WiredWX Christian Hobby Weather Tools
Would you like to react to this message? Create an account in a few clicks or log in to continue.

WiredWX Christian Hobby Weather ToolsLog in

 


Admin Virus

2 posters

descriptionAdmin Virus - Page 1 EmptyRe: Admin Virus

more_horiz
RogueKiller V8.0.3 [09/13/2012] by Tigzy
mail: tigzyRKgmailcom
Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
Blog: http://tigzyrk.blogspot.com

Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User : owner [Admin rights]
Mode : Shortcuts HJfix -- Date : 09/18/2012 09:15:03

¤¤¤ Bad processes : 1 ¤¤¤
[SUSP PATH] winxues.exe -- C:\Documents and Settings\owner\Local Settings\temp\winxues.exe -> KILLED [TermProc]

¤¤¤ Driver : [LOADED] ¤¤¤

¤¤¤ File attributes restored: ¤¤¤
Desktop: Success 0 / Fail 0
Quick launch: Success 0 / Fail 0
Programs: Success 4 / Fail 0
Start menu: Success 0 / Fail 0
User folder: Success 61 / Fail 0
My documents: Success 6 / Fail 6
My favorites: Success 0 / Fail 0
My pictures: Success 0 / Fail 0
My music: Success 0 / Fail 0
My videos: Success 0 / Fail 0
Local drives: Success 99 / Fail 0
Backup: [NOT FOUND]

Drives:
[C:] \Device\HarddiskVolume1 -- 0x3 --> Restored
[D:] \Device\CdRom0 -- 0x5 --> Skipped

¤¤¤ Infection : ¤¤¤

Finished : << RKreport[3].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt

descriptionAdmin Virus - Page 1 EmptyRe: Admin Virus

more_horiz
Any more issues?

We need to know any other issues that are plaguing your computer. Kindly give a summary so we know how to continue from here.

Many of the things to note for us would be:

  • Slow computer
  • Error messages
  • Fake antivirus alerts or the icon in the system tray
  • svchost.exe running at 100%
  • System crashes or blue screen of death

descriptionAdmin Virus - Page 1 EmptyRe: Admin Virus

more_horiz
Still the same two problems as before. Redirection to fun moods search engine when searching in the URL bar of Chrome and unable to access task manager. With that being said the computer runs considerably faster than before and is completely usable. These last two problems are just a tad irksome if anything.

descriptionAdmin Virus - Page 1 EmptyRe: Admin Virus

more_horiz
Kaspersky Virus Removal Tool

The Kaspersky Virus Removal Tool is a scan-and-remove solution from Kaspersky that searches out the most common malware and attempts to remove it from your computer.

Please download the Kaspersky Virus Removal Tool from Kaspersky's Official Link and save it to your Desktop.

  • Double-click the Setup file to install it on your computer.
  • Once it has installed, review and accept the agreement and press the Start button.
  • You will presented with the main interface, but don't scan yet, click the options tab (gear icon):
    Admin Virus - Page 1 Image1nz
  • On the Scan Scope tab, make sure to checkmark all the options, except for the CD/DVD drive:
    Admin Virus - Page 1 Image2pmb
  • On the Security Level tab, make sure to move the slider up denoting "Current Security Level: High":
    Admin Virus - Page 1 Image3vd
  • Now, go back to the Automatic Scan tab, and choose "Start Scanning". It may take several hours to complete. Please allow it to do so.
  • Once done scanning, choose the Report tab (page icon), select Detected Threats tab on left, and choose Disinfect All:
    Admin Virus - Page 1 Image5mf
  • Then, choose Save. Also, in the Automatic Report tab, select Save:
    Admin Virus - Page 1 Image4vy
  • Please post the reports in your next reply.
  • Once you exit, the tool should uninstall automatically.

descriptionAdmin Virus - Page 1 EmptyRe: Admin Virus

more_horiz
Could not access the kaspersky website from link or through a Google search.

descriptionAdmin Virus - Page 1 EmptyRe: Admin Virus

more_horiz
I tried downloading the kaspersky software from around seven third party sites to no avail. The browser continues to work and load like the download window is going to pop up, but nothing ever happens. It eventually times out.

descriptionAdmin Virus - Page 1 EmptyRe: Admin Virus

more_horiz
Let's try the following...If you cannot complete TDSSKiller, move on to aswMBR...

Please download and run TDSSKiller to your desktop as outlined below:

Doubleclick on TDSSKiller.exe to run the application, then click on Change parameters.

For Windows XP, double-click to start.
For Vista or Windows 7, do a right-click on the program, select Run as Administrator to start, & when prompted Allow to run.


Admin Virus - Page 1 Tdss_1

-------------------------

Check the boxes beside Verify Driver Digital Signature and Detect TDLFS file system, then click OK.

Admin Virus - Page 1 Tdss_2

------------------------

Click the Start Scan button.

Admin Virus - Page 1 Tdss_3

-----------------------

If a suspicious object is detected, the default action will be Skip, click on Continue
If you get the warning about a file UnsignedFile.Multi.Generic or LockedFile.Multi.Generic please choose
Skip and click on Continue


Admin Virus - Page 1 Tdss_4

----------------------

If malicious objects are found, they will show in the Scan results and offer three (3) options.

Ensure Cure is selected, then click Continue => Reboot now to finish the cleaning process.
Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.


Admin Virus - Page 1 Tdss_5


--------------------

A report will be created in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste its contents on your next reply.
Sometimes these logs can be very large, in that case please attach it or zip it up and attach it.

-------------------

Here's a summary of what to do if you would like to print it out:

If a suspicious object is detected, the default action will be Skip, click on Continue
If you get the warning about a file UnsignedFile.Multi.Generic or LockedFile.Multi.Generic please choose
Skip and click on Continue

If malicious objects are found, they will show in the Scan results and offer three (3) options.

