Trojan.DNSChanger and SearchScopes

Page 1 of 2 1, 2  Next

View previous topic View next topic Go down

Trojan.DNSChanger and SearchScopes

Post by DarrenC on Thu Mar 26, 2015 6:13 pm

# AdwCleaner v4.113 - Logfile created 26/03/2015 at 09:38:35
# Updated 22/03/2015 by Xplode
# Database : 2015-03-23.1 [Server]
# Operating system : Windows 8.1  (x64)
# Username : Michelle - MICHELLE-LAPTOP
# Running from : C:\Users\Michelle\Downloads\adwcleaner_4.113.exe
# Option : Cleaning

***** [ Services ] *****


***** [ Files / Folders ] *****


***** [ Scheduled tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{A25AC313-DD19-4238-ACA2-401D6BEE4321}

***** [ Web browsers ] *****

#NAME?


-\\ Mozilla Firefox v36.0.4 (x86 en-US)


#NAME?


*************************

AdwCleaner[R0].txt - [2864 bytes] - [06/11/2014 13:57:52]
AdwCleaner[R10].txt - [3914 bytes] - [25/03/2015 07:03:04]
AdwCleaner[R11].txt - [2025 bytes] - [25/03/2015 07:14:17]
AdwCleaner[R12].txt - [2144 bytes] - [25/03/2015 07:22:14]
AdwCleaner[R13].txt - [2263 bytes] - [25/03/2015 07:31:11]
AdwCleaner[R14].txt - [2384 bytes] - [25/03/2015 07:38:42]
AdwCleaner[R15].txt - [2504 bytes] - [25/03/2015 07:45:48]
AdwCleaner[R16].txt - [2624 bytes] - [25/03/2015 07:52:26]
AdwCleaner[R17].txt - [2744 bytes] - [25/03/2015 08:00:31]
AdwCleaner[R18].txt - [8420 bytes] - [25/03/2015 12:50:11]
AdwCleaner[R19].txt - [2984 bytes] - [25/03/2015 13:00:33]
AdwCleaner[R1].txt - [1061 bytes] - [06/11/2014 14:44:30]
AdwCleaner[R20].txt - [4127 bytes] - [25/03/2015 13:31:00]
AdwCleaner[R21].txt - [3164 bytes] - [25/03/2015 13:51:55]
AdwCleaner[R22].txt - [4295 bytes] - [25/03/2015 18:40:21]
AdwCleaner[R23].txt - [4355 bytes] - [25/03/2015 18:43:21]
AdwCleaner[R24].txt - [3464 bytes] - [25/03/2015 19:02:10]
AdwCleaner[R25].txt - [3584 bytes] - [25/03/2015 20:07:33]
AdwCleaner[R26].txt - [3704 bytes] - [26/03/2015 08:50:29]
AdwCleaner[R27].txt - [3764 bytes] - [26/03/2015 08:53:47]
AdwCleaner[R28].txt - [3824 bytes] - [26/03/2015 09:08:37]
AdwCleaner[R2].txt - [2041 bytes] - [12/11/2014 14:52:06]
AdwCleaner[R3].txt - [1085 bytes] - [12/11/2014 15:09:50]
AdwCleaner[R4].txt - [8259 bytes] - [24/03/2015 11:15:43]
AdwCleaner[R5].txt - [1372 bytes] - [24/03/2015 11:30:07]
AdwCleaner[R6].txt - [1431 bytes] - [24/03/2015 11:39:29]
AdwCleaner[R7].txt - [11126 bytes] - [24/03/2015 14:03:22]
AdwCleaner[R8].txt - [2761 bytes] - [24/03/2015 15:35:24]
AdwCleaner[R9].txt - [3221 bytes] - [25/03/2015 06:56:29]
AdwCleaner[S0].txt - [2760 bytes] - [06/11/2014 14:00:09]
AdwCleaner[S10].txt - [2333 bytes] - [25/03/2015 07:31:27]
AdwCleaner[S11].txt - [2453 bytes] - [25/03/2015 07:38:55]
AdwCleaner[S12].txt - [2573 bytes] - [25/03/2015 07:46:07]
AdwCleaner[S13].txt - [2693 bytes] - [25/03/2015 07:53:13]
AdwCleaner[S14].txt - [2813 bytes] - [25/03/2015 08:01:31]
AdwCleaner[S15].txt - [8525 bytes] - [25/03/2015 12:52:20]
AdwCleaner[S16].txt - [4202 bytes] - [25/03/2015 13:40:26]
AdwCleaner[S17].txt - [3233 bytes] - [25/03/2015 14:02:31]
AdwCleaner[S18].txt - [4428 bytes] - [25/03/2015 18:43:30]
AdwCleaner[S19].txt - [3533 bytes] - [25/03/2015 19:03:58]
AdwCleaner[S1].txt - [2128 bytes] - [12/11/2014 14:55:27]
AdwCleaner[S20].txt - [3653 bytes] - [26/03/2015 06:22:14]
AdwCleaner[S21].txt - [3275 bytes] - [26/03/2015 09:38:35]
AdwCleaner[S2].txt - [8190 bytes] - [24/03/2015 11:21:29]
AdwCleaner[S3].txt - [1499 bytes] - [24/03/2015 12:01:00]
AdwCleaner[S4].txt - [10551 bytes] - [24/03/2015 14:38:47]
AdwCleaner[S5].txt - [2835 bytes] - [24/03/2015 15:42:14]
AdwCleaner[S6].txt - [3309 bytes] - [25/03/2015 06:57:01]
AdwCleaner[S7].txt - [3999 bytes] - [25/03/2015 07:07:31]
AdwCleaner[S8].txt - [2093 bytes] - [25/03/2015 07:14:43]
AdwCleaner[S9].txt - [2212 bytes] - [25/03/2015 07:23:23]

########## EOF - C:\AdwCleaner\AdwCleaner[S21].txt - [3808  bytes] ##########




Malwarebytes Anti-Malware

Scan Date: 3/26/2015
Scan Time: 9:46:23 AM
Logfile:
Administrator: Yes

Version: 2.01.4.1018
Malware Database: v2015.03.26.05
Rootkit Database: v2015.02.25.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 8.1
CPU: x64
File System: NTFS
User: Michelle

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 367136
Time Elapsed: 36 min, 41 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 1
Trojan.DNSChanger, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS\Interfaces\{5EA0F310-66E7-47DE-8308-90A94C0279A0}|NameServer, 31.168.228.251,82.166.96.251, Good: (), Bad: (31.168.228.251,82.166.96.251),,[c954ef5b880263d3a8518d6c3acbf30d]

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)


(end)







No matter how many times I run these scans, these 2 things keep coming back and I'm not sure how to get rid of them...

DarrenC
Novice
Novice

Posts Posts : 34
Joined Joined : 2015-03-26
OS OS : Windows 8.1
Points Points : 6698
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Trojan.DNSChanger and SearchScopes

Post by Superdave on Thu Mar 26, 2015 6:31 pm

Hello and welcome to GeekPolice.Net My name is Dave. I will be helping you out with your particular problem on your computer.

1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
2. The fixes are specific to your problem and should only be used for this issue on this machine.
3. If you don't know or understand something, please don't hesitate to ask.
4. Please DO NOT run any other tools or scans while I am helping you.
5. It is important that you reply to this thread. Do not start a new topic.
6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
7. Absence of symptoms does not mean that everything is clear.

If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line.
*************************************************************************

After you run MBAM are you cleaning the infections?
*************************************************
Please download [You must be registered and logged in to see this link.] to your desktop.

Warning! Once the scan is complete JRT will shut down your browser with NO warning.

Shut down your protection software now to avoid potential conflicts.

•Temporarily disable your Antivirus and any Antispyware real time protection before performing a scan. Click [You must be registered and logged in to see this link.] link to see a list of security programs that should be disabled and how to disable them.

•Run the tool by double-clicking it. If you are using Windows Vista or Windows 7, right-click JRT and select Run as Administrator

•The tool will open and start scanning your system.

•Please be patient as this can take a while to complete depending on your system's specifications.

•On completion, a log (JRT.txt) is saved to your desktop and will automatically open.

•Copy and Paste the JRT.txt log into your next message.
*****************************************
Download Security Check by screen317 from one of the following links and save it to your desktop.

[You must be registered and logged in to see this link.]
[You must be registered and logged in to see this link.]

* Double-click Security Check.bat
* Follow the on-screen instructions inside of the black box.
* A Notepad document should open automatically called checkup.txt
* Post the contents of that document in your next reply.
***************************************************************
Malwarebytes' Anti-Rootkit

Please download [You must be registered and logged in to see this link.] and save it to your desktop.

  • Be sure to print out and follow the instructions provided on that same page for performing a scan.
  • Caution: This is a beta version so also read the disclaimer and [You must be registered and logged in to see this link.] all your data before using.
  • When the scan completes, click on the Cleanup button to remove any threats found and reboot the computer if prompted to do so.
  • Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
  • If there are problems with Internet access, Windows Update, Windows Firewall or other system issues, run the fixdamage tool located in the folder Malwarebytes Anti-Rootkit was run from and reboot your computer.
  • Two files (mbar-log-YYYY-MM-DD, system-log.txt) will be created and saved within that same folder.
  • Copy and paste the contents of these two log files in your next reply.


Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.

Superdave
Captain
Captain

Posts Posts : 4202
Joined Joined : 2010-02-01
Gender Gender : Male
OS OS : Windows 8.1 and a dual-boot with XP Home SP3
Protection Protection : MSE, Windows Defender, Windows firewall
Points Points : 83171
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Trojan.DNSChanger and SearchScopes

