Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Google keeps redirecting me


  • This topic is locked This topic is locked
16 replies to this topic

#1 ap12345

ap12345

  • Members
  • 16 posts
  • OFFLINE
  •  
  • Local time:10:42 PM

Posted 29 July 2011 - 05:47 PM

This isn't the first time this has happened, i did what i did last time i had a problem. I performed a quick scan with malwarebytes and removed everything it found. Unfortunately it didn't work. I need to know is this being caused by any sort of malware and if so how do i get rid of it? Here are my logs-

.
DDS (Ver_2011-06-23.01) - NTFSAMD64
Internet Explorer: 8.0.6001.19088 BrowserJavaVersion: 1.6.0_22
Run by Anurag at 18:11:58 on 2011-07-29
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.6133.3687 [GMT -5:00]
.
AV: Norton 360 Premier Edition *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton 360 Premier Edition *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton 360 Premier Edition *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Program Files (x86)\MediaMall\MediaMallServer.exe
C:\Program Files (x86)\Norton 360\Norton 360\Engine\5.1.0.29\ccSvcHst.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\SysWOW64\PerfCenterCPL32.exe
C:\Windows\SysWOW64\yA
C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\WINDOWS\System32\wpcumi.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\igfxpers.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files (x86)\WallpaperSS\WallpaperSS.exe
C:\Program Files (x86)\Lexmark X125\LEX125SU.exe
C:\hp\support\hpsysdrv.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Ask.com\Updater\Updater.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
C:\Program Files (x86)\Norton 360\Norton 360\Engine\5.1.0.29\ccSvcHst.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k HPService
C:\Program Files (x86)\Windows Media Player\wmplayer.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\SysWOW64\DllHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\hp\kbd\kbd.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Windows\system32\wuauclt.exe
C:\Users\Anurag\Downloads\HijackThis.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Users\Anurag\Downloads\Defogger.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\consent.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\SysWOW64\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://securityresponse.symantec.com/avcenter/fix_homepage
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=84&bd=Pavilion&pf=cndt
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=84&bd=Pavilion&pf=cndt
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=84&bd=Pavilion&pf=cndt
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: UrlSearchHook Class: {00000000-6e41-4fd3-8538-502f5495e5fc} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
uURLSearchHooks: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll
mURLSearchHooks: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll
mWinlogon: Userinit=userinit.exe,
BHO: {013625e1-3a59-493f-bbbd-fe051f9c5973} - C:\Windows\SysWow64\authfwcfg32.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn4\yt.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
BHO: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - C:\Program Files (x86)\Norton 360\Norton 360\Engine\5.1.0.29\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - C:\Program Files (x86)\Norton 360\Norton 360\Engine\5.1.0.29\IPS\IPSBHO.DLL
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll
BHO: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
BHO: Shockwave Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn4\YTSingleInstance.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn4\yt.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - C:\Program Files (x86)\Norton 360\Norton 360\Engine\5.1.0.29\coIEPlg.dll
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
TB: Shockwave Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
TB: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll
TB: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRun: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN
uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
uRun: [WallpaperSS] C:\Program Files (x86)\WallpaperSS\WallpaperSS.exe
uRun: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe
uRun: [AdobeBridge]
uRun: [conhost] C:\Users\Anurag\AppData\Roaming\Microsoft\conhost.exe
mRun: [hpsysdrv] c:\hp\support\hpsysdrv.exe
mRun: [KBD] C:\HP\KBD\KbdStub.EXE
mRun: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre1.6.0_01\bin\jusched.exe"
mRun: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
mRun: [KeePass 2 PreLoad] "C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe" --preload
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [SwitchBoard] "C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe"
mRun: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin
mRun: [<NO NAME>]
mRun: [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe"
mRun: [TkBellExe] "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot
mRunOnce: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /install /silent
dRunOnce: [FlashPlayerUpdate] C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10p_ActiveX.exe -update activex
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\LEXMAR~1.LNK - C:\Program Files (x86)\Lexmark X125\LEX125SU.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_43C348BC2E93EB2B.dll/cmsidewiki.html
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\OFFICE11\REFIEBAR.DLL
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
LSP: C:\Windows\system32\wpclsp.dll
DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} - hxxp://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1291582944862
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {BEA7310D-06C4-4339-A784-DC3804819809} - hxxp://images3.pnimedia.com/ProductAssets/costcous/activex/v3_0_0_7/PhotoCenter_ActiveX_Control.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} - hxxps://m0.valero.com/dana-cached/sc/JuniperSetupClient.cab
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{9B4A71D2-FB58-4D01-88BA-C769A34592AF} : DhcpNameServer = 192.168.0.1
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
C:\Windows\SysWow64\authfwcfg32.dll
BHO-X64: &Yahoo! Toolbar Helper: {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn4\yt.dll
BHO-X64: 0x1 - No File
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: RealPlayer Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
BHO-X64: Conduit Engine: {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll
BHO-X64: Symantec NCO BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Norton 360\Engine\5.1.0.29\coIEPlg.dll
BHO-X64: Symantec NCO BHO - No File
BHO-X64: Symantec Intrusion Prevention: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Norton 360\Engine\5.1.0.29\IPS\IPSBHO.DLL
BHO-X64: Symantec Intrusion Prevention - No File
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO-X64: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll
BHO-X64: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll
BHO-X64: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
BHO-X64: Shockwave Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
BHO-X64: Ask Toolbar BHO - No File
BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO-X64: SingleInstance Class: {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn4\YTSingleInstance.dll
BHO-X64: HP Smart BHO Class: {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
BHO-X64: HP Smart BHO Class - No File
TB-X64: Yahoo! Toolbar: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn4\yt.dll
TB-X64: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Norton 360\Engine\5.1.0.29\coIEPlg.dll
TB-X64: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
TB-X64: Shockwave Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
TB-X64: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll
TB-X64: Conduit Engine: {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll
TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
mRun-x64: [hpsysdrv] c:\hp\support\hpsysdrv.exe
mRun-x64: [KBD] C:\HP\KBD\KbdStub.EXE
mRun-x64: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
mRun-x64: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre1.6.0_01\bin\jusched.exe"
mRun-x64: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
mRun-x64: [KeePass 2 PreLoad] "C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe" --preload
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun-x64: [SwitchBoard] "C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe"
mRun-x64: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin
mRun-x64: [(Default)]
mRun-x64: [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe"
mRun-x64: [TkBellExe] "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot
mRunOnce-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /install /silent
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Anurag\AppData\Roaming\Mozilla\Firefox\Profiles\x0tenxw3.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/firefox
FF - prefs.js: keyword.URL - hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=MTV&o=1590&locale=en_US&apn_uid=a6fa0180-0b0e-41e2-9e36-a00c79da0f4a&apn_ptnrs=^AAH&apn_sauid=A8EC3CE4-9326-4C78-A9DD-C54A9845863A&apn_dtid=^YYYYYY^YY^US&q=
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 63151
FF - prefs.js: network.proxy.type - 0
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.57\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
FF - plugin: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
FF - plugin: C:\Users\Anurag\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
============= SERVICES / DRIVERS ===============
.
R0 SymDS;Symantec Data Store;C:\Windows\system32\drivers\N360x64\0501000.01D\SYMDS64.SYS --> C:\Windows\system32\drivers\N360x64\0501000.01D\SYMDS64.SYS [?]
R0 SymEFA;Symantec Extended File Attributes;C:\Windows\system32\drivers\N360x64\0501000.01D\SYMEFA64.SYS --> C:\Windows\system32\drivers\N360x64\0501000.01D\SYMEFA64.SYS [?]
R1 BHDrvx64;BHDrvx64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\BASHDefs\20110723.001\BHDrvx64.sys [2011-7-22 1151096]
R1 IDSVia64;IDSVia64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\IPSDefs\20110728.031\IDSviA64.sys [2011-7-28 488056]
R1 SymIRON;Symantec Iron Driver;C:\Windows\system32\drivers\N360x64\0501000.01D\Ironx64.SYS --> C:\Windows\system32\drivers\N360x64\0501000.01D\Ironx64.SYS [?]
R1 SYMTDIv;Symantec Vista Network Dispatch Driver;C:\Windows\system32\drivers\N360x64\0501000.01D\SYMTDIV.SYS --> C:\Windows\system32\drivers\N360x64\0501000.01D\SYMTDIV.SYS [?]
R2 MediaMall Server;MediaMall Server;C:\Program Files (x86)\MediaMall\MediaMallServer.exe [2011-6-17 4407664]
R2 N360;Norton 360;C:\Program Files (x86)\Norton 360\Norton 360\Engine\5.1.0.29\ccSvcHst.exe [2011-6-26 130008]
R2 swprv32;Microsoft Software Shadow Copy Provider ;C:\WINDOWS\System32\PerfCenterCPL32.exe [2011-7-29 549888]
R2 TeamViewer6;TeamViewer 6;C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-2-4 2271608]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2011-7-27 136824]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-10-12 136176]
S3 BBSvc;Bing Bar Update Service;C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-2-28 183560]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-10-12 136176]
S3 PerfHost;Performance Counter DLL Host;C:\WINDOWS\SysWOW64\perfhost.exe [2008-1-20 19968]
S3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 USBTINSP;TI-Nspire™ Handheld Device Driver;C:\Windows\system32\DRIVERS\tinspusb.sys --> C:\Windows\system32\DRIVERS\tinspusb.sys [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-3-18 1020768]
S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\WINDOWS\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2010-10-11 93184]
.
=============== File Associations ===============
.
JSEFile=C:\Windows\SysWOW64\WScript.exe "%1" %*
.
=============== Created Last 30 ================
.
2011-07-29 22:19:42 41272 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2011-07-29 22:19:38 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-07-29 21:49:59 -------- d-----w- C:\Users\Anurag\AppData\Roaming\GetRightToGo
2011-07-29 20:20:51 549888 ----a-w- C:\Windows\SysWow64\yA
2011-07-29 20:20:51 549888 ----a-w- C:\Windows\SysWow64\PerfCenterCPL32.exe
2011-07-29 20:20:51 345600 ----a-w- C:\Windows\SysWow64\authfwcfg32.dll
2011-07-23 15:31:15 -------- d-----w- C:\Program Files\Realtek
2011-07-20 23:30:41 404640 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-07-12 22:58:34 2762240 ----a-w- C:\Windows\System32\win32k.sys
2011-07-12 22:58:32 450048 ----a-w- C:\Windows\System32\winsrv.dll
2011-07-12 22:58:31 85504 ----a-w- C:\Windows\System32\csrsrv.dll
2011-07-12 15:27:45 -------- d-----w- C:\Users\Anurag\AppData\Local\Downloaded Installations
2011-07-07 23:04:49 -------- d-----w- C:\Users\Anurag\AppData\Roaming\Malwarebytes
2011-07-07 23:04:43 -------- d-----w- C:\ProgramData\Malwarebytes
2011-07-07 23:04:40 25912 ----a-w- C:\Windows\System32\drivers\mbam.sys
2011-07-06 15:18:30 -------- d-----w- C:\Users\Anurag\AppData\Roaming\Xilisoft Corporation
2011-07-06 15:18:14 -------- d-----w- C:\Program Files (x86)\Xilisoft
2011-06-30 21:52:49 11776 ----a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\nprjplug.dll
2011-06-30 21:52:31 -------- d-----w- C:\Program Files (x86)\Common Files\xing shared
2011-06-30 21:52:19 150712 ----a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\nppl3260.dll
2011-06-30 21:52:13 105472 ----a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\nprpjplug.dll
2011-06-30 21:52:07 499712 ----a-w- C:\Windows\SysWow64\msvcp71.dll
2011-06-30 21:52:07 348160 ----a-w- C:\Windows\SysWow64\msvcr71.dll
.
==================== Find3M ====================
.
2011-06-26 18:28:45 174200 ----a-w- C:\Windows\System32\drivers\SYMEVENT64x86.SYS
2011-05-28 06:28:00 1147904 ----a-w- C:\Windows\System32\wininet.dll
2011-05-28 06:24:04 56832 ----a-w- C:\Windows\System32\licmgr10.dll
2011-05-28 06:23:47 1538560 ----a-w- C:\Windows\System32\inetcpl.cpl
2011-05-28 06:23:30 132096 ----a-w- C:\Windows\System32\iesysprep.dll
2011-05-28 06:23:29 77312 ----a-w- C:\Windows\System32\iesetup.dll
2011-05-28 06:08:58 916480 ----a-w- C:\Windows\SysWow64\wininet.dll
2011-05-28 06:04:30 43520 ----a-w- C:\Windows\SysWow64\licmgr10.dll
2011-05-28 06:04:17 1469440 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2011-05-28 06:04:03 71680 ----a-w- C:\Windows\SysWow64\iesetup.dll
2011-05-28 06:04:03 109056 ----a-w- C:\Windows\SysWow64\iesysprep.dll
2011-05-28 05:33:37 479232 ----a-w- C:\Windows\System32\html.iec
2011-05-28 05:10:26 385024 ----a-w- C:\Windows\SysWow64\html.iec
2011-05-28 04:53:37 162816 ----a-w- C:\Windows\System32\ieUnatt.exe
2011-05-28 04:52:18 1638912 ----a-w- C:\Windows\System32\mshtml.tlb
2011-05-28 04:33:03 133632 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2011-05-28 04:31:44 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2011-05-25 00:14:10 270720 ------w- C:\Windows\System32\MpSigStub.exe
2011-05-02 16:35:51 975360 ----a-w- C:\Windows\System32\inetcomm.dll
2011-05-02 15:58:28 738816 ----a-w- C:\Windows\SysWow64\inetcomm.dll
.
============= FINISH: 18:12:25.25 ===============

