Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Nothing responds, everything seems slow and freezes, windows explorer crashing?


  • This topic is locked This topic is locked
20 replies to this topic

#1 taranicolex

taranicolex

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:10:10 AM

Posted 30 September 2013 - 11:54 AM

Hey, so for the last couple days everything seems to stop responding and eventually freezes up. Even my task manager will stop responding. Windows explorer will eventually just stop working and whole computer will freeze and won't come back at all and I have to force shut down my computer. Any right clicks are so slow and and when I type in my start menu it freezes up as well. I figured I have a virus so the first thing I did was I restored my computer back to an earlier time. It did nothing. I installed malewarbytes onto my computer and tried to do a system scan and it would freeze up about 20 seconds in and I would have to force shut down my computer cause I couldn't get it to do nothing. It did this on both normal and safe mode. I downloaded avast and did a full system scan with that. It ran but it took 38 hours to finish and found nothing. I've tried ccleaner and defragging. I've looked this up for countless hours. I can't seem to figure this out. This computer is also fairly new, I got it in January this year. Also I don't have that much downloaded and not even that many files so I don't know if there is a virus or what. Any help on this would be highly appreciated. Thanks.


Edited by taranicolex, 30 September 2013 - 12:12 PM.


BC AdBot (Login to Remove)

 


#2 bloopie

bloopie

    Bleepin' Sith Turner


  • Malware Response Instructor
  • 6,344 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New York
  • Local time:12:10 PM

Posted 30 September 2013 - 12:23 PM

Hello tatanicolex, and welcome to Bleeping Computer! :)

My name is bloopie and I'll be helping you with your problems as best I can! :thumbup2:

I have moved this topic to the Malware Removal Forum where it will stay.

A few things to keep in mind while we are working together:
  • If you have since resolved the original problem you were having, I would appreciate it if you let me know.
  • If you are unsure about any of the steps just post what you can and I will guide you!
  • Please tell me if you have your original Windows CD/DVD available.
  • Please copy and paste all logs here unless otherwise instructed!
  • Upon completing the steps below I will review your topic an do my best to resolve your issues.
  • Please do not run any other tools without my instruction to do so!
==========

Please download Farbar Recovery Scan Tool and save it to your Desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will produce a log called FRST.txt in the same directory the tool is run from.
  • Please copy and paste log back here.
  • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.
bloopie

#3 taranicolex

taranicolex
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:10:10 AM

Posted 30 September 2013 - 12:58 PM

I tried running the Farbar scan and it seem to run 30 seconds or so and freeze my computer and wouldn't scan anymore. I tried a couple times and seem to stop both times at something called SCHEDLGU.TXT. I had to force shut down my computer when it froze, Anoher thing is I don't have the windows cd to this computer.



#4 taranicolex

taranicolex
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:10:10 AM

Posted 30 September 2013 - 01:10 PM

Ok I tried again. This time it ran all the way. Here the FRST log.

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 27-09-2013 02
Ran by Tara (administrator) on TARA-PC on 30-09-2013 11:04:26
Running from C:\Users\Tara\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US)
Internet Explorer Version 10
Boot Mode: Safe Mode (with Networking)

==================== Processes (Whitelisted) =================

(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [IntelTBRunOnce] - C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs [4526 2010-11-29] ()
HKLM\...\Run: [ETDCtrl] - C:\Program Files\Elantech\ETDCtrl.exe [2588968 2010-11-11] (ELAN Microelectronics Corp.)
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12673128 2011-08-16] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2277480 2011-08-16] (Realtek Semiconductor)
HKLM\...\Run: [Power Management] - C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [1831016 2011-08-02] (Acer Incorporated)
HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [Logitech Download Assistant] - C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM-x32\...\Run: [BackupManagerTray] - C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe [297280 2011-04-23] (NTI Corporation)
HKLM-x32\...\Run: [OOTag] - C:\Program Files (x86)\Acer\OOBEOffer\OOTag.exe [13856 2010-02-22] (Microsoft)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [343168 2011-10-13] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [LManager] - C:\Program Files (x86)\Launch Manager\LManager.exe [1103440 2011-06-30] (Dritek System Inc.)
HKLM-x32\...\Run: [NUSB3MON] - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-16] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [Dolby Advanced Audio v2] - C:\Dolby PCEE4\pcee4.exe [506712 2011-06-01] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [SuiteTray] - C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [341360 2011-09-20] (Egis Technology Inc.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-09-05] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-08-30] (AVAST Software)
HKU\Default\...\RunOnce: [ScrSav] - C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe [162408 2011-09-12] ()
HKU\Default User\...\RunOnce: [ScrSav] - C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe [162408 2011-09-12] ()

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.safesearch.net/?utm_medium=ie&utm_campaign=134878622171&utm_source=sm&utm_content=1&utm_term=695f8072-4d2f-4dad-85f1-8a06865b9bb6
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x84CDB9FA6D1ACE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.safesearch.net/?utm_medium=ie&utm_campaign=134878622171&utm_source=sm&utm_content=1&utm_term=695f8072-4d2f-4dad-85f1-8a06865b9bb6
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.safesearch.net/?utm_medium=ie&utm_campaign=134878622171&utm_source=sm&utm_content=1&utm_term=695f8072-4d2f-4dad-85f1-8a06865b9bb6
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {4B51C980-C6B0-11E1-9136-AED16088709B} URL =
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.safesearch.net/search?q={searchTerms}&utm_medium=ie&utm_campaign=134878622171&utm_source=sm&utm_content=1&utm_term=695f8072-4d2f-4dad-85f1-8a06865b9bb6
SearchScopes: HKLM - {FC0C0170-4EB0-430D-A7F3-939EE7EA1A25} URL = http://www.safesearch.net/search?q={searchTerms}&utm_medium=ie&utm_campaign=134878622171&utm_source=sm&utm_content=1&utm_term=695f8072-4d2f-4dad-85f1-8a06865b9bb6
SearchScopes: HKLM-x32 - DefaultScope {4B51C980-C6B0-11E1-9136-AED16088709B} URL = http://www.safesearch.net/search?q={searchTerms}&utm_medium=ie&utm_campaign=134878622171&utm_source=sm&utm_content=1&utm_term=695f8072-4d2f-4dad-85f1-8a06865b9bb6
SearchScopes: HKLM-x32 - {4B51C980-C6B0-11E1-9136-AED16088709B} URL = http://www.safesearch.net/search?q={searchTerms}&utm_medium=ie&utm_campaign=134878622171&utm_source=sm&utm_content=1&utm_term=695f8072-4d2f-4dad-85f1-8a06865b9bb6
SearchScopes: HKCU - DefaultScope {4B51C980-C6B0-11E1-9136-AED16088709B} URL = http://www.safesearch.net/search?q={searchTerms}&utm_medium=ie&utm_campaign=134878622171&utm_source=sm&utm_content=1&utm_term=695f8072-4d2f-4dad-85f1-8a06865b9bb6
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.safesearch.net/search?q={searchTerms}&utm_medium=ie&utm_campaign=134878622171&utm_source=sm&utm_content=1&utm_term=695f8072-4d2f-4dad-85f1-8a06865b9bb6
SearchScopes: HKCU - {4B51C980-C6B0-11E1-9136-AED16088709B} URL = http://www.safesearch.net/search?q={searchTerms}&utm_medium=ie&utm_campaign=134878622171&utm_source=sm&utm_content=1&utm_term=695f8072-4d2f-4dad-85f1-8a06865b9bb6
SearchScopes: HKCU - {FC0C0170-4EB0-430D-A7F3-939EE7EA1A25} URL = http://www.safesearch.net/search?q={searchTerms}&utm_medium=ie&utm_campaign=134878622171&utm_source=sm&utm_content=1&utm_term=695f8072-4d2f-4dad-85f1-8a06865b9bb6
BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: SafeSearch - {e27d5867-80de-4449-9c03-71707c0db05b} - C:\Program Files\SafeSearch\ie\adxloader64.dll ()
BHO-x32: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: SafeSearch - {e27d5867-80de-4449-9c03-71707c0db05b} - C:\Program Files\SafeSearch\ie\adxloader.dll ()
Toolbar: HKLM - SafeSearch Toolbar - {fc0c0170-4eb0-430d-a7f3-939ee7ea1a25} - C:\Program Files\SafeSearch\ie\adxloader64.dll ()
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM-x32 - SafeSearch Toolbar - {fc0c0170-4eb0-430d-a7f3-939ee7ea1a25} - C:\Program Files\SafeSearch\ie\adxloader.dll ()
Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\Tara\AppData\Roaming\Mozilla\Firefox\Profiles\tgw2b36b.default

FF DefaultSearchEngine: SafeSearch
FF SelectedSearchEngine: SafeSearch


FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll ()
FF Plugin: @java.com/DTPlugin,version=10.40.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.40.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.40.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: avsoftware.org/safesearch - C:\Program Files\SafeSearch\npsafesearch.dll (AVSoftware, Ltd)
FF SearchPlugin: C:\Users\Tara\AppData\Roaming\Mozilla\Firefox\Profiles\tgw2b36b.default\searchplugins\safesearch-1.xml
FF SearchPlugin: C:\Users\Tara\AppData\Roaming\Mozilla\Firefox\Profiles\tgw2b36b.default\searchplugins\safesearch.xml
FF Extension: No Name - C:\Users\Tara\AppData\Roaming\Mozilla\Firefox\Profiles\tgw2b36b.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK

==================== Services (Whitelisted) =================

S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-08-30] (AVAST Software)
S2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [137960 2013-08-30] (AVAST Software)
S2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [256832 2011-04-23] (NTI Corporation)
S3 MozillaMaintenance; "C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe" [x]

