the usb is still not working fine even after running that tool. It has the shortcut virus.
Secondly when my pc boots up, this pops up everytime.
JRT LOG~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.4.5 (08.13.2013:1)
OS: Windows 8 Single Language x64
Ran by hassaan on Wed 08/14/2013 at 10:35:37.89
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Suspicious HKCU\..\Run entries found. Trojan:JS/Medfos.B?
Value Name Type Value Data
========================================================================================
Pokki REG_EXPAND_SZ C:\Windows\system32\rundll32.exe "%LOCALAPPDATA%\Pokki\Engine\LaunchDeskband.dll",RunLaunchDeskband
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\torch
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\torch
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{FB9AE199-EC6A-42D6-AA95-96BCF13E1391}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{FB9AE199-EC6A-42D6-AA95-96BCF13E1391}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Users\hassaan\appdata\local\torch"
~~~ FireFox
Emptied folder: C:\Users\hassaan\AppData\Roaming\mozilla\firefox\profiles\x3jt7h3g.default\minidumps [1 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Wed 08/14/2013 at 10:41:01.33
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
COMBOFIX LOGComboFix 13-08-13.03 - hassaan 08/14/2013 10:50:49.1.4 - x64
Microsoft Windows 8 Single Language 6.2.9200.0.1252.1.2057.18.3992.2686 [GMT 5:00]
Running from: c:\users\hassaan\Desktop\ComboFix.exe
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\hassaan\AppData\Roaming\IHelper
c:\users\hassaan\AppData\Roaming\IHelper\06a33effacfd719f9dd32e8c5a529c55ea333bc9\info\Contacts_0.plist
c:\users\hassaan\AppData\Roaming\IHelper\06a33effacfd719f9dd32e8c5a529c55ea333bc9\info\Contacts_1.plist
c:\users\hassaan\AppData\Roaming\IHelper\06a33effacfd719f9dd32e8c5a529c55ea333bc9\info\Contacts_2.plist
c:\users\hassaan\AppData\Roaming\IHelper\06a33effacfd719f9dd32e8c5a529c55ea333bc9\info\Contacts_3.plist
c:\users\hassaan\AppData\Roaming\IHelper\06a33effacfd719f9dd32e8c5a529c55ea333bc9\info\Contacts_4.plist
c:\users\hassaan\AppData\Roaming\IHelper\06a33effacfd719f9dd32e8c5a529c55ea333bc9\info\Contacts_5.plist
c:\users\hassaan\AppData\Roaming\IHelper\06a33effacfd719f9dd32e8c5a529c55ea333bc9\info\Contacts_6.plist
c:\users\hassaan\AppData\Roaming\IHelper\06a33effacfd719f9dd32e8c5a529c55ea333bc9\info\Contacts_7.plist
c:\users\hassaan\AppData\Roaming\IHelper\06a33effacfd719f9dd32e8c5a529c55ea333bc9\system\ArtworkDB
c:\users\hassaan\AppData\Roaming\IHelper\06a33effacfd719f9dd32e8c5a529c55ea333bc9\system\Books.plist
c:\users\hassaan\AppData\Roaming\IHelper\06a33effacfd719f9dd32e8c5a529c55ea333bc9\system\DCIM_APPLE.plist
c:\users\hassaan\AppData\Roaming\IHelper\06a33effacfd719f9dd32e8c5a529c55ea333bc9\system\iTunesCDB
c:\users\hassaan\AppData\Roaming\IHelper\06a33effacfd719f9dd32e8c5a529c55ea333bc9\system\iTunesCDB.unzip
c:\users\hassaan\AppData\Roaming\IHelper\06a33effacfd719f9dd32e8c5a529c55ea333bc9\system\MediaLibrary.sqlitedb-shm
c:\users\hassaan\AppData\Roaming\IHelper\06a33effacfd719f9dd32e8c5a529c55ea333bc9\system\MediaLibrary.sqlitedb-wal
c:\users\hassaan\AppData\Roaming\IHelper\06a33effacfd719f9dd32e8c5a529c55ea333bc9\system\MediaLibrary.sqlitedb
c:\users\hassaan\AppData\Roaming\IHelper\06a33effacfd719f9dd32e8c5a529c55ea333bc9\system\Photos.sqlite
c:\users\hassaan\AppData\Roaming\IHelper\06a33effacfd719f9dd32e8c5a529c55ea333bc9\system\Purchases.plist
c:\users\hassaan\AppData\Roaming\IHelper\06a33effacfd719f9dd32e8c5a529c55ea333bc9\system\Recordings.db
c:\users\hassaan\AppData\Roaming\IHelper\06a33effacfd719f9dd32e8c5a529c55ea333bc9\user\IMG_1508.JPG
.
.
