Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Roommate's Computer is Infected with the FBI $300 Fine Ransomware


  • This topic is locked This topic is locked
2 replies to this topic

#1 devin.beech

devin.beech

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:09:29 PM

Posted 29 August 2013 - 12:49 PM

Hey guys,

 

My name is Devin and I've been using this site to help take viruses off of my family members' computers for a couple years. You guys have some extremely helpful stuff up here.

 

Anyways, my roommate's computer is locked out now due to the ransomware that asks for the user to buy a $300 MoneyPak card. He has a 64-bit operating Windows 7. I came to this site, found a thread on this topic, and started to follow it step by step. I saw that we needed to post the .txt from the first scan with FRST, so here it is.

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-08-2013
Ran by SYSTEM on 29-08-2013 13:34:24
Running from H:\
Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US)
Internet Explorer Version 9
Boot Mode: Recovery
 
The current controlset is ControlSet001
ATTENTION!:=====> If the system is bootable FRST could be run from normal or Safe mode to create a complete log.
 
==================== Registry (Whitelisted) ==================
 
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [41056 2013-05-08] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM-x32\...\Run: [vProt] - C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe [2404016 2013-08-26] ()
HKLM-x32\...\Run: [WD Drive Manager] - C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe [480768 2009-06-26] (WDC)
HKLM-x32\...\Run: [WD Anywhere Backup] - C:\Program Files (x86)\WD\WD Anywhere Backup\MemeoLauncher2.exe [222432 2009-09-23] (Memeo Inc.)
HKLM-x32\...\Run: [Memeo AutoSync] - C:\Program Files (x86)\Memeo\AutoSync\MemeoLauncher2.exe [144608 2009-05-29] (Memeo Inc.)
HKLM-x32\...\Run: [AVG_UI] - C:\Program Files (x86)\AVG\AVG2013\avgui.exe [4411440 2013-06-30] (AVG Technologies CZ, s.r.o.)
HKU\Brandon\...\Run: [Google Update] - C:\Users\Brandon\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-09-19] (Google Inc.)
HKU\Brandon\...\Winlogon: [Shell] explorer.exe,C:\Users\Brandon\AppData\Roaming\cache.dat [98304 2013-07-08] () <==== ATTENTION 
HKU\Default\...\RunOnce: [IsMyWinLockerReboot] - msiexec.exe /qn /x{voidguid} [x]
HKU\Default\...\RunOnce: [ScrSav] - C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe [154144 2010-07-29] ()
HKU\Default User\...\RunOnce: [IsMyWinLockerReboot] - msiexec.exe /qn /x{voidguid} [x]
HKU\Default User\...\RunOnce: [ScrSav] - C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe [154144 2010-07-29] ()
AppInit_DLLs-x32: c:\progra~3\browse~1\261519~1.190\{16cdf~1\browse~1.dll  [2691536 2013-07-26] ()
Startup: C:\Users\Brandon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk ->  (No File)
 
==================== Services (Whitelisted) =================
 
S2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [86224 2012-09-07] (Avira Operations GmbH & Co. KG)
S2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [110032 2012-09-07] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [465360 2012-09-07] (Avira Operations GmbH & Co. KG)
S2 Application Sendori; C:\Program Files (x86)\Sendori\SendoriSvc.exe [119072 2013-07-01] (Sendori, Inc.)
S2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [4939312 2013-07-04] (AVG Technologies CZ, s.r.o.)
S2 avgwd; C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [283136 2013-07-23] (AVG Technologies CZ, s.r.o.)
S2 Browser Manager; C:\ProgramData\Browser Manager\2.6.1519.190\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe [2847696 2013-07-26] ()
S2 CltMngSvc; C:\Program Files (x86)\SearchProtect\bin\CltMngSvc.exe [97056 2013-05-07] (Conduit)
S2 DefaultTabSearch; C:\Program Files (x86)\DefaultTab\DefaultTabSearch.exe [572928 2013-02-10] ()
S2 IBUpdaterService; C:\Windows\system32\dmwu.exe [1447728 2013-05-27] ()
S4 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
S4 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S2 MemeoBackgroundService; C:\Program Files (x86)\WD\WD Anywhere Backup\MemeoBackgroundService.exe [25824 2009-09-23] (Memeo)
S2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [257344 2011-02-15] (NTI Corporation)
S2 Service Sendori; C:\Program Files (x86)\Sendori\Sendori.Service.exe [22304 2013-07-01] (sendori)
S2 sndappv2; C:\Program Files (x86)\Sendori\sndappv2.exe [3623200 2013-07-01] (Sendori)
S2 Updater By SweetPacks; C:\Program Files\Updater By SweetPacks\ExtensionUpdaterService.exe [188760 2013-05-16] ()
S2 vToolbarUpdater15.5.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\ToolbarUpdater.exe [1643184 2013-08-14] (AVG Secure Search)
S2 WDBtnMgrSvc.exe; C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe [119296 2009-06-26] (WDC)
S2 Yontoo Desktop Updater; C:\Program Files (x86)\Yontoo\Y2Desktop.Updater.exe [23552 2013-04-30] (Microsoft)
 