Ensure Cure is selected, then click Continue => Reboot now to finish the cleaning process.
Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.


avast! aswMBR

Please download aswMBR from here


  • Save aswMBR.exe to your Desktop
  • Double click aswMBR.exe to run it
  • Click the Scan button to start the scan as illustrated below


Admin Virus - Page 1 AswMBR_Scan

Note: Do not take action against any **Rootkit** entries until I have reviewed the log. Often there are false positives


  • Once the scan finishes click Save log to save the log to your Desktop
    Admin Virus - Page 1 AswMBR_SaveLog

  • Copy and paste the contents of aswMBR.txt back here for review

descriptionAdmin Virus - Page 1 EmptyRe: Admin Virus

more_horiz
TDSSKiller did not load.


aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-09-22 19:15:43
-----------------------------
19:15:43.343 OS Version: Windows 5.1.2600 Service Pack 3
19:15:43.343 Number of processors: 2 586 0x304
19:15:43.343 ComputerName: COMPUTER_1 UserName: owner
19:15:43.734 Initialize success
19:15:56.531 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-e
19:15:56.531 Disk 0 Vendor: ST340014AS 3.20 Size: 38166MB BusType: 3
19:15:56.562 Disk 0 MBR read successfully
19:15:56.562 Disk 0 MBR scan
19:15:56.562 Disk 0 Windows XP default MBR code
19:15:56.562 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 38154 MB offset 63
19:15:56.562 Disk 0 scanning sectors +78140160
19:15:56.640 Disk 0 scanning C:\WINDOWS\system32\drivers
19:16:02.281 Service scanning
19:16:17.875 Modules scanning
19:16:26.296 Disk 0 trace - called modules:
19:16:26.296 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
19:16:26.312 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86f4eab8]
19:16:26.312 3 CLASSPNP.SYS[f7556fd7] -> nt!IofCallDriver -> \Device\00000064[0x86f3e3b8]
19:16:26.312 5 ACPI.sys[f74cd620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-e[0x86f4fd98]
19:16:26.312 Scan finished successfully
19:16:52.546 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\owner\Desktop\Fix This Computer\MBR.dat"
19:16:52.546 The log file has been saved successfully to "C:\Documents and Settings\owner\Desktop\Fix This Computer\aswMBR.txt"

descriptionAdmin Virus - Page 1 EmptyRe: Admin Virus

more_horiz
Please reboot to Safe Mode (tap the F8 key before Windows begins to load and select the Safe Mode option from the menu). Then, try again please.

descriptionAdmin Virus - Page 1 EmptyRe: Admin Virus

more_horiz
Booting into safe mode was unsuccessful. It said windows did not load properly and suggested I start windows normally with the last known working configuration.

descriptionAdmin Virus - Page 1 EmptyRe: Admin Virus

more_horiz
Scan for malware

Admin Virus - Page 1 Bf_new Please download Malwarebytes Anti-Malware from HERE.


Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. If you are prompted to restart, please allow it to restart your computer. Failure to do this, will cause the infection to still be active on the computer.
  • Please save the log to a location you will remember.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • The log can also be found at C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Copy and paste the entire report in your next reply.



Please download OTL to your Desktop. (If you already have it downloaded, then just follow the instructions below).

  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Under the Custom Scan box paste this in

    msconfig
    safebootminimal
    activex
    drivers32
    netsvcs
    CreateRestorePoint
    %AppData%\Roaming\Mozilla\Firefox\Profiles\*.default\extensions\ /s /md5
    %AppData%\Local\
    %systemroot%\system32\sysprep
    *.xpi /md5
    %systemroot%\Downloaded Program Files\
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
    hklm\software\clients\startmenuinternet|command /rs
    hklm\software\clients\startmenuinternet|command /64 /rs
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\system32\drivers\*.sys /90
    %systemroot%\System32\config\*.sav
    %SYSTEMDRIVE%\*.exe /md5
    "%WinDir%\$NtUninstallKB*$." /30
    %systemdrive%\Program Files\Common Files\ComObjects\*.* /s
    %systemroot%\*. /mp /s
    %systemroot%\*. /rp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\Installer\ /s
    %systemroot%\system32\Cache\ /s
    %systemroot%\system32\config\systemprofile\Application Data /s
    %PROGRAMFILES%\*.
    %appdata%\*.*
    /md5start
    volsnap.sys
    services.exe
    userinit.exe
    afd.sys
    tcpip.sys
    netbt.sys
    ipsec.sys
    dnsrslvr.dll
    ipnathlp.dll
    netman.dll
    WMIsvc.dll
    srsvc.dll
    sr.sys
    wscsvc.dll
    wuauserv.dll
    qmgr.dll
    es.dll
    cryptsvc.dll
    svchost.exe
    rpcss.dll
    tdx.sys
    wininit.exe
    winlogon.exe
    atapi.sys
    explorer.exe
    /md5stop

  • Click the Run Scanbutton. Do not change any settings unless otherwise told to do so. The scan wont take long.

    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) and paste (Edit->Paste) the contents of these files, one at a time


Note: in the event that OTL fails to run, please use alternate download links to try again:

http://oldtimer.geekstogo.com/OTL.com
http://oldtimer.geekstogo.com/OTL.scr

descriptionAdmin Virus - Page 1 EmptyRe: Admin Virus

more_horiz
Malwarebytes Anti-Malware 1.65.0.1400
www.malwarebytes.org

Database version: v2012.09.28.07

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
owner :: COMPUTER_1 [administrator]

10/1/2012 2:25:43 PM
mbam-log-2012-10-01 (14-25-43).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 185415
Time elapsed: 5 minute(s), 50 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{625F420E-A4A9-4B40-BC23-716C1C43893A} (Adware.Adurr) -> Quarantined and deleted successfully.

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 5
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System|DisableTaskMgr (PUM.Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System|DisableRegistryTools (PUM.Hijack.Regedit) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully.
HKLM\SOFTWARE\Microsoft\Security Center|AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully.
HKLM\SOFTWARE\Microsoft\Security Center|FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully.
HKLM\SOFTWARE\Microsoft\Security Center|UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully.

Folders Detected: 0
(No malicious items detected)

Files Detected: 1
C:\Documents and Settings\owner\My Documents\Downloads\FreeFileViewer2011Setup.exe (PUP.BundleOffers.IIQ) -> Quarantined and deleted successfully.

(end)

descriptionAdmin Virus - Page 1 EmptyRe: Admin Virus

more_horiz
An error occurred during the OTC scan. "Access violation at address CCC0460. Read of address CCCC0460." The program then froze and no reports were produced.

descriptionAdmin Virus - Page 1 EmptyRe: Admin Virus

more_horiz
Please download the latest version of Kaspersky GetSystemInfo (GSI) from Kaspersky and save it to your Desktop.

Note: please close all other applications running on your system.

Double click GetSystemInfo.exe to open it. It will display an agreement. Click on I Agree to continue.

Click the Settings button.Admin Virus - Page 1 2hd457o

Admin Virus - Page 1 Settingsslider

Set the slider to Maximum.

Admin Virus - Page 1 Driversports

IMPORTANT! Then, click Customize - choose Driver / Ports tab and uncheck Scan Ports.


Admin Virus - Page 1 Generaltab

On the General tab, make sure all of the boxes are checked.


Admin Virus - Page 1 Misce

On the Misc tab, make sure all the checkboxes are checked.

Then, click OK on the windows that you launched.


Admin Virus - Page 1 2ekm73m
Click Create Report to run it.

Admin Virus - Page 1 Beginscanning
It will begin scanning.

It will create a zip folder called GetSystemInfo_XXXXXXXXXXXXXX.zip on your Desktop.

