Windows update error code FFFFFFF [Solved/Closed]

punitive 13 Posts Sunday April 11, 2010Registration date April 24, 2010 Last seen - Apr 21, 2010 at 06:24 AM - Latest reply: Kamrul08 27 Posts Monday November 28, 2011Registration date December 22, 2011 Last seen
- Dec 14, 2011 at 10:15 AM
hello all

ok I have a problem with windows updating, I get an error (code FFFFFFFF) im running windows vista.
i cosequently get bluescreened alot.
i have searched the internet thourouly and have found that the above code is generated from a virus, it all points to (MS10-015) which is (Alureon rootkit)
now this problem can of coarse be cured by formatting BUT im sure there is someone out there that can tell me differently? im really hoping its just a case of deleting some files and voilla.

please help (any information will be gratefully recieved)

thx
See more 

11 replies

Ambucias 53263 Posts Monday February 1, 2010Registration dateModeratorStatus July 19, 2018 Last seen - Apr 21, 2010 at 06:54 AM
0
Thank you
Hi there,

Somehow, your problem seems familiar!

So you get the "blue screen of death"?

Indeed blue screen may be cause by aluron rootkit.

I suggest to you the following:

To keep your system safe, you must follow the instructions hereunder to the letter:

1. Download Combofix to your desktop.

http://www.combofix.org/download.php

2.Close all open Windows including this one.

Close or disable all running Antivirus, Antispyware, and Firewall programs as they may interfere with the proper running of ComboFix.

3. Double click on the ComboFix icon.

Windows is issuing this prompt because ComboFix does not have a digital signature. This is perfectly normal and safe and you can click on the Run button to continue.

4. Accept the disclaimer and the recovery

5.You should now press the Yes button to continue. If at any time during the Recovery Console installation you receive a message stating that it failed to install, please allow ComboFix to continue with the scan of your computer.

ComboFix will disconnect your computer from the Internet, so do not be surprised or concerned if you receive any warnings stating that you are no longer on the Internet. When ComboFix has finished it will automatically restore your Internet connection.

While the program is scanning your computer, it will change your clock format, so do not be concerned when you see this happen. When ComboFix is finished it will restore your clock settings to their previous settings.

If you see your Windows desktop disappear, do not worry. This is normal and ComboFix will restore your desktop before it is finished. Eventually you will see a new screen that states the program is almost finished and telling you the programs log file, or report, will be located at C:\ComboFix.txt.

Once you are done, paste the log here and report to me on how your system is behaving.

Good luck

Ambucias
punitive 13 Posts Sunday April 11, 2010Registration date April 24, 2010 Last seen - Apr 23, 2010 at 07:03 AM
no errors found in scannow or malaware, so all seems ok and I havnt had a bluescreen in 18 hours :) yeah
tyvm
Ambucias 53263 Posts Monday February 1, 2010Registration dateModeratorStatus July 19, 2018 Last seen - Apr 23, 2010 at 07:09 AM
Hi

The scannow recovers missing files that's why.

Now, do me a favor, turn off your system restore for about 45 seconds and turn it back on. Then create a new restore point, it will give you a safe point to return to in case of a problem. You can name it after me if you wish.

Mark! Be careful out there on the Web because someday worst can happen.

