Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

cannot open most websites in chrome or IE, cannot log in to google drive


  • This topic is locked This topic is locked
94 replies to this topic

#1 nielsenja

nielsenja

  • Members
  • 53 posts
  • OFFLINE
  •  
  • Local time:04:02 AM

Posted 17 December 2013 - 01:39 AM

Internet works fine on every device on my home network except my PC (details below).  Works just fine on 2 iMacs, 2 iPhones, a laptop, and iPad.

 

However, when I use my PC, for the last few months I have noticed that:

 

In Chrome Version 31.0.1650.63 m, I cannot access anything Google related, I get "This webpage is not available." Error code: ERR_FAILED

 

In Internet Explorer Version 9.0.8112.16421 64-bit, I cannot access anything Google related, I get "Internet Explorer cannot display the webpage".

 

Google Drive Sync also brings up a dialog box to sign in that says it cannot load and acts as though I am not connected to the internet.

 

But I can successfully go to any site using Firefox.  I have been "getting by" using Firefox for the last month or so but it is getting frustrating.  When I searched last month (before I got frustrated and stopped trying to fix the problem), it seemed that many other people were having similar issues that were malware-related, which is what leads me to this forum.

 

I use Kaspersky PURE 3.0 and Microsoft Security Essentials, and I have attempted to find/remove/fix malware/rootkits/etc using Malwarebytes Anti-Malware, TDSSKiller, CCleaner, AVG, and a number of other programs.  I have tried flushing my DNS cache and tried reconfiguring my router.  Nothing has fixed this issue.

 

Any help you can provide is VERY appreciated.

 

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 9.0.8112.16526  BrowserJavaVersion: 10.45.2
Run by Jon at 22:11:05 on 2013-12-16
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.1.1033.18.8190.5963 [GMT -8:00]
.
AV: Kaspersky PURE 3.0 *Enabled/Updated* {C3113FBF-4BCB-4461-D78D-6EDFEC9593E5}
AV: Microsoft Security Essentials *Enabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Kaspersky PURE 3.0 *Enabled/Updated* {7870DE5B-6DF1-4BEF-ED3D-55AD9712D958}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Enabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
FW: Kaspersky PURE 3.0 *Enabled* {FB2ABE9A-01A4-4539-FCD2-C7EA1246D49E}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe
c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Program Files (x86)\Belkin\F9L1103\v1\Common\RaRegistry64.exe
c:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Users\Jon\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\PROGRA~2\KASPER~1\KASPER~1.0\KASPER~2\stpass.exe
C:\Users\Jon\AppData\Local\Apps\2.0\OQ4KM2CA.Z6R\Q1EZAPQ6.JCT\curs..tion_9e9e83ddf3ed3ead_0005.0001_181b5e0542e9eb6c\CurseClient.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
c:\Program Files\Microsoft Security Client\MpCmdRun.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
BHO: E-Web Print: {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll
BHO: Kaspersky Passsword Manager Toolbar: {215BA832-75A3-426E-A4FC-7C5B58CE6A10} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\Kaspersky Password Manager\spIEBho.dll
BHO: Content Blocker Plugin: {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll
BHO: Virtual Keyboard Plugin: {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Safe Money Plugin: {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\OnlineBanking\online_banking_bho.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\office15\URLREDIR.DLL
BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO: URL Advisor Plugin: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\UrlAdvisor\klwtbbho.dll
TB: E-Web Print: {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll
TB: Kaspersky Passsword Manager Toolbar: {215BA832-75A3-426E-A4FC-7C5B58CE6A10} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\Kaspersky Password Manager\spIEBho.dll
EB: E-Web Print: {A60C1DC7-64B3-4AD9-8E67-035D11B8B2B0} - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll
uRun: [Spotify Web Helper] "C:\Users\Jon\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
mRun: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe"
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
StartupFolder: C:\Users\Jon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip
uPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: NoDriveTypeAutoRun = dword:28
mPolicies-Explorer: NoDrives = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\ie_banner_deny.htm
IE: {0C4CC089-D306-440D-9772-464E226F6539} - {0BA14598-4178-4CE5-B1F1-B5C6408A3F2E} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\UrlAdvisor\klwtbbho.dll
.
INFO: HKLM has more than 50 listed domains.
   If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} - hxxp://support.asus.com/select/asusTek_sys_ctrl3.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab
TCP: NameServer = 192.168.1.254
TCP: Interfaces\{44F1C3A3-8AC4-42FE-852B-41EFB1DAFEC6} : DHCPNameServer = 192.168.1.254
TCP: Interfaces\{5428896A-DC45-4EC1-98F4-5D5F44292EE2} : DHCPNameServer = 192.168.1.254
TCP: Interfaces\{6474E8DA-FDB5-4870-B1CF-78F84D577F75} : DHCPNameServer = 192.168.1.254
TCP: Interfaces\{DC76D51B-FF98-4C75-B906-60C0C7A5783D} : DHCPNameServer = 192.168.1.254
TCP: Interfaces\{E0E51646-53ED-476C-9565-C8D6D525E2E9} : DHCPNameServer = 192.168.1.254
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\office15\MSOSB.DLL
SSODL: WebCheck - <orphaned>
x64-BHO: Lync Browser Helper: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll
x64-BHO: Content Blocker Plugin: {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll
x64-BHO: Virtual Keyboard Plugin: {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
x64-BHO: Safe Money Plugin: {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\OnlineBanking\online_banking_bho.dll
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL
x64-BHO: Microsoft SkyDrive Pro Browser Helper: {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL
x64-BHO: URL Advisor Plugin: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\UrlAdvisor\klwtbbho.dll
x64-Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
x64-IE: {0C4CC089-D306-440D-9772-464E226F6539} - {0BA14598-4178-4CE5-B1F1-B5C6408A3F2E} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ONBttnIE.dll
x64-IE: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
x64-IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\UrlAdvisor\klwtbbho.dll
x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
x64-Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - <orphaned>
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Jon\AppData\Roaming\Mozilla\Firefox\Profiles\d1oarrbu.default\
FF - plugin: C:\PROGRA~2\KASPER~1\KASPER~1.0\KASPER~2\npKPMAutofill.dll
FF - plugin: C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\Logitech\Harmony Remote Driver\NprtHarmonyPlugin.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrlui.dll
FF - plugin: C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll
.
---- FIREFOX POLICIES ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
============= SERVICES / DRIVERS ===============
.
R0 CSCrySec;InfoWatch Encrypt Sector Library driver;C:\Windows\System32\drivers\CSCrySec.sys [2013-9-3 84536]
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2013-9-27 248240]
R0 SCMNdisP;General NDIS Protocol Driver;C:\Windows\System32\drivers\SCMNdisP.sys [2012-6-9 25056]
R1 avgtp;avgtp;C:\Windows\System32\drivers\avgtpx64.sys [2013-8-30 45856]
R1 CSVirtualDiskDrv;InfoWatch Virtual Disk driver;C:\Windows\System32\drivers\CSVirtualDiskDrv.sys [2013-9-3 66616]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\System32\drivers\klim6.sys [2012-8-2 28504]
R1 kltdi;kltdi;C:\Windows\System32\drivers\kltdi.sys [2012-10-18 54368]
R1 kneps;kneps;C:\Windows\System32\drivers\kneps.sys [2012-8-13 178448]
R2 AODDriver4.01;AODDriver4.01;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys [2012-4-9 57472]
R2 AVP;Kaspersky Anti-Virus Service;C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe [2012-12-20 356128]
R2 MSSQL$SQLEXPRESSEFILM;SQL Server (SQLEXPRESSEFILM);C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2010-12-10 29293408]
R2 OfficeSvc;Microsoft Office Service;C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [2013-3-14 1907896]
R2 RalinkRegistryWriter64;RalinkRegistryWriter64;C:\Program Files (x86)\Belkin\F9L1103\v1\Common\RaRegistry64.exe [2013-11-14 447488]
R3 amdiox64;AMD IO Driver;C:\Windows\System32\drivers\amdiox64.sys [2011-12-2 46136]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2012-11-6 96256]
R3 klkbdflt;Kaspersky Lab KLKBDFLT;C:\Windows\System32\drivers\klkbdflt.sys [2012-9-3 29280]
R3 klmouflt;Kaspersky Lab KLMOUFLT;C:\Windows\System32\drivers\klmouflt.sys [2012-9-3 29280]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2011-6-10 539240]
R3 SSMO4Filter;MMO-4 Mouse;C:\Windows\System32\drivers\MO4Driver.sys [2011-7-27 21504]
S2 AODDriver4.2;AODDriver4.2;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys [2012-4-9 57472]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 vToolbarUpdater15.5.0;vToolbarUpdater15.5.0;C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\ToolbarUpdater.exe --> C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\ToolbarUpdater.exe [?]
S3 BCMH43XX;Broadcom 802.11 USB Network Adapter Driver;C:\Windows\System32\drivers\bcmwlhigh664.sys [2012-6-9 1256192]
S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;C:\Windows\System32\drivers\LGBusEnum.sys [2009-11-23 22408]
S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;C:\Windows\System32\drivers\LGVirHid.sys [2009-11-23 16008]
S3 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2011-4-27 134944]
S3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2013-10-23 348376]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2013-5-21 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2013-5-21 30208]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-12-13 54784]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2011-12-2 1255736]
S4 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2012-12-19 240640]
S4 AMD FUEL Service;AMD FUEL Service;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-12-19 361984]
S4 CSObjectsSrv;CryptoStorage control service;C:\Program Files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe [2012-12-21 819040]
S4 EpsonCustomerParticipation;EpsonCustomerParticipation;C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe [2012-5-10 608864]
S4 EpsonScanSvc;Epson Scanner Service;C:\Windows\System32\escsvc64.exe [2013-6-20 135824]
S4 Fitbit Connect;Fitbit Connect Service;C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe [2013-2-25 1239584]
S4 MediaMall Server;MediaMall Server;C:\Program Files (x86)\MediaMall\MediaMallServer.exe [2012-12-27 4038448]
S4 WSWNA3100;WSWNA3100;C:\Program Files (x86)\NETGEAR\WNA3100\WifiSvc.exe [2012-6-9 303360]
.
=============== File Associations ===============
.
ShellExec: SC2Editor.exe: open="C:/Program Files (x86)/StarCraft II/Support/SC2Editor.exe" "%1"
ShellExec: SC2Switcher.exe: open="C:/Program Files (x86)/StarCraft II/Support/SC2Switcher.exe" "%1"
.
=============== Created Last 30 ================
.
2013-12-17 06:02:17    10285968    ----a-w-    C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{85C7747A-4EFE-4FBD-83A8-9B8152183188}\mpengine.dll
2013-12-17 05:53:40    --------    d-sh--w-    C:\$RECYCLE.BIN
2013-12-17 05:45:31    98816    ----a-w-    C:\Windows\sed.exe
2013-12-17 05:45:31    256000    ----a-w-    C:\Windows\PEV.exe
2013-12-17 05:45:31    208896    ----a-w-    C:\Windows\MBR.exe
2013-12-16 03:43:00    10285968    ----a-w-    C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-12-16 03:13:59    167424    ----a-w-    C:\Program Files\Windows Media Player\wmplayer.exe
2013-12-16 03:13:59    164864    ----a-w-    C:\Program Files (x86)\Windows Media Player\wmplayer.exe
2013-12-16 03:13:58    12625920    ----a-w-    C:\Windows\System32\wmploc.DLL
2013-12-16 03:13:57    12625408    ----a-w-    C:\Windows\SysWow64\wmploc.DLL
2013-12-11 08:32:05    335360    ----a-w-    C:\Windows\System32\msieftp.dll
2013-12-11 08:32:05    301568    ----a-w-    C:\Windows\SysWow64\msieftp.dll
2013-12-11 08:32:02    3155968    ----a-w-    C:\Windows\System32\win32k.sys
2013-12-11 08:32:01    465920    ----a-w-    C:\Windows\System32\WMPhoto.dll
2013-12-11 08:32:01    417792    ----a-w-    C:\Windows\SysWow64\WMPhoto.dll
2013-12-06 22:37:42    965000    ------w-    C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{DD11F24D-E72F-4E93-B950-BD180A1DA77E}\gapaengine.dll
2013-11-19 19:36:45    --------    d-----w-    C:\Users\Jon\AppData\Local\SWTOR
.
==================== Find3M  ====================
.
2013-11-19 10:21:41    267936    ------w-    C:\Windows\System32\MpSigStub.exe
2013-11-15 01:37:29    2334720    ----a-w-    C:\Windows\System32\jscript9.dll
2013-11-15 01:29:03    1392128    ----a-w-    C:\Windows\System32\wininet.dll
2013-11-15 01:28:41    1494528    ----a-w-    C:\Windows\System32\inetcpl.cpl
2013-11-15 01:22:21    173056    ----a-w-    C:\Windows\System32\ieUnatt.exe
2013-11-15 01:20:47    599040    ----a-w-    C:\Windows\System32\vbscript.dll
2013-11-15 01:18:03    2382848    ----a-w-    C:\Windows\System32\mshtml.tlb
2013-11-14 22:50:50    1806848    ----a-w-    C:\Windows\SysWow64\jscript9.dll
2013-11-14 22:42:41    1129472    ----a-w-    C:\Windows\SysWow64\wininet.dll
2013-11-14 22:42:32    1427968    ----a-w-    C:\Windows\SysWow64\inetcpl.cpl
2013-11-14 22:38:54    142848    ----a-w-    C:\Windows\SysWow64\ieUnatt.exe
2013-11-14 22:38:16    420864    ----a-w-    C:\Windows\SysWow64\vbscript.dll
2013-11-14 22:35:52    2382848    ----a-w-    C:\Windows\SysWow64\mshtml.tlb
2013-11-12 02:23:09    2048    ----a-w-    C:\Windows\System32\tzres.dll
2013-11-12 02:07:29    2048    ----a-w-    C:\Windows\SysWow64\tzres.dll
2013-10-29 05:38:16    96168    ----a-w-    C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2013-10-29 05:33:56    71048    ----a-w-    C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-10-29 05:33:56    692616    ----a-w-    C:\Windows\SysWow64\FlashPlayerApp.exe
2013-10-19 02:18:57    81408    ----a-w-    C:\Windows\System32\imagehlp.dll
2013-10-19 01:36:59    159232    ----a-w-    C:\Windows\SysWow64\imagehlp.dll
2013-10-16 12:19:09    29280    ----a-w-    C:\Windows\System32\drivers\klmouflt.sys
2013-10-16 12:19:08    29280    ----a-w-    C:\Windows\System32\drivers\klkbdflt.sys
2013-10-16 12:19:04    90208    ----a-w-    C:\Windows\System32\drivers\klflt.sys
2013-10-16 12:19:02    7717984    ----a-w-    C:\Windows\System32\drivers\kl1.sys
2013-10-12 02:32:04    150016    ----a-w-    C:\Windows\System32\wshom.ocx
2013-10-12 02:31:04    202752    ----a-w-    C:\Windows\System32\scrrun.dll
2013-10-12 02:30:42    830464    ----a-w-    C:\Windows\System32\nshwfp.dll
2013-10-12 02:29:21    859648    ----a-w-    C:\Windows\System32\IKEEXT.DLL
2013-10-12 02:29:08    324096    ----a-w-    C:\Windows\System32\FWPUCLNT.DLL
2013-10-12 02:04:36    121856    ----a-w-    C:\Windows\SysWow64\wshom.ocx
2013-10-12 02:03:31    163840    ----a-w-    C:\Windows\SysWow64\scrrun.dll
2013-10-12 02:03:08    656896    ----a-w-    C:\Windows\SysWow64\nshwfp.dll
2013-10-12 02:01:25    216576    ----a-w-    C:\Windows\SysWow64\FWPUCLNT.DLL
2013-10-12 01:33:39    156160    ----a-w-    C:\Windows\System32\cscript.exe
2013-10-12 01:33:26    168960    ----a-w-    C:\Windows\System32\wscript.exe
2013-10-12 01:15:48    141824    ----a-w-    C:\Windows\SysWow64\wscript.exe
2013-10-12 01:15:48    126976    ----a-w-    C:\Windows\SysWow64\cscript.exe
2013-10-05 20:25:35    1474048    ----a-w-    C:\Windows\System32\crypt32.dll
2013-10-05 19:57:25    1168384    ----a-w-    C:\Windows\SysWow64\crypt32.dll
2013-10-04 02:28:31    190464    ----a-w-    C:\Windows\System32\SmartcardCredentialProvider.dll
2013-10-04 02:25:17    197120    ----a-w-    C:\Windows\System32\credui.dll
2013-10-04 02:24:49    1930752    ----a-w-    C:\Windows\System32\authui.dll
2013-10-04 02:16:30    116736    ----a-w-    C:\Windows\System32\drivers\drmk.sys
2013-10-04 01:58:50    152576    ----a-w-    C:\Windows\SysWow64\SmartcardCredentialProvider.dll
2013-10-04 01:56:25    168960    ----a-w-    C:\Windows\SysWow64\credui.dll
2013-10-04 01:56:00    1796096    ----a-w-    C:\Windows\SysWow64\authui.dll
2013-10-04 01:36:04    230400    ----a-w-    C:\Windows\System32\drivers\portcls.sys
2013-10-03 02:23:48    404480    ----a-w-    C:\Windows\System32\gdi32.dll
2013-10-03 02:00:44    311808    ----a-w-    C:\Windows\SysWow64\gdi32.dll
2013-09-28 01:09:10    497152    ----a-w-    C:\Windows\System32\drivers\afd.sys
2013-09-27 17:53:06    248240    ----a-w-    C:\Windows\System32\drivers\MpFilter.sys
2013-09-27 17:53:06    134944    ----a-w-    C:\Windows\System32\drivers\NisDrvWFP.sys
2013-09-25 02:26:40    95680    ----a-w-    C:\Windows\System32\drivers\ksecdd.sys
2013-09-25 02:26:40    154560    ----a-w-    C:\Windows\System32\drivers\ksecpkg.sys
2013-09-25 02:23:33    28672    ----a-w-    C:\Windows\System32\sspisrv.dll
2013-09-25 02:23:33    135680    ----a-w-    C:\Windows\System32\sspicli.dll
2013-09-25 02:23:01    28160    ----a-w-    C:\Windows\System32\secur32.dll
2013-09-25 02:22:59    340992    ----a-w-    C:\Windows\System32\schannel.dll
2013-09-25 02:21:50    307200    ----a-w-    C:\Windows\System32\ncrypt.dll
2013-09-25 02:21:07    1447936    ----a-w-    C:\Windows\System32\lsasrv.dll
2013-09-25 01:58:17    96768    ----a-w-    C:\Windows\SysWow64\sspicli.dll
2013-09-25 01:57:26    22016    ----a-w-    C:\Windows\SysWow64\secur32.dll
2013-09-25 01:57:24    247808    ----a-w-    C:\Windows\SysWow64\schannel.dll
2013-09-25 01:56:42    220160    ----a-w-    C:\Windows\SysWow64\ncrypt.dll
2013-09-25 01:03:24    30720    ----a-w-    C:\Windows\System32\lsass.exe
.
============= FINISH: 22:11:28.88 ===============
 

Attached Files



BC AdBot (Login to Remove)

 


#2 HelpBot

HelpBot

    Bleepin' Binary Bot


  • Bots
  • 12,729 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:02 AM

Posted 22 December 2013 - 01:40 AM

Hello and welcome to Bleeping Computer!

I am HelpBot: an automated program designed to help the Bleeping Computer Staff better assist you! This message contains very important information, so please read through all of it before doing anything.

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

To help Bleeping Computer better assist you please perform the following steps:

***************************************************

step1.gif In order to continue receiving help at BleepingComputer.com, YOU MUST tell me if you still need help or if your issue has already been resolved on your own or through another resource! To tell me this, please click on the following link and follow the instructions there.

