EB6-2B7ECD876F8E}.job

- c:\windows\system32\msfeedssync.exe [2006-11-02 09:45]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.google.com/

mStart Page = hxxp://www.google.com

uInternet Settings,ProxyOverride = *.local

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000

TCP: DhcpNameServer = 192.168.1.1

.

.

**************************************************************************

.

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2013-05-29 22:06

Windows 6.0.6000 NTFS

.

scanning hidden processes ...

.

scanning hidden autostart entries ...

.

scanning hidden files ...

.

scan completed successfully

hidden files: 0

.

**************************************************************************

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

.

--------------------- DLLs Loaded Under Running Processes ---------------------

.

- - - - - - - > 'Explorer.exe'(2936)

c:\users\Mad Fad\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll

c:\program files\Hewlett-Packard\HP Advisor\Pillars\Market\MLDeskBand.dll

.

Completion time: 2013-05-29 22:08:34

ComboFix-quarantined-files.txt 2013-05-30 02:08

ComboFix2.txt 2013-05-28 02:30

.

Pre-Run: 146,111,279,104 bytes free

Post-Run: 146,242,908,160 bytes free

.

- - End Of File - - A9F175991D2CDAEFAD702ECC61E095DC

Link to post
Share on other sites

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

Folder::

c:\progra~2\85829C~1

c:\progra~2\85C39C~1

c:\progra~2\8520-1~4

c:\progra~2\!!8520~1

c:\progra~2\8520-1~3

c:\progra~2\8520-1~2

c:\progra~2\PD1C3~1

c:\progra~2\8520-1~1

c:\programdata\r4Bmi7waQJy9

JavaClearCache::

Save this as CFScript.txt, in the same location as ComboFix.exe

CFScriptB-4.gif

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

Link to post
Share on other sites

Here you go:

ComboFix 13-05-30.02 - Mad Fad 05/30/2013 7:02.2.2 - x86

Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.1982.1199 [GMT -4:00]

Running from: c:\users\Mad Fad\Downloads\ComboFix.exe

Command switches used :: c:\users\Mad Fad\Downloads\cfscript.txt

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\progra~2\!!8520~1

c:\progra~2\8520-1~1

c:\progra~2\8520-1~2

c:\progra~2\8520-1~3

c:\progra~2\8520-1~4

c:\progra~2\85829C~1

c:\progra~2\85C39C~1

c:\progra~2\PD1C3~1

c:\programdata\r4Bmi7waQJy9

.

.

((((((((((((((((((((((((( Files Created from 2013-04-28 to 2013-05-30 )))))))))))))))))))))))))))))))

.

.

2013-05-30 11:11 . 2013-05-30 11:11 -------- d-----w- c:\users\Mad Fad\AppData\Local\temp

2013-05-30 11:11 . 2013-05-30 11:11 -------- d-----w- c:\users\Default\AppData\Local\temp

2013-05-29 10:28 . 2013-05-29 10:29 115 ----a-w- c:\windows\DeleteOnReboot.bat

2013-05-28 17:49 . 2013-05-14 05:49 7016152 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{15C99DC4-3574-4ED9-A77C-23A18B603B2C}\mpengine.dll

2013-05-28 17:29 . 2013-05-28 17:29 -------- d-----w- c:\windows\ERUNT

2013-05-28 17:28 . 2013-05-28 17:40 -------- d-----w- C:\JRT

2013-05-28 02:42 . 2013-05-28 02:42 -------- d-sh--w- c:\programdata\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}

2013-05-27 21:12 . 2013-05-27 21:12 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2013-05-27 21:12 . 2013-04-04 18:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys

2013-05-27 19:23 . 2009-07-14 01:19 38480 ----a-w- c:\windows\system32\drivers\WdfLdr.sys

2013-05-27 19:23 . 2009-07-14 01:19 445008 ----a-w- c:\windows\system32\drivers\Wdf01000.sys

2013-05-27 19:17 . 2013-05-27 19:17 -------- d-----w- c:\windows\system32\searchplugins

2013-05-27 19:17 . 2013-05-27 19:17 -------- d-----w- c:\windows\system32\Extensions

2013-05-12 16:34 . 2013-05-09 08:59 29816 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys

2013-05-12 16:34 . 2013-05-09 08:59 368944 ----a-w- c:\windows\system32\drivers\aswSP.sys

2013-05-12 16:34 . 2013-05-09 08:59 49760 ----a-w- c:\windows\system32\drivers\aswRdr.sys

2013-05-12 16:34 . 2013-05-09 08:59 765736 ----a-w- c:\windows\system32\drivers\aswSnx.sys

2013-05-12 16:34 . 2013-05-09 08:59 56080 ----a-w- c:\windows\system32\drivers\aswTdi.sys

2013-05-12 16:34 . 2013-05-09 08:59 174664 ----a-w- c:\windows\system32\drivers\aswVmm.sys

2013-05-12 16:34 . 2013-05-09 08:59 49376 ----a-w- c:\windows\system32\drivers\aswRvrt.sys

2013-05-12 16:34 . 2013-05-09 08:59 66336 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys

2013-05-12 16:34 . 2013-05-09 08:58 229648 ----a-w- c:\windows\system32\aswBoot.exe

2013-05-12 16:33 . 2013-05-09 08:58 41664 ----a-w- c:\windows\avastSS.scr

2013-05-12 16:31 . 2013-05-12 16:31 -------- d-----w- c:\program files\AVAST Software

2013-05-12 16:30 . 2013-05-12 16:31 -------- d-----w- c:\programdata\AVAST Software

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2013-05-23 03:28 . 2013-04-20 13:29 37664 ----a-w- c:\windows\system32\drivers\avgtpx86.sys

2013-05-02 06:06 . 2010-12-04 23:22 238872 ------w- c:\windows\system32\MpSigStub.exe

2013-03-06 03:46 . 2013-03-06 03:46 71024 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2013-03-06 03:46 . 2013-03-06 03:46 691568 ----a-w- c:\windows\system32\FlashPlayerApp.exe

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]

@="{472083B0-C522-11CF-8763-00608CC02F24}"

[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]

2013-05-09 08:58 121968 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]

@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]

2012-11-13 23:32 129272 ----a-w- c:\users\Mad Fad\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]

@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]

2012-11-13 23:32 129272 ----a-w- c:\users\Mad Fad\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]

@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]

2012-11-13 23:32 129272 ----a-w- c:\users\Mad Fad\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-08-23 455968]

"HPAdvisor"="c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2007-10-02 1783136]

"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 102400]

"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-10-01 181544]

"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-09-19 202032]

"OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-09-04 554320]

"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-08-17 218408]

"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-23 80896]

"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-11 49152]

"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-09-13 480560]

"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-08 311296]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]

"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-01-17 185872]

"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2013-04-04 887432]

"Nikon Message Center 2"="c:\program files\Nikon\Nikon Message Center 2\NkMC2.exe" [2010-05-25 619008]

"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-01-28 59720]

"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2012-10-25 421888]

"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2013-02-18 152392]

"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-05-09 4858968]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-24 13601312]

"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-06-24 92704]

"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2011-10-14 2299176]

.

c:\users\Mad Fad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Dropbox.lnk - c:\users\Mad Fad\AppData\Roaming\Dropbox\bin\Dropbox.exe [2013-3-12 29106336]

OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

.

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-1-2 210520]

McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.0.318\SSScheduler.exe [N/A]

Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

.

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]

BootExecute REG_MULTI_SZ autocheck autochk /r \??\C:\0autocheck autochk *

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]

"DisableMonitoring"=dword:00000001

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

"DisableMonitoring"=dword:00000001

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]

"DisableMonitoring"=dword:00000001

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

.

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]

2007-08-23 22:34 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe

.

Contents of the 'Scheduled Tasks' folder

.

2013-05-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1178580412-3150187080-1603977272-1000Core.job

- c:\users\Mad Fad\AppData\Local\Google\Update\GoogleUpdate.exe [2009-12-05 22:18]

.

2013-05-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1178580412-3150187080-1603977272-1000UA.job

- c:\users\Mad Fad\AppData\Local\Google\Update\GoogleUpdate.exe [2009-12-05 22:18]

.

