...bringing home all sorts of who-knows-what ;-) I would be most appreciative for some assistance in cleaning the goblins out of her...
Because I can tell y'all like a challenge (not really, I was simply ignorant) I have done most of the things a user is directed NOT to do prior to your assistance, as enumerated in the "before you post" thread. Sorry Specifically, before admitting that I'm out of my depth, I tried many and various means for removal of the shadowy software lurking in my PC -- registry cleaning (a la Glary Utilities), a couple of anti spyware/root kit tools like Malwarebytes, AVG (until I got fed up & tried to remove it), and then I found Hiran's Boot CD -- and in one blurred, frenzied and ineffective night I tried all sorts of options in the suite of tools. Combofix included, but although I opened the program, I don't think I used any of its tools, but not sure. Also tried ClamWin AV, which is the only thing that named some of the elusive trojans. Here is that scan log; infected files are at the end:
Scan Started Mon Aug 19 15:21:03 2013
-------------------------------------------------------------------------------
WARNING: Can't open file C:\Boot\BCD: Permission denied
WARNING: Can't open file C:\pagefile.sys: Permission denied
C:\Program Files (x86)\Creative\ShareDLL\CADI\CtPresetW.dll: moved to 'C:\Qoobox\Quarantine\CtPresetW.dll.infected'
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\033645cb82d642d47aa605cc88e0e3ca_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\049b06736804db2f5e7621bebf6ed59e_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\07bd1d916181adf10240b62971ccf64e_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\09f52e0a31fd18662690f8bd772e66e4_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\0b51c6cc08e821819fc4d861dd43abf9_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\102e8dbbecf306b873cfca4be985e399_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1148650d479f382165a373d3dbe95a90_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\121b3ed2f250f997cb71d0cdf2b59822_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\169fc132319d105a90d0644948e7bc3b_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1a14b697ac72b698323074f874c8888b_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1c7aa1bc7ce76500a52b91ec4ce58b47_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\23e0fbdbaedcfc2208c1509a8293872e_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2d478076527342ef7fcdbecb4ecdc28a_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2ecf015b6012bd91248be329bbd2bf47_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3031c930d4aa06a42755f87a67e9af8b_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3047a828acdf97013d991028b880c556_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\33b84a1097cc036a3fd4b4353cc63f69_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3c12f6e1467c4ac4966c5bb8e2f20ee3_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3da4117aeb23d4e0d33dbbc262bee0d8_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3e65d1ff502c8948ba275bdc9778e2ea_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3f91b791638dd75bbdf72f5345cd64dc_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3ff144a43259042866d488203c817df5_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\41ba34bcdb2177f953c214a169f0c227_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4240280e49be3991007efb65cbc599ff_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4591ef02cebc8ec876cac822eddeaed2_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\46d6cc5a3e6bf68989208591f0b5ebef_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4a52d2b4827844c4b4e19a12df7fd831_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4f2fb8045bc240825db618b02e093265_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\50759155b0276663b5a4a49979d5594b_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\51356229475c76892b3edfb4487c0a2f_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\57f6e27b1d1a8b0912fb77c9a58a3cd0_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\68294f27f83983725ebbab624846cbb2_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\69cc8aca239d277ad44c008e2257886a_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6b209b20d48fd8de500c0c0073e1640b_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6c9ae8a5f86c33ae67f6fc15b7ff7d8c_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6d33e26fd8288b0fb339322306765dfd_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7270e2d4532469b59a90c7bb6deba41d_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\764ff12e6bfa66cbad00cb446cbac448_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7d9dfa7d386a104a25fd530f7bf56273_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\844e98caa4582b782bcf7e623354afed_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8a4e5055d1760287dde00e446b672ea6_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8b897ef36142f0e23e409c077d20065d_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8d5bc829e84337ce16dc414c2fadc916_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8f050e05aaff7e90980ab0b5d7f83707_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9b5d0040b5a564605fb08b44ed340451_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