.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-06-23.01)
.
Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 10/10/2010 2:24:06 PM
System Uptime: 7/29/2011 5:08:36 PM (1 hours ago)
.
Motherboard: PEGATRON CORPORATION | | Benicia
Processor: Pentium® Dual-Core CPU E5200 @ 2.50GHz | CPU 1 | 2400/800mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 919 GiB total, 659.368 GiB free.
D: is FIXED (NTFS) - 12 GiB total, 1.627 GiB free.
E: is CDROM ()
F: is FIXED (FAT32) - 233 GiB total, 45.795 GiB free.
G: is Removable
H: is Removable
I: is Removable
J: is Removable
.
==== Disabled Device Manager Items =============
.
Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
Description: Officejet 6000 E609n
Device ID: ROOT\MULTIFUNCTION\0000
Manufacturer: HP
Name: Officejet 6000 E609n
PNP Device ID: ROOT\MULTIFUNCTION\0000
Service:
.
Class GUID: {4d36e979-e325-11ce-bfc1-08002be10318}
Description: Officejet 6000 E609n
Device ID: ROOT\PRINTER\0000
Manufacturer: HP
Name: Officejet 6000 E609n
PNP Device ID: ROOT\PRINTER\0000
Service:
.
==== System Restore Points ===================
.
.
==== Installed Programs ======================
.
Update for Microsoft Office 2007 (KB2508958)
6000E609_eDocs
6000E609_Help
6000E609n
Adobe AIR
Adobe Community Help
Adobe Digital Editions
Adobe Download Assistant
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Photoshop CS5.1
Adobe Reader 9.4.0
Adobe Shockwave Player 11.6
Apple Application Support
Apple Software Update
Ask Toolbar
Audacity 1.2.6
Avatar: Path of Zuko
AVS Image Converter 2.0.2.160
AVS Update Manager 1.0
AVS4YOU Software Navigator 1.4
Bing Bar
BPDSoftware
BPDSoftware_Ini
Brother HL-2040
BufferChm
Cards_Calendar_OrderGift_DoMorePlugout
Citrix Presentation Server Client - Web Only
Compatibility Pack for the 2007 Office system
Conduit Engine
Connectivity Library and TI-Nspire™ handheld drivers
CyberLink DVD Suite Deluxe
DeviceDiscovery
Driver Detective
Enhanced Multimedia Keyboard Solution
Game Maker 8.0
Google Chrome
Google Toolbar for Internet Explorer
Google Update Helper
GPBaseService2
Hardware Diagnostic Tools
Hewlett-Packard Active Check for Health Check
Hewlett-Packard Asset Agent for Health Check
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
HP Active Support Library
HP Customer Experience Enhancements
HP Customer Feedback
HP Demo
HP Photosmart Essential 2.5
HP Picasso Media Center Add-In
HP Recovery Manager RSS
HP Total Care Advisor
HP Update
HPPhotoSmartPhotobookWebPack1
HPProductAssistant
HPSSupply
HPTCSSetup
Java Auto Updater
Java™ 6 Update 22
Java™ SE Runtime Environment 6 Update 1
JCreator Pro 5.00
jZip
KeePass Password Safe 2.14
LabelPrint
Lexmark 730 Series
Lexmark X125
LightScribe System Software 1.14.17.1
LightScribeTemplateLabeler
Malwarebytes' Anti-Malware version 1.51.1.1800
MarketResearch
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office File Validation Add-In
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Ultimate 2007
Microsoft Office Visio Professional 2003
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft SQL Server 2005
Microsoft SQL Server 2005 Tools Express Edition
Microsoft SQL Server Setup Support Files (English)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Works
Microsoft_VC80_ATL_x86
Microsoft_VC80_CRT_x86
Microsoft_VC80_MFC_x86
Microsoft_VC80_MFCLOC_x86
Microsoft_VC90_ATL_x86
Microsoft_VC90_CRT_x86
Microsoft_VC90_MFC_x86
Microsoft_VC90_MFCLOC_x86
Mozilla Firefox 5.0 (x86 en-US)
muvee autoProducer 6.1
My HP Games
My.Freeze.com NetAssistant
Norton 360 Premier Edition
Norton Security Scan
PDF Settings CS5
PlayOn
Power2Go
PowerDirector
ProductContext
PSSWCORE
Python 2.5.2
QuickTime
RealNetworks - Microsoft Visual C++ 2008 Runtime
RealPlayer
Realtek High Definition Audio Driver
RealUpgrade 1.0
RealUpgrade 1.1
Safari
Security Update for 2007 Microsoft Office System (KB2288621)
Security Update for 2007 Microsoft Office System (KB2288931)
Security Update for 2007 Microsoft Office System (KB2345043)
Security Update for 2007 Microsoft Office System (KB2509488)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft Office 2007 System (KB2541012)
Security Update for Microsoft Office Access 2007 (KB979440)
Security Update for Microsoft Office Excel 2007 (KB2541007)
Security Update for Microsoft Office Groove 2007 (KB2494047)
Security Update for Microsoft Office InfoPath 2007 (KB2510061)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office PowerPoint 2007 (KB2535818)
Security Update for Microsoft Office PowerPoint Viewer 2007 (KB2464623)
Security Update for Microsoft Office Publisher 2007 (KB2284697)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB2344993)
SmartWebPrinting
SolutionCenter
sp44626
SpongeBob and the Clash of Triton
SPORE Creature Creator Trial Edition
Status
Synthesia (remove only)
TaxACT 2010
TeamViewer 6
TI-Nspire™ Computer Software
Toolbox
TrayApp
TWC Customer Controls
Unity Web Player
Update for 2007 Microsoft Office System (KB2284654)
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office 2007 System (KB2539530)
Update for Microsoft Office Access 2007 Help (KB963663)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office Infopath 2007 Help (KB963662)
Update for Microsoft Office OneNote 2007 (KB980729)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Outlook 2007 (KB2509470)
Update for Microsoft Office Outlook 2007 Help (KB963677)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Publisher 2007 Help (KB963667)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
Update for Outlook 2007 Junk Email Filter (KB2553975)
uTorrentBar Toolbar
VideoToolkit01
VLC media player 0.9.2
Wallpaper SlideShow LT 1.4.5
WebReg
WinRAR 4.01 (32-bit)
Xilisoft FLV Converter
Yahoo! Software Update
Yahoo! Toolbar
YouSendIt Express
.
==== Event Viewer Messages From Past Week ========
.
7/28/2011 4:08:28 PM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {4991D34B-80A1-4291-83B6-3328366B9097} to the user srinic-PC\Anurag SID (S-1-5-21-2798213428-4013127124-2554937251-1001) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
7/28/2011 3:13:07 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Mcx2Svc service.
7/25/2011 7:16:50 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the fdPHost service.
7/24/2011 1:37:52 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Search service to connect.
7/24/2011 1:37:52 PM, Error: Service Control Manager [7000] - The Windows Search service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
7/24/2011 1:24:20 PM, Error: Service Control Manager [7034] - The SQL Server VSS Writer service terminated unexpectedly. It has done this 1 time(s).
7/22/2011 3:21:08 PM, Error: Service Control Manager [7000] - The AST Service service failed to start due to the following error: The system cannot find the file specified.
.
==== End Of File ===========================

Edited by ap12345, 29 July 2011 - 06:15 PM.


BC AdBot (Login to Remove)

 


#2 CatByte

CatByte

    bleepin' tiger


  • Malware Response Team
  • 14,664 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Canada
  • Local time:12:42 AM

Posted 30 July 2011 - 03:53 PM

Hi,

Please do the following

Refer to the ComboFix User's Guide

  • Download ComboFix from one of these locations:

    Link 1
    Link 2

    * IMPORTANT !!! Place ComboFix.exe on your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.


    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


    ---------------------------------------------------------------------------------------------
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.

    ---------------------------------------------------------------------------------------------