Post by DarrenC on Thu Mar 26, 2015 11:02 pm

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.6 (03.22.2015:1)
OS: Windows 8.1 x64
Ran by Michelle on Thu 03/26/2015 at 12:30:22.52
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders



~~~ FireFox

Successfully deleted the following from C:\Users\Michelle\AppData\Roaming\mozilla\firefox\profiles\thf2gyrq.default\prefs.js

user_pref("extensions.xpiState", "{\"app-profile\":{\"\":{\"d\":\"C:\\\\Users\\\\Michelle\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Pro



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Thu 03/26/2015 at 12:53:15.55
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~



Results of screen317's Security Check version 0.99.99  
  x64 (UAC is enabled)  
Internet Explorer 11  
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!  
Windows Defender  
WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
Junk Cleaner    
Java 8 Update 40  
Adobe Reader XI  
Mozilla Firefox (36.0.4)
Google Chrome 37.0.2062.120 Google Chrome out of date!  
````````Process Check: objlist.exe by Laurent````````  
Windows Defender MSMpEng.exe
IObit IObit Malware Fighter IMFsrv.exe  
IObit IObit Malware Fighter IMF.exe  
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:  %
````````````````````End of Log``````````````````````


Malwarebytes Anti-Rootkit BETA 1.09.1.1004

Database version:
 main:    v2015.03.26.07
 rootkit: v2015.03.26.01

Windows 8.1 x64 NTFS
Internet Explorer 11.0.9600.17690
Michelle :: MICHELLE-LAPTOP [administrator]

3/26/2015 15:26
mbar-log-2015-03-26 (15-26-30).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 369239
Time elapsed: 33 minute(s), 2 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

Physical Sectors Detected: 0
(No malicious items detected)

(end)

---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.09.1.1004

(c) Malwarebytes Corporation 2011-2012

OS version: 6.3.9200 Windows 8.1 x64

Account is Administrative

Internet Explorer version: 11.0.9600.17690

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED, D:\ DRIVE_FIXED
CPU speed: 2.167000 GHz
Memory total: 8472772608, free: 5476102144

Downloaded database version: v2015.03.26.07
Downloaded database version: v2015.03.26.01
Downloaded database version: v2015.03.09.01
=======================================
Initializing...
------------ Kernel report ------------
    03/26/2015 14:46:04
------------ Loaded modules -----------
\SystemRoot\system32\ntoskrnl.exe
\SystemRoot\system32\hal.dll
\SystemRoot\system32\kd.dll
\SystemRoot\system32\mcupdate_GenuineIntel.dll
\SystemRoot\System32\drivers\werkernel.sys
\SystemRoot\System32\drivers\CLFS.SYS
\SystemRoot\System32\drivers\tm.sys
\SystemRoot\system32\PSHED.dll
\SystemRoot\system32\BOOTVID.dll
\SystemRoot\system32\CI.dll
\SystemRoot\System32\drivers\msrpc.sys
\SystemRoot\system32\drivers\Wdf01000.sys
\SystemRoot\system32\drivers\WDFLDR.SYS
\SystemRoot\System32\Drivers\acpiex.sys
\SystemRoot\System32\Drivers\WppRecorder.sys
\SystemRoot\System32\drivers\ACPI.sys
\SystemRoot\System32\drivers\WMILIB.SYS
\SystemRoot\System32\Drivers\cng.sys
\SystemRoot\System32\drivers\msisadrv.sys
\SystemRoot\System32\drivers\pci.sys
\SystemRoot\System32\drivers\vdrvroot.sys
\SystemRoot\system32\drivers\pdc.sys
\SystemRoot\System32\drivers\partmgr.sys
\SystemRoot\System32\drivers\spaceport.sys
\SystemRoot\System32\drivers\volmgr.sys
\SystemRoot\System32\drivers\volmgrx.sys
\SystemRoot\System32\drivers\mountmgr.sys
\SystemRoot\System32\drivers\storahci.sys
\SystemRoot\System32\drivers\storport.sys
\SystemRoot\system32\drivers\fltmgr.sys
\SystemRoot\System32\drivers\fileinfo.sys
\SystemRoot\System32\Drivers\Wof.sys
\SystemRoot\system32\drivers\WdFilter.sys
\SystemRoot\System32\Drivers\Ntfs.sys
\SystemRoot\System32\Drivers\ksecdd.sys
\SystemRoot\System32\drivers\MBI.sys
\SystemRoot\System32\drivers\pcw.sys
\SystemRoot\System32\Drivers\Fs_Rec.sys
\SystemRoot\system32\drivers\ndis.sys
\SystemRoot\system32\drivers\NETIO.SYS
\SystemRoot\System32\Drivers\ksecpkg.sys
\SystemRoot\System32\drivers\tcpip.sys
\SystemRoot\System32\drivers\fwpkclnt.sys
\SystemRoot\system32\DRIVERS\wfplwfs.sys
\SystemRoot\System32\DRIVERS\fvevol.sys
\SystemRoot\System32\drivers\volsnap.sys
\SystemRoot\System32\Drivers\SmartDefragDriver.sys
\SystemRoot\System32\drivers\rdyboost.sys
\SystemRoot\System32\Drivers\mup.sys
\SystemRoot\System32\drivers\intelpep.sys
\SystemRoot\System32\drivers\disk.sys
\SystemRoot\System32\drivers\CLASSPNP.SYS
\SystemRoot\System32\Drivers\crashdmp.sys
\SystemRoot\System32\drivers\cdrom.sys
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\System32\Drivers\Beep.SYS
\SystemRoot\System32\drivers\BasicRender.sys
\SystemRoot\System32\drivers\dxgkrnl.sys
\SystemRoot\System32\drivers\watchdog.sys
\SystemRoot\System32\drivers\dxgmms1.sys
\SystemRoot\System32\drivers\BasicDisplay.sys
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\system32\DRIVERS\tdx.sys
\SystemRoot\system32\DRIVERS\TDI.SYS
\SystemRoot\system32\drivers\ws2ifsl.sys
\SystemRoot\System32\DRIVERS\netbt.sys
\SystemRoot\system32\drivers\afd.sys
\SystemRoot\system32\DRIVERS\pacer.sys
\SystemRoot\system32\DRIVERS\vwififlt.sys
\SystemRoot\system32\DRIVERS\vfilter.sys
\SystemRoot\system32\DRIVERS\netbios.sys
\SystemRoot\system32\DRIVERS\rdbss.sys
\SystemRoot\system32\DRIVERS\wanarp.sys
\SystemRoot\system32\drivers\nsiproxy.sys
\SystemRoot\System32\drivers\npsvctrig.sys
\SystemRoot\System32\drivers\mssmbios.sys
\SystemRoot\System32\Drivers\dfsc.sys
\SystemRoot\system32\DRIVERS\ahcache.sys
\SystemRoot\System32\drivers\CompositeBus.sys
\SystemRoot\System32\drivers\serscan.sys
\SystemRoot\system32\drivers\ksthunk.sys
\SystemRoot\system32\drivers\ks.sys
\SystemRoot\system32\DRIVERS\kdnic.sys
\SystemRoot\System32\drivers\umbus.sys
\SystemRoot\system32\DRIVERS\igdkmd64.sys
\SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
\SystemRoot\System32\drivers\USBXHCI.SYS
\SystemRoot\System32\drivers\ucx01000.sys
\SystemRoot\System32\drivers\TXEIx64.sys
\SystemRoot\System32\drivers\HDAudBus.sys
\SystemRoot\system32\DRIVERS\rtwlane.sys
\SystemRoot\System32\drivers\vwifibus.sys
\SystemRoot\system32\DRIVERS\RtsP2Stor.sys
\SystemRoot\system32\DRIVERS\Rt630x64.sys
\SystemRoot\System32\drivers\serial.sys
\SystemRoot\System32\drivers\serenum.sys
\SystemRoot\System32\drivers\i8042prt.sys
\SystemRoot\system32\DRIVERS\SynTP.sys
\SystemRoot\system32\DRIVERS\USBD.SYS
\SystemRoot\System32\drivers\kbdclass.sys
\SystemRoot\System32\drivers\mouclass.sys
\SystemRoot\System32\Drivers\fastfat.SYS
\SystemRoot\System32\drivers\CmBatt.sys
\SystemRoot\System32\drivers\BATTC.SYS
\SystemRoot\system32\DRIVERS\Smb_driver_Intel.sys
\SystemRoot\System32\drivers\WirelessButtonDriver64.sys
\SystemRoot\System32\drivers\HIDCLASS.SYS
\SystemRoot\System32\drivers\HIDPARSE.SYS
\SystemRoot\System32\drivers\intelppm.sys
\SystemRoot\System32\drivers\iaiogpioe.sys
\SystemRoot\System32\Drivers\msgpioclx.sys
\SystemRoot\System32\drivers\msgpiowin32.sys
\SystemRoot\System32\drivers\wmiacpi.sys
\SystemRoot\System32\drivers\UEFI.sys
\SystemRoot\System32\drivers\NdisVirtualBus.sys
\SystemRoot\System32\drivers\swenum.sys
\SystemRoot\System32\drivers\iwdbus.sys
\SystemRoot\System32\drivers\rdpbus.sys
\SystemRoot\System32\drivers\UsbHub3.sys
\SystemRoot\system32\drivers\RTKVHD64.sys
\SystemRoot\system32\drivers\portcls.sys
\SystemRoot\system32\drivers\drmk.sys
\SystemRoot\system32\DRIVERS\IntcDAud.sys
\SystemRoot\System32\drivers\usbccgp.sys
\SystemRoot\system32\DRIVERS\usbscan.sys
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\drivers\usbprint.sys
\SystemRoot\System32\drivers\dc3d.sys
\SystemRoot\System32\drivers\hidusb.sys
\SystemRoot\System32\drivers\kbdhid.sys
\SystemRoot\System32\drivers\mouhid.sys
\SystemRoot\System32\Drivers\usbvideo.sys
\SystemRoot\System32\TSDDD.dll
\SystemRoot\System32\cdd.dll
\SystemRoot\System32\ATMFD.DLL
\SystemRoot\System32\drivers\monitor.sys
\SystemRoot\System32\Drivers\dump_diskdump.sys
\SystemRoot\System32\Drivers\dump_storahci.sys
\SystemRoot\System32\Drivers\dump_dumpfve.sys
\SystemRoot\system32\drivers\luafv.sys
\??\C:\Windows\system32\drivers\mbam.sys
\SystemRoot\system32\DRIVERS\lltdio.sys
\SystemRoot\system32\DRIVERS\nwifi.sys
\SystemRoot\system32\DRIVERS\ndisuio.sys
\SystemRoot\system32\DRIVERS\rspndr.sys
\SystemRoot\System32\drivers\condrv.sys
\SystemRoot\system32\drivers\HTTP.sys
\SystemRoot\system32\DRIVERS\bowser.sys
\SystemRoot\System32\drivers\mpsdrv.sys
\SystemRoot\system32\DRIVERS\mrxsmb.sys
\SystemRoot\system32\DRIVERS\mrxsmb20.sys
\SystemRoot\system32\DRIVERS\vwifimp.sys
\SystemRoot\system32\DRIVERS\mrxsmb10.sys
\SystemRoot\system32\drivers\Ndu.sys
\SystemRoot\system32\drivers\peauth.sys
\SystemRoot\System32\Drivers\secdrv.SYS
\SystemRoot\System32\DRIVERS\srvnet.sys
\SystemRoot\System32\drivers\tcpipreg.sys
\SystemRoot\System32\DRIVERS\srv2.sys
\SystemRoot\System32\DRIVERS\srv.sys
\SystemRoot\System32\drivers\ipnat.sys
\SystemRoot\system32\drivers\WudfPf.sys
\SystemRoot\System32\drivers\WUDFRd.sys
\SystemRoot\System32\drivers\WpdUpFltr.sys
\SystemRoot\system32\Drivers\WdNisDrv.sys
\??\C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys
\??\C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys
\??\C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys
\??\C:\Windows\system32\drivers\MBAMSwissArmy.sys
\SystemRoot\system32\DRIVERS\virtualnet.sys
\??\C:\Windows\system32\drivers\mbamchameleon.sys
----------- End -----------
Done!

Scan started
Database versions:
 main:    v2015.03.26.07
 rootkit: v2015.03.26.01

<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers...
File "C:\Windows\System32\drivers\1394ohci.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\1394ohci.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\acpi.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\acpi.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\acpipagr.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\acpipagr.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\acpipmi.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\acpipmi.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\acpitime.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\acpitime.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\AGP440.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\AGP440.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\amdk8.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\amdk8.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\amdppm.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\amdppm.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\intelppm.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\intelppm.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\isapnp.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\isapnp.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\kdnic.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\kdnic.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\sbp2port.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\sbp2port.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\sdstor.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\sdstor.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\serenum.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\serenum.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\serial.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\serial.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\sfloppy.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\sfloppy.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\spaceport.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\spaceport.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\atapi.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\atapi.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\ataport.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\ataport.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\BasicDisplay.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\BasicDisplay.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\BasicRender.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\BasicRender.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\battc.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\battc.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\BtaMPM.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\BtaMPM.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\BthAvrcpTg.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\BthAvrcpTg.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\bthhfenum.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\bthhfenum.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\BthhfHid.