2013-05-29 c:\windows\Tasks\User_Feed_Synchronization-{D38B8088-739A-4735-9EB6-2B7ECD876F8E}.job

- c:\windows\system32\msfeedssync.exe [2006-11-02 09:45]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.google.com/

mStart Page = hxxp://www.google.com

uInternet Settings,ProxyOverride = *.local

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000

TCP: DhcpNameServer = 192.168.1.1

.

.

**************************************************************************

.

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2013-05-30 07:11

Windows 6.0.6000 NTFS

.

scanning hidden processes ...

.

scanning hidden autostart entries ...

.

scanning hidden files ...

.

scan completed successfully

hidden files: 0

.

**************************************************************************

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

.

--------------------- DLLs Loaded Under Running Processes ---------------------

.

- - - - - - - > 'Explorer.exe'(4160)

c:\users\Mad Fad\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll

c:\program files\Hewlett-Packard\HP Advisor\Pillars\Market\MLDeskBand.dll

.

Completion time: 2013-05-30 07:14:19

ComboFix-quarantined-files.txt 2013-05-30 11:14

ComboFix2.txt 2013-05-30 02:08

ComboFix3.txt 2013-05-28 02:30

.

Pre-Run: 144,916,496,384 bytes free

Post-Run: 153,868,648,448 bytes free

.

- - End Of File - - AA794FC3BA86FB9402C3CA5A1049BEE5

Link to post
Share on other sites

Please scan your machine with ESET OnlineScan

  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the esetonlinebtn.png button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on esetsmartinstaller_enu.exe to download the ESET Smart Installer.
      Save it to your Desktop.
    • Double click on the esetsmartinstaller_enu.png to download the ESET Smart Installer. icon on your Desktop.

    [*]Check "YES, I accept the Terms of Use."

    [*]Click the Start button.

    [*]Accept any security warnings from your browser.

    [*]Under Scan Settings, check "Scan Archives" and "Remove found threats"

    [*]Click Advanced settings and select the following:

    • Scan potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology

    [*]ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.

    [*]When the scan completes, click List Threats

    [*]Click Export, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.

    [*]Click the Back button.

    [*]Click the Finish button.

Link to post
Share on other sites

Here you go:

C:\Qoobox\Quarantine\C\Users\Mad Fad\Firefox_Setup_20.0.exe.vir Win32/InstallCore.BL application cleaned by deleting - quarantined

C:\Qoobox\Quarantine\C\Users\Mad Fad\SoftonicDownloader_for_photomerge.exe.vir a variant of Win32/SoftonicDownloader.E application cleaned by deleting - quarantined

C:\Users\Mad Fad\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\1\d5faec1-5dadf17f probably a variant of Java/TrojanDownloader.Agent.NFH trojan cleaned by deleting - quarantined

C:\Users\Mad Fad\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\51308611-5654fd54 probably a variant of Java/TrojanDownloader.Agent.NFH trojan cleaned by deleting - quarantined

C:\Users\Mad Fad\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\788bb311-20790e76 probably a variant of Win32/Spy.Banker.KNYQRIS trojan cleaned by deleting - quarantined

C:\Users\Mad Fad\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\788bb311-2395ff83 probably a variant of Win32/Spy.Banker.KNYQRIS trojan cleaned by deleting - quarantined

C:\Users\Mad Fad\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2\7a106902-2c7ccf00 probably a variant of Java/TrojanDownloader.Agent.NFH trojan cleaned by deleting - quarantined

C:\Users\Mad Fad\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\26\2f3b2f1a-3c781b32 probably a variant of Java/TrojanDownloader.Agent.NFH trojan cleaned by deleting - quarantined

C:\Users\Mad Fad\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32\14a8f120-1f7c2000 probably a variant of Java/TrojanDownloader.Agent.NFH trojan cleaned by deleting - quarantined

C:\Users\Mad Fad\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32\36705760-6e894786 probably a variant of Java/TrojanDownloader.Agent.NFH trojan cleaned by deleting - quarantined

C:\Users\Mad Fad\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40\17205428-632062ad a variant of Java/Exploit.CVE-2013-0422.BF trojan cleaned by deleting - quarantined

C:\Users\Mad Fad\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40\5a173ce8-4b1ac38b multiple threats cleaned by deleting - quarantined

C:\Users\Mad Fad\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48\5851e4f0-429f5792 probably a variant of Java/TrojanDownloader.Agent.NFH trojan cleaned by deleting - quarantined

C:\Users\Mad Fad\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48\6bbe10f0-3b4d0cdc probably a variant of Java/TrojanDownloader.Agent.NFH trojan cleaned by deleting - quarantined

C:\Users\Mad Fad\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53\7313cab5-5e522a2f probably a variant of Java/TrojanDownloader.Agent.NFH trojan cleaned by deleting - quarantined

C:\Users\Mad Fad\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.40\agent\stub_data\stubinst_pkg_en-us.cab Win32/OpenCandy application deleted - quarantined

C:\Users\Mad Fad\Misc Downloads\Firefox_Setup_16.0.1.exe a variant of Win32/InstallCore.AY application cleaned by deleting - quarantined

Link to post
Share on other sites

javaicon.gif Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older versions of Java components and upgrade the application.

Upgrading Java :

Please download JavaRa to your desktop and unzip it to its own folder

  • Run JavaRa.exe, then click Remove JRE.
  • Run the built-in uninstallers for all copies of java listed
  • Click the Next button
  • Click the Next button again
  • Click the Java Manual Download link
  • A browser window will open with the Java download page
  • Click the Windows Offline (32-bit) or Windows Offline (64-bit) link to download Java (based on your browser type)
  • Run the installer
  • Close JavaRa

Link to post
Share on other sites

Did this, and got this message:

GetDefaultBrowserError:2

Then used the verify installation link on the Oracle Java download page, which initially showed no installation, and then provided a Java Detection link to run. Ran that and verified the current version as Java 7, update 21.

What's next, to try and update to Vista SP1 and then SP2? Perform an OS reinstall? Something else?

Link to post
Share on other sites

Manually installed Vista SP1

Checked for upgradability to Windows 7, using the Window Upgrade Advisor and Belarc Advsior

Uninstall of many apps incompatible with upgrade to Windows 7, and lots of unneeded programs.

I have been unable to unistall the AVG toolbar and Blackberry media sync, even though I downladed and ran the AVG toolbar removal tool.

Installed many additional Vista updates, including SP2

Installed TuneUp Utilities and ran twice

Avast reported a Rootkit while defragging via TuneUp (SVC:McComponentHostService > C:)

I deleted this, and Avast recommended a boot scan.

Did this and it found at least two files containing Win32:Malware_gen

Nothing listed in Avast detection history, though. Perhaps these had already been quarantined?

Ran MBAM in safe mode, no detections.

Ran tuneup utilities again.

For some time now, Vista has been showing a Blocked Startup Programs icon.

When I ask it to 'Show or remove' blocked programs, I get an error - Application failed to initialize: 0x80106ba.

Interestingly, I am given the option to Run a blocked progam, and the only one listed is MBAM.

And when I went to look for my most recent MBAM log, it appears to have been deleted. My guess is by TuneUp Utilities.

So, despite my like for the program, I uninstalled TuneUp Utilities.

During download for many additional Window updates, Avast reported two rootkits:

SVC:TuneUp.Utilities.Svc and .Drv. I deleted these and Avast requested a boot scan.

It's not clear if that ran normally (didn't look like it), but perhaps that's a consequence of being amidst Windows updates.

To help you see where I am now on this, a current DDS log and MBAM log are attached.

I'm assuming I would now need to get Vista all in order prior to considering the update to Windows 7.

And that it may generally be easier to start from a clean slate than to go through this process.

Please advise, and thanks in advance.

DDS (Ver_2012-11-20.01) - NTFS_x86

Internet Explorer: 7.0.6002.18005 BrowserJavaVersion: 10.21.2

Run by Mad Fad at 12:52:39 on 2013-06-02

Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.1982.746 [GMT -4:00]

.

AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}

SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}

.

============== Running Processes ================

.

