Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

homepage has been changed


  • Please log in to reply
14 replies to this topic

#1 MrMajeika

MrMajeika

  • Members
  • 125 posts
  • OFFLINE
  •  
  • Local time:02:25 AM

Posted 01 February 2014 - 02:10 PM

My homepage for some reason has been changed and to i think something called websearch, can't remember properly as i have changed it back now. Also the default search bar changed but i have deleted it. Just worried that there is something on my computer, I have run MalwareBytes and it came up with a couple of trojans which have now been removed. Anything else I should run?

 

 

 

 

 

 

 

 

 



BC AdBot (Login to Remove)

 


#2 xXToffeeXx

xXToffeeXx

    Bleepin' Polar Bear


  • Malware Response Instructor
  • 6,086 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:The Arctic Circle
  • Local time:03:25 AM

Posted 01 February 2014 - 04:26 PM

Hi,
 
Please download AdwCleaner by Xplode and save to your Desktop.

  • Double click on AdwCleaner.exe to run the tool.
    Vista/Windows 7/8 users right-click and select Run As Administrator.
  • Click on the Scan button.
  • AdwCleaner will begin...be patient as the scan may take some time to complete.
  • Click on the Clean button.
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
  • After rebooting, a logfile report (AdwCleaner[S#].txt) will open automatically (where the largest value of # represents the most recent report).
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of that logfile will also be saved in the C:\AdwCleaner folder.

 

-------------


thisisujrt.gif Please download Junkware Removal Tool to your desktop.

  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.

 

xXToffeeXx~


~If I am helping you and you have not had a reply from me in two days, please send me a PM~

 

logo-25.pngID Ransomware - Identify What Ransomware Encrypted Your Files [Support Topic] - If we have helped you out and you want to support what we do, you can do so here

 

 ~Twitter~ | ~Malware Analyst at Emsisoft~


#3 MrMajeika

MrMajeika
  • Topic Starter

  • Members
  • 125 posts
  • OFFLINE
  •  
  • Local time:02:25 AM

Posted 02 February 2014 - 07:30 PM

# AdwCleaner v3.018 - Report created 03/02/2014 at 00:09:27
# Updated 28/01/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Robert - ROBERT-PC
# Running from : C:\Users\Robert\Desktop\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\Users\Robert\AppData\Local\torch

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16428


-\\ Mozilla Firefox v26.0 (en-US)

[ File : C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\pmdi8ids.default-1351194393250\prefs.js ]

Line Deleted : user_pref("browser.search.defaultenginename,S", "WebSearch");
Line Deleted : user_pref("browser.search.defaulturl", "hxxp://websearch.searchinweb.info/?pid=1273&r=2014/02/01&hid=10220156603326327033&lg=EN&cc=GB&unqvl=47&l=1&q=");
Line Deleted : user_pref("browser.search.order.1", "WebSearch");
Line Deleted : user_pref("browser.search.order.1,S", "WebSearch");
Line Deleted : user_pref("browser.search.selectedEngine,S", "WebSearch");
Line Deleted : user_pref("keyword.URL", "hxxp://websearch.searchinweb.info/?pid=1273&r=2014/02/01&hid=10220156603326327033&lg=EN&cc=GB&unqvl=47&l=1&q=");

-\\ Google Chrome v

[ File : C:\Users\Robert\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Deleted : homepage
Deleted : urls_to_restore_on_startup

*************************

AdwCleaner[R0].txt - [14780 octets] - [07/12/2013 01:13:19]
AdwCleaner[R1].txt - [1063 octets] - [10/12/2013 18:26:19]
AdwCleaner[R2].txt - [2426 octets] - [03/02/2014 00:08:29]
AdwCleaner[S0].txt - [14731 octets] - [07/12/2013 01:15:05]
AdwCleaner[S1].txt - [1127 octets] - [10/12/2013 18:27:46]
AdwCleaner[S2].txt - [2371 octets] - [03/02/2014 00:09:27]

########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [2431 octets] ##########

 

 

 

 

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.0 (01.07.2014:1)
OS: Windows 7 Home Premium x64
Ran by Robert on 03/02/2014 at  0:17:15.05
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files

Successfully deleted: [File] C:\windows\Tasks\Happy Lyrics Update.job



~~~ Folders

Successfully deleted: [Folder] "C:\ProgramData\youtubeadblocker"



~~~ FireFox

Emptied folder: C:\Users\Robert\AppData\Roaming\mozilla\firefox\profiles\pmdi8ids.default-1351194393250\minidumps [30 files]



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 03/02/2014 at  0:30:11.28
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


 



#4 xXToffeeXx

xXToffeeXx

    Bleepin' Polar Bear


  • Malware Response Instructor
  • 6,086 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:The Arctic Circle
  • Local time:03:25 AM

Posted 03 February 2014 - 11:18 AM

Hi,
 
I'd like us to scan your machine with ESET OnlineScan

  • Hold down Control and click on this link to open ESET OnlineScan in a new window.
  • Click the esetonlinebtn.png button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the esetsmartinstaller_enu.png icon on your desktop.
  • Check "YES, I accept the Terms of Use."
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Under scan settings, check "Scan Archives" and "Remove found threats"
  • Click Advanced settings and select the following:
    • Scan potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, click List Threats
  • Click Export, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Click the Back button.
  • Click the Finish button.

