Jump to content

Help Removing Worm:MSIL/Necast.D


Recommended Posts



New to the forum and goona need some help with the experts here smile.png


My computer flagged me recently (by Windows Action Center) to remove this worm in my laptop... Tried to scan it NIS 2013 and Malwarebytes PRO and both didn't find/remove anything... I ran combofix, adwcleaner, Roguekiller and Junk Removal Tool and still the warning shows up (after every other scan and reboot)


Posting here the log from combofix, adwcleaner, RogueKiller for reference... Any help would be appreciated!


PS - Computer is a Sony VAIO w/ Windows 7 Ultimate 64bit...


ComboFix 13-12-13.01 - Jojo 12/13/2013  10:04:35.1.2 - x64

Microsoft Windows 7 Ultimate   6.1.7601.1.1252.1.1033.18.6111.3800 [GMT -5:00]

Running from: c:\users\Jojo\Downloads\ComboFix.exe

AV: Norton Internet Security *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}

FW: Norton Internet Security *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}

SP: Norton Internet Security *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}



(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))






(((((((((((((((((((((((((   Files Created from 2013-11-13 to 2013-12-13  )))))))))))))))))))))))))))))))



2013-12-13 15:12 . 2013-12-13 15:12 -------- d-----w- c:\users\Default\AppData\Local\temp

2013-12-13 13:39 . 2013-04-04 19:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys

2013-12-13 13:39 . 2013-12-13 13:39 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware

2013-12-13 12:25 . 2013-05-10 04:30 167424 ----a-w- c:\program files\Windows Media Player\wmplayer.exe

2013-12-13 12:25 . 2013-05-10 03:48 164864 ----a-w- c:\program files (x86)\Windows Media Player\wmplayer.exe

2013-12-13 12:25 . 2013-05-10 05:56 12625920 ----a-w- c:\windows\system32\wmploc.DLL

2013-12-13 12:25 . 2013-05-10 04:56 12625408 ----a-w- c:\windows\SysWow64\wmploc.DLL

2013-12-13 12:25 . 2013-05-10 05:56 14631424 ----a-w- c:\windows\system32\wmp.dll

2013-12-13 04:08 . 2013-12-13 04:10 -------- d-----w- c:\windows\system32\drivers\NISx64\1501000.012

2013-12-13 02:28 . 2013-12-13 02:28 -------- d-----w- c:\users\Jojo\AppData\Roaming\Garmin

2013-12-13 02:26 . 2013-12-13 02:26 -------- d-----w- c:\users\Jojo\AppData\Local\Garmin

2013-12-13 02:25 . 2013-12-13 02:25 -------- d-----w- c:\windows\SysWow64\Garmin

2013-12-13 02:25 . 2013-12-13 02:25 -------- d-----w- c:\programdata\Garmin

2013-12-13 02:25 . 2013-12-13 02:25 -------- d-----w- c:\program files (x86)\Garmin

2013-12-13 02:25 . 2013-12-13 02:25 -------- d-----w- c:\programdata\Package Cache

2013-12-02 02:36 . 2013-10-14 23:00 28368 ----a-w- c:\windows\system32\IEUDINIT.EXE

2013-12-02 02:32 . 2013-12-02 02:32 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe

2013-12-02 02:32 . 2013-12-02 02:32 194048 ----a-w- c:\windows\SysWow64\elshyph.dll

2013-12-02 00:34 . 2013-12-02 00:34 -------- d-----w- c:\program files (x86)\GUM9424.tmp

2013-12-02 00:34 . 2013-12-02 00:34 50053120 ----a-w- c:\program files (x86)\GUT9425.tmp

2013-12-02 00:29 . 2013-12-02 00:29 -------- d-----w- c:\program files\Google

2013-12-02 00:29 . 2013-12-13 04:01 -------- d-----w- c:\users\Jojo\AppData\Local\Google

2013-12-02 00:29 . 2013-12-02 00:30 -------- d-----w- c:\program files (x86)\Google




((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))


2013-12-13 04:09 . 2012-05-01 01:59 177752 ----a-w- c:\windows\system32\drivers\SYMEVENT64x86.SYS

2013-12-13 02:57 . 2012-05-04 02:28 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2013-12-13 02:57 . 2012-05-04 02:28 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe

2013-11-17 18:17 . 2012-05-02 02:07 82896128 ----a-w- c:\windows\system32\MRT.exe