C:\Windows\system32\wininit.exe

C:\Windows\system32\lsm.exe

C:\Windows\system32\nvvsvc.exe

C:\Windows\system32\SLsvc.exe

C:\Windows\servicing\TrustedInstaller.exe

C:\Windows\system32\rundll32.exe

C:\Program Files\AVAST Software\Avast\AvastSvc.exe

C:\Windows\system32\WLANExt.exe

C:\Windows\System32\spoolsv.exe

C:\Program Files\Common Files\LightScribe\LSSrvc.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe

C:\Windows\system32\SearchIndexer.exe

C:\Windows\system32\DRIVERS\xaudio.exe

C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Windows\system32\taskeng.exe

C:\Windows\system32\taskeng.exe

C:\Program Files\Synaptics\SynTP\SynTPStart.exe

C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe

C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe

C:\Windows\system32\wbem\wmiprvse.exe

C:\Program Files\AVAST Software\Avast\AvastUI.exe

C:\Windows\System32\rundll32.exe

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe

C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe

C:\Program Files\Windows Media Player\wmpnscfg.exe

C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe

C:\Windows\system32\wbem\unsecapp.exe

C:\Users\Mad Fad\AppData\Roaming\Dropbox\bin\Dropbox.exe

C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

C:\Windows\system32\wbem\wmiprvse.exe

C:\Program Files\Windows Media Player\wmpnetwk.exe

C:\Windows\system32\wuauclt.exe

C:\Windows\system32\SearchProtocolHost.exe

C:\Windows\system32\SearchFilterHost.exe

c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe

C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE

C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\system32\svchost.exe -k rpcss

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k LocalService

C:\Windows\system32\svchost.exe -k NetworkService

C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

C:\Windows\System32\svchost.exe -k HPZ12

C:\Windows\System32\svchost.exe -k HPZ12

C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

C:\Windows\system32\svchost.exe -k imgsvc

C:\Windows\System32\svchost.exe -k WerSvcGroup

C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

.

============== Pseudo HJT Report ===============

.

uStart Page = hxxp://www.google.com/

mStart Page = hxxp://www.google.com

BHO: MSS+ Identifier: {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - LocalServer32 - <no file>

BHO: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll

BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll

BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll

TB: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll

uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden

uRun: [HPAdvisor] c:\program files\hewlett-packard\hp advisor\HPAdvisor.exe autoRun

uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe

mRun: [synTPStart] c:\program files\synaptics\syntp\SynTPStart.exe

mRun: [uCam_Menu] "c:\program files\cyberlink\youcam\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\youcam" update "software\cyberlink\youcam\1.0"

mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe

mRun: [WAWifiMessage] c:\program files\hewlett-packard\hp wireless assistant\WiFiMsg.exe

mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript

mRun: [Nikon Message Center 2] c:\program files\nikon\nikon message center 2\NkMC2.exe -s

mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui

mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup

mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit

mRun: [synTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe

StartupFolder: c:\users\madfad~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\dropbox.lnk - c:\users\mad fad\appdata\roaming\dropbox\bin\Dropbox.exe

StartupFolder: c:\users\madfad~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE

uPolicies-Explorer: NoDrives = dword:0

mPolicies-Explorer: NoDrives = dword:0

mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0

mPolicies-System: EnableUIADesktopToggle = dword:0

IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000

IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office12\ONBttnIE.dll

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab

DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab

DPF: {CAFEEFAC-0017-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab

TCP: NameServer = 192.168.1.1

TCP: Interfaces\{924D4EAF-CC8A-4222-831E-68F8B6F5E82F} : DHCPNameServer = 192.168.1.1

Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\belarcadvisor\system\BAVoilaX.dll

Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll

LSA: Security Packages = kerberos msv1_0 schannel wdigest tspkg

mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"

.

============= SERVICES / DRIVERS ===============

.

R0 aswRvrt;aswRvrt;c:\windows\system32\drivers\aswRvrt.sys [2013-5-12 49376]

R0 aswVmm;aswVmm;c:\windows\system32\drivers\aswVmm.sys [2013-5-12 174664]

R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2013-5-12 765736]

R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2013-5-12 368944]

R1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx86.sys [2013-4-20 37664]

R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2013-5-12 29816]

R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2013-5-12 66336]

R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2013-5-12 46808]

R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2013-5-31 21504]

R2 MBAMScheduler;MBAMScheduler;c:\program files\malwarebytes' anti-malware\mbamscheduler.exe [2013-5-27 418376]

R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2013-5-27 701512]

R2 vToolbarUpdater15.2.0;vToolbarUpdater15.2.0;c:\program files\common files\avg secure search\vtoolbarupdater\15.2.0\ToolbarUpdater.exe [2013-5-22 1015984]

R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2013-5-27 22856]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]

S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-7-13 160944]

S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]

.

=============== Created Last 30 ================

.

2013-06-02 16:22:52 -------- d-----w- c:\program files\Windows Portable Devices

2013-06-02 15:01:09 92672 ----a-w- c:\windows\system32\UIAnimation.dll

2013-06-02 15:01:06 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll

2013-06-02 15:01:05 3023360 ----a-w- c:\windows\system32\UIRibbon.dll

2013-06-02 14:59:53 369664 ----a-w- c:\windows\system32\WMPhoto.dll

2013-06-02 14:59:44 974848 ----a-w- c:\windows\system32\WindowsCodecs.dll

2013-06-02 14:59:44 321024 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll

2013-06-02 14:59:44 252928 ----a-w- c:\windows\system32\dxdiag.exe

2013-06-02 14:59:44 195584 ----a-w- c:\windows\system32\dxdiagn.dll

2013-06-02 14:59:44 189440 ----a-w- c:\windows\system32\WindowsCodecsExt.dll

2013-06-02 14:59:42 519680 ----a-w- c:\windows\system32\d3d11.dll

2013-06-02 14:49:23 5120 ----a-w- c:\windows\system32\wmi.dll

2013-06-02 14:49:23 157696 ----a-w- c:\windows\system32\imagehlp.dll

2013-06-02 14:49:23 12800 ----a-w- c:\windows\system32\drivers\fs_rec.sys

2013-06-02 14:17:40 9728 ----a-w- c:\windows\system32\Wdfres.dll

2013-06-02 14:17:30 66560 ----a-w- c:\windows\system32\drivers\WUDFPf.sys

2013-06-02 14:17:30 155136 ----a-w- c:\windows\system32\drivers\WUDFRd.sys

2013-06-02 14:17:29 16896 ----a-w- c:\windows\system32\winusb.dll

2013-06-02 14:17:28 73216 ----a-w- c:\windows\system32\WUDFSvc.dll

2013-06-02 14:17:28 172032 ----a-w- c:\windows\system32\WUDFPlatform.dll

2013-06-02 14:17:27 47720 ----a-w- c:\windows\system32\drivers\WdfLdr.sys

2013-06-02 14:17:26 526952 ----a-w- c:\windows\system32\drivers\Wdf01000.sys

2013-06-02 14:17:21 38912 ----a-w- c:\windows\system32\WUDFCoinstaller.dll

2013-06-02 14:17:21 196608 ----a-w- c:\windows\system32\WUDFHost.exe

2013-06-02 14:17:20 613888 ----a-w- c:\windows\system32\WUDFx.dll

2013-06-02 14:07:11 2048 ----a-w- c:\windows\system32\tzres.dll

2013-06-02 14:06:35 34304 ----a-w- c:\windows\system32\atmlib.dll

2013-06-02 14:06:35 293376 ----a-w- c:\windows\system32\atmfd.dll

2013-06-02 14:03:15 979456 ----a-w- c:\windows\system32\MFH264Dec.dll

2013-06-02 14:03:14 478720 ----a-w- c:\windows\system32\dxgi.dll

2013-06-02 14:03:14 135680 ----a-w- c:\windows\system32\XpsRasterService.dll

2013-06-02 14:03:13 876032 ----a-w- c:\windows\system32\XpsPrint.dll

2013-06-02 14:03:11 357376 ----a-w- c:\windows\system32\MFHEAACdec.dll

2013-06-02 14:03:10 302592 ----a-w- c:\windows\system32\mfmp4src.dll

2013-06-02 14:03:10 261632 ----a-w- c:\windows\system32\mfreadwrite.dll

2013-06-02 14:03:09 2873344 ----a-w- c:\windows\system32\mf.dll

2013-06-02 14:03:08 667648 ----a-w- c:\windows\system32\printfilterpipelinesvc.exe

2013-06-02 14:03:07 209920 ----a-w- c:\windows\system32\mfplat.dll

2013-06-02 14:03:06 586240 ----a-w- c:\windows\system32\stobject.dll

2013-06-02 14:02:58 98816 ----a-w- c:\windows\system32\mfps.dll

2013-06-02 14:02:58 26112 ----a-w- c:\windows\system32\printfilterpipelineprxy.dll

