Malwarebytes successfully blocked access to potentially malicious website


Here are the logs -


Hello and welcome


P2P/Piracy Warning:



If you're using Peer 2 Peer software such as uTorrent, BitTorrent or similar you must either fully uninstall them or completely disable them from running while being assisted here.

Failure to remove or disable such software will result in your topic being closed and no further assistance being provided.

If you have illegal/cracked software, cracks, keygens etc. on the system, please remove or uninstall them now and read the policy on Piracy.


Run Malwarebytes,  Open > Settings Tab > Scanner Settings > Under action for PUP > Select: Show in Results List and Check for removal.

Please Update and run a Quick scan

Make sure that everything is checked, and click Remove Selected on any found items.


Post the produced log




Download Farbar Recovery Scan Tool and save it to your desktop.


Note: You need to run the version compatible with your system (32 bit or 64 bit). If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

Double-click to run it. When the tool opens click Yes to disclaimer.
Press Scan button.
It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.



Thanks for your help with this. Here are the logs you need -


Thanks for your help with this.  The scan did not detect anything.  Here is the log -


Malwarebytes Anti-Malware (Trial)

Database version: v2014.02.25.10

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16736
sdeehan :: LHK1TBT1 [administrator]

Protection: Enabled

2/25/2014 4:10:23 PM
mbam-log-2014-02-25 (16-10-23).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 1012698
Time elapsed: 2 hour(s), 4 minute(s), 15 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)




  1. Here is the result of that -


Farbar Recovery Scan Tool (x64) Version: 26-02-2014

Ran by sdeehan at 2014-02-25 19:18:26

Running from C:\Users\sdeehan\Desktop

Boot Mode: Normal

================== Search: "rpcss.dll" ===================


[2010-11-20 22:24] - [2010-11-20 22:24] - 0512000 ____A (Microsoft Corporation) 5C627D1B1138676C0A7AB2C2C190D123


[2010-11-20 22:24] - [2010-11-20 22:24] - 0513024 ____A (Microsoft Corporation) BAC15C7DDC4587900203909343E9A914

====== End Of Search ======

You have a ZeroAccess Rootkit infection. If you use this PC for any financial transactions or on-line banking you should inform the companies concerned that your system may have been compromised by a hacker and change all passwords used on a clean machine. Do not use this machine again to log into any acounts or make any on-line purchases until we are sure it is clean.


Download attached fixlist.txt file and save it to the Desktop, or the folder you saved FRST into.

NOTE. It's important that both FRST and fixlist.txt are in the same location or the fix will not work.


Run FRST and press the Fix button just once and wait.

The tool will make a log on the Desktop (Fixlog.txt). Please post it to your reply.




Run Malwarebytes,  Open > Settings Tab > Scanner Settings > Under action for PUP > Select: Show in Results List and Check for removal.

Please Update and run a Quick scan

Make sure that everything is checked, and click Remove Selected on any found items.


Post the produced logs...









Here is the result -


Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 26-02-2014
Ran by sdeehan at 2014-02-25 19:33:48 Run:1
Running from C:\Users\sdeehan\Desktop
Boot Mode: Normal

Content of fixlist:
HKU\S-1-5-21-299502267-343818398-725345543-1237573\...\Run: [Google Update*] - [X] <===== ATTENTION (ZeroAccess rootkit hidden path)
HKU\S-1-5-21-299502267-343818398-725345543-1237573\...\Policies\Explorer: [NoWindowsUpdate] 1
HKU\S-1-5-21-299502267-343818398-725345543-1237573\...\Policies\Explorer: [NoSMMyPictures] 1
HKU\S-1-5-21-299502267-343818398-725345543-1237573\...\Policies\Explorer: [NoStartMenuMyMusic] 1
HKU\S-1-5-21-299502267-343818398-725345543-1237573\...\Policies\Explorer: [ForceStartMenuLogOff] 1
HKU\S-1-5-21-299502267-343818398-725345543-1237573\...\Policies\Explorer: [NoSMConfigurePrograms] 1
HKU\S-1-5-21-299502267-343818398-725345543-1237573\...\Policies\Explorer: [NoAutoUpdate] 1
HKU\S-1-5-21-299502267-343818398-725345543-1237573\...\Policies\Explorer: [NoSharedDocuments] 1
HKU\S-1-5-21-299502267-343818398-725345543-1237573\...\Policies\Explorer: [DisallowCpl] 1
HKU\S-1-5-21-299502267-343818398-725345543-1237573\...\Policies\Explorer: [NoWelcomeScreen] 1
HKU\S-1-5-21-299502267-343818398-725345543-1237573\...409d6c4515e9\InprocServer32: [Default-shell32] \\?\globalroot\Device\HarddiskVolume2\Users\sdeehan\AppData\Local\Temp\sdwbprv\sfuuovv\wow.dll ATTENTION! ====> ZeroAccess?
Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Winsock: Catalog5 01 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5 05 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\System32\mswsock.dll"
Winsock: Catalog5-x64 01 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5-x64 05 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\System32\mswsock.dll"
cmd: netsh winsock reset
U4 *etadpug; "C:\Program Files (x86)\Google\Desktop\Install\{6df8e0a8-8c80-f05b-aa32-b589c7192ba8}\   \...\???\{6df8e0a8-8c80-f05b-aa32-b589c7192ba8}\GoogleUpdate.exe" < <==== ATTENTION (ZeroAccess)
S1 netdeezn; \??\C:\WINDOWS\system32\drivers\netdeezn.sys [X]
S1 Teefer3; system32\DRIVERS\Teefer3.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
C:\Program Files (x86)\Google\Desktop\Install
Replace: C:\Windows\winsxs\amd64_microsoft-windows-com-base-qfe-rpcss_31bf3856ad364e35_6.1.7601.17514_none_c7f0e16b547f887d\rpcss.dll C:\Windows\System32\rpcss.dll

