Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

registry keys and remote access trojans


  • Please log in to reply
6 replies to this topic

#1 Druidic

Druidic

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:11:21 PM

Posted 17 January 2014 - 07:11 AM

Hello, 
 
I recently purchased a new laptop with windows 8. Within the first week I connected to an untrusted public network and somehow was infected with a remote access trojan I believe, as the mouse was taken over and various user account settings were changed and I believe numerous viruses infected my device. I reinstalled windows 8 OS but still had issues with remote access takeovers, and I suspect the original factory image may have been compromised? I have since reinstalled various times, as well as recently upgraded to 8.1; but I still feel like there are infections in my device as I have strange browser issues and other woes. Can someone please assist me to completely disinfect and secure my device once and for all?

Edited by Queen-Evie, 17 January 2014 - 10:37 AM.
moved from Windows 8


BC AdBot (Login to Remove)

 


#2 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,490 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:01:21 AM

Posted 17 January 2014 - 09:40 PM

Hello druidic. Let's see what we get back.

Please download MiniToolBox, save it to your desktop and run it.
Checkmark the following checkboxes:
  • Flush DNS
  • Report IE Proxy Settings
  • Reset IE Proxy Settings
  • Report FF Proxy Settings
  • Reset FF Proxy Settings
  • List content of Hosts
  • List IP configuration
  • List Winsock Entries
  • List last 10 Event Viewer log
  • List Installed Programs
  • List Users, Partitions and Memory size.
Click Go and post the result (Result.txt). A copy of Result.txt will be saved in the same directory the tool is run.
Note: When using "Reset FF Proxy Settings" option Firefox should be closed.



Download TDSSKiller and save it to your desktop.
  • Extract (unzip) its contents to your desktop.
  • Open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
  • If an infected file is detected, the default action will be Cure, click on Continue.
  • If a suspicious file is detected, the default action will be Skip, click on Continue.
  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory (usually C:\ folder) in the form of TDSSKiller_xxxx_log.txt. Please copy and paste the contents of that file here.
.
.
.
ADW Cleaner

Please download AdwCleaner by Xplode and save to your Desktop.
  • Double click on AdwCleaner.exe to run the tool
  • Click on the Scan button.
  • AdwCleaner will begin to scan your computer like it did before.
  • After the scan has finished...
    <-insert any special instructions here for what to uncheck OR remove this line if there are none->
  • This time click on the Clean button.
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
  • After rebooting, a logfile report (AdwCleaner[S#].txt) will open automatically (where the largest value of # represents the most recent report).
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of that logfile will also be saved in the C:\AdwCleaner folder.
  • .
    .
    .

    thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Post the contents of JRT.txt into your next message.
    .
    .
    .
    .
    • Last run ESET.
      • Hold down Control and click on this link to open ESET OnlineScan in a new window.
      • Click the esetonlinebtn.png button.
      • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
      • Click on esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop.
      • Double click on the esetsmartinstaller_enu.png icon on your desktop.
      • Check "YES, I accept the Terms of Use."
      • Click the Start button.
      • Accept any security warnings from your browser.
      • Under scan settings, check "Scan Archives" and "Remove found threats"
      • Click Advanced settings and select the following:
      • Scan potentially unwanted applications
      • Scan for potentially unsafe applications
      • Enable Anti-Stealth technology
      • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
      • When the scan completes, click List Threats
      • Click Export, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
      • Click the Back button.
      • Click the Finish button.
      • NOTE:Sometimes if ESET finds no infections it will not create a log.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#3 Druidic

Druidic
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:11:21 PM

Posted 21 January 2014 - 04:27 AM

Here are my results:MiniToolBox by Farbar  Version: 18-12-2013

Ran by person (ATTENTION: The logged in user is not administrator) on 21-01-2014 at 03:24:12
Running from "C:\Users\person\Downloads"
Windows 8.1  (X64)
Boot Mode: Normal
***************************************************************************
 
========================= Flush DNS: ===================================
 
Windows IP Configuration
 
Successfully flushed the DNS Resolver Cache.
 
