Jump to content

cheshire constabulary ukash ransom


Recommended Posts

Searched for this on the forums and have tried to boot up in safe mode but as soon as I get the windows desk top the computer shuts down and restarts with the police page in front.

Cntrl alt delete does not seem to work but this could be due to faulty keyboard (daughter and milk incident).

Any help very gladly accepted.

I'm not at all computer savvy so small steps will be needed.

Thanks

Link to post
Share on other sites

Welcome to the forum, here's how we deal with that malware:

  • Please download Farbar Recovery Scan Tool and save it to a flash drive.

    Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

    Plug the flash drive into the infected PC.

  • If you are using Windows 8 consult How to use the Windows 8 System Recovery Environment Command Prompt to enter System Recovery Command prompt.

    If you are using Vista or Windows 7 enter System Recovery Options.

    To enter System Recovery Options from the Advanced Boot Options:

    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.
    Note: In case you can not enter System Recovery Options by using F8 method, you can use Windows installation disc, or make a repair disc. Any Windows installation disc or a repair disc made on another computer can be used.

    To make a repair disk on Windows 7 consult: http://www.sevenforums.com/tutorials/2083-system-repair-disc-create.html

    To enter System Recovery Options by using Windows installation disc:

    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.
  • On the System Recovery Options menu you will get the following options:
      • Startup Repair

        System Restore

        Windows Complete PC Restore

        Windows Memory Diagnostic Tool

        Command Prompt

        Select Command Prompt

        Once in the Command Prompt:

    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst (for x64 bit version type e:\frst64) and press Enter

      Note: Replace letter e with the drive letter of your flash drive.

    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.
MrC
Link to post
Share on other sites

here's the text file

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-10-2013
Ran by SYSTEM on MININT-T4ECT7H on 17-10-2013 21:33:19
Running from G:\
Windows 7 Home Premium (X64) OS Language: English(US)
Internet Explorer Version 10
Boot Mode: Recovery
 
The current controlset is ControlSet001
ATTENTION!:=====> If the system is bootable FRST could be run from normal or Safe mode to create a complete log.
 
==================== Registry (Whitelisted) ==================
 
HKLM\...\Run: [Acer ePower Management] - C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [860040 2011-01-05] (Acer Incorporated)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM-x32\...\Run: [Norton Online Backup] - C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-01] (Symantec Corporation)
HKLM-x32\...\Run: [Monitor] - C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe [103936 2013-06-26] (LeapFrog Enterprises, Inc.)
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-10-24] (Apple Inc.)
HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3568312 2013-10-17] (AVAST Software)
HKU\Bethune\...\Run: [swg] - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2011-05-02] (Google Inc.)
HKU\Default\...\RunOnce: [scrSav] - C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe [154144 2010-01-14] ()
HKU\Default User\...\RunOnce: [scrSav] - C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe [154144 2010-01-14] ()
Startup: C:\Users\Bethune\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\8tfrlcfr2.lnk
ShortcutTarget: 8tfrlcfr2.lnk -> C:\PROGRA~3\2rfclrft8.plz (Eggenberg Corporation)
Startup: C:\Users\Bethune\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk ->  (No File)
Startup: C:\Users\Bethune\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\JL Alpine Advent Calendar.lnk
ShortcutTarget: JL Alpine Advent Calendar.lnk -> C:\Program Files (x86)\JL Alpine Advent Calendar\JL Alpine Advent Calendar.exe ()
 
==================== Services (Whitelisted) =================
 
S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2013-10-17] (AVAST Software)
S3 MWLService; C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [305520 2010-05-26] (Egis Technology Inc.)
S2 NCO; C:\Program Files (x86)\Norton Identity Safe\Engine\2014.6.0.27\NST.exe [129424 2013-10-05] (Symantec Corporation)
S2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-01] (Symantec Corporation)
S2 RapportMgmtService; C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [1435928 2013-09-10] (Trusteer Ltd.)
S2 SimpleHelpSimpleGatewayService; C:\Program Files\SimpleHelpService\SimpleService.exe [96416 2013-03-20] ()
S2 Winmgmt; C:\PROGRA~3\7tlf0h2l.pzz [60512 2013-10-12] (Microsoft Corporation)
S2 Winmgmt; C:\PROGRA~3\7tlf0h2l.pzz [60512 2013-10-12] (Microsoft Corporation)
 
