Hi, this is my first visit to the forum.
For around a week and a half we have been having trouble on our relatively new however out of warranty (I.e. 5 months) desktop computer.
A common browser hijacker: feed.helperbar.com, was discovered about 12 days ago on all 4 users on Chrome and Firefox. Antivirus removal attempts failed, and eventually another issue came onto some of the users: You could not open or close any programs (except File Explorer) or run Ctr+Alt+Del (so you could not access task manager) and when you tried to switch user, you were greeted by a black and blank screen. The only other option was to completely turn off the PC by the mains.
We also attempted to perform a system restore, but discovered that there were no restore points available until after the infection.
After backing up to an external hard drive, we realised that the virus may in fact be infected on that, too, since it was backed up after the infection.
The next step was Malwarebytes. Here is the log from one of the full scans (if you need a quick scan log, please ask, we have one too)
Malwarebytes Anti-Malware (Trial) 1.75.0.1300
www.malwarebytes.org
Database version: v2013.12.29.03
Windows 8 x64 NTFS
Internet Explorer 10.0.9200.16750
sarah :: DESKTOP [administrator]
Protection: Enabled
29/12/2013 18:37:23
MBAM-log-2013-12-29 (20-04-02).txt
Scan type: Full scan (C:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 657644
Time elapsed: 1 hour(s), 20 minute(s), 25 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 4
C:\__COPY\copyFred\Downloads\iLividSetupV1(1).exe (PUP.Optional.Bandoo) -> No action taken.
C:\__COPY\copyFred\Downloads\iLividSetupV1.exe (PUP.Optional.Bandoo) -> No action taken.
C:\__COPY\copyGeorge\Downloads\CoolMP3ToAACConverterSetup.exe (PUP.Adware.RKN) -> No action taken.
C:\__COPY\copyGeorge\Downloads\Setup_FreeConverter.exe (PUP.Optional.Bandoo.A) -> No action taken.
(end)
Then we tried a DDS scan:
DDS
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.16537 BrowserJavaVersion: 10.45.2
Run by sarah at 22:33:24 on 2013-12-29
Microsoft Windows 8 6.2.9200.0.1252.44.2057.18.8087.6038 [GMT 0:00]
.
AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {ADA629C7-7F48-5689-624A-3B76997E0892}
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {16C7C823-5972-5907-58FA-0004E2F9422F}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: McAfee Firewall *Enabled* {959DA8E2-3527-57D1-4915-924367AD4FE9}
.
============== Running Processes ===============
.
C:\windows\system32\svchost.exe -k DcomLaunch
C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE
C:\windows\system32\nvvsvc.exe
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\system32\dwm.exe
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Program Files\IDT\WDM\STacSV64.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\windows\system32\nvvsvc.exe
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\windows\system32\svchost.exe -k apphost
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\windows\system32\dashost.exe
C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\WinTV\TVServer\CaptureGenUSB.exe
C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
C:\Program Files\McAfee\AppStats\MfeASUM.exe
C:\windows\system32\mfevtps.exe
C:\windows\system32\rundll32.exe
C:\windows\system32\rundll32.exe
C:\windows\SysWOW64\NlsSrv32.exe
C:\windows\SysWOW64\rundll32.exe
C:\windows\system32\svchost.exe -k imgsvc
C:\Program Files\McAfee\MSC\McAPExe.exe
C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\windows\system32\taskhostex.exe
C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe
C:\windows\System32\svchost.exe -k LocalServicePeerNet
C:\windows\Explorer.EXE
C:\windows\system32\taskeng.exe
C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler.exe
C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler64.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\LiveComm.exe
C:\windows\system32\SearchIndexer.exe
c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
C:\Windows\System32\RuntimeBroker.exe
C:\Program Files\IDT\WDM\Beats64.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files (x86)\Samsung\Kies\Kies.exe
C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe
C:\Program Files (x86)\Garmin\ANT Agent\ANT Agent.exe
C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe
C:\Program Files (x86)\WinTV\WinTV7\WinTVTray.exe
C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
C:\windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\BATINDICATOR.exe
C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\BATINDICATOR_HIDList.exe
C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\CNYHKEY.exe
C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\APSDaemon.exe
C:\Program Files\Common Files\McAfee\Platform\mcuicnt.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
c:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteService.exe