(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))



*Note* empty entries & legit default entries are not shown 




"AML"="c:\program files (x86)\Sony\VAIO Launcher\AML.exe" [2008-09-09 1097728]

"ISBMgr.exe"="c:\program files (x86)\Sony\ISB Utility\ISBMgr.exe" [2008-04-04 317280]

"VWLASU"="c:\program files\Sony\VAIO Wireless Wizard\AutoLaunchWLASU.exe" [2008-05-20 24576]

"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-08-05 98304]

"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]

"HPUsageTrackingLEDM"="c:\program files (x86)\HP\HP UT LEDM\bin\hppusg.exe" [2009-08-04 30264]

"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]



"Malwarebytes Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2013-04-04 532040]


c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-7-1 1079584]



"ConsentPromptBehaviorAdmin"= 5 (0x5)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableUIADesktopToggle"= 0 (0x0)


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]

2008-11-06 01:32 98304 ----a-w- c:\windows\System32\VESWinlogon.dll


R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]

R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]

R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]

R3 mvusbews;USB EWS Device;c:\windows\system32\Drivers\mvusbews.sys;c:\windows\SYSNATIVE\Drivers\mvusbews.sys [x]

R3 netw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys;c:\windows\SYSNATIVE\DRIVERS\netw5v64.sys [x]

R3 PcaSp60;Rawether NDIS 6.X SPR Protocol Driver;c:\windows\system32\DRIVERS\PcaSp60.sys;c:\windows\SYSNATIVE\DRIVERS\PcaSp60.sys [x]

R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]

R3 SOHCImp;VAIO Media plus Content Importer;c:\program files (x86)\Sony\VAIO Media plus\SOHCImp.exe;c:\program files (x86)\Sony\VAIO Media plus\SOHCImp.exe [x]

R3 SOHDms;VAIO Media plus Digital Media Server;c:\program files (x86)\Sony\VAIO Media plus\SOHDms.exe;c:\program files (x86)\Sony\VAIO Media plus\SOHDms.exe [x]

R3 SOHDs;VAIO Media plus Device Searcher;c:\program files (x86)\Sony\VAIO Media plus\SOHDs.exe;c:\program files (x86)\Sony\VAIO Media plus\SOHDs.exe [x]

R3 SwitchBoard;Adobe SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]

R3 Synth3dVsc;Synth3dVsc; [x]

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]

R3 tsusbhub;tsusbhub; [x]

R3 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;c:\program files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe;c:\program files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [x]

R3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;c:\program files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe;c:\program files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe [x]


R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]

S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]

S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NISx64\1501000.012\SYMDS64.SYS;c:\windows\SYSNATIVE\drivers\NISx64\1501000.012\SYMDS64.SYS [x]

S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NISx64\1501000.012\SYMEFA64.SYS;c:\windows\SYSNATIVE\drivers\NISx64\1501000.012\SYMEFA64.SYS [x]

S1 BHDrvx64;BHDrvx64;c:\program files (x86)\Norton Internet Security\NortonData\\Definitions\BASHDefs\20131203.001\BHDrvx64.sys;c:\program files (x86)\Norton Internet Security\NortonData\\Definitions\BASHDefs\20131203.001\BHDrvx64.sys [x]

S1 ccSet_NIS;NIS Settings Manager;c:\windows\system32\drivers\NISx64\1501000.012\ccSetx64.sys;c:\windows\SYSNATIVE\drivers\NISx64\1501000.012\ccSetx64.sys [x]

S1 IDSVia64;IDSVia64;c:\program files (x86)\Norton Internet Security\NortonData\\Definitions\IPSDefs\20131212.001\IDSvia64.sys;c:\program files (x86)\Norton Internet Security\NortonData\\Definitions\IPSDefs\20131212.001\IDSvia64.sys [x]

S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NISx64\1501000.012\Ironx64.SYS;c:\windows\SYSNATIVE\drivers\NISx64\1501000.012\Ironx64.SYS [x]

S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\System32\Drivers\NISx64\1501000.012\SYMNETS.SYS;c:\windows\SYSNATIVE\Drivers\NISx64\1501000.012\SYMNETS.SYS [x]

S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]

S2 Garmin Core Update Service;Garmin Core Update Service;c:\program files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe;c:\program files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [x]