========================= IE Proxy Settings: ============================== 
 
Proxy is not enabled.
No Proxy Server is set.
========================= Hosts content: =================================
 
 
 
========================= IP Configuration: ================================
 
 
 
# ----------------------------------
# IPv4 Configuration
# ----------------------------------
pushd interface ipv4
 
reset
set global icmpredirects=enabled
set interface interface="Local Area Connection* 1" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Ethernet" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Wi-Fi" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="ethernet_11" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Local Area Connection* 12" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="ethernet_3" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Bluetooth Network Connection" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
 
 
popd
# End of IPv4 configuration
 
 
 
Windows IP Configuration
 
   Host Name . . . . . . . . . . . . : place
   Primary Dns Suffix  . . . . . . . : 
   Node Type . . . . . . . . . . . . : Hybrid
   IP Routing Enabled. . . . . . . . : No
   WINS Proxy Enabled. . . . . . . . : No
   DNS Suffix Search List. . . . . . : att.net
 
Ethernet adapter Bluetooth Network Connection:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : Bluetooth Device (Personal Area Network)
   Physical Address. . . . . . . . . : 64-5A-04-86-9B-79
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
 
Wireless LAN adapter Local Area Connection* 12:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : Microsoft Wi-Fi Direct Virtual Adapter
   Physical Address. . . . . . . . . : 16-5A-04-86-9B-78
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
 
Wireless LAN adapter Wi-Fi:
 
   Connection-specific DNS Suffix  . : att.net
   Description . . . . . . . . . . . : Dell Wireless 1705 802.11b/g/n (2.4GHZ)
   Physical Address. . . . . . . . . : 64-5A-04-86-9B-78
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
   Link-local IPv6 Address . . . . . : fe80::bdc3:179b:c321:9243%4(Preferred) 
   IPv4 Address. . . . . . . . . . . : 192.168.1.66(Preferred) 
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Lease Obtained. . . . . . . . . . : Tuesday, January 21, 2014 3:01:22 AM
   Lease Expires . . . . . . . . . . : Wednesday, January 22, 2014 3:01:22 AM
   Default Gateway . . . . . . . . . : 192.168.1.254
   DHCP Server . . . . . . . . . . . : 192.168.1.254
   DHCPv6 IAID . . . . . . . . . . . : 325343748
   DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-19-D8-81-5B-74-86-7A-3F-3B-14
   DNS Servers . . . . . . . . . . . : 8.8.8.8
                                       8.8.4.4
   NetBIOS over Tcpip. . . . . . . . : Enabled
 
Ethernet adapter Ethernet:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : att.net
   Description . . . . . . . . . . . : Realtek PCIe FE Family Controller
   Physical Address. . . . . . . . . : 74-86-7A-3F-3B-14
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
 
Tunnel adapter Local Area Connection* 13:
 
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
   IPv6 Address. . . . . . . . . . . : 2001:0:9d38:90d7:38e5:1d04:3f57:febd(Preferred) 
   Link-local IPv6 Address . . . . . : fe80::38e5:1d04:3f57:febd%6(Preferred) 
   Default Gateway . . . . . . . . . : ::
   DHCPv6 IAID . . . . . . . . . . . : 117440512
   DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-19-D8-81-5B-74-86-7A-3F-3B-14
   NetBIOS over Tcpip. . . . . . . . : Disabled
 
Tunnel adapter isatap.att.net:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : att.net
   Description . . . . . . . . . . . : Microsoft ISATAP Adapter
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
DNS request timed out.
    timeout was 2 seconds.
Server:  UnKnown
Address:  8.8.8.8
 
DNS request timed out.
    timeout was 2 seconds.
DNS request timed out.
    timeout was 2 seconds.
DNS request timed out.
    timeout was 2 seconds.
DNS request timed out.
    timeout was 2 seconds.
 
Pinging google.com [173.194.115.7] with 32 bytes of data:
Reply from 173.194.115.7: bytes=32 time=31ms TTL=54
Reply from 173.194.115.7: bytes=32 time=30ms TTL=54
 
Ping statistics for 173.194.115.7:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 30ms, Maximum = 31ms, Average = 30ms
Server:  google-public-dns-a.google.com
Address:  8.8.8.8
 
Name:    yahoo.com
Addresses:  98.138.253.109
 206.190.36.45
 98.139.183.24
 
 
Pinging yahoo.com [98.138.253.109] with 32 bytes of data:
Reply from 98.138.253.109: bytes=32 time=74ms TTL=49
Reply from 98.138.253.109: bytes=32 time=90ms TTL=49
 