Microsoft MVP - 2010, 2011, 2012, 2013, 2014, 2015


#3 ap12345

ap12345
  • Topic Starter

  • Members
  • 16 posts
  • OFFLINE
  •  
  • Local time:10:42 PM

Posted 30 July 2011 - 05:14 PM

Thank you so much for replying. Here is the log-

ComboFix 11-07-31.01 - Anurag 07/30/2011 16:34:37.1.2 - x64
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.6133.3689 [GMT -5:00]
Running from: c:\users\Anurag\Desktop\ComboFix.exe
AV: Norton 360 Premier Edition *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
FW: Norton 360 Premier Edition *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
SP: Norton 360 Premier Edition *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\webserver
c:\users\Anand\AppData\Roaming\Mozilla\Firefox\Profiles\kfld98jx.default\extensions\{08e85e0d-a0f4-43ef-ae73-f256b209be43}
c:\users\Anand\AppData\Roaming\Mozilla\Firefox\Profiles\kfld98jx.default\extensions\{08e85e0d-a0f4-43ef-ae73-f256b209be43}\chrome.manifest
c:\users\Anand\AppData\Roaming\Mozilla\Firefox\Profiles\kfld98jx.default\extensions\{08e85e0d-a0f4-43ef-ae73-f256b209be43}\chrome\xulcache.jar
c:\users\Anand\AppData\Roaming\Mozilla\Firefox\Profiles\kfld98jx.default\extensions\{08e85e0d-a0f4-43ef-ae73-f256b209be43}\defaults\preferences\xulcache.js
c:\users\Anand\AppData\Roaming\Mozilla\Firefox\Profiles\kfld98jx.default\extensions\{08e85e0d-a0f4-43ef-ae73-f256b209be43}\install.rdf
c:\users\Anand\AppData\Roaming\Mozilla\Firefox\Profiles\kfld98jx.default\extensions\{3bb1df99-ef96-416e-bb1c-78ff8f6ed85c}
c:\users\Anand\AppData\Roaming\Mozilla\Firefox\Profiles\kfld98jx.default\extensions\{3bb1df99-ef96-416e-bb1c-78ff8f6ed85c}\chrome.manifest
c:\users\Anand\AppData\Roaming\Mozilla\Firefox\Profiles\kfld98jx.default\extensions\{3bb1df99-ef96-416e-bb1c-78ff8f6ed85c}\chrome\xulcache.jar
c:\users\Anand\AppData\Roaming\Mozilla\Firefox\Profiles\kfld98jx.default\extensions\{3bb1df99-ef96-416e-bb1c-78ff8f6ed85c}\defaults\preferences\xulcache.js
c:\users\Anand\AppData\Roaming\Mozilla\Firefox\Profiles\kfld98jx.default\extensions\{3bb1df99-ef96-416e-bb1c-78ff8f6ed85c}\install.rdf
c:\users\Anand\AppData\Roaming\Mozilla\Firefox\Profiles\kfld98jx.default\extensions\{a13a5f83-6939-4cca-8a1f-91004d660213}
c:\users\Anand\AppData\Roaming\Mozilla\Firefox\Profiles\kfld98jx.default\extensions\{a13a5f83-6939-4cca-8a1f-91004d660213}\chrome.manifest
c:\users\Anand\AppData\Roaming\Mozilla\Firefox\Profiles\kfld98jx.default\extensions\{a13a5f83-6939-4cca-8a1f-91004d660213}\chrome\xulcache.jar
c:\users\Anand\AppData\Roaming\Mozilla\Firefox\Profiles\kfld98jx.default\extensions\{a13a5f83-6939-4cca-8a1f-91004d660213}\defaults\preferences\xulcache.js
c:\users\Anand\AppData\Roaming\Mozilla\Firefox\Profiles\kfld98jx.default\extensions\{a13a5f83-6939-4cca-8a1f-91004d660213}\install.rdf
c:\users\Anurag\AppData\Roaming\Mozilla\Firefox\Profiles\x0tenxw3.default\extensions\{08e85e0d-a0f4-43ef-ae73-f256b209be43}
c:\users\Anurag\AppData\Roaming\Mozilla\Firefox\Profiles\x0tenxw3.default\extensions\{08e85e0d-a0f4-43ef-ae73-f256b209be43}\chrome.manifest
c:\users\Anurag\AppData\Roaming\Mozilla\Firefox\Profiles\x0tenxw3.default\extensions\{08e85e0d-a0f4-43ef-ae73-f256b209be43}\chrome\xulcache.jar
c:\users\Anurag\AppData\Roaming\Mozilla\Firefox\Profiles\x0tenxw3.default\extensions\{08e85e0d-a0f4-43ef-ae73-f256b209be43}\defaults\preferences\xulcache.js
c:\users\Anurag\AppData\Roaming\Mozilla\Firefox\Profiles\x0tenxw3.default\extensions\{08e85e0d-a0f4-43ef-ae73-f256b209be43}\install.rdf
c:\users\Anurag\AppData\Roaming\Mozilla\Firefox\Profiles\x0tenxw3.default\extensions\{3bb1df99-ef96-416e-bb1c-78ff8f6ed85c}
c:\users\Anurag\AppData\Roaming\Mozilla\Firefox\Profiles\x0tenxw3.default\extensions\{3bb1df99-ef96-416e-bb1c-78ff8f6ed85c}\chrome.manifest
c:\users\Anurag\AppData\Roaming\Mozilla\Firefox\Profiles\x0tenxw3.default\extensions\{3bb1df99-ef96-416e-bb1c-78ff8f6ed85c}\chrome\xulcache.jar
c:\users\Anurag\AppData\Roaming\Mozilla\Firefox\Profiles\x0tenxw3.default\extensions\{3bb1df99-ef96-416e-bb1c-78ff8f6ed85c}\defaults\preferences\xulcache.js
c:\users\Anurag\AppData\Roaming\Mozilla\Firefox\Profiles\x0tenxw3.default\extensions\{3bb1df99-ef96-416e-bb1c-78ff8f6ed85c}\install.rdf
c:\users\Anurag\AppData\Roaming\Mozilla\Firefox\Profiles\x0tenxw3.default\extensions\{a13a5f83-6939-4cca-8a1f-91004d660213}
c:\users\Anurag\AppData\Roaming\Mozilla\Firefox\Profiles\x0tenxw3.default\extensions\{a13a5f83-6939-4cca-8a1f-91004d660213}\chrome.manifest
c:\users\Anurag\AppData\Roaming\Mozilla\Firefox\Profiles\x0tenxw3.default\extensions\{a13a5f83-6939-4cca-8a1f-91004d660213}\chrome\xulcache.jar
c:\users\Anurag\AppData\Roaming\Mozilla\Firefox\Profiles\x0tenxw3.default\extensions\{a13a5f83-6939-4cca-8a1f-91004d660213}\defaults\preferences\xulcache.js
c:\users\Anurag\AppData\Roaming\Mozilla\Firefox\Profiles\x0tenxw3.default\extensions\{a13a5f83-6939-4cca-8a1f-91004d660213}\install.rdf
c:\users\shridevi\AppData\Roaming\Mozilla\Firefox\Profiles\0soy7kfv.default\extensions\{08e85e0d-a0f4-43ef-ae73-f256b209be43}
c:\users\shridevi\AppData\Roaming\Mozilla\Firefox\Profiles\0soy7kfv.default\extensions\{08e85e0d-a0f4-43ef-ae73-f256b209be43}\chrome.manifest
c:\users\shridevi\AppData\Roaming\Mozilla\Firefox\Profiles\0soy7kfv.default\extensions\{08e85e0d-a0f4-43ef-ae73-f256b209be43}\chrome\xulcache.jar
c:\users\shridevi\AppData\Roaming\Mozilla\Firefox\Profiles\0soy7kfv.default\extensions\{08e85e0d-a0f4-43ef-ae73-f256b209be43}\defaults\preferences\xulcache.js
c:\users\shridevi\AppData\Roaming\Mozilla\Firefox\Profiles\0soy7kfv.default\extensions\{08e85e0d-a0f4-43ef-ae73-f256b209be43}\install.rdf
c:\users\shridevi\AppData\Roaming\Mozilla\Firefox\Profiles\0soy7kfv.default\extensions\{3bb1df99-ef96-416e-bb1c-78ff8f6ed85c}
c:\users\shridevi\AppData\Roaming\Mozilla\Firefox\Profiles\0soy7kfv.default\extensions\{3bb1df99-ef96-416e-bb1c-78ff8f6ed85c}\chrome.manifest
c:\users\shridevi\AppData\Roaming\Mozilla\Firefox\Profiles\0soy7kfv.default\extensions\{3bb1df99-ef96-416e-bb1c-78ff8f6ed85c}\chrome\xulcache.jar
c:\users\shridevi\AppData\Roaming\Mozilla\Firefox\Profiles\0soy7kfv.default\extensions\{3bb1df99-ef96-416e-bb1c-78ff8f6ed85c}\defaults\preferences\xulcache.js
c:\users\shridevi\AppData\Roaming\Mozilla\Firefox\Profiles\0soy7kfv.default\extensions\{3bb1df99-ef96-416e-bb1c-78ff8f6ed85c}\install.rdf
c:\users\shridevi\AppData\Roaming\Mozilla\Firefox\Profiles\0soy7kfv.default\extensions\{a13a5f83-6939-4cca-8a1f-91004d660213}
c:\users\shridevi\AppData\Roaming\Mozilla\Firefox\Profiles\0soy7kfv.default\extensions\{a13a5f83-6939-4cca-8a1f-91004d660213}\chrome.manifest
c:\users\shridevi\AppData\Roaming\Mozilla\Firefox\Profiles\0soy7kfv.default\extensions\{a13a5f83-6939-4cca-8a1f-91004d660213}\chrome\xulcache.jar
c:\users\shridevi\AppData\Roaming\Mozilla\Firefox\Profiles\0soy7kfv.default\extensions\{a13a5f83-6939-4cca-8a1f-91004d660213}\defaults\preferences\xulcache.js
c:\users\shridevi\AppData\Roaming\Mozilla\Firefox\Profiles\0soy7kfv.default\extensions\{a13a5f83-6939-4cca-8a1f-91004d660213}\install.rdf
c:\users\srinic\AppData\Roaming\Mozilla\Firefox\Profiles\5htqmnem.default\extensions\{08e85e0d-a0f4-43ef-ae73-f256b209be43}
c:\users\srinic\AppData\Roaming\Mozilla\Firefox\Profiles\5htqmnem.default\extensions\{08e85e0d-a0f4-43ef-ae73-f256b209be43}\chrome.manifest
c:\users\srinic\AppData\Roaming\Mozilla\Firefox\Profiles\5htqmnem.default\extensions\{08e85e0d-a0f4-43ef-ae73-f256b209be43}\chrome\xulcache.jar
c:\users\srinic\AppData\Roaming\Mozilla\Firefox\Profiles\5htqmnem.default\extensions\{08e85e0d-a0f4-43ef-ae73-f256b209be43}\defaults\preferences\xulcache.js
c:\users\srinic\AppData\Roaming\Mozilla\Firefox\Profiles\5htqmnem.default\extensions\{08e85e0d-a0f4-43ef-ae73-f256b209be43}\install.rdf
c:\users\srinic\AppData\Roaming\Mozilla\Firefox\Profiles\5htqmnem.default\extensions\{3bb1df99-ef96-416e-bb1c-78ff8f6ed85c}
c:\users\srinic\AppData\Roaming\Mozilla\Firefox\Profiles\5htqmnem.default\extensions\{3bb1df99-ef96-416e-bb1c-78ff8f6ed85c}\chrome.manifest
c:\users\srinic\AppData\Roaming\Mozilla\Firefox\Profiles\5htqmnem.default\extensions\{3bb1df99-ef96-416e-bb1c-78ff8f6ed85c}\chrome\xulcache.jar
c:\users\srinic\AppData\Roaming\Mozilla\Firefox\Profiles\5htqmnem.default\extensions\{3bb1df99-ef96-416e-bb1c-78ff8f6ed85c}\defaults\preferences\xulcache.js
c:\users\srinic\AppData\Roaming\Mozilla\Firefox\Profiles\5htqmnem.default\extensions\{3bb1df99-ef96-416e-bb1c-78ff8f6ed85c}\install.rdf
c:\users\srinic\AppData\Roaming\Mozilla\Firefox\Profiles\5htqmnem.default\extensions\{a13a5f83-6939-4cca-8a1f-91004d660213}
c:\users\srinic\AppData\Roaming\Mozilla\Firefox\Profiles\5htqmnem.default\extensions\{a13a5f83-6939-4cca-8a1f-91004d660213}\chrome.manifest
c:\users\srinic\AppData\Roaming\Mozilla\Firefox\Profiles\5htqmnem.default\extensions\{a13a5f83-6939-4cca-8a1f-91004d660213}\chrome\xulcache.jar
c:\users\srinic\AppData\Roaming\Mozilla\Firefox\Profiles\5htqmnem.default\extensions\{a13a5f83-6939-4cca-8a1f-91004d660213}\defaults\preferences\xulcache.js
c:\users\srinic\AppData\Roaming\Mozilla\Firefox\Profiles\5htqmnem.default\extensions\{a13a5f83-6939-4cca-8a1f-91004d660213}\install.rdf
c:\users\srinic\AppData\Roaming\Mozilla\Firefox\Profiles\ibaswvib.default\extensions\{08e85e0d-a0f4-43ef-ae73-f256b209be43}
c:\users\srinic\AppData\Roaming\Mozilla\Firefox\Profiles\ibaswvib.default\extensions\{08e85e0d-a0f4-43ef-ae73-f256b209be43}\chrome.manifest
c:\users\srinic\AppData\Roaming\Mozilla\Firefox\Profiles\ibaswvib.default\extensions\{08e85e0d-a0f4-43ef-ae73-f256b209be43}\chrome\xulcache.jar
c:\users\srinic\AppData\Roaming\Mozilla\Firefox\Profiles\ibaswvib.default\extensions\{08e85e0d-a0f4-43ef-ae73-f256b209be43}\defaults\preferences\xulcache.js
c:\users\srinic\AppData\Roaming\Mozilla\Firefox\Profiles\ibaswvib.default\extensions\{08e85e0d-a0f4-43ef-ae73-f256b209be43}\install.rdf
c:\users\srinic\AppData\Roaming\Mozilla\Firefox\Profiles\ibaswvib.default\extensions\{3bb1df99-ef96-416e-bb1c-78ff8f6ed85c}
c:\users\srinic\AppData\Roaming\Mozilla\Firefox\Profiles\ibaswvib.default\extensions\{3bb1df99-ef96-416e-bb1c-78ff8f6ed85c}\chrome.manifest
c:\users\srinic\AppData\Roaming\Mozilla\Firefox\Profiles\ibaswvib.default\extensions\{3bb1df99-ef96-416e-bb1c-78ff8f6ed85c}\chrome\xulcache.jar
c:\users\srinic\AppData\Roaming\Mozilla\Firefox\Profiles\ibaswvib.default\extensions\{3bb1df99-ef96-416e-bb1c-78ff8f6ed85c}\defaults\preferences\xulcache.js
c:\users\srinic\AppData\Roaming\Mozilla\Firefox\Profiles\ibaswvib.default\extensions\{3bb1df99-ef96-416e-bb1c-78ff8f6ed85c}\install.rdf
c:\users\srinic\AppData\Roaming\Mozilla\Firefox\Profiles\ibaswvib.default\extensions\{a13a5f83-6939-4cca-8a1f-91004d660213}
c:\users\srinic\AppData\Roaming\Mozilla\Firefox\Profiles\ibaswvib.default\extensions\{a13a5f83-6939-4cca-8a1f-91004d660213}\chrome.manifest
c:\users\srinic\AppData\Roaming\Mozilla\Firefox\Profiles\ibaswvib.default\extensions\{a13a5f83-6939-4cca-8a1f-91004d660213}\chrome\xulcache.jar
c:\users\srinic\AppData\Roaming\Mozilla\Firefox\Profiles\ibaswvib.default\extensions\{a13a5f83-6939-4cca-8a1f-91004d660213}\defaults\preferences\xulcache.js
c:\users\srinic\AppData\Roaming\Mozilla\Firefox\Profiles\ibaswvib.default\extensions\{a13a5f83-6939-4cca-8a1f-91004d660213}\install.rdf
c:\windows\SysWow64\jusched.exe