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\BthhfHid.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\cdrom.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\cdrom.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\CmBatt.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\CmBatt.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\CompositeBus.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\CompositeBus.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\disk.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\disk.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\drmk.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\drmk.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\drmkaud.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\drmkaud.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\EhStorTcgDrv.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\EhStorTcgDrv.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\errdev.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\errdev.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\fdc.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\fdc.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\flpydisk.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\flpydisk.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\circlass.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\circlass.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\fxppm.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\fxppm.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\npsvctrig.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\npsvctrig.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\usbprint.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\usbprint.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\hdaudbus.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\hdaudbus.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\HdAudio.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\HdAudio.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\hidbatt.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\hidbatt.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\hidbth.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\hidbth.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\hidclass.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\hidclass.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\hidi2c.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\hidi2c.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\hidparse.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\hidparse.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\hidusb.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\hidusb.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\monitor.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\monitor.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\msgpiowin32.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\msgpiowin32.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\msisadrv.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\msisadrv.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\msiscsi.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\msiscsi.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\mssmbios.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\mssmbios.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\MTConfig.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\MTConfig.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\parport.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\parport.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\pci.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\pci.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\pciide.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\pciide.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\pciidex.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\pciidex.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\pcmcia.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\pcmcia.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\portcls.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\portcls.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\processr.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\processr.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\rdpbus.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\rdpbus.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\stornvme.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\stornvme.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\swenum.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\swenum.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\terminpt.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\terminpt.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\tpm.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\tpm.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\TsUsbGD.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\TsUsbGD.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\uaspstor.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\uaspstor.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\UCX01000.SYS" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\UCX01000.SYS" is compressed (flags = 1)
File "C:\Windows\System32\drivers\uefi.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\uefi.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\umbus.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\umbus.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\umpass.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\umpass.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\usbccgp.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\usbccgp.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\usbcir.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\usbcir.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\usbd.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\usbd.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\usbehci.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\usbehci.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\usbhub.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\usbhub.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\USBHUB3.SYS" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\USBHUB3.SYS" is compressed (flags = 1)
File "C:\Windows\System32\drivers\usbohci.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\usbohci.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\usbport.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\usbport.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\USBSTOR.SYS" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\USBSTOR.SYS" is compressed (flags = 1)
File "C:\Windows\System32\drivers\usbuhci.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\usbuhci.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\usbvideo.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\usbvideo.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\USBXHCI.SYS" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\USBXHCI.SYS" is compressed (flags = 1)
File "C:\Windows\System32\drivers\vdrvroot.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\vdrvroot.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\volmgr.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\volmgr.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\volsnap.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\volsnap.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\vwifibus.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\vwifibus.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\wacompen.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\wacompen.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\winusb.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\winusb.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\wmiacpi.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\wmiacpi.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\WSDPrint.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\WSDPrint.sys" is compressed (flags = 1)
Done!
Drive 0
This is a System drive
Scanning MBR on drive 0...
Inspecting partition table:
This drive is a GPT Drive.
MBR Signature: 55AA
Disk Signature: 2873FD28

GPT Protective MBR Partition information:

   Partition 0 type is EFI-GPT (0xee)
   Partition is NOT ACTIVE.
   Partition starts at LBA: 1  Numsec = 4294967295

   Partition 1 type is Empty (0x0)
   Partition is NOT ACTIVE.
   Partition starts at LBA: 0  Numsec = 0

   Partition 2 type is Empty (0x0)
   Partition is NOT ACTIVE.
   Partition starts at LBA: 0  Numsec = 0

   Partition 3 type is Empty (0x0)
   Partition is NOT ACTIVE.
   Partition starts at LBA: 0  Numsec = 0

GPT Partition information:

   GPT Header Signature 4546492050415254
   GPT Header Revision 65536 Size 92 CRC 3540175431
   GPT Header CurrentLba = 1 BackupLba 976773167
   GPT Header FirstUsableLba 34  LastUsableLba 976773134
   GPT Header Guid f1ca3f94-a415-4cb1-a75d-76d3f31f71e7
   GPT Header Contains 128 partition entries starting at LBA 2
   GPT Header Partition entry size = 128

   Backup GPT header Signature 4546492050415254
   Backup GPT header Revision 65536 Size 92 CRC 3540175431
   Backup GPT header CurrentLba = 976773167 BackupLba 1
   Backup GPT header FirstUsableLba 34  LastUsableLba 976773134
   Backup GPT header Guid f1ca3f94-a415-4cb1-a75d-76d3f31f71e7
   Backup GPT header Contains 128 partition entries starting at LBA 976773135
   Backup GPT header Partition entry size = 128

   Partition 0 Type de94bba4-6d1-4d40-a16a-bfd5179d6ac
   Partition ID afb30c02-23dc-483c-8da1-47684f214a2
   FirstLBA 2048  Last LBA 1333247
   Attributes 1
   Partition Name                 Basic data partition

   Partition 1 Type c12a7328-f81f-11d2-ba4b-0a0c93ec93b
   Partition ID eab73b34-83f7-4183-a74d-46ba927a14b0
   FirstLBA 1333248  Last LBA 1865727
   Attributes 0
   Partition Name                 EFI system partition

   GPT Partition 1 is bootable
   Partition 2 Type e3c9e316-b5c-4db8-817d-f92df0215ae
   Partition ID 21422bb4-df2d-4d25-8db4-31fe8497e829
   FirstLBA 1865728  Last LBA 2127871
   Attributes 0
   Partition Name         Microsoft reserved partition

   Partition 3 Type ebd0a0a2-b9e5-4433-87c0-68b6b72699c7
   Partition ID 59a4051a-cc13-49ab-bebf-41c2fa8c148c
   FirstLBA 2127872  Last LBA 929617919
   Attributes 0
   Partition Name                 Basic data partition

   Partition 4 Type ebd0a0a2-b9e5-4433-87c0-68b6b72699c7
   Partition ID f876c3b5-6fb7-4773-acaa-aeec989866c
   FirstLBA 929617920  Last LBA 976762879
   Attributes 1
   Partition Name                 Basic data partition

Disk Size: 500107862016 bytes
Sector size: 512 bytes

Done!
Physical Sector Size: 512
Drive: 1, DevicePointer: 0xffffe000ab08a060, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\disk\
--------- Disk Stack ------
DevicePointer: 0xffffe000ab08ab20, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xffffe000ab08a060, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\disk\
DevicePointer: 0xffffe000aadd1330, DeviceName: \Device\0000003c\, DriverName: \Driver\RSP2STOR\
------------ End ----------
Alternate DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
Drive 1
Scanning MBR on drive 1...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: 0

Partition information:

   Partition 0 type is Other (0xb)
   Partition is NOT ACTIVE.
   Partition starts at LBA: 8192  Numsec = 7979008

   Partition 1 type is Empty (0x0)
   Partition is NOT ACTIVE.
   Partition starts at LBA: 0  Numsec = 0

   Partition 2 type is Empty (0x0)
   Partition is NOT ACTIVE.
   Partition starts at LBA: 0  Numsec = 0

   Partition 3 type is Empty (0x0)
   Partition is NOT ACTIVE.
   Partition starts at LBA: 0  Numsec = 0

Disk Size: 4089446400 bytes
Sector size: 512 bytes

Done!
Infected: HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS\Interfaces\{5EA0F310-66E7-47DE-8308-90A94C0279A0}|NameServer --> [Trojan.DNSChanger]
Scan finished
Creating System Restore point...
Cleaning up...
Removal scheduling successful. System shutdown needed.
=======================================


Removal queue found; removal started
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-r.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-1-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-1-r.mbam...
Removal finished
---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.09.1.1004

(c) Malwarebytes Corporation 2011-2012

OS version: 6.3.9200 Windows 8.1 x64