9bb34e4a824539a9beaa5219eae3a64b_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a2917eedc30797a12920d8012653265e_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a6c82625a7a95e0c7b4284a9a1d883e2_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ab913a1d7eee1e429ec3abaff5b1620f_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ade23b912d0c3e1abae02fbb64975b76_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b19f341a36468a6a39ffb0d280f6d336_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b4e6e30a45e4aa79fa27fbddf5363b15_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b5724232facc542c4c366528017177c1_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\bc9ce41a6bc5152c1ffe764ae12143a8_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\bdf935d91b9907e0d2e14a582c308c8a_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\c1c5472bb5c698de9a3a9dfa39296ce4_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\c39dea9c049e6b8c9fca7ffdaa0e9688_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\c689064be407e1c74d7aa125e51a5dd2_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\c69a8968a46a35e3e091cc4e5d6a7e6e_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\c73add8524540e2385dd2df9e781c1b9_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\c8132611abe0e5eca0b8f7e8cbf7dd1d_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\cc0a29fb795e598881213cf0f134b1cc_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\d0ddcfc62115b7a14ea8676b7644aa5a_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\d54af066da8d738fdfcf6cfeed483166_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\d7beeb857d4435b5b77912fb7c7cb5a1_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\dd493c4537a14931d5b6e63490c65ff0_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\de66b6c415bda6afac89ca285eb7c4c5_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\e053acf0f1aafb92c4e811d259e95410_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\e07f532128c3e21aee6016e64f3872b1_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\e371cd75ca7f6c64f505d624188780c1_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ebcadaaf5291757baa797716a1aaa702_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ee9d86034348152be99975864fcf2183_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\eeabb80d0bcd3f9f8e56bc7bff52c522_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f082e472fad03cbc2b870c945d1fe78b_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f4ff103e299a22c850065b1f08e22544_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f50247895c8cca5f8feabd5efb1e0ac6_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f9ac9fa9bdd2db2c93c05d33539f7651_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fb5e40d256c3c4fbb336e1cdc2688d51_d11f5272-a737-490e-ac55-87e51c7c4e4f: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Search\Data\Applications\Windows\tmp.edb: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Bluetooth File Transfer Wizard.lnk: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\MpSfc.bin: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-EF17B81B8BEC21E07B878AA88994B27AEB19C5F2.bin.67: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-EF17B81B8BEC21E07B878AA88994B27AEB19C5F2.bin.7E: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-EF17B81B8BEC21E07B878AA88994B27AEB19C5F2.bin.80: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-EF17B81B8BEC21E07B878AA88994B27AEB19C5F2.bin.87: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-EF17B81B8BEC21E07B878AA88994B27AEB19C5F2.bin.A0: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-EF17B81B8BEC21E07B878AA88994B27AEB19C5F2.bin.VE0: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-EF17B81B8BEC21E07B878AA88994B27AEB19C5F2.bin.VE1: Permission denied
WARNING: Can't open file C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-EF17B81B8BEC21E07B878AA88994B27AEB19C5F2.bin.VF: Permission denied
C:\Qoobox\Quarantine\CtPresetW.dll.infected not moved/copied since already in quarantine
WARNING: Can't open file C:\System Volume Information\Syscache.hve: Permission denied
WARNING: Can't open file C:\System Volume Information\Syscache.hve.LOG1: Permission denied
WARNING: Can't open file C:\System Volume Information\{05f081fd-0873-11e3-9bb4-7071bc10bd06}{3808876b-c176-4e48-b7ae-04046e6cc752}: Permission denied
WARNING: Can't open file C:\System Volume Information\{0f1592b2-f269-11e2-8021-7071bc10bd06}{3808876b-c176-4e48-b7ae-04046e6cc752}: Permission denied
WARNING: Can't open file C:\System Volume Information\{1c11a4c0-fba7-11e2-b122-7071bc10bd06}{3808876b-c176-4e48-b7ae-04046e6cc752}: Permission denied
WARNING: Can't open file C:\System Volume Information\{26507b0e-056f-11e3-b4e4-7071bc10bd06}{3808876b-c176-4e48-b7ae-04046e6cc752}: Permission denied
WARNING: Can't open file C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}: Permission denied
WARNING: Can't open file C:\System Volume Information\{3bdac356-00d7-11e3-8b59-7071bc10bd06}{3808876b-c176-4e48-b7ae-04046e6cc752}: Permission denied
WARNING: Can't open file C:\System Volume Information\{681b83d7-01c4-11e3-8478-7071bc10bd06}{3808876b-c176-4e48-b7ae-04046e6cc752}: Permission denied