F:\autorun.inf
.
.
((((((((((((((((((((((((( Files Created from 2011-06-28 to 2011-07-30 )))))))))))))))))))))))))))))))
.
.
2011-07-30 22:07 . 2011-07-30 22:07 -------- d-----w- c:\users\srinic\AppData\Local\temp
2011-07-30 22:07 . 2011-07-30 22:07 -------- d-----w- c:\users\shridevi\AppData\Local\temp
2011-07-30 21:20 . 2011-07-30 21:29 -------- d-----w- C:\32788R22FWJFW
2011-07-29 22:19 . 2011-07-30 21:19 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-07-29 21:49 . 2011-07-29 22:02 -------- d-----w- c:\users\Anurag\AppData\Roaming\GetRightToGo
2011-07-29 20:20 . 2011-07-29 20:20 345600 ----a-w- c:\windows\SysWow64\authfwcfg32.dll
2011-07-29 20:20 . 2011-07-28 22:41 549888 ----a-w- c:\windows\SysWow64\yA
2011-07-29 20:20 . 2011-07-28 22:41 549888 ----a-w- c:\windows\SysWow64\PerfCenterCPL32.exe
2011-07-23 15:31 . 2011-07-23 15:31 -------- d-----w- c:\program files\Realtek
2011-07-20 23:30 . 2011-07-20 23:30 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-07-12 22:58 . 2011-06-02 13:22 2762240 ----a-w- c:\windows\system32\win32k.sys
2011-07-12 22:58 . 2011-04-20 15:16 450048 ----a-w- c:\windows\system32\winsrv.dll
2011-07-12 22:58 . 2011-04-20 15:11 85504 ----a-w- c:\windows\system32\csrsrv.dll
2011-07-12 15:32 . 2011-07-12 15:32 -------- d-----w- c:\users\Anand\AppData\Local\Downloaded Installations
2011-07-12 15:27 . 2011-07-12 15:27 -------- d-----w- c:\users\Anurag\AppData\Local\Downloaded Installations
2011-07-07 23:04 . 2011-07-07 23:04 -------- d-----w- c:\users\Anurag\AppData\Roaming\Malwarebytes
2011-07-07 23:04 . 2011-07-07 23:04 -------- d-----w- c:\programdata\Malwarebytes
2011-07-07 23:04 . 2011-07-07 00:52 25912 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-07-06 15:18 . 2011-07-06 15:18 -------- d-----w- c:\users\Anurag\AppData\Roaming\Xilisoft Corporation
2011-07-06 15:18 . 2011-07-06 15:18 -------- d-----w- c:\program files (x86)\Xilisoft
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-30 21:52 . 2011-06-30 21:52 499712 ----a-w- c:\windows\SysWow64\msvcp71.dll
2011-06-30 21:52 . 2011-06-30 21:52 348160 ----a-w- c:\windows\SysWow64\msvcr71.dll
2011-06-26 18:28 . 2010-10-10 21:59 174200 ----a-w- c:\windows\system32\drivers\SYMEVENT64x86.SYS
2011-06-07 17:10 . 2011-06-24 13:53 8873296 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{BF1F51E4-DAEB-4DE8-AC04-1A26AF1E44C8}\mpengine.dll
2011-05-28 06:28 . 2011-06-15 20:46 1147904 ----a-w- c:\windows\system32\wininet.dll
2011-05-28 06:24 . 2011-06-15 20:46 56832 ----a-w- c:\windows\system32\licmgr10.dll
2011-05-28 06:23 . 2011-06-15 20:46 1538560 ----a-w- c:\windows\system32\inetcpl.cpl
2011-05-28 06:23 . 2011-06-15 20:46 132096 ----a-w- c:\windows\system32\iesysprep.dll
2011-05-28 06:23 . 2011-06-15 20:46 77312 ----a-w- c:\windows\system32\iesetup.dll
2011-05-28 06:08 . 2011-06-15 20:46 916480 ----a-w- c:\windows\SysWow64\wininet.dll
2011-05-28 06:04 . 2011-06-15 20:46 43520 ----a-w- c:\windows\SysWow64\licmgr10.dll
2011-05-28 06:04 . 2011-06-15 20:46 1469440 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2011-05-28 06:04 . 2011-06-15 20:46 71680 ----a-w- c:\windows\SysWow64\iesetup.dll
2011-05-28 06:04 . 2011-06-15 20:46 109056 ----a-w- c:\windows\SysWow64\iesysprep.dll
2011-05-28 05:33 . 2011-06-15 20:46 479232 ----a-w- c:\windows\system32\html.iec
2011-05-28 05:10 . 2011-06-15 20:46 385024 ----a-w- c:\windows\SysWow64\html.iec
2011-05-28 04:53 . 2011-06-15 20:46 162816 ----a-w- c:\windows\system32\ieUnatt.exe
2011-05-28 04:52 . 2011-06-15 20:46 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2011-05-28 04:33 . 2011-06-15 20:46 133632 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2011-05-28 04:31 . 2011-06-15 20:46 1638912 ----a-w- c:\windows\SysWow64\mshtml.tlb
2011-05-25 00:14 . 2010-12-03 22:08 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-05-02 16:35 . 2011-06-15 20:46 975360 ----a-w- c:\windows\system32\inetcomm.dll
2011-05-02 15:58 . 2011-06-15 20:46 738816 ----a-w- c:\windows\SysWow64\inetcomm.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files (x86)\Ask.com\GenericAskToolbar.dll" [2011-05-17 1490312]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files (x86)\uTorrentBar\tbuTor.dll" [2010-12-09 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{013625E1-3A59-493F-BBBD-FE051F9C5973}]
2011-07-29 20:20 345600 ----a-w- c:\windows\SysWOW64\authfwcfg32.dll
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-12-09 18:51 3911776 ----a-w- c:\program files (x86)\ConduitEngine\ConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
2010-12-09 18:51 3911776 ----a-w- c:\program files (x86)\uTorrentBar\tbuTor.dll
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2011-05-17 18:29 1490312 ----a-w- c:\program files (x86)\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files (x86)\Ask.com\GenericAskToolbar.dll" [2011-05-17 1490312]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files (x86)\uTorrentBar\tbuTor.dll" [2010-12-09 3911776]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files (x86)\ConduitEngine\ConduitEngine.dll" [2010-12-09 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1555968]
"HPADVISOR"="c:\program files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2008-07-03 972080]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-10-12 39408]
"WallpaperSS"="c:\program files (x86)\WallpaperSS\WallpaperSS.exe" [2010-11-16 454344]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 65536]
"KBD"="c:\hp\KBD\KbdStub.EXE" [2006-12-08 65536]
"HP Health Check Scheduler"="c:\program files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-06-02 75008]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"SunJavaUpdateSched"="c:\program files (x86)\Java\jre1.6.0_01\bin\jusched.exe" [2007-04-07 132760]
"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]
"AppleSyncNotifier"="c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-04-20 58656]
"KeePass 2 PreLoad"="c:\program files (x86)\KeePass Password Safe 2\KeePass.exe" [2011-01-02 1670656]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-04-27 421160]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5.5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360]
"ApnUpdater"="c:\program files (x86)\Ask.com\Updater\Updater.exe" [2011-05-17 395144]
"TkBellExe"="c:\program files (x86)\real\realplayer\Update\realsched.exe" [2011-06-30 273544]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="c:\windows\SysWOW64\Macromed\Flash\FlashUtil10p_ActiveX.exe" [2011-04-22 235168]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Lexmark X125 Settings Utility.lnk - c:\program files (x86)\Lexmark X125\LEX125SU.exe [2010-10-14 1990656]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-12 136176]
R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-12 136176]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\System32\Drivers\N360x64\0308000.029\SYMNDISV.SYS [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 USBTINSP;TI-Nspire™ Handheld Device Driver;c:\windows\system32\DRIVERS\tinspusb.sys [x]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 1020768]
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360x64\0501000.01D\SYMDS64.SYS [x]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360x64\0501000.01D\SYMEFA64.SYS [x]
S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\BASHDefs\20110723.001\BHDrvx64.sys [2011-07-23 1151096]
S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\IPSDefs\20110729.030\IDSvia64.sys [2011-07-07 488056]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360x64\0501000.01D\Ironx64.SYS [x]
S1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\system32\drivers\N360x64\0501000.01D\SYMTDIV.SYS [x]
S2 MediaMall Server;MediaMall Server;c:\program files (x86)\MediaMall\MediaMallServer.exe [2011-07-30 4411248]
S2 N360;Norton 360;c:\program files (x86)\Norton 360\Norton 360\Engine\5.1.0.29\ccSvcHst.exe [2011-04-17 130008]
S2 TeamViewer6;TeamViewer 6;c:\program files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-04-01 2271608]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2011-07-28 136824]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2011-07-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-12 18:27]
.
2011-07-30 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-12 18:27]
.
2011-07-28 c:\windows\Tasks\Norton Security Scan for Anurag.job
- c:\progra~2\NORTON~3\NORTON~1\Engine\311~1.6\Nss.exe [2011-06-27 16:39]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-06-11 178712]
"WPCUMI"="c:\windows\system32\WpcUmi.exe" [2006-11-02 182784]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2010-07-21 2306448]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-15 499608]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-02-27 154648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-02-27 227352]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-02-27 202264]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Supplementary Scan -------
.
uStart Page = hxxp://securityresponse.symantec.com/avcenter/fix_homepage
uLocal Page = c:\windows\system32\blank.htm
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=84&bd=Pavilion&pf=cndt
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_43C348BC2E93EB2B.dll/cmsidewiki.html
LSP: c:\windows\system32\wpclsp.dll
TCP: DhcpNameServer = 192.168.0.1
CLSID: {603d3801-bd81-11d0-a3a5-00c04fd706ec} - %SystemRoot%\SysWow64\browseui.dll
FF - ProfilePath - c:\users\Anurag\AppData\Roaming\Mozilla\Firefox\Profiles\x0tenxw3.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/firefox
FF - prefs.js: keyword.URL - hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=MTV&o=1590&locale=en_US&apn_uid=a6fa0180-0b0e-41e2-9e36-a00c79da0f4a&apn_ptnrs=^AAH&apn_sauid=A8EC3CE4-9326-4C78-A9DD-C54A9845863A&apn_dtid=^YYYYYY^YY^US&q=
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 63151
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKCU-Run-WMPNSCFG - c:\program files (x86)\Windows Media Player\WMPNSCFG.exe
Wow6432Node-HKCU-Run-AdobeBridge - (no file)
Wow6432Node-HKCU-Run-conhost - c:\users\Anurag\AppData\Roaming\Microsoft\conhost.exe
Wow6432Node-HKLM-Run-Adobe Reader Speed Launcher - c:\program files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - (no file)
WebBrowser-{30F9B915-B755-4826-820B-08FBA6BD249D} - (no file)
HKLM-Run-Windows Defender - c:\program files (x86)\Windows Defender\MSASCui.exe
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
AddRemove-Lexmark 730 Series - c:\program files (x86) (x86)\Lexmark 730 Series\Install\x64\Uninst.exe
AddRemove-sp44626 - c:\hp\Softpaq\sp44626\sp44626.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\N360]
"ImagePath"="\"c:\program files (x86)\Norton 360\Norton 360\Engine\5.1.0.29\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files (x86)\Norton 360\Norton 360\Engine\5.1.0.29\diMaster.dll\" /prefetch:1"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@=""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@="FlashBroker"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
Completion time: 2011-07-30 17:09:41
ComboFix-quarantined-files.txt 2011-07-30 22:09
.
Pre-Run: 711,526,371,328 bytes free
Post-Run: 712,844,685,312 bytes free
.
- - End Of File - - DB7208ABA3EA31DBECC0BA784BC00A1F

