also @ TechSpot: China reclaims world's fastest supercomputer title

System Check virus help needed

Discussion in 'Virus and Malware Removal' started by toffee801, Jan 3, 2012.

Post New Reply
  1. Broni Malware Annihilator Posts: 40,022   +187

    For x32 (x86) bit systems download Farbar Recovery Scan Tool and save it to your desktop.
    For x64 bit systems download Farbar Recovery Scan Tool x64 and save it to your desktop.

    • Double click on downloaded file to run it.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will produce a log (FRST.txt) on your desktop.
    • Please copy and paste it to your reply.
  2. toffee801 Newcomer, in training Posts: 41

    Farbar log

    Scan result of Farbars's Recovery Tool (FRST written by farbar) Version 2.3.2
    Ran by Sharon at 2012-01-04 21:15:11
    Running from C:\Users\Sharon\Desktop
    Service Pack 2 (X86) OS Language: English(US)
    Attention: Could not load system hive.ERROR: The process cannot access the file because it is being used by another process.

    ========================== Registry (Whitelisted) =============

    HKU\Default\...\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter [x]
    HKU\Default User\...\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter [x]
    HKLM\...\Winlogon: [Userinit] [x]
    HKLM\...\Winlogon: [Shell]

    ================================ Services (Whitelisted) ==================


    ========================== Drivers (Whitelisted) =============


    ========================== NetSvcs (Whitelisted) ===========

    ============ One Month Created Files and Folders ==============

    2012-01-04 20:22 - 2012-01-04 20:22 - 0044607 ____A C:\Users\Sharon\Desktop\bootkit_remover.zip
    2012-01-04 20:19 - 2012-01-04 20:19 - 0011224 ___AC C:\ComboFix.txt
    2012-01-04 20:15 - 2012-01-04 20:15 - 0000000 _SHDC C:\$RECYCLE.BIN
    2012-01-04 19:25 - 2012-01-04 20:19 - 0000000 ___DC C:\ComboFix
    2012-01-03 23:00 - 2012-01-03 23:00 - 2322184 ____A (ESET) C:\Users\Sharon\Downloads\esetsmartinstaller_enu.exe
    2012-01-03 22:51 - 2012-01-03 22:51 - 0446464 ____A (OldTimer Tools) C:\Users\Sharon\Desktop\TFC.exe
    2012-01-03 22:37 - 2012-01-03 22:37 - 0869194 ____A C:\Users\Sharon\Desktop\SecurityCheck.exe
    2012-01-03 22:24 - 2012-01-03 22:25 - 0006266 ___AC C:\JavaRa.log
    2012-01-03 21:44 - 2012-01-03 21:44 - 0057320 ____A C:\Users\Sharon\Desktop\Extras.Txt
    2012-01-03 21:42 - 2012-01-03 21:42 - 0091976 ____A C:\Users\Sharon\Desktop\OTL.Txt
    2012-01-03 21:32 - 2012-01-03 21:32 - 0584192 ____A (OldTimer Tools) C:\Users\Sharon\Desktop\OTL.exe.part
    2012-01-03 21:32 - 2012-01-03 21:32 - 0584192 ____A (OldTimer Tools) C:\Users\Sharon\Desktop\OTL.exe
    2012-01-03 20:13 - 2012-01-03 20:13 - 0000000 ____D C:\Users\Sharon\Desktop\bootkit_remover
    2012-01-03 19:55 - 2012-01-03 19:55 - 1932256 ____A (Symantec Corporation) C:\Users\Sharon\Desktop\FixTDSS.exe
    2012-01-03 19:36 - 2012-01-04 21:15 - 0000000 ___DC C:\FRST
    2012-01-03 19:35 - 2012-01-04 21:14 - 0858478 ____A C:\Users\Sharon\Desktop\FRST.exe
    2012-01-03 19:23 - 2012-01-03 19:26 - 1578288 ____A (Kaspersky Lab ZAO) C:\Users\Sharon\Desktop\tdsskiller.exe
    2012-01-03 18:05 - 2011-06-25 22:45 - 0256000 ____A C:\Windows\PEV.exe
    2012-01-03 18:05 - 2010-11-07 09:20 - 0208896 ____A C:\Windows\MBR.exe
    2012-01-03 18:05 - 2009-04-19 20:56 - 0060416 ____A (NirSoft) C:\Windows\NIRCMD.exe
    2012-01-03 18:05 - 2000-08-30 16:00 - 0518144 ____A (SteelWerX) C:\Windows\SWREG.exe
    2012-01-03 18:05 - 2000-08-30 16:00 - 0406528 ____A (SteelWerX) C:\Windows\SWSC.exe
    2012-01-03 18:05 - 2000-08-30 16:00 - 0098816 ____A C:\Windows\sed.exe
    2012-01-03 18:05 - 2000-08-30 16:00 - 0080412 ____A C:\Windows\grep.exe
    2012-01-03 18:05 - 2000-08-30 16:00 - 0068096 ____A C:\Windows\zip.exe
    2012-01-03 18:01 - 2012-01-04 19:02 - 4370643 ____R (Swearware) C:\Users\Sharon\Desktop\ComboFix.exe
    2012-01-03 17:51 - 2012-01-04 19:00 - 0002097 ____A C:\Users\Sharon\Desktop\aswMBR.txt
    2012-01-03 17:46 - 2012-01-04 18:59 - 4704768 ____A (AVAST Software) C:\Users\Sharon\Desktop\aswMBR.exe
    2012-01-03 17:44 - 2012-01-03 17:44 - 0000555 ____A C:\Users\Sharon\Documents\aswMBR.txt
    2012-01-02 23:07 - 2012-01-02 23:07 - 0607260 ____R (Swearware) C:\Users\Sharon\Desktop\dds.scr