==================== Drivers (Whitelisted) ====================
 
S2 aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [38984 2013-10-17] (AVAST Software)
S2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [84328 2013-10-17] (AVAST Software)
S1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2013-10-17] (AVAST Software)
S0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-10-17] ()
S1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1032416 2013-10-17] (AVAST Software)
S1 aswSP; C:\Windows\system32\drivers\aswSP.sys [409832 2013-10-17] (AVAST Software)
S1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [65264 2013-10-17] (AVAST Software)
S0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [205320 2013-10-17] ()
S1 ccSet_NST; C:\Windows\system32\drivers\NSTx64\7DE06000.01B\ccSetx64.sys [162392 2013-09-27] (Symantec Corporation)
S3 FlyUsb; C:\Windows\System32\DRIVERS\FlyUsb.sys [24576 2008-04-01] (LeapFrog)
S3 glavcam; C:\Windows\System32\DRIVERS\glavcam.sys [80000 2011-11-29] (Windows ® Codename Longhorn DDK provider)
S1 RapportCerberus_56758; C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_56758.sys [589872 2013-09-08] ()
S1 RapportCerberus_56758; C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_56758.sys [589872 2013-09-08] ()
S1 RapportEI64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [265872 2013-09-10] (Trusteer Ltd.)
S1 RapportEI64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [265872 2013-09-10] (Trusteer Ltd.)
S0 RapportKE64; C:\Windows\System32\Drivers\RapportKE64.sys [295696 2013-09-10] (Trusteer Ltd.)
S1 RapportPG64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [384432 2013-09-10] (Trusteer Ltd.)
S1 RapportPG64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [384432 2013-09-10] (Trusteer Ltd.)
S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [74240 2011-02-16] (Research In Motion Limited)
S3 RimVSerPort; C:\Windows\System32\DRIVERS\RimSerial_AMD64.sys [31744 2009-01-09] (Research in Motion Ltd)
 