#4 CatByte

CatByte

    bleepin' tiger


  • Malware Response Team
  • 14,664 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Canada
  • Local time:12:42 AM

Posted 30 July 2011 - 05:55 PM

Hi

Please do the following:


submit a file to virustotal for analysis
  • Use the browse button on that page to navigate to the location of the file to be scanned.
  • In the right hand panel,
  • click on the file c:\windows\SysWow64\authfwcfg32.dll
  • then click the open button.
  • The file will now be displayed in the submit box.
  • Scroll down a bit and click "send file", wait for the results
  • If you get a message saying File has already been analyzed: click Reanalyze file now
  • Once scanned, copy and paste the link to the results page in your next reply.


Make sure you have copied and saved the results before continuing.
Do the same for the following files
c:\windows\SysWow64\yA
c:\windows\SysWow64\PerfCenterCPL32.exe

Microsoft MVP - 2010, 2011, 2012, 2013, 2014, 2015


#5 ap12345

ap12345
  • Topic Starter

  • Members
  • 16 posts
  • OFFLINE
  •  
  • Local time:10:42 PM

Posted 30 July 2011 - 06:43 PM

Thanks again, here's the link
http://www.virustotal.com/file-scan/report.html?id=a4badf273118499ee16e595530747400cf881cdfd2ac0532f26b4d97a5918a5e-1312069026

#6 CatByte

CatByte

    bleepin' tiger


  • Malware Response Team
  • 14,664 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Canada
  • Local time:12:42 AM

Posted 30 July 2011 - 07:31 PM

can you please do the other two files I asked for as well, thanks :)

Microsoft MVP - 2010, 2011, 2012, 2013, 2014, 2015


#7 ap12345

ap12345
  • Topic Starter

  • Members
  • 16 posts
  • OFFLINE
  •  
  • Local time:10:42 PM

Posted 30 July 2011 - 08:22 PM

Sorry i didn't see that. Anyway here they are

http://www.virustotal.com/file-scan/report.html?id=677554299826a686b168172cd3395215d76e093b39d0e6a6e790c2b5e9521ddb-1312073505
http://www.virustotal.com/file-scan/report.html?id=677554299826a686b168172cd3395215d76e093b39d0e6a6e790c2b5e9521ddb-1312074972

#8 CatByte

CatByte

    bleepin' tiger


  • Malware Response Team
  • 14,664 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Canada
  • Local time:12:42 AM

Posted 30 July 2011 - 08:52 PM

Hi,

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://www.bleepingcomputer.com/forums/topic411967.html/page__view__findpost__p__2353298

Collect::
c:\windows\SysWow64\authfwcfg32.dll
c:\windows\SysWow64\yA
c:\windows\SysWow64\PerfCenterCPL32.exe

Registry::
[-HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{013625E1-3A59-493F-BBBD-FE051F9C5973}]

FireFox::
FF - ProfilePath - c:\users\Anurag\AppData\Roaming\Mozilla\Firefox\Profiles\x0tenxw3.default\
FF - prefs.js: network.proxy.http_port - 63151

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As... Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save ...

Posted Image
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Microsoft MVP - 2010, 2011, 2012, 2013, 2014, 2015


#9 ap12345

ap12345
  • Topic Starter

  • Members
  • 16 posts
  • OFFLINE
  •  
  • Local time:10:42 PM

Posted 30 July 2011 - 09:27 PM

Ok here's the log-

ComboFix 11-07-31.01 - Anurag 07/30/2011 21:08:01.2.2 - x64
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.6133.3550 [GMT -5:00]
Running from: c:\users\Anurag\Desktop\ComboFix.exe
Command switches used :: c:\users\Anurag\Desktop\CFScript.txt
AV: Norton 360 Premier Edition *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
FW: Norton 360 Premier Edition *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
SP: Norton 360 Premier Edition *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Object\bhO_project.dll
c:\program files (x86)\StartNow Toolbar
c:\program files (x86)\StartNow Toolbar\Resources\images\btn-msn.png
c:\program files (x86)\StartNow Toolbar\Resources\images\chevronButton.png
c:\program files (x86)\StartNow Toolbar\Resources\images\engine_images.png
c:\program files (x86)\StartNow Toolbar\Resources\images\engine_maps.png
c:\program files (x86)\StartNow Toolbar\Resources\images\engine_news.png
c:\program files (x86)\StartNow Toolbar\Resources\images\engine_videos.png
c:\program files (x86)\StartNow Toolbar\Resources\images\engine_web.png
c:\program files (x86)\StartNow Toolbar\Resources\images\icon_amazon.png
c:\program files (x86)\StartNow Toolbar\Resources\images\icon_ebay.png
c:\program files (x86)\StartNow Toolbar\Resources\images\icon_facebook.png
c:\program files (x86)\StartNow Toolbar\Resources\images\icon_games.png
c:\program files (x86)\StartNow Toolbar\Resources\images\icon_shopping.png
c:\program files (x86)\StartNow Toolbar\Resources\images\icon_travel.png
c:\program files (x86)\StartNow Toolbar\Resources\images\icon_twitter.png
c:\program files (x86)\StartNow Toolbar\Resources\images\separator.png
c:\program files (x86)\StartNow Toolbar\Resources\images\splitter.png
c:\program files (x86)\StartNow Toolbar\Resources\images\startnow_logo.png
c:\program files (x86)\StartNow Toolbar\Resources\installer.xml
c:\program files (x86)\StartNow Toolbar\Resources\protect\index.html
c:\program files (x86)\StartNow Toolbar\Resources\protect\NotIE6.css
c:\program files (x86)\StartNow Toolbar\Resources\protect\OnlyIE6.css
c:\program files (x86)\StartNow Toolbar\Resources\protect\SearchProtectIcon.png
c:\program files (x86)\StartNow Toolbar\Resources\protect\window.css
c:\program files (x86)\StartNow Toolbar\Resources\protect\window.js
c:\program files (x86)\StartNow Toolbar\Resources\reactivate\index.html
c:\program files (x86)\StartNow Toolbar\Resources\reactivate\LeftImage.png
c:\program files (x86)\StartNow Toolbar\Resources\reactivate\NotIE6.css
c:\program files (x86)\StartNow Toolbar\Resources\reactivate\OnlyIE6.css
c:\program files (x86)\StartNow Toolbar\Resources\reactivate\window.css
c:\program files (x86)\StartNow Toolbar\Resources\reactivate\window.js
c:\program files (x86)\StartNow Toolbar\Resources\searchbox\dropdown_button_normal.png
c:\program files (x86)\StartNow Toolbar\Resources\searchbox\searchbox_button_hover.png
c:\program files (x86)\StartNow Toolbar\Resources\searchbox\searchbox_button_normal.png
c:\program files (x86)\StartNow Toolbar\Resources\searchbox\searchbox_input_left.png
c:\program files (x86)\StartNow Toolbar\Resources\searchbox\searchbox_input_middle.png
c:\program files (x86)\StartNow Toolbar\Resources\toolbar.xml
c:\program files (x86)\StartNow Toolbar\Resources\toolbarbutton\hover_c.png
c:\program files (x86)\StartNow Toolbar\Resources\toolbarbutton\hover_l.png
c:\program files (x86)\StartNow Toolbar\Resources\toolbarbutton\hover_r.png
c:\program files (x86)\StartNow Toolbar\Resources\toolbarbutton\normal_c.png
c:\program files (x86)\StartNow Toolbar\Resources\toolbarbutton\normal_l.png
c:\program files (x86)\StartNow Toolbar\Resources\toolbarbutton\normal_r.png
c:\program files (x86)\StartNow Toolbar\Resources\update.xml
c:\program files (x86)\StartNow Toolbar\StartNowToolbarUninstall.exe
c:\program files (x86)\StartNow Toolbar\Toolbar32.dll
c:\program files (x86)\StartNow Toolbar\ToolbarUpdaterService.exe
c:\program files (x86)\StartNow Toolbar\uninstall.dat
c:\windows\SysWow64\authfwcfg32.dll
c:\windows\SysWow64\PerfCenterCPL32.exe
c:\windows\SysWow64\yA
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_Toolbar Updater Service
-------\Service_Toolbar Updater Service
.
.
((((((((((((((((((((((((( Files Created from 2011-06-28 to 2011-07-31 )))))))))))))))))))))))))))))))
.
.
2011-07-31 02:15 . 2011-07-31 02:15 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\temp
2011-07-31 02:15 . 2011-07-31 02:15 -------- d-----w- c:\users\srinic\AppData\Local\temp
2011-07-31 02:15 . 2011-07-31 02:15 -------- d-----w- c:\users\shridevi\AppData\Local\temp
2011-07-31 02:15 . 2011-07-31 02:15 -------- d-----w- c:\users\Mcx1\AppData\Local\temp
2011-07-31 02:15 . 2011-07-31 02:15 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-07-31 02:15 . 2011-07-31 02:15 -------- d-----w- c:\users\Anand\AppData\Local\temp
2011-07-30 23:36 . 2011-07-30 23:39 158067944 ----a-w- c:\program files (x86)\OpenOffice.exe
2011-07-30 23:36 . 2011-07-31 02:14 -------- d-----w- c:\program files (x86)\Object
2011-07-30 23:36 . 2011-07-30 23:39 -------- d-----w- c:\program files\OpenOffice
2011-07-30 23:36 . 2011-07-30 23:36 -------- d-----w- c:\program files (x86)\DealPly
2011-07-30 23:36 . 2011-07-30 23:36 428664 ----a-w- c:\program files (x86)\OpenOffice Downloader.exe
2011-07-29 22:19 . 2011-07-31 02:17 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-07-29 21:49 . 2011-07-29 22:02 -------- d-----w- c:\users\Anurag\AppData\Roaming\GetRightToGo
2011-07-23 15:31 . 2011-07-23 15:31 -------- d-----w- c:\program files\Realtek
2011-07-20 23:30 . 2011-07-20 23:30 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-07-12 22:58 . 2011-06-02 13:22 2762240 ----a-w- c:\windows\system32\win32k.sys
2011-07-12 22:58 . 2011-04-20 15:16 450048 ----a-w- c:\windows\system32\winsrv.dll
2011-07-12 22:58 . 2011-04-20 15:11 85504 ----a-w- c:\windows\system32\csrsrv.dll
2011-07-12 15:32 . 2011-07-12 15:32 -------- d-----w- c:\users\Anand\AppData\Local\Downloaded Installations
2011-07-12 15:27 . 2011-07-12 15:27 -------- d-----w- c:\users\Anurag\AppData\Local\Downloaded Installations
2011-07-07 23:04 . 2011-07-07 23:04 -------- d-----w- c:\users\Anurag\AppData\Roaming\Malwarebytes
2011-07-07 23:04 . 2011-07-07 23:04 -------- d-----w- c:\programdata\Malwarebytes
2011-07-07 23:04 . 2011-07-07 00:52 25912 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-07-06 15:18 . 2011-07-06 15:18 -------- d-----w- c:\users\Anurag\AppData\Roaming\Xilisoft Corporation
2011-07-06 15:18 . 2011-07-06 15:18 -------- d-----w- c:\program files (x86)\Xilisoft
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-30 21:52 . 2011-06-30 21:52 499712 ----a-w- c:\windows\SysWow64\msvcp71.dll
2011-06-30 21:52 . 2011-06-30 21:52 348160 ----a-w- c:\windows\SysWow64\msvcr71.dll
2011-06-26 18:28 . 2010-10-10 21:59 174200 ----a-w- c:\windows\system32\drivers\SYMEVENT64x86.SYS
2011-06-07 17:10 . 2011-06-24 13:53 8873296 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{BF1F51E4-DAEB-4DE8-AC04-1A26AF1E44C8}\mpengine.dll
2011-05-28 06:28 . 2011-06-15 20:46 1147904 ----a-w- c:\windows\system32\wininet.dll
2011-05-28 06:24 . 2011-06-15 20:46 56832 ----a-w- c:\windows\system32\licmgr10.dll
2011-05-28 06:23 . 2011-06-15 20:46 1538560 ----a-w- c:\windows\system32\inetcpl.cpl