==================== Drivers (Whitelisted) ====================
 
S1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [246072 2013-07-19] (AVG Technologies CZ, s.r.o.)
S0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [71480 2013-07-19] (AVG Technologies CZ, s.r.o.)
S1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [206648 2013-07-19] (AVG Technologies CZ, s.r.o.)
S0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [311608 2013-07-19] (AVG Technologies CZ, s.r.o.)
S0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [116536 2013-06-30] (AVG Technologies CZ, s.r.o.)
S2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [98848 2012-09-07] (Avira GmbH)
S0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [45880 2013-07-09] (AVG Technologies CZ, s.r.o.)
S1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [240952 2013-03-20] (AVG Technologies CZ, s.r.o.)
S1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [45856 2013-08-14] (AVG Technologies)
S1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132832 2012-09-07] (Avira GmbH)
S1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [27760 2012-09-07] (Avira GmbH)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
S3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2013-04-24] (Anchorfree Inc.)
 
==================== NetSvcs (Whitelisted) ===================
 
 
==================== One Month Created Files and Folders ========
 
2013-08-29 09:28 - 2013-08-29 09:28 - 00003434 _____ C:\Windows\System32\Tasks\Browser Manager
2013-08-29 08:38 - 2013-08-29 09:28 - 00000004 _____ C:\Users\Brandon\AppData\Roaming\cache.ini
2013-08-27 18:55 - 2013-08-27 18:56 - 00000000 ____D C:\Users\Brandon\Desktop\Jaws (1975) [1080p]
2013-08-27 18:08 - 2013-08-27 18:08 - 00001074 _____ C:\Users\Public\Desktop\VLC media player.lnk
2013-08-27 18:07 - 2013-08-27 18:07 - 00000000 ____D C:\Program Files (x86)\VideoLAN
2013-08-27 08:23 - 2013-08-27 18:00 - 00022373 _____ C:\Users\Brandon\Documents\effective speaking bullet points.odt
2013-08-27 08:17 - 2013-08-27 08:17 - 00000080 _____ C:\Windows\SysWOW64\usergui.cfg
2013-08-27 08:17 - 2013-08-27 08:17 - 00000060 _____ C:\Windows\SysWOW64\userguistate.cfg
2013-08-27 08:17 - 2013-08-27 08:17 - 00000050 _____ C:\Windows\SysWOW64\outlook.cfg
2013-08-27 08:06 - 2013-08-29 09:23 - 00000999 _____ C:\Windows\setupact.log
2013-08-27 08:06 - 2013-08-27 08:06 - 00000000 _____ C:\Windows\setuperr.log
2013-08-26 05:37 - 2013-08-26 05:37 - 00000000 ___HD C:\Windows\System32\CanonIJ Uninstaller Information
2013-08-26 05:37 - 2013-08-26 05:37 - 00000000 ___HD C:\ProgramData\CanonBJ
2013-08-26 05:36 - 2012-03-14 01:00 - 00385024 _____ (CANON INC.) C:\Windows\System32\CNMLMAA.DLL
2013-08-26 05:35 - 2010-03-18 15:26 - 00348672 _____ (CANON INC.) C:\Windows\System32\CNC280L.dll
2013-08-26 05:35 - 2010-03-18 15:25 - 00307200 _____ (CANON INC.) C:\Windows\SysWOW64\CNC280L.dll
2013-08-26 05:35 - 2010-03-18 13:13 - 01354240 _____ (CANON INC.) C:\Windows\System32\CNC280C.dll
2013-08-26 05:35 - 2010-03-18 13:13 - 00112128 _____ (CANON INC.) C:\Windows\System32\CNC280I.dll
2013-08-26 05:35 - 2010-03-18 13:11 - 00106496 _____ (CANON INC.) C:\Windows\SysWOW64\CNC280U.dll
2013-08-26 05:35 - 2009-11-13 10:38 - 00012800 _____ C:\Windows\SysWOW64\CNC1746D.TBL
2013-08-26 05:35 - 2009-11-13 10:38 - 00012800 _____ C:\Windows\System32\CNC1746D.TBL
2013-08-26 05:35 - 2008-08-25 14:02 - 00017920 _____ (CANON INC.) C:\Windows\System32\CNHMCA6.dll
2013-08-26 05:35 - 2008-08-25 14:02 - 00015872 _____ (CANON INC.) C:\Windows\SysWOW64\CNHMCA.dll
2013-08-26 04:33 - 2013-08-26 17:14 - 00026263 _____ C:\Users\Brandon\Documents\fraannkk.odt
2013-08-26 04:20 - 2013-08-26 04:20 - 00000151 _____ C:\Users\Brandon\Documents\frank stella sites.txt