==================== NetSvcs (Whitelisted) ===================
 
 
==================== One Month Created Files and Folders ========
 
2013-10-17 21:32 - 2013-10-17 21:32 - 00000000 ____D C:\FRST
2013-10-17 09:09 - 2013-10-17 09:09 - 00000000 ____D C:\Users\Bethune\AppData\Roaming\AVAST Software
2013-10-17 09:08 - 2013-10-17 12:16 - 00000448 _____ C:\Windows\setupact.log
2013-10-17 09:08 - 2013-10-17 09:08 - 00021998 _____ C:\Windows\PFRO.log
2013-10-17 09:08 - 2013-10-17 09:08 - 00000000 _____ C:\Windows\setuperr.log
2013-10-17 08:51 - 2013-10-17 12:26 - 00036022 _____ C:\Windows\WindowsUpdate.log
2013-10-16 15:06 - 2013-10-17 12:24 - 95025368 ____T C:\ProgramData\8tfrlcfr2.pff
2013-10-16 15:06 - 2013-10-17 12:17 - 00000000 _____ C:\ProgramData\8tfrlcfr2.ctrl
2013-10-16 15:06 - 2013-10-16 15:06 - 00229376 _____ (Eggenberg Corporation) C:\ProgramData\2rfclrft8.plz
2013-10-16 15:06 - 2013-10-16 15:06 - 00060512 ____T (Microsoft Corporation) C:\ProgramData\8tfrlcfr2.pzz
2013-10-12 01:58 - 2013-10-16 15:09 - 95025368 ____T C:\ProgramData\7tlf0h2l.pff
2013-10-12 01:58 - 2013-10-16 15:08 - 00000000 _____ C:\ProgramData\7tlf0h2l.ctrl
2013-10-12 01:58 - 2013-10-12 01:58 - 00060512 ____T (Microsoft Corporation) C:\ProgramData\7tlf0h2l.pzz
2013-10-10 18:20 - 2013-09-22 15:27 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-10-10 18:20 - 2013-09-22 14:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-10-10 18:20 - 2013-09-20 19:38 - 02706432 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-10-10 18:20 - 2013-09-20 19:30 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-10-10 18:19 - 2013-09-22 15:28 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-10-10 18:19 - 2013-09-22 15:28 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-10-10 18:19 - 2013-09-22 15:27 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-10-10 18:19 - 2013-09-22 15:27 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-10-10 18:19 - 2013-09-22 15:27 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-10-10 18:19 - 2013-09-22 15:27 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-10-10 18:19 - 2013-09-22 15:27 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-10-10 18:19 - 2013-09-22 15:27 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-10-10 18:19 - 2013-09-22 15:27 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-10-10 18:19 - 2013-09-22 15:27 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-10-10 18:19 - 2013-09-22 15:27 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-10-10 18:19 - 2013-09-22 15:27 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-10-10 18:19 - 2013-09-22 14:55 - 02241024 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-10-10 18:19 - 2013-09-22 14:55 - 01365504 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-10-10 18:19 - 2013-09-22 14:55 - 00051712 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2013-10-10 18:19 - 2013-09-22 14:54 - 19252224 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-10-10 18:19 - 2013-09-22 14:54 - 15404544 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-10-10 18:19 - 2013-09-22 14:54 - 03959296 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-10-10 18:19 - 2013-09-22 14:54 - 02647552 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-10-10 18:19 - 2013-09-22 14:54 - 00855552 _____ (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-10-10 18:19 - 2013-09-22 14:54 - 00603136 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-10-10 18:19 - 2013-09-22 14:54 - 00136704 _____ (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2013-10-10 18:19 - 2013-09-22 14:54 - 00067072 _____ (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2013-10-10 18:19 - 2013-09-22 14:54 - 00053248 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-10-10 18:19 - 2013-09-22 14:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2013-10-10 18:19 - 2013-09-20 18:48 - 00089600 _____ (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