Regards
punitive 13 Posts Sunday April 11, 2010Registration date April 24, 2010 Last seen - Apr 24, 2010 at 05:08 AM
done all that thx again, all malaeare/antivirus/firewalls are now enabled :)
ComboFix 11-12-13.03 - FIRAS 12/14/2011 23:45:53.2.2 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3574.2435 [GMT 8:00]
Running from: c:\users\FIRAS\Downloads\ComboFix.exe
AV: AVG Internet Security 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
FW: AVG Firewall *Disabled* {621CC794-9486-F902-D092-0484E8EA828B}
SP: AVG Internet Security 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: IObit Malware Fighter *Enabled/Updated* {A751AC20-3B48-5237-898A-78C4436BB78D}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\FIRAS\AppData\Roaming\FIRASlog.dat
.
.
((((((((((((((((((((((((( Files Created from 2011-11-14 to 2011-12-14 )))))))))))))))))))))))))))))))
.
.
2011-12-14 15:49 . 2011-12-14 15:49 -------- d-----w- c:\users\FIRAS\AppData\Local\temp
2011-12-14 15:49 . 2011-12-14 15:49 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-12-14 09:39 . 2011-12-14 09:39 -------- d-----w- c:\users\FIRAS\AppData\Local\Mozilla
2011-12-14 05:04 . 2011-12-14 05:04 56200 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{41ACCC28-9EA0-4EEE-9BAC-DBD2F5098417}\offreg.dll
2011-12-13 07:34 . 2011-12-13 07:34 -------- d-----w- c:\users\FIRAS\AppData\Local\PowerChallenge
2011-12-10 19:34 . 2011-12-14 02:32 -------- d-----w- c:\users\FIRAS\AppData\Roaming\Xfire
2011-12-10 19:34 . 2011-12-12 03:44 -------- d-----w- c:\programdata\Xfire
2011-12-10 19:34 . 2011-12-10 19:34 -------- d-----w- c:\program files\Xfire
2011-12-10 17:33 . 2011-12-10 17:33 -------- d-----w- c:\users\FIRAS\AppData\Local\GamersFirst LIVE!
2011-12-10 17:26 . 2011-12-10 17:26 -------- d-----w- c:\program files\Pando Networks
2011-12-10 17:26 . 2011-12-13 07:21 -------- d-----w- c:\program files\GamersFirst
2011-12-08 12:10 . 2011-12-08 12:10 -------- d-----w- c:\users\FIRAS\jagexcache
2011-12-08 04:58 . 2011-12-08 04:58 -------- d-----w- c:\program files\NVIDIA Corporation
2011-12-08 04:57 . 2011-12-08 04:57 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2011-12-08 04:15 . 2011-12-08 04:15 -------- d-----w- c:\program files\PowerISO
2011-12-08 04:04 . 2011-12-08 04:07 -------- d-----w- C:\Arquivos de programas
2011-12-08 01:04 . 2011-12-14 03:48 -------- d-----w- c:\users\FIRAS\AppData\Roaming\DMCache
2011-12-07 15:43 . 2011-12-07 15:43 -------- d-----w- c:\users\FIRAS\AppData\Local\Microsoft Games
2011-12-07 15:27 . 2011-12-07 15:27 -------- d-----w- c:\program files\Software
2011-12-07 13:34 . 2003-09-02 18:28 724992 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iKernel.dll
2011-12-07 13:34 . 2003-09-02 18:27 69715 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\ctor.dll
2011-12-07 13:34 . 2003-09-02 18:26 266240 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iscript.dll
2011-12-07 13:34 . 2003-09-02 18:26 192512 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iuser.dll
2011-12-07 13:34 . 2003-09-02 18:25 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\DotNetInstaller.exe
2011-12-07 13:34 . 2003-09-02 18:23 32768 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\Objectps.dll
2011-12-07 13:34 . 2011-12-07 13:34 311428 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\Setup.dll
2011-12-07 13:34 . 2011-12-07 13:34 184452 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iGdi.dll
2011-12-07 06:42 . 2011-11-21 10:47 6823496 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{41ACCC28-9EA0-4EEE-9BAC-DBD2F5098417}\mpengine.dll
2011-12-07 06:30 . 2011-09-29 09:30 80416 ----a-w- c:\windows\system32\RtNicProp32.dll
2011-12-07 06:30 . 2011-09-29 09:30 490088 ----a-w- c:\windows\system32\drivers\Rt86win7.sys
2011-12-07 06:21 . 2011-10-19 14:15 20312 ----a-w- c:\windows\system32\RegistryDefragBootTime.exe