WARNING: Can't open file C:\System Volume Information\{7d723cd5-f88d-11e2-8073-7071bc10bd06}{3808876b-c176-4e48-b7ae-04046e6cc752}: Permission denied
WARNING: Can't open file C:\System Volume Information\{86e88912-015c-11e3-b7f3-7071bc10bd06}{3808876b-c176-4e48-b7ae-04046e6cc752}: Permission denied
WARNING: Can't open file C:\System Volume Information\{86e8894c-015c-11e3-b7f3-7071bc10bd06}{3808876b-c176-4e48-b7ae-04046e6cc752}: Permission denied
WARNING: Can't open file C:\System Volume Information\{cc871934-070a-11e3-97c7-7071bc10bd06}{3808876b-c176-4e48-b7ae-04046e6cc752}: Permission denied
WARNING: Can't open file C:\System Volume Information\{d2cbd652-0815-11e3-9608-7071bc10bd06}{3808876b-c176-4e48-b7ae-04046e6cc752}: Permission denied
WARNING: Can't open file C:\System Volume Information\{ea593ef7-05f0-11e3-94b7-7071bc10bd06}{3808876b-c176-4e48-b7ae-04046e6cc752}: Permission denied
WARNING: Can't open file C:\System Volume Information\{ea593f0e-05f0-11e3-94b7-7071bc10bd06}{3808876b-c176-4e48-b7ae-04046e6cc752}: Permission denied
WARNING: Can't open file C:\Users\Matt\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1: Permission denied
WARNING: Can't open file C:\Users\Matt\ntuser.dat.LOG1: Permission denied
C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\acrobroker.exe: moved to 'C:\Qoobox\Quarantine\acrobroker.exe.infected'
WARNING: Can't open file C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT.LOG1: Permission denied
WARNING: Can't open file C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT.LOG1: Permission denied
WARNING: Can't open file C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb: Permission denied
WARNING: Can't open file C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb: Permission denied
WARNING: Can't open file C:\Windows\System32\config\default: Permission denied
WARNING: Can't open file C:\Windows\System32\config\DEFAULT.LOG1: Permission denied
WARNING: Can't open file C:\Windows\System32\config\RegBack\DEFAULT: Permission denied
WARNING: Can't open file C:\Windows\System32\config\RegBack\SAM: Permission denied
WARNING: Can't open file C:\Windows\System32\config\RegBack\SECURITY: Permission denied
WARNING: Can't open file C:\Windows\System32\config\RegBack\SOFTWARE: Permission denied
WARNING: Can't open file C:\Windows\System32\config\RegBack\SYSTEM: Permission denied
WARNING: Can't open file C:\Windows\System32\config\sam: Permission denied
WARNING: Can't open file C:\Windows\System32\config\SAM.LOG1: Permission denied
WARNING: Can't open file C:\Windows\System32\config\security: Permission denied
WARNING: Can't open file C:\Windows\System32\config\SECURITY.LOG1: Permission denied
WARNING: Can't open file C:\Windows\System32\config\software: Permission denied
WARNING: Can't open file C:\Windows\System32\config\SOFTWARE.LOG1: Permission denied
WARNING: Can't open file C:\Windows\System32\config\system: Permission denied
WARNING: Can't open file C:\Windows\System32\config\SYSTEM.LOG1: Permission denied
WARNING: Can't open file C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDiagLog.etl: Permission denied
WARNING: Can't open file C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-Application.etl: Permission denied
WARNING: Can't open file C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventlog-Security.etl: Permission denied
WARNING: Can't open file C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-System.etl: Permission denied
WARNING: Can't open file C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTUBPM.etl: Permission denied
WARNING: Can't open file C:\Windows\System32\Microsoft\Protect\Recovery\Recovery.dat.LOG1: Permission denied
WARNING: Can't open file C:\Windows\System32\Microsoft\Protect\Recovery\Recovery.dat{02b8b5e0-ec81-11df-873b-00306724f956}.TM.blf: Permission denied
WARNING: Can't open file C:\Windows\System32\Microsoft\Protect\Recovery\Recovery.dat{02b8b5e0-ec81-11df-873b-00306724f956}.TMContainer00000000000000000001.regtrans-ms: Permission denied
WARNING: Can't open file C:\Windows\System32\Microsoft\Protect\Recovery\Recovery.dat{02b8b5e0-ec81-11df-873b-00306724f956}.TMContainer00000000000000000002.regtrans-ms: Permission denied
WARNING: Can't open file C:\Windows\Temp\TmpFile1: Permission denied
C:\Program Files (x86)\Creative\ShareDLL\CADI\CtPresetW.dll: Win.Trojan.Agent-469329 FOUND
C:\Qoobox\Quarantine\CtPresetW.dll.infected: Win.Trojan.Agent-469329 FOUND
C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\acrobroker.exe: Win.Trojan.Agent-428274 FOUND
----------- SCAN SUMMARY -----------
Known viruses: 2668520
Engine version: 0.97.6
Scanned directories: 35367
Scanned files: 192194
Infected files: 3
Not copied: 1
Data scanned: 41281.57 MB
Data read: 52875.22 MB (ratio 0.78:1)
Time: 8136.986 sec (135 m 36 s)
Re: other inconvenient actions I may have taken, well, I can't actually recall everything I did... I think that night wrapped up with me randomly deleting some [likely benign/important] files/shares/permissions I didn't recognize (as though I would really know what belongs, anyway...) then when THAT somehow failed to fix everything, I unplugged the Interwebs, turned off the PC and engaged in exclusively analog activities for a few days. Now I have turned it back on and come here, with nothing to offer except a challenge, and my useless ego in sacrifice.