    2012-01-02 23:04 - 2012-01-02 23:04 - 0000746 ____A C:\Users\Sharon\Desktop\gmer.log
    2012-01-02 22:22 - 2012-01-02 22:22 - 0302592 ____A C:\Users\Sharon\Desktop\mntdhvp6.exe
    2012-01-02 21:03 - 2012-01-02 21:03 - 0000000 ____D C:\Users\All Users\WindowsSearch
    2012-01-02 21:03 - 2012-01-02 21:03 - 0000000 ____D C:\ProgramData\WindowsSearch
    2012-01-02 20:32 - 2012-01-02 20:32 - 0000906 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2012-01-02 20:32 - 2012-01-02 20:32 - 0000000 ___DC C:\Program Files\Malwarebytes' Anti-Malware
    2012-01-02 20:32 - 2011-12-10 15:24 - 0020464 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
    2012-01-02 20:31 - 2012-01-03 18:55 - 0000000 ____D C:\Windows\ERDNT
    2012-01-02 20:27 - 2012-01-04 20:19 - 0000000 ___DC C:\Qoobox
    2012-01-02 19:59 - 2012-01-02 19:59 - 0000000 ____D C:\found.000
    2011-12-31 15:10 - 2011-12-31 15:10 - 0437399 ____A C:\Users\Sharon\Downloads\Confirmation.pdf
    2011-12-13 18:12 - 2011-11-23 05:37 - 2043904 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
    2011-12-13 18:12 - 2011-11-08 06:42 - 0002048 ____A (Microsoft Corporation) C:\Windows\System32\tzres.dll
    2011-12-13 18:12 - 2011-11-02 22:22 - 0916992 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
    2011-12-13 18:12 - 2011-11-02 22:21 - 1212416 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
    2011-12-13 18:12 - 2011-11-02 22:21 - 0105984 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
    2011-12-13 18:12 - 2011-11-02 22:20 - 0206848 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll
    2011-12-13 18:12 - 2011-11-02 22:18 - 5978112 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
    2011-12-13 18:12 - 2011-11-02 22:18 - 0611840 ____A (Microsoft Corporation) C:\Windows\System32\mstime.dll
    2011-12-13 18:12 - 2011-11-02 22:18 - 0602112 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
    2011-12-13 18:12 - 2011-11-02 22:18 - 0066560 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
    2011-12-13 18:12 - 2011-11-02 22:18 - 0055296 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll
    2011-12-13 18:12 - 2011-11-02 22:17 - 2000384 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
    2011-12-13 18:12 - 2011-11-02 22:17 - 1469440 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
    2011-12-13 18:12 - 2011-11-02 22:17 - 11081728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
    2011-12-13 18:12 - 2011-11-02 22:17 - 0387584 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
    2011-12-13 18:12 - 2011-11-02 22:17 - 0184320 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll
    2011-12-13 18:12 - 2011-11-02 22:17 - 0164352 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
    2011-12-13 18:12 - 2011-11-02 22:17 - 0109056 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
    2011-12-13 18:12 - 2011-11-02 22:17 - 0071680 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
    2011-12-13 18:12 - 2011-11-02 22:17 - 0055808 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
    2011-12-13 18:12 - 2011-11-02 22:17 - 0043520 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll
    2011-12-13 18:12 - 2011-11-02 22:17 - 0025600 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
    2011-12-13 18:12 - 2011-11-02 21:22 - 0385024 ____A (Microsoft Corporation) C:\Windows\System32\html.iec
    2011-12-13 18:12 - 2011-11-02 20:45 - 0174080 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
    2011-12-13 18:12 - 2011-11-02 20:45 - 0133632 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
    2011-12-13 18:12 - 2011-11-02 20:44 - 0013312 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe
    2011-12-13 18:12 - 2011-11-02 20:43 - 1638912 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
    2011-12-13 18:12 - 2011-10-27 00:01 - 3602816 ____A (Microsoft Corporation) C:\Windows\System32\ntkrnlpa.exe
    2011-12-13 18:12 - 2011-10-27 00:01 - 3550080 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
    2011-12-13 18:12 - 2011-10-25 07:56 - 0049152 ____A (Microsoft Corporation) C:\Windows\System32\csrsrv.dll
    2011-12-13 18:12 - 2011-10-14 08:02 - 0429056 ____A (Microsoft Corporation) C:\Windows\System32\EncDec.dll
    2011-12-05 00:08 - 2011-12-05 00:08 - 26819850 ____A C:\Users\Sharon\Downloads\?? (how great is your love) - SNSD LyricsEng. Sub.mp4

