Hi Brent! Welcome to the forums!!
My secret agent name on the forums is
SweetTech (you can call me Agent ST for short), it's a pleasure to meet you.
I would be glad to take a look at your log and help you with solving any malware problems.
If you have since resolved the issues you were originally experiencing, or have received help elsewhere, please inform me so that this topic can be closed. If you have not, please adhere to the guidelines below and then follow instructions as outlined further below:
- Logs from malware removal programs (OTL is one of them) can take some time to analyze. I need you to be patient while I analyze any logs you post. Please remember, I am a volunteer, and I do have a life outside of these forums.
- Please make sure to carefully read any instruction that I give you. Attention to detail is important! Since I cannot see or directly interact with your computer I am dependent on you to "be my eyes" and provide as much information as you can regarding the current state of your computer.
- If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
- In Windows Vista and Windows 7, all tools need to be started by right clicking and selecting Run as Administrator!
- If I instruct you to download a specific tool in which you already have, please delete the copy that you have and re-download the tool. The reason I ask you to do this is because these tools are updated fairly regularly.
- Do not do things I do not ask for, such as running a spyware scan on your computer. The one thing that you should always do, is to make sure sure that your anti-virus definitions are up-to-date!
- Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
- I am going to stick with you until ALL malware is gone from your system. I would appreciate it if you would do the same. From this point, we're in this together
Because of this, you must reply within three days failure to reply will result in the topic being closed!
- Lastly, I am no magician. I will try very hard to fix your issues, but no promises can be made. Also be aware that some infections are so severe that you might need to resort to reformatting and reinstalling your operating system.
Don't worry, this only happens in severe cases, but it sadly does happen. Be prepared to back up your data. Have means of backing up your data available.
____________________________________________________
Running OTS FixStart OTS Copy/Paste the information inside the codebox below into the panel where it says "Paste fix here" and then click the
Run Fix button.
[Kill Explorer]
[Unregister Dlls]
[Processes - Safe List]
YY -> xti.exe -> C:\Users\cody\AppData\Local\xti.exe
[Win32 Services - Safe List]
YN -> (RelevantKnowledge) RelevantKnowledge [Auto | Stopped] ->
[Registry - Safe List]
< FireFox Settings [Prefs.js] > -> C:\Users\cody\AppData\Roaming\Mozilla\FireFox\Profiles\cr28hxdp.default\prefs.js
YN -> extensions.enabledItems -> {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
YN -> extensions.enabledItems -> {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
YN -> extensions.enabledItems -> {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
YN -> extensions.enabledItems -> {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
YN -> extensions.enabledItems -> {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
YN -> {5C255C8A-E604-49b4-9D64-90988571CECB} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar
YN -> "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" [HKLM] -> [Yahoo! Toolbar]
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\
YN -> WebBrowser\\"{D0523BB4-21E7-11DD-9AB7-415B56D89593}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
YN -> WebBrowser\\"{D4027C7F-154A-4066-A1AD-4243D8127440}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
< Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
YN -> "ISUSPM" -> [C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe -scheduler]
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\
YN -> {8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab [Java Plug-in 1.6.0_26]
YN -> {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab [Java Plug-in 1.6.0_05]
YN -> {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab [Java Plug-in 1.6.0_26]
YN -> {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab [Java Plug-in 1.6.0_26]
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2
YN -> \{9bdabf0c-9871-11de-9b83-001f1655757f}\shell\AutoRun\command\\"" -> [F:\Setup.exe]
YN -> \{9bdabf0c-9871-11de-9b83-001f1655757f} ->
YN -> \{9bdabf0c-9871-11de-9b83-001f1655757f}\shell\Install\command\\"" -> [F:\Setup.exe]
< Registry Shell Spawning - Select to Repair > -> HKEY_CURRENT_USER\SOFTWARE\Classes\<key>\shell\[command]\command
YN -> exefile [open] -> "C:\Users\cody\AppData\Local\xti.exe" -a "%1" %*
< File Associations - Select to Repair > -> HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>\
YY -> .exe [@ = exefile] -> C:\Users\cody\AppData\Local\xti.exe
[Files/Folders - Created Within 30 Days]
NY -> xti.exe -> C:\Users\cody\AppData\Local\xti.exe
[Files/Folders - Modified Within 30 Days]
NY -> w4bv85b1ha6atq -> C:\ProgramData\w4bv85b1ha6atq
NY -> w4bv85b1ha6atq -> C:\Users\cody\AppData\Local\w4bv85b1ha6atq
[Files - No Company Name]
NY -> w4bv85b1ha6atq -> C:\Users\cody\AppData\Local\w4bv85b1ha6atq
NY -> w4bv85b1ha6atq -> C:\ProgramData\w4bv85b1ha6atq
[Alternate Data Streams]
NY -> @Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:206E2596
NY -> @Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:0FF263E8
[Empty Temp Folders]
[EmptyFlash]
[CreateRestorePoint]
The fix should only take a very short time. When the fix is completed a message box will popup either telling you that it is finished, or that a reboot is needed to complete the fix. If the fix is complete, click the
Ok button and Notepad will open with a log of actions taken during the fix. Post that log back here in your next reply.
If a reboot is required, click the "Yes" button to reboot the machine. After the reboot, OTS will finish moving any files that could not be moved during the fix and NotePad will open with the final results at that time. Post that log back here in your next reply.
NEXT:Scanning with GMERBefore scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.
Download
GMER Rootkit Scanner from
here or
here.
- Extract the contents of the zipped file to desktop.
- Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
- If it gives you a warning about rootkit activity and asks if you want to run scan...click on NO.
Click the image to enlarge it
- In the right panel, you will see several boxes that have been checked. Uncheck the following ...
- IAT/EAT
- Drives/Partition other than Systemdrive (typically C:\)
- Show All (don't miss this one)
- Then click the Scan button & wait for it to finish.
- Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
- Save it where you can easily find it, such as your desktop, and attach it in your reply.
Notes:**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries -- If you encounter any problems, try running GMER in safe mode.
-- If GMER crashes or keeps resulting in a BSODs, uncheck Devices on the right side before scanning.
NEXT:What issues are you currently experiencing with your computer?