HKU\S-1-5-21-299502267-343818398-725345543-1237573\Software\Microsoft\Windows\CurrentVersion\Run\\Google Update* => Value deleted successfully.
HKU\S-1-5-21-299502267-343818398-725345543-1237573\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoWindowsUpdate => Value deleted successfully.
HKU\S-1-5-21-299502267-343818398-725345543-1237573\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSMMyPictures => Value deleted successfully.
HKU\S-1-5-21-299502267-343818398-725345543-1237573\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoStartMenuMyMusic => Value deleted successfully.
HKU\S-1-5-21-299502267-343818398-725345543-1237573\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\ForceStartMenuLogOff => Value deleted successfully.
HKU\S-1-5-21-299502267-343818398-725345543-1237573\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSMConfigurePrograms => Value deleted successfully.
HKU\S-1-5-21-299502267-343818398-725345543-1237573\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoAutoUpdate => Value deleted successfully.
HKU\S-1-5-21-299502267-343818398-725345543-1237573\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSharedDocuments => Value deleted successfully.
HKU\S-1-5-21-299502267-343818398-725345543-1237573\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisallowCpl => Value deleted successfully.
HKU\S-1-5-21-299502267-343818398-725345543-1237573\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoWelcomeScreen => Value deleted successfully.
HKU\S-1-5-21-299502267-343818398-725345543-1237573\Software\Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9} => Key deleted successfully.
HKCR\PROTOCOLS\Filter\application/x-ica => Key deleted successfully.
HKCR\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC} => Key not found.
HKCR\PROTOCOLS\Filter\application/x-ica; charset=euc-jp => Key deleted successfully.
HKCR\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC} => Key not found.
HKCR\PROTOCOLS\Filter\application/x-ica; charset=ISO-8859-1 => Key deleted successfully.
HKCR\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC} => Key not found.
HKCR\PROTOCOLS\Filter\application/x-ica; charset=MS936 => Key deleted successfully.
HKCR\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC} => Key not found.
HKCR\PROTOCOLS\Filter\application/x-ica; charset=MS949 => Key deleted successfully.
HKCR\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC} => Key not found.
HKCR\PROTOCOLS\Filter\application/x-ica; charset=MS950 => Key deleted successfully.
HKCR\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC} => Key not found.
HKCR\PROTOCOLS\Filter\application/x-ica; charset=UTF-8 => Key deleted successfully.
HKCR\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC} => Key not found.
HKCR\PROTOCOLS\Filter\application/x-ica; charset=UTF8 => Key deleted successfully.
HKCR\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC} => Key not found.
HKCR\PROTOCOLS\Filter\application/x-ica;charset=euc-jp => Key deleted successfully.
HKCR\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC} => Key not found.
HKCR\PROTOCOLS\Filter\application/x-ica;charset=ISO-8859-1 => Key deleted successfully.
HKCR\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC} => Key not found.
HKCR\PROTOCOLS\Filter\application/x-ica;charset=MS936 => Key deleted successfully.
HKCR\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC} => Key not found.
HKCR\PROTOCOLS\Filter\application/x-ica;charset=MS949 => Key deleted successfully.
HKCR\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC} => Key not found.
HKCR\PROTOCOLS\Filter\application/x-ica;charset=MS950 => Key deleted successfully.
HKCR\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC} => Key not found.
HKCR\PROTOCOLS\Filter\application/x-ica;charset=UTF-8 => Key deleted successfully.
HKCR\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC} => Key not found.
HKCR\PROTOCOLS\Filter\application/x-ica;charset=UTF8 => Key deleted successfully.
HKCR\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC} => Key not found.
HKCR\PROTOCOLS\Filter\ica => Key deleted successfully.
HKCR\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC} => Key not found.
Winsock: Catalog5 entry 000000000001\\LibraryPath  was set successfully to %SystemRoot%\system32\NLAapi.dll
Winsock: Catalog5 entry 000000000005\\LibraryPath  was set successfully to %SystemRoot%\System32\mswsock.dll
Winsock: Catalog5-x64 entry 000000000001\\LibraryPath  was set successfully to %SystemRoot%\system32\NLAapi.dll
Winsock: Catalog5-x64 entry 000000000005\\LibraryPath  was set successfully to %SystemRoot%\System32\mswsock.dll

=========  netsh winsock reset =========

Sucessfully reset the Winsock Catalog.
You must restart the computer in order to complete the reset.