Account is Administrative

Internet Explorer version: 11.0.9600.17690

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED, D:\ DRIVE_FIXED
CPU speed: 2.167000 GHz
Memory total: 8472772608, free: 5209358336

=======================================
Initializing...
------------ Kernel report ------------
    03/26/2015 15:26:10
------------ Loaded modules -----------
\SystemRoot\system32\ntoskrnl.exe
\SystemRoot\system32\hal.dll
\SystemRoot\system32\kd.dll
\SystemRoot\system32\mcupdate_GenuineIntel.dll
\SystemRoot\System32\drivers\werkernel.sys
\SystemRoot\System32\drivers\CLFS.SYS
\SystemRoot\System32\drivers\tm.sys
\SystemRoot\system32\PSHED.dll
\SystemRoot\system32\BOOTVID.dll
\SystemRoot\system32\CI.dll
\SystemRoot\System32\drivers\msrpc.sys
\SystemRoot\system32\drivers\Wdf01000.sys
\SystemRoot\system32\drivers\WDFLDR.SYS
\SystemRoot\System32\Drivers\acpiex.sys
\SystemRoot\System32\Drivers\WppRecorder.sys
\SystemRoot\System32\drivers\ACPI.sys
\SystemRoot\System32\drivers\WMILIB.SYS
\SystemRoot\System32\Drivers\cng.sys
\SystemRoot\System32\drivers\msisadrv.sys
\SystemRoot\System32\drivers\pci.sys
\SystemRoot\System32\drivers\vdrvroot.sys
\SystemRoot\system32\drivers\pdc.sys
\SystemRoot\System32\drivers\partmgr.sys
\SystemRoot\System32\drivers\spaceport.sys
\SystemRoot\System32\drivers\volmgr.sys
\SystemRoot\System32\drivers\volmgrx.sys
\SystemRoot\System32\drivers\mountmgr.sys
\SystemRoot\System32\drivers\storahci.sys
\SystemRoot\System32\drivers\storport.sys
\SystemRoot\system32\drivers\fltmgr.sys
\SystemRoot\System32\drivers\fileinfo.sys
\SystemRoot\System32\Drivers\Wof.sys
\SystemRoot\system32\drivers\WdFilter.sys
\SystemRoot\System32\Drivers\Ntfs.sys
\SystemRoot\System32\Drivers\ksecdd.sys
\SystemRoot\System32\drivers\MBI.sys
\SystemRoot\System32\drivers\pcw.sys
\SystemRoot\System32\Drivers\Fs_Rec.sys
\SystemRoot\system32\drivers\ndis.sys
\SystemRoot\system32\drivers\NETIO.SYS
\SystemRoot\System32\Drivers\ksecpkg.sys
\SystemRoot\System32\drivers\tcpip.sys
\SystemRoot\System32\drivers\fwpkclnt.sys
\SystemRoot\system32\DRIVERS\wfplwfs.sys
\SystemRoot\System32\DRIVERS\fvevol.sys
\SystemRoot\System32\drivers\volsnap.sys
\SystemRoot\System32\Drivers\SmartDefragDriver.sys
\SystemRoot\System32\drivers\rdyboost.sys
\SystemRoot\System32\Drivers\mup.sys
\SystemRoot\System32\drivers\intelpep.sys
\SystemRoot\System32\drivers\disk.sys
\SystemRoot\System32\drivers\CLASSPNP.SYS
\SystemRoot\System32\Drivers\crashdmp.sys
\SystemRoot\System32\drivers\cdrom.sys
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\System32\Drivers\Beep.SYS
\SystemRoot\System32\drivers\BasicRender.sys
\SystemRoot\System32\drivers\dxgkrnl.sys
\SystemRoot\System32\drivers\watchdog.sys
\SystemRoot\System32\drivers\dxgmms1.sys
\SystemRoot\System32\drivers\BasicDisplay.sys
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\system32\DRIVERS\tdx.sys
\SystemRoot\system32\DRIVERS\TDI.SYS
\SystemRoot\system32\drivers\ws2ifsl.sys
\SystemRoot\System32\DRIVERS\netbt.sys
\SystemRoot\system32\drivers\afd.sys
\SystemRoot\system32\DRIVERS\pacer.sys
\SystemRoot\system32\DRIVERS\vwififlt.sys
\SystemRoot\system32\DRIVERS\vfilter.sys
\SystemRoot\system32\DRIVERS\netbios.sys
\SystemRoot\system32\DRIVERS\rdbss.sys
\SystemRoot\system32\DRIVERS\wanarp.sys
\SystemRoot\system32\drivers\nsiproxy.sys
\SystemRoot\System32\drivers\npsvctrig.sys
\SystemRoot\System32\drivers\mssmbios.sys
\SystemRoot\System32\Drivers\dfsc.sys
\SystemRoot\system32\DRIVERS\ahcache.sys
\SystemRoot\System32\drivers\CompositeBus.sys
\SystemRoot\System32\drivers\serscan.sys
\SystemRoot\system32\drivers\ksthunk.sys
\SystemRoot\system32\drivers\ks.sys
\SystemRoot\system32\DRIVERS\kdnic.sys
\SystemRoot\System32\drivers\umbus.sys
\SystemRoot\system32\DRIVERS\igdkmd64.sys
\SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
\SystemRoot\System32\drivers\USBXHCI.SYS
\SystemRoot\System32\drivers\ucx01000.sys
\SystemRoot\System32\drivers\TXEIx64.sys
\SystemRoot\System32\drivers\HDAudBus.sys
\SystemRoot\system32\DRIVERS\rtwlane.sys
\SystemRoot\System32\drivers\vwifibus.sys
\SystemRoot\system32\DRIVERS\RtsP2Stor.sys
\SystemRoot\system32\DRIVERS\Rt630x64.sys
\SystemRoot\System32\drivers\serial.sys
\SystemRoot\System32\drivers\serenum.sys
\SystemRoot\System32\drivers\i8042prt.sys
\SystemRoot\system32\DRIVERS\SynTP.sys
\SystemRoot\system32\DRIVERS\USBD.SYS
\SystemRoot\System32\drivers\kbdclass.sys
\SystemRoot\System32\drivers\mouclass.sys
\SystemRoot\System32\Drivers\fastfat.SYS
\SystemRoot\System32\drivers\CmBatt.sys
\SystemRoot\System32\drivers\BATTC.SYS
\SystemRoot\system32\DRIVERS\Smb_driver_Intel.sys
\SystemRoot\System32\drivers\WirelessButtonDriver64.sys
\SystemRoot\System32\drivers\HIDCLASS.SYS
\SystemRoot\System32\drivers\HIDPARSE.SYS
\SystemRoot\System32\drivers\intelppm.sys
\SystemRoot\System32\drivers\iaiogpioe.sys
\SystemRoot\System32\Drivers\msgpioclx.sys
\SystemRoot\System32\drivers\msgpiowin32.sys
\SystemRoot\System32\drivers\wmiacpi.sys
\SystemRoot\System32\drivers\UEFI.sys
\SystemRoot\System32\drivers\NdisVirtualBus.sys
\SystemRoot\System32\drivers\swenum.sys
\SystemRoot\System32\drivers\iwdbus.sys
\SystemRoot\System32\drivers\rdpbus.sys
\SystemRoot\System32\drivers\UsbHub3.sys
\SystemRoot\system32\drivers\RTKVHD64.sys
\SystemRoot\system32\drivers\portcls.sys
\SystemRoot\system32\drivers\drmk.sys
\SystemRoot\system32\DRIVERS\IntcDAud.sys
\SystemRoot\System32\drivers\usbccgp.sys
\SystemRoot\system32\DRIVERS\usbscan.sys
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\drivers\usbprint.sys
\SystemRoot\System32\drivers\dc3d.sys
\SystemRoot\System32\drivers\hidusb.sys
\SystemRoot\System32\drivers\kbdhid.sys
\SystemRoot\System32\drivers\mouhid.sys
\SystemRoot\System32\Drivers\usbvideo.sys
\SystemRoot\System32\TSDDD.dll
\SystemRoot\System32\cdd.dll
\SystemRoot\System32\ATMFD.DLL
\SystemRoot\System32\drivers\monitor.sys
\SystemRoot\System32\Drivers\dump_diskdump.sys
\SystemRoot\System32\Drivers\dump_storahci.sys
\SystemRoot\System32\Drivers\dump_dumpfve.sys
\SystemRoot\system32\drivers\luafv.sys
\??\C:\Windows\system32\drivers\mbam.sys
\SystemRoot\system32\DRIVERS\lltdio.sys
\SystemRoot\system32\DRIVERS\nwifi.sys
\SystemRoot\system32\DRIVERS\ndisuio.sys
\SystemRoot\system32\DRIVERS\rspndr.sys
\SystemRoot\System32\drivers\condrv.sys
\SystemRoot\system32\drivers\HTTP.sys
\SystemRoot\system32\DRIVERS\bowser.sys
\SystemRoot\System32\drivers\mpsdrv.sys
\SystemRoot\system32\DRIVERS\mrxsmb.sys
\SystemRoot\system32\DRIVERS\mrxsmb20.sys
\SystemRoot\system32\DRIVERS\vwifimp.sys
\SystemRoot\system32\DRIVERS\mrxsmb10.sys
\SystemRoot\system32\drivers\Ndu.sys
\SystemRoot\system32\drivers\peauth.sys
\SystemRoot\System32\Drivers\secdrv.SYS
\SystemRoot\System32\DRIVERS\srvnet.sys
\SystemRoot\System32\drivers\tcpipreg.sys
\SystemRoot\System32\DRIVERS\srv2.sys
\SystemRoot\System32\DRIVERS\srv.sys
\SystemRoot\System32\drivers\ipnat.sys
\SystemRoot\system32\drivers\WudfPf.sys
\SystemRoot\System32\drivers\WUDFRd.sys
\SystemRoot\System32\drivers\WpdUpFltr.sys
\SystemRoot\system32\Drivers\WdNisDrv.sys
\??\C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys
\??\C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys
\??\C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys
\??\C:\Windows\system32\drivers\mbamchameleon.sys
\??\C:\Windows\system32\drivers\MBAMSwissArmy.sys
----------- End -----------
Done!

Scan started
Database versions:
 main:    v2015.03.26.07
 rootkit: v2015.03.26.01

<<<2>>>
Physical Sector Size: 512
Drive: 0, DevicePointer: 0xffffe000a8dd2060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\
--------- Disk Stack ------
DevicePointer: 0xffffe000a8dd3500, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xffffe000a8dd2060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\
DevicePointer: 0xffffe000a8cb7060, DeviceName: \Device\0000002d\, DriverName: \Driver\storahci\
------------ End ----------
Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers...
File "C:\Windows\System32\drivers\1394ohci.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\1394ohci.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\acpi.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\acpi.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\acpipagr.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\acpipagr.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\acpipmi.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\acpipmi.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\acpitime.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\acpitime.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\AGP440.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\AGP440.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\amdk8.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\amdk8.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\amdppm.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\amdppm.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\intelppm.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\intelppm.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\isapnp.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\isapnp.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\kdnic.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\kdnic.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\sbp2port.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\sbp2port.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\sdstor.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\sdstor.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\serenum.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\serenum.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\serial.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\serial.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\sfloppy.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\sfloppy.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\spaceport.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\spaceport.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\atapi.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\atapi.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\ataport.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\ataport.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\BasicDisplay.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\BasicDisplay.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\BasicRender.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\BasicRender.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\battc.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\battc.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\BtaMPM.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\BtaMPM.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\BthAvrcpTg.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\BthAvrcpTg.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\bthhfenum.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\bthhfenum.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\BthhfHid.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\BthhfHid.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\cdrom.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\cdrom.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\CmBatt.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\CmBatt.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\CompositeBus.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\CompositeBus.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\disk.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\disk.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\drmk.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\drmk.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\drmkaud.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\drmkaud.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\EhStorTcgDrv.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\EhStorTcgDrv.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\errdev.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\errdev.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\fdc.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\fdc.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\flpydisk.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\flpydisk.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\circlass.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\circlass.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\fxppm.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\fxppm.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\npsvctrig.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\npsvctrig.