Ping statistics for 98.138.253.109:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 74ms, Maximum = 90ms, Average = 82ms
 
Pinging 127.0.0.1 with 32 bytes of data:
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
 
Ping statistics for 127.0.0.1:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 0ms, Maximum = 0ms, Average = 0ms
===========================================================================
Interface List
  9...64 5a 04 86 9b 79 ......Bluetooth Device (Personal Area Network)
  7...16 5a 04 86 9b 78 ......Microsoft Wi-Fi Direct Virtual Adapter
  4...64 5a 04 86 9b 78 ......Dell Wireless 1705 802.11b/g/n (2.4GHZ)
  3...74 86 7a 3f 3b 14 ......Realtek PCIe FE Family Controller
  1...........................Software Loopback Interface 1
  6...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface
 10...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter
===========================================================================
 
IPv4 Route Table
===========================================================================
Active Routes:
Network Destination        Netmask          Gateway       Interface  Metric
          0.0.0.0          0.0.0.0    192.168.1.254     192.168.1.66     25
        127.0.0.0        255.0.0.0         On-link         127.0.0.1    306
        127.0.0.1  255.255.255.255         On-link         127.0.0.1    306
  127.255.255.255  255.255.255.255         On-link         127.0.0.1    306
      192.168.1.0    255.255.255.0         On-link      192.168.1.66    281
     192.168.1.66  255.255.255.255         On-link      192.168.1.66    281
    192.168.1.255  255.255.255.255         On-link      192.168.1.66    281
        224.0.0.0        240.0.0.0         On-link         127.0.0.1    306
        224.0.0.0        240.0.0.0         On-link      192.168.1.66    281
  255.255.255.255  255.255.255.255         On-link         127.0.0.1    306
  255.255.255.255  255.255.255.255         On-link      192.168.1.66    281
===========================================================================
Persistent Routes:
  None
 
IPv6 Route Table
===========================================================================
Active Routes:
 If Metric Network Destination      Gateway
  6    306 ::/0                     On-link
  1    306 ::1/128                  On-link
  6    306 2001::/32                On-link
  6    306 2001:0:9d38:90d7:38e5:1d04:3f57:febd/128
                                    On-link
  4    281 fe80::/64                On-link
  6    306 fe80::/64                On-link
  6    306 fe80::38e5:1d04:3f57:febd/128
                                    On-link
  4    281 fe80::bdc3:179b:c321:9243/128
                                    On-link
  1    306 ff00::/8                 On-link
  4    281 ff00::/8                 On-link
  6    306 ff00::/8                 On-link
===========================================================================
Persistent Routes:
  None
========================= Winsock entries =====================================
 