==================== Drivers (Whitelisted) ====================

S2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-08-30] (AVAST Software)
R1 aswFW; C:\Windows\system32\drivers\aswFW.sys [131232 2013-08-30] (AVAST Software)
R1 aswKbd; C:\Windows\System32\Drivers\aswKbd.sys [22600 2013-08-30] (AVAST Software)
S2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-08-30] (AVAST Software)
R0 aswNdis; C:\Windows\System32\DRIVERS\aswNdis.sys [12368 2013-07-17] (ALWIL Software)
R0 aswNdis2; C:\Windows\System32\drivers\aswNdis2.sys [270824 2013-08-30] (AVAST Software)
R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-08-30] (AVAST Software)
S0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-08-30] ()
S1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-08-30] (AVAST Software)
S1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-08-30] (AVAST Software)
S1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-08-30] (AVAST Software)
S0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [204880 2013-08-30] ()
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-13] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-09-30 10:48 - 2013-09-30 10:48 - 00000000 ____D C:\Program Files (x86)\ESET
2013-09-30 10:33 - 2013-09-30 10:33 - 01953880 _____ (Farbar) C:\Users\Tara\Desktop\FRST64.exe
2013-09-30 10:33 - 2013-09-30 10:33 - 00000000 ____D C:\FRST
2013-09-29 17:04 - 2013-09-29 17:04 - 00047488 _____ C:\Users\Tara\Desktop\sfcdetails.txt
2013-09-29 14:50 - 2013-09-29 14:53 - 00000000 ____D C:\Users\Tara\AppData\Roaming\.minecraft
2013-09-29 14:50 - 2013-09-29 14:50 - 00675988 _____ C:\Users\Tara\Downloads\Minecraft(2).exe
2013-09-29 14:46 - 2013-09-29 15:10 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2013-09-29 14:46 - 2013-08-30 00:48 - 00270824 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNdis2.sys
2013-09-29 14:46 - 2013-08-30 00:48 - 00131232 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFW.sys
2013-09-29 14:46 - 2013-08-30 00:48 - 00022600 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2013-09-29 14:46 - 2013-07-17 02:17 - 00012368 _____ (ALWIL Software) C:\Windows\system32\Drivers\aswNdis.sys
2013-09-29 14:44 - 2013-09-29 14:44 - 00001926 _____ C:\Users\Public\Desktop\avast! Internet Security.lnk
2013-09-29 14:29 - 2013-09-29 14:29 - 01059840 _____ C:\Users\Tara\Downloads\MicrosoftFixit50981.msi
2013-09-29 14:23 - 2013-08-30 00:48 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2013-09-29 14:23 - 2013-08-30 00:48 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2013-09-29 14:23 - 2013-08-30 00:48 - 00204880 _____ C:\Windows\system32\Drivers\aswVmm.sys
2013-09-29 14:23 - 2013-08-30 00:48 - 00080816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2013-09-29 14:23 - 2013-08-30 00:48 - 00072016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2013-09-29 14:23 - 2013-08-30 00:48 - 00065336 _____ C:\Windows\system32\Drivers\aswRvrt.sys
2013-09-29 14:23 - 2013-08-30 00:48 - 00064288 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys
2013-09-29 14:23 - 2013-08-30 00:48 - 00033400 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys
2013-09-29 14:23 - 2013-08-30 00:47 - 00287840 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2013-09-29 14:22 - 2013-08-30 00:47 - 00041664 _____ (AVAST Software) C:\Windows\avastSS.scr
2013-09-29 14:21 - 2013-09-29 14:22 - 131918888 _____ C:\Users\Tara\Downloads\avast_free_antivirus_setup(2).exe
2013-09-29 13:48 - 2013-09-29 13:48 - 02347384 _____ (ESET) C:\Users\Tara\Downloads\esetsmartinstaller_enu.exe
2013-09-29 13:15 - 2013-09-29 13:15 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Tara\Downloads\mbam-setup-1.75.0.1300(2).exe
2013-09-27 21:12 - 2013-09-27 21:13 - 00000000 ____D C:\Users\Tara\AppData\Local\Google
2013-09-27 21:12 - 2013-09-27 21:13 - 00000000 ____D C:\Program Files (x86)\Google
2013-09-27 21:10 - 2013-09-27 21:11 - 131918888 _____ C:\Users\Tara\Downloads\avast_free_antivirus_setup(1).exe
2013-09-27 21:09 - 2013-09-27 21:10 - 131918888 _____ C:\Users\Tara\Downloads\avast_free_antivirus_setup.exe
2013-09-27 20:59 - 2013-09-27 20:59 - 00326144 _____ (AVAST Software) C:\Users\Tara\Downloads\aswclear(1).exe
2013-09-27 20:54 - 2013-09-27 20:54 - 00326144 _____ (AVAST Software) C:\Users\Tara\Downloads\aswclear.exe
2013-09-27 20:54 - 2013-09-27 20:54 - 00003238 _____ C:\Windows\System32\Tasks\{02F6D41C-4EBD-45B7-9713-F051E69DC6EF}
2013-09-27 11:16 - 2013-09-27 11:16 - 00000258 __RSH C:\Users\Tara\ntuser.pol
2013-09-27 10:02 - 2013-09-29 14:46 - 00000000 _____ C:\Windows\SysWOW64\config.nt
2013-09-27 10:02 - 2013-09-29 14:22 - 00000000 ____D C:\ProgramData\AVAST Software
2013-09-27 10:02 - 2013-09-29 14:22 - 00000000 ____D C:\Program Files\AVAST Software
2013-09-27 10:01 - 2013-09-27 10:01 - 00000000 ____D C:\Users\Tara\Documents\Add-in Express
2013-09-27 10:01 - 2013-09-27 10:01 - 00000000 ____D C:\Program Files\SafeSearch
2013-09-27 10:00 - 2013-09-27 10:00 - 00961944 _____ C:\Users\Tara\Downloads\avast-free-antivirus.exe
2013-09-27 07:22 - 2013-09-27 07:22 - 00675988 _____ C:\Users\Tara\Downloads\Minecraft.exe
2013-09-27 07:22 - 2013-09-27 07:22 - 00675988 _____ C:\Users\Tara\Desktop\Minecraft.exe
2013-09-27 06:52 - 2013-09-27 06:52 - 10284816 _____ (Malwarebytes Corporation                                    ) C:\Users\Tara\Downloads\mbam-setup.exe
2013-09-27 06:29 - 2013-09-27 06:30 - 00000000 ____D C:\AdwCleaner
2013-09-27 06:29 - 2013-09-27 06:29 - 01042066 _____ C:\Users\Tara\Downloads\adwcleaner.exe
2013-09-27 06:25 - 2013-09-27 06:25 - 00018880 _____ C:\ComboFix.txt
2013-09-27 05:47 - 2013-09-27 06:49 - 00000000 ____D C:\Windows\erdnt
2013-09-26 23:12 - 2013-09-26 23:12 - 00000000 ____D C:\TDSSKiller_Quarantine
2013-09-26 23:06 - 2013-09-26 23:06 - 02748256 _____ (Kaspersky Lab ZAO) C:\Users\Tara\Downloads\tdsskiller.exe
2013-09-26 22:57 - 2013-09-26 22:57 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Tara\Downloads\mbam-setup-1.75.0.1300(1).exe
2013-09-26 22:45 - 2013-09-26 23:21 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2013-09-26 22:44 - 2013-09-26 22:44 - 37672592 _____ (Safer-Networking Ltd.                                       ) C:\Users\Tara\Downloads\spybotsd-2.1.21-SR2.exe
2013-09-26 06:31 - 2013-09-26 09:01 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-09-26 06:31 - 2013-09-26 06:32 - 00000000 ____D C:\Users\Tara\AppData\Roaming\Mozilla
2013-09-26 06:31 - 2013-09-26 06:31 - 00001111 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-09-26 05:40 - 2013-09-29 16:12 - 00001736 _____ C:\Windows\setupact.log
2013-09-26 05:40 - 2013-09-26 05:40 - 00000000 _____ C:\Windows\setuperr.log
2013-09-26 05:39 - 2013-09-29 14:37 - 00013052 _____ C:\Windows\PFRO.log
2013-09-26 05:34 - 2013-09-26 05:34 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Tara\Downloads\mbam-setup-1.75.0.1300.exe
2013-09-26 05:34 - 2013-09-26 05:34 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-09-26 05:30 - 2013-09-26 05:30 - 04369632 _____ (Piriform Ltd) C:\Users\Tara\Downloads\ccsetup406.exe
2013-09-26 05:27 - 2013-09-26 05:27 - 01852384 _____ C:\Users\Tara\Downloads\wrar500es.exe
2013-09-26 05:27 - 2013-09-26 05:27 - 00000000 ____D C:\Users\Tara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2013-09-26 05:27 - 2013-09-26 05:27 - 00000000 ____D C:\Program Files (x86)\WinRAR
2013-09-26 05:20 - 2013-09-26 05:20 - 01761296 _____ C:\Users\Tara\Downloads\wrar500.exe
2013-09-25 20:40 - 2009-07-13 21:54 - 00001304 _____ C:\Users\Tara\Desktop\Notepad.lnk
2013-09-24 04:03 - 2013-09-24 04:03 - 40048208 _____ (Blizzard Entertainment) C:\Users\Tara\Downloads\Diablo-III-Setup-enUS.exe
2013-09-23 19:49 - 2013-09-23 19:49 - 29036456 _____ (Oracle Corporation) C:\Users\Tara\Downloads\jre-7u40-windows-i586(2).exe
2013-09-23 19:49 - 2013-09-23 19:49 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-09-23 19:49 - 2013-09-23 19:49 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-09-23 19:49 - 2013-09-23 19:49 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-09-23 19:49 - 2013-09-23 19:49 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-09-23 19:49 - 2013-09-23 19:49 - 00000000 ____D C:\ProgramData\Oracle
2013-09-23 19:49 - 2013-09-23 19:49 - 00000000 ____D C:\Program Files (x86)\Java
2013-09-23 19:48 - 2013-09-23 19:48 - 29036456 _____ (Oracle Corporation) C:\Users\Tara\Downloads\jre-7u40-windows-i586(1).exe
2013-09-23 19:47 - 2013-09-23 19:48 - 29036456 _____ (Oracle Corporation) C:\Users\Tara\Downloads\jre-7u40-windows-i586.exe
2013-09-23 19:47 - 2013-09-23 19:47 - 30669224 _____ (Oracle Corporation) C:\Users\Tara\Downloads\jre-7u40-windows-x64(2).exe
2013-09-23 19:38 - 2013-09-23 19:38 - 01069408 _____ (Solid State Networks) C:\Users\Tara\Downloads\install_reader11_en_mssa_aaa_aih.exe
2013-09-23 19:37 - 2013-09-23 19:38 - 30669224 _____ (Oracle Corporation) C:\Users\Tara\Downloads\jre-7u40-windows-x64(1).exe
2013-09-23 19:36 - 2013-09-23 19:36 - 00000000 ____D C:\Program Files\Java
2013-09-23 19:35 - 2013-09-23 19:35 - 30669224 _____ (Oracle Corporation) C:\Users\Tara\Downloads\jre-7u40-windows-x64.exe
2013-09-22 20:02 - 2013-09-22 20:02 - 00000000 ____D C:\Users\Tara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\THQ
2013-09-22 20:02 - 2013-09-22 20:02 - 00000000 ____D C:\Program Files (x86)\THQ
2013-09-20 22:50 - 2013-09-24 04:04 - 00000000 ____D C:\Program Files (x86)\Diablo III
2013-09-17 02:20 - 2013-09-17 02:20 - 00006192 _____ C:\Users\Tara\Documents\MegamanX ending.gp5
2013-09-17 02:12 - 2013-09-17 02:12 - 00002408 _____ C:\Users\Tara\Documents\awaw.gp5
2013-09-17 01:48 - 2013-09-17 01:48 - 00000896 _____ C:\Users\Tara\Desktop\Guitar Pro 5.lnk
2013-09-17 01:48 - 2013-09-17 01:48 - 00000000 ____D C:\Program Files (x86)\Guitar Pro 5
2013-09-15 20:29 - 2013-09-27 04:06 - 00000000 ____D C:\Users\Tara\Documents\house
2013-09-12 15:24 - 2013-08-09 22:22 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-09-12 15:24 - 2013-08-09 22:22 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-09-12 15:24 - 2013-08-09 22:22 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-09-12 15:24 - 2013-08-09 22:21 - 19246592 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-09-12 15:24 - 2013-08-09 22:21 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-09-12 15:24 - 2013-08-09 22:21 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-09-12 15:24 - 2013-08-09 22:20 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-09-12 15:24 - 2013-08-09 22:20 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-09-12 15:24 - 2013-08-09 22:20 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-09-12 15:24 - 2013-08-09 22:20 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-09-12 15:24 - 2013-08-09 22:20 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-09-12 15:24 - 2013-08-09 22:20 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-09-12 15:24 - 2013-08-09 22:20 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-09-12 15:24 - 2013-08-09 22:20 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-09-12 15:24 - 2013-08-09 20:59 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-09-12 15:24 - 2013-08-09 20:59 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-09-12 15:24 - 2013-08-09 20:58 - 14332928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-09-12 15:24 - 2013-08-09 20:58 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-09-12 15:24 - 2013-08-09 20:58 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-09-12 15:24 - 2013-08-09 20:58 - 02048000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-09-12 15:24 - 2013-08-09 20:58 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-09-12 15:24 - 2013-08-09 20:58 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-09-12 15:24 - 2013-08-09 20:58 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-09-12 15:24 - 2013-08-09 20:58 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-09-12 15:24 - 2013-08-09 20:58 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-09-12 15:24 - 2013-08-09 20:58 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-09-12 15:24 - 2013-08-09 20:58 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-09-12 15:24 - 2013-08-09 20:17 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-09-12 15:24 - 2013-08-09 20:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-09-12 15:24 - 2013-08-09 19:27 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-09-12 15:24 - 2013-08-09 19:17 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-09-11 15:06 - 2013-08-07 18:20 - 03155456 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-09-11 15:06 - 2013-08-04 19:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys
2013-09-11 15:06 - 2013-08-01 19:23 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-09-11 15:06 - 2013-08-01 19:15 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-09-11 15:06 - 2013-08-01 19:15 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2013-09-11 15:06 - 2013-08-01 19:15 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-09-11 15:06 - 2013-08-01 19:15 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2013-09-11 15:06 - 2013-08-01 19:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2013-09-11 15:06 - 2013-08-01 19:14 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2013-09-11 15:06 - 2013-08-01 19:13 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2013-09-11 15:06 - 2013-08-01 19:13 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2013-09-11 15:06 - 2013-08-01 19:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2013-09-11 15:06 - 2013-08-01 19:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2013-09-11 15:06 - 2013-08-01 19:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 19:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 19:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 19:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 19:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 19:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 19:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 19:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 19:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 19:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 19:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 19:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 19:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 19:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 19:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 19:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 19:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 19:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 19:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 19:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 19:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 19:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 19:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 19:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 19:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 19:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 19:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 19:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 18:59 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-09-11 15:06 - 2013-08-01 18:59 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-09-11 15:06 - 2013-08-01 18:51 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-09-11 15:06 - 2013-08-01 18:50 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2013-09-11 15:06 - 2013-08-01 18:50 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2013-09-11 15:06 - 2013-08-01 18:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-09-11 15:06 - 2013-08-01 18:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2013-09-11 15:06 - 2013-08-01 18:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 18:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 18:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 18:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 18:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 18:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 18:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 18:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 18:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 18:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 18:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 18:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 18:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 18:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 18:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 18:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 18:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 18:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 18:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 18:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 18:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 18:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 18:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 18:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 18:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2013-09-11 15:06 - 2013-08-01 17:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2013-09-11 15:06 - 2013-08-01 17:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-09-11 15:06 - 2013-08-01 17:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-09-11 15:06 - 2013-08-01 17:45 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-09-11 15:06 - 2013-08-01 17:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-09-11 15:06 - 2013-08-01 17:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 17:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 17:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2013-09-11 15:06 - 2013-08-01 17:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2013-09-11 15:06 - 2013-07-25 19:24 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2013-09-11 15:06 - 2013-07-25 19:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2013-09-11 15:06 - 2013-07-25 18:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2013-09-11 15:06 - 2013-07-25 18:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll

==================== One Month Modified Files and Folders =======

2013-09-30 10:48 - 2013-09-30 10:48 - 00000000 ____D C:\Program Files (x86)\ESET
2013-09-30 10:33 - 2013-09-30 10:33 - 01953880 _____ (Farbar) C:\Users\Tara\Desktop\FRST64.exe
2013-09-30 10:33 - 2013-09-30 10:33 - 00000000 ____D C:\FRST
2013-09-29 17:04 - 2013-09-29 17:04 - 00047488 _____ C:\Users\Tara\Desktop\sfcdetails.txt
2013-09-29 16:26 - 2013-02-11 10:53 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-09-29 16:12 - 2013-09-26 05:40 - 00001736 _____ C:\Windows\setupact.log
2013-09-29 16:12 - 2009-07-13 22:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-09-29 15:13 - 2012-02-28 01:09 - 02091337 _____ C:\Windows\WindowsUpdate.log
2013-09-29 15:13 - 2009-07-13 21:45 - 00016976 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-29 15:13 - 2009-07-13 21:45 - 00016976 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-29 15:10 - 2013-09-29 14:46 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2013-09-29 14:53 - 2013-09-29 14:50 - 00000000 ____D C:\Users\Tara\AppData\Roaming\.minecraft
2013-09-29 14:51 - 2013-02-11 13:56 - 00000000 ____D C:\Users\Tara\AppData\Local\Adobe
2013-09-29 14:50 - 2013-09-29 14:50 - 00675988 _____ C:\Users\Tara\Downloads\Minecraft(2).exe
2013-09-29 14:46 - 2013-09-27 10:02 - 00000000 _____ C:\Windows\SysWOW64\config.nt
2013-09-29 14:44 - 2013-09-29 14:44 - 00001926 _____ C:\Users\Public\Desktop\avast! Internet Security.lnk
2013-09-29 14:37 - 2013-09-26 05:39 - 00013052 _____ C:\Windows\PFRO.log
2013-09-29 14:29 - 2013-09-29 14:29 - 01059840 _____ C:\Users\Tara\Downloads\MicrosoftFixit50981.msi
2013-09-29 14:22 - 2013-09-29 14:21 - 131918888 _____ C:\Users\Tara\Downloads\avast_free_antivirus_setup(2).exe
2013-09-29 14:22 - 2013-09-27 10:02 - 00000000 ____D C:\ProgramData\AVAST Software
2013-09-29 14:22 - 2013-09-27 10:02 - 00000000 ____D C:\Program Files\AVAST Software
2013-09-29 13:48 - 2013-09-29 13:48 - 02347384 _____ (ESET) C:\Users\Tara\Downloads\esetsmartinstaller_enu.exe
2013-09-29 13:15 - 2013-09-29 13:15 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Tara\Downloads\mbam-setup-1.75.0.1300(2).exe
2013-09-27 21:13 - 2013-09-27 21:12 - 00000000 ____D C:\Users\Tara\AppData\Local\Google
2013-09-27 21:13 - 2013-09-27 21:12 - 00000000 ____D C:\Program Files (x86)\Google
2013-09-27 21:11 - 2013-09-27 21:10 - 131918888 _____ C:\Users\Tara\Downloads\avast_free_antivirus_setup(1).exe
2013-09-27 21:10 - 2013-09-27 21:09 - 131918888 _____ C:\Users\Tara\Downloads\avast_free_antivirus_setup.exe
2013-09-27 20:59 - 2013-09-27 20:59 - 00326144 _____ (AVAST Software) C:\Users\Tara\Downloads\aswclear(1).exe
2013-09-27 20:54 - 2013-09-27 20:54 - 00326144 _____ (AVAST Software) C:\Users\Tara\Downloads\aswclear.exe
2013-09-27 20:54 - 2013-09-27 20:54 - 00003238 _____ C:\Windows\System32\Tasks\{02F6D41C-4EBD-45B7-9713-F051E69DC6EF}
2013-09-27 11:16 - 2013-09-27 11:16 - 00000258 __RSH C:\Users\Tara\ntuser.pol
2013-09-27 11:16 - 2013-02-11 03:20 - 00000000 ____D C:\Users\Tara
2013-09-27 10:01 - 2013-09-27 10:01 - 00000000 ____D C:\Users\Tara\Documents\Add-in Express
2013-09-27 10:01 - 2013-09-27 10:01 - 00000000 ____D C:\Program Files\SafeSearch
2013-09-27 10:01 - 2009-07-13 20:20 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2013-09-27 10:01 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\SysWOW64\GroupPolicy
2013-09-27 10:00 - 2013-09-27 10:00 - 00961944 _____ C:\Users\Tara\Downloads\avast-free-antivirus.exe
2013-09-27 07:22 - 2013-09-27 07:22 - 00675988 _____ C:\Users\Tara\Downloads\Minecraft.exe
2013-09-27 07:22 - 2013-09-27 07:22 - 00675988 _____ C:\Users\Tara\Desktop\Minecraft.exe
2013-09-27 06:52 - 2013-09-27 06:52 - 10284816 _____ (Malwarebytes Corporation                                    ) C:\Users\Tara\Downloads\mbam-setup.exe
2013-09-27 06:49 - 2013-09-27 05:47 - 00000000 ____D C:\Windows\erdnt
2013-09-27 06:30 - 2013-09-27 06:29 - 00000000 ____D C:\AdwCleaner
2013-09-27 06:29 - 2013-09-27 06:29 - 01042066 _____ C:\Users\Tara\Downloads\adwcleaner.exe
2013-09-27 06:25 - 2013-09-27 06:25 - 00018880 _____ C:\ComboFix.txt
2013-09-27 06:24 - 2009-07-13 19:34 - 00000215 _____ C:\Windows\system.ini
2013-09-27 05:47 - 2013-02-22 06:10 - 00000000 ____D C:\Users\hedev
2013-09-27 04:06 - 2013-09-15 20:29 - 00000000 ____D C:\Users\Tara\Documents\house
2013-09-27 02:54 - 2011-10-31 00:50 - 00000000 ____D C:\ProgramData\McAfee
2013-09-27 02:54 - 2011-10-31 00:50 - 00000000 ____D C:\Program Files (x86)\McAfee
2013-09-26 23:25 - 2013-02-12 00:42 - 00000000 ____D C:\Users\Tara\Documents\My Games
2013-09-26 23:21 - 2013-09-26 22:45 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2013-09-26 23:12 - 2013-09-26 23:12 - 00000000 ____D C:\TDSSKiller_Quarantine
2013-09-26 23:06 - 2013-09-26 23:06 - 02748256 _____ (Kaspersky Lab ZAO) C:\Users\Tara\Downloads\tdsskiller.exe
2013-09-26 22:57 - 2013-09-26 22:57 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Tara\Downloads\mbam-setup-1.75.0.1300(1).exe
2013-09-26 22:44 - 2013-09-26 22:44 - 37672592 _____ (Safer-Networking Ltd.                                       ) C:\Users\Tara\Downloads\spybotsd-2.1.21-SR2.exe
2013-09-26 22:33 - 2013-06-28 02:30 - 00000000 ____D C:\Program Files (x86)\Steam
2013-09-26 09:01 - 2013-09-26 06:31 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-09-26 06:32 - 2013-09-26 06:31 - 00000000 ____D C:\Users\Tara\AppData\Roaming\Mozilla
2013-09-26 06:31 - 2013-09-26 06:31 - 00001111 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-09-26 06:31 - 2013-08-16 16:55 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-09-26 06:10 - 2013-02-11 03:21 - 00061624 _____ C:\Users\Tara\AppData\Local\GDIPFONTCACHEV1.DAT
2013-09-26 06:03 - 2009-07-13 21:45 - 00291664 _____ C:\Windows\system32\FNTCACHE.DAT
2013-09-26 05:40 - 2013-09-26 05:40 - 00000000 _____ C:\Windows\setuperr.log
2013-09-26 05:34 - 2013-09-26 05:34 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Tara\Downloads\mbam-setup-1.75.0.1300.exe
2013-09-26 05:34 - 2013-09-26 05:34 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-09-26 05:32 - 2013-02-26 00:55 - 00000000 ____D C:\Users\Tara\AppData\Roaming\BitTorrent
2013-09-26 05:32 - 2013-02-12 07:08 - 00000000 ____D C:\Windows\Minidump
2013-09-26 05:32 - 2007-07-11 18:49 - 00000000 ____D C:\Windows\Panther
2013-09-26 05:30 - 2013-09-26 05:30 - 04369632 _____ (Piriform Ltd) C:\Users\Tara\Downloads\ccsetup406.exe
2013-09-26 05:27 - 2013-09-26 05:27 - 01852384 _____ C:\Users\Tara\Downloads\wrar500es.exe
2013-09-26 05:27 - 2013-09-26 05:27 - 00000000 ____D C:\Users\Tara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2013-09-26 05:27 - 2013-09-26 05:27 - 00000000 ____D C:\Program Files (x86)\WinRAR
2013-09-26 05:20 - 2013-09-26 05:20 - 01761296 _____ C:\Users\Tara\Downloads\wrar500.exe
2013-09-26 05:08 - 2013-02-11 10:17 - 00000000 ___RD C:\Users\Tara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-09-26 04:38 - 2013-02-11 02:03 - 00000000 ____D C:\Users\Tara\AppData\Roaming\Skype
2013-09-25 22:34 - 2013-08-09 14:28 - 00000000 ____D C:\Program Files (x86)\Diablo II
2013-09-24 04:04 - 2013-09-20 22:50 - 00000000 ____D C:\Program Files (x86)\Diablo III
2013-09-24 04:03 - 2013-09-24 04:03 - 40048208 _____ (Blizzard Entertainment) C:\Users\Tara\Downloads\Diablo-III-Setup-enUS.exe
2013-09-23 20:23 - 2013-02-11 10:53 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-09-23 20:23 - 2013-02-11 10:53 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-09-23 20:23 - 2011-10-31 00:59 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-09-23 20:03 - 2011-10-31 00:49 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-09-23 20:03 - 2011-10-31 00:49 - 00000000 ____D C:\ProgramData\Skype
2013-09-23 19:49 - 2013-09-23 19:49 - 29036456 _____ (Oracle Corporation) C:\Users\Tara\Downloads\jre-7u40-windows-i586(2).exe
2013-09-23 19:49 - 2013-09-23 19:49 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-09-23 19:49 - 2013-09-23 19:49 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-09-23 19:49 - 2013-09-23 19:49 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-09-23 19:49 - 2013-09-23 19:49 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-09-23 19:49 - 2013-09-23 19:49 - 00000000 ____D C:\ProgramData\Oracle
2013-09-23 19:49 - 2013-09-23 19:49 - 00000000 ____D C:\Program Files (x86)\Java
2013-09-23 19:49 - 2013-02-11 10:43 - 00868264 _____ (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2013-09-23 19:49 - 2013-02-11 10:43 - 00790440 _____ (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2013-09-23 19:48 - 2013-09-23 19:48 - 29036456 _____ (Oracle Corporation) C:\Users\Tara\Downloads\jre-7u40-windows-i586(1).exe
2013-09-23 19:48 - 2013-09-23 19:47 - 29036456 _____ (Oracle Corporation) C:\Users\Tara\Downloads\jre-7u40-windows-i586.exe
2013-09-23 19:47 - 2013-09-23 19:47 - 30669224 _____ (Oracle Corporation) C:\Users\Tara\Downloads\jre-7u40-windows-x64(2).exe
2013-09-23 19:45 - 2011-10-31 00:57 - 00000000 ____D C:\ProgramData\Adobe
2013-09-23 19:45 - 2011-10-31 00:57 - 00000000 ____D C:\Program Files (x86)\Adobe
2013-09-23 19:38 - 2013-09-23 19:38 - 01069408 _____ (Solid State Networks) C:\Users\Tara\Downloads\install_reader11_en_mssa_aaa_aih.exe
2013-09-23 19:38 - 2013-09-23 19:37 - 30669224 _____ (Oracle Corporation) C:\Users\Tara\Downloads\jre-7u40-windows-x64(1).exe
2013-09-23 19:36 - 2013-09-23 19:36 - 00000000 ____D C:\Program Files\Java
2013-09-23 19:36 - 2013-02-11 12:22 - 01095080 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll
2013-09-23 19:36 - 2013-02-11 12:22 - 00973736 _____ (Oracle Corporation) C:\Windows\system32\deployJava1.dll
2013-09-23 19:35 - 2013-09-23 19:35 - 30669224 _____ (Oracle Corporation) C:\Users\Tara\Downloads\jre-7u40-windows-x64.exe
2013-09-23 19:33 - 2013-07-16 20:43 - 00000000 ____D C:\Program Files (x86)\Cube World
2013-09-23 19:33 - 2013-06-28 02:46 - 00000000 ____D C:\Users\Tara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2013-09-23 19:33 - 2013-03-14 18:31 - 00000000 ____D C:\Users\Tara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2013-09-23 19:33 - 2013-03-14 18:31 - 00000000 ____D C:\Program Files\Starcraft
2013-09-23 19:33 - 2013-03-11 04:47 - 00000000 ____D C:\Program Files (x86)\iTunes
2013-09-23 19:33 - 2013-02-20 06:14 - 00000000 ____D C:\Program Files (x86)\PhotoFiltre 7
2013-09-23 19:33 - 2013-02-11 10:17 - 00000000 ___RD C:\Users\Tara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-09-23 19:33 - 2013-02-11 03:20 - 00000000 ___RD C:\Users\Tara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2013-09-23 19:33 - 2013-02-11 03:20 - 00000000 ___RD C:\Users\Tara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2013-09-23 19:33 - 2013-02-11 00:40 - 00000000 ____D C:\Program Files (x86)\World of Warcraft
2013-09-23 19:33 - 2012-02-28 01:32 - 00000000 ____D C:\Program Files (x86)\EgisTec MyWinLocker
2013-09-23 19:33 - 2012-02-28 01:23 - 00000000 ____D C:\Dolby PCEE4
2013-09-23 19:33 - 2012-02-28 01:21 - 00000000 ____D C:\Program Files\Elantech
2013-09-23 19:33 - 2012-02-28 01:18 - 00000000 ____D C:\Program Files (x86)\Launch Manager
2013-09-23 19:33 - 2010-11-21 00:17 - 00000000 ____D C:\Program Files\Windows Journal
2013-09-23 19:33 - 2009-07-13 22:32 - 00000000 ____D C:\Program Files\Windows Sidebar
2013-09-23 19:33 - 2009-07-13 22:32 - 00000000 ____D C:\Program Files\DVD Maker
2013-09-23 19:33 - 2009-07-13 20:20 - 00000000 __RSD C:\Windows\Media
2013-09-23 19:33 - 2009-07-13 20:20 - 00000000 __RHD C:\Users\Public\Libraries
2013-09-23 19:33 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\SysWOW64\migwiz
2013-09-23 19:33 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\registration
2013-09-23 19:33 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\IME
2013-09-23 19:33 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\AppCompat
2013-09-23 19:32 - 2013-02-11 00:39 - 00000000 ____D C:\ProgramData\Battle.net
2013-09-23 19:21 - 2013-02-28 20:05 - 00000000 ____D C:\Users\Tara\Documents\Emulators
2013-09-22 20:02 - 2013-09-22 20:02 - 00000000 ____D C:\Users\Tara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\THQ
2013-09-22 20:02 - 2013-09-22 20:02 - 00000000 ____D C:\Program Files (x86)\THQ
2013-09-19 00:34 - 2009-07-13 22:13 - 00726316 _____ C:\Windows\system32\PerfStringBackup.INI
2013-09-17 02:20 - 2013-09-17 02:20 - 00006192 _____ C:\Users\Tara\Documents\MegamanX ending.gp5
2013-09-17 02:12 - 2013-09-17 02:12 - 00002408 _____ C:\Users\Tara\Documents\awaw.gp5
2013-09-17 01:48 - 2013-09-17 01:48 - 00000896 _____ C:\Users\Tara\Desktop\Guitar Pro 5.lnk
2013-09-17 01:48 - 2013-09-17 01:48 - 00000000 ____D C:\Program Files (x86)\Guitar Pro 5
2013-09-14 15:08 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\rescache
2013-09-12 15:27 - 2009-07-13 22:08 - 00032602 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-09-12 15:24 - 2013-07-13 03:00 - 00000000 ____D C:\Windows\system32\MRT
2013-09-12 15:23 - 2013-02-11 14:20 - 79143768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe

Some content of TEMP:
====================
C:\Users\Tara\AppData\Local\Temp\Quarantine.exe
C:\Users\Tara\AppData\Local\Temp\ssdl30055.exe
C:\Users\Tara\AppData\Local\Temp\ssdl48467.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe
[2011-07-13 22:30] - [2011-07-13 22:30] - 2616320 ____A (Microsoft Corporation) 401490E8AD8649A46411555CA17C8CDE

C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-09-23 20:23

==================== End Of Log ============================

 

 

Here's the addition log.

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 27-09-2013 02
Ran by Tara at 2013-09-30 11:07:50
Running from C:\Users\Tara\Desktop
Boot Mode: Safe Mode (with Networking)
==========================================================


==================== Security Center ========================

AV: avast! Internet Security (Enabled - Up to date) {2B2D1395-420B-D5C9-657E-930FE358FC3C}
AS: avast! Internet Security (Enabled - Up to date) {904CF271-6431-DA47-5FCE-A87D98DFB681}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: avast! Internet Security (Enabled) {131692B0-0864-D491-4E21-3A3A1D8BBB47}

==================== Installed Programs ======================

Acer Backup Manager (x32 Version: 3.0.0.99)
Acer Crystal Eye Webcam (x32 Version: 1.0.1904)
Acer ePower Management (x32 Version: 6.00.3008)
Acer eRecovery Management (x32 Version: 5.00.3504)
Acer Registration (x32 Version: 1.04.3504)
Acer ScreenSaver (x32 Version: 1.1.0913.2011)
Acer Updater (x32 Version: 1.02.3500)
Adobe AIR (x32 Version: 2.7.1.19610)
Adobe Flash Player 11 ActiveX (x32 Version: 11.8.800.175)
Adobe Flash Player 11 Plugin (x32 Version: 11.8.800.168)
Adobe Reader XI (11.0.04) (x32 Version: 11.0.04)
AMD APP SDK Runtime (Version: 2.5.775.2)
AMD Catalyst Install Manager (Version: 3.0.847.0)
Apple Application Support (x32 Version: 2.2.2)
Apple Mobile Device Support (Version: 6.0.0.59)
Apple Software Update (x32 Version: 2.1.3.127)
Atheros Communications Inc.® AR81Family Gigabit/Fast Ethernet Driver (x32 Version: 1.0.0.36)
avast! Internet Security (x32 Version: 8.0.1497.0)
Backup Manager V3 (x32 Version: 3.0.0.99)
BitTorrent (x32 Version: 7.8.0.29112)
Catalyst Control Center - Branding (x32 Version: 1.00.0000)
Catalyst Control Center (x32 Version: 2011.1013.754.12275)
Catalyst Control Center InstallProxy (x32 Version: 2011.1013.754.12275)
Catalyst Control Center Localization All (x32 Version: 2011.1013.754.12275)
Catalyst Control Center Profiles Mobile (x32 Version: 2011.1013.754.12275)
CCC Help Chinese Standard (x32 Version: 2011.1013.0753.12275)
CCC Help Chinese Traditional (x32 Version: 2011.1013.0753.12275)
CCC Help Czech (x32 Version: 2011.1013.0753.12275)
CCC Help Danish (x32 Version: 2011.1013.0753.12275)
CCC Help Dutch (x32 Version: 2011.1013.0753.12275)
CCC Help English (x32 Version: 2011.1013.0753.12275)
CCC Help Finnish (x32 Version: 2011.1013.0753.12275)
CCC Help French (x32 Version: 2011.1013.0753.12275)
CCC Help German (x32 Version: 2011.1013.0753.12275)
CCC Help Greek (x32 Version: 2011.1013.0753.12275)
CCC Help Hungarian (x32 Version: 2011.1013.0753.12275)
CCC Help Italian (x32 Version: 2011.1013.0753.12275)
CCC Help Japanese (x32 Version: 2011.1013.0753.12275)
CCC Help Korean (x32 Version: 2011.1013.0753.12275)
CCC Help Norwegian (x32 Version: 2011.1013.0753.12275)
CCC Help Polish (x32 Version: 2011.1013.0753.12275)
CCC Help Portuguese (x32 Version: 2011.1013.0753.12275)
CCC Help Russian (x32 Version: 2011.1013.0753.12275)
CCC Help Spanish (x32 Version: 2011.1013.0753.12275)
CCC Help Swedish (x32 Version: 2011.1013.0753.12275)
CCC Help Thai (x32 Version: 2011.1013.0753.12275)
CCC Help Turkish (x32 Version: 2011.1013.0753.12275)
ccc-utility64 (Version: 2011.1013.754.12275)
clear.fi Client (x32 Version: 1.00.3500)
Cube World version 0.0.1 (x32 Version: 0.0.1)
D3DX10 (x32 Version: 15.4.2368.0902)
Diablo II (x32)
Dolby Advanced Audio v2 (x32 Version: 7.2.7000.7)
ETDWare PS/2-X64 8.0.6.0_WHQL (Version: 8.0.6.0)
Fooz Kids Platform (x32 Version: 2.1)
Galerie de photos Windows Live (x32 Version: 15.4.3502.0922)
Guitar Pro 5.2 (x32)
Identity Card (x32 Version: 1.00.3501)
Intel® Display Audio Driver (x32 Version: 6.14.00.3074)
Intel® Management Engine Components (x32 Version: 7.0.0.1144)
Intel® Rapid Storage Technology (x32 Version: 10.1.2.1004)
Intel® Turbo Boost Technology Monitor 2.0 (Version: 2.1.23.0)
iTunes (Version: 10.7.0.21)
Java 7 Update 40 (64-bit) (Version: 7.0.400)
Java 7 Update 40 (x32 Version: 7.0.400)
Java Auto Updater (x32 Version: 2.1.9.8)
Junk Mail filter update (x32 Version: 15.4.3502.0922)
Launch Manager (x32 Version: 5.1.7)
MagicDisc 2.7.106 (x32)
Mesh Runtime (x32 Version: 15.4.5722.2)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Office 2010 (x32 Version: 14.0.4763.1000)
Microsoft Silverlight (Version: 5.1.20513.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (Version: 10.0.30319)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319 (x32 Version: 10.0.30319)
MotioninJoy Gamepad tool 0.7.1001 (Version: 0.7.1001)
Mozilla Firefox 24.0 (x86 en-US) (x32 Version: 24.0)
Mozilla Maintenance Service (x32 Version: 24.0)
MSVCRT (x32 Version: 15.4.2862.0708)
MSVCRT_amd64 (x32 Version: 15.4.2862.0708)
MyWinLocker (Version: 4.0.14.27)
MyWinLocker 4 (x32 Version: 4.0.14.27)
MyWinLocker Suite (x32 Version: 4.0.14.19)
NTI Media Maker 9 (x32 Version: 9.0.2.9002)
Path of Exile (x32 Version: 0.10.0.22770)
PhotoFiltre 7 (HKCU)
Project64 1.6 (x32 Version: 1.6)
PX Profile Update (x32 Version: 1.00.1.)
Realtek High Definition Audio Driver (x32 Version: 6.0.1.6438)
Realtek USB 2.0 Card Reader (x32 Version: 6.1.7600.30123)
Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.34.0)
SafeSearch (Version: 0.9.2.0)
Shared C Run-time for x64 (Version: 10.0.0)
Shredder (Version: 2.0.8.9)
Shredder (x32 Version: 2.0.8.9)
Skype Click to Call (x32 Version: 6.12.13601)
Skype™ 6.6 (x32 Version: 6.6.106)
Star Wars: The Old Republic (x32 Version: 1.00)
Starcraft (x32)
Steam (x32 Version: 1.0.0.0)
System Requirements Lab CYRI (x32 Version: 5.0.6.0)
Team Fortress 2 (x32)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1)
Ventrilo Client for Windows x64 (Version: 3.0.8.0)
Welcome Center (x32 Version: 1.02.3504)
Windows Live (x32 Version: 15.4.3502.0922)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3538.0513)
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0)
Windows Live Installer (x32 Version: 15.4.3502.0922)
Windows Live Language Selector (Version: 15.4.3538.0513)
Windows Live Mail (x32 Version: 15.4.3502.0922)
Windows Live Mesh (x32 Version: 15.4.3502.0922)
Windows Live Messenger (x32 Version: 15.4.3538.0513)
Windows Live MIME IFilter (Version: 15.4.3502.0922)
Windows Live Movie Maker (x32 Version: 15.4.3502.0922)
Windows Live Photo Common (x32 Version: 15.4.3502.0922)
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922)
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109)
Windows Live Remote Client (Version: 15.4.5722.2)
Windows Live Remote Client Resources (Version: 15.4.5722.2)
Windows Live Remote Service (Version: 15.4.5722.2)
Windows Live Remote Service Resources (Version: 15.4.5722.2)
Windows Live SOXE (x32 Version: 15.4.3502.0922)
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922)
Windows Live UX Platform (x32 Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109)
Windows Live Writer (x32 Version: 15.4.3502.0922)
Windows Live Writer Resources (x32 Version: 15.4.3502.0922)
WinRAR 5.00 (32-bit) (x32 Version: 5.00.0)
World of Warcraft (x32 Version: 5.3.0.17128)