2013-08-22 19:09 - 2013-08-27 09:30 - 00000516 _____ C:\Users\Brandon\Documents\SOURCES.txt
2013-08-22 10:19 - 2013-08-22 10:19 - 00630784 _____ C:\Users\Brandon\Downloads\chapter1 - introducing public speaking.ppt
2013-08-17 09:01 - 2013-08-17 09:39 - 00000000 ____D C:\Users\Brandon\Desktop\Oblivion (2013) [1080p]
2013-08-16 20:49 - 2013-07-24 19:54 - 17830400 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-08-16 20:49 - 2013-07-24 19:37 - 02312704 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-08-16 20:49 - 2013-07-24 19:35 - 10926080 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-08-16 20:49 - 2013-07-24 19:31 - 01346560 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-08-16 20:49 - 2013-07-24 19:30 - 01392128 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-08-16 20:49 - 2013-07-24 19:29 - 01494528 _____ (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2013-08-16 20:49 - 2013-07-24 19:29 - 00237056 _____ (Microsoft Corporation) C:\Windows\System32\url.dll
2013-08-16 20:49 - 2013-07-24 19:29 - 00086016 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-08-16 20:49 - 2013-07-24 19:28 - 02147840 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-08-16 20:49 - 2013-07-24 19:28 - 00816640 _____ (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-08-16 20:49 - 2013-07-24 19:28 - 00729088 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-08-16 20:49 - 2013-07-24 19:28 - 00599040 _____ (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2013-08-16 20:49 - 2013-07-24 19:28 - 00173056 _____ (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2013-08-16 20:49 - 2013-07-24 19:27 - 02382848 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-08-16 20:49 - 2013-07-24 19:27 - 00096768 _____ (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2013-08-16 20:49 - 2013-07-24 19:26 - 00248320 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-08-16 20:49 - 2013-07-24 18:40 - 12334080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-08-16 20:49 - 2013-07-24 18:32 - 01800704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-08-16 20:49 - 2013-07-24 18:30 - 09738752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-08-16 20:49 - 2013-07-24 18:26 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-08-16 20:49 - 2013-07-24 18:26 - 01104384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-08-16 20:49 - 2013-07-24 18:25 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-08-16 20:49 - 2013-07-24 18:24 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-08-16 20:49 - 2013-07-24 18:24 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-08-16 20:49 - 2013-07-24 18:23 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-08-16 20:49 - 2013-07-24 18:23 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-08-16 20:49 - 2013-07-24 18:23 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-08-16 20:49 - 2013-07-24 18:23 - 00420864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-08-16 20:49 - 2013-07-24 18:23 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-08-16 20:49 - 2013-07-24 18:22 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-08-16 20:49 - 2013-07-24 18:22 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-08-16 20:49 - 2013-07-24 18:22 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-08-15 20:19 - 2013-08-15 20:19 - 00001159 _____ C:\Users\Public\Desktop\Memeo AutoSync.lnk
2013-08-15 20:19 - 2013-08-15 20:19 - 00000000 ____D C:\Program Files (x86)\Memeo
2013-08-15 20:17 - 2013-08-15 20:17 - 00001192 _____ C:\Users\Public\Desktop\WD Anywhere Backup.lnk
2013-08-15 20:17 - 2013-08-15 20:17 - 00000000 ____D C:\Program Files (x86)\WD
2013-08-15 20:16 - 2013-08-15 20:16 - 00003045 _____ C:\Users\Brandon\Desktop\WD WinDLG.lnk
2013-08-15 20:16 - 2013-08-15 20:16 - 00000000 ____D C:\Program Files\Western Digital