    ============ 3 Months Modified Files and Folders ===============

    2012-01-04 21:15 - 2012-01-03 19:36 - 0000000 ___DC C:\FRST
    2012-01-04 21:14 - 2012-01-03 19:35 - 0858478 ____A C:\Users\Sharon\Desktop\FRST.exe
    2012-01-04 20:39 - 2006-11-02 04:47 - 0003616 ____A C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
    2012-01-04 20:39 - 2006-11-02 04:47 - 0003616 ____A C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
    2012-01-04 20:22 - 2012-01-04 20:22 - 0044607 ____A C:\Users\Sharon\Desktop\bootkit_remover.zip
    2012-01-04 20:19 - 2012-01-04 20:19 - 0011224 ___AC C:\ComboFix.txt
    2012-01-04 20:19 - 2012-01-04 19:25 - 0000000 ___DC C:\ComboFix
    2012-01-04 20:19 - 2012-01-02 20:27 - 0000000 ___DC C:\Qoobox
    2012-01-04 20:15 - 2012-01-04 20:15 - 0000000 _SHDC C:\$RECYCLE.BIN
    2012-01-04 20:04 - 2006-11-02 02:23 - 0000249 ___AC C:\Windows\system.ini
    2012-01-04 19:43 - 2011-03-06 01:54 - 0000000 ____D C:\Users\Sharon\AppData\Local\CrashDumps
    2012-01-04 19:26 - 2009-08-11 21:29 - 1684176 ____A C:\Windows\WindowsUpdate.log
    2012-01-04 19:14 - 2010-11-05 19:41 - 0000000 ____D C:\Program Files\Norton 360
    2012-01-04 19:14 - 2010-11-05 19:41 - 0000000 ____D C:\Program Files\Common Files\Symantec Shared
    2012-01-04 19:14 - 2010-11-05 19:31 - 0000000 ____D C:\Users\All Users\Norton
    2012-01-04 19:14 - 2010-11-05 19:31 - 0000000 ____D C:\ProgramData\Norton
    2012-01-04 19:13 - 2010-11-05 19:41 - 0000000 ____D C:\Users\All Users\NortonInstaller
    2012-01-04 19:13 - 2010-11-05 19:41 - 0000000 ____D C:\ProgramData\NortonInstaller
    2012-01-04 19:02 - 2012-01-03 18:01 - 4370643 ____R (Swearware) C:\Users\Sharon\Desktop\ComboFix.exe
    2012-01-04 19:00 - 2012-01-03 17:51 - 0002097 ____A C:\Users\Sharon\Desktop\aswMBR.txt
    2012-01-04 18:59 - 2012-01-03 17:46 - 4704768 ____A (AVAST Software) C:\Users\Sharon\Desktop\aswMBR.exe
    2012-01-04 18:39 - 2010-10-10 00:31 - 3079716864 __ASH C:\hiberfil.sys
    2012-01-04 18:39 - 2006-11-02 05:01 - 0000006 ___AH C:\Windows\Tasks\SA.DAT
    2012-01-03 23:10 - 2006-11-02 05:01 - 0032564 ____A C:\Windows\Tasks\SCHEDLGU.TXT
    2012-01-03 23:01 - 2009-08-29 14:22 - 0000000 ____D C:\Users\Sharon\AppData\Roaming\uTorrent
    2012-01-03 23:00 - 2012-01-03 23:00 - 2322184 ____A (ESET) C:\Users\Sharon\Downloads\esetsmartinstaller_enu.exe
    2012-01-03 22:51 - 2012-01-03 22:51 - 0446464 ____A (OldTimer Tools) C:\Users\Sharon\Desktop\TFC.exe
    2012-01-03 22:37 - 2012-01-03 22:37 - 0869194 ____A C:\Users\Sharon\Desktop\SecurityCheck.exe
    2012-01-03 22:29 - 2008-01-20 18:47 - 0046648 ____A C:\Windows\PFRO.log
    2012-01-03 22:25 - 2012-01-03 22:24 - 0006266 ___AC C:\JavaRa.log
    2012-01-03 22:24 - 2008-10-29 15:26 - 0000000 ____D C:\Program Files\Java
    2012-01-03 21:44 - 2012-01-03 21:44 - 0057320 ____A C:\Users\Sharon\Desktop\Extras.Txt
    2012-01-03 21:42 - 2012-01-03 21:42 - 0091976 ____A C:\Users\Sharon\Desktop\OTL.Txt
    2012-01-03 21:32 - 2012-01-03 21:32 - 0584192 ____A (OldTimer Tools) C:\Users\Sharon\Desktop\OTL.exe.part
    2012-01-03 21:32 - 2012-01-03 21:32 - 0584192 ____A (OldTimer Tools) C:\Users\Sharon\Desktop\OTL.exe
    2012-01-03 21:06 - 2006-11-02 02:23 - 0000027 ____A C:\Windows\System32\Drivers\etc\hosts
    2012-01-03 20:13 - 2012-01-03 20:13 - 0000000 ____D C:\Users\Sharon\Desktop\bootkit_remover
    2012-01-03 19:55 - 2012-01-03 19:55 - 1932256 ____A (Symantec Corporation) C:\Users\Sharon\Desktop\FixTDSS.exe
    2012-01-03 19:26 - 2012-01-03 19:23 - 1578288 ____A (Kaspersky Lab ZAO) C:\Users\Sharon\Desktop\tdsskiller.exe
    2012-01-03 19:10 - 2006-11-02 03:18 - 0000000 ___RD C:\users\Public
    2012-01-03 19:10 - 2006-11-02 03:18 - 0000000 ___RD C:\users\Default