==================== Restore Points  =========================


==================== Hosts content: ==========================

2009-07-13 19:34 - 2013-09-27 06:24 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost

==================== Scheduled Tasks (whitelisted) =============

Task: {17933A45-0D2D-4F06-90DC-C84E74C360E2} - System32\Tasks\{35E5867B-984B-4EE2-89F6-23725D197225} => Firefox.exe http://ui.skype.com/ui/0/6.3.0.105/en/abandoninstall?page=tsProgressBar
Task: {52CCD173-E02E-4CA1-913A-BAE21E29FA24} - System32\Tasks\{9C41A5DC-17FB-425E-864F-68FE683DD2DC} => Firefox.exe http://ui.skype.com/ui/0/6.1.0.129.272/en/abandoninstall?page=tsProgressBar
Task: {59F04F43-CF11-4686-84A0-37F219832E71} - System32\Tasks\Microsoft\Windows\Windows Activation Technologies\ValidationTask => C:\Windows\system32\Wat\WatAdminSvc.exe [2013-02-11] (Microsoft Corporation)
Task: {7E158629-44D2-47BC-81F9-A3120966F21E} - System32\Tasks\EgisUpdate => C:\Program Files\EgisTec IPS\EgisUpdate.exe [2011-03-28] (Egis Technology Inc.)
Task: {9D2E8575-DA19-499C-ABAE-95F648294F2A} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2013-08-30] (AVAST Software)
Task: {D86A8D97-2BB6-4DCC-B294-FDA7F4184499} - System32\Tasks\PMMUpdate => C:\Program Files\EgisTec IPS\PMMUpdate.exe [2011-03-28] (Egis Technology Inc.)
Task: {D9809442-6411-45AC-8F7D-07CA890CDAA8} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-23] (Adobe Systems Incorporated)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Loaded Modules (whitelisted) =============

2009-01-21 17:45 - 2009-01-21 17:45 - 01401856 _____ () C:\Program Files (x86)\EgisTec MyWinLocker\x64\LIBEAY32.dll
2013-09-26 06:31 - 2013-09-10 19:26 - 03279768 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll

==================== Alternate Data Streams (whitelisted) =========


==================== Safe Mode (whitelisted) ===================

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="2"

==================== Faulty Device Manager Devices =============

Name: aswRvrt
Description: aswRvrt
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: aswRvrt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: avast! Network Shield Support
Description: avast! Network Shield Support
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: aswTdi
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: aswVmm
Description: aswVmm
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: aswVmm
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: Security Processor Loader Driver
Description: Security Processor Loader Driver
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: spldr
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: 1.3M HD WebCam
Description: USB Video Device
Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f}
Manufacturer: Microsoft
Service: usbvideo
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: =========================

Application errors:
==================
Error: (09/30/2013 10:53:17 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (09/30/2013 10:47:51 AM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (09/30/2013 10:47:36 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (09/30/2013 10:42:57 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (09/30/2013 10:34:22 AM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (09/30/2013 09:26:34 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (09/29/2013 05:02:07 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (09/29/2013 04:31:16 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (09/29/2013 04:13:12 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (09/29/2013 03:10:37 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


System errors:
=============
Error: (09/30/2013 11:07:49 AM) (Source: iaStor) (User: )
Description: The device, \Device\Ide\iaStor0, did not respond within the timeout period.

Error: (09/30/2013 11:07:27 AM) (Source: iaStor) (User: )
Description: The device, \Device\Ide\iaStor0, did not respond within the timeout period.

Error: (09/30/2013 11:07:26 AM) (Source: iaStor) (User: )
Description: The device, \Device\Ide\iaStor0, did not respond within the timeout period.

Error: (09/30/2013 11:07:25 AM) (Source: iaStor) (User: )
Description: The device, \Device\Ide\iaStor0, did not respond within the timeout period.

Error: (09/30/2013 11:07:24 AM) (Source: iaStor) (User: )
Description: The device, \Device\Ide\iaStor0, did not respond within the timeout period.

Error: (09/30/2013 11:07:23 AM) (Source: iaStor) (User: )
Description: The device, \Device\Ide\iaStor0, did not respond within the timeout period.

Error: (09/30/2013 11:06:27 AM) (Source: Service Control Manager) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
%%1068

Error: (09/30/2013 11:06:27 AM) (Source: Service Control Manager) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
%%1068

Error: (09/30/2013 11:06:27 AM) (Source: Service Control Manager) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
%%1068

Error: (09/30/2013 11:04:24 AM) (Source: Service Control Manager) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
%%1068


Microsoft Office Sessions:
=========================
Error: (09/30/2013 10:53:17 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (09/30/2013 10:47:51 AM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Tara\Downloads\esetsmartinstaller_enu.exe

Error: (09/30/2013 10:47:36 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (09/30/2013 10:42:57 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (09/30/2013 10:34:22 AM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Tara\Downloads\esetsmartinstaller_enu.exe

Error: (09/30/2013 09:26:34 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (09/29/2013 05:02:07 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (09/29/2013 04:31:16 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (09/29/2013 04:13:12 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (09/29/2013 03:10:37 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


CodeIntegrity Errors:
===================================
  Date: 2013-09-27 06:23:01.105
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2013-09-27 06:23:01.074
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


==================== Memory info ===========================

Percentage of memory in use: 17%
Total physical RAM: 5995.86 MB
Available physical RAM: 4963.79 MB
Total Pagefile: 11989.9 MB
Available Pagefile: 11006.94 MB
Total Virtual: 8192 MB
Available Virtual: 8191.85 MB

==================== Drives ================================

Drive c: (Acer) (Fixed) (Total:449.66 GB) (Free:313.92 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: E00F1085)
Partition 1: (Not Active) - (Size=16 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=450 GB) - (Type=07 NTFS)

==================== End Of Log ============================



#5 bloopie

bloopie

    Bleepin' Sith Turner


  • Malware Response Instructor
  • 6,344 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New York
  • Local time:12:10 PM

Posted 30 September 2013 - 02:23 PM

Hello again,

There is some adware in your logs, but not all that much malware. I see you have run Combofix before a few days ago, could you please post that log for me as well? You can find the log at C:\Combofix.txt.

I would also like to see the contents of the sfcdetails file on your desktop (C:\Users\Tara\Desktop\sfcdetails.txt).

==========

Next, please run these two programs:

 

Step :step1:

Please download AdwCleaner by Xplode onto your desktop.

  • Close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
  • Click on Delete.
  • Confirm each time with Ok.
  • You will be prompted to restart your computer. A text file will open after the restart.
  • Please post the contents of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.

==========

 

Step :step2:

 

 

thisisujrt.gif Please download Junkware Removal Tool to your desktop.

  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.

==========

Please post all requested logs for me in your next reply!

bloopie


Edited by bloopie, 30 September 2013 - 05:19 PM.
fixed typo


#6 taranicolex

taranicolex
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:10:10 AM

Posted 30 September 2013 - 02:51 PM

Ok here's the Adwcleaner log.

 

# AdwCleaner v3.005 - Report created 30/09/2013 at 12:39:28
# Updated 22/09/2013 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Tara - TARA-PC
# Running from : C:\Users\Tara\Desktop\AdwCleaner(2).exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

File Deleted : C:\Users\Tara\AppData\Roaming\Mozilla\Firefox\Profiles\tgw2b36b.default\searchplugins\safesearch.xml

***** [ Shortcuts ] *****


***** [ Registry ] *****


***** [ Browsers ] *****

-\\ Internet Explorer v10.0.9200.16686


-\\ Mozilla Firefox v24.0 (en-US)

[ File : C:\Users\Tara\AppData\Roaming\Mozilla\Firefox\Profiles\tgw2b36b.default\prefs.js ]

Line Deleted : user_pref("browser.search.defaultthis.engineName", "SafeSearch Web Search");

*************************

AdwCleaner[R0].txt - [3333 octets] - [27/09/2013 06:29:53]
AdwCleaner[R1].txt - [1099 octets] - [30/09/2013 12:35:44]
AdwCleaner[R2].txt - [1157 octets] - [30/09/2013 12:39:11]
AdwCleaner[S0].txt - [3067 octets] - [27/09/2013 06:30:42]
AdwCleaner[S1].txt - [1083 octets] - [30/09/2013 12:39:28]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1143 octets] ##########

 

 

 

Here's the JRT log.

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.3 (09.27.2013:1)
OS: Windows 7 Home Premium x64
Ran by Tara on Mon 09/30/2013 at 12:44:58.73
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{fc0c0170-4eb0-430d-a7f3-939ee7ea1a25}
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-3390557223-503640728-3712725754-1001\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\AboutURLs\\Tabs



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\safesearch.safesearch1
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3390557223-503640728-3712725754-1001\Software\SweetIM
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\mypc backup
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{4B51C980-C6B0-11E1-9136-AED16088709B}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{FC0C0170-4EB0-430D-A7F3-939EE7EA1A25}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{4B51C980-C6B0-11E1-9136-AED16088709B}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E27D5867-80DE-4449-9C03-71707C0DB05B}



~~~ Files



