No Internet access after running Combofix for Google redirect virus

Solved
By irukab
Jan 18, 2012
  1. irukab

    irukab Newcomer, in training Topic Starter Posts: 39

    Sorry about that. See below.

    Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 31-12-2012
    Ran by SYSTEM at 02-01-2013 22:17:52
    Running from D:\
    Windows 7 Starter (X86) OS Language: English(US)
    The current controlset is ControlSet001

    ==================== Registry (Whitelisted) ===================

    HKLM\...\Run: [ETDWare] %ProgramFiles%\Elantech\ETDCtrl.exe [548744 2010-04-12] (ELAN Microelectronic Corp.)
    HKLM\...\Run: [HotkeyMon] AsusSender.exe C:\Program Files\EeePC\HotkeyService\HotKeyMon.exe [95744 2010-09-02] (ASUSTeK Computer Inc.)
    HKLM\...\Run: [HotkeyService] AsusSender.exe C:\Program Files\EeePC\HotkeyService\HotkeyService.exe [1245104 2010-09-03] (ASUSTeK Computer Inc.)
    HKLM\...\Run: [SuperHybridEngine] AsusSender.exe C:\Program Files\EeePC\SHE\SuperHybridEngine.exe [412600 2010-06-09] (ASUSTeK Computer Inc.)
    HKLM\...\Run: [LiveUpdate] AsusSender.exe C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe auto [1095080 2011-07-13] (AsusTek Computer Inc.)
    HKLM\...\Run: [CapsHook] AsusSender.exe C:\Program Files\EeePC\CapsHook\CapsHook.exe [445344 2010-05-28] (ASUS)
    HKLM\...\Run: [Intel AppUp(SM) center] "C:\Program Files\Intel\IntelAppStore\bin\serviceManager.lnk" [1260 2011-01-18] ()
    HKLM\...\Run: [MobileConnect] %programfiles%\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe /silent [2412032 2009-09-18] (Vodafone)
    HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-05-30] (Apple Inc.)
    HKLM\...\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray [462920 2012-07-03] (Malwarebytes Corporation)
    HKLM\...\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW [1259376 2011-07-28] ()
    HKLM\...\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2011-10-24] (Apple Inc.)
    HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-04-03] (Adobe Systems Incorporated)
    HKLM\...\Run: [TkBellExe] "C:\Program Files\Real\RealPlayer\update\realsched.exe" -osboot [296096 2012-07-02] (RealNetworks, Inc.)
    HKLM\...\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [421776 2012-06-07] (Apple Inc.)
    HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
    HKU\Default\...\Run: [Best Buy pc app] C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Best Buy\Best Buy pc app.appref-ms [x]
    HKU\Default\...\RunOnce: [Reboot] AsusSender.exe C:\Windows\Reboot.exe 60 [92096 2010-12-12] (AsusTek Computer Inc.)
    HKU\Default\...\RunOnce: [IconPatch] C:\Windows\AP\IconPatch.vbs [x]
    HKU\Default\...\RunOnce: [AskScreensaver] C:\Program Files\Asus\AsusScreensaver\AsusScreensaver.exe [797104 2010-09-07] (AsusTek Computer Inc.)
    HKU\Default User\...\Run: [Best Buy pc app] C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Best Buy\Best Buy pc app.appref-ms [x]
    HKU\Default User\...\RunOnce: [Reboot] AsusSender.exe C:\Windows\Reboot.exe 60 [92096 2010-12-12] (AsusTek Computer Inc.)
    HKU\Default User\...\RunOnce: [IconPatch] C:\Windows\AP\IconPatch.vbs [x]
    HKU\Default User\...\RunOnce: [AskScreensaver] C:\Program Files\Asus\AsusScreensaver\AsusScreensaver.exe [797104 2010-09-07] (AsusTek Computer Inc.)
    HKU\Iruka Brown\...\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2011-05-08] (Google Inc.)
    HKU\Iruka Brown\...\Run: [Google Update] "C:\Users\Iruka Brown\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2011-05-08] (Google Inc.)
    HKU\Iruka Brown\...\Run: [RCUI] "C:\PROGRA~1\RINGCE~1\RINGCE~1\RCUI.exe" [500992 2010-11-23] (RingCentral, Inc.)
    HKU\Iruka Brown\...\Run: [RCHotKey] "C:\Program Files\RingCentral\RingCentral Call Controller\RCHotKey.exe" [38144 2010-11-23] (RingCentral, Inc.)
    Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
    Startup: C:\Users\All Users\Start Menu\Programs\Startup\AsusVibeLauncher.lnk
    ShortcutTarget: AsusVibeLauncher.lnk -> C:\Program Files\ASUS\AsusVibe\AsusVibeLauncher.exe (ASUSTeK Computer Inc.)
    Startup: C:\Users\All Users\Start Menu\Programs\Startup\Marketsplash Print Software.lnk
    ShortcutTarget: Marketsplash Print Software.lnk -> C:\Program Files\Hewlett-Packard\Marketsplash by HP\HPLocalWebPrintAgent.exe (Hewlett-Packard Company)
    Startup: C:\Users\Default\Start Menu\Programs\Startup\Best Buy pc app.lnk
    ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (Microsoft)
    Startup: C:\Users\Default User\Start Menu\Programs\Startup\Best Buy pc app.lnk
    ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (Microsoft)