========= End of CMD: =========

*etadpug => Service deleted successfully.
netdeezn => Service deleted successfully.
Teefer3 => Service deleted successfully.
VGPU => Service deleted successfully.
C:\Users\sdeehan\AppData\Local\Google\Desktop\Install => Moved successfully.
C:\Program Files (x86)\Google\Desktop\Install => Moved successfully.
C:\$Recycle.Bin\S-1-5-21-299502267-343818398-725345543-1237573\$6df8e0a88c80f05baa32b589c7192ba8 => Moved successfully.
C:\Users\sdeehan\AppData\Local\Temp\sdwbprv\sfuuovv\wow.dll => Moved successfully.
C:\Users\sdeehan\AppData\Local\Temp\InstallFlashPlayer.exe => Moved successfully.
C:\Users\sdeehan\AppData\Local\Temp\O58R9.exe => Moved successfully.
C:\Windows\System32\rpcss.dll => Moved successfully.
C:\Windows\winsxs\amd64_microsoft-windows-com-base-qfe-rpcss_31bf3856ad364e35_6.1.7601.17514_none_c7f0e16b547f887d\rpcss.dll copied successfully to C:\Windows\System32\rpcss.dll

==== End of Fixlog ====

Yep, it is written in the log.....



=========  netsh winsock reset =========

Sucessfully reset the Winsock Catalog.
You must restart the computer in order to complete the reset.


You can do that after Malwarebytes completes. Once the re-boot is done run another scan with FRST, only one log will be produced, post that with MB log...





Here are the logs from the MB quick scan - before I re-booted it did not detect any malicious items - log posted below.  But after the re-boot,  a pop-up message showed up and stated that MB blocked and quarantined an item - 


I am going to run FRST now and post that log in my next message



Malwarebytes Anti-Malware (Trial)

Database version: v2014.02.25.12

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16736
sdeehan :: LHK1TBT1 [administrator]

Protection: Enabled

2/25/2014 7:37:52 PM
mbam-log-2014-02-25 (19-37-52).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 1012876
Time elapsed: 1 hour(s), 49 minute(s), 16 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)






Here is the log from the FRST scan -


Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 26-02-2014
Ran by sdeehan (administrator) on LHK1TBT1 on 25-02-2014 22:01:51
Running from C:\Users\sdeehan\Desktop
Windows 7 Enterprise Service Pack 1 (X64) OS Language: English(US)
Internet Explorer Version 10
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(Microsoft Corporation) c:\Program Files\Microsoft Security Client\MsMpEng.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\STacSV64.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe
(Microsoft Corporation) C:\WINDOWS\system32\WLANExt.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
(1E) C:\Program Files\1E\NomadBranch\NomadBranch.exe
(O2Micro International) C:\WINDOWS\system32\DRIVERS\o2flash.exe
(Microsoft Corporation) c:\Program Files\Microsoft Security Client\NisSrv.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\ssonsvr.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\HidFind.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apntex.exe
(APN) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
(Microsoft Corporation) C:\WINDOWS\CCM\CcmExec.exe
(Smurfit-Stone Container Corp.) C:\Windows\SSCCUtils\SSCCUpdates.exe
(Microsoft Corporation) C:\WINDOWS\CCM\RemCtrl\CmRcService.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\WINDOWS\CCM\SCNotification.exe
(Microsoft Corporation) C:\WINDOWS\System32\MsSpellCheckingFacility.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [Apoint] - C:\Program Files\DellTPad\Apoint.exe [608112 2011-07-07] (Alps Electric Co., Ltd.)
HKLM-x32\...\Run: [ApnTBMon] - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1758160 2014-02-13] (APN)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [HideSCAHealth] 1
HKLM\...\Policies\Explorer: [NoWelcomeScreen] 1
HKLM\...\Policies\Explorer: [NoPublishingWizard] 1
HKLM\...\Policies\Explorer: [NoWebServices] 1
HKU\.DEFAULT\...\RunOnce: [Microsoft Security Client] - C:\Program Files\Microsoft Security Client\msseces.exe [1356240 2013-06-20] (Microsoft Corporation)
HKU\S-1-5-19\...\Run: [sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-20\...\Run: [sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-21-299502267-343818398-725345543-1237573\...409d6c4515e9\InprocServer32: [Default-shell32] \\?\globalroot\Device\HarddiskVolume2\Users\sdeehan\AppData\Local\Temp\sdwbprv\sfuuovv\wow.dll ATTENTION! ====> ZeroAccess?