2011-05-28 06:23 . 2011-06-15 20:46 132096 ----a-w- c:\windows\system32\iesysprep.dll
2011-05-28 06:23 . 2011-06-15 20:46 77312 ----a-w- c:\windows\system32\iesetup.dll
2011-05-28 06:08 . 2011-06-15 20:46 916480 ----a-w- c:\windows\SysWow64\wininet.dll
2011-05-28 06:04 . 2011-06-15 20:46 43520 ----a-w- c:\windows\SysWow64\licmgr10.dll
2011-05-28 06:04 . 2011-06-15 20:46 1469440 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2011-05-28 06:04 . 2011-06-15 20:46 71680 ----a-w- c:\windows\SysWow64\iesetup.dll
2011-05-28 06:04 . 2011-06-15 20:46 109056 ----a-w- c:\windows\SysWow64\iesysprep.dll
2011-05-28 05:33 . 2011-06-15 20:46 479232 ----a-w- c:\windows\system32\html.iec
2011-05-28 05:10 . 2011-06-15 20:46 385024 ----a-w- c:\windows\SysWow64\html.iec
2011-05-28 04:53 . 2011-06-15 20:46 162816 ----a-w- c:\windows\system32\ieUnatt.exe
2011-05-28 04:52 . 2011-06-15 20:46 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2011-05-28 04:33 . 2011-06-15 20:46 133632 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2011-05-28 04:31 . 2011-06-15 20:46 1638912 ----a-w- c:\windows\SysWow64\mshtml.tlb
2011-05-25 00:14 . 2010-12-03 22:08 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-05-02 16:35 . 2011-06-15 20:46 975360 ----a-w- c:\windows\system32\inetcomm.dll
2011-05-02 15:58 . 2011-06-15 20:46 738816 ----a-w- c:\windows\SysWow64\inetcomm.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-07-30_22.07.52 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-21 03:20 . 2011-07-30 16:51 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-01-21 03:20 . 2011-07-31 02:17 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-01-21 03:20 . 2011-07-30 16:51 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-01-21 03:20 . 2011-07-31 02:17 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-10-15 04:43 . 2011-07-31 02:17 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-10-15 04:43 . 2011-07-30 15:51 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-10-15 04:43 . 2011-07-31 02:17 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-10-15 04:43 . 2011-07-30 15:51 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2011-07-30 15:50 . 2011-07-30 15:50 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-07-31 02:17 . 2011-07-31 02:17 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-07-31 02:17 . 2011-07-31 02:17 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2011-07-30 15:50 . 2011-07-30 15:50 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2008-01-21 03:20 . 2011-07-30 16:51 475136 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-01-21 03:20 . 2011-07-31 02:17 475136 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-10-10 17:59 . 2011-07-31 02:15 249776 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2011-07-30 23:40 . 2011-07-30 23:40 219648 c:\windows\Installer\1ae7c8d.msi
+ 2006-11-02 12:33 . 2011-07-31 02:15 10743808 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
+ 2011-07-31 02:15 . 2011-07-31 02:15 10743808 c:\windows\ERDNT\subs\SCHEMA.DAT
+ 2011-07-31 02:06 . 2011-07-31 02:06 10743808 c:\windows\ERDNT\Hiv-backup\SCHEMA.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-12-09 18:51 3911776 ----a-w- c:\program files (x86)\ConduitEngine\ConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448}]
2011-06-16 13:56 78600 ----a-w- c:\program files (x86)\DealPly\DealPlyIE.dll
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
2010-12-09 18:51 3911776 ----a-w- c:\program files (x86)\uTorrentBar\tbuTor.dll
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2011-05-17 18:29 1490312 ----a-w- c:\program files (x86)\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files (x86)\Ask.com\GenericAskToolbar.dll" [2011-05-17 1490312]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files (x86)\uTorrentBar\tbuTor.dll" [2010-12-09 3911776]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files (x86)\ConduitEngine\ConduitEngine.dll" [2010-12-09 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1555968]
"HPADVISOR"="c:\program files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2008-07-03 972080]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-10-12 39408]
"WallpaperSS"="c:\program files (x86)\WallpaperSS\WallpaperSS.exe" [2010-11-16 454344]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 65536]
"KBD"="c:\hp\KBD\KbdStub.EXE" [2006-12-08 65536]
"HP Health Check Scheduler"="c:\program files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-06-02 75008]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"SunJavaUpdateSched"="c:\program files (x86)\Java\jre1.6.0_01\bin\jusched.exe" [2007-04-07 132760]
"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]
"AppleSyncNotifier"="c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-04-20 58656]
"KeePass 2 PreLoad"="c:\program files (x86)\KeePass Password Safe 2\KeePass.exe" [2011-01-02 1670656]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-04-27 421160]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5.5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360]
"ApnUpdater"="c:\program files (x86)\Ask.com\Updater\Updater.exe" [2011-05-17 395144]
"TkBellExe"="c:\program files (x86)\real\realplayer\Update\realsched.exe" [2011-06-30 273544]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="c:\windows\SysWOW64\Macromed\Flash\FlashUtil10p_ActiveX.exe" [2011-04-22 235168]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Lexmark X125 Settings Utility.lnk - c:\program files (x86)\Lexmark X125\LEX125SU.exe [2010-10-14 1990656]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-12 136176]
R2 swprv32;Microsoft Software Shadow Copy Provider ;c:\windows\system32\PerfCenterCPL32.exe [x]
R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-12 136176]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\System32\Drivers\N360x64\0308000.029\SYMNDISV.SYS [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 USBTINSP;TI-Nspire™ Handheld Device Driver;c:\windows\system32\DRIVERS\tinspusb.sys [x]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 1020768]
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360x64\0501000.01D\SYMDS64.SYS [x]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360x64\0501000.01D\SYMEFA64.SYS [x]
S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\BASHDefs\20110723.001\BHDrvx64.sys [2011-07-23 1151096]
S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\IPSDefs\20110729.030\IDSvia64.sys [2011-07-07 488056]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360x64\0501000.01D\Ironx64.SYS [x]
S1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\system32\drivers\N360x64\0501000.01D\SYMTDIV.SYS [x]
S2 MediaMall Server;MediaMall Server;c:\program files (x86)\MediaMall\MediaMallServer.exe [2011-07-30 4411248]
S2 N360;Norton 360;c:\program files (x86)\Norton 360\Norton 360\Engine\5.1.0.29\ccSvcHst.exe [2011-04-17 130008]
S2 TeamViewer6;TeamViewer 6;c:\program files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-04-01 2271608]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2011-07-28 136824]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2011-07-31 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-12 18:27]
.
2011-07-30 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-12 18:27]
.
2011-07-28 c:\windows\Tasks\Norton Security Scan for Anurag.job
- c:\progra~2\NORTON~3\NORTON~1\Engine\311~1.6\Nss.exe [2011-06-27 16:39]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"combofix"="c:\combofix\CF16489.cfxxe" [X]
"IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-06-11 178712]
"WPCUMI"="c:\windows\system32\WpcUmi.exe" [2006-11-02 182784]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2010-07-21 2306448]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-15 499608]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-02-27 154648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-02-27 227352]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-02-27 202264]
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.startnow.com/?src=startpage&provider=Bing&provider_code=Z059&partner_id=308&product_id=435&affiliate_id=&channel=dptoby&toolbar_id=200&toolbar_version=2.0&install_country=US&install_date=20110730&user_guid=9D1344F33E564752AF89F65200C09414&machine_id=b1d47d9ab7ab39400bb5d669d71e0c22&browser=IE&os=win&os_version=6.0-x64-SP1
uLocal Page = c:\windows\system32\blank.htm
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=84&bd=Pavilion&pf=cndt
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_70C5B381380DB17F.dll/cmsidewiki.html
LSP: c:\windows\system32\wpclsp.dll
TCP: DhcpNameServer = 192.168.0.1
CLSID: {603d3801-bd81-11d0-a3a5-00c04fd706ec} - %SystemRoot%\SysWow64\browseui.dll
FF - ProfilePath - c:\users\Anurag\AppData\Roaming\Mozilla\Firefox\Profiles\x0tenxw3.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/firefox
FF - prefs.js: keyword.URL - hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=MTV&o=1590&locale=en_US&apn_uid=a6fa0180-0b0e-41e2-9e36-a00c79da0f4a&apn_ptnrs=^AAH&apn_sauid=A8EC3CE4-9326-4C78-A9DD-C54A9845863A&apn_dtid=^YYYYYY^YY^US&q=
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - (no file)
WebBrowser-{30F9B915-B755-4826-820B-08FBA6BD249D} - (no file)
AddRemove-StartNow Toolbar - c:\program files (x86)\StartNow Toolbar\StartNowToolbarUninstall.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\N360]
"ImagePath"="\"c:\program files (x86)\Norton 360\Norton 360\Engine\5.1.0.29\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files (x86)\Norton 360\Norton 360\Engine\5.1.0.29\diMaster.dll\" /prefetch:1"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@=""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@="FlashBroker"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Bonjour\mDNSResponder.exe
c:\program files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe
c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE
c:\windows\SysWOW64\DllHost.exe
c:\hp\kbd\kbd.exe
.
**************************************************************************
.
Completion time: 2011-07-30 21:24:44 - machine was rebooted
ComboFix-quarantined-files.txt 2011-07-31 02:24
ComboFix2.txt 2011-07-30 22:09
.
Pre-Run: 711,840,886,784 bytes free
Post-Run: 711,817,355,264 bytes free
.
- - End Of File - - 9D3D0E491196E9442CDD9A2D6134D3A9
Upload was successful