    ==================== Services (Whitelisted) ===================

    2 AsusService; C:\Windows\System32\AsusService.exe [219136 2009-08-18] ()
    2 MBAMService; "C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe" [655944 2012-07-03] (Malwarebytes Corporation)
    2 VMCService; "C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe" [9216 2009-09-18] (Vodafone)
    3 McComponentHostService; "C:\Program Files\McAfee Security Scan\2.1.121\McCHSvc.exe" [x]

    ==================== Drivers (Whitelisted) ====================

    1 AsUpIO; C:\Windows\System32\drivers\AsUpIO.sys [11832 2011-02-09] ()
    3 ETD; C:\Windows\System32\DRIVERS\ETD.sys [109960 2010-04-13] (ELAN Microelectronic Corp.)
    3 hwusbfake; C:\Windows\System32\DRIVERS\ewusbfake.sys [100736 2009-07-23] (Huawei Technologies Co., Ltd.)
    3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [13880 2009-07-20] ( )
    3 MBAMProtector; \??\C:\windows\system32\drivers\mbam.sys [22344 2012-07-03] (Malwarebytes Corporation)
    3 MBAMSwissArmy; \??\C:\windows\system32\drivers\mbamswissarmy.sys [40776 2012-10-26] (Malwarebytes Corporation)
    3 btwampfl; C:\Windows\System32\drivers\btwampfl.sys [x]
    3 btwaudio; C:\Windows\System32\drivers\btwaudio.sys [x]
    3 btwavdt; C:\Windows\system32\DRIVERS\btwavdt.sys [x]
    3 btwl2cap; C:\Windows\System32\DRIVERS\btwl2cap.sys [x]
    3 btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [x]