CLICK THIS LINK >>> http://www.bleepingcomputer.com/logreply/517726 <<< CLICK THIS LINK



If you no longer need help, then all you needed to do was the previous instructions of telling me so. You can skip the rest of this post. If you do need help please continue with Step 2 below.

***************************************************

step2.gifIf you still need help, I would like you to post a Reply to this topic (click the "Add Reply" button in the lower right hand of this page). In that reply, please include the following information:

  • If you have not done so already, include a clear description of the problems you're having, along with any steps you may have performed so far.
  • A new DDS log. For your convenience, you will find the instructions for generating these logs repeated at the bottom of this post.
    • Please do this even if you have previously posted logs for us.
    • If you were unable to produce the logs originally please try once more.
    • If you are unable to create a log please provide detailed information about your installed Windows Operating System including the Version, Edition and if it is a 32bit or a 64bit system.
    • If you are unsure about any of these characteristics just post what you can and we will guide you.
  • Please tell us if you have your original Windows CD/DVD available.
  • Upon completing the above steps and posting a reply, another staff member will review your topic and do their best to resolve your issues.

Thank you for your patience, and again sorry for the delay.

***************************************************

We need to see some information about what is happening in your machine. Please perform the following scan again:

  • Download DDS by sUBs from the following link if you no longer have it available and save it to your destop.

    DDS.com Download Link
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control can be found HERE.

As I am just a silly little program running on the BleepingComputer.com servers, please do not send me private messages as I do not know how to read and reply to them! Thanks!

#3 nielsenja

nielsenja
  • Topic Starter

  • Members
  • 53 posts
  • OFFLINE
  •  
  • Local time:04:02 AM

Posted 23 December 2013 - 10:56 PM

Re: Step 2, I am home for the holidays and won't be back at the computer in question until this Friday. I will generate a new DDS log at that time if that's ok.


Thank you in advance for any help you can provide!

#4 nielsenja

nielsenja
  • Topic Starter

  • Members
  • 53 posts
  • OFFLINE
  •  
  • Local time:04:02 AM

Posted 27 December 2013 - 07:24 PM

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 9.0.8112.16526  BrowserJavaVersion: 10.45.2
Run by Jon at 16:22:34 on 2013-12-27
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.1.1033.18.8190.5989 [GMT -8:00]
.
AV: Kaspersky PURE 3.0 *Enabled/Updated* {C3113FBF-4BCB-4461-D78D-6EDFEC9593E5}
AV: Microsoft Security Essentials *Enabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Kaspersky PURE 3.0 *Enabled/Updated* {7870DE5B-6DF1-4BEF-ED3D-55AD9712D958}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Enabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
FW: Kaspersky PURE 3.0 *Enabled* {FB2ABE9A-01A4-4539-FCD2-C7EA1246D49E}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe
c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Program Files (x86)\Belkin\F9L1103\v1\Common\RaRegistry64.exe
c:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\Explorer.EXE
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Users\Jon\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
C:\Users\Jon\AppData\Local\Apps\2.0\OQ4KM2CA.Z6R\Q1EZAPQ6.JCT\curs..tion_9e9e83ddf3ed3ead_0005.0001_181b5e0542e9eb6c\CurseClient.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
c:\Program Files\Microsoft Security Client\NisSrv.exe
C:\PROGRA~2\KASPER~1\KASPER~1.0\KASPER~2\stpass.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
BHO: E-Web Print: {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll
BHO: Kaspersky Passsword Manager Toolbar: {215BA832-75A3-426E-A4FC-7C5B58CE6A10} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\Kaspersky Password Manager\spIEBho.dll
BHO: Content Blocker Plugin: {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll
BHO: Virtual Keyboard Plugin: {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Safe Money Plugin: {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\OnlineBanking\online_banking_bho.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\office15\URLREDIR.DLL
BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO: URL Advisor Plugin: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\UrlAdvisor\klwtbbho.dll
TB: E-Web Print: {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll
TB: Kaspersky Passsword Manager Toolbar: {215BA832-75A3-426E-A4FC-7C5B58CE6A10} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\Kaspersky Password Manager\spIEBho.dll
EB: E-Web Print: {A60C1DC7-64B3-4AD9-8E67-035D11B8B2B0} - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll
uRun: [Spotify Web Helper] "C:\Users\Jon\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
mRun: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe"
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
StartupFolder: C:\Users\Jon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip
uPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: NoDriveTypeAutoRun = dword:28
mPolicies-Explorer: NoDrives = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\ie_banner_deny.htm
IE: {0C4CC089-D306-440D-9772-464E226F6539} - {0BA14598-4178-4CE5-B1F1-B5C6408A3F2E} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\UrlAdvisor\klwtbbho.dll
.
INFO: HKLM has more than 50 listed domains.
   If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} - hxxp://support.asus.com/select/asusTek_sys_ctrl3.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab
TCP: NameServer = 192.168.1.254
TCP: Interfaces\{44F1C3A3-8AC4-42FE-852B-41EFB1DAFEC6} : DHCPNameServer = 192.168.1.254
TCP: Interfaces\{5428896A-DC45-4EC1-98F4-5D5F44292EE2} : DHCPNameServer = 192.168.1.254
TCP: Interfaces\{6474E8DA-FDB5-4870-B1CF-78F84D577F75} : DHCPNameServer = 192.168.1.254
TCP: Interfaces\{DC76D51B-FF98-4C75-B906-60C0C7A5783D} : DHCPNameServer = 192.168.1.254
TCP: Interfaces\{E0E51646-53ED-476C-9565-C8D6D525E2E9} : DHCPNameServer = 192.168.1.254
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\office15\MSOSB.DLL
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: Lync Browser Helper: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll
x64-BHO: Content Blocker Plugin: {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll
x64-BHO: Virtual Keyboard Plugin: {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
x64-BHO: Safe Money Plugin: {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\OnlineBanking\online_banking_bho.dll
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL
x64-BHO: Microsoft SkyDrive Pro Browser Helper: {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL
x64-BHO: URL Advisor Plugin: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\UrlAdvisor\klwtbbho.dll
x64-Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
x64-IE: {0C4CC089-D306-440D-9772-464E226F6539} - {0BA14598-4178-4CE5-B1F1-B5C6408A3F2E} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ONBttnIE.dll
x64-IE: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
x64-IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\UrlAdvisor\klwtbbho.dll
x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
x64-Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - <orphaned>
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Jon\AppData\Roaming\Mozilla\Firefox\Profiles\d1oarrbu.default\
FF - plugin: C:\PROGRA~2\KASPER~1\KASPER~1.0\KASPER~2\npKPMAutofill.dll
FF - plugin: C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\Logitech\Harmony Remote Driver\NprtHarmonyPlugin.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrlui.dll
FF - plugin: C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll
.
---- FIREFOX POLICIES ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
============= SERVICES / DRIVERS ===============
.
R0 CSCrySec;InfoWatch Encrypt Sector Library driver;C:\Windows\System32\drivers\CSCrySec.sys [2013-9-3 84536]
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2013-9-27 248240]
R0 SCMNdisP;General NDIS Protocol Driver;C:\Windows\System32\drivers\SCMNdisP.sys [2012-6-9 25056]
R1 avgtp;avgtp;C:\Windows\System32\drivers\avgtpx64.sys [2013-8-30 45856]
R1 CSVirtualDiskDrv;InfoWatch Virtual Disk driver;C:\Windows\System32\drivers\CSVirtualDiskDrv.sys [2013-9-3 66616]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\System32\drivers\klim6.sys [2012-8-2 28504]
R1 kltdi;kltdi;C:\Windows\System32\drivers\kltdi.sys [2012-10-18 54368]
R1 kneps;kneps;C:\Windows\System32\drivers\kneps.sys [2012-8-13 178448]
R2 AODDriver4.01;AODDriver4.01;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys [2012-4-9 57472]
R2 AVP;Kaspersky Anti-Virus Service;C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe [2012-12-20 356128]
R2 MSSQL$SQLEXPRESSEFILM;SQL Server (SQLEXPRESSEFILM);C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2010-12-10 29293408]
R2 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2011-4-27 134944]
R2 OfficeSvc;Microsoft Office Service;C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [2013-3-14 1907896]
R2 RalinkRegistryWriter64;RalinkRegistryWriter64;C:\Program Files (x86)\Belkin\F9L1103\v1\Common\RaRegistry64.exe [2013-11-14 447488]
R3 amdiox64;AMD IO Driver;C:\Windows\System32\drivers\amdiox64.sys [2011-12-2 46136]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2012-11-6 96256]
R3 klkbdflt;Kaspersky Lab KLKBDFLT;C:\Windows\System32\drivers\klkbdflt.sys [2012-9-3 29280]
R3 klmouflt;Kaspersky Lab KLMOUFLT;C:\Windows\System32\drivers\klmouflt.sys [2012-9-3 29280]
R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2013-10-23 348376]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2011-6-10 539240]
R3 SSMO4Filter;MMO-4 Mouse;C:\Windows\System32\drivers\MO4Driver.sys [2011-7-27 21504]
S2 AODDriver4.2;AODDriver4.2;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys [2012-4-9 57472]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 vToolbarUpdater15.5.0;vToolbarUpdater15.5.0;C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\ToolbarUpdater.exe --> C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\ToolbarUpdater.exe [?]
S3 BCMH43XX;Broadcom 802.11 USB Network Adapter Driver;C:\Windows\System32\drivers\bcmwlhigh664.sys [2012-6-9 1256192]
S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;C:\Windows\System32\drivers\LGBusEnum.sys [2009-11-23 22408]
S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;C:\Windows\System32\drivers\LGVirHid.sys [2009-11-23 16008]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2013-5-21 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2013-5-21 30208]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-12-13 54784]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2011-12-2 1255736]
S4 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2012-12-19 240640]
S4 AMD FUEL Service;AMD FUEL Service;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-12-19 361984]
S4 CSObjectsSrv;CryptoStorage control service;C:\Program Files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe [2012-12-21 819040]
S4 EpsonCustomerParticipation;EpsonCustomerParticipation;C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe [2012-5-10 608864]
S4 EpsonScanSvc;Epson Scanner Service;C:\Windows\System32\escsvc64.exe [2013-6-20 135824]
S4 Fitbit Connect;Fitbit Connect Service;C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe [2013-2-25 1239584]
S4 MediaMall Server;MediaMall Server;C:\Program Files (x86)\MediaMall\MediaMallServer.exe [2012-12-27 4038448]
S4 WSWNA3100;WSWNA3100;C:\Program Files (x86)\NETGEAR\WNA3100\WifiSvc.exe [2012-6-9 303360]
.
=============== File Associations ===============
.
ShellExec: SC2Editor.exe: open="C:/Program Files (x86)/StarCraft II/Support/SC2Editor.exe" "%1"
ShellExec: SC2Switcher.exe: open="C:/Program Files (x86)/StarCraft II/Support/SC2Switcher.exe" "%1"
.
=============== Created Last 30 ================
.
2013-12-27 17:34:33    10315576    ----a-w-    C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{DF7BF89D-6D54-4972-85E8-ABE0A4FC3CEA}\mpengine.dll
2013-12-20 14:55:17    10315576    ----a-w-    C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-12-17 05:53:40    --------    d-sh--w-    C:\$RECYCLE.BIN
2013-12-17 05:45:31    98816    ----a-w-    C:\Windows\sed.exe
2013-12-17 05:45:31    256000    ----a-w-    C:\Windows\PEV.exe
2013-12-17 05:45:31    208896    ----a-w-    C:\Windows\MBR.exe
2013-12-16 03:13:59    167424    ----a-w-    C:\Program Files\Windows Media Player\wmplayer.exe
2013-12-16 03:13:59    164864    ----a-w-    C:\Program Files (x86)\Windows Media Player\wmplayer.exe
2013-12-16 03:13:58    12625920    ----a-w-    C:\Windows\System32\wmploc.DLL
2013-12-16 03:13:57    12625408    ----a-w-    C:\Windows\SysWow64\wmploc.DLL
2013-12-11 08:32:05    335360    ----a-w-    C:\Windows\System32\msieftp.dll
2013-12-11 08:32:05    301568    ----a-w-    C:\Windows\SysWow64\msieftp.dll
2013-12-11 08:32:02    3155968    ----a-w-    C:\Windows\System32\win32k.sys
2013-12-11 08:32:01    465920    ----a-w-    C:\Windows\System32\WMPhoto.dll
2013-12-11 08:32:01    417792    ----a-w-    C:\Windows\SysWow64\WMPhoto.dll
2013-12-06 22:37:42    965000    ------w-    C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{DD11F24D-E72F-4E93-B950-BD180A1DA77E}\gapaengine.dll
.
==================== Find3M  ====================
.
2013-11-19 10:21:41    267936    ------w-    C:\Windows\System32\MpSigStub.exe
2013-11-15 01:37:29    2334720    ----a-w-    C:\Windows\System32\jscript9.dll
2013-11-15 01:29:03    1392128    ----a-w-    C:\Windows\System32\wininet.dll
2013-11-15 01:28:41    1494528    ----a-w-    C:\Windows\System32\inetcpl.cpl
2013-11-15 01:22:21    173056    ----a-w-    C:\Windows\System32\ieUnatt.exe
2013-11-15 01:20:47    599040    ----a-w-    C:\Windows\System32\vbscript.dll
2013-11-15 01:18:03    2382848    ----a-w-    C:\Windows\System32\mshtml.tlb
2013-11-14 22:50:50    1806848    ----a-w-    C:\Windows\SysWow64\jscript9.dll
2013-11-14 22:42:41    1129472    ----a-w-    C:\Windows\SysWow64\wininet.dll
2013-11-14 22:42:32    1427968    ----a-w-    C:\Windows\SysWow64\inetcpl.cpl
2013-11-14 22:38:54    142848    ----a-w-    C:\Windows\SysWow64\ieUnatt.exe
2013-11-14 22:38:16    420864    ----a-w-    C:\Windows\SysWow64\vbscript.dll
2013-11-14 22:35:52    2382848    ----a-w-    C:\Windows\SysWow64\mshtml.tlb
2013-11-12 02:23:09    2048    ----a-w-    C:\Windows\System32\tzres.dll
2013-11-12 02:07:29    2048    ----a-w-    C:\Windows\SysWow64\tzres.dll
2013-10-29 05:38:16    96168    ----a-w-    C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2013-10-29 05:33:56    71048    ----a-w-    C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-10-29 05:33:56    692616    ----a-w-    C:\Windows\SysWow64\FlashPlayerApp.exe
2013-10-19 02:18:57    81408    ----a-w-    C:\Windows\System32\imagehlp.dll
2013-10-19 01:36:59    159232    ----a-w-    C:\Windows\SysWow64\imagehlp.dll
2013-10-16 12:19:09    29280    ----a-w-    C:\Windows\System32\drivers\klmouflt.sys
2013-10-16 12:19:08    29280    ----a-w-    C:\Windows\System32\drivers\klkbdflt.sys
2013-10-16 12:19:04    90208    ----a-w-    C:\Windows\System32\drivers\klflt.sys
2013-10-16 12:19:02    7717984    ----a-w-    C:\Windows\System32\drivers\kl1.sys
2013-10-12 02:32:04    150016    ----a-w-    C:\Windows\System32\wshom.ocx
2013-10-12 02:31:04    202752    ----a-w-    C:\Windows\System32\scrrun.dll
2013-10-12 02:30:42    830464    ----a-w-    C:\Windows\System32\nshwfp.dll
2013-10-12 02:29:21    859648    ----a-w-    C:\Windows\System32\IKEEXT.DLL
2013-10-12 02:29:08    324096    ----a-w-    C:\Windows\System32\FWPUCLNT.DLL
2013-10-12 02:04:36    121856    ----a-w-    C:\Windows\SysWow64\wshom.ocx
2013-10-12 02:03:31    163840    ----a-w-    C:\Windows\SysWow64\scrrun.dll
2013-10-12 02:03:08    656896    ----a-w-    C:\Windows\SysWow64\nshwfp.dll
2013-10-12 02:01:25    216576    ----a-w-    C:\Windows\SysWow64\FWPUCLNT.DLL
2013-10-12 01:33:39    156160    ----a-w-    C:\Windows\System32\cscript.exe
2013-10-12 01:33:26    168960    ----a-w-    C:\Windows\System32\wscript.exe
2013-10-12 01:15:48    141824    ----a-w-    C:\Windows\SysWow64\wscript.exe
2013-10-12 01:15:48    126976    ----a-w-    C:\Windows\SysWow64\cscript.exe
2013-10-05 20:25:35    1474048    ----a-w-    C:\Windows\System32\crypt32.dll
2013-10-05 19:57:25    1168384    ----a-w-    C:\Windows\SysWow64\crypt32.dll
2013-10-04 02:28:31    190464    ----a-w-    C:\Windows\System32\SmartcardCredentialProvider.dll
2013-10-04 02:25:17    197120    ----a-w-    C:\Windows\System32\credui.dll
2013-10-04 02:24:49    1930752    ----a-w-    C:\Windows\System32\authui.dll
2013-10-04 02:16:30    116736    ----a-w-    C:\Windows\System32\drivers\drmk.sys
2013-10-04 01:58:50    152576    ----a-w-    C:\Windows\SysWow64\SmartcardCredentialProvider.dll
2013-10-04 01:56:25    168960    ----a-w-    C:\Windows\SysWow64\credui.dll
2013-10-04 01:56:00    1796096    ----a-w-    C:\Windows\SysWow64\authui.dll
2013-10-04 01:36:04    230400    ----a-w-    C:\Windows\System32\drivers\portcls.sys
2013-10-03 02:23:48    404480    ----a-w-    C:\Windows\System32\gdi32.dll
2013-10-03 02:00:44    311808    ----a-w-    C:\Windows\SysWow64\gdi32.dll
.
============= FINISH: 16:22:49.48 ===============
 

Attached Files



#5 nielsenja

nielsenja
  • Topic Starter

  • Members
  • 53 posts
  • OFFLINE
  •  
  • Local time:04:02 AM

Posted 27 December 2013 - 07:25 PM

And, yes, I do have the original Windows 7 DVD available.

 

Thanks again!



#6 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,375 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:05:02 AM

Posted 28 December 2013 - 09:03 PM

Greetings nielsenja and :welcome: to BleepingComputer's Virus/Trojan/Spyware/Malware Removal forum.

My name is Oh My! and I am here to help you! Now that we are "friends" please call me Gary.

If you would allow me to call you by your first name I would prefer to do that. :thumbup2:

===================================================

Ground Rules:
  • First, I would like to inform you that most of us here at Bleeping Computer offer our expert assistance out of the goodness of our hearts. Please try to match our commitment to you with your patience toward us. If this was easy we would never have met. :)
  • Please do not run any tools or take any steps other than those I will provide for you while we work on your computer together. I need to be certain about the state of your computer in order to provide appropriate and effective steps for you to take. Most often "well intentioned" (and usually panic driven!) independent efforts can make things much worse for both of us. If at any point you would prefer to take your own steps please let me know, I will not be offended. I would be happy to focus on the many others who are waiting in line for assistance.
  • Please perform all steps in the order they are listed in each set of instructions. Some steps may be a bit complicated. If things are not clear, be sure to stop and let me know. We need to work on this together with confidence.
  • Please copy and paste all logs into your post unless directed otherwise. Please do not re-run any programs I suggest. If you encounter problems simply stop and tell me.
  • When you post your reply, use the Replytopic.jpg button instead.
  • In the upper right hand corner of the topic you will see the Followtopic.jpg button. Click on this then choose Immediate E-Mail notification and then Proceed and you will be sent an email once I have posted a response.
  • If you do not reply to your topic after 5 days we assume it has been abandoned and I will close it.
  • When your computer is clean I will alert you of such. I will also provide for you detailed information about how you can combat future infections.
  • I would like to remind you to make no further changes to your computer unless I direct you to do so.
  • Now let's get started :thumbup2:
===================================================

Now that I am assisting you, you can expect that I will be very responsive to your situation. If you are able, I would request you check this thread at least once per day so that we can try to resolve your issues effectively and efficiently. If you are going to be delayed please be considerate and post that information so that I know you are still with me. Unfortunately, there are many people waiting to be assisted and not enough of us at BleepingComputer to go around. I appreciate your understanding and diligence.