#10 CatByte

CatByte

    bleepin' tiger


  • Malware Response Team
  • 14,664 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Canada
  • Local time:12:42 AM

Posted 30 July 2011 - 10:09 PM

Hi,

Please do the following:

On your keyboard, press the Windows logo key and the letter R to open a Run command box

enter the following two commands one at a time, hitting enter after each.

sc stop swprv32
sc delete swprv32

Reboot the machine.


NEXT


  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <-- very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Go here to run an online scanner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish

Microsoft MVP - 2010, 2011, 2012, 2013, 2014, 2015


#11 ap12345

ap12345
  • Topic Starter

  • Members
  • 16 posts
  • OFFLINE
  •  
  • Local time:10:42 PM

Posted 31 July 2011 - 09:59 AM

Thanks again here are the logs-
Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org

Database version: 7332

Windows 6.0.6001 Service Pack 1
Internet Explorer 8.0.6001.19088

7/30/2011 10:36:38 PM
mbam-log-2011-07-30 (22-36-38).txt

Scan type: Quick scan
Objects scanned: 231743
Time elapsed: 2 minute(s), 15 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


ESETSCAN

C:\Qoobox\Quarantine\[4]-Submit_2011-07-30_21.07.42.zip multiple threats
C:\Qoobox\Quarantine\C\Users\Anand\AppData\Roaming\Mozilla\Firefox\Profiles\kfld98jx.default\extensions\{08e85e0d-a0f4-43ef-ae73-f256b209be43}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan
C:\Qoobox\Quarantine\C\Users\Anand\AppData\Roaming\Mozilla\Firefox\Profiles\kfld98jx.default\extensions\{08e85e0d-a0f4-43ef-ae73-f256b209be43}\chrome\xulcache.jar.vir JS/Agent.NDJ trojan
C:\Qoobox\Quarantine\C\Users\Anand\AppData\Roaming\Mozilla\Firefox\Profiles\kfld98jx.default\extensions\{3bb1df99-ef96-416e-bb1c-78ff8f6ed85c}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan
C:\Qoobox\Quarantine\C\Users\Anand\AppData\Roaming\Mozilla\Firefox\Profiles\kfld98jx.default\extensions\{3bb1df99-ef96-416e-bb1c-78ff8f6ed85c}\chrome\xulcache.jar.vir JS/Agent.NDJ trojan
C:\Qoobox\Quarantine\C\Users\Anand\AppData\Roaming\Mozilla\Firefox\Profiles\kfld98jx.default\extensions\{a13a5f83-6939-4cca-8a1f-91004d660213}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan
C:\Qoobox\Quarantine\C\Users\Anand\AppData\Roaming\Mozilla\Firefox\Profiles\kfld98jx.default\extensions\{a13a5f83-6939-4cca-8a1f-91004d660213}\chrome\xulcache.jar.vir JS/Agent.NDJ trojan
C:\Qoobox\Quarantine\C\Users\Anurag\AppData\Roaming\Mozilla\Firefox\Profiles\x0tenxw3.default\extensions\{08e85e0d-a0f4-43ef-ae73-f256b209be43}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan
C:\Qoobox\Quarantine\C\Users\Anurag\AppData\Roaming\Mozilla\Firefox\Profiles\x0tenxw3.default\extensions\{08e85e0d-a0f4-43ef-ae73-f256b209be43}\chrome\xulcache.jar.vir JS/Agent.NDJ trojan
C:\Qoobox\Quarantine\C\Users\Anurag\AppData\Roaming\Mozilla\Firefox\Profiles\x0tenxw3.default\extensions\{3bb1df99-ef96-416e-bb1c-78ff8f6ed85c}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan
C:\Qoobox\Quarantine\C\Users\Anurag\AppData\Roaming\Mozilla\Firefox\Profiles\x0tenxw3.default\extensions\{3bb1df99-ef96-416e-bb1c-78ff8f6ed85c}\chrome\xulcache.jar.vir JS/Agent.NDJ trojan
C:\Qoobox\Quarantine\C\Users\Anurag\AppData\Roaming\Mozilla\Firefox\Profiles\x0tenxw3.default\extensions\{a13a5f83-6939-4cca-8a1f-91004d660213}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan
C:\Qoobox\Quarantine\C\Users\Anurag\AppData\Roaming\Mozilla\Firefox\Profiles\x0tenxw3.default\extensions\{a13a5f83-6939-4cca-8a1f-91004d660213}\chrome\xulcache.jar.vir JS/Agent.NDJ trojan
C:\Qoobox\Quarantine\C\Users\shridevi\AppData\Roaming\Mozilla\Firefox\Profiles\0soy7kfv.default\extensions\{08e85e0d-a0f4-43ef-ae73-f256b209be43}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan
C:\Qoobox\Quarantine\C\Users\shridevi\AppData\Roaming\Mozilla\Firefox\Profiles\0soy7kfv.default\extensions\{08e85e0d-a0f4-43ef-ae73-f256b209be43}\chrome\xulcache.jar.vir JS/Agent.NDJ trojan
C:\Qoobox\Quarantine\C\Users\shridevi\AppData\Roaming\Mozilla\Firefox\Profiles\0soy7kfv.default\extensions\{3bb1df99-ef96-416e-bb1c-78ff8f6ed85c}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan
C:\Qoobox\Quarantine\C\Users\shridevi\AppData\Roaming\Mozilla\Firefox\Profiles\0soy7kfv.default\extensions\{3bb1df99-ef96-416e-bb1c-78ff8f6ed85c}\chrome\xulcache.jar.vir JS/Agent.NDJ trojan
C:\Qoobox\Quarantine\C\Users\shridevi\AppData\Roaming\Mozilla\Firefox\Profiles\0soy7kfv.default\extensions\{a13a5f83-6939-4cca-8a1f-91004d660213}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan
C:\Qoobox\Quarantine\C\Users\shridevi\AppData\Roaming\Mozilla\Firefox\Profiles\0soy7kfv.default\extensions\{a13a5f83-6939-4cca-8a1f-91004d660213}\chrome\xulcache.jar.vir JS/Agent.NDJ trojan
C:\Qoobox\Quarantine\C\Users\srinic\AppData\Roaming\Mozilla\Firefox\Profiles\5htqmnem.default\extensions\{08e85e0d-a0f4-43ef-ae73-f256b209be43}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan
C:\Qoobox\Quarantine\C\Users\srinic\AppData\Roaming\Mozilla\Firefox\Profiles\5htqmnem.default\extensions\{08e85e0d-a0f4-43ef-ae73-f256b209be43}\chrome\xulcache.jar.vir JS/Agent.NDJ trojan
C:\Qoobox\Quarantine\C\Users\srinic\AppData\Roaming\Mozilla\Firefox\Profiles\5htqmnem.default\extensions\{3bb1df99-ef96-416e-bb1c-78ff8f6ed85c}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan
C:\Qoobox\Quarantine\C\Users\srinic\AppData\Roaming\Mozilla\Firefox\Profiles\5htqmnem.default\extensions\{3bb1df99-ef96-416e-bb1c-78ff8f6ed85c}\chrome\xulcache.jar.vir JS/Agent.NDJ trojan
C:\Qoobox\Quarantine\C\Users\srinic\AppData\Roaming\Mozilla\Firefox\Profiles\5htqmnem.default\extensions\{a13a5f83-6939-4cca-8a1f-91004d660213}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan
C:\Qoobox\Quarantine\C\Users\srinic\AppData\Roaming\Mozilla\Firefox\Profiles\5htqmnem.default\extensions\{a13a5f83-6939-4cca-8a1f-91004d660213}\chrome\xulcache.jar.vir JS/Agent.NDJ trojan
C:\Qoobox\Quarantine\C\Users\srinic\AppData\Roaming\Mozilla\Firefox\Profiles\ibaswvib.default\extensions\{08e85e0d-a0f4-43ef-ae73-f256b209be43}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan
C:\Qoobox\Quarantine\C\Users\srinic\AppData\Roaming\Mozilla\Firefox\Profiles\ibaswvib.default\extensions\{08e85e0d-a0f4-43ef-ae73-f256b209be43}\chrome\xulcache.jar.vir JS/Agent.NDJ trojan
C:\Qoobox\Quarantine\C\Users\srinic\AppData\Roaming\Mozilla\Firefox\Profiles\ibaswvib.default\extensions\{3bb1df99-ef96-416e-bb1c-78ff8f6ed85c}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan
C:\Qoobox\Quarantine\C\Users\srinic\AppData\Roaming\Mozilla\Firefox\Profiles\ibaswvib.default\extensions\{3bb1df99-ef96-416e-bb1c-78ff8f6ed85c}\chrome\xulcache.jar.vir JS/Agent.NDJ trojan
C:\Qoobox\Quarantine\C\Users\srinic\AppData\Roaming\Mozilla\Firefox\Profiles\ibaswvib.default\extensions\{a13a5f83-6939-4cca-8a1f-91004d660213}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan
C:\Qoobox\Quarantine\C\Users\srinic\AppData\Roaming\Mozilla\Firefox\Profiles\ibaswvib.default\extensions\{a13a5f83-6939-4cca-8a1f-91004d660213}\chrome\xulcache.jar.vir JS/Agent.NDJ trojan
C:\Qoobox\Quarantine\C\WINDOWS\SysWOW64\authfwcfg32.dll.vir Win32/BHO.NZK trojan
C:\Qoobox\Quarantine\C\WINDOWS\SysWOW64\PerfCenterCPL32.exe.vir Win32/TrojanDownloader.Tracur.D trojan
C:\Qoobox\Quarantine\C\WINDOWS\SysWOW64\yA.vir Win32/TrojanDownloader.Tracur.D trojan
C:\Users\srinic\AppData\Local\Google\Chrome\User Data\Default\Default\kclhngcbdegelpccmjgfkjmnloheodgp\contentscript.js Win32/TrojanDownloader.Tracur.F trojan
C:\Users\srinic\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\srinic\Local Settings\Application Data\Google\Chrome\User Data\Default\Default\jkgbagkpcfpflelglihmmnicakibhgcm\contentscript.js Win32/TrojanDownloader.Tracur.F trojan
C:\Users\srinic\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\srinic\Local Settings\Application Data\Google\Chrome\User Data\Default\Default\kfeldkdbhmbikmbnedichjoopdmnokme\contentscript.js Win32/TrojanDownloader.Tracur.F trojan
C:\Users\srinic\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29\20db519d-212be5d8 multiple threats
C:\Users\srinic\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29\61a815d-38aa8e33 a variant of Java/Exploit.CVE-2009-2843.B trojan
C:\Users\srinic\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32\4697cd20-1ec2b5de a variant of Java/Exploit.Agent.NAC trojan
C:\Users\srinic\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51\425fc2f3-41e3c1f5 Java/Exploit.CVE-2009-2843.B trojan
C:\Users\srinic\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52\640f9e74-71a13b99 multiple threats
C:\Users\srinic\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54\50cce1b6-5573c58c a variant of Java/TrojanDownloader.Agent.NBA trojan
F:\SRINIC-PC\Backup Set 2008-12-03 204321\Backup Files 2010-05-02 190007\Backup files 1.zip multiple threats
F:\SRINIC-PC\Backup Set 2008-12-03 204321\Backup Files 2010-08-08 190007\Backup files 1.zip multiple threats

#12 CatByte

CatByte

    bleepin' tiger


  • Malware Response Team
  • 14,664 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Canada
  • Local time:12:42 AM

Posted 31 July 2011 - 10:11 AM

Hi

Please do the following:

F:\SRINIC-PC\Backup Set 2008-12-03 204321\Backup Files 2010-05-02 190007\Backup files 1.zip multiple threats
F:\SRINIC-PC\Backup Set 2008-12-03 204321\Backup Files 2010-08-08 190007\Backup files 1.zip multiple threats

I would delete those back ups completely, then make a new set once I give you the "all clean"


  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

File::
C:\Users\srinic\AppData\Local\Google\Chrome\User Data\Default\Default\kclhngcbdegelpccmjgfkjmnloheodgp\contentscript.js 
C:\Users\srinic\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\srinic\Local Settings\Application Data\Google\Chrome\User Data\Default\Default\jkgbagkpcfpflelglihmmnicakibhgcm\contentscript.js 
C:\Users\srinic\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\srinic\Local Settings\Application Data\Google\Chrome\User Data\Default\Default\kfeldkdbhmbikmbnedichjoopdmnokme\contentscript.js 
C:\Users\srinic\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29\20db519d-212be5d8 
C:\Users\srinic\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29\61a815d-38aa8e33 
C:\Users\srinic\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32\4697cd20-1ec2b5de 
C:\Users\srinic\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51\425fc2f3-41e3c1f5 
C:\Users\srinic\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52\640f9e74-71a13b99 
C:\Users\srinic\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54\50cce1b6-5573c58c 

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As... Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save ...

Posted Image
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.



NEXT



Visit ADOBEand download the latest version of Acrobat Reader (version X)
Having the latest updates ensures there are no security vulnerabilities in your system.

NEXT

Posted Image
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
  • Download the latest version of Java Runtime Environment (JRE) 26 and save it to your desktop.
  • Scroll down to where it says JDK 6 Update 26 (JDK or JRE)
  • Click the Download JRE button to the right
  • Select the Windows platform from the dropdown menu.
  • Read the License Agreement and then check the box that says: "I agree to the Java SE Runtime Environment 6u26 with JavaFX 1 License Agreement". Click on Continue. The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add or Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u26-windows-i586.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH Checked
      Applications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.



NEXT


Please advise how your computer is running now and if there are any outstanding issues.

Microsoft MVP - 2010, 2011, 2012, 2013, 2014, 2015


#13 ap12345

ap12345
  • Topic Starter

  • Members
  • 16 posts
  • OFFLINE
  •  
  • Local time:10:42 PM

Posted 31 July 2011 - 12:17 PM

Thanks. I installed the java update, and the adobe reader update. Here's the log-