2013-10-10 18:19 - 2013-09-20 18:39 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-10-09 06:57 - 2013-09-13 17:10 - 00497152 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\afd.sys
2013-10-09 06:57 - 2013-09-07 18:30 - 01903552 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-10-09 06:57 - 2013-09-07 18:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\System32\mswsock.dll
2013-10-09 06:57 - 2013-09-07 18:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll
2013-10-09 06:57 - 2013-08-28 18:17 - 05549504 _____ (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2013-10-09 06:57 - 2013-08-28 18:16 - 01732032 _____ (Microsoft Corporation) C:\Windows\System32\ntdll.dll
2013-10-09 06:57 - 2013-08-28 18:16 - 00859648 _____ (Microsoft Corporation) C:\Windows\System32\tdh.dll
2013-10-09 06:57 - 2013-08-28 18:16 - 00243712 _____ (Microsoft Corporation) C:\Windows\System32\wow64.dll
2013-10-09 06:57 - 2013-08-28 18:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\System32\advapi32.dll
2013-10-09 06:57 - 2013-08-28 17:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-10-09 06:57 - 2013-08-28 17:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-10-09 06:57 - 2013-08-28 17:50 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-10-09 06:57 - 2013-08-28 17:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2013-10-09 06:57 - 2013-08-28 17:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2013-10-09 06:57 - 2013-08-27 17:21 - 03155968 _____ (Microsoft Corporation) C:\Windows\System32\win32k.sys
2013-10-09 06:57 - 2013-07-12 02:41 - 00185344 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\usbvideo.sys
2013-10-09 06:57 - 2013-07-12 02:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\usbcir.sys
2013-10-09 06:57 - 2013-07-04 04:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\System32\WebClnt.dll
2013-10-09 06:57 - 2013-07-04 04:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\System32\comctl32.dll
2013-10-09 06:57 - 2013-07-04 04:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\System32\davclnt.dll
2013-10-09 06:57 - 2013-07-04 03:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
2013-10-09 06:57 - 2013-07-04 03:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll
2013-10-09 06:57 - 2013-07-04 03:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2013-10-09 06:57 - 2013-07-04 02:11 - 00140800 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\mrxdav.sys
2013-10-09 06:57 - 2013-07-02 20:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\hidclass.sys
2013-10-09 06:57 - 2013-07-02 20:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\hidparse.sys
2013-10-09 06:57 - 2013-06-25 14:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\Wdf01000.sys
2013-10-09 06:57 - 2013-06-05 21:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\System32\lpk.dll
2013-10-09 06:57 - 2013-06-05 21:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\System32\fontsub.dll
2013-10-09 06:57 - 2013-06-05 21:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\System32\dciman32.dll
2013-10-09 06:57 - 2013-06-05 21:47 - 00046080 _____ (Adobe Systems) C:\Windows\System32\atmlib.dll
2013-10-09 06:57 - 2013-06-05 20:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2013-10-09 06:57 - 2013-06-05 20:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2013-10-09 06:57 - 2013-06-05 20:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2013-10-09 06:57 - 2013-06-05 19:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\System32\atmfd.dll
