Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

DirtyDecrypt.exe (cannot view any of the documents on my computer)


  • This topic is locked This topic is locked
17 replies to this topic

#1 feeonme

feeonme

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:11:37 PM

Posted 11 August 2013 - 03:09 PM

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.16635  BrowserJavaVersion: 10.25.2
Run by Dad at 15:59:16 on 2013-08-11
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.1.1033.18.12278.9652 [GMT -4:00]
.
AV: AVG AntiVirus Free Edition 2013 *Enabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
AV: Lavasoft Ad-Aware *Disabled/Updated* {E0D97DD4-42BA-B3F2-A5A7-22E9ACE81FC7}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Lavasoft Ad-Aware *Disabled/Updated* {5BB89C30-6480-BC7C-9F17-199BD76F557A}
SP: AVG AntiVirus Free Edition 2013 *Enabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
FW: Lavasoft Ad-Aware *Disabled* {D8E2FCF1-08D5-B2AA-8EF8-8BDC523B58BC}
.
============== Running Processes ===============
.
C:\PROGRA~2\AVG\AVG2013\avgrsa.exe
C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe
C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.4.0\ToolbarUpdater.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.4.0\loggingserver.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\AVG\AVG2013\avgnsa.exe
C:\Program Files (x86)\AVG\AVG2013\avgemca.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe
C:\Program Files (x86)\AVG\AVG2013\avgui.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\AVG Secure Search\vprot.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM64.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\CORE-STATIC\CCC.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.btvguide.com/
uWindow Title = Internet Explorer, optimized for Bing and MSN
uURLSearchHooks: {A3BC75A2-1F87-4686-AA43-5347D756017C} - <orphaned>
dURLSearchHooks: Ad-Aware Security Add-on: {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\adawaretb\adawareDx.dll
mWinlogon: Userinit = userinit.exe
BHO: DivX Plus Web Player HTML5 <video>: {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
BHO: SteadyVideoBHO Class: {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files (x86)\AMD\SteadyVideo\SteadyVideo.dll
BHO: Ad-Aware Security Add-on: {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\adawaretb\adawareDx.dll
BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\15.4.0.5\AVG Secure Search_toolbar.dll
BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
TB: <No Name>: {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - LocalServer32 - <no file>
TB: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\15.4.0.5\AVG Secure Search_toolbar.dll
TB: Ad-Aware Security Add-on: {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\adawaretb\adawareDx.dll
uRun: [ccleaner] "C:\Program Files (x86)\CCleaner\CCleaner64.exe" /AUTO
uRun: [HydraVisionDesktopManager] "C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe"
mRun: [ATICustomerCare] "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe"
mRun: [Ad-Aware Browsing Protection] "C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe"
mRun: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe
mRun: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLY
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe"
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Open Client to monitor &1 - C:\Windows\web\AOpenClient.htm
IE: Open Client to monitor &2 - C:\Windows\web\AOpenClient.htm
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/_layouts/ClientBin/ieawsdc32.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_15-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_15-windows-i586.cab
TCP: NameServer = 209.18.47.61 209.18.47.62
TCP: Interfaces\{34D8ECAB-D865-48FE-B806-ED0FFDB4CD82} : DHCPNameServer = 209.18.47.61 209.18.47.62
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - <orphaned>
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\15.4.0\ViProtocol.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
x64-BHO: SteadyVideoBHO Class: {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab
x64-Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll
x64-Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll
x64-Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - <orphaned>
x64-Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\twcib4d7.default\
FF - prefs.js: keyword.URL - hxxp://safesearchr.lavasoft.com/?source=3336ca5f&tbp=url&toolbarid=adawaretb&u=046CBA92B2E36DBCB1E04A50C5323B70&q=
FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin.dll
FF - plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\15.4.0\npsitesafety.dll
FF - plugin: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
FF - plugin: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\Dad\AppData\Local\HuluDesktop\instances\0.9.14.1\nphdplg.dll
FF - plugin: C:\Users\Dad\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll
FF - plugin: C:\Windows\SysWOW64\npdeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
FF - ExtSQL: !HIDDEN! 2012-12-17 23:41; 64ffxtbr@TelevisionFanatic.com; C:\Program Files (x86)\TelevisionFanatic\bar\1.bin
.
---- FIREFOX POLICIES ----
FF - user.js: general.useragent.extra.brc -
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSHA;AVGIDSHA;C:\Windows\System32\drivers\avgidsha.sys [2013-7-20 71480]
R0 Avgloga;AVG Logging Driver;C:\Windows\System32\drivers\avgloga.sys [2013-7-20 311608]
R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\drivers\avgmfx64.sys [2013-7-1 116536]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\drivers\avgrkx64.sys [2013-7-10 45880]
R0 gfibto;gfibto;C:\Windows\System32\drivers\gfibto.sys [2012-12-9 14456]
R1 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\drivers\avgidsdrivera.sys [2013-7-20 246072]
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\drivers\avgldx64.sys [2013-7-20 206648]
R1 Avgtdia;AVG TDI Driver;C:\Windows\System32\drivers\avgtdia.sys [2013-3-21 240952]
R1 avgtp;avgtp;C:\Windows\System32\drivers\avgtpx64.sys [2012-9-27 45856]
R1 SBRE;SBRE;C:\Windows\System32\drivers\sbredrv.sys [2010-5-12 57976]
R2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2010/02/27 15:02:17];C:\Program Files (x86)\CyberLink\PowerDVD9\000.fcl [2009-9-1 146928]
R2 Ad-Aware Service;Ad-Aware Service;C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe [2012-12-7 1236368]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2013-6-4 241152]
R2 AMD FUEL Service;AMD FUEL Service;C:\Program Files\ATI Technologies\ATI.ACE\FUEL\Fuel.Service.exe [2013-6-4 361984]
R2 AODDriver4.01;AODDriver4.01;C:\Program Files\ATI Technologies\ATI.ACE\FUEL\amd64\aoddriver2.sys [2012-4-9 57472]
R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [2013-7-4 4939312]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [2013-7-23 283136]
R2 cpuz134;cpuz134;C:\Windows\System32\drivers\cpuz134_x64.sys [2011-1-4 21480]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-3-23 398184]
R2 vToolbarUpdater15.4.0;vToolbarUpdater15.4.0;C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.4.0\ToolbarUpdater.exe [2013-7-29 1616048]
R3 amdiox64;AMD IO Driver;C:\Windows\System32\drivers\amdiox64.sys [2011-1-26 46136]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2013-4-24 96768]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2013-3-23 24176]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2009-3-2 187392]
S2 AODDriver4.2;AODDriver4.2;C:\Program Files\ATI Technologies\ATI.ACE\FUEL\amd64\aoddriver2.sys [2012-4-9 57472]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-3-23 682344]
S2 SBAMSvc;Ad-Aware;C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe [2012-9-20 3677000]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;C:\Program Files (x86)\AVG\AVG10\Toolbar\ToolbarBroker.exe [2011-4-13 1025352]
S3 AVMNgBasM780;AVerMedia M780 Base Driver;C:\Windows\System32\drivers\AVerBas.sys [2009-6-11 72448]
S3 AVMNgCapM780;AVerMedia M780 Audio/Video Capture Driver;C:\Windows\System32\drivers\AVerCap.sys [2009-6-11 442368]
S3 AVMNgTunM780;AVerMedia M780 TVTuner Driver;C:\Windows\System32\drivers\AVerTun.sys [2009-6-11 240768]
S3 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys [2012-10-30 57856]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2012-9-12 1512448]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2013-3-7 19456]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2013-3-7 57856]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2011-8-2 51712]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-5-4 1255736]
S4 CLKMSVC10_9EC60124;CyberLink Product - 2012/01/21 19:29:51;C:\Program Files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe [2010-11-18 240112]
S4 VCL MySQL Database Server;VCL MySQL Database Server;"C:\Program Files (x86)\Chemistry Lab\mysql\bin\mysqld.exe" "VCL MySQL Database Server" --> C:\Program Files (x86)\Chemistry Lab\mysql\bin\mysqld.exe [?]
.
=============== Created Last 30 ================
.
2013-08-11 02:19:38    --------    d-----w-    C:\Users\Dad\AppData\Local\The Witcher
2013-08-07 23:08:36    --------    d-----w-    C:\ProgramData\SecTaskMan
2013-08-06 03:56:30    --------    d-----w-    C:\Program Files (x86)\The Witcher Enhanced Edition
2013-07-29 19:26:34    --------    d-----w-    C:\recovered crap
2013-07-29 19:01:51    --------    d-----w-    C:\Users\Dad\AppData\Local\Wondershare
2013-07-29 19:01:51    --------    d-----w-    C:\Program Files (x86)\Common Files\Wondershare
2013-07-29 19:01:48    --------    d-----w-    C:\Program Files (x86)\Temp
2013-07-29 19:01:47    --------    d-----w-    C:\Program Files (x86)\Wondershare
2013-07-21 14:32:17    --------    d-----w-    C:\Users\Dad\AppData\Roaming\AVG Secure Search
2013-07-20 05:51:00    311608    ----a-w-    C:\Windows\System32\drivers\avgloga.sys
2013-07-20 05:50:56    71480    ----a-w-    C:\Windows\System32\drivers\avgidsha.sys
2013-07-20 05:50:56    246072    ----a-w-    C:\Windows\System32\drivers\avgidsdrivera.sys
2013-07-20 05:50:50    206648    ----a-w-    C:\Windows\System32\drivers\avgldx64.sys
.
==================== Find3M  ====================
.
2013-07-29 20:32:22    45856    ----a-w-    C:\Windows\System32\drivers\avgtpx64.sys
2013-07-15 23:31:59    71048    ----a-w-    C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-07-15 23:31:59    692104    ----a-w-    C:\Windows\SysWow64\FlashPlayerApp.exe
2013-07-10 05:32:38    45880    ----a-w-    C:\Windows\System32\drivers\avgrkx64.sys
2013-07-02 21:54:53    25640    ----a-w-    C:\Windows\gdrv.sys
2013-07-01 05:45:28    116536    ----a-w-    C:\Windows\System32\drivers\avgmfx64.sys
2013-06-13 01:48:23    867240    ----a-w-    C:\Windows\SysWow64\npdeployJava1.dll
2013-06-13 01:48:17    789416    ----a-w-    C:\Windows\SysWow64\deployJava1.dll
2013-06-13 01:47:57    96168    ----a-w-    C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2013-06-11 23:43:37    1767936    ----a-w-    C:\Windows\SysWow64\wininet.dll
2013-06-11 23:43:00    2877440    ----a-w-    C:\Windows\SysWow64\jscript9.dll
2013-06-11 23:42:58    61440    ----a-w-    C:\Windows\SysWow64\iesetup.dll
2013-06-11 23:42:58    109056    ----a-w-    C:\Windows\SysWow64\iesysprep.dll
2013-06-11 23:26:20    2241024    ----a-w-    C:\Windows\System32\wininet.dll
2013-06-11 23:25:16    3958784    ----a-w-    C:\Windows\System32\jscript9.dll
2013-06-11 23:25:13    67072    ----a-w-    C:\Windows\System32\iesetup.dll
2013-06-11 23:25:13    136704    ----a-w-    C:\Windows\System32\iesysprep.dll
2013-06-11 22:51:45    71680    ----a-w-    C:\Windows\SysWow64\RegisterIEPKEYs.exe
2013-06-11 22:50:58    89600    ----a-w-    C:\Windows\System32\RegisterIEPKEYs.exe
2013-06-07 03:22:18    2706432    ----a-w-    C:\Windows\System32\mshtml.tlb
2013-06-07 02:37:52    2706432    ----a-w-    C:\Windows\SysWow64\mshtml.tlb
2013-06-05 03:34:27    3153920    ----a-w-    C:\Windows\System32\win32k.sys
2013-06-04 23:12:08    78432    ----a-w-    C:\Windows\System32\atimpc64.dll
2013-06-04 23:12:08    78432    ----a-w-    C:\Windows\System32\amdpcom64.dll
2013-06-04 23:12:06    71704    ----a-w-    C:\Windows\SysWow64\atimpc32.dll
2013-06-04 23:12:06    71704    ----a-w-    C:\Windows\SysWow64\amdpcom32.dll
2013-06-04 23:12:02    139696    ----a-w-    C:\Windows\System32\atiuxp64.dll
2013-06-04 23:12:02    123216    ----a-w-    C:\Windows\SysWow64\atiuxpag.dll
2013-06-04 23:12:00    97448    ----a-w-    C:\Windows\SysWow64\atiu9pag.dll
2013-06-04 23:12:00    113464    ----a-w-    C:\Windows\System32\atiu9p64.dll
2013-06-04 23:11:58    1182056    ----a-w-    C:\Windows\System32\aticfx64.dll
2013-06-04 23:11:56    990976    ----a-w-    C:\Windows\SysWow64\aticfx32.dll
2013-06-04 23:11:52    8431232    ----a-w-    C:\Windows\System32\atidxx64.dll
2013-06-04 23:11:50    7378560    ----a-w-    C:\Windows\SysWow64\atidxx32.dll
2013-06-04 23:11:46    4415256    ----a-w-    C:\Windows\SysWow64\atiumdva.dll
2013-06-04 23:11:42    5963328    ----a-w-    C:\Windows\SysWow64\atiumdag.dll
2013-06-04 23:11:38    4957536    ----a-w-    C:\Windows\System32\atiumd6a.dll
2013-06-04 23:11:34    6984088    ----a-w-    C:\Windows\System32\atiumd64.dll
2013-06-04 23:09:44    11833856    ----a-w-    C:\Windows\System32\drivers\atikmdag.sys
2013-06-04 22:51:20    229376    ----a-w-    C:\Windows\System32\clinfo.exe
2013-06-04 22:51:08    1187342    ----a-w-    C:\Windows\System32\amdocl_as64.exe
2013-06-04 22:51:08    1061902    ----a-w-    C:\Windows\System32\amdocl_ld64.exe
2013-06-04 22:51:06    995342    ----a-w-    C:\Windows\SysWow64\amdocl_as32.exe
2013-06-04 22:51:06    798734    ----a-w-    C:\Windows\SysWow64\amdocl_ld32.exe
2013-06-04 22:51:04    98304    ----a-w-    C:\Windows\System32\OpenVideo64.dll
2013-06-04 22:50:58    82944    ----a-w-    C:\Windows\SysWow64\OpenVideo.dll
2013-06-04 22:50:52    86016    ----a-w-    C:\Windows\System32\OVDecode64.dll
2013-06-04 22:50:48    72704    ----a-w-    C:\Windows\SysWow64\OVDecode.dll
2013-06-04 22:50:32    27800576    ----a-w-    C:\Windows\System32\amdocl64.dll
2013-06-04 22:48:22    23421440    ----a-w-    C:\Windows\SysWow64\amdocl.dll
2013-06-04 22:46:30    63488    ----a-w-    C:\Windows\System32\OpenCL.dll
2013-06-04 22:46:26    57344    ----a-w-    C:\Windows\SysWow64\OpenCL.dll
2013-06-04 22:33:48    24250880    ----a-w-    C:\Windows\System32\atio6axx.dll
2013-06-04 22:27:48    368640    ----a-w-    C:\Windows\System32\atiapfxx.exe
2013-06-04 22:25:14    51200    ----a-w-    C:\Windows\System32\aticalrt64.dll
2013-06-04 22:25:12    46080    ----a-w-    C:\Windows\SysWow64\aticalrt.dll
2013-06-04 22:25:06    44544    ----a-w-    C:\Windows\System32\aticalcl64.dll
2013-06-04 22:25:04    44032    ----a-w-    C:\Windows\SysWow64\aticalcl.dll
2013-06-04 22:25:00    118784    ----a-w-    C:\Windows\System32\coinst_13.101.dll
2013-06-04 22:24:52    16082944    ----a-w-    C:\Windows\System32\aticaldd64.dll
2013-06-04 22:20:26    13703168    ----a-w-    C:\Windows\SysWow64\aticaldd.dll
2013-06-04 22:13:12    19906560    ----a-w-    C:\Windows\SysWow64\atioglxx.dll
2013-06-04 22:03:30    442368    ----a-w-    C:\Windows\System32\atidemgy.dll
2013-06-04 22:03:18    26112    ----a-w-    C:\Windows\System32\atimuixx.dll
2013-06-04 22:03:14    562688    ----a-w-    C:\Windows\System32\atieclxx.exe
2013-06-04 22:02:24    241152    ----a-w-    C:\Windows\System32\atiesrxx.exe
2013-06-04 22:00:56    120320    ----a-w-    C:\Windows\System32\atitmm64.dll
2013-06-04 22:00:30    59392    ----a-w-    C:\Windows\System32\atiedu64.dll
2013-06-04 22:00:22    43520    ----a-w-    C:\Windows\SysWow64\ati2edxx.dll
2013-06-04 21:36:02    95232    ----a-w-    C:\Windows\System32\amdave64.dll
2013-06-04 21:35:54    89600    ----a-w-    C:\Windows\SysWow64\amdave32.dll
2013-06-04 21:35:54    594944    ----a-w-    C:\Windows\System32\atiadlxx.dll
2013-06-04 21:35:44    419840    ----a-w-    C:\Windows\SysWow64\atiadlxy.dll
2013-06-04 21:35:40    89088    ----a-w-    C:\Windows\System32\atisamu64.dll
2013-06-04 21:35:32    80896    ----a-w-    C:\Windows\SysWow64\atisamu32.dll
2013-06-04 21:35:32    17408    ----a-w-    C:\Windows\System32\atig6pxx.dll
2013-06-04 21:35:28    15872    ----a-w-    C:\Windows\SysWow64\atiglpxx.dll
2013-06-04 21:35:28    15872    ----a-w-    C:\Windows\System32\atiglpxx.dll
2013-06-04 21:35:24    41984    ----a-w-    C:\Windows\System32\atig6txx.dll
2013-06-04 21:35:14    36352    ----a-w-    C:\Windows\SysWow64\atigktxx.dll
2013-06-04 21:35:04    608768    ----a-w-    C:\Windows\System32\drivers\atikmpag.sys
2013-06-04 21:31:40    43520    ----a-w-    C:\Windows\System32\drivers\ati2erec.dll
2013-06-04 06:00:13    624128    ----a-w-    C:\Windows\System32\qedit.dll
2013-06-04 04:53:07    509440    ----a-w-    C:\Windows\SysWow64\qedit.dll
.
============= FINISH: 15:59:27.42 ===============
 