C:\Program Files (x86)\McAfee Online Backup\MOBKbackup.exe
C:\Program Files (x86)\McAfee Online Backup\MOBKbackup.exe
C:\windows\system32\vssvc.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\windows\System32\cscript.exe
C:\windows\SysWOW64\netsh.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uSearch Bar = hxxp://www.google.com/ie
uSearch Page = hxxp://www.google.com
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mWinlogon: Userinit = userinit.exe,
BHO: MSS+ Identifier: {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.130\McAfeeMSS_IE.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: McAfee SiteAdvisor BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO: HP Network Check Helper: {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
TB: McAfee SiteAdvisor Toolbar: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll
uRun: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload
uRun: [KiesAirMessage] C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup
uRun: [ANT Agent] C:\Program Files (x86)\Garmin\ANT Agent\ANT Agent.exe
uRun: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
uRun: [ApplePhotoStreams] C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
mRun: [BATINDICATOR] C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\BATINDICATOR.exe
mRun: [BATINDICATORHL] C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\BATINDICATOR_HIDList.exe
mRun: [OSDTool] C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\CNYHKEY.exe
mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
mRun: [BingDesktop] C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe /fromkey
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [mcpltui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
StartupFolder: C:\Users\sarah\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ONENOT~1.LNK - C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\StartUp\MCAFEE~1.LNK - C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\StartUp\WINTVR~1.LNK - C:\Program Files (x86)\WinTV\WinTV7\WinTVTray.exe
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
TCP: NameServer = 192.168.1.254 192.168.1.254
TCP: Interfaces\{C78E59CE-E374-45F7-9183-6DBA27383EC7} : DHCPNameServer = 192.168.1.254 192.168.1.254
TCP: Interfaces\{FB33815A-B733-4E7B-8B5F-6A2E595E8F63} : DHCPNameServer = 192.168.1.254 192.168.1.254
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: McAfee SiteAdvisor BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll
x64-BHO: HP Network Check Helper: {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll
x64-TB: McAfee SiteAdvisor Toolbar: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll
x64-Run: [BeatsOSDApp] C:\Program Files\IDT\WDM\beats64.exe
x64-Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe
x64-RunOnce: [NCPluginUpdater] "C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" Update
x64-IE: {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
x64-Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl64.dll
x64-Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll
x64-Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - <orphaned>
x64-Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\sarah\AppData\Roaming\Mozilla\Firefox\Profiles\f9jbdcic.default\
FF - prefs.js: browser.startup.homepage - hxxps://www.google.co.uk
FF - prefs.js: keyword.URL - hxxp://uk.search.yahoo.com/search?fr=mcafee&p=
FF - plugin: c:\PROGRA~2\mcafee\msc\npMcSnFFPl.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\McAfee\SiteAdvisor\NPMcFFPlg32.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Program Files\McAfee Security Scan\3.8.130\npMcAfeeMSS.dll
FF - plugin: C:\Users\sarah\AppData\Roaming\Mozilla\Firefox\Profiles\f9jbdcic.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins\npGarmin.dll
FF - plugin: C:\windows\SysWOW64\Adobe\Director\np32dsw_1202122.dll
FF - plugin: C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll
.
============= SERVICES / DRIVERS ===============
.
R0 amd_sata;amd_sata;C:\windows\System32\Drivers\amd_sata.sys [2013-3-31 80552]
R0 amd_xata;amd_xata;C:\windows\System32\Drivers\amd_xata.sys [2013-3-31 26280]
R1 CLVirtualDrive;CLVirtualDrive;C:\windows\System32\Drivers\CLVirtualDrive.sys [2013-5-23 92536]
R3 cfwids;McAfee Inc. cfwids;C:\windows\System32\Drivers\cfwids.sys [2013-6-17 70112]
R3 hcw17bda;Hauppauge SMS1000-based;C:\windows\System32\Drivers\hcw17b64.sys [2012-10-23 78192]
S2 EsgScanner;EsgScanner;C:\windows\System32\Drivers\EsgScanner.sys [2013-12-19 22704]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);C:\windows\System32\Drivers\ssudbus.sys [2013-10-28 107288]
S3 esgiguard;esgiguard;C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [2011-3-2 13088]
S3 HipShieldK;McAfee Inc. HipShieldK;C:\windows\System32\Drivers\HipShieldK.sys [2013-10-15 197704]
.
=============== Created Last 30 ================
.