((((((((((((((((((((((((( Files Created from 2013-07-14 to 2013-08-14 )))))))))))))))))))))))))))))))
.
.
2013-08-14 05:55 . 2013-08-14 05:55 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-08-14 05:35 . 2013-08-14 05:35 -------- d-----w- c:\windows\ERUNT
2013-08-14 05:32 . 2013-08-14 05:32 -------- d-----w- c:\programdata\Panda Security
2013-08-14 05:32 . 2013-08-14 05:32 -------- d-----w- c:\program files (x86)\Panda USB Vaccine
2013-08-13 18:42 . 2013-08-05 11:14 78161360 ----a-w- c:\windows\system32\MRT.exe
2013-08-13 18:39 . 2013-08-13 18:39 -------- d-----w- c:\program files\CCleaner
2013-08-13 18:17 . 2013-08-13 18:17 -------- d-----w- c:\users\hassaan\AppData\Roaming\Malwarebytes
2013-08-13 18:17 . 2013-08-13 18:17 -------- d-----w- c:\programdata\Malwarebytes
2013-08-13 18:17 . 2013-08-13 18:17 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2013-08-13 18:17 . 2013-04-04 09:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-08-13 18:17 . 2013-08-13 18:17 -------- d-----w- c:\users\hassaan\AppData\Local\Programs
2013-08-13 18:12 . 2013-08-13 18:29 -------- d-----w- C:\MSI
2013-07-25 04:33 . 2013-07-25 04:33 -------- d-----w- c:\users\hassaan\AppData\Roaming\IDT
2013-07-19 07:26 . 2013-07-19 15:11 -------- d-----w- c:\program files (x86)\Kepard
2013-07-18 07:59 . 2013-07-18 07:59 -------- d-----w- c:\users\hassaan\AppData\Local\Google
2013-07-18 05:52 . 2013-08-14 05:29 -------- d-----w- c:\programdata\TorchCrashHandler
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-08-10 15:14 . 2013-07-05 04:07 17536 ----a-w- c:\programdata\Microsoft\windowssampling\Sqm\Manifest\Sqm3.bin
2013-07-04 14:28 . 2012-07-26 08:13 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-06-27 09:57 . 2013-06-28 04:31 172920 ----a-w- c:\windows\system32\drivers\idmwfp.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2012-10-01 15:38 1720976 ----a-w- c:\progra~2\MICROS~1\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2012-10-01 15:38 1720976 ----a-w- c:\progra~2\MICROS~1\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2012-10-01 15:38 1720976 ----a-w- c:\progra~2\MICROS~1\Office15\GROOVEEX.DLL
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-06-21 19875432]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"BtTray"="c:\program files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BtTray.exe" [2012-08-02 363520]
"HP Quick Launch"="c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe" [2012-07-09 580512]
"HP CoolSense"="c:\program files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe" [2011-08-26 1342008]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-21 59720]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-05-15 152392]
.
c:\users\hassaan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Send to OneNote.lnk - c:\program files\Microsoft Office\Office15\ONENOTEM.EXE /tsr [2012-10-1 185992]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableCursorSuppression"= 1 (0x1)
"ConsentPromptBehaviorUser"= 3 (0x3)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoAutorun"= 1 (0x1)
.
R1 jjehnhuz;jjehnhuz;c:\windows\system32\drivers\jjehnhuz.sys;c:\windows\SYSNATIVE\drivers\jjehnhuz.sys
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe
R2 TorchCrashHandler;Torch Crash Handler;c:\users\hassaan\AppData\Local\Torch\Update\TorchCrashHandler.exe;c:\users\hassaan\AppData\Local\Torch\Update\TorchCrashHandler.exe
R3 IDMWFP;IDMWFP;c:\windows\system32\DRIVERS\idmwfp.sys;c:\windows\SYSNATIVE\DRIVERS\idmwfp.sys
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
R3 SmbDrv;SmbDrv;c:\windows\System32\drivers\Smb_driver_AMDASF.sys;c:\windows\SYSNATIVE\drivers\Smb_driver_AMDASF.sys
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\System32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys
R3 WUDFWpdMtp;WUDFWpdMtp;c:\windows\system32\DRIVERS\WUDFRd.sys;c:\windows\SYSNATIVE\DRIVERS\WUDFRd.sys
S0 iaStorA;iaStorA;c:\windows\System32\drivers\iaStorA.sys;c:\windows\SYSNATIVE\drivers\iaStorA.sys
S2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe;c:\windows\SYSNATIVE\Hpservice.exe
S2 HPWMISVC;HPWMISVC;c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe;c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