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://intranet.rocktenn.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://intranet.rocktenn.com
SearchScopes: HKCU - {B821BB6D-0EDE-4AFF-ABCD-4514A6C859C7} URL = http://www.search.ask.com/web?tpid=AVRV7&o=APN11068&pf=V7&p2=%5EB5N%5EYYYYYY%5EYY%5EUS&gct=&itbv={searchTerms}&psv=
BHO: Avery Toolbar - {41565256-3700-A76A-76A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVRV7\Passport_x64.dll (APN LLC.)
BHO-x32: Avery Toolbar - {41565256-3700-A76A-76A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVRV7\Passport.dll (APN LLC.)
BHO-x32: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKLM - Avery Toolbar - {41565256-3700-A76A-76A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVRV7\Passport_x64.dll (APN LLC.)
Toolbar: HKLM-x32 - Avery Toolbar - {41565256-3700-A76A-76A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVRV7\Passport.dll (APN LLC.)
DPF: HKLM-x32 {E06E2E99-0AA1-11D4-ABA6-0060082AA75C}
Tcpip\Parameters: [DhcpNameServer]

==================== Services (Whitelisted) =================

R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2014-02-13] (APN LLC.)
R2 CcmExec; C:\WINDOWS\CCM\CcmExec.exe [1842352 2013-08-31] (Microsoft Corporation)
R2 CmRcService; C:\WINDOWS\CCM\RemCtrl\CmRcService.exe [633952 2012-11-21] (Microsoft Corporation)
S3 lpasvc; C:\Program Files\Microsoft Policy Platform\policyHost.exe [50280 2012-08-02] (Microsoft Corporation)
S3 lppsvc; C:\Program Files\Microsoft Policy Platform\policyHost.exe [50280 2012-08-02] (Microsoft Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2013-06-20] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366600 2013-06-20] (Microsoft Corporation)
R2 NomadBranch; C:\Program Files\1E\NomadBranch\NomadBranch.exe [2160952 2013-03-07] (1E)
S3 smstsmgr; C:\WINDOWS\CCM\TSManager.exe [401584 2013-08-31] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

S3 d554gps; C:\Windows\system32\drivers\d554gps64.sys [101416 2011-07-07] (Ericsson AB)
S3 ecnssndis; C:\Windows\System32\Drivers\wwuss64.sys [26664 2011-07-07] (Ericsson AB)
S3 ecnssndisfltr; C:\Windows\System32\Drivers\wwussf64.sys [30248 2011-07-07] (Ericsson AB)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
S3 Mbm3CBus; C:\Windows\system32\drivers\Mbm3CBus.sys [411208 2011-07-07] (MCCI Corporation)
S3 Mbm3DevMt; C:\Windows\system32\drivers\Mbm3DevMt.sys [419912 2011-07-07] (MCCI Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [247216 2013-06-18] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [139616 2013-06-18] (Microsoft Corporation)
S3 nwdelgobi3kfilter; C:\Windows\system32\drivers\nwdelgobi3kfilter.sys [34304 2011-07-07] (Novatel Wireless Inc)
S3 nwdelserial; C:\Windows\system32\drivers\nwdelserial.sys [234112 2011-07-07] (Novatel Wireless Inc.)
R3 prepdrvr; C:\Windows\System32\DRIVERS\prepdrv.sys [26984 2012-11-21] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