S2 HP LaserJet Service;HP LaserJet Service;c:\program files (x86)\HP\HPLaserJetService\HPLaserJetService.exe;c:\program files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [x]

S2 HPSIService;HP SI Service;c:\windows\system32\HPSIsvc.exe;c:\windows\SYSNATIVE\HPSIsvc.exe [x]

S2 IntuitUpdateServiceV4;Intuit Update Service v4;c:\program files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe;c:\program files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe [x]

S2 NIS;Norton Internet Security;c:\program files (x86)\Norton Internet Security\Engine\\NIS.exe;c:\program files (x86)\Norton Internet Security\Engine\\NIS.exe [x]

S2 regi;regi;c:\windows\system32\drivers\regi.sys;c:\windows\SYSNATIVE\drivers\regi.sys [x]

S2 RtkAudioService;Realtek Audio Service;c:\windows\RtkAudioService.exe;c:\windows\RtkAudioService.exe [x]

S2 SampleCollector;VAIO Care Performance Service;c:\program files\Sony\VAIO Care\VCPerfService.exe;c:\program files\Sony\VAIO Care\VCPerfService.exe [x]

S2 uCamMonitor;CamMonitor;c:\program files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe;c:\program files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [x]

S2 VAIO Power Management;VAIO Power Management;c:\program files\Sony\VAIO Power Management\SPMService.exe;c:\program files\Sony\VAIO Power Management\SPMService.exe [x]

S2 VCFw;VAIO Content Folder Watcher;c:\program files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe;c:\program files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [x]

S3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;c:\windows\system32\DRIVERS\ArcSoftKsUFilter.sys;c:\windows\SYSNATIVE\DRIVERS\ArcSoftKsUFilter.sys [x]

S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys;c:\windows\SYSNATIVE\DRIVERS\btwl2cap.sys [x]


S3 SFEP;Sony Firmware Extension Parser;c:\windows\system32\DRIVERS\SFEP.sys;c:\windows\SYSNATIVE\DRIVERS\SFEP.sys [x]

S3 VUAgent;VUAgent;c:\program files\Sony\VAIO Update\VUAgent.exe;c:\program files\Sony\VAIO Update\VUAgent.exe [x]

S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys;c:\windows\SYSNATIVE\DRIVERS\yk62x64.sys [x]



--- Other Services/Drivers In Memory ---



*Deregistered* - EraserUtilDrv11312

*Deregistered* - EraserUtilRebootDrv


[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]

2013-12-13 01:40 1210320 ----a-w- c:\program files (x86)\Google\Chrome\Application\31.0.1650.63\Installer\chrmstp.exe


Contents of the 'Scheduled Tasks' folder


2013-12-13 c:\windows\Tasks\Adobe Flash Player Updater.job

- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-04 02:57]


2013-12-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-12-02 00:28]


2013-12-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-12-02 00:28]



--------- X64 Entries -----------




"Apoint"="c:\program files\Apoint\Apoint.exe" [2008-07-18 152576]

"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-09-03 7938080]

"Skytel"="c:\program files\Realtek\Audio\HDA\Skytel.exe" [2009-09-03 1833504]

"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-15 499608]


------- Supplementary Scan -------


uLocal Page = c:\windows\system32\blank.htm

mLocal Page = c:\windows\SysWOW64\blank.htm

IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm

IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm

TCP: DhcpNameServer =

FF - ProfilePath - c:\users\Jojo\AppData\Roaming\Mozilla\Firefox\Profiles\0qjpdr4k.default\

FF - user.js: yahoo.ytff.general.dontshowhpoffer - true


- - - - ORPHANS REMOVED - - - -


Wow6432Node-HKLM-Run-<NO NAME> - (no file)

HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start





"ImagePath"="\"c:\program files (x86)\Norton Internet Security\Engine\\NIS.exe\" /s \"NIS\" /m \"c:\program files (x86)\Norton Internet Security\Engine\\diMaster.dll\" /prefetch:1"