It should automatically upload it to http://www.getsysteminfo.com. If it does not, then please submit it manually by going to the site and doing the upload process.

It will redirect to a page, where it will provide a sharing URL for specialists. Copy and paste the url of the GSI Parser report in your next reply.

descriptionAdmin Virus - Page 1 EmptyRe: Admin Virus

more_horiz
http://www.getsysteminfo.com/read.php?file=01c09ea4395212df93120289072a4c95

descriptionAdmin Virus - Page 1 EmptyRe: Admin Virus

more_horiz
Purge old temporary files

Download CCleaner Slim and save it to your Desktop - [URL='http://www.majorgeeks.com/CCleaner_Slim_No_Toolbar_d4191.html']Alternate download link[/URL]

When the file has been saved, go to your Desktop and double-click on ccsetupxxx_slim.exe
Follow the prompts to install the program.

* Double-click the CCleaner shortcut on the desktop to start the program.
* Click on the Options block on the left, then choose Cookies.
* Under Cookies to Delete, highlight any cookies you would like to retain permanently
* Click the right arrow > to move them to the Cookies to Keep window.
* Go into Options > Advanced & uncheck Only delete files in Windows Temp folders older than 48 hours
* Click Cleaner on the left then Run Cleaner on the right to run the program.
* Important: Make sure that ALL browser windows are closed before selecting Run Cleaner

Caution: Only use the Registry feature if you are very familiar with the registry.
Always back up your registry before making any changes. Exit CCleaner after it has completed it's process.

Any more issues?

We need to know any other issues that are plaguing your computer. Kindly give a summary so we know how to continue from here.

Many of the things to note for us would be:


  • Slow computer
  • Error messages
  • Fake antivirus alerts or the icon in the system tray
  • svchost.exe running at 100%
  • System crashes or blue screen of death

descriptionAdmin Virus - Page 1 EmptyRe: Admin Virus

more_horiz
Should I uncheck programs that I do not want deleted? For example I have Office loaded on the machine but no original discs or product keys to load it back on the machine if it gets deleted permanently.

descriptionAdmin Virus - Page 1 EmptyRe: Admin Virus

more_horiz
If you're in the Cleaner tab, then no programs will be deleted whatsoever. CCleaner does not delete programs without your permission. However, it chooses to clean up temporary files saved by Microsoft Office, among other products, to help boost the speed of your computer and programs overall. Smile...

Only in the Tools tab do you have the ability to remove programs, and you have to be the one to activate it.

descriptionAdmin Virus - Page 1 EmptyRe: Admin Virus

more_horiz
Alright, thank you for clearing that up for me. However, even after running CCleaner, both problems still exist.

descriptionAdmin Virus - Page 1 EmptyRe: Admin Virus

more_horiz
Please try the Kaspersky Virus Removal Tool noted here: http://www.GeekPolice.net/t29097p15-admin-virus#202393

descriptionAdmin Virus - Page 1 EmptyRe: Admin Virus

more_horiz
Sorry, but the same thing still happens. That page never loads, no download ever pops up, ect. It eventually times out. Even when I tried to download it from third party sites like softpedia it just times out.

descriptionAdmin Virus - Page 1 EmptyRe: Admin Virus

more_horiz
Run Dr. Web CureIt, and post log please: http://www.freedrweb.com/cureit/

descriptionAdmin Virus - Page 1 EmptyRe: Admin Virus

more_horiz
Page times out upon clicking the download link. Some good news: no more redirection when searching in the omnibox. Just changed the default in settings on Chrome and so far so good.

descriptionAdmin Virus - Page 1 EmptyRe: Admin Virus

more_horiz
What other user accounts do you have? Can you use a different account temporarily to try to get it to download?

descriptionAdmin Virus - Page 1 EmptyRe: Admin Virus

more_horiz
Created a new account with admin privileges, but it still times out when clicking the free download button on Dr.Web site.

descriptionAdmin Virus - Page 1 EmptyRe: Admin Virus

more_horiz
Let's do some final scans...


Delete old copy of ComboFix,

download and run new copy, http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Post new log.