2013-06-02 14:02:58 258048 ----a-w- c:\windows\system32\winspool.drv

2013-06-02 14:01:27 623616 ----a-w- c:\windows\system32\localspl.dll

2013-06-02 14:01:19 172544 ----a-w- c:\windows\system32\wintrust.dll

2013-06-02 14:01:16 1314816 ----a-w- c:\windows\system32\quartz.dll

2013-06-02 14:01:04 293376 ----a-w- c:\windows\system32\psisdecd.dll

2013-06-02 14:01:03 69632 ----a-w- c:\windows\system32\Mpeg2Data.ax

2013-06-02 14:01:03 57856 ----a-w- c:\windows\system32\MSDvbNP.ax

2013-06-02 14:01:03 217088 ----a-w- c:\windows\system32\psisrndr.ax

2013-06-02 14:01:00 23552 ----a-w- c:\windows\system32\mciseq.dll

2013-06-02 14:01:00 189952 ----a-w- c:\windows\system32\winmm.dll

2013-06-02 13:59:30 1205064 ----a-w- c:\windows\system32\ntdll.dll

2013-06-02 13:57:36 75776 ----a-w- c:\windows\system32\synceng.dll

2013-06-02 13:57:34 66560 ----a-w- c:\windows\system32\packager.dll

2013-06-02 13:57:30 429056 ----a-w- c:\windows\system32\EncDec.dll

2013-06-02 13:57:26 3603816 ----a-w- c:\windows\system32\ntkrnlpa.exe

2013-06-02 13:57:26 3551080 ----a-w- c:\windows\system32\ntoskrnl.exe

2013-06-02 13:57:25 64000 ----a-w- c:\windows\system32\smss.exe

2013-06-02 13:57:25 49152 ----a-w- c:\windows\system32\csrsrv.dll

2013-06-02 13:53:20 1082232 ----a-w- c:\windows\system32\drivers\ntfs.sys

2013-06-02 13:53:15 204288 ----a-w- c:\windows\system32\ncrypt.dll

2013-06-02 13:53:12 680448 ----a-w- c:\windows\system32\msvcrt.dll

2013-06-02 13:52:41 985088 ----a-w- c:\windows\system32\crypt32.dll

2013-06-02 13:52:40 133120 ----a-w- c:\windows\system32\cryptsvc.dll

2013-06-02 13:52:39 98304 ----a-w- c:\windows\system32\cryptnet.dll

2013-06-02 13:52:13 905576 ----a-w- c:\windows\system32\drivers\tcpip.sys

2013-06-02 13:52:10 1400832 ----a-w- c:\windows\system32\msxml6.dll

2013-06-02 13:49:27 708608 ----a-w- c:\program files\common files\system\ado\msado15.dll

2013-06-02 13:49:23 377344 ----a-w- c:\windows\system32\winhttp.dll

2013-06-02 13:49:20 497152 ----a-w- c:\windows\system32\qdvd.dll

2013-06-02 13:38:53 2409784 ----a-w- c:\program files\windows mail\OESpamFilter.dat

2013-06-02 13:17:01 2067968 ----a-w- c:\windows\system32\mstscax.dll

2013-06-02 13:15:55 180736 ----a-w- c:\windows\system32\drivers\rdpwd.sys

2013-06-02 13:15:50 1248768 ----a-w- c:\windows\system32\msxml3.dll

2013-06-02 13:15:16 707584 ----a-w- c:\program files\common files\system\wab32.dll

2013-06-02 13:13:36 440704 ----a-w- c:\windows\system32\drivers\ksecdd.sys

2013-06-02 13:13:35 278528 ----a-w- c:\windows\system32\schannel.dll

2013-06-02 13:13:35 1259008 ----a-w- c:\windows\system32\lsasrv.dll

2013-06-02 13:13:33 9728 ----a-w- c:\windows\system32\lsass.exe

2013-06-02 13:13:33 72704 ----a-w- c:\windows\system32\secur32.dll

2013-06-02 13:13:28 15872 ----a-w- c:\windows\system32\drivers\usb8023.sys

2013-06-02 12:58:28 613376 ----a-w- c:\windows\system32\rdpencom.dll

2013-06-02 12:34:35 2422272 ----a-w- c:\windows\system32\wucltux.dll

2013-06-02 12:34:02 88576 ----a-w- c:\windows\system32\wudriver.dll

2013-06-02 12:33:51 33792 ----a-w- c:\windows\system32\wuapp.exe

2013-06-02 12:33:51 171904 ----a-w- c:\windows\system32\wuwebv.dll

2013-06-01 14:57:33 -------- d-----w- c:\users\mad fad\appdata\roaming\TuneUp Software

2013-06-01 14:56:34 -------- d-----w- c:\programdata\TuneUp Software

2013-06-01 14:36:25 -------- d-----w- c:\program files\Dropbox

2013-06-01 14:20:30 -------- d-----w- c:\windows\system32\vi-VN

2013-06-01 14:20:30 -------- d-----w- c:\windows\system32\eu-ES

2013-06-01 14:20:30 -------- d-----w- c:\windows\system32\ca-ES

2013-06-01 13:41:15 -------- d-----w- c:\windows\system32\EventProviders

2013-06-01 13:01:11 18904 ----a-w- c:\windows\system32\StructuredQuerySchemaTrivial.bin

2013-06-01 12:47:33 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll

2013-06-01 12:47:33 49472 ----a-w- c:\windows\system32\netfxperf.dll

2013-06-01 12:47:33 297808 ----a-w- c:\windows\system32\mscoree.dll

2013-06-01 12:47:33 295264 ----a-w- c:\windows\system32\PresentationHost.exe

2013-06-01 12:47:32 1130824 ----a-w- c:\windows\system32\dfshim.dll

2013-06-01 12:43:58 289792 ----a-w- c:\windows\system32\spinstall.exe

2013-06-01 12:42:59 710144 ----a-w- c:\windows\system32\Magnify.exe

2013-06-01 12:41:59 279552 ----a-w- c:\windows\system32\services.exe

2013-06-01 12:40:19 161752 ----a-w- c:\windows\system32\drivers\msrpc.sys

2013-06-01 12:38:59 532992 ----a-w- c:\windows\system32\wpcao.dll

2013-06-01 12:37:59 17408 ----a-w- c:\windows\system32\midimap.dll

2013-06-01 12:34:11 2048 ----a-w- c:\windows\system32\winrsmgr.dll

2013-06-01 12:33:24 40448 ----a-w- c:\windows\system32\winrs.exe

2013-06-01 12:33:24 20480 ----a-w- c:\windows\system32\winrshost.exe

2013-06-01 12:33:24 12800 ----a-w- c:\windows\system32\wsmprovhost.exe

2013-06-01 12:33:18 10240 ----a-w- c:\windows\system32\wsmplpxy.dll

2013-06-01 12:33:18 10240 ----a-w- c:\windows\system32\winrssrv.dll

2013-06-01 12:33:15 81408 ----a-w- c:\windows\system32\wevtfwd.dll

2013-06-01 12:33:15 79872 ----a-w- c:\windows\system32\wecutil.exe

2013-06-01 12:33:15 56320 ----a-w- c:\windows\system32\wecapi.dll

2013-06-01 12:33:15 54272 ----a-w- c:\windows\system32\WsmRes.dll

2013-06-01 12:33:15 146944 ----a-w- c:\windows\system32\wecsvc.dll

2013-06-01 12:33:10 41472 ----a-w- c:\windows\system32\pwrshplugin.dll

2013-06-01 12:32:52 201184 ----a-w- c:\windows\system32\winrm.vbs

2013-06-01 12:32:19 214016 ----a-w- c:\windows\system32\WsmWmiPl.dll

2013-06-01 12:32:19 145408 ----a-w- c:\windows\system32\WsmAuto.dll

2013-06-01 12:32:18 252416 ----a-w- c:\windows\system32\WSManMigrationPlugin.dll

2013-06-01 12:32:18 241152 ----a-w- c:\windows\system32\winrscmd.dll

2013-06-01 12:32:17 246272 ----a-w- c:\windows\system32\WSManHTTPConfig.exe

2013-06-01 12:32:16 1181696 ----a-w- c:\windows\system32\WsmSvc.dll

2013-06-01 11:59:41 168960 ----a-w- c:\program files\windows media player\wmplayer.exe

