[list]Hi,
Multiple Antivirus Programs
You are running more than 1 Antivirus program!
AV: avast! Antivirus Disabled/Updated
AV: AVG Internet Security 2013 Disabled/Updated
Running - more than one - antivirus program is not recommended because:
[*]They can conflict with each other.
[*]Report the other antivirus software as malicious.
[*]Antivirus programs use an enormous amount of computer’s resources… actively scanning your computer.
[*]Can cause your computer to become unstable…run slowly and even, in rare cases, BSOD crash…etc
I strongly suggest you uninstall one of them. Which one, is your decision.
Open notepad and copy/paste the text present inside the code box below:
Folder::
c:\users\Jack Foley\AppData\Roaming\Microsoft\Network\Connections\Pbk\_hiddenPbk
DirLook::
c:\users\Jack Foley\.shsh
c:\users\Jack Foley\AppData\Roaming\redsn0w
FileLook::
c:\windows\system32\drivers\tapSF0901.sys
Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSIDLL"=-
Driver::
vToolbarUpdater15.1.0
KillAll::
File::
c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.1.0\ToolbarUpdater.exe
RegNull::
[HKEY_USERS\S-1-5-21-3130723657-4083518555-1479036497-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{1695CB16-A955-5ED1-79D1-F0D7D3560BA9}*]
"iamccjfjlmckbcdikg"=hex:69,61,63,67,64,6d,6c,65,6b,6f,63,6d,68,69,6f,62,62,6c,
00,04
"hagdmjknmnfhpbdp"=hex:69,61,63,67,64,6d,6c,65,6b,6f,63,6d,68,69,6f,62,62,6c,
00,00
"halbobggiflpihen"=hex:66,61,6f,66,69,68,61,64,62,6c,6c,68,00,f5
[HKEY_USERS\S-1-5-21-3130723657-4083518555-1479036497-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{537BD1E7-FE65-0D90-EEAB-65734BD8CA8F}*]
"iaehpfnnhmikbdnhmd"=hex:6a,61,6e,6d,65,6d,62,6e,65,64,68,6e,69,68,6b,68,6d,68,
6f,6c,00,00
"haghfmdnhdehnmdg"=hex:6a,61,6e,6d,65,6d,62,6e,65,64,68,6e,69,68,6b,68,6d,68,
6f,6c,00,00
"gapanhoimljpoe"=hex:6b,61,6b,6d,6f,69,67,64,6b,64,6a,70,65,62,61,6b,64,6b,6b,
66,6c,6e,00,80
Save this as CFScript.txt
http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
Close all browser windows and refering to the picture above.
Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
ComboFix will will re-run. When finished, it will produce a log for you.
Attach the contents of the log in your next reply. (typical location: C:[b]ComboFix.txt[/b] )
Re-run zoek.exe as you did before but use this script:
msitzk32.dll;z
msitzk32.dll;a
C:\Users\Jack Foley\AppData\Local\CrashDumps\dwm.exe.*.dmp;f
emptyalltemp;
autoclean;
Click on RunScript button and attach here fresh zoek log