==================== One Month Created Files and Folders ========

2014-02-25 19:18 - 2014-02-25 19:21 - 00000630 _____ () C:\Users\sdeehan\Desktop\Search.txt
2014-02-25 18:40 - 2014-02-25 18:40 - 00031292 _____ () C:\Users\sdeehan\Desktop\Addition.txt
2014-02-25 18:39 - 2014-02-25 22:01 - 00007846 _____ () C:\Users\sdeehan\Desktop\FRST.txt
2014-02-25 18:39 - 2014-02-25 22:01 - 00000000 ____D () C:\FRST
2014-02-25 18:38 - 2014-02-25 18:38 - 02155520 _____ (Farbar) C:\Users\sdeehan\Desktop\FRST64.exe
2014-02-25 15:37 - 2014-02-25 15:37 - 00021936 _____ () C:\Users\sdeehan\Desktop\attach.txt
2014-02-25 15:37 - 2014-02-25 15:37 - 00018738 _____ () C:\Users\sdeehan\Desktop\dds.txt
2014-02-25 15:35 - 2014-02-25 15:36 - 00688992 ____R (Swearware) C:\Users\sdeehan\Desktop\dds.scr
2014-02-25 06:15 - 2014-02-25 06:15 - 00001119 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-02-25 06:14 - 2014-02-25 06:15 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-02-25 06:14 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2014-02-24 18:08 - 2014-02-24 18:11 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\sdeehan\Desktop\mbam-setup-
2014-02-13 09:35 - 2014-02-13 09:35 - 00000000 ____D () C:\Users\sdeehan\AppData\Roaming\Malwarebytes
2014-02-13 09:35 - 2014-02-13 09:35 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-02-12 22:09 - 2014-02-12 22:09 - 00000000 ____D () C:\WINDOWS\pss
2014-02-11 00:21 - 2014-02-11 00:21 - 00000000 ____S () C:\WINDOWS\system32\nkdm.mvr
2014-02-10 22:25 - 2014-02-25 21:23 - 00000074 _____ () C:\WINDOWS\system32\cwvulob.dac
2014-02-10 22:11 - 2014-02-10 22:11 - 00000064 _____ () C:\WINDOWS\system32\zhtngob.rvi
2014-02-10 22:11 - 2014-02-10 22:11 - 00000000 _____ () C:\WINDOWS\system32\lfsefo.ibt
2014-02-10 22:02 - 2014-02-10 22:02 - 00228999 ____S () C:\WINDOWS\system32\mqsmxe.oof
2014-02-10 21:33 - 2014-02-10 21:33 - 00014398 _____ () C:\WINDOWS\system32\CcmFramework.ini
2014-02-10 21:33 - 2014-02-10 21:33 - 00000621 _____ () C:\WINDOWS\system32\CcmFramework.h
2014-02-10 21:32 - 2014-02-10 21:32 - 00000000 ____D () C:\WINDOWS\ms
2014-02-10 07:33 - 2014-02-10 07:33 - 00000000 ____D () C:\a0efeec8-29bc-4ba1-9e6b-b2362f37e45c_Cache
2014-02-09 11:36 - 2014-02-13 09:38 - 00000000 ____D () C:\Users\sdeehan\AppData\Local\ASVworks
2014-02-04 16:58 - 2014-02-04 17:15 - 00001576 _____ () C:\WINDOWS\comsetup.log
2014-01-27 15:36 - 2014-01-27 15:36 - 00000000 ____D () C:\ProgramData\1E
2014-01-27 15:36 - 2014-01-27 15:36 - 00000000 ____D () C:\Program Files\1E
2014-01-27 15:33 - 2013-10-12 03:45 - 02241536 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2014-01-27 15:33 - 2013-10-12 03:45 - 01364992 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2014-01-27 15:33 - 2013-10-12 03:45 - 00051712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2014-01-27 15:33 - 2013-10-12 03:43 - 03959808 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2014-01-27 15:33 - 2013-10-12 03:43 - 02648576 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2014-01-27 15:33 - 2013-10-12 03:43 - 00855552 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2014-01-27 15:33 - 2013-10-12 03:43 - 00603136 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2014-01-27 15:33 - 2013-10-12 03:43 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieui.dll
2014-01-27 15:33 - 2013-10-12 03:43 - 00136704 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesysprep.dll
2014-01-27 15:33 - 2013-10-12 03:43 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll
2014-01-27 15:33 - 2013-10-12 03:43 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2014-01-27 15:33 - 2013-10-12 03:43 - 00039936 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll
2014-01-27 15:33 - 2013-10-12 02:03 - 01767936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2014-01-27 15:33 - 2013-10-12 02:03 - 01138176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2014-01-27 15:33 - 2013-10-12 02:02 - 02877952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2014-01-27 15:33 - 2013-10-12 02:02 - 02049024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2014-01-27 15:33 - 2013-10-12 02:02 - 00690688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2014-01-27 15:33 - 2013-10-12 02:02 - 00493056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2014-01-27 15:33 - 2013-10-12 02:02 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieui.dll
2014-01-27 15:33 - 2013-10-12 02:02 - 00109056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesysprep.dll
2014-01-27 15:33 - 2013-10-12 02:02 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesetup.dll
2014-01-27 15:33 - 2013-10-12 02:02 - 00039424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2014-01-27 15:33 - 2013-10-12 02:02 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iernonce.dll
2014-01-27 15:33 - 2013-10-12 01:35 - 02706432 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2014-01-27 15:33 - 2013-10-12 01:08 - 02706432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2014-01-27 15:33 - 2013-10-12 00:44 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\system32\RegisterIEPKEYs.exe
2014-01-27 15:33 - 2013-10-12 00:15 - 00071680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RegisterIEPKEYs.exe
2014-01-27 15:32 - 2013-10-12 03:43 - 19269632 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-01-27 15:32 - 2013-10-12 03:43 - 15404544 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2014-01-27 15:32 - 2013-10-12 02:02 - 14355968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2014-01-27 15:32 - 2013-10-12 02:02 - 13761024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2014-01-27 14:29 - 2014-02-10 21:32 - 00000000 ____D () C:\WINDOWS\system32\{3DA228BE-34DA-49f4-A081-66465B077429}
2014-01-27 12:54 - 2014-01-27 12:55 - 00001945 _____ () C:\WINDOWS\epplauncher.mif
2014-01-27 12:54 - 2014-01-27 12:55 - 00000000 ____D () C:\Program Files\Microsoft Security Client
2014-01-27 12:54 - 2014-01-27 12:54 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client
2014-01-27 12:50 - 2014-01-27 12:50 - 00000000 ____D () C:\Program Files\Windows Firewall Configuration Provider
2014-01-27 12:41 - 2014-02-10 21:33 - 00003827 _____ () C:\WINDOWS\system32\InstallUtil.InstallLog
2014-01-27 12:40 - 2014-02-11 15:22 - 00000000 ____D () C:\WINDOWS\ccmcache
2014-01-27 12:40 - 2014-02-10 21:34 - 00000000 ____D () C:\WINDOWS\CCM
2014-01-27 12:38 - 2014-01-27 12:39 - 00000000 ____D () C:\Program Files\Microsoft Policy Platform