2013-06-01 11:59:38 8147456 ----a-w- c:\windows\system32\wmploc.DLL

2013-06-01 11:58:05 125952 ----a-w- c:\windows\system32\srvsvc.dll

2013-06-01 11:58:04 17920 ----a-w- c:\windows\system32\netevent.dll

2013-06-01 11:57:19 502272 ----a-w- c:\windows\system32\usp10.dll

2013-06-01 11:57:12 66048 ----a-w- c:\program files\windows mail\wabmig.exe

2013-06-01 11:57:12 515584 ----a-w- c:\program files\windows mail\wab.exe

2013-06-01 11:57:11 33280 ----a-w- c:\program files\windows mail\wabfind.dll

2013-06-01 11:57:05 72704 ----a-w- c:\windows\system32\fontsub.dll

2013-06-01 11:56:57 413696 ----a-w- c:\windows\system32\odbc32.dll

2013-06-01 11:56:49 253952 ----a-w- c:\program files\common files\system\ado\msadox.dll

2013-06-01 11:56:45 241664 ----a-w- c:\program files\common files\system\ado\msadomd.dll

2013-06-01 11:56:43 57344 ----a-w- c:\program files\common files\system\msadc\msadcs.dll

2013-06-01 11:56:43 180224 ----a-w- c:\program files\common files\system\msadc\msadco.dll

2013-06-01 11:52:41 78336 ----a-w- c:\windows\system32\ieencode.dll

2013-06-01 11:52:29 69632 ----a-w- c:\windows\system32\drivers\bowser.sys

2013-06-01 11:52:15 75264 ----a-w- c:\windows\system32\drivers\dfsc.sys

2013-06-01 11:51:51 1162240 ----a-w- c:\windows\system32\mfc42u.dll

2013-06-01 11:51:51 1136640 ----a-w- c:\windows\system32\mfc42.dll

2013-06-01 11:51:44 1616384 ----a-w- c:\program files\windows mail\msoe.dll

2013-06-01 11:51:37 81920 ----a-w- c:\windows\system32\iccvid.dll

2013-06-01 11:51:18 305152 ----a-w- c:\windows\system32\drivers\srv.sys

2013-06-01 11:51:10 214016 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys

2013-06-01 11:51:09 79872 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys

2013-06-01 11:51:09 106496 ----a-w- c:\windows\system32\drivers\mrxsmb.sys

2013-06-01 11:50:59 86528 ----a-w- c:\windows\system32\dnsrslvr.dll

2013-06-01 11:50:59 25088 ----a-w- c:\windows\system32\dnscacheugc.exe

2013-06-01 11:50:48 67072 ----a-w- c:\windows\system32\asycfilt.dll

2013-06-01 11:50:37 1316864 ----a-w- c:\windows\system32\ole32.dll

2013-06-01 11:50:35 339968 ----a-w- c:\program files\windows nt\accessories\wordpad.exe

2013-06-01 11:50:21 128000 ----a-w- c:\windows\system32\spoolsv.exe

2013-06-01 11:50:14 157184 ----a-w- c:\windows\system32\t2embed.dll

2013-06-01 11:49:57 273408 ----a-w- c:\windows\system32\drivers\afd.sys

2013-06-01 11:48:56 1169408 ----a-w- c:\windows\system32\sdclt.exe

2013-06-01 11:48:41 10926592 ----a-w- c:\program files\movie maker\MOVIEMK.dll

2013-06-01 11:48:34 150016 ----a-w- c:\program files\movie maker\MOVIEMK.exe

2013-06-01 11:48:26 146432 ----a-w- c:\windows\system32\drivers\srv2.sys

2013-06-01 11:48:24 102400 ----a-w- c:\windows\system32\drivers\srvnet.sys

2013-06-01 11:48:03 317952 ----a-w- c:\windows\system32\MP4SDECD.DLL

2013-06-01 11:47:51 430080 ----a-w- c:\windows\system32\vbscript.dll

2013-06-01 11:47:15 954752 ----a-w- c:\windows\system32\mfc40.dll

2013-06-01 11:47:13 954288 ----a-w- c:\windows\system32\mfc40u.dll

2013-06-01 11:46:52 36864 ----a-w- c:\windows\system32\rtutils.dll

2013-06-01 11:46:32 867328 ----a-w- c:\windows\system32\wmpmde.dll

2013-06-01 11:46:24 231424 ----a-w- c:\windows\system32\msshsq.dll

2013-06-01 11:45:47 1696256 ----a-w- c:\windows\system32\gameux.dll

2013-06-01 11:45:45 28672 ----a-w- c:\windows\system32\Apphlpdm.dll

2013-06-01 11:45:42 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll

2013-06-01 11:45:18 322560 ----a-w- c:\windows\system32\sbe.dll

2013-06-01 11:45:17 177664 ----a-w- c:\windows\system32\mpg2splt.ax

2013-06-01 11:45:16 153088 ----a-w- c:\windows\system32\sbeio.dll

2013-06-01 11:44:07 601600 ----a-w- c:\windows\system32\schedsvc.dll

2013-06-01 11:44:06 352768 ----a-w- c:\windows\system32\taskschd.dll

2013-06-01 11:44:03 345600 ----a-w- c:\windows\system32\wmicmiplugin.dll

2013-06-01 11:44:03 171520 ----a-w- c:\windows\system32\taskeng.exe

2013-06-01 11:43:56 270336 ----a-w- c:\windows\system32\taskcomp.dll

2013-06-01 11:43:41 739328 ----a-w- c:\windows\system32\inetcomm.dll

2013-06-01 11:43:30 81920 ----a-w- c:\windows\system32\consent.exe

2013-06-01 11:39:03 677888 ----a-w- c:\windows\system32\mstsc.exe

2013-06-01 11:39:02 63488 ----a-w- c:\windows\system32\tscupgrd.exe

2013-06-01 11:11:33 531968 ----a-w- c:\windows\system32\comctl32.dll

2013-05-31 16:14:04 -------- d-----w- c:\program files\Belarc

2013-05-31 13:20:40 -------- d-----w- C:\PerfLogs

2013-05-31 12:16:25 193024 ----a-w- c:\windows\system32\recdisc.exe

2013-05-31 12:16:19 6656 ----a-w- c:\windows\system32\sdspres.dll

2013-05-31 12:14:56 28160 ----a-w- c:\windows\system32\sxproxy.dll

2013-05-31 12:12:59 83968 ----a-w- c:\program files\windows journal\jnwdui.dll

2013-05-31 12:11:59 816128 ----a-w- c:\windows\system32\d3dim700.dll

2013-05-31 12:10:59 52736 ----a-w- c:\windows\system32\inetmib1.dll

2013-05-31 12:09:59 896512 ----a-w- c:\program files\windows media player\wmpnetwk.exe

2013-05-31 12:08:58 35840 ----a-w- c:\windows\system32\UI0Detect.exe

2013-05-31 11:27:04 -------- d-----w- c:\users\mad fad\appdata\local\Microsoft Corporation

2013-05-31 11:26:04 -------- d-----w- c:\program files\Microsoft Windows 7 Upgrade Advisor

2013-05-31 11:02:45 7016152 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{76ae87f7-ee13-4411-b67b-016b254f610d}\mpengine.dll

2013-05-31 11:00:00 94112 ----a-w- c:\windows\system32\WindowsAccessBridge.dll

2013-05-30 11:39:06 -------- d-----w- c:\program files\ESET

2013-05-30 11:14:21 -------- d-----w- c:\users\mad fad\appdata\local\temp

2013-05-30 11:13:27 -------- d-sh--w- C:\$RECYCLE.BIN

2013-05-29 10:28:47 115 ----a-w- c:\windows\DeleteOnReboot.bat

2013-05-28 17:29:32 -------- d-----w- c:\windows\ERUNT

2013-05-28 17:28:16 -------- d-----w- C:\JRT

2013-05-28 02:42:00 -------- d-sh--w- c:\programdata\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}

2013-05-28 02:13:44 98816 ----a-w- c:\windows\sed.exe

2013-05-28 02:13:44 256000 ----a-w- c:\windows\PEV.exe

2013-05-28 02:13:44 208896 ----a-w- c:\windows\MBR.exe

2013-05-27 21:12:38 22856 ----a-w- c:\windows\system32\drivers\mbam.sys

2013-05-27 21:12:38 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2013-05-27 20:50:56 -------- d-----w- c:\windows\pss

2013-05-27 19:17:14 -------- d-----w- c:\windows\system32\searchplugins

2013-05-27 19:17:14 -------- d-----w- c:\windows\system32\Extensions

2013-05-12 16:34:39 765736 ----a-w- c:\windows\system32\drivers\aswSnx.sys

2013-05-12 16:34:37 174664 ----a-w- c:\windows\system32\drivers\aswVmm.sys

2013-05-12 16:34:33 49376 ----a-w- c:\windows\system32\drivers\aswRvrt.sys

2013-05-12 16:34:29 66336 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys

2013-05-12 16:33:29 41664 ----a-w- c:\windows\avastSS.scr

2013-05-12 16:31:09 -------- d-----w- c:\program files\AVAST Software

2013-05-12 16:30:03 -------- d-----w- c:\programdata\AVAST Software

.