~~~ Folders

Successfully deleted: [Empty Folder] C:\Users\Tara\appdata\local\{A1F445F6-86CE-4C53-8977-E5253A7DA8A1}



~~~ FireFox

Successfully deleted: [File] C:\Users\Tara\AppData\Roaming\mozilla\firefox\profiles\tgw2b36b.default\searchplugins\safesearch-1.xml
Successfully deleted the following from C:\Users\Tara\AppData\Roaming\mozilla\firefox\profiles\tgw2b36b.default\prefs.js


user_pref("browser.search.defaultengine", "SafeSearch");
user_pref("browser.search.defaultenginename", "SafeSearch");

user_pref("browser.search.selectedEngine", "SafeSearch");



user_pref("plugin.state.npsafesearch", 0);
Emptied folder: C:\Users\Tara\AppData\Roaming\mozilla\firefox\profiles\tgw2b36b.default\minidumps [5 files]



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Mon 09/30/2013 at 12:47:07.28
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 

 

Here's the Combofix log.

 

ComboFix 13-09-26.03 - Tara 09/27/2013   5:49.1.4 - x64 NETWORK
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.1.1033.18.5996.4880 [GMT -7:00]
Running from: c:\users\Tara\Downloads\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Created a new restore point
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\DSearchLink
c:\programdata\DSearchLink\DSearchLink.exe
c:\windows\wininit.ini
.
.
(((((((((((((((((((((((((   Files Created from 2013-08-27 to 2013-09-27  )))))))))))))))))))))))))))))))
.
.
2013-09-27 10:11 . 2013-09-16 07:50    9694160    ----a-w-    c:\programdata\Microsoft\Windows Defender\Definition Updates\{AED76555-6E0C-47E6-B1D6-1E9FA7920804}\mpengine.dll
2013-09-27 06:12 . 2013-09-27 06:12    --------    d-----w-    C:\TDSSKiller_Quarantine
2013-09-27 05:58 . 2013-09-27 05:58    --------    d-----w-    c:\program files (x86)\Malwarebytes' Anti-Malware
2013-09-27 05:58 . 2013-04-04 21:50    25928    ----a-w-    c:\windows\system32\drivers\mbam.sys
2013-09-27 05:45 . 2013-09-27 06:21    --------    d-----w-    c:\programdata\Spybot - Search & Destroy
2013-09-26 12:34 . 2013-09-26 12:34    --------    d-----w-    c:\users\Tara\AppData\Roaming\Malwarebytes
2013-09-26 12:34 . 2013-09-26 12:34    --------    d-----w-    c:\programdata\Malwarebytes
2013-09-26 12:05 . 2013-09-26 12:08    --------    d-----w-    c:\program files (x86)\MyPC Backup
2013-09-26 12:05 . 2013-09-26 12:13    --------    d-----w-    c:\users\Tara\AppData\Roaming\Systweak
2013-09-26 12:05 . 2012-09-05 20:48    19368    ----a-w-    c:\windows\system32\roboot64.exe
2013-09-26 12:05 . 2013-09-26 12:05    --------    d-----w-    c:\programdata\Babylon
2013-09-24 02:49 . 2013-09-24 02:49    --------    d-----w-    c:\programdata\Oracle
2013-09-24 02:49 . 2013-09-24 02:49    96168    ----a-w-    c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-09-24 02:49 . 2013-09-24 02:49    --------    d-----w-    c:\program files (x86)\Java
2013-09-24 02:45 . 2013-09-24 02:45    --------    d-----w-    c:\program files (x86)\Common Files\Adobe
2013-09-24 02:36 . 2013-09-24 02:36    --------    d-----w-    c:\program files\Java
2013-09-23 03:02 . 2013-09-23 03:02    --------    d-----w-    c:\program files (x86)\THQ
2013-09-23 02:01 . 2013-09-23 02:01    --------    d-----w-    c:\users\Tara\AppData\Roaming\iPumper
2013-09-21 05:50 . 2013-09-24 11:04    --------    d-----w-    c:\program files (x86)\Diablo III
2013-09-17 08:48 . 2013-09-17 08:48    --------    d-----w-    c:\program files (x86)\Guitar Pro 5
2013-09-16 19:30 . 2013-09-16 19:30    4806016    ----a-w-    c:\program files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll
2013-09-16 19:30 . 2013-09-16 19:30    4806016    ----a-w-    c:\program files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll
2013-09-11 22:06 . 2013-08-05 02:25    155584    ----a-w-    c:\windows\system32\drivers\ataport.sys
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-09-26 12:52 . 2011-03-29 01:36    22240    ----a-w-    c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-09-24 03:23 . 2013-02-11 17:53    692616    ----a-w-    c:\windows\SysWow64\FlashPlayerApp.exe
2013-09-24 03:23 . 2011-10-31 07:59    71048    ----a-w-    c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-09-24 02:49 . 2013-02-11 17:43    790440    ----a-w-    c:\windows\SysWow64\deployJava1.dll
2013-09-24 02:49 . 2013-02-11 17:43    868264    ----a-w-    c:\windows\SysWow64\npDeployJava1.dll
2013-09-24 02:36 . 2013-02-11 19:22    973736    ----a-w-    c:\windows\system32\deployJava1.dll
2013-09-24 02:36 . 2013-02-11 19:22    1095080    ----a-w-    c:\windows\system32\npDeployJava1.dll
2013-09-12 22:23 . 2013-02-11 21:20    79143768    ----a-w-    c:\windows\system32\MRT.exe
2013-08-07 11:22 . 2010-11-21 03:27    278800    ------w-    c:\windows\system32\MpSigStub.exe
2013-08-02 01:48 . 2013-09-11 22:06    44032    ----a-w-    c:\windows\apppatch\acwow64.dll
2013-07-25 09:25 . 2013-08-14 08:44    1888768    ----a-w-    c:\windows\system32\WMVDECOD.DLL
2013-07-25 08:57 . 2013-08-14 08:44    1620992    ----a-w-    c:\windows\SysWow64\WMVDECOD.DLL
2013-07-19 01:58 . 2013-08-14 08:44    2048    ----a-w-    c:\windows\system32\tzres.dll
2013-07-19 01:41 . 2013-08-14 08:44    2048    ----a-w-    c:\windows\SysWow64\tzres.dll
2013-07-09 05:52 . 2013-08-14 08:45    224256    ----a-w-    c:\windows\system32\wintrust.dll
2013-07-09 05:51 . 2013-08-14 08:45    1217024    ----a-w-    c:\windows\system32\rpcrt4.dll
2013-07-09 05:46 . 2013-08-14 08:45    1472512    ----a-w-    c:\windows\system32\crypt32.dll
2013-07-09 05:46 . 2013-08-14 08:45    184320    ----a-w-    c:\windows\system32\cryptsvc.dll
2013-07-09 05:46 . 2013-08-14 08:45    139776    ----a-w-    c:\windows\system32\cryptnet.dll
2013-07-09 04:52 . 2013-08-14 08:45    663552    ----a-w-    c:\windows\SysWow64\rpcrt4.dll
2013-07-09 04:52 . 2013-08-14 08:45    175104    ----a-w-    c:\windows\SysWow64\wintrust.dll
2013-07-09 04:46 . 2013-08-14 08:45    1166848    ----a-w-    c:\windows\SysWow64\crypt32.dll
2013-07-09 04:46 . 2013-08-14 08:45    140288    ----a-w-    c:\windows\SysWow64\cryptsvc.dll
2013-07-09 04:46 . 2013-08-14 08:45    103936    ----a-w-    c:\windows\SysWow64\cryptnet.dll
2013-07-06 06:03 . 2013-08-14 08:44    1910208    ----a-w-    c:\windows\system32\drivers\tcpip.sys
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"BackupManagerTray"="c:\program files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe" [2011-04-24 297280]
"OOTag"="c:\program files (x86)\Acer\OOBEOffer\OOTag.exe" [2010-02-23 13856]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-10-13 343168]
"LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2011-07-01 1103440]
"NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-11-17 113288]
"Dolby Advanced Audio v2"="c:\dolby pcee4\pcee4.exe" [2011-06-01 506712]
"SuiteTray"="c:\program files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe" [2011-09-20 341360]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-09-05 958576]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"IsMyWinLockerReboot"="msiexec.exe" [2010-11-21 73216]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDFilter.sys [x]
R1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDNServ.sys [x]
R1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDVDisk.sys [x]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe;c:\program files (x86)\Launch Manager\dsiwmis.exe [x]
R2 ePowerSvc;ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [x]
R2 GREGService;GREGService;c:\program files (x86)\Acer\Registration\GREGsvc.exe;c:\program files (x86)\Acer\Registration\GREGsvc.exe [x]
R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
R2 Live Updater Service;Live Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe;c:\program files\Acer\Acer Updater\UpdaterService.exe [x]
R2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe;c:\program files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [x]
R2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys;c:\windows\SYSNATIVE\DRIVERS\TurboB.sys [x]
R2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [x]
R3 EgisTec Ticket Service;EgisTec Ticket Service;c:\program files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe;c:\program files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe [x]
R3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
R3 intelkmd;intelkmd;c:\windows\system32\DRIVERS\igdpmd64.sys;c:\windows\SYSNATIVE\DRIVERS\igdpmd64.sys [x]
R3 MotioninJoyXFilter;MotioninJoy Virtual Xinput device Filter Driver;c:\windows\system32\DRIVERS\MijXfilt.sys;c:\windows\SYSNATIVE\DRIVERS\MijXfilt.sys [x]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 TurboBoost;Intel® Turbo Boost Technology Monitor 2.0;c:\program files\Intel\TurboBoost\TurboBoost.exe;c:\program files\Intel\TurboBoost\TurboBoost.exe [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys;c:\windows\SYSNATIVE\DRIVERS\ETD.sys [x]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3hub.sys [x]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3xhc.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation    REG_MULTI_SZ       SSDPSRV SCardSvr TBS QWAVE wcncsvc
.
Contents of the 'Scheduled Tasks' folder
.
2013-09-27 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-02-11 03:23]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelTBRunOnce"="wscript.exe" [2009-07-14 168960]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-08-16 12673128]
"RtHDVBg_Dolby"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-08-16 2277480]
"Power Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2011-08-02 1831016]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-08-09 167704]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-08-09 392472]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-08-09 416024]
"Logitech Download Assistant"="c:\windows\System32\LogiLDA.dll" [2012-09-20 1832760]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm

mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Tara\AppData\Roaming\Mozilla\Firefox\Profiles\tgw2b36b.default\
FF - ExtSQL: 2013-09-23 20:03; {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}; c:\program files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF - ExtSQL: 2013-09-26 06:32; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\users\Tara\AppData\Roaming\Mozilla\Firefox\Profiles\tgw2b36b.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
SafeBoot-51599607.sys
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
Toolbar-Locked - (no file)
HKLM-Run-ETDCtrl - c:\program files (x86)\Elantech\ETDCtrl.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_175_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_175_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_175_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_175_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
   00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2013-09-27  06:25:47
ComboFix-quarantined-files.txt  2013-09-27 13:25
.
Pre-Run: 338,329,083,904 bytes free
Post-Run: 338,198,298,624 bytes free
.
- - End Of File - - 502047025FCE14D45C3CD4BF10877484

 

 

And here's the sfc scan I did that was on my desktop. Though when I did that it never got past 27%.

 

2013-09-27 02:12:41, Info                  CSI    00000009 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 02:12:41, Info                  CSI    0000000a [SR] Beginning Verify and Repair transaction
2013-09-27 02:12:43, Info                  CSI    0000000c [SR] Verify complete
2013-09-27 02:12:44, Info                  CSI    0000000d [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 02:12:44, Info                  CSI    0000000e [SR] Beginning Verify and Repair transaction
2013-09-27 02:12:45, Info                  CSI    00000010 [SR] Verify complete
2013-09-27 02:12:46, Info                  CSI    00000011 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 02:12:46, Info                  CSI    00000012 [SR] Beginning Verify and Repair transaction
2013-09-27 02:12:47, Info                  CSI    00000014 [SR] Verify complete
2013-09-27 02:12:47, Info                  CSI    00000015 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 02:12:47, Info                  CSI    00000016 [SR] Beginning Verify and Repair transaction
2013-09-27 02:12:49, Info                  CSI    00000018 [SR] Verify complete
2013-09-27 02:12:49, Info                  CSI    00000019 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 02:12:49, Info                  CSI    0000001a [SR] Beginning Verify and Repair transaction
2013-09-27 02:12:51, Info                  CSI    0000001c [SR] Verify complete
2013-09-27 02:12:51, Info                  CSI    0000001d [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 02:12:51, Info                  CSI    0000001e [SR] Beginning Verify and Repair transaction
2013-09-27 02:12:54, Info                  CSI    00000020 [SR] Verify complete
2013-09-27 02:12:54, Info                  CSI    00000021 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 02:12:54, Info                  CSI    00000022 [SR] Beginning Verify and Repair transaction
2013-09-27 02:12:57, Info                  CSI    00000024 [SR] Verify complete
2013-09-27 02:12:57, Info                  CSI    00000025 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 02:12:57, Info                  CSI    00000026 [SR] Beginning Verify and Repair transaction
2013-09-27 02:12:59, Info                  CSI    00000028 [SR] Verify complete
2013-09-27 02:12:59, Info                  CSI    00000029 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 02:12:59, Info                  CSI    0000002a [SR] Beginning Verify and Repair transaction
2013-09-27 02:13:01, Info                  CSI    0000002c [SR] Verify complete
2013-09-27 02:13:01, Info                  CSI    0000002d [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 02:13:01, Info                  CSI    0000002e [SR] Beginning Verify and Repair transaction
2013-09-27 02:13:04, Info                  CSI    00000030 [SR] Verify complete
2013-09-27 02:13:04, Info                  CSI    00000031 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 02:13:04, Info                  CSI    00000032 [SR] Beginning Verify and Repair transaction
2013-09-27 02:13:05, Info                  CSI    00000034 [SR] Verify complete
2013-09-27 02:13:06, Info                  CSI    00000035 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 02:13:06, Info                  CSI    00000036 [SR] Beginning Verify and Repair transaction
2013-09-27 02:13:06, Info                  CSI    00000038 [SR] Verify complete
2013-09-27 02:13:06, Info                  CSI    00000039 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 02:13:06, Info                  CSI    0000003a [SR] Beginning Verify and Repair transaction
2013-09-27 02:13:10, Info                  CSI    0000003d [SR] Verify complete
2013-09-27 02:13:11, Info                  CSI    0000003e [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 02:13:11, Info                  CSI    0000003f [SR] Beginning Verify and Repair transaction
2013-09-27 02:13:15, Info                  CSI    00000043 [SR] Verify complete
2013-09-27 02:13:16, Info                  CSI    00000044 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 02:13:16, Info                  CSI    00000045 [SR] Beginning Verify and Repair transaction
2013-09-27 02:13:18, Info                  CSI    00000048 [SR] Verify complete
2013-09-27 02:13:19, Info                  CSI    00000049 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 02:13:19, Info                  CSI    0000004a [SR] Beginning Verify and Repair transaction
2013-09-27 02:13:25, Info                  CSI    0000004d [SR] Verify complete
2013-09-27 02:13:26, Info                  CSI    0000004e [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 02:13:26, Info                  CSI    0000004f [SR] Beginning Verify and Repair transaction
2013-09-27 02:13:30, Info                  CSI    00000051 [SR] Verify complete
2013-09-27 02:13:31, Info                  CSI    00000052 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 02:13:31, Info                  CSI    00000053 [SR] Beginning Verify and Repair transaction
2013-09-27 02:13:37, Info                  CSI    00000078 [SR] Verify complete
2013-09-27 02:13:37, Info                  CSI    00000079 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 02:13:37, Info                  CSI    0000007a [SR] Beginning Verify and Repair transaction
2013-09-27 02:13:42, Info                  CSI    0000007c [SR] Verify complete
2013-09-27 02:13:42, Info                  CSI    0000007d [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 02:13:42, Info                  CSI    0000007e [SR] Beginning Verify and Repair transaction
2013-09-27 02:13:46, Info                  CSI    00000080 [SR] Verify complete
2013-09-27 02:13:46, Info                  CSI    00000081 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 02:13:46, Info                  CSI    00000082 [SR] Beginning Verify and Repair transaction
2013-09-27 02:13:50, Info                  CSI    00000084 [SR] Verify complete
2013-09-27 02:13:50, Info                  CSI    00000085 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 02:13:50, Info                  CSI    00000086 [SR] Beginning Verify and Repair transaction
2013-09-27 02:13:55, Info                  CSI    00000088 [SR] Verify complete
2013-09-27 02:13:55, Info                  CSI    00000089 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 02:13:55, Info                  CSI    0000008a [SR] Beginning Verify and Repair transaction
2013-09-27 02:13:59, Info                  CSI    0000008c [SR] Verify complete
2013-09-27 02:13:59, Info                  CSI    0000008d [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 02:13:59, Info                  CSI    0000008e [SR] Beginning Verify and Repair transaction
2013-09-27 02:14:07, Info                  CSI    00000092 [SR] Verify complete
2013-09-27 02:14:07, Info                  CSI    00000093 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 02:14:07, Info                  CSI    00000094 [SR] Beginning Verify and Repair transaction
2013-09-27 02:14:13, Info                  CSI    000000b5 [SR] Verify complete
2013-09-27 02:14:13, Info                  CSI    000000b6 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 02:14:13, Info                  CSI    000000b7 [SR] Beginning Verify and Repair transaction
2013-09-27 02:14:21, Info                  CSI    000000b9 [SR] Verify complete
2013-09-27 02:14:22, Info                  CSI    000000ba [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 02:14:22, Info                  CSI    000000bb [SR] Beginning Verify and Repair transaction
2013-09-27 02:14:32, Info                  CSI    000000bf [SR] Verify complete
2013-09-27 02:14:32, Info                  CSI    000000c0 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 02:14:32, Info                  CSI    000000c1 [SR] Beginning Verify and Repair transaction