2013-10-09 06:57 - 2013-06-05 19:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2013-10-09 06:57 - 2013-06-05 19:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2013-10-09 06:56 - 2013-09-04 04:12 - 00343040 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\usbhub.sys
2013-10-09 06:56 - 2013-09-04 04:11 - 00325120 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\usbport.sys
2013-10-09 06:56 - 2013-09-04 04:11 - 00099840 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\usbccgp.sys
2013-10-09 06:56 - 2013-09-04 04:11 - 00052736 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\usbehci.sys
2013-10-09 06:56 - 2013-09-04 04:11 - 00030720 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\usbuhci.sys
2013-10-09 06:56 - 2013-09-04 04:11 - 00025600 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\usbohci.sys
2013-10-09 06:56 - 2013-09-04 04:11 - 00007808 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\usbd.sys
2013-10-09 06:56 - 2013-08-28 17:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-10-09 06:56 - 2013-08-28 16:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-10-09 06:56 - 2013-08-28 16:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-10-09 06:56 - 2013-08-28 16:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-10-09 06:56 - 2013-08-28 16:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-10-09 06:56 - 2013-08-27 17:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\System32\scavengeui.dll
2013-10-09 06:56 - 2013-08-01 04:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys
2013-10-09 06:56 - 2013-07-20 02:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
2013-10-09 06:56 - 2013-07-20 02:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2013-10-03 13:25 - 2013-10-03 13:25 - 00000000 ____D C:\Windows\System32\Tasks\Norton Identity Safe
2013-10-03 09:25 - 2013-10-17 08:48 - 00002455 _____ C:\Users\Public\Desktop\Norton Identity Safe.LNK
2013-10-03 09:25 - 2013-10-17 08:48 - 00000000 ____D C:\Windows\System32\Drivers\NSTx64
2013-10-03 09:25 - 2013-10-03 09:25 - 00000000 ____D C:\Program Files (x86)\Norton Identity Safe
2013-10-03 09:21 - 2013-10-17 09:06 - 01032416 _____ (AVAST Software) C:\Windows\System32\Drivers\aswSnx.sys
2013-10-03 09:21 - 2013-10-17 09:06 - 00409832 _____ (AVAST Software) C:\Windows\System32\Drivers\aswSP.sys
2013-10-03 09:21 - 2013-10-17 09:06 - 00334648 _____ (AVAST Software) C:\Windows\System32\aswBoot.exe
2013-10-03 09:21 - 2013-10-17 09:06 - 00205320 _____ C:\Windows\System32\Drivers\aswVmm.sys
2013-10-03 09:21 - 2013-10-17 09:06 - 00092544 _____ (AVAST Software) C:\Windows\System32\Drivers\aswRdr2.sys
2013-10-03 09:21 - 2013-10-17 09:06 - 00084328 _____ (AVAST Software) C:\Windows\System32\Drivers\aswMonFlt.sys
2013-10-03 09:21 - 2013-10-17 09:06 - 00065776 _____ C:\Windows\System32\Drivers\aswRvrt.sys
2013-10-03 09:21 - 2013-10-17 09:06 - 00065264 _____ (AVAST Software) C:\Windows\System32\Drivers\aswTdi.sys
2013-10-03 09:21 - 2013-10-17 09:06 - 00038984 _____ (AVAST Software) C:\Windows\System32\Drivers\aswFsBlk.sys
2013-10-03 09:21 - 2013-10-17 09:06 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2013-10-03 09:21 - 2013-10-17 09:06 - 00001970 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2013-10-03 09:21 - 2013-10-17 09:03 - 00000000 _____ C:\Windows\SysWOW64\config.nt
2013-10-03 09:20 - 2013-10-17 09:06 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2013-10-03 09:20 - 2013-10-03 09:20 - 00000000 ____D C:\Program Files\AVAST Software
2013-10-03 09:19 - 2013-10-17 09:03 - 00000000 ____D C:\ProgramData\AVAST Software
2013-10-03 09:14 - 2013-10-03 09:17 - 131918888 _____ C:\Users\Bethune\Downloads\avast_free_antivirus_setup.exe
2013-09-18 06:38 - 2013-09-28 03:50 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
 
