Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

blank app pics, no internet connection, computer loads 'properly' to safemode


  • Please log in to reply
26 replies to this topic

#1 MsYvaine

MsYvaine

  • Members
  • 61 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:uk-london
  • Local time:06:16 PM

Posted 05 November 2013 - 12:48 PM

Hello guys, my heroes...!

 

Once again I'm turning to you, gurus...

My boyfriend's computer died last night, he discovered the abundance of torrents and here we go...trouble again.

The symptomps:

The computer would not load into normal mode, when it does, then it loads everything for the first time and then when the clock appears tehre is a "refreshin" moment and then all the apps go blank. Documents have the horizontal lines, apps are simply blank. Wherever I try to click anywhere the blue circle appears and the computer is working hard, but nothing happens.

In safe mode it sort of OK, but there is no network even in safe mode with network... I haven't run the diagnostics just yet, as it is not clear if I should do them also in safe mode.

What I've tried so far:

Run antivirus: Microsoft Essentials - no threats

Run MBAM - nothing

Antispyware - numerous threats, reboot, nothing has changed.

I have also run a Windows check and everything came back normal, no issues anywhere.

 

the reason why I think this is a malware is because there were signs before that something was wrong: when he downloaded a torrent he wanted to put the file on a stick, first the copy process stopped, then TC did not respond to anything, then nothing responded, but the mouse was moving, finally the mouse got stuck as well.

The fan was around 90%.

This happened 3 times, for the first 2 times the computer rebooted into normal win mode, then he tried to delete the movie, started TC and it took a good 2-3 times (reboot) to be able to delete the file. Once the file that he wanted to put on the stick was deleted it was back to normal with the computer.

Except for the last time, where we are now. Eventhough the file was deleted in safe mode, the computer would not start-up properly.

Edit: OS Win 7 Ultimate 32bit(I think)

 

Here we are now and I am once again asking you guys to please help me!

What's next?

Thanks a lot in advance.


Edited by MsYvaine, 05 November 2013 - 12:50 PM.


BC AdBot (Login to Remove)

 


#2 HelpBot

HelpBot

    Bleepin' Binary Bot


  • Bots
  • 9,630 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:16 PM

Posted 10 November 2013 - 12:50 PM

Hello and welcome to Bleeping Computer!

I am HelpBot: an automated program designed to help the Bleeping Computer Staff better assist you! This message contains very important information, so please read through all of it before doing anything.

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

To help Bleeping Computer better assist you please perform the following steps:

***************************************************

step1.gif In order to continue receiving help at BleepingComputer.com, YOU MUST tell me if you still need help or if your issue has already been resolved on your own or through another resource! To tell me this, please click on the following link and follow the instructions there.

CLICK THIS LINK >>> http://www.bleepingcomputer.com/logreply/513122 <<< CLICK THIS LINK



If you no longer need help, then all you needed to do was the previous instructions of telling me so. You can skip the rest of this post. If you do need help please continue with Step 2 below.

***************************************************

step2.gifIf you still need help, I would like you to post a Reply to this topic (click the "Add Reply" button in the lower right hand of this page). In that reply, please include the following information:

  • If you have not done so already, include a clear description of the problems you're having, along with any steps you may have performed so far.
  • A new DDS log. For your convenience, you will find the instructions for generating these logs repeated at the bottom of this post.
    • Please do this even if you have previously posted logs for us.
    • If you were unable to produce the logs originally please try once more.
    • If you are unable to create a log please provide detailed information about your installed Windows Operating System including the Version, Edition and if it is a 32bit or a 64bit system.
    • If you are unsure about any of these characteristics just post what you can and we will guide you.
  • Please tell us if you have your original Windows CD/DVD available.
  • Upon completing the above steps and posting a reply, another staff member will review your topic and do their best to resolve your issues.

Thank you for your patience, and again sorry for the delay.

***************************************************

We need to see some information about what is happening in your machine. Please perform the following scan again:

  • Download DDS by sUBs from the following link if you no longer have it available and save it to your destop.

    DDS.com Download Link
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control can be found HERE.

As I am just a silly little program running on the BleepingComputer.com servers, please do not send me private messages as I do not know how to read and reply to them! Thanks!

#3 MsYvaine

MsYvaine
  • Topic Starter

  • Members
  • 61 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:uk-london
  • Local time:06:16 PM

Posted 11 November 2013 - 06:05 AM

The problem hasn't been solved and here are the details:
 
My boyfriend's laptop stopped working after he used a stick on the computer for the third time, he also uses utorrent.
The symptomphs:
the computer loads normally, until the clock appears when the app pictures reload and apart from some random ones they stay blank and the computer freezes completely. No internet connection.
It loads into safe mode with networking and with network for the last 2-3 times (I don't know waht happened as I didn't do anything).
I run the followings:
MBAM - nothing
ADwCleaner - the log shows up when the computer loads into normal mode, but freezes, anyway, I could only get these info out of the log: Conduit, pricegong and smartbar are in the system. 
Full windows scan that came back normal.
Microsoft Essentials full scan - normal.
Antispyware - numerous threats found, reboot, nothing change in the state of the computer.
All of them were performed in safe mode.
 
Before this one last breakdown, he had experienced 2 similar occassions. He plugged in the stick and it froze, he had to force the shut down, but deleting the file from TC solved the problem (all of them are torrent downloaded files...)
 
Now I could run DSS, before I couldn't download it and when plugging the stick in, it didn't realised it.
So here are the results:
 
 
 
 
DDS (Ver_2012-11-20.01) - NTFS_AMD64 NETWORK
Internet Explorer: 10.0.9200.16720
Run by Babyke at 10:33:42 on 2013-11-11
Microsoft Windows 7 Ultimate   6.1.7601.1.1250.36.1038.18.1787.1184 [GMT 0:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Enabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\Explorer.EXE
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Windows\system32\ctfmon.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\Microsoft Security Client\MpCmdRun.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com
dURLSearchHooks: {A3BC75A2-1F87-4686-AA43-5347D756017C} - <orphaned>
BHO: DivX Plus Web Player HTML5 <video>: {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
BHO: HP Network Check Helper: {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
uRun: [EPLTarget\P0000000000000000] C:\Windows\System32\spool\DRIVERS\x64\3\E_IATIHLE.EXE /EPT "EPLTarget\P0000000000000000" /M "Epson Stylus SX235"
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
uRun: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRun: [Google Update] "C:\Users\Babyke\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [uTorrent] "C:\Users\Babyke\AppData\Roaming\uTorrent\uTorrent.exe"  /MINIMIZED
uRun: [SearchProtection] "C:\Users\Babyke\AppData\Roaming\Search Protection\SearchProtection.EXE" /autostart
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
uRunOnce: [Report] C:\AdwCleaner[S3].txt
mRun: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
StartupFolder: C:\Users\Babyke\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\Babyke\AppData\Roaming\Dropbox\bin\Dropbox.exe
uPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: NoDrives = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
IE: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files (x86)\PokerStars\PokerStarsUpdate.exe
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: NameServer = 192.168.0.1
TCP: Interfaces\{421A97B7-F8C0-45E5-B98E-A768BDB54ECB} : DHCPNameServer = 192.168.0.1
TCP: Interfaces\{421A97B7-F8C0-45E5-B98E-A768BDB54ECB}\07F607C616271333 : DHCPNameServer = 194.168.4.100 194.168.8.100
TCP: Interfaces\{421A97B7-F8C0-45E5-B98E-A768BDB54ECB}\14B4F4350275966696 : DHCPNameServer = 192.168.2.1
TCP: Interfaces\{421A97B7-F8C0-45E5-B98E-A768BDB54ECB}\14B6F63775966696 : DHCPNameServer = 194.168.4.100 194.168.8.100
TCP: Interfaces\{421A97B7-F8C0-45E5-B98E-A768BDB54ECB}\35B4957363636303 : DHCPNameServer = 192.168.0.1
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: Easy Photo Print: {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll
x64-TB: Easy Photo Print: {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
x64-Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Babyke\AppData\Roaming\Mozilla\Firefox\Profiles\rijjfjwg.default-1373065617686\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://uk.search.yahoo.com?type=714647&fr=spigot-yhp-ff
FF - prefs.js: keyword.URL - hxxp://uk.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=714647&p=
FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
FF - plugin: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrlui.dll
FF - plugin: C:\Users\Babyke\AppData\Local\Google\Update\1.3.21.165\npGoogleUpdate3.dll
FF - plugin: C:\Users\Babyke\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
FF - plugin: C:\Users\Babyke\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: C:\Users\Babyke\AppData\Roaming\Mozilla\plugins\npo1d.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll
.
============= SERVICES / DRIVERS ===============
.
R0 amd_sata;amd_sata;C:\Windows\System32\drivers\amd_sata.sys [2010-5-14 73856]
R0 amd_xata;amd_xata;C:\Windows\System32\drivers\amd_xata.sys [2010-5-14 28800]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2013-5-23 143120]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2013-5-25 347680]
R3 usbfilter;AMD USB Filter Driver;C:\Windows\System32\drivers\usbfilter.sys [2012-12-26 38528]
S0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2013-6-18 247216]
S1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
S1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
S2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-5-14 759048]
S2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2010-9-29 203264]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe [2012-9-27 86528]
S2 HTCMonitorService;HTCMonitorService;C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe [2013-1-29 87368]
S2 PassThru Service;Internet Pass-Through Service;C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [2012-12-7 167424]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-9-5 171680]
S3 dmvsc;dmvsc;C:\Windows\System32\drivers\dmvsc.sys [2011-4-12 71168]
S3 HTCAND64;HTC Device Driver;C:\Windows\System32\drivers\ANDROIDUSB.sys [2013-6-12 33736]
S3 htcnprot;HTC NDIS Protocol Driver;C:\Windows\System32\drivers\htcnprot.sys [2012-12-7 36928]
S3 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2013-1-20 139616]
S3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2013-8-12 366600]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2010-11-21 20992]
S3 Sony PC Companion;Sony PC Companion;C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe [2013-1-3 155824]
S3 Synth3dVsc;Synth3dVsc;C:\Windows\System32\drivers\Synth3dVsc.sys [2011-4-12 88960]
S3 terminpt;Microsoft Remote Desktop Input Driver;C:\Windows\System32\drivers\terminpt.sys [2011-4-12 34816]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 tsusbhub;tsusbhub;C:\Windows\System32\drivers\tsusbhub.sys [2011-4-12 117248]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-9-28 53760]
S3 WatAdminSvc;Windows aktiválási technológiák szolgáltatás;C:\Windows\System32\Wat\WatAdminSvc.exe [2013-3-10 1255736]
.
=============== Created Last 30 ================
.
2013-11-11 10:32:24 10280728 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{19C5E894-6C1F-476A-9A5D-309343EE39A1}\mpengine.dll
2013-11-04 17:11:17 10280728 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-10-30 11:16:09 -------- d-----w- C:\Users\Babyke\AppData\Roaming\Zotero
2013-10-30 11:16:09 -------- d-----w- C:\Users\Babyke\AppData\Local\Zotero
2013-10-30 11:15:56 -------- d-----w- C:\Program Files (x86)\Zotero Standalone
2013-10-18 02:31:56 965000 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{403E4B88-D8DF-4336-85AA-368F837A0728}\gapaengine.dll
.
==================== Find3M  ====================
.
2013-10-09 00:36:31 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-10-09 00:36:31 692616 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-09-22 23:28:06 1767936 ----a-w- C:\Windows\SysWow64\wininet.dll
2013-09-22 23:27:49 2876928 ----a-w- C:\Windows\SysWow64\jscript9.dll
2013-09-22 23:27:48 61440 ----a-w- C:\Windows\SysWow64\iesetup.dll
2013-09-22 23:27:48 109056 ----a-w- C:\Windows\SysWow64\iesysprep.dll
2013-09-22 22:55:10 2241024 ----a-w- C:\Windows\System32\wininet.dll
2013-09-22 22:54:51 3959296 ----a-w- C:\Windows\System32\jscript9.dll
2013-09-22 22:54:50 67072 ----a-w- C:\Windows\System32\iesetup.dll
2013-09-22 22:54:50 136704 ----a-w- C:\Windows\System32\iesysprep.dll
2013-09-21 03:38:39 2706432 ----a-w- C:\Windows\System32\mshtml.tlb
2013-09-21 03:30:24 2706432 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2013-09-21 02:48:36 89600 ----a-w- C:\Windows\System32\RegisterIEPKEYs.exe
2013-09-21 02:39:47 71680 ----a-w- C:\Windows\SysWow64\RegisterIEPKEYs.exe
2013-08-28 01:21:06 3155968 ----a-w- C:\Windows\System32\win32k.sys
.
============= FINISH: 10:34:24,88 ===============
 
 
There are some lines with hungarian words, please let me know if you need translation, but as i saw them, most of them have the smae roots as the english equivalent.
 