2013-12-29 12:54:03 25928 ----a-w- C:\windows\System32\drivers\mbam.sys
2013-12-29 12:54:03 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-12-29 12:29:11 -------- d-----w- C:\Users\sarah\AppData\Roaming\Malwarebytes
2013-12-29 12:28:42 -------- d-----w- C:\ProgramData\Malwarebytes
2013-12-19 18:53:44 -------- d-----w- C:\Users\sarah\AppData\Local\CrashDumps
2013-12-19 14:37:30 22704 ----a-w- C:\windows\System32\drivers\EsgScanner.sys
2013-12-19 14:37:28 110080 ----a-r- C:\Users\sarah\AppData\Roaming\Microsoft\Installer\{CD09642E-061D-4844-BA37-ED1480916404}\IconF7A21AF7.exe
2013-12-19 14:37:28 110080 ----a-r- C:\Users\sarah\AppData\Roaming\Microsoft\Installer\{CD09642E-061D-4844-BA37-ED1480916404}\IconD7F16134.exe
2013-12-19 14:37:28 110080 ----a-r- C:\Users\sarah\AppData\Roaming\Microsoft\Installer\{CD09642E-061D-4844-BA37-ED1480916404}\Icon1226A4C5.exe
2013-12-19 14:37:26 -------- d-----w- C:\sh4ldr
2013-12-19 14:37:26 -------- d-----w- C:\Program Files\Enigma Software Group
2013-12-19 14:36:54 -------- d-----w- C:\windows\CD09642E061D4844BA37ED1480916404.TMP
2013-12-19 14:36:53 -------- d-----w- C:\Program Files (x86)\Common Files\Wise Installation Wizard
2013-12-19 14:04:04 -------- d-----w- C:\ProgramData\SMR410
2013-12-19 14:03:05 -------- d-----w- C:\Users\sarah\AppData\Local\NPE
2013-12-18 19:35:44 344064 ----a-w- C:\windows\SysWow64\msvcr70.dll
2013-12-15 22:45:01 -------- d-sh--w- C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
2013-12-15 22:45:01 -------- d--h--w- C:\ProgramData\Common Files
2013-12-15 22:42:35 -------- d-----w- C:\Users\sarah\AppData\Local\Programs
2013-12-14 11:54:15 23350272 ----a-w- C:\Program Files\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll
2013-12-14 11:54:13 22615040 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll
2013-12-13 00:54:31 62976 ----a-w- C:\windows\System32\imagehlp.dll
2013-12-13 00:53:45 222720 ----a-w- C:\windows\System32\scrobj.dll
2013-12-13 00:53:45 194048 ----a-w- C:\windows\System32\scrrun.dll
2013-12-13 00:53:45 162304 ----a-w- C:\windows\SysWow64\scrobj.dll
2013-12-13 00:53:45 156160 ----a-w- C:\windows\SysWow64\scrrun.dll
2013-12-13 00:53:45 146944 ----a-w- C:\windows\System32\cscript.exe
2013-12-13 00:53:45 143872 ----a-w- C:\windows\System32\wshom.ocx
2013-12-13 00:53:45 115712 ----a-w- C:\windows\SysWow64\cscript.exe
2013-12-13 00:53:41 420864 ----a-w- C:\windows\System32\WMPhoto.dll
2013-12-13 00:53:41 368640 ----a-w- C:\windows\SysWow64\WMPhoto.dll
2013-12-13 00:53:38 4036608 ----a-w- C:\windows\System32\win32k.sys
2013-12-13 00:53:26 288768 ----a-w- C:\windows\System32\drivers\portcls.sys
2013-12-13 00:53:25 312320 ----a-w- C:\windows\System32\msieftp.dll
2013-12-13 00:53:25 273408 ----a-w- C:\windows\SysWow64\msieftp.dll
2013-12-07 00:28:33 -------- d-----w- C:\Program Files (x86)\MyFree Codec
2013-12-06 23:48:18 -------- d-----w- C:\Program Files (x86)\MarkAny
.
==================== Find3M ====================
.