    ==================== NetSvcs (Whitelisted) ===================


    ==================== One Month Created Files and Folders ========

    2013-01-02 22:17 - 2013-01-02 22:17 - 00000000 ____D C:\FRST
    2013-01-02 16:26 - 2008-05-07 21:03 - 00303616 ____A ( ) C:\SetACL.exe
    2013-01-02 15:56 - 2004-06-11 15:33 - 00290304 ____A (Microsoft Corporation) C:\subinacl.exe
    2013-01-02 15:16 - 2013-01-02 15:16 - 00003224 ____N C:\bootsqm.dat
    2013-01-02 15:04 - 2013-01-02 15:25 - 00002233 ____A C:\Users\Public\Desktop\Tweaking.com - Windows Repair (All in One).lnk
    2013-01-02 15:04 - 2013-01-02 15:04 - 00000000 ____D C:\Program Files\Tweaking.com
    2013-01-02 15:03 - 2013-01-02 15:03 - 05415956 ____A C:\Users\Iruka Brown\Downloads\tweaking.com_windows_repair_aio_setup (2).exe
    2013-01-02 15:03 - 2013-01-02 15:03 - 05415956 ____A C:\Users\Iruka Brown\Downloads\tweaking.com_windows_repair_aio_setup (1).exe
    2013-01-02 15:01 - 2013-01-02 15:01 - 05415956 ____A C:\Users\Iruka Brown\Downloads\tweaking.com_windows_repair_aio_setup.exe
    2012-12-30 23:55 - 2012-12-30 23:55 - 00000000 ____D C:\Users\Iruka Brown\Downloads\Autoruns (1)
    2012-12-30 23:54 - 2012-12-30 23:54 - 00540921 ____A C:\Users\Iruka Brown\Downloads\Autoruns (1).zip
    2012-12-30 14:09 - 2012-12-30 14:09 - 00326144 ____A (AVAST Software) C:\Users\Iruka Brown\Downloads\aswclear (2).exe
    2012-12-30 13:50 - 2012-12-30 13:51 - 03847400 ____A C:\Users\Iruka Brown\Downloads\32bit (1).exe
    2012-12-30 09:28 - 2012-12-16 06:13 - 00295424 ____A (Adobe Systems Incorporated) C:\Windows\System32\atmfd.dll
    2012-12-30 09:28 - 2012-12-16 06:13 - 00034304 ____A (Adobe Systems) C:\Windows\System32\atmlib.dll
    2012-12-30 09:25 - 2012-11-13 18:48 - 12320256 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
    2012-12-30 09:25 - 2012-11-13 18:14 - 09738240 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
    2012-12-30 09:25 - 2012-11-13 18:09 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
    2012-12-30 09:25 - 2012-11-13 17:58 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
    2012-12-30 09:25 - 2012-11-13 17:57 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
    2012-12-30 09:25 - 2012-11-13 17:57 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
    2012-12-30 09:25 - 2012-11-13 17:55 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
    2012-12-30 09:25 - 2012-11-13 17:51 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
    2012-12-30 09:25 - 2012-11-13 17:49 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
    2012-12-30 09:25 - 2012-11-13 17:49 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
    2012-12-30 09:25 - 2012-11-13 17:48 - 00420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
    2012-12-30 09:25 - 2012-11-13 17:47 - 00607744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
    2012-12-30 09:25 - 2012-11-13 17:46 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
    2012-12-30 09:25 - 2012-11-13 17:45 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
    2012-12-30 09:25 - 2012-11-13 17:44 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
    2012-12-30 09:25 - 2012-11-13 17:41 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
    2012-12-21 18:55 - 2012-11-01 21:11 - 00376832 ____A (Microsoft Corporation) C:\Windows\System32\dpnet.dll
    2012-12-21 18:55 - 2012-10-04 08:47 - 00169984 ____A (Microsoft Corporation) C:\Windows\System32\winsrv.dll
    2012-12-21 18:55 - 2012-10-04 08:43 - 00868352 ____A (Microsoft Corporation) C:\Windows\System32\kernel32.dll
    2012-12-21 18:55 - 2012-10-04 08:43 - 00293376 ____A (Microsoft Corporation) C:\Windows\System32\KernelBase.dll
    2012-12-21 18:55 - 2012-10-04 08:40 - 00005120 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
    2012-12-21 18:55 - 2012-10-04 08:40 - 00004608 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
    2012-12-21 18:55 - 2012-10-04 08:40 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
    2012-12-21 18:55 - 2012-10-04 08:40 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
    2012-12-21 18:55 - 2012-10-04 08:40 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
    2012-12-21 18:55 - 2012-10-04 08:40 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
    2012-12-21 18:55 - 2012-10-04 08:40 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
    2012-12-21 18:55 - 2012-10-04 08:40 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
    2012-12-21 18:55 - 2012-10-04 08:40 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
    2012-12-21 18:55 - 2012-10-04 08:40 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
    2012-12-21 18:55 - 2012-10-04 08:40 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
    2012-12-21 18:55 - 2012-10-04 08:40 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
    2012-12-21 18:55 - 2012-10-04 08:40 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
    2012-12-21 18:55 - 2012-10-04 08:40 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
    2012-12-21 18:55 - 2012-10-04 08:40 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
    2012-12-21 18:55 - 2012-10-04 08:40 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
    2012-12-21 18:55 - 2012-10-04 08:40 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
    2012-12-21 18:55 - 2012-10-04 08:40 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
    2012-12-21 18:55 - 2012-10-04 08:40 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
    2012-12-21 18:55 - 2012-10-04 08:40 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
    2012-12-21 18:55 - 2012-10-04 08:40 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
    2012-12-21 18:55 - 2012-10-04 08:40 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
    2012-12-21 18:55 - 2012-10-04 08:40 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
    2012-12-21 18:55 - 2012-10-04 08:40 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
    2012-12-21 18:55 - 2012-10-04 06:57 - 00271360 ____A (Microsoft Corporation) C:\Windows\System32\conhost.exe
    2012-12-21 18:55 - 2012-10-04 06:41 - 00006144 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
    2012-12-21 18:55 - 2012-10-04 06:41 - 00004608 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
    2012-12-21 18:55 - 2012-10-04 06:41 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
    2012-12-21 18:55 - 2012-10-04 06:41 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
    2012-12-21 18:54 - 2012-11-08 20:42 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\tzres.dll