2013-09-27 02:14:33, Info                  CSI    000000c3 [SR] Cannot repair member file [l:20{10}]"artui3.h1s" of Microsoft-Windows-Help-Artui3.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2013-09-27 02:14:34, Info                  CSI    000000c5 [SR] Cannot repair member file [l:20{10}]"artui3.h1s" of Microsoft-Windows-Help-Artui3.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2013-09-27 02:14:34, Info                  CSI    000000c6 [SR] This component was referenced by [l:266{133}]"Microsoft-Windows-WindowsFoundation-LanguagePack-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.Windows Foundation Language Pack"
2013-09-27 02:14:34, Info                  CSI    000000c9 [SR] Could not reproject corrupted file [ml:520{260},l:66{33}]"\??\C:\Windows\Help\Windows\en-US"\[l:20{10}]"artui3.h1s"; source file in store is also corrupted
2013-09-27 02:14:34, Info                  CSI    000000cb [SR] Verify complete
2013-09-27 02:14:34, Info                  CSI    000000cc [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 02:14:34, Info                  CSI    000000cd [SR] Beginning Verify and Repair transaction
2013-09-27 02:14:35, Info                  CSI    000000cf [SR] Verify complete
2013-09-27 02:14:35, Info                  CSI    000000d0 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 02:14:35, Info                  CSI    000000d1 [SR] Beginning Verify and Repair transaction
2013-09-27 02:14:37, Info                  CSI    000000d3 [SR] Verify complete
2013-09-27 02:14:37, Info                  CSI    000000d4 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 02:14:37, Info                  CSI    000000d5 [SR] Beginning Verify and Repair transaction
2013-09-27 02:14:44, Info                  CSI    000000e8 [SR] Verify complete
2013-09-27 02:14:44, Info                  CSI    000000e9 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 02:14:44, Info                  CSI    000000ea [SR] Beginning Verify and Repair transaction
2013-09-27 02:14:45, Info                  CSI    000000ec [SR] Verify complete
2013-09-27 02:14:45, Info                  CSI    000000ed [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 02:14:45, Info                  CSI    000000ee [SR] Beginning Verify and Repair transaction
2013-09-27 02:14:47, Info                  CSI    000000f0 [SR] Verify complete
2013-09-27 02:14:47, Info                  CSI    000000f1 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 02:14:47, Info                  CSI    000000f2 [SR] Beginning Verify and Repair transaction
2013-09-27 02:14:48, Info                  CSI    000000f4 [SR] Verify complete
2013-09-27 02:14:49, Info                  CSI    000000f5 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 02:14:49, Info                  CSI    000000f6 [SR] Beginning Verify and Repair transaction
2013-09-27 02:14:53, Info                  CSI    000000f9 [SR] Verify complete
2013-09-27 02:14:53, Info                  CSI    000000fa [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 02:14:53, Info                  CSI    000000fb [SR] Beginning Verify and Repair transaction
2013-09-27 20:42:39, Info                  CSI    00000009 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 20:42:39, Info                  CSI    0000000a [SR] Beginning Verify and Repair transaction
2013-09-27 20:42:41, Info                  CSI    0000000c [SR] Verify complete
2013-09-27 20:43:04, Info                  CSI    0000000d [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 20:43:04, Info                  CSI    0000000e [SR] Beginning Verify and Repair transaction
2013-09-27 20:43:05, Info                  CSI    00000010 [SR] Verify complete
2013-09-27 20:43:06, Info                  CSI    00000011 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 20:43:06, Info                  CSI    00000012 [SR] Beginning Verify and Repair transaction
2013-09-27 20:43:29, Info                  CSI    00000014 [SR] Verify complete
2013-09-27 20:43:29, Info                  CSI    00000015 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 20:43:29, Info                  CSI    00000016 [SR] Beginning Verify and Repair transaction
2013-09-27 20:43:53, Info                  CSI    00000018 [SR] Verify complete
2013-09-27 20:44:15, Info                  CSI    00000019 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 20:44:15, Info                  CSI    0000001a [SR] Beginning Verify and Repair transaction
2013-09-27 20:44:16, Info                  CSI    0000001c [SR] Verify complete
2013-09-27 20:44:17, Info                  CSI    0000001d [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 20:44:17, Info                  CSI    0000001e [SR] Beginning Verify and Repair transaction
2013-09-27 20:44:19, Info                  CSI    00000020 [SR] Verify complete
2013-09-27 20:44:20, Info                  CSI    00000021 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 20:44:20, Info                  CSI    00000022 [SR] Beginning Verify and Repair transaction
2013-09-27 20:44:44, Info                  CSI    00000024 [SR] Verify complete
2013-09-27 20:44:44, Info                  CSI    00000025 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 20:44:44, Info                  CSI    00000026 [SR] Beginning Verify and Repair transaction
2013-09-27 20:44:46, Info                  CSI    00000028 [SR] Verify complete
2013-09-27 20:44:46, Info                  CSI    00000029 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 20:44:46, Info                  CSI    0000002a [SR] Beginning Verify and Repair transaction
2013-09-27 20:44:48, Info                  CSI    0000002c [SR] Verify complete
2013-09-27 20:44:48, Info                  CSI    0000002d [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 20:44:48, Info                  CSI    0000002e [SR] Beginning Verify and Repair transaction
2013-09-27 20:44:51, Info                  CSI    00000030 [SR] Verify complete
2013-09-27 20:44:51, Info                  CSI    00000031 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 20:44:51, Info                  CSI    00000032 [SR] Beginning Verify and Repair transaction
2013-09-27 20:44:52, Info                  CSI    00000034 [SR] Verify complete
2013-09-27 20:44:52, Info                  CSI    00000035 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 20:44:52, Info                  CSI    00000036 [SR] Beginning Verify and Repair transaction
2013-09-27 20:44:53, Info                  CSI    00000038 [SR] Verify complete
2013-09-27 20:44:53, Info                  CSI    00000039 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 20:44:53, Info                  CSI    0000003a [SR] Beginning Verify and Repair transaction
2013-09-27 20:44:57, Info                  CSI    0000003d [SR] Verify complete
2013-09-27 20:44:57, Info                  CSI    0000003e [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 20:44:57, Info                  CSI    0000003f [SR] Beginning Verify and Repair transaction
2013-09-27 20:45:04, Info                  CSI    00000043 [SR] Verify complete
2013-09-27 20:45:05, Info                  CSI    00000044 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 20:45:05, Info                  CSI    00000045 [SR] Beginning Verify and Repair transaction
2013-09-27 20:45:07, Info                  CSI    00000048 [SR] Verify complete
2013-09-27 20:45:07, Info                  CSI    00000049 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 20:45:07, Info                  CSI    0000004a [SR] Beginning Verify and Repair transaction
2013-09-27 20:45:10, Info                  CSI    0000004d [SR] Verify complete
2013-09-27 20:45:10, Info                  CSI    0000004e [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 20:45:10, Info                  CSI    0000004f [SR] Beginning Verify and Repair transaction
2013-09-27 20:45:14, Info                  CSI    00000051 [SR] Verify complete
2013-09-27 20:45:14, Info                  CSI    00000052 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 20:45:14, Info                  CSI    00000053 [SR] Beginning Verify and Repair transaction
2013-09-27 20:45:19, Info                  CSI    00000078 [SR] Verify complete
2013-09-27 20:45:20, Info                  CSI    00000079 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 20:45:20, Info                  CSI    0000007a [SR] Beginning Verify and Repair transaction
2013-09-27 20:45:23, Info                  CSI    0000007c [SR] Verify complete
2013-09-27 20:45:24, Info                  CSI    0000007d [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 20:45:24, Info                  CSI    0000007e [SR] Beginning Verify and Repair transaction
2013-09-27 20:45:27, Info                  CSI    00000080 [SR] Verify complete
2013-09-27 20:45:27, Info                  CSI    00000081 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 20:45:27, Info                  CSI    00000082 [SR] Beginning Verify and Repair transaction
2013-09-27 20:45:30, Info                  CSI    00000084 [SR] Verify complete
2013-09-27 20:45:31, Info                  CSI    00000085 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 20:45:31, Info                  CSI    00000086 [SR] Beginning Verify and Repair transaction
2013-09-27 20:45:34, Info                  CSI    00000088 [SR] Verify complete
2013-09-27 20:45:34, Info                  CSI    00000089 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 20:45:34, Info                  CSI    0000008a [SR] Beginning Verify and Repair transaction
2013-09-27 20:45:37, Info                  CSI    0000008c [SR] Verify complete
2013-09-27 20:45:38, Info                  CSI    0000008d [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 20:45:38, Info                  CSI    0000008e [SR] Beginning Verify and Repair transaction
2013-09-27 20:45:44, Info                  CSI    00000092 [SR] Verify complete
2013-09-27 20:45:44, Info                  CSI    00000093 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 20:45:44, Info                  CSI    00000094 [SR] Beginning Verify and Repair transaction
2013-09-27 20:45:49, Info                  CSI    000000b5 [SR] Verify complete
2013-09-27 20:45:49, Info                  CSI    000000b6 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 20:45:49, Info                  CSI    000000b7 [SR] Beginning Verify and Repair transaction
2013-09-27 20:45:57, Info                  CSI    000000b9 [SR] Verify complete
2013-09-27 20:45:58, Info                  CSI    000000ba [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 20:45:58, Info                  CSI    000000bb [SR] Beginning Verify and Repair transaction
2013-09-27 20:46:07, Info                  CSI    000000bf [SR] Verify complete
2013-09-27 20:46:07, Info                  CSI    000000c0 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 20:46:07, Info                  CSI    000000c1 [SR] Beginning Verify and Repair transaction
2013-09-27 20:46:08, Info                  CSI    000000c3 [SR] Cannot repair member file [l:20{10}]"artui3.h1s" of Microsoft-Windows-Help-Artui3.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2013-09-27 20:46:09, Info                  CSI    000000c5 [SR] Cannot repair member file [l:20{10}]"artui3.h1s" of Microsoft-Windows-Help-Artui3.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2013-09-27 20:46:09, Info                  CSI    000000c6 [SR] This component was referenced by [l:266{133}]"Microsoft-Windows-WindowsFoundation-LanguagePack-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.Windows Foundation Language Pack"
2013-09-27 20:46:09, Info                  CSI    000000c9 [SR] Could not reproject corrupted file [ml:520{260},l:66{33}]"\??\C:\Windows\Help\Windows\en-US"\[l:20{10}]"artui3.h1s"; source file in store is also corrupted
2013-09-27 20:46:09, Info                  CSI    000000cb [SR] Verify complete
2013-09-27 20:46:09, Info                  CSI    000000cc [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 20:46:09, Info                  CSI    000000cd [SR] Beginning Verify and Repair transaction
2013-09-27 20:46:10, Info                  CSI    000000cf [SR] Verify complete
2013-09-27 20:46:10, Info                  CSI    000000d0 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 20:46:10, Info                  CSI    000000d1 [SR] Beginning Verify and Repair transaction
2013-09-27 20:46:11, Info                  CSI    000000d3 [SR] Verify complete
2013-09-27 20:46:12, Info                  CSI    000000d4 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 20:46:12, Info                  CSI    000000d5 [SR] Beginning Verify and Repair transaction
2013-09-27 20:46:17, Info                  CSI    000000e8 [SR] Verify complete
2013-09-27 20:46:17, Info                  CSI    000000e9 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 20:46:17, Info                  CSI    000000ea [SR] Beginning Verify and Repair transaction
2013-09-27 20:46:18, Info                  CSI    000000ec [SR] Verify complete
2013-09-27 20:46:18, Info                  CSI    000000ed [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 20:46:18, Info                  CSI    000000ee [SR] Beginning Verify and Repair transaction
2013-09-27 20:46:20, Info                  CSI    000000f0 [SR] Verify complete
2013-09-27 20:46:20, Info                  CSI    000000f1 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 20:46:20, Info                  CSI    000000f2 [SR] Beginning Verify and Repair transaction
2013-09-27 20:46:21, Info                  CSI    000000f4 [SR] Verify complete
2013-09-27 20:46:22, Info                  CSI    000000f5 [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 20:46:22, Info                  CSI    000000f6 [SR] Beginning Verify and Repair transaction
2013-09-27 20:46:25, Info                  CSI    000000f9 [SR] Verify complete
2013-09-27 20:46:26, Info                  CSI    000000fa [SR] Verifying 100 (0x0000000000000064) components
2013-09-27 20:46:26, Info                  CSI    000000fb [SR] Beginning Verify and Repair transaction
2013-09-29 16:33:21, Info                  CSI    00000009 [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:33:21, Info                  CSI    0000000a [SR] Beginning Verify and Repair transaction
2013-09-29 16:33:22, Info                  CSI    0000000c [SR] Verify complete
2013-09-29 16:33:23, Info                  CSI    0000000d [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:33:23, Info                  CSI    0000000e [SR] Beginning Verify and Repair transaction
2013-09-29 16:33:24, Info                  CSI    00000010 [SR] Verify complete
2013-09-29 16:33:25, Info                  CSI    00000011 [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:33:25, Info                  CSI    00000012 [SR] Beginning Verify and Repair transaction
2013-09-29 16:33:26, Info                  CSI    00000014 [SR] Verify complete
2013-09-29 16:33:27, Info                  CSI    00000015 [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:33:27, Info                  CSI    00000016 [SR] Beginning Verify and Repair transaction
2013-09-29 16:33:28, Info                  CSI    00000018 [SR] Verify complete
2013-09-29 16:33:29, Info                  CSI    00000019 [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:33:29, Info                  CSI    0000001a [SR] Beginning Verify and Repair transaction
2013-09-29 16:33:31, Info                  CSI    0000001c [SR] Verify complete
2013-09-29 16:33:31, Info                  CSI    0000001d [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:33:31, Info                  CSI    0000001e [SR] Beginning Verify and Repair transaction
2013-09-29 16:33:34, Info                  CSI    00000020 [SR] Verify complete
2013-09-29 16:33:34, Info                  CSI    00000021 [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:33:34, Info                  CSI    00000022 [SR] Beginning Verify and Repair transaction
2013-09-29 16:33:37, Info                  CSI    00000024 [SR] Verify complete
2013-09-29 16:33:37, Info                  CSI    00000025 [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:33:37, Info                  CSI    00000026 [SR] Beginning Verify and Repair transaction
2013-09-29 16:33:39, Info                  CSI    00000028 [SR] Verify complete
2013-09-29 16:33:39, Info                  CSI    00000029 [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:33:39, Info                  CSI    0000002a [SR] Beginning Verify and Repair transaction
2013-09-29 16:33:41, Info                  CSI    0000002c [SR] Verify complete
2013-09-29 16:33:41, Info                  CSI    0000002d [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:33:41, Info                  CSI    0000002e [SR] Beginning Verify and Repair transaction
2013-09-29 16:33:44, Info                  CSI    00000030 [SR] Verify complete
2013-09-29 16:33:44, Info                  CSI    00000031 [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:33:44, Info                  CSI    00000032 [SR] Beginning Verify and Repair transaction
2013-09-29 16:33:46, Info                  CSI    00000034 [SR] Verify complete
2013-09-29 16:33:46, Info                  CSI    00000035 [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:33:46, Info                  CSI    00000036 [SR] Beginning Verify and Repair transaction
2013-09-29 16:33:47, Info                  CSI    00000038 [SR] Verify complete
2013-09-29 16:33:47, Info                  CSI    00000039 [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:33:47, Info                  CSI    0000003a [SR] Beginning Verify and Repair transaction
2013-09-29 16:33:51, Info                  CSI    0000003d [SR] Verify complete
2013-09-29 16:33:51, Info                  CSI    0000003e [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:33:51, Info                  CSI    0000003f [SR] Beginning Verify and Repair transaction
2013-09-29 16:33:56, Info                  CSI    00000043 [SR] Verify complete
2013-09-29 16:33:56, Info                  CSI    00000044 [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:33:56, Info                  CSI    00000045 [SR] Beginning Verify and Repair transaction
2013-09-29 16:33:59, Info                  CSI    00000048 [SR] Verify complete
2013-09-29 16:33:59, Info                  CSI    00000049 [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:33:59, Info                  CSI    0000004a [SR] Beginning Verify and Repair transaction
2013-09-29 16:34:03, Info                  CSI    0000004d [SR] Verify complete
2013-09-29 16:34:03, Info                  CSI    0000004e [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:34:03, Info                  CSI    0000004f [SR] Beginning Verify and Repair transaction
2013-09-29 16:34:16, Info                  CSI    00000051 [SR] Verify complete