2013-12-04 00:53:54 78304 ----a-w- C:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-12-04 00:53:54 694240 ----a-w- C:\windows\SysWow64\FlashPlayerApp.exe
2013-11-26 22:07:44 10856 ----a-w- C:\windows\System32\drivers\mfeclnrk.sys
2013-11-26 22:07:22 96112 ----a-w- C:\windows\System32\drivers\mfencrk.sys
2013-11-26 22:07:02 411944 ----a-w- C:\windows\System32\drivers\mfencbdc.sys
2013-11-04 16:51:44 70112 ----a-w- C:\windows\System32\drivers\cfwids.sys
2013-11-04 16:46:34 343696 ----a-w- C:\windows\System32\drivers\mfewfpk.sys
2013-11-04 16:46:16 182752 ----a-w- C:\windows\System32\mfevtps.exe
2013-11-04 16:43:04 782360 ----a-w- C:\windows\System32\drivers\mfehidk.sys
2013-11-04 16:41:22 519576 ----a-w- C:\windows\System32\drivers\mfefirek.sys
2013-11-04 16:40:00 311120 ----a-w- C:\windows\System32\drivers\mfeavfk.sys
2013-11-04 16:39:20 179792 ----a-w- C:\windows\System32\drivers\mfeapfk.sys
2013-11-04 16:28:52 69344 ----a-w- C:\windows\System32\drivers\mfeelamk.sys
2013-10-28 01:12:12 204568 ----a-w- C:\windows\System32\drivers\ssudmdm.sys
2013-10-28 01:12:10 107288 ----a-w- C:\windows\System32\drivers\ssudbus.sys
2013-10-25 06:19:22 2241536 ----a-w- C:\windows\System32\wininet.dll
2013-10-25 06:19:12 915968 ----a-w- C:\windows\System32\uxtheme.dll
2013-10-25 06:17:57 3959808 ----a-w- C:\windows\System32\jscript9.dll
2013-10-25 04:45:11 1767936 ----a-w- C:\windows\SysWow64\wininet.dll
2013-10-25 04:43:42 2877952 ----a-w- C:\windows\SysWow64\jscript9.dll
2013-10-19 04:04:07 59392 ----a-w- C:\windows\SysWow64\imagehlp.dll
2013-10-10 11:53:35 96600 ----a-w- C:\windows\System32\drivers\wfplwfs.sys
2013-10-10 09:21:20 1160192 ----a-w- C:\windows\System32\IKEEXT.DLL
2013-10-10 09:20:43 723968 ----a-w- C:\windows\System32\BFE.DLL
2013-10-08 22:30:32 35328 ----a-w- C:\windows\SysWow64\wuapp.exe
2013-10-08 22:30:17 84992 ----a-w- C:\windows\SysWow64\wudriver.dll
2013-10-08 22:30:17 126976 ----a-w- C:\windows\SysWow64\wuwebv.dll
2013-10-08 22:28:11 40448 ----a-w- C:\windows\System32\wuapp.exe
2013-10-08 22:27:56 99328 ----a-w- C:\windows\System32\wudriver.dll
2013-10-08 22:27:56 252928 ----a-w- C:\windows\System32\WUSettingsProvider.dll
2013-10-08 22:27:56 1622016 ----a-w- C:\windows\System32\wucltux.dll
2013-10-08 22:27:56 142848 ----a-w- C:\windows\System32\wuwebv.dll
2013-10-08 22:27:45 175104 ----a-w- C:\windows\System32\storewuauth.dll
2013-10-08 07:50:37 96168 ----a-w- C:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-10-05 06:10:20 285016 ----a-w- C:\windows\System32\drivers\spaceport.sys
2013-10-02 23:25:41 1300992 ----a-w- C:\windows\System32\gdi32.dll
2013-10-02 02:50:07 447320 ----a-w- C:\windows\System32\drivers\USBHUB3.SYS
2013-10-01 23:37:57 1569280 ----a-w- C:\windows\SysWow64\crypt32.dll
2013-10-01 23:37:53 2035712 ----a-w- C:\windows\SysWow64\authui.dll
2013-10-01 23:26:49 1890816 ----a-w- C:\windows\System32\crypt32.dll
2013-10-01 23:26:45 2304512 ----a-w- C:\windows\System32\authui.dll
2013-10-01 22:22:19 1022976 ----a-w- C:\windows\SysWow64\gdi32.dll
.
============= FINISH: 22:35:28.82 ===============
We also have an attach log, but instructed not to post it.
Lastly, I spoke to microsoft about the issue and they recommended using their expensive yet 'money back guaranteed' services whereby they will manually remove the virus/malware using remote access. If you guys can help me out, I would rather that than paying $99 or $149!