==================== One Month Modified Files and Folders =======

2014-02-25 22:02 - 2014-02-25 18:39 - 00007846 _____ () C:\Users\sdeehan\Desktop\FRST.txt
2014-02-25 22:01 - 2014-02-25 18:39 - 00000000 ____D () C:\FRST
2014-02-25 21:48 - 2012-08-23 15:05 - 01435123 _____ () C:\WINDOWS\WindowsUpdate.log
2014-02-25 21:46 - 2009-07-13 23:45 - 00019120 ____H () C:\WINDOWS\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-02-25 21:46 - 2009-07-13 23:45 - 00019120 ____H () C:\WINDOWS\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-02-25 21:41 - 2012-08-23 15:08 - 00000568 _____ () C:\WINDOWS\SMSCFG.INI
2014-02-25 21:38 - 2009-07-14 00:08 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-02-25 21:38 - 2009-07-13 23:51 - 00043309 _____ () C:\WINDOWS\setupact.log
2014-02-25 21:23 - 2014-02-10 22:25 - 00000074 _____ () C:\WINDOWS\system32\cwvulob.dac
2014-02-25 21:07 - 2013-10-02 08:30 - 00000830 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-02-25 19:21 - 2014-02-25 19:18 - 00000630 _____ () C:\Users\sdeehan\Desktop\Search.txt
2014-02-25 18:40 - 2014-02-25 18:40 - 00031292 _____ () C:\Users\sdeehan\Desktop\Addition.txt
2014-02-25 18:38 - 2014-02-25 18:38 - 02155520 _____ (Farbar) C:\Users\sdeehan\Desktop\FRST64.exe
2014-02-25 15:37 - 2014-02-25 15:37 - 00021936 _____ () C:\Users\sdeehan\Desktop\attach.txt
2014-02-25 15:37 - 2014-02-25 15:37 - 00018738 _____ () C:\Users\sdeehan\Desktop\dds.txt
2014-02-25 15:36 - 2014-02-25 15:35 - 00688992 ____R (Swearware) C:\Users\sdeehan\Desktop\dds.scr
2014-02-25 14:51 - 2012-08-23 15:47 - 00119564 __RSH () C:\ProgramData\ntuser.pol
2014-02-25 14:28 - 2012-08-23 15:06 - 00000352 _____ () C:\WINDOWS\system32\config\netlogon.ftl
2014-02-25 06:15 - 2014-02-25 06:15 - 00001119 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-02-25 06:15 - 2014-02-25 06:14 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-02-24 18:11 - 2014-02-24 18:08 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\sdeehan\Desktop\mbam-setup-
2014-02-21 16:56 - 2013-11-22 13:41 - 00000000 ____D () C:\Users\sdeehan\Desktop\Smithfield Call Reports
2014-02-21 15:20 - 2009-07-13 22:20 - 00000000 ____D () C:\WINDOWS\system32\NDF
2014-02-20 13:23 - 2013-10-28 10:12 - 00116899 _____ () C:\Users\sdeehan\Desktop\Inline Open Order Sheet 10-28-13.xlsx
2014-02-20 12:01 - 2012-08-23 15:12 - 00000000 ____D () C:\Users\SvcPCNet
2014-02-13 16:27 - 2013-02-21 08:11 - 00000000 ____D () C:\Users\sdeehan\Desktop\My Accounts
2014-02-13 15:49 - 2011-05-04 14:10 - 00748302 _____ () C:\WINDOWS\system32\perfh00C.dat
2014-02-13 15:49 - 2011-05-04 14:10 - 00748094 _____ () C:\WINDOWS\system32\perfh00A.dat
2014-02-13 15:49 - 2011-05-04 14:10 - 00158886 _____ () C:\WINDOWS\system32\perfc00A.dat
2014-02-13 15:49 - 2011-05-04 14:10 - 00149860 _____ () C:\WINDOWS\system32\perfc00C.dat
2014-02-13 15:49 - 2009-07-14 00:13 - 02573054 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-02-13 11:33 - 2010-11-20 22:47 - 00049190 _____ () C:\WINDOWS\PFRO.log
2014-02-13 09:38 - 2014-02-09 11:36 - 00000000 ____D () C:\Users\sdeehan\AppData\Local\ASVworks