Thank you for your patience thus far. Please do this.

===================================================

Multiple Antivirus Programs

-------------------

I do not recommend that you have more than one anti virus product installed on your computer at a time. The reason for this is that if both products have their automatic (Real-Time) protection switched on, then those products which do not encrypt the virus strings within them can cause other anti virus products to cause "false alarms". It can also lead to a clash as both products fight for access to files which are opened again this is the resident/automatic protection. In general terms, the two programs may conflict and cause:
  • False Alarms: When the anti virus software tells you that your PC has a virus when it actually doesn't.
  • System Performance Problems: Your system may lock up due to both products attempting to access the same file at the same time.
I would like you to uninstall Kaspersky PURE 3.0 in part to rule out this program as a possible cause of your symptoms. You can do this via Add/Remove Programs, or Programs and Features in the Control Panel.

===================================================

Farbar Recovery Scan Tool (FRST)

--------------------
  • Download Farbar Recover Scan Tool for either 32 bit or 64 bit systems and save it to your desktop
  • If you are unsure if you have 32 bit or 64 bit simply download and try one. If that doesn't run properly the other one should
  • Double click the icon
  • Click Yes to the disclaimer
  • Make sure the Addition.txt box is checked
  • Click Scan and allow the program to run
  • Click OK on the Scan complete screen, then OK on the Addition.txt pop up screen
  • 2 Notepad documents should now be open on your desktop.
  • Please copy and paste the contents of both in your reply
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • Did Kaspersky unintall properly?
  • FRST results
  • Addition log
  • How is your computer running?

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"May you be richly rewarded by the Lord, the God of Israel, under whose wings you have come to take refuge."

#7 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,375 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:05:02 AM

Posted 01 January 2014 - 06:45 PM

Greetings,

===================================================

3 Day Bump

It has been more than 3 days since my last post.
  • Do you still need help with this?
  • If after 48hrs you have not replied to this thread then it will have to be closed.

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"May you be richly rewarded by the Lord, the God of Israel, under whose wings you have come to take refuge."

#8 nielsenja

nielsenja
  • Topic Starter

  • Members
  • 53 posts
  • OFFLINE
  •  
  • Local time:04:02 AM

Posted 02 January 2014 - 12:02 AM

  • Did Kaspersky unintall properly?
  • FRST results
  • Addition log
  • How is your computer running?

 

Kaspersky uninstalled just fine.  The problem existed before Kaspersky though, as I went out & paid big bucks for it once I discovered there was a problem.  Hopefully I will be able to continue using it?

 

Computer is running fine, although it didn't have performance issues to start with, only the redirect/connection issues, which were not resolved with the Kaspersky uninstall or with running FRST.

 

I apologise that I didn't respond faster, the notification e-mail did not get delivered to my inbox.  I have added it to my contacts & created a filter for it to prevent such a long delay again.

 

Thanks again!

 

FRST results:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-01-2014 01
Ran by Jon (administrator) on HOTMESS on 01-01-2014 20:56:16
Running from C:\Users\Jon\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US)
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe
(Spotify Ltd) C:\Users\Jon\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Curse) C:\Users\Jon\AppData\Local\Apps\2.0\OQ4KM2CA.Z6R\Q1EZAPQ6.JCT\curs..tion_9e9e83ddf3ed3ead_0005.0001_181b5e0542e9eb6c\CurseClient.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\Belkin\F9L1103\v1\Common\RaRegistry64.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\PrintIsolationHost.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [1266912 2013-10-23] (Microsoft Corporation)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-09-05] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKCU\...\Run: [Spotify Web Helper] - C:\Users\Jon\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1168896 2013-12-03] (Spotify Ltd)
Startup: C:\Users\Jon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip ()

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x13E43A97EFFACE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: E-Web Print - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\EPSON Software\E-Web Print\ewps_tb.dll (SEIKO EPSON CORPORATION)
BHO-x32: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM-x32 - E-Web Print - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\EPSON Software\E-Web Print\ewps_tb.dll (SEIKO EPSON CORPORATION)
DPF: HKLM-x32 {0D41B8C5-2599-4893-8183-00195EC8D5F9} http://support.asus.com/select/asusTek_sys_ctrl3.cab
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\office15\MSOSB.DLL (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254

FireFox:
========
FF ProfilePath: C:\Users\Jon\AppData\Roaming\Mozilla\Firefox\Profiles\d1oarrbu.default
FF user.js: detected! => C:\Users\Jon\AppData\Roaming\Mozilla\Firefox\Profiles\d1oarrbu.default\user.js
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\15.5.0\\npsitesafety.dll No File
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @logitech.com/HarmonyRemote,version=1.0.0 - C:\Program Files (x86)\Logitech\Harmony Remote Driver\NprtHarmonyPlugin.dll (Logitech Inc.)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @soe.sony.com/installer,version=1.0.3 - C:\Users\Jon\AppData\LocalLow\Sony Online Entertainment\npsoe.dll No File
FF Extension: Adblock Plus - C:\Users\Jon\AppData\Roaming\Mozilla\Firefox\Profiles\d1oarrbu.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF HKLM-x32\...\Firefox\Extensions: [e-webprint@epson.com] - C:\Program Files (x86)\Epson Software\E-Web Print\Firefox Add-on
FF Extension: E-Web Print - C:\Program Files (x86)\Epson Software\E-Web Print\Firefox Add-on
FF HKCU\...\Firefox\Extensions: [{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}] - C:\Program Files (x86)\Wajam\Firefox\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}.xpi

Chrome:
=======
CHR Extension: (Docs) - C:\Users\Jon\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0
CHR Extension: (Google Drive) - C:\Users\Jon\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0
CHR Extension: (YouTube) - C:\Users\Jon\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0
CHR Extension: (Google Search) - C:\Users\Jon\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0
CHR Extension: (Kaspersky URL Advisor) - C:\Users\Jon\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj\13.0.2.558_0
CHR Extension: (Password Manager plugin) - C:\Users\Jon\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdnahjkclbpahfnjmpcbacidgllghba\7.0.3.11
CHR Extension: (Safe Money) - C:\Users\Jon\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh\13.0.2.558_0
CHR Extension: (Content Blocker) - C:\Users\Jon\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail\13.0.2.614_0
CHR Extension: (Virtual Keyboard) - C:\Users\Jon\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh\13.0.2.614_0
CHR Extension: (MyHarmony Chrome Plugin) - C:\Users\Jon\AppData\Local\Google\Chrome\User Data\Default\Extensions\omaonpoimgkmbllpdihbnmgphjoipdhf\1.2.0.0_0
CHR Extension: (Gmail) - C:\Users\Jon\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR Extension: (Anti-Banner) - C:\Users\Jon\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman\13.0.2.558_0
CHR HKLM-x32\...\Chrome\Extension: [jpmbfleldcgkldadpdinhjjopdfpjfjp] - C:\Users\Jon\AppData\Local\Wajam\Chrome\wajam.crx
CHR HKLM-x32\...\Chrome\Extension: [ndibdjnfmopecpmkdieinmbadjfpblof] - C:\ProgramData\\ChromeExt\\avg.crx
CHR HKLM-x32\...\Chrome\Extension: [omaonpoimgkmbllpdihbnmgphjoipdhf] - C:\Program Files (x86)\Logitech\Harmony Remote Driver\harmony_chrome.crx

==================== Services (Whitelisted) =================

S4 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-12-19] (Advanced Micro Devices, Inc.)
S4 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [135824 2011-12-11] (Seiko Epson Corporation)
S4 Fitbit Connect; C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe [1239584 2013-02-25] (Fitbit, Inc.)
S4 MediaMall Server; C:\Program Files (x86)\MediaMall\MediaMallServer.exe [4038448 2013-06-11] (MediaMall Technologies, Inc.)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2013-10-23] (Microsoft Corporation)
R2 MSSQL$SQLEXPRESSEFILM; c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [29293408 2010-12-10] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [348376 2013-10-23] (Microsoft Corporation)
R2 OfficeSvc; C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [1907896 2013-11-02] (Microsoft Corporation)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [75136 2013-03-21] ()
R2 RalinkRegistryWriter64; C:\Program Files (x86)\Belkin\F9L1103\v1\Common\RaRegistry64.exe [447488 2012-07-04] (Ralink Technology, Corp.)
S4 WSWNA3100; C:\Program Files (x86)\NETGEAR\WNA3100\WifiSvc.exe [303360 2011-12-07] ()
S2 vToolbarUpdater15.5.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\ToolbarUpdater.exe [x]

==================== Drivers (Whitelisted) ====================

R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [13368 2009-04-06] ()
R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [45856 2013-09-01] (AVG Technologies)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [248240 2013-09-27] (Microsoft Corporation)
R3 msvad_simple; C:\Windows\System32\drivers\povrtdev.sys [28528 2012-11-02] (MediaMall Technologies, Inc.)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15416 2009-05-14] ()
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [134944 2013-09-27] (Microsoft Corporation)
R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-13] (Brother Industries Ltd.)
R3 SSMO4Filter; C:\Windows\System32\drivers\MO4Driver.sys [21504 2011-07-27] (Sagatek Co. Ltd.)
S3 ALSysIO; \??\C:\Users\Jon\AppData\Local\Temp\ALSysIO64.sys [x]
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-13] (Microsoft Corporation)
S3 catchme; \??\C:\asdf\catchme.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-01-01 20:56 - 2014-01-01 20:56 - 00012618 _____ C:\Users\Jon\Desktop\FRST.txt
2014-01-01 20:56 - 2014-01-01 20:56 - 00000000 ____D C:\FRST
2014-01-01 20:55 - 2014-01-01 20:55 - 01931426 _____ (Farbar) C:\Users\Jon\Desktop\FRST64.exe
2014-01-01 20:38 - 2014-01-01 20:38 - 00292024 _____ C:\Windows\Minidump\010114-25927-01.dmp
2013-12-27 16:28 - 2013-12-27 16:28 - 01518819 _____ C:\Users\Jon\Desktop\Walmart backup.zip
2013-12-27 16:27 - 2013-12-27 16:27 - 00003051 _____ C:\Users\Jon\Desktop\mSecure.lnk
2013-12-27 16:27 - 2013-12-27 16:27 - 00000000 ____D C:\Users\Jon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\mSeven Software
2013-12-27 16:27 - 2013-12-27 16:27 - 00000000 ____D C:\Users\Jon\AppData\Local\Downloaded Installations
2013-12-27 16:27 - 2013-12-27 16:27 - 00000000 ____D C:\Program Files (x86)\mSeven Software
2013-12-27 16:26 - 2013-12-27 16:26 - 04969044 _____ C:\Users\Jon\Downloads\mSecureWindows3.5.1.zip
2013-12-20 06:44 - 2013-12-20 06:44 - 00292024 _____ C:\Windows\Minidump\122013-17830-01.dmp
2013-12-19 17:50 - 2013-12-19 19:02 - 00000000 ____D C:\Users\Jon\Desktop\Pictures for Digital Frames
2013-12-18 16:28 - 2013-12-18 16:28 - 00292024 _____ C:\Windows\Minidump\121813-21980-01.dmp
2013-12-17 10:29 - 2013-12-17 10:29 - 00292024 _____ C:\Windows\Minidump\121713-23088-01.dmp
2013-12-16 22:19 - 2013-12-16 22:20 - 00819136 _____ (Google Inc.) C:\Users\Jon\Desktop\googledrivesync.exe
2013-12-16 22:15 - 2013-12-16 22:15 - 00002219 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-12-16 21:58 - 2013-12-16 21:58 - 01339005 _____ C:\ComboFix.txt
2013-12-16 21:45 - 2013-12-16 21:58 - 00000000 ____D C:\Qoobox
2013-12-16 21:45 - 2013-12-16 21:56 - 00000000 ____D C:\Windows\erdnt
2013-12-16 21:45 - 2011-06-25 22:45 - 00256000 _____ C:\Windows\PEV.exe
2013-12-16 21:45 - 2010-11-07 09:20 - 00208896 _____ C:\Windows\MBR.exe
2013-12-16 21:45 - 2009-04-19 20:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-12-16 21:45 - 2000-08-30 16:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-12-16 21:45 - 2000-08-30 16:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-12-16 21:45 - 2000-08-30 16:00 - 00098816 _____ C:\Windows\sed.exe
2013-12-16 21:45 - 2000-08-30 16:00 - 00080412 _____ C:\Windows\grep.exe
2013-12-16 21:45 - 2000-08-30 16:00 - 00068096 _____ C:\Windows\zip.exe
2013-12-16 21:43 - 2013-12-16 21:44 - 05154128 ____R (Swearware) C:\Users\Jon\Desktop\asdf.exe
2013-12-16 20:38 - 2013-12-16 20:38 - 00819136 _____ (Google Inc.) C:\Users\Jon\Downloads\googledrivesync.exe
2013-12-15 19:13 - 2013-05-09 21:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2013-12-15 19:13 - 2013-05-09 21:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2013-12-15 19:13 - 2013-05-09 20:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2013-12-15 19:13 - 2013-05-09 20:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2013-12-15 19:10 - 2013-11-14 17:37 - 02334720 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-12-15 19:10 - 2013-11-14 17:29 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-12-15 19:10 - 2013-11-14 17:29 - 01347072 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-12-15 19:10 - 2013-11-14 17:28 - 01494528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-12-15 19:10 - 2013-11-14 17:28 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-12-15 19:10 - 2013-11-14 17:25 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-12-15 19:10 - 2013-11-14 17:22 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-12-15 19:10 - 2013-11-14 17:20 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-12-15 19:10 - 2013-11-14 17:20 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-12-15 19:10 - 2013-11-14 17:19 - 02147840 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-12-15 19:10 - 2013-11-14 17:19 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-12-15 19:10 - 2013-11-14 17:18 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-12-15 19:10 - 2013-11-14 17:18 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-12-15 19:10 - 2013-11-14 17:12 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-12-15 19:10 - 2013-11-14 15:13 - 12344320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-12-15 19:10 - 2013-11-14 14:50 - 01806848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-12-15 19:10 - 2013-11-14 14:43 - 01105408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-12-15 19:10 - 2013-11-14 14:42 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-12-15 19:10 - 2013-11-14 14:42 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-12-15 19:10 - 2013-11-14 14:41 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-12-15 19:10 - 2013-11-14 14:40 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-12-15 19:10 - 2013-11-14 14:38 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-12-15 19:10 - 2013-11-14 14:38 - 00420864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-12-15 19:10 - 2013-11-14 14:38 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-12-15 19:10 - 2013-11-14 14:37 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-12-15 19:10 - 2013-11-14 14:36 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-12-15 19:10 - 2013-11-14 14:36 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-12-15 19:10 - 2013-11-14 14:35 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-12-15 19:10 - 2013-11-14 14:32 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-12-15 19:09 - 2013-11-14 18:09 - 17847296 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-12-15 19:09 - 2013-11-14 17:42 - 10926080 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-12-15 19:09 - 2013-11-14 14:50 - 09739264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-12-15 19:02 - 2013-12-15 19:02 - 00292024 _____ C:\Windows\Minidump\121513-19983-01.dmp
2013-12-11 00:32 - 2013-11-23 10:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-12-11 00:32 - 2013-11-23 09:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-12-11 00:32 - 2013-10-29 18:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2013-12-11 00:32 - 2013-10-29 18:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
2013-12-11 00:32 - 2013-10-29 17:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-12-11 00:31 - 2013-11-11 18:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-12-11 00:31 - 2013-11-11 18:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-12-11 00:31 - 2013-10-18 18:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2013-12-11 00:31 - 2013-10-18 17:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2013-12-11 00:31 - 2013-10-11 18:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2013-12-11 00:31 - 2013-10-11 18:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2013-12-11 00:31 - 2013-10-11 18:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
2013-12-11 00:31 - 2013-10-11 18:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2013-12-11 00:31 - 2013-10-11 17:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2013-12-11 00:31 - 2013-10-11 17:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2013-12-11 00:31 - 2013-10-11 17:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
2013-12-11 00:31 - 2013-10-11 17:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2013-12-11 00:31 - 2013-10-03 18:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2013-12-11 00:31 - 2013-10-03 17:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2013-12-10 00:17 - 2013-12-10 00:18 - 00292024 _____ C:\Windows\Minidump\121013-20264-01.dmp
2013-12-06 14:25 - 2013-12-06 14:25 - 00292024 _____ C:\Windows\Minidump\120613-21933-01.dmp
2013-12-03 12:54 - 2014-01-01 20:44 - 00082266 _____ C:\Windows\IE11_main.log
2013-12-03 12:49 - 2013-12-03 12:49 - 00292024 _____ C:\Windows\Minidump\120313-19375-01.dmp
2013-12-03 10:36 - 2013-12-03 10:36 - 00292024 _____ C:\Windows\Minidump\120313-17955-01.dmp