The file, "attach.txt" from the DDS run, is zipped into the attachment along with aswMBR.txt and .dat which were produced once I hit the "save log" button... despite the scan still running on my C: drive. Wasn't sure you needed that part, so figured I'll get the ball rolling with what I've got, and gladly post the rest of the aswMBR log once it is done, if you wish.
That about covers it, I think that is everything I can do to complicate things. (Unless you think I ought to stick some big magnets onto the harddrive enclosure...? :-)) Thanks in advance,
Best,
Matt
PS- I know this isn't reflected in the log, but I DID just turn off the S&D Tea Timer. However, the program ignored my attempts to uncheck the "SD Helper", even when run as an admin. FYI.
I dont recognize any malware in your logs and it seems you have run several tools yourself that most likely would have cleaned anything up. Not sure what led you to think you had a malware problem.
I cant really help with the Spybot issue as I dont use it myself. Only suggestion would be that If you can locate its folder in C: Program files you might find a uninstall.exe to run, reboot then download and reinstall it.
Thank you for taking the time to review my logs. I am relieved to hear that you see no indication of malware! I wonder if my system could be remotely compromised, without any malware being present? My reason for asking (and most of the evidence that led me to believe my system is infected) is that I've had various system settings related to networking and security changing, without my knowledge or action (so far as I know). For example, at least twice I've disabled an inbound firewall rule which allows any remote computer to use SSTP to port 443, but it has re-enabled itself. Also found firewall rules apparently geared to allow me to run a DNS server.
Another example; an online port scan (SpeedGuide.net) found my port 161UDP to be open... I spent 10 minutes reading about that port, scanned again, and it was no longer listed open, simply unresponsive.
My security center service has suddenly become disabled several times, giving me a message, "The security center service cannot be started" when I try to restart it.
DNS-associated services spontaneously re-enable.
After reading that DCOM can present a security risk, I looked at the DCOM service... all options are grayed-out and unavailable to change. Normal?
A second Windows & boot-option has mysteriously appeared. When selected, I'm told the location is inaccessible, and to repair the system with the install disc. When I try that, it only sees one install and finds no problems to repair.
Day before yesterday, I found my router's firewall disabled (Motorola SB900). Set it back to highest level. An hour later, was unable to re-login to the router, had to do a hard reset to factory default. Upon regaining access, firewall was down again. Pretty sure the router ships with it enabled...
Looks like combofix did run. If you click on start in the search field type in combofix /uninstall
click ok or enter to uninstall combofix.
Next visit this page for directions on running it and the download link.
Lets see what it can did up and we will go from there.
Hi sorry about the delay; my net connection was totally hijacked! I thought I was going to have to fully reinstall Windows; even the original-disc system repair was resulting in a BSOD! Only by using regedit from the command line, and deleting all the weird networking keys I could find, was I able to finally use the Startup repair tool effectively- whew! It seems to be of note, that at one point the netstat /v command showed about a dozen ports actively listening to "eleven.ebola.cz"... not a connection I deliberately made, for sure.
Anyhoo, after getting back online, uninstalled old Combofix and installed from link provided. Followed install/run directions exactly, log follows:
Two more downloads to get. Aswmbr.exe and TDSSkiller.exe:
Please download aswMBR.exe to your desktop.
Download Aswmbr.exe to your desktop.
Right click on icon and select "run as admin."
For the question: Would you like to download latest Avast! virus definitions?" Click YES to download the additional files..then
Click the "Scan" button to start scan.
Once the scan is done click the"Save log", save it to your desktop and post it in your next reply.
Right click on TDSSKiller.exe and chose "run as admin" , then click on Change parameters.
Put a checkmark beside loaded modules box.
A reboot will be needed to apply the changes. Please reboot at the prompt to apply the change.
TDSSKiller will launch automatically after the reboot. Also your computer may seem very slow and unusable. This is normal. Give it enough time to load your background programs.
Then click on Change parameters in TDSSKiller.
Check all boxes then click OK.
Click the Start Scan button.
The scan should take no longer than 2 minutes.
If a suspicious object is detected, the default action will be Skip, click on Continue.
If malicious objects are found, they will show in the Scan results
Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.
more than one report will be created in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". The one that I need is the larger one. Please copy and paste the contents of that file here. Please Download TDSSkiller
Launch it.
Click on change parameters-Select TDLFS file system
Click on "Scan".
Please post the LOG report(log file should be in your C drive)