==================== Find3M ====================

.

2013-05-31 12:57:41 101888 ----a-w- c:\windows\system32\ifxcardm.dll

2013-05-31 12:57:23 82432 ----a-w- c:\windows\system32\axaltocm.dll

2013-05-31 10:59:23 866720 ----a-w- c:\windows\system32\npDeployJava1.dll

2013-05-31 10:59:23 788896 ----a-w- c:\windows\system32\deployJava1.dll

2013-05-23 03:28:38 37664 ----a-w- c:\windows\system32\drivers\avgtpx86.sys

2013-05-02 06:06:08 238872 ------w- c:\windows\system32\MpSigStub.exe

2013-04-15 14:20:04 638328 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys

2013-04-13 10:56:44 37376 ----a-w- c:\windows\system32\cdd.dll

2013-04-13 06:20:24 834048 ----a-w- c:\windows\system32\wininet.dll

2013-04-13 04:38:47 389632 ----a-w- c:\windows\system32\html.iec

2013-04-13 03:42:58 1383424 ----a-w- c:\windows\system32\mshtml.tlb

2013-04-09 01:36:18 2049024 ----a-w- c:\windows\system32\win32k.sys

2013-03-08 03:53:50 376320 ----a-w- c:\windows\system32\winsrv.dll

2013-03-06 03:46:28 71024 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2013-03-06 03:46:28 691568 ----a-w- c:\windows\system32\FlashPlayerApp.exe

.

============= FINISH: 12:56:02.91 ===============

Malwarebytes Anti-Malware (Trial) 1.75.0.1300

www.malwarebytes.org

Database version: v2013.06.02.03

Windows Vista Service Pack 2 x86 NTFS

Internet Explorer 7.0.6002.18005

Mad Fad :: MADFAD-PC [administrator]

Protection: Enabled

6/2/2013 2:19:47 PM

mbam-log-2013-06-02 (14-19-47).txt

Scan type: Full scan (C:\|D:\|E:\|)

Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM

Scan options disabled: P2P

Objects scanned: 389628

Time elapsed: 1 hour(s), 32 minute(s), 6 second(s)

Memory Processes Detected: 0

(No malicious items detected)

Memory Modules Detected: 0

(No malicious items detected)

Registry Keys Detected: 0

(No malicious items detected)

Registry Values Detected: 0

(No malicious items detected)

Registry Data Items Detected: 0

(No malicious items detected)

Folders Detected: 0

(No malicious items detected)

Files Detected: 0

(No malicious items detected)

(end)

Link to post
Share on other sites

Please download the latest version of TDSSKiller from here and save it to your Desktop.

  • Doubleclick on TDSSKiller.exe to run the application, then click on Change parameters.
    image000q.png
  • Put a checkmark beside loaded modules.
    2012081514h0118.png
  • A reboot will be needed to apply the changes. Do it.
  • TDSSKiller will launch automatically after the reboot. Also your computer may seem very slow and unusable. This is normal. Give it enough time to load your background programs.
  • Then click on Change parameters in TDSSKiller.
  • Check all boxes then click OK.
    2012081517h0349.png
  • Click the Start Scan button.
    19695967.jpg
  • The scan should take no longer than 2 minutes.
  • If a suspicious object is detected, the default action will be Skip, click on Continue.
    67776163.jpg
  • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
    Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
    62117367.jpg
    Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.
  • A report will be created in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.

Link to post
Share on other sites

Please download Malwarebytes Anti-Rootkit here.

  • Unzip the contents to a folder on the Desktop.
  • Open the folder where the contents were unzipped and run mbar.exe ( right-click and select Run as administrator for Vista and Windows 7).
  • Follow the instructions in the wizard to update and allow the program to scan your computer for threats.
  • Click on the Cleanup button to remove any threats and reboot if prompted to do so.
  • Wait while the system shuts down and the cleanup process is performed.
  • Please post the two logs produced.

Please note: This tool is still in BETA mode, so please ensure you have backed up any important files.

Link to post
Share on other sites

<p>Scan finished, no malware found. Since some of the 'rootkits' detected by TDSSKiller were obviously part of HP bloatware on the system, is it time to run DeCrapifier? Or something else? Still getting the Windows blocked startup programs message as well. </p>