Catalog5 01 C:\WINDOWS\SysWOW64\napinsp.dll [53760] (Microsoft Corporation)
Catalog5 02 C:\WINDOWS\SysWOW64\pnrpnsp.dll [68096] (Microsoft Corporation)
Catalog5 03 C:\WINDOWS\SysWOW64\pnrpnsp.dll [68096] (Microsoft Corporation)
Catalog5 04 C:\WINDOWS\SysWOW64\NLAapi.dll [64000] (Microsoft Corporation)
Catalog5 05 C:\WINDOWS\SysWOW64\mswsock.dll [270848] (Microsoft Corporation)
Catalog5 06 C:\WINDOWS\SysWOW64\winrnr.dll [21504] (Microsoft Corporation)
Catalog5 07 C:\WINDOWS\SysWOW64\wshbth.dll [51200] (Microsoft Corporation)
Catalog9 01 C:\WINDOWS\SysWOW64\mswsock.dll [270848] (Microsoft Corporation)
Catalog9 02 C:\WINDOWS\SysWOW64\mswsock.dll [270848] (Microsoft Corporation)
Catalog9 03 C:\WINDOWS\SysWOW64\mswsock.dll [270848] (Microsoft Corporation)
Catalog9 04 C:\WINDOWS\SysWOW64\mswsock.dll [270848] (Microsoft Corporation)
Catalog9 05 C:\WINDOWS\SysWOW64\mswsock.dll [270848] (Microsoft Corporation)
Catalog9 06 C:\WINDOWS\SysWOW64\mswsock.dll [270848] (Microsoft Corporation)
Catalog9 07 C:\WINDOWS\SysWOW64\mswsock.dll [270848] (Microsoft Corporation)
Catalog9 08 C:\WINDOWS\SysWOW64\mswsock.dll [270848] (Microsoft Corporation)
Catalog9 09 C:\WINDOWS\SysWOW64\mswsock.dll [270848] (Microsoft Corporation)
Catalog9 10 C:\WINDOWS\SysWOW64\mswsock.dll [270848] (Microsoft Corporation)
Catalog9 11 C:\WINDOWS\SysWOW64\mswsock.dll [270848] (Microsoft Corporation)
x64-Catalog5 01 C:\Windows\System32\napinsp.dll [67584] (Microsoft Corporation)
x64-Catalog5 02 C:\Windows\System32\pnrpnsp.dll [87040] (Microsoft Corporation)
x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [87040] (Microsoft Corporation)
x64-Catalog5 04 C:\Windows\System32\NLAapi.dll [84480] (Microsoft Corporation)
x64-Catalog5 05 C:\Windows\System32\mswsock.dll [338432] (Microsoft Corporation)
x64-Catalog5 06 C:\Windows\System32\winrnr.dll [30208] (Microsoft Corporation)
x64-Catalog5 07 C:\Windows\System32\wshbth.dll [63488] (Microsoft Corporation)
x64-Catalog9 01 C:\Windows\System32\mswsock.dll [338432] (Microsoft Corporation)
x64-Catalog9 02 C:\Windows\System32\mswsock.dll [338432] (Microsoft Corporation)
x64-Catalog9 03 C:\Windows\System32\mswsock.dll [338432] (Microsoft Corporation)
x64-Catalog9 04 C:\Windows\System32\mswsock.dll [338432] (Microsoft Corporation)
x64-Catalog9 05 C:\Windows\System32\mswsock.dll [338432] (Microsoft Corporation)
x64-Catalog9 06 C:\Windows\System32\mswsock.dll [338432] (Microsoft Corporation)
x64-Catalog9 07 C:\Windows\System32\mswsock.dll [338432] (Microsoft Corporation)
x64-Catalog9 08 C:\Windows\System32\mswsock.dll [338432] (Microsoft Corporation)
x64-Catalog9 09 C:\Windows\System32\mswsock.dll [338432] (Microsoft Corporation)
x64-Catalog9 10 C:\Windows\System32\mswsock.dll [338432] (Microsoft Corporation)
x64-Catalog9 11 C:\Windows\System32\mswsock.dll [338432] (Microsoft Corporation)
 
========================= Event log errors: ===============================
 
Application errors:
==================
Error: (01/21/2014 03:11:14 AM) (Source: Application Error) (User: )
Description: Faulting application name: dragon.exe, version: 31.0.0.0, time stamp: 0x52cc43d4
Faulting module name: dragon.dll, version: 31.0.0.0, time stamp: 0x52cc4250
Exception code: 0x80000003
Fault offset: 0x005733a0
Faulting process id: 0x1b58
Faulting application start time: 0xdragon.exe0
Faulting application path: dragon.exe1
Faulting module path: dragon.exe2
Report Id: dragon.exe3
Faulting package full name: dragon.exe4
Faulting package-relative application ID: dragon.exe5
 
Error: (01/21/2014 03:10:01 AM) (Source: ESENT) (User: )
Description: DllHost (6032) WebCacheLocal: Database recovery/restore failed with unexpected error -566.
 
Error: (01/21/2014 03:10:01 AM) (Source: ESENT) (User: )
Description: DllHost (6032) WebCacheLocal: Database C:\Users\person\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat: Page 1218 (0x000004c2) failed verification due to a timestamp mismatch.  The 'before' timestamp persisted to the log record was 0x41f09 but the actual timestamp on the page was 0x41ded.  The 'after' update timestamp 0x41f0e that would have updated the on page timestamp.  Recovery/restore will fail with error -566.  If this condition persists then please restore the database from a previous backup. This problem is likely due to faulty hardware "losing" one or more flushes on this page sometime in the past. Please contact your hardware vendor for further assistance diagnosing the problem.
 