Thanks a lot
For around a week and a half we have been having trouble on our relatively new however out of warranty (I.e. 5 months) desktop computer.
A common browser hijacker: feed.helperbar.com, was discovered about 12 days ago on all 4 users on Chrome and Firefox. Antivirus removal attempts failed, and eventually another issue came onto some of the users: You could not open or close any programs (except File Explorer) or run Ctr+Alt+Del (so you could not access task manager) and when you tried to switch user, you were greeted by a black and blank screen. The only other option was to completely turn off the PC by the mains.
We also attempted to perform a system restore, but discovered that there were no restore points available until after the infection.

After backing up to an external hard drive, we realised that the virus may in fact be infected on that, too, since it was backed up after the infection.
The next step was Malwarebytes. Here is the log from one of the full scans (if you need a quick scan log, please ask, we have one too)
Malwarebytes Anti-Malware (Trial) 1.75.0.1300
www.malwarebytes.org
Database version: v2013.12.29.03
Windows 8 x64 NTFS
Internet Explorer 10.0.9200.16750
sarah :: DESKTOP [administrator]
Protection: Enabled
29/12/2013 18:37:23
MBAM-log-2013-12-29 (20-04-02).txt
Scan type: Full scan (C:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 657644
Time elapsed: 1 hour(s), 20 minute(s), 25 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 4
C:\__COPY\copyFred\Downloads\iLividSetupV1(1).exe (PUP.Optional.Bandoo) -> No action taken.
C:\__COPY\copyFred\Downloads\iLividSetupV1.exe (PUP.Optional.Bandoo) -> No action taken.
C:\__COPY\copyGeorge\Downloads\CoolMP3ToAACConverterSetup.exe (PUP.Adware.RKN) -> No action taken.
C:\__COPY\copyGeorge\Downloads\Setup_FreeConverter.exe (PUP.Optional.Bandoo.A) -> No action taken.
(end)
Then we tried a DDS scan:
DDS
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.16537 BrowserJavaVersion: 10.45.2
Run by sarah at 22:33:24 on 2013-12-29
Microsoft Windows 8 6.2.9200.0.1252.44.2057.18.8087.6038 [GMT 0:00]
.
AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {ADA629C7-7F48-5689-624A-3B76997E0892}
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {16C7C823-5972-5907-58FA-0004E2F9422F}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: McAfee Firewall *Enabled* {959DA8E2-3527-57D1-4915-924367AD4FE9}
.
============== Running Processes ===============
.
C:\windows\system32\svchost.exe -k DcomLaunch
C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE
C:\windows\system32\nvvsvc.exe
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\system32\dwm.exe
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Program Files\IDT\WDM\STacSV64.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\windows\system32\nvvsvc.exe
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\windows\system32\svchost.exe -k apphost
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\windows\system32\dashost.exe
C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\WinTV\TVServer\CaptureGenUSB.exe
C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
C:\Program Files\McAfee\AppStats\MfeASUM.exe
C:\windows\system32\mfevtps.exe
C:\windows\system32\rundll32.exe
C:\windows\system32\rundll32.exe
C:\windows\SysWOW64\NlsSrv32.exe
C:\windows\SysWOW64\rundll32.exe
C:\windows\system32\svchost.exe -k imgsvc
C:\Program Files\McAfee\MSC\McAPExe.exe
C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\windows\system32\taskhostex.exe
C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe
C:\windows\System32\svchost.exe -k LocalServicePeerNet
C:\windows\Explorer.EXE
C:\windows\system32\taskeng.exe
C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler.exe
C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler64.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\LiveComm.exe
C:\windows\system32\SearchIndexer.exe
c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
C:\Windows\System32\RuntimeBroker.exe
C:\Program Files\IDT\WDM\Beats64.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files (x86)\Samsung\Kies\Kies.exe
C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe
C:\Program Files (x86)\Garmin\ANT Agent\ANT Agent.exe
C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe
C:\Program Files (x86)\WinTV\WinTV7\WinTVTray.exe
C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
C:\windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\BATINDICATOR.exe
C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\BATINDICATOR_HIDList.exe
C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\CNYHKEY.exe
C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\APSDaemon.exe
C:\Program Files\Common Files\McAfee\Platform\mcuicnt.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
c:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteService.exe