S3 BtAudioBusSrv;IVT Bluetooth Audio Bus Service;c:\windows\System32\Drivers\BtAudioBus.sys;c:\windows\SYSNATIVE\Drivers\BtAudioBus.sys
S3 BthL2caScoIfSrv;Bluetooth Profile Interface Driver Service;c:\windows\System32\Drivers\BtL2caScoIf.sys;c:\windows\SYSNATIVE\Drivers\BtL2caScoIf.sys
S3 BthLEEnum;Bluetooth Low Energy Driver;c:\windows\system32\DRIVERS\BthLEEnum.sys;c:\windows\SYSNATIVE\DRIVERS\BthLEEnum.sys
S3 btUrbFilterDrv;IVT URB Bluetooth Filter Driver Service;c:\windows\System32\Drivers\IvtUrbBtFlt.sys;c:\windows\SYSNATIVE\Drivers\IvtUrbBtFlt.sys
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys
S3 netr28x;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28x.sys;c:\windows\SYSNATIVE\DRIVERS\netr28x.sys
S3 RSBASTOR;Realtek PCIE CardReader Driver - BA;c:\windows\system32\DRIVERS\RtsBaStor.sys;c:\windows\SYSNATIVE\DRIVERS\RtsBaStor.sys
S3 rtbth;RTBTH Bluetooth Device Driver;c:\windows\System32\drivers\rtbth.sys;c:\windows\SYSNATIVE\drivers\rtbth.sys
S3 RTL8168;Realtek 8168 NT Driver;c:\windows\system32\DRIVERS\Rt630x64.sys;c:\windows\SYSNATIVE\DRIVERS\Rt630x64.sys
S3 SmbDrvI;SmbDrvI;c:\windows\system32\DRIVERS\Smb_driver_Intel.sys;c:\windows\SYSNATIVE\DRIVERS\Smb_driver_Intel.sys
S3 WirelessButtonDriver;HP Wireless Button Driver Service;c:\windows\System32\drivers\WirelessButtonDriver64.sys;c:\windows\SYSNATIVE\drivers\WirelessButtonDriver64.sys
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
apphost REG_MULTI_SZ apphostsvc
iissvcs REG_MULTI_SZ w3svc was
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2012-10-01 15:37 2322576 ----a-w- c:\progra~1\MICROS~1\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2012-10-01 15:37 2322576 ----a-w- c:\progra~1\MICROS~1\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2012-10-01 15:37 2322576 ----a-w- c:\progra~1\MICROS~1\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\IDM Shell Extension]
@="{CDC95B92-E27C-4745-A8C5-64A52A78855D}"
[HKEY_CLASSES_ROOT\CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D}]
2012-11-15 23:07 23496 ----a-w- c:\program files (x86)\Internet Download Manager\IDMShellExt64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-07-28 170304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-07-28 398656]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-07-28 440640]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2012-07-21 1425408]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Download all links with IDM - c:\program files (x86)\Internet Download Manager\IEGetAll.htm
IE: Download with IDM - c:\program files (x86)\Internet Download Manager\IEExt.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office15\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\MICROS~1\Office15\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{88DDEC8B-1690-4023-B4CA-06BF673A694C}: NameServer = 8.8.8.8 8.8.4.4
Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
FF - ProfilePath - c:\users\hassaan\AppData\Roaming\Mozilla\Firefox\Profiles\x3jt7h3g.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.pk/
FF - ExtSQL: 2013-07-04 19:45;
[email protected]; c:\users\hassaan\AppData\Roaming\IDM\idmmzcc5
FF - ExtSQL: 2013-07-04 19:49; {19503e42-ca3c-4c27-b1e2-9cdb2170ee34}; c:\users\hassaan\AppData\Roaming\Mozilla\Firefox\Profiles\x3jt7h3g.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}.xpi
FF - ExtSQL: 2013-07-24 12:32; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\users\hassaan\AppData\Roaming\Mozilla\Firefox\Profiles\x3jt7h3g.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKCU-Run-Pokki - %LOCALAPPDATA%\Pokki\Engine\LaunchDeskband.dll
Wow6432Node-HKLM-Run-Kepard - c:\program files (x86)\Kepard\Kepard.exe
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
AddRemove-{B8019B54-F9BE-490A-9619-6D06F18F129F} - c:\program files (x86)\InstallShield Installation Information\{B8019B54-F9BE-490A-9619-6D06F18F129F}\setup.exe
AddRemove-Torch - c:\users\hassaan\AppData\Local\Torch\uninstall.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
@SACL=(02 0000)
.
Completion time: 2013-08-14 10:57:11
ComboFix-quarantined-files.txt 2013-08-14 05:57
.
Pre-Run: 408,208,388,096 bytes free
Post-Run: 408,196,120,576 bytes free
.
- - End Of File - - 93A3003D755C09217C0222148781706A
D41D8CD98F00B204E9800998ECF8427E