descriptionAdmin Virus - Page 1 EmptyRe: Admin Virus

more_horiz
ComboFix 12-10-04.02 - owner 10/06/2012 14:44:28.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1015.494 [GMT -4:00]
Running from: c:\documents and settings\owner\My Documents\Downloads\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_ABP470N5
-------\Service_abp470n5
.
.
((((((((((((((((((((((((( Files Created from 2012-09-06 to 2012-10-06 )))))))))))))))))))))))))))))))
.
.
2012-10-05 18:06 . 2012-10-05 18:06 -------- d-----w- c:\documents and settings\J
2012-10-02 23:32 . 2012-10-02 23:32 -------- d-----w- c:\program files\CCleaner
2012-09-16 14:52 . 2012-09-16 14:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2012-09-06 19:06 . 2012-09-06 19:06 -------- d-----w- c:\program files\Common Files\Skype
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-07 21:04 . 2012-02-12 16:42 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-08-28 15:14 . 2008-04-14 04:42 916992 ----a-w- c:\windows\system32\wininet.dll
2012-08-28 15:14 . 2008-04-14 04:41 43520 ------w- c:\windows\system32\licmgr10.dll
2012-08-28 15:14 . 2008-04-14 04:42 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-08-28 12:07 . 2008-04-13 23:07 385024 ------w- c:\windows\system32\html.iec
2004-10-01 19:00 . 2011-10-18 02:56 110592 ----a-w- c:\program files\Uninstall_CDS.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2012-07-13 17420464]
"PowerBar"="c:\program files\CyberLink DVD Solution\Multimedia Launcher\PowerBar.exe" [2004-04-21 159744]
"chromium"="c:\documents and settings\owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe" [2012-09-25 1239064]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"RemoteControl"="c:\program files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2003-12-08 110592]
"InCD"="c:\program files\Ahead\InCD\InCD.exe" [2005-07-08 1397760]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 225280]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-10-08 229376]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-10-08 196608]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-03-06 421736]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"= 1 (0x1)
"DisableRegistryTools"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\WINDOWS\\system32\\igfxtray.exe"=
"c:\\WINDOWS\\system32\\NeroCheck.exe"=
"c:\\Documents and Settings\\owner\\Local Settings\\Application Data\\Google\\Update\\GoogleUpdate.exe"=
"c:\\WINDOWS\\system32\\hkcmd.exe"=
"c:\\Program Files\\CyberLink DVD Solution\\PowerDVD\\PDVDServ.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\GrooveMonitor.exe"=
"c:\\WINDOWS\\system32\\SNDVOL32.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\WINWORD.EXE"=
"c:\\Documents and Settings\\owner\\Local Settings\\Application Data\\Google\\Chrome\\Application\\chrome.exe"=
"c:\\WINDOWS\\system32\\wuauclt.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\iTunes\\iTunesHelper.exe"=
"c:\\Program Files\\Adobe\\Acrobat 5.0\\Reader\\AcroRd32.exe"=
"c:\\WINDOWS\\system32\\calc.exe"=
"c:\\PROGRA~1\\MICROS~2\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Apple Software Update\\SoftwareUpdate.exe"=
"c:\\Program Files\\AVG\\AVG PC Tuneup\\BoostSpeed.exe"=
"c:\\Program Files\\CyberLink DVD Solution\\Multimedia Launcher\\PowerBar.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\WINDOWS\\system32\\netsh.exe"=
"c:\\Documents and Settings\\owner\\Desktop\\Fix This Computer\\adwcleaner.exe"=
"c:\\Program Files\\Common Files\\Apple\\Mobile Device Support\\SyncServer.exe"=
"c:\\DOCUME~1\\owner\\LOCALS~1\\Temp\\winkpgr.exe"=
"c:\\DOCUME~1\\owner\\LOCALS~1\\Temp\\winwuvm.exe"=
.
R3 RTL8192su;%RTL8192su.DeviceDesc.DispName%;c:\windows\system32\drivers\RTL8192su.sys [7/8/2010 3:09 PM 606056]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [7/13/2012 2:14 PM 160944]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - ABP470N5
.
Contents of the 'Scheduled Tasks' folder
.
2012-10-02 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 21:57]
.
2012-10-06 c:\windows\Tasks\AVG PC Tuneup Integrator Start On owner Logon.job
- c:\program files\AVG\AVG PC Tuneup\BoostSpeed.exe [2012-02-28 22:20]
.
2012-10-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1715567821-1004336348-1606980848-1003Core.job
- c:\documents and settings\owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-11-29 20:17]
.
2012-10-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1715567821-1004336348-1606980848-1003UA.job
- c:\documents and settings\owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-11-29 20:17]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.254
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-10-06 14:53
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'explorer.exe'(2832)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Ahead\InCD\InCDsrv.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\WgaTray.exe
c:\program files\iPod\bin\iPodService.exe
c:\docume~1\owner\LOCALS~1\Temp\winkpgr.exe
c:\docume~1\owner\LOCALS~1\Temp\winwuvm.exe
.
**************************************************************************
.
Completion time: 2012-10-06 14:59:37 - machine was rebooted
ComboFix-quarantined-files.txt 2012-10-06 18:59
ComboFix2.txt 2012-09-16 00:47
ComboFix3.txt 2012-09-15 20:23
.
Pre-Run: 25,525,874,688 bytes free
Post-Run: 25,397,964,800 bytes free
.
- - End Of File - - 07B25C115F8CD68CC3208FDE17C23560

descriptionAdmin Virus - Page 1 EmptyRe: Admin Virus

more_horiz
Purge old temporary files

Download CCleaner Slim and save it to your Desktop - [URL='http://www.majorgeeks.com/CCleaner_Slim_No_Toolbar_d4191.html']Alternate download link[/URL]

When the file has been saved, go to your Desktop and double-click on ccsetupxxx_slim.exe
Follow the prompts to install the program.

* Double-click the CCleaner shortcut on the desktop to start the program.
* Click on the Options block on the left, then choose Cookies.
* Under Cookies to Delete, highlight any cookies you would like to retain permanently
* Click the right arrow > to move them to the Cookies to Keep window.
* Go into Options > Advanced & uncheck Only delete files in Windows Temp folders older than 48 hours
* Click Cleaner on the left then Run Cleaner on the right to run the program.
* Important: Make sure that ALL browser windows are closed before selecting Run Cleaner

Caution: Only use the Registry feature if you are very familiar with the registry.
Always back up your registry before making any changes. Exit CCleaner after it has completed it's process.

Security Check

Please download Security Check by screen317 from SpywareInfoforum.org or [URL='http://screen317.changelog.fr/SecurityCheck.exe']Changelog.fr[/URL].

  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.


Let me know of any more issues after CCleaner being run...

descriptionAdmin Virus - Page 1 EmptyRe: Admin Virus

more_horiz
Results of screen317's Security Check version 0.99.51
Windows XP Service Pack 3 x86 (UAC is disabled!)
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Disabled!
Please wait while WMIC is being installed.
WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware version 1.65.0.1400
AVG PC Tuneup
CCleaner
````````Process Check: objlist.exe by Laurent````````
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:: 16% Defragment your hard drive soon! (Do NOT defrag if SSD!)
````````````````````End of Log``````````````````````

descriptionAdmin Virus - Page 1 EmptyRe: Admin Virus

more_horiz
Still says that the task manager has been disabled by your administrator.

descriptionAdmin Virus - Page 1 EmptyRe: Admin Virus

more_horiz
Please open OTL, copy the content below in the box and paste it to the Custom Scans/Fixes box in OTL:

:OTL
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1

:commands
[emptytemp]
[reboot]


Then, hit Run Fix. When the fix log launches, please post that in your next reply.


Then, let me know of anymore issues.

descriptionAdmin Virus - Page 1 EmptyRe: Admin Virus

more_horiz
Stuck on windows is shutting down for about 20 minutes. Should I force it?

descriptionAdmin Virus - Page 1 EmptyRe: Admin Virus

more_horiz
All processes killed
========== OTL ==========
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableRegistryTools deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableTaskMgr deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: J
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Google Chrome cache emptied: 8495472 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: owner
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 2130322 bytes
->FireFox cache emptied: 49099362 bytes
->Google Chrome cache emptied: 6255848 bytes
->Flash cache emptied: 723 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 2577 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 439 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 63.00 mb


OTL by OldTimer - Version 3.2.70.0 log created on 10082012_134740

Files\Folders moved on Reboot...