 



BC AdBot (Login to Remove)

 


#2 feeonme

feeonme
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:11:37 PM

Posted 14 August 2013 - 09:13 AM

A local repair shop was able to fully remove the malware from my computer but has not been able to recover any of my documents. I have research papers from my work over the last 5 years and am now unable to access the only copy I had of any of them. If anyone has any insight at all on how to recover files affected by this particular malware I would be most appreciative.



#3 HelpBot

HelpBot

    Bleepin' Binary Bot


  • Bots
  • 12,731 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:37 PM

Posted 16 August 2013 - 03:10 PM

Hello and welcome to Bleeping Computer!

I am HelpBot: an automated program designed to help the Bleeping Computer Staff better assist you! This message contains very important information, so please read through all of it before doing anything.

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

To help Bleeping Computer better assist you please perform the following steps:

***************************************************

step1.gif In order to continue receiving help at BleepingComputer.com, YOU MUST tell me if you still need help or if your issue has already been resolved on your own or through another resource! To tell me this, please click on the following link and follow the instructions there.

CLICK THIS LINK >>> http://www.bleepingcomputer.com/logreply/504060 <<< CLICK THIS LINK



If you no longer need help, then all you needed to do was the previous instructions of telling me so. You can skip the rest of this post. If you do need help please continue with Step 2 below.

***************************************************

step2.gifIf you still need help, I would like you to post a Reply to this topic (click the "Add Reply" button in the lower right hand of this page). In that reply, please include the following information:

  • If you have not done so already, include a clear description of the problems you're having, along with any steps you may have performed so far.
  • A new DDS log. For your convenience, you will find the instructions for generating these logs repeated at the bottom of this post.
    • Please do this even if you have previously posted logs for us.
    • If you were unable to produce the logs originally please try once more.
    • If you are unable to create a log please provide detailed information about your installed Windows Operating System including the Version, Edition and if it is a 32bit or a 64bit system.
    • If you are unsure about any of these characteristics just post what you can and we will guide you.
  • Please tell us if you have your original Windows CD/DVD available.
  • Upon completing the above steps and posting a reply, another staff member will review your topic and do their best to resolve your issues.

Thank you for your patience, and again sorry for the delay.

***************************************************

We need to see some information about what is happening in your machine. Please perform the following scan again:

  • Download DDS by sUBs from the following link if you no longer have it available and save it to your destop.

    DDS.com Download Link
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control can be found HERE.

As I am just a silly little program running on the BleepingComputer.com servers, please do not send me private messages as I do not know how to read and reply to them! Thanks!

#4 feeonme

feeonme
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:11:37 PM

Posted 16 August 2013 - 11:12 PM

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.16660  BrowserJavaVersion: 10.25.2
Run by Dad at 0:06:09 on 2013-08-17
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.1.1033.18.12278.10116 [GMT -4:00]
.
AV: Dr.Web Anti-virus *Enabled/Outdated* {A8C161B2-600A-42FD-97E0-4C12952A9FEC}
AV: Lavasoft Ad-Aware *Disabled/Updated* {E0D97DD4-42BA-B3F2-A5A7-22E9ACE81FC7}
SP: Dr.Web Anti-virus *Enabled/Outdated* {13A08056-4630-4D73-AD50-7760EEADD551}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Lavasoft Ad-Aware *Disabled/Updated* {5BB89C30-6480-BC7C-9F17-199BD76F557A}
FW: Lavasoft Ad-Aware *Disabled* {D8E2FCF1-08D5-B2AA-8EF8-8BDC523B58BC}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\atieclxx.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
C:\Program Files\DrWeb\dwservice.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.4.0\ToolbarUpdater.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.4.0\loggingserver.exe
C:\Program Files\Common Files\Doctor Web\Scanning Engine\dwengine.exe
C:\Program Files\Common Files\Doctor Web\Scanning Engine\dwarkdaemon.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\DrWeb\dwnetfilter.exe
C:\Program Files\Common Files\Doctor Web\Scanning Engine\dwengine.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
C:\Program Files\DrWeb\spideragent.exe
C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\AVG Secure Search\vprot.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM64.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\CORE-STATIC\CCC.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Windows\system32\Macromed\Flash\FlashUtil64_11_7_700_224_ActiveX.exe
C:\Program Files\DrWeb\SpiderAgent_Adm.exe
C:\Program Files\DrWeb\spideragent.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.btvguide.com/
uWindow Title = Internet Explorer, optimized for Bing and MSN
dURLSearchHooks: Ad-Aware Security Add-on: {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\adawaretb\adawareDx.dll
mWinlogon: Userinit = userinit.exe
BHO: DivX Plus Web Player HTML5 <video>: {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
BHO: SteadyVideoBHO Class: {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files (x86)\AMD\SteadyVideo\SteadyVideo.dll
BHO: Ad-Aware Security Add-on: {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\adawaretb\adawareDx.dll
BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\15.4.0.5\AVG Secure Search_toolbar.dll
BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
TB: <No Name>: {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - LocalServer32 - <no file>
TB: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\15.4.0.5\AVG Secure Search_toolbar.dll
TB: Ad-Aware Security Add-on: {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\adawaretb\adawareDx.dll
uRun: [ccleaner] "C:\Program Files (x86)\CCleaner\CCleaner64.exe" /AUTO
uRun: [HydraVisionDesktopManager] "C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe"
mRun: [ATICustomerCare] "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe"
mRun: [Ad-Aware Browsing Protection] "C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe"
mRun: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe"
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Open Client to monitor &1 - C:\Windows\web\AOpenClient.htm
IE: Open Client to monitor &2 - C:\Windows\web\AOpenClient.htm
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/_layouts/ClientBin/ieawsdc32.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_15-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_15-windows-i586.cab
TCP: NameServer = 209.18.47.61 209.18.47.62
TCP: Interfaces\{34D8ECAB-D865-48FE-B806-ED0FFDB4CD82} : DHCPNameServer = 209.18.47.61 209.18.47.62
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - <orphaned>
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\15.4.0\ViProtocol.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
x64-BHO: SteadyVideoBHO Class: {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-Run: [SpIDerAgent] "C:\Program Files\DrWeb\spideragent.exe"
x64-DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab
x64-Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll
x64-Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll
x64-Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - <orphaned>
x64-Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\twcib4d7.default\
FF - prefs.js: keyword.URL - hxxp://safesearchr.lavasoft.com/?source=3336ca5f&tbp=url&toolbarid=adawaretb&u=046CBA92B2E36DBCB1E04A50C5323B70&q=
FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin.dll
FF - plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\15.4.0\npsitesafety.dll
FF - plugin: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
FF - plugin: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\Dad\AppData\Local\HuluDesktop\instances\0.9.14.1\nphdplg.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll
FF - plugin: C:\Windows\SysWOW64\npdeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
FF - ExtSQL: !HIDDEN! 2012-12-17 23:41; 64ffxtbr@TelevisionFanatic.com; C:\Program Files (x86)\TelevisionFanatic\bar\1.bin
.
---- FIREFOX POLICIES ----
FF - user.js: general.useragent.extra.brc -
.
============= SERVICES / DRIVERS ===============
.
R0 DwProt;DrWeb Protection;C:\Windows\System32\drivers\dwprot.sys [2013-8-13 255672]
R0 gfibto;gfibto;C:\Windows\System32\drivers\gfibto.sys [2012-12-9 14456]
R0 SpiderG3;DrWeb file system scanner;C:\Windows\System32\drivers\spiderg3.sys [2013-8-13 234168]
R1 avgtp;avgtp;C:\Windows\System32\drivers\avgtpx64.sys [2012-9-27 45856]
R1 DrWebWfp;DrWebWfp;C:\Windows\System32\drivers\dw_wfp.sys [2013-8-13 74912]
R1 SBRE;SBRE;C:\Windows\System32\drivers\sbredrv.sys [2010-5-12 57976]
R2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2010/02/27 15:02:17];C:\Program Files (x86)\CyberLink\PowerDVD9\000.fcl [2009-9-1 146928]
R2 Ad-Aware Service;Ad-Aware Service;C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe [2012-12-7 1236368]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2013-6-4 241152]
R2 AMD FUEL Service;AMD FUEL Service;C:\Program Files\ATI Technologies\ATI.ACE\FUEL\Fuel.Service.exe [2013-6-4 361984]
R2 AODDriver4.01;AODDriver4.01;C:\Program Files\ATI Technologies\ATI.ACE\FUEL\amd64\aoddriver2.sys [2012-4-9 57472]
R2 cpuz134;cpuz134;C:\Windows\System32\drivers\cpuz134_x64.sys [2011-1-4 21480]
R2 DrWebAVService;Dr.Web Control Service;C:\Program Files\DrWeb\dwservice.exe [2013-8-13 5263600]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-3-23 398184]
R2 SBAMSvc;Ad-Aware;C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe [2012-9-20 3677000]
R2 vToolbarUpdater15.4.0;vToolbarUpdater15.4.0;C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.4.0\ToolbarUpdater.exe [2013-7-29 1616048]
R3 amdiox64;AMD IO Driver;C:\Windows\System32\drivers\amdiox64.sys [2011-1-26 46136]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2013-4-24 96768]
R3 DrWebEngine;Dr.Web Scanning Engine (DrWebEngine);C:\Program Files\Common Files\Doctor Web\Scanning Engine\dwengine.exe [2013-8-13 1968192]
R3 DrWebNetFilter;Dr.Web Net Filtering Service;C:\Program Files\DrWeb\dwnetfilter.exe [2013-8-13 5435648]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2013-3-23 24176]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2009-3-2 187392]
S2 AODDriver4.2;AODDriver4.2;C:\Program Files\ATI Technologies\ATI.ACE\FUEL\amd64\aoddriver2.sys [2012-4-9 57472]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-3-23 682344]
S3 AVMNgBasM780;AVerMedia M780 Base Driver;C:\Windows\System32\drivers\AVerBas.sys [2009-6-11 72448]
S3 AVMNgCapM780;AVerMedia M780 Audio/Video Capture Driver;C:\Windows\System32\drivers\AVerCap.sys [2009-6-11 442368]
S3 AVMNgTunM780;AVerMedia M780 TVTuner Driver;C:\Windows\System32\drivers\AVerTun.sys [2009-6-11 240768]
S3 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys [2012-10-30 57856]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2012-9-12 1512448]
S3 hitmanpro37;HitmanPro 3.7 Support Driver;C:\Windows\System32\drivers\hitmanpro37.sys [2013-8-13 32000]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2013-3-7 19456]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2013-3-7 57856]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2011-8-2 51712]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-5-4 1255736]
S4 CLKMSVC10_9EC60124;CyberLink Product - 2012/01/21 19:29:51;C:\Program Files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe [2010-11-18 240112]
.
=============== Created Last 30 ================
.
2013-08-15 06:17:56    --------    d-----w-    C:\Windows\System32\MRT
2013-08-15 04:24:59    3968960    ----a-w-    C:\Windows\SysWow64\ntkrnlpa.exe
2013-08-15 04:24:59    3913664    ----a-w-    C:\Windows\SysWow64\ntoskrnl.exe
2013-08-15 04:24:58    5550528    ----a-w-    C:\Windows\System32\ntoskrnl.exe
2013-08-15 04:24:58    5120    ----a-w-    C:\Windows\SysWow64\wow32.dll
2013-08-15 04:24:58    243712    ----a-w-    C:\Windows\System32\wow64.dll
2013-08-15 04:24:58    1732032    ----a-w-    C:\Windows\System32\ntdll.dll
2013-08-15 04:24:58    14336    ----a-w-    C:\Windows\SysWow64\ntvdm64.dll
2013-08-15 04:24:58    1292192    ----a-w-    C:\Windows\SysWow64\ntdll.dll
2013-08-15 04:24:57    7680    ----a-w-    C:\Windows\SysWow64\instnm.exe
2013-08-15 04:24:57    25600    ----a-w-    C:\Windows\SysWow64\setup16.exe
2013-08-15 04:24:57    2048    ----a-w-    C:\Windows\SysWow64\user.exe
2013-08-15 04:24:56    39936    ----a-w-    C:\Windows\System32\drivers\tssecsrv.sys
2013-08-15 04:24:55    1910208    ----a-w-    C:\Windows\System32\drivers\tcpip.sys
2013-08-15 00:15:42    --------    d-sh--w-    C:\Users\Dad\AppData\Roaming\wyUpdate AU
2013-08-14 03:28:37    --------    d-----w-    C:\Users\Dad\AppData\Roaming\Mael
2013-08-14 03:22:14    --------    d-----w-    C:\Program Files (x86)\HxD
2013-08-14 03:18:01    --------    d-sh--w-    C:\DrWeb Quarantine
2013-08-14 01:32:32    --------    d-sh--w-    C:\found.001
2013-08-13 23:17:39    255672    ----a-w-    C:\Windows\System32\drivers\dwprot.sys
2013-08-13 23:17:36    74912    ----a-w-    C:\Windows\System32\drivers\dw_wfp.sys
2013-08-13 23:17:36    234168    ----a-w-    C:\Windows\System32\drivers\spiderg3.sys
2013-08-13 23:17:20    --------    d-----w-    C:\Program Files\Common Files\Doctor Web
2013-08-13 23:17:07    --------    d-----w-    C:\Program Files\DrWeb
2013-08-13 22:53:58    --------    d-----w-    C:\ProgramData\Doctor Web
2013-08-13 22:39:55    --------    d-----w-    C:\Users\Dad\Doctor Web
2013-08-13 21:49:00    32000    ----a-w-    C:\Windows\System32\drivers\hitmanpro37.sys
2013-08-13 21:39:33    --------    d-----w-    C:\ProgramData\HitmanPro
2013-08-13 20:29:37    --------    d---a-w-    C:\.Trash-999
2013-08-13 19:41:34    --------    d-----w-    C:\Program Files\Speccy
2013-08-11 02:19:38    --------    d-----w-    C:\Users\Dad\AppData\Local\The Witcher
2013-08-07 23:08:36    --------    d-----w-    C:\ProgramData\SecTaskMan
2013-08-06 03:56:30    --------    d-----w-    C:\Program Files (x86)\The Witcher Enhanced Edition
2013-07-29 19:26:34    --------    d-----w-    C:\recovered crap
2013-07-29 19:01:51    --------    d-----w-    C:\Users\Dad\AppData\Local\Wondershare
2013-07-29 19:01:51    --------    d-----w-    C:\Program Files (x86)\Common Files\Wondershare
2013-07-29 19:01:48    --------    d-----w-    C:\Program Files (x86)\Temp
2013-07-29 19:01:47    --------    d-----w-    C:\Program Files (x86)\Wondershare
2013-07-21 14:32:17    --------    d-----w-    C:\Users\Dad\AppData\Roaming\AVG Secure Search
.
==================== Find3M  ====================
.
2013-07-29 20:32:22    45856    ----a-w-    C:\Windows\System32\drivers\avgtpx64.sys
2013-07-26 05:13:37    2241024    ----a-w-    C:\Windows\System32\wininet.dll
2013-07-26 05:12:08    3958784    ----a-w-    C:\Windows\System32\jscript9.dll
2013-07-26 05:12:04    136704    ----a-w-    C:\Windows\System32\iesysprep.dll
2013-07-26 05:12:03    67072    ----a-w-    C:\Windows\System32\iesetup.dll
2013-07-26 03:35:08    2706432    ----a-w-    C:\Windows\System32\mshtml.tlb
2013-07-26 03:13:24    1767936    ----a-w-    C:\Windows\SysWow64\wininet.dll
2013-07-26 03:12:04    2877440    ----a-w-    C:\Windows\SysWow64\jscript9.dll
2013-07-26 03:12:00    61440    ----a-w-    C:\Windows\SysWow64\iesetup.dll
2013-07-26 03:12:00    109056    ----a-w-    C:\Windows\SysWow64\iesysprep.dll
2013-07-26 02:49:14    2706432    ----a-w-    C:\Windows\SysWow64\mshtml.tlb
2013-07-26 02:39:38    89600    ----a-w-    C:\Windows\System32\RegisterIEPKEYs.exe
2013-07-26 01:59:38    71680    ----a-w-    C:\Windows\SysWow64\RegisterIEPKEYs.exe
2013-07-25 09:25:54    1888768    ----a-w-    C:\Windows\System32\WMVDECOD.DLL
2013-07-25 08:57:27    1620992    ----a-w-    C:\Windows\SysWow64\WMVDECOD.DLL
2013-07-19 01:58:42    2048    ----a-w-    C:\Windows\System32\tzres.dll
2013-07-19 01:41:01    2048    ----a-w-    C:\Windows\SysWow64\tzres.dll
2013-07-15 23:31:59    71048    ----a-w-    C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-07-15 23:31:59    692104    ----a-w-    C:\Windows\SysWow64\FlashPlayerApp.exe
2013-07-09 05:52:52    224256    ----a-w-    C:\Windows\System32\wintrust.dll
2013-07-09 05:51:16    1217024    ----a-w-    C:\Windows\System32\rpcrt4.dll
2013-07-09 05:46:20    184320    ----a-w-    C:\Windows\System32\cryptsvc.dll
2013-07-09 05:46:20    1472512    ----a-w-    C:\Windows\System32\crypt32.dll
2013-07-09 05:46:20    139776    ----a-w-    C:\Windows\System32\cryptnet.dll
2013-07-09 04:52:33    663552    ----a-w-    C:\Windows\SysWow64\rpcrt4.dll
2013-07-09 04:52:10    175104    ----a-w-    C:\Windows\SysWow64\wintrust.dll
2013-07-09 04:46:31    140288    ----a-w-    C:\Windows\SysWow64\cryptsvc.dll
2013-07-09 04:46:31    1166848    ----a-w-    C:\Windows\SysWow64\crypt32.dll
2013-07-09 04:46:31    103936    ----a-w-    C:\Windows\SysWow64\cryptnet.dll
2013-07-09 04:45:07    44032    ----a-w-    C:\Windows\apppatch\acwow64.dll
2013-07-02 21:54:53    25640    ----a-w-    C:\Windows\gdrv.sys
2013-06-13 01:48:23    867240    ----a-w-    C:\Windows\SysWow64\npdeployJava1.dll
2013-06-13 01:48:17    789416    ----a-w-    C:\Windows\SysWow64\deployJava1.dll
2013-06-13 01:47:57    96168    ----a-w-    C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2013-06-05 03:34:27    3153920    ----a-w-    C:\Windows\System32\win32k.sys
2013-06-04 23:12:08    78432    ----a-w-    C:\Windows\System32\atimpc64.dll
2013-06-04 23:12:08    78432    ----a-w-    C:\Windows\System32\amdpcom64.dll
2013-06-04 23:12:06    71704    ----a-w-    C:\Windows\SysWow64\atimpc32.dll
2013-06-04 23:12:06    71704    ----a-w-    C:\Windows\SysWow64\amdpcom32.dll
2013-06-04 23:12:02    139696    ----a-w-    C:\Windows\System32\atiuxp64.dll
2013-06-04 23:12:02    123216    ----a-w-    C:\Windows\SysWow64\atiuxpag.dll
2013-06-04 23:12:00    97448    ----a-w-    C:\Windows\SysWow64\atiu9pag.dll
2013-06-04 23:12:00    113464    ----a-w-    C:\Windows\System32\atiu9p64.dll
2013-06-04 23:11:58    1182056    ----a-w-    C:\Windows\System32\aticfx64.dll
2013-06-04 23:11:56    990976    ----a-w-    C:\Windows\SysWow64\aticfx32.dll
2013-06-04 23:11:52    8431232    ----a-w-    C:\Windows\System32\atidxx64.dll
2013-06-04 23:11:50    7378560    ----a-w-    C:\Windows\SysWow64\atidxx32.dll
2013-06-04 23:11:46    4415256    ----a-w-    C:\Windows\SysWow64\atiumdva.dll
2013-06-04 23:11:42    5963328    ----a-w-    C:\Windows\SysWow64\atiumdag.dll
2013-06-04 23:11:38    4957536    ----a-w-    C:\Windows\System32\atiumd6a.dll
2013-06-04 23:11:34    6984088    ----a-w-    C:\Windows\System32\atiumd64.dll
2013-06-04 23:09:44    11833856    ----a-w-    C:\Windows\System32\drivers\atikmdag.sys
2013-06-04 22:51:20    229376    ----a-w-    C:\Windows\System32\clinfo.exe
2013-06-04 22:51:08    1187342    ----a-w-    C:\Windows\System32\amdocl_as64.exe
2013-06-04 22:51:08    1061902    ----a-w-    C:\Windows\System32\amdocl_ld64.exe
2013-06-04 22:51:06    995342    ----a-w-    C:\Windows\SysWow64\amdocl_as32.exe
2013-06-04 22:51:06    798734    ----a-w-    C:\Windows\SysWow64\amdocl_ld32.exe
2013-06-04 22:51:04    98304    ----a-w-    C:\Windows\System32\OpenVideo64.dll
2013-06-04 22:50:58    82944    ----a-w-    C:\Windows\SysWow64\OpenVideo.dll
2013-06-04 22:50:52    86016    ----a-w-    C:\Windows\System32\OVDecode64.dll
2013-06-04 22:50:48    72704    ----a-w-    C:\Windows\SysWow64\OVDecode.dll
2013-06-04 22:50:32    27800576    ----a-w-    C:\Windows\System32\amdocl64.dll
2013-06-04 22:48:22    23421440    ----a-w-    C:\Windows\SysWow64\amdocl.dll
2013-06-04 22:46:30    63488    ----a-w-    C:\Windows\System32\OpenCL.dll
2013-06-04 22:46:26    57344    ----a-w-    C:\Windows\SysWow64\OpenCL.dll
2013-06-04 22:33:48    24250880    ----a-w-    C:\Windows\System32\atio6axx.dll
2013-06-04 22:27:48    368640    ----a-w-    C:\Windows\System32\atiapfxx.exe
2013-06-04 22:25:14    51200    ----a-w-    C:\Windows\System32\aticalrt64.dll
2013-06-04 22:25:12    46080    ----a-w-    C:\Windows\SysWow64\aticalrt.dll
2013-06-04 22:25:06    44544    ----a-w-    C:\Windows\System32\aticalcl64.dll
2013-06-04 22:25:04    44032    ----a-w-    C:\Windows\SysWow64\aticalcl.dll
2013-06-04 22:25:00    118784    ----a-w-    C:\Windows\System32\coinst_13.101.dll
2013-06-04 22:24:52    16082944    ----a-w-    C:\Windows\System32\aticaldd64.dll
2013-06-04 22:20:26    13703168    ----a-w-    C:\Windows\SysWow64\aticaldd.dll
2013-06-04 22:13:12    19906560    ----a-w-    C:\Windows\SysWow64\atioglxx.dll
2013-06-04 22:03:30    442368    ----a-w-    C:\Windows\System32\atidemgy.dll
2013-06-04 22:03:18    26112    ----a-w-    C:\Windows\System32\atimuixx.dll
2013-06-04 22:03:14    562688    ----a-w-    C:\Windows\System32\atieclxx.exe
2013-06-04 22:02:24    241152    ----a-w-    C:\Windows\System32\atiesrxx.exe
2013-06-04 22:00:56    120320    ----a-w-    C:\Windows\System32\atitmm64.dll
2013-06-04 22:00:30    59392    ----a-w-    C:\Windows\System32\atiedu64.dll
2013-06-04 22:00:22    43520    ----a-w-    C:\Windows\SysWow64\ati2edxx.dll
2013-06-04 21:36:02    95232    ----a-w-    C:\Windows\System32\amdave64.dll
2013-06-04 21:35:54    89600    ----a-w-    C:\Windows\SysWow64\amdave32.dll
2013-06-04 21:35:54    594944    ----a-w-    C:\Windows\System32\atiadlxx.dll
2013-06-04 21:35:44    419840    ----a-w-    C:\Windows\SysWow64\atiadlxy.dll
2013-06-04 21:35:40    89088    ----a-w-    C:\Windows\System32\atisamu64.dll
2013-06-04 21:35:32    80896    ----a-w-    C:\Windows\SysWow64\atisamu32.dll
2013-06-04 21:35:32    17408    ----a-w-    C:\Windows\System32\atig6pxx.dll
2013-06-04 21:35:28    15872    ----a-w-    C:\Windows\SysWow64\atiglpxx.dll
2013-06-04 21:35:28    15872    ----a-w-    C:\Windows\System32\atiglpxx.dll
2013-06-04 21:35:24    41984    ----a-w-    C:\Windows\System32\atig6txx.dll
2013-06-04 21:35:14    36352    ----a-w-    C:\Windows\SysWow64\atigktxx.dll
2013-06-04 21:35:04    608768    ----a-w-    C:\Windows\System32\drivers\atikmpag.sys
2013-06-04 21:31:40    43520    ----a-w-    C:\Windows\System32\drivers\ati2erec.dll
2013-06-04 06:00:13    624128    ----a-w-    C:\Windows\System32\qedit.dll
2013-06-04 04:53:07    509440    ----a-w-    C:\Windows\SysWow64\qedit.dll
.
============= FINISH:  0:06:41.11 ===============

Attached Files



#5 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,444 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:08:37 PM

Posted 22 August 2013 - 08:21 PM

Greetings feeonme and :welcome: to BleepingComputer's Virus/Trojan/Spyware/Malware Removal forum.

My name is Oh My! and I am here to help you! Now that we are "friends" please call me Gary.

If you would allow me to call you by your first name I would prefer to do that. :thumbup2:

===================================================

Ground Rules:
  • First, I would like to inform you that most of us here at Bleeping Computer offer our expert assistance out of the goodness of our hearts. Please try to match our commitment to you with your patience toward us. If this was easy we would never have met. :)
  • Please do not run any tools or take any steps other than those I will provide for you while we work on your computer together. I need to be certain about the state of your computer in order to provide appropriate and effective steps for you to take. Most often "well intentioned" (and usually panic driven!) independent efforts can make things much worse for both of us. If at any point you would prefer to take your own steps please let me know, I will not be offended. I would be happy to focus on the many others who are waiting in line for assistance.
  • Please perform all steps in the order they are listed in each set of instructions. Some steps may be a bit complicated. If things are not clear, be sure to stop and let me know. We need to work on this together with confidence.
  • Please copy and paste all logs into your post unless directed otherwise. Please do not re-run any programs I suggest. If you encounter problems simply stop and tell me.
  • When you post your reply, use the Replytopic.jpg button instead.
  • In the upper right hand corner of the topic you will see the Followtopic.jpg button. Click on this then choose Immediate E-Mail notification and then Proceed and you will be sent an email once I have posted a response.
  • If you do not reply to your topic after 5 days we assume it has been abandoned and I will close it.
  • When your computer is clean I will alert you of such. I will also provide for you detailed information about how you can combat future infections.
  • I would like to remind you to make no further changes to your computer unless I direct you to do so.
  • Now let's get started :thumbup2:
===================================================

Now that I am assisting you, you can expect that I will be very responsive to your situation. If you are able, I would request you check this thread at least once per day so that we can try to resolve your issues effectively and efficiently. If you are going to be delayed please be considerate and post that information so that I know you are still with me. Unfortunately, there are many people waiting to be assisted and not enough of us at BleepingComputer to go around. I appreciate your understanding and diligence.

Thank you for your patience thus far. I am pretty certain we will not be able to decrypt your files but we can take a look anyway. Please run this program for me.

===================================================

Farbar Recovery Scan Tool (FRST)

--------------------
  • Download Farbar Recover Scan Tool for either 32 bit or 64 bit systems and save it to your desktop
  • If you are unsure if you have 32 bit or 64 bit simply download and try one. If that doesn't run properly the other one should
  • Double click the icon
  • Click Yes to the disclaimer
  • Click Scan and allow the program to run
  • Click OK on the Scan complete screen, then OK on the Addition.txt pop up screen
  • 2 Notepad documents should now be open on your desktop.
  • Please copy and paste the contents of both in your reply
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • FRST results
  • Addition log

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"May you be richly rewarded by the Lord, the God of Israel, under whose wings you have come to take refuge."

#6 feeonme

feeonme
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:11:37 PM

Posted 22 August 2013 - 09:40 PM

Hi Gary,

I am Bill and thanks for attempting to recover my files with me. I do have a local repair also attempting but I left him a copy of my HD so only you will be working on this one. I will let you know if he comes up with something as well.

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version:

21-08-2013 02
Ran by Dad (administrator) on 22-08-2013 22:36:38
Running from C:\Users\Dad\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: English

(US)
Internet Explorer Version 10
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG

\AVG2013\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG

\AVG2013\avgwdsvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared

\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared

\Windows Live\WLIDSvcM.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG

\AVG2013\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG

\AVG2013\avgemca.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG

\AVG2013\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG

\AVG2013\avgcsrva.exe
(Microsoft Corporation) c:\Program Files\Microsoft Mouse and

Keyboard Center\ipoint.exe
(Microsoft Corporation) c:\Program Files\Microsoft Mouse and

Keyboard Center\itype.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG

\AVG2013\avgui.exe
() C:\Program Files (x86)\AVG Secure Search\vprot.exe
(Microsoft Corporation) C:\Program Files (x86)\Internet Explorer

\IELowutil.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox

\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash

\FlashPlayerPlugin_11_8_800_94.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash

\FlashPlayerPlugin_11_8_800_94.exe

==================== Registry (Whitelisted) ==================

MountPoints2: {e235ac7c-7580-11df-ab43-806e6f6e6963} - SIOP 6-

12.exe
HKLM-x32\...\Run: [AVG_UI] - C:\Program Files (x86)\AVG

\AVG2013\avgui.exe [4411440 2013-07-01] (AVG Technologies CZ,

s.r.o.)
HKU\Cameron\...\Run: [AVG-Secure-Search-Update_JUNE2013_TB] - C:

\Program Files (x86)\AVG Secure Search\AVG-Secure-Search-

Update_JUNE2013_TB.exe [1266712 2013-06-02] (AVG Secure Search)
HKU\Cameron\...\RunOnce: [spchecker] - "C:\Program Files

(x86)\AVG\AVG10\Notification\SPCheckerTE.exe" [x]

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

http://www.btvguide.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect

Cache = http://www.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

http://www.msn.com/?ocid=EIE9HP&PC=UP52
URLSearchHook: (No Name) - {327f75ed-061b-4339-8cc6-5dd45ad1396d}

-  No File
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-

E1416B8B2E3A} URL = http://www.bing.com/search?

FORM=WLETDF&PC=WLEM&q={searchTerms}&src=IE-SearchBox
SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL =

http://isearch.avg.com/search?cid={7CECD3AF-5805-4563-AFD7-

A69E709F3384}&mid=0462bdbd2686e6ff2ea61229b13397e1-

b9d813a388f68b94ef43008cab2feaf22f3c7b5a&lang=en&ds=AVG&pr=fr&d=20

12-09-27 16:24:28&v=15.2.0.5&pid=avg&sg=0&sap=dsp&q={searchTerms}
SearchScopes: HKCU - {A30C9813-46F6-4FC2-8C8A-4AEBA3B6C1AE} URL =

http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q=

{searchTerms}

&locale=&apn_ptnrs=TV&apn_dtid=OSJ000YYUS&apn_uid=38AB23E3-7044-

4A07-9C6B-75FF3C156CE1&apn_sauid=110ABBC4-4163-4E96-A066-

0EA08980613F
BHO: SteadyVideoBHO Class - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928}

- C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro

Devices)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-

5164760863C6} - C:\Program Files\Common Files\Microsoft Shared

\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Toolbar BHO - {074d3229-0a22-491b-b9dd-ff3171d75f25} -

C:\PROGRA~2\MARINE~2\bar\1.bin\57bar.dll (MindSpark)
BHO-x32: Search Assistant BHO - {0eeaa2c3-0cd7-4364-b82e-

f9257081c860} - C:\Program Files (x86)\MarineAquarium3Free_57\bar

\1.bin\57SrcAs.dll (MindSpark)
BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-

46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus

Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO-x32: SteadyVideoBHO Class - {6C680BAE-655C-4E3D-8FC4-

E6A520C3D928} - C:\Program Files (x86)\amd\SteadyVideo

\SteadyVideo.dll (Advanced Micro Devices)
BHO-x32: Ad-Aware Security Add-on - {6c97a91e-4524-4019-86af-

2aa2d567bf5c} - C:\Program Files (x86)\adawaretb\adawareDx.dll ()
BHO-x32: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-

D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll

(Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-

8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft

Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-

73684A933233} - C:\Program Files (x86)\AVG Secure Search

\15.5.0.2\AVG Secure Search_toolbar.dll (AVG Secure Search)
BHO-x32: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74

-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll

(Oracle Corporation)
Toolbar: HKLM-x32 - No Name - {CCC7A320-B3CA-4199-B1A6-

9F516DD69829} -  No File
Toolbar: HKLM-x32 - AVG Security Toolbar - {95B7759C-8C7F-4BF1-

B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search

\15.5.0.2\AVG Secure Search_toolbar.dll (AVG Secure Search)
Toolbar: HKLM-x32 - Ad-Aware Security Add-on - {6c97a91e-4524-

4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\adawaretb

\adawareDx.dll ()
Toolbar: HKLM-x32 - Marine Aquarium Lite - {07189b84-b33b-4a1e-

9b32-ad203c983c20} - C:\Program Files

(x86)\MarineAquarium3Free_57\bar\1.bin\57bar.dll (MindSpark)
Toolbar: HKCU - No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} -

 No File
Toolbar: HKCU - No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} -

 No File
DPF: HKLM {67DABFBF-D0AB-41FA-9C46-CC0F21721616}

http://download.divx.com/player/DivXBrowserPlugin.cab
DPF: HKLM-x32 {02BCC737-B171-4746-94C9-0D8A0B2C0089}

http://office.microsoft.com/_layouts/ClientBin/ieawsdc32.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} -  

No File
Handler-x32: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1}

-  No File
Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} -

C:\Program Files (x86)\Common Files\AVG Secure Search

\ViProtocolInstaller\15.5.0\ViProtocol.dll (AVG Secure Search)
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:

\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro

Devices)
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:

\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro

Devices)
Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} -

C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll

(Advanced Micro Devices)
Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} -

C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll

(Advanced Micro Devices)
Hosts: 127.0.0.1    localhost
Tcpip\Parameters: [DhcpNameServer] 209.18.47.61 209.18.47.62

FireFox:
========
FF ProfilePath: C:\Users\Dad\AppData\Roaming\Mozilla\Firefox

\Profiles\twcib4d7.default
FF user.js: detected! => C:\Users\Dad\AppData\Roaming\Mozilla

\Firefox\Profiles\twcib4d7.default\user.js
FF Keyword.URL: hxxp://safesearchr.lavasoft.com/?

source=3336ca5f&tbp=url&toolbarid=adawaretb&u=046CBA92B2E36DBCB1E0

4A50C5323B70&q=
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed

\Flash\NPSWF64_11_8_800_94.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program

Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files

\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft

Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows

\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows

\system32\Adobe\Director\np32dsw.dll No File
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files

(x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @avg.com/AVG SiteSafety

plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin - C:

\Program Files (x86)\Common Files\AVG Secure Search

\SiteSafetyInstaller\15.5.0\\npsitesafety.dll (AVG Technologies)
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 - C:

\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX,

LLC)
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:

\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX,

LLC.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files

(x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows

\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program

Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @MarineAquarium3Free_57.com/Plugin - C:\Program

Files (x86)\MarineAquarium3Free_57\bar\1.bin\NP57Stub.dll

(MindSpark)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program

Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll (

Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:

\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

(Microsoft Corporation)
FF Plugin-x32: @soe.sony.com/installer,version=1.0.3 - C:\Users

\Dad\AppData\Roaming\Sony Online Entertainment\npsoe.dll ()
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:

\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll

(Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:

\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll

(Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader

11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @hulu.com/Hulu Desktop - C:\Users\Dad\AppData

\Local\HuluDesktop\instances\0.9.14.1\nphdplg.dll (Hulu LLC)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users

\Dad\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll No

File
FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Program

Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin.dll

(Amazon.com, Inc.)
FF SearchPlugin: C:\Users\Dad\AppData\Roaming\Mozilla\Firefox

\Profiles\twcib4d7.default\searchplugins\askcom.xml
FF SearchPlugin: C:\Users\Dad\AppData\Roaming\Mozilla\Firefox

\Profiles\twcib4d7.default\searchplugins\bing-zugo.xml
FF SearchPlugin: C:\Users\Dad\AppData\Roaming\Mozilla\Firefox

\Profiles\twcib4d7.default\searchplugins\eq2-at-zam.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox

\searchplugins\adawaretb.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox

\searchplugins\avg-secure-search.xml
FF Extension: Marine Aquarium Lite - C:\Users\Dad\AppData\Roaming

\Mozilla\Firefox\Profiles\twcib4d7.default\Extensions

\57ffxtbr@MarineAquarium3Free_57.com
FF Extension: TelevisionFanatic - C:\Users\Dad\AppData\Roaming

\Mozilla\Firefox\Profiles\twcib4d7.default\Extensions

\64ffxtbr@TelevisionFanatic.com
FF Extension: Ad-Aware Security Add-on - C:\Users\Dad\AppData

\Roaming\Mozilla\Firefox\Profiles\twcib4d7.default\Extensions

\{87934c42-161d-45bc-8cef-ef18abe2a30c}
FF Extension: adblockpopups - C:\Users\Dad\AppData\Roaming

\Mozilla\Firefox\Profiles\twcib4d7.default\Extensions

\adblockpopups@jessehakanen.net.xpi
FF Extension: testpilot - C:\Users\Dad\AppData\Roaming\Mozilla

\Firefox\Profiles\twcib4d7.default\Extensions

\testpilot@labs.mozilla.com.xpi
FF Extension: Java Console - C:\Program Files (x86)\Mozilla

Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Program Files (x86)\Mozilla

Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Program Files (x86)\Mozilla

Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox

\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM-x32\...\Firefox\Extensions: [avg@toolbar] C:\ProgramData

\AVG Secure Search\FireFoxExt\15.5.0.2
FF Extension: AVG Security Toolbar - C:\ProgramData\AVG Secure

Search\FireFoxExt\15.5.0.2
FF HKLM-x32\...\Firefox\Extensions:

[64ffxtbr@TelevisionFanatic.com] C:\Program Files

(x86)\TelevisionFanatic\bar\1.bin
FF Extension: TelevisionFanatic - C:\Program Files

(x86)\TelevisionFanatic\bar\1.bin
FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-

ae97e717ed8b}] C:\Program Files (x86)\DivX\DivX Plus Web Player

\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 &lt;video&gt; - C:

\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF HKLM-x32\...\Firefox\Extensions:

[57ffxtbr@MarineAquarium3Free_57.com] C:\Program Files

(x86)\MarineAquarium3Free_57\bar\1.bin
FF Extension: Marine Aquarium Lite - C:\Program Files

(x86)\MarineAquarium3Free_57\bar\1.bin

==================== Services (Whitelisted) =================

S4 Ad-Aware Service; C:\Program Files (x86)\Ad-Aware Antivirus

\AdAwareService.exe [1236368 2012-12-07] (Lavasoft Limited)
S4 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE

\Fuel\Fuel.Service.exe [361984 2013-06-04] (Advanced Micro

Devices, Inc.)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe

[4939312 2013-07-04] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [283136

2013-07-23] (AVG Technologies CZ, s.r.o.)
S4 CLKMSVC10_9EC60124; C:\Program Files (x86)\CyberLink

\PowerDVD9\NavFilter\kmsvc.exe [240112 2010-11-18] (CyberLink)
S4 MarineAquarium3Free_57Service; C:\PROGRA~2\MARINE~2\bar\1.bin

\57barsvc.exe [42504 2013-08-21] (COMPANYVERS_NAME)
S4 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-

Malware\mbamscheduler.exe [398184 2012-12-14] (Malwarebytes

Corporation)
S4 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware

\mbamservice.exe [682344 2012-12-14] (Malwarebytes Corporation)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2012-08-01]

()
S4 RichVideo; C:\Program Files (x86)\CyberLink\Shared files

\RichVideo.exe [247152 2009-07-06] ()
S4 SBAMSvc; C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe

[3677000 2012-09-20] (GFI Software)
S4 vToolbarUpdater15.5.0; C:\Program Files (x86)\Common Files\AVG

Secure Search\vToolbarUpdater\15.5.0\ToolbarUpdater.exe [1643184

2013-08-17] (AVG Secure Search)

==================== Drivers (Whitelisted) ====================

R2 AODDriver4.01; C:\Program Files\ATI Technologies\ATI.ACE\Fuel

\amd64\AODDriver2.sys [57472 2012-04-09] (Advanced Micro Devices)
S2 AODDriver4.2; C:\Program Files\ATI Technologies\ATI.ACE\Fuel

\amd64\AODDriver2.sys [57472 2012-04-09] (Advanced Micro Devices)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys

[246072 2013-07-20] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [71480 2013

-07-20] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [206648

2013-07-20] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [311608 2013-

07-20] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [116536

2013-07-01] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [45880 2013

-07-10] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [240952 2013-

03-21] (AVG Technologies CZ, s.r.o.)
R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [45856 2013-08

-17] (AVG Technologies)
S3 AVMNgBasM780; C:\Windows\System32\DRIVERS\AVerBas.sys [72448

2009-06-11] (AVerMedia TECHNOLOGIES, Inc.)
S3 AVMNgCapM780; C:\Windows\System32\DRIVERS\AVerCap.sys [442368

2009-06-11] (AVerMedia TECHNOLOGIES, Inc.)
S3 AVMNgTunM780; C:\Windows\System32\DRIVERS\AVerTun.sys [240768

2009-06-11] (AVerMedia TECHNOLOGIES, Inc.)
S3 DrvSnSht; C:\Program Files (x86)\R-Drive Image\DrvSnSht64.sys

[132432 2010-06-01] (R-TT Inc.)
S3 DrvSnSht; C:\Program Files (x86)\R-Drive Image\DrvSnSht64.sys

[132432 2010-06-01] (R-TT Inc.)
S3 gdrv; C:\Windows\gdrv.sys [25640 2013-07-02] (Windows ®

Server 2003 DDK provider)
S3 gdrv; C:\Windows\gdrv.sys [25640 2013-07-02] (Windows ®

Server 2003 DDK provider)
R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [14456 2012-12-

09] (GFI Software)
S3 hitmanpro37; C:\Windows\system32\drivers\hitmanpro37.sys [32000

2013-08-13] ()
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [24176

2012-12-14] (Malwarebytes Corporation)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [24176

2012-12-14] (Malwarebytes Corporation)
S3 R-ImageDisk; C:\Program Files (x86)\R-Drive Image\R-

ImageDisk64.sys [181840 2013-01-15] (R-TT Inc.)
S3 R-ImageDisk; C:\Program Files (x86)\R-Drive Image\R-

ImageDisk64.sys [181840 2013-01-15] (R-TT Inc.)
R0 speedfan; C:\Windows\SysWow64\speedfan.sys [14104 2007-02-07]

(Windows ® Server 2003 DDK provider)
R0 speedfan; C:\Windows\SysWow64\speedfan.sys [14104 2007-02-07]

(Windows ® Server 2003 DDK provider)
R2 {B154377D-700F-42cc-9474-23858FBDF4BD}; C:\Program Files

(x86)\CyberLink\PowerDVD9\000.fcl [146928 2009-09-01] (CyberLink

Corp.)
R2 {B154377D-700F-42cc-9474-23858FBDF4BD}; C:\Program Files

(x86)\CyberLink\PowerDVD9\000.fcl [146928 2009-09-01] (CyberLink

Corp.)
S3 ALSysIO; No ImagePath
S0 Lbd; system32\DRIVERS\Lbd.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-08-22 22:35 - 2013-08-22 22:35 - 01576476 _____ (Farbar) C:

\Users\Dad\Downloads\FRST64.exe
2013-08-21 20:44 - 2013-08-21 20:44 - 00000000 ____D C:\Users\Dad

\AppData\Roaming\AVG2013
2013-08-21 20:43 - 2013-08-21 20:43 - 00000965 _____ C:\Users

\Public\Desktop\AVG 2013.lnk
2013-08-21 20:42 - 2013-08-21 20:43 - 00000000 ____D C:

\ProgramData\AVG2013
2013-08-21 20:42 - 2013-08-21 20:42 - 00000000 ___HD C:\$AVG
2013-08-21 20:28 - 2013-08-22 03:18 - 00000000 ____D C:\Users\Dad

\AppData\Local\Avg2013
2013-08-21 20:27 - 2013-08-21 20:27 - 04491784 _____ (AVG

Technologies) C:\Users\Dad\Downloads

\avg_free_stb_all_2013_3392_cnet.exe
2013-08-21 20:17 - 2013-08-21 20:17 - 00007597 _____ C:\Users\Dad

\AppData\Local\resmon.resmoncfg
2013-08-21 20:16 - 2013-08-21 20:16 - 00079200 _____ C:\Users\Dad

\AppData\Local\GDIPFONTCACHEV1.DAT
2013-08-21 19:49 - 2013-08-22 09:43 - 00000168 _____ C:\Windows

\setupact.log
2013-08-21 19:49 - 2013-08-21 19:49 - 00342840 _____ C:\Windows

\system32\FNTCACHE.DAT
2013-08-21 19:49 - 2013-08-21 19:49 - 00000000 _____ C:\Windows

\setuperr.log
2013-08-21 19:39 - 2013-08-22 09:47 - 00044760 _____ C:\Windows

\WindowsUpdate.log
2013-08-21 17:55 - 2013-08-21 18:04 - 00000000 ____D C:\Program

Files (x86)\R-Drive Image
2013-08-21 17:55 - 2013-08-21 17:55 - 00001062 _____ C:\Users\Dad

\Desktop\R-Drive Image.lnk
2013-08-21 17:55 - 2013-08-21 17:55 - 00000000 ____D C:\Users\Dad

\Documents\R-TT
2013-08-21 17:55 - 2013-08-21 17:55 - 00000000 ____D C:\Users\Dad

\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\R-Drive

Image
2013-08-21 17:53 - 2013-08-21 17:54 - 61115088 _____ (R-Tools

Technology Inc.) C:\Users\Dad\Downloads\RDriveImage5.exe
2013-08-21 14:51 - 2013-08-21 14:51 - 00000000 ____D C:\Users\Dad

\AppData\Roaming\MarineAquarium3Free_57
2013-08-21 13:42 - 2013-08-21 13:42 - 00000000 ____D C:\Users\Dad

\AppData\Roaming\Marine Aquarium Lite
2013-08-21 13:21 - 2013-08-21 13:21 - 00000931 _____ C:\Users\Dad

\Desktop\SereneScreen Marine Aquarium Lite.lnk
2013-08-21 13:21 - 2013-08-21 13:21 - 00000000 ____D C:\Users\Dad

\AppData\Local\MarineAquarium3Free_57
2013-08-21 13:21 - 2013-08-21 13:21 - 00000000 ____D C:\Program

Files (x86)\SereneScreen
2013-08-21 13:21 - 2013-08-21 13:21 - 00000000 ____D C:\Program

Files (x86)\MarineAquarium3Free_57
2013-08-21 13:21 - 2012-03-06 10:22 - 06037504 _____

(SereneScreen) C:\Windows\SysWOW64\MarineAquariumLite.scr
2013-08-21 13:21 - 2012-03-06 10:22 - 06037504 _____

(SereneScreen) C:\Windows\system32\MarineAquariumLite.scr
2013-08-20 03:40 - 2013-08-20 03:40 - 00028854 _____ C:\Users\Dad

\Desktop\cc_20130820_034027.reg
2013-08-20 00:06 - 2013-08-20 00:06 - 00000045 _____ C:\Users\Dad

\Desktop\defiler.txt
2013-08-18 01:26 - 2013-08-18 01:26 - 00000359 _____ C:\Users\Dad

\Recycle Bin - Shortcut.lnk
2013-08-17 00:05 - 2013-08-17 00:05 - 00688992 ____R (Swearware)

C:\Users\Dad\Downloads\dds.com
2013-08-16 21:14 - 2013-08-16 21:14 - 00000000 ____D C:\Program

Files (x86)\Mozilla Firefox
2013-08-15 02:23 - 2013-07-26 01:13 - 02241024 _____ (Microsoft

Corporation) C:\Windows\system32\wininet.dll
2013-08-15 02:23 - 2013-07-26 01:13 - 01365504 _____ (Microsoft

Corporation) C:\Windows\system32\urlmon.dll
2013-08-15 02:23 - 2013-07-26 01:13 - 00051712 _____ (Microsoft

Corporation) C:\Windows\system32\ie4uinit.exe
2013-08-15 02:23 - 2013-07-26 01:12 - 19239424 _____ (Microsoft

Corporation) C:\Windows\system32\mshtml.dll
2013-08-15 02:23 - 2013-07-26 01:12 - 15405056 _____ (Microsoft

Corporation) C:\Windows\system32\ieframe.dll
2013-08-15 02:23 - 2013-07-26 01:12 - 03958784 _____ (Microsoft

Corporation) C:\Windows\system32\jscript9.dll
2013-08-15 02:23 - 2013-07-26 01:12 - 02647040 _____ (Microsoft

Corporation) C:\Windows\system32\iertutil.dll
2013-08-15 02:23 - 2013-07-26 01:12 - 00855552 _____ (Microsoft

Corporation) C:\Windows\system32\jscript.dll
2013-08-15 02:23 - 2013-07-26 01:12 - 00603136 _____ (Microsoft

Corporation) C:\Windows\system32\msfeeds.dll
2013-08-15 02:23 - 2013-07-26 01:12 - 00526336 _____ (Microsoft

Corporation) C:\Windows\system32\ieui.dll
2013-08-15 02:23 - 2013-07-26 01:12 - 00136704 _____ (Microsoft

Corporation) C:\Windows\system32\iesysprep.dll
2013-08-15 02:23 - 2013-07-26 01:12 - 00067072 _____ (Microsoft

Corporation) C:\Windows\system32\iesetup.dll
2013-08-15 02:23 - 2013-07-26 01:12 - 00053760 _____ (Microsoft

Corporation) C:\Windows\system32\jsproxy.dll
2013-08-15 02:23 - 2013-07-26 01:12 - 00039936 _____ (Microsoft

Corporation) C:\Windows\system32\iernonce.dll
2013-08-15 02:23 - 2013-07-25 23:35 - 02706432 _____ (Microsoft

Corporation) C:\Windows\system32\mshtml.tlb
2013-08-15 02:23 - 2013-07-25 23:13 - 01767936 _____ (Microsoft

Corporation) C:\Windows\SysWOW64\wininet.dll
2013-08-15 02:23 - 2013-07-25 23:13 - 01141248 _____ (Microsoft

Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-08-15 02:23 - 2013-07-25 23:12 - 14329344 _____ (Microsoft

Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-08-15 02:23 - 2013-07-25 23:12 - 02877440 _____ (Microsoft

Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-08-15 02:23 - 2013-07-25 23:12 - 02048512 _____ (Microsoft

Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-08-15 02:23 - 2013-07-25 23:12 - 00690688 _____ (Microsoft

Corporation) C:\Windows\SysWOW64\jscript.dll
2013-08-15 02:23 - 2013-07-25 23:12 - 00493056 _____ (Microsoft

Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-08-15 02:23 - 2013-07-25 23:12 - 00391168 _____ (Microsoft

Corporation) C:\Windows\SysWOW64\ieui.dll
2013-08-15 02:23 - 2013-07-25 23:12 - 00109056 _____ (Microsoft

Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-08-15 02:23 - 2013-07-25 23:12 - 00061440 _____ (Microsoft

Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-08-15 02:23 - 2013-07-25 23:12 - 00039936 _____ (Microsoft

Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-08-15 02:23 - 2013-07-25 23:11 - 13761024 _____ (Microsoft

Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-08-15 02:23 - 2013-07-25 23:11 - 00033280 _____ (Microsoft

Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-08-15 02:23 - 2013-07-25 22:49 - 02706432 _____ (Microsoft

Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-08-15 02:23 - 2013-07-25 22:39 - 00089600 _____ (Microsoft

Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-08-15 02:23 - 2013-07-25 21:59 - 00071680 _____ (Microsoft

Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-08-15 02:17 - 2013-08-15 02:19 - 00000000 ____D C:\Windows

\system32\MRT
2013-08-15 00:25 - 2013-07-25 05:25 - 01888768 _____ (Microsoft

Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-08-15 00:25 - 2013-07-25 04:57 - 01620992 _____ (Microsoft

Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-08-15 00:25 - 2013-07-18 21:58 - 00002048 _____ (Microsoft

Corporation) C:\Windows\system32\tzres.dll
2013-08-15 00:25 - 2013-07-18 21:41 - 00002048 _____ (Microsoft

Corporation) C:\Windows\SysWOW64\tzres.dll
2013-08-15 00:25 - 2013-07-09 01:52 - 00224256 _____ (Microsoft

Corporation) C:\Windows\system32\wintrust.dll
2013-08-15 00:25 - 2013-07-09 01:51 - 01217024 _____ (Microsoft

Corporation) C:\Windows\system32\rpcrt4.dll
2013-08-15 00:25 - 2013-07-09 01:46 - 01472512 _____ (Microsoft

Corporation) C:\Windows\system32\crypt32.dll
2013-08-15 00:25 - 2013-07-09 01:46 - 00184320 _____ (Microsoft

Corporation) C:\Windows\system32\cryptsvc.dll
2013-08-15 00:25 - 2013-07-09 01:46 - 00139776 _____ (Microsoft

Corporation) C:\Windows\system32\cryptnet.dll
2013-08-15 00:25 - 2013-07-09 00:52 - 00663552 _____ (Microsoft

Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2013-08-15 00:25 - 2013-07-09 00:52 - 00175104 _____ (Microsoft

Corporation) C:\Windows\SysWOW64\wintrust.dll
2013-08-15 00:25 - 2013-07-09 00:46 - 01166848 _____ (Microsoft

Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-08-15 00:25 - 2013-07-09 00:46 - 00140288 _____ (Microsoft

Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-08-15 00:25 - 2013-07-09 00:46 - 00103936 _____ (Microsoft

Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-08-15 00:24 - 2013-07-09 02:03 - 05550528 _____ (Microsoft

Corporation) C:\Windows\system32\ntoskrnl.exe
2013-08-15 00:24 - 2013-07-09 01:54 - 01732032 _____ (Microsoft

Corporation) C:\Windows\system32\ntdll.dll
2013-08-15 00:24 - 2013-07-09 01:53 - 00243712 _____ (Microsoft

Corporation) C:\Windows\system32\wow64.dll
2013-08-15 00:24 - 2013-07-09 01:03 - 03968960 _____ (Microsoft

Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-08-15 00:24 - 2013-07-09 01:03 - 03913664 _____ (Microsoft

Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-08-15 00:24 - 2013-07-09 00:53 - 01292192 _____ (Microsoft

Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-08-15 00:24 - 2013-07-09 00:52 - 00005120 _____ (Microsoft

Corporation) C:\Windows\SysWOW64\wow32.dll
2013-08-15 00:24 - 2013-07-08 22:49 - 00025600 _____ (Microsoft

Corporation) C:\Windows\SysWOW64\setup16.exe
2013-08-15 00:24 - 2013-07-08 22:49 - 00014336 _____ (Microsoft

Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-08-15 00:24 - 2013-07-08 22:49 - 00007680 _____ (Microsoft

Corporation) C:\Windows\SysWOW64\instnm.exe
2013-08-15 00:24 - 2013-07-08 22:49 - 00002048 _____ (Microsoft

Corporation) C:\Windows\SysWOW64\user.exe
2013-08-15 00:24 - 2013-07-06 02:03 - 01910208 _____ (Microsoft

Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-08-15 00:24 - 2013-06-15 00:32 - 00039936 _____ (Microsoft

Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2013-08-14 20:15 - 2013-08-14 20:15 - 00000000 __SHD C:\Users\Dad

\AppData\Roaming\wyUpdate AU
2013-08-13 23:43 - 2013-08-13 23:43 - 01110476 _____ C:\Users\Dad

\Downloads\7z920.exe
2013-08-13 23:38 - 2013-08-13 23:38 - 00628779 _____ C:\Users\Dad

\Downloads\GrantPerms64.zip
2013-08-13 23:38 - 2013-08-13 23:38 - 00000000 ____D C:\Users\Dad

\Downloads\GrantPerms64
2013-08-13 23:35 - 2013-08-13 23:35 - 00000000 ____D C:\Users\Dad

\Downloads\testdisk-6.13.win
2013-08-13 23:34 - 2013-08-13 23:34 - 03432173 _____ C:\Users\Dad

\Downloads\testdisk-6.13.win.zip
2013-08-13 23:30 - 2013-08-13 23:30 - 01153912 _____ (Emsi

Software GmbH) C:\Users\Dad\Downloads\BlitzBlank.exe
2013-08-13 23:28 - 2013-08-13 23:28 - 00000000 ____D C:\Users\Dad

\AppData\Roaming\Mael
2013-08-13 23:22 - 2013-08-13 23:22 - 00000881 _____ C:\Users

\Public\Desktop\HxD.lnk
2013-08-13 23:22 - 2013-08-13 23:22 - 00000000 ____D C:\Program

Files (x86)\HxD
2013-08-13 23:21 - 2013-08-13 23:21 - 00872029 _____ C:\Users\Dad

\Downloads\HxDSetupEN.zip
2013-08-13 23:15 - 2013-08-13 23:15 - 00001784 _____ C:\sc-

cleaner.txt
2013-08-13 23:13 - 2013-08-13 23:13 - 00406144 _____ (Bleeping

Computer, LLC) C:\Users\Dad\Downloads\sc-cleaner.exe
2013-08-13 23:12 - 2013-08-13 23:12 - 00386464 _____ (Bleeping

Computer, LLC) C:\Users\Dad\Downloads\show-hidden.exe
2013-08-13 21:32 - 2013-08-13 21:32 - 00000000 __SHD C:\found.001
2013-08-13 20:52 - 2013-08-13 20:52 - 00000000 ____D C:\Users\Dad

\Downloads\gmer
2013-08-13 20:51 - 2013-08-13 20:51 - 00294216 _____ C:\Users\Dad

\Downloads\gmer.zip
2013-08-13 19:17 - 2013-08-21 17:58 - 00000000 ____D C:\Windows

\System32\Tasks\Doctor Web
2013-08-13 19:17 - 2013-08-13 19:17 - 00000000 ____D C:\Program

Files\Common Files\Doctor Web
2013-08-13 18:57 - 2011-07-16 22:21 - 00302592 _____ C:\Users\Dad

\Desktop\gmer.exe
2013-08-13 18:55 - 2013-08-13 19:03 - 178138344 _____ (Doctor Web,

Ltd.) C:\Users\Dad\Downloads\drweb-800-win.exe
2013-08-13 18:53 - 2013-08-13 19:17 - 00000000 ____D C:

\ProgramData\Doctor Web
2013-08-13 18:39 - 2013-08-17 00:40 - 00000000 ____D C:\Users\Dad

\Doctor Web
2013-08-13 18:14 - 2013-08-13 18:14 - 00379531 _____ C:\Users\Dad

\Downloads\rannohdecryptor.zip
2013-08-13 18:13 - 2013-08-18 01:25 - 00000000 ____D C:\Users\Dad

\Desktop\Scans
2013-08-13 18:12 - 2013-08-13 18:12 - 00537684 _____ C:\Users\Dad

\Downloads\rectordecryptor.zip
2013-08-13 18:08 - 2013-08-13 18:09 - 00547136 _____ C:\Users\Dad

\Downloads\xoristdecryptor.zip
2013-08-13 17:49 - 2013-08-13 17:49 - 00032000 _____ C:\Windows

\system32\Drivers\hitmanpro37.sys
2013-08-13 17:45 - 2013-08-13 17:45 - 00001246 _____ C:\Windows

\system32\.crusader
2013-08-13 17:39 - 2013-08-13 17:45 - 00000000 ____D C:

\ProgramData\HitmanPro
2013-08-13 17:23 - 2013-08-22 13:05 - 00006816 ____H C:\Windows

\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289

-439d-8115-601632D005A0
2013-08-13 17:23 - 2013-08-22 13:05 - 00006816 ____H C:\Windows

\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289

-439d-8115-601632D005A0
2013-08-13 17:23 - 2013-08-13 17:23 - 00000552 _____ C:\Windows

\system32\spsys.log
2013-08-13 16:29 - 2013-08-13 16:29 - 00000000 ____D C:\.Trash-999
2013-08-13 15:55 - 2013-08-13 15:55 - 00000000 ____D C:\Users\Dad

\Desktop\rkill
2013-08-13 15:47 - 2013-08-13 15:53 - 00000000 ____D C:\Users\Dad

\Desktop\RK_Quarantine
2013-08-13 15:41 - 2013-08-13 15:41 - 00000839 _____ C:\Users

\Public\Desktop\Speccy.lnk
2013-08-13 15:41 - 2013-08-13 15:41 - 00000000 ____D C:\Program

Files\Speccy
2013-08-12 16:15 - 2013-08-12 16:15 - 00089364 _____ C:\Users\Dad

\Desktop\cc_20130812_161514.reg
2013-08-11 15:59 - 2013-08-17 00:06 - 00025106 _____ C:\Users\Dad

\Desktop\dds.txt
2013-08-11 15:59 - 2013-08-17 00:06 - 00019954 _____ C:\Users\Dad

\Desktop\attach.txt
2013-08-10 22:19 - 2013-08-10 23:41 - 00000000 ____D C:\Users\Dad

\AppData\Local\The Witcher
2013-08-10 22:19 - 2013-08-10 23:12 - 00000000 ____D C:\Users\Dad

\Documents\The Witcher
2013-08-07 19:08 - 2013-08-07 19:20 - 00000000 ____D C:

\ProgramData\SecTaskMan
2013-08-05 23:56 - 2013-08-06 00:06 - 00000000 ____D C:\Program

Files (x86)\The Witcher Enhanced Edition
2013-08-05 23:56 - 2013-08-06 00:04 - 00000000 ____D C:\Users

\Public\Documents\The Witcher
2013-07-30 08:29 - 2013-07-30 08:29 - 00002212 _____ C:\Users

\Public\Desktop\Google Earth.lnk
2013-07-29 15:26 - 2013-07-29 15:27 - 00000000 ____D C:\recovered

crap
2013-07-29 15:01 - 2013-07-29 15:01 - 00000000 ____D C:\Users\Dad

\AppData\Local\Wondershare
2013-07-29 15:01 - 2013-07-29 15:01 - 00000000 ____D C:\Program

Files (x86)\Wondershare
2013-07-23 19:42 - 2013-07-23 19:42 - 00059471 _____ C:\Users\Dad

\Downloads\DetrimentCallMacro.cs
2013-07-23 19:41 - 2013-07-23 19:41 - 00059471 ____R C:\Users\Dad

\Desktop\DetrimentCallMacro.cs

==================== One Month Modified Files and Folders =======

2013-08-22 22:35 - 2013-08-22 22:35 - 01576476 _____ (Farbar) C:

\Users\Dad\Downloads\FRST64.exe
2013-08-22 22:32 - 2012-12-30 21:01 - 00000000 ____D C:\Users\Dad

\AppData\Roaming\Advanced Combat Tracker
2013-08-22 22:28 - 2010-07-02 17:07 - 00000892 _____ C:\Windows

\Tasks\GoogleUpdateTaskMachineUA.job
2013-08-22 21:46 - 2012-04-02 10:42 - 00000830 _____ C:\Windows

\Tasks\Adobe Flash Player Updater.job
2013-08-22 18:50 - 2010-10-13 15:39 - 00000000 ____D C:

\ProgramData\MFAData
2013-08-22 18:37 - 2013-08-21 19:39 - 00044760 _____ C:\Windows

\WindowsUpdate.log
2013-08-22 17:28 - 2010-07-02 17:07 - 00000888 _____ C:\Windows

\Tasks\GoogleUpdateTaskMachineCore.job
2013-08-22 13:29 - 2010-02-13 16:08 - 00003906 _____ C:\Windows

\System32\Tasks\User_Feed_Synchronization-{4BDA6678-DDD8-49F1-

8CD5-5304E4058D66}
2013-08-22 13:05 - 2013-08-13 17:23 - 00006816 ____H C:\Windows

\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289

-439d-8115-601632D005A0
2013-08-22 13:05 - 2013-08-13 17:23 - 00006816 ____H C:\Windows

\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289

-439d-8115-601632D005A0
2013-08-22 09:43 - 2013-08-21 19:49 - 00000168 _____ C:\Windows

\setupact.log
2013-08-22 09:43 - 2009-07-14 01:08 - 00000006 ____H C:\Windows

\Tasks\SA.DAT
2013-08-22 03:18 - 2013-08-21 20:28 - 00000000 ____D C:\Users\Dad

\AppData\Local\Avg2013
2013-08-21 23:30 - 2013-05-22 20:20 - 00000000 ____D C:\Users\Dad

\AppData\Roaming\Mumble
2013-08-21 21:36 - 2013-01-07 20:42 - 00000000 ____D C:\Program

Files (x86)\Raid Hub Client
2013-08-21 20:44 - 2013-08-21 20:44 - 00000000 ____D C:\Users\Dad

\AppData\Roaming\AVG2013
2013-08-21 20:43 - 2013-08-21 20:43 - 00000965 _____ C:\Users

\Public\Desktop\AVG 2013.lnk
2013-08-21 20:43 - 2013-08-21 20:42 - 00000000 ____D C:

\ProgramData\AVG2013
2013-08-21 20:42 - 2013-08-21 20:42 - 00000000 ___HD C:\$AVG
2013-08-21 20:27 - 2013-08-21 20:27 - 04491784 _____ (AVG

Technologies) C:\Users\Dad\Downloads

\avg_free_stb_all_2013_3392_cnet.exe
2013-08-21 20:23 - 2013-01-07 20:42 - 00000000 ___SD C:\Users\Dad

\wc
2013-08-21 20:17 - 2013-08-21 20:17 - 00007597 _____ C:\Users\Dad

\AppData\Local\resmon.resmoncfg
2013-08-21 20:16 - 2013-08-21 20:16 - 00079200 _____ C:\Users\Dad

\AppData\Local\GDIPFONTCACHEV1.DAT
2013-08-21 19:54 - 2010-02-16 21:12 - 00000000 ____D C:\Users\Dad

\AppData\Roaming\ProfitUI Reborn Updater
2013-08-21 19:49 - 2013-08-21 19:49 - 00342840 _____ C:\Windows

\system32\FNTCACHE.DAT
2013-08-21 19:49 - 2013-08-21 19:49 - 00000000 _____ C:\Windows

\setuperr.log
2013-08-21 19:36 - 2009-07-14 01:08 - 00032576 _____ C:\Windows

\Tasks\SCHEDLGU.TXT
2013-08-21 18:04 - 2013-08-21 17:55 - 00000000 ____D C:\Program

Files (x86)\R-Drive Image
2013-08-21 17:58 - 2013-08-13 19:17 - 00000000 ____D C:\Windows

\System32\Tasks\Doctor Web
2013-08-21 17:55 - 2013-08-21 17:55 - 00001062 _____ C:\Users\Dad

\Desktop\R-Drive Image.lnk
2013-08-21 17:55 - 2013-08-21 17:55 - 00000000 ____D C:\Users\Dad

\Documents\R-TT
2013-08-21 17:55 - 2013-08-21 17:55 - 00000000 ____D C:\Users\Dad

\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\R-Drive

Image
2013-08-21 17:54 - 2013-08-21 17:53 - 61115088 _____ (R-Tools

Technology Inc.) C:\Users\Dad\Downloads\RDriveImage5.exe
2013-08-21 14:51 - 2013-08-21 14:51 - 00000000 ____D C:\Users\Dad

\AppData\Roaming\MarineAquarium3Free_57
2013-08-21 13:42 - 2013-08-21 13:42 - 00000000 ____D C:\Users\Dad

\AppData\Roaming\Marine Aquarium Lite
2013-08-21 13:21 - 2013-08-21 13:21 - 00000931 _____ C:\Users\Dad

\Desktop\SereneScreen Marine Aquarium Lite.lnk
2013-08-21 13:21 - 2013-08-21 13:21 - 00000000 ____D C:\Users\Dad

\AppData\Local\MarineAquarium3Free_57
2013-08-21 13:21 - 2013-08-21 13:21 - 00000000 ____D C:\Program

Files (x86)\SereneScreen
2013-08-21 13:21 - 2013-08-21 13:21 - 00000000 ____D C:\Program

Files (x86)\MarineAquarium3Free_57
2013-08-21 11:46 - 2012-04-02 10:42 - 00692104 _____ (Adobe

Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-08-21 11:46 - 2012-04-02 10:42 - 00003768 _____ C:\Windows

\System32\Tasks\Adobe Flash Player Updater
2013-08-21 11:46 - 2011-05-21 09:28 - 00071048 _____ (Adobe

Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-08-20 03:40 - 2013-08-20 03:40 - 00028854 _____ C:\Users\Dad

\Desktop\cc_20130820_034027.reg
2013-08-20 00:06 - 2013-08-20 00:06 - 00000045 _____ C:\Users\Dad

\Desktop\defiler.txt
2013-08-18 12:00 - 2012-07-19 09:46 - 00001868 _____ C:\Users

\Public\Desktop\Ad-Aware Antivirus.lnk
2013-08-18 10:11 - 2012-04-25 18:48 - 00000000 ____D C:\Program

Files (x86)\Mozilla Maintenance Service
2013-08-18 01:31 - 2010-11-16 17:32 - 00000000 ____D C:\PERRLA
2013-08-18 01:29 - 2012-02-26 13:59 - 00000000 ____D C:\Users\Dad

\Documents\Student teach 1
2013-08-18 01:26 - 2013-08-18 01:26 - 00000359 _____ C:\Users\Dad

\Recycle Bin - Shortcut.lnk
2013-08-18 01:26 - 2010-02-13 15:47 - 00000000 ____D C:\Users\Dad
2013-08-18 01:25 - 2013-08-13 18:13 - 00000000 ____D C:\Users\Dad

\Desktop\Scans
2013-08-17 11:34 - 2009-07-13 23:20 - 00000000 ____D C:\Windows

\rescache
2013-08-17 10:02 - 2012-09-27 16:24 - 00000000 ____D C:\Program

Files (x86)\AVG Secure Search
2013-08-17 10:01 - 2013-05-21 14:49 - 00003715 _____ C:\Program

Files (x86)\Mozilla Firefoxavg-secure-search.xml
2013-08-17 10:01 - 2012-09-27 16:24 - 00045856 _____ (AVG

Technologies) C:\Windows\system32\Drivers\avgtpx64.sys
2013-08-17 00:40 - 2013-08-13 18:39 - 00000000 ____D C:\Users\Dad

\Doctor Web
2013-08-17 00:06 - 2013-08-11 15:59 - 00025106 _____ C:\Users\Dad

\Desktop\dds.txt
2013-08-17 00:06 - 2013-08-11 15:59 - 00019954 _____ C:\Users\Dad

\Desktop\attach.txt
2013-08-17 00:05 - 2013-08-17 00:05 - 00688992 ____R (Swearware)

C:\Users\Dad\Downloads\dds.com
2013-08-16 21:14 - 2013-08-16 21:14 - 00000000 ____D C:\Program

Files (x86)\Mozilla Firefox
2013-08-15 18:38 - 2010-02-13 18:25 - 00000000 ____D C:\Windows

\Panther
2013-08-15 02:21 - 2009-07-14 01:13 - 00793184 _____ C:\Windows

\system32\PerfStringBackup.INI
2013-08-15 02:19 - 2013-08-15 02:17 - 00000000 ____D C:\Windows

\system32\MRT
2013-08-15 02:19 - 2010-02-13 17:23 - 00000000 ____D C:

\ProgramData\Microsoft Help
2013-08-15 02:17 - 2010-02-13 16:46 - 78161360 _____ (Microsoft

Corporation) C:\Windows\system32\MRT.exe
2013-08-14 20:15 - 2013-08-14 20:15 - 00000000 __SHD C:\Users\Dad

\AppData\Roaming\wyUpdate AU
2013-08-13 23:45 - 2009-07-13 23:20 - 00000000 ____D C:\Windows

\system32\NDF
2013-08-13 23:43 - 2013-08-13 23:43 - 01110476 _____ C:\Users\Dad

\Downloads\7z920.exe
2013-08-13 23:43 - 2012-12-01 18:50 - 00000000 ____D C:\Program

Files (x86)\7-Zip
2013-08-13 23:38 - 2013-08-13 23:38 - 00628779 _____ C:\Users\Dad

\Downloads\GrantPerms64.zip
2013-08-13 23:38 - 2013-08-13 23:38 - 00000000 ____D C:\Users\Dad

\Downloads\GrantPerms64
2013-08-13 23:35 - 2013-08-13 23:35 - 00000000 ____D C:\Users\Dad

\Downloads\testdisk-6.13.win
2013-08-13 23:34 - 2013-08-13 23:34 - 03432173 _____ C:\Users\Dad

\Downloads\testdisk-6.13.win.zip
2013-08-13 23:30 - 2013-08-13 23:30 - 01153912 _____ (Emsi

Software GmbH) C:\Users\Dad\Downloads\BlitzBlank.exe
2013-08-13 23:28 - 2013-08-13 23:28 - 00000000 ____D C:\Users\Dad

\AppData\Roaming\Mael
2013-08-13 23:22 - 2013-08-13 23:22 - 00000881 _____ C:\Users

\Public\Desktop\HxD.lnk
2013-08-13 23:22 - 2013-08-13 23:22 - 00000000 ____D C:\Program

Files (x86)\HxD
2013-08-13 23:21 - 2013-08-13 23:21 - 00872029 _____ C:\Users\Dad

\Downloads\HxDSetupEN.zip
2013-08-13 23:15 - 2013-08-13 23:15 - 00001784 _____ C:\sc-

cleaner.txt
2013-08-13 23:13 - 2013-08-13 23:13 - 00406144 _____ (Bleeping

Computer, LLC) C:\Users\Dad\Downloads\sc-cleaner.exe
2013-08-13 23:12 - 2013-08-13 23:12 - 00386464 _____ (Bleeping

Computer, LLC) C:\Users\Dad\Downloads\show-hidden.exe
2013-08-13 21:32 - 2013-08-13 21:32 - 00000000 __SHD C:\found.001
2013-08-13 20:52 - 2013-08-13 20:52 - 00000000 ____D C:\Users\Dad

\Downloads\gmer
2013-08-13 20:51 - 2013-08-13 20:51 - 00294216 _____ C:\Users\Dad

\Downloads\gmer.zip
2013-08-13 19:17 - 2013-08-13 19:17 - 00000000 ____D C:\Program

Files\Common Files\Doctor Web
2013-08-13 19:17 - 2013-08-13 18:53 - 00000000 ____D C:

\ProgramData\Doctor Web
2013-08-13 19:03 - 2013-08-13 18:55 - 178138344 _____ (Doctor Web,

Ltd.) C:\Users\Dad\Downloads\drweb-800-win.exe
2013-08-13 18:51 - 2012-09-20 15:16 - 00000000 ____D C:\Users\Dad

\Documents\GCU TESOL
2013-08-13 18:14 - 2013-08-13 18:14 - 00379531 _____ C:\Users\Dad

\Downloads\rannohdecryptor.zip
2013-08-13 18:12 - 2013-08-13 18:12 - 00537684 _____ C:\Users\Dad

\Downloads\rectordecryptor.zip
2013-08-13 18:09 - 2013-08-13 18:08 - 00547136 _____ C:\Users\Dad

\Downloads\xoristdecryptor.zip
2013-08-13 17:49 - 2013-08-13 17:49 - 00032000 _____ C:\Windows

\system32\Drivers\hitmanpro37.sys
2013-08-13 17:45 - 2013-08-13 17:45 - 00001246 _____ C:\Windows

\system32\.crusader
2013-08-13 17:45 - 2013-08-13 17:39 - 00000000 ____D C:

\ProgramData\HitmanPro
2013-08-13 17:23 - 2013-08-13 17:23 - 00000552 _____ C:\Windows

\system32\spsys.log
2013-08-13 16:29 - 2013-08-13 16:29 - 00000000 ____D C:\.Trash-999
2013-08-13 15:55 - 2013-08-13 15:55 - 00000000 ____D C:\Users\Dad

\Desktop\rkill
2013-08-13 15:53 - 2013-08-13 15:47 - 00000000 ____D C:\Users\Dad

\Desktop\RK_Quarantine
2013-08-13 15:41 - 2013-08-13 15:41 - 00000839 _____ C:\Users

\Public\Desktop\Speccy.lnk
2013-08-13 15:41 - 2013-08-13 15:41 - 00000000 ____D C:\Program

Files\Speccy
2013-08-12 16:15 - 2013-08-12 16:15 - 00089364 _____ C:\Users\Dad

\Desktop\cc_20130812_161514.reg
2013-08-12 16:13 - 2011-01-02 04:16 - 00001017 _____ C:\Users

\Public\Desktop\CCleaner.lnk
2013-08-12 16:13 - 2010-02-13 16:24 - 00000000 ____D C:\Program

Files (x86)\CCleaner
2013-08-10 23:41 - 2013-08-10 22:19 - 00000000 ____D C:\Users\Dad

\AppData\Local\The Witcher
2013-08-10 23:12 - 2013-08-10 22:19 - 00000000 ____D C:\Users\Dad

\Documents\The Witcher
2013-08-07 19:20 - 2013-08-07 19:08 - 00000000 ____D C:

\ProgramData\SecTaskMan
2013-08-07 10:30 - 2010-11-16 17:38 - 00000000 ____D C:\Users\Dad

\Documents\My PERRLA Papers
2013-08-06 09:55 - 2010-02-13 16:24 - 00000000 ____D C:\Program

Files (x86)\Steam
2013-08-06 00:06 - 2013-08-05 23:56 - 00000000 ____D C:\Program

Files (x86)\The Witcher Enhanced Edition
2013-08-06 00:04 - 2013-08-05 23:56 - 00000000 ____D C:\Users

\Public\Documents\The Witcher
2013-08-05 23:56 - 2010-02-13 15:57 - 00000000 ____D C:\Program

Files (x86)\InstallShield Installation Information
2013-08-05 21:53 - 2013-07-02 23:07 - 00000000 ____D C:\Users\Dad

\AppData\Roaming\Origin
2013-08-05 21:53 - 2013-07-02 23:07 - 00000000 ____D C:\Users\Dad

\AppData\Local\Origin
2013-08-05 21:50 - 2013-07-02 23:05 - 00000000 ____D C:\Program

Files (x86)\Origin
2013-07-30 08:29 - 2013-07-30 08:29 - 00002212 _____ C:\Users

\Public\Desktop\Google Earth.lnk
2013-07-29 16:28 - 2012-05-22 17:17 - 00000000 ____D C:\Program

Files (x86)\Ad-Aware Antivirus
2013-07-29 16:28 - 2012-04-20 19:27 - 00000000 ____D C:\Users\Dad

\AppData\Local\EQ2MAP_Updater
2013-07-29 16:28 - 2011-11-28 11:56 - 00000000 ____D C:

\ProgramData\AVG Secure Search
2013-07-29 16:28 - 2011-04-20 13:34 - 00000000 ____D C:\Users

\Guest
2013-07-29 16:28 - 2010-06-17 20:25 - 00000000 ____D C:\Users\Dad

\AppData\Local\Progvo_Software
2013-07-29 16:28 - 2010-03-21 22:39 - 00000000 ____D C:\Users\Dad

\AppData\Roaming\Ventrilo
2013-07-29 16:28 - 2010-03-05 23:16 - 00000000 ____D C:\Users

\Cameron
2013-07-29 16:28 - 2010-02-13 16:57 - 00000000 __RHD C:\MSOCache
2013-07-29 16:28 - 2010-02-13 16:25 - 00000000 ____D C:\Program

Files (x86)\Google
2013-07-29 16:28 - 2009-07-13 23:20 - 00000000 ____D C:\Windows

\registration
2013-07-29 16:28 - 2009-07-13 23:20 - 00000000 ____D C:\Windows

\AppCompat
2013-07-29 15:27 - 2013-07-29 15:26 - 00000000 ____D C:\recovered

crap
2013-07-29 15:01 - 2013-07-29 15:01 - 00000000 ____D C:\Users\Dad

\AppData\Local\Wondershare
2013-07-29 15:01 - 2013-07-29 15:01 - 00000000 ____D C:\Program

Files (x86)\Wondershare
2013-07-26 01:13 - 2013-08-15 02:23 - 02241024 _____ (Microsoft

Corporation) C:\Windows\system32\wininet.dll
2013-07-26 01:13 - 2013-08-15 02:23 - 01365504 _____ (Microsoft

Corporation) C:\Windows\system32\urlmon.dll
2013-07-26 01:13 - 2013-08-15 02:23 - 00051712 _____ (Microsoft

Corporation) C:\Windows\system32\ie4uinit.exe
2013-07-26 01:12 - 2013-08-15 02:23 - 19239424 _____ (Microsoft

Corporation) C:\Windows\system32\mshtml.dll
2013-07-26 01:12 - 2013-08-15 02:23 - 15405056 _____ (Microsoft

Corporation) C:\Windows\system32\ieframe.dll
2013-07-26 01:12 - 2013-08-15 02:23 - 03958784 _____ (Microsoft

Corporation) C:\Windows\system32\jscript9.dll
2013-07-26 01:12 - 2013-08-15 02:23 - 02647040 _____ (Microsoft

Corporation) C:\Windows\system32\iertutil.dll
2013-07-26 01:12 - 2013-08-15 02:23 - 00855552 _____ (Microsoft

Corporation) C:\Windows\system32\jscript.dll
2013-07-26 01:12 - 2013-08-15 02:23 - 00603136 _____ (Microsoft

Corporation) C:\Windows\system32\msfeeds.dll
2013-07-26 01:12 - 2013-08-15 02:23 - 00526336 _____ (Microsoft

Corporation) C:\Windows\system32\ieui.dll
2013-07-26 01:12 - 2013-08-15 02:23 - 00136704 _____ (Microsoft

Corporation) C:\Windows\system32\iesysprep.dll
2013-07-26 01:12 - 2013-08-15 02:23 - 00067072 _____ (Microsoft

Corporation) C:\Windows\system32\iesetup.dll
2013-07-26 01:12 - 2013-08-15 02:23 - 00053760 _____ (Microsoft

Corporation) C:\Windows\system32\jsproxy.dll
2013-07-26 01:12 - 2013-08-15 02:23 - 00039936 _____ (Microsoft

Corporation) C:\Windows\system32\iernonce.dll
2013-07-25 23:35 - 2013-08-15 02:23 - 02706432 _____ (Microsoft

Corporation) C:\Windows\system32\mshtml.tlb
2013-07-25 23:13 - 2013-08-15 02:23 - 01767936 _____ (Microsoft

Corporation) C:\Windows\SysWOW64\wininet.dll
2013-07-25 23:13 - 2013-08-15 02:23 - 01141248 _____ (Microsoft

Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-07-25 23:12 - 2013-08-15 02:23 - 14329344 _____ (Microsoft

Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-07-25 23:12 - 2013-08-15 02:23 - 02877440 _____ (Microsoft

Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-07-25 23:12 - 2013-08-15 02:23 - 02048512 _____ (Microsoft

Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-07-25 23:12 - 2013-08-15 02:23 - 00690688 _____ (Microsoft

Corporation) C:\Windows\SysWOW64\jscript.dll
2013-07-25 23:12 - 2013-08-15 02:23 - 00493056 _____ (Microsoft

Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-07-25 23:12 - 2013-08-15 02:23 - 00391168 _____ (Microsoft

Corporation) C:\Windows\SysWOW64\ieui.dll
2013-07-25 23:12 - 2013-08-15 02:23 - 00109056 _____ (Microsoft

Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-07-25 23:12 - 2013-08-15 02:23 - 00061440 _____ (Microsoft

Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-07-25 23:12 - 2013-08-15 02:23 - 00039936 _____ (Microsoft

Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-07-25 23:11 - 2013-08-15 02:23 - 13761024 _____ (Microsoft

Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-07-25 23:11 - 2013-08-15 02:23 - 00033280 _____ (Microsoft

Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-07-25 22:49 - 2013-08-15 02:23 - 02706432 _____ (Microsoft

Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-07-25 22:39 - 2013-08-15 02:23 - 00089600 _____ (Microsoft

Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-07-25 21:59 - 2013-08-15 02:23 - 00071680 _____ (Microsoft

Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-07-25 05:25 - 2013-08-15 00:25 - 01888768 _____ (Microsoft

Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-07-25 04:57 - 2013-08-15 00:25 - 01620992 _____ (Microsoft

Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-07-23 19:42 - 2013-07-23 19:42 - 00059471 _____ C:\Users\Dad

\Downloads\DetrimentCallMacro.cs
2013-07-23 19:41 - 2013-07-23 19:41 - 00059471 ____R C:\Users\Dad

\Desktop\DetrimentCallMacro.cs

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-08-22 12:58

==================== End Of Log ============================

 



#7 feeonme

feeonme
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:11:37 PM

Posted 22 August 2013 - 10:08 PM

Oops, my bad attached the second file. After rereading your post I caught my mistake here it is for you.

 

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 21-08-2013 02
Ran by Dad at 2013-08-22 22:36:57
Running from C:\Users\Dad\Downloads
Boot Mode: Normal
==========================================================


==================== Installed Programs =======================

   
 2013 (Version: 2013.0.3392)
 Update for Microsoft Office 2007 (KB2508958) (x32)
7-Zip 9.20 (x32)
7-Zip 9.20 (x64 edition) (Version: 9.20.00.0)
7-Zip 9.21 (x32 Version: 9.21.00.0)
Ad-Aware Antivirus (x32 Version: 10.4.47.4163)
Ad-Aware Security Add-on (x32 Version: 2.2.0.17)
Adobe Flash Player 11 ActiveX (x32 Version: 11.8.800.94)
Adobe Flash Player 11 Plugin (x32 Version: 11.8.800.94)
Adobe Reader XI (11.0.03) (x32 Version: 11.0.03)
Adobe Shockwave Player 11.5 (x32 Version: 11.5.9.615)
Advanced Combat Tracker (remove only) (x32)
Amazon MP3 Downloader 1.0.15 (x32 Version: 1.0.15)
AMD Accelerated Video Transcoding (Version: 13.10.100.30604)
AMD APP SDK Runtime (Version: 10.0.1084.4)
AMD Catalyst Control Center (x32 Version: 2013.0604.1838.31590)
AMD Catalyst Install Manager (Version: 8.0.915.0)
AMD Drag and Drop Transcoding (Version: 2.00.0000)
AMD Fuel (Version: 2013.0604.1838.31590)
AMD Media Foundation Decoders (Version: 1.0.80604.1838)
AMD Steady Video Plug-In  (Version: 2.06.0000)
AMD Wireless Display v3.0 (Version: 1.0.0.12)
Arx Fatalis (x32)
ATI Catalyst Registration (x32 Version: 3.00.0000)
AVG 2013 (Version: 13.0.3211)
AVG 2013 (Version: 13.0.3392)
BioShock Infinite (x32)
Catalyst Control Center - Branding (x32 Version: 1.00.0000)
Catalyst Control Center Graphics Previews Common (x32 Version: 2013.0604.1838.31590)
Catalyst Control Center InstallProxy (x32 Version: 2013.0604.1838.31590)
Catalyst Control Center Localization All (x32 Version: 2013.0604.1838.31590)
CCC Help Chinese Standard (x32 Version: 2013.0604.1837.31590)
CCC Help Chinese Traditional (x32 Version: 2013.0604.1837.31590)
CCC Help Czech (x32 Version: 2013.0604.1837.31590)
CCC Help Danish (x32 Version: 2013.0604.1837.31590)
CCC Help Dutch (x32 Version: 2013.0604.1837.31590)
CCC Help English (x32 Version: 2013.0604.1837.31590)
CCC Help Finnish (x32 Version: 2013.0604.1837.31590)
CCC Help French (x32 Version: 2013.0604.1837.31590)
CCC Help German (x32 Version: 2013.0604.1837.31590)
CCC Help Greek (x32 Version: 2013.0604.1837.31590)
CCC Help Hungarian (x32 Version: 2013.0604.1837.31590)
CCC Help Italian (x32 Version: 2013.0604.1837.31590)
CCC Help Japanese (x32 Version: 2013.0604.1837.31590)
CCC Help Korean (x32 Version: 2013.0604.1837.31590)
CCC Help Norwegian (x32 Version: 2013.0604.1837.31590)
CCC Help Polish (x32 Version: 2013.0604.1837.31590)
CCC Help Portuguese (x32 Version: 2013.0604.1837.31590)
CCC Help Russian (x32 Version: 2013.0604.1837.31590)
CCC Help Spanish (x32 Version: 2013.0604.1837.31590)
CCC Help Swedish (x32 Version: 2013.0604.1837.31590)
CCC Help Thai (x32 Version: 2013.0604.1837.31590)
CCC Help Turkish (x32 Version: 2013.0604.1837.31590)
ccc-utility64 (Version: 2013.0604.1838.31590)
CCleaner (Version: 4.04)
CPUID CPU-Z 1.56
Crysis®3 (x32 Version: 1.0.0.0)
CyberLink Blu-ray Disc Suite (x32 Version: 7.0.1929)
CyberLink Power2Go (x32 Version: 6.1.3401)
CyberLink PowerDirector (x32 Version: 7.0.3227a)
CyberLink PowerDVD 9 (x32 Version: 9.0.3815.52)
D3DX10 (x32 Version: 15.4.2368.0902)
Data Lifeguard Diagnostic for Windows 1.24 (x32)
DivX Setup (x32 Version: 2.6.1.24)
Dual-Core Optimizer (x32 Version: 1.1.4.0169)
eBook: Elementary Education: Content Knowledge Study Guide (x32 Version: 2.0)
EQ2MAP Updater 1.2.10 (x32 Version: 1.2.10)
EverQuest II (us english) (HKCU)
EverQuest II (us) (HKCU)
EverQuest II: Sentinel’s Fate (x32 Version: 1.00.000)
Far Cry 3 Blood Dragon (x32 Version: 1.02)
Google Earth (x32 Version: 7.1.1.1888)
Google Update Helper (x32 Version: 1.3.21.153)
GoToMeeting 5.4.0.1082 (HKCU Version: 5.4.0.1082)
Half-Life 2: Deathmatch (x32)
Half-Life 2: Lost Coast (x32)
HxD Hex Editor version 1.7.7.0 (x32 Version: 1.7.7.0)
HydraVision (x32 Version: 4.2.252.0)
iCloud (Version: 2.0.2.187)
iTunes (Version: 10.7.0.21)
Java 7 Update 25 (x32 Version: 7.0.250)
Java Auto Updater (x32 Version: 2.1.9.5)
Jing (x32 Version: 2.8.13007.1)
Junk Mail filter update (x32 Version: 16.4.3505.0912)
Lavasoft Registry Tuner (x32 Version: 1.0.35)
Legends of Norrath (HKCU)
Malwarebytes Anti-Malware version 1.70.0.1100 (x32 Version: 1.70.0.1100)
Marine Aquarium Lite Firefox Toolbar  (x32)
Marine Aquarium Lite Internet Explorer Toolbar (x32)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Mouse and Keyboard Center (Version: 2.1.177.0)
Microsoft Office 2007 Service Pack 3 (SP3) (x32)
Microsoft Office Excel MUI (English) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office File Validation Add-In (x32 Version: 14.0.5130.5003)
Microsoft Office Home and Student 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000)
Microsoft Office OneNote MUI (English) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office PowerPoint MUI (English) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (Spanish) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proofing (English) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office Shared 64-bit MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Shared MUI (English) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Shared Setup Metadata MUI (English) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Word MUI (English) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Silverlight (Version: 5.1.20513.0)
Microsoft SkyDrive (HKCU Version: 16.4.6013.0910)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000)
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (x32 Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (Version: 9.0.30729.5570)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (x32 Version: 9.0.30729.5570)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (Version: 9.0.21022)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (Version: 10.0.30319)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (x32 Version: 11.0.50727.1)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (x32 Version: 11.0.50727.1)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 (Version: 11.0.50727)
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 (Version: 11.0.50727)
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 (x32 Version: 11.0.50727)
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 (x32 Version: 11.0.50727)
Movie Maker (x32 Version: 16.4.3505.0912)
Mozilla Firefox 23.0.1 (x86 en-US) (x32 Version: 23.0.1)
Mozilla Maintenance Service (x32 Version: 23.0.1)
MSVCRT (x32 Version: 15.4.2862.0708)
MSVCRT_amd64 (x32 Version: 15.4.2862.0708)
MSVCRT110 (x32 Version: 16.4.1108.0727)
MSVCRT110_amd64 (Version: 16.4.1109.0912)
MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0)
MSXML 4.0 SP2 Parser and SDK (x32 Version: 4.20.9818.0)
Mumble 1.2.4 (x32 Version: 1.2.4)
Nero Suite (x32)
NVIDIA PhysX (x32 Version: 9.12.0213)
OLYMPUS Master 2 (x32 Version: 1.0.4)
OpenOffice.org 3.2 (x32 Version: 3.2.9483)
Origin (x32 Version: 9.2.1.4399)
PDF Combine (x32)
pdfsam (x32 Version: 2.2.1)
PERRLA (x32 Version: 7.3.3)
Photo Gallery (x32 Version: 16.4.3505.0912)
ProfitUI Reborn Updater (HKCU)
PunkBuster Services (x32 Version: 0.993)
QuickTime (x32 Version: 7.72.80.56)
Raid Hub Client (x32 Version: 1.1.15)
R-Drive Image 5.1 (x32 Version: 5.1.5104)
Safari (x32 Version: 5.34.57.2)
Speccy (Version: 1.22)
SpeedFan (remove only) (x32)
Star Wars Jedi Knight: Dark Forces II (x32)
Steam (x32 Version: 1.0.0.0)
TeamSpeak 3 Client
The Witcher Enhanced Edition (x32 Version: 1.4.5.1280)
Tomb Raider (x32)
TrueCrypt (x32 Version: 7.1a)
Unity Web Player (HKCU Version: )
Update for 2007 Microsoft Office System (KB967642) (x32)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2836939) (x32 Version: 1)
Update for Microsoft Office 2007 Help for Common Features (KB963673) (x32)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (x32)
Update for Microsoft Office Script Editor Help (KB963671) (x32)
Uplay (x32 Version: 3.0)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0)
Ventrilo Client (x32 Version: 3.0.7)
Video Card Stability Test (x32 Version: v.1.0.0.3)
Visual C++ 2008 x86 Runtime - (v9.0.30729) (x32 Version: 9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01 (x32 Version: 9.0.30729.01)
Visual C++ 8.0 Runtime Setup Package (x64) (x32 Version: 9.0.0.623)
Visual Studio 2008 x64 Redistributables (x32 Version: 10.0.0.2)
Visual Studio 2010 x64 Redistributables (Version: 13.0.0.1)
VoiceOver Kit (x32 Version: 1.42.128.0)
Windows Live Communications Platform (x32 Version: 16.4.3505.0912)
Windows Live Essentials (x32 Version: 16.4.3505.0912)
Windows Live Family Safety (Version: 16.4.3505.0912)
Windows Live Family Safety (x32 Version: 16.4.3505.0912)
Windows Live ID Sign-in Assistant (Version: 7.250.4311.0)
Windows Live Installer (x32 Version: 16.4.3505.0912)
Windows Live Mail (x32 Version: 16.4.3505.0912)
Windows Live Messenger (x32 Version: 16.4.3505.0912)
Windows Live MIME IFilter (Version: 16.4.3505.0912)
Windows Live Photo Common (x32 Version: 16.4.3505.0912)
Windows Live PIMT Platform (x32 Version: 16.4.3505.0912)
Windows Live SOXE (x32 Version: 16.4.3505.0912)
Windows Live SOXE Definitions (x32 Version: 16.4.3505.0912)
Windows Live UX Platform (x32 Version: 16.4.3505.0912)
Windows Live UX Platform Language Pack (x32 Version: 16.4.3505.0912)
Windows Live Writer (x32 Version: 16.4.3505.0912)
Windows Live Writer Resources (x32 Version: 16.4.3505.0912)
Windows Media Player Firefox Plugin (x32 Version: 1.0.0.8)

==================== Restore Points  =========================

07-08-2013 23:19:35 Removed Dual-Core Optimizer.
13-08-2013 23:09:04 Removed AVG 2013
13-08-2013 23:10:20 Removed AVG 2013
13-08-2013 23:17:00 Dr.Web Anti-virus for Windows installation
15-08-2013 06:16:29 Windows Update
21-08-2013 21:58:04 Dr.Web Anti-virus for Windows uninstallation
21-08-2013 23:41:37 Windows Update
22-08-2013 00:42:05 Installed AVG 2013
22-08-2013 00:42:28 Installed AVG 2013

==================== Hosts content: ==========================

2009-07-13 22:34 - 2013-08-13 15:50 - 00000741 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1    localhost

==================== Scheduled Tasks (whitelisted) =============

Task: {11FD3219-EF1E-4DAA-B6D4-89342A4FF3FE} - System32\Tasks\Ad-Aware Update (Daily 1) => C:\Program Files (x86)\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe No File
Task: {17C9BEF6-5A17-45EE-BB77-8BD57763180C} - System32\Tasks\Ad-Aware Update (Daily 3) => C:\Program Files (x86)\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe No File
Task: {191E3A7E-D01A-4156-8327-EB96DDCA9502} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-01-29] (Microsoft Corporation)
Task: {212DD518-51B5-4B8B-BBBC-C0EE04827D79} - System32\Tasks\{14379CD4-935C-4DAC-8E50-A764445D1C1E} => C:\Program Files (x86)\QuickTime\QuickTimePlayer.exe [2012-04-18] (Apple Inc.)
Task: {233E77FC-00DD-462A-AF83-C71605AC7C4B} - System32\Tasks\{C1CBBAE7-F40D-4057-B9C0-AABD2127447B} => C:\Windows\SysWOW64\javaws.exe [2013-06-12] (Oracle Corporation)
Task: {33DC8403-4085-4F33-896A-A51381B9C847} - System32\Tasks\{25F4C227-30E1-4999-93E8-88CF4FFA9C06} => C:\Program Files (x86)\Ahead\Nero ShowTime\ShowTime.exe [2005-06-13] (Nero Software AG)
Task: {3F6CA0F2-835B-4F7C-8E1E-BDEB0C586154} - System32\Tasks\Ad-Aware Update (Daily 4) => C:\Program Files (x86)\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe No File
Task: {563AD382-710C-4178-BD6A-15FF1C80AC0C} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-08-21] (Adobe Systems Incorporated)
Task: {5BABA81F-FF3B-4EED-8A51-5E67ECAF46AA} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task
Task: {6C56E38B-62C5-4030-9442-73A3C9F45637} - System32\Tasks\Ad-Aware Update (Daily 2) => C:\Program Files (x86)\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe No File
Task: {7E44DB2B-48BC-48B0-9C15-E69272E8E2D4} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-01-29] (Microsoft Corporation)
Task: {8EE89BB3-C54B-417B-A548-A05458831AF7} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2013-01-29] (Microsoft)
Task: {9B61ED70-7AB3-4D2B-B4D5-49865DE8021B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-07-02] (Google Inc.)
Task: {9C420C8A-F13D-487E-BB43-3DC6581A387C} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe [2010-11-20] (Microsoft Corporation)
Task: {A2718C48-A4DC-4C20-B639-C6CF06557388} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-01-29] (Microsoft Corporation)
Task: {A4F91068-3433-412B-82E0-7BDF671D21EA} - System32\Tasks\{0F873AA1-7A61-4598-8C74-2443AAEDA03B} => C:\Program Files (x86)\Skype\\Phone\Skype.exe No File
Task: {B312F74C-6EC4-49E9-A778-6E17EFFFDCAE} - System32\Tasks\CCleanerSkipUAC => C:\Program Files (x86)\CCleaner\CCleaner.exe [2013-07-22] (Piriform Ltd)
Task: {B4C55F5D-E0AA-4A59-96A0-62DA070E304A} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-01-29] (Microsoft Corporation)
Task: {B8C1EA0F-A0E2-4CEA-AEB8-E0EC75806CFF} - System32\Tasks\{1814E004-85C3-4CAD-A9B5-B3665B25B0EB} => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe No File
Task: {C01A2ACA-3DB6-450C-96EE-62DE499E139D} - System32\Tasks\User_Feed_Synchronization-{4BDA6678-DDD8-49F1-8CD5-5304E4058D66} => C:\Windows\system32\msfeedssync.exe [2013-03-15] (Microsoft Corporation)
Task: {DFD721B3-6309-4419-BAFA-51F1D4CE17D6} - System32\Tasks\Ad-Aware Antivirus Scheduled Scan => C:\PROGRA~2\AD-AWA~1\AdAwareLauncher.exe [2012-12-07] (Lavasoft Limited)
Task: {EDBAC125-606E-41CB-A0DC-6555C771BE42} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-07-02] (Google Inc.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (08/22/2013 03:42:40 AM) (Source: Application Error) (User: )
Description: Faulting application name: IEXPLORE.EXE, version: 10.0.9200.16660, time stamp: 0x51f1c5f3
Faulting module name: atidxx32.dll, version: 8.17.10.494, time stamp: 0x51ae686d
Exception code: 0xc0000005
Fault offset: 0x003d0df8
Faulting process id: 0xae4
Faulting application start time: 0xIEXPLORE.EXE0
Faulting application path: IEXPLORE.EXE1
Faulting module path: IEXPLORE.EXE2
Report Id: IEXPLORE.EXE3

Error: (08/21/2013 02:52:08 PM) (Source: Application Error) (User: )
Description: Faulting application name: firefox.exe, version: 23.0.1.4974, time stamp: 0x520bc252
Faulting module name: xul.dll, version: 23.0.1.4974, time stamp: 0x520bc166
Exception code: 0xc0000005
Fault offset: 0x0017af08
Faulting process id: 0x78c
Faulting application start time: 0xfirefox.exe0
Faulting application path: firefox.exe1
Faulting module path: firefox.exe2
Report Id: firefox.exe3

Error: (08/21/2013 01:08:25 PM) (Source: Application Error) (User: )
Description: Faulting application name: FlashPlayerPlugin_11_8_800_94.exe, version: 11.8.800.94, time stamp: 0x51c4d74d
Faulting module name: FlashPlayerPlugin_11_8_800_94.exe, version: 11.8.800.94, time stamp: 0x51c4d74d
Exception code: 0x40000015
Fault offset: 0x00017ae0
Faulting process id: 0x14c4
Faulting application start time: 0xFlashPlayerPlugin_11_8_800_94.exe0
Faulting application path: FlashPlayerPlugin_11_8_800_94.exe1
Faulting module path: FlashPlayerPlugin_11_8_800_94.exe2
Report Id: FlashPlayerPlugin_11_8_800_94.exe3

Error: (08/21/2013 00:59:08 PM) (Source: Application Error) (User: )
Description: Faulting application name: IEXPLORE.EXE, version: 10.0.9200.16660, time stamp: 0x51f1c5f3
Faulting module name: atidxx32.dll, version: 8.17.10.494, time stamp: 0x51ae686d
Exception code: 0xc0000005
Fault offset: 0x003d0df8
Faulting process id: 0xde8
Faulting application start time: 0xIEXPLORE.EXE0
Faulting application path: IEXPLORE.EXE1
Faulting module path: IEXPLORE.EXE2
Report Id: IEXPLORE.EXE3

Error: (08/20/2013 09:05:01 AM) (Source: Windows Search Service) (User: )
Description: The index cannot be initialized.


Details:
    The content index catalog is corrupt.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (08/20/2013 09:05:01 AM) (Source: Windows Search Service) (User: )
Description: The application cannot be initialized.

Context: Windows Application


Details:
    The content index catalog is corrupt.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (08/20/2013 09:05:01 AM) (Source: Windows Search Service) (User: )
Description: The gatherer object cannot be initialized.

Context: Windows Application, SystemIndex Catalog


Details:
    The content index catalog is corrupt.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (08/20/2013 09:05:01 AM) (Source: Windows Search Service) (User: )
Description: The plug-in in <Search.TripoliIndexer> cannot be initialized.

Context: Windows Application, SystemIndex Catalog


Details:
    Element not found.  (HRESULT : 0x80070490) (0x80070490)

Error: (08/20/2013 09:05:01 AM) (Source: Windows Search Service) (User: )
Description: The plug-in in <Search.JetPropStore> cannot be initialized.

Context: Windows Application, SystemIndex Catalog


Details:
    The content index catalog is corrupt.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (08/20/2013 09:05:01 AM) (Source: Windows Search Service) (User: )
Description: The Windows Search Service cannot load the property store information.

Context: Windows Application, SystemIndex Catalog


Details:
    The content index database is corrupt.  (HRESULT : 0xc0041800) (0xc0041800)


System errors:
=============
Error: (08/22/2013 09:44:04 AM) (Source: Service Control Manager) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
Lbd

Error: (08/22/2013 09:43:53 AM) (Source: Service Control Manager) (User: )
Description: The AODDriver4.2 service failed to start due to the following error:
%%2

Error: (08/22/2013 03:42:46 AM) (Source: Service Control Manager) (User: )
Description: The ScRegSetValueExW call failed for FailureActions with the following error:
%%5

Error: (08/21/2013 07:52:56 PM) (Source: Service Control Manager) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
Lbd

Error: (08/21/2013 07:52:54 PM) (Source: Service Control Manager) (User: )
Description: The AODDriver4.2 service failed to start due to the following error:
%%2

Error: (08/21/2013 07:49:47 PM) (Source: Service Control Manager) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
Lbd

Error: (08/21/2013 07:49:39 PM) (Source: Service Control Manager) (User: )
Description: The AODDriver4.2 service failed to start due to the following error:
%%2

Error: (08/21/2013 07:36:56 PM) (Source: Service Control Manager) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
Lbd

Error: (08/21/2013 07:36:56 PM) (Source: Service Control Manager) (User: )
Description: The AODDriver4.2 service failed to start due to the following error:
%%2

Error: (08/21/2013 07:36:50 PM) (Source: Service Control Manager) (User: )
Description: The AODDriver4.2 service failed to start due to the following error:
%%2


Microsoft Office Sessions:
=========================
Error: (04/03/2013 06:29:47 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 603 seconds with 420 seconds of active time.  This session ended with a crash.

Error: (04/03/2013 06:19:20 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 5547 seconds with 1140 seconds of active time.  This session ended with a crash.


==================== Memory info ===========================

Percentage of memory in use: 16%
Total physical RAM: 12278.14 MB
Available physical RAM: 10226.74 MB
Total Pagefile: 24554.46 MB
Available Pagefile: 22310.18 MB
Total Virtual: 8192 MB
Available Virtual: 8191.8 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:1191.99 GB) (Free:885.55 GB) NTFS
Drive d: (SIOP 6-12) (CDROM) (Total:0.3 GB) (Free:0 GB) CDFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 1192 GB) (Disk ID: A9DAE134)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=-919130341376) - (Type=07 NTFS)

==================== End Of Log ============================

 



#8 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,444 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:08:37 PM

Posted 25 August 2013 - 08:37 AM

Hi Bill,

I apologize for the extended delay, I did not receive notification that you had replied.

Unfortunately the logs confirm what we expected. There is no workable information upon which we could at least attempt to decrypt your files. I am assuming your repair shop is finding the same but if not please let me know.

Please let me know if there is anything else I might be able to assist you with.
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"May you be richly rewarded by the Lord, the God of Israel, under whose wings you have come to take refuge."

#9 feeonme

feeonme
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:11:37 PM

Posted 25 August 2013 - 08:41 AM

Hi Gary,

The local guy thinks it has someting to do with the way windows is looking at the file he feels the files themselves are still intact, I know none of the files have changed sizes. Would it help if I attached one of the documents?

 

 

“Adversity is the diamond dust heave polishes its jewels with”  ~Robert Leighton

Thanks, Bill

Edited by feeonme, 25 August 2013 - 08:50 AM.


#10 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,444 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:08:37 PM

Posted 25 August 2013 - 09:12 AM

I don't know if it will be of any help, and that explanation sounds foreign to me but go ahead and upload the file here. I will have one of our encryption experts take a peek at it.
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"May you be richly rewarded by the Lord, the God of Israel, under whose wings you have come to take refuge."

#11 feeonme

feeonme
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:11:37 PM

Posted 25 August 2013 - 03:45 PM

Gary,

 

I submitted that file on the link you provided. Its just a copy of my resume, so nothing to private about it.

 

Bill



#12 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,444 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:08:37 PM

Posted 25 August 2013 - 03:46 PM

Thanks Bill I will touch base with our expert.
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"May you be richly rewarded by the Lord, the God of Israel, under whose wings you have come to take refuge."

#13 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,444 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:08:37 PM

Posted 27 August 2013 - 02:07 PM

I have not heard back from our expert so I will try to touch base with him again.
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"May you be richly rewarded by the Lord, the God of Israel, under whose wings you have come to take refuge."

#14 feeonme

feeonme
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:11:37 PM

Posted 27 August 2013 - 04:44 PM

Awesome Gary, and thanks for your diligence.



#15 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,444 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:08:37 PM

Posted 27 August 2013 - 06:11 PM

Hi Bill,

I heard back and unfortunately it is not good news. Not only will we be unable to decrypt those files, there is no real hope of being able to decrypt them in the future. It gets real technical as to the reason why, but our consultant is one of the best there is when it comes to encryption/decryption.

I wish I had better news but this is what I expected we might find. I suspect your local shop will be unable to decrypt the files as well. If you are paying for that service you might want to reconsider.

Let me know if there is anything else I might be able to assist you with.
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"May you be richly rewarded by the Lord, the God of Israel, under whose wings you have come to take refuge."




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users