==================== One Month Modified Files and Folders =======

2014-01-01 20:56 - 2014-01-01 20:56 - 00012618 _____ C:\Users\Jon\Desktop\FRST.txt
2014-01-01 20:56 - 2014-01-01 20:56 - 00000000 ____D C:\FRST
2014-01-01 20:56 - 2013-08-31 23:48 - 01947136 _____ C:\Windows\WindowsUpdate.log
2014-01-01 20:55 - 2014-01-01 20:55 - 01931426 _____ (Farbar) C:\Users\Jon\Desktop\FRST64.exe
2014-01-01 20:55 - 2009-07-13 20:45 - 00021888 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-01 20:55 - 2009-07-13 20:45 - 00021888 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-01 20:53 - 2013-09-10 13:34 - 00000000 ____D C:\Users\Jon\AppData\Local\Deployment
2014-01-01 20:53 - 2013-09-04 22:15 - 00044704 _____ C:\Windows\setupact.log
2014-01-01 20:53 - 2012-07-02 23:09 - 00000888 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-01 20:53 - 2012-05-28 21:38 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-01 20:53 - 2009-07-13 21:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-01 20:52 - 2013-09-05 10:29 - 00037220 _____ C:\Windows\PFRO.log
2014-01-01 20:52 - 2013-09-02 19:40 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2014-01-01 20:51 - 2013-09-03 22:49 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2014-01-01 20:45 - 2009-07-13 21:13 - 00807114 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-01 20:44 - 2013-12-03 12:54 - 00082266 _____ C:\Windows\IE11_main.log
2014-01-01 20:43 - 2013-08-31 09:08 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2014-01-01 20:40 - 2012-05-28 21:38 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-01-01 20:40 - 2012-05-28 21:38 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-01-01 20:40 - 2011-12-03 12:27 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-01-01 20:38 - 2014-01-01 20:38 - 00292024 _____ C:\Windows\Minidump\010114-25927-01.dmp
2014-01-01 20:38 - 2013-09-30 16:28 - 882455860 _____ C:\Windows\MEMORY.DMP
2014-01-01 20:38 - 2011-12-03 10:10 - 00000000 ____D C:\Windows\Minidump
2013-12-29 02:03 - 2012-07-02 23:09 - 00000892 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-12-27 16:28 - 2013-12-27 16:28 - 01518819 _____ C:\Users\Jon\Desktop\Walmart backup.zip
2013-12-27 16:28 - 2012-07-02 23:12 - 00000000 ___SD C:\Users\Jon\Google Drive
2013-12-27 16:27 - 2013-12-27 16:27 - 00003051 _____ C:\Users\Jon\Desktop\mSecure.lnk
2013-12-27 16:27 - 2013-12-27 16:27 - 00000000 ____D C:\Users\Jon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\mSeven Software
2013-12-27 16:27 - 2013-12-27 16:27 - 00000000 ____D C:\Users\Jon\AppData\Local\Downloaded Installations
2013-12-27 16:27 - 2013-12-27 16:27 - 00000000 ____D C:\Program Files (x86)\mSeven Software
2013-12-27 16:26 - 2013-12-27 16:26 - 04969044 _____ C:\Users\Jon\Downloads\mSecureWindows3.5.1.zip
2013-12-20 06:44 - 2013-12-20 06:44 - 00292024 _____ C:\Windows\Minidump\122013-17830-01.dmp
2013-12-20 06:44 - 2009-07-13 21:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2013-12-19 22:18 - 2012-07-23 22:19 - 00000000 ____D C:\Users\Jon\AppData\Roaming\Spotify
2013-12-19 19:02 - 2013-12-19 17:50 - 00000000 ____D C:\Users\Jon\Desktop\Pictures for Digital Frames
2013-12-19 18:18 - 2013-09-13 18:10 - 00000000 ____D C:\Users\Jon\AppData\Local\Spotify
2013-12-18 16:28 - 2013-12-18 16:28 - 00292024 _____ C:\Windows\Minidump\121813-21980-01.dmp
2013-12-18 10:36 - 2013-09-06 11:58 - 00000000 ____D C:\Users\Jon\AppData\Local\Battle.net
2013-12-17 10:29 - 2013-12-17 10:29 - 00292024 _____ C:\Windows\Minidump\121713-23088-01.dmp
2013-12-16 22:20 - 2013-12-16 22:19 - 00819136 _____ (Google Inc.) C:\Users\Jon\Desktop\googledrivesync.exe
2013-12-16 22:15 - 2013-12-16 22:15 - 00002219 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-12-16 22:15 - 2013-09-05 10:26 - 00000000 ____D C:\Users\Jon\AppData\Local\Google
2013-12-16 22:15 - 2012-07-02 23:09 - 00000000 ____D C:\Program Files (x86)\Google
2013-12-16 21:58 - 2013-12-16 21:58 - 01339005 _____ C:\ComboFix.txt
2013-12-16 21:58 - 2013-12-16 21:45 - 00000000 ____D C:\Qoobox
2013-12-16 21:58 - 2013-09-05 10:17 - 00000000 ____D C:\Users\Jon\AppData\Local\Apps\2.0
2013-12-16 21:56 - 2013-12-16 21:45 - 00000000 ____D C:\Windows\erdnt
2013-12-16 21:53 - 2009-07-13 18:34 - 00000215 _____ C:\Windows\system.ini
2013-12-16 21:52 - 2009-07-13 18:34 - 87556096 _____ C:\Windows\system32\config\software.bak
2013-12-16 21:52 - 2009-07-13 18:34 - 19398656 _____ C:\Windows\system32\config\system.bak
2013-12-16 21:52 - 2009-07-13 18:34 - 05242880 _____ C:\Windows\system32\config\default.bak
2013-12-16 21:52 - 2009-07-13 18:34 - 00262144 _____ C:\Windows\system32\config\security.bak
2013-12-16 21:52 - 2009-07-13 18:34 - 00262144 _____ C:\Windows\system32\config\sam.bak
2013-12-16 21:44 - 2013-12-16 21:43 - 05154128 ____R (Swearware) C:\Users\Jon\Desktop\asdf.exe
2013-12-16 21:41 - 2011-12-02 19:45 - 00000000 ____D C:\Users\Jon
2013-12-16 20:38 - 2013-12-16 20:38 - 00819136 _____ (Google Inc.) C:\Users\Jon\Downloads\googledrivesync.exe
2013-12-16 09:24 - 2013-09-06 11:59 - 00000000 ____D C:\Program Files (x86)\Hearthstone
2013-12-16 03:01 - 2013-08-14 02:01 - 00000000 ____D C:\Windows\system32\MRT
2013-12-16 03:00 - 2011-12-02 20:09 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-12-15 21:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\rescache
2013-12-15 20:17 - 2013-09-06 11:57 - 00000000 ____D C:\Program Files (x86)\Battle.net
2013-12-15 20:16 - 2013-09-10 18:48 - 00000000 ____D C:\Program Files (x86)\StarCraft II
2013-12-15 20:16 - 2012-05-15 23:39 - 00000000 ____D C:\Program Files (x86)\Diablo III
2013-12-15 20:16 - 2011-12-02 20:03 - 00000000 ____D C:\Program Files (x86)\World of Warcraft
2013-12-15 19:32 - 2009-07-13 20:45 - 00435720 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-15 19:18 - 2013-03-14 19:25 - 00000000 ____D C:\Program Files\Microsoft Office 15
2013-12-15 19:12 - 2012-01-07 15:34 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-12-15 19:02 - 2013-12-15 19:02 - 00292024 _____ C:\Windows\Minidump\121513-19983-01.dmp
2013-12-10 00:18 - 2013-12-10 00:17 - 00292024 _____ C:\Windows\Minidump\121013-20264-01.dmp
2013-12-06 14:58 - 2012-07-02 23:09 - 00003888 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-12-06 14:58 - 2012-07-02 23:09 - 00003636 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-12-06 14:25 - 2013-12-06 14:25 - 00292024 _____ C:\Windows\Minidump\120613-21933-01.dmp
2013-12-03 12:58 - 2013-09-03 23:06 - 00000000 ___SD C:\Users\Jon\Documents\Passwords Database
2013-12-03 12:49 - 2013-12-03 12:49 - 00292024 _____ C:\Windows\Minidump\120313-19375-01.dmp
2013-12-03 10:36 - 2013-12-03 10:36 - 00292024 _____ C:\Windows\Minidump\120313-17955-01.dmp

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-12-27 10:26

==================== End Of Log ============================

 

Addition.txt:

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 01-01-2014 01
Ran by Jon at 2014-01-01 20:57:04
Running from C:\Users\Jon\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}

==================== Installed Programs ======================

Adobe AIR (x32 Version: 3.4.0.2540 - Adobe Systems Incorporated)
Adobe AIR (x32 Version: 3.4.0.2540 - Adobe Systems Incorporated) Hidden
Adobe Flash Player 11 ActiveX (x32 Version: 11.8.800.94 - Adobe Systems Incorporated)
Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.170 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.05) (x32 Version: 11.0.05 - Adobe Systems Incorporated)
AMD Accelerated Video Transcoding (Version: 12.5.100.21219 - Advanced Micro Devices, Inc.) Hidden
AMD APP SDK Runtime (Version: 10.0.1084.4 - Advanced Micro Devices Inc.) Hidden
AMD Catalyst Install Manager (Version: 8.0.903.0 - Advanced Micro Devices, Inc.)
AMD Drag and Drop Transcoding (Version: 2.00.0000 - Advanced Micro Devices, Inc.) Hidden
AMD Fuel (Version: 2012.1219.1521.27485 - Advanced Micro Devices, Inc.) Hidden
AMD Media Foundation Decoders (Version: 1.0.71219.1540 - Advanced Micro Devices, Inc.) Hidden
AMD VISION Engine Control Center (x32 Version: 2012.1219.1521.27485 - Advanced Micro Devices, Inc.) Hidden
Application Profiles (x32 Version: 2.0.4331.36041 - Advanced Micro Devices, Inc.) Hidden
Battle.net (x32 Version:  - Blizzard Entertainment)
Belkin N750 Dual Band Wireless USB Adapter (x32 Version: 1.5.11.0 - Belkin International, Inc.)
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Graphics Previews Common (x32 Version: 2012.1219.1521.27485 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2011.1109.2212.39826 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2012.1219.1521.27485 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2012.1219.1521.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Standard (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Traditional (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Czech (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Danish (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Dutch (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help English (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Finnish (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help French (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help German (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Greek (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Hungarian (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Italian (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Japanese (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Korean (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Norwegian (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Polish (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Portuguese (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Russian (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Spanish (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Swedish (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Thai (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Turkish (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
ccc-utility64 (Version: 2012.1219.1521.27485 - Advanced Micro Devices, Inc.) Hidden
CCleaner (Version: 4.05 - Piriform)
Cisco EAP-FAST Module (x32 Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (x32 Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (x32 Version: 1.1.6 - Cisco Systems, Inc.)
Core Temp version 0.99.7 (Version: 0.99.7 - Arthur Liberman)
Curse Client (HKCU Version: 5.1.1.792 - Curse)
DC Universe Online Live (HKCU Version:  - Sony Online Entertainment)
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (x32 Version:  - Microsoft)
Diablo III (x32 Version:  - Blizzard Entertainment)
Epson Connect Printer Setup (x32 Version: 1.1.1 - SEIKO EPSON CORPORATION)
EPSON Connect version 1.0 (x32 Version: 1.0 - Epson America Inc.)
Epson Customer Participation (Version: 1.4.0.0 - SEIKO EPSON CORPORATION)
Epson Event Manager (x32 Version: 3.01.0003 - Seiko Epson Corporation)
Epson E-Web Print (x32 Version: 1.17.0000 - SEIKO EPSON CORPORATION)
Epson FAX Utility (x32 Version: 1.31.00 - SEIKO EPSON CORPORATION)
EPSON Printer Finder (x32 Version: 1.0.0 - SEIKO EPSON CORPORATION)
EPSON Remote Print Uninstall (Version:  - SEIKO EPSON Corporation)
EPSON Scan (x32 Version:  - Seiko Epson Corporation)
EPSON WF-3530 Series Printer Uninstall (Version:  - SEIKO EPSON Corporation)
EpsonNet Print (x32 Version: 2.5.00 - SEIKO EPSON CORPORATION)
Fitbit Connect (x32 Version: 1.0.0.2578 - Fitbit Inc.)
GameFly (x32 Version: 1.1.918 - GameFly, Inc.) Hidden
Google Chrome (x32 Version: 31.0.1650.63 - Google Inc.)
Google Drive (x32 Version: 1.13.5782.599 - Google, Inc.)
Google Update Helper (x32 Version: 1.3.22.3 - Google Inc.) Hidden
Guild Wars 2 (x32 Version:  - NCsoft Corporation, Ltd.)
Harmony Browser Plug-in (x32 Version: 2.0 - Logitech)
Hearthstone (x32 Version:  - Blizzard Entertainment)
Java 7 Update 45 (x32 Version: 7.0.450 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
Logitech Gaming Software (Version: 8.20.74 - Logitech Inc.) Hidden
Malwarebytes Anti-Malware version 1.75.0.1300 (x32 Version: 1.75.0.1300 - Malwarebytes Corporation)
Microsoft .NET Framework 1.1 (x32 Version:  - )
Microsoft .NET Framework 1.1 (x32 Version: 1.1.4322 - Microsoft) Hidden
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft Office Access MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Access Setup Metadata MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Home and Student 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Spanish) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared Setup Metadata MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Single Image 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Publisher 2013 - en-us (Version: 15.0.4551.1011 - Microsoft Corporation)
Microsoft Security Client (Version: 4.4.0304.0 - Microsoft Corporation) Hidden
Microsoft Security Essentials (Version: 4.4.304.0 - Microsoft Corporation)
Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation)
Microsoft SQL Server 2005 (x32 Version:  - Microsoft Corporation)
Microsoft SQL Server 2005 Express Edition (SQLEXPRESSEFILM) (x32 Version: 9.4.5000.00 - Microsoft Corporation) Hidden
Microsoft SQL Server 2005 Tools Express Edition (x32 Version: 9.4.5000.00 - Microsoft Corporation) Hidden
Microsoft SQL Server Native Client (Version: 9.00.5000.00 - Microsoft Corporation)
Microsoft SQL Server Setup Support Files (English) (x32 Version: 9.00.5000.00 - Microsoft Corporation)
Microsoft SQL Server VSS Writer (Version: 9.00.5000.00 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation)
Mozilla Firefox 26.0 (x86 en-US) (x32 Version: 26.0 - Mozilla)
Mozilla Maintenance Service (x32 Version: 26.0 - Mozilla)
mSecure (x32 Version: 3.133 - mSeven Software LLC)
MSXML 4.0 SP3 Parser (KB2721691) (x32 Version: 4.30.2114.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (x32 Version: 4.30.2117.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB973685) (x32 Version: 4.30.2107.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (x32 Version: 4.30.2100.0 - Microsoft Corporation)
Mumble 1.2.3 (x32 Version: 1.2.3 - Thorvald Natvig)
NETGEAR WNA3100 wireless USB 2.0 adapter (x32 Version: 1.01.206 - NETGEAR)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4551.1011 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4551.1011 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4551.1011 - Microsoft Corporation) Hidden
Origin (x32 Version: 9.1.10.2728 - Electronic Arts, Inc.)
PlayOn (x32 Version: 3.6.16 - MediaMall Technologies, Inc.)
QuickTime (x32 Version: 7.74.80.86 - Apple Inc.)
RIFT (HKCU Version:  - Trion Worlds, Inc.)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32 Version:  - Microsoft) Hidden
SimCity™ (x32 Version: 1.0.0.0 - Electronic Arts)
Software Updater (x32 Version: 4.1.7 - SEIKO EPSON CORPORATION)
Spotify (HKCU Version: 0.9.6.81.gd359a796 - Spotify AB)
Star Trek Away Team (x32 Version:  - )
Star Trek Bridge Commander (x32 Version:  - )
Star Trek Legacy (x32 Version: 1.00.0000 - Bethesda Softworks)
Star Trek Online (x32 Version:  - Cryptic Studios)
Star Trek Voyager Elite Force (x32 Version:  - )
Star Wars: Knights of the Old Republic (x32 Version:  - BioWare)
Star Wars: Knights of the Old Republic II (x32 Version:  - LucasArts)
Star Wars: The Old Republic (x32 Version: 1.00 - Electronic Arts, Inc.)
StarCraft II (x32 Version:  - Blizzard Entertainment)
Steam (x32 Version: 1.0.0.0 - Valve Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3 - Microsoft Corporation)
Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2810071) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2826026) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft OneNote 2010 (KB2810072) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Word 2010 (KB2837593) 32-Bit Edition (x32 Version:  - Microsoft)
Ventrilo Client for Windows x64 (Version: 3.0.8.0 - Flagship Industries, Inc.)
Visual Studio 2010 x64 Redistributables (Version: 13.0.0.1 - AVG Technologies)
VLC media player 2.1.0 (x32 Version: 2.1.0 - VideoLAN)
Windows Media Player Firefox Plugin (x32 Version: 1.0.0.8 - Microsoft Corp)
World of Warcraft (x32 Version:  - Blizzard Entertainment)
ZoneAlarm Antivirus (x32 Version: 11.0.780.000 - Check Point Software Technologies Ltd.) Hidden

==================== Restore Points  =========================

18-12-2013 11:00:14 Windows Update
19-12-2013 08:11:18 Windows Update
20-12-2013 14:47:49 Windows Update
20-12-2013 15:10:04 Windows Update
27-12-2013 17:33:31 Windows Update
28-12-2013 00:27:34 Installed mSecure.
28-12-2013 11:00:13 Windows Update
02-01-2014 04:42:51 Windows Update

==================== Hosts content: ==========================

2009-07-13 18:34 - 2013-12-16 21:53 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost

==================== Scheduled Tasks (whitelisted) =============

Task: {0FD6B6E2-D107-483A-B135-1D61760EDACF} - System32\Tasks\{0C0D86BF-E207-4D1D-86D8-A9892F0FFCF0} => D:\setup.exe [2012-11-20] (Belkin International, Inc.)
Task: {1D268369-4BD5-4CE8-9C95-DEA29869B539} - System32\Tasks\{8BC0139A-7A20-418F-A931-D9850AAFD196} => D:\AUTORUN.EXE
Task: {21BD284A-0434-4F44-B4B6-4C8EBDC1FC9B} - System32\Tasks\{1D71A954-1552-4DA2-8DD3-715D107270AC} => D:\AUTORUN.EXE
Task: {24D2AEEE-C055-47FA-A027-E8AFB6832CBA} - System32\Tasks\{20128B30-C097-459D-8FEC-EA93FF2DD911} => C:\Program Files (x86)\Activision\Bridge Commander\stbc.exe [2002-04-09] ()
Task: {2B7FBB5B-0C50-4183-B1CB-3437708B129B} - System32\Tasks\{ACF6C4B1-626E-460E-B399-C30FBF9DC4F1} => D:\setup.exe [2012-11-20] (Belkin International, Inc.)
Task: {2FDF5496-1103-4ED4-9CCA-1A5AE84D0E02} - System32\Tasks\{435E228C-6160-41F1-81EE-3FACC4291502} => D:\setup.exe [2012-11-20] (Belkin International, Inc.)
Task: {30318F08-4E61-4C4E-856E-220B55B9FF2C} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-08-21] (Piriform Ltd)
Task: {366FE686-3015-40DF-9479-8F7362AF72D8} - System32\Tasks\{191EE59F-73B8-4DC2-A10F-6A81A6719DDA} => D:\setup.exe [2012-11-20] (Belkin International, Inc.)
Task: {39541455-BCC3-49AE-B4F4-44FD7BCD977B} - System32\Tasks\{EC018763-6894-4358-97D7-6148591888F2} => C:\Program Files (x86)\Activision\Bridge Commander\stbc.exe [2002-04-09] ()
Task: {3C682B5B-9F7B-46B3-ABFC-28F500B7969C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-07-02] (Google Inc.)
Task: {46E58112-815A-4609-9DB7-48630E870518} - System32\Tasks\{E0FF6EFF-6165-486C-8F8F-DC0ABE47A6F4} => D:\setup.exe [2012-11-20] (Belkin International, Inc.)
Task: {5291C48C-BA5B-4FC3-8ADB-E078BCF41330} - System32\Tasks\{23DF2C0D-5391-406E-B13E-1F42C7A5C50A} => C:\Windows\System32\msiexec.exe [2010-11-20] (Microsoft Corporation)
Task: {5C75073E-165D-45E5-90CD-95B700A2555C} - System32\Tasks\{E3FDA37C-ABF6-4F06-AC1E-CEE1684A0602} => C:\Program Files (x86)\Activision\Bridge Commander\stbc.exe [2002-04-09] ()
Task: {5D67F3CB-B827-4F47-A6CE-5053CE173595} - System32\Tasks\{DFF6B731-415D-472E-B3AF-EEF635E03A0C} => D:\AUTORUN.EXE
Task: {6CB1F39A-C8C1-4D39-A2ED-39E2FEE68911} - System32\Tasks\{6D6ECFCA-2CCC-4BB8-8D29-592A15E5C9A7} => D:\demo32.exe
Task: {6DAB7AE6-5053-4494-93FC-7C6798B87675} - System32\Tasks\{DFF267A8-4F9E-4BAC-95B4-8ECD8D505493} => D:\AUTORUN.EXE
Task: {71789361-55CA-416A-BE9D-7AD7C33D1B1F} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-07-02] (Google Inc.)
Task: {73086B20-5FC5-4A64-A703-DA0FD1EF3A79} - System32\Tasks\{1193C870-D62E-49B5-970B-7A616A5F1980} => D:\AUTORUN.EXE
Task: {73A4DF58-22BA-4ECF-B55F-E77D7DFA7C70} - System32\Tasks\Adobe online update program => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-09-05] (Adobe Systems Incorporated)
Task: {7413F819-AB49-4835-9E92-7C607448FE44} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office 15\root\office15\msoia.exe [2013-11-14] (Microsoft Corporation)
Task: {7519BAE0-6421-4301-85EA-C8D253BEDD44} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [2013-11-02] (Microsoft Corporation)
Task: {7B2E3834-7A1C-4998-9D98-A27DFAE8CD6C} - System32\Tasks\{79321915-AA07-4808-8C36-14A092613568} => D:\AUTORUN.EXE
Task: {7EFC71AD-AF17-4257-A5AB-CB08FE6A4322} - System32\Tasks\{764825EE-5C2B-4F2E-AE25-FD92D95CB154} => D:\AUTORUN.EXE
Task: {9143157E-59F4-4707-87FE-E98CA502FCC4} - System32\Tasks\{F070EBE3-3D2A-403E-9EF2-EA2EC645925E} => D:\setup.exe [2012-11-20] (Belkin International, Inc.)
Task: {9509D16A-B482-4993-9FDD-ADE5113DF434} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-01-01] (Adobe Systems Incorporated)
Task: {96213A40-FE5A-4A72-84C2-3859E9C321AE} - System32\Tasks\Apple Diagnostics => C:\Program Files (x86)\Common Files\Apple\Internet Services\EReporter.exe
Task: {9A068C3B-49F3-4641-8EE5-6515743604C6} - System32\Tasks\{2A17AEA3-EB3F-483C-B6BD-B17ED0D44AC0} => D:\eFilmLt.exe
Task: {9B4EAC72-4A36-4AAF-80AE-A19B70FEB705} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02] (Oracle Corporation)
Task: {9ECA5633-D167-49BB-9408-DB1B9234C3D7} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office 15\root\office15\msoia.exe [2013-11-14] (Microsoft Corporation)
Task: {9F3330D4-EAD3-4D56-ADF6-47ED70974F51} - System32\Tasks\{1D4475FB-0EB0-4362-B029-73CE303F34A8} => D:\setup.exe [2012-11-20] (Belkin International, Inc.)
Task: {A00D5D90-9153-463E-A07E-0CBB888940E8} - System32\Tasks\{7F8B1557-D9A0-42FE-9D81-52DF6DADC3C5} => D:\setup.exe [2012-11-20] (Belkin International, Inc.)
Task: {A4035522-1116-4162-BB6A-81B711E28949} - System32\Tasks\{B89D1B00-B922-40A7-BC45-0257651F5C71} => D:\setup.exe [2012-11-20] (Belkin International, Inc.)
Task: {C302FA64-6433-4548-A721-48685E69FF0E} - System32\Tasks\RunOW => C:\Program Files (x86)\Overwolf\OverwolfLauncher.exe
Task: {C957894C-D494-460C-A571-3F8E39AAEB1F} - System32\Tasks\{D1F99E1A-DDA4-4020-8BB9-7D8A981DFC7F} => D:\setup.exe [2012-11-20] (Belkin International, Inc.)
Task: {CA232402-0EE6-467C-B38B-238391DACA02} - System32\Tasks\Google Updater and Installer => C:\Users\Jon\AppData\Local\Google\Update\GoogleUpdate.exe
Task: {CD3082EE-4062-4C03-94DD-5622CFF5D54C} - System32\Tasks\{0F917514-76EA-45DD-95DA-ECB440A11700} => D:\Setup\Setup.exe
Task: {D2AED5B2-EC4F-45D7-80AD-E12FEE956202} - System32\Tasks\{52871E41-E292-4733-96FC-4B80FDC7026C} => D:\AUTORUN.EXE
Task: {D9C23DFC-5C9B-4EE1-BC7C-D8A6D11DF2DC} - System32\Tasks\{AE8487CC-9861-431F-BE59-1D8FAE958E5D} => D:\AUTORUN.EXE
Task: {DDB48931-067D-4F1C-95E0-3CB02A276517} - System32\Tasks\{84588442-F272-4E63-920B-EF23D3258F81} => D:\setup.exe [2012-11-20] (Belkin International, Inc.)
Task: {E5FB4D68-36B4-4A8F-9132-66BC480ACDD2} - System32\Tasks\{0FA15343-EA9D-4E13-9FD7-5FDFC7978908} => D:\setup.exe [2012-11-20] (Belkin International, Inc.)
Task: {EB67F209-F7C5-4824-9825-856002186B81} - System32\Tasks\{71CED9D7-6FD1-4AEC-A17A-6FD2B464EA73} => D:\AUTORUN.EXE
Task: {EF4F6E8B-937E-453E-87FC-7A85A5BE1484} - System32\Tasks\Core Temp Autostart => C:\Program Files\Core Temp\Core Temp.exe [2010-07-02] ()
Task: {EFE72344-37AA-4EF0-94C6-B9E12A397A9D} - System32\Tasks\{F570E7A4-017C-4F76-93C5-A3E88F37E0EA} => D:\eFilmLt.exe
Task: {FC6352FB-C549-4F61-BCD3-B1DA4FB5D235} - System32\Tasks\{11967EE9-5D0F-4974-90CE-36C8CE74E635} => D:\AUTORUN.EXE
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe <==== ATTENTION
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe <==== ATTENTION

==================== Loaded Modules (whitelisted) =============

2013-11-14 03:45 - 2013-11-14 03:45 - 08866472 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2013-12-16 22:03 - 2013-12-16 22:02 - 00014848 _____ () C:\Users\Jon\AppData\Local\Apps\2.0\OQ4KM2CA.Z6R\Q1EZAPQ6.JCT\curs..tion_9e9e83ddf3ed3ead_0005.0001_181b5e0542e9eb6c\Curse.CurseClient.WowDb.dll
2013-12-16 22:03 - 2013-12-16 22:02 - 00035840 _____ () C:\Users\Jon\AppData\Local\Apps\2.0\OQ4KM2CA.Z6R\Q1EZAPQ6.JCT\curs..tion_9e9e83ddf3ed3ead_0005.0001_181b5e0542e9eb6c\Curse.Advertising.dll
2013-09-02 19:39 - 2014-01-01 20:43 - 03559024 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\ProgramData\TEMP:5C321E34

==================== Safe Mode (whitelisted) ===================


==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (01/01/2014 08:54:43 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/01/2014 08:40:20 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (12/27/2013 09:33:38 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (12/20/2013 06:45:49 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (12/19/2013 04:43:55 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (12/18/2013 04:29:48 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (12/17/2013 10:30:46 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (12/16/2013 10:02:20 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (12/16/2013 09:54:52 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (12/16/2013 09:45:33 PM) (Source: System Restore) (User: )
Description: Failed to create restore point (Process = C:\Windows\system32\wbem\wmiprvse.exe; Description = ComboFix created restore point; Error = 0x8007043c).


System errors:
=============
Error: (01/01/2014 08:54:15 PM) (Source: DCOM) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

Error: (01/01/2014 08:53:33 PM) (Source: Service Control Manager) (User: )
Description: The vToolbarUpdater15.5.0 service failed to start due to the following error:
%%2

Error: (01/01/2014 08:53:15 PM) (Source: Service Control Manager) (User: )
Description: The AODDriver4.2 service failed to start due to the following error:
%%2

Error: (01/01/2014 08:44:56 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80070643: Internet Explorer 11 for Windows 7 for x64-based Systems.

Error: (01/01/2014 08:40:01 PM) (Source: DCOM) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

Error: (01/01/2014 08:39:02 PM) (Source: Service Control Manager) (User: )
Description: The vToolbarUpdater15.5.0 service failed to start due to the following error:
%%2

Error: (01/01/2014 08:38:58 PM) (Source: Service Control Manager) (User: )
Description: The AODDriver4.2 service failed to start due to the following error:
%%2

Error: (01/01/2014 08:38:49 PM) (Source: BugCheck) (User: )
Description: 0x00000001 (0x000000007749132a, 0x0000000000000000, 0x000000000000ffff, 0xfffff88007ed2ca0)C:\Windows\MEMORY.DMP010114-25927-01

Error: (01/01/2014 08:38:49 PM) (Source: EventLog) (User: )
Description: The previous system shutdown at 2:35:28 AM on ‎12/‎29/‎2013 was unexpected.

Error: (12/28/2013 03:01:16 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80070643: Internet Explorer 11 for Windows 7 for x64-based Systems.


Microsoft Office Sessions:
=========================
Error: (01/01/2014 08:54:43 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/01/2014 08:40:20 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (12/27/2013 09:33:38 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (12/20/2013 06:45:49 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (12/19/2013 04:43:55 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (12/18/2013 04:29:48 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (12/17/2013 10:30:46 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (12/16/2013 10:02:20 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (12/16/2013 09:54:52 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (12/16/2013 09:45:33 PM) (Source: System Restore)(User: )
Description: C:\Windows\system32\wbem\wmiprvse.exeComboFix created restore point0x8007043c


CodeIntegrity Errors:
===================================
  Date: 2013-12-29 00:31:05.380
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.

  Date: 2013-12-29 00:31:05.380
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.

  Date: 2013-12-29 00:31:05.380
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.

  Date: 2013-12-29 00:31:05.380
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\KLELAMX64\klelam.sys because the set of per-page image hashes could not be found on the system.

  Date: 2013-12-29 00:31:05.380
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\KLELAMX64\klelam.sys because the set of per-page image hashes could not be found on the system.

  Date: 2013-12-29 00:31:05.380
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\KLELAMX64\klelam.sys because the set of per-page image hashes could not be found on the system.

  Date: 2013-12-28 00:30:15.990
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.

  Date: 2013-12-28 00:30:15.989
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.

  Date: 2013-12-28 00:30:15.987
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.

  Date: 2013-12-28 00:30:15.980
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\KLELAMX64\klelam.sys because the set of per-page image hashes could not be found on the system.


==================== Memory info ===========================

Percentage of memory in use: 29%
Total physical RAM: 8190.05 MB
Available physical RAM: 5787.84 MB
Total Pagefile: 16378.29 MB
Available Pagefile: 13924.43 MB
Total Virtual: 8192 MB
Available Virtual: 8191.76 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:465.66 GB) (Free:182.73 GB) NTFS
Drive d: (Belkin F9L1103v1) (CDROM) (Total:0.09 GB) (Free:0 GB) CDFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 3ED682B0)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=466 GB) - (Type=07 NTFS)

==================== End Of Log ============================



#9 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,375 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:05:02 AM

Posted 04 January 2014 - 07:03 PM

Greetings,

I am very sorry for the extended delay as I was never notified you replied. If I ever fail to reply to you in 24 hours don't hesitate to send me a Private Message to let me know you posted.

Please run these for me.

===================================================

Farbar's Recovery Scan Tool - Run Fix in Normal or Safe Mode

--------------------
  • Press the windows key Windows_Logo_key.gif + r on your keyboard at the same time. Type in notepad and press Enter
  • Please copy and paste the contents of the below code box into the open notepad and save it to your desktop (<<<Important) as fixlist.txt
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
FF user.js: detected! => C:\Users\Jon\AppData\Roaming\Mozilla\Firefox\Profiles\d1oarrbu.default\user.js
FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\15.5.0\\npsitesafety.dll No File
FF Plugin HKCU: @soe.sony.com/installer,version=1.0.3 - C:\Users\Jon\AppData\LocalLow\Sony Online Entertainment\npsoe.dll No File
CHR HKLM-x32\...\Chrome\Extension: [ndibdjnfmopecpmkdieinmbadjfpblof] - C:\ProgramData\\ChromeExt\\avg.crx
CHR HKLM-x32\...\Chrome\Extension: [omaonpoimgkmbllpdihbnmgphjoipdhf] - C:\Program Files (x86)\Logitech\Harmony Remote Driver\harmony_chrome.crx
AlternateDataStreams: C:\ProgramData\TEMP:5C321E34
Task: {0FD6B6E2-D107-483A-B135-1D61760EDACF} - System32\Tasks\{0C0D86BF-E207-4D1D-86D8-A9892F0FFCF0} => D:\setup.exe [2012-11-20] (Belkin International, Inc.)
Task: {1D268369-4BD5-4CE8-9C95-DEA29869B539} - System32\Tasks\{8BC0139A-7A20-418F-A931-D9850AAFD196} => D:\AUTORUN.EXE
Task: {21BD284A-0434-4F44-B4B6-4C8EBDC1FC9B} - System32\Tasks\{1D71A954-1552-4DA2-8DD3-715D107270AC} => D:\AUTORUN.EXE
Task: {5D67F3CB-B827-4F47-A6CE-5053CE173595} - System32\Tasks\{DFF6B731-415D-472E-B3AF-EEF635E03A0C} => D:\AUTORUN.EXE
Task: {6CB1F39A-C8C1-4D39-A2ED-39E2FEE68911} - System32\Tasks\{6D6ECFCA-2CCC-4BB8-8D29-592A15E5C9A7} => D:\demo32.exe
Task: {6DAB7AE6-5053-4494-93FC-7C6798B87675} - System32\Tasks\{DFF267A8-4F9E-4BAC-95B4-8ECD8D505493} => D:\AUTORUN.EXE
Task: {73086B20-5FC5-4A64-A703-DA0FD1EF3A79} - System32\Tasks\{1193C870-D62E-49B5-970B-7A616A5F1980} => D:\AUTORUN.EXE
Task: {7B2E3834-7A1C-4998-9D98-A27DFAE8CD6C} - System32\Tasks\{79321915-AA07-4808-8C36-14A092613568} => D:\AUTORUN.EXE
Task: {7EFC71AD-AF17-4257-A5AB-CB08FE6A4322} - System32\Tasks\{764825EE-5C2B-4F2E-AE25-FD92D95CB154} => D:\AUTORUN.EXE
Task: {9143157E-59F4-4707-87FE-E98CA502FCC4} - System32\Tasks\{F070EBE3-3D2A-403E-9EF2-EA2EC645925E} => D:\setup.exe [2012-11-20] (Belkin International, Inc.)
Task: {9A068C3B-49F3-4641-8EE5-6515743604C6} - System32\Tasks\{2A17AEA3-EB3F-483C-B6BD-B17ED0D44AC0} => D:\eFilmLt.exe
Task: {CD3082EE-4062-4C03-94DD-5622CFF5D54C} - System32\Tasks\{0F917514-76EA-45DD-95DA-ECB440A11700} => D:\Setup\Setup.exe
Task: {D2AED5B2-EC4F-45D7-80AD-E12FEE956202} - System32\Tasks\{52871E41-E292-4733-96FC-4B80FDC7026C} => D:\AUTORUN.EXE
Task: {D9C23DFC-5C9B-4EE1-BC7C-D8A6D11DF2DC} - System32\Tasks\{AE8487CC-9861-431F-BE59-1D8FAE958E5D} => D:\AUTORUN.EXE
Task: {DDB48931-067D-4F1C-95E0-3CB02A276517} - System32\Tasks\{84588442-F272-4E63-920B-EF23D3258F81} => D:\setup.exe [2012-11-20] (Belkin International, Inc.)
Task: {E5FB4D68-36B4-4A8F-9132-66BC480ACDD2} - System32\Tasks\{0FA15343-EA9D-4E13-9FD7-5FDFC7978908} => D:\setup.exe [2012-11-20] (Belkin International, Inc.)
Task: {EB67F209-F7C5-4824-9825-856002186B81} - System32\Tasks\{71CED9D7-6FD1-4AEC-A17A-6FD2B464EA73} => D:\AUTORUN.EXE
Task: {EFE72344-37AA-4EF0-94C6-B9E12A397A9D} - System32\Tasks\{F570E7A4-017C-4F76-93C5-A3E88F37E0EA} => D:\eFilmLt.exe
Task: {FC6352FB-C549-4F61-BCD3-B1DA4FB5D235} - System32\Tasks\{11967EE9-5D0F-4974-90CE-36C8CE74E635} => D:\AUTORUN.EXE
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe <==== ATTENTION
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe <==== ATTENTION
  • Launch FRST and press the Fix button just once and wait, the program will automatically launch fixlist.txt.
  • The tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
===================================================

Please download and run Microsoft Fix it 50688.

===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • Fixlog
  • Did the Microsoft Fix run properly?

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"May you be richly rewarded by the Lord, the God of Israel, under whose wings you have come to take refuge."

#10 nielsenja

nielsenja
  • Topic Starter

  • Members
  • 53 posts
  • OFFLINE
  •  
  • Local time:04:02 AM

Posted 04 January 2014 - 09:23 PM

Yes, Microsoft Fix ran properly.

 

Here is the Fixlog:

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 04-01-2014
Ran by Jon at 2014-01-04 18:22:10 Run:1
Running from C:\Users\Jon\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
FF user.js: detected! => C:\Users\Jon\AppData\Roaming\Mozilla\Firefox\Profiles\d1oarrbu.default\user.js
FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\15.5.0\\npsitesafety.dll No File
FF Plugin HKCU: @soe.sony.com/installer,version=1.0.3 - C:\Users\Jon\AppData\LocalLow\Sony Online Entertainment\npsoe.dll No File
CHR HKLM-x32\...\Chrome\Extension: [ndibdjnfmopecpmkdieinmbadjfpblof] - C:\ProgramData\\ChromeExt\\avg.crx
CHR HKLM-x32\...\Chrome\Extension: [omaonpoimgkmbllpdihbnmgphjoipdhf] - C:\Program Files (x86)\Logitech\Harmony Remote Driver\harmony_chrome.crx
AlternateDataStreams: C:\ProgramData\TEMP:5C321E34
Task: {0FD6B6E2-D107-483A-B135-1D61760EDACF} - System32\Tasks\{0C0D86BF-E207-4D1D-86D8-A9892F0FFCF0} => D:\setup.exe [2012-11-20] (Belkin International, Inc.)
Task: {1D268369-4BD5-4CE8-9C95-DEA29869B539} - System32\Tasks\{8BC0139A-7A20-418F-A931-D9850AAFD196} => D:\AUTORUN.EXE
Task: {21BD284A-0434-4F44-B4B6-4C8EBDC1FC9B} - System32\Tasks\{1D71A954-1552-4DA2-8DD3-715D107270AC} => D:\AUTORUN.EXE
Task: {5D67F3CB-B827-4F47-A6CE-5053CE173595} - System32\Tasks\{DFF6B731-415D-472E-B3AF-EEF635E03A0C} => D:\AUTORUN.EXE
Task: {6CB1F39A-C8C1-4D39-A2ED-39E2FEE68911} - System32\Tasks\{6D6ECFCA-2CCC-4BB8-8D29-592A15E5C9A7} => D:\demo32.exe
Task: {6DAB7AE6-5053-4494-93FC-7C6798B87675} - System32\Tasks\{DFF267A8-4F9E-4BAC-95B4-8ECD8D505493} => D:\AUTORUN.EXE
Task: {73086B20-5FC5-4A64-A703-DA0FD1EF3A79} - System32\Tasks\{1193C870-D62E-49B5-970B-7A616A5F1980} => D:\AUTORUN.EXE
Task: {7B2E3834-7A1C-4998-9D98-A27DFAE8CD6C} - System32\Tasks\{79321915-AA07-4808-8C36-14A092613568} => D:\AUTORUN.EXE
Task: {7EFC71AD-AF17-4257-A5AB-CB08FE6A4322} - System32\Tasks\{764825EE-5C2B-4F2E-AE25-FD92D95CB154} => D:\AUTORUN.EXE
Task: {9143157E-59F4-4707-87FE-E98CA502FCC4} - System32\Tasks\{F070EBE3-3D2A-403E-9EF2-EA2EC645925E} => D:\setup.exe [2012-11-20] (Belkin International, Inc.)
Task: {9A068C3B-49F3-4641-8EE5-6515743604C6} - System32\Tasks\{2A17AEA3-EB3F-483C-B6BD-B17ED0D44AC0} => D:\eFilmLt.exe
Task: {CD3082EE-4062-4C03-94DD-5622CFF5D54C} - System32\Tasks\{0F917514-76EA-45DD-95DA-ECB440A11700} => D:\Setup\Setup.exe
Task: {D2AED5B2-EC4F-45D7-80AD-E12FEE956202} - System32\Tasks\{52871E41-E292-4733-96FC-4B80FDC7026C} => D:\AUTORUN.EXE
Task: {D9C23DFC-5C9B-4EE1-BC7C-D8A6D11DF2DC} - System32\Tasks\{AE8487CC-9861-431F-BE59-1D8FAE958E5D} => D:\AUTORUN.EXE
Task: {DDB48931-067D-4F1C-95E0-3CB02A276517} - System32\Tasks\{84588442-F272-4E63-920B-EF23D3258F81} => D:\setup.exe [2012-11-20] (Belkin International, Inc.)
Task: {E5FB4D68-36B4-4A8F-9132-66BC480ACDD2} - System32\Tasks\{0FA15343-EA9D-4E13-9FD7-5FDFC7978908} => D:\setup.exe [2012-11-20] (Belkin International, Inc.)
Task: {EB67F209-F7C5-4824-9825-856002186B81} - System32\Tasks\{71CED9D7-6FD1-4AEC-A17A-6FD2B464EA73} => D:\AUTORUN.EXE
Task: {EFE72344-37AA-4EF0-94C6-B9E12A397A9D} - System32\Tasks\{F570E7A4-017C-4F76-93C5-A3E88F37E0EA} => D:\eFilmLt.exe
Task: {FC6352FB-C549-4F61-BCD3-B1DA4FB5D235} - System32\Tasks\{11967EE9-5D0F-4974-90CE-36C8CE74E635} => D:\AUTORUN.EXE
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe <==== ATTENTION
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe <==== ATTENTION
*****************

HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully.
C:\Users\Jon\AppData\Roaming\Mozilla\Firefox\Profiles\d1oarrbu.default\user.js => Moved successfully.
HKLM\Software\Wow6432Node\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin => Key deleted successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\15.5.0\\npsitesafety.dll not found.
HKCU\Software\MozillaPlugins\@soe.sony.com/installer,version=1.0.3 => Key deleted successfully.
C:\Users\Jon\AppData\LocalLow\Sony Online Entertainment\npsoe.dll not found.
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof => Key deleted successfully.
"C:\ProgramData\\ChromeExt\\avg.crx" => File/Directory not found.
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\omaonpoimgkmbllpdihbnmgphjoipdhf => Key deleted successfully.
C:\Program Files (x86)\Logitech\Harmony Remote Driver\harmony_chrome.crx => Moved successfully.
C:\ProgramData\TEMP => ":5C321E34" ADS removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0FD6B6E2-D107-483A-B135-1D61760EDACF} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0FD6B6E2-D107-483A-B135-1D61760EDACF} => Key deleted successfully.
C:\Windows\System32\Tasks\{0C0D86BF-E207-4D1D-86D8-A9892F0FFCF0} => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{0C0D86BF-E207-4D1D-86D8-A9892F0FFCF0} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1D268369-4BD5-4CE8-9C95-DEA29869B539} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1D268369-4BD5-4CE8-9C95-DEA29869B539} => Key deleted successfully.
C:\Windows\System32\Tasks\{8BC0139A-7A20-418F-A931-D9850AAFD196} => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{8BC0139A-7A20-418F-A931-D9850AAFD196} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{21BD284A-0434-4F44-B4B6-4C8EBDC1FC9B} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{21BD284A-0434-4F44-B4B6-4C8EBDC1FC9B} => Key deleted successfully.
C:\Windows\System32\Tasks\{1D71A954-1552-4DA2-8DD3-715D107270AC} => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{1D71A954-1552-4DA2-8DD3-715D107270AC} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5D67F3CB-B827-4F47-A6CE-5053CE173595} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5D67F3CB-B827-4F47-A6CE-5053CE173595} => Key deleted successfully.
C:\Windows\System32\Tasks\{DFF6B731-415D-472E-B3AF-EEF635E03A0C} => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{DFF6B731-415D-472E-B3AF-EEF635E03A0C} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6CB1F39A-C8C1-4D39-A2ED-39E2FEE68911} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6CB1F39A-C8C1-4D39-A2ED-39E2FEE68911} => Key deleted successfully.
C:\Windows\System32\Tasks\{6D6ECFCA-2CCC-4BB8-8D29-592A15E5C9A7} => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{6D6ECFCA-2CCC-4BB8-8D29-592A15E5C9A7} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6DAB7AE6-5053-4494-93FC-7C6798B87675} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6DAB7AE6-5053-4494-93FC-7C6798B87675} => Key deleted successfully.
C:\Windows\System32\Tasks\{DFF267A8-4F9E-4BAC-95B4-8ECD8D505493} => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{DFF267A8-4F9E-4BAC-95B4-8ECD8D505493} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{73086B20-5FC5-4A64-A703-DA0FD1EF3A79} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{73086B20-5FC5-4A64-A703-DA0FD1EF3A79} => Key deleted successfully.
C:\Windows\System32\Tasks\{1193C870-D62E-49B5-970B-7A616A5F1980} => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{1193C870-D62E-49B5-970B-7A616A5F1980} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7B2E3834-7A1C-4998-9D98-A27DFAE8CD6C} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7B2E3834-7A1C-4998-9D98-A27DFAE8CD6C} => Key deleted successfully.
C:\Windows\System32\Tasks\{79321915-AA07-4808-8C36-14A092613568} => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{79321915-AA07-4808-8C36-14A092613568} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7EFC71AD-AF17-4257-A5AB-CB08FE6A4322} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7EFC71AD-AF17-4257-A5AB-CB08FE6A4322} => Key deleted successfully.
C:\Windows\System32\Tasks\{764825EE-5C2B-4F2E-AE25-FD92D95CB154} => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{764825EE-5C2B-4F2E-AE25-FD92D95CB154} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9143157E-59F4-4707-87FE-E98CA502FCC4} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9143157E-59F4-4707-87FE-E98CA502FCC4} => Key deleted successfully.
C:\Windows\System32\Tasks\{F070EBE3-3D2A-403E-9EF2-EA2EC645925E} => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{F070EBE3-3D2A-403E-9EF2-EA2EC645925E} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9A068C3B-49F3-4641-8EE5-6515743604C6} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9A068C3B-49F3-4641-8EE5-6515743604C6} => Key deleted successfully.
C:\Windows\System32\Tasks\{2A17AEA3-EB3F-483C-B6BD-B17ED0D44AC0} => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{2A17AEA3-EB3F-483C-B6BD-B17ED0D44AC0} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CD3082EE-4062-4C03-94DD-5622CFF5D54C} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CD3082EE-4062-4C03-94DD-5622CFF5D54C} => Key deleted successfully.
C:\Windows\System32\Tasks\{0F917514-76EA-45DD-95DA-ECB440A11700} => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{0F917514-76EA-45DD-95DA-ECB440A11700} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D2AED5B2-EC4F-45D7-80AD-E12FEE956202} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D2AED5B2-EC4F-45D7-80AD-E12FEE956202} => Key deleted successfully.
C:\Windows\System32\Tasks\{52871E41-E292-4733-96FC-4B80FDC7026C} => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{52871E41-E292-4733-96FC-4B80FDC7026C} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D9C23DFC-5C9B-4EE1-BC7C-D8A6D11DF2DC} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D9C23DFC-5C9B-4EE1-BC7C-D8A6D11DF2DC} => Key deleted successfully.
C:\Windows\System32\Tasks\{AE8487CC-9861-431F-BE59-1D8FAE958E5D} => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{AE8487CC-9861-431F-BE59-1D8FAE958E5D} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DDB48931-067D-4F1C-95E0-3CB02A276517} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DDB48931-067D-4F1C-95E0-3CB02A276517} => Key deleted successfully.
C:\Windows\System32\Tasks\{84588442-F272-4E63-920B-EF23D3258F81} => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{84588442-F272-4E63-920B-EF23D3258F81} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E5FB4D68-36B4-4A8F-9132-66BC480ACDD2} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E5FB4D68-36B4-4A8F-9132-66BC480ACDD2} => Key deleted successfully.
C:\Windows\System32\Tasks\{0FA15343-EA9D-4E13-9FD7-5FDFC7978908} => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{0FA15343-EA9D-4E13-9FD7-5FDFC7978908} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EB67F209-F7C5-4824-9825-856002186B81} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EB67F209-F7C5-4824-9825-856002186B81} => Key deleted successfully.
C:\Windows\System32\Tasks\{71CED9D7-6FD1-4AEC-A17A-6FD2B464EA73} => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{71CED9D7-6FD1-4AEC-A17A-6FD2B464EA73} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EFE72344-37AA-4EF0-94C6-B9E12A397A9D} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EFE72344-37AA-4EF0-94C6-B9E12A397A9D} => Key deleted successfully.
C:\Windows\System32\Tasks\{F570E7A4-017C-4F76-93C5-A3E88F37E0EA} => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{F570E7A4-017C-4F76-93C5-A3E88F37E0EA} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FC6352FB-C549-4F61-BCD3-B1DA4FB5D235} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FC6352FB-C549-4F61-BCD3-B1DA4FB5D235} => Key deleted successfully.
C:\Windows\System32\Tasks\{11967EE9-5D0F-4974-90CE-36C8CE74E635} => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{11967EE9-5D0F-4974-90CE-36C8CE74E635} => Key deleted successfully.
C:\Windows\Tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.

==== End of Fixlog ====



#11 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,375 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:05:02 AM

Posted 04 January 2014 - 09:29 PM

How is your computer running? Any difference?
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"May you be richly rewarded by the Lord, the God of Israel, under whose wings you have come to take refuge."

#12 nielsenja

nielsenja
  • Topic Starter

  • Members
  • 53 posts
  • OFFLINE
  •  
  • Local time:04:02 AM

Posted 04 January 2014 - 09:31 PM

No change, unfortunately.



#13 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,375 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:05:02 AM

Posted 04 January 2014 - 09:35 PM

Please rerun FRST and post the fresh log.
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"May you be richly rewarded by the Lord, the God of Israel, under whose wings you have come to take refuge."

#14 nielsenja

nielsenja
  • Topic Starter

  • Members
  • 53 posts
  • OFFLINE
  •  
  • Local time:04:02 AM

Posted 04 January 2014 - 09:41 PM

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-01-2014
Ran by Jon (administrator) on HOTMESS on 04-01-2014 18:40:07
Running from C:\Users\Jon\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US)
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\Belkin\F9L1103\v1\Common\RaRegistry64.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Spotify Ltd) C:\Users\Jon\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Curse) C:\Users\Jon\AppData\Local\Apps\2.0\OQ4KM2CA.Z6R\Q1EZAPQ6.JCT\curs..tion_9e9e83ddf3ed3ead_0005.0001_181b5e0542e9eb6c\CurseClient.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Electronic Arts) C:\Program Files (x86)\Origin\Origin.exe
(Electronic Arts) C:\Program Files (x86)\Origin\OriginClientService.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [1266912 2013-10-23] (Microsoft Corporation)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-09-05] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKCU\...\Run: [Spotify Web Helper] - C:\Users\Jon\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1168896 2013-12-03] (Spotify Ltd)
Startup: C:\Users\Jon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip ()

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x13E43A97EFFACE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: E-Web Print - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\EPSON Software\E-Web Print\ewps_tb.dll (SEIKO EPSON CORPORATION)
BHO-x32: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM-x32 - E-Web Print - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\EPSON Software\E-Web Print\ewps_tb.dll (SEIKO EPSON CORPORATION)
DPF: HKLM-x32 {0D41B8C5-2599-4893-8183-00195EC8D5F9} http://support.asus.com/select/asusTek_sys_ctrl3.cab
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\office15\MSOSB.DLL (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254

FireFox:
========
FF ProfilePath: C:\Users\Jon\AppData\Roaming\Mozilla\Firefox\Profiles\d1oarrbu.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @logitech.com/HarmonyRemote,version=1.0.0 - C:\Program Files (x86)\Logitech\Harmony Remote Driver\NprtHarmonyPlugin.dll (Logitech Inc.)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: Adblock Plus - C:\Users\Jon\AppData\Roaming\Mozilla\Firefox\Profiles\d1oarrbu.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF HKLM-x32\...\Firefox\Extensions: [e-webprint@epson.com] - C:\Program Files (x86)\Epson Software\E-Web Print\Firefox Add-on
FF Extension: E-Web Print - C:\Program Files (x86)\Epson Software\E-Web Print\Firefox Add-on
FF HKCU\...\Firefox\Extensions: [{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}] - C:\Program Files (x86)\Wajam\Firefox\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}.xpi

Chrome:
=======
CHR Extension: (Docs) - C:\Users\Jon\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0
CHR Extension: (Google Drive) - C:\Users\Jon\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0
CHR Extension: (YouTube) - C:\Users\Jon\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0
CHR Extension: (Google Search) - C:\Users\Jon\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0
CHR Extension: (Password Manager plugin) - C:\Users\Jon\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdnahjkclbpahfnjmpcbacidgllghba\7.0.3.11
CHR Extension: (Gmail) - C:\Users\Jon\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR HKLM-x32\...\Chrome\Extension: [jpmbfleldcgkldadpdinhjjopdfpjfjp] - C:\Users\Jon\AppData\Local\Wajam\Chrome\wajam.crx

==================== Services (Whitelisted) =================

S4 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-12-19] (Advanced Micro Devices, Inc.)
S4 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [135824 2011-12-11] (Seiko Epson Corporation)
S4 Fitbit Connect; C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe [1239584 2013-02-25] (Fitbit, Inc.)
S4 MediaMall Server; C:\Program Files (x86)\MediaMall\MediaMallServer.exe [4038448 2013-06-11] (MediaMall Technologies, Inc.)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2013-10-23] (Microsoft Corporation)
R2 MSSQL$SQLEXPRESSEFILM; c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [29293408 2010-12-10] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [348376 2013-10-23] (Microsoft Corporation)
R2 OfficeSvc; C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [1907896 2013-11-02] (Microsoft Corporation)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [75136 2013-03-21] ()
R2 RalinkRegistryWriter64; C:\Program Files (x86)\Belkin\F9L1103\v1\Common\RaRegistry64.exe [447488 2012-07-04] (Ralink Technology, Corp.)
S4 WSWNA3100; C:\Program Files (x86)\NETGEAR\WNA3100\WifiSvc.exe [303360 2011-12-07] ()
S2 vToolbarUpdater15.5.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\ToolbarUpdater.exe [x]

==================== Drivers (Whitelisted) ====================

R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [13368 2009-04-06] ()
R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [45856 2013-09-01] (AVG Technologies)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [248240 2013-09-27] (Microsoft Corporation)
R3 msvad_simple; C:\Windows\System32\drivers\povrtdev.sys [28528 2012-11-02] (MediaMall Technologies, Inc.)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15416 2009-05-14] ()
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [134944 2013-09-27] (Microsoft Corporation)
R3 SSMO4Filter; C:\Windows\System32\drivers\MO4Driver.sys [21504 2011-07-27] (Sagatek Co. Ltd.)
S3 ALSysIO; \??\C:\Users\Jon\AppData\Local\Temp\ALSysIO64.sys [x]
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-13] (Microsoft Corporation)
S3 catchme; \??\C:\asdf\catchme.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-01-04 18:22 - 2014-01-04 18:22 - 00671232 _____ C:\Users\Jon\Desktop\MicrosoftFixit50688.msi
2014-01-04 18:22 - 2014-01-04 18:22 - 00000000 ____D C:\Users\Jon\Desktop\FRST-OlderVersion
2014-01-04 16:57 - 2014-01-04 16:57 - 00000000 ____D C:\Users\Jon\Documents\Electronic Arts
2014-01-04 16:47 - 2014-01-04 16:47 - 00001351 _____ C:\Users\Public\Desktop\The Sims Medieval.lnk
2014-01-03 15:49 - 2014-01-03 15:49 - 00275544 _____ C:\Windows\Minidump\010314-18829-01.dmp
2014-01-01 20:56 - 2014-01-04 18:40 - 00010891 _____ C:\Users\Jon\Desktop\FRST.txt
2014-01-01 20:56 - 2014-01-04 18:22 - 00000000 ____D C:\FRST
2014-01-01 20:55 - 2014-01-04 18:22 - 01931368 _____ (Farbar) C:\Users\Jon\Desktop\FRST64.exe
2014-01-01 20:38 - 2014-01-01 20:38 - 00292024 _____ C:\Windows\Minidump\010114-25927-01.dmp
2013-12-27 16:28 - 2013-12-27 16:28 - 01518819 _____ C:\Users\Jon\Desktop\Walmart backup.zip
2013-12-27 16:27 - 2013-12-27 16:27 - 00003051 _____ C:\Users\Jon\Desktop\mSecure.lnk
2013-12-27 16:27 - 2013-12-27 16:27 - 00000000 ____D C:\Users\Jon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\mSeven Software
2013-12-27 16:27 - 2013-12-27 16:27 - 00000000 ____D C:\Users\Jon\AppData\Local\Downloaded Installations
2013-12-27 16:27 - 2013-12-27 16:27 - 00000000 ____D C:\Program Files (x86)\mSeven Software
2013-12-27 16:26 - 2013-12-27 16:26 - 04969044 _____ C:\Users\Jon\Downloads\mSecureWindows3.5.1.zip
2013-12-20 06:44 - 2013-12-20 06:44 - 00292024 _____ C:\Windows\Minidump\122013-17830-01.dmp
2013-12-19 17:50 - 2013-12-19 19:02 - 00000000 ____D C:\Users\Jon\Desktop\Pictures for Digital Frames
2013-12-18 16:28 - 2013-12-18 16:28 - 00292024 _____ C:\Windows\Minidump\121813-21980-01.dmp
2013-12-17 10:29 - 2013-12-17 10:29 - 00292024 _____ C:\Windows\Minidump\121713-23088-01.dmp
2013-12-16 22:19 - 2013-12-16 22:20 - 00819136 _____ (Google Inc.) C:\Users\Jon\Desktop\googledrivesync.exe
2013-12-16 22:15 - 2013-12-16 22:15 - 00002219 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-12-16 21:58 - 2013-12-16 21:58 - 01339005 _____ C:\ComboFix.txt
2013-12-16 21:45 - 2013-12-16 21:58 - 00000000 ____D C:\Qoobox
2013-12-16 21:45 - 2013-12-16 21:56 - 00000000 ____D C:\Windows\erdnt
2013-12-16 21:45 - 2011-06-25 22:45 - 00256000 _____ C:\Windows\PEV.exe
2013-12-16 21:45 - 2010-11-07 09:20 - 00208896 _____ C:\Windows\MBR.exe
2013-12-16 21:45 - 2009-04-19 20:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-12-16 21:45 - 2000-08-30 16:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-12-16 21:45 - 2000-08-30 16:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-12-16 21:45 - 2000-08-30 16:00 - 00098816 _____ C:\Windows\sed.exe
2013-12-16 21:45 - 2000-08-30 16:00 - 00080412 _____ C:\Windows\grep.exe
2013-12-16 21:45 - 2000-08-30 16:00 - 00068096 _____ C:\Windows\zip.exe
2013-12-16 21:43 - 2013-12-16 21:44 - 05154128 ____R (Swearware) C:\Users\Jon\Desktop\asdf.exe
2013-12-16 20:38 - 2013-12-16 20:38 - 00819136 _____ (Google Inc.) C:\Users\Jon\Downloads\googledrivesync.exe
2013-12-15 19:13 - 2013-05-09 21:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2013-12-15 19:13 - 2013-05-09 21:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2013-12-15 19:13 - 2013-05-09 20:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2013-12-15 19:13 - 2013-05-09 20:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2013-12-15 19:10 - 2013-11-14 17:37 - 02334720 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-12-15 19:10 - 2013-11-14 17:29 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-12-15 19:10 - 2013-11-14 17:29 - 01347072 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-12-15 19:10 - 2013-11-14 17:28 - 01494528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-12-15 19:10 - 2013-11-14 17:28 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-12-15 19:10 - 2013-11-14 17:25 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-12-15 19:10 - 2013-11-14 17:22 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-12-15 19:10 - 2013-11-14 17:20 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-12-15 19:10 - 2013-11-14 17:20 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-12-15 19:10 - 2013-11-14 17:19 - 02147840 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-12-15 19:10 - 2013-11-14 17:19 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-12-15 19:10 - 2013-11-14 17:18 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-12-15 19:10 - 2013-11-14 17:18 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-12-15 19:10 - 2013-11-14 17:12 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-12-15 19:10 - 2013-11-14 15:13 - 12344320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-12-15 19:10 - 2013-11-14 14:50 - 01806848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-12-15 19:10 - 2013-11-14 14:43 - 01105408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-12-15 19:10 - 2013-11-14 14:42 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-12-15 19:10 - 2013-11-14 14:42 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-12-15 19:10 - 2013-11-14 14:41 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-12-15 19:10 - 2013-11-14 14:40 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-12-15 19:10 - 2013-11-14 14:38 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-12-15 19:10 - 2013-11-14 14:38 - 00420864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-12-15 19:10 - 2013-11-14 14:38 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-12-15 19:10 - 2013-11-14 14:37 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-12-15 19:10 - 2013-11-14 14:36 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-12-15 19:10 - 2013-11-14 14:36 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-12-15 19:10 - 2013-11-14 14:35 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-12-15 19:10 - 2013-11-14 14:32 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-12-15 19:09 - 2013-11-14 18:09 - 17847296 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-12-15 19:09 - 2013-11-14 17:42 - 10926080 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-12-15 19:09 - 2013-11-14 14:50 - 09739264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-12-15 19:02 - 2013-12-15 19:02 - 00292024 _____ C:\Windows\Minidump\121513-19983-01.dmp
2013-12-11 00:32 - 2013-11-23 10:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-12-11 00:32 - 2013-11-23 09:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-12-11 00:32 - 2013-10-29 18:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2013-12-11 00:32 - 2013-10-29 18:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
2013-12-11 00:32 - 2013-10-29 17:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-12-11 00:31 - 2013-11-11 18:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-12-11 00:31 - 2013-11-11 18:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-12-11 00:31 - 2013-10-18 18:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2013-12-11 00:31 - 2013-10-18 17:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2013-12-11 00:31 - 2013-10-11 18:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2013-12-11 00:31 - 2013-10-11 18:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2013-12-11 00:31 - 2013-10-11 18:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
2013-12-11 00:31 - 2013-10-11 18:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2013-12-11 00:31 - 2013-10-11 17:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2013-12-11 00:31 - 2013-10-11 17:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2013-12-11 00:31 - 2013-10-11 17:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
2013-12-11 00:31 - 2013-10-11 17:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2013-12-11 00:31 - 2013-10-03 18:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2013-12-11 00:31 - 2013-10-03 17:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2013-12-10 00:17 - 2013-12-10 00:18 - 00292024 _____ C:\Windows\Minidump\121013-20264-01.dmp
2013-12-06 14:25 - 2013-12-06 14:25 - 00292024 _____ C:\Windows\Minidump\120613-21933-01.dmp