==================== One Month Modified Files and Folders =======
 
2013-10-17 21:32 - 2013-10-17 21:32 - 00000000 ____D C:\FRST
2013-10-17 12:26 - 2013-10-17 08:51 - 00036022 _____ C:\Windows\WindowsUpdate.log
2013-10-17 12:26 - 2009-07-13 20:45 - 00009920 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-10-17 12:26 - 2009-07-13 20:45 - 00009920 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-10-17 12:24 - 2013-10-16 15:06 - 95025368 ____T C:\ProgramData\8tfrlcfr2.pff
2013-10-17 12:20 - 2013-01-24 13:08 - 00000000 ____D C:\Users\Bethune\AppData\Roaming\Dropbox
2013-10-17 12:17 - 2013-10-16 15:06 - 00000000 _____ C:\ProgramData\8tfrlcfr2.ctrl
2013-10-17 12:17 - 2013-01-24 13:11 - 00000000 ___RD C:\Users\Bethune\Dropbox
2013-10-17 12:16 - 2013-10-17 09:08 - 00000448 _____ C:\Windows\setupact.log
2013-10-17 12:16 - 2009-07-13 21:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-10-17 11:10 - 2012-06-06 11:35 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-10-17 09:11 - 2013-03-20 08:59 - 00000000 ____D C:\Program Files\SimpleHelpService
2013-10-17 09:09 - 2013-10-17 09:09 - 00000000 ____D C:\Users\Bethune\AppData\Roaming\AVAST Software
2013-10-17 09:08 - 2013-10-17 09:08 - 00021998 _____ C:\Windows\PFRO.log
2013-10-17 09:08 - 2013-10-17 09:08 - 00000000 _____ C:\Windows\setuperr.log
2013-10-17 09:06 - 2013-10-03 09:21 - 01032416 _____ (AVAST Software) C:\Windows\System32\Drivers\aswSnx.sys
2013-10-17 09:06 - 2013-10-03 09:21 - 00409832 _____ (AVAST Software) C:\Windows\System32\Drivers\aswSP.sys
2013-10-17 09:06 - 2013-10-03 09:21 - 00334648 _____ (AVAST Software) C:\Windows\System32\aswBoot.exe
2013-10-17 09:06 - 2013-10-03 09:21 - 00205320 _____ C:\Windows\System32\Drivers\aswVmm.sys
2013-10-17 09:06 - 2013-10-03 09:21 - 00092544 _____ (AVAST Software) C:\Windows\System32\Drivers\aswRdr2.sys
2013-10-17 09:06 - 2013-10-03 09:21 - 00084328 _____ (AVAST Software) C:\Windows\System32\Drivers\aswMonFlt.sys
2013-10-17 09:06 - 2013-10-03 09:21 - 00065776 _____ C:\Windows\System32\Drivers\aswRvrt.sys
2013-10-17 09:06 - 2013-10-03 09:21 - 00065264 _____ (AVAST Software) C:\Windows\System32\Drivers\aswTdi.sys
2013-10-17 09:06 - 2013-10-03 09:21 - 00038984 _____ (AVAST Software) C:\Windows\System32\Drivers\aswFsBlk.sys
2013-10-17 09:06 - 2013-10-03 09:21 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2013-10-17 09:06 - 2013-10-03 09:21 - 00001970 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2013-10-17 09:06 - 2013-10-03 09:20 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2013-10-17 09:03 - 2013-10-03 09:21 - 00000000 _____ C:\Windows\SysWOW64\config.nt
2013-10-17 09:03 - 2013-10-03 09:19 - 00000000 ____D C:\ProgramData\AVAST Software
2013-10-17 08:48 - 2013-10-03 09:25 - 00002455 _____ C:\Users\Public\Desktop\Norton Identity Safe.LNK
2013-10-17 08:48 - 2013-10-03 09:25 - 00000000 ____D C:\Windows\System32\Drivers\NSTx64
2013-10-16 15:09 - 2013-10-12 01:58 - 95025368 ____T C:\ProgramData\7tlf0h2l.pff
2013-10-16 15:08 - 2013-10-12 01:58 - 00000000 _____ C:\ProgramData\7tlf0h2l.ctrl
2013-10-16 15:06 - 2013-10-16 15:06 - 00229376 _____ (Eggenberg Corporation) C:\ProgramData\2rfclrft8.plz
2013-10-16 15:06 - 2013-10-16 15:06 - 00060512 ____T (Microsoft Corporation) C:\ProgramData\8tfrlcfr2.pzz
2013-10-16 14:52 - 2011-05-02 14:27 - 00000000 ____D C:\Users\Bethune\AppData\Roaming\Skype
2013-10-14 09:58 - 2009-07-13 21:13 - 00727334 _____ C:\Windows\System32\PerfStringBackup.INI
2013-10-12 02:09 - 2007-07-11 17:49 - 00000000 ____D C:\Windows\Panther
2013-10-12 01:58 - 2013-10-12 01:58 - 00060512 ____T (Microsoft Corporation) C:\ProgramData\7tlf0h2l.pzz
2013-10-10 19:31 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\rescache
2013-10-10 18:42 - 2009-07-13 20:45 - 00291344 _____ C:\Windows\System32\FNTCACHE.DAT
2013-10-10 18:41 - 2013-03-13 16:11 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-10-10 18:41 - 2011-03-10 09:24 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-10-10 18:10 - 2013-08-25 18:01 - 00000000 ____D C:\Windows\System32\MRT
2013-10-10 18:06 - 2011-05-22 11:47 - 80541720 _____ (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-10-10 11:00 - 2011-07-07 13:16 - 00000000 ____D C:\Users\Bethune\AppData\Roaming\SoftGrid Client
2013-10-09 08:10 - 2012-06-06 11:35 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-10-09 08:10 - 2012-06-06 11:35 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-10-09 08:10 - 2011-05-14 01:23 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-10-08 09:41 - 2011-05-02 05:53 - 00000900 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-10-08 09:41 - 2011-05-02 05:53 - 00000896 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-10-07 09:40 - 2011-05-02 05:53 - 00003898 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-10-07 09:40 - 2011-05-02 05:53 - 00003646 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-10-06 14:18 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\NDF
2013-10-03 13:25 - 2013-10-03 13:25 - 00000000 ____D C:\Windows\System32\Tasks\Norton Identity Safe
2013-10-03 09:29 - 2011-05-02 05:00 - 00000000 ____D C:\ProgramData\Norton
2013-10-03 09:25 - 2013-10-03 09:25 - 00000000 ____D C:\Program Files (x86)\Norton Identity Safe
2013-10-03 09:20 - 2013-10-03 09:20 - 00000000 ____D C:\Program Files\AVAST Software
2013-10-03 09:17 - 2013-10-03 09:14 - 131918888 _____ C:\Users\Bethune\Downloads\avast_free_antivirus_setup.exe
2013-10-02 23:17 - 2013-01-04 12:11 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-09-28 03:50 - 2013-09-18 06:38 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-09-28 03:50 - 2013-01-04 12:12 - 00000000 ____D C:\Users\Bethune\AppData\Local\Mozilla
2013-09-22 15:28 - 2013-10-10 18:19 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-09-22 15:28 - 2013-10-10 18:19 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-09-22 15:27 - 2013-10-10 18:20 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-09-22 15:27 - 2013-10-10 18:19 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-09-22 15:27 - 2013-10-10 18:19 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-09-22 15:27 - 2013-10-10 18:19 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-09-22 15:27 - 2013-10-10 18:19 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-09-22 15:27 - 2013-10-10 18:19 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-09-22 15:27 - 2013-10-10 18:19 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-09-22 15:27 - 2013-10-10 18:19 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-09-22 15:27 - 2013-10-10 18:19 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-09-22 15:27 - 2013-10-10 18:19 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-09-22 15:27 - 2013-10-10 18:19 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-09-22 14:55 - 2013-10-10 18:19 - 02241024 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-09-22 14:55 - 2013-10-10 18:19 - 01365504 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-09-22 14:55 - 2013-10-10 18:19 - 00051712 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2013-09-22 14:54 - 2013-10-10 18:20 - 00526336 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-09-22 14:54 - 2013-10-10 18:19 - 19252224 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-09-22 14:54 - 2013-10-10 18:19 - 15404544 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-09-22 14:54 - 2013-10-10 18:19 - 03959296 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-09-22 14:54 - 2013-10-10 18:19 - 02647552 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-09-22 14:54 - 2013-10-10 18:19 - 00855552 _____ (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-09-22 14:54 - 2013-10-10 18:19 - 00603136 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-09-22 14:54 - 2013-10-10 18:19 - 00136704 _____ (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2013-09-22 14:54 - 2013-10-10 18:19 - 00067072 _____ (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2013-09-22 14:54 - 2013-10-10 18:19 - 00053248 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-09-22 14:54 - 2013-10-10 18:19 - 00039936 _____ (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2013-09-20 19:38 - 2013-10-10 18:20 - 02706432 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-09-20 19:30 - 2013-10-10 18:20 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-09-20 18:48 - 2013-10-10 18:19 - 00089600 _____ (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
2013-09-20 18:39 - 2013-10-10 18:19 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
 