2011-12-07 06:16 . 2011-08-19 08:33 25944 ----a-w- c:\windows\system32\SmartDefragBootTime.exe
2011-12-07 06:16 . 2010-11-26 10:02 15672 ----a-w- c:\windows\system32\drivers\SmartDefragDriver.sys
2011-12-07 06:16 . 2011-12-08 00:45 -------- d-----w- c:\users\FIRAS\AppData\Roaming\IObit
2011-12-07 06:16 . 2011-12-07 06:16 -------- d-----w- c:\program files\IObit Toolbar
2011-12-07 06:16 . 2011-12-07 06:16 -------- d-----w- c:\program files\Application Updater
2011-12-07 06:16 . 2011-12-07 06:16 -------- d-----w- c:\program files\Common Files\Spigot
2011-12-07 06:15 . 2011-12-07 06:17 -------- d-----w- c:\programdata\IObit
2011-12-07 06:15 . 2011-12-07 06:16 -------- d-----w- c:\program files\IObit
2011-12-06 01:48 . 2011-12-06 01:48 -------- d-----w- c:\users\FIRAS\AppData\Local\Apps
2011-12-06 01:48 . 2011-12-07 09:57 -------- d-----w- c:\users\FIRAS\AppData\Local\Deployment
2011-12-06 01:17 . 2011-12-12 13:57 -------- d-----w- c:\program files\SystemRequirementsLab
2011-12-06 01:17 . 2011-12-12 13:57 -------- d-----w- c:\users\FIRAS\AppData\Roaming\SystemRequirementsLab
2011-12-05 14:05 . 2011-12-05 14:05 -------- d-----w- c:\users\FIRAS\AppData\Roaming\Megaupload
2011-11-30 00:19 . 2011-12-08 08:35 -------- d-----w- c:\program files\Counter-Strike Xtreme V6
2011-11-29 15:17 . 2011-12-07 06:02 737072 ----a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore-2\Microsoft.MediaCenter.Sports.UI.dll
2011-11-29 15:16 . 2011-12-07 06:02 4283672 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll
2011-11-29 15:16 . 2011-12-07 05:51 42776 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll
2011-11-29 15:16 . 2011-11-29 15:16 539968 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2011-11-29 14:30 . 2011-11-29 14:30 -------- d-----w- c:\program files\Megaupload
2011-11-29 14:19 . 2011-12-08 12:09 -------- d--h--w- c:\program files\InstallShield Installation Information
2011-11-29 14:13 . 2004-02-26 16:00 962612 ----a-w- c:\windows\system32\mfc42d.dll
2011-11-29 14:13 . 2004-02-16 16:00 434252 ----a-w- c:\windows\system32\MSVCRTD.DLL
2011-11-29 14:13 . 2007-12-17 09:14 12400 ----a-w- c:\windows\system32\drivers\AsIO.sys
2011-11-29 14:13 . 2006-01-10 08:50 24576 ----a-w- c:\windows\system32\AsIO.dll
2011-11-29 14:13 . 2011-12-08 12:09 -------- d-----w- c:\program files\ASUS
2011-11-29 14:09 . 2009-05-13 11:11 6504 ----a-w- c:\windows\system32\drivers\ASACPI.sys
2011-11-29 14:08 . 2011-11-29 14:08 -------- d-----w- c:\users\FIRAS\.swt
2011-11-29 14:00 . 2011-12-14 13:06 -------- d-----w- c:\users\FIRAS\AppData\Local\Akamai
2011-11-29 14:00 . 2011-11-29 14:02 -------- d-----w- c:\users\FIRAS\.nexus
2011-11-29 14:00 . 2011-11-29 14:07 -------- d-----w- C:\botclient
2011-11-29 13:27 . 2011-11-29 13:29 -------- d-----w- c:\users\FIRAS\AppData\Roaming\EpicBot
2011-11-29 13:25 . 2011-11-29 13:25 -------- d-sh--w- c:\windows\system32\AI_RecycleBin
2011-11-29 13:25 . 2011-11-29 13:25 -------- d-----w- c:\programdata\W3i
2011-11-29 13:25 . 2011-11-29 13:25 -------- d-----w- c:\program files\W3i
2011-11-29 13:25 . 2011-11-29 13:25 -------- d-----w- c:\program files\EpicBot
2011-11-29 13:24 . 2011-11-29 13:24 -------- d-----w- c:\program files\Free Offers from Freeze.com
2011-11-29 13:22 . 2011-09-29 16:03 1290608 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-11-29 13:22 . 2011-12-14 05:53 -------- d-----w- c:\program files\Steam
2011-11-29 13:22 . 2011-10-01 04:37 708608 ----a-w- c:\program files\Common Files\System\wab32.dll
2011-11-29 13:22 . 2011-09-29 03:37 2341888 ----a-w- c:\windows\system32\win32k.sys
2011-11-15 03:50 . 2011-11-15 03:50 112096 ----a-w- c:\windows\system32\drivers\scdemu.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-10 20:12 . 2011-10-28 12:46 138056 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2011-12-10 20:12 . 2011-10-28 12:46 138056 ----a-w- c:\users\FIRAS\AppData\Roaming\PnkBstrK.sys