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

descriptionAdmin Virus - Page 1 EmptyRe: Admin Virus

more_horiz
Still can't access task manager.

descriptionAdmin Virus - Page 1 EmptyRe: Admin Virus

more_horiz
Open OTL once again, press Quick Scan, and post log please. I'd like to take one more close look...

descriptionAdmin Virus - Page 1 EmptyRe: Admin Virus

more_horiz
OTL logfile created on: 10/9/2012 2:11:05 PM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\owner\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1015.43 Mb Total Physical Memory | 500.49 Mb Available Physical Memory | 49.29% Memory free
1.64 Gb Paging File | 1.17 Gb Available in Paging File | 71.09% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.26 Gb Total Space | 23.37 Gb Free Space | 62.73% Space Free | Partition Type: NTFS
Drive D: | 55.22 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: COMPUTER_1 | User Name: owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/10/09 14:10:30 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\owner\Desktop\OTL.exe
PRC - [2012/10/09 14:07:39 | 000,031,402 | ---- | M] () -- C:\Documents and Settings\owner\Local Settings\temp\mehuct.exe
PRC - [2012/10/09 14:07:35 | 000,012,970 | ---- | M] () -- C:\Documents and Settings\owner\Local Settings\temp\winghoeqs.exe
PRC - [2012/09/25 05:43:01 | 001,239,064 | ---- | M] (Google Inc.) -- C:\Documents and Settings\owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
PRC - [2011/11/03 18:20:58 | 000,803,144 | ---- | M] (AVG) -- C:\Program Files\AVG\AVG PC Tuneup\BoostSpeed.exe
PRC - [2009/03/10 23:18:14 | 000,934,792 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\WgaTray.exe
PRC - [2008/04/14 00:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2005/07/08 17:24:46 | 000,871,424 | ---- | M] (Nero AG) -- C:\Program Files\Ahead\InCD\InCDsrv.exe
PRC - [2005/07/08 10:25:10 | 001,397,760 | ---- | M] (Nero AG) -- C:\Program Files\Ahead\InCD\InCD.exe
PRC - [2003/12/08 17:35:14 | 000,110,592 | ---- | M] (Cyberlink Corp.) -- C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe


========== Modules (No Company Name) ==========

MOD - [2012/10/09 14:07:39 | 000,031,402 | ---- | M] () -- C:\Documents and Settings\owner\Local Settings\temp\mehuct.exe
MOD - [2012/10/09 14:07:35 | 000,012,970 | ---- | M] () -- C:\Documents and Settings\owner\Local Settings\temp\winghoeqs.exe
MOD - [2012/09/25 05:42:58 | 000,460,312 | ---- | M] () -- C:\Documents and Settings\owner\Local Settings\Application Data\Google\Chrome\Application\22.0.1229.79\ppgooglenaclpluginchrome.dll
MOD - [2012/09/25 05:42:57 | 012,278,808 | ---- | M] () -- C:\Documents and Settings\owner\Local Settings\Application Data\Google\Chrome\Application\22.0.1229.79\PepperFlash\pepflashplayer.dll
MOD - [2012/09/25 05:42:55 | 004,005,912 | ---- | M] () -- C:\Documents and Settings\owner\Local Settings\Application Data\Google\Chrome\Application\22.0.1229.79\pdf.dll
MOD - [2012/09/25 05:41:27 | 000,156,712 | ---- | M] () -- C:\Documents and Settings\owner\Local Settings\Application Data\Google\Chrome\Application\22.0.1229.79\avutil-51.dll
MOD - [2012/09/25 05:41:26 | 000,275,496 | ---- | M] () -- C:\Documents and Settings\owner\Local Settings\Application Data\Google\Chrome\Application\22.0.1229.79\avformat-54.dll
MOD - [2012/09/25 05:41:24 | 002,168,360 | ---- | M] () -- C:\Documents and Settings\owner\Local Settings\Application Data\Google\Chrome\Application\22.0.1229.79\avcodec-54.dll
MOD - [2012/02/20 21:29:04 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2012/02/20 21:28:42 | 001,242,472 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/11/03 18:21:06 | 000,350,024 | ---- | M] () -- C:\Program Files\AVG\AVG PC Tuneup\madExcept_.bpl
MOD - [2011/11/03 18:21:06 | 000,184,136 | ---- | M] () -- C:\Program Files\AVG\AVG PC Tuneup\madBasic_.bpl
MOD - [2011/11/03 18:21:06 | 000,050,504 | ---- | M] () -- C:\Program Files\AVG\AVG PC Tuneup\madDisAsm_.bpl
MOD - [2008/04/14 00:42:00 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
MOD - [2008/04/14 00:41:52 | 000,059,904 | ---- | M] () -- C:\WINDOWS\system32\devenum.dll


========== Services (SafeList) ==========

SRV - [2012/07/13 14:14:14 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2005/07/08 17:24:46 | 000,871,424 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files\Ahead\InCD\InCDsrv.exe -- (InCDsrv)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\ComboFix\catchme.sys -- (catchme)
DRV - File not found [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\imkrin.sys -- (abp470n5)
DRV - [2010/07/08 15:09:10 | 000,606,056 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RTL8192su.sys -- (RTL8192su)
DRV - [2009/08/26 18:10:26 | 000,213,544 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k)
DRV - [2008/04/14 01:15:30 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2008/04/13 23:06:08 | 000,084,480 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ac97via.sys -- (VIAudio)
DRV - [2007/05/15 01:03:24 | 000,445,696 | R--- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\rt73.sys -- (RT73)
DRV - [2005/07/08 17:17:56 | 000,008,704 | ---- | M] (Nero AG) [Recognizer | System | Unknown] -- C:\WINDOWS\System32\drivers\InCDrec.sys -- (InCDrec)
DRV - [2005/07/08 17:17:54 | 000,099,584 | ---- | M] (Nero AG) [File_System | Disabled | Running] -- C:\WINDOWS\System32\drivers\InCDfs.sys -- (InCDfs)
DRV - [2005/07/08 17:17:36 | 000,029,696 | ---- | M] (Nero AG) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\InCDpass.sys -- (InCDPass)
DRV - [2005/07/08 10:17:32 | 000,028,672 | ---- | M] (Nero AG) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\InCDrm.sys -- (incdrm)
DRV - [2003/12/05 05:46:36 | 000,010,368 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pfc.sys -- (pfc)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKLM\..\URLSearchHook: {e917fc61-7f80-4f1f-a882-cdffffbe4c8d} - C:\Program Files\D-Link Toolbar\dlinktb.dll (AOL LLC.)
IE - HKLM\..\SearchScopes,Backup.Old.DefaultScope = {443789B7-F39C-4b5c-9287-DA72D38F4FE6}
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKLM\..\SearchScopes\{3EEF15EC-2ABA-0A31-2D9C-385F5AB25C69}: "URL" = http://slirsredirect.search.aol.com/redirector/sredir?sredir=843&query={searchTerms}&invocationType=tb50-ie-dlink-chromesbox-en-us
IE - HKLM\..\SearchScopes\{443789B7-F39C-4b5c-9287-DA72D38F4FE6}: "URL" = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=adknlg&chnl=adknlg&cd=2XzuyEtN2Y1L1QzutDzzzzyCtA0BzyyE0AtC0CtCtByE0DtDtN0D0Tzu0CtBtAyEtN1L2XzutBtFtCtFtCtFtAtCtB&cr=1715934213