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\usbprint.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\usbprint.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\hdaudbus.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\hdaudbus.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\HdAudio.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\HdAudio.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\hidbatt.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\hidbatt.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\hidbth.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\hidbth.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\hidclass.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\hidclass.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\hidi2c.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\hidi2c.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\hidparse.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\hidparse.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\hidusb.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\hidusb.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\monitor.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\monitor.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\msgpiowin32.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\msgpiowin32.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\msisadrv.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\msisadrv.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\msiscsi.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\msiscsi.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\mssmbios.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\mssmbios.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\MTConfig.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\MTConfig.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\parport.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\parport.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\pci.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\pci.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\pciide.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\pciide.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\pciidex.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\pciidex.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\pcmcia.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\pcmcia.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\portcls.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\portcls.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\processr.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\processr.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\rdpbus.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\rdpbus.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\stornvme.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\stornvme.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\swenum.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\swenum.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\terminpt.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\terminpt.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\tpm.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\tpm.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\TsUsbGD.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\TsUsbGD.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\uaspstor.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\uaspstor.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\UCX01000.SYS" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\UCX01000.SYS" is compressed (flags = 1)
File "C:\Windows\System32\drivers\uefi.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\uefi.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\umbus.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\umbus.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\umpass.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\umpass.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\usbccgp.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\usbccgp.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\usbcir.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\usbcir.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\usbd.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\usbd.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\usbehci.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\usbehci.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\usbhub.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\usbhub.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\USBHUB3.SYS" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\USBHUB3.SYS" is compressed (flags = 1)
File "C:\Windows\System32\drivers\usbohci.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\usbohci.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\usbport.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\usbport.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\USBSTOR.SYS" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\USBSTOR.SYS" is compressed (flags = 1)
File "C:\Windows\System32\drivers\usbuhci.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\usbuhci.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\usbvideo.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\usbvideo.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\USBXHCI.SYS" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\USBXHCI.SYS" is compressed (flags = 1)
File "C:\Windows\System32\drivers\vdrvroot.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\vdrvroot.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\volmgr.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\volmgr.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\volsnap.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\volsnap.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\vwifibus.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\vwifibus.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\wacompen.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\wacompen.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\winusb.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\winusb.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\wmiacpi.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\wmiacpi.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\WSDPrint.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\WSDPrint.sys" is compressed (flags = 1)
Done!
Drive 0
This is a System drive
Scanning MBR on drive 0...
Inspecting partition table:
This drive is a GPT Drive.
MBR Signature: 55AA
Disk Signature: 2873FD28

GPT Protective MBR Partition information:

   Partition 0 type is EFI-GPT (0xee)
   Partition is NOT ACTIVE.
   Partition starts at LBA: 1  Numsec = 4294967295

   Partition 1 type is Empty (0x0)
   Partition is NOT ACTIVE.
   Partition starts at LBA: 0  Numsec = 0

   Partition 2 type is Empty (0x0)
   Partition is NOT ACTIVE.
   Partition starts at LBA: 0  Numsec = 0

   Partition 3 type is Empty (0x0)
   Partition is NOT ACTIVE.
   Partition starts at LBA: 0  Numsec = 0

GPT Partition information:

   GPT Header Signature 4546492050415254
   GPT Header Revision 65536 Size 92 CRC 3540175431
   GPT Header CurrentLba = 1 BackupLba 976773167
   GPT Header FirstUsableLba 34  LastUsableLba 976773134
   GPT Header Guid f1ca3f94-a415-4cb1-a75d-76d3f31f71e7
   GPT Header Contains 128 partition entries starting at LBA 2
   GPT Header Partition entry size = 128

   Backup GPT header Signature 4546492050415254
   Backup GPT header Revision 65536 Size 92 CRC 3540175431
   Backup GPT header CurrentLba = 976773167 BackupLba 1
   Backup GPT header FirstUsableLba 34  LastUsableLba 976773134
   Backup GPT header Guid f1ca3f94-a415-4cb1-a75d-76d3f31f71e7
   Backup GPT header Contains 128 partition entries starting at LBA 976773135
   Backup GPT header Partition entry size = 128

   Partition 0 Type de94bba4-6d1-4d40-a16a-bfd5179d6ac
   Partition ID afb30c02-23dc-483c-8da1-47684f214a2
   FirstLBA 2048  Last LBA 1333247
   Attributes 1
   Partition Name                 Basic data partition

   Partition 1 Type c12a7328-f81f-11d2-ba4b-0a0c93ec93b
   Partition ID eab73b34-83f7-4183-a74d-46ba927a14b0
   FirstLBA 1333248  Last LBA 1865727
   Attributes 0
   Partition Name                 EFI system partition

   GPT Partition 1 is bootable
   Partition 2 Type e3c9e316-b5c-4db8-817d-f92df0215ae
   Partition ID 21422bb4-df2d-4d25-8db4-31fe8497e829
   FirstLBA 1865728  Last LBA 2127871
   Attributes 0
   Partition Name         Microsoft reserved partition

   Partition 3 Type ebd0a0a2-b9e5-4433-87c0-68b6b72699c7
   Partition ID 59a4051a-cc13-49ab-bebf-41c2fa8c148c
   FirstLBA 2127872  Last LBA 929617919
   Attributes 0
   Partition Name                 Basic data partition

   Partition 4 Type ebd0a0a2-b9e5-4433-87c0-68b6b72699c7
   Partition ID f876c3b5-6fb7-4773-acaa-aeec989866c
   FirstLBA 929617920  Last LBA 976762879
   Attributes 1
   Partition Name                 Basic data partition

Disk Size: 500107862016 bytes
Sector size: 512 bytes

Done!
Physical Sector Size: 512
Drive: 1, DevicePointer: 0xffffe000ab08a060, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\disk\
--------- Disk Stack ------
DevicePointer: 0xffffe000ab08ab20, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xffffe000ab08a060, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\disk\
DevicePointer: 0xffffe000aadd1330, DeviceName: \Device\0000003c\, DriverName: \Driver\RSP2STOR\
------------ End ----------
Alternate DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
Drive 1
Scanning MBR on drive 1...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: 0

Partition information:

   Partition 0 type is Other (0xb)
   Partition is NOT ACTIVE.
   Partition starts at LBA: 8192  Numsec = 7979008

   Partition 1 type is Empty (0x0)
   Partition is NOT ACTIVE.
   Partition starts at LBA: 0  Numsec = 0

   Partition 2 type is Empty (0x0)
   Partition is NOT ACTIVE.
   Partition starts at LBA: 0  Numsec = 0

   Partition 3 type is Empty (0x0)
   Partition is NOT ACTIVE.
   Partition starts at LBA: 0  Numsec = 0

Disk Size: 4089446400 bytes
Sector size: 512 bytes

Done!
Scan finished
=======================================


Removal queue found; removal started
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-r.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-1-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-1-r.mbam...
Removal finished



So everything appears clean but I still had a popup in Chrome

DarrenC
Novice
Novice

Posts Posts : 34
Joined Joined : 2015-03-26
OS OS : Windows 8.1
Points Points : 6698
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Trojan.DNSChanger and SearchScopes

Post by DarrenC on Fri Mar 27, 2015 1:28 am

I ran Malwarebytes Anti-Malware again and got the DNSChanger trojan again..


Malwarebytes Anti-Malware

Scan Date: 3/26/2015
Scan Time: 5:41:06 PM
Logfile:
Administrator: Yes

Version: 2.01.4.1018
Malware Database: v2015.03.27.01
Rootkit Database: v2015.03.26.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 8.1
CPU: x64
File System: NTFS
User: Michelle

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 368134
Time Elapsed: 35 min, 0 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 1
Trojan.DNSChanger, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS\Interfaces\{5EA0F310-66E7-47DE-8308-90A94C0279A0}|NameServer, 31.168.228.251,82.166.96.251, Good: (), Bad: (31.168.228.251,82.166.96.251),,[5d20ec5e9dedf83e3d2d966461a47d83]

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)


(end)

DarrenC
Novice
Novice

Posts Posts : 34
Joined Joined : 2015-03-26
OS OS : Windows 8.1
Points Points : 6698
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Trojan.DNSChanger and SearchScopes

Post by Superdave on Fri Mar 27, 2015 1:32 am

Could you post a screenshot of that popup?

[You must be registered and logged in to see this link.]

I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
[You must be registered and logged in to see this link.]

•Click the button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

  • Click on to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the icon on your desktop.

•Check
•Click the button.
•Accept any security warnings from your browser.

  • Leave the check mark next to Remove found threats.

•Check
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push
•Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the button.
•Push
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt

Superdave
Captain
Captain

Posts Posts : 4202
Joined Joined : 2010-02-01
Gender Gender : Male
OS OS : Windows 8.1 and a dual-boot with XP Home SP3
Protection Protection : MSE, Windows Defender, Windows firewall
Points Points : 83171
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Trojan.DNSChanger and SearchScopes

Post by DarrenC on Fri Mar 27, 2015 5:13 pm

I can't post a link because I'm a new member. I uploaded it to imgur and it's u7Ne7tL.png

ESET came back clean.

DarrenC
Novice
Novice

Posts Posts : 34
Joined Joined : 2015-03-26
OS OS : Windows 8.1
Points Points : 6698
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Trojan.DNSChanger and SearchScopes

Post by DarrenC on Fri Mar 27, 2015 6:08 pm

Also BMdv3wg and 4YpHKdK on imgur. One shows another popup. The other shows ads that are being inserted into web pages that don't normally have them.

DarrenC
Novice
Novice

Posts Posts : 34
Joined Joined : 2015-03-26
OS OS : Windows 8.1
Points Points : 6698
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Trojan.DNSChanger and SearchScopes

Post by Superdave on Fri Mar 27, 2015 10:13 pm

Once you take the screenshot and save in Paint, save it on your computer where you can find it. When you make your next post click on Add photo and browse to where you saved your screenshot and select it.

Superdave
Captain
Captain

Posts Posts : 4202
Joined Joined : 2010-02-01
Gender Gender : Male
OS OS : Windows 8.1 and a dual-boot with XP Home SP3
Protection Protection : MSE, Windows Defender, Windows firewall
Points Points : 83171
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Trojan.DNSChanger and SearchScopes

Post by DarrenC on Fri Mar 27, 2015 10:28 pm





DarrenC
Novice
Novice

Posts Posts : 34
Joined Joined : 2015-03-26
OS OS : Windows 8.1
Points Points : 6698
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Trojan.DNSChanger and SearchScopes

Post by Superdave on Sat Mar 28, 2015 6:35 pm

I need to take a closer look at your computer. Please run this and post the logs.

Download DDS from [You must be registered and logged in to see this link.] or [You must be registered and logged in to see this link.] and save it to your desktop.

Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)

* XP users Double click on dds to run it.
* If your antivirus or firewall try to block DDS then please allow it to run.
* When finished DDS will open two (2) logs.
* Save both reports to your desktop.
* The instructions here ask you to attach the Attach.txt.



1) DDS.txt
2) Attach.txt
Instead of attaching, please copy/past both logs into your Thread

Note: DDS will instruct you to post the Attach.txt log as an attachment.
Please just post it as you would any other log by copying and pasting it into the reply.

•Close the program window, and delete the program from your desktop.

Please note: You may have to disable any script protection running if the scan fails to run.
After downloading the tool, disconnect from the internet and disable all antivirus protection.
Run the scan, enable your A/V and reconnect to the internet.
Information on A/V control [You must be registered and logged in to see this link.].Then post your DDS logs. (DDS.txt and Attach.txt )

Superdave
Captain
Captain

Posts Posts : 4202
Joined Joined : 2010-02-01
Gender Gender : Male
OS OS : Windows 8.1 and a dual-boot with XP Home SP3
Protection Protection : MSE, Windows Defender, Windows firewall
Points Points : 83171
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Trojan.DNSChanger and SearchScopes

Post by DarrenC on Mon Mar 30, 2015 3:25 pm

DDS is telling me that it was not meant to run in compatibility mode.

DarrenC
Novice
Novice

Posts Posts : 34
Joined Joined : 2015-03-26
OS OS : Windows 8.1
Points Points : 6698
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Trojan.DNSChanger and SearchScopes

Post by Superdave on Mon Mar 30, 2015 6:11 pm

Ok. Please run MBAM again and make sure the infection is cleaned.

Superdave
Captain
Captain

Posts Posts : 4202
Joined Joined : 2010-02-01
Gender Gender : Male
OS OS : Windows 8.1 and a dual-boot with XP Home SP3
Protection Protection : MSE, Windows Defender, Windows firewall
Points Points : 83171
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Trojan.DNSChanger and SearchScopes

Post by DarrenC on Tue Mar 31, 2015 9:49 pm

Malwarebytes Anti-Malware

Scan Date: 3/31/2015
Scan Time: 12:59:40 PM
Logfile:
Administrator: Yes

Version: 2.01.4.1018
Malware Database: v2015.03.31.07
Rootkit Database: v2015.03.31.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 8.1
CPU: x64
File System: NTFS
User: Michelle

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 367400
Time Elapsed: 55 min, 15 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 1
Trojan.DNSChanger, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS\Interfaces\{5EA0F310-66E7-47DE-8308-90A94C0279A0}|NameServer, 31.168.228.251,82.166.96.251, Good: (), Bad: (31.168.228.251,82.166.96.251),Replaced,[d142df6d9feb82b46f38f6067b8a7789]

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)


(end)



No matter how many times I do the scan and clean, this Trojan is still there.

DarrenC
Novice
Novice

Posts Posts : 34
Joined Joined : 2015-03-26
OS OS : Windows 8.1
Points Points : 6698
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Trojan.DNSChanger and SearchScopes

Post by Superdave on Tue Mar 31, 2015 9:58 pm

Please go to Control Panel, Programs and Features and make sure that there are no unwanted programs there. Also, check you browser to make sure there are no Add-ons.

Superdave
Captain
Captain

Posts Posts : 4202
Joined Joined : 2010-02-01
Gender Gender : Male
OS OS : Windows 8.1 and a dual-boot with XP Home SP3
Protection Protection : MSE, Windows Defender, Windows firewall
Points Points : 83171
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Trojan.DNSChanger and SearchScopes

Post by DarrenC on Tue Mar 31, 2015 10:04 pm

Both are clean. I had an "UltraVNC" record in my Programs that I couldn't uninstall so I deleted the registry key for it.

DarrenC
Novice
Novice

Posts Posts : 34
Joined Joined : 2015-03-26
OS OS : Windows 8.1
Points Points : 6698
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Trojan.DNSChanger and SearchScopes

Post by Superdave on Tue Mar 31, 2015 10:16 pm

[You must be registered and logged in to see this link.] wrote:Both are clean. I had an "UltraVNC" record in my Programs that I couldn't uninstall so I deleted the registry key for it.
You might want to look in Program Files to see if there is anything left there.

Superdave
Captain
Captain

Posts Posts : 4202
Joined Joined : 2010-02-01
Gender Gender : Male
OS OS : Windows 8.1 and a dual-boot with XP Home SP3
Protection Protection : MSE, Windows Defender, Windows firewall
Points Points : 83171
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Trojan.DNSChanger and SearchScopes

Post by DarrenC on Wed Apr 01, 2015 5:43 pm

There was nothing out of the ordinary that I could find

DarrenC
Novice
Novice

Posts Posts : 34
Joined Joined : 2015-03-26
OS OS : Windows 8.1
Points Points : 6698
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Trojan.DNSChanger and SearchScopes

Post by Superdave on Wed Apr 01, 2015 5:54 pm

So, where do we stand now?

Superdave
Captain
Captain

Posts Posts : 4202
Joined Joined : 2010-02-01
Gender Gender : Male
OS OS : Windows 8.1 and a dual-boot with XP Home SP3
Protection Protection : MSE, Windows Defender, Windows firewall
Points Points : 83171
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Trojan.DNSChanger and SearchScopes

Post by DarrenC on Wed Apr 01, 2015 5:59 pm

Same as before. Had more pop-ups today.

DarrenC
Novice
Novice

Posts Posts : 34
Joined Joined : 2015-03-26
OS OS : Windows 8.1
Points Points : 6698
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Trojan.DNSChanger and SearchScopes

Post by Superdave on Wed Apr 01, 2015 6:04 pm

What browser are you using?

Superdave
Captain
Captain

Posts Posts : 4202
Joined Joined : 2010-02-01
Gender Gender : Male
OS OS : Windows 8.1 and a dual-boot with XP Home SP3
Protection Protection : MSE, Windows Defender, Windows firewall
Points Points : 83171
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Trojan.DNSChanger and SearchScopes

Post by DarrenC on Wed Apr 01, 2015 6:15 pm

Chrome

DarrenC
Novice
Novice

Posts Posts : 34
Joined Joined : 2015-03-26
OS OS : Windows 8.1
Points Points : 6698
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Trojan.DNSChanger and SearchScopes

Post by Superdave on Wed Apr 01, 2015 6:25 pm

Do you receive any pop-ups with other browsers?

Superdave
Captain
Captain

Posts Posts : 4202
Joined Joined : 2010-02-01
Gender Gender : Male
OS OS : Windows 8.1 and a dual-boot with XP Home SP3
Protection Protection : MSE, Windows Defender, Windows firewall
Points Points : 83171
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Trojan.DNSChanger and SearchScopes

Post by DarrenC on Wed Apr 01, 2015 7:58 pm

Nope. It is apparently just Chrome.

DarrenC
Novice
Novice

Posts Posts : 34
Joined Joined : 2015-03-26
OS OS : Windows 8.1
Points Points : 6698
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Trojan.DNSChanger and SearchScopes

Post by Superdave on Wed Apr 01, 2015 11:11 pm

Did you try uninstalling and re-installing Chrome? Did you check if there are any add-ons in Chrome?

Superdave
Captain
Captain

Posts Posts : 4202
Joined Joined : 2010-02-01
Gender Gender : Male
OS OS : Windows 8.1 and a dual-boot with XP Home SP3
Protection Protection : MSE, Windows Defender, Windows firewall
Points Points : 83171
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Trojan.DNSChanger and SearchScopes

Post by DarrenC on Mon Apr 06, 2015 6:01 pm

Uninstalled Chrome. Ran everything I had for scans. Antimalware came back with the same thing, and now I am getting popups in Firefox...

DarrenC
Novice
Novice

Posts Posts : 34
Joined Joined : 2015-03-26
OS OS : Windows 8.1
Points Points : 6698
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Trojan.DNSChanger and SearchScopes

Post by Superdave on Mon Apr 06, 2015 6:45 pm

Ok, please run MBAM and AdwCleaner again and see if it picks up anything.

Superdave
Captain
Captain

Posts Posts : 4202
Joined Joined : 2010-02-01
Gender Gender : Male
OS OS : Windows 8.1 and a dual-boot with XP Home SP3
Protection Protection : MSE, Windows Defender, Windows firewall
Points Points : 83171
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Trojan.DNSChanger and SearchScopes

Post by DarrenC on Mon Apr 06, 2015 9:24 pm

Malwarebytes Anti-Malware
[You must be registered and logged in to see this link.]

Scan Date: 4/6/2015
Scan Time: 1:37:10 PM
Logfile:
Administrator: Yes

Version: 2.01.4.1018
Malware Database: v2015.04.06.09
Rootkit Database: v2015.03.31.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 8.1
CPU: x64
File System: NTFS
User: Michelle

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 360493
Time Elapsed: 40 min, 13 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)


(end)




# AdwCleaner v4.200 - Logfile created 06/04/2015 at 13:37:00
# Updated 29/03/2015 by Xplode
# Database : 2015-03-29.1 [Server]
# Operating system : Windows 8.1 (x64)
# Username : Michelle - MICHELLE-LAPTOP
# Running from : C:\Users\Michelle\Downloads\adwcleaner_4.200.exe
# Option : Scan

***** [ Services ] *****


***** [ Files / Folders ] *****

File Found : C:\Users\Michelle\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_kbfnbcaeplbcioakkpcpgfkobkghlhen_0.localstorage
File Found : C:\Users\Michelle\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_kbfnbcaeplbcioakkpcpgfkobkghlhen_0.localstorage-journal
Folder Found : C:\Users\Michelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbfnbcaeplbcioakkpcpgfkobkghlhen

***** [ Scheduled tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****


***** [ Web browsers ] *****

#NAME?


-\\ Mozilla Firefox v37.0.1 (x86 en-US)


#NAME?

[C:\Users\Michelle\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Found [Extension] : kbfnbcaeplbcioakkpcpgfkobkghlhen
[C:\Users\Michelle\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Found [Startup_URLs] : [You must be registered and logged in to see this link.] target="_blank" rel="nofollow">hxxp://www.better-search.net/?barid=1605756566386807156&src=10&crg=&ppd=,,,,,,,,,www.smilebox.com&st=23&i=998&did=10874", "hxxp://Lasaoren.com/?f=7&a=lrn_clickconnect_14_39_ch&cd=2XzuyEtN2Y1L1Qzuzy0C0A0DzyyB0A0CyCtB0CtB0C0EtB0CtN0D0Tzu0SzyzyzztN1L2XzutAtFtBtFyEtFtBtN1L1CzutCyEtBzytDyD1V1OtN1L1G1B1V1N2Y1L1Qzu2SyC0EyB0F0DtC0DyBtG0CyC0E0CtG0ByByCyBtGtDyEyEzytGyEyDyDyD0EyD0D0DzytDyE0F2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0EtA0AtDyByD0EzytGyEyE0D0BtGyEzztA0CtGzz0CyCtAtG0CtAyDyDyByC0A0C0CtCyBtC2Q&cr=1639992324&ir=