"ImagePath"="\"c:\program files\Sony\VAIO Care\VCPerfService.exe\" \"/service\" \"/sstates\" \"/sampleinterval=5000\" \"/procinterval=5\" \"/dllinterval=120\" \"/counter=\Processor(_Total)\% Processor Time:1/counter=\PhysicalDisk(_Total)\Disk Bytes/sec:1\" \"/counter=\Network Interface(*)\Bytes Total/sec:1\" \"/expandcounter=\Processor Information(*)\Processor Frequency:1\" \"/expandcounter=\Processor(*)\% Idle Time:1\" \"/expandcounter=\Processor(*)\% C1 Time:1\" \"/expandcounter=\Processor(*)\% C2 Time:1\" \"/expandcounter=\Processor(*)\% C3 Time:1\" \"/expandcounter=\Processor(*)\% Processor Time:1\" \"/directory=inteldata\""


"TrustedImagePaths"="c:\program files (x86)\Norton Internet Security\Engine\;c:\program files (x86)\Norton Internet Security\Engine64\"


--------------------- LOCKED REGISTRY KEYS ---------------------



@Denied: (A 2) (Everyone)














@Denied: (A 2) (Everyone)











@Denied: (A 2) (Everyone)














@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"













@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx, 1"












@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"










@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx, 1"












@Denied: (A 2) (Everyone)










[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Common Client\ccIPC\Channels]

@Denied: (C D) (Everyone)































































[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Common Client\ccIPC\Endpoints]

@Denied: (C D) (Everyone)




















































































































































































































































































































@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)




@Denied: (Full) (Everyone)


Completion time: 2013-12-13  10:14:37

ComboFix-quarantined-files.txt  2013-12-13 15:14


Pre-Run: 206,233,321,472 bytes free

Post-Run: 206,077,300,736 bytes free


- - End Of File - - 8F4433C512BF60E084BF677E7573B9D2





* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * 


# AdwCleaner v3.015 - Report created 15/12/2013 at 10:17:20

# Updated 10/12/2013 by Xplode

# Operating System : Windows 7 Ultimate Service Pack 1 (64 bits)

# Username : Jojo - JOJO-PC

# Running from : C:\Users\Jojo\Downloads\AdwCleaner.exe

# Option : Clean


***** [ Services ] *****



***** [ Files / Folders ] *****


Folder Deleted : C:\Users\Jojo\AppData\Roaming\Mozilla\Firefox\Profiles\0qjpdr4k.default\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}

File Deleted : C:\Users\Jojo\AppData\Roaming\Mozilla\Firefox\Profiles\0qjpdr4k.default\user.js


***** [ Shortcuts ] *****



***** [ Registry ] *****


Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho

Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1

Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32

Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{058F0E48-61CA-4964-9FBA-1978A1BB060D}

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{18F33C35-8EF2-40D7-8BA4-932B0121B472}

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}

Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}

Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}


***** [ Browsers ] *****


-\\ Internet Explorer v11.0.9600.16428



-\\ Mozilla Firefox v25.0.1 (en-US)


[ File : C:\Users\Jojo\AppData\Roaming\Mozilla\Firefox\Profiles\0qjpdr4k.default\prefs.js ]



-\\ Google Chrome v31.0.1650.63


[ File : C:\Users\Jojo\AppData\Local\Google\Chrome\User Data\Default\preferences ]





AdwCleaner[R0].txt - [1977 octets] - [15/12/2013 10:15:46]

AdwCleaner[s0].txt - [1922 octets] - [15/12/2013 10:17:20]


########## EOF - C:\AdwCleaner\AdwCleaner[s0].txt - [1982 octets] ##########



# AdwCleaner v3.015 - Report created 15/12/2013 at 10:15:46

# Updated 10/12/2013 by Xplode

# Operating System : Windows 7 Ultimate Service Pack 1 (64 bits)

# Username : Jojo - JOJO-PC

# Running from : C:\Users\Jojo\Downloads\AdwCleaner.exe

# Option : Scan


***** [ Services ] *****



***** [ Files / Folders ] *****


File Found : C:\Users\Jojo\AppData\Roaming\Mozilla\Firefox\Profiles\0qjpdr4k.default\user.js

Folder Found : C:\Users\Jojo\AppData\Roaming\Mozilla\Firefox\Profiles\0qjpdr4k.default\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}


***** [ Shortcuts ] *****



***** [ Registry ] *****


Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}

Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}

Key Found : HKLM\SOFTWARE\Classes\CLSID\{058F0E48-61CA-4964-9FBA-1978A1BB060D}

Key Found : HKLM\SOFTWARE\Classes\CLSID\{18F33C35-8EF2-40D7-8BA4-932B0121B472}

Key Found : HKLM\SOFTWARE\Classes\protector_dll.protectorbho

Key Found : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1

Key Found : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32

Key Found : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs

Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}

Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}


***** [ Browsers ] *****


-\\ Internet Explorer v11.0.9600.16428



-\\ Mozilla Firefox v25.0.1 (en-US)