Thanks a lot!


#4 nasdaq

nasdaq

  • Malware Response Team
  • 19,049 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:01:16 PM

Posted 11 November 2013 - 10:45 AM

Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

--RogueKiller--
  • Download & SAVE to your Desktop RogueKiller for 32bit or Roguekiller for 64bit
  • Quit all programs that you may have started.
  • Please disconnect any USB or external drives from the computer before you run this scan!
  • For Vista or Windows 7, right-click and select "Run as Administrator to start"
  • For Windows XP, double-click to start.
  • Wait until Prescan has finished ...
  • Then Click on "Scan" button
  • Wait until the Status box shows "Scan Finished"
  • click on "delete"
  • Wait until the Status box shows "Deleting Finished"
  • Click on "Report" and copy/paste the content of the Notepad into your next reply.
  • The log should be found in RKreport[1].txt on your Desktop
  • Exit/Close RogueKiller+
===

Get the latest version of AdwCleaner.

Please download AdwCleaner by Xplode onto your Desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click the Scan button and wait for the process to complete.
  • Click the Report button and the report will open in Notepad.
IMPORTANT
  • If you click the Clean button all items listed in the report will be removed.
If you find some false positive items or programs that you wish to keep, Close the AdwCleaner windows.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click the Scan button and wait for the process to complete.
  • Check off the element(s) you wish to keep.
  • Click on the Clean button follow the prompts.
  • A log file will automatically open after the scan has finished.
  • Please post the content of that log file with your next answer.
  • You can find the log file at C:\AdwCleaner[Sn].txt (n is a number).
thisisujrt.gif Please download
Junkware Removal Tool to your Desktop.
  • Please close your security software to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista or 7, right-mouse click it and select Run as administrator.
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete, depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your Desktop and will automatically open.
  • Please post the contents of JRT.txt into your reply.
===

Please download ComboFix from any of the links below, and save it to your desktop. For information regarding this download, please visit this web page: Turorial
Link 1
Link 2

IMPORTANT !!! Save ComboFix.exe to your Desktop

1. Close any open browsers.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
3. Do not install any other programs until this if fixed.


How to : Disable Anti-virus and Firewall...
http://www.bleepingcomputer.com/forums/topic114351.html

Double click on ComboFix.exe and follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt
Note: Do not mouse click ComboFix's window while it's running. That may cause it to stall

Note: If you have difficulty properly disabling your protective programs, refer to this link --> http://www.bleepingcomputer.com/forums/topic114351.html

Note: If after running ComboFix you get this error message "Illegal operation attempted on a registry key that has been marked for deletion." when attempting to run a program all you need to do is restart the computer to reset the registry.
===

Please paste the logs in your next reply DO NOT ATTACH THEM.
Let me know what problem persists.

#5 MsYvaine

MsYvaine
  • Topic Starter

  • Members
  • 61 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:uk-london
  • Local time:06:16 PM

Posted 11 November 2013 - 04:09 PM

Hello nasdaq,
 
Thanks for your quick reply.
Here are the logs which I could create as unfortunatelly the computer freezes at some point.
 
RogueKiller V8.7.7 _x64_ [Nov 11 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Feedback : http://www.adlice.com/forum/
Website : http://www.adlice.com/softwares/roguekiller/
Blog : http://tigzyrk.blogspot.com/
 
Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Safe mode with network support
User : Babyke [Admin rights]
Mode : Remove -- Date : 11/11/2013 20:43:44
| ARK || FAK || MBR |
 
¤¤¤ Bad processes : 0 ¤¤¤
 
¤¤¤ Registry Entries : 6 ¤¤¤
[RUN][SUSP PATH] HKCU\[...]\Run : SearchProtection ("C:\Users\Babyke\AppData\Roaming\Search Protection\SearchProtection.EXE" /autostart [x]) -> DELETED
[RUN][SUSP PATH] HKUS\S-1-5-21-231758204-126888405-1835614825-1000\[...]\Run : SearchProtection ("C:\Users\Babyke\AppData\Roaming\Search Protection\SearchProtection.EXE" /autostart [x]) -> [0x2] A rendszer nem találja a megadott fájlt. 
[HJ POL][PUM] HKLM\[...]\System : DisableRegistryTools (0) -> DELETED
[HJ POL][PUM] HKLM\[...]\Wow6432Node\[...]\System : DisableRegistryTools (0) -> [0x2] A rendszer nem találja a megadott fájlt. 
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
 
¤¤¤ Scheduled tasks : 0 ¤¤¤
 
¤¤¤ Startup Entries : 0 ¤¤¤
 
¤¤¤ Web browsers : 0 ¤¤¤
 
¤¤¤ Particular Files / Folders: ¤¤¤
 
¤¤¤ Driver : [NOT LOADED 0x0] ¤¤¤
 
¤¤¤ External Hives: ¤¤¤
 
¤¤¤ Infection :  ¤¤¤
 
¤¤¤ HOSTS File: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts
 
 
127.0.0.1       localhost
 
 
¤¤¤ MBR Check: ¤¤¤
 
+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) Hitachi HTS545025B9A300 SATA Disk Device +++++
--- User ---
[MBR] 98c4e83f227507a19a91f4c0ff0d86dc
[BSP] a9a5d0325709daf2d2ccedd3fbc5e5ff : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 50374 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 103372800 | Size: 187998 Mo
User = LL1 ... OK!
User != LL2 ... KO!
--- LL2 ---
[MBR] b2d386f3cf327c7fc7922a5606ec7ffd
[BSP] 972aa1b1d57184f1211bc8c1c82a2073 : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 199 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 409600 | Size: 221388 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 453812224 | Size: 16783 Mo
3 - [XXXXXX] FAT32-LBA (0x0c) [VISIBLE] Offset (sectors): 488183808 | Size: 103 Mo
 
Finished : << RKreport[0]_D_11112013_204344.txt >>
RKreport[0]_S_11112013_204257.txt
 
ADWCLEANER:
 
# AdwCleaner v3.012 - Report created 11/11/2013 at 20:49:10
# Updated 11/11/2013 by Xplode
# Operating System : Windows 7 Ultimate Service Pack 1 (64 bits)
# Username : Babyke - BABYKE-PC
# Running from : C:\Users\Babyke\Desktop\adwcleaner (1).exe
# Option : Scan
 
***** [ Services ] *****
 
 
***** [ Files / Folders ] *****
 
Folder Found : C:\Users\Babyke\AppData\Local\Google\Chrome\User Data\Default\Extensions\cflheckfmhopnialghigdlggahiomebp
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
Key Found : HKCU\Software\Google\Chrome\Extensions\cflheckfmhopnialghigdlggahiomebp
Key Found : HKCU\Software\powerpack
Key Found : [x64] HKCU\Software\powerpack
Key Found : HKLM\Software\Classes\Installer\Features\9EC6D81181F59F2459A84176A626F9ED
Key Found : HKLM\Software\Classes\Installer\Products\9EC6D81181F59F2459A84176A626F9ED
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{3E288F79-03E4-4983-A48E-0D879B51FF19}
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\cflheckfmhopnialghigdlggahiomebp
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_skype_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_skype_RASMANCS
 
***** [ Browsers ] *****
 
-\\ Internet Explorer v10.0.9200.16720
 
 
-\\ Mozilla Firefox v24.0 (en-US)
 
[ File : C:\Users\Babyke\AppData\Roaming\Mozilla\Firefox\Profiles\rijjfjwg.default-1373065617686\prefs.js ]
 
 
-\\ Google Chrome v30.0.1599.101
 
[ File : C:\Users\Babyke\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
 
*************************
 
AdwCleaner[R0].txt - [1683 octets] - [11/11/2013 20:49:10]
 
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [1743 octets] ##########
 
 
The laslt log is the first log of adwcleaner. It wants to reboot and would reboot to normal mode where it still freezes. I could make a picture by a phone of the first part of the final adwcleaner log. I will upload the picture from my tablet to be sure it is not infected.
I didn't go on from here as I don't know if I should. 
 
On the desktop when it loaded into normal mode there was a bit of change: most of the icons loaded except those that are internet related, eg.: mozilla, ie, youtube downloader
 
Let me know how to proceed.

EDIT: the pic was made by a phone and uploaded from a tablet...
 
Thanks

Edited by MsYvaine, 11 November 2013 - 04:16 PM.


#6 nasdaq

nasdaq

  • Malware Response Team
  • 19,049 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:01:16 PM

Posted 12 November 2013 - 09:36 AM

Download correct tool for your operating system.
Farbar Recovery Scan Tool (64 bit)
Farbar Recovery Scan Tool (32 bit)
and save it to a folder on your computer's Desktop.
Double-click to run it. When the tool opens click Yes to disclaimer.
Press Scan button.
It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
===

#7 MsYvaine

MsYvaine
  • Topic Starter

  • Members
  • 61 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:uk-london
  • Local time:06:16 PM

Posted 12 November 2013 - 04:29 PM

Hi,

 

I've got mixed results...

Here is the addition of the farbar utility and that's how far Ive got till now.

It froze during scanning and says getting application errors: 18627, it has been scanning for 20-25 mins and shows this...I cant close it, so ill force the laptop to stop and will try to run farbar again later.