ComboFix 11-07-31.01 - Anurag 07/31/2011 10:59:47.3.2 - x64
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.6133.3844 [GMT -5:00]
Running from: c:\users\Anurag\Desktop\ComboFix.exe
Command switches used :: c:\users\Anurag\Desktop\CFScript.txt
AV: Norton 360 Premier Edition *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
FW: Norton 360 Premier Edition *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
SP: Norton 360 Premier Edition *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\users\srinic\AppData\Local\Google\Chrome\User Data\Default\Default\kclhngcbdegelpccmjgfkjmnloheodgp\contentscript.js"
"c:\users\srinic\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\srinic\Local Settings\Application Data\Google\Chrome\User Data\Default\Default\jkgbagkpcfpflelglihmmnicakibhgcm\contentscript.js"
"c:\users\srinic\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\srinic\Local Settings\Application Data\Google\Chrome\User Data\Default\Default\kfeldkdbhmbikmbnedichjoopdmnokme\contentscript.js"
"c:\users\srinic\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29\20db519d-212be5d8"
"c:\users\srinic\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29\61a815d-38aa8e33"
"c:\users\srinic\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32\4697cd20-1ec2b5de"
"c:\users\srinic\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51\425fc2f3-41e3c1f5"
"c:\users\srinic\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52\640f9e74-71a13b99"
"c:\users\srinic\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54\50cce1b6-5573c58c"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\srinic\AppData\Local\Google\Chrome\User Data\Default\Default\kclhngcbdegelpccmjgfkjmnloheodgp\contentscript.js
c:\users\srinic\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\srinic\Local Settings\Application Data\Google\Chrome\User Data\Default\Default\jkgbagkpcfpflelglihmmnicakibhgcm\contentscript.js
c:\users\srinic\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\srinic\Local Settings\Application Data\Google\Chrome\User Data\Default\Default\kfeldkdbhmbikmbnedichjoopdmnokme\contentscript.js
c:\users\srinic\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29\20db519d-212be5d8
c:\users\srinic\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29\61a815d-38aa8e33
c:\users\srinic\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32\4697cd20-1ec2b5de
c:\users\srinic\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51\425fc2f3-41e3c1f5
c:\users\srinic\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52\640f9e74-71a13b99
c:\users\srinic\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54\50cce1b6-5573c58c
.
.
((((((((((((((((((((((((( Files Created from 2011-06-28 to 2011-07-31 )))))))))))))))))))))))))))))))
.
.
2011-07-31 16:06 . 2011-07-31 16:06 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\temp
2011-07-31 16:06 . 2011-07-31 16:06 -------- d-----w- c:\users\srinic\AppData\Local\temp
2011-07-31 16:06 . 2011-07-31 16:06 -------- d-----w- c:\users\shridevi\AppData\Local\temp
2011-07-31 16:06 . 2011-07-31 16:06 -------- d-----w- c:\users\Mcx1\AppData\Local\temp
2011-07-31 16:06 . 2011-07-31 16:06 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-07-31 16:06 . 2011-07-31 16:06 -------- d-----w- c:\users\Anand\AppData\Local\temp
2011-07-31 03:41 . 2011-07-31 03:41 -------- d-----w- c:\program files (x86)\ESET
2011-07-31 03:24 . 2011-07-07 00:52 41272 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-07-30 23:36 . 2011-07-30 23:39 158067944 ----a-w- c:\program files (x86)\OpenOffice.exe
2011-07-30 23:36 . 2011-07-31 02:14 -------- d-----w- c:\program files (x86)\Object
2011-07-30 23:36 . 2011-07-30 23:39 -------- d-----w- c:\program files\OpenOffice
2011-07-30 23:36 . 2011-07-30 23:36 -------- d-----w- c:\program files (x86)\DealPly
2011-07-30 23:36 . 2011-07-30 23:36 428664 ----a-w- c:\program files (x86)\OpenOffice Downloader.exe
2011-07-29 22:19 . 2011-07-31 03:24 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-07-29 21:49 . 2011-07-29 22:02 -------- d-----w- c:\users\Anurag\AppData\Roaming\GetRightToGo
2011-07-23 15:31 . 2011-07-23 15:31 -------- d-----w- c:\program files\Realtek
2011-07-20 23:30 . 2011-07-20 23:30 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-07-12 22:58 . 2011-06-02 13:22 2762240 ----a-w- c:\windows\system32\win32k.sys
2011-07-12 22:58 . 2011-04-20 15:16 450048 ----a-w- c:\windows\system32\winsrv.dll
2011-07-12 22:58 . 2011-04-20 15:11 85504 ----a-w- c:\windows\system32\csrsrv.dll
2011-07-12 15:32 . 2011-07-12 15:32 -------- d-----w- c:\users\Anand\AppData\Local\Downloaded Installations
2011-07-12 15:27 . 2011-07-12 15:27 -------- d-----w- c:\users\Anurag\AppData\Local\Downloaded Installations
2011-07-07 23:04 . 2011-07-07 23:04 -------- d-----w- c:\users\Anurag\AppData\Roaming\Malwarebytes
2011-07-07 23:04 . 2011-07-07 23:04 -------- d-----w- c:\programdata\Malwarebytes
2011-07-07 23:04 . 2011-07-07 00:52 25912 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-07-06 15:18 . 2011-07-06 15:18 -------- d-----w- c:\users\Anurag\AppData\Roaming\Xilisoft Corporation
2011-07-06 15:18 . 2011-07-06 15:18 -------- d-----w- c:\program files (x86)\Xilisoft
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-30 21:52 . 2011-06-30 21:52 499712 ----a-w- c:\windows\SysWow64\msvcp71.dll
2011-06-30 21:52 . 2011-06-30 21:52 348160 ----a-w- c:\windows\SysWow64\msvcr71.dll
2011-06-26 18:28 . 2010-10-10 21:59 174200 ----a-w- c:\windows\system32\drivers\SYMEVENT64x86.SYS
2011-06-07 17:10 . 2011-06-24 13:53 8873296 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{BF1F51E4-DAEB-4DE8-AC04-1A26AF1E44C8}\mpengine.dll
2011-05-28 06:28 . 2011-06-15 20:46 1147904 ----a-w- c:\windows\system32\wininet.dll
2011-05-28 06:24 . 2011-06-15 20:46 56832 ----a-w- c:\windows\system32\licmgr10.dll
2011-05-28 06:23 . 2011-06-15 20:46 1538560 ----a-w- c:\windows\system32\inetcpl.cpl
2011-05-28 06:23 . 2011-06-15 20:46 132096 ----a-w- c:\windows\system32\iesysprep.dll
2011-05-28 06:23 . 2011-06-15 20:46 77312 ----a-w- c:\windows\system32\iesetup.dll
2011-05-28 06:08 . 2011-06-15 20:46 916480 ----a-w- c:\windows\SysWow64\wininet.dll
2011-05-28 06:04 . 2011-06-15 20:46 43520 ----a-w- c:\windows\SysWow64\licmgr10.dll
2011-05-28 06:04 . 2011-06-15 20:46 1469440 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2011-05-28 06:04 . 2011-06-15 20:46 71680 ----a-w- c:\windows\SysWow64\iesetup.dll
2011-05-28 06:04 . 2011-06-15 20:46 109056 ----a-w- c:\windows\SysWow64\iesysprep.dll
2011-05-28 05:33 . 2011-06-15 20:46 479232 ----a-w- c:\windows\system32\html.iec
2011-05-28 05:10 . 2011-06-15 20:46 385024 ----a-w- c:\windows\SysWow64\html.iec
2011-05-28 04:53 . 2011-06-15 20:46 162816 ----a-w- c:\windows\system32\ieUnatt.exe
2011-05-28 04:52 . 2011-06-15 20:46 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2011-05-28 04:33 . 2011-06-15 20:46 133632 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2011-05-28 04:31 . 2011-06-15 20:46 1638912 ----a-w- c:\windows\SysWow64\mshtml.tlb
2011-05-25 00:14 . 2010-12-03 22:08 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-05-02 16:35 . 2011-06-15 20:46 975360 ----a-w- c:\windows\system32\inetcomm.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-07-30_22.07.52 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-21 03:20 . 2011-07-31 15:27 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-01-21 03:20 . 2011-07-30 16:51 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-01-21 03:20 . 2011-07-30 16:51 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-01-21 03:20 . 2011-07-31 15:27 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-01-21 02:23 . 2011-07-31 15:21 63724 c:\windows\system32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 15:45 . 2011-07-31 15:21 77310 c:\windows\system32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2010-11-02 22:23 . 2011-07-31 15:21 10094 c:\windows\system32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2798213428-4013127124-2554937251-1001_UserData.bin
- 2010-10-10 19:46 . 2011-07-30 15:55 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-10-10 19:46 . 2011-07-31 11:10 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-10-10 19:46 . 2011-07-30 15:55 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-10-10 19:46 . 2011-07-31 11:10 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-10-10 19:46 . 2011-07-31 11:10 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-10-10 19:46 . 2011-07-30 15:55 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2011-01-07 06:28 . 2011-07-30 16:36 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-01-07 06:28 . 2011-07-31 15:48 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-01-07 06:28 . 2011-07-30 16:36 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2011-01-07 06:28 . 2011-07-31 15:48 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2011-01-07 06:28 . 2011-07-30 16:36 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-01-07 06:28 . 2011-07-31 15:48 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-10-15 04:43 . 2011-07-31 15:17 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-10-15 04:43 . 2011-07-30 15:51 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-10-15 04:43 . 2011-07-30 15:51 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-10-15 04:43 . 2011-07-31 15:17 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-07-31 08:47 . 2011-07-31 08:47 22016 c:\windows\Installer\124fb0c.msi
- 2011-07-30 15:50 . 2011-07-30 15:50 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-07-31 15:17 . 2011-07-31 15:17 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-07-30 15:50 . 2011-07-30 15:50 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-07-31 15:17 . 2011-07-31 15:17 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2008-01-21 03:20 . 2011-07-31 15:27 475136 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-01-21 03:20 . 2011-07-30 16:51 475136 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2006-11-02 12:46 . 2011-07-30 15:57 607168 c:\windows\system32\perfh009.dat
+ 2006-11-02 12:46 . 2011-07-31 15:23 607168 c:\windows\system32\perfh009.dat
- 2006-11-02 12:46 . 2011-07-30 15:57 104808 c:\windows\system32\perfc009.dat
+ 2006-11-02 12:46 . 2011-07-31 15:23 104808 c:\windows\system32\perfc009.dat
+ 2010-10-10 17:59 . 2011-07-31 15:14 249936 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2011-07-30 23:40 . 2011-07-30 23:40 219648 c:\windows\Installer\1ae7c8d.msi
+ 2006-11-02 12:33 . 2011-07-31 02:15 10743808 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
+ 2011-07-31 02:15 . 2011-07-31 02:15 10743808 c:\windows\ERDNT\subs\SCHEMA.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-12-09 18:51 3911776 ----a-w- c:\program files (x86)\ConduitEngine\ConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448}]
2011-06-16 13:56 78600 ----a-w- c:\program files (x86)\DealPly\DealPlyIE.dll
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
2010-12-09 18:51 3911776 ----a-w- c:\program files (x86)\uTorrentBar\tbuTor.dll
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2011-05-17 18:29 1490312 ----a-w- c:\program files (x86)\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files (x86)\Ask.com\GenericAskToolbar.dll" [2011-05-17 1490312]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files (x86)\uTorrentBar\tbuTor.dll" [2010-12-09 3911776]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files (x86)\ConduitEngine\ConduitEngine.dll" [2010-12-09 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1555968]
"HPADVISOR"="c:\program files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2008-07-03 972080]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-10-12 39408]
"WallpaperSS"="c:\program files (x86)\WallpaperSS\WallpaperSS.exe" [2010-11-16 454344]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 65536]
"KBD"="c:\hp\KBD\KbdStub.EXE" [2006-12-08 65536]
"HP Health Check Scheduler"="c:\program files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-06-02 75008]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"SunJavaUpdateSched"="c:\program files (x86)\Java\jre1.6.0_01\bin\jusched.exe" [2007-04-07 132760]
"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]
"AppleSyncNotifier"="c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-04-20 58656]
"KeePass 2 PreLoad"="c:\program files (x86)\KeePass Password Safe 2\KeePass.exe" [2011-01-02 1670656]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-04-27 421160]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5.5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360]
"ApnUpdater"="c:\program files (x86)\Ask.com\Updater\Updater.exe" [2011-05-17 395144]
"TkBellExe"="c:\program files (x86)\real\realplayer\Update\realsched.exe" [2011-06-30 273544]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="c:\windows\SysWOW64\Macromed\Flash\FlashUtil10p_ActiveX.exe" [2011-04-22 235168]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Lexmark X125 Settings Utility.lnk - c:\program files (x86)\Lexmark X125\LEX125SU.exe [2010-10-14 1990656]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-12 136176]
R2 swprv32;Microsoft Software Shadow Copy Provider ;c:\windows\system32\PerfCenterCPL32.exe [x]
R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-12 136176]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\System32\Drivers\N360x64\0308000.029\SYMNDISV.SYS [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 USBTINSP;TI-Nspire™ Handheld Device Driver;c:\windows\system32\DRIVERS\tinspusb.sys [x]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 1020768]
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360x64\0501000.01D\SYMDS64.SYS [x]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360x64\0501000.01D\SYMEFA64.SYS [x]
S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\BASHDefs\20110723.001\BHDrvx64.sys [2011-07-23 1151096]
S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\IPSDefs\20110729.030\IDSvia64.sys [2011-07-07 488056]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360x64\0501000.01D\Ironx64.SYS [x]
S1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\system32\drivers\N360x64\0501000.01D\SYMTDIV.SYS [x]
S2 MediaMall Server;MediaMall Server;c:\program files (x86)\MediaMall\MediaMallServer.exe [2011-07-30 4411248]
S2 N360;Norton 360;c:\program files (x86)\Norton 360\Norton 360\Engine\5.1.0.29\ccSvcHst.exe [2011-04-17 130008]
S2 TeamViewer6;TeamViewer 6;c:\program files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-04-01 2271608]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2011-07-28 136824]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2011-07-31 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-12 18:27]
.
2011-07-31 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-12 18:27]
.
2011-07-28 c:\windows\Tasks\Norton Security Scan for Anurag.job
- c:\progra~2\NORTON~3\NORTON~1\Engine\311~1.6\Nss.exe [2011-06-27 16:39]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-06-11 178712]
"WPCUMI"="c:\windows\system32\WpcUmi.exe" [2006-11-02 182784]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2010-07-21 2306448]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-15 499608]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-02-27 154648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-02-27 227352]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-02-27 202264]
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.startnow.com/?src=startpage&provider=Bing&provider_code=Z059&partner_id=308&product_id=435&affiliate_id=&channel=dptoby&toolbar_id=200&toolbar_version=2.0&install_country=US&install_date=20110730&user_guid=9D1344F33E564752AF89F65200C09414&machine_id=b1d47d9ab7ab39400bb5d669d71e0c22&browser=IE&os=win&os_version=6.0-x64-SP1
uLocal Page = c:\windows\system32\blank.htm
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=84&bd=Pavilion&pf=cndt
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_70C5B381380DB17F.dll/cmsidewiki.html
LSP: c:\windows\system32\wpclsp.dll
TCP: DhcpNameServer = 192.168.0.1
CLSID: {603d3801-bd81-11d0-a3a5-00c04fd706ec} - %SystemRoot%\SysWow64\browseui.dll
FF - ProfilePath - c:\users\Anurag\AppData\Roaming\Mozilla\Firefox\Profiles\x0tenxw3.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/firefox
FF - prefs.js: keyword.URL - hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=MTV&o=1590&locale=en_US&apn_uid=a6fa0180-0b0e-41e2-9e36-a00c79da0f4a&apn_ptnrs=^AAH&apn_sauid=A8EC3CE4-9326-4C78-A9DD-C54A9845863A&apn_dtid=^YYYYYY^YY^US&q=
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - (no file)
WebBrowser-{30F9B915-B755-4826-820B-08FBA6BD249D} - (no file)
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\N360]
"ImagePath"="\"c:\program files (x86)\Norton 360\Norton 360\Engine\5.1.0.29\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files (x86)\Norton 360\Norton 360\Engine\5.1.0.29\diMaster.dll\" /prefetch:1"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@=""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@="FlashBroker"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
Completion time: 2011-07-31 11:08:46
ComboFix-quarantined-files.txt 2011-07-31 16:08
ComboFix2.txt 2011-07-31 02:26
ComboFix3.txt 2011-07-30 22:09
.
Pre-Run: 711,224,979,456 bytes free
Post-Run: 711,193,325,568 bytes free
.
- - End Of File - - 39875FE69B4A490FFC2340BC187A5097

#14 CatByte

CatByte

    bleepin' tiger


  • Malware Response Team
  • 14,664 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Canada
  • Local time:12:42 AM

Posted 31 July 2011 - 01:09 PM

How is the computer running now? Are there any outstanding issues?

Microsoft MVP - 2010, 2011, 2012, 2013, 2014, 2015


#15 ap12345

ap12345
  • Topic Starter

  • Members
  • 16 posts
  • OFFLINE
  •  
  • Local time:10:42 PM

Posted 31 July 2011 - 03:16 PM

So far there hasn't been any redirection, thanks for all your help!




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users