<p> </p>

<p>MBAM anti-rootkit log below. </p>

<p> </p>

<div>---------------------------------------</div>

<div>Malwarebytes Anti-Rootkit BETA 1.06.0.1003</div>

<div> </div>

<div>© Malwarebytes Corporation 2011-2012</div>

<div> </div>

<div>OS version: 6.0.6002 Windows Vista Service Pack 2 x86</div>

<div> </div>

<div>Account is Administrative</div>

<div> </div>

<div>Internet Explorer version: 7.0.6002.18005</div>

<div> </div>

<div>File system is: NTFS</div>

<div>Disk drives: C:\ DRIVE_FIXED, D:\ DRIVE_FIXED</div>

<div>CPU speed: 2.000000 GHz</div>

<div>Memory total: 2078461952, free: 908181504</div>

<div> </div>

<div>Downloaded database version: v2013.06.03.05</div>

<div>Downloaded database version: v2013.05.22.01</div>

<div>Initializing...</div>

<div>------------ Kernel report ------------</div>

<div>     06/03/2013 07:44:05</div>

<div>------------ Loaded modules -----------</div>

<div>\SystemRoot\system32\ntkrnlpa.exe</div>

<div>\SystemRoot\system32\hal.dll</div>

<div>\SystemRoot\system32\kdcom.dll</div>

<div>\SystemRoot\system32\PSHED.dll</div>

<div>\SystemRoot\system32\BOOTVID.dll</div>

<div>\SystemRoot\system32\CLFS.SYS</div>

<div>\SystemRoot\system32\CI.dll</div>

<div>\SystemRoot\system32\drivers\Wdf01000.sys</div>

<div>\SystemRoot\system32\drivers\WDFLDR.SYS</div>

<div>\SystemRoot\system32\drivers\acpi.sys</div>

<div>\SystemRoot\system32\drivers\WMILIB.SYS</div>

<div>\SystemRoot\system32\drivers\msisadrv.sys</div>

<div>\SystemRoot\system32\drivers\pci.sys</div>

<div>\SystemRoot\System32\drivers\partmgr.sys</div>

<div>\SystemRoot\system32\DRIVERS\compbatt.sys</div>

<div>\SystemRoot\system32\DRIVERS\BATTC.SYS</div>

<div>\SystemRoot\system32\drivers\volmgr.sys</div>

<div>\SystemRoot\System32\drivers\volmgrx.sys</div>

<div>\SystemRoot\system32\drivers\pciide.sys</div>

<div>\SystemRoot\system32\drivers\PCIIDEX.SYS</div>

<div>\SystemRoot\System32\drivers\mountmgr.sys</div>

<div>\SystemRoot\system32\drivers\atapi.sys</div>

<div>\SystemRoot\system32\drivers\ataport.SYS</div>

<div>\SystemRoot\system32\drivers\fltmgr.sys</div>

<div>\SystemRoot\system32\drivers\fileinfo.sys</div>

<div>\SystemRoot\System32\Drivers\ksecdd.sys</div>

<div>\SystemRoot\system32\drivers\ndis.sys</div>

<div>\SystemRoot\system32\drivers\msrpc.sys</div>

<div>\SystemRoot\system32\drivers\NETIO.SYS</div>

<div>\SystemRoot\System32\drivers\tcpip.sys</div>

<div>\SystemRoot\System32\drivers\fwpkclnt.sys</div>

<div>\SystemRoot\System32\Drivers\Ntfs.sys</div>

<div>\SystemRoot\system32\drivers\wd.sys</div>

<div>\SystemRoot\system32\drivers\volsnap.sys</div>

<div>\SystemRoot\System32\Drivers\spldr.sys</div>

<div>\SystemRoot\System32\Drivers\mup.sys</div>

<div>\SystemRoot\System32\drivers\ecache.sys</div>

<div>\SystemRoot\system32\drivers\disk.sys</div>

<div>\SystemRoot\system32\drivers\CLASSPNP.SYS</div>

<div>\SystemRoot\system32\drivers\crcdisk.sys</div>

<div>\SystemRoot\System32\Drivers\aswVmm.sys</div>

<div>\SystemRoot\System32\Drivers\aswRvrt.sys</div>

<div>\SystemRoot\system32\DRIVERS\tunnel.sys</div>

<div>\SystemRoot\system32\DRIVERS\tunmp.sys</div>

<div>\SystemRoot\system32\DRIVERS\amdk8.sys</div>

<div>\SystemRoot\system32\DRIVERS\CmBatt.sys</div>

<div>\SystemRoot\system32\DRIVERS\HpqRemHid.sys</div>

<div>\SystemRoot\system32\DRIVERS\HIDCLASS.SYS</div>

<div>\SystemRoot\system32\DRIVERS\HIDPARSE.SYS</div>

<div>\SystemRoot\system32\DRIVERS\wmiacpi.sys</div>

<div>\SystemRoot\system32\DRIVERS\nvsmu.sys</div>

<div>\SystemRoot\system32\DRIVERS\usbohci.sys</div>

<div>\SystemRoot\system32\DRIVERS\USBPORT.SYS</div>

<div>\SystemRoot\system32\DRIVERS\usbehci.sys</div>

<div>\SystemRoot\system32\DRIVERS\cdrom.sys</div>

<div>\SystemRoot\system32\DRIVERS\HDAudBus.sys</div>

<div>\SystemRoot\system32\DRIVERS\ohci1394.sys</div>

<div>\SystemRoot\system32\DRIVERS\1394BUS.SYS</div>

<div>\SystemRoot\system32\DRIVERS\sdbus.sys</div>

<div>\SystemRoot\system32\DRIVERS\rimmptsk.sys</div>

<div>\SystemRoot\system32\DRIVERS\rimsptsk.sys</div>

<div>\SystemRoot\system32\DRIVERS\rixdptsk.sys</div>

<div>\SystemRoot\system32\DRIVERS\nvmfdx32.sys</div>

<div>\SystemRoot\system32\DRIVERS\bcmwl6.sys</div>

<div>\SystemRoot\system32\DRIVERS\nvlddmkm.sys</div>

<div>\SystemRoot\System32\drivers\dxgkrnl.sys</div>

<div>\SystemRoot\System32\drivers\watchdog.sys</div>

<div>\SystemRoot\system32\DRIVERS\i8042prt.sys</div>

<div>\SystemRoot\system32\DRIVERS\kbdclass.sys</div>

<div>\SystemRoot\system32\DRIVERS\SynTP.sys</div>

<div>\SystemRoot\system32\DRIVERS\USBD.SYS</div>

<div>\SystemRoot\system32\DRIVERS\mouclass.sys</div>

<div>\SystemRoot\system32\DRIVERS\msiscsi.sys</div>

<div>\SystemRoot\system32\DRIVERS\storport.sys</div>

<div>\SystemRoot\system32\DRIVERS\TDI.SYS</div>

<div>\SystemRoot\system32\DRIVERS\rasl2tp.sys</div>

<div>\SystemRoot\system32\DRIVERS\ndistapi.sys</div>

<div>\SystemRoot\system32\DRIVERS\ndiswan.sys</div>

<div>\SystemRoot\system32\DRIVERS\raspppoe.sys</div>

<div>\SystemRoot\system32\DRIVERS\raspptp.sys</div>

<div>\SystemRoot\system32\DRIVERS\rassstp.sys</div>

<div>\SystemRoot\system32\DRIVERS\termdd.sys</div>

<div>\SystemRoot\system32\DRIVERS\swenum.sys</div>

<div>\SystemRoot\system32\DRIVERS\ks.sys</div>

<div>\SystemRoot\system32\DRIVERS\mssmbios.sys</div>

<div>\SystemRoot\system32\DRIVERS\umbus.sys</div>

<div>\SystemRoot\system32\DRIVERS\kbdhid.sys</div>

<div>\SystemRoot\system32\DRIVERS\usbhub.sys</div>

<div>\SystemRoot\System32\Drivers\NDProxy.SYS</div>

<div>\SystemRoot\system32\drivers\CHDART.sys</div>

<div>\SystemRoot\system32\drivers\portcls.sys</div>

<div>\SystemRoot\system32\drivers\drmk.sys</div>

<div>\SystemRoot\system32\DRIVERS\HSXHWAZL.sys</div>

<div>\SystemRoot\system32\DRIVERS\HSX_DPV.sys</div>

<div>\SystemRoot\system32\DRIVERS\HSX_CNXT.sys</div>

<div>\SystemRoot\system32\drivers\modem.sys</div>

<div>\SystemRoot\system32\DRIVERS\usbccgp.sys</div>

<div>\SystemRoot\System32\Drivers\usbvideo.sys</div>

<div>\SystemRoot\System32\Drivers\aswSnx.SYS</div>

<div>\SystemRoot\System32\Drivers\Fs_Rec.SYS</div>

<div>\SystemRoot\System32\Drivers\Null.SYS</div>

<div>\SystemRoot\System32\Drivers\Beep.SYS</div>

<div>\??\C:\Windows\system32\drivers\avgtpx86.sys</div>

<div>\SystemRoot\System32\drivers\vga.sys</div>

<div>\SystemRoot\System32\drivers\VIDEOPRT.SYS</div>

<div>\SystemRoot\System32\DRIVERS\RDPCDD.sys</div>

<div>\SystemRoot\system32\drivers\rdpencdd.sys</div>

<div>\SystemRoot\System32\Drivers\Msfs.SYS</div>

<div>\SystemRoot\System32\Drivers\Npfs.SYS</div>

<div>\SystemRoot\System32\DRIVERS\rasacd.sys</div>

<div>\SystemRoot\system32\DRIVERS\tdx.sys</div>

<div>\SystemRoot\System32\Drivers\aswTdi.SYS</div>

<div>\SystemRoot\system32\DRIVERS\smb.sys</div>

<div>\SystemRoot\system32\drivers\afd.sys</div>

<div>\SystemRoot\System32\Drivers\AswRdr.SYS</div>

<div>\SystemRoot\System32\DRIVERS\netbt.sys</div>

<div>\SystemRoot\system32\drivers\ws2ifsl.sys</div>

<div>\SystemRoot\system32\DRIVERS\pacer.sys</div>

<div>\SystemRoot\system32\DRIVERS\netbios.sys</div>

<div>\SystemRoot\system32\DRIVERS\wanarp.sys</div>

<div>\SystemRoot\system32\DRIVERS\rdbss.sys</div>

<div>\SystemRoot\system32\drivers\nsiproxy.sys</div>

<div>\SystemRoot\System32\Drivers\dfsc.sys</div>

<div>\SystemRoot\System32\Drivers\aswSP.SYS</div>

<div>\SystemRoot\System32\Drivers\crashdmp.sys</div>

<div>\SystemRoot\System32\Drivers\dump_dumpata.sys</div>

<div>\SystemRoot\System32\Drivers\dump_atapi.sys</div>

<div>\SystemRoot\System32\win32k.sys</div>

<div>\SystemRoot\System32\drivers\Dxapi.sys</div>

<div>\SystemRoot\system32\DRIVERS\monitor.sys</div>