2011-12-10 20:12 . 2011-10-28 12:46 189248 ----a-w- c:\windows\system32\PnkBstrB.exe
2011-12-10 20:12 . 2011-10-28 12:46 189248 ----a-w- c:\windows\system32\PnkBstrB.ex0
2011-12-10 20:12 . 2011-10-28 12:45 75136 ----a-w- c:\windows\system32\PnkBstrA.exe
2011-12-05 14:08 . 2011-10-22 12:04 737072 ----a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore\Microsoft.MediaCenter.Sports.UI.dll
2011-12-05 14:07 . 2011-10-22 12:04 4283672 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll
2011-12-05 14:07 . 2011-10-22 12:04 42776 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll
2011-12-05 14:07 . 2011-10-22 12:04 539984 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2011-12-05 14:06 . 2011-10-18 23:48 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-30 19:16 . 2011-10-30 19:16 232512 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2011-10-30 18:50 . 2011-10-30 18:50 3696 ----a-w- c:\windows\system32\ealregsnapshot1.reg
2011-10-20 06:53 . 2011-10-20 06:53 12920 ----a-w- c:\windows\system32\apl001.sys
2011-10-20 06:53 . 2011-10-20 06:53 10872 ----a-w- c:\windows\system32\apf001.sys
2011-10-20 02:41 . 2011-10-20 02:41 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-10-20 01:47 . 2009-07-14 02:05 152576 ----a-w- c:\windows\system32\msclmd.dll
2011-10-19 16:02 . 2011-10-19 16:02 86528 ----a-w- c:\windows\system32\iesysprep.dll
2011-10-19 16:02 . 2011-10-19 16:02 76800 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-10-19 16:02 . 2011-10-19 16:02 74752 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-10-19 16:02 . 2011-10-19 16:02 74752 ----a-w- c:\windows\system32\iesetup.dll
2011-10-19 16:02 . 2011-10-19 16:02 63488 ----a-w- c:\windows\system32\tdc.ocx
2011-10-19 16:02 . 2011-10-19 16:02 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-10-19 16:02 . 2011-10-19 16:02 420864 ----a-w- c:\windows\system32\vbscript.dll
2011-10-19 16:02 . 2011-10-19 16:02 367104 ----a-w- c:\windows\system32\html.iec
2011-10-19 16:02 . 2011-10-19 16:02 35840 ----a-w- c:\windows\system32\imgutil.dll
2011-10-19 16:02 . 2011-10-19 16:02 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-10-19 16:02 . 2011-10-19 16:02 23552 ----a-w- c:\windows\system32\licmgr10.dll
2011-10-19 16:02 . 2011-10-19 16:02 1798144 ----a-w- c:\windows\system32\jscript9.dll
2011-10-19 16:02 . 2011-10-19 16:02 161792 ----a-w- c:\windows\system32\msls31.dll
2011-10-19 16:02 . 2011-10-19 16:02 152064 ----a-w- c:\windows\system32\wextract.exe
2011-10-19 16:02 . 2011-10-19 16:02 150528 ----a-w- c:\windows\system32\iexpress.exe
2011-10-19 16:02 . 2011-10-19 16:02 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2011-10-19 16:02 . 2011-10-19 16:02 1427456 ----a-w- c:\windows\system32\inetcpl.cpl
2011-10-19 16:02 . 2011-10-19 16:02 11776 ----a-w- c:\windows\system32\mshta.exe
2011-10-19 16:02 . 2011-10-19 16:02 1126912 ----a-w- c:\windows\system32\wininet.dll
2011-10-19 16:02 . 2011-10-19 16:02 110592 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-10-19 16:02 . 2011-10-19 16:02 101888 ----a-w- c:\windows\system32\admparse.dll
2011-09-29 09:30 . 2011-06-09 22:34 100896 ----a-w- c:\windows\system32\RTNUninst32.dll
2011-09-26 21:58 . 2011-10-22 19:33 3461120 ----a-w- c:\windows\system32\steam.dll
2011-11-21 04:04 . 2011-12-14 09:37 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-10-18 39408]
"Mega Manager"="c:\program files\Megaupload\Mega Manager\MegaManager.exe" [2011-09-08 2116608]
"DAEMON Tools Pro Agent"="c:\program files\DAEMON Tools Pro\DTAgent.exe" [2011-08-17 4527424]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
"Steam"="c:\program files\Steam\Steam.exe" [2011-12-12 1242448]
"Akamai NetSession Interface"="c:\users\FIRAS\AppData\Local\Akamai\netsession_win.exe" [2011-12-06 3305248]