C:\Program Files (x86)\McAfee Online Backup\MOBKbackup.exe
C:\Program Files (x86)\McAfee Online Backup\MOBKbackup.exe
C:\windows\system32\vssvc.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\windows\System32\cscript.exe
C:\windows\SysWOW64\netsh.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uSearch Bar = hxxp://www.google.com/ie
uSearch Page = hxxp://www.google.com
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mWinlogon: Userinit = userinit.exe,
BHO: MSS+ Identifier: {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.130\McAfeeMSS_IE.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: McAfee SiteAdvisor BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO: HP Network Check Helper: {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
TB: McAfee SiteAdvisor Toolbar: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll
uRun: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload
uRun: [KiesAirMessage] C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup
uRun: [ANT Agent] C:\Program Files (x86)\Garmin\ANT Agent\ANT Agent.exe
uRun: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
uRun: [ApplePhotoStreams] C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
mRun: [BATINDICATOR] C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\BATINDICATOR.exe
mRun: [BATINDICATORHL] C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\BATINDICATOR_HIDList.exe
mRun: [OSDTool] C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\CNYHKEY.exe
mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
mRun: [BingDesktop] C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe /fromkey
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [mcpltui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
StartupFolder: C:\Users\sarah\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ONENOT~1.LNK - C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\StartUp\MCAFEE~1.LNK - C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\StartUp\WINTVR~1.LNK - C:\Program Files (x86)\WinTV\WinTV7\WinTVTray.exe
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
TCP: NameServer = 192.168.1.254 192.168.1.254
TCP: Interfaces\{C78E59CE-E374-45F7-9183-6DBA27383EC7} : DHCPNameServer = 192.168.1.254 192.168.1.254
TCP: Interfaces\{FB33815A-B733-4E7B-8B5F-6A2E595E8F63} : DHCPNameServer = 192.168.1.254 192.168.1.254
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: McAfee SiteAdvisor BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll
x64-BHO: HP Network Check Helper: {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll
x64-TB: McAfee SiteAdvisor Toolbar: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll
x64-Run: [BeatsOSDApp] C:\Program Files\IDT\WDM\beats64.exe
x64-Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe
x64-RunOnce: [NCPluginUpdater] "C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" Update
x64-IE: {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
x64-Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl64.dll
x64-Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll
x64-Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - <orphaned>
x64-Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\sarah\AppData\Roaming\Mozilla\Firefox\Profiles\f9jbdcic.default\
FF - prefs.js: browser.startup.homepage - hxxps://www.google.co.uk
FF - prefs.js: keyword.URL - hxxp://uk.search.yahoo.com/search?fr=mcafee&p=
FF - plugin: c:\PROGRA~2\mcafee\msc\npMcSnFFPl.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\McAfee\SiteAdvisor\NPMcFFPlg32.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Program Files\McAfee Security Scan\3.8.130\npMcAfeeMSS.dll
FF - plugin: C:\Users\sarah\AppData\Roaming\Mozilla\Firefox\Profiles\f9jbdcic.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins\npGarmin.dll
FF - plugin: C:\windows\SysWOW64\Adobe\Director\np32dsw_1202122.dll
FF - plugin: C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll
.
============= SERVICES / DRIVERS ===============
.
R0 amd_sata;amd_sata;C:\windows\System32\Drivers\amd_sata.sys [2013-3-31 80552]
R0 amd_xata;amd_xata;C:\windows\System32\Drivers\amd_xata.sys [2013-3-31 26280]
R1 CLVirtualDrive;CLVirtualDrive;C:\windows\System32\Drivers\CLVirtualDrive.sys [2013-5-23 92536]
R3 cfwids;McAfee Inc. cfwids;C:\windows\System32\Drivers\cfwids.sys [2013-6-17 70112]
R3 hcw17bda;Hauppauge SMS1000-based;C:\windows\System32\Drivers\hcw17b64.sys [2012-10-23 78192]
S2 EsgScanner;EsgScanner;C:\windows\System32\Drivers\EsgScanner.sys [2013-12-19 22704]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);C:\windows\System32\Drivers\ssudbus.sys [2013-10-28 107288]
S3 esgiguard;esgiguard;C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [2011-3-2 13088]
S3 HipShieldK;McAfee Inc. HipShieldK;C:\windows\System32\Drivers\HipShieldK.sys [2013-10-15 197704]
.
=============== Created Last 30 ================
.
