Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
Posted 15 May 2012 - 07:09 PM
Edited by hamluis, 18 May 2012 - 06:07 AM.
Moved from Am I Infected to Malware Removal Logs per request - Hamluis.
Posted 16 May 2012 - 03:09 AM
You're experiencing this issue on 2 laptops? I just want to make sure I'm understanding things correctly.Both laptops do the same thing at start up...freeze at a black screen with a blinking cursor. I have tried the following:
Have I helped you? If you'd like to assist in the fight against malware, click here 
The instructions seen in this post have been specifically tailored to this user and the issues they are experiencing with their computer. If you think you have a similar problem, please first read this topic, and then begin your own, new thread. I do not offer private support via Private Message.
Posted 16 May 2012 - 09:16 AM
Posted 18 May 2012 - 02:52 AM
Have I helped you? If you'd like to assist in the fight against malware, click here 
The instructions seen in this post have been specifically tailored to this user and the issues they are experiencing with their computer. If you think you have a similar problem, please first read this topic, and then begin your own, new thread. I do not offer private support via Private Message.
Posted 18 May 2012 - 10:16 AM
Posted 19 May 2012 - 01:31 AM
Have I helped you? If you'd like to assist in the fight against malware, click here 
The instructions seen in this post have been specifically tailored to this user and the issues they are experiencing with their computer. If you think you have a similar problem, please first read this topic, and then begin your own, new thread. I do not offer private support via Private Message.
Posted 19 May 2012 - 06:51 AM
Posted 19 May 2012 - 07:24 AM
One or more of the identified infections is a backdoor trojan and password stealer.This type of infection allows hackers to access and remotely control your computer, log keystrokes, steal critical system information, and download and execute files without your knowledge.
If you do any banking or other financial transactions on the PC or if it contains any other sensitive information, then from a clean computer, change all passwords where applicable.
It would also be wise to contact those same financial institutions to appraise them of your situation.
start HKLM\...\Run: [] [x] HKLM\...\Run: [PC MightyMax 2011 Tray Icon] "C:\Program Files (x86)\PC MightyMax 2011\TrayIcon.exe" [122368 2011-04-08] () HKLM\...\Run: [wmuine] rundll32.exe "C:\windows\TEMP\wmuine.dll",CreateRenderToEnvMap [x] C:\windows\TEMP\wmuine.dll HKLM\...\Run: [octsra] rundll32.exe "C:\windows\TEMP\octsra.dll",BAOCloseFile [x] C:\windows\TEMP\octsra.dll HKLM-x32\...\Run: [MyWebSearch Email Plugin] C:\PROGRA~2\MYWEBS~1\bar\2.bin\mwsoemon.exe [32849 2011-04-13] (MyWebSearch.com) HKLM-x32\...\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~2\MYWEBS~1\bar\2.bin\m3SrchMn.exe" /m=2 /w /h [x] HKLM-x32\...\Run: [] [x] HKLM-x32\...\Run: [iBryte browseforchange Desktop] C:\Program Files (x86)\iBryte\browseforchange\ibrytedesktop.exe [163840 2011-12-23] (iBryte) HKLM-x32\...\Run: [iBryte playbryte Desktop] C:\Program Files (x86)\iBryte\playbryte\ibrytedesktop.exe [163840 2011-12-23] (iBryte) HKLM-x32\...\Run: [configremote] C:\ProgramData\configremote.exe [x] C:\ProgramData\configremote.exe HKLM-x32\...\Run: [krnlhtml] C:\windows\system32\config\systemprofile\AppData\Roaming\krnlhtml.exe [x] C:\windows\system32\config\systemprofile\AppData\Roaming\krnlhtml.exe HKLM-x32\...\Run: [dplaysvr] %LOCALAPPDATA%\dplaysvr.exe [x] %LOCALAPPDATA%\dplaysvr.exe HKU\Haley\...\Run: [MyWebSearch Email Plugin] C:\PROGRA~2\MYWEBS~1\bar\2.bin\mwsoemon.exe [32849 2011-04-13] (MyWebSearch.com) HKU\Haley\...\Run: [configremote] C:\ProgramData\configremote.exe [x] C:\ProgramData\configremote.exe HKU\Haley\...\Run: [krnlhtml] C:\windows\system32\config\systemprofile\AppData\Roaming\krnlhtml.exe [x] C:\windows\system32\config\systemprofile\AppData\Roaming\krnlhtml.exe HKU\Haley\...