2014-02-13 09:35 - 2014-02-13 09:35 - 00000000 ____D () C:\Users\sdeehan\AppData\Roaming\Malwarebytes
2014-02-13 09:35 - 2014-02-13 09:35 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-02-12 22:09 - 2014-02-12 22:09 - 00000000 ____D () C:\WINDOWS\pss
2014-02-11 15:22 - 2014-01-27 12:40 - 00000000 ____D () C:\WINDOWS\ccmcache
2014-02-11 00:21 - 2014-02-11 00:21 - 00000000 ____S () C:\WINDOWS\system32\nkdm.mvr
2014-02-11 00:20 - 2012-08-23 15:47 - 00000000 ____D () C:\Users\sdeehan
2014-02-11 00:16 - 2012-08-23 15:08 - 00000000 ____D () C:\WINDOWS\ccmsetup
2014-02-10 22:11 - 2014-02-10 22:11 - 00000064 _____ () C:\WINDOWS\system32\zhtngob.rvi
2014-02-10 22:11 - 2014-02-10 22:11 - 00000000 _____ () C:\WINDOWS\system32\lfsefo.ibt
2014-02-10 22:02 - 2014-02-10 22:02 - 00228999 ____S () C:\WINDOWS\system32\mqsmxe.oof
2014-02-10 21:34 - 2014-01-27 12:40 - 00000000 ____D () C:\WINDOWS\CCM
2014-02-10 21:33 - 2014-02-10 21:33 - 00014398 _____ () C:\WINDOWS\system32\CcmFramework.ini
2014-02-10 21:33 - 2014-02-10 21:33 - 00000621 _____ () C:\WINDOWS\system32\CcmFramework.h
2014-02-10 21:33 - 2014-01-27 12:41 - 00003827 _____ () C:\WINDOWS\system32\InstallUtil.InstallLog
2014-02-10 21:32 - 2014-02-10 21:32 - 00000000 ____D () C:\WINDOWS\ms
2014-02-10 21:32 - 2014-01-27 14:29 - 00000000 ____D () C:\WINDOWS\system32\{3DA228BE-34DA-49f4-A081-66465B077429}
2014-02-10 07:33 - 2014-02-10 07:33 - 00000000 ____D () C:\a0efeec8-29bc-4ba1-9e6b-b2362f37e45c_Cache
2014-02-07 08:56 - 2011-05-04 11:41 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-02-04 17:15 - 2014-02-04 16:58 - 00001576 _____ () C:\WINDOWS\comsetup.log
2014-02-04 16:58 - 2009-07-13 22:20 - 00000000 ____D () C:\WINDOWS\registration
2014-01-28 16:00 - 2011-05-04 11:34 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-01-27 15:36 - 2014-01-27 15:36 - 00000000 ____D () C:\ProgramData\1E
2014-01-27 15:36 - 2014-01-27 15:36 - 00000000 ____D () C:\Program Files\1E
2014-01-27 12:55 - 2014-01-27 12:54 - 00001945 _____ () C:\WINDOWS\epplauncher.mif
2014-01-27 12:55 - 2014-01-27 12:54 - 00000000 ____D () C:\Program Files\Microsoft Security Client
2014-01-27 12:54 - 2014-01-27 12:54 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client
2014-01-27 12:50 - 2014-01-27 12:50 - 00000000 ____D () C:\Program Files\Windows Firewall Configuration Provider
2014-01-27 12:39 - 2014-01-27 12:38 - 00000000 ____D () C:\Program Files\Microsoft Policy Platform
2014-01-27 12:39 - 2012-08-23 15:09 - 00000000 ____D () C:\WINDOWS\SysWOW64\CCM
2014-01-27 12:38 - 2009-07-13 22:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-01-26 00:07 - 2010-11-20 22:27 - 00270496 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

LastRegBack: 2014-02-19 08:20

==================== End Of Log ============================


Yes I would like to see he log, if it exceeds forum character limit you can attach the file. Select "More Reply Options" tab under the reply box, that opens new reply options. Now select "Browse" tab to navigate to the file, select that file, then select "Attach This File"  That can be done multiple times if there are multiple files to attach..