 

-------------

Please download MiniToolBox, save it to your desktop and run it.
Checkmark the following checkboxes:

  • Flush DNS
  • Report IE Proxy Settings
  • Reset IE Proxy Settings
  • Report FF Proxy Settings
  • Reset FF Proxy Settings
  • List content of Hosts
  • List IP configuration
  • List Winsock Entries
  • List last 10 Event Viewer log
  • List Installed Programs
  • List Devices
  • List Users, Partitions and Memory size.
  • List Minidump Files
  • List Restore Points

Click Go and post the result (Result.txt). A copy of Result.txt will be saved in the same directory the tool is run.
 
Note: When using "Reset FF Proxy Settings" option Firefox should be closed.

-------------

Also, how is your computer running now?
 
xXToffeeXx~


~If I am helping you and you have not had a reply from me in two days, please send me a PM~

 

logo-25.pngID Ransomware - Identify What Ransomware Encrypted Your Files [Support Topic] - If we have helped you out and you want to support what we do, you can do so here

 

 ~Twitter~ | ~Malware Analyst at Emsisoft~


#5 MrMajeika

MrMajeika
  • Topic Starter

  • Members
  • 125 posts
  • OFFLINE
  •  
  • Local time:02:25 AM

Posted 05 February 2014 - 05:57 AM

C:\Users\All Users\InstallMate\{0D44A143-88C2-407A-A291-C0E0D6A783B5}\Custom.dll    Win32/InstalleRex.M application    
C:\Users\All Users\InstallMate\{29F8C73F-515F-4B84-A96F-197DF21BE5C9}\Custom.dll    Win32/InstalleRex.M application    
C:\Windows\SysWOW64\Adobe\Shockwave 11\gt.exe    Win32/Bundled.Toolbar.Google.D application    
C:\$Recycle.Bin\S-1-5-21-3534789133-3684532335-1148534474-1001\$RY91KPT\readme.zip    NSIS/TrojanDownloader.Adload.J trojan    deleted - quarantined
C:\Program Files (x86)\WSSvc.dll    a variant of Win32/SProtector.D application    cleaned by deleting - quarantined
C:\Program Files (x86)\WS_x64.Enabler    a variant of Win64/SProtector.A application    cleaned by deleting - quarantined
C:\ProgramData\InstallMate\{0D44A143-88C2-407A-A291-C0E0D6A783B5}\Custom.dll    Win32/InstalleRex.M application    cleaned by deleting - quarantined
C:\ProgramData\InstallMate\{29F8C73F-515F-4B84-A96F-197DF21BE5C9}\Custom.dll    Win32/InstalleRex.M application    cleaned by deleting - quarantined
C:\Users\Robert\AppData\Local\Temp\DownloadManagerR.exe    a variant of Win32/OutBrowse.D application    cleaned by deleting - quarantined
C:\Users\Robert\AppData\Local\Temp\dlmEF85.tmp\flactomp3_setup.exe    a variant of Win32/OutBrowse.D application    cleaned by deleting - quarantined
C:\Users\Robert\Downloads\cbsidlm-cbsi176-Free_Flac_to_MP3-ORG-75758784.exe    a variant of Win32/CNETInstaller.B application    cleaned by deleting - quarantined
C:\Users\Robert\Downloads\ccsetup314.exe    Win32/Bundled.Toolbar.Google.E application    cleaned by deleting - quarantined
C:\Users\Robert\Downloads\ccsetup315.exe    Win32/Bundled.Toolbar.Google.E application    cleaned by deleting - quarantined
C:\Users\Robert\Downloads\ccsetup317.exe    Win32/Bundled.Toolbar.Google.E application    cleaned by deleting - quarantined
C:\Users\Robert\Downloads\ccsetup319.exe    Win32/Bundled.Toolbar.Google.E application    cleaned by deleting - quarantined
C:\Users\Robert\Downloads\ccsetup402.exe    Win32/Bundled.Toolbar.Google.D application    cleaned by deleting - quarantined
C:\Users\Robert\Downloads\ccsetup409.exe    Win32/Bundled.Toolbar.Google.D application    cleaned by deleting - quarantined
C:\Users\Robert\Downloads\Katy Perry - PRISM (Deluxe) {2013-Album}\readme.zip    NSIS/TrojanDownloader.Adload.J trojan    deleted - quarantined
C:\Windows\Installer\MSI11BD.tmp    a variant of Win32/Bundled.Toolbar.Ask.F application    cleaned by deleting - quarantined
C:\Windows\System32\Adobe\Shockwave 11\gt.exe    Win32/Bundled.Toolbar.Google.D application    cleaned by deleting - quarantined
 

MiniToolBox by Farbar  Version: 23-01-2014
Ran by Robert (administrator) on 05-02-2014 at 10:49:39
Running from "C:\Users\Robert\Desktop"
Microsoft Windows 7 Home Premium  Service Pack 1 (X64)
Boot Mode: Normal
***************************************************************************

========================= Flush DNS: ===================================

Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========================= IE Proxy Settings: ==============================

Proxy is not enabled.
No Proxy Server is set.

"Reset IE Proxy Settings": IE Proxy Settings were reset.

========================= FF Proxy Settings: ==============================


"Reset FF Proxy Settings": Firefox Proxy settings were reset.