2013-12-29 12:54:03 25928 ----a-w- C:\windows\System32\drivers\mbam.sys
2013-12-29 12:54:03 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-12-29 12:29:11 -------- d-----w- C:\Users\sarah\AppData\Roaming\Malwarebytes
2013-12-29 12:28:42 -------- d-----w- C:\ProgramData\Malwarebytes
2013-12-19 18:53:44 -------- d-----w- C:\Users\sarah\AppData\Local\CrashDumps
2013-12-19 14:37:30 22704 ----a-w- C:\windows\System32\drivers\EsgScanner.sys
2013-12-19 14:37:28 110080 ----a-r- C:\Users\sarah\AppData\Roaming\Microsoft\Installer\{CD09642E-061D-4844-BA37-ED1480916404}\IconF7A21AF7.exe
2013-12-19 14:37:28 110080 ----a-r- C:\Users\sarah\AppData\Roaming\Microsoft\Installer\{CD09642E-061D-4844-BA37-ED1480916404}\IconD7F16134.exe
2013-12-19 14:37:28 110080 ----a-r- C:\Users\sarah\AppData\Roaming\Microsoft\Installer\{CD09642E-061D-4844-BA37-ED1480916404}\Icon1226A4C5.exe
2013-12-19 14:37:26 -------- d-----w- C:\sh4ldr
2013-12-19 14:37:26 -------- d-----w- C:\Program Files\Enigma Software Group
2013-12-19 14:36:54 -------- d-----w- C:\windows\CD09642E061D4844BA37ED1480916404.TMP
2013-12-19 14:36:53 -------- d-----w- C:\Program Files (x86)\Common Files\Wise Installation Wizard
2013-12-19 14:04:04 -------- d-----w- C:\ProgramData\SMR410
2013-12-19 14:03:05 -------- d-----w- C:\Users\sarah\AppData\Local\NPE
2013-12-18 19:35:44 344064 ----a-w- C:\windows\SysWow64\msvcr70.dll
2013-12-15 22:45:01 -------- d-sh--w- C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
2013-12-15 22:45:01 -------- d--h--w- C:\ProgramData\Common Files
2013-12-15 22:42:35 -------- d-----w- C:\Users\sarah\AppData\Local\Programs
2013-12-14 11:54:15 23350272 ----a-w- C:\Program Files\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll
2013-12-14 11:54:13 22615040 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll
2013-12-13 00:54:31 62976 ----a-w- C:\windows\System32\imagehlp.dll
2013-12-13 00:53:45 222720 ----a-w- C:\windows\System32\scrobj.dll
2013-12-13 00:53:45 194048 ----a-w- C:\windows\System32\scrrun.dll
2013-12-13 00:53:45 162304 ----a-w- C:\windows\SysWow64\scrobj.dll
2013-12-13 00:53:45 156160 ----a-w- C:\windows\SysWow64\scrrun.dll
2013-12-13 00:53:45 146944 ----a-w- C:\windows\System32\cscript.exe
2013-12-13 00:53:45 143872 ----a-w- C:\windows\System32\wshom.ocx
2013-12-13 00:53:45 115712 ----a-w- C:\windows\SysWow64\cscript.exe
2013-12-13 00:53:41 420864 ----a-w- C:\windows\System32\WMPhoto.dll
2013-12-13 00:53:41 368640 ----a-w- C:\windows\SysWow64\WMPhoto.dll
2013-12-13 00:53:38 4036608 ----a-w- C:\windows\System32\win32k.sys
2013-12-13 00:53:26 288768 ----a-w- C:\windows\System32\drivers\portcls.sys
2013-12-13 00:53:25 312320 ----a-w- C:\windows\System32\msieftp.dll
2013-12-13 00:53:25 273408 ----a-w- C:\windows\SysWow64\msieftp.dll
2013-12-07 00:28:33 -------- d-----w- C:\Program Files (x86)\MyFree Codec
2013-12-06 23:48:18 -------- d-----w- C:\Program Files (x86)\MarkAny
.
==================== Find3M ====================
.