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Backup.Old.Start Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKCU\..\URLSearchHook: {e917fc61-7f80-4f1f-a882-cdffffbe4c8d} - C:\Program Files\D-Link Toolbar\dlinktb.dll (AOL LLC.)
IE - HKCU\..\SearchScopes,Backup.Old.DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=adknlg&chnl=adknlg&cd=2XzuyEtN2Y1L1QzutDzzzzyCtA0BzyyE0AtC0CtCtByE0DtDtN0D0Tzu0CtBtAyEtN1L2XzutBtFtCtFtCtFtAtCtB&cr=1715934213
IE - HKCU\..\SearchScopes\{3EEF15EC-2ABA-0A31-2D9C-385F5AB25C69}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC
IE - HKCU\..\SearchScopes\{443789B7-F39C-4b5c-9287-DA72D38F4FE6}: "URL" = http://slirsredirect.search.aol.com/redirector/sredir?sredir=843&query={searchTerms}&invocationType=tb50-ie-dlink-chromesbox-en-us
IE - HKCU\..\SearchScopes\{B1D56A4B-5CED-4B41-9B77-0A5DC4BF522C}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=BCPA&o=16145&src=crm&q={searchTerms}&locale=en_US&apn_ptnrs=QK&apn_dtid=YYYYYYYYUS&apn_uid=1BBE81BB-B060-43AC-B230-96905DD94A50&apn_sauid=3DCDC55B-8D9D-48E3-BF23-EEF4671BCE37
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Search"
FF - prefs.js..browser.search.defaultenginename: "Search"
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\owner\Local Settings\Application Data\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\owner\Local Settings\Application Data\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)


[2012/01/23 10:42:06 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\owner\Application Data\Mozilla\Extensions
[2012/08/21 13:55:31 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\n5g4619o.default\extensions
[2012/08/21 13:55:31 | 000,000,000 | ---D | M] ("Shopping Sidekick") -- C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\n5g4619o.default\extensions\crossriderapp5058@crossrider.com

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\owner\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.89\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\owner\Local Settings\Application Data\Google\Chrome\Application\22.0.1229.79\gcswf32.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\owner\Local Settings\Application Data\Google\Chrome\Application\22.0.1229.79\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\owner\Local Settings\Application Data\Google\Chrome\Application\22.0.1229.79\pdf.dll
CHR - plugin: Skype Toolbars (Enabled) = C:\Documents and Settings\owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.8.0.8855_0\npSkypeChromePlugin.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Acrobat 5.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\owner\Local Settings\Application Data\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - Extension: Skype Click to Call = C:\Documents and Settings\owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.8.0.8855_0\
CHR - Extension: SaveValet = C:\Documents and Settings\owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mffdcionknddopdmdnloanoafafkmckb\1.7.0.105_0\

O1 HOSTS File: ([2012/10/06 14:52:45 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx ()
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (D-Link Toolbar Loader) - {f01858c7-2a68-4d93-9e22-502eae3917c2} - C:\Program Files\D-Link Toolbar\dlinktb.dll (AOL LLC.)
O3 - HKLM\..\Toolbar: (D-Link Toolbar) - {61874dfa-9adf-44e5-8e61-f3913707e7d7} - C:\Program Files\D-Link Toolbar\dlinktb.dll (AOL LLC.)
O3 - HKCU\..\Toolbar\WebBrowser: (D-Link Toolbar) - {61874DFA-9ADF-44E5-8E61-F3913707E7D7} - C:\Program Files\D-Link Toolbar\dlinktb.dll (AOL LLC.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe (Nero AG)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [RemoteControl] C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
O4 - HKCU..\Run: [chromium] C:\Documents and Settings\owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
O4 - HKCU..\Run: [PowerBar] C:\Program Files\CyberLink DVD Solution\Multimedia Launcher\PowerBar.exe (Cyberlink, Corp.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll (Intertrust Technologies, Inc.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C9705ABE-3D7C-4881-9D68-3B7DD6D1B571}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - (igfxsrvc.dll) - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/10/17 22:40:14 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2011/02/08 22:46:43 | 000,000,000 | R--D | M] - D:\AutoPlay -- [ UDF ]
O32 - AutoRun File - [2010/01/09 21:37:38 | 000,000,042 | R--- | M] () - D:\autorun.inf -- [ UDF ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2012/10/09 14:10:28 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\owner\Desktop\OTL.exe
[2012/10/08 13:47:40 | 000,000,000 | ---D | C] -- C:\_OTL
[2012/10/08 11:30:58 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\owner\Recent
[2012/10/08 11:30:58 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2012/10/06 14:59:43 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2012/10/02 19:32:36 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2012/10/02 19:32:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\CCleaner
[2012/09/28 11:18:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss
[2012/09/16 10:52:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
[2012/09/15 15:49:58 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2012/09/15 15:48:29 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2012/09/15 15:48:29 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2012/09/15 15:48:29 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2012/09/15 15:48:29 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2012/09/15 15:48:19 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/09/15 15:48:17 | 000,000,000 | R--D | C] -- C:\Documents and Settings\owner\My Documents\My Videos
[2012/09/15 15:48:17 | 000,000,000 | R--D | C] -- C:\Documents and Settings\owner\Start Menu\Programs\Administrative Tools
[2012/09/15 15:48:07 | 000,000,000 | ---D | C] -- C:\WINDOWS\erdnt
[2012/09/14 19:03:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\owner\Desktop\Fix This Computer

========== Files - Modified Within 30 Days ==========

[2012/10/09 14:14:04 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\TEMP
[2012/10/09 14:10:30 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\owner\Desktop\OTL.exe
[2012/10/09 14:07:12 | 000,314,508 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/10/09 14:07:12 | 000,040,836 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/10/09 14:04:19 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/10/09 14:04:18 | 000,000,368 | ---- | M] () -- C:\WINDOWS\tasks\AVG PC Tuneup Integrator Start On owner Logon.job
[2012/10/09 14:03:05 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/10/09 12:48:01 | 000,000,978 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1715567821-1004336348-1606980848-1003UA.job
[2012/10/09 12:48:00 | 000,000,926 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1715567821-1004336348-1606980848-1003Core.job
[2012/10/06 14:52:45 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2012/10/02 18:07:01 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/09/28 16:12:25 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/09/28 13:52:06 | 000,002,284 | ---- | M] () -- C:\Documents and Settings\owner\Desktop\Google Chrome.lnk
[2012/09/28 13:52:06 | 000,002,262 | ---- | M] () -- C:\Documents and Settings\owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/09/15 15:50:03 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2012/09/12 14:32:42 | 000,000,118 | ---- | M] () -- C:\WINDOWS\System32\MRT.INI