========================= Hosts content: =================================



========================= IP Configuration: ================================

Atheros AR9285 Wireless Network Adapter = Wireless Network Connection (Connected)
Marvell Yukon 88E8040 Family PCI-E Fast Ethernet Controller = Local Area Connection 2 (Media disconnected)


# ----------------------------------
# IPv4 Configuration
# ----------------------------------
pushd interface ipv4

reset
set global icmpredirects=enabled
add route prefix=169.254.0.0/16 interface="iftype0_0" nexthop=192.168.1.5 metric=1 publish=Yes


popd
# End of IPv4 configuration



Windows IP Configuration

   Host Name . . . . . . . . . . . . : Robert-PC
   Primary Dns Suffix  . . . . . . . :
   Node Type . . . . . . . . . . . . : Hybrid
   IP Routing Enabled. . . . . . . . : No
   WINS Proxy Enabled. . . . . . . . : No

Wireless LAN adapter Wireless Network Connection:

   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Atheros AR9285 Wireless Network Adapter
   Physical Address. . . . . . . . . : 4C-ED-DE-64-6D-92
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
   Link-local IPv6 Address . . . . . : fe80::9519:d459:ccca:d0ab%21(Preferred)
   IPv4 Address. . . . . . . . . . . : 192.168.1.8(Preferred)
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Lease Obtained. . . . . . . . . . : 04 February 2014 21:52:43
   Lease Expires . . . . . . . . . . : 06 February 2014 10:45:37
   Default Gateway . . . . . . . . . : 192.168.1.1
   DHCP Server . . . . . . . . . . . : 192.168.1.1
   DHCPv6 IAID . . . . . . . . . . . : 458026462
   DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-13-FB-13-43-00-24-54-3F-B7-5E
   DNS Servers . . . . . . . . . . . : 192.168.1.1
                                       0.0.0.0
   NetBIOS over Tcpip. . . . . . . . : Enabled

Ethernet adapter Local Area Connection 2:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Marvell Yukon 88E8040 Family PCI-E Fast Ethernet Controller
   Physical Address. . . . . . . . . : 00-24-54-E9-C4-0B
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes

Tunnel adapter isatap.{BB4136A7-C163-42E8-9AD8-04EF754654DC}:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Microsoft ISATAP Adapter #3
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
DNS request timed out.
    timeout was 2 seconds.
Server:  UnKnown
Address:  192.168.1.1

DNS request timed out.
    timeout was 2 seconds.
Name:    google.com
Address:  2a00:1450:4009:803::1005


Pinging google.com [173.194.34.131] with 32 bytes of data:
Reply from 173.194.34.131: bytes=32 time=30ms TTL=55
Reply from 173.194.34.131: bytes=32 time=30ms TTL=55

Ping statistics for 173.194.34.131:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 30ms, Maximum = 30ms, Average = 30ms
Server:  UnKnown
Address:  192.168.1.1

Name:    yahoo.com
Addresses:  98.139.183.24
      206.190.36.45
      98.138.253.109


Pinging yahoo.com [98.139.183.24] with 32 bytes of data:
Reply from 98.139.183.24: bytes=32 time=133ms TTL=50
Reply from 98.139.183.24: bytes=32 time=137ms TTL=50

Ping statistics for 98.139.183.24:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 133ms, Maximum = 137ms, Average = 135ms

Pinging 127.0.0.1 with 32 bytes of data:
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128

Ping statistics for 127.0.0.1:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 0ms, Maximum = 0ms, Average = 0ms
===========================================================================
Interface List
 21...4c ed de 64 6d 92 ......Atheros AR9285 Wireless Network Adapter
 11...00 24 54 e9 c4 0b ......Marvell Yukon 88E8040 Family PCI-E Fast Ethernet Controller
  1...........................Software Loopback Interface 1
 20...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #3
===========================================================================

IPv4 Route Table
===========================================================================
Active Routes:
Network Destination        Netmask          Gateway       Interface  Metric
          0.0.0.0          0.0.0.0      192.168.1.1      192.168.1.8     25
        127.0.0.0        255.0.0.0         On-link         127.0.0.1    306
        127.0.0.1  255.255.255.255         On-link         127.0.0.1    306
  127.255.255.255  255.255.255.255         On-link         127.0.0.1    306
      169.254.0.0      255.255.0.0      192.168.1.5      192.168.1.8     26
      192.168.1.0    255.255.255.0         On-link       192.168.1.8    281
      192.168.1.8  255.255.255.255         On-link       192.168.1.8    281
    192.168.1.255  255.255.255.255         On-link       192.168.1.8    281
        224.0.0.0        240.0.0.0         On-link         127.0.0.1    306
        224.0.0.0        240.0.0.0         On-link       192.168.1.8    281
  255.255.255.255  255.255.255.255         On-link         127.0.0.1    306
  255.255.255.255  255.255.255.255         On-link       192.168.1.8    281
===========================================================================
Persistent Routes:
  Network Address          Netmask  Gateway Address  Metric
      169.254.0.0      255.255.0.0      192.168.1.5       1
===========================================================================

IPv6 Route Table
===========================================================================
Active Routes:
 If Metric Network Destination      Gateway
  1    306 ::1/128                  On-link
 21    281 fe80::/64                On-link
 21    281 fe80::9519:d459:ccca:d0ab/128
                                    On-link
  1    306 ff00::/8                 On-link
 21    281 ff00::/8                 On-link
===========================================================================
Persistent Routes:
  None
========================= Winsock entries =====================================

Catalog5 01 mswsock.dll [] (Microsoft Corporation)
ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"