2013-08-15 19:38 - 2013-08-15 19:38 - 00000000 ___SD C:\Memeo
2013-08-15 19:37 - 2013-08-15 19:37 - 00000000 ____D C:\ProgramData\MemeoCommon
2013-08-15 19:36 - 2013-08-15 19:36 - 00000000 ____D C:\Users\Brandon\AppData\Roaming\WD
2013-08-15 19:34 - 2013-08-15 19:34 - 00000000 ____D C:\Users\Brandon\AppData\Roaming\Memeo
2013-08-15 19:27 - 2013-08-15 19:27 - 00000000 ____D C:\Program Files (x86)\Western Digital
2013-08-15 19:26 - 2013-08-15 19:26 - 00000000 ____D C:\Program Files (x86)\WDC
2013-08-15 19:25 - 2013-08-15 19:25 - 00020992 _____ C:\Windows\jestertb.dll
2013-08-15 19:24 - 2013-08-15 19:24 - 00001063 _____ C:\Users\Brandon\Desktop\My Book - Shortcut.lnk
2013-08-15 18:06 - 2013-08-18 15:23 - 00027092 _____ C:\Users\Brandon\Documents\Effective Speaking Assignment.odt
2013-08-15 11:36 - 2013-07-25 01:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\System32\WMVDECOD.DLL
2013-08-15 11:36 - 2013-07-25 00:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-08-15 11:36 - 2013-07-08 21:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\System32\rpcrt4.dll
2013-08-15 11:36 - 2013-07-08 21:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-08-15 11:36 - 2013-07-08 21:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-08-15 11:36 - 2013-07-08 20:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2013-08-15 11:35 - 2013-07-18 17:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\System32\tzres.dll
2013-08-15 11:35 - 2013-07-18 17:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-08-15 11:35 - 2013-07-08 22:03 - 05550528 _____ (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2013-08-15 11:35 - 2013-07-08 21:54 - 01732032 _____ (Microsoft Corporation) C:\Windows\System32\ntdll.dll
2013-08-15 11:35 - 2013-07-08 21:53 - 00243712 _____ (Microsoft Corporation) C:\Windows\System32\wow64.dll
2013-08-15 11:35 - 2013-07-08 21:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\System32\wintrust.dll
2013-08-15 11:35 - 2013-07-08 21:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2013-08-15 11:35 - 2013-07-08 21:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2013-08-15 11:35 - 2013-07-08 21:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2013-08-15 11:35 - 2013-07-08 20:53 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-08-15 11:35 - 2013-07-08 20:53 - 00098304 _____ C:\Users\Brandon\AppData\Roaming\cache.dat
2013-08-15 11:35 - 2013-07-08 20:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2013-08-15 11:35 - 2013-07-08 20:52 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-08-15 11:35 - 2013-07-08 20:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-08-15 11:35 - 2013-07-08 20:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-08-15 11:35 - 2013-07-08 20:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-08-15 11:35 - 2013-07-08 18:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-08-15 11:35 - 2013-07-08 18:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-08-15 11:35 - 2013-07-08 18:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-08-15 11:35 - 2013-07-08 18:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-08-15 11:34 - 2013-07-05 22:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-08-15 11:34 - 2013-06-14 20:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\tssecsrv.sys
2013-08-11 08:33 - 2013-08-19 19:21 - 00000000 ____D C:\Users\Brandon\Desktop\Vegas projects
2013-07-31 20:39 - 2013-07-31 20:39 - 00361119 _____ C:\Users\Brandon\AppData\Local\newhb.crx
2013-07-30 21:34 - 2013-08-29 09:24 - 00000000 ___RD C:\Users\Brandon\Dropbox
2013-07-30 21:34 - 2013-07-30 21:34 - 00001050 _____ C:\Users\Brandon\Desktop\Dropbox.lnk
2013-07-30 21:33 - 2013-08-29 09:24 - 00000000 ____D C:\Users\Brandon\AppData\Roaming\Dropbox
 
==================== One Month Modified Files and Folders =======
 
2013-08-29 09:28 - 2013-08-29 09:28 - 00003434 _____ C:\Windows\System32\Tasks\Browser Manager
2013-08-29 09:28 - 2013-08-29 08:38 - 00000004 _____ C:\Users\Brandon\AppData\Roaming\cache.ini
2013-08-29 09:28 - 2012-11-08 15:29 - 01226987 _____ C:\Windows\WindowsUpdate.log
2013-08-29 09:28 - 2009-07-13 20:45 - 00016976 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-29 09:28 - 2009-07-13 20:45 - 00016976 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-29 09:26 - 2012-09-24 18:39 - 00000000 ____D C:\ProgramData\Sendori
2013-08-29 09:24 - 2013-07-30 21:34 - 00000000 ___RD C:\Users\Brandon\Dropbox
2013-08-29 09:24 - 2013-07-30 21:33 - 00000000 ____D C:\Users\Brandon\AppData\Roaming\Dropbox
2013-08-29 09:24 - 2013-05-02 16:59 - 00000000 ____D C:\Users\Brandon\AppData\Roaming\Yontoo
2013-08-29 09:23 - 2013-08-27 08:06 - 00000999 _____ C:\Windows\setupact.log
2013-08-29 09:23 - 2013-06-26 13:02 - 00001910 _____ C:\Windows\Tasks\Plus-HD-2.2-chromeinstaller.job
2013-08-29 09:23 - 2013-06-26 13:02 - 00001834 _____ C:\Windows\Tasks\Plus-HD-2.2-firefoxinstaller.job
2013-08-29 09:23 - 2013-06-26 13:02 - 00001202 _____ C:\Windows\Tasks\Plus-HD-2.2-codedownloader.job
2013-08-29 09:23 - 2013-06-26 13:02 - 00001198 _____ C:\Windows\Tasks\Plus-HD-2.2-updater.job
2013-08-29 09:23 - 2013-06-26 13:02 - 00001102 _____ C:\Windows\Tasks\Plus-HD-2.2-enabler.job
2013-08-29 09:23 - 2012-09-19 11:17 - 00000896 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-08-29 09:23 - 2009-07-13 21:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-08-29 08:57 - 2012-10-01 18:18 - 00000916 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3076334653-4188182924-1428757934-1000UA.job
2013-08-29 08:47 - 2013-02-22 19:06 - 00000000 ____D C:\ProgramData\MFAData
2013-08-29 08:47 - 2009-07-13 21:13 - 00727120 _____ C:\Windows\System32\PerfStringBackup.INI
2013-08-29 08:43 - 2013-06-22 22:04 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-08-29 08:39 - 2013-05-02 18:39 - 00000294 _____ C:\Windows\Tasks\DSite.job
2013-08-29 08:35 - 2012-09-19 11:17 - 00000900 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-08-29 07:56 - 2012-09-19 11:17 - 00000000 ____D C:\Program Files (x86)\Google
2013-08-28 21:15 - 2012-09-19 17:07 - 00000000 ____D C:\Users\Brandon\AppData\Roaming\Spotify
2013-08-28 21:00 - 2012-09-19 17:07 - 00000000 ____D C:\Users\Brandon\AppData\Local\Spotify
2013-08-28 20:55 - 2012-09-20 17:15 - 00000000 ____D C:\Users\Brandon\AppData\Roaming\vlc
2013-08-28 17:22 - 2013-07-22 15:46 - 00002018 _____ C:\Users\Public\Desktop\Adobe Reader 9.lnk
2013-08-27 20:49 - 2013-06-15 20:39 - 00000005 _____ C:\Users\Brandon\AppData\Roaming\WBPU-TTL.DAT
2013-08-27 18:56 - 2013-08-27 18:55 - 00000000 ____D C:\Users\Brandon\Desktop\Jaws (1975) [1080p]
2013-08-27 18:08 - 2013-08-27 18:08 - 00001074 _____ C:\Users\Public\Desktop\VLC media player.lnk
2013-08-27 18:07 - 2013-08-27 18:07 - 00000000 ____D C:\Program Files (x86)\VideoLAN
2013-08-27 18:00 - 2013-08-27 08:23 - 00022373 _____ C:\Users\Brandon\Documents\effective speaking bullet points.odt
2013-08-27 17:59 - 2012-10-01 18:18 - 00000864 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3076334653-4188182924-1428757934-1000Core.job
2013-08-27 09:30 - 2013-08-22 19:09 - 00000516 _____ C:\Users\Brandon\Documents\SOURCES.txt
2013-08-27 08:17 - 2013-08-27 08:17 - 00000080 _____ C:\Windows\SysWOW64\usergui.cfg
2013-08-27 08:17 - 2013-08-27 08:17 - 00000060 _____ C:\Windows\SysWOW64\userguistate.cfg
2013-08-27 08:17 - 2013-08-27 08:17 - 00000050 _____ C:\Windows\SysWOW64\outlook.cfg
2013-08-27 08:17 - 2013-03-21 14:55 - 00000718 _____ C:\Windows\SysWOW64\userawacs.cfg
2013-08-27 08:06 - 2013-08-27 08:06 - 00000000 _____ C:\Windows\setuperr.log
2013-08-26 23:36 - 2013-05-02 16:56 - 00000000 ____D C:\Users\Brandon\AppData\Roaming\uTorrent
2013-08-26 17:15 - 2013-05-02 14:15 - 00000000 ____D C:\Windows\SysWOW64\cache
2013-08-26 17:15 - 2013-05-02 14:15 - 00000000 ____D C:\Program Files (x86)\AVG SafeGuard toolbar
2013-08-26 17:14 - 2013-08-26 04:33 - 00026263 _____ C:\Users\Brandon\Documents\fraannkk.odt
2013-08-26 05:37 - 2013-08-26 05:37 - 00000000 ___HD C:\Windows\System32\CanonIJ Uninstaller Information
2013-08-26 05:37 - 2013-08-26 05:37 - 00000000 ___HD C:\ProgramData\CanonBJ
2013-08-26 05:36 - 2009-07-13 19:20 - 00000000 __RSD C:\Windows\Media
2013-08-26 04:20 - 2013-08-26 04:20 - 00000151 _____ C:\Users\Brandon\Documents\frank stella sites.txt
2013-08-23 14:01 - 2012-09-19 13:31 - 00000000 ____D C:\Users\Brandon\AppData\Roaming\Skype
2013-08-22 10:19 - 2013-08-22 10:19 - 00630784 _____ C:\Users\Brandon\Downloads\chapter1 - introducing public speaking.ppt
2013-08-19 19:21 - 2013-08-11 08:33 - 00000000 ____D C:\Users\Brandon\Desktop\Vegas projects
2013-08-18 15:23 - 2013-08-15 18:06 - 00027092 _____ C:\Users\Brandon\Documents\Effective Speaking Assignment.odt
2013-08-17 11:03 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\rescache
2013-08-17 09:39 - 2013-08-17 09:01 - 00000000 ____D C:\Users\Brandon\Desktop\Oblivion (2013) [1080p]
2013-08-17 04:44 - 2009-07-13 20:45 - 00309224 _____ C:\Windows\System32\FNTCACHE.DAT
2013-08-16 20:51 - 2013-07-11 23:00 - 00000000 ____D C:\Windows\System32\MRT
2013-08-16 20:51 - 2012-09-18 21:22 - 78161360 _____ (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-08-15 20:19 - 2013-08-15 20:19 - 00001159 _____ C:\Users\Public\Desktop\Memeo AutoSync.lnk
2013-08-15 20:19 - 2013-08-15 20:19 - 00000000 ____D C:\Program Files (x86)\Memeo
2013-08-15 20:17 - 2013-08-15 20:17 - 00001192 _____ C:\Users\Public\Desktop\WD Anywhere Backup.lnk
2013-08-15 20:17 - 2013-08-15 20:17 - 00000000 ____D C:\Program Files (x86)\WD
2013-08-15 20:16 - 2013-08-15 20:16 - 00003045 _____ C:\Users\Brandon\Desktop\WD WinDLG.lnk
2013-08-15 20:16 - 2013-08-15 20:16 - 00000000 ____D C:\Program Files\Western Digital
2013-08-15 19:38 - 2013-08-15 19:38 - 00000000 ___SD C:\Memeo
2013-08-15 19:37 - 2013-08-15 19:37 - 00000000 ____D C:\ProgramData\MemeoCommon
2013-08-15 19:36 - 2013-08-15 19:36 - 00000000 ____D C:\Users\Brandon\AppData\Roaming\WD
2013-08-15 19:34 - 2013-08-15 19:34 - 00000000 ____D C:\Users\Brandon\AppData\Roaming\Memeo
2013-08-15 19:34 - 2012-09-18 19:15 - 00066816 _____ C:\Users\Brandon\AppData\Local\GDIPFONTCACHEV1.DAT
2013-08-15 19:27 - 2013-08-15 19:27 - 00000000 ____D C:\Program Files (x86)\Western Digital
2013-08-15 19:26 - 2013-08-15 19:26 - 00000000 ____D C:\Program Files (x86)\WDC
2013-08-15 19:25 - 2013-08-15 19:25 - 00020992 _____ C:\Windows\jestertb.dll
2013-08-15 19:24 - 2013-08-15 19:24 - 00001063 _____ C:\Users\Brandon\Desktop\My Book - Shortcut.lnk
2013-08-14 17:49 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\NDF
2013-08-14 17:34 - 2013-05-02 14:15 - 00045856 _____ (AVG Technologies) C:\Windows\System32\Drivers\avgtpx64.sys
2013-08-03 09:17 - 2012-09-26 11:27 - 00000000 ____D C:\ProgramData\Browser Manager
2013-08-01 10:24 - 2012-09-20 17:13 - 00000000 ____D C:\Users\Brandon\AppData\Roaming\Audacity
2013-07-31 20:39 - 2013-07-31 20:39 - 00361119 _____ C:\Users\Brandon\AppData\Local\newhb.crx
2013-07-31 20:39 - 2013-07-27 07:39 - 00000079 _____ C:\Users\Brandon\AppData\Roaming\WB.CFG
2013-07-30 21:34 - 2013-07-30 21:34 - 00001050 _____ C:\Users\Brandon\Desktop\Dropbox.lnk
2013-07-30 21:34 - 2012-09-18 19:15 - 00000000 ____D C:\users\Brandon
2013-07-30 21:33 - 2012-09-19 12:31 - 00000242 _____ C:\Windows\wininit.ini
 
Files to move or delete:
====================
ZeroAccess:
C:\Program Files (x86)\Google\Desktop\Install\{b84bcedc-f1cb-b3d4-9e86-f146c5c1815e}
C:\Users\Brandon\AppData\Roaming\cache.dat
C:\Users\Brandon\AppData\Roaming\cache.ini
C:\Users\Brandon\AppData\Local\Temp\vlc-2.0.8-win32.exe
 
==================== Known DLLs (Whitelisted) ================
 
 
==================== Bamital & volsnap Check =================
 
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
C:\Program Files\Windows Defender\mpsvc.dll => ATTENTION: ZeroAccess. Use DeleteJunctionsIndirectory: C:\Program Files\Windows Defender
 
==================== EXE ASSOCIATION =====================
 
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
 
==================== Restore Points  =========================
 
Restore point made on: 2013-08-17 11:02:31
Restore point made on: 2013-08-18 10:02:29
Restore point made on: 2013-08-25 17:02:36
 
==================== Memory info =========================== 
 
Percentage of memory in use: 22%
Total physical RAM: 2806.7 MB
Available physical RAM: 2179.41 MB
Total Pagefile: 2804.9 MB
Available Pagefile: 2170.79 MB
Total Virtual: 8192 MB
Available Virtual: 8191.88 MB
 
==================== Drives ================================
 
Drive c: (Acer) (Fixed) (Total:281.99 GB) (Free:125.05 GB) NTFS
Drive e: (PQSERVICE) (Fixed) (Total:16 GB) (Free:5.28 GB) NTFS
Drive h: (UDISK 2.0) (Removable) (Total:1.92 GB) (Free:0.83 GB) FAT
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Drive y: (SYSTEM RESERVED) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: 2CC066AA)
Partition 1: (Not Active) - (Size=16 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=282 GB) - (Type=07 NTFS)
 
========================================================
Disk: 2 (Size: 2 GB) (Disk ID: 8DAA8C73)
Partition 1: (Active) - (Size=2 GB) - (Type=0E)
 
 
LastRegBack: 2013-08-22 08:32
 
==================== End Of Log ============================

 

 

 

 

 

Any help on the next steps would be much appreciated.

Thanks



BC AdBot (Login to Remove)

 


#2 HelpBot

HelpBot

    Bleepin' Binary Bot


  • Bots
  • 12,602 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:29 PM

Posted 03 September 2013 - 12:50 PM

Hello and welcome to Bleeping Computer!

I am HelpBot: an automated program designed to help the Bleeping Computer Staff better assist you! This message contains very important information, so please read through all of it before doing anything.

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

To help Bleeping Computer better assist you please perform the following steps:

***************************************************

step1.gif In order to continue receiving help at BleepingComputer.com, YOU MUST tell me if you still need help or if your issue has already been resolved on your own or through another resource! To tell me this, please click on the following link and follow the instructions there.

CLICK THIS LINK >>> http://www.bleepingcomputer.com/logreply/506033 <<< CLICK THIS LINK



If you no longer need help, then all you needed to do was the previous instructions of telling me so. You can skip the rest of this post. If you do need help please continue with Step 2 below.

***************************************************

step2.gifIf you still need help, I would like you to post a Reply to this topic (click the "Add Reply" button in the lower right hand of this page). In that reply, please include the following information:

  • If you have not done so already, include a clear description of the problems you're having, along with any steps you may have performed so far.
  • A new DDS log. For your convenience, you will find the instructions for generating these logs repeated at the bottom of this post.
    • Please do this even if you have previously posted logs for us.
    • If you were unable to produce the logs originally please try once more.
    • If you are unable to create a log please provide detailed information about your installed Windows Operating System including the Version, Edition and if it is a 32bit or a 64bit system.
    • If you are unsure about any of these characteristics just post what you can and we will guide you.
  • Please tell us if you have your original Windows CD/DVD available.
  • Upon completing the above steps and posting a reply, another staff member will review your topic and do their best to resolve your issues.

Thank you for your patience, and again sorry for the delay.

***************************************************

We need to see some information about what is happening in your machine. Please perform the following scan again:

  • Download DDS by sUBs from the following link if you no longer have it available and save it to your destop.

    DDS.com Download Link
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control can be found HERE.

As I am just a silly little program running on the BleepingComputer.com servers, please do not send me private messages as I do not know how to read and reply to them! Thanks!

#3 HelpBot

HelpBot

    Bleepin' Binary Bot


  • Bots
  • 12,602 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:29 PM

Posted 08 September 2013 - 12:50 PM

Hello again!

I haven't heard from you in 5 days. Therefore, I am going to assume that you no longer need our help, and close this topic.

If you do still need help, please send a Private Message to any Moderator within the next five days. Be sure to include a link to your topic in your Private Message.

Thank you for using Bleeping Computer, and have a great day!




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users