========== Files Created - No Company Name ==========

[2012/09/15 15:55:26 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\TEMP
[2012/09/15 15:50:03 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2012/09/15 15:49:59 | 000,260,272 | R-S- | C] () -- C:\cmldr
[2012/09/15 15:48:29 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2012/09/15 15:48:29 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2012/09/15 15:48:29 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2012/09/15 15:48:29 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2012/09/15 15:48:29 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2012/02/17 04:15:42 | 000,000,118 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2012/02/16 15:57:39 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2012/02/12 12:35:21 | 000,000,440 | R-S- | C] () -- C:\Documents and Settings\owner\ntuser.pol
[2011/10/17 22:56:11 | 000,110,592 | ---- | C] () -- C:\Program Files\Uninstall_CDS.exe
[2011/10/17 22:42:56 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2011/10/17 22:37:11 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2011/10/17 18:31:12 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2011/10/17 18:30:02 | 000,264,616 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT

========== ZeroAccess Check ==========


[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2011/09/05 09:56:22 | 001,510,400 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/02/09 08:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2008/04/14 00:42:10 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2012/04/16 10:32:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CanonBJ
[2012/01/10 22:27:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\D-Link Toolbar
[2012/02/12 14:48:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\iolo
[2012/05/09 08:55:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\RegWork
[2012/03/18 22:52:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2012/02/28 18:05:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\owner\Application Data\AVG
[2011/10/17 22:58:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\owner\Application Data\InterTrust
[2012/02/12 14:46:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\owner\Application Data\iolo
[2012/01/10 21:37:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\owner\Application Data\VirtualStore

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 145 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4

< End of report >

descriptionAdmin Virus - Page 1 EmptyRe: Admin Virus

more_horiz
Please run OTL
  • Under the Custom Scans/Fixes box at the bottom, copy and paste in the following:

    :OTL
    PRC - [2012/10/09 14:07:39 | 000,031,402 | ---- | M] () -- C:\Documents and Settings\owner\Local Settings\temp\mehuct.exe
    PRC - [2012/10/09 14:07:35 | 000,012,970 | ---- | M] () -- C:\Documents and Settings\owner\Local Settings\temp\winghoeqs.exe
    MOD - [2012/10/09 14:07:39 | 000,031,402 | ---- | M] () -- C:\Documents and Settings\owner\Local Settings\temp\mehuct.exe
    MOD - [2012/10/09 14:07:35 | 000,012,970 | ---- | M] () -- C:\Documents and Settings\owner\Local Settings\temp\winghoeqs.exe
    DRV - File not found [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\imkrin.sys -- (abp470n5)
    IE - HKLM\..\SearchScopes\{3EEF15EC-2ABA-0A31-2D9C-385F5AB25C69}: "URL" = http://slirsredirect.search.aol.com/redirector/sredir?sredir=843&query={searchTerms}&invocationType=tb50-ie-dlink-chromesbox-en-us
    IE - HKLM\..\SearchScopes\{443789B7-F39C-4b5c-9287-DA72D38F4FE6}: "URL" = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=adknlg&chnl=adknlg&cd=2XzuyEtN2Y1L1QzutDzzzzyCtA0BzyyE0AtC0CtCtByE0DtDtN0D0Tzu0CtBtAyEtN1L2XzutBtFtCtFtCtFtAtCtB&cr=1715934213
    IE - HKCU\..\URLSearchHook: {e917fc61-7f80-4f1f-a882-cdffffbe4c8d} - C:\Program Files\D-Link Toolbar\dlinktb.dll (AOL LLC.)
    IE - HKCU\..\SearchScopes,Backup.Old.DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=adknlg&chnl=adknlg&cd=2XzuyEtN2Y1L1QzutDzzzzyCtA0BzyyE0AtC0CtCtByE0DtDtN0D0Tzu0CtBtAyEtN1L2XzutBtFtCtFtCtFtAtCtB&cr=1715934213
    IE - HKCU\..\SearchScopes\{443789B7-F39C-4b5c-9287-DA72D38F4FE6}: "URL" = http://slirsredirect.search.aol.com/redirector/sredir?sredir=843&query={searchTerms}&invocationType=tb50-ie-dlink-chromesbox-en-us
    IE - HKCU\..\SearchScopes\{B1D56A4B-5CED-4B41-9B77-0A5DC4BF522C}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=BCPA&o=16145&src=crm&q={searchTerms}&locale=en_US&apn_ptnrs=QK&apn_dtid=YYYYYYYYUS&apn_uid=1BBE81BB-B060-43AC-B230-96905DD94A50&apn_sauid=3DCDC55B-8D9D-48E3-BF23-EEF4671BCE37
    IE - HKLM\..\URLSearchHook: {e917fc61-7f80-4f1f-a882-cdffffbe4c8d} - C:\Program Files\D-Link Toolbar\dlinktb.dll (AOL LLC.)
    IE - HKLM\..\SearchScopes,Backup.Old.DefaultScope = {443789B7-F39C-4b5c-9287-DA72D38F4FE6}
    IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    FF - prefs.js..browser.search.selectedEngine: "Search"
    FF - prefs.js..browser.search.defaultenginename: "Search"
    [2012/08/21 13:55:31 | 000,000,000 | ---D | M] ("Shopping Sidekick") -- C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\n5g4619o.default\extensions\crossriderapp5058@crossrider.com
    O2 - BHO: (D-Link Toolbar Loader) - {f01858c7-2a68-4d93-9e22-502eae3917c2} - C:\Program Files\D-Link Toolbar\dlinktb.dll (AOL LLC.)
    O3 - HKLM\..\Toolbar: (D-Link Toolbar) - {61874dfa-9adf-44e5-8e61-f3913707e7d7} - C:\Program Files\D-Link Toolbar\dlinktb.dll (AOL LLC.)
    O3 - HKCU\..\Toolbar\WebBrowser: (D-Link Toolbar) - {61874DFA-9ADF-44E5-8E61-F3913707E7D7} - C:\Program Files\D-Link Toolbar\dlinktb.dll (AOL LLC.)
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
    [2012/01/10 22:27:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\D-Link Toolbar
    [2012/05/09 08:55:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\RegWork
    @Alternate Data Stream - 145 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
    @Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4

    :files
    c:\program files\regwork

    :commands
    [emptytemp]
    [reboot]


  • Then click the Run Fix button at the top.
  • Note: The fix for OTL automatically hides your Desktop and Start menu so the fix can be completed. Do not be alerted, as this is normal.
  • Please do not exit the program. It might take a while to fix, but allow it to run. If it asks to reboot the computer, allow it to reboot. If the program freezes, and the computer fails to reboot - let me know.
    Lastly, post the contents of the log. (Located at C:\_OTL\Moved Files)

descriptionAdmin Virus - Page 1 EmptyRe: Admin Virus

more_horiz
Stuck on windows shutting down screen. Comp not frozen though. Mouse still functional.