    ==================== One Month Modified Files and Folders ========

    2013-01-02 22:17 - 2013-01-02 22:17 - 00000000 ____D C:\FRST
    2013-01-02 17:04 - 2009-07-27 02:11 - 00726316 ____A C:\Windows\System32\PerfStringBackup.INI
    2013-01-02 16:56 - 2009-07-13 20:33 - 00350176 ____A C:\Windows\System32\FNTCACHE.DAT
    2013-01-02 15:25 - 2013-01-02 15:04 - 00002233 ____A C:\Users\Public\Desktop\Tweaking.com - Windows Repair (All in One).lnk
    2013-01-02 15:16 - 2013-01-02 15:16 - 00003224 ____N C:\bootsqm.dat
    2013-01-02 15:04 - 2013-01-02 15:04 - 00000000 ____D C:\Program Files\Tweaking.com
    2013-01-02 15:03 - 2013-01-02 15:03 - 05415956 ____A C:\Users\Iruka Brown\Downloads\tweaking.com_windows_repair_aio_setup (2).exe
    2013-01-02 15:03 - 2013-01-02 15:03 - 05415956 ____A C:\Users\Iruka Brown\Downloads\tweaking.com_windows_repair_aio_setup (1).exe
    2013-01-02 15:01 - 2013-01-02 15:01 - 05415956 ____A C:\Users\Iruka Brown\Downloads\tweaking.com_windows_repair_aio_setup.exe
    2012-12-30 23:58 - 2012-11-01 03:34 - 00000000 ____D C:\Users\Iruka Brown\Downloads\Autoruns
    2012-12-30 23:55 - 2012-12-30 23:55 - 00000000 ____D C:\Users\Iruka Brown\Downloads\Autoruns (1)
    2012-12-30 23:54 - 2012-12-30 23:54 - 00540921 ____A C:\Users\Iruka Brown\Downloads\Autoruns (1).zip
    2012-12-30 14:17 - 2009-07-13 18:04 - 00002577 ____A C:\Windows\System32\config.nt
    2012-12-30 14:13 - 2011-05-08 10:27 - 01946213 ____A C:\Windows\WindowsUpdate.log
    2012-12-30 14:12 - 2009-07-13 20:34 - 00009696 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2012-12-30 14:12 - 2009-07-13 20:34 - 00009696 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2012-12-30 14:09 - 2012-12-30 14:09 - 00326144 ____A (AVAST Software) C:\Users\Iruka Brown\Downloads\aswclear (2).exe
    2012-12-30 13:58 - 2011-05-08 06:28 - 00000892 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
    2012-12-30 13:57 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
    2012-12-30 13:57 - 2009-07-13 20:39 - 00090398 ____A C:\Windows\setupact.log
    2012-12-30 13:51 - 2012-12-30 13:50 - 03847400 ____A C:\Users\Iruka Brown\Downloads\32bit (1).exe
    2012-12-30 13:42 - 2012-05-27 05:27 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
    2012-12-30 13:19 - 2011-05-17 08:35 - 00000932 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1611172488-2531530254-924118653-1000UA.job
    2012-12-30 13:18 - 2011-05-08 06:28 - 00000896 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
    2012-12-30 12:18 - 2011-05-17 08:35 - 00000880 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1611172488-2531530254-924118653-1000Core.job
    2012-12-30 11:08 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\rescache
    2012-12-30 10:04 - 2011-05-09 13:59 - 00093036 ____A C:\Windows\PFRO.log
    2012-12-30 09:29 - 2009-07-13 18:04 - 00000944 ____A C:\Windows\win.ini
    2012-12-30 09:06 - 2012-01-15 12:59 - 65087872 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
    2012-12-21 18:49 - 2012-03-24 17:34 - 00002475 ____A C:\Users\Iruka Brown\Desktop\Google Chrome.lnk
    2012-12-21 18:44 - 2012-05-27 05:27 - 00697272 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
    2012-12-21 18:44 - 2011-08-12 06:35 - 00073656 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
    2012-12-16 06:13 - 2012-12-30 09:28 - 00295424 ____A (Adobe Systems Incorporated) C:\Windows\System32\atmfd.dll
    2012-12-16 06:13 - 2012-12-30 09:28 - 00034304 ____A (Adobe Systems) C:\Windows\System32\atmlib.dll

