Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

security check by screen317 won't run


  • This topic is locked This topic is locked
33 replies to this topic

#1 TamiTX

TamiTX

  • Members
  • 27 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:01:46 AM

Posted 18 August 2013 - 09:20 PM

My computer in infected with Zaccess Trojan. I looked it up in the forum and printed the removal directions. I only got as far as running defogger and then tried to run security check by screen317. The notepad document does not come up. What should I do?



BC AdBot (Login to Remove)

 


#2 TamiTX

TamiTX
  • Topic Starter

  • Members
  • 27 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:01:46 AM

Posted 20 August 2013 - 07:02 PM

Does anyone know how to get rid of the Zero Access Trojan (zaccess)?



#3 HelpBot

HelpBot

    Bleepin' Binary Bot


  • Bots
  • 12,658 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:46 AM

Posted 23 August 2013 - 09:25 PM

Hello and welcome to Bleeping Computer!

I am HelpBot: an automated program designed to help the Bleeping Computer Staff better assist you! This message contains very important information, so please read through all of it before doing anything.

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

To help Bleeping Computer better assist you please perform the following steps:

***************************************************

step1.gif In order to continue receiving help at BleepingComputer.com, YOU MUST tell me if you still need help or if your issue has already been resolved on your own or through another resource! To tell me this, please click on the following link and follow the instructions there.

CLICK THIS LINK >>> http://www.bleepingcomputer.com/logreply/504860 <<< CLICK THIS LINK



If you no longer need help, then all you needed to do was the previous instructions of telling me so. You can skip the rest of this post. If you do need help please continue with Step 2 below.

***************************************************

step2.gifIf you still need help, I would like you to post a Reply to this topic (click the "Add Reply" button in the lower right hand of this page). In that reply, please include the following information:

  • If you have not done so already, include a clear description of the problems you're having, along with any steps you may have performed so far.
  • A new DDS log. For your convenience, you will find the instructions for generating these logs repeated at the bottom of this post.
    • Please do this even if you have previously posted logs for us.
    • If you were unable to produce the logs originally please try once more.
    • If you are unable to create a log please provide detailed information about your installed Windows Operating System including the Version, Edition and if it is a 32bit or a 64bit system.
    • If you are unsure about any of these characteristics just post what you can and we will guide you.
  • Please tell us if you have your original Windows CD/DVD available.
  • Upon completing the above steps and posting a reply, another staff member will review your topic and do their best to resolve your issues.

Thank you for your patience, and again sorry for the delay.

***************************************************

We need to see some information about what is happening in your machine. Please perform the following scan again:

  • Download DDS by sUBs from the following link if you no longer have it available and save it to your destop.

    DDS.com Download Link
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control can be found HERE.

As I am just a silly little program running on the BleepingComputer.com servers, please do not send me private messages as I do not know how to read and reply to them! Thanks!

#4 dev00790

dev00790

    Bleeping Chocoholic


  • Members
  • 5,037 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:06:46 AM

Posted 25 August 2013 - 08:46 AM

Hi,

My forum name is Dev00790 and I'll be helping you clean up your computer.

I will reply as soon as possible (typically within 24 hours). In turn, I ask that you please respond within 72 hours. If you know you will be away longer than that, I just ask for notice ahead of time.
Please be patient while I assist you.

Some points for you to keep in mind while I am helping you to make things go easier and faster for both of us:
 

  • Please do NOT run, install or uninstall any programs,  unless instructed to do so.
    • We ask you to run different tools in a specific order to ensure the malware is completely removed from your machine, and running any additional tools may detect false positives, interfere with our tools, or cause unforeseen damage or system instability.
          
       
  • Please do not attach logs or use code boxes, just copy and paste the text.
    • Due to the high volume of logs we receive it helps to receive everything in the same format, and code boxes make the logs very difficult to read. Also, attachments require us to download and open the reports when it is easier to just read the reports in your post.
          
  • Please read every post completely before doing anything.   
    • Pay special attention to the NOTE: lines, these entries identify an individual issue or important step in the cleanup process.
          
  • Please provide feedback about your experience as we go.  
    • A short statement describing how the computer is working helps us understand where to go next, for example: I am still getting redirected, the computer is running normally, etc. Please do not describe the computer as "the same", this requires the extra step of looking back at your previous post.
          
  • I'm currently a trainee in the Malware Removal Training program and therefore my answers have to be checked by a Teacher before they get posted to you.
    There may be a delay due to this. I apologize in advance if this happens. Hold tight while I get the first set of instructions out to you.


NOTE: At the top of your post, click on the Watch Topic Button, select Immediate Notification, and click on Proceed. This will send you an e-mail as soon as I reply to your topic, allowing us to resolve the issue faster.

NOTE: Backup any files that cannot be replaced. Removing malware can be unpredictable and this step can save a lot of heartaches if things don't go as planed. You can put them on a CD/DVD, external drive or a pen drive, anywhere except on the computer.

NOTE: It is good practice to copy and paste the instructions into notepad and print them in case it is necessary for you to go offline during the cleanup process. To open notepad, navigate to Start Menu > All Programs > Accessories > Notepad. Please remember to copy the entire post so you do not miss any instructions.

 

 

---------------------

 

:step1:

 

 

  • Download DDS by sUBs from one of the following links:
  • Save it to your desktop.
  • Double click on the DDS icon, and allow it to run.
  • DDS will now display a red window with an option screen called DDS: Settings
  • Mark the options dds.txt and attach.txt.
  • Click on Start.
  • If you did not disable a script-blocker that may be part of your antimalware program, you may receive a warning from your antimalware product asking if you would like DDS.com to run. Please allow it to do so.
  • DDS will automatically open both logfiles.
  • You can find them on your desktop as well.
  • Please post the content of those logfiles with your next answer.

Please note:  You may have to disable any script protection running if the scan fails to run.  After downloading the tool, disconnect from the internet and disable all antivirus protection.  Run the scan, enable your A/V and reconnect to the internet.  

Information on A/V control HERE


Edited by dev00790, 25 August 2013 - 08:47 AM.

Regards, dev00790

---------------------------------------

Marge: "Homer, the plant called. They said if you don't show up tomorrow don't bother showing up on Monday." Homer: "Woo-hoo! Four-day weekend!"I do not reply to Private Messages (PMs) asking for assistance - please use the forums instead. If I have been helping you, and I have not replied to your latest post in 48 hours please send me a PM. My Blog


#5 TamiTX

TamiTX
  • Topic Starter

  • Members
  • 27 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:01:46 AM

Posted 25 August 2013 - 07:52 PM

I tried running DDS as you requested above. It ran but no text files were created.



#6 dev00790

dev00790

    Bleeping Chocoholic


  • Members
  • 5,037 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:06:46 AM

Posted 28 August 2013 - 03:58 AM

Ok

 

Please download Farbar Recovery Scan Tool and save it to your desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.

Regards, dev00790

---------------------------------------

Marge: "Homer, the plant called. They said if you don't show up tomorrow don't bother showing up on Monday." Homer: "Woo-hoo! Four-day weekend!"I do not reply to Private Messages (PMs) asking for assistance - please use the forums instead. If I have been helping you, and I have not replied to your latest post in 48 hours please send me a PM. My Blog


#7 TamiTX

TamiTX
  • Topic Starter

  • Members
  • 27 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:01:46 AM

Posted 28 August 2013 - 04:51 PM

I ran Farbar  Recovery Scan tool as you requested. Here are the results.