    2012-01-03 18:55 - 2012-01-02 20:31 - 0000000 ____D C:\Windows\ERDNT
    2012-01-03 17:44 - 2012-01-03 17:44 - 0000555 ____A C:\Users\Sharon\Documents\aswMBR.txt
    2012-01-02 23:07 - 2012-01-02 23:07 - 0607260 ____R (Swearware) C:\Users\Sharon\Desktop\dds.scr
    2012-01-02 23:04 - 2012-01-02 23:04 - 0000746 ____A C:\Users\Sharon\Desktop\gmer.log
    2012-01-02 22:22 - 2012-01-02 22:22 - 0302592 ____A C:\Users\Sharon\Desktop\mntdhvp6.exe
    2012-01-02 21:03 - 2012-01-02 21:03 - 0000000 ____D C:\Users\All Users\WindowsSearch
    2012-01-02 21:03 - 2012-01-02 21:03 - 0000000 ____D C:\ProgramData\WindowsSearch
    2012-01-02 20:32 - 2012-01-02 20:32 - 0000906 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2012-01-02 20:32 - 2012-01-02 20:32 - 0000000 ___DC C:\Program Files\Malwarebytes' Anti-Malware
    2012-01-02 20:31 - 2009-12-31 16:23 - 0000000 ____D C:\Users\All Users\WinZip
    2012-01-02 20:31 - 2009-12-31 16:23 - 0000000 ____D C:\ProgramData\WinZip
    2012-01-02 20:17 - 2006-11-02 02:33 - 0703388 ____A C:\Windows\System32\PerfStringBackup.INI
    2012-01-02 20:12 - 2009-08-11 21:35 - 0000000 ____D C:\Users\Sharon\AppData\Local\VirtualStore
    2012-01-02 19:59 - 2012-01-02 19:59 - 0000000 ____D C:\found.000
    2012-01-01 23:17 - 2011-03-05 19:54 - 0000000 ____D C:\Users\Sharon\GG pictures
    2011-12-31 15:10 - 2011-12-31 15:10 - 0437399 ____A C:\Users\Sharon\Downloads\Confirmation.pdf
    2011-12-31 14:40 - 2011-12-31 14:33 - 747152984 ____A C:\Users\Sharon\Downloads\[111230].KBS.Gayo Daejun.111230.HDTV.1080i.The.Boys.tp
    2011-12-26 00:17 - 2011-12-26 00:17 - 6159131 ____A C:\Users\Sharon\Downloads\[fancam]110720 kimpo airport SNSD TIFFANY.flv
    2011-12-22 20:24 - 2009-09-11 00:15 - 0136704 ____A C:\Users\Sharon\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    2011-12-14 13:45 - 2006-11-02 03:18 - 0000000 ____D C:\Windows\rescache
    2011-12-14 13:28 - 2006-11-02 04:47 - 0419664 ____A C:\Windows\System32\FNTCACHE.DAT
    2011-12-14 12:25 - 2008-11-14 23:30 - 0000000 ____D C:\Users\All Users\Microsoft Help
    2011-12-14 12:25 - 2008-11-14 23:30 - 0000000 ____D C:\ProgramData\Microsoft Help
    2011-12-14 12:22 - 2006-11-02 02:24 - 52988224 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe
    2011-12-11 18:00 - 2011-12-11 18:00 - 9547328 ____A C:\Users\Sharon\Downloads\Shoujo_Sect_-_Volume_01_Chapter_01_[otenba].zip
    2011-12-10 15:24 - 2012-01-02 20:32 - 0020464 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
    2011-12-05 02:10 - 2011-12-05 02:07 - 275352696 ____A C:\Users\Sharon\Downloads\[Kra] Sunny - Tiffany Dont Forget Me.ts
    2011-12-05 00:14 - 2011-12-05 00:14 - 33736029 ____A C:\Users\Sharon\Downloads\Dear Mom - SNSD ???? LyricsEng. Sub.mp4
    2011-12-05 00:08 - 2011-12-05 00:08 - 26819850 ____A C:\Users\Sharon\Downloads\?? (how great is your love) - SNSD LyricsEng. Sub.mp4
    2011-12-03 20:28 - 2011-10-10 20:33 - 0000000 ____D C:\Users\Sharon\Downloads\Rosetta Stone V3 - Chinese (Mandarin)
    2011-12-03 20:25 - 2011-09-24 22:45 - 0000000 ____D C:\Users\Sharon\Downloads\Butterfly Hu Die
    2011-12-01 19:10 - 2011-12-01 18:53 - 0010860 ____A C:\Users\Sharon\Documents\hmm.xlsx
    2011-11-30 13:36 - 2011-11-30 13:36 - 3388326 ____A C:\Users\Sharon\Downloads\logic_games_explanations_for_pt29-38.pdf
    2011-11-29 12:57 - 2011-11-29 12:25 - 0000000 ____D C:\Users\Sharon\Downloads\Sunny.2011.720p.HDRip.x264.AC3-ZERO
    2011-11-29 11:28 - 2011-11-29 11:28 - 2843930 ____A C:\Users\Sharon\Downloads\lg_explanations_for_preptests_52-61.pdf
    2011-11-28 12:56 - 2011-11-28 12:56 - 0296524 ____A C:\Users\Sharon\Desktop\https___os.lsac.org_Release_Share_DisplayPDFs.pdf
    2011-11-26 22:01 - 2011-11-15 21:16 - 0056981 ____A C:\Users\Sharon\Desktop\1L questionnaire.pdf