Error: (01/19/2014 08:56:44 AM) (Source: Application Hang) (User: )
Description: The program backgroundTaskHost.exe version 6.3.9600.16384 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: 1afc
 
Start Time: 01cf15259a8aea9d
 
Termination Time: 4294967295
 
Application Path: C:\WINDOWS\system32\backgroundTaskHost.exe
 
Report Id: e830f25c-8119-11e3-be7f-645a04869b79
 
Faulting package full name: Facebook.Facebook_1.2.0.12_x64__8xx8rvfyw5nnt
 
Faulting package-relative application ID: App
 
Error: (01/18/2014 10:23:13 PM) (Source: Application Error) (User: )
Description: Faulting application name: quickset.exe, version: 10.15.18.3, time stamp: 0x5135633d
Faulting module name: quickset.exe, version: 10.15.18.3, time stamp: 0x5135633d
Exception code: 0xc0000005
Fault offset: 0x000000000001847d
Faulting process id: 0x122c
Faulting application start time: 0xquickset.exe0
Faulting application path: quickset.exe1
Faulting module path: quickset.exe2
Report Id: quickset.exe3
Faulting package full name: quickset.exe4
Faulting package-relative application ID: quickset.exe5
 
Error: (01/18/2014 09:38:55 AM) (Source: Application Hang) (User: )
Description: The program backgroundTaskHost.exe version 6.3.9600.16384 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: 1f14
 
Start Time: 01cf1461a2073e7f
 
Termination Time: 4294967295
 
Application Path: C:\WINDOWS\system32\backgroundTaskHost.exe
 
Report Id: a281b4fc-8056-11e3-be7e-74867a3f3b14
 
Faulting package full name: Facebook.Facebook_1.2.0.12_x64__8xx8rvfyw5nnt
 
Faulting package-relative application ID: App
 
Error: (01/18/2014 09:03:56 AM) (Source: Application Hang) (User: )
Description: The program backgroundTaskHost.exe version 6.3.9600.16384 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: 1398
 
Start Time: 01cf145d71229aaf
 
Termination Time: 4294967295
 
Application Path: C:\WINDOWS\system32\backgroundTaskHost.exe
 
Report Id: beece3bf-8051-11e3-be7e-74867a3f3b14
 
Faulting package full name: Facebook.Facebook_1.2.0.12_x64__8xx8rvfyw5nnt
 
Faulting package-relative application ID: App
 
Error: (01/18/2014 03:51:24 AM) (Source: Application Error) (User: )
Description: Faulting application name: fixmapi.exe, version: 6.3.9600.16384, time stamp: 0x52158b32
Faulting module name: KERNELBASE.dll, version: 6.3.9600.16408, time stamp: 0x523d4548
Exception code: 0xc06d007e
Fault offset: 0x00012eec
Faulting process id: 0x110c
Faulting application start time: 0xfixmapi.exe0
Faulting application path: fixmapi.exe1
Faulting module path: fixmapi.exe2
Report Id: fixmapi.exe3
Faulting package full name: fixmapi.exe4
Faulting package-relative application ID: fixmapi.exe5
 
Error: (01/18/2014 03:51:03 AM) (Source: Application Error) (User: )
Description: Faulting application name: fixmapi.exe, version: 6.3.9600.16384, time stamp: 0x52158b32
Faulting module name: KERNELBASE.dll, version: 6.3.9600.16408, time stamp: 0x523d4548
Exception code: 0xc06d007e
Fault offset: 0x00012eec
Faulting process id: 0x28f4
Faulting application start time: 0xfixmapi.exe0
Faulting application path: fixmapi.exe1
Faulting module path: fixmapi.exe2
Report Id: fixmapi.exe3
Faulting package full name: fixmapi.exe4
Faulting package-relative application ID: fixmapi.exe5
 
Error: (01/18/2014 03:50:52 AM) (Source: Application Error) (User: )
Description: Faulting application name: fixmapi.exe, version: 6.3.9600.16384, time stamp: 0x52158b32
Faulting module name: KERNELBASE.dll, version: 6.3.9600.16408, time stamp: 0x523d4548
Exception code: 0xc06d007e
Fault offset: 0x00012eec
Faulting process id: 0x3274
Faulting application start time: 0xfixmapi.exe0
Faulting application path: fixmapi.exe1
Faulting module path: fixmapi.exe2
Report Id: fixmapi.exe3
Faulting package full name: fixmapi.exe4
Faulting package-relative application ID: fixmapi.exe5
 
 
System errors:
=============
Error: (01/21/2014 03:05:08 AM) (Source: DCOM) (User: NT AUTHORITY)
Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}NT AUTHORITYLOCAL SERVICES-1-5-19LocalHost (Using LRPC)UnavailableUnavailable
 
Error: (01/21/2014 03:04:37 AM) (Source: Service Control Manager) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.
 