[ File : C:\Users\Jojo\AppData\Roaming\Mozilla\Firefox\Profiles\0qjpdr4k.default\prefs.js ]



-\\ Google Chrome v31.0.1650.63


[ File : C:\Users\Jojo\AppData\Local\Google\Chrome\User Data\Default\preferences ]





AdwCleaner[R0].txt - [1837 octets] - [15/12/2013 10:15:46]


########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [1897 octets] ##########




* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * 


RogueKiller V8.7.11 _x64_ [Nov 25 2013] by Tigzy

mail : tigzyRK<at>gmail<dot>com


Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version

Started in : Normal mode

User : Jojo [Admin rights]

Mode : Remove -- Date : 12/15/2013 10:28:05

| ARK || FAK || MBR |


¤¤¤ Bad processes : 1 ¤¤¤

[sUSP PATH] RTKAUDIOSERVICE.EXE -- C:\Windows\RtkAudioService.exe [-] -> KILLED [TermProc]


¤¤¤ Registry Entries : 4 ¤¤¤

[HJ POL][PUM] HKLM\[...]\System : DisableRegistryTools (0) -> DELETED

[HJ POL][PUM] HKLM\[...]\Wow6432Node\[...]\System : DisableRegistryTools (0) -> [0x2] The system cannot find the file specified. 

[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)

[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)


¤¤¤ Scheduled tasks : 0 ¤¤¤


¤¤¤ Startup Entries : 0 ¤¤¤


¤¤¤ Web browsers : 0 ¤¤¤


¤¤¤ Particular Files / Folders: ¤¤¤


¤¤¤ Driver : [NOT LOADED 0x0] ¤¤¤


¤¤¤ External Hives: ¤¤¤


¤¤¤ Infection :  ¤¤¤


¤¤¤ HOSTS File: ¤¤¤

--> %SystemRoot%\System32\drivers\etc\hosts       localhost

::1             localhost



¤¤¤ MBR Check: ¤¤¤


+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) Hitachi HTS723232L9SA60 +++++

--- User ---

[MBR] f116f6ccbe1e7ace87f2dc6fc4c7550f

[bSP] 9544985f2d52f9a6419f4667ec1cb1ee : Windows 7/8 MBR Code

Partition table:

0 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 11649 Mo

1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 23859200 | Size: 293594 Mo

User = LL1 ... OK!

User = LL2 ... OK!


Finished : << RKreport[0]_D_12152013_102805.txt >>





* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * 



Junkware Removal Tool (JRT) by Thisisu

Version: 6.0.8 (11.05.2013:1)