Catalog5 02 C:\windows\SysWOW64\napinsp.dll [52224] (Microsoft Corporation)
Catalog5 03 C:\windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 04 C:\windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 05 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280] (Microsoft Corp.)
Catalog5 06 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280] (Microsoft Corp.)
Catalog5 07 C:\windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog5 08 C:\windows\SysWOW64\winrnr.dll [20992] (Microsoft Corporation)
Catalog9 01 C:\windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 02 C:\windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 03 C:\windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 04 C:\windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 05 C:\windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 06 C:\windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 07 C:\windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 08 C:\windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 09 C:\windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 10 C:\windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
x64-Catalog5 01 mswsock.dll [File Not found] (Microsoft Corporation)
ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"

x64-Catalog5 02 C:\Windows\System32\napinsp.dll [68096] (Microsoft Corporation)
x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
x64-Catalog5 04 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
x64-Catalog5 05 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [171392] (Microsoft Corp.)
x64-Catalog5 06 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [171392] (Microsoft Corp.)
x64-Catalog5 07 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog5 08 C:\Windows\System32\winrnr.dll [28672] (Microsoft Corporation)
x64-Catalog9 01 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 02 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 03 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 04 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 05 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 06 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 07 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 08 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 09 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 10 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)

========================= Event log errors: ===============================

Application errors:
==================
Error: (02/05/2014 10:43:49 AM) (Source: Google Update) (User: Robert-PC)
Description: Network Request Error.
Error: 0x80072ee7. Http status code: 0.
Url=https://www.facebook.com/omaha/update.php
Trying config: source=FireFox, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80004005. Http status code 0.
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80004005. Http status code 0.
Trying config: source=FireFox, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80004005. Http status code 0.
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80

Error: (02/05/2014 04:29:05 AM) (Source: Google Update) (User: Robert-PC)
Description: Network Request Error.
Error: 0x80072ee7. Http status code: 0.
Url=https://www.facebook.com/omaha/update.php
Trying config: source=FireFox, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80004005. Http status code 0.
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80004005. Http status code 0.
Trying config: source=FireFox, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80004005. Http status code 0.
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80

Error: (02/05/2014 02:21:32 AM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (02/04/2014 09:59:39 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (02/04/2014 09:59:29 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (02/04/2014 09:59:24 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (02/04/2014 09:59:12 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.


System errors:
=============
Error: (02/04/2014 09:48:31 PM) (Source: Service Control Manager) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
TfFsMon
TFSysMon

Error: (02/03/2014 11:45:41 PM) (Source: Service Control Manager) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
TfFsMon
TFSysMon


Microsoft Office Sessions:
=========================
Error: (02/05/2014 10:43:49 AM) (Source: Google Update)(User: Robert-PC)
Description: Network Request Error.
Error: 0x80072ee7. Http status code: 0.
Url=https://www.facebook.com/omaha/update.php
Trying config: source=FireFox, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80004005. Http status code 0.
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80004005. Http status code 0.
Trying config: source=FireFox, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80004005. Http status code 0.
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80

Error: (02/05/2014 04:29:05 AM) (Source: Google Update)(User: Robert-PC)
Description: Network Request Error.
Error: 0x80072ee7. Http status code: 0.
Url=https://www.facebook.com/omaha/update.php
Trying config: source=FireFox, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80004005. Http status code 0.
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80004005. Http status code 0.
Trying config: source=FireFox, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80004005. Http status code 0.
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80

Error: (02/05/2014 02:21:32 AM) (Source: SideBySide)(User: )
Description: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestc:\program files (x86)\ESET\eset online scanner\ESETSmartInstaller.exe

Error: (02/04/2014 09:59:39 PM) (Source: SideBySide)(User: )
Description: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Robert\Desktop\esetsmartinstaller_enu.exe

Error: (02/04/2014 09:59:29 PM) (Source: SideBySide)(User: )
Description: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Robert\Desktop\esetsmartinstaller_enu.exe

Error: (02/04/2014 09:59:24 PM) (Source: SideBySide)(User: )
Description: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Robert\Desktop\esetsmartinstaller_enu.exe

Error: (02/04/2014 09:59:12 PM) (Source: SideBySide)(User: )
Description: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Robert\Desktop\esetsmartinstaller_enu.exe


CodeIntegrity Errors:
===================================
  Date: 2012-04-02 00:43:14.587
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Users\Robert\AppData\Local\Temp\OnlineScanner\Anti-Virus\fsgk.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2012-04-02 00:43:14.546
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Users\Robert\AppData\Local\Temp\OnlineScanner\Anti-Virus\fsgk.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