Error: (01/21/2014 03:04:06 AM) (Source: Service Control Manager) (User: )
Description: The Software Protection service failed to start due to the following error: 
%%1053
 
Error: (01/21/2014 03:04:06 AM) (Source: Service Control Manager) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Software Protection service to connect.
 
Error: (01/21/2014 03:01:17 AM) (Source: EventLog) (User: )
Description: The previous system shutdown at 2:39:20 AM on ?1/?21/?2014 was unexpected.
 
Error: (01/21/2014 02:47:33 AM) (Source: DCOM) (User: NT AUTHORITY)
Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}NT AUTHORITYLOCAL SERVICES-1-5-19LocalHost (Using LRPC)UnavailableUnavailable
 
Error: (01/21/2014 02:42:28 AM) (Source: Service Control Manager) (User: )
Description: The Software Protection service failed to start due to the following error: 
%%1053
 
Error: (01/21/2014 02:42:28 AM) (Source: Service Control Manager) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Software Protection service to connect.
 
Error: (01/21/2014 02:39:20 AM) (Source: EventLog) (User: )
Description: The previous system shutdown at 2:27:55 AM on ?1/?21/?2014 was unexpected.
 
Error: (01/21/2014 00:36:09 AM) (Source: DCOM) (User: NT AUTHORITY)
Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}NT AUTHORITYLOCAL SERVICES-1-5-19LocalHost (Using LRPC)UnavailableUnavailable
 
 
Microsoft Office Sessions:
=========================
Error: (01/21/2014 03:11:14 AM) (Source: Application Error)(User: )
Description: dragon.exe31.0.0.052cc43d4dragon.dll31.0.0.052cc425080000003005733a01b5801cf1688b6e02b30C:\Program Files (x86)\Comodo\Dragon\dragon.exeC:\Program Files (x86)\Comodo\Dragon\dragon.dllf9dda473-827b-11e3-be82-645a04869b79
 
Error: (01/21/2014 03:10:01 AM) (Source: ESENT)(User: )
Description: DllHost6032WebCacheLocal: -566
 
Error: (01/21/2014 03:10:01 AM) (Source: ESENT)(User: )
Description: DllHost6032WebCacheLocal: C:\Users\person\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat1218 (0x000004c2)0x41f090x41ded-5660x41f0e
 
Error: (01/19/2014 08:56:44 AM) (Source: Application Hang)(User: )
Description: backgroundTaskHost.exe6.3.9600.163841afc01cf15259a8aea9d4294967295C:\WINDOWS\system32\backgroundTaskHost.exee830f25c-8119-11e3-be7f-645a04869b79Facebook.Facebook_1.2.0.12_x64__8xx8rvfyw5nntApp
 
Error: (01/18/2014 10:23:13 PM) (Source: Application Error)(User: )
Description: quickset.exe10.15.18.35135633dquickset.exe10.15.18.35135633dc0000005000000000001847d122c01cf146ec06bebc4C:\Program Files\Dell\QuickSet\quickset.exeC:\Program Files\Dell\QuickSet\quickset.exe68739bb1-80c1-11e3-be7f-645a04869b79
 
Error: (01/18/2014 09:38:55 AM) (Source: Application Hang)(User: )
Description: backgroundTaskHost.exe6.3.9600.163841f1401cf1461a2073e7f4294967295C:\WINDOWS\system32\backgroundTaskHost.exea281b4fc-8056-11e3-be7e-74867a3f3b14Facebook.Facebook_1.2.0.12_x64__8xx8rvfyw5nntApp
 
Error: (01/18/2014 09:03:56 AM) (Source: Application Hang)(User: )
Description: backgroundTaskHost.exe6.3.9600.16384139801cf145d71229aaf4294967295C:\WINDOWS\system32\backgroundTaskHost.exebeece3bf-8051-11e3-be7e-74867a3f3b14Facebook.Facebook_1.2.0.12_x64__8xx8rvfyw5nntApp
 
Error: (01/18/2014 03:51:24 AM) (Source: Application Error)(User: )
Description: fixmapi.exe6.3.9600.1638452158b32KERNELBASE.dll6.3.9600.16408523d4548c06d007e00012eec110c01cf1432d79570a4C:\WINDOWS\SysWOW64\fixmapi.exeC:\WINDOWS\SYSTEM32\KERNELBASE.dll16fbc6ca-8026-11e3-be7e-74867a3f3b14
 