<div>\SystemRoot\System32\TSDDD.dll</div>

<div>\SystemRoot\System32\cdd.dll</div>

<div>\SystemRoot\system32\drivers\luafv.sys</div>

<div>\??\C:\Windows\system32\drivers\aswMonFlt.sys</div>

<div>\??\C:\Windows\system32\drivers\mbam.sys</div>

<div>\SystemRoot\System32\Drivers\aswFsBlk.SYS</div>

<div>\SystemRoot\system32\drivers\WudfPf.sys</div>

<div>\SystemRoot\system32\drivers\spsys.sys</div>

<div>\SystemRoot\system32\DRIVERS\lltdio.sys</div>

<div>\SystemRoot\system32\DRIVERS\nwifi.sys</div>

<div>\SystemRoot\system32\DRIVERS\ndisuio.sys</div>

<div>\SystemRoot\system32\DRIVERS\rspndr.sys</div>

<div>\SystemRoot\system32\drivers\HTTP.sys</div>

<div>\SystemRoot\System32\DRIVERS\srvnet.sys</div>

<div>\SystemRoot\system32\DRIVERS\bowser.sys</div>

<div>\SystemRoot\System32\drivers\mpsdrv.sys</div>

<div>\SystemRoot\system32\DRIVERS\mrxsmb.sys</div>

<div>\SystemRoot\system32\DRIVERS\mrxsmb10.sys</div>

<div>\SystemRoot\system32\DRIVERS\mrxsmb20.sys</div>

<div>\SystemRoot\System32\DRIVERS\srv2.sys</div>

<div>\SystemRoot\System32\DRIVERS\srv.sys</div>

<div>\SystemRoot\system32\DRIVERS\mdmxsdk.sys</div>

<div>\SystemRoot\system32\drivers\peauth.sys</div>

<div>\SystemRoot\System32\Drivers\secdrv.SYS</div>

<div>\SystemRoot\System32\drivers\tcpipreg.sys</div>

<div>\SystemRoot\system32\DRIVERS\xaudio.sys</div>

<div>\SystemRoot\system32\DRIVERS\cdfs.sys</div>

<div>\??\C:\Windows\system32\drivers\mbamchameleon.sys</div>

<div>\??\C:\Windows\system32\drivers\mbamswissarmy.sys</div>

<div>\Windows\System32\ntdll.dll</div>

<div>----------- End -----------</div>

<div>Done!</div>

<div><<<1>>></div>

<div>Upper Device Name: \Device\Harddisk0\DR0</div>

<div>Upper Device Object: 0xffffffff8559b5b0</div>

<div>Upper Device Driver Name: \Driver\disk\</div>

<div>Lower Device Name: \Device\Ide\IdeDeviceP2T0L0-3\</div>

<div>Lower Device Object: 0xffffffff853945e0</div>

<div>Lower Device Driver Name: \Driver\atapi\</div>

<div><<<2>>></div>

<div>Device number: 0, partition: 1</div>

<div>Physical Sector Size: 512</div>

<div>Drive: 0, DevicePointer: 0xffffffff8559b5b0, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\</div>

<div>--------- Disk Stack ------</div>

<div>DevicePointer: 0xffffffff8559b1d0, DeviceName: Unknown, DriverName: \Driver\partmgr\</div>

<div>DevicePointer: 0xffffffff8559b5b0, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\</div>

<div>DevicePointer: 0xffffffff853944b8, DeviceName: Unknown, DriverName: \Driver\ACPI\</div>

<div>DevicePointer: 0xffffffff853945e0, DeviceName: \Device\Ide\IdeDeviceP2T0L0-3\, DriverName: \Driver\atapi\</div>

<div>------------ End ----------</div>

<div>Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\</div>

<div>Upper DeviceData: 0x0, 0x0, 0x0</div>

<div>Lower DeviceData: 0x0, 0x0, 0x0</div>

<div><<<3>>></div>

<div>Volume: C:</div>

<div>File system type: NTFS</div>

<div>SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes</div>

<div><<<2>>></div>

<div>Device number: 0, partition: 1</div>

<div><<<3>>></div>

<div>Volume: C:</div>

<div>File system type: NTFS</div>

<div>SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes</div>

<div>Scanning drivers directory: C:\Windows\system32\drivers...</div>

<div><<<2>>></div>

<div>Device number: 0, partition: 1</div>

<div><<<3>>></div>

<div>Volume: C:</div>

<div>File system type: NTFS</div>

<div>SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes</div>

<div>Done!</div>

<div>Drive 0</div>

<div>Scanning MBR on drive 0...</div>

<div>Inspecting partition table:</div>

<div>MBR Signature: 55AA</div>

<div>Disk Signature: 122CD09B</div>

<div> </div>

<div>Partition information:</div>

<div> </div>

<div>    Partition 0 type is Primary (0x7)</div>

<div>    Partition is ACTIVE.</div>

<div>    Partition starts at LBA: 63  Numsec = 463362732</div>

<div>    Partition file system is NTFS</div>

<div>    Partition is bootable</div>

<div> </div>

<div>    Partition 1 type is Primary (0x7)</div>

<div>    Partition is NOT ACTIVE.</div>

<div>    Partition starts at LBA: 463362795  Numsec = 25029270</div>

<div> </div>

<div>    Partition 2 type is Empty (0x0)</div>

<div>    Partition is NOT ACTIVE.</div>

<div>    Partition starts at LBA: 0  Numsec = 0</div>

<div> </div>

<div>    Partition 3 type is Empty (0x0)</div>

<div>    Partition is NOT ACTIVE.</div>

<div>    Partition starts at LBA: 0  Numsec = 0</div>

<div> </div>

<div>Disk Size: 250059350016 bytes</div>

<div>Sector size: 512 bytes</div>

<div> </div>

<div>Scanning physical sectors of unpartitioned space on drive 0 (1-62-488377168-488397168)...</div>

<div>Done!</div>

<div>Scan finished</div>

<div>=======================================</div>

<div> </div>

<div> </div>

<div>Removal queue found; removal started</div>

<div>Removing c:\programdata\malwarebytes' anti-malware (portable)\mbr_0_i.mbam...</div>

<div>Removing c:\programdata\malwarebytes' anti-malware (portable)\bootstrap_0_0_63_i.mbam...</div>

<div>Removing c:\programdata\malwarebytes' anti-malware (portable)\mbr_0_r.mbam...</div>

<div>Removal finished</div>

<div> </div>

Link to post
Share on other sites

Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

For directions on how, see How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs

Do NOT turn off the firewall

Please download Rkill by Grinler and save it to your desktop.

Link 2
Link 3
Link 4
Double-click on the Rkill desktop icon to run the tool.
If using Vista or Windows 7, right-click on it and Run As Administrator.
A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
If not, delete the file, then download and use the one provided in Link 2.
If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
If the tool does not run from any of the links provided, please let me know.
If your antivirus program gives a prompt message, respond positive to allow RKILL to run.
If a malware-rogue gives a message regarding RKILL, proceed forward to running RKILL

IF you still have a problem running RKILL, you can download iExplore.exe or eXplorer.exe, which are renamed copies of rkill.com, and try them instead.

When all done, rkill.txt log file will be on your desktop. Copy & Paste contents of Rkill.txt into a reply.

More Information about Rkill can be found at this link: http://www.bleepingcomputer.com/forums/topic308364.html

Link to post
Share on other sites

No Run as Administrator option provided for this type of file. The first link ran just fine (Black DOS box stayed open), and generated the log below.

Rkill 2.5.2 by Lawrence Abrams (Grinler)

http://www.bleepingcomputer.com/

Copyright 2008-2013 BleepingComputer.com

More Information about Rkill can be found at this link:

http://www.bleepingcomputer.com/forums/topic308364.html

Program started at: 06/03/2013 11:55:35 AM in x86 mode.

Windows Version: Windows Vista Home Premium Service Pack 2

Checking for Windows services to stop:

* No malware services found to stop.

Checking for processes to terminate:

* No malware processes found to kill.

Checking Registry for malware related settings:

* No issues found in the Registry.

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.

Performing miscellaneous checks:

* No issues found.

Checking Windows Service Integrity:

* Windows Defender (WinDefend) is not Running.

Startup Type set to: Manual

Searching for Missing Digital Signatures:

* No issues found.

Checking HOSTS File:

* HOSTS file entries found:

127.0.0.1 localhost

Program finished at: 06/03/2013 11:57:53 AM

Execution time: 0 hours(s), 2 minute(s), and 18 seconds(s)

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.