=========================== Installed Programs ============================

888poker
Ace Stream Media 2.1.5.3 (Version: 2.1.5.3)
Adobe Flash Player 12 ActiveX (Version: 12.0.0.44)
Adobe Flash Player 12 Plugin (Version: 12.0.0.44)
Adobe Reader XI (11.0.05) (Version: 11.0.05)
Adobe Shockwave Player 11.6 (Version: 11.6.8.638)
Atheros Client Installation Program (Version: 1.0.2.1119)
Atheros Client Installation Program (Version: 9.0)
BatteryLifeExtender (Version: 1.0.5)
BitTorrent (Version: 7.8.2.30332)
Canon Easy-WebPrint EX (Version: 1.3.5.0)
Canon IJ Network Scanner Selector EX
Canon IJ Network Tool (Version: 3.1.0)
Canon IJ Scan Utility
Canon MG3200 series MP Drivers (Version: 1.01)
Canon MG3200 series On-screen Manual (Version: 7.5.0)
Canon MG3200 series User Registration
Canon My Image Garden (Version: 1.0.0)
Canon My Image Garden Design Files (Version: 1.0.0)
Canon My Printer (Version: 3.0.0)
Canon Quick Menu (Version: 2.0.0)
CCleaner (Version: 4.09)
Convert Audio Free FLAC to MP3 version 1.0 (Version: 1.0)
CPUID HWMonitor 1.21
CyberLink DVD Suite (Version: 6.0.2806)
CyberLink LabelPrint (Version: 2.5.1916)
CyberLink Power2Go (Version: 6.0.3108a)
CyberLink PowerDirector (Version: 7.0.3213)
CyberLink PowerDVD 8 (Version: 8.0.2815b)
CyberLink PowerProducer (Version: 5.0.1.1812)
CyberLink YouCam (Version: 2.0.3911)
D3DX10 (Version: 15.4.2368.0902)
DivX Setup (Version: 2.6.1.22)
Dusk Till Dawn Poker (Version: )
DVD Flick 1.3.0.7 (Version: 1.3.0.7)
Easy Display Manager (Version: 3.2)
Easy SpeedUp Manager (Version: 3.0.0.5)
EasyBatteryManager (Version: 4.0.0.3)
ESET Online Scanner v3
Facebook Video Calling 2.0.0.447 (Version: 2.0.447)
ffdshow v1.2.4496 [2012-12-13] (Version: 1.2.4496.0)
FLV Player (Version: 1.0)
FM Scout (Version: 3.22)
Football Manager 2005 (Version: 5.0.0)
FormatFactory 3.1.1 (Version: 3.1.1)
Full Tilt Poker (Version: 4.48.2.WIN.FullTilt.COM)
GOM Player (Version: 2.1.50.5145)
Google Talk Plugin (Version: 4.9.1.16010)
ImgBurn (Version: 2.5.7.0)
Intel® Graphics Media Accelerator Driver (Version: 8.15.10.2104)
Intel® Rapid Storage Technology (Version: 9.5.4.1001)
Java 7 Update 51 (Version: 7.0.510)
Java Auto Updater (Version: 2.1.9.8)
Junk Mail filter update (Version: 15.4.3502.0922)
Malwarebytes Anti-Malware version 1.75.0.1300 (Version: 1.75.0.1300)
Marvell Miniport Driver (Version: 11.45.4.3)
Media Player Codec Pack 4.2.7 (Version: 4.2.7)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 (Version: 1.1.4322)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30320)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Games for Windows - LIVE Redistributable (Version: 3.5.92.0)
Microsoft Games for Windows Marketplace (Version: 3.5.50.0)
Microsoft Office 2010 (Version: 14.0.4763.1000)
Microsoft Office Click-to-Run 2010 (Version: 14.0.4763.1000)
Microsoft Office Starter 2010 - English (Version: 14.0.4763.1000)
Microsoft Security Client (Version: 4.4.0304.0)
Microsoft Security Essentials (Version: 4.4.304.0)
Microsoft Silverlight (Version: 5.1.20913.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319 (Version: 10.0.30319)
Mozilla Firefox 26.0 (x86 en-US) (Version: 26.0)
Mozilla Maintenance Service (Version: 26.0)
MSVCRT (Version: 15.4.2862.0708)
MSVCRT_amd64 (Version: 15.4.2862.0708)
MyTomTom 3.2.0.1220 (Version: 3.2.0.1220)
PokerStars
Portforward Static IP Address 1.0.47 (Version: 1.0.47)
Rapport (Version: 3.5.1205.20)
Rapport (Version: 3.5.1304.46)
Realtek High Definition Audio Driver (Version: 6.0.1.6662)
S Agent (Version: 1.0.9)
S Service (Version: 1.0)
Samsung Kies (Version: 2.6.0.13064_2)
Samsung Recovery Solution 4 (Version: 4.0.0.6)
Samsung Story Album Viewer (Version: 1.0.0.13054_1)
Samsung Support Center (Version: 1.0.2)
Samsung Update Plus (Version: 2.0)
SAMSUNG USB Driver for Mobile Phones (Version: 1.5.27.0)
SamsungMovie (Version: 1.0.0)
Skype Click to Call (Version: 6.13.13771)
Skype Translate (Version: 1.0.0.43)
Skype™ 6.11 (Version: 6.11.102)
SopCast 3.5.0 (Version: 3.5.0)
Spotify (Version: 0.8.5.1333.g822e0de8)
SpywareBlaster 5.0 (Version: 5.0.0)
Steam (Version: 1.0.0.0)
StreamTorrent 1.0
StreamTransport version: 1.0.2.2171
SUPERAntiSpyware (Version: 5.1.1002)
swMSM (Version: 12.0.0.1)
Synaptics Pointing Device Driver (Version: 15.0.10.0)
System Requirements Lab CYRI (Version: 6.0.7.0)
System Requirements Lab for Intel (Version: 4.5.15.0)
tbbMeter Loader Service (Version: 1.0.0)
Tournament Indicator 2.1.2
Trusteer Endpoint Protection (Version: 3.5.1304.46)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
User Guide (Version: 1.0)
VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0)
Visual Studio C++ 10.0 Runtime (Version: 10.0.0)
VLC media player 2.1.0 (Version: 2.1.0)
WebCam Recorder
William Hill Poker
Windows Live Communications Platform (Version: 15.4.3502.0922)
Windows Live Essentials (Version: 15.4.3502.0922)
Windows Live Essentials (Version: 15.4.3555.0308)
Windows Live Family Safety (Version: 15.4.3555.0308)
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0)
Windows Live Installer (Version: 15.4.3502.0922)
Windows Live Language Selector (Version: 15.4.3555.0308)
Windows Live Mail (Version: 15.4.3502.0922)
Windows Live Messenger (Version: 15.4.3538.0513)
Windows Live MIME IFilter (Version: 15.4.3502.0922)
Windows Live Movie Maker (Version: 15.4.3502.0922)
Windows Live Photo Common (Version: 15.4.3502.0922)
Windows Live Photo Gallery (Version: 15.4.3502.0922)
Windows Live PIMT Platform (Version: 15.4.3508.1109)
Windows Live SOXE (Version: 15.4.3502.0922)
Windows Live SOXE Definitions (Version: 15.4.3502.0922)
Windows Live Sync (Version: 14.0.8117.416)
Windows Live UX Platform (Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (Version: 15.4.3508.1109)
Windows Live Writer (Version: 15.4.3502.0922)
Windows Live Writer Resources (Version: 15.4.3502.0922)
Windows Media Player Firefox Plugin (Version: 1.0.0.8)
WinPcap 4.1.2 (Version: 4.1.0.2001)
WinZip 16.0 (Version: 16.0.9661)
WS.Supporter 1.80
Xvid 1.2.2 final uninstall (Version: 1.2)
Xvid Video Codec (Version: 1.3.2)
Yahoo! Software Update
Yaniv Card Game v2.8 (Version: 2.8)
Zipeg (Version: 2.9.3.1316)