 

the log:

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10-11-2013 01
Ran by Babyke at 2013-11-12 21:00:55
Running from C:\Users\Babyke\Desktop\farbar
Boot Mode: Safe Mode (with Networking)
==========================================================
 
 
==================== Security Center ========================
 
AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
 
==================== Installed Programs ======================
 
µTorrent (HKCU Version: 3.3.2.30180)
A Microsoft .NET-keretrendszer 4-es verziójához tartozó ügyfélprofil HUN nyelvi csomagja (Version: 4.0.30319)
ABBYY FineReader 9.0 Sprint (x32 Version: 9.01.513.58212)
Adobe AIR (x32 Version: 3.5.0.1060)
Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.117)
Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117)
Adobe Reader XI (11.0.05) (x32 Version: 11.0.05)
Apple Application Support (x32 Version: 2.3.2)
Apple Mobile Device Support (Version: 6.0.1.3)
Apple Software Update (x32 Version: 2.1.3.127)
ATI Catalyst Install Manager (Version: 3.0.790.0)
BCDC++ 0.790bx (x32 Version: 0.790bx)
Bonjour (Version: 3.0.0.10)
Broadcom 802.11 Wireless LAN Adapter (Version: 5.60.350.6)
Catalyst Control Center - Branding (x32 Version: 1.00.0000)
Catalyst Control Center Graphics Previews Common (x32 Version: 2010.0929.2212.37971)
Catalyst Control Center Graphics Previews Vista (x32 Version: 2010.0929.2212.37971)
Catalyst Control Center InstallProxy (x32 Version: 2010.0929.2212.37971)
Catalyst Control Center Localization All (x32 Version: 2010.0929.2212.37971)
CCC Help Chinese Standard (x32 Version: 2010.0929.2211.37971)
CCC Help Chinese Traditional (x32 Version: 2010.0929.2211.37971)
CCC Help Czech (x32 Version: 2010.0929.2211.37971)
CCC Help Danish (x32 Version: 2010.0929.2211.37971)
CCC Help Dutch (x32 Version: 2010.0929.2211.37971)
CCC Help English (x32 Version: 2010.0929.2211.37971)
CCC Help Finnish (x32 Version: 2010.0929.2211.37971)
CCC Help French (x32 Version: 2010.0929.2211.37971)
CCC Help German (x32 Version: 2010.0929.2211.37971)
CCC Help Greek (x32 Version: 2010.0929.2211.37971)
CCC Help Hungarian (x32 Version: 2010.0929.2211.37971)
CCC Help Italian (x32 Version: 2010.0929.2211.37971)
CCC Help Japanese (x32 Version: 2010.0929.2211.37971)
CCC Help Korean (x32 Version: 2010.0929.2211.37971)
CCC Help Norwegian (x32 Version: 2010.0929.2211.37971)
CCC Help Polish (x32 Version: 2010.0929.2211.37971)
CCC Help Portuguese (x32 Version: 2010.0929.2211.37971)
CCC Help Russian (x32 Version: 2010.0929.2211.37971)
CCC Help Spanish (x32 Version: 2010.0929.2211.37971)
CCC Help Swedish (x32 Version: 2010.0929.2211.37971)
CCC Help Thai (x32 Version: 2010.0929.2211.37971)
CCC Help Turkish (x32 Version: 2010.0929.2211.37971)
ccc-core-static (x32 Version: 2010.0929.2212.37971)
ccc-utility64 (Version: 2010.0929.2212.37971)
CCleaner (Version: 4.05)
DivX Setup (x32 Version: 2.6.1.22)
Dropbox (HKCU Version: 2.0.27)
Epson Easy Photo Print 2 (x32 Version: 2.2.4.0)
Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser) (x32 Version: 1.00.0000)
Epson Event Manager (x32 Version: 2.50.0000)
EPSON Scan (x32)
EPSON SX235 Series Printer Uninstall
EpsonNet Print (x32 Version: 2.5.00)
ESET Online Scanner v3 (x32)
Facebook Video Calling 1.2.0.287 (x32 Version: 1.2.287)
FLV Media Player version 1.3 (x32 Version: 1.3)
Full Tilt Poker (x32 Version: 4.63.10.WIN.FullTilt.COM)
Google Chrome (x32 Version: 30.0.1599.101)
Google Earth (x32 Version: 7.1.1.1888)
Google Talk Plugin (x32 Version: 4.8.2.15856)
Google Update Helper (x32 Version: 1.3.21.165)
Hálózati útmutató EPSON SX235 Series (x32)
Használati útmutató EPSON SX235 Series (x32)
Hewlett-Packard ACLM.NET v1.2.1.1 (x32 Version: 1.00.0000)
HP Product Detection (x32 Version: 11.14.0006)
HP Support Assistant (x32 Version: 7.0.39.15)
HTC Driver Installer (x32 Version: 4.2.0.001)
HTC Sync Manager (x32 Version: 2.0.60.0)
IPTInstaller (x32 Version: 4.0.8)
iTunes (Version: 11.0.1.12)
Malwarebytes Anti-Malware 1.75.0.1300 verzió (x32 Version: 1.75.0.1300)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile HUN Language Pack (Version: 4.0.30319)
Microsoft Security Client (Version: 4.3.0219.0)
Microsoft Security Essentials (Version: 4.3.219.0)
Microsoft Silverlight (Version: 5.1.20913.0)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 (x32 Version: 9.0.30411)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Mozilla Firefox 24.0 (x86 en-US) (x32 Version: 24.0)
Mozilla Maintenance Service (x32 Version: 24.0)
MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0)
PokerStars (x32)
Ralink RT2860 Wireless LAN Card (x32 Version: 3.1.13.0)
Realtek Ethernet Controller Driver For Windows 7 (x32 Version: 7.18.322.2010)
Search Protection (HKCU Version: 7.5.0.1)
Skype™ 6.9 (x32 Version: 6.9.106)
Sony Ericsson Update Engine (x32 Version: 2.13.6.201305161305)
Sony PC Companion 2.10.165 (x32 Version: 2.10.165)
SUPERAntiSpyware (Version: 5.6.1032)
Synaptics Pointing Device Driver (Version: 15.1.6.64)
Total Commander Ultima Prime 4.1.0.0 (x32 Version: 4.1.0.0)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0)
Visual Studio 2008 x64 Redistributables (x32 Version: 10.0.0.2)
VLC media player 2.0.0 (x32 Version: 2.0.0)
Windows Driver Package - Broadcom Bluetooth  (06/15/2009 6.2.0.9000) (Version: 06/15/2009 6.2.0.9000)
Windows Driver Package - Broadcom Bluetooth  (07/30/2009 6.2.0.9405) (Version: 07/30/2009 6.2.0.9405)
Windows Driver Package - Broadcom HIDClass  (07/28/2009 6.2.0.9800) (Version: 07/28/2009 6.2.0.9800)
WinRAR archiváló (x32)
YTD Video Downloader 3.9.6 (x32 Version: 3.9.6)
Zotero Standalone 4.0.11 (x86 en-US) (x32 Version: 4.0.11)
 
==================== Restore Points  =========================
 
 
==================== Hosts content: ==========================
 
2009-07-14 02:34 - 2013-07-03 18:28 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost
 
==================== Scheduled Tasks (whitelisted) =============
 
Task: {130765A6-05C1-40EA-A112-C023950C83DB} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis Install => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-27] (Hewlett-Packard Company)
Task: {309D8FBC-7842-47B7-888D-1E91D1334D64} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-12-27] (Google Inc.)
Task: {60BBF0D9-0A9F-4BE8-B099-68C856024193} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-08-21] (Piriform Ltd)
Task: {7BA1B922-0C5F-4621-A9D4-62825D069990} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-27] (Hewlett-Packard Company)
Task: {9ACF9285-F329-4470-B849-5C053149FE18} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-27] (Hewlett-Packard Company)
Task: {A4988E29-760F-43E0-9F0C-A9975BF2E282} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {B937FB6B-0C31-4033-BBF7-29F2E6378202} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-12-27] (Google Inc.)
Task: {F0657678-0DF2-46B8-B316-1D2ACA9A68CD} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-09] (Adobe Systems Incorporated)
Task: {F54F9CF0-C2CC-42E3-B14D-A4709AC7A1A4} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-231758204-126888405-1835614825-1000Core => C:\Users\Babyke\AppData\Local\Google\Update\GoogleUpdate.exe [2013-02-16] (Google Inc.)
Task: {F8C53301-6D09-42A4-A87F-A472D939E7CD} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-231758204-126888405-1835614825-1000UA => C:\Users\Babyke\AppData\Local\Google\Update\GoogleUpdate.exe [2013-02-16] (Google Inc.)
Task: {F9119E75-ED63-4CDB-8803-D479B14186F2} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2013-04-01] (Hewlett-Packard Company)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-231758204-126888405-1835614825-1000Core.job => C:\Users\Babyke\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-231758204-126888405-1835614825-1000UA.job => C:\Users\Babyke\AppData\Local\Google\Update\GoogleUpdate.exe
 
==================== Loaded Modules (whitelisted) =============
 
2012-12-26 17:13 - 2010-03-15 11:28 - 00052224 _____ () C:\Program Files (x86)\WinRAR\rarext64.dll
2013-10-17 00:22 - 2013-10-09 00:02 - 04055504 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\pdf.dll
2013-10-17 00:22 - 2013-10-09 00:02 - 00415184 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\ppGoogleNaClPluginChrome.dll
2013-10-17 00:22 - 2013-10-09 00:01 - 01604560 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\ffmpegsumo.dll
2013-11-11 10:29 - 2013-11-11 10:29 - 04591616 _____ () C:\Users\Babyke\AppData\Local\Google\Chrome\User Data\SwiftShader\1.0.5.0\libglesv2.dll
2013-11-11 10:29 - 2013-11-11 10:29 - 00112128 _____ () C:\Users\Babyke\AppData\Local\Google\Chrome\User Data\SwiftShader\1.0.5.0\libegl.dll
 
==================== Alternate Data Streams (whitelisted) =========
 
 
==================== Safe Mode (whitelisted) ===================
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="2"
 
==================== Faulty Device Manager Devices =============
 
Name: Security Processor Loader Driver
Description: Security Processor Loader Driver
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer: 
Service: spldr
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (11/12/2013 08:56:12 PM) (Source: SideBySide) (User: )
Description: Az aktiválási környezet létrehozása C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1 esetében nem sikerült. Hiba található a(z) C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2 jegyzék- vagy házirendfájl C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. sorában.
Az alkalmazás által kért összetevő-verzió ütközik egy másik, már aktív összetevő-verzióval.
Az ütköző összetevők:
1. összetevő: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
2. összetevő: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
 
Error: (11/12/2013 08:56:12 PM) (Source: SideBySide) (User: )
Description: Az aktiválási környezet létrehozása C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1 esetében nem sikerült. Hiba található a(z) C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2 jegyzék- vagy házirendfájl C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. sorában.
Az alkalmazás által kért összetevő-verzió ütközik egy másik, már aktív összetevő-verzióval.
Az ütköző összetevők:
1. összetevő: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
2. összetevő: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
 
Error: (11/12/2013 08:52:21 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


#8 nasdaq

nasdaq

  • Malware Response Team
  • 19,049 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:01:16 PM

Posted 13 November 2013 - 07:56 AM



Following steps involve registry editing. Please create new restore point before proceeding!!!
How to:
XP - http://support.microsoft.com/kb/948247
Vista and Seven - http://windows.microsoft.com/en-gb/windows7/create-a-restore-point
Windows 8 - http://www.eightforums.com/tutorials/4690-restore-point-create-windows-8-a.html

Download this program to your desktop.
Tweaking.com - Windows Repair 1.9.16
http://www.bleepingcomputer.com/download/windows-repair-all-in-one-portable/


Extract and launch the Repair_Windows.exe file

Click on Start repairs tab-click on Start

check mark following options alone

Reset Registry Permissions
Reset File Permissions
Register System Files
Repair WMI
Repair Windows Firewall
Repair Internet Explorer
Repair MDAC & MS Jet
Repair Hosts File
Remove Policies Set By Infections
Repair Icons
Repair Winsock & DNS Cache
Remove Temp Files
Repair Proxy Settings
Unhide Non System Files
Repair Windows Updates
Repair CD/DVD Missing/Not Working
  • Checkmark Restart System When Finished option
  • click the Start button
  • System should restart after repair
Can you now run Farbar tool and submit the FRST.txt log?

#9 MsYvaine

MsYvaine
  • Topic Starter

  • Members
  • 61 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:uk-london
  • Local time:06:16 PM

Posted 13 November 2013 - 04:39 PM

hi nasdaq,

 

Hm.. well it may sound silly, but I'm rather a newbee... can I create a restore point in safe mode?

I've tried to create a restore point in normal mode, but the laptop froze before the system protection window opened... 

Shall I disable all the apps starting with startup in normal mode and try to do the restore?

Or proceed without a restoration point?

To be honest I have no idea if there was a previous restore point on the computer. Is there a way to find this out?

 

Thanks!



#10 nasdaq

nasdaq

  • Malware Response Team
  • 19,049 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:01:16 PM

Posted 14 November 2013 - 08:05 AM

You may be able to correct you situation by restoring windows to a date prior to the beginning of your difficulties with this computer.

Read the instructions on this page.

How to do a System restore in Windows Vista and Windows 7
http://www.technospot.net/blogs/how-to-do-a-system-restore-in-windows-vista-and-windows-7/

Click System Restore Select a date prior to the start of your difficulties with this computer.