    2011-11-23 05:37 - 2011-12-13 18:12 - 2043904 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
    2011-11-14 19:59 - 2011-11-14 19:59 - 3596358 ____A C:\Users\Sharon\Downloads\03 Say yes.mp3
    2011-11-10 19:03 - 2006-11-02 03:18 - 0000000 ____D C:\Program Files\Common Files\System
    2011-11-10 01:25 - 2010-04-10 12:23 - 0000000 ____D C:\Program Files\Mozilla Firefox
    2011-11-08 21:14 - 2006-11-02 04:52 - 0063335 ____A C:\Windows\setupact.log
    2011-11-08 17:29 - 2011-11-08 17:29 - 0496648 ____A C:\Users\Sharon\2qjkkk8.gif
    2011-11-08 17:29 - 2009-08-11 21:35 - 0000000 ____D C:\users\Sharon
    2011-11-08 17:28 - 2011-11-08 17:28 - 0049007 ____A C:\Users\Sharon\tumblr_lhh1rlbZBM1qc9s1uo1_500.jpg
    2011-11-08 06:42 - 2011-12-13 18:12 - 0002048 ____A (Microsoft Corporation) C:\Windows\System32\tzres.dll
    2011-11-06 14:10 - 2011-10-10 21:31 - 0000000 ____D C:\Users\All Users\FLEXnet
    2011-11-06 14:10 - 2011-10-10 21:31 - 0000000 ____D C:\ProgramData\FLEXnet
    2011-11-02 22:31 - 2011-11-02 22:31 - 11142660 ____A C:\Users\Sharon\Downloads\????? ??_???.mp4
    2011-11-02 22:29 - 2011-11-02 22:29 - 12072567 ____A C:\Users\Sharon\Downloads\????? ??_???.mp4
    2011-11-02 22:26 - 2011-11-02 22:26 - 11869656 ____A C:\Users\Sharon\Downloads\????? ??_???.mp4
    2011-11-02 22:22 - 2011-12-13 18:12 - 0916992 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
    2011-11-02 22:21 - 2011-12-13 18:12 - 1212416 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
    2011-11-02 22:21 - 2011-12-13 18:12 - 0105984 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
    2011-11-02 22:20 - 2011-12-13 18:12 - 0206848 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll
    2011-11-02 22:18 - 2011-12-13 18:12 - 5978112 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
    2011-11-02 22:18 - 2011-12-13 18:12 - 0611840 ____A (Microsoft Corporation) C:\Windows\System32\mstime.dll
    2011-11-02 22:18 - 2011-12-13 18:12 - 0602112 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
    2011-11-02 22:18 - 2011-12-13 18:12 - 0066560 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
    2011-11-02 22:18 - 2011-12-13 18:12 - 0055296 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll
    2011-11-02 22:17 - 2011-12-13 18:12 - 2000384 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
    2011-11-02 22:17 - 2011-12-13 18:12 - 1469440 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
    2011-11-02 22:17 - 2011-12-13 18:12 - 11081728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
    2011-11-02 22:17 - 2011-12-13 18:12 - 0387584 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
    2011-11-02 22:17 - 2011-12-13 18:12 - 0184320 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll
    2011-11-02 22:17 - 2011-12-13 18:12 - 0164352 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
    2011-11-02 22:17 - 2011-12-13 18:12 - 0109056 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
    2011-11-02 22:17 - 2011-12-13 18:12 - 0071680 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
    2011-11-02 22:17 - 2011-12-13 18:12 - 0055808 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
    2011-11-02 22:17 - 2011-12-13 18:12 - 0043520 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll
    2011-11-02 22:17 - 2011-12-13 18:12 - 0025600 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
    2011-11-02 21:22 - 2011-12-13 18:12 - 0385024 ____A (Microsoft Corporation) C:\Windows\System32\html.iec
    2011-11-02 21:15 - 2011-11-02 21:09 - 547436824 ____A C:\Users\Sharon\Downloads\[2011-10-23] The Boys (SBS Inkigayo).tp
    2011-11-02 21:04 - 2011-11-02 21:01 - 69742602 ____A C:\Users\Sharon\Downloads\111021.SJ_Kiss_the_Radio.SNSD.guest.wmv