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-08-2013
Ran by Tami Baughman (administrator) on 28-08-2013 16:45:30
Running from C:\Users\Tami Baughman\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US)
Internet Explorer Version 10
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(AMD) C:\windows\system32\atiesrxx.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(Alcatel-Lucent) C:\Program Files (x86)\Common Files\Motive\McciCMService.exe
(Alcatel-Lucent) C:\Program Files\Common Files\Motive\McciCMService.exe
(Symantec Corporation) C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.6.22\ccSvcHst.exe
() C:\Program Files\Macrium\Reflect\ReflectService.exe
(TOSHIBA Corporation) C:\Windows\system32\TODDSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TECO\TecoService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgemca.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe
(AMD) C:\windows\system32\atieclxx.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Symantec Corporation) C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.6.22\ccSvcHst.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TECO\Teco.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
(Microsoft Corporation) C:\Program Files\Microsoft Device Center\itype.exe
(Microsoft Corporation) C:\Program Files\Microsoft Device Center\ipoint.exe
(SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Dropbox, Inc.) C:\Users\Tami Baughman\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe
(TOSHIBA Corporation) C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
(TOSHIBA CORPORATION.) C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe
(Fisher-Price) C:\Program Files (x86)\Fisher-Price\iXL\iXL.Middleware.exe
(Apple Computer, Inc.) C:\Program Files (x86)\QuickTime\qttask.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgui.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
(TOSHIBA Corporation) C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
(AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\ToolbarUpdater.exe
() C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\loggingserver.exe
() C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Reimage®) C:\Program Files\Reimage\Reimage Repair\ReiGuard.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Adobe Systems Incorporated) C:\windows\system32\Macromed\Flash\FlashUtil64_11_8_800_94_ActiveX.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [] -  [x]
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10134560 2010-03-22] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [896032 2010-03-22] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2052392 2010-03-10] (Synaptics Incorporated)
HKLM\...\Run: [TPwrMain] - C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [566184 2010-09-28] (TOSHIBA Corporation)
HKLM\...\Run: [HSON] - C:\Program Files\TOSHIBA\TBS\HSON.exe [52600 2009-03-09] (TOSHIBA Corporation)
HKLM\...\Run: [SmoothView] - C:\Program Files\Toshiba\SmoothView\SmoothView.exe [508216 2009-07-28] (TOSHIBA Corporation)
HKLM\...\Run: [00TCrdMain] - C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [915320 2010-05-10] (TOSHIBA Corporation)
HKLM\...\Run: [Teco] - C:\Program Files\TOSHIBA\TECO\Teco.exe [1489760 2010-04-06] (TOSHIBA Corporation)
HKLM\...\Run: [TosWaitSrv] - C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe [705368 2010-02-23] (TOSHIBA Corporation)
HKLM\...\Run: [SmartFaceVWatcher] - C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatcher.exe [238080 2009-10-19] (TOSHIBA Corporation)
HKLM\...\Run: [TosVolRegulator] - C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [24376 2009-11-11] (TOSHIBA Corporation)
HKLM\...\Run: [TosSENotify] - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [709976 2010-02-05] (TOSHIBA Corporation)
HKLM\...\Run: [TosNC] - C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe [595816 2010-03-19] (TOSHIBA Corporation)
HKLM\...\Run: [TosReelTimeMonitor] - C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe [35672 2010-03-03] (TOSHIBA Corporation)
HKLM\...\Run: [IntelliType Pro] - c:\Program Files\Microsoft Device Center\itype.exe [1464928 2012-06-26] (Microsoft Corporation)
HKLM\...\Run: [IntelliPoint] - c:\Program Files\Microsoft Device Center\ipoint.exe [2004584 2012-06-26] (Microsoft Corporation)
HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware (cleanup)] - rundll32.exe "C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll",ProcessCleanupScript [1091432 2012-12-14] (Malwarebytes Corporation)
HKCU\...\Run: [SUPERAntiSpyware] - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [6581488 2013-08-15] (SUPERAntiSpyware)
HKCU\...\Run: [Google Update*] -  [x] <===== ATTENTION (ZeroAccess rootkit hidden path)
HKCU\...\Winlogon: [Shell] explorer.exe <==== ATTENTION
HKCU\...\Command Processor:  <======= ATTENTION
HKCU\...\Policies\system: [DisableLockWorkstation] 0
MountPoints2: {495cae5d-0e23-11e1-97d8-1c75088bdecc} - E:\AutoRun.exe
MountPoints2: {495cae67-0e23-11e1-97d8-1c75088bdecc} - E:\AutoRun.exe
MountPoints2: {677f1c62-66ee-11e0-905c-1c75088bdecc} - E:\LaunchU3.exe -a
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-03-15] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [SVPWUTIL] - C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe [352256 2010-02-22] (TOSHIBA CORPORATION)
HKLM-x32\...\Run: [HWSetup] - C:\Program Files\TOSHIBA\Utilities\HWSetup.exe [423936 2010-03-04] (TOSHIBA Electronics, Inc.)
HKLM-x32\...\Run: [KeNotify] - C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe [34160 2009-12-25] (TOSHIBA CORPORATION)
HKLM-x32\...\Run: [ToshibaServiceStation] - C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe [1295736 2011-02-11] (TOSHIBA Corporation)
HKLM-x32\...\Run: [TWebCamera] - C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe [2454840 2010-02-24] (TOSHIBA CORPORATION.)
HKLM-x32\...\Run: [NortonOnlineBackupReminder] - C:\Program Files (x86)\Toshiba\Toshiba Online Backup\Activation\TOBuActivation.exe [3218792 2010-08-17] (Toshiba)
HKLM-x32\...\Run: [ToshibaAppPlace] - C:\Program Files (x86)\Toshiba\Toshiba App Place\ToshibaAppPlace.exe [552960 2010-09-23] (Toshiba)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [iXL_MiddleWare] - C:\Program Files (x86)\Fisher-Price\iXL\iXL.Middleware.exe [56376 2011-08-04] (Fisher-Price)
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\qttask.exe [77824 2013-04-11] (Apple Computer, Inc.)
HKLM-x32\...\Run: [vProt] - C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe [2314416 2013-08-25] ()
HKLM-x32\...\Run: [AVG_UI] - C:\Program Files (x86)\AVG\AVG2013\avgui.exe [4411440 2013-07-01] (AVG Technologies CZ, s.r.o.)
Startup: C:\Users\Tami Baughman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Tami Baughman\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Tami Baughman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
URLSearchHook: (No Name) - {752929fc-c897-4620-9fa8-0303247277e2} -  No File
SearchScopes: HKLM-x32 - {461fc775-35b6-4d0b-9ff3-af280bfaba83} URL = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=YTxdm003YYus&ptnrS=YTxdm003YYus&si=CN7So7_TmLMCFcxcMgoddnMAFg&ptb=6CB5BA01-2C0A-47CC-B701-B9B8359FEC0B&ind=2012102322&n=77ee3eb2&psa=&st=sb&searchfor={searchTerms}
SearchScopes: HKCU - DefaultScope {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://mysearch.avg.com/search?cid={B4D01020-5CE2-40D2-A261-3DCA471E5627}&mid=85285ff702e347d39465cd3c4e6f373f-d66a9737b1e127a2a21fd64a39d6ec5abb983db7&lang=en&ds=rg011&pr=sa&d=2013-08-24 12:13:06&v=15.4.0.5&pid=safeguard&sg=0&sap=dsp&q={searchTerms}
SearchScopes: HKCU - {461fc775-35b6-4d0b-9ff3-af280bfaba83} URL = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=YTxdm003YYus&ptnrS=YTxdm003YYus&si=CN7So7_TmLMCFcxcMgoddnMAFg&ptb=6CB5BA01-2C0A-47CC-B701-B9B8359FEC0B&ind=2012102322&n=77ee3eb2&psa=&st=sb&searchfor={searchTerms}
SearchScopes: HKCU - {52E6124F-3058-41E9-B47D-75E4301A258C} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3282134&CUI=UN34118778131586125
SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://mysearch.avg.com/search?cid={B4D01020-5CE2-40D2-A261-3DCA471E5627}&mid=85285ff702e347d39465cd3c4e6f373f-d66a9737b1e127a2a21fd64a39d6ec5abb983db7&lang=en&ds=rg011&pr=sa&d=2013-08-24 12:13:06&v=15.4.0.5&pid=safeguard&sg=0&sap=dsp&q={searchTerms}
SearchScopes: HKCU - {A5C802ED-3C2E-442D-91FA-F145A437781D} URL = http://search.yahoo.com/search?p={searchterms}&ei=UTF-8&fr=w3i&type=W3i_DS,136,0_0,Search,20120101,17118,0,18,0
SearchScopes: HKCU - {FCF585C3-924B-4F21-BF51-7295943DC6DA} URL =
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: TOSHIBA Media Controller Plug-in - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\x64\TOSHIBAMediaControllerIE.dll (TOSHIBA Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: AVG SafeGuard toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\15.5.0.2\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search)
BHO-x32: GamesBar from ATT - {a813911c-202d-4343-a0f2-5906d512fec5} - C:\Program Files (x86)\att_en\encyclopediabritannicagamesbarX.dll ()
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: No Name - {af77c74d-a46e-4671-afa0-1a09b1d4be39} -  No File
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: No Name - {e5af9d32-01d7-47b8-9eb6-87d9afce744f} -  No File
BHO-x32: TOSHIBA Media Controller Plug-in - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll (TOSHIBA Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - GamesBar from ATT - {a813911c-202d-4343-a0f2-5906d512fec5} - C:\Program Files (x86)\att_en\encyclopediabritannicagamesbarX.dll ()
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKLM-x32 - AVG SafeGuard toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\15.5.0.2\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File
Toolbar: HKCU - No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} -  No File
DPF: HKLM-x32 {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Program%20Files%20(x86)/Plants%20vs.%20Zombies%20-%20Game%20of%20the%20Year%20Edition/Images/stg_drm.ocx
DPF: HKLM-x32 {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: HKLM-x32 {1FDFCFC3-B893-43E1-9138-4A2D2452A551} https://www.t-mobilepictures.com/myalbum/scripts/downloader/FileDownloader7.cab
DPF: HKLM-x32 {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://akamaicdn.webex.com/client/WBXclient-T27L10NSP32EP1-13926/webex/ieatgpc1.cab
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\15.5.0\ViProtocol.dll (AVG Secure Search)
Winsock: Catalog5 01 mswsock.dll [326144] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5 07 mswsock.dll [326144] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\System32\mswsock.dll"
Winsock: Catalog5-x64 01 mswsock.dll [326144] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5-x64 07 mswsock.dll [326144] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\System32\mswsock.dll"
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254

Chrome:
=======
CHR HomePage: hxxp://mysearch.avg.com/?cid={B4D01020-5CE2-40D2-A261-3DCA471E5627}&mid=85285ff702e347d39465cd3c4e6f373f-d66a9737b1e127a2a21fd64a39d6ec5abb983db7&lang=en&ds=rg011&pr=sa&d=2013-08-24 12:13:06&v=15.4.0.5&pid=safeguard&sg=0&sap=hp
CHR RestoreOnStartup: "hxxp://mysearch.avg.com/?cid={B4D01020-5CE2-40D2-A261-3DCA471E5627}&mid=85285ff702e347d39465cd3c4e6f373f-d66a9737b1e127a2a21fd64a39d6ec5abb983db7&lang=en&ds=rg011&pr=sa&d=2013-08-24 12:13:06&v=15.4.0.5&pid=safeguard&sg=0&sap=hp"
CHR HKLM-x32\...\Chrome\Extension: [ndibdjnfmopecpmkdieinmbadjfpblof] - C:\ProgramData\AVG SafeGuard toolbar\ChromeExt\15.5.0.2\avg.crx

==================== Services (Whitelisted) =================

R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [140672 2012-07-11] (SUPERAntiSpyware.com)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [4939312 2013-07-04] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [283136 2013-07-23] (AVG Technologies CZ, s.r.o.)
S3 GoogleDesktopManager; C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe [1838592 2012-10-31] (Google)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [398184 2012-12-14] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [682344 2012-12-14] (Malwarebytes Corporation)
R2 McciCMService64; C:\Program Files\Common Files\Motive\McciCMService.exe [517632 2009-08-14] (Alcatel-Lucent)
R2 PCCUJobMgr; C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.6.22\ccSvcHst.exe [126392 2009-08-24] (Symantec Corporation)
R2 ReflectService.exe; C:\Program Files\Macrium\Reflect\ReflectService.exe [301760 2012-10-31] ()
R2 ReimageRealTimeProtection; C:\Program Files\Reimage\Reimage Repair\ReiGuard.exe [4393320 2013-08-27] (Reimage®)
R2 vToolbarUpdater15.5.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\ToolbarUpdater.exe [1643184 2013-08-25] (AVG Secure Search)
U2 *etadpug; "C:\Program Files (x86)\Google\Desktop\Install\{ac074fcf-d3e7-934a-caa6-9f94cb918cf7}\   \...\???\{ac074fcf-d3e7-934a-caa6-9f94cb918cf7}\GoogleUpdate.exe" < <==== ATTENTION (ZeroAccess)

==================== Drivers (Whitelisted) ====================

R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [246072 2013-07-20] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [71480 2013-07-20] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [206648 2013-07-20] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [311608 2013-07-20] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [116536 2013-07-01] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [45880 2013-07-10] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [240952 2013-03-21] (AVG Technologies CZ, s.r.o.)
R1 avgtp; C:\windows\system32\drivers\avgtpx64.sys [45856 2013-08-25] (AVG Technologies)
S3 mbamchameleon; C:\windows\system32\drivers\mbamchameleon.sys [36680 2013-05-27] ()
S3 mbamchameleon; C:\windows\system32\drivers\mbamchameleon.sys [36680 2013-05-27] ()
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [24176 2012-12-14] (Malwarebytes Corporation)
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [24176 2012-12-14] (Malwarebytes Corporation)
S3 MREMP50; C:\PROGRA~2\COMMON~1\Motive\MREMP50.SYS [21248 2009-08-14] (Printing Communications Assoc., Inc. (PCAUSA))
S3 MREMP50; C:\PROGRA~2\COMMON~1\Motive\MREMP50.SYS [21248 2009-08-14] (Printing Communications Assoc., Inc. (PCAUSA))
S3 MRESP50; C:\PROGRA~2\COMMON~1\Motive\MRESP50.SYS [20096 2009-08-14] (Printing Communications Assoc., Inc. (PCAUSA))
S3 MRESP50; C:\PROGRA~2\COMMON~1\Motive\MRESP50.SYS [20096 2009-08-14] (Printing Communications Assoc., Inc. (PCAUSA))
S3 PSMounterEx; C:\windows\system32\drivers\psmounterex.sys [57024 2012-10-31] ()
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S3 Serial; C:\Windows\system32\DRIVERS\serial.sys [94208 2009-07-13] (Brother Industries Ltd.)
S3 ZTEusbwwan; C:\Windows\System32\DRIVERS\ZTEusbwwan.sys [235008 2011-04-09] (ZTE Incorporated)
S3 cpuz134; \??\C:\Users\TAMIBA~1\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [x]
S3 massfilter; system32\drivers\massfilter.sys [x]
S3 MREMP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS [x]
S3 MREMPR5; \??\C:\PROGRA~2\COMMON~1\Motive\MREMPR5.SYS [x]
S3 MRENDIS5; \??\C:\PROGRA~2\COMMON~1\Motive\MRENDIS5.SYS [x]
S3 MRESP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS [x]
S1 mzkftgqj; \??\C:\windows\system32\drivers\mzkftgqj.sys [x]
S3 ZTEusbMB; system32\DRIVERS\ZTEusbnmeaext2.sys [x]
S3 ZTEusbnmea; system32\DRIVERS\ZTEusbnmea.sys [x]
S3 ZTEusbser6k; system32\DRIVERS\ZTEusbser6k.sys [x]

==================== NetSvcs (Whitelisted) ===================

==================== One Month Created Files and Folders ========

2013-08-28 16:43 - 2013-08-28 16:43 - 01579080 _____ (Farbar) C:\Users\Tami Baughman\Desktop\FRST64.exe
2013-08-27 12:21 - 2013-08-27 12:21 - 00002146 _____ C:\windows\system32\ScanResults.xml
2013-08-27 12:17 - 2013-08-27 12:17 - 00001056 _____ C:\windows\system32\SettingsFile
2013-08-26 18:30 - 2013-08-26 18:30 - 00000958 _____ C:\Users\Tami Baughman\Documents\virus notes.txt
2013-08-24 14:20 - 2013-08-24 14:20 - 00000000 _____ C:\windows\system32\reimage.nat
2013-08-24 14:14 - 2013-02-17 01:40 - 00028672 _____ (Microsoft Corporation) C:\windows\system32\IEUDINIT.EXE
2013-08-24 14:14 - 2010-11-20 06:07 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\Drivers\TsUsbGD.sys
2013-08-24 14:14 - 2009-06-10 15:35 - 00145792 _____ (Intel Corporation) C:\windows\system32\Drivers\E1G6032E.sys
2013-08-24 14:14 - 2009-06-10 12:45 - 00000003 _____ C:\windows\system32\Drivers\MsftWdf_Kernel_01009_Inbox_Critical.Wdf
2013-08-24 14:10 - 2013-08-24 14:10 - 00000000 ____D C:\Recovery
2013-08-24 12:39 - 2013-08-24 14:24 - 00000000 ____D C:\ReimageUndo
2013-08-24 12:39 - 2013-08-24 12:39 - 00009728 _____ C:\windows\system32\Native.exe
2013-08-24 12:21 - 2013-08-24 12:21 - 00000000 ____D C:\Users\Tami Baughman\AppData\Roaming\AVG2013
2013-08-24 12:20 - 2013-08-24 12:20 - 00003230 _____ C:\windows\System32\Tasks\SidebarExecute
2013-08-24 12:19 - 2013-08-24 12:19 - 00000936 _____ C:\Users\Public\Desktop\AVG 2013.lnk
2013-08-24 12:19 - 2013-08-24 12:19 - 00000000 ____D C:\Users\Tami Baughman\AppData\Roaming\TuneUp Software
2013-08-24 12:18 - 2013-08-24 12:20 - 00000000 ____D C:\ProgramData\AVG2013
2013-08-24 12:18 - 2013-08-24 12:18 - 00000000 ___HD C:\$AVG
2013-08-24 12:17 - 2013-08-24 12:17 - 00000000 ____D C:\Program Files (x86)\AVG
2013-08-24 12:14 - 2013-08-24 12:15 - 00000000 ____D C:\ProgramData\CDB
2013-08-24 12:14 - 2013-08-24 12:14 - 00001912 _____ C:\Users\Public\Desktop\PC Scan & Repair by Reimage.lnk
2013-08-24 12:14 - 2013-08-24 12:14 - 00000000 ____D C:\Users\TAMIBA~1\AppData\Local\AVG SafeGuard toolbar
2013-08-24 12:14 - 2013-08-24 12:14 - 00000000 ____D C:\Program Files\Reimage
2013-08-24 12:13 - 2013-08-28 14:54 - 00000000 ____D C:\ProgramData\MFAData
2013-08-24 12:13 - 2013-08-24 14:28 - 00000000 ____D C:\rei
2013-08-24 12:13 - 2013-08-24 12:25 - 00000000 ____D C:\Users\TAMIBA~1\AppData\Local\Avg2013
2013-08-24 12:13 - 2013-08-24 12:13 - 00000000 ____D C:\Users\TAMIBA~1\AppData\Local\MFAData
2013-08-24 12:12 - 2013-08-25 13:15 - 00000000 ____D C:\Program Files (x86)\AVG SafeGuard toolbar
2013-08-24 12:12 - 2013-08-25 13:14 - 00045856 _____ (AVG Technologies) C:\windows\system32\Drivers\avgtpx64.sys
2013-08-24 12:12 - 2013-08-24 12:26 - 00000000 ____D C:\ProgramData\AVG SafeGuard toolbar
2013-08-24 12:11 - 2013-08-24 14:10 - 00000179 _____ C:\windows\Reimage.ini
2013-08-22 20:50 - 2013-08-22 20:50 - 00000000 ____D C:\Users\Tami Baughman\Desktop\Autoruns
2013-08-22 20:46 - 2013-08-22 20:46 - 00550371 _____ C:\Users\Tami Baughman\Desktop\Autoruns.zip
2013-08-21 19:14 - 2013-08-21 19:14 - 00000000 ____D C:\Users\Tami Baughman\Desktop\2013 school forms
2013-08-21 19:03 - 2013-08-24 13:59 - 00000000 ____D C:\Users\Tami Baughman\Desktop\construction
2013-08-19 16:18 - 2013-08-19 16:18 - 00004555 _____ C:\AdwCleaner[S1].txt
2013-08-19 16:17 - 2013-08-19 16:18 - 00004665 _____ C:\AdwCleaner[R1].txt
2013-08-19 15:36 - 2013-08-19 15:36 - 00003955 _____ C:\Users\Tami Baughman\Desktop\RKreport[0]_S_08192013_153627.txt
2013-08-19 15:34 - 2013-08-19 15:37 - 00000000 ____D C:\Users\Tami Baughman\Desktop\RK_Quarantine
2013-08-19 15:32 - 2013-08-19 15:32 - 03814400 _____ C:\Users\Tami Baughman\Desktop\RogueKillerX64.exe
2013-08-19 15:24 - 2013-08-19 15:24 - 00688992 ____R (Swearware) C:\Users\Tami Baughman\Desktop\dds.com
2013-08-19 15:17 - 2013-08-19 15:18 - 00688992 ____R (Swearware) C:\Users\Tami Baughman\Downloads\dds.com
2013-08-18 21:14 - 2013-08-18 21:14 - 00891115 _____ C:\Users\Tami Baughman\Desktop\SecurityCheck.exe
2013-08-18 21:13 - 2013-08-19 11:24 - 00000488 _____ C:\Users\Tami Baughman\Desktop\defogger_disable.log
2013-08-18 21:13 - 2013-08-18 21:13 - 00050477 _____ C:\Users\Tami Baughman\Desktop\Defogger.exe
2013-08-18 21:13 - 2013-08-18 21:13 - 00000000 _____ C:\Users\Tami Baughman\defogger_reenable
2013-08-15 03:12 - 2013-07-26 00:13 - 01365504 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2013-08-15 03:12 - 2013-07-26 00:13 - 00051712 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2013-08-15 03:12 - 2013-07-26 00:12 - 03958784 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2013-08-15 03:12 - 2013-07-26 00:12 - 02647040 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2013-08-15 03:12 - 2013-07-26 00:12 - 00855552 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2013-08-15 03:12 - 2013-07-26 00:12 - 00603136 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2013-08-15 03:12 - 2013-07-26 00:12 - 00526336 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2013-08-15 03:12 - 2013-07-26 00:12 - 00136704 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll
2013-08-15 03:12 - 2013-07-26 00:12 - 00067072 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2013-08-15 03:12 - 2013-07-26 00:12 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2013-08-15 03:12 - 2013-07-25 22:35 - 02706432 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2013-08-15 03:12 - 2013-07-25 22:13 - 01141248 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2013-08-15 03:12 - 2013-07-25 22:12 - 02877440 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2013-08-15 03:12 - 2013-07-25 22:12 - 02048512 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2013-08-15 03:12 - 2013-07-25 22:12 - 00690688 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2013-08-15 03:12 - 2013-07-25 22:12 - 00493056 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2013-08-15 03:12 - 2013-07-25 22:12 - 00391168 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2013-08-15 03:12 - 2013-07-25 22:12 - 00109056 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesysprep.dll
2013-08-15 03:12 - 2013-07-25 22:12 - 00061440 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2013-08-15 03:12 - 2013-07-25 22:11 - 00033280 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2013-08-15 03:12 - 2013-07-25 21:49 - 02706432 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2013-08-15 03:12 - 2013-07-25 21:39 - 00089600 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe
2013-08-15 03:12 - 2013-07-25 20:59 - 00071680 _____ (Microsoft Corporation) C:\windows\SysWOW64\RegisterIEPKEYs.exe
2013-08-15 03:11 - 2013-07-26 00:13 - 02241024 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2013-08-15 03:11 - 2013-07-26 00:12 - 19239424 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2013-08-15 03:11 - 2013-07-26 00:12 - 15405056 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2013-08-15 03:11 - 2013-07-26 00:12 - 00053760 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2013-08-15 03:11 - 2013-07-25 22:13 - 01767936 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2013-08-15 03:11 - 2013-07-25 22:12 - 14329344 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2013-08-15 03:11 - 2013-07-25 22:12 - 00039936 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2013-08-15 03:11 - 2013-07-25 22:11 - 13761024 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2013-08-14 16:56 - 2013-07-18 20:58 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll
2013-08-14 16:56 - 2013-07-18 20:41 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\tzres.dll
2013-08-14 16:56 - 2013-07-09 00:52 - 00224256 _____ (Microsoft Corporation) C:\windows\system32\wintrust.dll
2013-08-14 16:56 - 2013-07-09 00:46 - 01472512 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll
2013-08-14 16:56 - 2013-07-09 00:46 - 00184320 _____ (Microsoft Corporation) C:\windows\system32\cryptsvc.dll
2013-08-14 16:56 - 2013-07-09 00:46 - 00139776 _____ (Microsoft Corporation) C:\windows\system32\cryptnet.dll
2013-08-14 16:56 - 2013-07-08 23:52 - 00175104 _____ (Microsoft Corporation) C:\windows\SysWOW64\wintrust.dll
2013-08-14 16:56 - 2013-07-08 23:46 - 01166848 _____ (Microsoft Corporation) C:\windows\SysWOW64\crypt32.dll
2013-08-14 16:56 - 2013-07-08 23:46 - 00140288 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptsvc.dll
2013-08-14 16:56 - 2013-07-08 23:46 - 00103936 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptnet.dll
2013-08-14 16:55 - 2013-07-25 04:25 - 01888768 _____ (Microsoft Corporation) C:\windows\system32\WMVDECOD.DLL
2013-08-14 16:55 - 2013-07-25 03:57 - 01620992 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMVDECOD.DLL
2013-08-14 16:55 - 2013-07-09 00:51 - 01217024 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2013-08-14 16:55 - 2013-07-08 23:52 - 00663552 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
2013-08-14 16:55 - 2013-07-06 01:03 - 01910208 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
2013-08-14 16:55 - 2013-06-14 23:32 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tssecsrv.sys
2013-08-14 16:55 - 2013-01-04 21:53 - 05553512 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2013-08-14 16:55 - 2013-01-04 21:00 - 03967848 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2013-08-14 16:55 - 2013-01-04 21:00 - 03913064 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2013-08-14 16:55 - 2013-01-03 20:51 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2013-08-14 16:55 - 2013-01-03 18:47 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2013-08-14 16:55 - 2013-01-03 18:47 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2013-08-14 16:55 - 2013-01-03 18:47 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2013-08-14 16:55 - 2013-01-03 18:47 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2013-08-14 16:55 - 2012-10-04 09:46 - 00243200 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2013-08-14 16:55 - 2011-11-17 08:41 - 01731920 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2013-08-14 16:55 - 2011-11-17 07:38 - 01292080 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2013-08-08 12:53 - 2013-08-08 12:53 - 15344555 _____ C:\Users\Tami Baughman\Downloads\Attachments_201388.zip

==================== One Month Modified Files and Folders =======

2013-08-28 16:45 - 2013-08-28 16:45 - 00000000 ____D C:\FRST
2013-08-28 16:43 - 2013-08-28 16:43 - 01579080 _____ (Farbar) C:\Users\Tami Baughman\Desktop\FRST64.exe
2013-08-28 16:34 - 2010-11-01 02:09 - 00000912 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-08-28 16:34 - 2010-11-01 02:09 - 00000908 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-08-28 15:58 - 2012-05-11 07:19 - 00000830 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2013-08-28 14:54 - 2013-08-24 12:13 - 00000000 ____D C:\ProgramData\MFAData
2013-08-28 02:00 - 2012-11-19 09:03 - 00000526 _____ C:\windows\Tasks\SUPERAntiSpyware Scheduled Task f8bc4dae-652e-493b-9b01-2d79dd6efde5.job
2013-08-27 19:25 - 2012-01-11 09:21 - 00000000 ____D C:\Users\Tami Baughman\Documents\Outlook Files
2013-08-27 17:12 - 2012-12-25 13:22 - 00000000 ____D C:\Users\Tami Baughman\AppData\Roaming\Dropbox
2013-08-27 16:54 - 2012-08-13 09:21 - 01833081 _____ C:\windows\WindowsUpdate.log
2013-08-27 12:21 - 2013-08-27 12:21 - 00002146 _____ C:\windows\system32\ScanResults.xml
2013-08-27 12:17 - 2013-08-27 12:17 - 00001056 _____ C:\windows\system32\SettingsFile
2013-08-26 22:13 - 2010-11-01 17:33 - 00000000 ____D C:\windows\Panther
2013-08-26 18:30 - 2013-08-26 18:30 - 00000958 _____ C:\Users\Tami Baughman\Documents\virus notes.txt
2013-08-25 19:12 - 2009-07-14 00:13 - 00743840 _____ C:\windows\system32\PerfStringBackup.INI
2013-08-25 13:15 - 2013-08-24 12:12 - 00000000 ____D C:\Program Files (x86)\AVG SafeGuard toolbar
2013-08-25 13:14 - 2013-08-24 12:12 - 00045856 _____ (AVG Technologies) C:\windows\system32\Drivers\avgtpx64.sys
2013-08-25 04:59 - 2009-07-13 22:20 - 00000000 ____D C:\windows\rescache
2013-08-24 20:23 - 2012-12-25 13:24 - 00000000 ___RD C:\Users\Tami Baughman\Dropbox
2013-08-24 20:23 - 2011-04-13 15:23 - 00000000 ___RD C:\Users\Tami Baughman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-08-24 20:23 - 2011-04-13 15:23 - 00000000 ___RD C:\Users\Tami Baughman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-08-24 20:20 - 2009-07-13 23:45 - 00016304 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-24 20:20 - 2009-07-13 23:45 - 00016304 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-24 20:13 - 2009-07-14 00:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2013-08-24 20:07 - 2009-07-14 00:32 - 00000000 ____D C:\Program Files\Windows Defender
2013-08-24 20:07 - 2009-07-14 00:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2013-08-24 20:06 - 2009-07-14 02:45 - 00000000 ____D C:\Program Files\Windows Journal
2013-08-24 19:04 - 2013-07-16 03:00 - 00000000 ____D C:\windows\system32\MRT
2013-08-24 18:55 - 2011-04-14 18:17 - 00001945 _____ C:\windows\epplauncher.mif
2013-08-24 14:28 - 2013-08-24 12:13 - 00000000 ____D C:\rei
2013-08-24 14:24 - 2013-08-24 12:39 - 00000000 ____D C:\ReimageUndo
2013-08-24 14:20 - 2013-08-24 14:20 - 00000000 _____ C:\windows\system32\reimage.nat
2013-08-24 14:16 - 2009-07-14 00:32 - 00000000 ____D C:\Program Files\Microsoft Games
2013-08-24 14:15 - 2009-07-14 00:09 - 00000000 ____D C:\windows\System32\Tasks\WPD
2013-08-24 14:15 - 2009-07-13 22:20 - 00000000 __RHD C:\Users\Public\Libraries
2013-08-24 14:15 - 2009-07-13 22:20 - 00000000 ____D C:\windows\system32\Recovery
2013-08-24 14:10 - 2013-08-24 14:10 - 00000000 ____D C:\Recovery
2013-08-24 14:10 - 2013-08-24 12:11 - 00000179 _____ C:\windows\Reimage.ini
2013-08-24 14:02 - 2011-05-12 06:38 - 00000000 ____D C:\Tami
2013-08-24 13:59 - 2013-08-21 19:03 - 00000000 ____D C:\Users\Tami Baughman\Desktop\construction
2013-08-24 12:39 - 2013-08-24 12:39 - 00009728 _____ C:\windows\system32\Native.exe
2013-08-24 12:26 - 2013-08-24 12:12 - 00000000 ____D C:\ProgramData\AVG SafeGuard toolbar
2013-08-24 12:25 - 2013-08-24 12:13 - 00000000 ____D C:\Users\TAMIBA~1\AppData\Local\Avg2013
2013-08-24 12:21 - 2013-08-24 12:21 - 00000000 ____D C:\Users\Tami Baughman\AppData\Roaming\AVG2013
2013-08-24 12:20 - 2013-08-24 12:20 - 00003230 _____ C:\windows\System32\Tasks\SidebarExecute
2013-08-24 12:20 - 2013-08-24 12:18 - 00000000 ____D C:\ProgramData\AVG2013
2013-08-24 12:19 - 2013-08-24 12:19 - 00000936 _____ C:\Users\Public\Desktop\AVG 2013.lnk
2013-08-24 12:19 - 2013-08-24 12:19 - 00000000 ____D C:\Users\Tami Baughman\AppData\Roaming\TuneUp Software
2013-08-24 12:18 - 2013-08-24 12:18 - 00000000 ___HD C:\$AVG
2013-08-24 12:17 - 2013-08-24 12:17 - 00000000 ____D C:\Program Files (x86)\AVG
2013-08-24 12:15 - 2013-08-24 12:14 - 00000000 ____D C:\ProgramData\CDB
2013-08-24 12:14 - 2013-08-24 12:14 - 00001912 _____ C:\Users\Public\Desktop\PC Scan & Repair by Reimage.lnk
2013-08-24 12:14 - 2013-08-24 12:14 - 00000000 ____D C:\Users\TAMIBA~1\AppData\Local\AVG SafeGuard toolbar
2013-08-24 12:14 - 2013-08-24 12:14 - 00000000 ____D C:\Program Files\Reimage
2013-08-24 12:13 - 2013-08-24 12:13 - 00000000 ____D C:\Users\TAMIBA~1\AppData\Local\MFAData
2013-08-22 20:50 - 2013-08-22 20:50 - 00000000 ____D C:\Users\Tami Baughman\Desktop\Autoruns
2013-08-22 20:46 - 2013-08-22 20:46 - 00550371 _____ C:\Users\Tami Baughman\Desktop\Autoruns.zip
2013-08-21 21:55 - 2011-07-03 09:03 - 00000000 ____D C:\Users\TAMIBA~1\AppData\Local\CrashDumps
2013-08-21 19:14 - 2013-08-21 19:14 - 00000000 ____D C:\Users\Tami Baughman\Desktop\2013 school forms
2013-08-20 18:58 - 2012-05-11 07:19 - 00692104 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2013-08-20 18:58 - 2012-05-11 07:19 - 00003768 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2013-08-20 18:58 - 2011-05-19 21:37 - 00071048 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-08-19 16:18 - 2013-08-19 16:18 - 00004555 _____ C:\AdwCleaner[S1].txt
2013-08-19 16:18 - 2013-08-19 16:17 - 00004665 _____ C:\AdwCleaner[R1].txt
2013-08-19 15:37 - 2013-08-19 15:34 - 00000000 ____D C:\Users\Tami Baughman\Desktop\RK_Quarantine
2013-08-19 15:36 - 2013-08-19 15:36 - 00003955 _____ C:\Users\Tami Baughman\Desktop\RKreport[0]_S_08192013_153627.txt
2013-08-19 15:32 - 2013-08-19 15:32 - 03814400 _____ C:\Users\Tami Baughman\Desktop\RogueKillerX64.exe
2013-08-19 15:24 - 2013-08-19 15:24 - 00688992 ____R (Swearware) C:\Users\Tami Baughman\Desktop\dds.com
2013-08-19 15:18 - 2013-08-19 15:17 - 00688992 ____R (Swearware) C:\Users\Tami Baughman\Downloads\dds.com
2013-08-19 14:43 - 2009-07-13 22:20 - 00000000 ____D C:\windows\system32\NDF
2013-08-19 11:24 - 2013-08-18 21:13 - 00000488 _____ C:\Users\Tami Baughman\Desktop\defogger_disable.log
2013-08-18 21:14 - 2013-08-18 21:14 - 00891115 _____ C:\Users\Tami Baughman\Desktop\SecurityCheck.exe
2013-08-18 21:13 - 2013-08-18 21:13 - 00050477 _____ C:\Users\Tami Baughman\Desktop\Defogger.exe
2013-08-18 21:13 - 2013-08-18 21:13 - 00000000 _____ C:\Users\Tami Baughman\defogger_reenable
2013-08-18 21:13 - 2011-04-13 15:21 - 00000000 ____D C:\Users\Tami Baughman
2013-08-15 10:31 - 2012-11-01 08:45 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2013-08-13 17:14 - 2011-07-05 10:22 - 00000000 ____D C:\recipes
2013-08-12 10:53 - 2012-05-27 07:24 - 00000000 ____D C:\Users\Tami Baughman\Desktop\receipts
2013-08-11 13:13 - 2011-04-15 16:37 - 00000000 ____D C:\bill receipts
2013-08-08 12:53 - 2013-08-08 12:53 - 15344555 _____ C:\Users\Tami Baughman\Downloads\Attachments_201388.zip
2013-08-05 16:14 - 2011-05-18 05:34 - 78161360 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2013-07-31 17:48 - 2011-11-25 21:38 - 00000000 ____D C:\Eric

Files to move or delete:
====================
ZeroAccess:
C:\Users\TAMIBA~1\AppData\Local\Google\Desktop\Install\{ac074fcf-d3e7-934a-caa6-9f94cb918cf7}
ZeroAccess:
C:\Program Files (x86)\Google\Desktop\Install\{ac074fcf-d3e7-934a-caa6-9f94cb918cf7}
C:\Users\Tami Baughman\AppData\Roaming\skype.ini

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

LastRegBack: 2013-08-24 19:28

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-08-2013
Ran by Tami Baughman at 2013-08-28 16:46:18
Running from C:\Users\Tami Baughman\Desktop
Boot Mode: Normal
==========================================================

==================== Installed Programs =======================

  
 2013 (Version: 2013.0.3392)
Adobe AIR (x32 Version: 3.4.0.2710)
Adobe Download Assistant (x32 Version: 1.2.3)
Adobe Flash Player 11 ActiveX (x32 Version: 11.8.800.94)
Adobe Flash Player 11 Plugin (x32 Version: 11.8.800.94)
Adobe Reader X (10.1.7) (x32 Version: 10.1.7)
Adobe Shockwave Player 11.6 (x32 Version: 11.6.6.636)
Amazon Add to Wish List IE Extension 1.2 (x32 Version: 1.2)
Amazon Links (x32 Version: 2.02)
Amazon MP3 Downloader 1.0.17 (x32 Version: 1.0.17)
ATI Catalyst Install Manager (Version: 3.0.765.0)
Atlantic Quest (x32 Version: 2.2.0.97)
ATT-PRT22 (x32)
AVG 2013 (Version: 13.0.3211)
AVG 2013 (Version: 13.0.3392)
AVG SafeGuard toolbar (x32 Version: 15.5.0.2)
Bejeweled 2 Deluxe (x32 Version: 2.2.0.95)
Cake Mania - Lights, Camera, Action!™ (x32 Version: 2.2.0.95)
Canon MP490 series MP Drivers
Catalyst Control Center - Branding (x32 Version: 1.00.0000)
Catalyst Control Center Core Implementation (x32 Version: 2010.0315.1050.17562)
Catalyst Control Center Graphics Full Existing (x32 Version: 2010.0315.1050.17562)
Catalyst Control Center Graphics Full New (x32 Version: 2010.0315.1050.17562)
Catalyst Control Center Graphics Light (x32 Version: 2010.0315.1050.17562)
Catalyst Control Center Graphics Previews Common (x32 Version: 2010.0315.1050.17562)
Catalyst Control Center Graphics Previews Vista (x32 Version: 2010.0315.1050.17562)
Catalyst Control Center Localization All (x32 Version: 2010.0315.1050.17562)
CCC Help Chinese Standard (x32 Version: 2010.0315.1049.17562)
CCC Help Chinese Traditional (x32 Version: 2010.0315.1049.17562)
CCC Help Czech (x32 Version: 2010.0315.1049.17562)
CCC Help Danish (x32 Version: 2010.0315.1049.17562)
CCC Help Dutch (x32 Version: 2010.0315.1049.17562)
CCC Help English (x32 Version: 2010.0315.1049.17562)
CCC Help Finnish (x32 Version: 2010.0315.1049.17562)
CCC Help French (x32 Version: 2010.0315.1049.17562)
CCC Help German (x32 Version: 2010.0315.1049.17562)
CCC Help Greek (x32 Version: 2010.0315.1049.17562)
CCC Help Hungarian (x32 Version: 2010.0315.1049.17562)
CCC Help Italian (x32 Version: 2010.0315.1049.17562)
CCC Help Japanese (x32 Version: 2010.0315.1049.17562)
CCC Help Korean (x32 Version: 2010.0315.1049.17562)
CCC Help Norwegian (x32 Version: 2010.0315.1049.17562)
CCC Help Polish (x32 Version: 2010.0315.1049.17562)
CCC Help Portuguese (x32 Version: 2010.0315.1049.17562)
CCC Help Russian (x32 Version: 2010.0315.1049.17562)
CCC Help Spanish (x32 Version: 2010.0315.1049.17562)
CCC Help Swedish (x32 Version: 2010.0315.1049.17562)
CCC Help Thai (x32 Version: 2010.0315.1049.17562)
CCC Help Turkish (x32 Version: 2010.0315.1049.17562)
ccc-core-static (x32 Version: 2010.0315.1050.17562)
ccc-utility64 (Version: 2010.0315.1050.17562)
CCleaner (Version: 3.21)
Chuzzle Deluxe (x32 Version: 2.2.0.95)
Cisco Connect (x32 Version: 1.2.10260.0)
Cisco WebEx Meetings (x32)
Cricut DesignStudio (x32)
D3DX10 (x32 Version: 15.4.2368.0902)
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (x32)
Dropbox (HKCU Version: 2.0.22)
FATE - The Traitor Soul (x32 Version: 2.2.0.95)
Fisher-Price iXL - Disney Princess (x32 Version: 2.0.0.13)
Fisher-Price iXL - Kai-lan (x32 Version: 2.0.0.19)
Fisher-Price iXL - SpongeBob (x32 Version: 2.0.0.5)
Fisher-Price iXL Computer Software (x32 Version: 2.0.2.8)
GamesBar from ATT (x32 Version: 3.2.0.3)
Google Chrome (x32 Version: 29.0.1547.57)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0)
Google Toolbar for Internet Explorer (x32 Version: 7.5.4413.1752)
Google Update Helper (x32 Version: 1.3.21.153)
Governor of Poker 2 Premium Edition (x32 Version: 2.2.0.95)
Java™ 6 Update 17 (x32 Version: 6.0.170)
Jewel Quest - Heritage (x32 Version: 2.2.0.95)
Junk Mail filter update (x32 Version: 15.4.3502.0922)
Label@Once 1.0 (x32 Version: 1.0)
Macrium Reflect Free Edition (Version: 5.0.5154)
Malwarebytes Anti-Malware version 1.70.0.1100 (x32 Version: 1.70.0.1100)
Mesh Runtime (x32 Version: 15.4.5722.2)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Mouse and Keyboard Center (Version: 1.1.500.0)
Microsoft Office 2010 Primary Interop Assemblies (x32 Version: 14.0.4763.1024)
Microsoft Office 2010 Service Pack 1 (SP1) (x32)
Microsoft Office Access MUI (English) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Access Setup Metadata MUI (English) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Excel MUI (English) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Home and Student 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.6029.1000)
Microsoft Office OneNote MUI (English) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Outlook MUI (English) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office PowerPoint MUI (English) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Proof (English) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Proof (French) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Proof (Spanish) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Proofing (English) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Publisher MUI (English) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Shared 64-bit MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared MUI (English) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Shared Setup Metadata MUI (English) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Single Image 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Word MUI (English) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Silverlight (Version: 5.1.20513.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (x32 Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (Version: 9.0.30729.5570)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (x32 Version: 9.0.30729.5570)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Microsoft Works 6-9 Converter (x32 Version: 9.7.0621)
MSVCRT (x32 Version: 15.4.2862.0708)
MSVCRT_amd64 (x32 Version: 15.4.2862.0708)
MSXML 4.0 SP3 Parser (KB2721691) (x32 Version: 4.30.2114.0)
MSXML 4.0 SP3 Parser (KB2758694) (x32 Version: 4.30.2117.0)
MSXML 4.0 SP3 Parser (KB973685) (x32 Version: 4.30.2107.0)
Mystery P.I. - The London Caper (x32 Version: 2.2.0.95)
Mystery P.I. - The New York Fortune (x32 Version: 2.2.0.97)
Picasa 3 (x32 Version: 3.9)
Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.95)
PlayReady PC Runtime amd64 (Version: 1.3.0)
PlayReady PC Runtime x86 (x32 Version: 1.3.0)
Polar Bowler (x32 Version: 2.2.0.95)
QuickTime (x32)
Realtek Ethernet Controller Driver For Windows 7 (x32 Version: 7.13.112.2010)
Realtek HDMI Audio Driver for ATI (x32 Version: 6.0.1.5992)
Realtek High Definition Audio Driver (x32 Version: 6.0.1.6069)
Realtek USB 2.0 Card Reader (x32 Version: 6.1.7600.30111)
Realtek WLAN Driver (x32 Version: 2.00.0013)
Reimage Repair (Version: 1.6.4.2)
Skype Launcher (x32 Version: 2.01)
Slingo Supreme (x32 Version: 2.2.0.95)
Speccy (Version: 1.16)
SUPERAntiSpyware (Version: 5.6.1012)
swMSM (x32 Version: 12.0.0.1)
Synaptics Pointing Device Driver (Version: 15.0.8.1)
Timez Attack Launcher (x32 Version: O)
Toshiba App Place (x32 Version: 1.0.6.3)
TOSHIBA Application Installer (x32 Version: 9.0.1.1)
TOSHIBA Assist (x32 Version: 3.00.11)
Toshiba Book Place (x32 Version: 2.2.6883)
TOSHIBA Bulletin Board (Version: 1.6.07.64)
TOSHIBA Bulletin Board (x32 Version: 1.6.07.64)
TOSHIBA Disc Creator (Version: 2.1.0.2 for x64)
TOSHIBA eco Utility (Version: 1.2.11.64)
TOSHIBA eco Utility (x32 Version: 1.2.11.64)
TOSHIBA Face Recognition (Version: 3.1.3.64)
TOSHIBA Face Recognition (x32 Version: 3.1.3.64)
TOSHIBA Flash Cards Support Utility (x32 Version: 1.63.0.6C)
TOSHIBA Hardware Setup (x32 Version: 1.63.0.22C)
TOSHIBA HDD/SSD Alert (Version: 3.1.64.6)
TOSHIBA HDD/SSD Alert (x32 Version: 3.1.64.6)
Toshiba Laptop Checkup (x32 Version: 2.0.6.22)
TOSHIBA Media Controller (x32 Version: 1.0.80.3.64)
TOSHIBA Media Controller Plug-in (x32 Version: 1.0.8.0)
Toshiba Online Backup (x32 Version: 2.0.0.25)
TOSHIBA PC Health Monitor (Version: 1.6.0.64)
TOSHIBA Quality Application (x32 Version: 1.0.3)
TOSHIBA Recovery Media Creator (Version: 2.1.0.4 for x64)
TOSHIBA ReelTime (Version: 1.6.06.64)
TOSHIBA ReelTime (x32 Version: 1.6.06.64)
TOSHIBA Service Station (x32 Version: 2.2.9)
TOSHIBA Supervisor Password (x32 Version: 1.63.0.9C)
TOSHIBA Value Added Package (Version: 1.3.19.64)
TOSHIBA Value Added Package (x32 Version: 1.3.19.64)
TOSHIBA Web Camera Application (x32 Version: 1.1.1.15)
ToshibaRegistration (x32 Version: 1.0.4)
Unity Web Player (HKCU Version: )
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1)
Update for Microsoft Office 2010 (KB2494150) (x32)
Update for Microsoft Office 2010 (KB2553065) (x32)
Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2553378) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2566458) (x32)
Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2687503) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2687509) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2767886) 32-Bit Edition (x32)
Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition (x32)
Update for Microsoft Outlook 2010 (KB2597090) 32-Bit Edition (x32)
Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition (x32)
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition (x32)
Update for Microsoft PowerPoint 2010 (KB2598240) 32-Bit Edition (x32)
Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition (x32)
Update Installer for WildTangent Games App (x32)
Utility Common Driver (x32 Version: 1.0.52.1C)
Visual Studio 2010 x64 Redistributables (Version: 13.0.0.1)
WildTangent Games (x32 Version: 1.0.2.5)
WildTangent Games App (Toshiba Games) (x32 Version: 4.0.5.14)
Windows Automated Installation Kit (Version: 2.0.0.0)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3502.0922)
Windows Live ID Sign-in Assistant (Version: 7.250.4225.0)
Windows Live Installer (x32 Version: 15.4.3502.0922)
Windows Live Language Selector (Version: 15.4.3502.0922)
Windows Live Mail (x32 Version: 15.4.3502.0922)
Windows Live Mesh (x32 Version: 15.4.3502.0922)
Windows Live Mesh ActiveX Control for Remote Connections (x32 Version: 15.4.5722.2)
Windows Live Messenger (x32 Version: 15.4.3502.0922)
Windows Live MIME IFilter (Version: 15.4.3502.0922)
Windows Live Movie Maker (x32 Version: 15.4.3502.0922)
Windows Live Photo Common (x32 Version: 15.4.3502.0922)
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922)
Windows Live PIMT Platform (x32 Version: 15.4.3502.0922)
Windows Live Remote Client (Version: 15.4.5722.2)
Windows Live Remote Client Resources (Version: 15.4.5722.2)
Windows Live Remote Service (Version: 15.4.5722.2)
Windows Live Remote Service Resources (Version: 15.4.5722.2)
Windows Live SOXE (x32 Version: 15.4.3502.0922)
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922)
Windows Live UX Platform (x32 Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (x32 Version: 15.4.3502.0922)
Windows Live Writer (x32 Version: 15.4.3502.0922)
Windows Live Writer Resources (x32 Version: 15.4.3502.0922)

==================== Restore Points  =========================

19-08-2013 01:56:49 Windows Backup
19-08-2013 01:59:16 august182013
20-08-2013 21:32:17 Windows Update
24-08-2013 17:03:47 Windows Update
24-08-2013 17:16:48 Installed AVG 2013
24-08-2013 17:17:47 Installed AVG 2013
24-08-2013 17:39:52 Reimage Repair Restore Point
24-08-2013 23:49:54 Windows Update
25-08-2013 23:48:30 Windows Backup

==================== Hosts content: ==========================

2009-07-13 21:34 - 2009-06-10 16:00 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {00DD97A5-31C7-42B6-A172-6423C894379A} - System32\Tasks\6fb80450 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup1765754704.exe No File
Task: {04AF5EFF-1C6C-4DDC-B195-82B8416A02A2} - System32\Tasks\8e0e7e08 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup563724608.exe No File
Task: {04B46E92-8C14-46FF-9DB2-68F5F8469748} - System32\Tasks\99665ac0 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup2573621952.exe No File
Task: {088482FA-65B8-4E17-9ABF-1DCD48E8D373} - System32\Tasks\Microsoft\Windows\Tcpip\IpAddressConflict1 => C:\Windows\System32\ndfapi.dll [2009-07-13] (Microsoft Corporation)
Task: {09C8831A-9A0F-47A5-A533-F36D0B238FE8} - System32\Tasks\12d5f1c0 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup3368559792.exe No File
Task: {09CE242B-3689-447E-B6D3-0C859A9BB32A} - System32\Tasks\ec5c050 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup903634312.exe No File
Task: {09F06BFE-A3C8-40E3-846A-6E6F4000C238} - System32\Tasks\Microsoft\Windows\Tcpip\IpAddressConflict2 => C:\Windows\System32\ndfapi.dll [2009-07-13] (Microsoft Corporation)
Task: {100A325B-5EA5-4A51-B7A5-37736BDE5476} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Device Center\ipoint.exe [2012-06-26] (Microsoft Corporation)
Task: {11A10E00-8DB7-4842-BCCF-C3AF23F1CDB1} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-08-20] (Adobe Systems Incorporated)
Task: {1351E819-063C-4400-BA68-54BF4AC5A670} - System32\Tasks\7c4d45f0 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup1183177776.exe No File
Task: {1392C598-5E7F-4B84-AF1F-E99DA9035BF2} - System32\Tasks\2807e470 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup3573800704.exe No File
Task: {14582464-7DB6-4373-A767-4E7DDD22FBE2} - System32\Tasks\79532cf8 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup3430246232.exe No File
Task: {15DCDF20-4D96-4A58-AA60-C628B0333A10} - System32\Tasks\466d9ae8 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup4289722152.exe No File
Task: {1EA746E1-55F8-423B-854C-AED72CE8F95D} - System32\Tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector => C:\Windows\System32\dfdts.dll [2009-07-13] (Microsoft Corporation)
Task: {21A51A4D-1E3E-42CE-9044-4B18FFEAE2F4} - System32\Tasks\b74157c0 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup3074512832.exe No File
Task: {24882E60-321B-4CF0-A93D-B3FD4E8835EF} - System32\Tasks\44dcae90 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup2373947368.exe No File
Task: {293CCE36-DDA6-405A-999F-AEBCA9E0DB5F} - System32\Tasks\Microsoft_Hardware_Launch_rundll32_exe => C:\Windows\System32\url.dll [2013-07-16] (Microsoft Corporation)
Task: {2A034E82-136C-4BD3-A466-2608CDC4C21D} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task
Task: {2B5A28EB-967A-4597-9174-26AC792BA4EB} - System32\Tasks\26c88680 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup1362628872.exe No File
Task: {31906830-C310-4BE5-8254-C49EDB2928E5} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-11-01] (Google Inc.)
Task: {389381E8-D3B9-439F-A01E-511F9767AE10} - System32\Tasks\ffb98858 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup3662284160.exe No File
Task: {3BCFE328-B00E-439E-B5C5-7771DFE2D6DF} - System32\Tasks\14b9d6b0 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup4208386040.exe No File
Task: {3FD2D780-6643-4359-B3E7-88A0298303D8} - System32\Tasks\965b4520 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup462512704.exe No File
Task: {40A205BE-79F9-41D2-8CC0-27713DC03C6B} - System32\Tasks\615cda18 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup499633344.exe No File
Task: {43AC923D-FD2A-4E6E-B3CB-2E20314DFDBB} - System32\Tasks\44e8c740 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup2226325952.exe No File
Task: {44845FBD-1E35-4D0D-A667-03003892770B} - System32\Tasks\c9ce0ec4 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup1789992012.exe No File
Task: {4AD46015-BC91-43C9-8285-C27E206071D0} - System32\Tasks\16b97868 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup767478072.exe No File
Task: {4BC7E98D-CC6E-43CF-AD2D-D660BCA459AA} - System32\Tasks\b453e530 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup4078855344.exe No File
Task: {4BC881F6-7660-415C-AB7C-9CDFD14CD9CE} - System32\Tasks\7b704980 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup1611432288.exe No File
Task: {4EE16799-7AEC-4DFC-A06D-EDC514188B50} - System32\Tasks\a759a740 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup2807670592.exe No File
Task: {5C9F502C-F590-4931-B9B6-3D412B3588BC} - System32\Tasks\dffd250 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup3620044624.exe No File
Task: {60223C36-2801-42C6-8FF6-71E79A58E4CD} - System32\Tasks\Microsoft\Windows\WindowsBackup\Windows Backup Monitor => C:\Windows\system32\sdclt.exe [2010-11-20] (Microsoft Corporation)
Task: {63FEB7E5-3CB9-492A-AF82-A509B980C585} - System32\Tasks\96572248 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup1881444808.exe No File
Task: {64EF2958-549F-41EB-835D-D70DF3C62D26} - System32\Tasks\5d4fe818 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup443304064.exe No File
Task: {66751008-1EE9-47FE-8766-681B7D588594} - System32\Tasks\Microsoft_Hardware_Launch_devicecenter_exe => c:\Program Files\Microsoft Device Center\devicecenter.exe [2012-06-26] (Microsoft)
Task: {6B57E48C-2059-4F2B-8889-769FBCB8B7B8} - System32\Tasks\4f4d6b40 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup4042491504.exe No File
Task: {6BF70069-4A09-4A54-A73D-554B340CD1DE} - System32\Tasks\1f0c8bf0 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup4006391552.exe No File
Task: {6DD75935-2A50-4272-A948-45CFCDFA571C} - System32\Tasks\8da4d4b0 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup1466597808.exe No File
Task: {70722405-5E5F-470F-84CC-FA0D4937D5C1} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-07-22] (Piriform Ltd)
Task: {7105444C-90E1-42E5-AAA7-0F2AD8C257B1} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Device Center\itype.exe [2012-06-26] (Microsoft Corporation)
Task: {759BACA7-8EA2-4C29-8B85-41702DEBA74C} - System32\Tasks\75fb5e70 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup2554866784.exe No File
Task: {761BF2E6-DDEE-4D7F-8CF6-CC26BF906148} - System32\Tasks\bb280578 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup1858262124.exe No File
Task: {76DA1861-2CF6-47CD-B9C8-AAAF492AC3FD} - System32\Tasks\SUPERAntiSpyware Scheduled Task f8bc4dae-652e-493b-9b01-2d79dd6efde5 => C:\Program Files\SUPERAntiSpyware\SASTask.exe [2011-05-04] (SUPERAdBlocker.com)
Task: {771A5F3E-FBEA-4972-B3E5-B4CBCA13459A} - System32\Tasks\39295780 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup262626688.exe No File
Task: {7855CA4D-56C1-432F-914B-98BC329FA85C} - System32\Tasks\6a1cf18 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup3496437072.exe No File
Task: {7954027B-5266-4BDB-A5D2-DAA00B6108B3} - System32\Tasks\ea1b90c0 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup3052828416.exe No File
Task: {7D8F6688-88D0-4021-88C7-33FB6FEF8794} - System32\Tasks\1323ae04 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup4205272708.exe No File
Task: {7F5E9875-A501-492E-A56B-3428124CDC52} - System32\Tasks\11c2bdc4 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup2670394424.exe No File
Task: {8134A6EA-5EE3-401A-823F-D278DC8B78A8} - System32\Tasks\bd358d88 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup740608584.exe No File
Task: {930DE07F-5F52-4F3C-B475-B1448CF44B26} - System32\Tasks\da0d1498 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup2367792216.exe No File
Task: {96B728BC-BF5C-4358-A026-76777B6E09DF} - System32\Tasks\3643bf2c => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup1878073024.exe No File
Task: {98EA5DA7-1198-43FA-9565-26310512AF03} - System32\Tasks\36a70938 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup3289335724.exe No File
Task: {994C86AD-A929-4B2C-88A0-4E25A107A029} - System32\Tasks\Microsoft\Windows\SystemRestore\SR => C:\Windows\System32\srrstr.dll [2010-11-20] (Microsoft Corporation)
Task: {9BC78B18-DBC3-4590-9109-5560A2B2F5A0} - System32\Tasks\8fee3b54 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup2414754644.exe No File
Task: {9F71A927-6779-4F19-ADAF-43DABE9D14E6} - System32\Tasks\de3250a0 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup3031455392.exe No File
Task: {A1F82B4F-EF49-4520-852E-4B5DB2BD78BC} - System32\Tasks\744c99d0 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup3398305536.exe No File
Task: {A2C7A81B-07D7-4F0D-8B5E-195CAF036E48} - System32\Tasks\1a28e50 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup3626013776.exe No File
Task: {A7C73732-9F11-4281-8D19-764D4EC9D94D} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => C:\Windows\System32\aepdu.dll [2010-11-20] (Microsoft Corporation)
Task: {ABD42E6F-355A-4BFC-820A-26938F04100A} - System32\Tasks\2c8ff560 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup639055968.exe No File
Task: {AE665FA6-20C1-4FF8-A615-95157333DD70} - System32\Tasks\4083a3f0 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup2289123072.exe No File
Task: {AFD5B731-B8EF-4C8D-8409-CB82B1E96DC3} - System32\Tasks\bc05b8a0 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup2244699552.exe No File
Task: {B2551E7E-7BB6-458E-B83D-BA654D93D0D4} - System32\Tasks\d05535e0 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup1517558840.exe No File
Task: {B3B1F7AD-016B-4391-B0C2-B87EAC3CDCBE} - System32\Tasks\db5a1af0 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup2983726976.exe No File
Task: {B4DFB9D0-6009-48E9-AA13-A30CA39E64B4} - System32\Tasks\9a9a7100 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup2085809832.exe No File
Task: {B4E9B47F-CE2E-4B26-80D8-44503DC23E4A} - System32\Tasks\711d8180 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup2849133688.exe No File
Task: {B6E4A954-399A-46AA-8E53-98FCB32D21B7} - System32\Tasks\a8e7fe00 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup2137392128.exe No File
Task: {B8401AEA-F6F2-4AC5-AF84-5481C99BF875} - System32\Tasks\135fd560 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup3979166944.exe No File
Task: {BA6F6EAC-4B94-475B-918F-B1F40C3855CD} - System32\Tasks\426bb040 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup204561728.exe No File
Task: {C001F69E-6E33-422C-A0E7-32744A9EF488} - System32\Tasks\737e1de0 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup1231416392.exe No File
Task: {C0314D52-68BD-4B0A-9EB1-B80F02E1BB1D} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2009-07-13] (Microsoft Corporation)
Task: {C5607E50-C4A7-41C2-9C27-A842682E5690} - System32\Tasks\WPD\SqmUpload_S-1-5-21-1772882299-3459105310-3479446728-1000 => C:\Windows\System32\portabledeviceapi.dll [2010-11-20] (Microsoft Corporation)
Task: {CB8C88A1-E94A-4E73-9681-8A6D7C98412E} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => C:\Windows\System32\sdengin2.dll [2010-11-20] (Microsoft Corporation)
Task: {CC637510-61BD-41E9-986A-213AB648791C} - System32\Tasks\3380b150 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup2768565144.exe No File
Task: {D5BD6F2C-053B-4C0A-922D-196246C4E2A2} - System32\Tasks\9356f780 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup2254798208.exe No File
Task: {D7B6E81D-3CF4-432C-84D2-24213F4316E6} - System32\Tasks\Microsoft\Windows\Autochk\Proxy => C:\Windows\System32\acproxy.dll [2009-07-13] (Microsoft Corporation)
Task: {E09B154C-044E-46A6-9CBC-69BDDCEFD325} - System32\Tasks\3ace06d0 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup290192224.exe No File
Task: {E22A8667-F75B-4BA9-BA46-067ED4429DE8} - System32\Tasks\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange => C:\Windows\System32\bfe.dll [2010-11-20] (Microsoft Corporation)
Task: {E68619E4-1D2D-41D7-A6F0-ABA78F19429C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-11-01] (Google Inc.)
Task: {E84F99AB-3778-4B6C-9381-72E5511DD992} - System32\Tasks\4e59b8a4 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup673654820.exe No File
Task: {E8D2E495-810F-48F1-AADE-CC2EB3C8CFEC} - System32\Tasks\85fd4d00 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup742094352.exe No File
Task: {EBCA0ACC-07D7-4CC8-BBF1-4D6FD05E9712} - System32\Tasks\SUPERAntiSpyware Scheduled Task 8227b8bb-fbab-464c-9ab2-a4547405d6f2 => C:\Program Files\SUPERAntiSpyware\SASTask.exe [2011-05-04] (SUPERAdBlocker.com)
Task: {EC2229AA-BCD6-4C7D-ACB4-CFB511C2259C} - System32\Tasks\78da3b9c => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup1386720028.exe No File
Task: {ED08C32F-0BDB-4930-8D11-0DD9E484C08A} - System32\Tasks\af0cf528 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup2828285992.exe No File
Task: {F54DD46F-A3A5-4B22-9A9C-71984E9D93E6} - System32\Tasks\a71d06d8 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup2116575592.exe No File
Task: {FD60E098-FCD7-40BE-9312-C5FE330E5366} - System32\Tasks\f7204f60 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup3505241824.exe No File
Task: {FEB5C438-ECAD-47F9-9321-F5CB8C5FA2B8} - System32\Tasks\71eca988 => C:\Users\TAMIBA~1\AppData\Local\Temp\\setup380435392.exe No File
Task: {FF902888-2D1B-4C47-8379-8A558322137B} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe [2010-11-20] (Microsoft Corporation)
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\SUPERAntiSpyware Scheduled Task 8227b8bb-fbab-464c-9ab2-a4547405d6f2.job => C:\Program Files\SUPERAntiSpyware\SASTask.exe
Task: C:\windows\Tasks\SUPERAntiSpyware Scheduled Task f8bc4dae-652e-493b-9b01-2d79dd6efde5.job => C:\Program Files\SUPERAntiSpyware\SASTask.exe

==================== Alternate Data Streams (whitelisted) ==========

AlternateDataStreams: C:\ProgramData\TEMP:2B27AEE1
AlternateDataStreams: C:\ProgramData\TEMP:2D09AB80
AlternateDataStreams: C:\ProgramData\TEMP:56EE2CAF
AlternateDataStreams: C:\ProgramData\TEMP:7B70C2D6
AlternateDataStreams: C:\Users\Tami Baughman\Desktop\#abc-student_home.url:favicon
AlternateDataStreams: C:\Users\Tami Baughman\Desktop\Cool Math.url:favicon
AlternateDataStreams: C:\Users\Tami Baughman\Desktop\disney jr.url:favicon
AlternateDataStreams: C:\Users\Tami Baughman\Desktop\Nick Jr.url:favicon
AlternateDataStreams: C:\Users\Tami Baughman\Desktop\starfall.url:favicon

==================== Faulty Device Manager Devices =============

==================== Event log errors: =========================

Application errors:
==================
Error: (08/27/2013 05:41:59 AM) (Source: TestWorker) (User: )
Description: TestWorkerFailed to send data to service: Norton PC Checkup Application Launcher

Error: (08/24/2013 10:30:31 PM) (Source: .NET Runtime Optimization Service) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - Failed to compile: System.Web.Extensions, Version=3.5.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35 . Error code = 0x80070020

Error: (08/24/2013 10:27:39 PM) (Source: .NET Runtime Optimization Service) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - Failed to compile: System.Web, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a . Error code = 0x80070020

Error: (08/24/2013 10:21:13 PM) (Source: .NET Runtime Optimization Service) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - Failed to compile: System.ServiceModel, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil . Error code = 0x80070020

Error: (08/24/2013 10:20:17 PM) (Source: .NET Runtime Optimization Service) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - Failed to compile: System.Web, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a . Error code = 0x80070020

Error: (08/24/2013 10:19:14 PM) (Source: .NET Runtime Optimization Service) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - Failed to compile: System.Runtime.Remoting, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 . Error code = 0x80070020

Error: (08/24/2013 10:18:23 PM) (Source: .NET Runtime Optimization Service) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - Failed to compile: System.Web, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a . Error code = 0x80070020

Error: (08/24/2013 10:15:49 PM) (Source: .NET Runtime Optimization Service) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - Failed to compile: System.Runtime.Remoting, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 . Error code = 0x80070020

Error: (08/24/2013 10:11:57 PM) (Source: .NET Runtime Optimization Service) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - Failed to compile: System.Web, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a . Error code = 0x80070020

Error: (08/24/2013 10:07:27 PM) (Source: .NET Runtime Optimization Service) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - Failed to compile: System.Web, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a . Error code = 0x80070020

System errors:
=============
Error: (08/24/2013 08:14:24 PM) (Source: Service Control Manager) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
luafv

Error: (08/24/2013 08:14:08 PM) (Source: Service Control Manager) (User: )
Description: The ScRegSetValueExW call failed for FailureActions with the following error:
%%5

Error: (08/24/2013 08:11:16 PM) (Source: Service Control Manager) (User: )
Description: The ScRegSetValueExW call failed for FailureActions with the following error:
%%5

Error: (08/24/2013 06:56:02 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80070490: Update for Windows 7 for x64-based Systems (KB2726535).

Error: (08/24/2013 06:55:13 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80070490: Security Update for Windows 7 for x64-based Systems (KB2839894).

Error: (08/24/2013 06:51:39 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80070490: Update for Windows 7 for x64-based Systems (KB2647753).

Error: (08/24/2013 04:46:01 PM) (Source: Service Control Manager) (User: )
Description: The TPCH Service service failed to start due to the following error:
%%1053

Error: (08/24/2013 04:46:01 PM) (Source: Service Control Manager) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the TPCH Service service to connect.

Error: (08/24/2013 04:46:01 PM) (Source: DCOM) (User: )
Description: 1053TPCHSrv{45CC1698-D1CF-417B-BC32-80EB79E05EF1}

Error: (08/24/2013 04:40:34 PM) (Source: Service Control Manager) (User: )
Description: The Windows Update service hung on starting.

Microsoft Office Sessions:
=========================
Error: (08/27/2013 05:41:59 AM) (Source: TestWorker)(User: )
Description: TestWorkerFailed to send data to service: Norton PC Checkup Application Launcher

Error: (08/24/2013 10:30:31 PM) (Source: .NET Runtime Optimization Service)(User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - Failed to compile: System.Web.Extensions, Version=3.5.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35 . Error code = 0x80070020
System.Web.Extensions, Version=3.5.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35

Error: (08/24/2013 10:27:39 PM) (Source: .NET Runtime Optimization Service)(User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - Failed to compile: System.Web, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a . Error code = 0x80070020
System.Web, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a

Error: (08/24/2013 10:21:13 PM) (Source: .NET Runtime Optimization Service)(User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - Failed to compile: System.ServiceModel, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil . Error code = 0x80070020
System.ServiceModel, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil

Error: (08/24/2013 10:20:17 PM) (Source: .NET Runtime Optimization Service)(User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - Failed to compile: System.Web, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a . Error code = 0x80070020
System.Web, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a

Error: (08/24/2013 10:19:14 PM) (Source: .NET Runtime Optimization Service)(User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - Failed to compile: System.Runtime.Remoting, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 . Error code = 0x80070020
System.Runtime.Remoting, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089

Error: (08/24/2013 10:18:23 PM) (Source: .NET Runtime Optimization Service)(User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - Failed to compile: System.Web, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a . Error code = 0x80070020
System.Web, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a

Error: (08/24/2013 10:15:49 PM) (Source: .NET Runtime Optimization Service)(User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - Failed to compile: System.Runtime.Remoting, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 . Error code = 0x80070020
System.Runtime.Remoting, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089

Error: (08/24/2013 10:11:57 PM) (Source: .NET Runtime Optimization Service)(User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - Failed to compile: System.Web, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a . Error code = 0x80070020
System.Web, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a

Error: (08/24/2013 10:07:27 PM) (Source: .NET Runtime Optimization Service)(User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - Failed to compile: System.Web, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a . Error code = 0x80070020
System.Web, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a

==================== Memory info ===========================

Percentage of memory in use: 68%
Total physical RAM: 3835.68 MB
Available physical RAM: 1213.82 MB
Total Pagefile: 7669.55 MB
Available Pagefile: 4864.68 MB
Total Virtual: 8192 MB
Available Virtual: 8191.81 MB

==================== Drives ================================

Drive c: (TI106050W0B) (Fixed) (Total:452.66 GB) (Free:372.77 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive e: (My Book) (Fixed) (Total:465.64 GB) (Free:433.02 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 932 GB) (Disk ID: 0014DB7F)
Partition 1: (Active) - (Size=1 GB) - (Type=27)
Partition 2: (Not Active) - (Size=453 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=477 GB) - (Type=17)

========================================================
Disk: 1 (Size: 466 GB) (Disk ID: 8D399BC0)
Partition 1: (Not Active) - (Size=466 GB) - (Type=0C)

==================== End Of Log ============================

 

 



#8 dev00790

dev00790

    Bleeping Chocoholic


  • Members
  • 5,037 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:06:46 AM

Posted 30 August 2013 - 04:39 AM

Hi

Please do the following next:

-------------

IMPORTANT NOTE: One or more of the identified infections is a backdoor Trojan.

Backdoor Trojans, Botnets, and IRCBots are very dangerous because they compromise system integrity by making changes that allow it to be used by the attacker for malicious purposes.
They can disable your anti-virus and security tools to prevent detection and removal. Remote attackers use backdoors as a means of accessing and taking control of a computer that bypasses security mechanisms.
This type of exploit allows them to steal sensitive information like passwords, personal and financial data which is then sent back to the hacker.
Read Danger: Remote Access Trojans.

You should disconnect the computer from the Internet and from any networked computers until it is cleaned. If your computer was used for online banking, paying bills, has credit card information or other sensitive data on it, all passwords should be changed immediately to include those used for taxes, email, eBay, paypal and any other online activities.
You should consider them to be compromised and change passwords from a clean computer, not the infected one. If not, an attacker may get the new passwords and transaction information.
Banking and credit card institutions should be notified immediately of the possible security breach. Failure to notify your financial institution and local law enforcement can result in refusal to reimburse funds lost due to fraud or similar criminal activity.
If using a router, you need to reset it with a strong logon/password before connecting again.

Although the infection has been identified and may be removed, your machine has likely been compromised and there is no way to be sure the computer can ever be trusted again. It is dangerous and incorrect to assume the computer is secure even if the malware appears to have been removed.
In some instances an infection may have caused so much damage to your system that it cannot be successfully cleaned or repaired. The malware may leave so many remnants behind that security tools cannot find them.
Many experts in the security community believe that once infected with this type of malware, the best course of action is to wipe the drive clean, reformat and reinstall the OS. Please read:


Quote

Whenever a system has been compromised by a backdoor payload, it is impossible to know if or how much the backdoor has been used to affect your system...There are only a few ways to return a compromised system to a confident security configuration. These include:
• Reimaging the system
• Restoring the entire system using a full system backup from before the backdoor infection
• Reformatting and reinstalling the system

Backdoors and What They Mean to You

This is what Jesper M. Johansson, Security Program Manager at Microsoft TechNet has to say:


Quote

The only way to clean a compromised system is to flatten and rebuild. That’s right. If you have a system that has been completely compromised, the only thing you can do is to flatten the system (reformat the system disk) and rebuild it from scratch (reinstall Windows and your applications).

Help: I Got Hacked. Now What Do I Do?.


We will do our best to clean the computer of any infections seen on the log. However, because of the nature of this Trojan, I cannot offer a total
guarantee that there are no remnants left in the system, or that the computer will be trustworthy.

Many security experts believe that once infected with this type of Trojan, the best course of action is to reformat and reinstall the Operating System.
Making this decision is based on what the computer is used for, and what information can be accessed from it.

Knowing the above, do you wish to proceed with cleaning the malware from the computer?


Regards, dev00790

---------------------------------------

Marge: "Homer, the plant called. They said if you don't show up tomorrow don't bother showing up on Monday." Homer: "Woo-hoo! Four-day weekend!"I do not reply to Private Messages (PMs) asking for assistance - please use the forums instead. If I have been helping you, and I have not replied to your latest post in 48 hours please send me a PM. My Blog


#9 dev00790

dev00790

    Bleeping Chocoholic


  • Members
  • 5,037 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:06:46 AM

Posted 02 September 2013 - 03:22 AM

Hi Are you still with us? The topic will be closed in 2 days unless we receive a response from you.


Regards, dev00790

---------------------------------------

Marge: "Homer, the plant called. They said if you don't show up tomorrow don't bother showing up on Monday." Homer: "Woo-hoo! Four-day weekend!"I do not reply to Private Messages (PMs) asking for assistance - please use the forums instead. If I have been helping you, and I have not replied to your latest post in 48 hours please send me a PM. My Blog


#10 TamiTX

TamiTX
  • Topic Starter

  • Members
  • 27 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:01:46 AM

Posted 02 September 2013 - 07:47 AM

I'm sorry. I replied before. Apparently it didn't go through. Before I began talking to you I used the re-image program to try and repair my laptop. I have backed everything up to an external hard drive but it was after the virus was there. What exactly do I need to do?



#11 dev00790

dev00790

    Bleeping Chocoholic


  • Members
  • 5,037 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:06:46 AM

Posted 02 September 2013 - 12:47 PM

Knowing the above, do you wish to proceed with cleaning the malware from the computer?


Regards, dev00790

---------------------------------------

Marge: "Homer, the plant called. They said if you don't show up tomorrow don't bother showing up on Monday." Homer: "Woo-hoo! Four-day weekend!"I do not reply to Private Messages (PMs) asking for assistance - please use the forums instead. If I have been helping you, and I have not replied to your latest post in 48 hours please send me a PM. My Blog


#12 TamiTX

TamiTX
  • Topic Starter

  • Members
  • 27 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:01:46 AM

Posted 02 September 2013 - 08:07 PM

Yes, I do. But what do I do? Has my back up been compromised since it was done after the virus?



#13 dev00790

dev00790

    Bleeping Chocoholic


  • Members
  • 5,037 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:06:46 AM

Posted 03 September 2013 - 11:52 AM

Hi

 

We think it would be best to clean the machine, then make another backup of the data. - That way you back up only clean data.

Let us know if you are happy to proceed on this basis?


Regards, dev00790

---------------------------------------

Marge: "Homer, the plant called. They said if you don't show up tomorrow don't bother showing up on Monday." Homer: "Woo-hoo! Four-day weekend!"I do not reply to Private Messages (PMs) asking for assistance - please use the forums instead. If I have been helping you, and I have not replied to your latest post in 48 hours please send me a PM. My Blog


#14 dev00790

dev00790

    Bleeping Chocoholic


  • Members
  • 5,037 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:06:46 AM

Posted 05 September 2013 - 01:39 PM

Hi Are you still with us? The topic will be closed in 3 days unless we receive a response from you.


Regards, dev00790

---------------------------------------

Marge: "Homer, the plant called. They said if you don't show up tomorrow don't bother showing up on Monday." Homer: "Woo-hoo! Four-day weekend!"I do not reply to Private Messages (PMs) asking for assistance - please use the forums instead. If I have been helping you, and I have not replied to your latest post in 48 hours please send me a PM. My Blog


#15 TamiTX

TamiTX
  • Topic Starter

  • Members
  • 27 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:01:46 AM

Posted 06 September 2013 - 07:04 AM

I have responded twice. I'm not sure why it's not going through. Yes, I want to gix the pc




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users