========================= Devices: ================================


========================= Memory info: ===================================

Percentage of memory in use: 45%
Total physical RAM: 3892.55 MB
Available physical RAM: 2139.57 MB
Total Pagefile: 7783.28 MB
Available Pagefile: 5718.68 MB
Total Virtual: 4095.88 MB
Available Virtual: 3964.04 MB

========================= Partitions: =====================================

1 Drive c: () (Fixed) (Total:365.66 GB) (Free:144.17 GB) NTFS
2 Drive d: () (Fixed) (Total:80 GB) (Free:76.98 GB) NTFS

========================= Users: ========================================

User accounts for \\ROBERT-PC

Administrator            ASPNET                   Guest                    
Robert                   

========================= Minidump Files ==================================

No minidump file found

========================= Restore Points ==================================

26-01-2014 00:52:43 Windows Update
26-01-2014 22:19:22 Installed Java 7 Update 51
29-01-2014 01:28:51 Windows Update
01-02-2014 12:10:50 Installed Rapport
02-02-2014 01:19:04 Windows Update
05-02-2014 02:21:15 Windows Update

**** End of log ****
 

 

Computer seems to be running fine. Eset said that there were three files it could not remove. Are those shown in the report



#6 AdamAL

AdamAL

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:05:25 AM

Posted 05 February 2014 - 09:13 AM

usually I remove such hijackers manually and then check with malwarebytes or adwcleaner



#7 xXToffeeXx

xXToffeeXx

    Bleepin' Polar Bear


  • Malware Response Instructor
  • 6,086 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:The Arctic Circle
  • Local time:03:25 AM

Posted 05 February 2014 - 03:03 PM

Hi,
 
Feel free to locate those files and delete them:
C:\Users\All Users\InstallMate\{0D44A143-88C2-407A-A291-C0E0D6A783B5}\Custom.dll
C:\Users\All Users\InstallMate\{29F8C73F-515F-4B84-A96F-197DF21BE5C9}\Custom.dll
C:\Windows\SysWOW64\Adobe\Shockwave 11\gt.exe
They are adware, so not really dangerous. More annoying than anything. 
 
-------------
 
Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

64-bit users go HERE

  • Double-click SystemLook.exe to run it.
  • Vista and 7 users:: Right click on SystemLook.exe, click Run As Administrator
  • Copy the content of the following box and paste it into the main textfield:

:filefind
*mswsock.dll*

  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.

Note: The log can also be found on your Desktop entitled SystemLook.txt
 
-------------
 
Please download Rkill (courtesy of BleepingComputer.com) to your desktop.
There are 2 different versions. If one of them won't run then download and try to run the other one.
You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.
 
rKill.exehttp://www.bleepingcomputer.com/download/rkill/dl/10/
iExplore.exe (renamed rKill.exe): http://www.bleepingcomputer.com/download/rkill/dl/11/

  • Double-click on the Rkill desktop icon to run the tool.
  • If using Vista or Windows 7 right-click on it and chooseRun As Administrator.
  • black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
  • If not, delete the file, then download and use the one provided in Link 2.
  • Do not reboot until instructed.
  • If the tool does not run from any of the links provided, please let me know.

There should be a text file named Rkill located on your desktop, copy and paste the contents into your next reply.
 
-------------
 

Uninstall adobe shockwave using the control panel and update here.

 

Unless you specifically use Java for something, I suggest uninstalling it.

 

Just a note, using p2p software and torrents is a really good way to get your computer infected with malware. It's possible some of the stuff we removed came from this software.

 
xXToffeeXx~


~If I am helping you and you have not had a reply from me in two days, please send me a PM~

 

logo-25.pngID Ransomware - Identify What Ransomware Encrypted Your Files [Support Topic] - If we have helped you out and you want to support what we do, you can do so here

 

 ~Twitter~ | ~Malware Analyst at Emsisoft~


#8 MrMajeika

MrMajeika
  • Topic Starter

  • Members
  • 125 posts
  • OFFLINE
  •  
  • Local time:02:25 AM

Posted 05 February 2014 - 06:26 PM

SystemLook 30.07.11 by jpshortstuff
Log created at 23:15 on 05/02/2014 by Robert
Administrator - Elevation successful