    2011-11-02 21:04 - 2011-11-02 20:57 - 557664400 ____A C:\Users\Sharon\Downloads\[2011-10-22] The Boys (MBC Music Core).tp
    2011-11-02 20:55 - 2011-11-02 20:48 - 200095541 ____A C:\Users\Sharon\Downloads\[SoShi Subs] SNSD - The Boys MV (Korean Ver.).mkv
    2011-11-02 20:45 - 2011-12-13 18:12 - 0174080 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
    2011-11-02 20:45 - 2011-12-13 18:12 - 0133632 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
    2011-11-02 20:44 - 2011-12-13 18:12 - 0013312 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe
    2011-11-02 20:43 - 2011-12-13 18:12 - 1638912 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
    2011-11-02 19:22 - 2011-11-02 19:20 - 205280632 ____A C:\Users\Sharon\Downloads\111102 SNSD @ ShimShimTapa Radio.mp4
    2011-11-02 19:13 - 2011-11-02 19:13 - 0032114 ____A C:\Users\Sharon\tumblr_lu14ypKpUH1qj3zhso2_400.jpg
    2011-11-02 17:18 - 2011-11-02 17:18 - 5158905 ____A C:\Users\Sharon\c0120174_4eb151bcafff9.gif
    2011-10-28 15:52 - 2011-10-28 15:52 - 0137904 ____A C:\Windows\Minidump\Mini102811-01.dmp
    2011-10-28 15:52 - 2010-09-24 20:52 - 383436647 ____A C:\Windows\MEMORY.DMP
    2011-10-28 15:52 - 2010-09-24 20:52 - 0000000 ____D C:\Windows\Minidump
    2011-10-27 00:01 - 2011-12-13 18:12 - 3602816 ____A (Microsoft Corporation) C:\Windows\System32\ntkrnlpa.exe
    2011-10-27 00:01 - 2011-12-13 18:12 - 3550080 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
    2011-10-25 20:45 - 2011-10-25 20:42 - 2107663704 ____A C:\Users\Sharon\Downloads\[isubs-squad.com]Running.Man.E60.720P.avi
    2011-10-25 07:56 - 2011-12-13 18:12 - 0049152 ____A (Microsoft Corporation) C:\Windows\System32\csrsrv.dll
    2011-10-23 12:26 - 2011-10-23 12:25 - 88591473 ____A C:\Users\Sharon\Downloads\SNSD - The Boys (kor ver) MV [eng sub romanization hangul].mp4
    2011-10-22 14:13 - 2011-10-22 14:11 - 180720369 ____A C:\Users\Sharon\Downloads\Girls Generation _ The Boys _ Comeback Special Stage 2011.10.21 _ KBS MUSIC BANK.mp4
    2011-10-16 23:49 - 2011-10-16 23:49 - 0256970 ____A C:\Users\Sharon\Downloads\WYWH.rar
    2011-10-16 23:44 - 2011-10-16 23:44 - 0627507 ____A C:\Users\Sharon\Downloads\RememberingSunday.pdf
    2011-10-16 22:46 - 2011-10-16 22:43 - 1697076516 ____A C:\Users\Sharon\Downloads\[isubs-squad.com]Running.Man.E59.720P.avi
    2011-10-14 08:02 - 2011-12-13 18:12 - 0429056 ____A (Microsoft Corporation) C:\Windows\System32\EncDec.dll
    2011-10-13 18:10 - 2006-11-02 03:18 - 0000000 ____D C:\Windows\Microsoft.NET
    2011-10-13 17:30 - 2010-11-09 23:45 - 0000000 ____D C:\Program Files\Microsoft Silverlight
    2011-10-10 21:48 - 2011-10-10 21:43 - 0000000 ___DC C:\Program Files\MagicDisc
    2011-10-10 21:46 - 2011-10-10 21:46 - 1352435 ____A C:\Users\Sharon\Downloads\setup_magicdisc(1).exe
    2011-10-10 21:46 - 2011-10-10 21:45 - 0000798 ____A C:\Users\Sharon\Start Menu\Programs\Startup\MagicDisc.lnk
    2011-10-10 21:46 - 2011-10-10 21:45 - 0000798 ____A C:\Users\Sharon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MagicDisc.lnk
    2011-10-10 21:46 - 2011-10-10 21:45 - 0000762 ____A C:\Users\Sharon\Desktop\MagicDisc.lnk
    2011-10-10 21:44 - 2011-10-10 21:44 - 1352435 ____A C:\Users\Sharon\Downloads\setup_magicdisc106.exe
    2011-10-10 21:43 - 2011-10-10 21:43 - 1352435 ____A C:\Users\Sharon\Downloads\setup_magicdisc.exe
    2011-10-10 21:30 - 2011-10-10 21:30 - 0000000 ____D C:\Program Files\Common Files\Macrovision Shared
    2011-10-10 21:25 - 2011-10-10 21:25 - 0000000 ____D C:\Users\Sharon\AppData\Local\WinZip
    2011-10-10 16:46 - 2011-10-10 16:45 - 72326400 ____A (Ingram Digital ) C:\Users\Sharon\Downloads\setup(1).exe
    2011-10-08 23:06 - 2011-10-08 23:03 - 1564736508 ____A C:\Users\Sharon\Downloads\[iSUBS-squad.com]Running.Man.E58.720P.avi