If that fails then Just run the Windows repair as I have suggested.

#11 MsYvaine

MsYvaine
  • Topic Starter

  • Members
  • 61 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:uk-london
  • Local time:06:16 PM

Posted 16 November 2013 - 04:08 PM

Dear nasdaq,
 
I could finally run farbar and here are the logs:
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 14-11-2013
Ran by Babyke at 2013-11-16 21:00:01
Running from C:\Users\Babyke\Desktop
Boot Mode: Safe Mode (with Networking)
==========================================================
 
 
==================== Security Center ========================
 
 
==================== Installed Programs ======================
 
µTorrent (HKCU Version: 3.3.2.30180)
A Microsoft .NET-keretrendszer 4-es verziójához tartozó ügyfélprofil HUN nyelvi csomagja (Version: 4.0.30319)
ABBYY FineReader 9.0 Sprint (x32 Version: 9.01.513.58212)
Adobe AIR (x32 Version: 3.5.0.1060)
Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.117)
Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117)
Adobe Reader XI (11.0.05) (x32 Version: 11.0.05)
Apple Application Support (x32 Version: 2.3.2)
Apple Mobile Device Support (Version: 6.0.1.3)
Apple Software Update (x32 Version: 2.1.3.127)
ATI Catalyst Install Manager (Version: 3.0.790.0)
BCDC++ 0.790bx (x32 Version: 0.790bx)
Bonjour (Version: 3.0.0.10)
Broadcom 802.11 Wireless LAN Adapter (Version: 5.60.350.6)
Catalyst Control Center - Branding (x32 Version: 1.00.0000)
Catalyst Control Center Graphics Previews Common (x32 Version: 2010.0929.2212.37971)
Catalyst Control Center Graphics Previews Vista (x32 Version: 2010.0929.2212.37971)
Catalyst Control Center InstallProxy (x32 Version: 2010.0929.2212.37971)
Catalyst Control Center Localization All (x32 Version: 2010.0929.2212.37971)
CCC Help Chinese Standard (x32 Version: 2010.0929.2211.37971)
CCC Help Chinese Traditional (x32 Version: 2010.0929.2211.37971)
CCC Help Czech (x32 Version: 2010.0929.2211.37971)
CCC Help Danish (x32 Version: 2010.0929.2211.37971)
CCC Help Dutch (x32 Version: 2010.0929.2211.37971)
CCC Help English (x32 Version: 2010.0929.2211.37971)
CCC Help Finnish (x32 Version: 2010.0929.2211.37971)
CCC Help French (x32 Version: 2010.0929.2211.37971)
CCC Help German (x32 Version: 2010.0929.2211.37971)
CCC Help Greek (x32 Version: 2010.0929.2211.37971)
CCC Help Hungarian (x32 Version: 2010.0929.2211.37971)
CCC Help Italian (x32 Version: 2010.0929.2211.37971)
CCC Help Japanese (x32 Version: 2010.0929.2211.37971)
CCC Help Korean (x32 Version: 2010.0929.2211.37971)
CCC Help Norwegian (x32 Version: 2010.0929.2211.37971)
CCC Help Polish (x32 Version: 2010.0929.2211.37971)
CCC Help Portuguese (x32 Version: 2010.0929.2211.37971)
CCC Help Russian (x32 Version: 2010.0929.2211.37971)
CCC Help Spanish (x32 Version: 2010.0929.2211.37971)
CCC Help Swedish (x32 Version: 2010.0929.2211.37971)
CCC Help Thai (x32 Version: 2010.0929.2211.37971)
CCC Help Turkish (x32 Version: 2010.0929.2211.37971)
ccc-core-static (x32 Version: 2010.0929.2212.37971)
ccc-utility64 (Version: 2010.0929.2212.37971)
CCleaner (Version: 4.05)
DivX Setup (x32 Version: 2.6.1.22)
Dropbox (HKCU Version: 2.0.27)
Epson Easy Photo Print 2 (x32 Version: 2.2.4.0)
Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser) (x32 Version: 1.00.0000)
Epson Event Manager (x32 Version: 2.50.0000)
EPSON Scan (x32)
EPSON SX235 Series Printer Uninstall
EpsonNet Print (x32 Version: 2.5.00)
ESET Online Scanner v3 (x32)
Facebook Video Calling 1.2.0.287 (x32 Version: 1.2.287)
FLV Media Player version 1.3 (x32 Version: 1.3)
Full Tilt Poker (x32 Version: 4.63.10.WIN.FullTilt.COM)
Google Chrome (x32 Version: 30.0.1599.101)
Google Earth (x32 Version: 7.1.1.1888)
Google Talk Plugin (x32 Version: 4.8.2.15856)
Google Update Helper (x32 Version: 1.3.21.165)
Hálózati útmutató EPSON SX235 Series (x32)
Használati útmutató EPSON SX235 Series (x32)
Hewlett-Packard ACLM.NET v1.2.1.1 (x32 Version: 1.00.0000)
HP Product Detection (x32 Version: 11.14.0006)
HP Support Assistant (x32 Version: 7.0.39.15)
HTC Driver Installer (x32 Version: 4.2.0.001)
HTC Sync Manager (x32 Version: 2.0.60.0)
IPTInstaller (x32 Version: 4.0.8)
iTunes (Version: 11.0.1.12)
Malwarebytes Anti-Malware 1.75.0.1300 verzió (x32 Version: 1.75.0.1300)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile HUN Language Pack (Version: 4.0.30319)
Microsoft Security Client (Version: 4.3.0219.0)
Microsoft Security Essentials (Version: 4.3.219.0)
Microsoft Silverlight (Version: 5.1.20913.0)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 (x32 Version: 9.0.30411)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Mozilla Firefox 24.0 (x86 en-US) (x32 Version: 24.0)
Mozilla Maintenance Service (x32 Version: 24.0)
MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0)
PokerStars (x32)
Ralink RT2860 Wireless LAN Card (x32 Version: 3.1.13.0)
Realtek Ethernet Controller Driver For Windows 7 (x32 Version: 7.18.322.2010)
Search Protection (HKCU Version: 7.5.0.1)
Skype™ 6.9 (x32 Version: 6.9.106)
Sony Ericsson Update Engine (x32 Version: 2.13.6.201305161305)
Sony PC Companion 2.10.165 (x32 Version: 2.10.165)
SUPERAntiSpyware (Version: 5.6.1032)
Synaptics Pointing Device Driver (Version: 15.1.6.64)
Total Commander Ultima Prime 4.1.0.0 (x32 Version: 4.1.0.0)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0)
Visual Studio 2008 x64 Redistributables (x32 Version: 10.0.0.2)
VLC media player 2.0.0 (x32 Version: 2.0.0)
Windows Driver Package - Broadcom Bluetooth  (06/15/2009 6.2.0.9000) (Version: 06/15/2009 6.2.0.9000)
Windows Driver Package - Broadcom Bluetooth  (07/30/2009 6.2.0.9405) (Version: 07/30/2009 6.2.0.9405)
Windows Driver Package - Broadcom HIDClass  (07/28/2009 6.2.0.9800) (Version: 07/28/2009 6.2.0.9800)
WinRAR archiváló (x32)
YTD Video Downloader 3.9.6 (x32 Version: 3.9.6)
Zotero Standalone 4.0.11 (x86 en-US) (x32 Version: 4.0.11)
 
==================== Restore Points  =========================
 
 
==================== Hosts content: ==========================
 
2009-07-14 02:34 - 2013-11-14 22:16 - 00000855 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost
 
==================== Scheduled Tasks (whitelisted) =============
 
Task: {130765A6-05C1-40EA-A112-C023950C83DB} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis Install => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-27] (Hewlett-Packard Company)
Task: {309D8FBC-7842-47B7-888D-1E91D1334D64} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-12-27] (Google Inc.)
Task: {60BBF0D9-0A9F-4BE8-B099-68C856024193} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-08-21] (Piriform Ltd)
Task: {7BA1B922-0C5F-4621-A9D4-62825D069990} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-27] (Hewlett-Packard Company)
Task: {9ACF9285-F329-4470-B849-5C053149FE18} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-27] (Hewlett-Packard Company)
Task: {A4988E29-760F-43E0-9F0C-A9975BF2E282} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {B937FB6B-0C31-4033-BBF7-29F2E6378202} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-12-27] (Google Inc.)
Task: {F0657678-0DF2-46B8-B316-1D2ACA9A68CD} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-09] (Adobe Systems Incorporated)
Task: {F54F9CF0-C2CC-42E3-B14D-A4709AC7A1A4} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-231758204-126888405-1835614825-1000Core => C:\Users\Babyke\AppData\Local\Google\Update\GoogleUpdate.exe [2013-02-16] (Google Inc.)
Task: {F8C53301-6D09-42A4-A87F-A472D939E7CD} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-231758204-126888405-1835614825-1000UA => C:\Users\Babyke\AppData\Local\Google\Update\GoogleUpdate.exe [2013-02-16] (Google Inc.)
Task: {F9119E75-ED63-4CDB-8803-D479B14186F2} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2013-04-01] (Hewlett-Packard Company)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-231758204-126888405-1835614825-1000Core.job => C:\Users\Babyke\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-231758204-126888405-1835614825-1000UA.job => C:\Users\Babyke\AppData\Local\Google\Update\GoogleUpdate.exe
 
==================== Loaded Modules (whitelisted) =============
 
2012-12-26 17:13 - 2010-03-15 11:28 - 00052224 _____ () C:\Program Files (x86)\WinRAR\rarext64.dll
2013-10-17 00:22 - 2013-10-09 00:02 - 04055504 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\pdf.dll
2013-10-17 00:22 - 2013-10-09 00:02 - 00415184 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\ppGoogleNaClPluginChrome.dll
2013-10-17 00:22 - 2013-10-09 00:01 - 01604560 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\ffmpegsumo.dll
2013-11-11 10:29 - 2013-11-11 10:29 - 04591616 _____ () C:\Users\Babyke\AppData\Local\Google\Chrome\User Data\SwiftShader\1.0.5.0\libglesv2.dll
2013-11-11 10:29 - 2013-11-11 10:29 - 00112128 _____ () C:\Users\Babyke\AppData\Local\Google\Chrome\User Data\SwiftShader\1.0.5.0\libegl.dll
 
==================== Alternate Data Streams (whitelisted) =========
 
 
==================== Safe Mode (whitelisted) ===================
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="2"
 
==================== Faulty Device Manager Devices =============
 
Name: Security Processor Loader Driver
Description: Security Processor Loader Driver
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer: 
Service: spldr
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (11/16/2013 08:58:01 PM) (Source: SideBySide) (User: )
Description: Az aktiválási környezet létrehozása C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1 esetében nem sikerült. Hiba található a(z) C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2 jegyzék- vagy házirendfájl C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. sorában.
Az alkalmazás által kért összetevő-verzió ütközik egy másik, már aktív összetevő-verzióval.
Az ütköző összetevők:
1. összetevő: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
2. összetevő: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
 
Error: (11/16/2013 08:58:01 PM) (Source: SideBySide) (User: )
Description: Az aktiválási környezet létrehozása C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1 esetében nem sikerült. Hiba található a(z) C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2 jegyzék- vagy házirendfájl C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. sorában.
Az alkalmazás által kért összetevő-verzió ütközik egy másik, már aktív összetevő-verzióval.
Az ütköző összetevők:
1. összetevő: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
2. összetevő: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
 
Error: (11/14/2013 09:43:18 PM) (Source: System Restore) (User: )
Description: Nem sikerült a visszaállítási pont létrehozása (Folyamat = C:\Windows\system32\wbem\wmiprvse.exe; Leírás = Tweaking.com - Windows Repair; Hiba = 0x8007043c).
 
Error: (11/14/2013 09:39:21 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (11/14/2013 09:11:54 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (11/13/2013 09:28:15 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (11/13/2013 08:43:00 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (11/12/2013 08:56:12 PM) (Source: SideBySide) (User: )
Description: Az aktiválási környezet létrehozása C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1 esetében nem sikerült. Hiba található a(z) C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2 jegyzék- vagy házirendfájl C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. sorában.
Az alkalmazás által kért összetevő-verzió ütközik egy másik, már aktív összetevő-verzióval.
Az ütköző összetevők:
1. összetevő: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
2. összetevő: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
 
Error: (11/12/2013 08:56:12 PM) (Source: SideBySide) (User: )
Description: Az aktiválási környezet létrehozása C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1 esetében nem sikerült. Hiba található a(z) C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2 jegyzék- vagy házirendfájl C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. sorában.
Az alkalmazás által kért összetevő-verzió ütközik egy másik, már aktív összetevő-verzióval.
Az ütköző összetevők:
1. összetevő: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
2. összetevő: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
 
Error: (11/12/2013 08:52:21 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
 
System errors:
=============
Error: (11/16/2013 08:59:03 PM) (Source: Service Control Manager) (User: )
Description: A(z) Számítógép-tallózó szolgáltatás függ a(z) Kiszolgáló szolgáltatástól, amely a következő hiba miatt nem tudott elindulni: 
%%1068
 
Error: (11/16/2013 08:59:03 PM) (Source: Service Control Manager) (User: )
Description: A(z) Számítógép-tallózó szolgáltatás függ a(z) Kiszolgáló szolgáltatástól, amely a következő hiba miatt nem tudott elindulni: 
%%1068
 
Error: (11/16/2013 08:59:03 PM) (Source: Service Control Manager) (User: )
Description: A(z) Számítógép-tallózó szolgáltatás függ a(z) Kiszolgáló szolgáltatástól, amely a következő hiba miatt nem tudott elindulni: 
%%1068
 
Error: (11/16/2013 08:59:03 PM) (Source: Service Control Manager) (User: )
Description: A(z) Számítógép-tallózó szolgáltatás függ a(z) Kiszolgáló szolgáltatástól, amely a következő hiba miatt nem tudott elindulni: 
%%1068
 
Error: (11/16/2013 08:59:03 PM) (Source: Service Control Manager) (User: )
Description: A(z) Számítógép-tallózó szolgáltatás függ a(z) Kiszolgáló szolgáltatástól, amely a következő hiba miatt nem tudott elindulni: 
%%1068
 
Error: (11/16/2013 08:59:03 PM) (Source: Service Control Manager) (User: )
Description: A(z) Számítógép-tallózó szolgáltatás függ a(z) Kiszolgáló szolgáltatástól, amely a következő hiba miatt nem tudott elindulni: 
%%1068
 
Error: (11/16/2013 08:57:31 PM) (Source: Service Control Manager) (User: )
Description: A(z) Számítógép-tallózó szolgáltatás függ a(z) Kiszolgáló szolgáltatástól, amely a következő hiba miatt nem tudott elindulni: 
%%1068
 
Error: (11/16/2013 08:57:31 PM) (Source: Service Control Manager) (User: )
Description: A(z) Számítógép-tallózó szolgáltatás függ a(z) Kiszolgáló szolgáltatástól, amely a következő hiba miatt nem tudott elindulni: 
%%1068
 
Error: (11/16/2013 08:57:31 PM) (Source: Service Control Manager) (User: )
Description: A(z) Számítógép-tallózó szolgáltatás függ a(z) Kiszolgáló szolgáltatástól, amely a következő hiba miatt nem tudott elindulni: 
%%1068
 
Error: (11/16/2013 08:57:31 PM) (Source: Service Control Manager) (User: )
Description: A(z) Számítógép-tallózó szolgáltatás függ a(z) Kiszolgáló szolgáltatástól, amely a következő hiba miatt nem tudott elindulni: 
%%1068
 
 
Microsoft Office Sessions:
=========================
Error: (11/16/2013 08:58:01 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Babyke\Downloads\esetsmartinstaller_enu(1).exe
 
Error: (11/16/2013 08:58:01 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Babyke\Downloads\esetsmartinstaller_enu.exe
 
Error: (11/14/2013 09:43:18 PM) (Source: System Restore)(User: )
Description: C:\Windows\system32\wbem\wmiprvse.exeTweaking.com - Windows Repair0x8007043c
 
Error: (11/14/2013 09:39:21 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (11/14/2013 09:11:54 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (11/13/2013 09:28:15 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (11/13/2013 08:43:00 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (11/12/2013 08:56:12 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Babyke\Downloads\esetsmartinstaller_enu(1).exe
 
Error: (11/12/2013 08:56:12 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Babyke\Downloads\esetsmartinstaller_enu.exe
 
Error: (11/12/2013 08:52:21 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
 
CodeIntegrity Errors:
===================================
  Date: 2013-07-03 19:25:05.878
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2013-07-03 19:25:05.831
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
 
==================== Memory info =========================== 
 
Percentage of memory in use: 40%
Total physical RAM: 1786.9 MB
Available physical RAM: 1056.83 MB
Total Pagefile: 3573.8 MB
Available Pagefile: 2917.32 MB
Total Virtual: 8192 MB
Available Virtual: 8191.82 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:49.19 GB) (Free:7.91 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (Új kötet) (Fixed) (Total:183.59 GB) (Free:43.82 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 233 GB) (Disk ID: B6A82D0E)
Partition 1: (Active) - (Size=49 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=184 GB) - (Type=07 NTFS)
 
==================== End Of Log ============================
 
And I'm sorry, I cant find where to attach a file, so here it is:
 
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-11-2013
Ran by Babyke (administrator) on BABYKE-PC on 16-11-2013 20:59:09
Running from C:\Users\Babyke\Desktop
Windows 7 Ultimate Service Pack 1 (X64) OS Language: 040E
Internet Explorer Version 10
Boot Mode: Safe Mode (with Networking)
 
==================== Processes (Whitelisted) =================
 
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Registry (Whitelisted) ==================
 
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2281256 2010-09-13] (Synaptics Incorporated)
HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [1356240 2013-08-12] (Microsoft Corporation)
HKCU\...\Run: [EPLTarget\P0000000000000000] - C:\Windows\System32\spool\drivers\x64\3\E_IATIHLE.EXE [283232 2013-02-10] (SEIKO EPSON CORPORATION)
HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20474528 2013-10-02] (Skype Technologies S.A.)
HKCU\...\Run: [SpybotSD TeaTimer] - C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe [2144088 2009-01-26] (Safer Networking Limited)
HKCU\...\Run: [Google Update] - C:\Users\Babyke\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-02-16] (Google Inc.)
HKCU\...\Run: [uTorrent] - C:\Users\Babyke\AppData\Roaming\uTorrent\uTorrent.exe [1130576 2013-09-10] (BitTorrent Inc.)
HKCU\...\Run: [SUPERAntiSpyware] - C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE [6589208 2013-10-29] (SUPERAntiSpyware)
HKCU\...\RunOnce: [Report] - C:\AdwCleaner\AdwCleaner[S0].txt [1867 2013-11-11] ()
HKLM-x32\...\Run: [EEventManager] - C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [979328 2010-10-12] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
Startup: C:\Users\Babyke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Babyke\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
 
==================== Internet (Whitelisted) ====================
 
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - {D204F78F-B750-4899-BA1A-FBC9C73E9343} URL = http://uk.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=714647&p={searchTerms}
BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
 
FireFox:
========
FF ProfilePath: C:\Users\Babyke\AppData\Roaming\Mozilla\Firefox\Profiles\rijjfjwg.default-1373065617686
FF DefaultSearchEngine: Yahoo
FF SelectedSearchEngine: Yahoo
FF Homepage: hxxp://uk.search.yahoo.com?type=714647&fr=spigot-yhp-ff
FF Keyword.URL: hxxp://uk.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=714647&p=
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Babyke\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll No File
FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\Babyke\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\Babyke\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF Plugin HKCU: @talk.google.com/O3DPlugin - C:\Users\Babyke\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Babyke\AppData\Local\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Babyke\AppData\Local\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 &lt;video&gt; - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
 
Chrome: 
=======
CHR Extension: (Google Wallet) - C:\Users\Babyke\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_1
CHR Extension: (DivX Plus Web Player HTML5 \u003Cvideo\u003E) - C:\Users\Babyke\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_1
CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx
 
==================== Services (Whitelisted) =================
 
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [143120 2013-05-23] (SUPERAntiSpyware.com)
S2 ABBYY.Licensing.FineReader.Sprint.9.0; C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [759048 2009-05-14] (ABBYY)
S2 HTCMonitorService; C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe [87368 2013-01-29] (Nero AG)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2013-08-12] (Microsoft Corporation)
S3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [366600 2013-08-12] (Microsoft Corporation)
S2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] ()
 
==================== Drivers (Whitelisted) ====================
 
S0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [247216 2013-06-18] (Microsoft Corporation)
S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [139616 2013-06-18] (Microsoft Corporation)
S1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [871408 2012-12-26] ()
S1 VD_FileDisk; C:\Windows\SysWow64\Drivers\VD_FileDisk.sys [15872 2006-01-13] (Flint Incorporation)
U3 ajega6ro; C:\Windows\System32\Drivers\ajega6ro.sys [0 ] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
S3 VGPU; System32\drivers\rdvgkmd.sys [x]
 
==================== NetSvcs (Whitelisted) ===================
 
 
==================== One Month Created Files and Folders ========
 
2013-11-16 20:59 - 2013-11-16 20:59 - 00009836 _____ C:\Users\Babyke\Desktop\FRST.txt
2013-11-16 20:57 - 2013-11-16 20:57 - 01957794 _____ (Farbar) C:\Users\Babyke\Desktop\FRST64.exe
2013-11-14 22:23 - 2013-11-14 22:23 - 00000356 _____ C:\Windows\PFRO.log
2013-11-14 21:43 - 2013-11-14 21:43 - 00000207 _____ C:\Windows\tweaking.com-regbackup-BABYKE-PC-Microsoft-Windows-7-Ultimate-(64-bit).dat
2013-11-14 21:43 - 2013-11-14 21:43 - 00000000 ____D C:\RegBackup
2013-11-14 21:42 - 2013-11-14 21:42 - 00000000 ____D C:\Users\Babyke\Desktop\Tweaking.com - Windows Repair
2013-11-14 21:40 - 2013-11-14 21:40 - 02804572 _____ C:\Users\Babyke\Desktop\tweaking.com_windows_repair_aio.zip
2013-11-12 20:59 - 2013-11-12 20:59 - 00000000 ____D C:\FRST
2013-11-12 20:54 - 2013-11-12 21:00 - 00000000 ____D C:\Users\Babyke\Desktop\farbar
2013-11-11 20:49 - 2013-11-11 20:52 - 00000000 ____D C:\AdwCleaner
2013-11-11 20:48 - 2013-11-11 20:48 - 01085542 _____ C:\Users\Babyke\Desktop\adwcleaner (1).exe
2013-11-11 20:43 - 2013-11-11 20:43 - 00002690 _____ C:\Users\Babyke\Desktop\RKreport[0]_D_11112013_204344.txt
2013-11-11 20:42 - 2013-11-11 20:42 - 00002549 _____ C:\Users\Babyke\Desktop\RKreport[0]_S_11112013_204257.txt
2013-11-11 20:35 - 2013-11-11 20:43 - 00000000 ____D C:\Users\Babyke\Desktop\RK_Quarantine
2013-11-11 20:35 - 2013-11-11 20:35 - 04118528 _____ C:\Users\Babyke\Desktop\RogueKillerX64 (1).exe
2013-11-11 20:33 - 2013-11-11 20:33 - 04118528 _____ C:\Users\Babyke\Downloads\RogueKillerX64.exe
2013-11-05 16:15 - 2013-11-16 20:21 - 00000672 _____ C:\Windows\setupact.log
2013-11-05 16:15 - 2013-11-05 16:15 - 00000000 _____ C:\Windows\setuperr.log
2013-11-05 16:13 - 2013-11-05 16:13 - 00006253 _____ C:\AdwCleaner[S3].txt
2013-11-05 16:12 - 2013-11-05 16:12 - 00006090 _____ C:\AdwCleaner[R1].txt
2013-11-05 11:37 - 2013-11-16 20:37 - 00011048 _____ C:\Windows\WindowsUpdate.log
2013-11-05 11:18 - 2013-11-05 11:18 - 00003544 ____N C:\bootsqm.dat
2013-11-04 19:14 - 2013-11-04 19:14 - 00206875 _____ C:\Users\Babyke\Downloads\[µBit][#46196][Transfer]Szuletett_Felesegek.torrent
2013-11-04 19:14 - 2013-11-04 19:14 - 00047760 _____ C:\Users\Babyke\Downloads\[µBit][#61097][Transfer]Szuletett_felesegek_(Desperate_Housewives)_2._evad___by_makvirag.torrent
2013-11-04 18:20 - 2013-11-04 18:21 - 00020396 _____ C:\Users\Babyke\Downloads\[µBit][#251509]Top.Gun.1986.BDRip.x264.HuN_Chris (1).torrent
2013-11-04 17:05 - 2013-11-04 17:05 - 00038239 _____ C:\Users\Babyke\Downloads\[µBit][#204331]Ice.Road.Truckers.S05.Hungarian.TVRip.XviD_LBAS.torrent
2013-11-04 17:05 - 2013-11-04 17:05 - 00022945 _____ C:\Users\Babyke\Downloads\[µBit][#208339]Ice.Road.Truckers.S04.Hungarian.TVRip.XviD_LBAS.torrent
2013-11-03 19:11 - 2013-11-03 19:11 - 00018287 _____ C:\Users\Babyke\Downloads\[µBit][#251418]Ice.Road.Truckers.S07E07.Load.Rules.Hungarian.PDTV.x264_LBAS.torrent
2013-11-03 19:11 - 2013-11-03 19:11 - 00016577 _____ C:\Users\Babyke\Downloads\[µBit][#251417]Ice.Road.Truckers.S07E06.Hail.to.The.King.Hungarian.PDTV.x264_LBAS.torrent
2013-11-03 18:44 - 2013-11-03 18:44 - 00020563 _____ C:\Users\Babyke\Downloads\[µBit][#251415]Ice.Road.Truckers.S07E04.Ice.Rodeo.Hungarian.PDTV.x264_LBAS.torrent
2013-11-03 18:44 - 2013-11-03 18:44 - 00016247 _____ C:\Users\Babyke\Downloads\[µBit][#251416]Ice.Road.Truckers.S07E05.World.War.Hugh.Hungarian.PDTV.x264_LBAS.torrent
2013-11-03 18:43 - 2013-11-03 18:43 - 00017487 _____ C:\Users\Babyke\Downloads\[µBit][#251407]Ice.Road.Truckers.S07E03.Fear.The.Crack.Hungarian.PDTV.x264_LBAS.torrent
2013-11-03 18:43 - 2013-11-03 18:43 - 00015732 _____ C:\Users\Babyke\Downloads\[µBit][#251406]Ice.Road.Truckers.S07E02.Art.Attack..Hungarian.PDTV.x264_LBAS.torrent
2013-11-03 18:15 - 2013-11-03 18:15 - 00016117 _____ C:\Users\Babyke\Downloads\[µBit][#251405]Ice.Road.Truckers.S07E01.Collision.Course.Hungarian.PDTV.x264_LBAS.torrent
2013-11-03 17:14 - 2013-11-03 17:14 - 00011608 _____ C:\Users\Babyke\Downloads\[µBit][#172631]uzoli_disclosure.xvid_3_.avi.torrent
2013-11-03 13:50 - 2013-11-03 13:50 - 00011954 _____ C:\Users\Babyke\Downloads\[µBit][#208778]Dupla.Dinamit.1991.RETAiL.DVDRip.Xvid.HUN_lmg019 (1).torrent
2013-11-03 12:46 - 2013-11-03 12:46 - 00021617 _____ C:\Users\Babyke\Downloads\[µBit][#55730][Transfer]Star_Wars_Old_Trilogy.torrent
2013-11-03 12:42 - 2013-11-03 12:42 - 00020396 _____ C:\Users\Babyke\Downloads\[µBit][#251509]Top.Gun.1986.BDRip.x264.HuN_Chris.torrent
2013-11-03 12:40 - 2013-11-03 12:40 - 00014989 _____ C:\Users\Babyke\Downloads\[µBit][#143452]Olve.vagy.halva.torrent
2013-11-03 12:34 - 2013-11-03 12:34 - 00011954 _____ C:\Users\Babyke\Downloads\[µBit][#208778]Dupla.Dinamit.1991.RETAiL.DVDRip.Xvid.HUN_lmg019.torrent
2013-11-02 18:34 - 2013-11-02 18:34 - 00015035 _____ C:\Users\Babyke\Downloads\[µBit][#250588]Return.to.Nims.Island.2013.DVDRip.XviD.HuN_Matrix.torrent
2013-11-02 12:01 - 2013-11-02 12:02 - 00021847 _____ C:\Users\Babyke\Downloads\[µBit][#182161]A_keresztapa_1_2_3.torrent
2013-10-31 21:11 - 2013-10-31 21:11 - 00018878 _____ C:\Users\Babyke\Downloads\[µBit][#213295]King.Arthur.2004.Directors.Cut.CuSToM.BDRip.XviD.HUN_ZHR.torrent
2013-10-31 19:48 - 2013-10-31 19:49 - 00015055 _____ C:\Users\Babyke\Downloads\[µBit][#251091]The.Lone.Ranger.2013.CUSTOM.DVDRip.XviD.HuN_Matrix.torrent
2013-10-30 17:45 - 2013-10-30 17:45 - 00014601 _____ C:\Users\Babyke\Downloads\[µBit][#251112]Szupercella.2013.CAM.XviD.MD.HUN_MOOvie.torrent
2013-10-30 11:16 - 2013-10-30 11:16 - 00001155 _____ C:\Users\Public\Desktop\Zotero Standalone.lnk
2013-10-30 11:16 - 2013-10-30 11:16 - 00000000 ____D C:\Users\Babyke\AppData\Roaming\Zotero
2013-10-30 11:16 - 2013-10-30 11:16 - 00000000 ____D C:\Users\Babyke\AppData\Local\Zotero
2013-10-30 11:15 - 2013-10-30 11:15 - 00000000 ____D C:\Program Files (x86)\Zotero Standalone
2013-10-30 11:14 - 2013-10-30 11:15 - 24366592 _____ (Mozilla) C:\Users\Babyke\Downloads\Zotero-4.0.11_setup.exe
2013-10-30 10:47 - 2013-10-30 10:47 - 00014693 _____ C:\Users\Babyke\Downloads\[µBit][#170275]A.ritus.2011.DVDRip.XviD.HUN_BiTZoNe.torrent
2013-10-30 10:46 - 2013-10-30 10:46 - 00015414 _____ C:\Users\Babyke\Downloads\[µBit][#251023]A.ritus.2011.DVDRip.Xvid.Hun_mihok (2).torrent
2013-10-30 10:46 - 2013-10-30 10:46 - 00015414 _____ C:\Users\Babyke\Downloads\[µBit][#251023]A.ritus.2011.DVDRip.Xvid.Hun_mihok (1).torrent
2013-10-30 10:43 - 2013-10-30 10:44 - 00015414 _____ C:\Users\Babyke\Downloads\[µBit][#251023]A.ritus.2011.DVDRip.Xvid.Hun_mihok.torrent
2013-10-28 20:10 - 2013-10-28 20:10 - 00020270 _____ C:\Users\Babyke\Downloads\[µBit][#249346]Halalhegy___A_Dyatlov_rejtely.2013.DVDRiP.HUN.XViD_ATOS.torrent
2013-10-28 20:10 - 2013-10-28 20:10 - 00020224 _____ C:\Users\Babyke\Downloads\[µBit][#249400]Halalhegy___A_Dyatlov_rejtely.2013.DVDRiP.HUN.XViD_ATOS.torrent
2013-10-28 20:10 - 2013-10-28 20:10 - 00014802 _____ C:\Users\Babyke\Downloads\[µBit][#250403]halalhegy.a.dyatlov_rejtely.2013.hun.bdrip.xvid_arrow (2).torrent
2013-10-28 20:10 - 2013-10-28 20:10 - 00014802 _____ C:\Users\Babyke\Downloads\[µBit][#250403]halalhegy.a.dyatlov_rejtely.2013.hun.bdrip.xvid_arrow (1).torrent
2013-10-28 16:43 - 2013-10-28 16:43 - 00012268 _____ C:\Users\Babyke\Downloads\[µBit][#249761]Szuletett.gengszterek.2012.DVDRip.XviD.AC3.5.1.Hun_easys.torrent
2013-10-28 16:33 - 2013-10-28 16:33 - 00011404 _____ C:\Users\Babyke\Downloads\[µBit][#250144]A.buddhizmus.het.csodaja.2011.HUN.TVRiP.XviD_BeNeTT.torrent
2013-10-28 16:24 - 2013-10-28 16:24 - 00014802 _____ C:\Users\Babyke\Downloads\[µBit][#250403]halalhegy.a.dyatlov_rejtely.2013.hun.bdrip.xvid_arrow.torrent
2013-10-28 16:15 - 2013-10-28 16:16 - 00018464 _____ C:\Users\Babyke\Downloads\[µBit][#250628]So.Undercover.2012.CUSTOM.BDRiP.HUN.XViD_TiGeR.torrent
2013-10-25 19:25 - 2013-10-25 19:25 - 00015004 _____ C:\Users\Babyke\Downloads\[µBit][#77426]Gru.2010.BDRip.XviD.Hun_HDTV.torrent
2013-10-25 19:19 - 2013-10-25 19:19 - 00015834 _____ C:\Users\Babyke\Downloads\[µBit][#247436]The.East.2013.BDRip.XviD.HuN_MicroBit.torrent
2013-10-25 18:57 - 2013-10-25 18:57 - 00016338 _____ C:\Users\Babyke\Downloads\[µBit][#249054]A.kolonia.2013.HUN.720p.BDRip.x264_GMC.torrent
2013-10-25 18:57 - 2013-10-25 18:57 - 00016338 _____ C:\Users\Babyke\Downloads\[µBit][#249054]A.kolonia.2013.HUN.720p.BDRip.x264_GMC (1).torrent
2013-10-25 18:39 - 2013-10-25 18:39 - 00019482 _____ C:\Users\Babyke\Downloads\[µBit][#249053]A.Vegzet.Ereklyei.Csontvaros.2013.BRRip.H.264.HunSub_TERACOD.torrent
2013-10-22 18:54 - 2013-10-22 18:54 - 00016131 _____ C:\Users\Babyke\Downloads\[µBit][#249322]The.Internship.2013.HUN.DVDRip.Xvid_Pacman.torrent
2013-10-22 18:47 - 2013-10-22 18:47 - 00013393 _____ C:\Users\Babyke\Downloads\[µBit][#249578]Gru.2.2013.CUSTOM.BDRiP.Hun.Md.XviD_Hafi.torrent
2013-10-22 18:46 - 2013-10-22 18:46 - 00017882 _____ C:\Users\Babyke\Downloads\[µBit][#249264]Gyakornokok.2013.HUN.TC.BDRiP.XviD_ARROW.torrent
2013-10-21 11:43 - 2013-10-21 11:43 - 00027666 _____ C:\Users\Babyke\Downloads\[µBit][#249683]Batman.Trilogy.Nolan.2005_2012.HUN.720p.BDRip.x264_GMC.torrent
2013-10-20 14:05 - 2013-10-20 14:05 - 00029668 _____ C:\Users\Babyke\Downloads\[µBit][#248863]Breaking.Bad.S05.HDTV.x264_MiXGROUP.torrent
2013-10-19 20:40 - 2013-10-19 20:40 - 00015506 _____ C:\Users\Babyke\Downloads\[µBit][#249122]Now.You.See.Me.2013.DVDRip.XviD.HuN_DreamSite.torrent
2013-10-19 19:38 - 2013-10-19 19:38 - 00013045 _____ C:\Users\Babyke\Downloads\[µBit][#249214]Az.acelember.2013.CUSTOM.BDRiP.XviD.MD.HUN_Hafi.torrent
2013-10-19 19:37 - 2013-10-19 19:37 - 00018999 _____ C:\Users\Babyke\Downloads\[µBit][#248880]White.House.Down.2013.RETAiL.BDRip.XviD.HuN_MicroBit.torrent
2013-10-18 21:35 - 2013-10-18 21:35 - 00026116 _____ C:\Users\Babyke\Downloads\[µBit][#242579]Breaking.Bad.S04.DVDRip.XviD_SAiNTS.torrent
 
==================== One Month Modified Files and Folders =======
 
2013-11-16 20:59 - 2013-11-16 20:59 - 00009836 _____ C:\Users\Babyke\Desktop\FRST.txt
2013-11-16 20:57 - 2013-11-16 20:57 - 01957794 _____ (Farbar) C:\Users\Babyke\Desktop\FRST64.exe
2013-11-16 20:37 - 2013-11-05 11:37 - 00011048 _____ C:\Windows\WindowsUpdate.log
2013-11-16 20:31 - 2011-04-12 10:42 - 00628570 _____ C:\Windows\system32\perfh00E.dat
2013-11-16 20:31 - 2011-04-12 10:42 - 00144574 _____ C:\Windows\system32\perfc00E.dat
2013-11-16 20:31 - 2009-07-14 05:13 - 01505620 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-16 20:23 - 2013-09-10 20:23 - 00000000 ____D C:\Users\Babyke\AppData\Roaming\uTorrent
2013-11-16 20:22 - 2012-12-27 22:26 - 00001024 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-11-16 20:22 - 2012-12-26 17:34 - 00057944 _____ C:\Users\Babyke\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-16 20:21 - 2013-11-05 16:15 - 00000672 _____ C:\Windows\setupact.log
2013-11-16 20:21 - 2009-07-14 05:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-11-14 22:35 - 2009-07-14 04:45 - 00275928 _____ C:\Windows\system32\FNTCACHE.DAT
2013-11-14 22:23 - 2013-11-14 22:23 - 00000356 _____ C:\Windows\PFRO.log
2013-11-14 22:15 - 2009-07-14 02:34 - 00000439 _____ C:\Windows\win.ini
2013-11-14 21:43 - 2013-11-14 21:43 - 00000207 _____ C:\Windows\tweaking.com-regbackup-BABYKE-PC-Microsoft-Windows-7-Ultimate-(64-bit).dat
2013-11-14 21:43 - 2013-11-14 21:43 - 00000000 ____D C:\RegBackup
2013-11-14 21:42 - 2013-11-14 21:42 - 00000000 ____D C:\Users\Babyke\Desktop\Tweaking.com - Windows Repair
2013-11-14 21:40 - 2013-11-14 21:40 - 02804572 _____ C:\Users\Babyke\Desktop\tweaking.com_windows_repair_aio.zip
2013-11-12 21:00 - 2013-11-12 20:54 - 00000000 ____D C:\Users\Babyke\Desktop\farbar
2013-11-12 20:59 - 2013-11-12 20:59 - 00000000 ____D C:\FRST
2013-11-11 20:52 - 2013-11-11 20:49 - 00000000 ____D C:\AdwCleaner
2013-11-11 20:48 - 2013-11-11 20:48 - 01085542 _____ C:\Users\Babyke\Desktop\adwcleaner (1).exe
2013-11-11 20:43 - 2013-11-11 20:43 - 00002690 _____ C:\Users\Babyke\Desktop\RKreport[0]_D_11112013_204344.txt
2013-11-11 20:43 - 2013-11-11 20:35 - 00000000 ____D C:\Users\Babyke\Desktop\RK_Quarantine
2013-11-11 20:42 - 2013-11-11 20:42 - 00002549 _____ C:\Users\Babyke\Desktop\RKreport[0]_S_11112013_204257.txt
2013-11-11 20:35 - 2013-11-11 20:35 - 04118528 _____ C:\Users\Babyke\Desktop\RogueKillerX64 (1).exe
2013-11-11 20:33 - 2013-11-11 20:33 - 04118528 _____ C:\Users\Babyke\Downloads\RogueKillerX64.exe
2013-11-11 10:34 - 2013-07-02 21:27 - 00011808 _____ C:\Users\Babyke\Desktop\dds.txt
2013-11-11 10:34 - 2013-07-02 21:27 - 00004916 _____ C:\Users\Babyke\Desktop\attach.txt
2013-11-11 10:17 - 2012-12-26 19:31 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-11-08 12:15 - 2012-12-27 22:26 - 00001028 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-11-05 16:15 - 2013-11-05 16:15 - 00000000 _____ C:\Windows\setuperr.log
2013-11-05 16:13 - 2013-11-05 16:13 - 00006253 _____ C:\AdwCleaner[S3].txt
2013-11-05 16:12 - 2013-11-05 16:12 - 00006090 _____ C:\AdwCleaner[R1].txt
2013-11-05 11:31 - 2012-12-26 15:21 - 00000000 ____D C:\Windows\Panther
2013-11-05 11:18 - 2013-11-05 11:18 - 00003544 ____N C:\bootsqm.dat
2013-11-04 20:24 - 2012-12-26 17:14 - 00000000 ____D C:\Users\Babyke\AppData\Roaming\vlc
2013-11-04 20:03 - 2013-06-12 14:57 - 00000000 ____D C:\Users\Babyke\AppData\Roaming\Dropbox
2013-11-04 19:43 - 2013-03-27 15:21 - 00001042 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-231758204-126888405-1835614825-1000UA.job
2013-11-04 19:14 - 2013-11-04 19:14 - 00206875 _____ C:\Users\Babyke\Downloads\[µBit][#46196][Transfer]Szuletett_Felesegek.torrent
2013-11-04 19:14 - 2013-11-04 19:14 - 00047760 _____ C:\Users\Babyke\Downloads\[µBit][#61097][Transfer]Szuletett_felesegek_(Desperate_Housewives)_2._evad___by_makvirag.torrent
2013-11-04 18:21 - 2013-11-04 18:20 - 00020396 _____ C:\Users\Babyke\Downloads\[µBit][#251509]Top.Gun.1986.BDRip.x264.HuN_Chris (1).torrent
2013-11-04 17:05 - 2013-11-04 17:05 - 00038239 _____ C:\Users\Babyke\Downloads\[µBit][#204331]Ice.Road.Truckers.S05.Hungarian.TVRip.XviD_LBAS.torrent
2013-11-04 17:05 - 2013-11-04 17:05 - 00022945 _____ C:\Users\Babyke\Downloads\[µBit][#208339]Ice.Road.Truckers.S04.Hungarian.TVRip.XviD_LBAS.torrent
2013-11-04 01:41 - 2013-03-27 15:21 - 00000990 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-231758204-126888405-1835614825-1000Core.job
2013-11-03 19:11 - 2013-11-03 19:11 - 00018287 _____ C:\Users\Babyke\Downloads\[µBit][#251418]Ice.Road.Truckers.S07E07.Load.Rules.Hungarian.PDTV.x264_LBAS.torrent
2013-11-03 19:11 - 2013-11-03 19:11 - 00016577 _____ C:\Users\Babyke\Downloads\[µBit][#251417]Ice.Road.Truckers.S07E06.Hail.to.The.King.Hungarian.PDTV.x264_LBAS.torrent
2013-11-03 18:44 - 2013-11-03 18:44 - 00020563 _____ C:\Users\Babyke\Downloads\[µBit][#251415]Ice.Road.Truckers.S07E04.Ice.Rodeo.Hungarian.PDTV.x264_LBAS.torrent
2013-11-03 18:44 - 2013-11-03 18:44 - 00016247 _____ C:\Users\Babyke\Downloads\[µBit][#251416]Ice.Road.Truckers.S07E05.World.War.Hugh.Hungarian.PDTV.x264_LBAS.torrent
2013-11-03 18:43 - 2013-11-03 18:43 - 00017487 _____ C:\Users\Babyke\Downloads\[µBit][#251407]Ice.Road.Truckers.S07E03.Fear.The.Crack.Hungarian.PDTV.x264_LBAS.torrent
2013-11-03 18:43 - 2013-11-03 18:43 - 00015732 _____ C:\Users\Babyke\Downloads\[µBit][#251406]Ice.Road.Truckers.S07E02.Art.Attack..Hungarian.PDTV.x264_LBAS.torrent
2013-11-03 18:15 - 2013-11-03 18:15 - 00016117 _____ C:\Users\Babyke\Downloads\[µBit][#251405]Ice.Road.Truckers.S07E01.Collision.Course.Hungarian.PDTV.x264_LBAS.torrent
2013-11-03 17:14 - 2013-11-03 17:14 - 00011608 _____ C:\Users\Babyke\Downloads\[µBit][#172631]uzoli_disclosure.xvid_3_.avi.torrent
2013-11-03 17:08 - 2009-07-14 04:45 - 00021280 _____ C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-11-03 17:08 - 2009-07-14 04:45 - 00021280 _____ C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-11-03 17:02 - 2013-06-12 15:21 - 00000000 ___RD C:\Users\Babyke\Dropbox
2013-11-03 17:00 - 2013-06-12 12:05 - 00000000 ____D C:\Users\Babyke\AppData\Local\HTC MediaHub
2013-11-03 13:50 - 2013-11-03 13:50 - 00011954 _____ C:\Users\Babyke\Downloads\[µBit][#208778]Dupla.Dinamit.1991.RETAiL.DVDRip.Xvid.HUN_lmg019 (1).torrent
2013-11-03 12:46 - 2013-11-03 12:46 - 00021617 _____ C:\Users\Babyke\Downloads\[µBit][#55730][Transfer]Star_Wars_Old_Trilogy.torrent
2013-11-03 12:42 - 2013-11-03 12:42 - 00020396 _____ C:\Users\Babyke\Downloads\[µBit][#251509]Top.Gun.1986.BDRip.x264.HuN_Chris.torrent
2013-11-03 12:40 - 2013-11-03 12:40 - 00014989 _____ C:\Users\Babyke\Downloads\[µBit][#143452]Olve.vagy.halva.torrent
2013-11-03 12:34 - 2013-11-03 12:34 - 00011954 _____ C:\Users\Babyke\Downloads\[µBit][#208778]Dupla.Dinamit.1991.RETAiL.DVDRip.Xvid.HUN_lmg019.torrent
2013-11-02 20:01 - 2009-07-14 05:32 - 00000000 ____D C:\Windows\system32\FxsTmp
2013-11-02 18:34 - 2013-11-02 18:34 - 00015035 _____ C:\Users\Babyke\Downloads\[µBit][#250588]Return.to.Nims.Island.2013.DVDRip.XviD.HuN_Matrix.torrent
2013-11-02 12:02 - 2013-11-02 12:01 - 00021847 _____ C:\Users\Babyke\Downloads\[µBit][#182161]A_keresztapa_1_2_3.torrent
2013-11-01 18:57 - 2013-03-28 15:40 - 00000000 ____D C:\Users\Babyke\AppData\Roaming\Skype
2013-11-01 07:23 - 2013-01-18 09:40 - 00000000 _____ C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2013-11-01 07:23 - 2012-12-26 20:11 - 00000052 _____ C:\Windows\SysWOW64\DOErrors.log
2013-10-31 21:11 - 2013-10-31 21:11 - 00018878 _____ C:\Users\Babyke\Downloads\[µBit][#213295]King.Arthur.2004.Directors.Cut.CuSToM.BDRip.XviD.HUN_ZHR.torrent
2013-10-31 19:49 - 2013-10-31 19:48 - 00015055 _____ C:\Users\Babyke\Downloads\[µBit][#251091]The.Lone.Ranger.2013.CUSTOM.DVDRip.XviD.HuN_Matrix.torrent
2013-10-31 15:27 - 2013-03-28 15:40 - 00000000 ____D C:\ProgramData\Skype
2013-10-31 15:26 - 2013-03-28 15:40 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-10-30 17:45 - 2013-10-30 17:45 - 00014601 _____ C:\Users\Babyke\Downloads\[µBit][#251112]Szupercella.2013.CAM.XviD.MD.HUN_MOOvie.torrent
2013-10-30 11:16 - 2013-10-30 11:16 - 00001155 _____ C:\Users\Public\Desktop\Zotero Standalone.lnk
2013-10-30 11:16 - 2013-10-30 11:16 - 00000000 ____D C:\Users\Babyke\AppData\Roaming\Zotero
2013-10-30 11:16 - 2013-10-30 11:16 - 00000000 ____D C:\Users\Babyke\AppData\Local\Zotero
2013-10-30 11:15 - 2013-10-30 11:15 - 00000000 ____D C:\Program Files (x86)\Zotero Standalone
2013-10-30 11:15 - 2013-10-30 11:14 - 24366592 _____ (Mozilla) C:\Users\Babyke\Downloads\Zotero-4.0.11_setup.exe
2013-10-30 10:47 - 2013-10-30 10:47 - 00014693 _____ C:\Users\Babyke\Downloads\[µBit][#170275]A.ritus.2011.DVDRip.XviD.HUN_BiTZoNe.torrent
2013-10-30 10:46 - 2013-10-30 10:46 - 00015414 _____ C:\Users\Babyke\Downloads\[µBit][#251023]A.ritus.2011.DVDRip.Xvid.Hun_mihok (2).torrent
2013-10-30 10:46 - 2013-10-30 10:46 - 00015414 _____ C:\Users\Babyke\Downloads\[µBit][#251023]A.ritus.2011.DVDRip.Xvid.Hun_mihok (1).torrent
2013-10-30 10:44 - 2013-10-30 10:43 - 00015414 _____ C:\Users\Babyke\Downloads\[µBit][#251023]A.ritus.2011.DVDRip.Xvid.Hun_mihok.torrent
2013-10-29 09:54 - 2013-09-17 18:53 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2013-10-29 09:54 - 2009-07-14 03:20 - 00000000 ____D C:\Windows\system32\NDF
2013-10-28 20:10 - 2013-10-28 20:10 - 00020270 _____ C:\Users\Babyke\Downloads\[µBit][#249346]Halalhegy___A_Dyatlov_rejtely.2013.DVDRiP.HUN.XViD_ATOS.torrent
2013-10-28 20:10 - 2013-10-28 20:10 - 00020224 _____ C:\Users\Babyke\Downloads\[µBit][#249400]Halalhegy___A_Dyatlov_rejtely.2013.DVDRiP.HUN.XViD_ATOS.torrent
2013-10-28 20:10 - 2013-10-28 20:10 - 00014802 _____ C:\Users\Babyke\Downloads\[µBit][#250403]halalhegy.a.dyatlov_rejtely.2013.hun.bdrip.xvid_arrow (2).torrent
2013-10-28 20:10 - 2013-10-28 20:10 - 00014802 _____ C:\Users\Babyke\Downloads\[µBit][#250403]halalhegy.a.dyatlov_rejtely.2013.hun.bdrip.xvid_arrow (1).torrent
2013-10-28 16:43 - 2013-10-28 16:43 - 00012268 _____ C:\Users\Babyke\Downloads\[µBit][#249761]Szuletett.gengszterek.2012.DVDRip.XviD.AC3.5.1.Hun_easys.torrent
2013-10-28 16:33 - 2013-10-28 16:33 - 00011404 _____ C:\Users\Babyke\Downloads\[µBit][#250144]A.buddhizmus.het.csodaja.2011.HUN.TVRiP.XviD_BeNeTT.torrent
2013-10-28 16:24 - 2013-10-28 16:24 - 00014802 _____ C:\Users\Babyke\Downloads\[µBit][#250403]halalhegy.a.dyatlov_rejtely.2013.hun.bdrip.xvid_arrow.torrent
2013-10-28 16:16 - 2013-10-28 16:15 - 00018464 _____ C:\Users\Babyke\Downloads\[µBit][#250628]So.Undercover.2012.CUSTOM.BDRiP.HUN.XViD_TiGeR.torrent
2013-10-26 13:31 - 2012-12-26 19:56 - 00000000 ____D C:\Program Files (x86)\Full Tilt Poker
2013-10-26 12:55 - 2012-12-26 20:25 - 00000000 ____D C:\Users\Babyke\AppData\Local\PokerStars
2013-10-25 19:25 - 2013-10-25 19:25 - 00015004 _____ C:\Users\Babyke\Downloads\[µBit][#77426]Gru.2010.BDRip.XviD.Hun_HDTV.torrent
2013-10-25 19:19 - 2013-10-25 19:19 - 00015834 _____ C:\Users\Babyke\Downloads\[µBit][#247436]The.East.2013.BDRip.XviD.HuN_MicroBit.torrent
2013-10-25 18:57 - 2013-10-25 18:57 - 00016338 _____ C:\Users\Babyke\Downloads\[µBit][#249054]A.kolonia.2013.HUN.720p.BDRip.x264_GMC.torrent
2013-10-25 18:57 - 2013-10-25 18:57 - 00016338 _____ C:\Users\Babyke\Downloads\[µBit][#249054]A.kolonia.2013.HUN.720p.BDRip.x264_GMC (1).torrent
2013-10-25 18:39 - 2013-10-25 18:39 - 00019482 _____ C:\Users\Babyke\Downloads\[µBit][#249053]A.Vegzet.Ereklyei.Csontvaros.2013.BRRip.H.264.HunSub_TERACOD.torrent
2013-10-23 01:43 - 2012-12-26 19:19 - 00000000 ____D C:\Users\Babyke\AppData\Roaming\Mozilla
2013-10-22 18:54 - 2013-10-22 18:54 - 00016131 _____ C:\Users\Babyke\Downloads\[µBit][#249322]The.Internship.2013.HUN.DVDRip.Xvid_Pacman.torrent
2013-10-22 18:47 - 2013-10-22 18:47 - 00013393 _____ C:\Users\Babyke\Downloads\[µBit][#249578]Gru.2.2013.CUSTOM.BDRiP.Hun.Md.XviD_Hafi.torrent
2013-10-22 18:46 - 2013-10-22 18:46 - 00017882 _____ C:\Users\Babyke\Downloads\[µBit][#249264]Gyakornokok.2013.HUN.TC.BDRiP.XviD_ARROW.torrent
2013-10-21 11:43 - 2013-10-21 11:43 - 00027666 _____ C:\Users\Babyke\Downloads\[µBit][#249683]Batman.Trilogy.Nolan.2005_2012.HUN.720p.BDRip.x264_GMC.torrent
2013-10-20 14:05 - 2013-10-20 14:05 - 00029668 _____ C:\Users\Babyke\Downloads\[µBit][#248863]Breaking.Bad.S05.HDTV.x264_MiXGROUP.torrent
2013-10-19 20:40 - 2013-10-19 20:40 - 00015506 _____ C:\Users\Babyke\Downloads\[µBit][#249122]Now.You.See.Me.2013.DVDRip.XviD.HuN_DreamSite.torrent
2013-10-19 19:38 - 2013-10-19 19:38 - 00013045 _____ C:\Users\Babyke\Downloads\[µBit][#249214]Az.acelember.2013.CUSTOM.BDRiP.XviD.MD.HUN_Hafi.torrent
2013-10-19 19:37 - 2013-10-19 19:37 - 00018999 _____ C:\Users\Babyke\Downloads\[µBit][#248880]White.House.Down.2013.RETAiL.BDRip.XviD.HuN_MicroBit.torrent
2013-10-18 21:35 - 2013-10-18 21:35 - 00026116 _____ C:\Users\Babyke\Downloads\[µBit][#242579]Breaking.Bad.S04.DVDRip.XviD_SAiNTS.torrent
2013-10-17 00:23 - 2013-07-03 22:37 - 00002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk
 
==================== Bamital & volsnap Check =================
 
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
 
 
LastRegBack: 2013-10-31 02:38
 
==================== End Of Log ============================
What's next?
Thanks!


#12 nasdaq

nasdaq

  • Malware Response Team
  • 19,049 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:01:16 PM

Posted 17 November 2013 - 08:29 AM




Open notepad (Start =>All Programs => Accessories => Notepad). Please copy the entire contents of the code box below.

start

HKCU\...\RunOnce: [Report] - C:\AdwCleaner\AdwCleaner[S0].txt [1867 2013-11-11] ()
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - {F751ABBD-904D-4D4F-9B68-BFA0A4756C80} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3289075&CUI=UN30443982252325128&UM=1
S3 catchme; \??\C:\ComboFix\catchme.sys [x]

end
Save the files as fixlist.txt in to the same folder as FRST
Run FRST and click Fix only once and wait
The tool will create a log (Fixlog.txt) please post it to your reply.
===

The fix above will only remove items that are not required.
It will not fix your problem with booting in normal mode.

Execute the instructions on this page.

Performing a Clean Startup
http://www.sevenforums.com/tutorials/179159-troubleshoot-application-conflicts-performing-clean-startup.html

With a trial and error you may be able to find out what is causing this problem.

Keep me posted.

#13 MsYvaine

MsYvaine
  • Topic Starter

  • Members
  • 61 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:uk-london
  • Local time:06:16 PM

Posted 17 November 2013 - 03:49 PM

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 17-11-2013 02
Ran by Babyke at 2013-11-17 20:30:11 Run:1
Running from C:\Users\Babyke\Desktop\farbar
Boot Mode: Safe Mode (with Networking)
==============================================
 
Content of fixlist:
*****************
start
 
HKCU\...\RunOnce: [Report] - C:\AdwCleaner\AdwCleaner[S0].txt [1867 2013-11-11] ()
SearchScopes: HKLM - DefaultScope value is missing.
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
 
end
*****************
 
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Report => Value deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{F751ABBD-904D-4D4F-9B68-BFA0A4756C80} => Key deleted successfully.
HKCR\CLSID\{F751ABBD-904D-4D4F-9B68-BFA0A4756C80} => Key not found.
catchme => Service deleted successfully.
 
==== End of Fixlog ====
 
that's the log and im doing the win7 clean startup thingy
thank you and will edit this post when I have results from that one


#14 MsYvaine

MsYvaine
  • Topic Starter

  • Members
  • 61 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:uk-london
  • Local time:06:16 PM

Posted 20 November 2013 - 09:54 AM

hi again, from normal mode :)

 

I am kinda puzzled a bit... here is what I've done with the clean startup:

 

Followed the steps as it was suggested and delted bittorrent at one point. After this I still carried out this trial and error steps and could NOT find any services or startup applications that were causing the corruption...

I can still see remnants of the bittorrent in the automatic startup tab, but it is causing nothing...

 

Every time the computer starts into normal mode and antispyware has been updated (sorry, I missed it when it's done it).

 

That's how we stand now.

 

How shall we go on?

 

Thakns



#15 nasdaq

nasdaq

  • Malware Response Team
  • 19,049 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:01:16 PM

Posted 20 November 2013 - 10:27 AM

There were many issues when you started that topic.

What is the present situation.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users