========== filefind ==========

Searching for "*mswsock.dll*"
C:\Windows\System32\mswsock.dll    --a---- 327168 bytes    [02:36 14/12/2013]    [02:36 14/12/2013] 9A9F9F1A77D6A80EE28B57664F00013E
C:\Windows\System32\en-US\mswsock.dll.mui    --a---- 10752 bytes    [05:35 14/07/2009]    [02:29 14/07/2009] E74EA79B9664AAE95551AF508BA21AE6
C:\Windows\SysWOW64\mswsock.dll    --a---- 231424 bytes    [02:36 14/12/2013]    [02:36 14/12/2013] E94C583CDE2348950155F2AF2876F34D
C:\Windows\SysWOW64\en-US\mswsock.dll.mui    --a---- 10752 bytes    [05:35 14/07/2009]    [02:02 14/07/2009] D6FDB41FBE5E44B18C4079892C71BB69
C:\Windows\winsxs\amd64_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.1.7600.16385_none_144848ad46fcc535\mswsock.dll    --a---- 320000 bytes    [23:21 13/07/2009]    [01:41 14/07/2009] FC76FE3C1E1FDB761244D4F74EF560FD
C:\Windows\winsxs\amd64_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.1.7601.17514_none_16795c7543eb48cf\mswsock.dll    --a---- 326144 bytes    [23:13 08/12/2013]    [05:27 20/11/2010] 1D5185A4C7E6695431AE4B55C3D7D333
C:\Windows\winsxs\amd64_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.1.7601.18254_none_164e004b440bdabf\mswsock.dll    --a---- 327168 bytes    [02:36 14/12/2013]    [02:36 14/12/2013] 9A9F9F1A77D6A80EE28B57664F00013E
C:\Windows\winsxs\amd64_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.1.7601.22444_none_16e26ee85d215bbf\mswsock.dll    --a---- 327168 bytes    [02:36 14/12/2013]    [02:36 14/12/2013] BDDB1FD258B92DEE00F222D3304B5D9C
C:\Windows\winsxs\amd64_microsoft-windows-w..cture-bsp.resources_31bf3856ad364e35_6.1.7600.16385_en-us_29d62e2c7d66c554\mswsock.dll.mui    --a---- 10752 bytes    [05:35 14/07/2009]    [02:29 14/07/2009] E74EA79B9664AAE95551AF508BA21AE6
C:\Windows\winsxs\Backup\amd64_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.1.7601.18254_none_164e004b440bdabf_mswsock.dll_e2ad0f2d    --a---- 327168 bytes    [16:36 14/12/2013]    [02:36 14/12/2013] 9A9F9F1A77D6A80EE28B57664F00013E
C:\Windows\winsxs\Backup\amd64_microsoft-windows-w..cture-bsp.resources_31bf3856ad364e35_6.1.7600.16385_en-us_29d62e2c7d66c554_mswsock.dll.mui_d7c2a730    --a---- 10752 bytes    [05:37 14/07/2009]    [05:37 14/07/2009] E74EA79B9664AAE95551AF508BA21AE6
C:\Windows\winsxs\Backup\x86_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.1.7601.18254_none_ba2f64c78bae6989_mswsock.dll_e2ad0f2d    --a---- 231424 bytes    [16:36 14/12/2013]    [02:36 14/12/2013] E94C583CDE2348950155F2AF2876F34D
C:\Windows\winsxs\Backup\x86_microsoft-windows-w..cture-bsp.resources_31bf3856ad364e35_6.1.7600.16385_en-us_cdb792a8c509541e_mswsock.dll.mui_d7c2a730    --a---- 10752 bytes    [05:37 14/07/2009]    [05:37 14/07/2009] D6FDB41FBE5E44B18C4079892C71BB69
C:\Windows\winsxs\x86_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.1.7600.16385_none_b829ad298e9f53ff\mswsock.dll    --a---- 232448 bytes    [23:12 13/07/2009]    [01:15 14/07/2009] 11A41F17527ED75D6B758FDD7F4FD00D
C:\Windows\winsxs\x86_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.1.7601.17514_none_ba5ac0f18b8dd799\mswsock.dll    --a---- 232448 bytes    [23:13 08/12/2013]    [04:19 20/11/2010] 8999B8631C7FD9F7F9EC3CAFD953BA24
C:\Windows\winsxs\x86_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.1.7601.18254_none_ba2f64c78bae6989\mswsock.dll    --a---- 231424 bytes    [02:36 14/12/2013]    [02:36 14/12/2013] E94C583CDE2348950155F2AF2876F34D
C:\Windows\winsxs\x86_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.1.7601.22444_none_bac3d364a4c3ea89\mswsock.dll    --a---- 231424 bytes    [02:36 14/12/2013]    [02:36 14/12/2013] 6547D445C4B69DC0083B619AC642DF04
C:\Windows\winsxs\x86_microsoft-windows-w..cture-bsp.resources_31bf3856ad364e35_6.1.7600.16385_en-us_cdb792a8c509541e\mswsock.dll.mui    --a---- 10752 bytes    [05:35 14/07/2009]    [02:02 14/07/2009] D6FDB41FBE5E44B18C4079892C71BB69

-= EOF =-

 

 

Rkill 2.6.5 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2014 BleepingComputer.com
More Information about Rkill can be found at this link:
 http://www.bleepingcomputer.com/forums/topic308364.html

Program started at: 02/05/2014 11:19:13 PM in x64 mode.
Windows Version: Windows 7 Home Premium Service Pack 1

Checking for Windows services to stop:

 * No malware services found to stop.

Checking for processes to terminate:

 * No malware processes found to kill.

Checking Registry for malware related settings:

 * No issues found in the Registry.

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
  * HKLM\Software\Classes\exefile\shell\open\command\\IsolatedCommand was changed. It was reset to "%1" %*!

  * HKLM\Software\Classes\exefile\shell\runas\command\\IsolatedCommand was changed. It was reset to "%1" %*!