    ==================== Known DLLs (Whitelisted) =================


    ==================== Bamital & volsnap Check =================

    C:\Windows\explorer.exe => MD5 is legit
    C:\Windows\System32\winlogon.exe => MD5 is legit
    C:\Windows\System32\wininit.exe => MD5 is legit
    C:\Windows\System32\svchost.exe => MD5 is legit
    C:\Windows\System32\services.exe => MD5 is legit
    C:\Windows\System32\User32.dll => MD5 is legit
    C:\Windows\System32\userinit.exe => MD5 is legit
    C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

    ==================== EXE ASSOCIATION =====================

    HKLM\...\.exe: exefile => OK
    HKLM\...\exefile\DefaultIcon: %1 => OK
    HKLM\...\exefile\open\command: "%1" %* => OK

    ==================== Restore Points =========================

    Restore point made on: 2012-10-31 19:20:04
    Restore point made on: 2012-11-08 05:53:03
    Restore point made on: 2012-11-15 08:02:52
    Restore point made on: 2012-11-22 20:49:21
    Restore point made on: 2012-11-30 09:21:09
    Restore point made on: 2012-12-02 11:45:16
    Restore point made on: 2012-12-30 09:05:35

    ==================== Memory info ===========================

    Percentage of memory in use: 34%
    Total physical RAM: 1014.12 MB
    Available physical RAM: 659.71 MB
    Total Pagefile: 1014.12 MB
    Available Pagefile: 660.15 MB
    Total Virtual: 2047.88 MB
    Available Virtual: 1960.7 MB

    ==================== Partitions =============================

    1 Drive c: () (Fixed) (Total:134.03 GB) (Free:68.14 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
    2 Drive d: () (Removable) (Total:1.86 GB) (Free:0.64 GB) FAT
    3 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS

    Disk ### Status Size Free Dyn Gpt
    -------- ------------- ------- ------- --- ---
    Disk 0 Online 149 GB 0 B
    Disk 1 Online 1901 MB 0 B

    Partitions of Disk 0:
    ===============

    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    Partition 1 Primary 134 GB 1024 KB
    Partition 2 Primary 15 GB 134 GB
    Partition 3 Primary 16 MB 149 GB

    =========================================================

    Disk: 0
    Partition 1
    Type : 07
    Hidden: No
    Active: Yes

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 0 C NTFS Partition 134 GB Healthy

    =========================================================

    Disk: 0
    Partition 2
    Type : 1B
    Hidden: Yes
    Active: No

    There is no volume associated with this partition.

    =========================================================

    Disk: 0
    Partition 3
    Type : EF
    Hidden: Yes
    Active: No

    There is no volume associated with this partition.

    =========================================================

    Partitions of Disk 1:
    ===============

    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    Partition 1 Primary 1900 MB 16 KB

    =========================================================

    Disk: 1
    Partition 1
    Type : 06
    Hidden: No
    Active: Yes

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 1 D FAT Removable 1900 MB Healthy

    =========================================================

    Last Boot: 2012-12-30 10:55

    ==================== End Of Log ============================
  2. Broni

    Broni Malware Annihilator Posts: 46,131   +251

    Download attached fixlist.txt file and save it to the very same USB flash drive you've been using. Plug the drive back in.

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    On Vista or Windows 7: Now please enter System Recovery Options.
    On Windows XP: Now please boot into the UBCD.
    Run FRST/FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.

    See if you can boot normally.

    Attached Files:

  3. irukab

    irukab Newcomer, in training Topic Starter Posts: 39

    I still can't boot normally. Fixlog.txt below.

    Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 31-12-2012
    Ran by SYSTEM at 2013-01-02 23:30:42 Run:1
    Running from D:\

    ==============================================

    DEFAULT hive was successfully copied to System32\config\HiveBackup
    DEFAULT hive was successfully restored from registry back up.
    SAM hive was successfully copied to System32\config\HiveBackup
    SAM hive was successfully restored from registry back up.
    SECURITY hive was successfully copied to System32\config\HiveBackup
    SECURITY hive was successfully restored from registry back up.
    SOFTWARE hive was successfully copied to System32\config\HiveBackup
    SOFTWARE hive was successfully restored from registry back up.
    SYSTEM hive was successfully copied to System32\config\HiveBackup
    SYSTEM hive was successfully restored from registry back up.

    ==== End of Fixlog ====
  4. Broni

    Broni Malware Annihilator Posts: 46,131   +251

    What exactly happens when you try to boot normally?
  5. irukab

    irukab Newcomer, in training Topic Starter Posts: 39

    After I press the power button, on a black screen the computer runs through a list of \windows32\drivers... files.

    Then a black screen comes up that has a brief message. It moves too quickly for me to read all of it, but the end says: The system is booting in safe mode - minimal services.

    Then the login page comes up.
  6. Broni

    Broni Malware Annihilator Posts: 46,131   +251

    Boot back to System Recovery Options and try "Startup repair".
  7. irukab

    irukab Newcomer, in training Topic Starter Posts: 39

    The result is: Startup Repair could not detect a Problem

    Then below that it says: If you have recently attached a device to this computer, such as a camera or portable music player, remove it and restart your computer. If you continue to see this message, contact your system administrator or computer manufacturer for assistance.

    I had the flash drive in the first time I ran that repair. I removed it and tried it 2 more times with the same message.
  8. Broni

    Broni Malware Annihilator Posts: 46,131   +251

    Do you have Windows 7 DVD?
  9. irukab

    irukab Newcomer, in training Topic Starter Posts: 39

    Not sure what that is. How can I find out? I have Windows 7 Starter -- it's a mini notebook with no DVD drive. A while back I downloaded DVDFab....
  10. Broni

    Broni Malware Annihilator Posts: 46,131   +251

    While in safe mode....

    Go Start>Run (Start Search in Vista/7), type in:
    msconfig
    Click OK (hit Enter in Vista/7).

    Click on Startup tab.
    Click Disable all
    IMPORTANT! In case of laptop, make sure, you do NOT disable any keyboard, or touchpad entries.

    Click Services tab.
    Put checkmark in Hide all Microsoft services
    Click Disable all.

    Click OK.
    Restart computer in Normal Mode.

    NOTE. If you use different firewall, than Windows firewall, turn Windows firewall on, just for this test, since your regular firewall won't be running.
    If you use Windows firewall, you're fine.

    Same problem?
  11. irukab

    irukab Newcomer, in training Topic Starter Posts: 39

    Geez, yes, I have the same problem...
     
  12. irukab

    irukab Newcomer, in training Topic Starter Posts: 39

    Geez, yes, I have the same problem...
  13. Broni

    Broni Malware Annihilator Posts: 46,131   +251

    I'm afraid that your Windows installation is corrupted beyond repair.
    I see no other choice but to reinstall Windows.
  14. irukab

    irukab Newcomer, in training Topic Starter Posts: 39

    Oh no. Okay. Would you be able to walk me through it?
  15. Broni

    Broni Malware Annihilator Posts: 46,131   +251

    You may have recovery partition there.
    What brand and model of laptop is it?
  16. irukab

    irukab Newcomer, in training Topic Starter Posts: 39

    Asus Eee PC
  17. Broni

    Broni Malware Annihilator Posts: 46,131   +251

  18. irukab

    irukab Newcomer, in training Topic Starter Posts: 39

    Thanks for your help, Broni. At first I couldn't get into Windows Setup, but then I found out that I had to press F2 to get into BIOS and disable Boot Booster so that I could see the option when I pressed F9.

    Now I'll re-download Malwarebytes and Avast. Is there anything else I should know?

    I really appreciate your help. Thank you.
     
  19. Broni

    Broni Malware Annihilator Posts: 46,131   +251

    Well, with fresh installation you should be good to go :)
  20. irukab

    irukab Newcomer, in training Topic Starter Posts: 39

    Cool. Thanks, again.
  21. Broni

    Broni Malware Annihilator Posts: 46,131   +251

    You're very welcome [​IMG]


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.