Error: (01/18/2014 03:51:03 AM) (Source: Application Error)(User: )
Description: fixmapi.exe6.3.9600.1638452158b32KERNELBASE.dll6.3.9600.16408523d4548c06d007e00012eec28f401cf1432cb6252cdC:\WINDOWS\SysWOW64\fixmapi.exeC:\WINDOWS\SYSTEM32\KERNELBASE.dll0a9eaba5-8026-11e3-be7e-74867a3f3b14
 
Error: (01/18/2014 03:50:52 AM) (Source: Application Error)(User: )
Description: fixmapi.exe6.3.9600.1638452158b32KERNELBASE.dll6.3.9600.16408523d4548c06d007e00012eec327401cf1432c51ec689C:\WINDOWS\SysWOW64\fixmapi.exeC:\WINDOWS\SYSTEM32\KERNELBASE.dll03f2aebe-8026-11e3-be7e-74867a3f3b14
 
 
CodeIntegrity Errors:
===================================
  Date: 2014-01-21 03:10:12.779
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\guard64.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-01-21 03:05:25.405
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\guard64.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2014-01-21 03:04:57.399
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\guard64.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-01-21 03:04:35.824
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\guard64.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-01-21 02:55:02.962
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\guard64.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-01-21 02:47:40.775
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\guard64.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2014-01-21 02:42:42.055
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\guard64.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-01-21 02:40:53.379
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\guard64.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-01-21 01:11:57.678
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\SysWOW64\guard32.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2014-01-21 01:11:56.816
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\SysWOW64\guard32.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
 
=========================== Installed Programs ============================
 
Adobe Flash Player 12 Plugin (Version: 12.0.0.43)
Amazon 1Button App for Windows Taskbar (Version: 1.0.0.2)
avast! Free Antivirus (Version: 9.0.2011)
BitRaider Web Client (Version: 1.1.9.9)
Comodo Dragon (Version: 31.0.0.0)
COMODO Firewall (Version: 6.3.39949.2976)
D3DX10 (Version: 15.4.2368.0902)
Dell Backup and Recovery - Support Software (Version: 1.5.0.0)
Dell Backup and Recovery (Version: 1.5.0.0)
Dell Digital Delivery (Version: 2.6.1000.0)
Dell Product Registration (Version: 1.16.1)
Dell System Detect (Version: 5.4.0.4)
Dell Touchpad (Version: 16.3.7.0)
Dell Update (Version: 0.9.1115.0)
Dell WLAN and Bluetooth Client Installation (Version: 10.0)
DSC/AA Factory Installer (Version: 3.3.6261.27)
Google Toolbar for Internet Explorer (Version: 1.0.0)
Google Toolbar for Internet Explorer (Version: 7.5.4805.320)
Google Update Helper (Version: 1.3.22.3)
Intel® Management Engine Components (Version: 8.1.0.1252)
Intel® Processor Graphics (Version: 10.18.10.3379)
Intel® Rapid Storage Technology (Version: 11.7.0.1013)
Intel® Trusted Connect Service Client (Version: 1.24.388.1)
Junk Mail filter update (Version: 16.4.3508.0205)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Office 365 Home Premium - en-us (Version: 15.0.4551.1512)
Microsoft Silverlight (Version: 5.1.20913.0)
Microsoft SkyDrive (Version: 17.0.2015.0811)
Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.59193)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Movie Maker (Version: 16.4.3508.0205)
MSVCRT (Version: 15.4.2862.0708)
MSVCRT_amd64 (Version: 15.4.2862.0708)
MSVCRT110 (Version: 16.4.1108.0727)
MSVCRT110_amd64 (Version: 16.4.1109.0912)
My Dell (Version: 3.4.6422.14)
Office 15 Click-to-Run Extensibility Component (Version: 15.0.4454.1510)
Office 15 Click-to-Run Licensing Component (Version: 15.0.4454.1510)
Office 15 Click-to-Run Localization Component (Version: 15.0.4454.1510)
Photo Gallery (Version: 16.4.3508.0205)
Qualcomm Atheros Bluetooth Suite (64) (Version: 8.0.0.218)
Quickset64 (Version: 10.15.018)
Realtek High Definition Audio Driver (Version: 6.0.1.6959)
Realtek USB 2.0 Card Reader (Version: 6.1.8400.39030)
Shared C Run-time for x64 (Version: 10.0.0)
Star Wars The Old Republic (Version: 7.0.0.30)
Star Wars: The Old Republic (Version: 1.00)
Windows Live Communications Platform (Version: 16.4.3508.0205)
Windows Live Essentials (Version: 16.4.3508.0205)
Windows Live Installer (Version: 16.4.3508.0205)
Windows Live Mail (Version: 16.4.3508.0205)
Windows Live Messenger (Version: 16.4.3508.0205)
Windows Live MIME IFilter (Version: 16.4.3508.0205)
Windows Live Photo Common (Version: 16.4.3508.0205)
Windows Live PIMT Platform (Version: 16.4.3508.0205)
Windows Live SOXE (Version: 16.4.3508.0205)
Windows Live SOXE Definitions (Version: 16.4.3508.0205)
Windows Live UX Platform (Version: 16.4.3508.0205)
Windows Live UX Platform Language Pack (Version: 16.4.3508.0205)
Windows Live Writer (Version: 16.4.3508.0205)
Windows Live Writer Resources (Version: 16.4.3508.0205)
 