Files to move or delete:
====================
C:\ProgramData\2rfclrft8.plz
C:\ProgramData\7tlf0h2l.ctrl
C:\ProgramData\7tlf0h2l.pff
C:\ProgramData\8tfrlcfr2.ctrl
C:\ProgramData\8tfrlcfr2.pff
 
 
Some content of TEMP:
====================
C:\Users\Bethune\AppData\Local\Temp\~tmf5569474145523156768.dll
 
 
==================== Known DLLs (Whitelisted) ================
 
 
==================== Bamital & volsnap Check =================
 
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
 
==================== EXE ASSOCIATION =====================
 
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
 
==================== Restore Points  =========================
 
6
Restore point made on: 2013-10-03 09:20:26
Restore point made on: 2013-10-04 04:12:40
Restore point made on: 2013-10-07 23:40:10
Restore point made on: 2013-10-10 18:00:41
Restore point made on: 2013-10-15 04:59:55
Restore point made on: 2013-10-17 09:04:29
 
==================== Memory info =========================== 
 
Percentage of memory in use: 24%
Total physical RAM: 2806.71 MB
Available physical RAM: 2128.53 MB
Total Pagefile: 2804.86 MB
Available Pagefile: 2122.56 MB
Total Virtual: 8192 MB
Available Virtual: 8191.88 MB
 
==================== Drives ================================
 
Drive c: (Acer) (Fixed) (Total:450.66 GB) (Free:283.7 GB) NTFS
Drive e: (PQSERVICE) (Fixed) (Total:15 GB) (Free:2.6 GB) NTFS
Drive g: () (Removable) (Total:0.49 GB) (Free:0.02 GB) FAT
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Drive y: (SYSTEM RESERVED) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[system with boot components (obtained from reading drive)]
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: A2A18DA8)
Partition 1: (Not Active) - (Size=15 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=451 GB) - (Type=07 NTFS)
 
========================================================
Disk: 1 (Size: 497 MB) (Disk ID: E53F59C3)
Partition 1: (Active) - (Size=497 MB) - (Type=06)
 
 
LastRegBack: 2013-10-10 15:24
 
==================== End Of Log ============================
Link to post
Share on other sites

Please download the attached fixlist.txt and copy it to your flashdrive.

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

On Vista or Windows 7: Now please enter System Recovery Options. (as you did before)

Run FRST64 or FRST (which ever one you're using) and press the Fix button just once and wait.

The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.

See if the computer boots normally now and if so..........run MBAR

If not...rescan with FRST and post the new log

Download Malwarebytes Anti-Rootkit from HERE

  • Unzip the contents to a folder in a convenient location.
  • Open the folder where the contents were unzipped and run mbar.exe
  • Follow the instructions in the wizard to update and allow the program to scan your computer for threats.
  • Click on the Cleanup button to remove any threats and reboot if prompted to do so.
  • Wait while the system shuts down and the cleanup process is performed.
  • Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
  • When done, please post the two logs produced they will be in the MBAR folder..... mbar-log.txt and system-log.txt
To attach a log if needed:

Bottom right corner of this page.

reply1.jpg

New window that comes up.

replyer1.jpg

~~~~~~~~~~~~~~~~~~~~~~~

Note:

If no additional threats were found, verify that your system is now running normally, making sure that the following items are functional:

Internet access

Windows Update

Windows Firewall

If there are additional problems with your system, such as any of those listed above or other system issues, then run the fixdamage tool included with Malwarebytes Anti-Rootkit and reboot. It's located in the Plugins folder which is in the MBAR folder.

Just run fixdamage.exe.

Verify that they are now functioning normally.

MrC

Link to post
Share on other sites

Well Done, lets run ComboFix to clear up any leftovers.

Please download and run ComboFix.

The most important things to remember when running it is to disable all your malware programs and run Combofix from your desktop.

Please visit this webpage for download links, and instructions for running ComboFix

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Information on disabling your malware programs can be found Here.

Make sure you run ComboFix from your desktop.

Give it at least 30-45 minutes to finish if needed.

Please include the C:\ComboFix.txt in your next reply for further review.

---------->NOTE<----------

If you get the message Illegal operation attempted on registry key that has been marked for deletion after you run ComboFix....please reboot the computer, this should resolve the problem. You may have to do this several times if needed.

MrC

Link to post
Share on other sites

  • Root Admin

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
 Share

  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.