FRST log still shows evidence of ZeroAccess, we continue...


Download attached fixlist.txt file and save it to the Desktop, or the folder you saved FRST into.

NOTE. It's important that both FRST and fixlist.txt are in the same location or the fix will not work.


Run FRST and press the Fix button just once and wait.

The tool will make a log on the Desktop (Fixlog.txt). Please post it to your reply.




1.Download Malwarebytes Anti-Rootkit from this link:




2. Unzip the File to a convenient location. (Recommend the Desktop)

3. Open the folder where the contents were unzipped to run mbar.exe




4. Double-click on the mbar.exe file, you may receive a User Account Control prompt asking if you are sure you wish to allow the program to run. Please allow the program to run and MBAR will now start to install any necessary drivers that are required for the program to operate correctly. If a rootkit is interfering with the installation of the drivers you will see a message that states that the DDA driver was not installed and that you should reboot your computer to install it. You will see this image:




5. If you receive this message, please click on the Yes button and Malwarebytes Anti-Rootkit will now restart your computer. Once the computer is rebooted and you login, MBAR will automatically start and you will now be at the start screen. (If no Rootkit warning you will go from step 4 to 6.)


6. The following image opens, select Next.




7. The following image opens, select Update




8. When the update completes select Next.




9. In the following window ensure "Targets" are ticked. Then select "Scan"




10. If an infection is found select the "Cleanup Button" to remove threats, Reboot if prompted. Wait while the system shuts down and the cleanup process is performed.




11. Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click "Cleanup Button" once more and repeat the process.

12. If no threats were found you will see the following image, Select Exit:




13. Verify that your system is now running normally, making sure that the following items are functional:


  • Internet access
  • Windows Update
  • Windows Firewall


14.  If there are additional problems with your system, such as any of those listed above or other system issues, then run the 'fixdamage' tool included within Malwarebytes Anti-Rootkit folder.


15. Select "Y" from your Keyboard, tap Enter.


16. The fix will be applied, select any key to Exit.


17. Let me know how your system now responds. Copy and paste the two following logs from the mbar folder:


System - log

Mbar - log   Date and time of scan will also be shown




We need to run an online AV scan to ensure there are no remnants of any infection left on your system that may have been missed. This scan is very thorough and well worth running, it can take several hours please be patient and let it complete:


Run Eset Online Scanner


**Note** You will need to use Internet explorer for this scan - Vista and win 7 right click on IE shortcut and run as admin


Go to Eset web page http://www.eset.com/us/online-scanner/ to run an online scan from ESET.


  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • click on the Run ESET Online Scanner button
  • Tick the box next to YES, I accept the Terms of Use.
    Click Start
  • When asked, allow the add/on to be installed
    Click Start
  • Make sure that the option Remove found threats is unticked
  • Click on Advanced Settings, ensure the options
  • Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
    Click Scan
  • wait for the virus definitions to be downloaded
  • Wait for the scan to finish


When the scan is complete


  • If no threats were found
  • put a checkmark in "Uninstall application on close"
  • close program
  • report to me that nothing was found


If threats were found


  • click on "list of threats found"
  • click on "export to text file" and save it as ESET SCAN and save to the desktop
  • Click on back
  • put a checkmark in "Uninstall application on close"
  • click on finish


close program


copy and paste the report in next reply






Here is the Log from running FRST


Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 26-02-2014
Ran by sdeehan at 2014-02-26 07:38:07 Run:2
Running from C:\Users\sdeehan\Desktop
Boot Mode: Normal

Content of fixlist:
HKU\S-1-5-21-299502267-343818398-725345543-1237573\...409d6c4515e9\InprocServer32: [Default-shell32] \\?\globalroot\Device\HarddiskVolume2\Users\sdeehan\AppData\Local\Temp\sdwbprv\sfuuovv\wow.dll ATTENTION! ====> ZeroAccess?

HKU\S-1-5-21-299502267-343818398-725345543-1237573\Software\Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9} => Key deleted successfully.

==== End of Fixlog ====

Thanks for the logs, the protection log is typical from an infected system. The error code for rpcss.dll will be related to where the patched file resides, MB is try to remove the infected file from FRST Quarantine folder. That folder is protected, basically it will not let go.... lol


Post the other logs whenever you`re ready, ESET scan will take several hours so we will have to be patient....





Link to post
Share on other sites

The intention of this forum is not to replace a company's IT department or outsource staff, nor can we anticipate alterations or configurations that may have been made to a business machine, or how it will interact with the tools commonly used in the removal of malware.

More than one machine could be at stake, possibly even the server. If sensitive material has been compromised by an infection, the company could be held liable.

To prevent any possible loss or corruption of company information, please inform your IT department or Supervisor when a workplace computer has been infected, immediately.

It may be in the company's best interest to re-image the machine.

Link to post
Share on other sites