========================= Devices: ================================
 
Could not list devices.
 
========================= Memory info: ===================================
 
Percentage of memory in use: 34%
Total physical RAM: 6013.27 MB
Available physical RAM: 3909.72 MB
Total Pagefile: 6973.27 MB
Available Pagefile: 4314.61 MB
Total Virtual: 4095.88 MB
Available Virtual: 3969.43 MB
 
========================= Partitions: =====================================
 
1 Drive c: (OS) (Fixed) (Total:452.09 GB) (Free:387.88 GB) NTFS
 
========================= Users: ========================================
 
User accounts for \\PLACE
 
Administrator            day                      Guest                    
person                   
 
 
**** End of log ****


#4 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,490 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:01:21 AM

Posted 21 January 2014 - 01:49 PM

Please post the rest.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#5 Druidic

Druidic
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:11:21 PM

Posted 22 January 2014 - 12:52 AM

okay im finishing



#6 Druidic

Druidic
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:11:21 PM

Posted 22 January 2014 - 03:28 AM

# AdwCleaner v3.017 - Report created 22/01/2014 at 01:52:26
# Updated 12/01/2014 by Xplode
# Operating System : Windows 8.1  (64 bits)
# Username : day - PLACE
# Running from : C:\Users\person\Downloads\AdwCleaner (1).exe
# Option : Scan

***** [ Services ] *****

***** [ Files / Folders ] *****

***** [ Shortcuts ] *****

***** [ Registry ] *****

Key Found : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
Key Found : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Key Found : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16384

-\\ Google Chrome v

[ File : C:\Users\day\AppData\Local\Google\Chrome\User Data\Default\preferences ]

[ File : C:\Users\person\AppData\Local\Google\Chrome\User Data\Default\preferences ]

*************************

AdwCleaner[R0].txt - [961 octets] - [22/01/2014 01:52:26]

########## EOF - \AdwCleaner\AdwCleaner[R0].txt - [1020 octets] ##########



#7 Druidic

Druidic
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:11:21 PM

Posted 22 January 2014 - 04:20 AM

# AdwCleaner v3.017 - Report created 22/01/2014 at 01:52:26

# Updated 12/01/2014 by Xplode
# Operating System : Windows 8.1  (64 bits)
# Username : day - PLACE
# Running from : C:\Users\person\Downloads\AdwCleaner (1).exe
# Option : Scan
 
***** [ Services ] *****
 
 
***** [ Files / Folders ] *****
 
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
Key Found : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
Key Found : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Key Found : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
 
***** [ Browsers ] *****
 
-\\ Internet Explorer v11.0.9600.16384
 
 
-\\ Google Chrome v
 
[ File : C:\Users\day\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
 
[ File : C:\Users\person\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
 
*************************
 
AdwCleaner[R0].txt - [961 octets] - [22/01/2014 01:52:26]
 
########## EOF - \AdwCleaner\AdwCleaner[R0].txt - [1020 octets] ##########

tdss killer logs keep saing post is too long . ill try splitting them up






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users