\Run: [dplaysvr] C:\windows\system32\config\systemprofile\AppData\Local\dplaysvr.exe [x] C:\windows\system32\config\systemprofile\AppData\Local\dplaysvr.exe HKU\Haley\...\Run: [Internet Security] C:\ProgramData\isecurity.exe [x] C:\ProgramData\isecurity.exe HKU\Haley\...\CurrentVersion\Windows: [Load] C:\Users\Haley\LOCALS~1\Temp\mssaensm.scr C:\Users\Haley\LOCALS~1\Temp\mssaensm.scr HKLM\...\Policies\Explorer\Run: [20540] C:\PROGRA~3\LOCALS~1\Temp\msaquvw.bat C:\PROGRA~3\LOCALS~1\Temp\msaquvw.bat HKLM\...\.exe: l??? <===== ATTENTION! SubSystems: [Windows] ATTENTION! ====> ZeroAccess TDL4: custom:26000022 <===== ATTENTION! end
Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

box Copy & Paste the following:msconfig safebootminimal activex drivers32 netsvcs "%WinDir%\$NtUninstallKB*$." /30 C:\Program Files\Common Files\ComObjects\*.* /s %systemroot%\*. /mp /s %systemroot%\*. /rp /s %systemroot%\system32\*.dll /lockedfiles %systemroot%\Tasks\*.job /lockedfiles %systemroot%\system32\drivers\*.sys /lockedfiles %systemroot%\System32\config\*.sav %systemroot%\system32\drivers\*.sys /90 %SYSTEMDRIVE%\*.exe /md5start volsnap.sys atapi.sys explorer.exe winlogon.exe wininit.exe tdx.sys /md5stop hklm\software\clients\startmenuinternet|command /rs hklm\software\clients\startmenuinternet|command /64 /rs
button.1. Any comments or questions you may have that you'd like for me to answer in my next post to you.
2. FRST fixlog.txt
3. GMER.txt log
4. OTL.txt & Extras.txt log files.
5. An update on how your computer is currently running.
Have I helped you? If you'd like to assist in the fight against malware, click here 
The instructions seen in this post have been specifically tailored to this user and the issues they are experiencing with their computer. If you think you have a similar problem, please first read this topic, and then begin your own, new thread. I do not offer private support via Private Message.
Posted 19 May 2012 - 08:54 AM
Posted 19 May 2012 - 08:55 AM
Those steps were for if you were able to boot up your computer successfully after running that FRST fix.question...how do I do the next step that says to remove a program by clicking on start? I can't start the machine up in windows and the system restore cd interface doesn't have a start choice does it?
Have I helped you? If you'd like to assist in the fight against malware, click here 
The instructions seen in this post have been specifically tailored to this user and the issues they are experiencing with their computer. If you think you have a similar problem, please first read this topic, and then begin your own, new thread. I do not offer private support via Private Message.
Posted 19 May 2012 - 09:00 AM
Posted 19 May 2012 - 09:52 AM
start SubSystems: [Windows] ATTENTION! ====> ZeroAccess TDL4: custom:26000022 <===== ATTENTION! HKU\Haley\...\CurrentVersion\Windows: [Load] C:\Users\Haley\LOCALS~1\Temp\mssaensm.scr Folder: C:\bd_logs C:\Users\All Users\Kaspersky Lab C:\ProgramData\Kaspersky Lab end
Have I helped you? If you'd like to assist in the fight against malware, click here 
The instructions seen in this post have been specifically tailored to this user and the issues they are experiencing with their computer. If you think you have a similar problem, please first read this topic, and then begin your own, new thread. I do not offer private support via Private Message.
Posted 19 May 2012 - 10:01 AM
Posted 19 May 2012 - 10:14 AM
Have I helped you? If you'd like to assist in the fight against malware, click here 
The instructions seen in this post have been specifically tailored to this user and the issues they are experiencing with their computer. If you think you have a similar problem, please first read this topic, and then begin your own, new thread. I do not offer private support via Private Message.
Posted 19 May 2012 - 10:39 AM
0 members, 0 guests, 0 anonymous users