OS: Windows 7 Ultimate x64

Ran by Jojo on Sun 12/15/2013 at 10:38:00.59






~~~ Services




~~~ Registry Values




~~~ Registry Keys




~~~ Files




~~~ Folders




~~~ FireFox


Emptied folder: C:\Users\Jojo\AppData\Roaming\mozilla\firefox\profiles\0qjpdr4k.default\minidumps [21 files]




~~~ Event Viewer Logs were cleared







Scan was completed on Sun 12/15/2013 at 10:44:59.30

End of JRT log






Link to post
Share on other sites

  • Root Admin

For future reference one should not run tools like Combofix on their own as there is a potential for data loss if an old or invalid version of the program was run.


Since you've run most of the tools from other posts you've seen without being requested that too can potentially be harmful as none of them backup your data before doing some potentially dangerous tasks.


So what issues are you still having or seeing?




Link to post
Share on other sites

Thanks for the heads up, will definitely keep that in mind in the future... Haven't really installed a lot of program from this computer since it's my 2nd laptop and serve as my backup unit for work...


Anyway, I'm still getting the warning message from Action Center (flag icon in the taskbar) to "Remove the Worm:MSIL/Necast.D"...

Link to post
Share on other sites

  • Root Admin


Please go here to run the online antivirus scannner from ESET.

  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked
  • Click on Advanced Settings and ensure these options are ticked:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Click Scan
  • Wait for the scan to finish
  • If any threats were found, click the 'List of found threats' , then click Export to text file....
  • Save it to your desktop, then please copy and paste that log as a reply to this topic.



Link to post
Share on other sites

Below is ESET's log, after reboot, the warning message still shows up... Also went ahead and ran Microsoft Safety Scanner and found nothing...


C:\Users\Jojo\AppData\Local\Adobe\AIH.599bb64a817c4183372491674253b856db56f4d7\GTB.exe Win32/Bundled.Toolbar.Google.D application cleaned by deleting - quarantined
Link to post
Share on other sites

  • Root Admin

Well the Action Center alone has no smarts to know so some program is passing that along to the Windows Action Center.


I'm 99% sure it's Norton that is passing that along.


Please open Norton antivirus and check your quarantine and see if you can empty the quarantine.  Then check or verify that you have the latest updates from Norton and reboot your computer.  Then do a Full System scan using Norton and let me know if it finds anything or not.

Link to post
Share on other sites

  • Root Admin

Okay let's try another antivirus scanner. Please fully disable Norton and MBAM and run this av scan.


  • Please download Dr.Web CureIt! antivirus and save it to your computer. The file size is in excess of 100MB
  • NOTE: Free usage of Dr.Web CureIt! for business purposes is illegal.
  • Internet Explorer may show a warning when downloading - the file is safe to download from the provided link.
  • Shutdown your antivirus to avoid any conflicts while scanning.
  • Once the scans have completed please re-enable your antivirus.
  • If using Malwarebytes Anti-Malware PRO you can right click over the tray icon and disable the Protection Modules
  • If needed you can also temporarily disable it from starting with Windows
  • Temporarily turn off any other security add-ons or applications you may also have.
  • Once you have downloaded Dr.Web CureIt! you should right click over it and choose Properties and verify it has a Digital Signature.
  • If it does not have a Digital Signature then do not run it.
  • Close all open programs including all Web browsers and then double-click on drweb-cureit.exe to start the installer.
  • You should have your User Account Control (UAC) enabled for improved security and which should then produce a dialog box asking for approval to run the installer.
  • Click on the Yes button to start the installer.
  • Click OK to scan your computer in the Enhanced Protection Mode
  • Click on the check box to agree to participate in their software improvement program.
  • Then if needed choose your Language by clicking on the small globe like icon in the upper right corner by the wrench.
  • Then click on the Continue button and then click on the Select objects for scanning link just below the "Start scanning" button.
  • Place a check mark on all the items except for Temporary files and System restore points - those items should not have a check mark on them.
  • Then click on the Start scanning button.
  • If a threat is found you can click on the Action column in the program.
  • Your options will be Cure or Ignore
  • If you see an item that you are absolutely sure is OK, then un-check the check box for that item, otherwise keep it on Cure.
  • Then click on the Neutralize button.
  • Once completed click on the green Open Report link. It will open the report in NOTEPAD
  • Save the report to your desktop. The report will be called Cureit.log
  • Close Dr.Web Cureit!
  • Reboot your computer to allow files that were in use to be moved/deleted during reboot.
  • After reboot, attach the log Cureit.log you saved previously in your next reply.
  • Re-Enable your antivirus and other security programs when all done.
Link to post
Share on other sites

  • Root Admin

This is an interesting one as there is very little information about it even from Microsoft.
Let me have you run the following and let's see if something loading may be causing this.
Create an Autoruns Log:

  • Please download Sysinternals Autoruns from here.
  • Save Autoruns.exe to your desktop and double-click it to run it.
  • Once it starts, please press the Esc key on your keyboard.
  • Now that scanning is stopped, click on the Options button at the top of the program and select Verify Code Signatures
  • Once that's done press the F5 key on your keyboard, this will start the scan again, this time let it finish.
  • When it's finished, please click on the File button at the top of the program and select Save and save the Autoruns.arn file to your desktop and close Autoruns.
  • Right click on the Autoruns.arn file on your desktop and hover your mouse over Send To and select Compressed (zipped) Folder
  • Attach the Autoruns.zip folder you just created to your next reply
Link to post
Share on other sites

  • Root Admin

Actually I see you have a topic open already over on the Bleepingcomputer site.  So as not to confuse helpers and waste resources (there are a limited amount of trained helpers to assist hundreds of users) I'll go ahead and close your topic here.


They should be able to get you fixed up over on the Bleeping site.




Thank you

Link to post
Share on other sites

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.