2013-12-04 00:53:54 78304 ----a-w- C:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-12-04 00:53:54 694240 ----a-w- C:\windows\SysWow64\FlashPlayerApp.exe
2013-11-26 22:07:44 10856 ----a-w- C:\windows\System32\drivers\mfeclnrk.sys
2013-11-26 22:07:22 96112 ----a-w- C:\windows\System32\drivers\mfencrk.sys
2013-11-26 22:07:02 411944 ----a-w- C:\windows\System32\drivers\mfencbdc.sys
2013-11-04 16:51:44 70112 ----a-w- C:\windows\System32\drivers\cfwids.sys
2013-11-04 16:46:34 343696 ----a-w- C:\windows\System32\drivers\mfewfpk.sys
2013-11-04 16:46:16 182752 ----a-w- C:\windows\System32\mfevtps.exe
2013-11-04 16:43:04 782360 ----a-w- C:\windows\System32\drivers\mfehidk.sys
2013-11-04 16:41:22 519576 ----a-w- C:\windows\System32\drivers\mfefirek.sys
2013-11-04 16:40:00 311120 ----a-w- C:\windows\System32\drivers\mfeavfk.sys
2013-11-04 16:39:20 179792 ----a-w- C:\windows\System32\drivers\mfeapfk.sys
2013-11-04 16:28:52 69344 ----a-w- C:\windows\System32\drivers\mfeelamk.sys
2013-10-28 01:12:12 204568 ----a-w- C:\windows\System32\drivers\ssudmdm.sys
2013-10-28 01:12:10 107288 ----a-w- C:\windows\System32\drivers\ssudbus.sys
2013-10-25 06:19:22 2241536 ----a-w- C:\windows\System32\wininet.dll
2013-10-25 06:19:12 915968 ----a-w- C:\windows\System32\uxtheme.dll
2013-10-25 06:17:57 3959808 ----a-w- C:\windows\System32\jscript9.dll
2013-10-25 04:45:11 1767936 ----a-w- C:\windows\SysWow64\wininet.dll
2013-10-25 04:43:42 2877952 ----a-w- C:\windows\SysWow64\jscript9.dll
2013-10-19 04:04:07 59392 ----a-w- C:\windows\SysWow64\imagehlp.dll
2013-10-10 11:53:35 96600 ----a-w- C:\windows\System32\drivers\wfplwfs.sys
2013-10-10 09:21:20 1160192 ----a-w- C:\windows\System32\IKEEXT.DLL
2013-10-10 09:20:43 723968 ----a-w- C:\windows\System32\BFE.DLL
2013-10-08 22:30:32 35328 ----a-w- C:\windows\SysWow64\wuapp.exe
2013-10-08 22:30:17 84992 ----a-w- C:\windows\SysWow64\wudriver.dll
2013-10-08 22:30:17 126976 ----a-w- C:\windows\SysWow64\wuwebv.dll
2013-10-08 22:28:11 40448 ----a-w- C:\windows\System32\wuapp.exe
2013-10-08 22:27:56 99328 ----a-w- C:\windows\System32\wudriver.dll
2013-10-08 22:27:56 252928 ----a-w- C:\windows\System32\WUSettingsProvider.dll
2013-10-08 22:27:56 1622016 ----a-w- C:\windows\System32\wucltux.dll
2013-10-08 22:27:56 142848 ----a-w- C:\windows\System32\wuwebv.dll
2013-10-08 22:27:45 175104 ----a-w- C:\windows\System32\storewuauth.dll
2013-10-08 07:50:37 96168 ----a-w- C:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-10-05 06:10:20 285016 ----a-w- C:\windows\System32\drivers\spaceport.sys
2013-10-02 23:25:41 1300992 ----a-w- C:\windows\System32\gdi32.dll
2013-10-02 02:50:07 447320 ----a-w- C:\windows\System32\drivers\USBHUB3.SYS
2013-10-01 23:37:57 1569280 ----a-w- C:\windows\SysWow64\crypt32.dll
2013-10-01 23:37:53 2035712 ----a-w- C:\windows\SysWow64\authui.dll
2013-10-01 23:26:49 1890816 ----a-w- C:\windows\System32\crypt32.dll
2013-10-01 23:26:45 2304512 ----a-w- C:\windows\System32\authui.dll
2013-10-01 22:22:19 1022976 ----a-w- C:\windows\SysWow64\gdi32.dll
.
============= FINISH: 22:35:28.82 ===============
We also have an attach log, but instructed not to post it.
Lastly, I spoke to microsoft about the issue and they recommended using their expensive yet 'money back guaranteed' services whereby they will manually remove the virus/malware using remote access. If you guys can help me out, I would rather that than paying $99 or $149!
Thanks a lot