==================== One Month Modified Files and Folders =======

2014-01-04 18:40 - 2014-01-01 20:56 - 00010891 _____ C:\Users\Jon\Desktop\FRST.txt
2014-01-04 18:24 - 2013-08-31 23:48 - 01301140 _____ C:\Windows\WindowsUpdate.log
2014-01-04 18:22 - 2014-01-04 18:22 - 00671232 _____ C:\Users\Jon\Desktop\MicrosoftFixit50688.msi
2014-01-04 18:22 - 2014-01-04 18:22 - 00000000 ____D C:\Users\Jon\Desktop\FRST-OlderVersion
2014-01-04 18:22 - 2014-01-01 20:56 - 00000000 ____D C:\FRST
2014-01-04 18:22 - 2014-01-01 20:55 - 01931368 _____ (Farbar) C:\Users\Jon\Desktop\FRST64.exe
2014-01-04 17:14 - 2013-03-19 20:55 - 00000000 ____D C:\Program Files (x86)\Origin
2014-01-04 17:10 - 2013-03-19 21:00 - 00000000 ____D C:\Program Files (x86)\Origin Games
2014-01-04 16:57 - 2014-01-04 16:57 - 00000000 ____D C:\Users\Jon\Documents\Electronic Arts
2014-01-04 16:47 - 2014-01-04 16:47 - 00001351 _____ C:\Users\Public\Desktop\The Sims Medieval.lnk
2014-01-04 16:46 - 2011-12-02 23:14 - 00853700 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2014-01-04 16:46 - 2009-07-13 21:13 - 00853700 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-04 16:44 - 2013-09-25 21:15 - 00133448 _____ C:\Windows\DirectX.log
2014-01-04 14:08 - 2013-09-05 10:39 - 00000000 ____D C:\Users\Jon\AppData\Local\Origin
2014-01-04 14:08 - 2013-03-19 21:00 - 00000000 ____D C:\Users\Jon\AppData\Roaming\Origin
2014-01-04 14:08 - 2013-03-19 20:55 - 00000000 ____D C:\ProgramData\Origin
2014-01-04 13:30 - 2013-09-04 22:15 - 00045208 _____ C:\Windows\setupact.log
2014-01-04 03:00 - 2013-12-03 12:54 - 00099561 _____ C:\Windows\IE11_main.log
2014-01-03 15:58 - 2009-07-13 20:45 - 00021888 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-03 15:58 - 2009-07-13 20:45 - 00021888 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-03 15:50 - 2013-09-10 13:34 - 00000000 ____D C:\Users\Jon\AppData\Local\Deployment
2014-01-03 15:50 - 2009-07-13 21:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-03 15:49 - 2014-01-03 15:49 - 00275544 _____ C:\Windows\Minidump\010314-18829-01.dmp
2014-01-03 15:49 - 2013-09-30 16:28 - 765990100 _____ C:\Windows\MEMORY.DMP
2014-01-03 15:49 - 2011-12-03 10:10 - 00000000 ____D C:\Windows\Minidump
2014-01-01 20:52 - 2013-09-05 10:29 - 00037220 _____ C:\Windows\PFRO.log
2014-01-01 20:52 - 2013-09-02 19:40 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2014-01-01 20:51 - 2013-09-03 22:49 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2014-01-01 20:43 - 2013-08-31 09:08 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2014-01-01 20:40 - 2012-05-28 21:38 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-01-01 20:40 - 2012-05-28 21:38 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-01-01 20:40 - 2011-12-03 12:27 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-01-01 20:38 - 2014-01-01 20:38 - 00292024 _____ C:\Windows\Minidump\010114-25927-01.dmp
2013-12-27 16:28 - 2013-12-27 16:28 - 01518819 _____ C:\Users\Jon\Desktop\Walmart backup.zip
2013-12-27 16:28 - 2012-07-02 23:12 - 00000000 ___SD C:\Users\Jon\Google Drive
2013-12-27 16:27 - 2013-12-27 16:27 - 00003051 _____ C:\Users\Jon\Desktop\mSecure.lnk
2013-12-27 16:27 - 2013-12-27 16:27 - 00000000 ____D C:\Users\Jon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\mSeven Software
2013-12-27 16:27 - 2013-12-27 16:27 - 00000000 ____D C:\Users\Jon\AppData\Local\Downloaded Installations
2013-12-27 16:27 - 2013-12-27 16:27 - 00000000 ____D C:\Program Files (x86)\mSeven Software
2013-12-27 16:26 - 2013-12-27 16:26 - 04969044 _____ C:\Users\Jon\Downloads\mSecureWindows3.5.1.zip
2013-12-20 06:44 - 2013-12-20 06:44 - 00292024 _____ C:\Windows\Minidump\122013-17830-01.dmp
2013-12-20 06:44 - 2009-07-13 21:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2013-12-19 22:18 - 2012-07-23 22:19 - 00000000 ____D C:\Users\Jon\AppData\Roaming\Spotify
2013-12-19 19:02 - 2013-12-19 17:50 - 00000000 ____D C:\Users\Jon\Desktop\Pictures for Digital Frames
2013-12-19 18:18 - 2013-09-13 18:10 - 00000000 ____D C:\Users\Jon\AppData\Local\Spotify
2013-12-18 16:28 - 2013-12-18 16:28 - 00292024 _____ C:\Windows\Minidump\121813-21980-01.dmp
2013-12-18 10:36 - 2013-09-06 11:58 - 00000000 ____D C:\Users\Jon\AppData\Local\Battle.net
2013-12-17 10:29 - 2013-12-17 10:29 - 00292024 _____ C:\Windows\Minidump\121713-23088-01.dmp
2013-12-16 22:20 - 2013-12-16 22:19 - 00819136 _____ (Google Inc.) C:\Users\Jon\Desktop\googledrivesync.exe
2013-12-16 22:15 - 2013-12-16 22:15 - 00002219 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-12-16 22:15 - 2013-09-05 10:26 - 00000000 ____D C:\Users\Jon\AppData\Local\Google
2013-12-16 22:15 - 2012-07-02 23:09 - 00000000 ____D C:\Program Files (x86)\Google
2013-12-16 21:58 - 2013-12-16 21:58 - 01339005 _____ C:\ComboFix.txt
2013-12-16 21:58 - 2013-12-16 21:45 - 00000000 ____D C:\Qoobox
2013-12-16 21:58 - 2013-09-05 10:17 - 00000000 ____D C:\Users\Jon\AppData\Local\Apps\2.0
2013-12-16 21:56 - 2013-12-16 21:45 - 00000000 ____D C:\Windows\erdnt
2013-12-16 21:53 - 2009-07-13 18:34 - 00000215 _____ C:\Windows\system.ini
2013-12-16 21:52 - 2009-07-13 18:34 - 87556096 _____ C:\Windows\system32\config\software.bak
2013-12-16 21:52 - 2009-07-13 18:34 - 19398656 _____ C:\Windows\system32\config\system.bak
2013-12-16 21:52 - 2009-07-13 18:34 - 05242880 _____ C:\Windows\system32\config\default.bak
2013-12-16 21:52 - 2009-07-13 18:34 - 00262144 _____ C:\Windows\system32\config\security.bak
2013-12-16 21:52 - 2009-07-13 18:34 - 00262144 _____ C:\Windows\system32\config\sam.bak
2013-12-16 21:44 - 2013-12-16 21:43 - 05154128 ____R (Swearware) C:\Users\Jon\Desktop\asdf.exe
2013-12-16 21:41 - 2011-12-02 19:45 - 00000000 ____D C:\Users\Jon
2013-12-16 20:38 - 2013-12-16 20:38 - 00819136 _____ (Google Inc.) C:\Users\Jon\Downloads\googledrivesync.exe
2013-12-16 09:24 - 2013-09-06 11:59 - 00000000 ____D C:\Program Files (x86)\Hearthstone
2013-12-16 03:01 - 2013-08-14 02:01 - 00000000 ____D C:\Windows\system32\MRT
2013-12-16 03:00 - 2011-12-02 20:09 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-12-15 21:26 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\rescache
2013-12-15 20:17 - 2013-09-06 11:57 - 00000000 ____D C:\Program Files (x86)\Battle.net
2013-12-15 20:16 - 2013-09-10 18:48 - 00000000 ____D C:\Program Files (x86)\StarCraft II
2013-12-15 20:16 - 2012-05-15 23:39 - 00000000 ____D C:\Program Files (x86)\Diablo III
2013-12-15 20:16 - 2011-12-02 20:03 - 00000000 ____D C:\Program Files (x86)\World of Warcraft
2013-12-15 19:32 - 2009-07-13 20:45 - 00435720 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-15 19:18 - 2013-03-14 19:25 - 00000000 ____D C:\Program Files\Microsoft Office 15
2013-12-15 19:12 - 2012-01-07 15:34 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-12-15 19:02 - 2013-12-15 19:02 - 00292024 _____ C:\Windows\Minidump\121513-19983-01.dmp
2013-12-10 00:18 - 2013-12-10 00:17 - 00292024 _____ C:\Windows\Minidump\121013-20264-01.dmp
2013-12-06 14:58 - 2012-07-02 23:09 - 00003888 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-12-06 14:58 - 2012-07-02 23:09 - 00003636 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-12-06 14:25 - 2013-12-06 14:25 - 00292024 _____ C:\Windows\Minidump\120613-21933-01.dmp

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-01-01 22:07

==================== End Of Log ============================

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 04-01-2014
Ran by Jon at 2014-01-04 18:40:39
Running from C:\Users\Jon\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}

==================== Installed Programs ======================

Adobe AIR (x32 Version: 3.4.0.2540 - Adobe Systems Incorporated)
Adobe AIR (x32 Version: 3.4.0.2540 - Adobe Systems Incorporated) Hidden
Adobe Flash Player 11 ActiveX (x32 Version: 11.8.800.94 - Adobe Systems Incorporated)
Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.170 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.05) (x32 Version: 11.0.05 - Adobe Systems Incorporated)
AMD Accelerated Video Transcoding (Version: 12.5.100.21219 - Advanced Micro Devices, Inc.) Hidden
AMD APP SDK Runtime (Version: 10.0.1084.4 - Advanced Micro Devices Inc.) Hidden
AMD Catalyst Install Manager (Version: 8.0.903.0 - Advanced Micro Devices, Inc.)
AMD Drag and Drop Transcoding (Version: 2.00.0000 - Advanced Micro Devices, Inc.) Hidden
AMD Fuel (Version: 2012.1219.1521.27485 - Advanced Micro Devices, Inc.) Hidden
AMD Media Foundation Decoders (Version: 1.0.71219.1540 - Advanced Micro Devices, Inc.) Hidden
AMD VISION Engine Control Center (x32 Version: 2012.1219.1521.27485 - Advanced Micro Devices, Inc.) Hidden
Application Profiles (x32 Version: 2.0.4331.36041 - Advanced Micro Devices, Inc.) Hidden
Battle.net (x32 Version:  - Blizzard Entertainment)
Belkin N750 Dual Band Wireless USB Adapter (x32 Version: 1.5.11.0 - Belkin International, Inc.)
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Graphics Previews Common (x32 Version: 2012.1219.1521.27485 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2011.1109.2212.39826 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2012.1219.1521.27485 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2012.1219.1521.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Standard (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Traditional (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Czech (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Danish (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Dutch (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help English (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Finnish (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help French (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help German (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Greek (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Hungarian (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Italian (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Japanese (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Korean (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Norwegian (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Polish (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Portuguese (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Russian (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Spanish (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Swedish (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Thai (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Turkish (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
ccc-utility64 (Version: 2012.1219.1521.27485 - Advanced Micro Devices, Inc.) Hidden
CCleaner (Version: 4.05 - Piriform)
Cisco EAP-FAST Module (x32 Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (x32 Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (x32 Version: 1.1.6 - Cisco Systems, Inc.)
Core Temp version 0.99.7 (Version: 0.99.7 - Arthur Liberman)
Curse Client (HKCU Version: 5.1.1.792 - Curse)
DC Universe Online Live (HKCU Version:  - Sony Online Entertainment)
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (x32 Version:  - Microsoft)
Diablo III (x32 Version:  - Blizzard Entertainment)
Epson Connect Printer Setup (x32 Version: 1.1.1 - SEIKO EPSON CORPORATION)
EPSON Connect version 1.0 (x32 Version: 1.0 - Epson America Inc.)
Epson Customer Participation (Version: 1.4.0.0 - SEIKO EPSON CORPORATION)
Epson Event Manager (x32 Version: 3.01.0003 - Seiko Epson Corporation)
Epson E-Web Print (x32 Version: 1.17.0000 - SEIKO EPSON CORPORATION)
Epson FAX Utility (x32 Version: 1.31.00 - SEIKO EPSON CORPORATION)
EPSON Printer Finder (x32 Version: 1.0.0 - SEIKO EPSON CORPORATION)
EPSON Remote Print Uninstall (Version:  - SEIKO EPSON Corporation)
EPSON Scan (x32 Version:  - Seiko Epson Corporation)
EPSON WF-3530 Series Printer Uninstall (Version:  - SEIKO EPSON Corporation)
EpsonNet Print (x32 Version: 2.5.00 - SEIKO EPSON CORPORATION)
Fitbit Connect (x32 Version: 1.0.0.2578 - Fitbit Inc.)
GameFly (x32 Version: 1.1.918 - GameFly, Inc.) Hidden
Google Chrome (x32 Version: 31.0.1650.63 - Google Inc.)
Google Drive (x32 Version: 1.13.5782.599 - Google, Inc.)
Google Update Helper (x32 Version: 1.3.22.3 - Google Inc.) Hidden
Guild Wars 2 (x32 Version:  - NCsoft Corporation, Ltd.)
Harmony Browser Plug-in (x32 Version: 2.0 - Logitech)
Hearthstone (x32 Version:  - Blizzard Entertainment)
Java 7 Update 45 (x32 Version: 7.0.450 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
Logitech Gaming Software (Version: 8.20.74 - Logitech Inc.) Hidden
Malwarebytes Anti-Malware version 1.75.0.1300 (x32 Version: 1.75.0.1300 - Malwarebytes Corporation)
Microsoft .NET Framework 1.1 (x32 Version:  - )
Microsoft .NET Framework 1.1 (x32 Version: 1.1.4322 - Microsoft) Hidden
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft Office Access MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Access Setup Metadata MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Home and Student 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Spanish) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared Setup Metadata MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Single Image 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Publisher 2013 - en-us (Version: 15.0.4551.1011 - Microsoft Corporation)
Microsoft Security Client (Version: 4.4.0304.0 - Microsoft Corporation) Hidden
Microsoft Security Essentials (Version: 4.4.304.0 - Microsoft Corporation)
Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation)
Microsoft SQL Server 2005 (x32 Version:  - Microsoft Corporation)
Microsoft SQL Server 2005 Express Edition (SQLEXPRESSEFILM) (x32 Version: 9.4.5000.00 - Microsoft Corporation) Hidden
Microsoft SQL Server 2005 Tools Express Edition (x32 Version: 9.4.5000.00 - Microsoft Corporation) Hidden
Microsoft SQL Server Native Client (Version: 9.00.5000.00 - Microsoft Corporation)
Microsoft SQL Server Setup Support Files (English) (x32 Version: 9.00.5000.00 - Microsoft Corporation)
Microsoft SQL Server VSS Writer (Version: 9.00.5000.00 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation)
Mozilla Firefox 26.0 (x86 en-US) (x32 Version: 26.0 - Mozilla)
Mozilla Maintenance Service (x32 Version: 26.0 - Mozilla)
mSecure (x32 Version: 3.133 - mSeven Software LLC)
MSXML 4.0 SP3 Parser (KB2721691) (x32 Version: 4.30.2114.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (x32 Version: 4.30.2117.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB973685) (x32 Version: 4.30.2107.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (x32 Version: 4.30.2100.0 - Microsoft Corporation)
Mumble 1.2.3 (x32 Version: 1.2.3 - Thorvald Natvig)
NETGEAR WNA3100 wireless USB 2.0 adapter (x32 Version: 1.01.206 - NETGEAR)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4551.1011 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4551.1011 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4551.1011 - Microsoft Corporation) Hidden
Origin (x32 Version: 9.1.10.2728 - Electronic Arts, Inc.)
PlayOn (x32 Version: 3.6.16 - MediaMall Technologies, Inc.)
QuickTime (x32 Version: 7.74.80.86 - Apple Inc.)
RIFT (HKCU Version:  - Trion Worlds, Inc.)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32 Version:  - Microsoft) Hidden
SimCity™ (x32 Version: 1.0.0.0 - Electronic Arts)
Software Updater (x32 Version: 4.1.7 - SEIKO EPSON CORPORATION)
Spotify (HKCU Version: 0.9.6.81.gd359a796 - Spotify AB)
Star Trek Away Team (x32 Version:  - )
Star Trek Bridge Commander (x32 Version:  - )
Star Trek Legacy (x32 Version: 1.00.0000 - Bethesda Softworks)
Star Trek Online (x32 Version:  - Cryptic Studios)
Star Trek Voyager Elite Force (x32 Version:  - )
Star Wars: Knights of the Old Republic (x32 Version:  - BioWare)
Star Wars: Knights of the Old Republic II (x32 Version:  - LucasArts)
Star Wars: The Old Republic (x32 Version: 1.00 - Electronic Arts, Inc.)
StarCraft II (x32 Version:  - Blizzard Entertainment)
Steam (x32 Version: 1.0.0.0 - Valve Corporation)
The Sims™ Medieval (x32 Version: 2.0.113.00107 - Electronic Arts)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3 - Microsoft Corporation)
Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2810071) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2826026) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft OneNote 2010 (KB2810072) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Word 2010 (KB2837593) 32-Bit Edition (x32 Version:  - Microsoft)
Ventrilo Client for Windows x64 (Version: 3.0.8.0 - Flagship Industries, Inc.)
Visual Studio 2010 x64 Redistributables (Version: 13.0.0.1 - AVG Technologies)
VLC media player 2.1.0 (x32 Version: 2.1.0 - VideoLAN)
Windows Media Player Firefox Plugin (x32 Version: 1.0.0.8 - Microsoft Corp)
World of Warcraft (x32 Version:  - Blizzard Entertainment)
ZoneAlarm Antivirus (x32 Version: 11.0.780.000 - Check Point Software Technologies Ltd.) Hidden

==================== Restore Points  =========================

20-12-2013 14:47:49 Windows Update
20-12-2013 15:10:04 Windows Update
27-12-2013 17:33:31 Windows Update
28-12-2013 00:27:34 Installed mSecure.
28-12-2013 11:00:13 Windows Update
02-01-2014 04:42:51 Windows Update
02-01-2014 11:00:11 Windows Update
03-01-2014 23:53:36 Windows Update
04-01-2014 11:00:11 Windows Update
05-01-2014 00:43:31 Installed DirectX
05-01-2014 00:45:35 Windows Update
05-01-2014 02:22:48 Installed Microsoft Fix it 50688

==================== Hosts content: ==========================

2009-07-13 18:34 - 2013-12-16 21:53 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost

==================== Scheduled Tasks (whitelisted) =============

Task: {24D2AEEE-C055-47FA-A027-E8AFB6832CBA} - System32\Tasks\{20128B30-C097-459D-8FEC-EA93FF2DD911} => C:\Program Files (x86)\Activision\Bridge Commander\stbc.exe [2002-04-09] ()
Task: {2B7FBB5B-0C50-4183-B1CB-3437708B129B} - System32\Tasks\{ACF6C4B1-626E-460E-B399-C30FBF9DC4F1} => D:\setup.exe [2012-11-20] (Belkin International, Inc.)
Task: {2FDF5496-1103-4ED4-9CCA-1A5AE84D0E02} - System32\Tasks\{435E228C-6160-41F1-81EE-3FACC4291502} => D:\setup.exe [2012-11-20] (Belkin International, Inc.)
Task: {30318F08-4E61-4C4E-856E-220B55B9FF2C} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-08-21] (Piriform Ltd)
Task: {366FE686-3015-40DF-9479-8F7362AF72D8} - System32\Tasks\{191EE59F-73B8-4DC2-A10F-6A81A6719DDA} => D:\setup.exe [2012-11-20] (Belkin International, Inc.)
Task: {39541455-BCC3-49AE-B4F4-44FD7BCD977B} - System32\Tasks\{EC018763-6894-4358-97D7-6148591888F2} => C:\Program Files (x86)\Activision\Bridge Commander\stbc.exe [2002-04-09] ()
Task: {3C682B5B-9F7B-46B3-ABFC-28F500B7969C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-07-02] (Google Inc.)
Task: {46E58112-815A-4609-9DB7-48630E870518} - System32\Tasks\{E0FF6EFF-6165-486C-8F8F-DC0ABE47A6F4} => D:\setup.exe [2012-11-20] (Belkin International, Inc.)
Task: {5291C48C-BA5B-4FC3-8ADB-E078BCF41330} - System32\Tasks\{23DF2C0D-5391-406E-B13E-1F42C7A5C50A} => C:\Windows\System32\msiexec.exe [2010-11-20] (Microsoft Corporation)
Task: {5C75073E-165D-45E5-90CD-95B700A2555C} - System32\Tasks\{E3FDA37C-ABF6-4F06-AC1E-CEE1684A0602} => C:\Program Files (x86)\Activision\Bridge Commander\stbc.exe [2002-04-09] ()
Task: {71789361-55CA-416A-BE9D-7AD7C33D1B1F} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-07-02] (Google Inc.)
Task: {73A4DF58-22BA-4ECF-B55F-E77D7DFA7C70} - System32\Tasks\Adobe online update program => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-09-05] (Adobe Systems Incorporated)
Task: {7413F819-AB49-4835-9E92-7C607448FE44} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office 15\root\office15\msoia.exe [2013-11-14] (Microsoft Corporation)
Task: {7519BAE0-6421-4301-85EA-C8D253BEDD44} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [2013-11-02] (Microsoft Corporation)
Task: {9509D16A-B482-4993-9FDD-ADE5113DF434} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-01-01] (Adobe Systems Incorporated)
Task: {96213A40-FE5A-4A72-84C2-3859E9C321AE} - System32\Tasks\Apple Diagnostics => C:\Program Files (x86)\Common Files\Apple\Internet Services\EReporter.exe
Task: {9B4EAC72-4A36-4AAF-80AE-A19B70FEB705} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02] (Oracle Corporation)
Task: {9ECA5633-D167-49BB-9408-DB1B9234C3D7} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office 15\root\office15\msoia.exe [2013-11-14] (Microsoft Corporation)
Task: {9F3330D4-EAD3-4D56-ADF6-47ED70974F51} - System32\Tasks\{1D4475FB-0EB0-4362-B029-73CE303F34A8} => D:\setup.exe [2012-11-20] (Belkin International, Inc.)
Task: {A00D5D90-9153-463E-A07E-0CBB888940E8} - System32\Tasks\{7F8B1557-D9A0-42FE-9D81-52DF6DADC3C5} => D:\setup.exe [2012-11-20] (Belkin International, Inc.)
Task: {A4035522-1116-4162-BB6A-81B711E28949} - System32\Tasks\{B89D1B00-B922-40A7-BC45-0257651F5C71} => D:\setup.exe [2012-11-20] (Belkin International, Inc.)
Task: {C302FA64-6433-4548-A721-48685E69FF0E} - System32\Tasks\RunOW => C:\Program Files (x86)\Overwolf\OverwolfLauncher.exe
Task: {C957894C-D494-460C-A571-3F8E39AAEB1F} - System32\Tasks\{D1F99E1A-DDA4-4020-8BB9-7D8A981DFC7F} => D:\setup.exe [2012-11-20] (Belkin International, Inc.)
Task: {CA232402-0EE6-467C-B38B-238391DACA02} - System32\Tasks\Google Updater and Installer => C:\Users\Jon\AppData\Local\Google\Update\GoogleUpdate.exe
Task: {EF4F6E8B-937E-453E-87FC-7A85A5BE1484} - System32\Tasks\Core Temp Autostart => C:\Program Files\Core Temp\Core Temp.exe [2010-07-02] ()

==================== Loaded Modules (whitelisted) =============

2013-11-14 03:45 - 2013-11-14 03:45 - 08866472 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2013-12-16 22:03 - 2013-12-16 22:02 - 00014848 _____ () C:\Users\Jon\AppData\Local\Apps\2.0\OQ4KM2CA.Z6R\Q1EZAPQ6.JCT\curs..tion_9e9e83ddf3ed3ead_0005.0001_181b5e0542e9eb6c\Curse.CurseClient.WowDb.dll
2013-12-16 22:03 - 2013-12-16 22:02 - 00035840 _____ () C:\Users\Jon\AppData\Local\Apps\2.0\OQ4KM2CA.Z6R\Q1EZAPQ6.JCT\curs..tion_9e9e83ddf3ed3ead_0005.0001_181b5e0542e9eb6c\Curse.Advertising.dll
2013-03-19 20:59 - 2014-01-04 14:06 - 00064000 _____ () C:\Program Files (x86)\Origin\tufao.dll
2013-09-02 19:39 - 2014-01-01 20:43 - 03559024 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll

==================== Alternate Data Streams (whitelisted) =========


==================== Safe Mode (whitelisted) ===================


==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (01/04/2014 05:09:56 PM) (Source: Application Error) (User: )
Description: Faulting application name: TSM.exe, version: 0.0.0.0, time stamp: 0x508f5967
Faulting module name: TSM.exe, version: 0.0.0.0, time stamp: 0x508f5967
Exception code: 0xc0000005
Fault offset: 0x00020c05
Faulting process id: 0x1378
Faulting application start time: 0xTSM.exe0
Faulting application path: TSM.exe1
Faulting module path: TSM.exe2
Report Id: TSM.exe3

Error: (01/04/2014 04:56:13 PM) (Source: .NET Runtime Optimization Service) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - Failed to compile: System.ServiceModel.Web, Version=3.5.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35 . Error code = 0x800705aa

Error: (01/04/2014 04:56:11 PM) (Source: .NET Runtime Optimization Service) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - Failed to compile: Microsoft.Transactions.Bridge, Version=3.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a . Error code = 0x800705aa

Error: (01/04/2014 04:56:09 PM) (Source: .NET Runtime Optimization Service) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - Failed to compile: System.IdentityModel.Selectors, Version=3.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 . Error code = 0x800705aa

Error: (01/04/2014 04:56:09 PM) (Source: .NET Runtime Optimization Service) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - Failed to compile: System.IdentityModel, Version=3.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 . Error code = 0x800705aa

Error: (01/04/2014 04:56:08 PM) (Source: .NET Runtime Optimization Service) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - Failed to compile: System.Runtime.Serialization, Version=3.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 . Error code = 0x800705aa

Error: (01/04/2014 04:56:04 PM) (Source: .NET Runtime Optimization Service) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - Failed to compile: SMDiagnostics, Version=3.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 . Error code = 0x800705aa

Error: (01/04/2014 04:56:04 PM) (Source: .NET Runtime Optimization Service) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - Failed to compile: System.ServiceModel, Version=3.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 . Error code = 0x800705aa

Error: (01/04/2014 04:55:40 PM) (Source: .NET Runtime Optimization Service) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - Failed to compile: System.Web.Extensions, Version=3.5.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35 . Error code = 0x800705aa

Error: (01/04/2014 04:55:38 PM) (Source: .NET Runtime Optimization Service) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - Failed to compile: System.ServiceModel.Web, Version=3.5.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35 . Error code = 0x800705aa


System errors:
=============
Error: (01/04/2014 01:31:17 PM) (Source: Schannel) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 70. The internal error state is 105.

Error: (01/04/2014 03:01:15 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80070643: Internet Explorer 11 for Windows 7 for x64-based Systems.

Error: (01/03/2014 03:54:55 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80070643: Internet Explorer 11 for Windows 7 for x64-based Systems.

Error: (01/03/2014 03:51:08 PM) (Source: DCOM) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

Error: (01/03/2014 03:50:10 PM) (Source: Service Control Manager) (User: )
Description: The vToolbarUpdater15.5.0 service failed to start due to the following error:
%%2

Error: (01/03/2014 03:50:07 PM) (Source: Service Control Manager) (User: )
Description: The AODDriver4.2 service failed to start due to the following error:
%%2

Error: (01/03/2014 03:49:57 PM) (Source: BugCheck) (User: )
Description: 0x00000024 (0x00000000001904fb, 0xfffff8800315a518, 0xfffff88003159d70, 0xfffff88001148493)C:\Windows\MEMORY.DMP010314-18829-01

Error: (01/03/2014 03:49:54 PM) (Source: EventLog) (User: )
Description: The previous system shutdown at 1:41:51 AM on ‎1/‎3/‎2014 was unexpected.

Error: (01/02/2014 03:01:26 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80070643: Internet Explorer 11 for Windows 7 for x64-based Systems.

Error: (01/01/2014 08:54:15 PM) (Source: DCOM) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)


Microsoft Office Sessions:
=========================
Error: (01/04/2014 05:09:56 PM) (Source: Application Error)(User: )
Description: TSM.exe0.0.0.0508f5967TSM.exe0.0.0.0508f5967c000000500020c05137801cf09b12028f749C:\Program Files (x86)\Origin Games\The Sims Medieval\Game\bin\TSM.exeC:\Program Files (x86)\Origin Games\The Sims Medieval\Game\bin\TSM.exe16790497-75a6-11e3-b828-5404a67eace1

Error: (01/04/2014 04:56:13 PM) (Source: .NET Runtime Optimization Service)(User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - Failed to compile: System.ServiceModel.Web, Version=3.5.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35 . Error code = 0x800705aa
System.ServiceModel.Web, Version=3.5.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35

Error: (01/04/2014 04:56:11 PM) (Source: .NET Runtime Optimization Service)(User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - Failed to compile: Microsoft.Transactions.Bridge, Version=3.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a . Error code = 0x800705aa
Microsoft.Transactions.Bridge, Version=3.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a

Error: (01/04/2014 04:56:09 PM) (Source: .NET Runtime Optimization Service)(User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - Failed to compile: System.IdentityModel.Selectors, Version=3.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 . Error code = 0x800705aa
System.IdentityModel.Selectors, Version=3.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089

Error: (01/04/2014 04:56:09 PM) (Source: .NET Runtime Optimization Service)(User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - Failed to compile: System.IdentityModel, Version=3.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 . Error code = 0x800705aa
System.IdentityModel, Version=3.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089

Error: (01/04/2014 04:56:08 PM) (Source: .NET Runtime Optimization Service)(User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - Failed to compile: System.Runtime.Serialization, Version=3.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 . Error code = 0x800705aa
System.Runtime.Serialization, Version=3.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089

Error: (01/04/2014 04:56:04 PM) (Source: .NET Runtime Optimization Service)(User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - Failed to compile: SMDiagnostics, Version=3.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 . Error code = 0x800705aa
SMDiagnostics, Version=3.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089

Error: (01/04/2014 04:56:04 PM) (Source: .NET Runtime Optimization Service)(User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - Failed to compile: System.ServiceModel, Version=3.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 . Error code = 0x800705aa
System.ServiceModel, Version=3.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089

Error: (01/04/2014 04:55:40 PM) (Source: .NET Runtime Optimization Service)(User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - Failed to compile: System.Web.Extensions, Version=3.5.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35 . Error code = 0x800705aa
System.Web.Extensions, Version=3.5.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35

Error: (01/04/2014 04:55:38 PM) (Source: .NET Runtime Optimization Service)(User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - Failed to compile: System.ServiceModel.Web, Version=3.5.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35 . Error code = 0x800705aa
System.ServiceModel.Web, Version=3.5.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35


CodeIntegrity Errors:
===================================
  Date: 2013-12-29 00:31:05.380
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.

  Date: 2013-12-29 00:31:05.380
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.

  Date: 2013-12-29 00:31:05.380
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.

  Date: 2013-12-29 00:31:05.380
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\KLELAMX64\klelam.sys because the set of per-page image hashes could not be found on the system.

  Date: 2013-12-29 00:31:05.380
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\KLELAMX64\klelam.sys because the set of per-page image hashes could not be found on the system.

  Date: 2013-12-29 00:31:05.380
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\KLELAMX64\klelam.sys because the set of per-page image hashes could not be found on the system.

  Date: 2013-12-28 00:30:15.990
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.

  Date: 2013-12-28 00:30:15.989
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.

  Date: 2013-12-28 00:30:15.987
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.

  Date: 2013-12-28 00:30:15.980
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\KLELAMX64\klelam.sys because the set of per-page image hashes could not be found on the system.


==================== Memory info ===========================

Percentage of memory in use: 28%
Total physical RAM: 8190.05 MB
Available physical RAM: 5825.91 MB
Total Pagefile: 16378.29 MB
Available Pagefile: 13906.18 MB
Total Virtual: 8192 MB
Available Virtual: 8191.78 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:465.66 GB) (Free:170.79 GB) NTFS
Drive d: (Belkin F9L1103v1) (CDROM) (Total:0.09 GB) (Free:0 GB) CDFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 3ED682B0)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=466 GB) - (Type=07 NTFS)

==================== End Of Log ============================



#15 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,375 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:05:02 AM

Posted 04 January 2014 - 10:04 PM

Thanks for running that. Please do these things.

===================================================

AdwCleaner by Xplode - Delete Adware

-------------------
  • Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browser
  • Double click on AdwCleaner.exe, select OK, then Run
  • Click on Scan
  • Upon completion click Clean and close programs if necessary
  • Click OK twice to reboot your computer
  • Copy and paste the contents of the text file on your desktop in your reply
  • You can also find the logfile at C:\AdwCleaner.txt
===================================================

Junkware Removal Tool by thisisu

-------------------
  • Please download Junkware Removal Tool and save it to your desktop.
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. (Click on this link to see a list of programs that should be disabled. The list is not all inclusive.)
  • Right-mouse click JRT.exe and select Run as administrator (Windows XP double click the icon)
  • Please allow the program time to run
  • Once completed a Notepad document will open on your desktop
  • Copy and paste the contents in your reply
===================================================

Run TDSSKiller by Kaspersky on Vista/7

--------------------
  • Please download Kaspersky's TDSSKiller and save it to your Desktop. <-Important!!!
  • If you desire you may print out and follow the instructions for performing a scan.
  • Right-click on TDSSKiller.exe and select Run As Administrator.
  • When the program opens, click the Start Scan button.

tdss1.png

  • Do not use the computer during the scan
  • If the scan completes with nothing found, click Close to exit.
  • Any objects found will show in the Scan results - Select action for found objects and offer three options.
  • If an infected file is detected, the default action will be Cure...do not change it.

tdss2.png

  • Click Continue > Reboot now to finish the cleaning process.<- Important!!

tdss4.png

  • If 'Suspicious' objects are detected, you will be given the option to Skip or Quarantine. Skip will be the default selection. Leave it as such for now.
  • A log file named TDSSKiller_version_date_time_log.txt will be created and saved to the root directory (usually Local Disk C:).
  • Copy and paste the contents of that file in your next reply.
-- If TDSSKiller does not run, try renaming it. To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123abc.com). If you do not see the file extension, please refer to these instructions. In some cases it may be necessary to redownload TDSSKiller and randomly rename it before downloading and saving to the computer or to perform the scan in "safe mode".


===================================================

aswMBR

--------------------
  • Download aswMBR and save it to your desktop.
  • Please disable your real time protection of any Antivirus, Antispyware or Antimalware programs temporarily. They will interfere and may cause unexpected results.
  • If you need help to disable your protection programs see here and here.
  • Double click the aswMBR.exe file to run it. Please allow when you are asked to download AVAST antivirus engine defs.
  • Wait until the AV update is done, then click on the Scan button to start. The program will launch a scan.

aswMBR1.png

  • When done, you will see Scan finished successfully. Please click on Save log and save the file to your desktop.

aswMBR2.png

  • Please post the contents of the log in your next reply.
NOTE: aswMBR will create MBR.dat file on your desktop. This is a copy of your MBR. Do NOT delete it.

===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • AdwCleaner log
  • Junkware log
  • TDSSKiller log
  • aswMBR log

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"May you be richly rewarded by the Lord, the God of Israel, under whose wings you have come to take refuge."




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users