    ========================= Known DLLs (Whitelisted) ============


    ========================= Bamital & volsnap Check ============

    C:\Windows\explorer.exe => MD5 is legit

    C:\Windows\System32\winlogon.exe => MD5 is legit

    C:\Windows\System32\wininit.exe => MD5 is legit

    C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

    ========================= Memory info ======================

    Percentage of memory in use: 42%
    Total physical RAM: 2938.31 MB
    Available physical RAM: 1686.2 MB
    Total Pagefile: 6080.92 MB
    Available Pagefile: 4880.68 MB
    Total Virtual: 2047.88 MB
    Available Virtual: 1958.58 MB

    ======================= Partitions =========================

    1 Drive c: () (Fixed) (Total:224.41 GB) (Free:95.55 GB) NTFS ==>[Drive with boot components]

    Disk ### Status Size Free Dyn Gpt
    -------- ---------- ------- ------- --- ---
    Disk 0 Online 233 GB 0 B
    Disk 1 No Media 0 B 0 B
    Disk 2 No Media 0 B 0 B

    Partitions of Disk 0:

    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    Partition 1 OEM 8 GB 1024 KB
    Partition 2 Primary 224 GB 8 GB

    Disk: 0
    Partition 1
    Type : 27
    Hidden: Yes
    Active: No

    There is no volume associated with this partition.

    Disk: 0
    Partition 2
    Type : 07
    Hidden: No
    Active: Yes

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 1 C NTFS Partition 224 GB Healthy System



    ==========================================================

    Last Boot: 2012-01-04 18:47

    ======================= End Of Log ==========================
  3. Broni Malware Annihilator Posts: 40,022   +187

    Download the FixTDSS.exe

    Save the file to your Windows desktop.
    Close all running programs.
    If you are running Windows XP, turn off System Restore. How to turn off or turn on Windows XP System Restore
    Double-click the FixTDSS.exe file to start the removal tool.
    Click Start to begin the process, and then allow the tool to run.
    OK any security prompts.
    Restart the computer when prompted by the tool.
    After the computer has started, the tool will inform you of the state of infection (make sure to let me know what it said)
    If you are running Windows XP, re-enable System Restore.
  4. toffee801 Newcomer, in training Posts: 41

    will do, thank you.
  5. toffee801 Newcomer, in training Posts: 41

    Hi Broni,

    The message is ***Infected MBR detected

    Should I click the repair button to repair it?

    Also, my computer is showing an error message today that MagicDisc can't open driver(mcdbus).