"Advanced SystemCare 5"="c:\program files\IObit\Advanced SystemCare 5\ASCTray.exe" [2011-12-12 619352]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-23 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-23 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-23 150552]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"EasyDownloads"="c:\program files\Easy Downloads\easydownloads.exe" [2011-10-29 854040]
"SearchSettings"="c:\program files\Common Files\Spigot\Search Settings\SearchSettings.exe" [2011-11-15 896352]
"IObit Malware Fighter"="c:\program files\IObit\IObit Malware Fighter\IMF.exe" [2011-10-08 4441944]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2011-11-15 312376]
.
c:\users\FIRAS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Xfire.lnk - c:\program files\Xfire\Xfire.exe [2011-6-25 3504640]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
GamersFirst LIVE!.lnk - c:\program files\GamersFirst\LIVE!\Live.exe [2011-8-16 2589808]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]
@="Service"
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-10-18 136176]
R3 apf001;apf001;c:\game\SoftnyxGame\WolfTeamIS\apf001.sys [2011-07-07 10872]
R3 GGSAFERDriver;GGSAFER Driver; [x]
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2011-10-18 136176]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 UrlFilter;UrlFilter;c:\program files\IObit\IObit Malware Fighter\drivers\win7_x86\UrlFilter.sys [2011-09-20 19792]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-10-19 1343400]
R4 FileMonitor;FileMonitor;c:\program files\IObit\IObit Malware Fighter\Drivers\win7_x86\FileMonitor.sys [2011-10-08 18768]
S0 SmartDefragDriver;SmartDefragDriver;c:\windows\System32\Drivers\SmartDefragDriver.sys [2010-11-26 15672]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2011-10-30 232512]
S2 AdvancedSystemCareService5;Advanced SystemCare Service 5;c:\program files\IObit\Advanced SystemCare 5\ASCService.exe [2011-12-12 494424]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 20992]
S2 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [2011-11-15 746392]
S2 IMFservice;IMF Service;c:\program files\IObit\IObit Malware Fighter\IMFsrv.exe [2011-10-08 820568]
S3 RegFilter;RegFilter;c:\program files\IObit\IObit Malware Fighter\drivers\win7_x86\regfilter.sys [2011-09-20 30600]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2011-09-29 490088]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-10-18 23:48]
.
2011-12-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-10-18 23:48]
.
2011-12-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-658857085-755703313-3253920453-1001Core.job
- c:\users\FIRAS\AppData\Local\Google\Update\GoogleUpdate.exe [2011-10-19 15:31]
.
2011-12-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-658857085-755703313-3253920453-1001UA.job
- c:\users\FIRAS\AppData\Local\Google\Update\GoogleUpdate.exe [2011-10-19 15:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\FIRAS\AppData\Roaming\Mozilla\Firefox\Profiles\w3zoviyz.default\
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-658857085-755703313-3253920453-1001_Classes\CLSID\{3ba512e0-d5b3-4fee-88f5-f575ee11b386}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"Model"=dword:0000015b
"Therad"=dword:00000007
.
[HKEY_USERS\S-1-5-21-658857085-755703313-3253920453-1001_Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"scansk"=hex(0):71,53,fb,2b,43,be,ed,94,2b,dc,4c,89,f6,38,08,ab,67,87,e1,cf,d7,
90,e1,87,65,a9,9e,d8,3e,43,cc,7b,2b,32,1d,53,55,ba,20,30,00,00,00,00,00,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-12-14 23:50:33
ComboFix-quarantined-files.txt 2011-12-14 15:50
ComboFix2.txt 2011-12-14 15:38
.
Pre-Run: 10,602,487,808 bytes free
Post-Run: 10,559,733,760 bytes free
.
- - End Of File - - 0C521D5C616CB006713533C122C25750
Kamrul08 27 Posts Monday November 28, 2011Registration date December 22, 2011 Last seen - Dec 14, 2011 at 10:15 AM
Good suggestion.