Performing miscellaneous checks:

 * No issues found.

Checking Windows Service Integrity:

 * No issues found.

Searching for Missing Digital Signatures:

 * No issues found.

Checking HOSTS File:

 * No issues found.

Program finished at: 02/05/2014 11:19:38 PM
Execution time: 0 hours(s), 0 minute(s), and 25 seconds(s)

 

 

I have tried locating the files you said to delete but they do not appear to be there. If i go to C:\Users there is no AllUser. Does this mean they have already been deleted?

 

Why do you recomnmend to uninstall java

 

Thanks
 



#9 xXToffeeXx

xXToffeeXx

    Bleepin' Polar Bear


  • Malware Response Instructor
  • 6,086 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:The Arctic Circle
  • Local time:03:25 AM

Posted 06 February 2014 - 03:19 PM

Hi,

 

Why do you recommend to uninstall java

Java is one of the biggest vectors of infection and many people simply not do need or ever use java. I do not use Java and have felt no effects from this.

 

Some reading on why you probably don't need Java:

You don't need Java
W3Techs usage statistics and market share data of Java on the web

 

-------------

 

I have tried locating the files you said to delete but they do not appear to be there. If i go to C:\Users there is no AllUser. Does this mean they have already been deleted?

Try the steps here and see if you can locate the files after.

 

-------------

 

Press Ctrl and R at the same time and a window named Run... should appear. Type cmd and press enter. A black windows should appear, type netsh winsock reset. Press enter.

 

-------------

 

How is your computer running now, any problems?

 

xXToffeeXx~


~If I am helping you and you have not had a reply from me in two days, please send me a PM~

 

logo-25.pngID Ransomware - Identify What Ransomware Encrypted Your Files [Support Topic] - If we have helped you out and you want to support what we do, you can do so here

 

 ~Twitter~ | ~Malware Analyst at Emsisoft~


#10 MrMajeika

MrMajeika
  • Topic Starter

  • Members
  • 125 posts
  • OFFLINE
  •  
  • Local time:02:25 AM

Posted 06 February 2014 - 08:15 PM

i enabled hidden files and folder and I can still not find them. C:\Users\AllUsers does not appear to be there



#11 xXToffeeXx

xXToffeeXx

    Bleepin' Polar Bear


  • Malware Response Instructor
  • 6,086 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:The Arctic Circle
  • Local time:03:25 AM

Posted 07 February 2014 - 02:51 PM

Hi,

 

Don't worry about it then. The detection is only for Google Toolbar, and it's part of adobe shockwave. You could probably uninstall adobe shockwave and it would remove the file most likely.

 

Did you do the rest of the steps? Also, how is your computer running?

 

xXToffeeXx~


~If I am helping you and you have not had a reply from me in two days, please send me a PM~

 

logo-25.pngID Ransomware - Identify What Ransomware Encrypted Your Files [Support Topic] - If we have helped you out and you want to support what we do, you can do so here

 

 ~Twitter~ | ~Malware Analyst at Emsisoft~


#12 MrMajeika

MrMajeika
  • Topic Starter

  • Members
  • 125 posts
  • OFFLINE
  •  
  • Local time:02:25 AM

Posted 07 February 2014 - 05:48 PM

Ok thanks. Computer seems to be running fine now. Has everything been removed now? I use microsoft security essentials as my antivirus. Is that good enough?



#13 xXToffeeXx

xXToffeeXx

    Bleepin' Polar Bear


  • Malware Response Instructor
  • 6,086 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:The Arctic Circle
  • Local time:03:25 AM

Posted 08 February 2014 - 03:31 PM

Hi,

 

Good to hear, seems we are done here then. One quick tool to be run to clear everything up:

 

Download 51a5ce45263de-delfix.pngDelfix by Xplode to your desktop. Delfix will delete all the used tools and logfiles.


Double-click Delfix.exe to start the tool.
Make sure the following items are checked:

  • Activate UAC (option only available from Vista upwards)
  • Remove disinfection tools
  • Create registry backup
  • Purge System Restore
  • Reset system settings

Now click "Run" and wait patiently.
Once finished a logfile will be created. You don't need to copy and paste it into your next reply.

 

I use microsoft security essentials as my antivirus. Is that good enough?

Yes, Microsoft security essentials should be good enough as your antivirus. You might also want to run a malwarebytes scan every so often too.

 

xXToffeeXx~


~If I am helping you and you have not had a reply from me in two days, please send me a PM~

 

logo-25.pngID Ransomware - Identify What Ransomware Encrypted Your Files [Support Topic] - If we have helped you out and you want to support what we do, you can do so here

 

 ~Twitter~ | ~Malware Analyst at Emsisoft~


#14 MrMajeika

MrMajeika
  • Topic Starter

  • Members
  • 125 posts
  • OFFLINE
  •  
  • Local time:02:25 AM

Posted 09 February 2014 - 06:28 PM

thanks so much for your help really appreciate it



#15 xXToffeeXx

xXToffeeXx

    Bleepin' Polar Bear


  • Malware Response Instructor
  • 6,086 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:The Arctic Circle
  • Local time:03:25 AM

Posted 10 February 2014 - 02:10 PM

Hi,

 

You are most welcome. Stay safe :)

 

xXToffeeXx~


~If I am helping you and you have not had a reply from me in two days, please send me a PM~

 

logo-25.pngID Ransomware - Identify What Ransomware Encrypted Your Files [Support Topic] - If we have helped you out and you want to support what we do, you can do so here

 

 ~Twitter~ | ~Malware Analyst at Emsisoft~





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users