    I want to remove MagicDisc but can't seem to (not today, but in the past).

    Also, this might be a question for later, but is there a way to remove IE completely? It used to give me a lot of grief until I switched over to Firefox.

    Thanks
  6. Broni Malware Annihilator Posts: 40,022   +187

    Yes.
     
  7. toffee801 Newcomer, in training Posts: 41

    Thanks sorry for my silly :) questions.

    Done - it says repair succeeded.
  8. Broni Malware Annihilator Posts: 40,022   +187

    Posy new Bootkit Remover log.
  9. toffee801 Newcomer, in training Posts: 41

    Can't paste it into Notepad, but

    232 GB \\.\PhysicalDrive0 OK <DOS/Win32 Boot code found>

    Thanks
  10. Broni Malware Annihilator Posts: 40,022   +187

    Excellent!

    How is computer doing?
  11. toffee801 Newcomer, in training Posts: 41

    Good, it stopped sending me to bad sites when I search for things... :)
  12. Broni Malware Annihilator Posts: 40,022   +187

    Good :)

    Update Adobe Flash Player
    Download the Latest Adobe Flash for Firefox and IE Without Any Extras: http://www.404techsupport.com/2010/...-flash-for-firefox-and-ie-without-any-extras/

    1. Update your Java version here: http://www.java.com/en/download/installed.jsp

    Note 1: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

    Note 2: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. If you don't want to run another extra service, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer.

    2. Now, we need to remove old Java version and its remnants...

    Download JavaRa to your desktop and unzip it to its own folder
    • Run JavaRa.exe (Vista users! Right click on JavaRa.exe, click Run As Administrator), pick the language of your choice and click Select. Then click Remove Older Versions.
    • Accept any prompts.

    Then continue with TFC and Eset scan (my reply #32)
  13. toffee801 Newcomer, in training Posts: 41

    For some reason I can't get Java to install, the update to version 30 doesn't work :(
  14. Broni Malware Annihilator Posts: 40,022   +187

    Run JavaRa first.
  15. toffee801 Newcomer, in training Posts: 41

    Error msg for Javara

    I get the below error log - I close all Browsers before doing it


    JavaRa 1.16 Removal Log.

    Report follows after line.

    ------------------------------------

    The JavaRa removal process was started on Tue Jan 03 22:24:40 2012

    Found and removed: C:\Program Files\Java\jre1.6.0

    Found and removed: C:\Users\Sharon\AppData\LocalLow\Sun\Java\jre1.6.0_15

    Found and removed: C:\Users\Sharon\AppData\LocalLow\Sun\Java\jre1.6.0_17

    Found and removed: C:\Users\Sharon\AppData\LocalLow\Sun\Java\jre1.6.0_20

    Found and removed: C:\Users\Sharon\AppData\LocalLow\Sun\Java\jre1.6.0_25

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0001-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0002-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0003-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0004-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0005-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0006-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0007-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0008-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0009-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0010-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0011-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0012-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0013-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0014-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0015-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0016-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0017-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0018-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0019-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0020-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0021-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0022-ABCDEFFDCBA}. The error returned was 124.

    JavaRa 1.16 Removal Log.

    Report follows after line.

    ------------------------------------

    The JavaRa removal process was started on Tue Jan 03 22:24:51 2012

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0001-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0002-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0003-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0004-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0005-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0006-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0007-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0008-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0009-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0010-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0011-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0012-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0013-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0014-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0015-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0016-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0017-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0018-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0019-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0020-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0021-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0022-ABCDEFFDCBA}. The error returned was 124.

    ------------------------------------

    Finished reporting.
  16. Broni Malware Annihilator Posts: 40,022   +187

    Try to update Java now.
  17. toffee801 Newcomer, in training Posts: 41

    It doesn't work...same error message.

    Thanks
  18. Broni Malware Annihilator Posts: 40,022   +187

  19. toffee801 Newcomer, in training Posts: 41

    Windows offline worked :)

    Ran Javara - seems to have worked as well.......?

    JavaRa 1.16 Removal Log.

    Report follows after line.

    ------------------------------------

    The JavaRa removal process was started on Tue Jan 03 22:24:40 2012

    Found and removed: C:\Program Files\Java\jre1.6.0

    Found and removed: C:\Users\Sharon\AppData\LocalLow\Sun\Java\jre1.6.0_15

    Found and removed: C:\Users\Sharon\AppData\LocalLow\Sun\Java\jre1.6.0_17

    Found and removed: C:\Users\Sharon\AppData\LocalLow\Sun\Java\jre1.6.0_20

    Found and removed: C:\Users\Sharon\AppData\LocalLow\Sun\Java\jre1.6.0_25
  20. Broni Malware Annihilator Posts: 40,022   +187

    Cool :)

    TFC and Eset...

    Bed time here.
    I'll check on you tomorrow :)