*************************

AdwCleaner[R0].txt - [958 bytes] - [26/03/2015 09:56:03]
AdwCleaner[R1].txt - [903 bytes] - [26/03/2015 12:27:59]
AdwCleaner[R2].txt - [1269 bytes] - [26/03/2015 13:48:21]
AdwCleaner[R3].txt - [1080 bytes] - [26/03/2015 13:57:50]
AdwCleaner[R4].txt - [1138 bytes] - [26/03/2015 17:43:18]
AdwCleaner[R5].txt - [1188 bytes] - [02/04/2015 14:10:22]
AdwCleaner[R6].txt - [1280 bytes] - [03/04/2015 09:40:10]
AdwCleaner[R7].txt - [1340 bytes] - [06/04/2015 08:47:17]
AdwCleaner[R8].txt - [1458 bytes] - [06/04/2015 09:00:13]
AdwCleaner[R9].txt - [2380 bytes] - [06/04/2015 13:37:00]
AdwCleaner[S0].txt - [1339 bytes] - [26/03/2015 13:49:20]
AdwCleaner[S1].txt - [1259 bytes] - [03/04/2015 09:27:12]
AdwCleaner[S21].txt - [3893 bytes] - [26/03/2015 09:38:37]
AdwCleaner[S2].txt - [1404 bytes] - [06/04/2015 08:48:14]

########## EOF - C:\AdwCleaner\AdwCleaner[R9].txt - [2676 bytes] ##########

DarrenC
Novice
Novice

Posts Posts : 34
Joined Joined : 2015-03-26
OS OS : Windows 8.1
Points Points : 6698
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Trojan.DNSChanger and SearchScopes

Post by Superdave on Mon Apr 06, 2015 9:55 pm

Please run AdwCleaner again and hit the delete button.

Superdave
Captain
Captain

Posts Posts : 4202
Joined Joined : 2010-02-01
Gender Gender : Male
OS OS : Windows 8.1 and a dual-boot with XP Home SP3
Protection Protection : MSE, Windows Defender, Windows firewall
Points Points : 83171
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Trojan.DNSChanger and SearchScopes

Post by DarrenC on Mon Apr 06, 2015 10:58 pm

Malwarebytes Anti-Malware
[You must be registered and logged in to see this link.]

Scan Date: 4/6/2015
Scan Time: 2:33:18 PM
Logfile:
Administrator: Yes

Version: 2.01.4.1018
Malware Database: v2015.04.06.09
Rootkit Database: v2015.03.31.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Enabled

OS: Windows 8.1
CPU: x64
File System: NTFS
User: Michelle

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 360249
Time Elapsed: 1 hr, 15 min, 31 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 1
Trojan.DNSChanger, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS\Interfaces\{5EA0F310-66E7-47DE-8308-90A94C0279A0}|NameServer, 31.168.228.251,82.166.96.251, Good: (), Bad: (31.168.228.251,82.166.96.251),,[2c35de8b35555cda2f52a05b35d027d9]

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)


(end)



Malwarebyte Antimalware found the DNSChanger again...
AdwCleaner came back clean.

Will scan again and see what happens

DarrenC
Novice
Novice

Posts Posts : 34
Joined Joined : 2015-03-26
OS OS : Windows 8.1
Points Points : 6698
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Trojan.DNSChanger and SearchScopes

Post by DarrenC on Tue Apr 07, 2015 12:28 am

Malwarebytes Anti-Rootkit BETA 1.09.1.1004
[You must be registered and logged in to see this link.]

Database version:
main: v2015.04.06.09
rootkit: v2015.03.31.01

Windows 8.1 x64 NTFS
Internet Explorer 11.0.9600.17690
Michelle :: MICHELLE-LAPTOP [administrator]

4/6/2015 14:35
mbar-log-2015-04-06 (14-35-15).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 360243
Time elapsed: 1 hour(s), 14 minute(s), 2 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 1
HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS\Interfaces\{5EA0F310-66E7-47DE-8308-90A94C0279A0}|NameServer (Trojan.DNSChanger) -> Bad: (31.168.228.251,82.166.96.251) Good: () -> Replace on reboot. [cc95a0c94c3e75c19fe222d9d035a25e]

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

Physical Sectors Detected: 0
(No malicious items detected)

(end)



Removed, scanned again, and it found it again...

DarrenC
Novice
Novice

Posts Posts : 34
Joined Joined : 2015-03-26
OS OS : Windows 8.1
Points Points : 6698
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Trojan.DNSChanger and SearchScopes

Post by Superdave on Tue Apr 07, 2015 1:03 am


  • Download [You must be registered and logged in to see this link.] and save it to your Desktop.
  • Extract its contents to your desktop.
  • Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.

  • If an infected file is detected, the default action will be Cure, click on Continue.

  • If a suspicious file is detected, the default action will be Skip, click on Continue.

  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.

  • Click the Report button and copy/paste the contents of it into your next reply
Note:It will also create a log in the C:\ directory..

Superdave
Captain
Captain

Posts Posts : 4202
Joined Joined : 2010-02-01
Gender Gender : Male
OS OS : Windows 8.1 and a dual-boot with XP Home SP3
Protection Protection : MSE, Windows Defender, Windows firewall
Points Points : 83171
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Trojan.DNSChanger and SearchScopes

Post by DarrenC on Tue Apr 07, 2015 5:47 pm

The Report is too long to post in a reply but TSDKiller found nothing

DarrenC
Novice
Novice

Posts Posts : 34
Joined Joined : 2015-03-26
OS OS : Windows 8.1
Points Points : 6698
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Trojan.DNSChanger and SearchScopes

Post by Superdave on Tue Apr 07, 2015 6:45 pm

Ok, please run MBAM again and see if anything pops up.

Superdave
Captain
Captain

Posts Posts : 4202
Joined Joined : 2010-02-01
Gender Gender : Male
OS OS : Windows 8.1 and a dual-boot with XP Home SP3
Protection Protection : MSE, Windows Defender, Windows firewall
Points Points : 83171
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Trojan.DNSChanger and SearchScopes

Post by DarrenC on Fri Apr 10, 2015 7:41 pm

The popups seem to have went away. Sorry for the delay. Just wanted to make sure that they were actually gone before I said they were gone. Thanks for your help!

DarrenC
Novice
Novice

Posts Posts : 34
Joined Joined : 2015-03-26
OS OS : Windows 8.1
Points Points : 6698
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Trojan.DNSChanger and SearchScopes

Post by Superdave on Fri Apr 10, 2015 10:34 pm

That is good news. Let's do some clean up.

Click Start> Computer> right click the C Drive and choose Properties> enter
Click Disk Cleanup from there.



Click OK on the Disk Cleanup Screen.
Click Yes on the Confirmation screen.



This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive)
**************************************************
This step will remove all cleaning tools we used, it'll reset restore points (so you won't get reinfected by accidentally using some older restore point) and it'll make some other minor adjustments...
This is a very crucial step so make sure you don't skip it.
Download [You must be registered and logged in to see this link.] to your desktop. Delfix will delete all the used tools and logfiles.

Double-click Delfix.exe to start the tool.
Make sure the following items are checked:

  • Activate UAC (optional; some users prefer to keep it off)
  • Remove disinfection tools
  • Create Registry backup
  • Purge System Restore Points
  • Re-set system settings

Now click "Run" and wait patiently.
Once finished a logfile will be created. You don't have to attach it to your next reply.
*********************************************
I suggest using [You must be registered and logged in to see this link.]. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

Check out [You must be registered and logged in to see this link.] for tips and free tools to help keep you safe in the future.

Also see [You must be registered and logged in to see this link.] for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!

Superdave
Captain
Captain

Posts Posts : 4202
Joined Joined : 2010-02-01
Gender Gender : Male
OS OS : Windows 8.1 and a dual-boot with XP Home SP3
Protection Protection : MSE, Windows Defender, Windows firewall
Points Points : 83171
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Trojan.DNSChanger and SearchScopes

Post by DarrenC on Mon Apr 13, 2015 3:59 pm

All done. Thanks for your help!

DarrenC
Novice
Novice

Posts Posts : 34
Joined Joined : 2015-03-26
OS OS : Windows 8.1
Points Points : 6698
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Trojan.DNSChanger and SearchScopes

Post by Superdave on Mon Apr 13, 2015 6:29 pm

You're welcome. I will lock this thread. If you need it re-opened, please send me a pm.

Superdave
Captain
Captain

Posts Posts : 4202
Joined Joined : 2010-02-01
Gender Gender : Male
OS OS : Windows 8.1 and a dual-boot with XP Home SP3
Protection Protection : MSE, Windows Defender, Windows firewall
Points Points : 83171
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Trojan.DNSChanger and SearchScopes

Post by DarrenC on Wed Apr 15, 2015 8:55 pm

Just had a pop up again, so I ran MBAM and got this:

Malwarebytes Anti-Malware
[You must be registered and logged in to see this link.]

Scan Date: 4/15/2015
Scan Time: 1:02:33 PM
Logfile:
Administrator: Yes

Version: 2.01.4.1018
Malware Database: v2015.04.15.08
Rootkit Database: v2015.03.31.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 8.1
CPU: x64
File System: NTFS
User: Michelle

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 358806
Time Elapsed: 38 min, 35 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 1
Trojan.DNSChanger, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS\Interfaces\{5EA0F310-66E7-47DE-8308-90A94C0279A0}|NameServer, 31.168.228.251,82.166.96.251, Good: (), Bad: (31.168.228.251,82.166.96.251),,[20c44b21741676c050ac15f0dc2aa060]

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)


(end)

DarrenC
Novice
Novice

Posts Posts : 34
Joined Joined : 2015-03-26
OS OS : Windows 8.1
Points Points : 6698
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Trojan.DNSChanger and SearchScopes

Post by Superdave on Wed Apr 15, 2015 8:57 pm

Please run TDSSKiller again.

Superdave
Captain
Captain

Posts Posts : 4202
Joined Joined : 2010-02-01
Gender Gender : Male
OS OS : Windows 8.1 and a dual-boot with XP Home SP3
Protection Protection : MSE, Windows Defender, Windows firewall
Points Points : 83171
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Trojan.DNSChanger and SearchScopes

Post by DarrenC on Wed Apr 15, 2015 9:06 pm

 ============================================================
14:05:29.0743 0x2258  Scan finished
14:05:29.0743 0x2258  ============================================================
14:05:29.0772 0x224c  Detected object count: 0
14:05:29.0772 0x224c  Actual detected object count: 0

The log was too long, but TDSSKiller found nothing

DarrenC
Novice
Novice

Posts Posts : 34
Joined Joined : 2015-03-26
OS OS : Windows 8.1
Points Points : 6698
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Trojan.DNSChanger and SearchScopes

Post by Superdave on Wed Apr 15, 2015 11:34 pm

Are you still getting the popups? Could you post the last ten lines of the log?

Superdave
Captain
Captain

Posts Posts : 4202
Joined Joined : 2010-02-01
Gender Gender : Male
OS OS : Windows 8.1 and a dual-boot with XP Home SP3
Protection Protection : MSE, Windows Defender, Windows firewall
Points Points : 83171
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Trojan.DNSChanger and SearchScopes

Post by DarrenC on Thu Apr 16, 2015 3:29 pm

14:05:02.0854 0x2258 ================ Scan global ===============================
14:05:02.0900 0x2258 [ 243F54DBA6EB48A369CA465E263ABA4A, 9D9F9DE783D000F3EA130EB68FD71319F21E4F1CD4232FB8B2F8A9A67E08F5F4 ] C:\Windows\system32\basesrv.dll
14:05:02.0944 0x2258 [ EAB311B0A7A8EA0346F14F08D4BC8F46, 11168E4074679F8A69DA714C0ABD0C68BA49D171B379343F14783C9C563202CA ] C:\Windows\system32\winsrv.dll
14:05:02.0987 0x2258 [ 3600ED7EA8AED849E20700551C0BD63B, 4A8C346C1646E80B58EF93F87F915A41E05CA2E993BB1C96955AE62A0669AF66 ] C:\Windows\system32\sxssrv.dll
14:05:03.0029 0x2258 [ 5BF02EBEFEDC706318C96E2E60EDCB91, DC866C5BC3A887CAAA7169AB9BB2992F6F877B3EA04B62B4F95B6BD54943155F ] C:\Windows\system32\services.exe
14:05:03.0043 0x2258 [ Global ] - ok
14:05:03.0045 0x2258 ================ Scan MBR ==================================
14:05:03.0063 0x2258 [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk0\DR0
14:05:03.0111 0x2258 \Device\Harddisk0\DR0 - ok
14:05:03.0132 0x2258 [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk1\DR1
14:05:03.0138 0x2258 \Device\Harddisk1\DR1 - ok
14:05:03.0141 0x2258 ================ Scan VBR ==================================
14:05:03.0149 0x2258 [ F349D616FC879D42E62A08BA18D53153 ] \Device\Harddisk0\DR0\Partition1
14:05:03.0175 0x2258 \Device\Harddisk0\DR0\Partition1 - ok
14:05:03.0192 0x2258 [ 6B3604872C1D0AB6EEF9E8F55E6C8275 ] \Device\Harddisk0\DR0\Partition2
14:05:03.0207 0x2258 \Device\Harddisk0\DR0\Partition2 - ok
14:05:03.0223 0x2258 [ A4425078424A8B22CA8325A649C43F11 ] \Device\Harddisk0\DR0\Partition3