2013-09-29 16:34:16, Info                  CSI    00000052 [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:34:16, Info                  CSI    00000053 [SR] Beginning Verify and Repair transaction
2013-09-29 16:34:22, Info                  CSI    00000078 [SR] Verify complete
2013-09-29 16:34:23, Info                  CSI    00000079 [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:34:23, Info                  CSI    0000007a [SR] Beginning Verify and Repair transaction
2013-09-29 16:34:27, Info                  CSI    0000007c [SR] Verify complete
2013-09-29 16:34:27, Info                  CSI    0000007d [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:34:27, Info                  CSI    0000007e [SR] Beginning Verify and Repair transaction
2013-09-29 16:34:32, Info                  CSI    00000080 [SR] Verify complete
2013-09-29 16:34:32, Info                  CSI    00000081 [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:34:32, Info                  CSI    00000082 [SR] Beginning Verify and Repair transaction
2013-09-29 16:34:36, Info                  CSI    00000084 [SR] Verify complete
2013-09-29 16:34:36, Info                  CSI    00000085 [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:34:36, Info                  CSI    00000086 [SR] Beginning Verify and Repair transaction
2013-09-29 16:34:41, Info                  CSI    00000088 [SR] Verify complete
2013-09-29 16:34:41, Info                  CSI    00000089 [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:34:41, Info                  CSI    0000008a [SR] Beginning Verify and Repair transaction
2013-09-29 16:34:45, Info                  CSI    0000008c [SR] Verify complete
2013-09-29 16:34:45, Info                  CSI    0000008d [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:34:45, Info                  CSI    0000008e [SR] Beginning Verify and Repair transaction
2013-09-29 16:34:53, Info                  CSI    00000092 [SR] Verify complete
2013-09-29 16:34:53, Info                  CSI    00000093 [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:34:53, Info                  CSI    00000094 [SR] Beginning Verify and Repair transaction
2013-09-29 16:34:59, Info                  CSI    000000b5 [SR] Verify complete
2013-09-29 16:34:59, Info                  CSI    000000b6 [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:34:59, Info                  CSI    000000b7 [SR] Beginning Verify and Repair transaction
2013-09-29 16:35:07, Info                  CSI    000000b9 [SR] Verify complete
2013-09-29 16:35:08, Info                  CSI    000000ba [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:35:08, Info                  CSI    000000bb [SR] Beginning Verify and Repair transaction
2013-09-29 16:35:18, Info                  CSI    000000bf [SR] Verify complete
2013-09-29 16:35:19, Info                  CSI    000000c0 [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:35:19, Info                  CSI    000000c1 [SR] Beginning Verify and Repair transaction
2013-09-29 16:35:20, Info                  CSI    000000c3 [SR] Cannot repair member file [l:20{10}]"artui3.h1s" of Microsoft-Windows-Help-Artui3.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2013-09-29 16:35:20, Info                  CSI    000000c5 [SR] Cannot repair member file [l:20{10}]"artui3.h1s" of Microsoft-Windows-Help-Artui3.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2013-09-29 16:35:20, Info                  CSI    000000c6 [SR] This component was referenced by [l:266{133}]"Microsoft-Windows-WindowsFoundation-LanguagePack-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.Windows Foundation Language Pack"
2013-09-29 16:35:20, Info                  CSI    000000c9 [SR] Could not reproject corrupted file [ml:520{260},l:66{33}]"\??\C:\Windows\Help\Windows\en-US"\[l:20{10}]"artui3.h1s"; source file in store is also corrupted
2013-09-29 16:35:21, Info                  CSI    000000cb [SR] Verify complete
2013-09-29 16:35:21, Info                  CSI    000000cc [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:35:21, Info                  CSI    000000cd [SR] Beginning Verify and Repair transaction
2013-09-29 16:35:21, Info                  CSI    000000cf [SR] Verify complete
2013-09-29 16:35:22, Info                  CSI    000000d0 [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:35:22, Info                  CSI    000000d1 [SR] Beginning Verify and Repair transaction
2013-09-29 16:35:23, Info                  CSI    000000d3 [SR] Verify complete
2013-09-29 16:35:24, Info                  CSI    000000d4 [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:35:24, Info                  CSI    000000d5 [SR] Beginning Verify and Repair transaction
2013-09-29 16:35:30, Info                  CSI    000000e8 [SR] Verify complete
2013-09-29 16:35:30, Info                  CSI    000000e9 [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:35:30, Info                  CSI    000000ea [SR] Beginning Verify and Repair transaction
2013-09-29 16:35:31, Info                  CSI    000000ec [SR] Verify complete
2013-09-29 16:35:32, Info                  CSI    000000ed [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:35:32, Info                  CSI    000000ee [SR] Beginning Verify and Repair transaction
2013-09-29 16:35:33, Info                  CSI    000000f0 [SR] Verify complete
2013-09-29 16:35:33, Info                  CSI    000000f1 [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:35:33, Info                  CSI    000000f2 [SR] Beginning Verify and Repair transaction
2013-09-29 16:35:35, Info                  CSI    000000f4 [SR] Verify complete
2013-09-29 16:35:35, Info                  CSI    000000f5 [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:35:35, Info                  CSI    000000f6 [SR] Beginning Verify and Repair transaction
2013-09-29 16:35:40, Info                  CSI    000000f9 [SR] Verify complete
2013-09-29 16:35:40, Info                  CSI    000000fa [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:35:40, Info                  CSI    000000fb [SR] Beginning Verify and Repair transaction
2013-09-29 16:47:07, Info                  CSI    000000ff [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:47:07, Info                  CSI    00000100 [SR] Beginning Verify and Repair transaction
2013-09-29 16:47:07, Info                  CSI    00000102 [SR] Verify complete
2013-09-29 16:47:07, Info                  CSI    00000103 [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:47:07, Info                  CSI    00000104 [SR] Beginning Verify and Repair transaction
2013-09-29 16:47:07, Info                  CSI    00000106 [SR] Verify complete
2013-09-29 16:47:07, Info                  CSI    00000107 [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:47:07, Info                  CSI    00000108 [SR] Beginning Verify and Repair transaction
2013-09-29 16:47:07, Info                  CSI    0000010a [SR] Verify complete
2013-09-29 16:47:07, Info                  CSI    0000010b [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:47:07, Info                  CSI    0000010c [SR] Beginning Verify and Repair transaction
2013-09-29 16:47:07, Info                  CSI    0000010e [SR] Verify complete
2013-09-29 16:47:08, Info                  CSI    0000010f [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:47:08, Info                  CSI    00000110 [SR] Beginning Verify and Repair transaction
2013-09-29 16:47:08, Info                  CSI    00000112 [SR] Verify complete
2013-09-29 16:47:08, Info                  CSI    00000113 [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:47:08, Info                  CSI    00000114 [SR] Beginning Verify and Repair transaction
2013-09-29 16:47:08, Info                  CSI    00000116 [SR] Verify complete
2013-09-29 16:47:09, Info                  CSI    00000117 [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:47:09, Info                  CSI    00000118 [SR] Beginning Verify and Repair transaction
2013-09-29 16:47:09, Info                  CSI    0000011a [SR] Verify complete
2013-09-29 16:47:09, Info                  CSI    0000011b [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:47:09, Info                  CSI    0000011c [SR] Beginning Verify and Repair transaction
2013-09-29 16:47:09, Info                  CSI    0000011e [SR] Verify complete
2013-09-29 16:47:09, Info                  CSI    0000011f [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:47:09, Info                  CSI    00000120 [SR] Beginning Verify and Repair transaction
2013-09-29 16:47:10, Info                  CSI    00000122 [SR] Verify complete
2013-09-29 16:47:10, Info                  CSI    00000123 [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:47:10, Info                  CSI    00000124 [SR] Beginning Verify and Repair transaction
2013-09-29 16:47:10, Info                  CSI    00000126 [SR] Verify complete
2013-09-29 16:47:10, Info                  CSI    00000127 [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:47:10, Info                  CSI    00000128 [SR] Beginning Verify and Repair transaction
2013-09-29 16:47:11, Info                  CSI    0000012a [SR] Verify complete
2013-09-29 16:47:11, Info                  CSI    0000012b [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:47:11, Info                  CSI    0000012c [SR] Beginning Verify and Repair transaction
2013-09-29 16:47:11, Info                  CSI    0000012e [SR] Verify complete
2013-09-29 16:47:11, Info                  CSI    0000012f [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:47:11, Info                  CSI    00000130 [SR] Beginning Verify and Repair transaction
2013-09-29 16:47:12, Info                  CSI    00000133 [SR] Verify complete
2013-09-29 16:47:13, Info                  CSI    00000134 [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:47:13, Info                  CSI    00000135 [SR] Beginning Verify and Repair transaction
2013-09-29 16:47:14, Info                  CSI    00000139 [SR] Verify complete
2013-09-29 16:47:14, Info                  CSI    0000013a [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:47:14, Info                  CSI    0000013b [SR] Beginning Verify and Repair transaction
2013-09-29 16:47:15, Info                  CSI    0000013e [SR] Verify complete
2013-09-29 16:47:15, Info                  CSI    0000013f [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:47:15, Info                  CSI    00000140 [SR] Beginning Verify and Repair transaction
2013-09-29 16:47:16, Info                  CSI    00000143 [SR] Verify complete
2013-09-29 16:47:16, Info                  CSI    00000144 [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:47:16, Info                  CSI    00000145 [SR] Beginning Verify and Repair transaction
2013-09-29 16:47:18, Info                  CSI    00000147 [SR] Verify complete
2013-09-29 16:47:18, Info                  CSI    00000148 [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:47:18, Info                  CSI    00000149 [SR] Beginning Verify and Repair transaction
2013-09-29 16:47:21, Info                  CSI    0000016e [SR] Verify complete
2013-09-29 16:47:21, Info                  CSI    0000016f [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:47:21, Info                  CSI    00000170 [SR] Beginning Verify and Repair transaction
2013-09-29 16:47:22, Info                  CSI    00000172 [SR] Verify complete
2013-09-29 16:47:22, Info                  CSI    00000173 [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:47:22, Info                  CSI    00000174 [SR] Beginning Verify and Repair transaction
2013-09-29 16:47:24, Info                  CSI    00000176 [SR] Verify complete
2013-09-29 16:47:24, Info                  CSI    00000177 [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:47:24, Info                  CSI    00000178 [SR] Beginning Verify and Repair transaction
2013-09-29 16:47:25, Info                  CSI    0000017a [SR] Verify complete
2013-09-29 16:47:25, Info                  CSI    0000017b [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:47:25, Info                  CSI    0000017c [SR] Beginning Verify and Repair transaction
2013-09-29 16:47:26, Info                  CSI    0000017e [SR] Verify complete
2013-09-29 16:47:26, Info                  CSI    0000017f [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:47:26, Info                  CSI    00000180 [SR] Beginning Verify and Repair transaction
2013-09-29 16:47:27, Info                  CSI    00000182 [SR] Verify complete
2013-09-29 16:47:27, Info                  CSI    00000183 [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:47:27, Info                  CSI    00000184 [SR] Beginning Verify and Repair transaction
2013-09-29 16:47:31, Info                  CSI    00000188 [SR] Verify complete
2013-09-29 16:47:31, Info                  CSI    00000189 [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:47:31, Info                  CSI    0000018a [SR] Beginning Verify and Repair transaction
2013-09-29 16:47:33, Info                  CSI    000001ab [SR] Verify complete
2013-09-29 16:47:33, Info                  CSI    000001ac [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:47:33, Info                  CSI    000001ad [SR] Beginning Verify and Repair transaction
2013-09-29 16:47:37, Info                  CSI    000001af [SR] Verify complete
2013-09-29 16:47:38, Info                  CSI    000001b0 [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:47:38, Info                  CSI    000001b1 [SR] Beginning Verify and Repair transaction
2013-09-29 16:47:40, Info                  CSI    000001b5 [SR] Verify complete
2013-09-29 16:47:40, Info                  CSI    000001b6 [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:47:40, Info                  CSI    000001b7 [SR] Beginning Verify and Repair transaction
2013-09-29 16:47:41, Info                  CSI    000001b9 [SR] Cannot repair member file [l:20{10}]"artui3.h1s" of Microsoft-Windows-Help-Artui3.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2013-09-29 16:47:41, Info                  CSI    000001bb [SR] Cannot repair member file [l:20{10}]"artui3.h1s" of Microsoft-Windows-Help-Artui3.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2013-09-29 16:47:41, Info                  CSI    000001bc [SR] This component was referenced by [l:266{133}]"Microsoft-Windows-WindowsFoundation-LanguagePack-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.Windows Foundation Language Pack"
2013-09-29 16:47:41, Info                  CSI    000001bf [SR] Could not reproject corrupted file [ml:520{260},l:66{33}]"\??\C:\Windows\Help\Windows\en-US"\[l:20{10}]"artui3.h1s"; source file in store is also corrupted
2013-09-29 16:47:41, Info                  CSI    000001c1 [SR] Verify complete
2013-09-29 16:47:41, Info                  CSI    000001c2 [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:47:41, Info                  CSI    000001c3 [SR] Beginning Verify and Repair transaction
2013-09-29 16:47:41, Info                  CSI    000001c5 [SR] Verify complete
2013-09-29 16:47:42, Info                  CSI    000001c6 [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:47:42, Info                  CSI    000001c7 [SR] Beginning Verify and Repair transaction
2013-09-29 16:47:42, Info                  CSI    000001c9 [SR] Verify complete
2013-09-29 16:47:42, Info                  CSI    000001ca [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:47:42, Info                  CSI    000001cb [SR] Beginning Verify and Repair transaction
2013-09-29 16:49:01, Info                  CSI    000001de [SR] Verify complete
2013-09-29 16:49:01, Info                  CSI    000001df [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:49:01, Info                  CSI    000001e0 [SR] Beginning Verify and Repair transaction
2013-09-29 16:49:01, Info                  CSI    000001e2 [SR] Verify complete
2013-09-29 16:49:01, Info                  CSI    000001e3 [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:49:01, Info                  CSI    000001e4 [SR] Beginning Verify and Repair transaction
2013-09-29 16:49:13, Info                  CSI    000001e6 [SR] Verify complete
2013-09-29 16:49:13, Info                  CSI    000001e7 [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:49:13, Info                  CSI    000001e8 [SR] Beginning Verify and Repair transaction
2013-09-29 16:49:14, Info                  CSI    000001ea [SR] Verify complete
2013-09-29 16:49:14, Info                  CSI    000001eb [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:49:14, Info                  CSI    000001ec [SR] Beginning Verify and Repair transaction
2013-09-29 16:49:23, Info                  CSI    000001ef [SR] Verify complete
2013-09-29 16:49:23, Info                  CSI    000001f0 [SR] Verifying 100 (0x0000000000000064) components
2013-09-29 16:49:23, Info                  CSI    000001f1 [SR] Beginning Verify and Repair transaction


 



#7 bloopie

bloopie

    Bleepin' Sith Turner


  • Malware Response Instructor
  • 6,344 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New York
  • Local time:12:10 PM

Posted 30 September 2013 - 03:16 PM

Hello again,
 
Okay, let's run this script with Combofix:

Run a Combofix Script


1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy the text in the codebox below, then paste it into the empty notepad:
 

Registry::

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelTBRunOnce"=-

ClearJavaCache::

Save this as CFScript.txt, in the same location as ComboFix.exe


CFScriptB-4.gif

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

==========

In addition to the latest Combofix log, please let me know how the machine is running now!

bloopie



#8 taranicolex

taranicolex
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:10:10 AM

Posted 30 September 2013 - 04:32 PM

Here's the Combofix log. Also it said my anti virus was enabled and I looked and made sure and it was disabled. I had all shields stopped and firewall off. I was confused why it was saying it was on. My computer seems a lot better. My browser stopped responding at first and was kinda slow but now it seems fast and everything seems to be repsonding now but here's this.

 

ComboFix 13-09-30.02 - Tara 09/30/2013  13:44:06.3.4 - x64 NETWORK
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.1.1033.18.5996.5090 [GMT -7:00]
Running from: c:\users\Tara\Desktop\ComboFix.exe
Command switches used :: c:\users\Tara\Desktop\CFScript.txt
AV: avast! Internet Security *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
FW: avast! Internet Security *Enabled* {131692B0-0864-D491-4E21-3A3A1D8BBB47}
SP: avast! Internet Security *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Created a new restore point
.
.
(((((((((((((((((((((((((   Files Created from 2013-08-28 to 2013-09-30  )))))))))))))))))))))))))))))))
.
.
2013-09-30 21:17 . 2013-09-30 21:17    --------    d-----w-    c:\users\hedev\AppData\Local\temp
2013-09-30 21:17 . 2013-09-30 21:17    --------    d-----w-    c:\users\Default\AppData\Local\temp
2013-09-30 19:44 . 2013-09-30 19:44    --------    d-----w-    c:\windows\ERUNT
2013-09-30 17:48 . 2013-09-30 17:48    --------    d-----w-    c:\program files (x86)\ESET
2013-09-30 17:33 . 2013-09-30 17:33    --------    d-----w-    C:\FRST
2013-09-29 21:50 . 2013-09-29 21:53    --------    d-----w-    c:\users\Tara\AppData\Roaming\.minecraft
2013-09-29 21:46 . 2013-08-30 07:48    270824    ----a-w-    c:\windows\system32\drivers\aswNdis2.sys
2013-09-29 21:46 . 2013-08-30 07:48    22600    ----a-w-    c:\windows\system32\drivers\aswKbd.sys
2013-09-29 21:46 . 2013-08-30 07:48    131232    ----a-w-    c:\windows\system32\drivers\aswFW.sys
2013-09-29 21:46 . 2013-07-17 09:17    12368    ----a-w-    c:\windows\system32\drivers\aswNdis.sys
2013-09-29 21:23 . 2013-08-30 07:48    378944    ----a-w-    c:\windows\system32\drivers\aswSP.sys
2013-09-29 21:23 . 2013-08-30 07:48    33400    ----a-w-    c:\windows\system32\drivers\aswFsBlk.sys
2013-09-29 21:23 . 2013-08-30 07:48    72016    ----a-w-    c:\windows\system32\drivers\aswRdr2.sys
2013-09-29 21:23 . 2013-08-30 07:48    65336    ----a-w-    c:\windows\system32\drivers\aswRvrt.sys
2013-09-29 21:23 . 2013-08-30 07:48    64288    ----a-w-    c:\windows\system32\drivers\aswTdi.sys
2013-09-29 21:23 . 2013-08-30 07:48    204880    ----a-w-    c:\windows\system32\drivers\aswVmm.sys
2013-09-29 21:23 . 2013-08-30 07:48    1030952    ----a-w-    c:\windows\system32\drivers\aswSnx.sys
2013-09-29 21:23 . 2013-08-30 07:48    80816    ----a-w-    c:\windows\system32\drivers\aswMonFlt.sys
2013-09-29 21:23 . 2013-08-30 07:47    287840    ----a-w-    c:\windows\system32\aswBoot.exe
2013-09-29 21:22 . 2013-08-30 07:47    41664    ----a-w-    c:\windows\avastSS.scr
2013-09-29 17:05 . 2013-09-30 20:54    76232    ----a-w-    c:\programdata\Microsoft\Windows Defender\Definition Updates\{E8711F9B-1BB4-4DEC-8CDA-3F29DF9295CC}\offreg.dll
2013-09-29 04:00 . 2013-09-16 07:50    9694160    ----a-w-    c:\programdata\Microsoft\Windows Defender\Definition Updates\{E8711F9B-1BB4-4DEC-8CDA-3F29DF9295CC}\mpengine.dll
2013-09-28 04:12 . 2013-09-28 04:13    --------    d-----w-    c:\program files (x86)\Google
2013-09-28 04:12 . 2013-09-28 04:13    --------    d-----w-    c:\users\Tara\AppData\Local\Google
2013-09-27 17:02 . 2013-09-29 21:22    --------    d-----w-    c:\programdata\AVAST Software
2013-09-27 17:02 . 2013-09-29 21:22    --------    d-----w-    c:\program files\AVAST Software
2013-09-27 17:01 . 2013-09-27 17:01    --------    d-----w-    c:\program files\SafeSearch
2013-09-27 13:29 . 2013-09-30 19:43    --------    d-----w-    C:\AdwCleaner
2013-09-27 06:12 . 2013-09-27 06:12    --------    d-----w-    C:\TDSSKiller_Quarantine
2013-09-27 05:45 . 2013-09-27 06:21    --------    d-----w-    c:\programdata\Spybot - Search & Destroy
2013-09-26 12:34 . 2013-09-26 12:34    --------    d-----w-    c:\programdata\Malwarebytes
2013-09-24 02:49 . 2013-09-24 02:49    --------    d-----w-    c:\programdata\Oracle
2013-09-24 02:49 . 2013-09-24 02:49    96168    ----a-w-    c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-09-24 02:49 . 2013-09-24 02:49    --------    d-----w-    c:\program files (x86)\Java
2013-09-24 02:45 . 2013-09-24 02:45    --------    d-----w-    c:\program files (x86)\Common Files\Adobe
2013-09-24 02:36 . 2013-09-24 02:36    --------    d-----w-    c:\program files\Java
2013-09-23 03:02 . 2013-09-23 03:02    --------    d-----w-    c:\program files (x86)\THQ
2013-09-21 05:50 . 2013-09-24 11:04    --------    d-----w-    c:\program files (x86)\Diablo III
2013-09-17 08:48 . 2013-09-17 08:48    --------    d-----w-    c:\program files (x86)\Guitar Pro 5
2013-09-16 19:30 . 2013-09-16 19:30    4806016    ----a-w-    c:\program files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll
2013-09-16 19:30 . 2013-09-16 19:30    4806016    ----a-w-    c:\program files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll
2013-09-11 22:06 . 2013-08-05 02:25    155584    ----a-w-    c:\windows\system32\drivers\ataport.sys
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-09-26 12:52 . 2011-03-29 01:36    22240    ----a-w-    c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-09-24 03:23 . 2013-02-11 17:53    692616    ----a-w-    c:\windows\SysWow64\FlashPlayerApp.exe
2013-09-24 03:23 . 2011-10-31 07:59    71048    ----a-w-    c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-09-24 02:49 . 2013-02-11 17:43    790440    ----a-w-    c:\windows\SysWow64\deployJava1.dll
2013-09-24 02:49 . 2013-02-11 17:43    868264    ----a-w-    c:\windows\SysWow64\npDeployJava1.dll
2013-09-24 02:36 . 2013-02-11 19:22    973736    ----a-w-    c:\windows\system32\deployJava1.dll
2013-09-24 02:36 . 2013-02-11 19:22    1095080    ----a-w-    c:\windows\system32\npDeployJava1.dll
2013-09-12 22:23 . 2013-02-11 21:20    79143768    ----a-w-    c:\windows\system32\MRT.exe
2013-08-07 11:22 . 2010-11-21 03:27    278800    ------w-    c:\windows\system32\MpSigStub.exe
2013-08-02 01:48 . 2013-09-11 22:06    44032    ----a-w-    c:\windows\apppatch\acwow64.dll
2013-07-25 09:25 . 2013-08-14 08:44    1888768    ----a-w-    c:\windows\system32\WMVDECOD.DLL
2013-07-25 08:57 . 2013-08-14 08:44    1620992    ----a-w-    c:\windows\SysWow64\WMVDECOD.DLL
2013-07-19 01:58 . 2013-08-14 08:44    2048    ----a-w-    c:\windows\system32\tzres.dll
2013-07-19 01:41 . 2013-08-14 08:44    2048    ----a-w-    c:\windows\SysWow64\tzres.dll
2013-07-09 05:52 . 2013-08-14 08:45    224256    ----a-w-    c:\windows\system32\wintrust.dll
2013-07-09 05:51 . 2013-08-14 08:45    1217024    ----a-w-    c:\windows\system32\rpcrt4.dll
2013-07-09 05:46 . 2013-08-14 08:45    1472512    ----a-w-    c:\windows\system32\crypt32.dll
2013-07-09 05:46 . 2013-08-14 08:45    184320    ----a-w-    c:\windows\system32\cryptsvc.dll
2013-07-09 05:46 . 2013-08-14 08:45    139776    ----a-w-    c:\windows\system32\cryptnet.dll
2013-07-09 04:52 . 2013-08-14 08:45    663552    ----a-w-    c:\windows\SysWow64\rpcrt4.dll
2013-07-09 04:52 . 2013-08-14 08:45    175104    ----a-w-    c:\windows\SysWow64\wintrust.dll
2013-07-09 04:46 . 2013-08-14 08:45    1166848    ----a-w-    c:\windows\SysWow64\crypt32.dll
2013-07-09 04:46 . 2013-08-14 08:45    140288    ----a-w-    c:\windows\SysWow64\cryptsvc.dll
2013-07-09 04:46 . 2013-08-14 08:45    103936    ----a-w-    c:\windows\SysWow64\cryptnet.dll
2013-07-06 06:03 . 2013-08-14 08:44    1910208    ----a-w-    c:\windows\system32\drivers\tcpip.sys
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"BackupManagerTray"="c:\program files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe" [2011-04-24 297280]
"OOTag"="c:\program files (x86)\Acer\OOBEOffer\OOTag.exe" [2010-02-23 13856]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-10-13 343168]
"LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2011-07-01 1103440]
"NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-11-17 113288]
"Dolby Advanced Audio v2"="c:\dolby pcee4\pcee4.exe" [2011-06-01 506712]
"SuiteTray"="c:\program files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe" [2011-09-20 341360]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-09-05 958576]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-08-30 4858968]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"IsMyWinLockerReboot"="msiexec.exe" [2010-11-21 73216]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R0 aswRvrt;aswRvrt; [x]
R0 aswVmm;aswVmm; [x]
R1 aswSnx;aswSnx; [x]
R1 aswSP;aswSP; [x]
R1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDFilter.sys [x]
R1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDNServ.sys [x]
R1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDVDisk.sys [x]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
R2 aswFsBlk;aswFsBlk; [x]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
R2 avast! Firewall;avast! Firewall;c:\program files\AVAST Software\Avast\afwServ.exe;c:\program files\AVAST Software\Avast\afwServ.exe [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe;c:\program files (x86)\Launch Manager\dsiwmis.exe [x]
R2 ePowerSvc;ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [x]
R2 GREGService;GREGService;c:\program files (x86)\Acer\Registration\GREGsvc.exe;c:\program files (x86)\Acer\Registration\GREGsvc.exe [x]
R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
R2 Live Updater Service;Live Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe;c:\program files\Acer\Acer Updater\UpdaterService.exe [x]
R2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe;c:\program files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [x]
R2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys;c:\windows\SYSNATIVE\DRIVERS\TurboB.sys [x]
R2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [x]
R3 EgisTec Ticket Service;EgisTec Ticket Service;c:\program files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe;c:\program files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe [x]
R3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
R3 intelkmd;intelkmd;c:\windows\system32\DRIVERS\igdpmd64.sys;c:\windows\SYSNATIVE\DRIVERS\igdpmd64.sys [x]
R3 MotioninJoyXFilter;MotioninJoy Virtual Xinput device Filter Driver;c:\windows\system32\DRIVERS\MijXfilt.sys;c:\windows\SYSNATIVE\DRIVERS\MijXfilt.sys [x]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 TurboBoost;Intel® Turbo Boost Technology Monitor 2.0;c:\program files\Intel\TurboBoost\TurboBoost.exe;c:\program files\Intel\TurboBoost\TurboBoost.exe [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 aswNdis;avast! Firewall NDIS Filter Service;c:\windows\system32\DRIVERS\aswNdis.sys;c:\windows\SYSNATIVE\DRIVERS\aswNdis.sys [x]
S0 aswNdis2;avast! Firewall Core Firewall Service;c:\windows\system32\drivers\aswNdis2.sys;c:\windows\SYSNATIVE\drivers\aswNdis2.sys [x]
S1 aswFW;avast! TDI Firewall Driver;c:\windows\system32\drivers\aswFW.sys;c:\windows\SYSNATIVE\drivers\aswFW.sys [x]
S1 aswKbd;aswKbd; [x]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys;c:\windows\SYSNATIVE\DRIVERS\ETD.sys [x]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3hub.sys [x]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3xhc.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation    REG_MULTI_SZ       SSDPSRV SCardSvr TBS QWAVE wcncsvc
.
Contents of the 'Scheduled Tasks' folder
.
2013-09-29 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-02-11 03:23]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-08-30 07:47    133840    ----a-w-    c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-08-16 12673128]
"RtHDVBg_Dolby"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-08-16 2277480]
"Power Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2011-08-02 1831016]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-08-09 167704]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-08-09 392472]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-08-09 416024]
"Logitech Download Assistant"="c:\windows\System32\LogiLDA.dll" [2012-09-20 1832760]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm


mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Tara\AppData\Roaming\Mozilla\Firefox\Profiles\tgw2b36b.default\
FF - ExtSQL: 2013-09-23 20:03; {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}; c:\program files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF - ExtSQL: 2013-09-26 06:32; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\users\Tara\AppData\Roaming\Mozilla\Firefox\Profiles\tgw2b36b.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF - ExtSQL: 2013-09-29 14:23; wrc@avast.com; c:\program files\AVAST Software\Avast\WebRep\FF
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
BHO-{e27d5867-80de-4449-9c03-71707c0db05b} - (no file)
Toolbar-{fc0c0170-4eb0-430d-a7f3-939ee7ea1a25} - (no file)
HKLM-Run-ETDCtrl - c:\program files (x86)\Elantech\ETDCtrl.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_175_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_175_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_175_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_175_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
   00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2013-09-30  14:18:45
ComboFix-quarantined-files.txt  2013-09-30 21:18
ComboFix2.txt  2013-09-27 13:25
.
Pre-Run: 337,113,559,040 bytes free
Post-Run: 337,450,782,720 bytes free
.
- - End Of File - - 57A5C19CE1D4D039737E068AC3737F77
 



#9 taranicolex

taranicolex
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:10:10 AM

Posted 30 September 2013 - 04:59 PM

Well It seems everything is working now. Everythings responding now, I can right click without it freezing, I can type in my start menu. Seems really fast again and I'm not in safe mode. Hopefully it stays like this. I appreciate your help so much, you have no idea. I've spent hours trying to figure this out. Thank you so much.



#10 bloopie

bloopie

    Bleepin' Sith Turner


  • Malware Response Instructor
  • 6,344 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New York
  • Local time:12:10 PM

Posted 30 September 2013 - 05:16 PM

Hello again,

 

Excellent, glad to hear that! :) The help is my pleasure!
 
Okay, looking better! Now let's do a couple of more scans for leftovers:
 
Step :step1:

Please download Malwarebytes Anti-Malware mbamicontw5.gif and save it to your desktop.

  • Important!! When you save the mbam-setup file, rename it to something random (such as 123abc.exe) before beginning the download.

Malwarebytes may "make changes to your registry" as part of its disinfection routine. If using other security programs that detect registry changes (ie Spybot's Teatimer), they may interfere or alert you. Temporarily disable such programs or permit them to allow the changes.

  • Make sure you are connected to the Internet and double-click on the renamed file to install the application.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • Malwarebytes will automatically start and you will be asked to update the program before performing a scan.
  • If an update is found, the program will automatically update itself. Press the OK button and continue.
  • If you cannot update Malwarebytes or use the Internet to download any files to the infected computer, manually update the database by following the instructions in FAQ Section A: 4. Issues.
  • Under the Scanner tab, make sure the "Perform Quick Scan" option is selected.
  • Click on the Scan button.
  • When the scan is complete, click OK, then click the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked and then click Remove Selected.
  • When removal is completed, a log report will open in Notepad.
  • The log is automatically saved and can be viewed by clicking the Logs tab.
  • Copy and paste the contents of that report in your next reply. Be sure to post the complete log to include the top portion which shows the database version and your operating system.
  • Exit Malwarebytes when done.

Note: If Malwarebytes encounters a file that is difficult to remove, you will be asked to reboot your computer so it can proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot normally will prevent Malwarebytes from removing all the malware.

-- Some types of malware will target Malwarebytes and other security tools to keep them from running properly. If that's the case, use Malwarebytes Chameleon and follow the onscreen instructions. The Chameleon folder can be accessed by opening the program folder for Malwarebytes Anti-Malware (normally C:\Program Files\Malwarebytes' Anti-Malware or C:\Program Files (x86)\Malwarebytes' Anti-Malware).


==========

Step :step2:

I'd like us to scan your machine with ESET OnlineScan

Note: This scan may take some time to run!

  • Hold down Control and click on this link to open ESET OnlineScan in a new window.
  • Click the esetonlinebtn.png button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the esetsmartinstaller_enu.png
      icon on your desktop.
  • Check "YES, I accept the Terms of Use."
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Under scan settings, check "Scan Archives" and "Remove found threats"
  • Click Advanced settings and select the following:
    • Scan potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, click List Threats
  • Click Export, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Click the Back button.
  • Click the Finish button.

==========

Please post both requested logs in your next reply!

bloopie


Edited by bloopie, 30 September 2013 - 05:17 PM.


#11 taranicolex

taranicolex
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:10:10 AM

Posted 30 September 2013 - 05:50 PM

I tried to run malwarebytes and stopped responding and froze my comp and I had to force shut down my comp and now it's failing to start. I had to use my boyfriends computer to type this to you. I think its gone now



#12 taranicolex

taranicolex
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:10:10 AM

Posted 30 September 2013 - 06:05 PM

Yea it just wont turn on anymore.



#13 bloopie

bloopie

    Bleepin' Sith Turner


  • Malware Response Instructor
  • 6,344 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New York
  • Local time:12:10 PM

Posted 30 September 2013 - 06:14 PM

Hello again,

 

I was dreading that this issue may be hardware related. Since that looks like it is the case (I'm guessing a HDD failure), I'm going to have to turn you over to the main forums for continued help. Just let me know one thing:

 

Could you tell me exactly what happens when you try to turn the machine on?

 

Do you need to save anything from this hard drive?

 

bloopie



#14 taranicolex

taranicolex
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:10:10 AM

Posted 30 September 2013 - 06:31 PM

Windows failed to start. A recent hardware or software change might be the cause. 
 
What it says when I try to start.  It has an option to launch windows or has a startup repair. The repair option takes me to a grey screen and does nothing.
Also I would like to save some stuff on my pc if at all possible but i'm not sure how to go about doing that.


#15 bloopie

bloopie

    Bleepin' Sith Turner


  • Malware Response Instructor
  • 6,344 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New York
  • Local time:12:10 PM

Posted 30 September 2013 - 07:15 PM

Hello again,

Okay, what happens when you choose "launch Windows"?

==========

I'm going to suggest you post a new topic in the Windows 7 forum to continue with getting information off of this hard drive: http://www.bleepingcomputer.com/forums/f/167/windows-7/

Please include what we've done here (or maybe link them back to this topic), and let them know you'd like to either troubleshoot the HDD issue, and/or retrieve files from the HDD if it is indeed failing.

Let me know when you've created your new topic so that I can close this one!

Thank you,

bloopie




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users