descriptionAdmin Virus - Page 1 EmptyRe: Admin Virus

more_horiz
Force shutdown, and start back up. See if a log pops up within 5-10 minutes. If not, please post new OTL log as above.

descriptionAdmin Virus - Page 1 EmptyRe: Admin Virus

more_horiz
All processes killed
========== OTL ==========
No active process named mehuct.exe was found!
No active process named winghoeqs.exe was found!
Error: Unable to stop service abp470n5!
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\abp470n5 deleted successfully.
File C:\WINDOWS\system32\drivers\imkrin.sys not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{3EEF15EC-2ABA-0A31-2D9C-385F5AB25C69}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3EEF15EC-2ABA-0A31-2D9C-385F5AB25C69}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{443789B7-F39C-4b5c-9287-DA72D38F4FE6}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{443789B7-F39C-4b5c-9287-DA72D38F4FE6}\ not found.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{e917fc61-7f80-4f1f-a882-cdffffbe4c8d} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e917fc61-7f80-4f1f-a882-cdffffbe4c8d}\ deleted successfully.
C:\Program Files\D-Link Toolbar\dlinktb.dll moved successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{443789B7-F39C-4b5c-9287-DA72D38F4FE6}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{443789B7-F39C-4b5c-9287-DA72D38F4FE6}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B1D56A4B-5CED-4B41-9B77-0A5DC4BF522C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B1D56A4B-5CED-4B41-9B77-0A5DC4BF522C}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{e917fc61-7f80-4f1f-a882-cdffffbe4c8d} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e917fc61-7f80-4f1f-a882-cdffffbe4c8d}\ not found.
File C:\Program Files\D-Link Toolbar\dlinktb.dll not found.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Prefs.js: "Search" removed from browser.search.selectedEngine
Prefs.js: "Search" removed from browser.search.defaultenginename
C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\n5g4619o.default\extensions\crossriderapp5058@crossrider.com\skin folder moved successfully.
C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\n5g4619o.default\extensions\crossriderapp5058@crossrider.com\locale\en-US folder moved successfully.
C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\n5g4619o.default\extensions\crossriderapp5058@crossrider.com\locale folder moved successfully.
C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\n5g4619o.default\extensions\crossriderapp5058@crossrider.com\defaults\preferences folder moved successfully.
C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\n5g4619o.default\extensions\crossriderapp5058@crossrider.com\defaults folder moved successfully.
C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\n5g4619o.default\extensions\crossriderapp5058@crossrider.com\chrome\content folder moved successfully.
C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\n5g4619o.default\extensions\crossriderapp5058@crossrider.com\chrome folder moved successfully.
C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\n5g4619o.default\extensions\crossriderapp5058@crossrider.com folder moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f01858c7-2a68-4d93-9e22-502eae3917c2}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f01858c7-2a68-4d93-9e22-502eae3917c2}\ deleted successfully.
File C:\Program Files\D-Link Toolbar\dlinktb.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{61874dfa-9adf-44e5-8e61-f3913707e7d7} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{61874dfa-9adf-44e5-8e61-f3913707e7d7}\ deleted successfully.
File Link Toolbar\dlinktb.dll not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{61874DFA-9ADF-44E5-8E61-F3913707E7D7} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{61874DFA-9ADF-44E5-8E61-F3913707E7D7}\ not found.
File Link Toolbar\dlinktb.dll not found.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableTaskMgr deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableRegistryTools deleted successfully.
C:\Documents and Settings\All Users\Application Data\D-Link Toolbar\ieToolbar\resources\en-US\ui folder moved successfully.
C:\Documents and Settings\All Users\Application Data\D-Link Toolbar\ieToolbar\resources\en-US\ticker folder moved successfully.
C:\Documents and Settings\All Users\Application Data\D-Link Toolbar\ieToolbar\resources\en-US\rss folder moved successfully.
C:\Documents and Settings\All Users\Application Data\D-Link Toolbar\ieToolbar\resources\en-US\local folder moved successfully.
C:\Documents and Settings\All Users\Application Data\D-Link Toolbar\ieToolbar\resources\en-US\buttons folder moved successfully.
C:\Documents and Settings\All Users\Application Data\D-Link Toolbar\ieToolbar\resources\en-US folder moved successfully.
C:\Documents and Settings\All Users\Application Data\D-Link Toolbar\ieToolbar\resources folder moved successfully.
C:\Documents and Settings\All Users\Application Data\D-Link Toolbar\ieToolbar folder moved successfully.
C:\Documents and Settings\All Users\Application Data\D-Link Toolbar folder moved successfully.
C:\Documents and Settings\All Users\Application Data\RegWork\Backups folder moved successfully.
C:\Documents and Settings\All Users\Application Data\RegWork folder moved successfully.
ADS C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4 deleted successfully.
Unable to delete ADS C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4 .
========== FILES ==========
c:\program files\RegWork\Tmp folder moved successfully.
c:\program files\RegWork\Logs folder moved successfully.
c:\program files\RegWork folder moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: J
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: owner
->Temp folder emptied: 3479 bytes
->Temporary Internet Files folder emptied: 115329 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 6964996 bytes
->Flash cache emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 601088 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 16823 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 7.00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 10112012_094257

Files\Folders moved on Reboot...
File\Folder C:\WINDOWS\temp\Perflib_Perfdata_1328.dat not found!

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

descriptionAdmin Virus - Page 1 EmptyRe: Admin Virus

more_horiz
Good work!

Now, how is it all working. Please give summary, so we know how to continue from here...

descriptionAdmin Virus - Page 1 EmptyRe: Admin Virus

more_horiz
Running normal. Only weird thing is that whenever I shut down now it gets stuck on that same "Windows shutting down. . ." screen so I have to force it. Upon rebooting I get a winlogon.exe error. Task Manager still disabled by the Admin.

descriptionAdmin Virus - Page 1 EmptyRe: Admin Virus

more_horiz
Do you have the latest Windows Updates installed?

Check at http://update.microsoft.com

descriptionAdmin Virus - Page 1 EmptyRe: Admin Virus

more_horiz
I'm not able to receive updates from Microsoft because of the Windows invalidation.

descriptionAdmin Virus - Page 1 EmptyRe: Admin Virus

more_horiz
That seems to be the issue at this point, and there is nothing more to be done, unfortunately.

descriptionAdmin Virus - Page 1 EmptyRe: Admin Virus

more_horiz
Alright. Well, thank you for all your help.

descriptionAdmin Virus - Page 1 EmptyRe: Admin Virus

more_horiz
You're welcome. Didn't mean to sound short, was way behind yesterday.

Best of luck getting that activated again. After you do that, you'll be able to update Windows and probably solve half of its problems.

Topic marked solved. Smile...

descriptionAdmin Virus - Page 1 EmptyRe: Admin Virus

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum