Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Possible ZeroAccess virus - mssecex.exe


  • This topic is locked This topic is locked
29 replies to this topic

#1 Fhoosa

Fhoosa

  • Members
  • 123 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Seabrook, TX
  • Local time:03:57 AM

Posted 25 June 2013 - 11:55 AM

Thought I got rid of the virus.

But then yesterday I noticed that my File Sharing was not working anymore.  I was told that my Firewall was incorrectly configured.  And then last night I found mssecex.exe in my start-up program. 

Who knows what else has been comprimised?

I really need your help...!!!

 

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 9.0.8112.16490
Run by Debbie at 9:31:03 on 2013-06-25
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.1.1033.18.3034.1192 [GMT -7:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Enabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Microsoft Security Client\NisSrv.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files (x86)\Atheros\AWiCMgr.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\igfxpers.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE
C:\Program Files (x86)\BitComet\BitComet.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxps://www.google.com/
BHO: BitComet Helper: {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files (x86)\BitComet\tools\BitCometBHO_1.5.4.11.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
uRun: [BitComet] "C:\Program Files (x86)\BitComet\BitComet.exe" /tray
uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
uPolicies-Explorer: NoDriveTypeAutoRun = dword:221
uPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: NoDrives = dword:0
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: &D&ownload &with BitComet - C:\Program Files (x86)\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all with BitComet - C:\Program Files (x86)\BitComet\BitComet.exe/AddAllLink.htm
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
   If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {15B782AF-55D8-11D1-B477-006097098764} - hxxp://download.macromedia.com/pub/shockwave/cabs/authorware/awswaxf.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} - hxxps://support.dell.com/systemprofiler/SysProExe.CAB
DPF: {50647AB5-18FD-4142-82B0-5852478DD0D5} - hxxp://webeffective.keynote.com/applications/pconnector/download/ConnectorLauncher.cab
DPF: {682C59F5-478C-4421-9070-AD170D143B77} - hxxp://www.dell.com/support/troubleshooting/Content/Ode/pcd86.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {A084A130-28AE-4B32-B51A-1C8CE164BC88} - hxxp://www.convergysworkathome.com/AppHardT.CAB
DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} - hxxp://www.superadblocker.com/activex/sabspx.cab
DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} - hxxp://support.dell.com/systemprofiler/DellSystemLite.CAB
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab
DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.5.13.0.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - hxxps://secure.logmein.com//activex/ractrl.cab?lmi=928
TCP: NameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{7EFE49C3-3F89-4E0A-984B-7B6655B99F9C} : DHCPNameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{7EFE49C3-3F89-4E0A-984B-7B6655B99F9C}\6486F6F63716 : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{7EFE49C3-3F89-4E0A-984B-7B6655B99F9C}\84F4D454D244339323 : DHCPNameServer = 75.75.75.75 75.75.76.76
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
x64-Run: [AWiC] "C:\Program Files (x86)\Atheros\AWiCMgr.exe" -nogui
x64-Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
.
INFO: x64-HKLM has more than 50 listed domains.
   If you wish to scan all of them, select the 'Force scan all domains' option.
.
x64-Notify: igfxcui - igfxdev.dll
x64-mASetup: {12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\Windows\System32\ieudinit.exe
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2013-1-20 230320]
R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2011-4-21 55856]
R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-4-21 13336]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-9-12 418376]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-9-12 701512]
R2 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2012-8-30 130008]
R2 SftService;SoftThinks Agent Service;C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe [2011-4-21 1692480]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;C:\Windows\System32\drivers\L1C62x64.sys [2011-4-21 76912]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2012-9-12 25928]
R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2013-1-27 379360]
R3 Sftfs;Sftfs;C:\Windows\System32\drivers\Sftfslh.sys [2011-10-1 764264]
R3 Sftplay;Sftplay;C:\Windows\System32\drivers\Sftplaylh.sys [2011-10-1 268648]
R3 Sftvol;Sftvol;C:\Windows\System32\drivers\Sftvollh.sys [2011-10-1 22376]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2012-1-4 822624]
S2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-1 508776]
S3 CtClsFlt;Creative Camera Class Upper Filter Driver;C:\Windows\System32\drivers\CtClsFlt.sys [2011-4-21 172704]
S3 hitmanpro37;HitmanPro 3.7 Support Driver;C:\Windows\System32\drivers\hitmanpro37.sys [2013-6-24 32000]
S3 PCTDMDefrag;PCTDMDefrag;C:\Windows\System32\drivers\PCTDMDefrag.sys [2012-4-8 162328]
S3 PCTDSMon;PCTDSMon;C:\Windows\System32\drivers\PCTDSMon.sys [2012-4-8 189880]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2012-11-18 19456]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\System32\drivers\RtsUStor.sys [2011-4-21 232480]
S3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2009-6-10 187392]
S3 Sftredir;Sftredir;C:\Windows\System32\drivers\Sftredirlh.sys [2011-10-1 25960]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2012-11-18 57856]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-4-10 1255736]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\System32\drivers\yk62x64.sys [2009-6-10 389120]
S4 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-1 219496]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2013-06-25 08:56:24 9552976 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{B84545DF-E37D-4126-98AE-C37B71A1F543}\mpengine.dll
2013-06-25 07:01:18 108968 ----a-w- C:\Windows\System32\WindowsAccessBridge-64.dll
2013-06-25 06:59:52 96168 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2013-06-24 15:39:07 -------- d-----w- C:\Users\Debbie\AppData\Roaming\8Floor
2013-06-24 12:06:56 -------- d-----w- C:\Users\Debbie\AppData\Roaming\Chayowo Games
2013-06-24 10:29:21 9552976 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-06-24 10:18:13 -------- d-sh--w- C:\$RECYCLE.BIN
2013-06-24 09:42:36 98816 ----a-w- C:\Windows\sed.exe
2013-06-24 09:42:36 256000 ----a-w- C:\Windows\PEV.exe
2013-06-24 09:42:36 208896 ----a-w- C:\Windows\MBR.exe
2013-06-24 09:05:46 32000 ----a-w- C:\Windows\System32\drivers\hitmanpro37.sys
2013-06-23 15:41:05 65602 ----a-w- C:\Windows\SysWow64\cook3260.dll
2013-06-23 15:41:05 217127 ----a-w- C:\Windows\SysWow64\drv43260.dll
2013-06-23 15:41:05 208935 ----a-w- C:\Windows\SysWow64\drv33260.dll
2013-06-23 15:41:05 176165 ----a-w- C:\Windows\SysWow64\drv23260.dll
2013-06-23 15:41:05 102439 ----a-w- C:\Windows\SysWow64\sipr3260.dll
2013-06-23 15:41:04 626688 ----a-w- C:\Windows\SysWow64\vp7vfw.dll
2013-06-23 15:41:04 1184984 ----a-w- C:\Windows\SysWow64\wvc1dmod.dll
2013-06-23 15:41:01 -------- d-----w- C:\Program Files (x86)\VSO
2013-06-23 01:24:05 82816 ----a-w- C:\Users\Debbie\AppData\Roaming\pcouffin.sys
2013-06-22 07:59:19 -------- d-----w- C:\Program Files (x86)\Total Video Converter
2013-06-22 06:14:35 -------- d-----w- C:\Users\Debbie\My Backup Files
2013-06-22 05:14:07 964552 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{33152359-A02C-4A8E-BD14-6323700C0ACC}\gapaengine.dll
2013-06-21 09:11:55 42297 ----a-w- C:\Windows\System32\uninstall.exe
2013-06-21 08:20:57 40960 ----a-w- C:\Windows\SysWow64\ssubtmr6.dll
2013-06-21 08:20:57 36864 ----a-w- C:\Windows\SysWow64\trayicon_handler.ocx
2013-06-21 04:47:32 -------- d-----w- C:\Program Files (x86)\Common Files\Jaksta Technologies
2013-06-20 14:58:35 -------- d-----w- C:\Windows\Untold History - Descendant of the Sun Collector's Edition
2013-06-20 14:58:35 -------- d-----w- C:\Program Files (x86)\Untold History - Descendant of the Sun Collector's Edition
2013-06-20 05:26:16 -------- d-----w- C:\Users\Debbie\AppData\Local\{809AD72F-4679-4540-89ED-B9C986E67D80}
2013-06-20 04:08:16 -------- d-----w- C:\Users\Debbie\AppData\Local\{AA6B9902-7033-47E7-BAEA-BC1BD1AC8A70}
2013-06-14 03:55:24 -------- d-----w- C:\Users\Debbie\AppData\Roaming\4 Friends Games
2013-06-14 02:57:58 1910632 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2013-06-14 02:57:50 751104 ----a-w- C:\Windows\System32\win32spl.dll
2013-06-14 02:57:50 492544 ----a-w- C:\Windows\SysWow64\win32spl.dll
2013-06-14 02:57:40 30720 ----a-w- C:\Windows\System32\cryptdlg.dll
2013-06-14 02:57:39 24576 ----a-w- C:\Windows\SysWow64\cryptdlg.dll
2013-06-14 02:57:25 1424384 ----a-w- C:\Windows\System32\WindowsCodecs.dll
2013-06-14 02:57:25 1230336 ----a-w- C:\Windows\SysWow64\WindowsCodecs.dll
2013-06-14 02:56:37 903168 ----a-w- C:\Windows\SysWow64\certutil.exe
2013-06-14 02:56:37 1464320 ----a-w- C:\Windows\System32\crypt32.dll
2013-06-14 02:56:37 1192448 ----a-w- C:\Windows\System32\certutil.exe
2013-06-14 02:56:36 184320 ----a-w- C:\Windows\System32\cryptsvc.dll
2013-06-14 02:56:36 139776 ----a-w- C:\Windows\System32\cryptnet.dll
2013-06-14 02:56:36 1160192 ----a-w- C:\Windows\SysWow64\crypt32.dll
2013-06-14 02:56:36 103936 ----a-w- C:\Windows\SysWow64\cryptnet.dll
2013-06-14 02:56:34 52224 ----a-w- C:\Windows\System32\certenc.dll
2013-06-14 02:56:34 43008 ----a-w- C:\Windows\SysWow64\certenc.dll
2013-06-14 02:56:34 140288 ----a-w- C:\Windows\SysWow64\cryptsvc.dll
2013-06-14 02:56:16 1887232 ----a-w- C:\Windows\System32\d3d11.dll
2013-06-14 02:56:16 1505280 ----a-w- C:\Windows\SysWow64\d3d11.dll
2013-06-13 00:49:38 -------- d-----w- C:\Users\Debbie\AppData\Roaming\Deep Shadows
2013-06-13 00:43:24 -------- d-----w- C:\Program Files (x86)\Big City Adventure 8 - Tokyo
2013-06-13 00:41:40 -------- d-----w- C:\Games
2013-06-12 09:33:52 -------- d-----w- C:\Users\Debbie\AppData\Roaming\ERS Game Studios
2013-06-08 21:45:53 -------- d-----w- C:\Program Files (x86)\Common Files\Wise Installation Wizard
2013-06-04 14:42:24 -------- d-----w- C:\Dizzy-Games
2013-05-27 10:24:04 -------- d-----w- C:\Users\Debbie\AppData\Roaming\Big Top Games
2013-05-27 10:03:14 -------- d-----w- C:\Users\Debbie\AppData\Roaming\Blue Tea Games
.
==================== Find3M  ====================
.
2013-06-25 07:00:53 1093032 ----a-w- C:\Windows\System32\npDeployJava1.dll
2013-06-25 07:00:52 972712 ----a-w- C:\Windows\System32\deployJava1.dll
2013-06-25 06:59:34 867240 ----a-w- C:\Windows\SysWow64\npdeployJava1.dll
2013-06-25 06:59:34 789416 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2013-06-24 07:51:08 328704 ----a-w- C:\Windows\System32\services.exe
2013-06-14 03:13:54 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-06-14 03:13:54 692104 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-05-17 03:09:56 2312704 ----a-w- C:\Windows\System32\jscript9.dll
2013-05-17 03:02:29 1392128 ----a-w- C:\Windows\System32\wininet.dll
2013-05-17 03:01:13 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl
2013-05-17 02:56:09 173056 ----a-w- C:\Windows\System32\ieUnatt.exe
2013-05-17 02:56:00 599040 ----a-w- C:\Windows\System32\vbscript.dll
2013-05-17 02:51:27 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2013-05-16 22:39:39 1800704 ----a-w- C:\Windows\SysWow64\jscript9.dll
2013-05-16 22:28:26 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll
2013-05-16 22:27:30 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2013-05-16 22:21:37 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2013-05-16 22:20:30 420864 ----a-w- C:\Windows\SysWow64\vbscript.dll
2013-05-16 22:16:57 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2013-05-02 15:29:56 278800 ------w- C:\Windows\System32\MpSigStub.exe
2013-04-18 22:38:36 39904 ----a-w- C:\Windows\SysWow64\Media Player - Codec Pack Disc handler.exe
2013-04-18 22:38:36 39904 ----a-w- C:\Windows\SysWow64\dischandler.exe
2013-04-16 10:40:36 4012544 ----a-w- C:\Windows\System32\ffmpeg.dll
2013-04-16 10:39:26 127488 ----a-w- C:\Windows\System32\ff_vfw.dll
2013-04-16 10:39:14 4372992 ----a-w- C:\Windows\System32\ffdshow.ax
2013-04-16 10:38:32 474624 ----a-w- C:\Windows\System32\ff_kernelDeint.dll
2013-04-16 10:37:38 631296 ----a-w- C:\Windows\System32\TomsMoComp_ff.dll
2013-04-16 10:37:36 114688 ----a-w- C:\Windows\System32\ff_wmv9.dll
2013-04-16 10:37:32 183296 ----a-w- C:\Windows\System32\ff_unrar.dll
2013-04-16 10:37:30 156672 ----a-w- C:\Windows\System32\ff_libmad.dll
2013-04-16 10:37:28 222720 ----a-w- C:\Windows\System32\ff_libdts.dll
2013-04-16 10:37:28 1532928 ----a-w- C:\Windows\System32\ff_samplerate.dll
2013-04-16 10:37:24 190464 ----a-w- C:\Windows\System32\libmpeg2_ff.dll
2013-04-16 10:37:24 116224 ----a-w- C:\Windows\System32\ff_liba52.dll
2013-04-16 10:35:04 3915776 ----a-w- C:\Windows\SysWow64\ffmpeg.dll
2013-04-16 10:33:32 3501568 ----a-w- C:\Windows\SysWow64\ffdshow.ax
2013-04-16 10:32:28 157184 ----a-w- C:\Windows\SysWow64\ff_unrar.dll
2013-04-16 10:32:24 271360 ----a-w- C:\Windows\SysWow64\TomsMoComp_ff.dll
2013-04-16 10:32:18 99840 ----a-w- C:\Windows\SysWow64\ff_wmv9.dll
2013-04-16 10:32:16 211968 ----a-w- C:\Windows\SysWow64\ff_libdts.dll
2013-04-16 10:32:16 147456 ----a-w- C:\Windows\SysWow64\ff_libmad.dll
2013-04-16 10:32:14 1525760 ----a-w- C:\Windows\SysWow64\ff_samplerate.dll
2013-04-16 10:32:14 114688 ----a-w- C:\Windows\SysWow64\ff_liba52.dll
2013-04-16 10:32:10 136704 ----a-w- C:\Windows\SysWow64\libmpeg2_ff.dll
2013-04-14 19:28:05 74703 ----a-w- C:\Windows\SysWow64\mfc45.dat
2013-04-14 08:11:07 319488 ----a-w- C:\Windows\HideWin.exe
2013-04-13 12:24:54 1515520 ----a-w- C:\Windows\System32\LAVVideo.ax
2013-04-13 12:24:48 364720 ----a-w- C:\Windows\System32\IntelQuickSyncDecoder.dll
2013-04-13 12:24:40 509952 ----a-w- C:\Windows\System32\LAVSplitter.ax
2013-04-13 12:24:36 272384 ----a-w- C:\Windows\System32\LAVAudio.ax
2013-04-13 12:24:16 421600 ----a-w- C:\Windows\System32\swscale-lav-2.dll
2013-04-13 12:24:14 7977200 ----a-w- C:\Windows\System32\avcodec-lav-55.dll
2013-04-13 12:24:14 289008 ----a-w- C:\Windows\System32\avutil-lav-52.dll
2013-04-13 12:24:14 202648 ----a-w- C:\Windows\System32\avfilter-lav-3.dll
2013-04-13 12:24:14 194016 ----a-w- C:\Windows\System32\avresample-lav-1.dll
2013-04-13 12:24:14 1245920 ----a-w- C:\Windows\System32\avformat-lav-55.dll
2013-04-13 12:23:50 7788672 ----a-w- C:\Windows\SysWow64\avcodec-lav-55.dll
2013-04-13 12:23:50 424624 ----a-w- C:\Windows\SysWow64\LAVSplitter.ax
2013-04-13 12:23:50 400592 ----a-w- C:\Windows\SysWow64\swscale-lav-2.dll
2013-04-13 12:23:50 284336 ----a-w- C:\Windows\SysWow64\IntelQuickSyncDecoder.dll
2013-04-13 12:23:50 272192 ----a-w- C:\Windows\SysWow64\avutil-lav-52.dll
2013-04-13 12:23:50 244400 ----a-w- C:\Windows\SysWow64\LAVAudio.ax
2013-04-13 12:23:50 194632 ----a-w- C:\Windows\SysWow64\avfilter-lav-3.dll
2013-04-13 12:23:50 172728 ----a-w- C:\Windows\SysWow64\avresample-lav-1.dll
2013-04-13 12:23:50 1300152 ----a-w- C:\Windows\SysWow64\avformat-lav-55.dll
2013-04-13 12:23:50 1185456 ----a-w- C:\Windows\SysWow64\LAVVideo.ax
2013-04-13 05:49:23 135168 ----a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
2013-04-13 05:49:19 350208 ----a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
2013-04-13 05:49:19 308736 ----a-w- C:\Windows\apppatch\AppPatch64\AcGenral.dll
2013-04-13 05:49:19 111104 ----a-w- C:\Windows\apppatch\AppPatch64\acspecfc.dll
2013-04-13 04:45:16 474624 ----a-w- C:\Windows\apppatch\AcSpecfc.dll
2013-04-13 04:45:15 2176512 ----a-w- C:\Windows\apppatch\AcGenral.dll
2013-04-12 14:45:08 1656680 ----a-w- C:\Windows\System32\drivers\ntfs.sys
2013-04-11 14:22:56 770384 ----a-w- C:\Windows\SysWow64\msvcr100.dll
2013-04-11 14:22:56 421200 ----a-w- C:\Windows\SysWow64\msvcp100.dll
2013-04-10 06:01:54 265064 ----a-w- C:\Windows\System32\drivers\dxgmms1.sys
2013-04-10 06:01:53 983400 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys
2013-04-10 03:30:50 3153920 ----a-w- C:\Windows\System32\win32k.sys
2013-04-04 21:50:32 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys
2013-03-30 04:42:42 3379272 ----a-w- C:\Windows\System32\drivers\RTKVHD64.sys
2013-03-27 23:57:08 135240 ----a-w- C:\Windows\System32\RCoInstII64.dll
.
============= FINISH:  9:31:43.44 ===============
 

 

Attached Files



BC AdBot (Login to Remove)

 


#2 CatByte

CatByte

    bleepin' tiger


  • Malware Response Team
  • 14,664 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Canada
  • Local time:05:57 AM

Posted 25 June 2013 - 08:39 PM

Please download Farbar Recovery Scan Tool and save it to your desktop.

 

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

  • Double-click to run it. When the tool opens click Yes to disclaimer.

  • Press Scan button.

  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.

  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.


Microsoft MVP - 2010, 2011, 2012, 2013, 2014, 2015


#3 Fhoosa

Fhoosa
  • Topic Starter

  • Members
  • 123 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Seabrook, TX
  • Local time:03:57 AM

Posted 25 June 2013 - 08:56 PM

Here are the scans you requested.

 


Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-06-2013 02
Ran by Debbie (administrator) on 25-06-2013 18:47:01
Running from C:\Users\Debbie\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US)
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(Protexis Inc.) c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(SoftThinks SAS) C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe
(Atheros) C:\Program Files (x86)\Atheros\AWiCMgr.exe
(Microsoft Corporation) C:\Program Files\Microsoft IntelliPoint\ipoint.exe
(Intel Corporation) C:\WINDOWS\System32\igfxtray.exe
(Intel Corporation) C:\WINDOWS\System32\hkcmd.exe
(Intel Corporation) C:\WINDOWS\System32\igfxpers.exe
(SoftThinks - Dell) C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE
(www.BitComet.com) C:\Program Files (x86)\BitComet\BitComet.exe
() C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE
(Google Inc.) C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
(Microsoft Corporation) C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apntex.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\HidFind.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MpCmdRun.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe [392048 2010-06-04] (Alps Electric Co., Ltd.)
HKLM\...\Run: [AWiC] "C:\Program Files (x86)\Atheros\AWiCMgr.exe" -nogui [167936 2010-09-11] (Atheros)
HKLM\...\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2417032 2011-08-01] (Microsoft Corporation)
HKCU\...\Run: [BitComet] "C:\Program Files (x86)\BitComet\BitComet.exe" /tray [12805888 2013-02-19] (www.BitComet.com)
HKCU\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2012-08-23] (Google Inc.)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [253816 2013-03-12] (Oracle Corporation)
BootExecute:

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
HKLM-x32 SearchScopes: DefaultScope {6CE2F86E-11D5-474D-8190-095E6F2B66A5} URL =
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - {110a9ea2-8810-4c04-b916-cfd4e9427fec} URL = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?p2=^ZX^xdm039^YY^us&si=radiopi&ptb=160C0F77-45F9-44E3-A819-17095ED21E35&ind=2013012018&n=77fc2032&psa=&st=sb&searchfor={searchTerms}
SearchScopes: HKLM-x32 - {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://start.sweetpacks.com/?src=6&q={searchTerms}&st=12&crg=3.5000006.10042&barid={6C0043D1-9D81-11E2-AA34-FF36774A7524}
SearchScopes: HKCU - {110a9ea2-8810-4c04-b916-cfd4e9427fec} URL = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?p2=^ZX^xdm039^YY^us&si=radiopi&ptb=160C0F77-45F9-44E3-A819-17095ED21E35&ind=2013012018&n=77fc2032&psa=&st=sb&searchfor={searchTerms}
SearchScopes: HKCU - {2F1E335A-858A-4BE9-8F6B-D0AF1D018B53} URL =
SearchScopes: HKCU - {5a1d0d31-749c-4186-a295-4106e6e7b26a} URL =
SearchScopes: HKCU - {9BAFBD72-7B94-4C12-B0C9-E8655CB66489} URL =
SearchScopes: HKCU - {a5b9c0f5-5616-47cd-a95f-e43b488faccf} URL =
SearchScopes: HKCU - {cca2e567-1987-4100-a3c6-5b4267084510} URL =
SearchScopes: HKCU - {EEE6C360-6118-11DC-9C72-001320C79847} URL =
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO-x32: BitComet Helper - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files (x86)\BitComet\tools\BitCometBHO_1.5.4.11.dll (BitComet)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
DPF: HKLM-x32 {15B782AF-55D8-11D1-B477-006097098764} http://download.macromedia.com/pub/shockwave/cabs/authorware/awswaxf.cab
DPF: HKLM-x32 {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: HKLM-x32 {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: HKLM-x32 {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: HKLM-x32 {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} https://support.dell.com/systemprofiler/SysProExe.CAB
DPF: HKLM-x32 {50647AB5-18FD-4142-82B0-5852478DD0D5} http://webeffective.keynote.com/applications/pconnector/download/ConnectorLauncher.cab
DPF: HKLM-x32 {682C59F5-478C-4421-9070-AD170D143B77} http://www.dell.com/support/troubleshooting/Content/Ode/pcd86.cab
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab
DPF: HKLM-x32 {A084A130-28AE-4B32-B51A-1C8CE164BC88} http://www.convergysworkathome.com/AppHardT.CAB
DPF: HKLM-x32 {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} http://www.superadblocker.com/activex/sabspx.cab
DPF: HKLM-x32 {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} http://support.dell.com/systemprofiler/DellSystemLite.CAB
DPF: HKLM-x32 {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.5.13.0.cab
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: HKLM-x32 {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} https://secure.logmein.com//activex/ractrl.cab?lmi=928
Winsock: Catalog5 01 %SystemRoot%\System32\mswsock.dll [232448] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5-x64 01 %SystemRoot%\System32\mswsock.dll [326144] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76

Chrome:
=======
CHR RestoreOnStartup:   "urls_to_restore_on_startup": null
CHR Extension: (Borowuse2saave) - C:\Users\Debbie\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgdhoilbkagbdmdikoemnekflnckiild\1
CHR Extension: (caOntuinueattousavve) - C:\Users\Debbie\AppData\Local\Google\Chrome\User Data\Default\Extensions\dnibnghfkdkigmifdkcfhogddoacjfhb\1
CHR Extension: (SSaafe save) - C:\Users\Debbie\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipkiolacmfobbnpfcncjammhhdaiodoa\1
CHR Extension: (continuetosuave) - C:\Users\Debbie\AppData\Local\Google\Chrome\User Data\Default\Extensions\nomaimloplecjccghpgifabkepbhibbd\1

==================== Services (Whitelisted) =================

R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22056 2013-01-27] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [379360 2013-01-27] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

S3 hitmanpro37; C:\Windows\system32\drivers\hitmanpro37.sys [32000 2013-06-24] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [230320 2013-01-20] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [130008 2013-01-20] (Microsoft Corporation)
S3 PCTDMDefrag; C:\Windows\system32\drivers\PCTDMDefrag.sys [162328 2011-02-04] (PC Tools)
S3 PCTDMDefrag; C:\Windows\system32\drivers\PCTDMDefrag.sys [162328 2011-02-04] (PC Tools)
S3 PCTDSMon; C:\Windows\system32\drivers\PCTDSMon.sys [189880 2011-02-04] (PC Tools)
S3 PCTDSMon; C:\Windows\system32\drivers\PCTDSMon.sys [189880 2011-02-04] (PC Tools)
S3 Serial; C:\Windows\system32\DRIVERS\serial.sys [94208 2009-07-13] (Brother Industries Ltd.)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
U4 Partizan; system32\drivers\Partizan.sys [x]

==================== NetSvcs (Whitelisted) ===================

==================== One Month Created Files and Folders ========

Error(0) reading file: "C:\Windows\System32\ "
2013-06-25 18:46 - 2013-06-25 18:46 - 00000000 ____D C:\FRST
2013-06-25 18:44 - 2013-06-25 18:45 - 01931844 ____A (Farbar) C:\Users\Debbie\Desktop\FRST64.exe
2013-06-25 18:44 - 2013-06-25 18:44 - 01370251 ____A (Farbar) C:\Users\Debbie\Desktop\FRST.exe
2013-06-25 14:34 - 2013-06-25 14:34 - 00000000 ____D C:\ProgramData\vsosdk
2013-06-25 14:00 - 2013-06-25 15:13 - 00001057 ____A C:\Users\Debbie\AppData\Roaming\vso_ts_preview.xml
2013-06-25 10:39 - 2013-06-25 10:39 - 00000000 ____D C:\Program Files (x86)\7-Zip
2013-06-25 10:08 - 2013-06-25 10:12 - 00000000 ___RD C:\Users\Debbie\Desktop\Bleeping Computers
2013-06-25 09:27 - 2013-06-25 09:27 - 00688992 ____A (Swearware) C:\Users\Debbie\Downloads\dds.com
2013-06-25 00:01 - 2013-06-25 00:01 - 00312232 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
2013-06-25 00:01 - 2013-06-25 00:01 - 00108968 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge-64.dll
2013-06-25 00:01 - 2013-06-25 00:00 - 00189352 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
2013-06-25 00:01 - 2013-06-25 00:00 - 00188840 ____A (Oracle Corporation) C:\Windows\System32\java.exe
2013-06-25 00:00 - 2013-06-25 00:00 - 00000000 ____D C:\Program Files\Java
2013-06-24 23:59 - 2013-06-24 23:59 - 00263592 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-06-24 23:59 - 2013-06-24 23:59 - 00175016 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-06-24 23:59 - 2013-06-24 23:59 - 00175016 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-06-24 23:59 - 2013-06-24 23:59 - 00096168 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-06-24 23:59 - 2013-06-24 23:59 - 00000000 ____D C:\Program Files (x86)\Java
2013-06-24 22:58 - 2013-06-24 22:58 - 00144578 ____A C:\Users\Debbie\Documents\Firewall Rules.reg
2013-06-24 08:39 - 2013-06-24 08:39 - 00000000 ____D C:\Users\Debbie\AppData\Roaming\8Floor
2013-06-24 05:06 - 2013-06-24 05:06 - 00000000 ____D C:\Users\Debbie\AppData\Roaming\Chayowo Games
2013-06-24 03:11 - 2013-06-24 03:11 - 00031151 ____A C:\ComboFix.txt
2013-06-24 02:42 - 2013-06-24 03:12 - 00000000 ____D C:\Qoobox
2013-06-24 02:42 - 2013-06-24 03:07 - 00000000 ____D C:\Windows\erdnt
2013-06-24 02:42 - 2011-06-25 23:45 - 00256000 ____A C:\Windows\PEV.exe
2013-06-24 02:42 - 2010-11-07 10:20 - 00208896 ____A C:\Windows\MBR.exe
2013-06-24 02:42 - 2009-04-19 21:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe
2013-06-24 02:42 - 2000-08-30 17:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe
2013-06-24 02:42 - 2000-08-30 17:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe
2013-06-24 02:42 - 2000-08-30 17:00 - 00098816 ____A C:\Windows\sed.exe
2013-06-24 02:42 - 2000-08-30 17:00 - 00080412 ____A C:\Windows\grep.exe
2013-06-24 02:42 - 2000-08-30 17:00 - 00068096 ____A C:\Windows\zip.exe
2013-06-24 02:05 - 2013-06-24 02:05 - 00032000 ____A C:\Windows\System32\Drivers\hitmanpro37.sys
2013-06-23 08:41 - 2013-06-23 08:41 - 00000000 ____D C:\Program Files (x86)\VSO
2013-06-23 08:41 - 2009-09-02 13:44 - 01184984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wvc1dmod.dll
2013-06-23 08:41 - 2009-09-02 13:44 - 00626688 ____A (On2.com) C:\Windows\SysWOW64\vp7vfw.dll
2013-06-23 08:41 - 2009-09-02 13:44 - 00217127 ____A (RealNetworks, Inc.) C:\Windows\SysWOW64\drv43260.dll
2013-06-23 08:41 - 2009-09-02 13:44 - 00208935 ____A (RealNetworks, Inc.) C:\Windows\SysWOW64\drv33260.dll
2013-06-23 08:41 - 2009-09-02 13:44 - 00176165 ____A (RealNetworks, Inc.) C:\Windows\SysWOW64\drv23260.dll
2013-06-23 08:41 - 2009-09-02 13:44 - 00102439 ____A (RealNetworks, Inc.) C:\Windows\SysWOW64\sipr3260.dll
2013-06-23 08:41 - 2009-09-02 13:44 - 00065602 ____A (RealNetworks, Inc.) C:\Windows\SysWOW64\cook3260.dll
2013-06-22 18:24 - 2013-06-22 18:24 - 00082816 ____A (VSO Software) C:\Users\Debbie\AppData\Roaming\pcouffin.sys
2013-06-22 18:24 - 2013-06-22 18:24 - 00007859 ____A C:\Users\Debbie\AppData\Roaming\pcouffin.cat
2013-06-22 18:24 - 2013-06-22 18:24 - 00000055 ____A C:\Users\Debbie\AppData\Roaming\pcouffin.log
2013-06-22 01:38 - 2013-06-25 14:03 - 00000000 ____D C:\Users\Debbie\Documents\ConvertXToDVD
2013-06-22 01:14 - 2013-06-25 15:13 - 00000000 ____D C:\Users\Debbie\AppData\Roaming\Vso
2013-06-22 00:59 - 2013-06-24 00:40 - 00000000 ____D C:\Program Files (x86)\Total Video Converter
2013-06-21 23:31 - 2013-06-21 23:43 - 00001913 ____A C:\Users\Debbie\Desktop\HL.The Curse of Vox.CE.lnk
2013-06-21 23:14 - 2013-06-21 23:14 - 00000000 ____D C:\Users\Debbie\My Backup Files
2013-06-21 02:11 - 2013-06-21 02:11 - 00042297 ____A C:\Windows\System32\uninstall.exe
2013-06-21 01:20 - 2007-08-31 18:36 - 00036864 ____A (Robdogg Inc.) C:\Windows\SysWOW64\trayicon_handler.ocx
2013-06-21 01:20 - 2003-01-26 13:41 - 00040960 ____A (vbAccelerator) C:\Windows\SysWOW64\ssubtmr6.dll
2013-06-21 00:28 - 2013-06-21 00:28 - 00001032 ____A C:\Users\Public\Desktop\VLC media player.lnk
2013-06-20 23:17 - 2013-06-20 23:17 - 00007666 ____A C:\Users\Debbie\AppData\Local\Resmon.ResmonCfg
2013-06-20 22:43 - 2013-06-22 01:34 - 00214104 ____A C:\Users\Debbie\AppData\Local\GDIPFONTCACHEV1.DAT
2013-06-20 08:00 - 2013-06-20 08:00 - 00002490 ____A C:\Users\Debbie\Desktop\Untold History - Descendant of the Sun Collector's Edition.lnk
2013-06-20 07:58 - 2013-06-20 08:00 - 00000000 ____D C:\Program Files (x86)\Untold History - Descendant of the Sun Collector's Edition
2013-06-20 07:58 - 2013-06-20 07:58 - 00000000 ____D C:\Windows\Untold History - Descendant of the Sun Collector's Edition
2013-06-19 22:26 - 2013-06-19 22:26 - 00000000 ____D C:\Users\Debbie\AppData\Local\{809AD72F-4679-4540-89ED-B9C986E67D80}
2013-06-19 21:08 - 2013-06-19 21:08 - 00000000 ____D C:\Users\Debbie\AppData\Local\{AA6B9902-7033-47E7-BAEA-BC1BD1AC8A70}
2013-06-14 03:03 - 2013-05-16 21:05 - 17824768 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-14 03:03 - 2013-05-16 20:27 - 10926080 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-14 03:03 - 2013-05-16 20:09 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-06-14 03:03 - 2013-05-16 20:02 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-06-14 03:03 - 2013-05-16 20:02 - 01346560 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-14 03:03 - 2013-05-16 20:01 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2013-06-14 03:03 - 2013-05-16 20:00 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2013-06-14 03:03 - 2013-05-16 19:58 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-06-14 03:03 - 2013-05-16 19:56 - 00599040 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2013-06-14 03:03 - 2013-05-16 19:56 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2013-06-14 03:03 - 2013-05-16 19:55 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-06-14 03:03 - 2013-05-16 19:54 - 00729088 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-06-14 03:03 - 2013-05-16 19:53 - 02147840 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-14 03:03 - 2013-05-16 19:51 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-14 03:03 - 2013-05-16 19:51 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2013-06-14 03:03 - 2013-05-16 19:46 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-06-14 03:03 - 2013-05-16 16:08 - 12329984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-06-14 03:03 - 2013-05-16 15:49 - 09738752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-06-14 03:03 - 2013-05-16 15:39 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-06-14 03:03 - 2013-05-16 15:28 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-06-14 03:03 - 2013-05-16 15:28 - 01104384 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-06-14 03:03 - 2013-05-16 15:27 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-06-14 03:03 - 2013-05-16 15:26 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-06-14 03:03 - 2013-05-16 15:23 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-06-14 03:03 - 2013-05-16 15:21 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-06-14 03:03 - 2013-05-16 15:21 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-06-14 03:03 - 2013-05-16 15:20 - 00420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-06-14 03:03 - 2013-05-16 15:19 - 00607744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-06-14 03:03 - 2013-05-16 15:17 - 01796096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-06-14 03:03 - 2013-05-16 15:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-06-14 03:03 - 2013-05-16 15:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-06-14 03:03 - 2013-05-16 15:12 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-06-13 20:55 - 2013-06-13 20:55 - 00000000 ____D C:\Users\Debbie\AppData\Roaming\4 Friends Games
2013-06-13 20:31 - 2013-06-13 20:31 - 00001929 ____A C:\Users\Debbie\Desktop\Living Legends 2. Frozen Beauty.lnk
2013-06-13 19:57 - 2013-05-09 22:49 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll
2013-06-13 19:57 - 2013-05-09 20:20 - 00024576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
2013-06-13 19:57 - 2013-05-07 23:39 - 01910632 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-06-13 19:57 - 2013-04-25 22:51 - 00751104 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2013-06-13 19:57 - 2013-04-25 21:55 - 00492544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2013-06-13 19:57 - 2013-04-17 00:02 - 01230336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2013-06-13 19:57 - 2013-04-16 23:24 - 01424384 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll
2013-06-13 19:56 - 2013-05-12 22:51 - 01464320 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2013-06-13 19:56 - 2013-05-12 22:51 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2013-06-13 19:56 - 2013-05-12 22:51 - 00139776 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2013-06-13 19:56 - 2013-05-12 22:50 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll
2013-06-13 19:56 - 2013-05-12 21:45 - 01160192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-06-13 19:56 - 2013-05-12 21:45 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-06-13 19:56 - 2013-05-12 21:45 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-06-13 19:56 - 2013-05-12 20:43 - 01192448 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe
2013-06-13 19:56 - 2013-05-12 20:08 - 00903168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2013-06-13 19:56 - 2013-05-12 20:08 - 00043008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
2013-06-13 19:56 - 2013-04-25 16:30 - 01505280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2013-06-13 19:56 - 2013-03-31 15:52 - 01887232 ____A (Microsoft Corporation) C:\Windows\System32\d3d11.dll
2013-06-12 17:49 - 2013-06-12 17:49 - 00000000 ____D C:\Users\Debbie\AppData\Roaming\Deep Shadows
2013-06-12 17:43 - 2013-06-13 19:45 - 00000000 ____D C:\Program Files (x86)\Big City Adventure 8 - Tokyo
2013-06-12 17:41 - 2013-06-13 20:29 - 00000000 ____D C:\Games
2013-06-12 02:33 - 2013-06-22 22:35 - 00000000 ____D C:\Users\Debbie\AppData\Roaming\ERS Game Studios
2013-06-08 14:48 - 2013-06-08 14:48 - 00000000 ____A C:\autoexec.bat
2013-06-07 20:20 - 2013-06-19 22:27 - 00000000 ____D C:\Users\Debbie\Documents\image_jpeg - Gmail_files
2013-06-07 20:20 - 2013-06-07 20:20 - 00000410 ____A C:\Users\Debbie\Documents\image_jpeg - Gmail.htm
2013-06-05 14:03 - 2013-06-05 14:03 - 00023483 ____A C:\Users\Debbie\Documents\Comcast Pmt 6-5-13.htm
2013-06-04 07:42 - 2013-06-21 23:29 - 00000000 ____D C:\Dizzy-Games
2013-05-29 10:25 - 2013-05-29 10:25 - 00020803 ____A C:\Users\Debbie\Documents\theCatalog Checkout Order Confirmation_do.htm
2013-05-27 03:24 - 2013-05-27 03:24 - 00000000 ____D C:\Users\Debbie\AppData\Roaming\Big Top Games
2013-05-27 03:03 - 2013-05-27 03:03 - 00000000 ____D C:\Users\Debbie\AppData\Roaming\Blue Tea Games

==================== One Month Modified Files and Folders =======

2013-06-25 18:46 - 2013-06-25 18:46 - 00000000 ____D C:\FRST
2013-06-25 18:45 - 2013-06-25 18:44 - 01931844 ____A (Farbar) C:\Users\Debbie\Desktop\FRST64.exe
2013-06-25 18:44 - 2013-06-25 18:44 - 01370251 ____A (Farbar) C:\Users\Debbie\Desktop\FRST.exe
2013-06-25 18:44 - 2012-04-08 19:06 - 00000000 ____D C:\Users\Debbie\AppData\Roaming\BitComet
2013-06-25 18:13 - 2012-04-08 21:23 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-06-25 18:11 - 2012-04-16 19:55 - 00000898 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-06-25 15:13 - 2013-06-25 14:00 - 00001057 ____A C:\Users\Debbie\AppData\Roaming\vso_ts_preview.xml
2013-06-25 15:13 - 2013-06-22 01:14 - 00000000 ____D C:\Users\Debbie\AppData\Roaming\Vso
2013-06-25 15:13 - 2012-04-09 10:23 - 00000000 ____D C:\Users\Debbie\AppData\Roaming\vlc
2013-06-25 14:44 - 2013-06-22 01:38 - 00000000 ____D C:\Users\Debbie\Documents\ConvertXToDVD
2013-06-25 14:34 - 2013-06-25 14:34 - 00000000 ____D C:\ProgramData\vsosdk
2013-06-25 11:30 - 2013-04-21 14:22 - 01577103 ____A C:\Windows\WindowsUpdate.log
2013-06-25 10:39 - 2013-06-25 10:39 - 00000000 ____D C:\Program Files (x86)\7-Zip
2013-06-25 10:18 - 2009-07-13 21:45 - 00013872 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-06-25 10:18 - 2009-07-13 21:45 - 00013872 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-06-25 10:12 - 2013-06-25 10:08 - 00000000 ___RD C:\Users\Debbie\Desktop\Bleeping Computers
2013-06-25 09:27 - 2013-06-25 09:27 - 00688992 ____A (Swearware) C:\Users\Debbie\Downloads\dds.com
2013-06-25 00:01 - 2013-06-25 00:01 - 00312232 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
2013-06-25 00:01 - 2013-06-25 00:01 - 00108968 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge-64.dll
2013-06-25 00:00 - 2013-06-25 00:01 - 00189352 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
2013-06-25 00:00 - 2013-06-25 00:01 - 00188840 ____A (Oracle Corporation) C:\Windows\System32\java.exe
2013-06-25 00:00 - 2013-06-25 00:00 - 00000000 ____D C:\Program Files\Java
2013-06-25 00:00 - 2012-07-08 02:00 - 01093032 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll
2013-06-25 00:00 - 2011-04-21 17:11 - 00972712 ____A (Oracle Corporation) C:\Windows\System32\deployJava1.dll
2013-06-24 23:59 - 2013-06-24 23:59 - 00263592 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-06-24 23:59 - 2013-06-24 23:59 - 00175016 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-06-24 23:59 - 2013-06-24 23:59 - 00175016 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-06-24 23:59 - 2013-06-24 23:59 - 00096168 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-06-24 23:59 - 2013-06-24 23:59 - 00000000 ____D C:\Program Files (x86)\Java
2013-06-24 23:59 - 2012-06-18 16:15 - 00867240 ____A (Oracle Corporation) C:\Windows\SysWOW64\npdeployJava1.dll
2013-06-24 23:59 - 2012-04-08 21:35 - 00789416 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2013-06-24 23:39 - 2012-12-15 03:43 - 00000000 ____D C:\Users\Default\AppData\Local\SoftThinks
2013-06-24 23:39 - 2012-12-15 03:43 - 00000000 ____D C:\Users\Default User\AppData\Local\SoftThinks
2013-06-24 23:39 - 2011-04-21 17:33 - 00000000 ____D C:\Program Files (x86)\Dell DataSafe Local Backup
2013-06-24 23:38 - 2009-07-13 22:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-06-24 23:37 - 2013-04-21 14:19 - 00002352 ____A C:\Windows\setupact.log
2013-06-24 22:58 - 2013-06-24 22:58 - 00144578 ____A C:\Users\Debbie\Documents\Firewall Rules.reg
2013-06-24 19:02 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\System32\NDF
2013-06-24 08:41 - 2012-04-08 22:10 - 00000000 ____D C:\HOGs
2013-06-24 08:40 - 2012-04-12 10:50 - 00000000 ___RD C:\Users\Debbie\Desktop\New HOGs
2013-06-24 08:39 - 2013-06-24 08:39 - 00000000 ____D C:\Users\Debbie\AppData\Roaming\8Floor
2013-06-24 08:13 - 2012-12-24 23:18 - 00000000 ___RD C:\Users\Debbie\Desktop\HOGs...in progress
2013-06-24 05:06 - 2013-06-24 05:06 - 00000000 ____D C:\Users\Debbie\AppData\Roaming\Chayowo Games
2013-06-24 03:17 - 2013-04-21 14:19 - 00035720 ____A C:\Windows\PFRO.log
2013-06-24 03:12 - 2013-06-24 02:42 - 00000000 ____D C:\Qoobox
2013-06-24 03:11 - 2013-06-24 03:11 - 00031151 ____A C:\ComboFix.txt
2013-06-24 03:07 - 2013-06-24 02:42 - 00000000 ____D C:\Windows\erdnt
2013-06-24 02:58 - 2009-07-13 19:34 - 00000215 ____A C:\Windows\system.ini
2013-06-24 02:05 - 2013-06-24 02:05 - 00032000 ____A C:\Windows\System32\Drivers\hitmanpro37.sys
2013-06-24 01:51 - 2009-07-13 22:13 - 00779764 ____A C:\Windows\System32\PerfStringBackup.INI
2013-06-24 01:24 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\registration
2013-06-24 01:05 - 2012-04-08 18:22 - 00002198 ____A C:\Windows\epplauncher.mif
2013-06-24 00:51 - 2009-07-13 16:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2013-06-24 00:40 - 2013-06-22 00:59 - 00000000 ____D C:\Program Files (x86)\Total Video Converter
2013-06-23 08:41 - 2013-06-23 08:41 - 00000000 ____D C:\Program Files (x86)\VSO
2013-06-23 08:33 - 2013-01-13 16:41 - 00703720 ____A C:\Windows\System32\FNTCACHE.DAT
2013-06-22 22:35 - 2013-06-12 02:33 - 00000000 ____D C:\Users\Debbie\AppData\Roaming\ERS Game Studios
2013-06-22 18:24 - 2013-06-22 18:24 - 00082816 ____A (VSO Software) C:\Users\Debbie\AppData\Roaming\pcouffin.sys
2013-06-22 18:24 - 2013-06-22 18:24 - 00007859 ____A C:\Users\Debbie\AppData\Roaming\pcouffin.cat
2013-06-22 18:24 - 2013-06-22 18:24 - 00000055 ____A C:\Users\Debbie\AppData\Roaming\pcouffin.log
2013-06-22 01:34 - 2013-06-20 22:43 - 00214104 ____A C:\Users\Debbie\AppData\Local\GDIPFONTCACHEV1.DAT
2013-06-22 00:17 - 2012-04-08 18:22 - 00773980 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2013-06-21 23:43 - 2013-06-21 23:31 - 00001913 ____A C:\Users\Debbie\Desktop\HL.The Curse of Vox.CE.lnk
2013-06-21 23:29 - 2013-06-04 07:42 - 00000000 ____D C:\Dizzy-Games
2013-06-21 23:14 - 2013-06-21 23:14 - 00000000 ____D C:\Users\Debbie\My Backup Files
2013-06-21 23:14 - 2012-04-08 13:57 - 00000000 ____D C:\users\Debbie
2013-06-21 02:11 - 2013-06-21 02:11 - 00042297 ____A C:\Windows\System32\uninstall.exe
2013-06-21 00:28 - 2013-06-21 00:28 - 00001032 ____A C:\Users\Public\Desktop\VLC media player.lnk
2013-06-20 23:17 - 2013-06-20 23:17 - 00007666 ____A C:\Users\Debbie\AppData\Local\Resmon.ResmonCfg
2013-06-20 22:32 - 2012-04-08 13:59 - 00000000 ____D C:\Users\Debbie\AppData\Local\VirtualStore
2013-06-20 08:00 - 2013-06-20 08:00 - 00002490 ____A C:\Users\Debbie\Desktop\Untold History - Descendant of the Sun Collector's Edition.lnk
2013-06-20 08:00 - 2013-06-20 07:58 - 00000000 ____D C:\Program Files (x86)\Untold History - Descendant of the Sun Collector's Edition
2013-06-20 07:58 - 2013-06-20 07:58 - 00000000 ____D C:\Windows\Untold History - Descendant of the Sun Collector's Edition
2013-06-19 22:27 - 2013-06-07 20:20 - 00000000 ____D C:\Users\Debbie\Documents\image_jpeg - Gmail_files
2013-06-19 22:27 - 2013-05-24 09:11 - 00000000 ____D C:\Users\Debbie\Documents\ShowOrder_files
2013-06-19 22:26 - 2013-06-19 22:26 - 00000000 ____D C:\Users\Debbie\AppData\Local\{809AD72F-4679-4540-89ED-B9C986E67D80}
2013-06-19 21:08 - 2013-06-19 21:08 - 00000000 ____D C:\Users\Debbie\AppData\Local\{AA6B9902-7033-47E7-BAEA-BC1BD1AC8A70}
2013-06-14 03:58 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\rescache
2013-06-14 03:01 - 2012-04-09 08:55 - 75825640 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-06-13 20:55 - 2013-06-13 20:55 - 00000000 ____D C:\Users\Debbie\AppData\Roaming\4 Friends Games
2013-06-13 20:37 - 2012-04-08 18:53 - 00000000 ____D C:\Program Files (x86)\SpywareBlaster
2013-06-13 20:31 - 2013-06-13 20:31 - 00001929 ____A C:\Users\Debbie\Desktop\Living Legends 2. Frozen Beauty.lnk
2013-06-13 20:29 - 2013-06-12 17:41 - 00000000 ____D C:\Games
2013-06-13 20:13 - 2012-04-08 21:23 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-06-13 20:13 - 2012-04-08 21:23 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-06-13 19:46 - 2013-01-09 05:21 - 00000000 ____D C:\Windows\SysWOW64\3054
2013-06-13 19:46 - 2012-04-08 21:23 - 00000000 ____D C:\Windows\System32\Macromed
2013-06-13 19:45 - 2013-06-12 17:43 - 00000000 ____D C:\Program Files (x86)\Big City Adventure 8 - Tokyo
2013-06-13 19:45 - 2009-07-13 20:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2013-06-12 17:49 - 2013-06-12 17:49 - 00000000 ____D C:\Users\Debbie\AppData\Roaming\Deep Shadows
2013-06-12 11:15 - 2012-04-08 21:26 - 00000000 ____D C:\Users\Debbie\AppData\Local\Adobe
2013-06-08 14:48 - 2013-06-08 14:48 - 00000000 ____A C:\autoexec.bat
2013-06-07 20:20 - 2013-06-07 20:20 - 00000410 ____A C:\Users\Debbie\Documents\image_jpeg - Gmail.htm
2013-06-05 22:02 - 2012-11-02 15:39 - 00000000 ____D C:\MrFood Cookbooks
2013-06-05 14:03 - 2013-06-05 14:03 - 00023483 ____A C:\Users\Debbie\Documents\Comcast Pmt 6-5-13.htm
2013-06-02 19:40 - 2012-11-28 17:29 - 00000000 ____D C:\Users\Debbie\AppData\Roaming\dvdcss
2013-05-29 10:25 - 2013-05-29 10:25 - 00020803 ____A C:\Users\Debbie\Documents\theCatalog Checkout Order Confirmation_do.htm
2013-05-27 03:24 - 2013-05-27 03:24 - 00000000 ____D C:\Users\Debbie\AppData\Roaming\Big Top Games
2013-05-27 03:03 - 2013-05-27 03:03 - 00000000 ____D C:\Users\Debbie\AppData\Roaming\Blue Tea Games

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

LastRegBack: 2013-06-23 00:58

==================== End Of Log ============================

 

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-06-2013 02
Ran by Debbie (administrator) on 25-06-2013 18:47:01
Running from C:\Users\Debbie\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US)
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(Protexis Inc.) c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(SoftThinks SAS) C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe
(Atheros) C:\Program Files (x86)\Atheros\AWiCMgr.exe
(Microsoft Corporation) C:\Program Files\Microsoft IntelliPoint\ipoint.exe
(Intel Corporation) C:\WINDOWS\System32\igfxtray.exe
(Intel Corporation) C:\WINDOWS\System32\hkcmd.exe
(Intel Corporation) C:\WINDOWS\System32\igfxpers.exe
(SoftThinks - Dell) C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE
(www.BitComet.com) C:\Program Files (x86)\BitComet\BitComet.exe
() C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE
(Google Inc.) C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
(Microsoft Corporation) C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apntex.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\HidFind.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MpCmdRun.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe [392048 2010-06-04] (Alps Electric Co., Ltd.)
HKLM\...\Run: [AWiC] "C:\Program Files (x86)\Atheros\AWiCMgr.exe" -nogui [167936 2010-09-11] (Atheros)
HKLM\...\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2417032 2011-08-01] (Microsoft Corporation)
HKCU\...\Run: [BitComet] "C:\Program Files (x86)\BitComet\BitComet.exe" /tray [12805888 2013-02-19] (www.BitComet.com)
HKCU\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2012-08-23] (Google Inc.)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [253816 2013-03-12] (Oracle Corporation)
BootExecute:

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
HKLM-x32 SearchScopes: DefaultScope {6CE2F86E-11D5-474D-8190-095E6F2B66A5} URL =
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - {110a9ea2-8810-4c04-b916-cfd4e9427fec} URL = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?p2=^ZX^xdm039^YY^us&si=radiopi&ptb=160C0F77-45F9-44E3-A819-17095ED21E35&ind=2013012018&n=77fc2032&psa=&st=sb&searchfor={searchTerms}
SearchScopes: HKLM-x32 - {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://start.sweetpacks.com/?src=6&q={searchTerms}&st=12&crg=3.5000006.10042&barid={6C0043D1-9D81-11E2-AA34-FF36774A7524}
SearchScopes: HKCU - {110a9ea2-8810-4c04-b916-cfd4e9427fec} URL = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?p2=^ZX^xdm039^YY^us&si=radiopi&ptb=160C0F77-45F9-44E3-A819-17095ED21E35&ind=2013012018&n=77fc2032&psa=&st=sb&searchfor={searchTerms}
SearchScopes: HKCU - {2F1E335A-858A-4BE9-8F6B-D0AF1D018B53} URL =
SearchScopes: HKCU - {5a1d0d31-749c-4186-a295-4106e6e7b26a} URL =
SearchScopes: HKCU - {9BAFBD72-7B94-4C12-B0C9-E8655CB66489} URL =
SearchScopes: HKCU - {a5b9c0f5-5616-47cd-a95f-e43b488faccf} URL =
SearchScopes: HKCU - {cca2e567-1987-4100-a3c6-5b4267084510} URL =
SearchScopes: HKCU - {EEE6C360-6118-11DC-9C72-001320C79847} URL =
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO-x32: BitComet Helper - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files (x86)\BitComet\tools\BitCometBHO_1.5.4.11.dll (BitComet)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
DPF: HKLM-x32 {15B782AF-55D8-11D1-B477-006097098764} http://download.macromedia.com/pub/shockwave/cabs/authorware/awswaxf.cab
DPF: HKLM-x32 {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: HKLM-x32 {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: HKLM-x32 {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: HKLM-x32 {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} https://support.dell.com/systemprofiler/SysProExe.CAB
DPF: HKLM-x32 {50647AB5-18FD-4142-82B0-5852478DD0D5} http://webeffective.keynote.com/applications/pconnector/download/ConnectorLauncher.cab
DPF: HKLM-x32 {682C59F5-478C-4421-9070-AD170D143B77} http://www.dell.com/support/troubleshooting/Content/Ode/pcd86.cab
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab
DPF: HKLM-x32 {A084A130-28AE-4B32-B51A-1C8CE164BC88} http://www.convergysworkathome.com/AppHardT.CAB
DPF: HKLM-x32 {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} http://www.superadblocker.com/activex/sabspx.cab
DPF: HKLM-x32 {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} http://support.dell.com/systemprofiler/DellSystemLite.CAB
DPF: HKLM-x32 {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.5.13.0.cab
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: HKLM-x32 {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} https://secure.logmein.com//activex/ractrl.cab?lmi=928
Winsock: Catalog5 01 %SystemRoot%\System32\mswsock.dll [232448] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5-x64 01 %SystemRoot%\System32\mswsock.dll [326144] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76

Chrome:
=======
CHR RestoreOnStartup:   "urls_to_restore_on_startup": null
CHR Extension: (Borowuse2saave) - C:\Users\Debbie\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgdhoilbkagbdmdikoemnekflnckiild\1
CHR Extension: (caOntuinueattousavve) - C:\Users\Debbie\AppData\Local\Google\Chrome\User Data\Default\Extensions\dnibnghfkdkigmifdkcfhogddoacjfhb\1
CHR Extension: (SSaafe save) - C:\Users\Debbie\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipkiolacmfobbnpfcncjammhhdaiodoa\1
CHR Extension: (continuetosuave) - C:\Users\Debbie\AppData\Local\Google\Chrome\User Data\Default\Extensions\nomaimloplecjccghpgifabkepbhibbd\1

==================== Services (Whitelisted) =================

R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22056 2013-01-27] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [379360 2013-01-27] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

S3 hitmanpro37; C:\Windows\system32\drivers\hitmanpro37.sys [32000 2013-06-24] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [230320 2013-01-20] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [130008 2013-01-20] (Microsoft Corporation)
S3 PCTDMDefrag; C:\Windows\system32\drivers\PCTDMDefrag.sys [162328 2011-02-04] (PC Tools)
S3 PCTDMDefrag; C:\Windows\system32\drivers\PCTDMDefrag.sys [162328 2011-02-04] (PC Tools)
S3 PCTDSMon; C:\Windows\system32\drivers\PCTDSMon.sys [189880 2011-02-04] (PC Tools)
S3 PCTDSMon; C:\Windows\system32\drivers\PCTDSMon.sys [189880 2011-02-04] (PC Tools)
S3 Serial; C:\Windows\system32\DRIVERS\serial.sys [94208 2009-07-13] (Brother Industries Ltd.)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
U4 Partizan; system32\drivers\Partizan.sys [x]

==================== NetSvcs (Whitelisted) ===================

==================== One Month Created Files and Folders ========

Error(0) reading file: "C:\Windows\System32\ "
2013-06-25 18:46 - 2013-06-25 18:46 - 00000000 ____D C:\FRST
2013-06-25 18:44 - 2013-06-25 18:45 - 01931844 ____A (Farbar) C:\Users\Debbie\Desktop\FRST64.exe
2013-06-25 18:44 - 2013-06-25 18:44 - 01370251 ____A (Farbar) C:\Users\Debbie\Desktop\FRST.exe
2013-06-25 14:34 - 2013-06-25 14:34 - 00000000 ____D C:\ProgramData\vsosdk
2013-06-25 14:00 - 2013-06-25 15:13 - 00001057 ____A C:\Users\Debbie\AppData\Roaming\vso_ts_preview.xml
2013-06-25 10:39 - 2013-06-25 10:39 - 00000000 ____D C:\Program Files (x86)\7-Zip
2013-06-25 10:08 - 2013-06-25 10:12 - 00000000 ___RD C:\Users\Debbie\Desktop\Bleeping Computers
2013-06-25 09:27 - 2013-06-25 09:27 - 00688992 ____A (Swearware) C:\Users\Debbie\Downloads\dds.com
2013-06-25 00:01 - 2013-06-25 00:01 - 00312232 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
2013-06-25 00:01 - 2013-06-25 00:01 - 00108968 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge-64.dll
2013-06-25 00:01 - 2013-06-25 00:00 - 00189352 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
2013-06-25 00:01 - 2013-06-25 00:00 - 00188840 ____A (Oracle Corporation) C:\Windows\System32\java.exe
2013-06-25 00:00 - 2013-06-25 00:00 - 00000000 ____D C:\Program Files\Java
2013-06-24 23:59 - 2013-06-24 23:59 - 00263592 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-06-24 23:59 - 2013-06-24 23:59 - 00175016 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-06-24 23:59 - 2013-06-24 23:59 - 00175016 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-06-24 23:59 - 2013-06-24 23:59 - 00096168 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-06-24 23:59 - 2013-06-24 23:59 - 00000000 ____D C:\Program Files (x86)\Java
2013-06-24 22:58 - 2013-06-24 22:58 - 00144578 ____A C:\Users\Debbie\Documents\Firewall Rules.reg
2013-06-24 08:39 - 2013-06-24 08:39 - 00000000 ____D C:\Users\Debbie\AppData\Roaming\8Floor
2013-06-24 05:06 - 2013-06-24 05:06 - 00000000 ____D C:\Users\Debbie\AppData\Roaming\Chayowo Games
2013-06-24 03:11 - 2013-06-24 03:11 - 00031151 ____A C:\ComboFix.txt
2013-06-24 02:42 - 2013-06-24 03:12 - 00000000 ____D C:\Qoobox
2013-06-24 02:42 - 2013-06-24 03:07 - 00000000 ____D C:\Windows\erdnt
2013-06-24 02:42 - 2011-06-25 23:45 - 00256000 ____A C:\Windows\PEV.exe
2013-06-24 02:42 - 2010-11-07 10:20 - 00208896 ____A C:\Windows\MBR.exe
2013-06-24 02:42 - 2009-04-19 21:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe
2013-06-24 02:42 - 2000-08-30 17:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe
2013-06-24 02:42 - 2000-08-30 17:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe
2013-06-24 02:42 - 2000-08-30 17:00 - 00098816 ____A C:\Windows\sed.exe
2013-06-24 02:42 - 2000-08-30 17:00 - 00080412 ____A C:\Windows\grep.exe
2013-06-24 02:42 - 2000-08-30 17:00 - 00068096 ____A C:\Windows\zip.exe
2013-06-24 02:05 - 2013-06-24 02:05 - 00032000 ____A C:\Windows\System32\Drivers\hitmanpro37.sys
2013-06-23 08:41 - 2013-06-23 08:41 - 00000000 ____D C:\Program Files (x86)\VSO
2013-06-23 08:41 - 2009-09-02 13:44 - 01184984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wvc1dmod.dll
2013-06-23 08:41 - 2009-09-02 13:44 - 00626688 ____A (On2.com) C:\Windows\SysWOW64\vp7vfw.dll
2013-06-23 08:41 - 2009-09-02 13:44 - 00217127 ____A (RealNetworks, Inc.) C:\Windows\SysWOW64\drv43260.dll
2013-06-23 08:41 - 2009-09-02 13:44 - 00208935 ____A (RealNetworks, Inc.) C:\Windows\SysWOW64\drv33260.dll
2013-06-23 08:41 - 2009-09-02 13:44 - 00176165 ____A (RealNetworks, Inc.) C:\Windows\SysWOW64\drv23260.dll
2013-06-23 08:41 - 2009-09-02 13:44 - 00102439 ____A (RealNetworks, Inc.) C:\Windows\SysWOW64\sipr3260.dll
2013-06-23 08:41 - 2009-09-02 13:44 - 00065602 ____A (RealNetworks, Inc.) C:\Windows\SysWOW64\cook3260.dll
2013-06-22 18:24 - 2013-06-22 18:24 - 00082816 ____A (VSO Software) C:\Users\Debbie\AppData\Roaming\pcouffin.sys
2013-06-22 18:24 - 2013-06-22 18:24 - 00007859 ____A C:\Users\Debbie\AppData\Roaming\pcouffin.cat
2013-06-22 18:24 - 2013-06-22 18:24 - 00000055 ____A C:\Users\Debbie\AppData\Roaming\pcouffin.log
2013-06-22 01:38 - 2013-06-25 14:03 - 00000000 ____D C:\Users\Debbie\Documents\ConvertXToDVD
2013-06-22 01:14 - 2013-06-25 15:13 - 00000000 ____D C:\Users\Debbie\AppData\Roaming\Vso
2013-06-22 00:59 - 2013-06-24 00:40 - 00000000 ____D C:\Program Files (x86)\Total Video Converter
2013-06-21 23:31 - 2013-06-21 23:43 - 00001913 ____A C:\Users\Debbie\Desktop\HL.The Curse of Vox.CE.lnk
2013-06-21 23:14 - 2013-06-21 23:14 - 00000000 ____D C:\Users\Debbie\My Backup Files
2013-06-21 02:11 - 2013-06-21 02:11 - 00042297 ____A C:\Windows\System32\uninstall.exe
2013-06-21 01:20 - 2007-08-31 18:36 - 00036864 ____A (Robdogg Inc.) C:\Windows\SysWOW64\trayicon_handler.ocx
2013-06-21 01:20 - 2003-01-26 13:41 - 00040960 ____A (vbAccelerator) C:\Windows\SysWOW64\ssubtmr6.dll
2013-06-21 00:28 - 2013-06-21 00:28 - 00001032 ____A C:\Users\Public\Desktop\VLC media player.lnk
2013-06-20 23:17 - 2013-06-20 23:17 - 00007666 ____A C:\Users\Debbie\AppData\Local\Resmon.ResmonCfg
2013-06-20 22:43 - 2013-06-22 01:34 - 00214104 ____A C:\Users\Debbie\AppData\Local\GDIPFONTCACHEV1.DAT
2013-06-20 08:00 - 2013-06-20 08:00 - 00002490 ____A C:\Users\Debbie\Desktop\Untold History - Descendant of the Sun Collector's Edition.lnk
2013-06-20 07:58 - 2013-06-20 08:00 - 00000000 ____D C:\Program Files (x86)\Untold History - Descendant of the Sun Collector's Edition
2013-06-20 07:58 - 2013-06-20 07:58 - 00000000 ____D C:\Windows\Untold History - Descendant of the Sun Collector's Edition
2013-06-19 22:26 - 2013-06-19 22:26 - 00000000 ____D C:\Users\Debbie\AppData\Local\{809AD72F-4679-4540-89ED-B9C986E67D80}
2013-06-19 21:08 - 2013-06-19 21:08 - 00000000 ____D C:\Users\Debbie\AppData\Local\{AA6B9902-7033-47E7-BAEA-BC1BD1AC8A70}
2013-06-14 03:03 - 2013-05-16 21:05 - 17824768 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-14 03:03 - 2013-05-16 20:27 - 10926080 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-14 03:03 - 2013-05-16 20:09 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-06-14 03:03 - 2013-05-16 20:02 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-06-14 03:03 - 2013-05-16 20:02 - 01346560 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-14 03:03 - 2013-05-16 20:01 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2013-06-14 03:03 - 2013-05-16 20:00 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2013-06-14 03:03 - 2013-05-16 19:58 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-06-14 03:03 - 2013-05-16 19:56 - 00599040 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2013-06-14 03:03 - 2013-05-16 19:56 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2013-06-14 03:03 - 2013-05-16 19:55 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-06-14 03:03 - 2013-05-16 19:54 - 00729088 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-06-14 03:03 - 2013-05-16 19:53 - 02147840 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-14 03:03 - 2013-05-16 19:51 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-14 03:03 - 2013-05-16 19:51 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2013-06-14 03:03 - 2013-05-16 19:46 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-06-14 03:03 - 2013-05-16 16:08 - 12329984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-06-14 03:03 - 2013-05-16 15:49 - 09738752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-06-14 03:03 - 2013-05-16 15:39 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-06-14 03:03 - 2013-05-16 15:28 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-06-14 03:03 - 2013-05-16 15:28 - 01104384 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-06-14 03:03 - 2013-05-16 15:27 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-06-14 03:03 - 2013-05-16 15:26 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-06-14 03:03 - 2013-05-16 15:23 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-06-14 03:03 - 2013-05-16 15:21 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-06-14 03:03 - 2013-05-16 15:21 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-06-14 03:03 - 2013-05-16 15:20 - 00420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-06-14 03:03 - 2013-05-16 15:19 - 00607744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-06-14 03:03 - 2013-05-16 15:17 - 01796096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-06-14 03:03 - 2013-05-16 15:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-06-14 03:03 - 2013-05-16 15:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-06-14 03:03 - 2013-05-16 15:12 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-06-13 20:55 - 2013-06-13 20:55 - 00000000 ____D C:\Users\Debbie\AppData\Roaming\4 Friends Games
2013-06-13 20:31 - 2013-06-13 20:31 - 00001929 ____A C:\Users\Debbie\Desktop\Living Legends 2. Frozen Beauty.lnk
2013-06-13 19:57 - 2013-05-09 22:49 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll
2013-06-13 19:57 - 2013-05-09 20:20 - 00024576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
2013-06-13 19:57 - 2013-05-07 23:39 - 01910632 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-06-13 19:57 - 2013-04-25 22:51 - 00751104 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2013-06-13 19:57 - 2013-04-25 21:55 - 00492544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2013-06-13 19:57 - 2013-04-17 00:02 - 01230336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2013-06-13 19:57 - 2013-04-16 23:24 - 01424384 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll
2013-06-13 19:56 - 2013-05-12 22:51 - 01464320 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2013-06-13 19:56 - 2013-05-12 22:51 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2013-06-13 19:56 - 2013-05-12 22:51 - 00139776 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2013-06-13 19:56 - 2013-05-12 22:50 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll
2013-06-13 19:56 - 2013-05-12 21:45 - 01160192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-06-13 19:56 - 2013-05-12 21:45 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-06-13 19:56 - 2013-05-12 21:45 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-06-13 19:56 - 2013-05-12 20:43 - 01192448 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe
2013-06-13 19:56 - 2013-05-12 20:08 - 00903168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2013-06-13 19:56 - 2013-05-12 20:08 - 00043008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
2013-06-13 19:56 - 2013-04-25 16:30 - 01505280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2013-06-13 19:56 - 2013-03-31 15:52 - 01887232 ____A (Microsoft Corporation) C:\Windows\System32\d3d11.dll
2013-06-12 17:49 - 2013-06-12 17:49 - 00000000 ____D C:\Users\Debbie\AppData\Roaming\Deep Shadows
2013-06-12 17:43 - 2013-06-13 19:45 - 00000000 ____D C:\Program Files (x86)\Big City Adventure 8 - Tokyo
2013-06-12 17:41 - 2013-06-13 20:29 - 00000000 ____D C:\Games
2013-06-12 02:33 - 2013-06-22 22:35 - 00000000 ____D C:\Users\Debbie\AppData\Roaming\ERS Game Studios
2013-06-08 14:48 - 2013-06-08 14:48 - 00000000 ____A C:\autoexec.bat
2013-06-07 20:20 - 2013-06-19 22:27 - 00000000 ____D C:\Users\Debbie\Documents\image_jpeg - Gmail_files
2013-06-07 20:20 - 2013-06-07 20:20 - 00000410 ____A C:\Users\Debbie\Documents\image_jpeg - Gmail.htm
2013-06-05 14:03 - 2013-06-05 14:03 - 00023483 ____A C:\Users\Debbie\Documents\Comcast Pmt 6-5-13.htm
2013-06-04 07:42 - 2013-06-21 23:29 - 00000000 ____D C:\Dizzy-Games
2013-05-29 10:25 - 2013-05-29 10:25 - 00020803 ____A C:\Users\Debbie\Documents\theCatalog Checkout Order Confirmation_do.htm
2013-05-27 03:24 - 2013-05-27 03:24 - 00000000 ____D C:\Users\Debbie\AppData\Roaming\Big Top Games
2013-05-27 03:03 - 2013-05-27 03:03 - 00000000 ____D C:\Users\Debbie\AppData\Roaming\Blue Tea Games

==================== One Month Modified Files and Folders =======

2013-06-25 18:46 - 2013-06-25 18:46 - 00000000 ____D C:\FRST
2013-06-25 18:45 - 2013-06-25 18:44 - 01931844 ____A (Farbar) C:\Users\Debbie\Desktop\FRST64.exe
2013-06-25 18:44 - 2013-06-25 18:44 - 01370251 ____A (Farbar) C:\Users\Debbie\Desktop\FRST.exe
2013-06-25 18:44 - 2012-04-08 19:06 - 00000000 ____D C:\Users\Debbie\AppData\Roaming\BitComet
2013-06-25 18:13 - 2012-04-08 21:23 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-06-25 18:11 - 2012-04-16 19:55 - 00000898 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-06-25 15:13 - 2013-06-25 14:00 - 00001057 ____A C:\Users\Debbie\AppData\Roaming\vso_ts_preview.xml
2013-06-25 15:13 - 2013-06-22 01:14 - 00000000 ____D C:\Users\Debbie\AppData\Roaming\Vso
2013-06-25 15:13 - 2012-04-09 10:23 - 00000000 ____D C:\Users\Debbie\AppData\Roaming\vlc
2013-06-25 14:44 - 2013-06-22 01:38 - 00000000 ____D C:\Users\Debbie\Documents\ConvertXToDVD
2013-06-25 14:34 - 2013-06-25 14:34 - 00000000 ____D C:\ProgramData\vsosdk
2013-06-25 11:30 - 2013-04-21 14:22 - 01577103 ____A C:\Windows\WindowsUpdate.log
2013-06-25 10:39 - 2013-06-25 10:39 - 00000000 ____D C:\Program Files (x86)\7-Zip
2013-06-25 10:18 - 2009-07-13 21:45 - 00013872 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-06-25 10:18 - 2009-07-13 21:45 - 00013872 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-06-25 10:12 - 2013-06-25 10:08 - 00000000 ___RD C:\Users\Debbie\Desktop\Bleeping Computers
2013-06-25 09:27 - 2013-06-25 09:27 - 00688992 ____A (Swearware) C:\Users\Debbie\Downloads\dds.com
2013-06-25 00:01 - 2013-06-25 00:01 - 00312232 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
2013-06-25 00:01 - 2013-06-25 00:01 - 00108968 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge-64.dll
2013-06-25 00:00 - 2013-06-25 00:01 - 00189352 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
2013-06-25 00:00 - 2013-06-25 00:01 - 00188840 ____A (Oracle Corporation) C:\Windows\System32\java.exe
2013-06-25 00:00 - 2013-06-25 00:00 - 00000000 ____D C:\Program Files\Java
2013-06-25 00:00 - 2012-07-08 02:00 - 01093032 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll
2013-06-25 00:00 - 2011-04-21 17:11 - 00972712 ____A (Oracle Corporation) C:\Windows\System32\deployJava1.dll
2013-06-24 23:59 - 2013-06-24 23:59 - 00263592 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-06-24 23:59 - 2013-06-24 23:59 - 00175016 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-06-24 23:59 - 2013-06-24 23:59 - 00175016 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-06-24 23:59 - 2013-06-24 23:59 - 00096168 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-06-24 23:59 - 2013-06-24 23:59 - 00000000 ____D C:\Program Files (x86)\Java
2013-06-24 23:59 - 2012-06-18 16:15 - 00867240 ____A (Oracle Corporation) C:\Windows\SysWOW64\npdeployJava1.dll
2013-06-24 23:59 - 2012-04-08 21:35 - 00789416 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2013-06-24 23:39 - 2012-12-15 03:43 - 00000000 ____D C:\Users\Default\AppData\Local\SoftThinks
2013-06-24 23:39 - 2012-12-15 03:43 - 00000000 ____D C:\Users\Default User\AppData\Local\SoftThinks
2013-06-24 23:39 - 2011-04-21 17:33 - 00000000 ____D C:\Program Files (x86)\Dell DataSafe Local Backup
2013-06-24 23:38 - 2009-07-13 22:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-06-24 23:37 - 2013-04-21 14:19 - 00002352 ____A C:\Windows\setupact.log
2013-06-24 22:58 - 2013-06-24 22:58 - 00144578 ____A C:\Users\Debbie\Documents\Firewall Rules.reg
2013-06-24 19:02 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\System32\NDF
2013-06-24 08:41 - 2012-04-08 22:10 - 00000000 ____D C:\HOGs
2013-06-24 08:40 - 2012-04-12 10:50 - 00000000 ___RD C:\Users\Debbie\Desktop\New HOGs
2013-06-24 08:39 - 2013-06-24 08:39 - 00000000 ____D C:\Users\Debbie\AppData\Roaming\8Floor
2013-06-24 08:13 - 2012-12-24 23:18 - 00000000 ___RD C:\Users\Debbie\Desktop\HOGs...in progress
2013-06-24 05:06 - 2013-06-24 05:06 - 00000000 ____D C:\Users\Debbie\AppData\Roaming\Chayowo Games
2013-06-24 03:17 - 2013-04-21 14:19 - 00035720 ____A C:\Windows\PFRO.log
2013-06-24 03:12 - 2013-06-24 02:42 - 00000000 ____D C:\Qoobox
2013-06-24 03:11 - 2013-06-24 03:11 - 00031151 ____A C:\ComboFix.txt
2013-06-24 03:07 - 2013-06-24 02:42 - 00000000 ____D C:\Windows\erdnt
2013-06-24 02:58 - 2009-07-13 19:34 - 00000215 ____A C:\Windows\system.ini
2013-06-24 02:05 - 2013-06-24 02:05 - 00032000 ____A C:\Windows\System32\Drivers\hitmanpro37.sys
2013-06-24 01:51 - 2009-07-13 22:13 - 00779764 ____A C:\Windows\System32\PerfStringBackup.INI
2013-06-24 01:24 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\registration
2013-06-24 01:05 - 2012-04-08 18:22 - 00002198 ____A C:\Windows\epplauncher.mif
2013-06-24 00:51 - 2009-07-13 16:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2013-06-24 00:40 - 2013-06-22 00:59 - 00000000 ____D C:\Program Files (x86)\Total Video Converter
2013-06-23 08:41 - 2013-06-23 08:41 - 00000000 ____D C:\Program Files (x86)\VSO
2013-06-23 08:33 - 2013-01-13 16:41 - 00703720 ____A C:\Windows\System32\FNTCACHE.DAT
2013-06-22 22:35 - 2013-06-12 02:33 - 00000000 ____D C:\Users\Debbie\AppData\Roaming\ERS Game Studios
2013-06-22 18:24 - 2013-06-22 18:24 - 00082816 ____A (VSO Software) C:\Users\Debbie\AppData\Roaming\pcouffin.sys
2013-06-22 18:24 - 2013-06-22 18:24 - 00007859 ____A C:\Users\Debbie\AppData\Roaming\pcouffin.cat
2013-06-22 18:24 - 2013-06-22 18:24 - 00000055 ____A C:\Users\Debbie\AppData\Roaming\pcouffin.log
2013-06-22 01:34 - 2013-06-20 22:43 - 00214104 ____A C:\Users\Debbie\AppData\Local\GDIPFONTCACHEV1.DAT
2013-06-22 00:17 - 2012-04-08 18:22 - 00773980 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2013-06-21 23:43 - 2013-06-21 23:31 - 00001913 ____A C:\Users\Debbie\Desktop\HL.The Curse of Vox.CE.lnk
2013-06-21 23:29 - 2013-06-04 07:42 - 00000000 ____D C:\Dizzy-Games
2013-06-21 23:14 - 2013-06-21 23:14 - 00000000 ____D C:\Users\Debbie\My Backup Files
2013-06-21 23:14 - 2012-04-08 13:57 - 00000000 ____D C:\users\Debbie
2013-06-21 02:11 - 2013-06-21 02:11 - 00042297 ____A C:\Windows\System32\uninstall.exe
2013-06-21 00:28 - 2013-06-21 00:28 - 00001032 ____A C:\Users\Public\Desktop\VLC media player.lnk
2013-06-20 23:17 - 2013-06-20 23:17 - 00007666 ____A C:\Users\Debbie\AppData\Local\Resmon.ResmonCfg
2013-06-20 22:32 - 2012-04-08 13:59 - 00000000 ____D C:\Users\Debbie\AppData\Local\VirtualStore
2013-06-20 08:00 - 2013-06-20 08:00 - 00002490 ____A C:\Users\Debbie\Desktop\Untold History - Descendant of the Sun Collector's Edition.lnk
2013-06-20 08:00 - 2013-06-20 07:58 - 00000000 ____D C:\Program Files (x86)\Untold History - Descendant of the Sun Collector's Edition
2013-06-20 07:58 - 2013-06-20 07:58 - 00000000 ____D C:\Windows\Untold History - Descendant of the Sun Collector's Edition
2013-06-19 22:27 - 2013-06-07 20:20 - 00000000 ____D C:\Users\Debbie\Documents\image_jpeg - Gmail_files
2013-06-19 22:27 - 2013-05-24 09:11 - 00000000 ____D C:\Users\Debbie\Documents\ShowOrder_files
2013-06-19 22:26 - 2013-06-19 22:26 - 00000000 ____D C:\Users\Debbie\AppData\Local\{809AD72F-4679-4540-89ED-B9C986E67D80}
2013-06-19 21:08 - 2013-06-19 21:08 - 00000000 ____D C:\Users\Debbie\AppData\Local\{AA6B9902-7033-47E7-BAEA-BC1BD1AC8A70}
2013-06-14 03:58 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\rescache
2013-06-14 03:01 - 2012-04-09 08:55 - 75825640 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-06-13 20:55 - 2013-06-13 20:55 - 00000000 ____D C:\Users\Debbie\AppData\Roaming\4 Friends Games
2013-06-13 20:37 - 2012-04-08 18:53 - 00000000 ____D C:\Program Files (x86)\SpywareBlaster
2013-06-13 20:31 - 2013-06-13 20:31 - 00001929 ____A C:\Users\Debbie\Desktop\Living Legends 2. Frozen Beauty.lnk
2013-06-13 20:29 - 2013-06-12 17:41 - 00000000 ____D C:\Games
2013-06-13 20:13 - 2012-04-08 21:23 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-06-13 20:13 - 2012-04-08 21:23 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-06-13 19:46 - 2013-01-09 05:21 - 00000000 ____D C:\Windows\SysWOW64\3054
2013-06-13 19:46 - 2012-04-08 21:23 - 00000000 ____D C:\Windows\System32\Macromed
2013-06-13 19:45 - 2013-06-12 17:43 - 00000000 ____D C:\Program Files (x86)\Big City Adventure 8 - Tokyo
2013-06-13 19:45 - 2009-07-13 20:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2013-06-12 17:49 - 2013-06-12 17:49 - 00000000 ____D C:\Users\Debbie\AppData\Roaming\Deep Shadows
2013-06-12 11:15 - 2012-04-08 21:26 - 00000000 ____D C:\Users\Debbie\AppData\Local\Adobe
2013-06-08 14:48 - 2013-06-08 14:48 - 00000000 ____A C:\autoexec.bat
2013-06-07 20:20 - 2013-06-07 20:20 - 00000410 ____A C:\Users\Debbie\Documents\image_jpeg - Gmail.htm
2013-06-05 22:02 - 2012-11-02 15:39 - 00000000 ____D C:\MrFood Cookbooks
2013-06-05 14:03 - 2013-06-05 14:03 - 00023483 ____A C:\Users\Debbie\Documents\Comcast Pmt 6-5-13.htm
2013-06-02 19:40 - 2012-11-28 17:29 - 00000000 ____D C:\Users\Debbie\AppData\Roaming\dvdcss
2013-05-29 10:25 - 2013-05-29 10:25 - 00020803 ____A C:\Users\Debbie\Documents\theCatalog Checkout Order Confirmation_do.htm
2013-05-27 03:24 - 2013-05-27 03:24 - 00000000 ____D C:\Users\Debbie\AppData\Roaming\Big Top Games
2013-05-27 03:03 - 2013-05-27 03:03 - 00000000 ____D C:\Users\Debbie\AppData\Roaming\Blue Tea Games

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

LastRegBack: 2013-06-23 00:58

==================== End Of Log ============================

 

 

 

 

 

 

 

Attached Files



#4 CatByte

CatByte

    bleepin' tiger


  • Malware Response Team
  • 14,664 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Canada
  • Local time:05:57 AM

Posted 25 June 2013 - 09:09 PM

Please do the following:

Open notepad (Start =>All Programs => Accessories => Notepad). Please copy the entire contents of the code box below. (To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste).
Save it on your desktop as fixlist.txt

(if you saved FRST to a different folder and not your desktop originally, then save fixlist.txt to the same location as FRST was saved)


start
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
HKLM-x32 SearchScopes: DefaultScope {6CE2F86E-11D5-474D-8190-095E6F2B66A5} URL =
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - {110a9ea2-8810-4c04-b916-cfd4e9427fec} URL = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?p2=^ZX^xdm039^YY^us&si=radiopi&ptb=160C0F77-45F9-44E3-A819-17095ED21E35&ind=2013012018&n=77fc2032&psa=&st=sb&searchfor={searchTerms}
SearchScopes: HKLM-x32 - {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://start.sweetpacks.com/?src=6&q={searchTerms}&st=12&crg=3.5000006.10042&barid={6C0043D1-9D81-11E2-AA34-FF36774A7524}
SearchScopes: HKCU - {110a9ea2-8810-4c04-b916-cfd4e9427fec} URL = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?p2=^ZX^xdm039^YY^us&si=radiopi&ptb=160C0F77-45F9-44E3-A819-17095ED21E35&ind=2013012018&n=77fc2032&psa=&st=sb&searchfor={searchTerms}
SearchScopes: HKCU - {2F1E335A-858A-4BE9-8F6B-D0AF1D018B53} URL =
SearchScopes: HKCU - {5a1d0d31-749c-4186-a295-4106e6e7b26a} URL =
SearchScopes: HKCU - {9BAFBD72-7B94-4C12-B0C9-E8655CB66489} URL =
SearchScopes: HKCU - {a5b9c0f5-5616-47cd-a95f-e43b488faccf} URL =
SearchScopes: HKCU - {cca2e567-1987-4100-a3c6-5b4267084510} URL =
SearchScopes: HKCU - {EEE6C360-6118-11DC-9C72-001320C79847} URL =
Winsock: Catalog5 01 %SystemRoot%\System32\mswsock.dll [232448] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5-x64 01 %SystemRoot%\System32\mswsock.dll [326144] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
CHR Extension: (Borowuse2saave) - C:\Users\Debbie\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgdhoilbkagbdmdikoemnekflnckiild\1
CHR Extension: (caOntuinueattousavve) - C:\Users\Debbie\AppData\Local\Google\Chrome\User Data\Default\Extensions\dnibnghfkdkigmifdkcfhogddoacjfhb\1
CHR Extension: (SSaafe save) - C:\Users\Debbie\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipkiolacmfobbnpfcncjammhhdaiodoa\1
CHR Extension: (continuetosuave) - C:\Users\Debbie\AppData\Local\Google\Chrome\User Data\Default\Extensions\nomaimloplecjccghpgifabkepbhibbd\1
end
NOTICE: This script was written specifically for this user, for use on this particular machine. Running this on another machine may cause damage to your operating system

Now run FRST (or FRST64 if you have the 64bit version) and press the Fix button just once and wait.
The tool will make a log on your desktop (Fixlog.txt) please attach that log to your reply.

Note: FixList.txt and FRST must be saved to the same location or the fix will not work

Reboot Normally.

NEXT

Please create a new system restore point before running Malwarebytes Anti-Rootkit if you can.

MBAR tutorial

Download Malwarebytes Anti-Rootkit from HERE
  • Unzip the contents to a folder in a convenient location.
  • Open the folder where the contents were unzipped and run mbar.exe
  • Follow the instructions in the wizard to update and allow the program to scan your computer for threats.
  • Click on the Cleanup button to remove any threats and reboot if prompted to do so.
  • Wait while the system shuts down and the cleanup process is performed.
  • Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
  • When done, please post the two logs produced they will be in the MBAR folder..... mbar-log.txt and system-log.txt
~~~~~~~~~~~~~~~~~~~~~~~

Note:
If no additional threats were found, verify that your system is now running normally, making sure that the following items are functional:
Internet access
Windows Update
Windows Firewall

If there are additional problems with your system, such as any of those listed above or other system issues, then run the fixdamage tool included with Malwarebytes Anti-Rootkit located in the mbar\plugins folder and reboot.
Verify that your system is now functioning normally.

Microsoft MVP - 2010, 2011, 2012, 2013, 2014, 2015


#5 Fhoosa

Fhoosa
  • Topic Starter

  • Members
  • 123 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Seabrook, TX
  • Local time:03:57 AM

Posted 25 June 2013 - 10:27 PM

Here are the reports you wanted.

 

I've checked my system out and we still have a problem.  I am unable to find our other computer in Networks and it still won't let me enable file sharing or discovery.

 

Is this making any sense?

Attached Files



#6 CatByte

CatByte

    bleepin' tiger


  • Malware Response Team
  • 14,664 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Canada
  • Local time:05:57 AM

Posted 26 June 2013 - 05:31 AM

Please run the following

Refer to the ComboFix User's Guide
  • Download ComboFix from the following location:

    Link

    * IMPORTANT !!! Place ComboFix.exe on your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.
    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


    ---------------------------------------------------------------------------------------------
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.

    ---------------------------------------------------------------------------------------------
NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.

Microsoft MVP - 2010, 2011, 2012, 2013, 2014, 2015


#7 Fhoosa

Fhoosa
  • Topic Starter

  • Members
  • 123 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Seabrook, TX
  • Local time:03:57 AM

Posted 26 June 2013 - 08:07 AM

Good Morning...

 

Here is the ComboFix report.  I also discovered this morning that besides the ports on my computer being disabled, our other computer is stating the same thing.

 

ComboFix 13-06-25.01 - Debbie 06/26/2013   5:30.4.2 - x64
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.1.1033.18.3034.1489 [GMT -7:00]
Running from: c:\users\Debbie\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5}
SP: Microsoft Security Essentials *Disabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Debbie\AppData\Roaming\vso_ts_preview.xml
.
.
(((((((((((((((((((((((((   Files Created from 2013-05-26 to 2013-06-26  )))))))))))))))))))))))))))))))
.
.
2013-06-26 12:42 . 2013-06-26 12:42 -------- d-----w- c:\users\Public\AppData\Local\temp
2013-06-26 12:42 . 2013-06-26 12:42 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-06-26 02:26 . 2013-06-26 03:10 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable)
2013-06-26 01:46 . 2013-06-26 01:46 -------- d-----w- C:\FRST
2013-06-25 21:34 . 2013-06-25 21:34 -------- d-----w- c:\programdata\vsosdk
2013-06-25 17:39 . 2013-06-25 17:39 -------- d-----w- c:\program files (x86)\7-Zip
2013-06-25 08:56 . 2013-06-12 03:08 9552976 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B84545DF-E37D-4126-98AE-C37B71A1F543}\mpengine.dll
2013-06-25 07:01 . 2013-06-25 07:01 312232 ----a-w- c:\windows\system32\javaws.exe
2013-06-25 07:01 . 2013-06-25 07:01 108968 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2013-06-25 07:01 . 2013-06-25 07:00 189352 ----a-w- c:\windows\system32\javaw.exe
2013-06-25 07:01 . 2013-06-25 07:00 188840 ----a-w- c:\windows\system32\java.exe
2013-06-25 07:00 . 2013-06-25 07:00 -------- d-----w- c:\program files\Java
2013-06-25 07:00 . 2013-06-25 07:00 -------- d-----w- c:\program files (x86)\Common Files\Java
2013-06-25 06:59 . 2013-06-25 06:59 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-06-25 06:59 . 2013-06-25 06:59 -------- d-----w- c:\program files (x86)\Java
2013-06-24 15:39 . 2013-06-24 15:39 -------- d-----w- c:\users\Debbie\AppData\Roaming\8Floor
2013-06-24 12:06 . 2013-06-24 12:06 -------- d-----w- c:\users\Debbie\AppData\Roaming\Chayowo Games
2013-06-24 10:29 . 2013-06-12 03:08 9552976 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-06-24 09:05 . 2013-06-24 09:05 32000 ----a-w- c:\windows\system32\drivers\hitmanpro37.sys
2013-06-23 15:41 . 2009-09-02 20:44 65602 ----a-w- c:\windows\SysWow64\cook3260.dll
2013-06-23 15:41 . 2009-09-02 20:44 217127 ----a-w- c:\windows\SysWow64\drv43260.dll
2013-06-23 15:41 . 2009-09-02 20:44 208935 ----a-w- c:\windows\SysWow64\drv33260.dll
2013-06-23 15:41 . 2009-09-02 20:44 176165 ----a-w- c:\windows\SysWow64\drv23260.dll
2013-06-23 15:41 . 2009-09-02 20:44 102439 ----a-w- c:\windows\SysWow64\sipr3260.dll
2013-06-23 15:41 . 2009-09-02 20:44 626688 ----a-w- c:\windows\SysWow64\vp7vfw.dll
2013-06-23 15:41 . 2009-09-02 20:44 1184984 ----a-w- c:\windows\SysWow64\wvc1dmod.dll
2013-06-23 15:41 . 2013-06-23 15:41 -------- d-----w- c:\program files (x86)\VSO
2013-06-23 01:24 . 2013-06-23 01:24 82816 ----a-w- c:\users\Debbie\AppData\Roaming\pcouffin.sys
2013-06-22 08:14 . 2013-06-25 22:13 -------- d-----w- c:\users\Debbie\AppData\Roaming\Vso
2013-06-22 07:59 . 2013-06-24 07:40 -------- d-----w- c:\program files (x86)\Total Video Converter
2013-06-22 06:14 . 2013-06-22 06:14 -------- d-----w- c:\users\Debbie\My Backup Files
2013-06-22 05:14 . 2013-06-22 05:13 964552 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{33152359-A02C-4A8E-BD14-6323700C0ACC}\gapaengine.dll
2013-06-21 09:11 . 2013-06-21 09:11 42297 ----a-w- c:\windows\system32\uninstall.exe
2013-06-21 08:20 . 2007-09-01 01:36 36864 ----a-w- c:\windows\SysWow64\trayicon_handler.ocx
2013-06-21 08:20 . 2003-01-26 20:41 40960 ----a-w- c:\windows\SysWow64\ssubtmr6.dll
2013-06-21 04:47 . 2013-06-21 04:47 -------- d-----w- c:\program files (x86)\Common Files\Jaksta Technologies
2013-06-20 14:58 . 2013-06-20 15:00 -------- d-----w- c:\program files (x86)\Untold History - Descendant of the Sun Collector's Edition
2013-06-20 14:58 . 2013-06-20 14:58 -------- d-----w- c:\windows\Untold History - Descendant of the Sun Collector's Edition
2013-06-14 03:55 . 2013-06-14 03:55 -------- d-----w- c:\users\Debbie\AppData\Roaming\4 Friends Games
2013-06-14 02:57 . 2013-05-08 06:39 1910632 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-06-14 02:57 . 2013-04-26 05:51 751104 ----a-w- c:\windows\system32\win32spl.dll
2013-06-14 02:57 . 2013-04-26 04:55 492544 ----a-w- c:\windows\SysWow64\win32spl.dll
2013-06-14 02:57 . 2013-05-10 05:49 30720 ----a-w- c:\windows\system32\cryptdlg.dll
2013-06-14 02:57 . 2013-05-10 03:20 24576 ----a-w- c:\windows\SysWow64\cryptdlg.dll
2013-06-14 02:57 . 2013-04-17 07:02 1230336 ----a-w- c:\windows\SysWow64\WindowsCodecs.dll
2013-06-14 02:57 . 2013-04-17 06:24 1424384 ----a-w- c:\windows\system32\WindowsCodecs.dll
2013-06-14 02:56 . 2013-05-13 05:51 1464320 ----a-w- c:\windows\system32\crypt32.dll
2013-06-14 02:56 . 2013-05-13 03:43 1192448 ----a-w- c:\windows\system32\certutil.exe
2013-06-14 02:56 . 2013-05-13 03:08 903168 ----a-w- c:\windows\SysWow64\certutil.exe
2013-06-14 02:56 . 2013-05-13 05:51 184320 ----a-w- c:\windows\system32\cryptsvc.dll
2013-06-14 02:56 . 2013-05-13 05:51 139776 ----a-w- c:\windows\system32\cryptnet.dll
2013-06-14 02:56 . 2013-05-13 04:45 1160192 ----a-w- c:\windows\SysWow64\crypt32.dll
2013-06-14 02:56 . 2013-05-13 04:45 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll
2013-06-14 02:56 . 2013-05-13 05:50 52224 ----a-w- c:\windows\system32\certenc.dll
2013-06-14 02:56 . 2013-05-13 04:45 140288 ----a-w- c:\windows\SysWow64\cryptsvc.dll
2013-06-14 02:56 . 2013-05-13 03:08 43008 ----a-w- c:\windows\SysWow64\certenc.dll
2013-06-14 02:56 . 2013-04-25 23:30 1505280 ----a-w- c:\windows\SysWow64\d3d11.dll
2013-06-14 02:56 . 2013-03-31 22:52 1887232 ----a-w- c:\windows\system32\d3d11.dll
2013-06-13 00:49 . 2013-06-13 00:49 -------- d-----w- c:\users\Debbie\AppData\Roaming\Deep Shadows
2013-06-13 00:43 . 2013-06-14 02:45 -------- d-----w- c:\program files (x86)\Big City Adventure 8 - Tokyo
2013-06-13 00:41 . 2013-06-14 03:29 -------- d-----w- C:\Games
2013-06-12 09:33 . 2013-06-23 05:35 -------- d-----w- c:\users\Debbie\AppData\Roaming\ERS Game Studios
2013-06-08 21:45 . 2013-06-08 21:45 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2013-06-04 14:42 . 2013-06-22 06:29 -------- d-----w- C:\Dizzy-Games
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-06-25 07:00 . 2012-07-08 09:00 1093032 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-06-25 07:00 . 2011-04-22 00:11 972712 ----a-w- c:\windows\system32\deployJava1.dll
2013-06-25 06:59 . 2012-06-18 23:15 867240 ----a-w- c:\windows\SysWow64\npdeployJava1.dll
2013-06-25 06:59 . 2012-04-09 04:35 789416 ----a-w- c:\windows\SysWow64\deployJava1.dll
2013-06-24 07:51 . 2009-07-13 23:19 328704 ----a-w- c:\windows\system32\services.exe
2013-06-20 04:08 . 2012-11-21 05:14 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-06-14 10:01 . 2012-04-09 15:55 75825640 ----a-w- c:\windows\system32\MRT.exe
2013-06-14 03:13 . 2012-04-09 04:23 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-06-14 03:13 . 2012-04-09 04:23 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-05-21 18:08 . 2013-03-13 13:34 964552 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2013-05-02 15:29 . 2012-04-08 22:37 278800 ------w- c:\windows\system32\MpSigStub.exe
2013-04-18 22:38 . 2013-04-18 22:38 39904 ----a-w- c:\windows\SysWow64\Media Player - Codec Pack Disc handler.exe
2013-04-18 22:38 . 2013-04-18 22:38 39904 ----a-w- c:\windows\SysWow64\dischandler.exe
2013-04-16 10:40 . 2013-04-16 10:40 4012544 ----a-w- c:\windows\system32\ffmpeg.dll
2013-04-16 10:39 . 2013-04-16 10:39 127488 ----a-w- c:\windows\system32\ff_vfw.dll
2013-04-16 10:39 . 2013-04-16 10:39 4372992 ----a-w- c:\windows\system32\ffdshow.ax
2013-04-16 10:38 . 2013-04-16 10:38 474624 ----a-w- c:\windows\system32\ff_kernelDeint.dll
2013-04-16 10:37 . 2013-04-16 10:37 631296 ----a-w- c:\windows\system32\TomsMoComp_ff.dll
2013-04-16 10:37 . 2013-04-16 10:37 114688 ----a-w- c:\windows\system32\ff_wmv9.dll
2013-04-16 10:37 . 2013-04-16 10:37 183296 ----a-w- c:\windows\system32\ff_unrar.dll
2013-04-16 10:37 . 2013-04-16 10:37 156672 ----a-w- c:\windows\system32\ff_libmad.dll
2013-04-16 10:37 . 2013-04-16 10:37 222720 ----a-w- c:\windows\system32\ff_libdts.dll
2013-04-16 10:37 . 2013-04-16 10:37 1532928 ----a-w- c:\windows\system32\ff_samplerate.dll
2013-04-16 10:37 . 2013-04-16 10:37 190464 ----a-w- c:\windows\system32\libmpeg2_ff.dll
2013-04-16 10:37 . 2013-04-16 10:37 116224 ----a-w- c:\windows\system32\ff_liba52.dll
2013-04-16 10:35 . 2013-04-16 10:35 3915776 ----a-w- c:\windows\SysWow64\ffmpeg.dll
2013-04-16 10:33 . 2013-04-16 10:33 3501568 ----a-w- c:\windows\SysWow64\ffdshow.ax
2013-04-16 10:32 . 2013-04-16 10:32 157184 ----a-w- c:\windows\SysWow64\ff_unrar.dll
2013-04-16 10:32 . 2013-04-16 10:32 271360 ----a-w- c:\windows\SysWow64\TomsMoComp_ff.dll
2013-04-16 10:32 . 2013-04-16 10:32 99840 ----a-w- c:\windows\SysWow64\ff_wmv9.dll
2013-04-16 10:32 . 2013-04-16 10:32 211968 ----a-w- c:\windows\SysWow64\ff_libdts.dll
2013-04-16 10:32 . 2013-04-16 10:32 147456 ----a-w- c:\windows\SysWow64\ff_libmad.dll
2013-04-16 10:32 . 2013-04-16 10:32 1525760 ----a-w- c:\windows\SysWow64\ff_samplerate.dll
2013-04-16 10:32 . 2013-04-16 10:32 114688 ----a-w- c:\windows\SysWow64\ff_liba52.dll
2013-04-16 10:32 . 2013-04-16 10:32 136704 ----a-w- c:\windows\SysWow64\libmpeg2_ff.dll
2013-04-14 19:28 . 2013-04-14 19:28 74703 ----a-w- c:\windows\SysWow64\mfc45.dat
2013-04-14 08:11 . 2013-04-14 08:11 319488 ----a-w- c:\windows\HideWin.exe
2013-04-13 12:24 . 2013-04-13 12:24 1515520 ----a-w- c:\windows\system32\LAVVideo.ax
2013-04-13 12:24 . 2013-04-13 12:24 364720 ----a-w- c:\windows\system32\IntelQuickSyncDecoder.dll
2013-04-13 12:24 . 2013-04-13 12:24 509952 ----a-w- c:\windows\system32\LAVSplitter.ax
2013-04-13 12:24 . 2013-04-13 12:24 272384 ----a-w- c:\windows\system32\LAVAudio.ax
2013-04-13 12:24 . 2013-04-13 12:24 421600 ----a-w- c:\windows\system32\swscale-lav-2.dll
2013-04-13 12:24 . 2013-04-13 12:24 7977200 ----a-w- c:\windows\system32\avcodec-lav-55.dll
2013-04-13 12:24 . 2013-04-13 12:24 289008 ----a-w- c:\windows\system32\avutil-lav-52.dll
2013-04-13 12:24 . 2013-04-13 12:24 202648 ----a-w- c:\windows\system32\avfilter-lav-3.dll
2013-04-13 12:24 . 2013-04-13 12:24 194016 ----a-w- c:\windows\system32\avresample-lav-1.dll
2013-04-13 12:24 . 2013-04-13 12:24 1245920 ----a-w- c:\windows\system32\avformat-lav-55.dll
2013-04-13 12:23 . 2013-04-13 12:23 7788672 ----a-w- c:\windows\SysWow64\avcodec-lav-55.dll
2013-04-13 12:23 . 2013-04-13 12:23 424624 ----a-w- c:\windows\SysWow64\LAVSplitter.ax
2013-04-13 12:23 . 2013-04-13 12:23 400592 ----a-w- c:\windows\SysWow64\swscale-lav-2.dll
2013-04-13 12:23 . 2013-04-13 12:23 284336 ----a-w- c:\windows\SysWow64\IntelQuickSyncDecoder.dll
2013-04-13 12:23 . 2013-04-13 12:23 272192 ----a-w- c:\windows\SysWow64\avutil-lav-52.dll
2013-04-13 12:23 . 2013-04-13 12:23 244400 ----a-w- c:\windows\SysWow64\LAVAudio.ax
2013-04-13 12:23 . 2013-04-13 12:23 194632 ----a-w- c:\windows\SysWow64\avfilter-lav-3.dll
2013-04-13 12:23 . 2013-04-13 12:23 172728 ----a-w- c:\windows\SysWow64\avresample-lav-1.dll
2013-04-13 12:23 . 2013-04-13 12:23 1300152 ----a-w- c:\windows\SysWow64\avformat-lav-55.dll
2013-04-13 12:23 . 2013-04-13 12:23 1185456 ----a-w- c:\windows\SysWow64\LAVVideo.ax
2013-04-13 05:49 . 2013-05-15 14:04 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2013-04-13 05:49 . 2013-05-15 14:04 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
2013-04-13 05:49 . 2013-05-15 14:04 308736 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll
2013-04-13 05:49 . 2013-05-15 14:04 111104 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll
2013-04-13 04:45 . 2013-05-15 14:04 474624 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2013-04-13 04:45 . 2013-05-15 14:04 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll
2013-04-12 14:45 . 2013-04-23 23:12 1656680 ----a-w- c:\windows\system32\drivers\ntfs.sys
2013-04-11 14:22 . 2011-06-11 08:58 770384 ----a-w- c:\windows\SysWow64\msvcr100.dll
2013-04-11 14:22 . 2011-06-11 08:58 421200 ----a-w- c:\windows\SysWow64\msvcp100.dll
2013-04-10 06:01 . 2013-05-15 14:04 265064 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2013-04-10 06:01 . 2013-05-15 14:04 983400 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2013-04-10 03:30 . 2013-05-15 14:04 3153920 ----a-w- c:\windows\system32\win32k.sys
2013-04-04 21:50 . 2012-09-12 23:42 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-03-30 04:42 . 2013-04-12 05:29 3379272 ----a-w- c:\windows\system32\drivers\RTKVHD64.sys
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BitComet"="c:\program files (x86)\BitComet\BitComet.exe" [2013-02-19 12805888]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2012-08-23 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"RequireSignedAppInit_DLLs"=0 (0x0)
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ    \0
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x]
R2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [x]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x]
R2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys;c:\windows\SYSNATIVE\DRIVERS\CtClsFlt.sys [x]
R3 hitmanpro37;HitmanPro 3.7 Support Driver;c:\windows\system32\drivers\hitmanpro37.sys;c:\windows\SYSNATIVE\drivers\hitmanpro37.sys [x]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 PCTDMDefrag;PCTDMDefrag;c:\windows\system32\drivers\PCTDMDefrag.sys;c:\windows\SYSNATIVE\drivers\PCTDMDefrag.sys [x]
R3 PCTDSMon;PCTDSMon;c:\windows\system32\drivers\PCTDSMon.sys;c:\windows\SYSNATIVE\drivers\PCTDSMon.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
R3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys;c:\windows\SYSNATIVE\DRIVERS\yk62x64.sys [x]
R4 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [x]
S3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys;c:\windows\SYSNATIVE\DRIVERS\dc3d.sys [x]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x]
S3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys;c:\windows\SYSNATIVE\DRIVERS\point64.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
2013-06-26 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-09 03:13]
.
2013-05-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore1ce4d34c2b38d74.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-17 02:54]
.
2013-06-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-17 02:54]
.
2013-04-27 c:\windows\Tasks\Wise Registry Cleaner Schedule Task.job
- c:\program files (x86)\Wise\Wise Registry Cleaner\WiseRegCleaner.exe [2013-01-19 22:41]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2010-06-04 392048]
"AWiC"="c:\program files (x86)\Atheros\AWiCMgr.exe" [2010-09-11 167936]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-08-01 2417032]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-11-14 163360]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-11-14 387616]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-11-14 418336]
.
------- Supplementary Scan -------
.
uStart Page = https://www.google.com/
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: &D&ownload &with BitComet - c:\program files (x86)\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all with BitComet - c:\program files (x86)\BitComet\BitComet.exe/AddAllLink.htm
Trusted Zone: dell.com
TCP: DhcpNameServer = 75.75.75.75 75.75.76.76
DPF: {682C59F5-478C-4421-9070-AD170D143B77} - hxxp://www.dell.com/support/troubleshooting/Content/Ode/pcd86.cab
DPF: {A084A130-28AE-4B32-B51A-1C8CE164BC88} - hxxp://www.convergysworkathome.com/AppHardT.CAB
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-Dark Dimensions 3 - City of Ash Collector's EditionFinal - c:\windows\Dark Dimensions 3 - City of Ash Collector's Edition\uninstall.exe
AddRemove-{750257DE-6C19-85A3-804D-A2D5C02A4D22} - c:\progra~3\INSTAL~1\{4DB6F~1\Setup.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}"=hex:51,66,7a,6c,4c,1d,38,12,df,c1,0b,
   27,57,07,ba,54,e4,0e,43,d0,22,fb,89,5b
"{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc,
   1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7
"{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}"=hex:51,66,7a,6c,4c,1d,38,12,0c,e0,e4,
   3d,b8,cc,34,0e,c3,b9,18,39,ba,81,ae,74
"{4C892A24-5B3B-71C0-15A0-4E5A3A9C4F72}"=hex:51,66,7a,6c,4c,1d,38,12,4a,29,9a,
   48,09,15,ae,34,6a,b6,0d,1a,3f,c2,0b,66
"{53707962-6F74-2D53-2644-206D7942484F}"=hex:51,66,7a,6c,4c,1d,38,12,0c,7a,63,
   57,46,21,3d,68,59,52,63,2d,7c,1c,0c,5b
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07,
   72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57
"{7F6AFBF1-E065-4627-A2FD-810366367D01}"=hex:51,66,7a,6c,4c,1d,38,12,9f,f8,79,
   7b,57,ae,49,03,dd,eb,c2,43,63,68,39,15
"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,
   94,30,02,d1,0f,f1,da,12,24,73,56,27,d2
"{9FDDE16B-836F-4806-AB1F-1455CBEFF289}"=hex:51,66,7a,6c,4c,1d,38,12,05,e2,ce,
   9b,5d,cd,68,0d,d4,09,57,15,ce,b1,b6,9d
"{AA58ED58-01DD-4D91-8333-CF10577473F7}"=hex:51,66,7a,6c,4c,1d,38,12,36,ee,4b,
   ae,ef,4f,ff,08,fc,25,8c,50,52,2a,37,e3
"{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}"=hex:51,66,7a,6c,4c,1d,38,12,07,5b,93,
   aa,6e,60,ba,0b,f0,6d,b2,b7,80,44,00,83
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,
   df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd
"{C4CFC0DE-134F-4466-B2A2-FF7C59A8BFAD}"=hex:51,66,7a,6c,4c,1d,3b,1b,e3,6b,d4,
   ed,48,70,39,39,96,99,8d,11,69,db,ca,81
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:7f,a8,6b,13,be,27,cd,01
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
   d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,cb,61,7c,9f,07,a0,0d,43,a7,be,13,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
   d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,cb,61,7c,9f,07,a0,0d,43,a7,be,13,\
.
[HKEY_USERS\S-1-5-21-3197802315-1125251100-3617295894-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.**ˆ]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-3197802315-1125251100-3617295894-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.**ˆ\OpenWithList]
@Class="Shell"
"a"="vlc.exe"
"MRUList"="a"
.
[HKEY_USERS\S-1-5-21-3197802315-1125251100-3617295894-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.**罨¾+²G3àç*€What you'd be wanting with me,]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-3197802315-1125251100-3617295894-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.**罨¾+²G3àç*€What you'd be wanting with me,\OpenWithList]
@Class="Shell"
"a"="vlc.exe"
"MRUList"="a"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
   00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows CE Services]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
   00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2013-06-26  05:55:27
ComboFix-quarantined-files.txt  2013-06-26 12:55
ComboFix2.txt  2013-06-24 10:11
.
Pre-Run: 225,698,570,240 bytes free
Post-Run: 225,474,170,880 bytes free
.
- - End Of File - - 923154EB1A3DF888B2EB5B565AA55DF9
D41D8CD98F00B204E9800998ECF8427E
 



#8 CatByte

CatByte

    bleepin' tiger


  • Malware Response Team
  • 14,664 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Canada
  • Local time:05:57 AM

Posted 26 June 2013 - 08:15 AM

please run the following:
  • Please download MiniToolBox and save it to your desktop and run it.

    Checkmark following checkboxes:
    • Flush DNS
    • Report IE Proxy Settings
    • Report FF Proxy Settings
    • List content of Hosts
    • List installed programs.
    Click Go and post the result (Result.txt) that pops up. A copy of result.txt will be saved in the same directory the tool is run.
NEXT


Please download Farbar Service Scanner to your desktop and run it.
  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center
    • Windows Update
    • Windows Defender
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.

Microsoft MVP - 2010, 2011, 2012, 2013, 2014, 2015


#9 Fhoosa

Fhoosa
  • Topic Starter

  • Members
  • 123 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Seabrook, TX
  • Local time:03:57 AM

Posted 26 June 2013 - 08:36 AM

Here they are:

 

MiniToolBox

 

MiniToolBox by Farbar  Version: 16-06-2013
Ran by Debbie (administrator) on 26-06-2013 at 06:27:44
Running from "C:\Users\Debbie\Desktop"
Windows 7 Home Premium Service Pack 1 (X64)
Boot Mode: Normal
***************************************************************************

========================= Flush DNS: ===================================

Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========================= IE Proxy Settings: ==============================

Proxy is not enabled.
No Proxy Server is set.
========================= Hosts content: =================================

127.0.0.1       localhost

=========================== Installed Programs ============================

7-Zip 9.20
Adobe AIR (Version: 3.6.0.5970)
Adobe Flash Player 11 ActiveX (Version: 11.7.700.224)
Adobe Reader XI (11.0.03) (Version: 11.0.03)
Adobe Shockwave Player 12.0 (Version: 12.0.2.122)
Advanced Audio FX Engine (Version: 1.12.05)
Atheros Client Installation Program (Version: 9.0)
BitComet 1.35 (Version: 1.35)
Cisco EAP-FAST Module (Version: 2.2.14)
Cisco LEAP Module (Version: 1.0.19)
Cisco PEAP Module (Version: 1.1.6)
ConvertXtoDVD 4.1.19.365 (Version: 4.1.19.365)
CorelDRAW Graphics Suite X6 - Capture (Version: 16.0)
CorelDRAW Graphics Suite X6 - Common (Version: 16.0)
CorelDRAW Graphics Suite X6 - Connect (Version: 16.0)
CorelDRAW Graphics Suite X6 - Custom Data (Version: 16.0)
CorelDRAW Graphics Suite X6 - Draw (Version: 16.0)
CorelDRAW Graphics Suite X6 - EN (Version: 16.0)
CorelDRAW Graphics Suite X6 - Filters (Version: 16.0)
CorelDRAW Graphics Suite X6 - FontNav (Version: 16.0)
CorelDRAW Graphics Suite X6 - IPM (Version: 16.0)
CorelDRAW Graphics Suite X6 - PHOTO-PAINT (Version: 16.0)
CorelDRAW Graphics Suite X6 - Photozoom Plugin (Version: 16.0)
CorelDRAW Graphics Suite X6 - Redist (Version: 16.0)
CorelDRAW Graphics Suite X6 - Setup Files (Version: 16.0)
CorelDRAW Graphics Suite X6 - VBA (Version: 16.0)
CorelDRAW Graphics Suite X6 - VideoBrowser (Version: 16.0)
CorelDRAW Graphics Suite X6 - VSTA (Version: 16.0)
CorelDRAW Graphics Suite X6 - Writing Tools (Version: 16.0)
CorelDRAW Graphics Suite X6 (Version: 16.0)
Cozi (Version: 1.0.4323.24051)
D3DX10 (Version: 15.4.2368.0902)
Dark Dimensions 3 - City of Ash Collector's Edition (Version: Final)
Dark Parables 5 - The Final Cinderella Collector's Edition (Version: Final)
Dark Tales 5 - Edgar Allan Poes The Masque of the Red Death CE (Version: Final)
Dell DataSafe Local Backup - Support Software (Version: 9.4.60)
Dell DataSafe Local Backup (Version: 9.4.60)
Dell DataSafe Online (Version: 1.2.0014)
Dell Dock (Version: 2.0)
Dell Edoc Viewer (Version: 1.0.0)
Dell Getting Started Guide (Version: 1.00.0000)
Dell Home Systems Service Agreement (Version: 2.0.0)
Dell Perks Webslice IE8 (Version: 8.0)
Dell Product Registration (Version: 1.0.6)
Dell Support Center (Version: 3.2.6032.125)
Dell Touchpad (Version: 7.1107.101.209)
Dell Webcam Central (Version: 1.40.05)
Enigma Agency - The Case of Shadows Collectors Edition (Version: Final)
Fairly Twisted Tales - The Price Of A Rose with Guide (Version: 1.0)
Free Desktop Timer 1.1
Google Toolbar for Internet Explorer (Version: 1.0.0)
Google Toolbar for Internet Explorer (Version: 7.5.4209.2358)
Google Update Helper (Version: 1.3.21.145)
HL.The Curse of Vox.CE (Version: Final)
Intel® Control Center (Version: 1.2.1.1007)
Intel® Graphics Media Accelerator Driver (Version: 8.15.10.2869)
Intel® Rapid Storage Technology (Version: 9.6.4.1002)
Internet Explorer (Enable DEP)
Internet TV for Windows Media Center (Version: 4.2.2.0)
Java 7 Update 25 (64-bit) (Version: 7.0.250)
Java 7 Update 25 (Version: 7.0.250)
Java Auto Updater (Version: 2.1.9.5)
Junk Mail filter update (Version: 15.4.3502.0922)
K-Lite Codec Pack 9.8.4 (64-bit) (Version: 9.8.4)
K-Lite Mega Codec Pack 9.8.5 (Version: 9.8.5)
Live! Cam Avatar Creator (Version: 4.6.3009.1)
Living Legends 2. Frozen Beauty 1.0 (Version: 1.0)
Malwarebytes Anti-Malware version 1.75.0.1300 (Version: 1.75.0.1300)
Media Player Codec Pack 4.2.7 (Version: 4.2.7)
Mesh Runtime (Version: 15.4.5722.2)
Messenger Companion (Version: 15.4.3502.0922)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft IntelliPoint 8.2 (Version: 8.20.468.0)
Microsoft Office 2010 (Version: 14.0.4763.1000)
Microsoft Office Click-to-Run 2010 (Version: 14.0.4763.1000)
Microsoft Office Starter 2010 - English (Version: 14.0.4763.1000)
Microsoft Security Client (Version: 4.2.0223.1)
Microsoft Security Essentials (Version: 4.2.223.1)
Microsoft Silverlight (Version: 5.1.20125.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000)
Microsoft Visual Basic for Applications 7.1 (x86) (Version: 7.1.00.00)
Microsoft Visual Basic for Applications 7.1 (x86) English (Version: 7.1.0.0)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.50727.42)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual Studio Tools for Applications 2.0 - ENU (Version: 9.0.30729)
Microsoft Visual Studio Tools for Applications 2.0 Runtime (Version: 9.0.30729)
MSVCRT (Version: 15.4.2862.0708)
MSVCRT_amd64 (Version: 15.4.2862.0708)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
Mysteries of the Undead Cursed Island (Version: FINAL)
OpenAL
PrintMaster 2012 Platinum (Version: 4.0.0.230)
Quickset64 (Version: 10.06.02)
Realtek USB 2.0 Card Reader (Version: 6.1.7600.30109)
Reveries.Sisterly Love CE (Version: Final)
Roxio Burn (Version: 1.01)
SpywareBlaster 5.0 (Version: 5.0.0)
Strange Cases The Faces of Vengeance (Version: FINAL)
swMSM (Version: 12.0.0.1)
System Requirements Lab for Intel (Version: 4.5.13.0)
Untold History - Descendant of the Sun Collector's Edition (Version: Final)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2836939) (Version: 1)
Update Installer for WildTangent Games App
VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0)
VLC media player 2.0.7 (Version: 2.0.7)
Winamp (Version: 5.63 )
Winamp Detector Plug-in (Version: 1.0.0.1)
Windows Live Essentials (Version: 15.4.3502.0922)
Windows Live Essentials (Version: 15.4.3538.0513)
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0)
Windows Live Installer (Version: 15.4.3502.0922)
Windows Live Language Selector (Version: 15.4.3538.0513)
Windows Live Mail (Version: 15.4.3502.0922)
Windows Live Mesh (Version: 15.4.3502.0922)
Windows Live Mesh ActiveX Control for Remote Connections (Version: 15.4.5722.2)
Windows Live Messenger (Version: 15.4.3538.0513)
Windows Live Messenger Companion Core (Version: 15.4.3502.0922)
Windows Live MIME IFilter (Version: 15.4.3502.0922)
Windows Live Movie Maker (Version: 15.4.3502.0922)
Windows Live Photo Common (Version: 15.4.3502.0922)
Windows Live Photo Gallery (Version: 15.4.3502.0922)
Windows Live PIMT Platform (Version: 15.4.3508.1109)
Windows Live Remote Client (Version: 15.4.5722.2)
Windows Live Remote Client Resources (Version: 15.4.5722.2)
Windows Live Remote Service (Version: 15.4.5722.2)
Windows Live Remote Service Resources (Version: 15.4.5722.2)
Windows Live UX Platform (Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (Version: 15.4.3508.1109)
Windows Live Writer (Version: 15.4.3502.0922)
Windows Live Writer Resources (Version: 15.4.3502.0922)
WinRAR 4.00 (64-bit) (Version: 4.00.0)
Wise Registry Cleaner 7.68 (Version: 7.68)

**** End of log ****

 

 

FSS

 

Farbar Service Scanner Version: 16-06-2013
Ran by Debbie (administrator) on 26-06-2013 at 06:30:52
Running from "C:\Users\Debbie\Desktop"
Windows 7 Home Premium Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.

Windows Firewall:
=============

Firewall Disabled Policy:
==================

System Restore:
============

System Restore Disabled Policy:
========================

Action Center:
============

Windows Update:
============

Windows Autoupdate Disabled Policy:
============================

Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Demand. The default start type is Auto.
The ImagePath of WinDefend service is OK.
The ServiceDll of WinDefend service is OK.

Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1

Other Services:
==============

File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys => MD5 is legit
C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys
[2013-06-13 19:57] - [2013-05-07 23:39] - 1910632 ____A (Microsoft Corporation) 9849EA3843A2ADBDD1497E97A85D8CAE

C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll
[2013-06-13 19:56] - [2013-05-12 22:51] - 0184320 ____A (Microsoft Corporation) D8129C49798CBBFB2E4351D4B7B8EF9C

C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit

**** End of log ****

 

 

 



#10 CatByte

CatByte

    bleepin' tiger


  • Malware Response Team
  • 14,664 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Canada
  • Local time:05:57 AM

Posted 26 June 2013 - 01:12 PM

Please run the following:

Please download Junkware Removal Tool to your desktop.
  • Shutdown your antivirus to avoid any conflicts.
  • Right-mouse click JRT.exe and select Run as administrator
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message

NEXT


Download AdwCleaner from here and save it to your desktop.
  • Run AdwCleaner and select Delete
  • Once done it will ask to reboot, allow the reboot
  • On reboot a log will be produced, please attach the content of the log to your next reply
NEXT
  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <-- very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Go here to run an online scanner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish

Microsoft MVP - 2010, 2011, 2012, 2013, 2014, 2015


#11 Fhoosa

Fhoosa
  • Topic Starter

  • Members
  • 123 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Seabrook, TX
  • Local time:03:57 AM

Posted 26 June 2013 - 05:31 PM

Finally got done with the reports/scans..

 

Junkware Removal Tool

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 4.9.4 (05.06.2013:1)
OS: Windows 7 Home Premium x64
Ran by Debbie on Wed 06/26/2013 at 12:46:37.43
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 

~~~ Services

 

~~~ Registry Values

 

~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\1clickdownload
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\conduit
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\iminent
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\iminent
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\sweetim
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\sweetim
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\systweak
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\Software\competeinc
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\Software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\Software\conduitsearchscopes
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\Software\crossrider
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\Software\pricegong
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\Software\smartbar
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\sprotector
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\applications\ilividsetupv1.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\conduitinstaller_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\conduitinstaller_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\ilividsetupv1_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\ilividsetupv1_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\iminent_nonsearch_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\iminent_nonsearch_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\iminent_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\iminent_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\wajamupdater_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\wajamupdater_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\sp global
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\sprotector
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\classes\Toolbar.CT3289847
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\classes\Toolbar.CT3290229
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\clsid\{22222222-2222-2222-2222-220022442293}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\wow6432node\clsid\{22222222-2222-2222-2222-220022442293}

 

~~~ Files

 

~~~ Folders

Successfully deleted: [Folder] "C:\ProgramData\boost_interprocess"
Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin"
Successfully deleted: [Empty Folder] C:\Users\Debbie\appdata\local\{277A9279-E858-4E01-B512-5E944A0D5485}
Successfully deleted: [Empty Folder] C:\Users\Debbie\appdata\local\{5F588AD5-36BC-4859-98F9-D212B1362383}
Successfully deleted: [Empty Folder] C:\Users\Debbie\appdata\local\{809AD72F-4679-4540-89ED-B9C986E67D80}
Successfully deleted: [Empty Folder] C:\Users\Debbie\appdata\local\{AA6B9902-7033-47E7-BAEA-BC1BD1AC8A70}
Successfully deleted: [Empty Folder] C:\Users\Debbie\appdata\local\{E4845F8B-6A66-403C-95DB-C431BE685629}

 

~~~ Event Viewer Logs were cleared

 

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Wed 06/26/2013 at 12:51:36.28
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 

AdwCleaner

 

# AdwCleaner v2.303 - Logfile created 06/26/2013 at 12:53:56
# Updated 08/06/2013 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : Debbie - HOME
# Boot Mode : Normal
# Running from : C:\Users\Debbie\Desktop\AdwCleaner.exe
# Option [Delete]

***** [Services] *****

***** [Files / Folders] *****

***** [Registry] *****

Key Deleted : HKCU\Software\AppDataLow\Software\MyFunCards_5m
Key Deleted : HKCU\Software\BI
Key Deleted : HKCU\Software\InstallCore
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\grusskartencenter.com
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\grusskartencenter.com
Key Deleted : HKCU\Software\wecarereminder
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{544C2426-48FD-4C40-AE3B-31257FF334D0}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\DefaultTabBHO.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\RegistryHelper.DLL
Key Deleted : HKLM\SOFTWARE\Classes\DefaultTabBHO.DefaultTabBrowser
Key Deleted : HKLM\SOFTWARE\Classes\DefaultTabBHO.DefaultTabBrowserActiveX
Key Deleted : HKLM\SOFTWARE\Classes\DefaultTabBHO.DefaultTabBrowserActiveX.1
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Key Deleted : HKLM\Software\CompeteInc
Key Deleted : HKLM\Software\InfoAtoms
Key Deleted : HKLM\Software\InstallIQ
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{1917AB4C-E2E9-42ae-A51E-B5750F160BFB}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{A4341726-E922-47bb-86A6-23F4F4F67342}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{43969E3F-3E7C-4911-A8F1-79C6CA6AC731}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{B887CA3B-D82B-4A01-AD29-E97444D01CE6}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C815E3DA-0823-49B0-9270-D1771D58B317}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AFB904C4-C255-4540-B97E-A75A34F1FFB0}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1917AB4C-E2E9-42ae-A51E-B5750F160BFB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A4341726-E922-47bb-86A6-23F4F4F67342}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DCA1528D-A3C0-4A9F-AA6E-DCE643F91495}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{43969E3F-3E7C-4911-A8F1-79C6CA6AC731}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B887CA3B-D82B-4A01-AD29-E97444D01CE6}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C815E3DA-0823-49B0-9270-D1771D58B317}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1
Value Deleted : HKLM\SOFTWARE\Policies\Google\Chrome\ExtensionInstallForcelist [1]

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16490

[OK] Registry is clean.

-\\ Google Chrome v [Unable to get version]

File : C:\Users\Debbie\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[S3].txt - [12965 octets] - [26/06/2013 12:53:56]

########## EOF - C:\AdwCleaner[S3].txt - [13026 octets] ##########

 

Malwarebytes Anti-Malware (PRO) 1.75.0.1300
www.malwarebytes.org

Database version: v2013.06.26.05

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Debbie :: HOME [administrator]

Protection: Enabled

6/26/2013 12:59:33 PM
mbam-log-2013-06-26 (12-59-33).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 227114
Time elapsed: 8 minute(s), 52 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)

 

 

 

Attached Files



#12 CatByte

CatByte

    bleepin' tiger


  • Malware Response Team
  • 14,664 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Canada
  • Local time:05:57 AM

Posted 26 June 2013 - 06:39 PM

Please do the following:
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".

Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Press the WinKey + R to open a run box, type Notepad > click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://www.bleepingcomputer.com/forums/t/499197/possible-zeroaccess-virus-mssecexexe/#entry3088942

Collect::
C:\WINDOWS\System32\d33dxof.dll	
C:\WINDOWS\System32\d3ddx10_42.dll	
C:\WINDOWS\System32\dhcpcmonitoor.dll	
C:\WINDOWS\SysWOW64\d33dxof.dll	
C:\WINDOWS\SysWOW64\d3ddx10_42.dll	
C:\WINDOWS\SysWOW64\dhcpcmonitoor.dll

ClearJavaCache::
Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:

1.Click File;
2.Click Save As... Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save ...

CFScriptB-4.gif
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix may request an update; please allow it.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


NEXT


Please advise how the computer is running now and if there are any outstanding issues

Microsoft MVP - 2010, 2011, 2012, 2013, 2014, 2015


#13 Fhoosa

Fhoosa
  • Topic Starter

  • Members
  • 123 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Seabrook, TX
  • Local time:03:57 AM

Posted 26 June 2013 - 07:34 PM

In my Network and Charing Center I still am able to turn on my File Sharing and my Discovery.  Nothing is showing up in my Networks.  I don't have access to the other computer.  Also, on BitComet, my Port detecting is still disabled.  The other day when I checked into this, it kept telling me my Firewall was incorrectly configured.

 

 

ComboFix 13-06-26.01 - Debbie 06/26/2013  16:48:43.5.2 - x64
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.1.1033.18.3034.1669 [GMT -7:00]
Running from: c:\users\Debbie\Desktop\ComboFix.exe
Command switches used :: c:\users\Debbie\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5}
SP: Microsoft Security Essentials *Disabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\SysWOW64\d33dxof.dll
c:\windows\SysWOW64\d3ddx10_42.dll
c:\windows\SysWOW64\dhcpcmonitoor.dll
.
.
(((((((((((((((((((((((((   Files Created from 2013-05-27 to 2013-06-27  )))))))))))))))))))))))))))))))
.
.
2013-06-27 00:01 . 2013-06-27 00:01 -------- d-----w- c:\users\Public\AppData\Local\temp
2013-06-27 00:01 . 2013-06-27 00:01 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-06-26 22:38 . 2013-06-12 03:08 9552976 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1E86CA2F-B216-4477-A9D8-46509CB226A5}\mpengine.dll
2013-06-26 22:37 . 2013-06-12 03:08 9552976 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-06-26 20:18 . 2013-06-26 20:18 -------- d-----w- c:\program files (x86)\ESET
2013-06-26 19:46 . 2013-06-26 19:46 -------- d-----w- c:\windows\ERUNT
2013-06-26 19:46 . 2013-06-26 19:46 -------- d-----w- C:\JRT
2013-06-26 02:26 . 2013-06-26 03:10 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable)
2013-06-26 01:46 . 2013-06-26 01:46 -------- d-----w- C:\FRST
2013-06-25 21:34 . 2013-06-25 21:34 -------- d-----w- c:\programdata\vsosdk
2013-06-25 17:39 . 2013-06-25 17:39 -------- d-----w- c:\program files (x86)\7-Zip
2013-06-25 07:01 . 2013-06-25 07:01 312232 ----a-w- c:\windows\system32\javaws.exe
2013-06-25 07:01 . 2013-06-25 07:01 108968 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2013-06-25 07:01 . 2013-06-25 07:00 189352 ----a-w- c:\windows\system32\javaw.exe
2013-06-25 07:01 . 2013-06-25 07:00 188840 ----a-w- c:\windows\system32\java.exe
2013-06-25 07:00 . 2013-06-25 07:00 -------- d-----w- c:\program files\Java
2013-06-25 07:00 . 2013-06-25 07:00 -------- d-----w- c:\program files (x86)\Common Files\Java
2013-06-25 06:59 . 2013-06-25 06:59 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-06-25 06:59 . 2013-06-25 06:59 -------- d-----w- c:\program files (x86)\Java
2013-06-24 15:39 . 2013-06-24 15:39 -------- d-----w- c:\users\Debbie\AppData\Roaming\8Floor
2013-06-24 12:06 . 2013-06-24 12:06 -------- d-----w- c:\users\Debbie\AppData\Roaming\Chayowo Games
2013-06-24 09:05 . 2013-06-24 09:05 32000 ----a-w- c:\windows\system32\drivers\hitmanpro37.sys
2013-06-23 15:41 . 2009-09-02 20:44 65602 ----a-w- c:\windows\SysWow64\cook3260.dll
2013-06-23 15:41 . 2009-09-02 20:44 217127 ----a-w- c:\windows\SysWow64\drv43260.dll
2013-06-23 15:41 . 2009-09-02 20:44 208935 ----a-w- c:\windows\SysWow64\drv33260.dll
2013-06-23 15:41 . 2009-09-02 20:44 176165 ----a-w- c:\windows\SysWow64\drv23260.dll
2013-06-23 15:41 . 2009-09-02 20:44 102439 ----a-w- c:\windows\SysWow64\sipr3260.dll
2013-06-23 15:41 . 2009-09-02 20:44 626688 ----a-w- c:\windows\SysWow64\vp7vfw.dll
2013-06-23 15:41 . 2009-09-02 20:44 1184984 ----a-w- c:\windows\SysWow64\wvc1dmod.dll
2013-06-23 15:41 . 2013-06-23 15:41 -------- d-----w- c:\program files (x86)\VSO
2013-06-23 01:24 . 2013-06-23 01:24 82816 ----a-w- c:\users\Debbie\AppData\Roaming\pcouffin.sys
2013-06-22 08:14 . 2013-06-25 22:13 -------- d-----w- c:\users\Debbie\AppData\Roaming\Vso
2013-06-22 07:59 . 2013-06-24 07:40 -------- d-----w- c:\program files (x86)\Total Video Converter
2013-06-22 06:14 . 2013-06-22 06:14 -------- d-----w- c:\users\Debbie\My Backup Files
2013-06-22 05:14 . 2013-06-22 05:13 964552 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{33152359-A02C-4A8E-BD14-6323700C0ACC}\gapaengine.dll
2013-06-21 09:11 . 2013-06-21 09:11 42297 ----a-w- c:\windows\system32\uninstall.exe
2013-06-21 08:20 . 2007-09-01 01:36 36864 ----a-w- c:\windows\SysWow64\trayicon_handler.ocx
2013-06-21 08:20 . 2003-01-26 20:41 40960 ----a-w- c:\windows\SysWow64\ssubtmr6.dll
2013-06-21 04:47 . 2013-06-21 04:47 -------- d-----w- c:\program files (x86)\Common Files\Jaksta Technologies
2013-06-20 14:58 . 2013-06-20 15:00 -------- d-----w- c:\program files (x86)\Untold History - Descendant of the Sun Collector's Edition
2013-06-20 14:58 . 2013-06-20 14:58 -------- d-----w- c:\windows\Untold History - Descendant of the Sun Collector's Edition
2013-06-14 03:55 . 2013-06-14 03:55 -------- d-----w- c:\users\Debbie\AppData\Roaming\4 Friends Games
2013-06-14 02:57 . 2013-05-08 06:39 1910632 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-06-14 02:57 . 2013-04-26 05:51 751104 ----a-w- c:\windows\system32\win32spl.dll
2013-06-14 02:57 . 2013-04-26 04:55 492544 ----a-w- c:\windows\SysWow64\win32spl.dll
2013-06-14 02:57 . 2013-05-10 05:49 30720 ----a-w- c:\windows\system32\cryptdlg.dll
2013-06-14 02:57 . 2013-05-10 03:20 24576 ----a-w- c:\windows\SysWow64\cryptdlg.dll
2013-06-14 02:57 . 2013-04-17 07:02 1230336 ----a-w- c:\windows\SysWow64\WindowsCodecs.dll
2013-06-14 02:57 . 2013-04-17 06:24 1424384 ----a-w- c:\windows\system32\WindowsCodecs.dll
2013-06-14 02:56 . 2013-05-13 05:51 1464320 ----a-w- c:\windows\system32\crypt32.dll
2013-06-14 02:56 . 2013-05-13 03:43 1192448 ----a-w- c:\windows\system32\certutil.exe
2013-06-14 02:56 . 2013-05-13 03:08 903168 ----a-w- c:\windows\SysWow64\certutil.exe
2013-06-14 02:56 . 2013-05-13 05:51 184320 ----a-w- c:\windows\system32\cryptsvc.dll
2013-06-14 02:56 . 2013-05-13 05:51 139776 ----a-w- c:\windows\system32\cryptnet.dll
2013-06-14 02:56 . 2013-05-13 04:45 1160192 ----a-w- c:\windows\SysWow64\crypt32.dll
2013-06-14 02:56 . 2013-05-13 04:45 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll
2013-06-14 02:56 . 2013-05-13 05:50 52224 ----a-w- c:\windows\system32\certenc.dll
2013-06-14 02:56 . 2013-05-13 04:45 140288 ----a-w- c:\windows\SysWow64\cryptsvc.dll
2013-06-14 02:56 . 2013-05-13 03:08 43008 ----a-w- c:\windows\SysWow64\certenc.dll
2013-06-14 02:56 . 2013-04-25 23:30 1505280 ----a-w- c:\windows\SysWow64\d3d11.dll
2013-06-14 02:56 . 2013-03-31 22:52 1887232 ----a-w- c:\windows\system32\d3d11.dll
2013-06-13 00:49 . 2013-06-13 00:49 -------- d-----w- c:\users\Debbie\AppData\Roaming\Deep Shadows
2013-06-13 00:43 . 2013-06-14 02:45 -------- d-----w- c:\program files (x86)\Big City Adventure 8 - Tokyo
2013-06-13 00:41 . 2013-06-14 03:29 -------- d-----w- C:\Games
2013-06-12 09:33 . 2013-06-23 05:35 -------- d-----w- c:\users\Debbie\AppData\Roaming\ERS Game Studios
2013-06-08 21:45 . 2013-06-08 21:45 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2013-06-04 14:42 . 2013-06-22 06:29 -------- d-----w- C:\Dizzy-Games
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-06-25 07:00 . 2012-07-08 09:00 1093032 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-06-25 07:00 . 2011-04-22 00:11 972712 ----a-w- c:\windows\system32\deployJava1.dll
2013-06-25 06:59 . 2012-06-18 23:15 867240 ----a-w- c:\windows\SysWow64\npdeployJava1.dll
2013-06-25 06:59 . 2012-04-09 04:35 789416 ----a-w- c:\windows\SysWow64\deployJava1.dll
2013-06-24 07:51 . 2009-07-13 23:19 328704 ----a-w- c:\windows\system32\services.exe
2013-06-20 04:08 . 2012-11-21 05:14 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-06-14 10:01 . 2012-04-09 15:55 75825640 ----a-w- c:\windows\system32\MRT.exe
2013-06-14 03:13 . 2012-04-09 04:23 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-06-14 03:13 . 2012-04-09 04:23 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-05-21 18:08 . 2013-03-13 13:34 964552 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2013-05-02 15:29 . 2012-04-08 22:37 278800 ------w- c:\windows\system32\MpSigStub.exe
2013-04-18 22:38 . 2013-04-18 22:38 39904 ----a-w- c:\windows\SysWow64\Media Player - Codec Pack Disc handler.exe
2013-04-18 22:38 . 2013-04-18 22:38 39904 ----a-w- c:\windows\SysWow64\dischandler.exe
2013-04-16 10:40 . 2013-04-16 10:40 4012544 ----a-w- c:\windows\system32\ffmpeg.dll
2013-04-16 10:39 . 2013-04-16 10:39 127488 ----a-w- c:\windows\system32\ff_vfw.dll
2013-04-16 10:39 . 2013-04-16 10:39 4372992 ----a-w- c:\windows\system32\ffdshow.ax
2013-04-16 10:38 . 2013-04-16 10:38 474624 ----a-w- c:\windows\system32\ff_kernelDeint.dll
2013-04-16 10:37 . 2013-04-16 10:37 631296 ----a-w- c:\windows\system32\TomsMoComp_ff.dll
2013-04-16 10:37 . 2013-04-16 10:37 114688 ----a-w- c:\windows\system32\ff_wmv9.dll
2013-04-16 10:37 . 2013-04-16 10:37 183296 ----a-w- c:\windows\system32\ff_unrar.dll
2013-04-16 10:37 . 2013-04-16 10:37 156672 ----a-w- c:\windows\system32\ff_libmad.dll
2013-04-16 10:37 . 2013-04-16 10:37 222720 ----a-w- c:\windows\system32\ff_libdts.dll
2013-04-16 10:37 . 2013-04-16 10:37 1532928 ----a-w- c:\windows\system32\ff_samplerate.dll
2013-04-16 10:37 . 2013-04-16 10:37 190464 ----a-w- c:\windows\system32\libmpeg2_ff.dll
2013-04-16 10:37 . 2013-04-16 10:37 116224 ----a-w- c:\windows\system32\ff_liba52.dll
2013-04-16 10:35 . 2013-04-16 10:35 3915776 ----a-w- c:\windows\SysWow64\ffmpeg.dll
2013-04-16 10:33 . 2013-04-16 10:33 3501568 ----a-w- c:\windows\SysWow64\ffdshow.ax
2013-04-16 10:32 . 2013-04-16 10:32 157184 ----a-w- c:\windows\SysWow64\ff_unrar.dll
2013-04-16 10:32 . 2013-04-16 10:32 271360 ----a-w- c:\windows\SysWow64\TomsMoComp_ff.dll
2013-04-16 10:32 . 2013-04-16 10:32 99840 ----a-w- c:\windows\SysWow64\ff_wmv9.dll
2013-04-16 10:32 . 2013-04-16 10:32 211968 ----a-w- c:\windows\SysWow64\ff_libdts.dll
2013-04-16 10:32 . 2013-04-16 10:32 147456 ----a-w- c:\windows\SysWow64\ff_libmad.dll
2013-04-16 10:32 . 2013-04-16 10:32 1525760 ----a-w- c:\windows\SysWow64\ff_samplerate.dll
2013-04-16 10:32 . 2013-04-16 10:32 114688 ----a-w- c:\windows\SysWow64\ff_liba52.dll
2013-04-16 10:32 . 2013-04-16 10:32 136704 ----a-w- c:\windows\SysWow64\libmpeg2_ff.dll
2013-04-14 19:28 . 2013-04-14 19:28 74703 ----a-w- c:\windows\SysWow64\mfc45.dat
2013-04-14 08:11 . 2013-04-14 08:11 319488 ----a-w- c:\windows\HideWin.exe
2013-04-13 12:24 . 2013-04-13 12:24 1515520 ----a-w- c:\windows\system32\LAVVideo.ax
2013-04-13 12:24 . 2013-04-13 12:24 364720 ----a-w- c:\windows\system32\IntelQuickSyncDecoder.dll
2013-04-13 12:24 . 2013-04-13 12:24 509952 ----a-w- c:\windows\system32\LAVSplitter.ax
2013-04-13 12:24 . 2013-04-13 12:24 272384 ----a-w- c:\windows\system32\LAVAudio.ax
2013-04-13 12:24 . 2013-04-13 12:24 421600 ----a-w- c:\windows\system32\swscale-lav-2.dll
2013-04-13 12:24 . 2013-04-13 12:24 7977200 ----a-w- c:\windows\system32\avcodec-lav-55.dll
2013-04-13 12:24 . 2013-04-13 12:24 289008 ----a-w- c:\windows\system32\avutil-lav-52.dll
2013-04-13 12:24 . 2013-04-13 12:24 202648 ----a-w- c:\windows\system32\avfilter-lav-3.dll
2013-04-13 12:24 . 2013-04-13 12:24 194016 ----a-w- c:\windows\system32\avresample-lav-1.dll
2013-04-13 12:24 . 2013-04-13 12:24 1245920 ----a-w- c:\windows\system32\avformat-lav-55.dll
2013-04-13 12:23 . 2013-04-13 12:23 7788672 ----a-w- c:\windows\SysWow64\avcodec-lav-55.dll
2013-04-13 12:23 . 2013-04-13 12:23 424624 ----a-w- c:\windows\SysWow64\LAVSplitter.ax
2013-04-13 12:23 . 2013-04-13 12:23 400592 ----a-w- c:\windows\SysWow64\swscale-lav-2.dll
2013-04-13 12:23 . 2013-04-13 12:23 284336 ----a-w- c:\windows\SysWow64\IntelQuickSyncDecoder.dll
2013-04-13 12:23 . 2013-04-13 12:23 272192 ----a-w- c:\windows\SysWow64\avutil-lav-52.dll
2013-04-13 12:23 . 2013-04-13 12:23 244400 ----a-w- c:\windows\SysWow64\LAVAudio.ax
2013-04-13 12:23 . 2013-04-13 12:23 194632 ----a-w- c:\windows\SysWow64\avfilter-lav-3.dll
2013-04-13 12:23 . 2013-04-13 12:23 172728 ----a-w- c:\windows\SysWow64\avresample-lav-1.dll
2013-04-13 12:23 . 2013-04-13 12:23 1300152 ----a-w- c:\windows\SysWow64\avformat-lav-55.dll
2013-04-13 12:23 . 2013-04-13 12:23 1185456 ----a-w- c:\windows\SysWow64\LAVVideo.ax
2013-04-13 05:49 . 2013-05-15 14:04 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2013-04-13 05:49 . 2013-05-15 14:04 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
2013-04-13 05:49 . 2013-05-15 14:04 308736 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll
2013-04-13 05:49 . 2013-05-15 14:04 111104 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll
2013-04-13 04:45 . 2013-05-15 14:04 474624 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2013-04-13 04:45 . 2013-05-15 14:04 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll
2013-04-12 14:45 . 2013-04-23 23:12 1656680 ----a-w- c:\windows\system32\drivers\ntfs.sys
2013-04-11 14:22 . 2011-06-11 08:58 770384 ----a-w- c:\windows\SysWow64\msvcr100.dll
2013-04-11 14:22 . 2011-06-11 08:58 421200 ----a-w- c:\windows\SysWow64\msvcp100.dll
2013-04-10 06:01 . 2013-05-15 14:04 265064 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2013-04-10 06:01 . 2013-05-15 14:04 983400 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2013-04-10 03:30 . 2013-05-15 14:04 3153920 ----a-w- c:\windows\system32\win32k.sys
2013-04-04 21:50 . 2012-09-12 23:42 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-03-30 04:42 . 2013-04-12 05:29 3379272 ----a-w- c:\windows\system32\drivers\RTKVHD64.sys
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BitComet"="c:\program files (x86)\BitComet\BitComet.exe" [2013-02-19 12805888]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2012-08-23 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"RequireSignedAppInit_DLLs"=0 (0x0)
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ    \0
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x]
R2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys;c:\windows\SYSNATIVE\DRIVERS\CtClsFlt.sys [x]
R3 hitmanpro37;HitmanPro 3.7 Support Driver;c:\windows\system32\drivers\hitmanpro37.sys;c:\windows\SYSNATIVE\drivers\hitmanpro37.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 PCTDMDefrag;PCTDMDefrag;c:\windows\system32\drivers\PCTDMDefrag.sys;c:\windows\SYSNATIVE\drivers\PCTDMDefrag.sys [x]
R3 PCTDSMon;PCTDSMon;c:\windows\system32\drivers\PCTDSMon.sys;c:\windows\SYSNATIVE\drivers\PCTDSMon.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
R3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys;c:\windows\SYSNATIVE\DRIVERS\yk62x64.sys [x]
R4 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x]
S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [x]
S3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys;c:\windows\SYSNATIVE\DRIVERS\dc3d.sys [x]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys;c:\windows\SYSNATIVE\DRIVERS\point64.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
2013-06-27 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-09 03:13]
.
2013-05-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore1ce4d34c2b38d74.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-17 02:54]
.
2013-06-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-17 02:54]
.
2013-04-27 c:\windows\Tasks\Wise Registry Cleaner Schedule Task.job
- c:\program files (x86)\Wise\Wise Registry Cleaner\WiseRegCleaner.exe [2013-01-19 22:41]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2010-06-04 392048]
"AWiC"="c:\program files (x86)\Atheros\AWiCMgr.exe" [2010-09-11 167936]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-08-01 2417032]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-11-14 163360]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-11-14 387616]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-11-14 418336]
.
------- Supplementary Scan -------
.
uStart Page = https://www.google.com/
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: &D&ownload &with BitComet - c:\program files (x86)\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all with BitComet - c:\program files (x86)\BitComet\BitComet.exe/AddAllLink.htm
Trusted Zone: dell.com
TCP: DhcpNameServer = 75.75.75.75 75.75.76.76
DPF: {682C59F5-478C-4421-9070-AD170D143B77} - hxxp://www.dell.com/support/troubleshooting/Content/Ode/pcd86.cab
DPF: {A084A130-28AE-4B32-B51A-1C8CE164BC88} - hxxp://www.convergysworkathome.com/AppHardT.CAB
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-Dark Dimensions 3 - City of Ash Collector's EditionFinal - c:\windows\Dark Dimensions 3 - City of Ash Collector's Edition\uninstall.exe
AddRemove-{750257DE-6C19-85A3-804D-A2D5C02A4D22} - c:\progra~3\INSTAL~1\{4DB6F~1\Setup.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}"=hex:51,66,7a,6c,4c,1d,38,12,df,c1,0b,
   27,57,07,ba,54,e4,0e,43,d0,22,fb,89,5b
"{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc,
   1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7
"{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}"=hex:51,66,7a,6c,4c,1d,38,12,0c,e0,e4,
   3d,b8,cc,34,0e,c3,b9,18,39,ba,81,ae,74
"{4C892A24-5B3B-71C0-15A0-4E5A3A9C4F72}"=hex:51,66,7a,6c,4c,1d,38,12,4a,29,9a,
   48,09,15,ae,34,6a,b6,0d,1a,3f,c2,0b,66
"{53707962-6F74-2D53-2644-206D7942484F}"=hex:51,66,7a,6c,4c,1d,38,12,0c,7a,63,
   57,46,21,3d,68,59,52,63,2d,7c,1c,0c,5b
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07,
   72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57
"{7F6AFBF1-E065-4627-A2FD-810366367D01}"=hex:51,66,7a,6c,4c,1d,38,12,9f,f8,79,
   7b,57,ae,49,03,dd,eb,c2,43,63,68,39,15
"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,
   94,30,02,d1,0f,f1,da,12,24,73,56,27,d2
"{9FDDE16B-836F-4806-AB1F-1455CBEFF289}"=hex:51,66,7a,6c,4c,1d,38,12,05,e2,ce,
   9b,5d,cd,68,0d,d4,09,57,15,ce,b1,b6,9d
"{AA58ED58-01DD-4D91-8333-CF10577473F7}"=hex:51,66,7a,6c,4c,1d,38,12,36,ee,4b,
   ae,ef,4f,ff,08,fc,25,8c,50,52,2a,37,e3
"{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}"=hex:51,66,7a,6c,4c,1d,38,12,07,5b,93,
   aa,6e,60,ba,0b,f0,6d,b2,b7,80,44,00,83
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,
   df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd
"{C4CFC0DE-134F-4466-B2A2-FF7C59A8BFAD}"=hex:51,66,7a,6c,4c,1d,3b,1b,e3,6b,d4,
   ed,48,70,39,39,96,99,8d,11,69,db,ca,81
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:7f,a8,6b,13,be,27,cd,01
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
   d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,cb,61,7c,9f,07,a0,0d,43,a7,be,13,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
   d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,cb,61,7c,9f,07,a0,0d,43,a7,be,13,\
.
[HKEY_USERS\S-1-5-21-3197802315-1125251100-3617295894-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.**ˆ]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-3197802315-1125251100-3617295894-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.**ˆ\OpenWithList]
@Class="Shell"
"a"="vlc.exe"
"MRUList"="a"
.
[HKEY_USERS\S-1-5-21-3197802315-1125251100-3617295894-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.**罨¾+²G3àç*€What you'd be wanting with me,]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-3197802315-1125251100-3617295894-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.**罨¾+²G3àç*€What you'd be wanting with me,\OpenWithList]
@Class="Shell"
"a"="vlc.exe"
"MRUList"="a"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
   00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows CE Services]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
   00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
.
**************************************************************************
.
Completion time: 2013-06-26  17:20:52 - machine was rebooted
ComboFix-quarantined-files.txt  2013-06-27 00:20
ComboFix2.txt  2013-06-26 12:55
ComboFix3.txt  2013-06-24 10:11
.
Pre-Run: 224,932,450,304 bytes free
Post-Run: 224,802,967,552 bytes free
.
- - End Of File - - A3DA3D6A27BE64F510041959044FD3B6
D41D8CD98F00B204E9800998ECF8427E
Upload was successful
 



#14 CatByte

CatByte

    bleepin' tiger


  • Malware Response Team
  • 14,664 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Canada
  • Local time:05:57 AM

Posted 26 June 2013 - 09:06 PM

Please run the following:

Please download the ESET services repair tool, extract the file to your desktop.
  • Double-click ServicesRepair.exe,
  • If security notifications appear, click Continue or Run and then click Yes when asked if you want to proceed.
  • Once the tool has finished, you will be prompted to restart your computer. Click Yes to restart.
  • a log will be saved in the CCSupport folder the tool created on your desktop, please post the content in your next reply
Pasted from <http://kb.eset.com/esetkb/index?page=content&id=SOLN2895>

Microsoft MVP - 2010, 2011, 2012, 2013, 2014, 2015


#15 Fhoosa

Fhoosa
  • Topic Starter

  • Members
  • 123 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Seabrook, TX
  • Local time:03:57 AM

Posted 26 June 2013 - 09:27 PM

Here it is...

 

 

Log Opened: 2013-06-26 @ 19:20:28
19:20:28 - -----------------
19:20:28 - | Begin Logging |
19:20:28 - -----------------
19:20:28 - Fix started on a WIN_7 X64 computer
19:20:28 - Prep in progress.  Please Wait.
19:20:31 - Prep complete
19:20:31 - Repairing Services Now.  Please wait...
INFO: The restore action ignores the object name parameter (paths are read from the backup file). However, other actions that require the object name may be combined with -restore.
INFORMATION: Input file for restore operation opened: '.\Win7\BFE.sddl'
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BFE\Parameters\Policy\Persistent\SubLayer>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BFE\Parameters\Policy\Persistent\Provider>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BFE\Parameters\Policy\Persistent\Filter>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BFE\Parameters\Policy\Persistent>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BFE\Parameters\Policy\BootTime\Filter>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BFE\Parameters\Policy\BootTime>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BFE\Parameters\Policy>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BFE\Parameters>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BFE>

SetACL finished successfully.
INFO: The restore action ignores the object name parameter (paths are read from the backup file). However, other actions that require the object name may be combined with -restore.
INFORMATION: Input file for restore operation opened: '.\Win7\BITS.sddl'
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BITS\Security>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BITS\Performance>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BITS\Parameters>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\BITS>

SetACL finished successfully.
INFO: The restore action ignores the object name parameter (paths are read from the backup file). However, other actions that require the object name may be combined with -restore.
INFORMATION: Input file for restore operation opened: '.\Win7\iphlpsvc.sddl'
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\iphlpsvc\Teredo>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\iphlpsvc\Parameters\Teredo\{FA88062C-9A61-4C1E-AC45-7143F8F01AAD}>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\iphlpsvc\Parameters\Teredo>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\iphlpsvc\Parameters\Isatap\{8AD2FB26-F91E-44F1-9B24-3C0AE56C9CE0}>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\iphlpsvc\Parameters\Isatap>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\iphlpsvc\Parameters\IPHTTPS>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\iphlpsvc\Parameters>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\iphlpsvc\Interfaces>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\iphlpsvc\config>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\iphlpsvc>

SetACL finished successfully.
INFO: The restore action ignores the object name parameter (paths are read from the backup file). However, other actions that require the object name may be combined with -restore.
INFORMATION: Input file for restore operation opened: '.\Win7\MpsSvc.sddl'
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\MpsSvc\Security>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\MpsSvc\Parameters\PortKeywords\Teredo>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\MpsSvc\Parameters\PortKeywords\RPC-EPMap>
ERROR: Writing SD to <machine\System\CurrentControlset\Services\MpsSvc\Parameters\PortKeywords\RPC-EPMap> failed with: The system cannot find the file specified.
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\MpsSvc\Parameters\PortKeywords\IPTLSOut>
ERROR: Writing SD to <machine\System\CurrentControlset\Services\MpsSvc\Parameters\PortKeywords\IPTLSOut> failed with: The system cannot find the file specified.
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\MpsSvc\Parameters\PortKeywords\IPTLSIn>
ERROR: Writing SD to <machine\System\CurrentControlset\Services\MpsSvc\Parameters\PortKeywords\IPTLSIn> failed with: The system cannot find the file specified.
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\MpsSvc\Parameters\PortKeywords\DHCP>
ERROR: Writing SD to <machine\System\CurrentControlset\Services\MpsSvc\Parameters\PortKeywords\DHCP> failed with: The system cannot find the file specified.
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\MpsSvc\Parameters\PortKeywords>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\MpsSvc\Parameters>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\MpsSvc>

SetACL finished successfully.
INFO: The restore action ignores the object name parameter (paths are read from the backup file). However, other actions that require the object name may be combined with -restore.
INFORMATION: Input file for restore operation opened: '.\Win7\SharedAccess.sddl'
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\Logging>
ERROR: Writing SD to <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\Logging> failed with: The system cannot find the file specified.
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts>
ERROR: Writing SD to <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts> failed with: The system cannot find the file specified.
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications>
ERROR: Writing SD to <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications> failed with: The system cannot find the file specified.
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile>
ERROR: Writing SD to <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile> failed with: Access is denied.
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\RestrictedServices\Static\System>
ERROR: Writing SD to <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\RestrictedServices\Static\System> failed with: The system cannot find the file specified.
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\RestrictedServices\Static>
ERROR: Writing SD to <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\RestrictedServices\Static> failed with: The system cannot find the file specified.
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\RestrictedServices\Configurable\System>
ERROR: Writing SD to <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\RestrictedServices\Configurable\System> failed with: The system cannot find the file specified.
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\RestrictedServices\Configurable>
ERROR: Writing SD to <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\RestrictedServices\Configurable> failed with: Access is denied.
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\RestrictedServices>
ERROR: Writing SD to <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\RestrictedServices> failed with: Access is denied.
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile\Logging>
ERROR: Writing SD to <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile\Logging> failed with: The system cannot find the file specified.
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile\GloballyOpenPorts>
ERROR: Writing SD to <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile\GloballyOpenPorts> failed with: The system cannot find the file specified.
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile\AuthorizedApplications>
ERROR: Writing SD to <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile\AuthorizedApplications> failed with: The system cannot find the file specified.
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile>
ERROR: Writing SD to <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile> failed with: Access is denied.
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules>
ERROR: Writing SD to <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules> failed with: Access is denied.
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\Logging>
ERROR: Writing SD to <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\Logging> failed with: The system cannot find the file specified.
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts>
ERROR: Writing SD to <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts> failed with: The system cannot find the file specified.
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications>
ERROR: Writing SD to <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications> failed with: The system cannot find the file specified.
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile>
ERROR: Writing SD to <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile> failed with: Access is denied.
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy>
ERROR: Writing SD to <machine\System\CurrentControlset\Services\SharedAccess\Parameters\FirewallPolicy> failed with: Access is denied.
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Parameters>
ERROR: Writing SD to <machine\System\CurrentControlset\Services\SharedAccess\Parameters> failed with: Access is denied.
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Epoch2>
ERROR: Writing SD to <machine\System\CurrentControlset\Services\SharedAccess\Epoch2> failed with: Access is denied.
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Epoch>
ERROR: Writing SD to <machine\System\CurrentControlset\Services\SharedAccess\Epoch> failed with: Access is denied.
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Defaults\FirewallPolicy\StandardProfile\Logging>
ERROR: Writing SD to <machine\System\CurrentControlset\Services\SharedAccess\Defaults\FirewallPolicy\StandardProfile\Logging> failed with: The system cannot find the file specified.
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Defaults\FirewallPolicy\StandardProfile>
ERROR: Writing SD to <machine\System\CurrentControlset\Services\SharedAccess\Defaults\FirewallPolicy\StandardProfile> failed with: The system cannot find the file specified.
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Defaults\FirewallPolicy\PublicProfile\Logging>
ERROR: Writing SD to <machine\System\CurrentControlset\Services\SharedAccess\Defaults\FirewallPolicy\PublicProfile\Logging> failed with: The system cannot find the file specified.
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Defaults\FirewallPolicy\PublicProfile>
ERROR: Writing SD to <machine\System\CurrentControlset\Services\SharedAccess\Defaults\FirewallPolicy\PublicProfile> failed with: The system cannot find the file specified.
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Defaults\FirewallPolicy\FirewallRules>
ERROR: Writing SD to <machine\System\CurrentControlset\Services\SharedAccess\Defaults\FirewallPolicy\FirewallRules> failed with: The system cannot find the file specified.
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Defaults\FirewallPolicy\DomainProfile\Logging>
ERROR: Writing SD to <machine\System\CurrentControlset\Services\SharedAccess\Defaults\FirewallPolicy\DomainProfile\Logging> failed with: The system cannot find the file specified.
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Defaults\FirewallPolicy\DomainProfile>
ERROR: Writing SD to <machine\System\CurrentControlset\Services\SharedAccess\Defaults\FirewallPolicy\DomainProfile> failed with: The system cannot find the file specified.
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Defaults\FirewallPolicy>
ERROR: Writing SD to <machine\System\CurrentControlset\Services\SharedAccess\Defaults\FirewallPolicy> failed with: The system cannot find the file specified.
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess\Defaults>
ERROR: Writing SD to <machine\System\CurrentControlset\Services\SharedAccess\Defaults> failed with: The system cannot find the file specified.
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\SharedAccess>

SetACL finished successfully.
INFO: The restore action ignores the object name parameter (paths are read from the backup file). However, other actions that require the object name may be combined with -restore.
INFORMATION: Input file for restore operation opened: '.\Win7\WinDefend.sddl'
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\WinDefend\TriggerInfo\0>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\WinDefend\TriggerInfo>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\WinDefend\Security>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\WinDefend\Parameters>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\WinDefend>

SetACL finished successfully.
INFO: The restore action ignores the object name parameter (paths are read from the backup file). However, other actions that require the object name may be combined with -restore.
INFORMATION: Input file for restore operation opened: '.\Win7\wscsvc.sddl'
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\wscsvc\Security>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\wscsvc\Parameters>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\wscsvc>

SetACL finished successfully.
INFO: The restore action ignores the object name parameter (paths are read from the backup file). However, other actions that require the object name may be combined with -restore.
INFORMATION: Input file for restore operation opened: '.\Win7\wuauserv.sddl'
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\wuauserv\Security>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\wuauserv\Parameters>
INFORMATION: Restoring SD of: <machine\System\CurrentControlset\Services\wuauserv>

SetACL finished successfully.
19:20:33 - Services Repair Complete.
19:20:42 - Reboot Initiated






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users