14:05:03.0223 0x2258 \Device\Harddisk0\DR0\Partition3 - ok
14:05:03.0235 0x2258 [ C257F49A886D0C4FE22B2F67905CF952 ] \Device\Harddisk0\DR0\Partition4
14:05:03.0253 0x2258 \Device\Harddisk0\DR0\Partition4 - ok
14:05:03.0283 0x2258 [ 3F6D5BA1AABA1244C5E896B49006D81A ] \Device\Harddisk0\DR0\Partition5
14:05:03.0298 0x2258 \Device\Harddisk0\DR0\Partition5 - ok
14:05:03.0307 0x2258 [ 809537E426045146AF9D29A2EF90F984 ] \Device\Harddisk1\DR1\Partition1
14:05:03.0310 0x2258 \Device\Harddisk1\DR1\Partition1 - ok
14:05:03.0312 0x2258 ================ Scan generic autorun ======================
14:05:03.0374 0x2258 [ 0B091BD3E8F6BD5F985DE8E3DF17D837, 7082AFB9EE8EE2EAAAFA0DB129505117E2BA1D7059B193E0DEF514080F77D1BE ] C:\Windows\system32\igfxtray.exe
14:05:03.0389 0x2258 IgfxTray - ok
14:05:03.0442 0x2258 [ 1ECC8D5528F535EC6CECFB824B349418, 4035CD388A437F1564C6E4E86787756CF196CD0DFDDAD4DAFABDB583D370FF4F ] C:\Windows\system32\hkcmd.exe
14:05:03.0468 0x2258 HotKeysCmds - ok
14:05:03.0533 0x2258 [ 1B8C1C4B77BE157E322A05118A2E25E1, 978C8A511544DE5BC7BCB31B675356E8E764EFC435BCCDF360C8635668D6B072 ] C:\Windows\system32\igfxpers.exe
14:05:03.0559 0x2258 Persistence - ok
14:05:03.0883 0x2258 [ 586154542F56C285E6F53E4727928780, 7D009AE4310DF49492D20F3363C0A21A1461A6948809883266027D86A1EE87D5 ] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
14:05:04.0259 0x2258 RTHDVCPL - ok
14:05:04.0279 0x2258 SynTPEnh - ok
14:05:04.0339 0x2258 [ D0B542256A968DFCB8896C140FCE6047, 3F92A9871B521BCCCDFE6D9BFF88930B26C5DB86F6F6578554A3F2ECC5C5EBA0 ] C:\Program Files\iTunes\iTunesHelper.exe
14:05:04.0350 0x2258 iTunesHelper - ok
14:05:04.0355 0x2258 3D BubbleSound - ok
14:05:04.0502 0x2258 [ E2043ABD9E13E1B7BF74B1D05E15AA47, B59953E4F2392858601551A4FA2024742B99E6AF48D71C3155548C97E25A1FA9 ] C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe
14:05:04.0538 0x2258 HPMessageService - ok
14:05:04.0778 0x2258 [ 4CDF90E852837C827C855F8E8E2C5FE2, 1918CE3A880E2067D52C538096DA2D35DFCA2D742E2ED370CF2DFE22840024FD ] C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe
14:05:04.0977 0x2258 Intuit SyncManager - ok
14:05:05.0048 0x2258 [ 34D296AFC913E302953C70463EF09A48, BC413307CBC56C039EE8A05B51A56E14EF59678FBB33815AEB320078056C8CE7 ] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
14:05:05.0054 0x2258 HP Software Update - ok
14:05:05.0198 0x2258 [ 22F7B9670AD770C7ED7F4738204C8E5C, 7B793AC094CB1B073419B5DAE09DFBB8EBED03D29301F490AA76EA0667613438 ] C:\Program Files\HP\HP Officejet 6600\Bin\ScanToPCActivationApp.exe
14:05:05.0279 0x2258 HP Officejet 6600 (NET) - ok
14:05:05.0305 0x2258 Skype - ok
14:05:05.0459 0x2258 [ ACD929D8754B63BBBB68B48B96F8A99E, E4DD488BA151AAB58FC00458F69D5A7AC191BA488F2BDAF88BE432C24250AF94 ] C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe
14:05:05.0537 0x2258 Advanced SystemCare 8 - ok
14:05:05.0643 0x2258 [ CE9806603D3C635EA6E0BB79FE916D2E, E544A661AF49DF835D27748B75D2DC36CAA2A224CB385B406D32FC541B12C6C4 ] C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
14:05:05.0671 0x2258 GoogleChromeAutoLaunch_D767CAD71DA7DD1CDFD0D3EF6D1B23BA - ok
14:05:05.0677 0x2258 Waiting for KSN requests completion. In queue: 75
14:05:06.0677 0x2258 Waiting for KSN requests completion. In queue: 75
14:05:07.0677 0x2258 Waiting for KSN requests completion. In queue: 75
14:05:08.0678 0x2258 Waiting for KSN requests completion. In queue: 75
14:05:09.0735 0x2258 AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.7.205.0 ), 0x61100 ( enabled : updated )
14:05:09.0742 0x2258 Win FW state via NFP2: enabled
14:05:29.0743 0x2258 ============================================================
14:05:29.0743 0x2258 Scan finished
14:05:29.0743 0x2258 ============================================================
14:05:29.0772 0x224c Detected object count: 0
14:05:29.0772 0x224c Actual detected object count: 0
14:10:43.0627 0x2180 Deinitialize success

DarrenC
Novice
Novice

Posts Posts : 34
Joined Joined : 2015-03-26
OS OS : Windows 8.1
Points Points : 6698
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Trojan.DNSChanger and SearchScopes

Post by Superdave on Thu Apr 16, 2015 9:59 pm

What's the status of the computer now?

Superdave
Captain
Captain

Posts Posts : 4202
Joined Joined : 2010-02-01
Gender Gender : Male
OS OS : Windows 8.1 and a dual-boot with XP Home SP3
Protection Protection : MSE, Windows Defender, Windows firewall
Points Points : 83171
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Trojan.DNSChanger and SearchScopes

Post by DarrenC on Mon Apr 20, 2015 4:21 pm

==================================
08:25:13.0710 0x2b94 [ F349D616FC879D42E62A08BA18D53153 ] \Device\Harddisk0\DR0\Partition1
08:25:13.0741 0x2b94 \Device\Harddisk0\DR0\Partition1 - ok
08:25:13.0757 0x2b94 [ 6B3604872C1D0AB6EEF9E8F55E6C8275 ] \Device\Harddisk0\DR0\Partition2
08:25:13.0772 0x2b94 \Device\Harddisk0\DR0\Partition2 - ok
08:25:13.0788 0x2b94 [ A4425078424A8B22CA8325A649C43F11 ] \Device\Harddisk0\DR0\Partition3
08:25:13.0788 0x2b94 \Device\Harddisk0\DR0\Partition3 - ok
08:25:13.0788 0x2b94 [ C257F49A886D0C4FE22B2F67905CF952 ] \Device\Harddisk0\DR0\Partition4
08:25:13.0819 0x2b94 \Device\Harddisk0\DR0\Partition4 - ok
08:25:13.0851 0x2b94 [ 3F6D5BA1AABA1244C5E896B49006D81A ] \Device\Harddisk0\DR0\Partition5
08:25:13.0866 0x2b94 \Device\Harddisk0\DR0\Partition5 - ok
08:25:13.0872 0x2b94 [ 809537E426045146AF9D29A2EF90F984 ] \Device\Harddisk1\DR1\Partition1
08:25:13.0875 0x2b94 \Device\Harddisk1\DR1\Partition1 - ok
08:25:13.0876 0x2b94 ================ Scan generic autorun ======================
08:25:13.0929 0x2b94 [ 0B091BD3E8F6BD5F985DE8E3DF17D837, 7082AFB9EE8EE2EAAAFA0DB129505117E2BA1D7059B193E0DEF514080F77D1BE ] C:\Windows\system32\igfxtray.exe
08:25:13.0945 0x2b94 IgfxTray - ok
08:25:13.0976 0x2b94 [ 1ECC8D5528F535EC6CECFB824B349418, 4035CD388A437F1564C6E4E86787756CF196CD0DFDDAD4DAFABDB583D370FF4F ] C:\Windows\system32\hkcmd.exe
08:25:14.0007 0x2b94 HotKeysCmds - ok
08:25:14.0085 0x2b94 [ 1B8C1C4B77BE157E322A05118A2E25E1, 978C8A511544DE5BC7BCB31B675356E8E764EFC435BCCDF360C8635668D6B072 ] C:\Windows\system32\igfxpers.exe
08:25:14.0115 0x2b94 Persistence - ok
08:25:14.0471 0x2b94 [ 586154542F56C285E6F53E4727928780, 7D009AE4310DF49492D20F3363C0A21A1461A6948809883266027D86A1EE87D5 ] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
08:25:14.0767 0x2b94 RTHDVCPL - ok
08:25:14.0783 0x2b94 SynTPEnh - ok
08:25:14.0830 0x2b94 [ D0B542256A968DFCB8896C140FCE6047, 3F92A9871B521BCCCDFE6D9BFF88930B26C5DB86F6F6578554A3F2ECC5C5EBA0 ] C:\Program Files\iTunes\iTunesHelper.exe
08:25:14.0830 0x2b94 iTunesHelper - ok
08:25:14.0939 0x2b94 [ E2043ABD9E13E1B7BF74B1D05E15AA47, B59953E4F2392858601551A4FA2024742B99E6AF48D71C3155548C97E25A1FA9 ] C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe
08:25:14.0971 0x2b94 HPMessageService - ok
08:25:15.0209 0x2b94 [ 4CDF90E852837C827C855F8E8E2C5FE2, 1918CE3A880E2067D52C538096DA2D35DFCA2D742E2ED370CF2DFE22840024FD ] C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe
08:25:15.0506 0x2b94 Intuit SyncManager - ok
08:25:15.0573 0x2b94 [ 34D296AFC913E302953C70463EF09A48, BC413307CBC56C039EE8A05B51A56E14EF59678FBB33815AEB320078056C8CE7 ] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
08:25:15.0583 0x2b94 HP Software Update - ok
08:25:15.0723 0x2b94 [ 22F7B9670AD770C7ED7F4738204C8E5C, 7B793AC094CB1B073419B5DAE09DFBB8EBED03D29301F490AA76EA0667613438 ] C:\Program Files\HP\HP Officejet 6600\Bin\ScanToPCActivationApp.exe
08:25:15.0803 0x2b94 HP Officejet 6600 (NET) - ok
08:25:15.0823 0x2b94 Skype - ok
08:25:15.0973 0x2b94 [ ACD929D8754B63BBBB68B48B96F8A99E, E4DD488BA151AAB58FC00458F69D5A7AC191BA488F2BDAF88BE432C24250AF94 ] C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe
08:25:16.0073 0x2b94 Advanced SystemCare 8 - ok
08:25:16.0173 0x2b94 [ CE9806603D3C635EA6E0BB79FE916D2E, E544A661AF49DF835D27748B75D2DC36CAA2A224CB385B406D32FC541B12C6C4 ] C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
08:25:16.0203 0x2b94 GoogleChromeAutoLaunch_D767CAD71DA7DD1CDFD0D3EF6D1B23BA - ok
08:25:16.0203 0x2b94 Waiting for KSN requests completion. In queue: 135
08:25:17.0209 0x2b94 Waiting for KSN requests completion. In queue: 135
08:25:18.0210 0x2b94 Waiting for KSN requests completion. In queue: 135
08:25:19.0223 0x2b94 Waiting for KSN requests completion. In queue: 135
08:25:20.0256 0x2b94 AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.7.205.0 ), 0x61100 ( enabled : updated )
08:25:20.0271 0x2b94 Win FW state via NFP2: enabled
08:25:32.0797 0x2b94 ============================================================
08:25:32.0797 0x2b94 Scan finished
08:25:32.0797 0x2b94 ============================================================
08:25:32.0812 0x2b8c Detected object count: 0
08:25:32.0812 0x2b8c Actual detected object count: 0


Just finished running TDSSKiller. Nothing found, but I still have pop-ups

DarrenC
Novice
Novice

Posts Posts : 34
Joined Joined : 2015-03-26
OS OS : Windows 8.1
Points Points : 6698
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Trojan.DNSChanger and SearchScopes

Post by DarrenC on Mon Apr 20, 2015 5:00 pm

Malwarebytes Anti-Malware
[You must be registered and logged in to see this link.]

Scan Date: 4/20/2015
Scan Time: 9:20:15 AM
Logfile:
Administrator: Yes

Version: 2.01.4.1018
Malware Database: v2015.04.20.03
Rootkit Database: v2015.03.31.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 8.1
CPU: x64
File System: NTFS
User: Michelle

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 356563
Time Elapsed: 32 min, 5 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 1
Trojan.DNSChanger, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS\Interfaces\{5EA0F310-66E7-47DE-8308-90A94C0279A0}|NameServer, 31.168.228.251,82.166.96.251, Good: (), Bad: (31.168.228.251,82.166.96.251),,[e6edbcb2e8a294a29d3d4cb8bb4b44bc]

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)


(end)

This is the same item I've had since the beginning

DarrenC
Novice
Novice

Posts Posts : 34
Joined Joined : 2015-03-26
OS OS : Windows 8.1
Points Points : 6698
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Trojan.DNSChanger and SearchScopes

Post by DarrenC on Mon Apr 20, 2015 5:19 pm

# AdwCleaner v4.201 - Logfile created 20/04/2015 at 10:15:08
# Updated 08/04/2015 by Xplode
# Database : 2015-04-19.4 [Server]
# Operating system : Windows 8.1 (x64)
# Username : Michelle - MICHELLE-LAPTOP
# Running from : C:\Users\Michelle\Downloads\adwcleaner_4.201.exe
# Option : Scan

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Found : C:\Windows\SysWOW64\config\systemprofile\AppData\Local\VCL

***** [ Scheduled tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****


***** [ Web browsers ] *****

#NAME?


-\\ Mozilla Firefox v37.0.1 (x86 en-US)


#NAME?


*************************

AdwCleaner[R0].txt - [725 bytes] - [20/04/2015 10:15:08]

########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [783 bytes] ##########

DarrenC
Novice
Novice

Posts Posts : 34
Joined Joined : 2015-03-26
OS OS : Windows 8.1
Points Points : 6698
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Trojan.DNSChanger and SearchScopes

Post by Superdave on Mon Apr 20, 2015 6:57 pm

Is it affecting the operation of your computer?

Superdave
Captain
Captain

Posts Posts : 4202
Joined Joined : 2010-02-01
Gender Gender : Male
OS OS : Windows 8.1 and a dual-boot with XP Home SP3
Protection Protection : MSE, Windows Defender, Windows firewall
Points Points : 83171
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Trojan.DNSChanger and SearchScopes

Post by DarrenC on Mon Apr 20, 2015 8:02 pm

What do you mean?

I cannot run Chrome properly without pop-ups

DarrenC
Novice
Novice

Posts Posts : 34
Joined Joined : 2015-03-26
OS OS : Windows 8.1
Points Points : 6698
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Trojan.DNSChanger and SearchScopes

Post by Superdave on Tue Apr 21, 2015 12:39 am

[You must be registered and logged in to see this link.] wrote:What do you mean?

I cannot run Chrome properly without pop-ups
Does it happen with other browsers?

Superdave
Captain
Captain

Posts Posts : 4202
Joined Joined : 2010-02-01
Gender Gender : Male
OS OS : Windows 8.1 and a dual-boot with XP Home SP3
Protection Protection : MSE, Windows Defender, Windows firewall
Points Points : 83171
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Trojan.DNSChanger and SearchScopes

Post by DarrenC on Tue Apr 21, 2015 4:12 pm

Just Chrome

DarrenC
Novice
Novice

Posts Posts : 34
Joined Joined : 2015-03-26
OS OS : Windows 8.1
Points Points : 6698
# Likes # Likes : 0

View user profile

Back to top Go down

Page 1 of 2 1, 2  Next

View previous topic View next topic Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum