Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected Laptop - Conduit Search, HP Update, etc


  • This topic is locked This topic is locked
24 replies to this topic

#1 union410

union410

  • Members
  • 39 posts
  • OFFLINE
  •  
  • Local time:07:07 PM

Posted 17 March 2014 - 12:51 AM

Hello

 

My laptop is super slow. Doesn't matter if I use IE or Mozilla. I have an HP Update on the lower right of the screen that I can't remove no matter what I do. It only shows up in the browser. Multiple popups with every new screen.

 

This is essentially a home laptop that I really just want to use for work. I don't need anything other than Microsoft Office and the internet.

 

Any help would be awesome.

 

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:26:00 PM, on 3/16/2014
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18975)
Boot mode: Normal

Running processes:
C:\Windows\Explorer.EXE
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\HP\HP Software Update\hpwuschd2.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\PROGRA~1\SearchProtect\SearchProtect\bin\cltmng.exe
C:\PROGRA~1\SearchProtect\UI\bin\cltmngui.exe
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Hp\HP Software Update\HPWUCli.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com/?ctid=CT3317821&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SPD7EF345D-A846-435C-AC09-D35AB3117FAD&SSPV=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Pavilion&pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Pavilion&pf=cnnb
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: CrossriderApp0044150 - {11111111-1111-1111-1111-110411411150} - C:\Program Files\MediaPlayerEnhance\MediaPlayerEnhance-bho.dll
O2 - BHO: CrossriderApp0052800 - {11111111-1111-1111-1111-110511281100} - C:\Program Files\Plus-HD-8.9\Plus-HD-8.9-bho.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\2.0"
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Optimizer Pro] C:\Program Files\Optimizer Pro\OptProLauncher.exe
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\Windows\system32\Macromed\Flash\FlashUtil32_12_0_0_70_Plugin.exe -update plugin
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} (JuniperSetupClientControl Class) - https://juniper.net/dana-cached/sc/JuniperSetupClient.cab
O20 - AppInit_DLLs: C:\PROGRA~1\SearchProtect\SearchProtect\bin\SPVC32Loader.dll c:\progra~1\optimi~1\optpro~1.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f691e717\aestsrv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Search Protect by Conduit Service (CltMngSvc) - Conduit - C:\PROGRA~1\SearchProtect\Main\bin\CltMngSvc.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Google Update Service (gupdate1ca3367d83991a0) (gupdate1ca3367d83991a0) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Hewlett-Packard Corporation - C:\Windows\system32\Hpservice.exe
O23 - Service: HP Support Solutions Framework Service (HPSupportSolutionsFrameworkService) - Hewlett-Packard Company - C:\Program Files\Hp\Common\HPSupportSolutionsFrameworkService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Windows\SMINST\BLService.exe

--
End of file - 8961 bytes



BC AdBot (Login to Remove)

 


#2 TB-Psychotic

TB-Psychotic

  • Malware Response Team
  • 6,349 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:07 AM

Posted 17 March 2014 - 07:14 AM

Hi there,
my name is Marius and I will assist you with your malware related problems.

Before we move on, please read the following points carefully.

  • First, read my instructions completely. If there is anything that you do not understand kindly ask before proceeding.
  • Perform everything in the correct order. Sometimes one step requires the previous one.
  • If you have any problems while following my instructions, Stop there and tell me the exact nature of your problem.
  • Do not run any other scans without instruction or add/remove software unless I tell you to do so. This would change the output of our tools and could be confusing for me.
  • Post all logfiles as a reply rather than as an attachment unless I specifically ask you. If you can not post all logfiles in one reply, feel free to use more posts.
  • If I don't hear from you within 3 days from this initial or any subsequent post, then this thread will be closed.
  • Stay with me. I will give you some advice about prevention after the cleanup process. Absence of symptoms does not always mean the computer is clean.
  • My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.

 

 

 

 

Scan with FRST in normal mode

Please download Farbar's Recovery Scan Tool to your desktop: FRST 32bit or FRST 64bit (If not sure: Start --> Computer (right click) --> properties)

  • Run FRST.
  • Don´t change one of the checkboxes and hit Scan.
  • Logfiles are created on your desktop.
  • Poste the FRST.txt and (after the first scan only!) the Addition.txt.

 

 

 

 

Scan with Gmer rootkit scanner

Please download Gmer from here by clicking on the "Download EXE" Button.

  • Double click on the randomly named GMER.exe. If asked to allow gmer.sys driver to load, please consent.
  • If it gives you a warning about rootkit activity and asks if you want to run scan...click on NO.
  • In the right panel, you will see several boxes that have been checked. Uncheck the following ...
    • Sections
    • IAT/EAT
    • Show All ( should be unchecked by default )
  • Leave everything else as it is.
  • Close all other running programs as well as your Browser.
  • Click the Scan button & wait for it to finish.
  • Once done click on the Save.. button, and in the File name area, type in "ark.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop.
  • Please post the content of the ark.txt here.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries


Proud Member of UNITE & TB
 
My help is free, however, if you want to support my fight against malware, click here --> btn_donate_SM.gif <--(no worries, every little bit helps)

#3 union410

union410
  • Topic Starter

  • Members
  • 39 posts
  • OFFLINE
  •  
  • Local time:07:07 PM

Posted 17 March 2014 - 08:46 PM

Thanks for your quick reply!

 

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-03-2014  01
Ran by Chad (administrator) on CHAD-PC on 17-03-2014 18:34:14
Running from C:\Users\Chad\Downloads
Microsoft® Windows Vista™ Home Premium  Service Pack 1 (X86) OS Language: English(US)
Internet Explorer Version 8
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(ATI Technologies Inc.) C:\Windows\system32\Ati2evxx.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(Hewlett-Packard Corporation) C:\Windows\system32\Hpservice.exe
(ATI Technologies Inc.) C:\Windows\system32\Ati2evxx.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f691e717\aestsrv.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(CyberLink Corp.) C:\Program Files\HP\QuickPlay\QPService.exe
( Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
(Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
() C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
() C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
() C:\Windows\SMINST\BLService.exe
(Conduit) C:\Program Files\SearchProtect\Main\bin\CltMngSvc.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
(Conduit) C:\Program Files\SearchProtect\SearchProtect\bin\cltmng.exe
(Conduit) C:\Program Files\SearchProtect\UI\bin\cltmngui.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
() C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Hewlett-Packard) c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
(Hewlett-Packard) C:\Program Files\Hp\HP Software Update\HPWUCli.exe
(Microsoft Corporation) C:\Windows\system32\wuauclt.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [61440 2008-01-21] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1033512 2008-01-17] (Synaptics, Inc.)
HKLM\...\Run: [UCam_Menu] - C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [222504 2007-12-24] (CyberLink Corp.)
HKLM\...\Run: [QPService] - C:\Program Files\HP\QuickPlay\QPService.exe [468264 2008-05-14] (CyberLink Corp.)
HKLM\...\Run: [QlbCtrl.exe] - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [202032 2008-03-14] ( Hewlett-Packard Development Company, L.P.)
HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [40048 2007-05-11] (Adobe Systems Incorporated)
HKLM\...\Run: [HP Health Check Scheduler] - c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [70912 2008-04-15] (Hewlett-Packard)
HKLM\...\Run: [hpWirelessAssistant] - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [488752 2007-11-20] (Hewlett-Packard Development Company, L.P.)
HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2010-11-29] (Apple Inc.)
HKLM\...\Run: [HP Software Update] - C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM\...\Run: [] - [X]
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKU\S-1-5-21-2716735411-3156541709-3801604676-1000\...\Run: [LightScribe Control Panel] - C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2289664 2008-02-26] (Hewlett-Packard Company)
HKU\S-1-5-21-2716735411-3156541709-3801604676-1000\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-20] (Microsoft Corporation)
HKU\S-1-5-21-2716735411-3156541709-3801604676-1000\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-20] (Microsoft Corporation)
HKU\S-1-5-21-2716735411-3156541709-3801604676-1000\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2009-02-27] (Google Inc.)
HKU\S-1-5-21-2716735411-3156541709-3801604676-1000\...\Run: [Optimizer Pro] - C:\Program Files\Optimizer Pro\OptProLauncher.exe [135160 2014-01-28] (PC Utilities Software Limited)
HKU\S-1-5-21-2716735411-3156541709-3801604676-1000\...\RunOnce: [FlashPlayerUpdate] - C:\Windows\system32\Macromed\Flash\FlashUtil32_12_0_0_70_Plugin.exe -update plugin
AppInit_DLLs: C:\PROGRA~1\SearchProtect\SearchProtect\bin\SPVC32Loader.dll => C:\Program Files\SearchProtect\SearchProtect\bin\SPVC32Loader.dll [1050912 2014-03-03] (Conduit)
AppInit_DLLs:  c:\progra~1\optimi~1\optpro~1.dll => C:\Program Files\Optimizer Pro\OptProCrash.dll [2961368 2014-03-03] ()

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com/?ctid=CT3317821&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SPD7EF345D-A846-435C-AC09-D35AB3117FAD&SSPV=
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Pavilion&pf=cnnb
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
SearchScopes: HKLM - {0E6A666A-D1F0-42A3-B9C0-24F2F6863063} URL = http://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=hp-pvnb
SearchScopes: HKLM - {CD7F680C-9718-4A86-A9BC-FBCFEE7EF20A} URL = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpl
SearchScopes: HKCU - DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://search.conduit.com/Results.aspx?ctid=CT3317821&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=4&UP=SPD7EF345D-A846-435C-AC09-D35AB3117FAD&q={searchTerms}&SSPV=
SearchScopes: HKCU - URL http://search.conduit.com/Results.aspx?ctid=CT3317821&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=4&UP=SPD7EF345D-A846-435C-AC09-D35AB3117FAD&q={searchTerms}&SSPV=
SearchScopes: HKCU - SuggestionsURL_JSON http://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms}
SearchScopes: HKCU - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://search.conduit.com/Results.aspx?ctid=CT3317821&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=4&UP=SPD7EF345D-A846-435C-AC09-D35AB3117FAD&q={searchTerms}&SSPV=
SearchScopes: HKCU - {0E6A666A-D1F0-42A3-B9C0-24F2F6863063} URL = http://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=hp-pvnb
SearchScopes: HKCU - {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL = http://websearch.ask.com/redirect?client=ie&tb=SB&o=14084&src=crm&q={searchTerms}&locale=en_US
SearchScopes: HKCU - {CD7F680C-9718-4A86-A9BC-FBCFEE7EF20A} URL = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpl
SearchScopes: HKCU - {FAEB1A28-7EFD-4BA4-982A-1195CE984420} URL = http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=714647&p={searchTerms}
BHO: No Name - {02478D38-C3F9-4efb-9B51-7695ECA05670} -  No File
BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
BHO: MediaPlayerEnhance - {11111111-1111-1111-1111-110411411150} - C:\Program Files\MediaPlayerEnhance\MediaPlayerEnhance-bho.dll (Feven)
BHO: Plus-HD-8.9 - {11111111-1111-1111-1111-110511281100} - C:\Program Files\Plus-HD-8.9\Plus-HD-8.9-bho.dll (Plus HD)
BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll (Google Inc.)
BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://juniper.net/dana-cached/sc/JuniperSetupClient.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
ShellExecuteHooks:  - {AEB6717E-7E19-11d0-97EE-00C04FD91972} -  No File [ ]
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 184.16.33.54

FireFox:
========
FF ProfilePath: C:\Users\Chad\AppData\Roaming\Mozilla\Firefox\Profiles\sv1ctv5q.default
FF user.js: detected! => C:\Users\Chad\AppData\Roaming\Mozilla\Firefox\Profiles\sv1ctv5q.default\user.js
FF NewTab: hxxp://search.conduit.com/?ctid=CT3317821&octid=EB_ORIGINAL_CTID&SearchSource=69&CUI=&SSPV=&Lay=1&UM=4&UP=SPD7EF345D-A846-435C-AC09-D35AB3117FAD
FF DefaultSearchEngine: Conduit Search
FF SelectedSearchEngine: Conduit Search
FF Homepage: hxxp://search.conduit.com/?ctid=CT3317821&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SPD7EF345D-A846-435C-AC09-D35AB3117FAD&SSPV=
FF Keyword.URL: hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-yff26&p=
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFFICE.DLL (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.)
FF SearchPlugin: C:\Users\Chad\AppData\Roaming\Mozilla\Firefox\Profiles\sv1ctv5q.default\searchplugins\conduit-search.xml
FF SearchPlugin: C:\Users\Chad\AppData\Roaming\Mozilla\Firefox\Profiles\sv1ctv5q.default\searchplugins\yahoo_ff.xml
FF Extension: MediaPlayerEnhance - C:\Users\Chad\AppData\Roaming\Mozilla\Firefox\Profiles\sv1ctv5q.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com [2014-03-16]
FF Extension: Plus-HD-8.9 - C:\Users\Chad\AppData\Roaming\Mozilla\Firefox\Profiles\sv1ctv5q.default\Extensions\3889d70a-3fde-4565-9f53-587ed12a797a@b90fd175-524e-46e6-a91f-624789f3369f.com [2014-03-11]
FF Extension: Plus-HD-5.0 - C:\Users\Chad\AppData\Roaming\Mozilla\Firefox\Profiles\sv1ctv5q.default\Extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com [2014-03-11]
FF Extension: Microsoft .NET Framework Assistant - C:\Users\Chad\AppData\Roaming\Mozilla\Firefox\Profiles\sv1ctv5q.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}(72) [2010-11-18]
FF Extension: Yahoo! Toolbar - C:\Users\Chad\AppData\Roaming\Mozilla\Firefox\Profiles\sv1ctv5q.default\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} [2014-01-23]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []
FF HKLM\...\Firefox\Extensions: [{0329E7D6-6F54-462D-93F6-F5C3118BADF2}] - C:\Program Files\SpeedBit Video Downloader\SPFireFox
FF HKCU\...\Firefox\Extensions: [{6559F149-A8B8-4101-BF51-B328E3352ADB}] - C:\Users\Chad\AppData\Local\{6559F149-A8B8-4101-BF51-B328E3352ADB}

========================== Services (Whitelisted) =================

R2 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f691e717\aestsrv.exe [73728 2008-02-11] (Andrea Electronics Corporation)
S2 ca82e1a5; C:\Program Files\Optimizer Pro\OptProCrashSvc.dll [186496 2014-03-03] ()
R2 CltMngSvc; C:\Program Files\SearchProtect\Main\bin\CltMngSvc.exe [2454816 2014-03-03] (Conduit)
S2 gupdate1ca3367d83991a0; C:\Program Files\Google\Update\GoogleUpdate.exe [133104 2009-09-11] (Google Inc.)
R2 HP Health Check Service; c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [94208 2008-04-15] (Hewlett-Packard)
S2 HPSupportSolutionsFrameworkService; C:\Program Files\Hp\Common\HPSupportSolutionsFrameworkService.exe [46904 2013-12-17] (Hewlett-Packard Company)
R2 QPCapSvc; C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe [292248 2008-05-14] ()
R2 QPSched; C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe [116112 2008-05-14] ()
R2 Recovery Service for Windows; C:\Windows\SMINST\BLService.exe [341328 2008-03-26] ()

==================== Drivers (Whitelisted) ====================

R0 ahcix86s; C:\Windows\System32\DRIVERS\ahcix86s.sys [170000 2008-04-14] (AMD Technologies Inc.)
R0 Amddfltr; C:\Windows\System32\DRIVERS\Amddfltr.sys [15416 2008-01-07] (Advanced Micro Devices)
S3 HpqRemHid; C:\Windows\System32\DRIVERS\HpqRemHid.sys [7168 2007-07-11] (Hewlett-Packard Development Company, L.P.)
R3 libusb0; C:\Windows\System32\drivers\libusb0.sys [28672 2007-03-20] (http://libusb-win32.sourceforge.net)
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-20] (Microsoft Corporation)
S3 catchme; \??\C:\Users\Chad\AppData\Local\Temp\catchme.sys [X]
U1 eabfiltr;
S3 HTCAND32; System32\Drivers\ANDROIDUSB.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 Netaapl; system32\DRIVERS\netaapl.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S3 USBAAPL; System32\Drivers\usbaapl.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-03-17 18:34 - 2014-03-17 18:34 - 00017229 _____ () C:\Users\Chad\Downloads\FRST.txt
2014-03-17 18:33 - 2014-03-17 18:34 - 00000000 ____D () C:\FRST
2014-03-17 18:33 - 2014-03-17 18:33 - 01145856 _____ (Farbar) C:\Users\Chad\Downloads\FRST.exe
2014-03-16 22:27 - 2014-03-16 22:27 - 00008962 _____ () C:\Users\Chad\Desktop\hijackthis.log
2014-03-16 22:26 - 2014-03-16 22:26 - 00008962 _____ () C:\Users\Chad\Documents\hijackthis.log
2014-03-16 22:22 - 2014-03-16 22:25 - 00002521 _____ () C:\Users\Chad\Desktop\HiJackThis.lnk
2014-03-16 22:22 - 2014-03-16 22:22 - 00000000 ____D () C:\Users\Chad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
2014-03-16 22:21 - 2014-03-16 22:22 - 01402880 _____ () C:\Users\Chad\Downloads\HijackThis.msi
2014-03-16 11:05 - 2014-03-16 11:05 - 00000000 ____D () C:\Users\Chad\Downloads\The.Wolf.Of.Wall.Street.2013.1080p.BluRay.DTS-HD.MA.5.1.x264-PublicHD
2014-03-06 04:21 - 2014-03-06 04:21 - 00000000 ____D () C:\Windows\system32\SearchProtect
2014-03-03 12:41 - 2014-03-17 03:01 - 00001494 _____ () C:\Windows\Tasks\Plus-HD-8.9-updater.job
2014-03-03 12:40 - 2014-03-17 03:01 - 00001580 _____ () C:\Windows\Tasks\MediaPlayerEnhance-updater.job
2014-03-03 12:40 - 2014-03-03 12:40 - 00000000 ____D () C:\Users\Chad\AppData\Local\Tuguu_SL
2014-03-03 12:39 - 2014-03-17 03:01 - 00001536 _____ () C:\Windows\Tasks\MediaPlayerEnhance-codedownloader.job
2014-03-03 12:39 - 2014-03-17 03:01 - 00001450 _____ () C:\Windows\Tasks\Plus-HD-8.9-codedownloader.job
2014-03-03 12:39 - 2014-03-17 03:01 - 00001434 _____ () C:\Windows\Tasks\MediaPlayerEnhance-enabler.job
2014-03-03 12:39 - 2014-03-17 03:01 - 00001348 _____ () C:\Windows\Tasks\Plus-HD-8.9-enabler.job
2014-03-03 12:39 - 2014-03-03 12:39 - 00000000 ____D () C:\Users\Chad\AppData\Roaming\VOPackage
2014-03-03 12:39 - 2014-03-03 12:39 - 00000000 ____D () C:\Users\Chad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage
2014-03-03 12:38 - 2014-03-17 03:01 - 00003106 _____ () C:\Windows\Tasks\MediaPlayerEnhance-chromeinstaller.job
2014-03-03 12:38 - 2014-03-17 03:01 - 00003078 _____ () C:\Windows\Tasks\Plus-HD-8.9-chromeinstaller.job
2014-03-03 12:38 - 2014-03-17 03:01 - 00002368 _____ () C:\Windows\Tasks\MediaPlayerEnhance-firefoxinstaller.job
2014-03-03 12:38 - 2014-03-17 03:01 - 00002300 _____ () C:\Windows\Tasks\Plus-HD-8.9-firefoxinstaller.job
2014-03-03 12:38 - 2014-03-03 12:41 - 00000000 ____D () C:\Program Files\Plus-HD-8.9
2014-03-03 12:38 - 2014-03-03 12:40 - 00000000 ____D () C:\Program Files\MediaPlayerEnhance
2014-03-03 12:37 - 2014-03-06 04:24 - 00000000 ____D () C:\Program Files\SearchProtect
2014-03-03 12:37 - 2014-03-03 12:37 - 00000859 _____ () C:\Users\Chad\Desktop\Optimizer Pro.lnk
2014-03-03 12:37 - 2014-03-03 12:37 - 00000000 ____D () C:\Users\Chad\Documents\Optimizer Pro
2014-03-03 12:37 - 2014-03-03 12:37 - 00000000 ____D () C:\Users\Chad\AppData\Roaming\Optimizer Pro
2014-03-03 12:37 - 2014-03-03 12:37 - 00000000 ____D () C:\Program Files\Optimizer Pro
2014-03-03 12:35 - 2014-03-03 12:38 - 00000000 _____ () C:\END
2014-03-03 12:35 - 2014-03-03 12:37 - 00000000 ____D () C:\Users\Chad\AppData\Local\SearchProtect
2014-03-03 12:34 - 2014-03-03 12:34 - 00374408 _____ () C:\Users\Chad\Downloads\Setup.exe
2014-03-02 15:11 - 2014-03-02 15:20 - 00000000 ____D () C:\Users\Chad\Desktop\Movies
2014-02-19 19:04 - 2014-02-19 19:05 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-02-19 18:52 - 2014-02-19 19:01 - 00000188 _____ () C:\Users\Chad\Desktop\April Nike.txt

==================== One Month Modified Files and Folders =======

2014-03-17 18:34 - 2014-03-17 18:34 - 00017229 _____ () C:\Users\Chad\Downloads\FRST.txt
2014-03-17 18:34 - 2014-03-17 18:33 - 00000000 ____D () C:\FRST
2014-03-17 18:34 - 2008-12-17 17:51 - 00000021 _____ () C:\Users\Public\Documents\hpqp.txt
2014-03-17 18:33 - 2014-03-17 18:33 - 01145856 _____ (Farbar) C:\Users\Chad\Downloads\FRST.exe
2014-03-17 18:32 - 2006-11-02 05:47 - 00003216 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-03-17 18:32 - 2006-11-02 05:47 - 00003216 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-03-17 18:28 - 2008-09-27 02:28 - 01082221 _____ () C:\Windows\WindowsUpdate.log
2014-03-17 03:01 - 2014-03-03 12:41 - 00001494 _____ () C:\Windows\Tasks\Plus-HD-8.9-updater.job
2014-03-17 03:01 - 2014-03-03 12:40 - 00001580 _____ () C:\Windows\Tasks\MediaPlayerEnhance-updater.job
2014-03-17 03:01 - 2014-03-03 12:39 - 00001536 _____ () C:\Windows\Tasks\MediaPlayerEnhance-codedownloader.job
2014-03-17 03:01 - 2014-03-03 12:39 - 00001450 _____ () C:\Windows\Tasks\Plus-HD-8.9-codedownloader.job
2014-03-17 03:01 - 2014-03-03 12:39 - 00001434 _____ () C:\Windows\Tasks\MediaPlayerEnhance-enabler.job
2014-03-17 03:01 - 2014-03-03 12:39 - 00001348 _____ () C:\Windows\Tasks\Plus-HD-8.9-enabler.job
2014-03-17 03:01 - 2014-03-03 12:38 - 00003106 _____ () C:\Windows\Tasks\MediaPlayerEnhance-chromeinstaller.job
2014-03-17 03:01 - 2014-03-03 12:38 - 00003078 _____ () C:\Windows\Tasks\Plus-HD-8.9-chromeinstaller.job
2014-03-17 03:01 - 2014-03-03 12:38 - 00002368 _____ () C:\Windows\Tasks\MediaPlayerEnhance-firefoxinstaller.job
2014-03-17 03:01 - 2014-03-03 12:38 - 00002300 _____ () C:\Windows\Tasks\Plus-HD-8.9-firefoxinstaller.job
2014-03-17 03:01 - 2014-01-19 20:33 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-03-17 03:01 - 2009-09-11 22:28 - 00000886 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-03-17 03:01 - 2009-09-11 22:28 - 00000882 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-03-16 22:27 - 2014-03-16 22:27 - 00008962 _____ () C:\Users\Chad\Desktop\hijackthis.log
2014-03-16 22:26 - 2014-03-16 22:26 - 00008962 _____ () C:\Users\Chad\Documents\hijackthis.log
2014-03-16 22:25 - 2014-03-16 22:22 - 00002521 _____ () C:\Users\Chad\Desktop\HiJackThis.lnk
2014-03-16 22:22 - 2014-03-16 22:22 - 00000000 ____D () C:\Users\Chad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
2014-03-16 22:22 - 2014-03-16 22:21 - 01402880 _____ () C:\Users\Chad\Downloads\HijackThis.msi
2014-03-16 22:15 - 2014-01-25 22:49 - 00000000 ____D () C:\Program Files\Shutterfly
2014-03-16 22:14 - 2014-01-28 19:45 - 00000000 ____D () C:\Users\Chad\AppData\Roaming\BitTorrent
2014-03-16 11:05 - 2014-03-16 11:05 - 00000000 ____D () C:\Users\Chad\Downloads\The.Wolf.Of.Wall.Street.2013.1080p.BluRay.DTS-HD.MA.5.1.x264-PublicHD
2014-03-16 11:00 - 2014-01-19 20:33 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-03-16 11:00 - 2014-01-19 20:33 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-03-11 18:59 - 2006-11-02 03:33 - 00703388 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-03-09 15:51 - 2008-09-27 03:10 - 00000267 _____ () C:\Users\Public\Documents\hpqp.ini
2014-03-09 15:49 - 2006-11-02 06:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-03-06 04:24 - 2014-03-03 12:37 - 00000000 ____D () C:\Program Files\SearchProtect
2014-03-06 04:21 - 2014-03-06 04:21 - 00000000 ____D () C:\Windows\system32\SearchProtect
2014-03-05 22:01 - 2008-01-20 19:47 - 00144368 _____ () C:\Windows\PFRO.log
2014-03-05 21:54 - 2006-11-02 06:01 - 00032648 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-03-03 12:41 - 2014-03-03 12:38 - 00000000 ____D () C:\Program Files\Plus-HD-8.9
2014-03-03 12:40 - 2014-03-03 12:40 - 00000000 ____D () C:\Users\Chad\AppData\Local\Tuguu_SL
2014-03-03 12:40 - 2014-03-03 12:38 - 00000000 ____D () C:\Program Files\MediaPlayerEnhance
2014-03-03 12:39 - 2014-03-03 12:39 - 00000000 ____D () C:\Users\Chad\AppData\Roaming\VOPackage
2014-03-03 12:39 - 2014-03-03 12:39 - 00000000 ____D () C:\Users\Chad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage
2014-03-03 12:38 - 2014-03-03 12:35 - 00000000 _____ () C:\END
2014-03-03 12:37 - 2014-03-03 12:37 - 00000859 _____ () C:\Users\Chad\Desktop\Optimizer Pro.lnk
2014-03-03 12:37 - 2014-03-03 12:37 - 00000000 ____D () C:\Users\Chad\Documents\Optimizer Pro
2014-03-03 12:37 - 2014-03-03 12:37 - 00000000 ____D () C:\Users\Chad\AppData\Roaming\Optimizer Pro
2014-03-03 12:37 - 2014-03-03 12:37 - 00000000 ____D () C:\Program Files\Optimizer Pro
2014-03-03 12:37 - 2014-03-03 12:35 - 00000000 ____D () C:\Users\Chad\AppData\Local\SearchProtect
2014-03-03 12:34 - 2014-03-03 12:34 - 00374408 _____ () C:\Users\Chad\Downloads\Setup.exe
2014-03-03 08:24 - 2008-12-15 11:39 - 00000000 ____D () C:\Users\Chad
2014-03-02 15:20 - 2014-03-02 15:11 - 00000000 ____D () C:\Users\Chad\Desktop\Movies
2014-03-02 14:59 - 2009-02-21 14:40 - 00028672 _____ () C:\Users\Chad\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-02-28 19:03 - 2009-06-17 17:28 - 00000000 ____D () C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite
2014-02-28 19:03 - 2008-12-15 11:39 - 00000000 ____D () C:\Users\Chad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite
2014-02-28 19:03 - 2008-05-22 19:39 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite
2014-02-28 19:03 - 2008-05-22 19:39 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite
2014-02-28 19:00 - 2006-11-02 04:18 - 00000000 ___RD () C:\Users\Public
2014-02-23 21:55 - 2014-01-19 21:18 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-02-19 19:05 - 2014-02-19 19:04 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-02-19 19:01 - 2014-02-19 18:52 - 00000188 _____ () C:\Users\Chad\Desktop\April Nike.txt
2014-02-19 15:18 - 2014-01-31 04:05 - 00000000 ____D () C:\Windows\system32\MRT
2014-02-19 15:13 - 2006-11-02 03:24 - 85946576 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe

Some content of TEMP:
====================
C:\Users\Chad\AppData\Local\Temp\BackupSetup.exe
C:\Users\Chad\AppData\Local\Temp\bpuninstall.exe
C:\Users\Chad\AppData\Local\Temp\dsHostCheckerSetup.exe
C:\Users\Chad\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe
C:\Users\Chad\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe
C:\Users\Chad\AppData\Local\Temp\JuniperSetupClientInstaller.exe
C:\Users\Chad\AppData\Local\Temp\nsc915B.exe
C:\Users\Chad\AppData\Local\Temp\nsh1434.exe
C:\Users\Chad\AppData\Local\Temp\nsh8B13.exe
C:\Users\Chad\AppData\Local\Temp\nssBEA.exe
C:\Users\Chad\AppData\Local\Temp\SPSetup.exe
C:\Users\Chad\AppData\Local\Temp\utt53D9.tmp.exe
C:\Users\Chad\AppData\Local\Temp\uttA3ED.tmp.exe
C:\Users\Chad\AppData\Local\Temp\vcredist_x86.exe


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-03-09 15:42

==================== End Of Log ============================


Additional scan result of Farbar Recovery Scan Tool (x86) Version: 13-03-2014  01
Ran by Chad at 2014-03-17 18:34:57
Running from C:\Users\Chad\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

Activation Assistant for the 2007 Microsoft Office suites (HKLM\...\Activation Assistant for the 2007 Microsoft Office suites) (Version:  - Microsoft Corporation)
Activation Assistant for the 2007 Microsoft Office suites (Version: 1.0 - Microsoft Corporation) Hidden
Adobe AIR (HKLM\...\Adobe AIR) (Version: 4.0.0.1390 - Adobe Systems Incorporated)
Adobe AIR (Version: 4.0.0.1390 - Adobe Systems Incorporated) Hidden
Adobe Flash Player 10 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 10.0.12.36 - Adobe Systems Incorporated)
Adobe Flash Player 12 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 12.0.0.77 - Adobe Systems Incorporated)
Adobe Reader 8.1.0 (HKLM\...\{AC76BA86-7AD7-1033-7B44-A81000000003}) (Version: 8.1.0 - Adobe Systems Incorporated)
Adobe Shockwave Player (HKLM\...\{1BDC9633-895B-4842-BCB6-8FA1EC2A3C5A}) (Version: 10.2.0.023 - Adobe Systems, Inc.)
AMD Driver Support for HP 3D DriverGuard (Version: 5.1.0000.0066 - Advanced Micro Devices, Inc.) Hidden
Atheros Driver Installation Program (HKLM\...\{C3A32068-8AB1-4327-BB16-BED9C6219DC7}) (Version: 5.2 - Atheros)
ATI Catalyst Install Manager (HKLM\...\{80C2AD19-97A2-C829-38DE-5FD5B47F122B}) (Version: 3.0.664.0 - ATI Technologies, Inc.)
Cards_Calendar_OrderGift_DoMorePlugout (Version: 1.00.0000 - Hewlett-Packard) Hidden
Catalyst Control Center - Branding (HKLM\...\{3FA93E4C-CB3B-4B25-B091-9DB0FCC56A74}) (Version: 1.00.0000 - ATI)
Catalyst Control Center Core Implementation (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Graphics Full Existing (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Graphics Full New (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Graphics Light (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Graphics Previews Vista (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Localization Chinese Standard (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Localization Chinese Traditional (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Localization Czech (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Localization Danish (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Localization Dutch (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Localization Finnish (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Localization French (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Localization German (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Localization Greek (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Localization Hungarian (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Localization Italian (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Localization Japanese (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Localization Korean (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Localization Norwegian (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Localization Polish (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Localization Portuguese (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Localization Russian (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Localization Spanish (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Localization Swedish (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Localization Thai (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Localization Turkish (Version: 2008.0328.2322.39969 - ATI) Hidden
CCC Help Chinese Standard (Version: 2008.0328.2321.39969 - ATI) Hidden
CCC Help Chinese Traditional (Version: 2008.0328.2321.39969 - ATI) Hidden
CCC Help Czech (Version: 2008.0328.2321.39969 - ATI) Hidden
CCC Help Danish (Version: 2008.0328.2321.39969 - ATI) Hidden
CCC Help Dutch (Version: 2008.0328.2321.39969 - ATI) Hidden
CCC Help English (Version: 2008.0328.2321.39969 - ATI) Hidden
CCC Help Finnish (Version: 2008.0328.2321.39969 - ATI) Hidden
CCC Help French (Version: 2008.0328.2321.39969 - ATI) Hidden
CCC Help German (Version: 2008.0328.2321.39969 - ATI) Hidden
CCC Help Greek (Version: 2008.0328.2321.39969 - ATI) Hidden
CCC Help Hungarian (Version: 2008.0328.2321.39969 - ATI) Hidden
CCC Help Italian (Version: 2008.0328.2321.39969 - ATI) Hidden
CCC Help Japanese (Version: 2008.0328.2321.39969 - ATI) Hidden
CCC Help Korean (Version: 2008.0328.2321.39969 - ATI) Hidden
CCC Help Norwegian (Version: 2008.0328.2321.39969 - ATI) Hidden
CCC Help Polish (Version: 2008.0328.2321.39969 - ATI) Hidden
CCC Help Portuguese (Version: 2008.0328.2321.39969 - ATI) Hidden
CCC Help Russian (Version: 2008.0328.2321.39969 - ATI) Hidden
CCC Help Spanish (Version: 2008.0328.2321.39969 - ATI) Hidden
CCC Help Swedish (Version: 2008.0328.2321.39969 - ATI) Hidden
CCC Help Thai (Version: 2008.0328.2321.39969 - ATI) Hidden
CCC Help Turkish (Version: 2008.0328.2321.39969 - ATI) Hidden
ccc-core-static (Version: 2008.0328.2322.39969 - ATI) Hidden
ccc-utility (Version: 2008.0328.2322.39969 - ATI) Hidden
Cisco EAP-FAST Module (HKLM\...\{415B2719-AD3A-4944-B404-C472DB6085B3}) (Version: 2.1.6 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM\...\{83770D14-21B9-44B3-8689-F7B523F94560}) (Version: 1.0.12 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM\...\{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}) (Version: 1.0.13 - Cisco Systems, Inc.)
Compatibility Pack for the 2007 Office system (HKLM\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
CyberLink DVD Suite (HKLM\...\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 5.5.1519 - CyberLink Corp.)
CyberLink YouCam (HKLM\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 2.0.1616 - CyberLink Corp.)
CyberLink YouCam (Version: 2.0.1616 - CyberLink Corp.) Hidden
DMUninstaller (HKLM\...\DMUninstaller) (Version:  - ) <==== ATTENTION
Google Toolbar for Internet Explorer (HKLM\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.4805.320 - Google Inc.)
Google Toolbar for Internet Explorer (Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.22.5 - Google Inc.) Hidden
Hewlett-Packard Active Check for Health Check (Version: 1.1.15.2 - Hewlett-Packard) Hidden
Hewlett-Packard Asset Agent for Health Check (Version: 2.0.63.2 - HP) Hidden
HiJackThis (HKLM\...\{45A66726-69BC-466B-A7A4-12FCBA4883D7}) (Version: 1.0.0 - Trend Micro)
HP Active Support Library (Version: 3.1.4.1 - Hewlett-Packard) Hidden
HP Customer Experience Enhancements (HKLM\...\{C27C82E4-9C53-4D76-9ED3-A01A3D5EE679}) (Version: 5.6.0.2510 - Hewlett-Packard)
HP Doc Viewer (HKLM\...\{082702D5-5DD8-4600-BCE5-48B15174687F}) (Version: 1.03.0001 - Hewlett-Packard)
HP Help and Support (HKLM\...\{31216452-5540-4C96-B754-94890A63D5AB}) (Version: 2.0.10.0 - Hewlett-Packard)
HP Photosmart Essential 2.5 (HKLM\...\HP Photosmart Essential) (Version: 2.5 - HP)
HP Photosmart Essential 2.5 (Version: 1.02.0000 - Hewlett-Packard) Hidden
HP Quick Launch Buttons 6.40 D3 (HKLM\...\{34D2AB40-150D-475D-AE32-BD23FB5EE355}) (Version: 6.40 D3 - Hewlett-Packard)
HP QuickPlay 3.7 (HKLM\...\{45D707E9-F3C4-11D9-A373-0050BAE317E1}) (Version:  - )
HP Support Solutions Framework (HKLM\...\{23CCE784-A812-4647-AEFF-1DCCD4E57478}) (Version: 11.50.0000 - Hewlett-Packard Company)
HP Total Care Advisor (HKLM\...\{f32502b5-5b64-4882-bf61-77f23edcac4f}) (Version: 2.1.3359.2635 - Hewlett-Packard)
HP Update (HKLM\...\{97486FBE-A3FC-4783-8D55-EA37E9D171CC}) (Version: 5.005.000.002 - Hewlett-Packard)
HP User Guides 0102 (HKLM\...\{F48098CD-2D66-4861-85EC-DC1D4D09D5F9}) (Version: 1.01.0000 - Hewlett-Packard)
HP Wireless Assistant (HKLM\...\{A5CE7175-080D-49AC-B5A3-E7E3502428F5}) (Version: 3.00 I2 - Hewlett-Packard)
HPNetworkAssistant (Version: 1.1.70 - Hewlett-Packard.) Hidden
HPPhotoSmartDiscLabel_PaperLabel (Version: 2.02.0000 - Hewlett-Packard) Hidden
HPPhotoSmartDiscLabel_PrintOnDisc (Version: 2.02.0000 - Hewlett-Packard) Hidden
HPPhotoSmartDiscLabel_Tattoo (Version: 2.02.0000 - Hewlett-Packard) Hidden
HPPhotoSmartDiscLabelContent1 (Version: 2.02.0000 - Hewlett-Packard) Hidden
hpphotosmartdisclabelplugin (Version: 2.02.0000 - Hewlett-Packard) Hidden
HPPhotoSmartPhotobookHolidayPack1 (Version: 1.00.0000 - Hewlett-Packard) Hidden
HPPhotoSmartPhotobookModernPack1 (Version: 1.00.0000 - Hewlett-Packard) Hidden
HPPhotoSmartPhotobookPlayfulPack1 (Version: 1.00.0000 - Hewlett-Packard) Hidden
HPPhotoSmartPhotobookScrapbookPack1 (Version: 1.00.0000 - Hewlett-Packard) Hidden
HPPhotoSmartPhotobookWebPack1 (Version: 1.00.0000 - Hewlett-Packard) Hidden
HPTCSSetup (HKLM\...\{FA3B34BE-4246-4062-90A3-34CBBEA12B72}) (Version: 1.0.964.2626 - Hewlett-Packard Company)
IDT Audio (HKLM\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.5893.0 - IDT)
Java 7 Update 51 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.510 - Oracle)
Java Auto Updater (Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
Java™ 6 Update 5 (HKLM\...\{3248F0A8-6813-11D6-A77B-00B0D0160050}) (Version: 1.6.0.50 - Sun Microsystems, Inc.)
Juniper Citrix Services Client (HKCU\...\Juniper_Citrix_Services) (Version: 7.1.13.22557 - Juniper Networks)
Juniper Networks Host Checker (HKCU\...\Neoteris_Host_Checker) (Version: 7.1.15.25271 - Juniper Networks)
Juniper Networks, Inc. Setup Client (HKCU\...\Juniper_Setup_Client) (Version: 7.1.15.36013 - Juniper Networks, Inc.)
Juniper Networks, Inc. Setup Client Activex Control (HKLM\...\Juniper_Setup_Client Activex Control) (Version: 2.1.1.1 - Juniper Networks, Inc.)
Juniper Terminal Services Client (HKCU\...\Juniper_Term_Services) (Version: 7.1.15.25271 - Juniper Networks)
LabelPrint (HKLM\...\{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.20.2719 - CyberLink Corp.)
LibUSB-Win32-0.1.12.1 (HKLM\...\LibUSB-Win32_is1) (Version: 0.1.12.1 - LibUSB-Win32)
LightScribe System Software  1.12.33.2 (HKLM\...\{582287DA-0806-4AC0-BF19-C15E3A466034}) (Version: 1.12.33.2 - LightScribe)
MediaPlayerEnhance (HKLM\...\MediaPlayerEnhance) (Version: 1.34.2.13 - Feven) <==== ATTENTION
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint Viewer 2007 (English) (HKLM\...\{95120000-00AF-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Standard Edition 2003 (HKLM\...\{91120409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.20913.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Works (HKLM\...\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}) (Version: 9.7.0621 - Microsoft Corporation)
Mozilla Firefox 27.0.1 (x86 en-US) (HKLM\...\Mozilla Firefox 27.0.1 (x86 en-US)) (Version: 27.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 27.0.1 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
muvee autoProducer 6.1 (HKLM\...\{35F83303-C0C0-46B7-B8A8-ADA7C2AC5645}) (Version: 6.10.050 - muvee Technologies)
My HP Games (HKLM\...\WildTangent hp Master Uninstall) (Version: 1.0.0.43 - WildTangent)
OGA Notifier 2.0.0048.0 (Version: 2.0.0048.0 - Microsoft Corporation) Hidden
Optimizer Pro v3.2 (HKLM\...\Optimizer Pro_is1) (Version:  - ) <==== ATTENTION
PHStat2 2.8.1 (HKLM\...\{6CB203AC-E5A7-424E-B4DC-C16564185463}) (Version: 2.8.1 - Prentice Hall, Inc., a division of Pearson Education)
PHStat2 version 2.5.1 (HKLM\...\{363798A0-FE16-4BA8-8119-572A02202DBF}) (Version: 2.5.1 - Prentice Hall, Inc., a division of Pearson Education)
Plus-HD-8.9 (HKLM\...\Plus-HD-8.9) (Version: 1.34.2.13 - Plus HD) <==== ATTENTION
Power2Go (HKLM\...\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 5.6.3919 - CyberLink Corp.)
PowerDirector (HKLM\...\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 6.5.2719 - CyberLink Corp.)
ProtectSmart Hard Drive Protection (HKLM\...\{AAD72731-807A-4B79-AE05-9190B7002B7B}) (Version: 3.10 A7 - Hewlett-Packard)
PSSWCORE (Version: 2.02.0000 - Hewlett-Packard) Hidden
QuickFreedom 1.1.0 (HKLM\...\{676B241C-AED4-400B-98FF-267773B94B11}_is1) (Version:  - Dancool999)
QuickPlay SlingPlayer 0.4.6 (HKLM\...\SlingMedia.QPSlingPlayer_is1) (Version: 0.4.6 - SlingMedia)
QuickTime (HKLM\...\{57752979-A1C9-4C02-856B-FBB27AC4E02C}) (Version: 7.69.80.9 - Apple Inc.)
Realtek 8169 8168 8101E 8102E Ethernet Driver (HKLM\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 1.00.0000 - Realtek)
Realtek USB 2.0 Card Reader (HKLM\...\{DC24971E-1946-445D-8A82-CE685433FA7D}) (Version:  - Realtek Semiconductor Corp.)
Search Protect (HKLM\...\SearchProtect) (Version: 2.11.11.7 - Conduit) <==== ATTENTION
Skins (Version: 2008.0328.2322.39969 - ATI) Hidden
Slingbox Flash Tour (HKLM\...\{38EAC694-0D90-445F-8C17-8B50ADFE3162}) (Version: 1.0.0 - Sling Media)
SlingPlayer (HKLM\...\InstallShield_{004B0DCB-4C60-465B-8F01-44B0A4111187}) (Version: 1.04.0206 - Sling Media)
SlingPlayer (Version: 1.04.0206 - Sling Media) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 10.2.4.0 - Synaptics)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (HKLM\...\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707) (Version: 1 - Microsoft Corporation)
VideoToolkit01 (Version: 100.0.128.000 - Hewlett-Packard) Hidden
VO Package (HKLM\...\VOPackage) (Version: 1.0.0.0 - )

==================== Restore Points  =========================

17-03-2014 05:15:18 Removed Shutterfly Express Uploader
17-03-2014 05:16:38 Removed iTunes
17-03-2014 05:22:32 Installed HiJackThis
17-03-2014 05:24:03 Windows Update

==================== Hosts content: ==========================

2006-11-02 03:23 - 2011-05-26 23:45 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost

==================== Scheduled Tasks (whitelisted) =============

Task: {06F125FC-3726-4B1F-9490-F0BDDFF54890} - System32\Tasks\HP Health Check => c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [2008-04-15] (Hewlett-Packard)
Task: {0A986836-C4CF-4E58-A75A-F6B503C6FA55} - System32\Tasks\{3B21C084-532D-4016-8308-DDA21B2E3624} => C:\Program Files\Skype\Phone\Skype.exe
Task: {16D69E6A-842C-4F90-9844-B42504102D53} - System32\Tasks\Plus-HD-8.9-updater => C:\Program Files\Plus-HD-8.9\Plus-HD-8.9-updater.exe [2014-03-03] (Plus HD) <==== ATTENTION
Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {320124A7-D70F-41DE-A9D1-D5E8E19D5D91} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {3E2B548F-1A4B-4F8E-85DD-349052514553} - System32\Tasks\MediaPlayerEnhance-codedownloader => C:\Program Files\MediaPlayerEnhance\MediaPlayerEnhance-codedownloader.exe [2014-03-03] (Feven) <==== ATTENTION
Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-20] (Microsoft Corporation)
Task: {582EFF8B-112D-4E8B-92ED-063F0B09BDED} - System32\Tasks\MediaPlayerEnhance-firefoxinstaller => C:\Program Files\MediaPlayerEnhance\MediaPlayerEnhance-firefoxinstaller.exe [2014-03-03] (Feven) <==== ATTENTION
Task: {6D50A723-E06E-4538-986F-79F815ABC733} - System32\Tasks\Plus-HD-8.9-enabler => C:\Program Files\Plus-HD-8.9\Plus-HD-8.9-enabler.exe [2014-03-03] (Plus HD) <==== ATTENTION
Task: {80EA565C-E1B2-4607-8A28-64CDF37F3974} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2009-09-11] (Google Inc.)
Task: {967C3E50-BC2F-4C5D-B5DF-28AB676E42EA} - System32\Tasks\MediaPlayerEnhance-updater => C:\Program Files\MediaPlayerEnhance\MediaPlayerEnhance-updater.exe [2014-03-03] (Feven) <==== ATTENTION
Task: {9F4A5465-FAFC-4552-B838-8F23997CE97B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2009-09-11] (Google Inc.)
Task: {A2E4658A-478A-4373-BF56-D0349DA0EE44} - System32\Tasks\MediaPlayerEnhance-enabler => C:\Program Files\MediaPlayerEnhance\MediaPlayerEnhance-enabler.exe [2014-03-03] (Feven) <==== ATTENTION
Task: {C2ADC630-2109-4246-B5A8-D445730FD150} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-16] (Adobe Systems Incorporated)
Task: {C6F9C2E6-B5EE-40CF-A009-0F11C0953BC4} - System32\Tasks\Plus-HD-8.9-firefoxinstaller => C:\Program Files\Plus-HD-8.9\Plus-HD-8.9-firefoxinstaller.exe [2014-03-03] (Plus HD) <==== ATTENTION
Task: {DB2FB81F-AAA6-4BBD-A990-013EB48C8F38} - System32\Tasks\Plus-HD-8.9-codedownloader => C:\Program Files\Plus-HD-8.9\Plus-HD-8.9-codedownloader.exe [2014-03-03] (Plus HD) <==== ATTENTION
Task: {DB989D7A-E58E-4FC8-A763-98BD397E5998} - System32\Tasks\MediaPlayerEnhance-chromeinstaller => C:\Program Files\MediaPlayerEnhance\MediaPlayerEnhance-chromeinstaller.exe [2014-03-03] (Feven) <==== ATTENTION
Task: {E18FC506-0773-44B0-9461-DC74EF3B01A1} - System32\Tasks\Plus-HD-8.9-chromeinstaller => C:\Program Files\Plus-HD-8.9\Plus-HD-8.9-chromeinstaller.exe [2014-03-03] (Plus HD) <==== ATTENTION
Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-20] ()
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\MediaPlayerEnhance-chromeinstaller.job => C:\Program Files\MediaPlayerEnhance\MediaPlayerEnhance-chromeinstaller.exe <==== ATTENTION
Task: C:\Windows\Tasks\MediaPlayerEnhance-codedownloader.job => C:\Program Files\MediaPlayerEnhance\MediaPlayerEnhance-codedownloader.exe <==== ATTENTION
Task: C:\Windows\Tasks\MediaPlayerEnhance-enabler.job => C:\Program Files\MediaPlayerEnhance\MediaPlayerEnhance-enabler.exe <==== ATTENTION
Task: C:\Windows\Tasks\MediaPlayerEnhance-firefoxinstaller.job => C:\Program Files\MediaPlayerEnhance\MediaPlayerEnhance-firefoxinstaller.exe <==== ATTENTION
Task: C:\Windows\Tasks\MediaPlayerEnhance-updater.job => C:\Program Files\MediaPlayerEnhance\MediaPlayerEnhance-updater.exe <==== ATTENTION
Task: C:\Windows\Tasks\Plus-HD-8.9-chromeinstaller.job => C:\Program Files\Plus-HD-8.9\Plus-HD-8.9-chromeinstaller.exe <==== ATTENTION
Task: C:\Windows\Tasks\Plus-HD-8.9-codedownloader.job => C:\Program Files\Plus-HD-8.9\Plus-HD-8.9-codedownloader.exe <==== ATTENTION
Task: C:\Windows\Tasks\Plus-HD-8.9-enabler.job => C:\Program Files\Plus-HD-8.9\Plus-HD-8.9-enabler.exe <==== ATTENTION
Task: C:\Windows\Tasks\Plus-HD-8.9-firefoxinstaller.job => C:\Program Files\Plus-HD-8.9\Plus-HD-8.9-firefoxinstaller.exe <==== ATTENTION
Task: C:\Windows\Tasks\Plus-HD-8.9-updater.job => C:\Program Files\Plus-HD-8.9\Plus-HD-8.9-updater.exe <==== ATTENTION

==================== Loaded Modules (whitelisted) =============

2008-03-28 02:19 - 2008-03-28 02:19 - 00159744 _____ () C:\Windows\system32\atitmmxx.dll
2008-05-22 18:26 - 2008-05-14 22:56 - 00120216 _____ () C:\Program Files\HP\QuickPlay\Kernel\TV\CLSchMgr.dll
2008-05-22 18:26 - 2008-05-14 22:56 - 00038184 _____ () C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvcps.dll
2008-05-22 18:26 - 2008-05-14 22:56 - 00259480 _____ () C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapEngine.dll
2008-05-22 18:26 - 2008-05-14 22:56 - 00345384 _____ () C:\Program Files\HP\QuickPlay\Kernel\TV\CLTinyDB.dll
2007-07-12 12:55 - 2007-07-12 12:55 - 01581056 _____ () C:\Program Files\Common Files\LightScribe\QtCore4.dll
2007-08-14 12:59 - 2007-08-14 12:59 - 06365184 _____ () C:\Program Files\Common Files\LightScribe\QtGui4.dll
2007-07-12 12:55 - 2007-07-12 12:55 - 00131072 _____ () C:\Program Files\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll
2008-05-22 18:26 - 2008-05-14 22:56 - 00066856 _____ () C:\Program Files\HP\QuickPlay\Kernel\Common\MCEMediaStatus.dll
2008-05-22 18:26 - 2008-05-14 22:56 - 00292248 _____ () C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
2008-05-22 18:26 - 2008-05-14 22:56 - 00116112 _____ () C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
2008-05-22 19:55 - 2008-03-26 15:26 - 00341328 _____ () C:\Windows\SMINST\BLService.exe
2008-05-22 19:55 - 2006-09-13 13:54 - 00081920 _____ () C:\Windows\SMINST\STString.dll
2008-05-22 19:55 - 2007-11-14 15:46 - 00126976 _____ () C:\Windows\SMINST\STWmiM.dll
2008-05-22 18:38 - 2008-04-11 09:04 - 00685360 _____ () C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\ProgramData\TEMP:CD060F93

==================== Safe Mode (whitelisted) ===================

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"

==================== Disabled items from MSCONFIG ==============


==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (03/17/2014 06:32:57 PM) (Source: Windows Search Service) (User: )
Description: The entry <C:\USERS\CHAD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SV1CTV5Q.DEFAULT\STORAGE\PERSISTENT\CHROME\IDB\27775517150BCD8L2A2NAR1E7T-NAI6.SQLITE-JOURNAL> in the hash map cannot be updated.

Context:  Application, SystemIndex Catalog


Details:
    A device attached to the system is not functioning.   (0x8007001f)

Error: (03/17/2014 06:32:57 PM) (Source: Windows Search Service) (User: )
Description: The entry <C:\USERS\CHAD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SV1CTV5Q.DEFAULT\STORAGE\PERSISTENT\CHROME\IDB\16292413673B8D8L9ADN7R0EAT-N3IF.SQLITE-JOURNAL> in the hash map cannot be updated.

Context:  Application, SystemIndex Catalog


Details:
    A device attached to the system is not functioning.   (0x8007001f)

Error: (03/17/2014 06:31:05 PM) (Source: Windows Search Service) (User: )
Description: The entry <C:\USERS\CHAD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SV1CTV5Q.DEFAULT\STORAGE\PERSISTENT\CHROME\IDB\27775517150BCD8L2A2NAR1E7T-NAI6.SQLITE-JOURNAL> in the hash map cannot be updated.

Context:  Application, SystemIndex Catalog


Details:
    A device attached to the system is not functioning.   (0x8007001f)

Error: (03/17/2014 06:30:08 PM) (Source: Windows Search Service) (User: )
Description: The entry <C:\USERS\CHAD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SV1CTV5Q.DEFAULT\STORAGE\PERSISTENT\CHROME\IDB\27775517150BCD8L2A2NAR1E7T-NAI6.SQLITE-JOURNAL> in the hash map cannot be updated.

Context:  Application, SystemIndex Catalog


Details:
    A device attached to the system is not functioning.   (0x8007001f)

Error: (03/17/2014 06:29:20 PM) (Source: Windows Search Service) (User: )
Description: The entry <C:\USERS\CHAD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SV1CTV5Q.DEFAULT\STORAGE\PERSISTENT\CHROME\IDB\27775517150BCD8L2A2NAR1E7T-NAI6.SQLITE-JOURNAL> in the hash map cannot be updated.

Context:  Application, SystemIndex Catalog


Details:
    A device attached to the system is not functioning.   (0x8007001f)

Error: (03/16/2014 10:26:58 PM) (Source: Windows Search Service) (User: )
Description: The entry <C:\USERS\CHAD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SV1CTV5Q.DEFAULT\STORAGE\PERSISTENT\CHROME\IDB\16292413673B8D8L9ADN7R0EAT-N3IF.SQLITE-JOURNAL> in the hash map cannot be updated.

Context:  Application, SystemIndex Catalog


Details:
    A device attached to the system is not functioning.   (0x8007001f)

Error: (03/16/2014 10:26:56 PM) (Source: Windows Search Service) (User: )
Description: The entry <C:\USERS\CHAD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SV1CTV5Q.DEFAULT\STORAGE\PERSISTENT\CHROME\IDB\27775517150BCD8L2A2NAR1E7T-NAI6.SQLITE-JOURNAL> in the hash map cannot be updated.

Context:  Application, SystemIndex Catalog


Details:
    A device attached to the system is not functioning.   (0x8007001f)

Error: (03/16/2014 10:24:03 PM) (Source: Microsoft-Windows-CAPI2) (User: )
Description:
Details:
AddCoreCsiFiles : GetNextFileMapContent() failed.

System Error:
Reached the end of the file.

Error: (03/16/2014 10:24:02 PM) (Source: Microsoft-Windows-CAPI2) (User: )
Description:
Details:
AddCoreCsiFiles : GetNextFileMapContent() failed.

System Error:
Reached the end of the file.

Error: (03/16/2014 10:22:32 PM) (Source: Microsoft-Windows-CAPI2) (User: )
Description:
Details:
AddCoreCsiFiles : GetNextFileMapContent() failed.

System Error:
Reached the end of the file.


System errors:
=============

Microsoft Office Sessions:
=========================
Error: (03/17/2014 06:32:57 PM) (Source: Windows Search Service)(User: )
Description: Context:  Application, SystemIndex Catalog


Details:
    A device attached to the system is not functioning.   (0x8007001f)
C:\USERS\CHAD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SV1CTV5Q.DEFAULT\STORAGE\PERSISTENT\CHROME\IDB\27775517150BCD8L2A2NAR1E7T-NAI6.SQLITE-JOURNAL

Error: (03/17/2014 06:32:57 PM) (Source: Windows Search Service)(User: )
Description: Context:  Application, SystemIndex Catalog


Details:
    A device attached to the system is not functioning.   (0x8007001f)
C:\USERS\CHAD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SV1CTV5Q.DEFAULT\STORAGE\PERSISTENT\CHROME\IDB\16292413673B8D8L9ADN7R0EAT-N3IF.SQLITE-JOURNAL

Error: (03/17/2014 06:31:05 PM) (Source: Windows Search Service)(User: )
Description: Context:  Application, SystemIndex Catalog


Details:
    A device attached to the system is not functioning.   (0x8007001f)
C:\USERS\CHAD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SV1CTV5Q.DEFAULT\STORAGE\PERSISTENT\CHROME\IDB\27775517150BCD8L2A2NAR1E7T-NAI6.SQLITE-JOURNAL

Error: (03/17/2014 06:30:08 PM) (Source: Windows Search Service)(User: )
Description: Context:  Application, SystemIndex Catalog


Details:
    A device attached to the system is not functioning.   (0x8007001f)
C:\USERS\CHAD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SV1CTV5Q.DEFAULT\STORAGE\PERSISTENT\CHROME\IDB\27775517150BCD8L2A2NAR1E7T-NAI6.SQLITE-JOURNAL

Error: (03/17/2014 06:29:20 PM) (Source: Windows Search Service)(User: )
Description: Context:  Application, SystemIndex Catalog


Details:
    A device attached to the system is not functioning.   (0x8007001f)
C:\USERS\CHAD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SV1CTV5Q.DEFAULT\STORAGE\PERSISTENT\CHROME\IDB\27775517150BCD8L2A2NAR1E7T-NAI6.SQLITE-JOURNAL

Error: (03/16/2014 10:26:58 PM) (Source: Windows Search Service)(User: )
Description: Context:  Application, SystemIndex Catalog


Details:
    A device attached to the system is not functioning.   (0x8007001f)
C:\USERS\CHAD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SV1CTV5Q.DEFAULT\STORAGE\PERSISTENT\CHROME\IDB\16292413673B8D8L9ADN7R0EAT-N3IF.SQLITE-JOURNAL

Error: (03/16/2014 10:26:56 PM) (Source: Windows Search Service)(User: )
Description: Context:  Application, SystemIndex Catalog


Details:
    A device attached to the system is not functioning.   (0x8007001f)
C:\USERS\CHAD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SV1CTV5Q.DEFAULT\STORAGE\PERSISTENT\CHROME\IDB\27775517150BCD8L2A2NAR1E7T-NAI6.SQLITE-JOURNAL

Error: (03/16/2014 10:24:03 PM) (Source: Microsoft-Windows-CAPI2)(User: )
Description:
Details:
AddCoreCsiFiles : GetNextFileMapContent() failed.

System Error:
Reached the end of the file.

Error: (03/16/2014 10:24:02 PM) (Source: Microsoft-Windows-CAPI2)(User: )
Description:
Details:
AddCoreCsiFiles : GetNextFileMapContent() failed.

System Error:
Reached the end of the file.

Error: (03/16/2014 10:22:32 PM) (Source: Microsoft-Windows-CAPI2)(User: )
Description:
Details:
AddCoreCsiFiles : GetNextFileMapContent() failed.

System Error:
Reached the end of the file.


CodeIntegrity Errors:
===================================
  Date: 2014-03-17 18:34:32.034
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-03-17 18:34:31.838
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-03-17 18:34:31.662
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-03-17 18:34:31.486
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-03-17 18:34:31.307
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-03-17 18:34:31.143
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-03-17 18:34:30.934
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-03-17 18:34:30.526
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-03-16 22:25:48.370
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-03-16 22:25:48.049
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.


==================== Memory info ===========================

Percentage of memory in use: 37%
Total physical RAM: 2813.09 MB
Available physical RAM: 1752.54 MB
Total Pagefile: 5842.2 MB
Available Pagefile: 4728.89 MB
Total Virtual: 2047.88 MB
Available Virtual: 1920.96 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:222.84 GB) (Free:71.94 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (HP_RECOVERY) (Fixed) (Total:10.04 GB) (Free:1.75 GB) NTFS ==>[System with boot components (obtained from reading drive)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 233 GB) (Disk ID: 657A29EF)
Partition 1: (Active) - (Size=223 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=10 GB) - (Type=07 NTFS)

==================== End Of Log ============================



#4 union410

union410
  • Topic Starter

  • Members
  • 39 posts
  • OFFLINE
  •  
  • Local time:07:07 PM

Posted 17 March 2014 - 10:26 PM

I ran the Gmer Rootkit scanner and when the scan was finished it told me that there was a rootkit infection. I closed that window and tried to click save but it wouldn't let me. I copied the text, but couldn't open up anything to save it. I could not open any applications. I had to take my battery out to restart my laptop.

 

When I rebooted I tried to run another scan but my computer closes it after the scan runs for about 30 seconds. I tried to save a new exe but still couldn't scan.

 

Any advice on what to do now?



#5 TB-Psychotic

TB-Psychotic

  • Malware Response Team
  • 6,349 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:07 AM

Posted 18 March 2014 - 03:50 AM

Skip Gmer:

 

 

Scan with aswMBR

Please download aswMBR ( 4.5MB ) to your desktop.

  • Double click the aswMBR.exe icon, and click Run.
  • There will be a short delay before the next dialog box comes up. Please just wait a minute or two.
  • When asked if you'd like to "download the latest Avast! virus definitions", click Yes.
  • Typically this is about a 100MB download so depending on your connection speed it can take a short while to download and become ready.
  • Click the Scan button to start the scan once the update has finished downloading
  • On completion of the scan, click the save log button, save it to your desktop, then copy and paste it in your next reply.

Note: There will also be a file on your desktop named MBR.dat do not delete this for now. It is an actual backup of the MBR (master boot record).


Proud Member of UNITE & TB
 
My help is free, however, if you want to support my fight against malware, click here --> btn_donate_SM.gif <--(no worries, every little bit helps)

#6 union410

union410
  • Topic Starter

  • Members
  • 39 posts
  • OFFLINE
  •  
  • Local time:07:07 PM

Posted 18 March 2014 - 08:58 PM

aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software
Run date: 2014-03-18 18:41:04
-----------------------------
18:41:04.336    OS Version: Windows 6.0.6001 Service Pack 1
18:41:04.336    Number of processors: 2 586 0x301
18:41:04.337    ComputerName: CHAD-PC  UserName: Chad
18:41:06.459    Initialize success
18:44:53.694    AVAST engine defs: 14031802
18:45:51.714    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000008c
18:45:51.722    Disk 0 Vendor: SAMSUNG_ 1.2S Size: 238475MB BusType: 8
18:45:51.949    Disk 0 MBR read successfully
18:45:51.954    Disk 0 MBR scan
18:45:51.965    Disk 0 unknown MBR code
18:45:51.971    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS       228186 MB offset 63
18:45:52.011    Disk 0 Partition 2 00     07    HPFS/NTFS NTFS        10285 MB offset 467326976
18:45:52.044    Disk 0 scanning sectors +488390656
18:45:52.170    Disk 0 scanning C:\Windows\system32\drivers
18:46:06.966    Service scanning
18:46:40.512    Modules scanning
18:46:52.976    Disk 0 trace - called modules:
18:46:53.021    ntkrnlpa.exe CLASSPNP.SYS disk.sys hpdskflt.sys hal.dll Amddfltr.sys storport.sys ahcix86s.sys dxgkrnl.sys atikmdag.sys watchdog.sys ndis.sys athr.sys tcpip.sys NETIO.SYS partmgr.sys volmgr.sys ecache.sys volsnap.sys Ntfs.sys
18:46:53.410    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86ccc278]
18:46:53.431    3 CLASSPNP.SYS[807a6745] -> nt!IofCallDriver -> [0x86ccc978]
18:46:53.451    5 hpdskflt.sys[8b1a9f05] -> nt!IofCallDriver -> [0x86ccccd0]
18:46:53.473    7 Amddfltr.sys[8b1cb0b6] -> nt!IofCallDriver -> \Device\0000008c[0x86177c90]
18:46:55.338    AVAST engine scan C:\Windows
18:47:13.931    AVAST engine scan C:\Windows\system32
18:54:57.557    AVAST engine scan C:\Windows\system32\drivers
18:55:47.981    AVAST engine scan C:\Users\Chad
18:56:36.623    Disk 0 MBR has been saved successfully to "C:\Users\Chad\Downloads\MBR.dat"
18:56:36.658    The log file has been saved successfully to "C:\Users\Chad\Downloads\aswMBR.txt"



#7 TB-Psychotic

TB-Psychotic

  • Malware Response Team
  • 6,349 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:07 AM

Posted 19 March 2014 - 03:46 AM

Add-/remove programms

Click on start-->control panel.

Vista/7: Open Programs and Features
XP: Open add/remove programs

Search for and remove the following programs

DMUninstaller
Google Toolbar for Internet Explorer
MediaPlayerEnhance
Optimizer Pro v3.2
Plus-HD-8.9
Search Protect


Close the window.

 

 

 

When finished, rescan with FRST and provide new logs.


Proud Member of UNITE & TB
 
My help is free, however, if you want to support my fight against malware, click here --> btn_donate_SM.gif <--(no worries, every little bit helps)

#8 union410

union410
  • Topic Starter

  • Members
  • 39 posts
  • OFFLINE
  •  
  • Local time:07:07 PM

Posted 19 March 2014 - 08:54 AM

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-03-2014  01
Ran by Chad (administrator) on CHAD-PC on 19-03-2014 06:51:16
Running from C:\Users\Chad\Downloads
Microsoft® Windows Vista™ Home Premium  Service Pack 1 (X86) OS Language: English(US)
Internet Explorer Version 8
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(ATI Technologies Inc.) C:\Windows\system32\Ati2evxx.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(Hewlett-Packard Corporation) C:\Windows\system32\Hpservice.exe
(ATI Technologies Inc.) C:\Windows\system32\Ati2evxx.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f691e717\aestsrv.exe
(Hewlett-Packard Company) C:\Program Files\Hp\Common\HPSupportSolutionsFrameworkService.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
() C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
() C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
() C:\Windows\SMINST\BLService.exe
(Hewlett-Packard) c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(CyberLink Corp.) C:\Program Files\HP\QuickPlay\QPService.exe
( Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
(Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
() C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Windows\system32\wuauclt.exe
(Microsoft Corporation) C:\Windows\system32\msiexec.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [61440 2008-01-21] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1033512 2008-01-17] (Synaptics, Inc.)
HKLM\...\Run: [UCam_Menu] - C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [222504 2007-12-24] (CyberLink Corp.)
HKLM\...\Run: [QPService] - C:\Program Files\HP\QuickPlay\QPService.exe [468264 2008-05-14] (CyberLink Corp.)
HKLM\...\Run: [QlbCtrl.exe] - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [202032 2008-03-14] ( Hewlett-Packard Development Company, L.P.)
HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [40048 2007-05-11] (Adobe Systems Incorporated)
HKLM\...\Run: [HP Health Check Scheduler] - c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [70912 2008-04-15] (Hewlett-Packard)
HKLM\...\Run: [hpWirelessAssistant] - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [488752 2007-11-20] (Hewlett-Packard Development Company, L.P.)
HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2010-11-29] (Apple Inc.)
HKLM\...\Run: [HP Software Update] - C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM\...\Run: [] - [X]
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Runonce: [SpUninstallCleanUp] - REG delete HKEY_LOCAL_MACHINE\Software\SearchProtect /f
HKU\S-1-5-21-2716735411-3156541709-3801604676-1000\...\Run: [LightScribe Control Panel] - C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2289664 2008-02-26] (Hewlett-Packard Company)
HKU\S-1-5-21-2716735411-3156541709-3801604676-1000\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-20] (Microsoft Corporation)
HKU\S-1-5-21-2716735411-3156541709-3801604676-1000\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-20] (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com/?ctid=CT3317821&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SPD7EF345D-A846-435C-AC09-D35AB3117FAD&SSPV=
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Pavilion&pf=cnnb
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
SearchScopes: HKLM - {0E6A666A-D1F0-42A3-B9C0-24F2F6863063} URL = http://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=hp-pvnb
SearchScopes: HKLM - {CD7F680C-9718-4A86-A9BC-FBCFEE7EF20A} URL = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpl
SearchScopes: HKCU - DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://search.conduit.com/Results.aspx?ctid=CT3317821&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=4&UP=SPD7EF345D-A846-435C-AC09-D35AB3117FAD&q={searchTerms}&SSPV=
SearchScopes: HKCU - URL http://search.conduit.com/Results.aspx?ctid=CT3317821&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=4&UP=SPD7EF345D-A846-435C-AC09-D35AB3117FAD&q={searchTerms}&SSPV=
SearchScopes: HKCU - SuggestionsURL_JSON http://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms}
SearchScopes: HKCU - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://search.conduit.com/Results.aspx?ctid=CT3317821&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=4&UP=SPD7EF345D-A846-435C-AC09-D35AB3117FAD&q={searchTerms}&SSPV=
SearchScopes: HKCU - {0E6A666A-D1F0-42A3-B9C0-24F2F6863063} URL = http://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=hp-pvnb
SearchScopes: HKCU - {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL = http://websearch.ask.com/redirect?client=ie&tb=SB&o=14084&src=crm&q={searchTerms}&locale=en_US
SearchScopes: HKCU - {CD7F680C-9718-4A86-A9BC-FBCFEE7EF20A} URL = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpl
SearchScopes: HKCU - {FAEB1A28-7EFD-4BA4-982A-1195CE984420} URL = http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=714647&p={searchTerms}
BHO: No Name - {02478D38-C3F9-4efb-9B51-7695ECA05670} -  No File
BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://juniper.net/dana-cached/sc/JuniperSetupClient.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
ShellExecuteHooks:  - {AEB6717E-7E19-11d0-97EE-00C04FD91972} -  No File [ ]
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 184.16.33.54

FireFox:
========
FF ProfilePath: C:\Users\Chad\AppData\Roaming\Mozilla\Firefox\Profiles\sv1ctv5q.default
FF user.js: detected! => C:\Users\Chad\AppData\Roaming\Mozilla\Firefox\Profiles\sv1ctv5q.default\user.js
FF NewTab: about:newtab
FF DefaultSearchEngine: Conduit Search
FF SelectedSearchEngine: Conduit Search
FF Homepage: hxxp://search.conduit.com/?ctid=CT3317821&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SPD7EF345D-A846-435C-AC09-D35AB3117FAD&SSPV=
FF Keyword.URL: hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-yff26&p=
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFFICE.DLL (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.)
FF SearchPlugin: C:\Users\Chad\AppData\Roaming\Mozilla\Firefox\Profiles\sv1ctv5q.default\searchplugins\conduit-search.xml
FF SearchPlugin: C:\Users\Chad\AppData\Roaming\Mozilla\Firefox\Profiles\sv1ctv5q.default\searchplugins\yahoo_ff.xml
FF Extension: Plus-HD-5.0 - C:\Users\Chad\AppData\Roaming\Mozilla\Firefox\Profiles\sv1ctv5q.default\Extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com [2014-03-11]
FF Extension: Microsoft .NET Framework Assistant - C:\Users\Chad\AppData\Roaming\Mozilla\Firefox\Profiles\sv1ctv5q.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}(72) [2010-11-18]
FF Extension: Yahoo! Toolbar - C:\Users\Chad\AppData\Roaming\Mozilla\Firefox\Profiles\sv1ctv5q.default\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} [2014-01-23]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []
FF HKLM\...\Firefox\Extensions: [{0329E7D6-6F54-462D-93F6-F5C3118BADF2}] - C:\Program Files\SpeedBit Video Downloader\SPFireFox
FF HKCU\...\Firefox\Extensions: [{6559F149-A8B8-4101-BF51-B328E3352ADB}] - C:\Users\Chad\AppData\Local\{6559F149-A8B8-4101-BF51-B328E3352ADB}

========================== Services (Whitelisted) =================

R2 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f691e717\aestsrv.exe [73728 2008-02-11] (Andrea Electronics Corporation)
S2 gupdate1ca3367d83991a0; C:\Program Files\Google\Update\GoogleUpdate.exe [133104 2009-09-11] (Google Inc.)
R2 HP Health Check Service; c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [94208 2008-04-15] (Hewlett-Packard)
R2 HPSupportSolutionsFrameworkService; C:\Program Files\Hp\Common\HPSupportSolutionsFrameworkService.exe [46904 2013-12-17] (Hewlett-Packard Company)
R2 QPCapSvc; C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe [292248 2008-05-14] ()
R2 QPSched; C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe [116112 2008-05-14] ()
R2 Recovery Service for Windows; C:\Windows\SMINST\BLService.exe [341328 2008-03-26] ()

==================== Drivers (Whitelisted) ====================

R0 ahcix86s; C:\Windows\System32\DRIVERS\ahcix86s.sys [170000 2008-04-14] (AMD Technologies Inc.)
R0 Amddfltr; C:\Windows\System32\DRIVERS\Amddfltr.sys [15416 2008-01-07] (Advanced Micro Devices)
S3 HpqRemHid; C:\Windows\System32\DRIVERS\HpqRemHid.sys [7168 2007-07-11] (Hewlett-Packard Development Company, L.P.)
R3 libusb0; C:\Windows\System32\drivers\libusb0.sys [28672 2007-03-20] (http://libusb-win32.sourceforge.net)
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-20] (Microsoft Corporation)
S3 catchme; \??\C:\Users\Chad\AppData\Local\Temp\catchme.sys [X]
U1 eabfiltr;
S3 HTCAND32; System32\Drivers\ANDROIDUSB.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 Netaapl; system32\DRIVERS\netaapl.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S3 USBAAPL; System32\Drivers\usbaapl.sys [X]
U3 aswMBR; \??\C:\Users\Chad\AppData\Local\Temp\aswMBR.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-03-19 06:51 - 2014-03-19 06:51 - 00015025 _____ () C:\Users\Chad\Downloads\FRST.txt
2014-03-19 06:27 - 2014-03-19 06:27 - 00000000 ____D () C:\Users\Chad\Desktop\New Folder
2014-03-18 18:56 - 2014-03-18 18:56 - 00002025 _____ () C:\Users\Chad\Downloads\aswMBR.txt
2014-03-18 18:56 - 2014-03-18 18:56 - 00000512 _____ () C:\Users\Chad\Downloads\MBR1.dat
2014-03-18 07:29 - 2014-03-18 07:30 - 04745728 _____ (AVAST Software) C:\Users\Chad\Downloads\aswmbr.exe
2014-03-17 20:16 - 2014-03-17 20:16 - 00380416 _____ () C:\Users\Chad\Downloads\ux1xmwrz.exe
2014-03-17 20:11 - 2014-03-17 20:11 - 00380416 _____ () C:\Users\Chad\Downloads\3ot9tyic.exe
2014-03-17 18:49 - 2014-03-17 18:49 - 00380416 _____ () C:\Users\Chad\Downloads\fvm0li6t.exe
2014-03-17 18:34 - 2014-03-17 18:35 - 00034008 _____ () C:\Users\Chad\Downloads\Addition.txt
2014-03-17 18:33 - 2014-03-19 06:51 - 00000000 ____D () C:\FRST
2014-03-17 18:33 - 2014-03-17 18:33 - 01145856 _____ (Farbar) C:\Users\Chad\Downloads\FRST.exe
2014-03-16 22:27 - 2014-03-16 22:27 - 00008962 _____ () C:\Users\Chad\Desktop\hijackthis.log
2014-03-16 22:26 - 2014-03-16 22:26 - 00008962 _____ () C:\Users\Chad\Documents\hijackthis.log
2014-03-16 22:22 - 2014-03-16 22:25 - 00002521 _____ () C:\Users\Chad\Desktop\HiJackThis.lnk
2014-03-16 22:22 - 2014-03-16 22:22 - 00000000 ____D () C:\Users\Chad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
2014-03-16 22:21 - 2014-03-16 22:22 - 01402880 _____ () C:\Users\Chad\Downloads\HijackThis.msi
2014-03-16 11:05 - 2014-03-16 11:05 - 00000000 ____D () C:\Users\Chad\Downloads\The.Wolf.Of.Wall.Street.2013.1080p.BluRay.DTS-HD.MA.5.1.x264-PublicHD
2014-03-06 04:21 - 2014-03-06 04:21 - 00000000 ____D () C:\Windows\system32\SearchProtect
2014-03-03 12:40 - 2014-03-03 12:40 - 00000000 ____D () C:\Users\Chad\AppData\Local\Tuguu_SL
2014-03-03 12:39 - 2014-03-03 12:39 - 00000000 ____D () C:\Users\Chad\AppData\Roaming\VOPackage
2014-03-03 12:39 - 2014-03-03 12:39 - 00000000 ____D () C:\Users\Chad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage
2014-03-03 12:37 - 2014-03-19 06:43 - 00000000 ____D () C:\Program Files\SearchProtect
2014-03-03 12:37 - 2014-03-19 06:39 - 00000000 ____D () C:\Program Files\Optimizer Pro
2014-03-03 12:37 - 2014-03-03 12:37 - 00000000 ____D () C:\Users\Chad\Documents\Optimizer Pro
2014-03-03 12:35 - 2014-03-03 12:38 - 00000000 _____ () C:\END
2014-03-03 12:34 - 2014-03-03 12:34 - 00374408 _____ () C:\Users\Chad\Downloads\Setup.exe
2014-03-02 15:11 - 2014-03-02 15:20 - 00000000 ____D () C:\Users\Chad\Desktop\Movies
2014-02-19 19:04 - 2014-02-19 19:05 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-02-19 18:52 - 2014-02-19 19:01 - 00000188 _____ () C:\Users\Chad\Desktop\April Nike.txt

==================== One Month Modified Files and Folders =======

2014-03-19 06:51 - 2014-03-19 06:51 - 00015025 _____ () C:\Users\Chad\Downloads\FRST.txt
2014-03-19 06:51 - 2014-03-17 18:33 - 00000000 ____D () C:\FRST
2014-03-19 06:43 - 2014-03-03 12:37 - 00000000 ____D () C:\Program Files\SearchProtect
2014-03-19 06:41 - 2009-02-09 17:32 - 00000000 ____D () C:\Users\Chad\AppData\Local\Google
2014-03-19 06:41 - 2009-02-08 22:54 - 00000000 ____D () C:\ProgramData\Google
2014-03-19 06:41 - 2009-02-08 22:54 - 00000000 ____D () C:\Program Files\Google
2014-03-19 06:40 - 2009-09-11 22:28 - 00000886 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-03-19 06:39 - 2014-03-03 12:37 - 00000000 ____D () C:\Program Files\Optimizer Pro
2014-03-19 06:28 - 2006-11-02 03:33 - 00703388 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-03-19 06:27 - 2014-03-19 06:27 - 00000000 ____D () C:\Users\Chad\Desktop\New Folder
2014-03-19 03:15 - 2008-09-27 02:28 - 01520645 _____ () C:\Windows\WindowsUpdate.log
2014-03-19 03:06 - 2009-10-01 19:25 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-03-19 03:00 - 2006-11-02 05:47 - 00003216 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-03-19 03:00 - 2006-11-02 05:47 - 00003216 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-03-18 18:57 - 2014-01-19 20:33 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-03-18 18:56 - 2014-03-18 18:56 - 00002025 _____ () C:\Users\Chad\Downloads\aswMBR.txt
2014-03-18 18:56 - 2014-03-18 18:56 - 00000512 _____ () C:\Users\Chad\Downloads\MBR1.dat
2014-03-18 07:30 - 2014-03-18 07:29 - 04745728 _____ (AVAST Software) C:\Users\Chad\Downloads\aswmbr.exe
2014-03-18 07:28 - 2009-09-11 22:28 - 00000882 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-03-18 07:28 - 2008-09-27 03:10 - 00000267 _____ () C:\Users\Public\Documents\hpqp.ini
2014-03-17 21:50 - 2006-11-02 06:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-03-17 20:16 - 2014-03-17 20:16 - 00380416 _____ () C:\Users\Chad\Downloads\ux1xmwrz.exe
2014-03-17 20:11 - 2014-03-17 20:11 - 00380416 _____ () C:\Users\Chad\Downloads\3ot9tyic.exe
2014-03-17 19:23 - 2008-12-17 17:51 - 00000021 _____ () C:\Users\Public\Documents\hpqp.txt
2014-03-17 18:49 - 2014-03-17 18:49 - 00380416 _____ () C:\Users\Chad\Downloads\fvm0li6t.exe
2014-03-17 18:35 - 2014-03-17 18:34 - 00034008 _____ () C:\Users\Chad\Downloads\Addition.txt
2014-03-17 18:33 - 2014-03-17 18:33 - 01145856 _____ (Farbar) C:\Users\Chad\Downloads\FRST.exe
2014-03-16 22:27 - 2014-03-16 22:27 - 00008962 _____ () C:\Users\Chad\Desktop\hijackthis.log
2014-03-16 22:26 - 2014-03-16 22:26 - 00008962 _____ () C:\Users\Chad\Documents\hijackthis.log
2014-03-16 22:25 - 2014-03-16 22:22 - 00002521 _____ () C:\Users\Chad\Desktop\HiJackThis.lnk
2014-03-16 22:22 - 2014-03-16 22:22 - 00000000 ____D () C:\Users\Chad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
2014-03-16 22:22 - 2014-03-16 22:21 - 01402880 _____ () C:\Users\Chad\Downloads\HijackThis.msi
2014-03-16 22:15 - 2014-01-25 22:49 - 00000000 ____D () C:\Program Files\Shutterfly
2014-03-16 22:14 - 2014-01-28 19:45 - 00000000 ____D () C:\Users\Chad\AppData\Roaming\BitTorrent
2014-03-16 11:05 - 2014-03-16 11:05 - 00000000 ____D () C:\Users\Chad\Downloads\The.Wolf.Of.Wall.Street.2013.1080p.BluRay.DTS-HD.MA.5.1.x264-PublicHD
2014-03-16 11:00 - 2014-01-19 20:33 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-03-16 11:00 - 2014-01-19 20:33 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-03-06 04:21 - 2014-03-06 04:21 - 00000000 ____D () C:\Windows\system32\SearchProtect
2014-03-05 22:01 - 2008-01-20 19:47 - 00144368 _____ () C:\Windows\PFRO.log
2014-03-05 21:54 - 2006-11-02 06:01 - 00032648 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-03-03 12:40 - 2014-03-03 12:40 - 00000000 ____D () C:\Users\Chad\AppData\Local\Tuguu_SL
2014-03-03 12:39 - 2014-03-03 12:39 - 00000000 ____D () C:\Users\Chad\AppData\Roaming\VOPackage
2014-03-03 12:39 - 2014-03-03 12:39 - 00000000 ____D () C:\Users\Chad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage
2014-03-03 12:38 - 2014-03-03 12:35 - 00000000 _____ () C:\END
2014-03-03 12:37 - 2014-03-03 12:37 - 00000000 ____D () C:\Users\Chad\Documents\Optimizer Pro
2014-03-03 12:34 - 2014-03-03 12:34 - 00374408 _____ () C:\Users\Chad\Downloads\Setup.exe
2014-03-03 08:24 - 2008-12-15 11:39 - 00000000 ____D () C:\Users\Chad
2014-03-02 15:20 - 2014-03-02 15:11 - 00000000 ____D () C:\Users\Chad\Desktop\Movies
2014-03-02 14:59 - 2009-02-21 14:40 - 00028672 _____ () C:\Users\Chad\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-02-28 19:03 - 2009-06-17 17:28 - 00000000 ____D () C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite
2014-02-28 19:03 - 2008-12-15 11:39 - 00000000 ____D () C:\Users\Chad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite
2014-02-28 19:03 - 2008-05-22 19:39 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite
2014-02-28 19:03 - 2008-05-22 19:39 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite
2014-02-28 19:00 - 2006-11-02 04:18 - 00000000 ___RD () C:\Users\Public
2014-02-23 21:55 - 2014-01-19 21:18 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-02-19 19:05 - 2014-02-19 19:04 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-02-19 19:01 - 2014-02-19 18:52 - 00000188 _____ () C:\Users\Chad\Desktop\April Nike.txt
2014-02-19 15:18 - 2014-01-31 04:05 - 00000000 ____D () C:\Windows\system32\MRT
2014-02-19 15:13 - 2006-11-02 03:24 - 85946576 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe

Some content of TEMP:
====================
C:\Users\Chad\AppData\Local\Temp\BackupSetup.exe
C:\Users\Chad\AppData\Local\Temp\bpuninstall.exe
C:\Users\Chad\AppData\Local\Temp\dsHostCheckerSetup.exe
C:\Users\Chad\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe
C:\Users\Chad\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe
C:\Users\Chad\AppData\Local\Temp\JuniperSetupClientInstaller.exe
C:\Users\Chad\AppData\Local\Temp\nsc915B.exe
C:\Users\Chad\AppData\Local\Temp\nsh1434.exe
C:\Users\Chad\AppData\Local\Temp\nsh8B13.exe
C:\Users\Chad\AppData\Local\Temp\nssBEA.exe
C:\Users\Chad\AppData\Local\Temp\nsz47.exe
C:\Users\Chad\AppData\Local\Temp\SPSetup.exe
C:\Users\Chad\AppData\Local\Temp\utt53D9.tmp.exe
C:\Users\Chad\AppData\Local\Temp\uttA3ED.tmp.exe
C:\Users\Chad\AppData\Local\Temp\vcredist_x86.exe


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-03-17 20:23

==================== End Of Log ============================



#9 union410

union410
  • Topic Starter

  • Members
  • 39 posts
  • OFFLINE
  •  
  • Local time:07:07 PM

Posted 19 March 2014 - 08:57 AM

There was only one new log with this FRST scan. Should there have been two?



#10 TB-Psychotic

TB-Psychotic

  • Malware Response Team
  • 6,349 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:07 AM

Posted 19 March 2014 - 09:44 AM

Please run FRST again.

Ensure a checkmark is placed next to "addition.txt" and hit scan.

 

Post up the addition.txt when ready.


Proud Member of UNITE & TB
 
My help is free, however, if you want to support my fight against malware, click here --> btn_donate_SM.gif <--(no worries, every little bit helps)

#11 union410

union410
  • Topic Starter

  • Members
  • 39 posts
  • OFFLINE
  •  
  • Local time:07:07 PM

Posted 19 March 2014 - 01:02 PM

Sorry I missed that step.

 

Additional scan result of Farbar Recovery Scan Tool (x86) Version: 13-03-2014  01
Ran by Chad at 2014-03-19 08:47:19
Running from C:\Users\Chad\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

Activation Assistant for the 2007 Microsoft Office suites (HKLM\...\Activation Assistant for the 2007 Microsoft Office suites) (Version:  - Microsoft Corporation)
Activation Assistant for the 2007 Microsoft Office suites (Version: 1.0 - Microsoft Corporation) Hidden
Adobe AIR (HKLM\...\Adobe AIR) (Version: 4.0.0.1390 - Adobe Systems Incorporated)
Adobe AIR (Version: 4.0.0.1390 - Adobe Systems Incorporated) Hidden
Adobe Flash Player 10 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 10.0.12.36 - Adobe Systems Incorporated)
Adobe Flash Player 12 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 12.0.0.77 - Adobe Systems Incorporated)
Adobe Reader 8.1.0 (HKLM\...\{AC76BA86-7AD7-1033-7B44-A81000000003}) (Version: 8.1.0 - Adobe Systems Incorporated)
Adobe Shockwave Player (HKLM\...\{1BDC9633-895B-4842-BCB6-8FA1EC2A3C5A}) (Version: 10.2.0.023 - Adobe Systems, Inc.)
AMD Driver Support for HP 3D DriverGuard (Version: 5.1.0000.0066 - Advanced Micro Devices, Inc.) Hidden
Atheros Driver Installation Program (HKLM\...\{C3A32068-8AB1-4327-BB16-BED9C6219DC7}) (Version: 5.2 - Atheros)
ATI Catalyst Install Manager (HKLM\...\{80C2AD19-97A2-C829-38DE-5FD5B47F122B}) (Version: 3.0.664.0 - ATI Technologies, Inc.)
Cards_Calendar_OrderGift_DoMorePlugout (Version: 1.00.0000 - Hewlett-Packard) Hidden
Catalyst Control Center - Branding (HKLM\...\{3FA93E4C-CB3B-4B25-B091-9DB0FCC56A74}) (Version: 1.00.0000 - ATI)
Catalyst Control Center Core Implementation (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Graphics Full Existing (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Graphics Full New (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Graphics Light (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Graphics Previews Vista (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Localization Chinese Standard (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Localization Chinese Traditional (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Localization Czech (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Localization Danish (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Localization Dutch (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Localization Finnish (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Localization French (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Localization German (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Localization Greek (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Localization Hungarian (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Localization Italian (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Localization Japanese (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Localization Korean (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Localization Norwegian (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Localization Polish (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Localization Portuguese (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Localization Russian (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Localization Spanish (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Localization Swedish (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Localization Thai (Version: 2008.0328.2322.39969 - ATI) Hidden
Catalyst Control Center Localization Turkish (Version: 2008.0328.2322.39969 - ATI) Hidden
CCC Help Chinese Standard (Version: 2008.0328.2321.39969 - ATI) Hidden
CCC Help Chinese Traditional (Version: 2008.0328.2321.39969 - ATI) Hidden
CCC Help Czech (Version: 2008.0328.2321.39969 - ATI) Hidden
CCC Help Danish (Version: 2008.0328.2321.39969 - ATI) Hidden
CCC Help Dutch (Version: 2008.0328.2321.39969 - ATI) Hidden
CCC Help English (Version: 2008.0328.2321.39969 - ATI) Hidden
CCC Help Finnish (Version: 2008.0328.2321.39969 - ATI) Hidden
CCC Help French (Version: 2008.0328.2321.39969 - ATI) Hidden
CCC Help German (Version: 2008.0328.2321.39969 - ATI) Hidden
CCC Help Greek (Version: 2008.0328.2321.39969 - ATI) Hidden
CCC Help Hungarian (Version: 2008.0328.2321.39969 - ATI) Hidden
CCC Help Italian (Version: 2008.0328.2321.39969 - ATI) Hidden
CCC Help Japanese (Version: 2008.0328.2321.39969 - ATI) Hidden
CCC Help Korean (Version: 2008.0328.2321.39969 - ATI) Hidden
CCC Help Norwegian (Version: 2008.0328.2321.39969 - ATI) Hidden
CCC Help Polish (Version: 2008.0328.2321.39969 - ATI) Hidden
CCC Help Portuguese (Version: 2008.0328.2321.39969 - ATI) Hidden
CCC Help Russian (Version: 2008.0328.2321.39969 - ATI) Hidden
CCC Help Spanish (Version: 2008.0328.2321.39969 - ATI) Hidden
CCC Help Swedish (Version: 2008.0328.2321.39969 - ATI) Hidden
CCC Help Thai (Version: 2008.0328.2321.39969 - ATI) Hidden
CCC Help Turkish (Version: 2008.0328.2321.39969 - ATI) Hidden
ccc-core-static (Version: 2008.0328.2322.39969 - ATI) Hidden
ccc-utility (Version: 2008.0328.2322.39969 - ATI) Hidden
Cisco EAP-FAST Module (HKLM\...\{415B2719-AD3A-4944-B404-C472DB6085B3}) (Version: 2.1.6 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM\...\{83770D14-21B9-44B3-8689-F7B523F94560}) (Version: 1.0.12 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM\...\{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}) (Version: 1.0.13 - Cisco Systems, Inc.)
Compatibility Pack for the 2007 Office system (HKLM\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
CyberLink DVD Suite (HKLM\...\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 5.5.1519 - CyberLink Corp.)
CyberLink YouCam (HKLM\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 2.0.1616 - CyberLink Corp.)
CyberLink YouCam (Version: 2.0.1616 - CyberLink Corp.) Hidden
Hewlett-Packard Active Check for Health Check (Version: 1.1.15.2 - Hewlett-Packard) Hidden
Hewlett-Packard Asset Agent for Health Check (Version: 2.0.63.2 - HP) Hidden
HiJackThis (HKLM\...\{45A66726-69BC-466B-A7A4-12FCBA4883D7}) (Version: 1.0.0 - Trend Micro)
HP Active Support Library (Version: 3.1.4.1 - Hewlett-Packard) Hidden
HP Customer Experience Enhancements (HKLM\...\{C27C82E4-9C53-4D76-9ED3-A01A3D5EE679}) (Version: 5.6.0.2510 - Hewlett-Packard)
HP Doc Viewer (HKLM\...\{082702D5-5DD8-4600-BCE5-48B15174687F}) (Version: 1.03.0001 - Hewlett-Packard)
HP Help and Support (HKLM\...\{31216452-5540-4C96-B754-94890A63D5AB}) (Version: 2.0.10.0 - Hewlett-Packard)
HP Photosmart Essential 2.5 (HKLM\...\HP Photosmart Essential) (Version: 2.5 - HP)
HP Photosmart Essential 2.5 (Version: 1.02.0000 - Hewlett-Packard) Hidden
HP Quick Launch Buttons 6.40 D3 (HKLM\...\{34D2AB40-150D-475D-AE32-BD23FB5EE355}) (Version: 6.40 D3 - Hewlett-Packard)
HP QuickPlay 3.7 (HKLM\...\{45D707E9-F3C4-11D9-A373-0050BAE317E1}) (Version:  - )
HP Support Solutions Framework (HKLM\...\{23CCE784-A812-4647-AEFF-1DCCD4E57478}) (Version: 11.50.0000 - Hewlett-Packard Company)
HP Total Care Advisor (HKLM\...\{f32502b5-5b64-4882-bf61-77f23edcac4f}) (Version: 2.1.3359.2635 - Hewlett-Packard)
HP Update (HKLM\...\{97486FBE-A3FC-4783-8D55-EA37E9D171CC}) (Version: 5.005.000.002 - Hewlett-Packard)
HP User Guides 0102 (HKLM\...\{F48098CD-2D66-4861-85EC-DC1D4D09D5F9}) (Version: 1.01.0000 - Hewlett-Packard)
HP Wireless Assistant (HKLM\...\{A5CE7175-080D-49AC-B5A3-E7E3502428F5}) (Version: 3.00 I2 - Hewlett-Packard)
HPNetworkAssistant (Version: 1.1.70 - Hewlett-Packard.) Hidden
HPPhotoSmartDiscLabel_PaperLabel (Version: 2.02.0000 - Hewlett-Packard) Hidden
HPPhotoSmartDiscLabel_PrintOnDisc (Version: 2.02.0000 - Hewlett-Packard) Hidden
HPPhotoSmartDiscLabel_Tattoo (Version: 2.02.0000 - Hewlett-Packard) Hidden
HPPhotoSmartDiscLabelContent1 (Version: 2.02.0000 - Hewlett-Packard) Hidden
hpphotosmartdisclabelplugin (Version: 2.02.0000 - Hewlett-Packard) Hidden
HPPhotoSmartPhotobookHolidayPack1 (Version: 1.00.0000 - Hewlett-Packard) Hidden
HPPhotoSmartPhotobookModernPack1 (Version: 1.00.0000 - Hewlett-Packard) Hidden
HPPhotoSmartPhotobookPlayfulPack1 (Version: 1.00.0000 - Hewlett-Packard) Hidden
HPPhotoSmartPhotobookScrapbookPack1 (Version: 1.00.0000 - Hewlett-Packard) Hidden
HPPhotoSmartPhotobookWebPack1 (Version: 1.00.0000 - Hewlett-Packard) Hidden
HPTCSSetup (HKLM\...\{FA3B34BE-4246-4062-90A3-34CBBEA12B72}) (Version: 1.0.964.2626 - Hewlett-Packard Company)
IDT Audio (HKLM\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.5893.0 - IDT)
Java 7 Update 51 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.510 - Oracle)
Java Auto Updater (Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
Java™ 6 Update 5 (HKLM\...\{3248F0A8-6813-11D6-A77B-00B0D0160050}) (Version: 1.6.0.50 - Sun Microsystems, Inc.)
Juniper Citrix Services Client (HKCU\...\Juniper_Citrix_Services) (Version: 7.1.13.22557 - Juniper Networks)
Juniper Networks Host Checker (HKCU\...\Neoteris_Host_Checker) (Version: 7.1.15.25271 - Juniper Networks)
Juniper Networks, Inc. Setup Client (HKCU\...\Juniper_Setup_Client) (Version: 7.1.15.36013 - Juniper Networks, Inc.)
Juniper Networks, Inc. Setup Client Activex Control (HKLM\...\Juniper_Setup_Client Activex Control) (Version: 2.1.1.1 - Juniper Networks, Inc.)
Juniper Terminal Services Client (HKCU\...\Juniper_Term_Services) (Version: 7.1.15.25271 - Juniper Networks)
LabelPrint (HKLM\...\{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.20.2719 - CyberLink Corp.)
LibUSB-Win32-0.1.12.1 (HKLM\...\LibUSB-Win32_is1) (Version: 0.1.12.1 - LibUSB-Win32)
LightScribe System Software  1.12.33.2 (HKLM\...\{582287DA-0806-4AC0-BF19-C15E3A466034}) (Version: 1.12.33.2 - LightScribe)
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint Viewer 2007 (English) (HKLM\...\{95120000-00AF-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Standard Edition 2003 (HKLM\...\{91120409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Works (HKLM\...\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}) (Version: 9.7.0621 - Microsoft Corporation)
Mozilla Firefox 27.0.1 (x86 en-US) (HKLM\...\Mozilla Firefox 27.0.1 (x86 en-US)) (Version: 27.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 27.0.1 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
muvee autoProducer 6.1 (HKLM\...\{35F83303-C0C0-46B7-B8A8-ADA7C2AC5645}) (Version: 6.10.050 - muvee Technologies)
My HP Games (HKLM\...\WildTangent hp Master Uninstall) (Version: 1.0.0.43 - WildTangent)
OGA Notifier 2.0.0048.0 (Version: 2.0.0048.0 - Microsoft Corporation) Hidden
PHStat2 2.8.1 (HKLM\...\{6CB203AC-E5A7-424E-B4DC-C16564185463}) (Version: 2.8.1 - Prentice Hall, Inc., a division of Pearson Education)
PHStat2 version 2.5.1 (HKLM\...\{363798A0-FE16-4BA8-8119-572A02202DBF}) (Version: 2.5.1 - Prentice Hall, Inc., a division of Pearson Education)
Power2Go (HKLM\...\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 5.6.3919 - CyberLink Corp.)
PowerDirector (HKLM\...\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 6.5.2719 - CyberLink Corp.)
ProtectSmart Hard Drive Protection (HKLM\...\{AAD72731-807A-4B79-AE05-9190B7002B7B}) (Version: 3.10 A7 - Hewlett-Packard)
PSSWCORE (Version: 2.02.0000 - Hewlett-Packard) Hidden
QuickFreedom 1.1.0 (HKLM\...\{676B241C-AED4-400B-98FF-267773B94B11}_is1) (Version:  - Dancool999)
QuickPlay SlingPlayer 0.4.6 (HKLM\...\SlingMedia.QPSlingPlayer_is1) (Version: 0.4.6 - SlingMedia)
QuickTime (HKLM\...\{57752979-A1C9-4C02-856B-FBB27AC4E02C}) (Version: 7.69.80.9 - Apple Inc.)
Realtek 8169 8168 8101E 8102E Ethernet Driver (HKLM\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 1.00.0000 - Realtek)
Realtek USB 2.0 Card Reader (HKLM\...\{DC24971E-1946-445D-8A82-CE685433FA7D}) (Version:  - Realtek Semiconductor Corp.)
Skins (Version: 2008.0328.2322.39969 - ATI) Hidden
Slingbox Flash Tour (HKLM\...\{38EAC694-0D90-445F-8C17-8B50ADFE3162}) (Version: 1.0.0 - Sling Media)
SlingPlayer (HKLM\...\InstallShield_{004B0DCB-4C60-465B-8F01-44B0A4111187}) (Version: 1.04.0206 - Sling Media)
SlingPlayer (Version: 1.04.0206 - Sling Media) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 10.2.4.0 - Synaptics)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (HKLM\...\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707) (Version: 1 - Microsoft Corporation)
VideoToolkit01 (Version: 100.0.128.000 - Hewlett-Packard) Hidden
VO Package (HKLM\...\VOPackage) (Version: 1.0.0.0 - )

==================== Restore Points  =========================

17-03-2014 05:15:18 Removed Shutterfly Express Uploader
17-03-2014 05:16:38 Removed iTunes
17-03-2014 05:22:32 Installed HiJackThis
17-03-2014 05:24:03 Windows Update
19-03-2014 10:01:01 Windows Update
19-03-2014 10:10:45 Windows Update

==================== Hosts content: ==========================

2006-11-02 03:23 - 2011-05-26 23:45 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost

==================== Scheduled Tasks (whitelisted) =============

Task: {06F125FC-3726-4B1F-9490-F0BDDFF54890} - System32\Tasks\HP Health Check => c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [2008-04-15] (Hewlett-Packard)
Task: {0A986836-C4CF-4E58-A75A-F6B503C6FA55} - System32\Tasks\{3B21C084-532D-4016-8308-DDA21B2E3624} => C:\Program Files\Skype\Phone\Skype.exe
Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {320124A7-D70F-41DE-A9D1-D5E8E19D5D91} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-20] (Microsoft Corporation)
Task: {C2ADC630-2109-4246-B5A8-D445730FD150} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-16] (Adobe Systems Incorporated)
Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-20] ()
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Loaded Modules (whitelisted) =============

2008-05-22 18:26 - 2008-05-14 22:56 - 00292248 _____ () C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
2008-05-22 18:26 - 2008-05-14 22:56 - 00259480 _____ () C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapEngine.dll
2008-05-22 18:26 - 2008-05-14 22:56 - 00038184 _____ () C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvcps.dll
2008-05-22 18:26 - 2008-05-14 22:56 - 00116112 _____ () C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
2008-05-22 18:26 - 2008-05-14 22:56 - 00120216 _____ () C:\Program Files\HP\QuickPlay\Kernel\TV\CLSchMgr.dll
2008-05-22 18:26 - 2008-05-14 22:56 - 00345384 _____ () C:\Program Files\HP\QuickPlay\Kernel\TV\CLTinyDB.dll
2008-05-22 19:55 - 2008-03-26 15:26 - 00341328 _____ () C:\Windows\SMINST\BLService.exe
2008-05-22 19:55 - 2006-09-13 13:54 - 00081920 _____ () C:\Windows\SMINST\STString.dll
2008-05-22 19:55 - 2007-11-14 15:46 - 00126976 _____ () C:\Windows\SMINST\STWmiM.dll
2008-03-28 02:19 - 2008-03-28 02:19 - 00159744 _____ () C:\Windows\system32\atitmmxx.dll
2008-02-04 13:29 - 2008-02-04 13:29 - 00688128 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll
2007-07-12 12:55 - 2007-07-12 12:55 - 01581056 _____ () C:\Program Files\Common Files\LightScribe\QtCore4.dll
2007-08-14 12:59 - 2007-08-14 12:59 - 06365184 _____ () C:\Program Files\Common Files\LightScribe\QtGui4.dll
2007-07-12 12:55 - 2007-07-12 12:55 - 00131072 _____ () C:\Program Files\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll
2008-05-22 18:26 - 2008-05-14 22:56 - 00066856 _____ () C:\Program Files\HP\QuickPlay\Kernel\Common\MCEMediaStatus.dll
2008-05-22 18:38 - 2008-04-11 09:04 - 00685360 _____ () C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
2008-02-27 14:48 - 2008-02-27 14:48 - 00016384 ____R () C:\Program Files\ATI Technologies\ATI.ACE\Branding\Branding.dll
2014-02-19 19:04 - 2014-02-19 19:05 - 03578992 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\ProgramData\TEMP:CD060F93

==================== Safe Mode (whitelisted) ===================

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"

==================== Disabled items from MSCONFIG ==============


==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (03/19/2014 06:59:32 AM) (Source: Windows Search Service) (User: )
Description: The entry <C:\USERS\CHAD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SV1CTV5Q.DEFAULT\PERMISSIONS.SQLITE-JOURNAL> in the hash map cannot be updated.

Context:  Application, SystemIndex Catalog


Details:
    A device attached to the system is not functioning.   (0x8007001f)

Error: (03/19/2014 06:38:47 AM) (Source: Windows Search Service) (User: )
Description: The entry <C:\USERS\CHAD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SV1CTV5Q.DEFAULT\STORAGE\PERSISTENT\CHROME\IDB\3914039608BCD6LCA8NCR1E5T-N2I1.SQLITE-JOURNAL> in the hash map cannot be updated.

Context:  Application, SystemIndex Catalog


Details:
    A device attached to the system is not functioning.   (0x8007001f)

Error: (03/19/2014 06:38:44 AM) (Source: Windows Search Service) (User: )
Description: The entry <C:\USERS\CHAD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SV1CTV5Q.DEFAULT\STORAGE\PERSISTENT\CHROME\IDB\16292413673B8D8L9ADN7R0EAT-N3IF.SQLITE-JOURNAL> in the hash map cannot be updated.

Context:  Application, SystemIndex Catalog


Details:
    A device attached to the system is not functioning.   (0x8007001f)

Error: (03/19/2014 06:38:44 AM) (Source: Windows Search Service) (User: )
Description: The entry <C:\USERS\CHAD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SV1CTV5Q.DEFAULT\STORAGE\PERSISTENT\CHROME\IDB\27775517150BCD8L2A2NAR1E7T-NAI6.SQLITE-JOURNAL> in the hash map cannot be updated.

Context:  Application, SystemIndex Catalog


Details:
    A device attached to the system is not functioning.   (0x8007001f)

Error: (03/19/2014 06:38:42 AM) (Source: Windows Search Service) (User: )
Description: The entry <C:\USERS\CHAD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SV1CTV5Q.DEFAULT\STORAGE\PERSISTENT\CHROME\IDB\3914039608BCD6LCA8NCR1E5T-N2I1.SQLITE-JOURNAL> in the hash map cannot be updated.

Context:  Application, SystemIndex Catalog


Details:
    A device attached to the system is not functioning.   (0x8007001f)

Error: (03/19/2014 06:38:34 AM) (Source: Windows Search Service) (User: )
Description: The entry <C:\USERS\CHAD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SV1CTV5Q.DEFAULT\STORAGE\PERSISTENT\CHROME\IDB\27775517150BCD8L2A2NAR1E7T-NAI6.SQLITE-JOURNAL> in the hash map cannot be updated.

Context:  Application, SystemIndex Catalog


Details:
    A device attached to the system is not functioning.   (0x8007001f)

Error: (03/19/2014 06:38:34 AM) (Source: Windows Search Service) (User: )
Description: The entry <C:\USERS\CHAD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SV1CTV5Q.DEFAULT\STORAGE\PERSISTENT\CHROME\IDB\16292413673B8D8L9ADN7R0EAT-N3IF.SQLITE-JOURNAL> in the hash map cannot be updated.

Context:  Application, SystemIndex Catalog


Details:
    A device attached to the system is not functioning.   (0x8007001f)

Error: (03/19/2014 06:38:30 AM) (Source: Windows Search Service) (User: )
Description: The entry <C:\USERS\CHAD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SV1CTV5Q.DEFAULT\STORAGE\PERSISTENT\CHROME\IDB\3914039608BCD6LCA8NCR1E5T-N2I1.SQLITE-JOURNAL> in the hash map cannot be updated.

Context:  Application, SystemIndex Catalog


Details:
    A device attached to the system is not functioning.   (0x8007001f)

Error: (03/19/2014 06:38:30 AM) (Source: Windows Search Service) (User: )
Description: The entry <C:\USERS\CHAD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SV1CTV5Q.DEFAULT\STORAGE\PERSISTENT\CHROME\IDB\16292413673B8D8L9ADN7R0EAT-N3IF.SQLITE-JOURNAL> in the hash map cannot be updated.

Context:  Application, SystemIndex Catalog


Details:
    A device attached to the system is not functioning.   (0x8007001f)

Error: (03/19/2014 06:38:24 AM) (Source: Windows Search Service) (User: )
Description: The entry <C:\USERS\CHAD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SV1CTV5Q.DEFAULT\STORAGE\PERSISTENT\CHROME\IDB\27775517150BCD8L2A2NAR1E7T-NAI6.SQLITE-JOURNAL> in the hash map cannot be updated.

Context:  Application, SystemIndex Catalog


Details:
    A device attached to the system is not functioning.   (0x8007001f)


System errors:
=============

Microsoft Office Sessions:
=========================
Error: (03/19/2014 06:59:32 AM) (Source: Windows Search Service)(User: )
Description: Context:  Application, SystemIndex Catalog


Details:
    A device attached to the system is not functioning.   (0x8007001f)
C:\USERS\CHAD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SV1CTV5Q.DEFAULT\PERMISSIONS.SQLITE-JOURNAL

Error: (03/19/2014 06:38:47 AM) (Source: Windows Search Service)(User: )
Description: Context:  Application, SystemIndex Catalog


Details:
    A device attached to the system is not functioning.   (0x8007001f)
C:\USERS\CHAD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SV1CTV5Q.DEFAULT\STORAGE\PERSISTENT\CHROME\IDB\3914039608BCD6LCA8NCR1E5T-N2I1.SQLITE-JOURNAL

Error: (03/19/2014 06:38:44 AM) (Source: Windows Search Service)(User: )
Description: Context:  Application, SystemIndex Catalog


Details:
    A device attached to the system is not functioning.   (0x8007001f)
C:\USERS\CHAD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SV1CTV5Q.DEFAULT\STORAGE\PERSISTENT\CHROME\IDB\16292413673B8D8L9ADN7R0EAT-N3IF.SQLITE-JOURNAL

Error: (03/19/2014 06:38:44 AM) (Source: Windows Search Service)(User: )
Description: Context:  Application, SystemIndex Catalog


Details:
    A device attached to the system is not functioning.   (0x8007001f)
C:\USERS\CHAD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SV1CTV5Q.DEFAULT\STORAGE\PERSISTENT\CHROME\IDB\27775517150BCD8L2A2NAR1E7T-NAI6.SQLITE-JOURNAL

Error: (03/19/2014 06:38:42 AM) (Source: Windows Search Service)(User: )
Description: Context:  Application, SystemIndex Catalog


Details:
    A device attached to the system is not functioning.   (0x8007001f)
C:\USERS\CHAD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SV1CTV5Q.DEFAULT\STORAGE\PERSISTENT\CHROME\IDB\3914039608BCD6LCA8NCR1E5T-N2I1.SQLITE-JOURNAL

Error: (03/19/2014 06:38:34 AM) (Source: Windows Search Service)(User: )
Description: Context:  Application, SystemIndex Catalog


Details:
    A device attached to the system is not functioning.   (0x8007001f)
C:\USERS\CHAD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SV1CTV5Q.DEFAULT\STORAGE\PERSISTENT\CHROME\IDB\27775517150BCD8L2A2NAR1E7T-NAI6.SQLITE-JOURNAL

Error: (03/19/2014 06:38:34 AM) (Source: Windows Search Service)(User: )
Description: Context:  Application, SystemIndex Catalog


Details:
    A device attached to the system is not functioning.   (0x8007001f)
C:\USERS\CHAD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SV1CTV5Q.DEFAULT\STORAGE\PERSISTENT\CHROME\IDB\16292413673B8D8L9ADN7R0EAT-N3IF.SQLITE-JOURNAL

Error: (03/19/2014 06:38:30 AM) (Source: Windows Search Service)(User: )
Description: Context:  Application, SystemIndex Catalog


Details:
    A device attached to the system is not functioning.   (0x8007001f)
C:\USERS\CHAD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SV1CTV5Q.DEFAULT\STORAGE\PERSISTENT\CHROME\IDB\3914039608BCD6LCA8NCR1E5T-N2I1.SQLITE-JOURNAL

Error: (03/19/2014 06:38:30 AM) (Source: Windows Search Service)(User: )
Description: Context:  Application, SystemIndex Catalog


Details:
    A device attached to the system is not functioning.   (0x8007001f)
C:\USERS\CHAD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SV1CTV5Q.DEFAULT\STORAGE\PERSISTENT\CHROME\IDB\16292413673B8D8L9ADN7R0EAT-N3IF.SQLITE-JOURNAL

Error: (03/19/2014 06:38:24 AM) (Source: Windows Search Service)(User: )
Description: Context:  Application, SystemIndex Catalog


Details:
    A device attached to the system is not functioning.   (0x8007001f)
C:\USERS\CHAD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SV1CTV5Q.DEFAULT\STORAGE\PERSISTENT\CHROME\IDB\27775517150BCD8L2A2NAR1E7T-NAI6.SQLITE-JOURNAL


CodeIntegrity Errors:
===================================
  Date: 2014-03-19 08:46:32.960
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-03-19 08:46:32.787
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-03-19 08:46:32.619
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-03-19 08:46:32.445
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-03-19 08:46:32.276
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-03-19 08:46:32.114
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-03-19 08:46:31.897
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-03-19 08:46:31.293
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-03-19 06:51:29.872
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-03-19 06:51:29.599
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.


==================== Memory info ===========================

Percentage of memory in use: 38%
Total physical RAM: 2813.09 MB
Available physical RAM: 1718.73 MB
Total Pagefile: 5856.2 MB
Available Pagefile: 4596.43 MB
Total Virtual: 2047.88 MB
Available Virtual: 1932.08 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:222.84 GB) (Free:67.44 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (HP_RECOVERY) (Fixed) (Total:10.04 GB) (Free:1.75 GB) NTFS ==>[System with boot components (obtained from reading drive)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 233 GB) (Disk ID: 657A29EF)
Partition 1: (Active) - (Size=223 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=10 GB) - (Type=07 NTFS)

==================== End Of Log ============================



#12 TB-Psychotic

TB-Psychotic

  • Malware Response Team
  • 6,349 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:07 AM

Posted 19 March 2014 - 03:26 PM

No Antivirus Program installed!

I don't see an Anti Virus Program running on your machine.

Download and install an antivirus program, and make sure that you keep it updated
New viruses come out every minute, so it is essential that you have the latest signatures for your antivirus program to provide you with the best possible protection from malicious software.

Two good antivirus programs free for non-commercial home use are
Avast!
or
Microsoft Security Essentials

Note: You should only have one antivirus installed at a time. Having more than one antivirus program installed at once is likely to cause conflicts and may well decrease your overall protection as well as impairing the performance of your PC.

 

 

 

 

Going over your logs I noticed that you have BitTorrent installed.

  • Avoid gaming sites, pirated software, cracking tools, keygens, and peer-to-peer (P2P) file sharing programs.
  • They are a security risk which can make your computer susceptible to a wide variety of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites.
  • Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and malicious Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users.
  • The best way to reduce the risk of infection is to avoid these types of web sites and not use any P2P applications.

It is pretty much certain that if you continue to use P2P programs, you will get infected again.
I would recommend that you uninstall BitTorrent, however that choice is up to you. If you choose to remove these programs, you can do so via Start > Control Panel > Add/Remove Programs.
If you wish to keep it, please do not use it until your computer is cleaned.

 

 

 

 

Fix with FRST (normal mode)

  • Open notepad (Start =>All Programs => Accessories => Notepad).
  • Please copy the entire contents of the code box below.
    (To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste).
  • Save it to the same direction as frst.exe (or frst64.exe) as fixlist.txt.

    SearchScopes: HKLM - {0E6A666A-D1F0-42A3-B9C0-24F2F6863063} URL = http://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=hp-pvnb
    SearchScopes: HKLM - {CD7F680C-9718-4A86-A9BC-FBCFEE7EF20A} URL = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpl
    SearchScopes: HKCU - DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://search.conduit.com/Results.aspx?ctid=CT3317821&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=4&UP=SPD7EF345D-A846-435C-AC09-D35AB3117FAD&q={searchTerms}&SSPV=
    SearchScopes: HKCU - URL http://search.conduit.com/Results.aspx?ctid=CT3317821&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=4&UP=SPD7EF345D-A846-435C-AC09-D35AB3117FAD&q={searchTerms}&SSPV=
    SearchScopes: HKCU - SuggestionsURL_JSON http://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms}
    SearchScopes: HKCU - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://search.conduit.com/Results.aspx?ctid=CT3317821&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=4&UP=SPD7EF345D-A846-435C-AC09-D35AB3117FAD&q={searchTerms}&SSPV=
    SearchScopes: HKCU - {0E6A666A-D1F0-42A3-B9C0-24F2F6863063} URL = http://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=hp-pvnb
    SearchScopes: HKCU - {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL = http://websearch.ask.com/redirect?client=ie&tb=SB&o=14084&src=crm&q={searchTerms}&locale=en_US
    SearchScopes: HKCU - {CD7F680C-9718-4A86-A9BC-FBCFEE7EF20A} URL = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpl
    SearchScopes: HKCU - {FAEB1A28-7EFD-4BA4-982A-1195CE984420} URL = http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=714647&p={searchTerms}
    BHO: No Name - {02478D38-C3F9-4efb-9B51-7695ECA05670} -  No File
    Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
    FF DefaultSearchEngine: Conduit Search
    FF SelectedSearchEngine: Conduit Search
    FF Homepage: hxxp://search.conduit.com/?ctid=CT3317821&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SPD7EF345D-A846-435C-AC09-D35AB3117FAD&SSPV=
    FF Keyword.URL: hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-yff26&p=
    FF SearchPlugin: C:\Users\Chad\AppData\Roaming\Mozilla\Firefox\Profiles\sv1ctv5q.default\searchplugins\conduit-search.xml
    FF SearchPlugin: C:\Users\Chad\AppData\Roaming\Mozilla\Firefox\Profiles\sv1ctv5q.default\searchplugins\yahoo_ff.xml
    FF Extension: Plus-HD-5.0 - C:\Users\Chad\AppData\Roaming\Mozilla\Firefox\Profiles\sv1ctv5q.default\Extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com [2014-03-11]
    FF Extension: Microsoft .NET Framework Assistant - C:\Users\Chad\AppData\Roaming\Mozilla\Firefox\Profiles\sv1ctv5q.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}(72) [2010-11-18]
    FF Extension: Yahoo! Toolbar - C:\Users\Chad\AppData\Roaming\Mozilla\Firefox\Profiles\sv1ctv5q.default\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} [2014-01-23]
    FF HKLM\...\Firefox\Extensions: [{0329E7D6-6F54-462D-93F6-F5C3118BADF2}] - C:\Program Files\SpeedBit Video Downloader\SPFireFox
    FF HKCU\...\Firefox\Extensions: [{6559F149-A8B8-4101-BF51-B328E3352ADB}] - C:\Users\Chad\AppData\Local\{6559F149-A8B8-4101-BF51-B328E3352ADB}
    HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com/?ctid=CT3317821&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SPD7EF345D-A846-435C-AC09-D35AB3117FAD&SSPV=
    AlternateDataStreams: C:\ProgramData\TEMP:CD060F93
    
    2014-03-06 04:21 - 2014-03-06 04:21 - 00000000 ____D () C:\Windows\system32\SearchProtect
    2014-03-03 12:40 - 2014-03-03 12:40 - 00000000 ____D () C:\Users\Chad\AppData\Local\Tuguu_SL
    2014-03-03 12:37 - 2014-03-19 06:43 - 00000000 ____D () C:\Program Files\SearchProtect
    2014-03-03 12:37 - 2014-03-19 06:39 - 00000000 ____D () C:\Program Files\Optimizer Pro
    2014-03-03 12:37 - 2014-03-03 12:37 - 00000000 ____D () C:\Users\Chad\Documents\Optimizer Pro
    2014-03-03 12:39 - 2014-03-03 12:39 - 00000000 ____D () C:\Users\Chad\AppData\Roaming\VOPackage
    2014-03-03 12:39 - 2014-03-03 12:39 - 00000000 ____D () C:\Users\Chad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage
    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
  • Run frst.exe (on 64bit, run frst64.exe) and press the Fix button just once and wait.
  • The tool will make a log (Fixlog.txt) which you find where you saved FRST. Please post it to your reply.

 

 

 

 

Full System Scan with Malwarebytes Antimalware

  • If not existing, please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.


If the program is already installed:
  • Run Malwarebytes Antimalware
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform fullscan, place a checkmark on all hard drives, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location.
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Post that log back here.


Proud Member of UNITE & TB
 
My help is free, however, if you want to support my fight against malware, click here --> btn_donate_SM.gif <--(no worries, every little bit helps)

#13 union410

union410
  • Topic Starter

  • Members
  • 39 posts
  • OFFLINE
  •  
  • Local time:07:07 PM

Posted 20 March 2014 - 08:15 PM

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 13-03-2014  01
Ran by Chad at 2014-03-20 18:14:23 Run:1
Running from C:\Users\Chad\Downloads
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
SearchScopes: HKLM - {0E6A666A-D1F0-42A3-B9C0-24F2F6863063} URL = http://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=hp-pvnb
SearchScopes: HKLM - {CD7F680C-9718-4A86-A9BC-FBCFEE7EF20A} URL = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpl
SearchScopes: HKCU - DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://search.conduit.com/Results.aspx?ctid=CT3317821&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=4&UP=SPD7EF345D-A846-435C-AC09-D35AB3117FAD&q={searchTerms}&SSPV=
SearchScopes: HKCU - URL http://search.conduit.com/Results.aspx?ctid=CT3317821&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=4&UP=SPD7EF345D-A846-435C-AC09-D35AB3117FAD&q={searchTerms}&SSPV=
SearchScopes: HKCU - SuggestionsURL_JSON http://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms}
SearchScopes: HKCU - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://search.conduit.com/Results.aspx?ctid=CT3317821&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=4&UP=SPD7EF345D-A846-435C-AC09-D35AB3117FAD&q={searchTerms}&SSPV=
SearchScopes: HKCU - {0E6A666A-D1F0-42A3-B9C0-24F2F6863063} URL = http://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=hp-pvnb
SearchScopes: HKCU - {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL = http://websearch.ask.com/redirect?client=ie&tb=SB&o=14084&src=crm&q={searchTerms}&locale=en_US
SearchScopes: HKCU - {CD7F680C-9718-4A86-A9BC-FBCFEE7EF20A} URL = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpl
SearchScopes: HKCU - {FAEB1A28-7EFD-4BA4-982A-1195CE984420} URL = http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=714647&p={searchTerms}
BHO: No Name - {02478D38-C3F9-4efb-9B51-7695ECA05670} -  No File
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
FF DefaultSearchEngine: Conduit Search
FF SelectedSearchEngine: Conduit Search
FF Homepage: hxxp://search.conduit.com/?ctid=CT3317821&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SPD7EF345D-A846-435C-AC09-D35AB3117FAD&SSPV=
FF Keyword.URL: hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-yff26&p=
FF SearchPlugin: C:\Users\Chad\AppData\Roaming\Mozilla\Firefox\Profiles\sv1ctv5q.default\searchplugins\conduit-search.xml
FF SearchPlugin: C:\Users\Chad\AppData\Roaming\Mozilla\Firefox\Profiles\sv1ctv5q.default\searchplugins\yahoo_ff.xml
FF Extension: Plus-HD-5.0 - C:\Users\Chad\AppData\Roaming\Mozilla\Firefox\Profiles\sv1ctv5q.default\Extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com [2014-03-11]
FF Extension: Microsoft .NET Framework Assistant - C:\Users\Chad\AppData\Roaming\Mozilla\Firefox\Profiles\sv1ctv5q.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}(72) [2010-11-18]
FF Extension: Yahoo! Toolbar - C:\Users\Chad\AppData\Roaming\Mozilla\Firefox\Profiles\sv1ctv5q.default\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} [2014-01-23]
FF HKLM\...\Firefox\Extensions: [{0329E7D6-6F54-462D-93F6-F5C3118BADF2}] - C:\Program Files\SpeedBit Video Downloader\SPFireFox
FF HKCU\...\Firefox\Extensions: [{6559F149-A8B8-4101-BF51-B328E3352ADB}] - C:\Users\Chad\AppData\Local\{6559F149-A8B8-4101-BF51-B328E3352ADB}
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com/?ctid=CT3317821&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SPD7EF345D-A846-435C-AC09-D35AB3117FAD&SSPV=
AlternateDataStreams: C:\ProgramData\TEMP:CD060F93

2014-03-06 04:21 - 2014-03-06 04:21 - 00000000 ____D () C:\Windows\system32\SearchProtect
2014-03-03 12:40 - 2014-03-03 12:40 - 00000000 ____D () C:\Users\Chad\AppData\Local\Tuguu_SL
2014-03-03 12:37 - 2014-03-19 06:43 - 00000000 ____D () C:\Program Files\SearchProtect
2014-03-03 12:37 - 2014-03-19 06:39 - 00000000 ____D () C:\Program Files\Optimizer Pro
2014-03-03 12:37 - 2014-03-03 12:37 - 00000000 ____D () C:\Users\Chad\Documents\Optimizer Pro
2014-03-03 12:39 - 2014-03-03 12:39 - 00000000 ____D () C:\Users\Chad\AppData\Roaming\VOPackage
2014-03-03 12:39 - 2014-03-03 12:39 - 00000000 ____D () C:\Users\Chad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage
*****************

HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0E6A666A-D1F0-42A3-B9C0-24F2F6863063} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{0E6A666A-D1F0-42A3-B9C0-24F2F6863063} => Key not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CD7F680C-9718-4A86-A9BC-FBCFEE7EF20A} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{CD7F680C-9718-4A86-A9BC-FBCFEE7EF20A} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\URL => Value deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\SuggestionsURL_JSON => Value deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0E6A666A-D1F0-42A3-B9C0-24F2F6863063} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{0E6A666A-D1F0-42A3-B9C0-24F2F6863063} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CD7F680C-9718-4A86-A9BC-FBCFEE7EF20A} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{CD7F680C-9718-4A86-A9BC-FBCFEE7EF20A} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{FAEB1A28-7EFD-4BA4-982A-1195CE984420} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{FAEB1A28-7EFD-4BA4-982A-1195CE984420} => Key not found.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670} => Key deleted successfully.
HKCR\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670} => Key not found.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Value deleted successfully.
HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Key not found.
Firefox DefaultSearchEngine deleted successfully.
Firefox SelectedSearchEngine deleted successfully.
Firefox homepage deleted successfully.
Firefox Keyword.URL deleted successfully.
"C:\Users\Chad\AppData\Roaming\Mozilla\Firefox\Profiles\sv1ctv5q.default\searchplugins\conduit-search.xml" => not found.
C:\Users\Chad\AppData\Roaming\Mozilla\Firefox\Profiles\sv1ctv5q.default\searchplugins\yahoo_ff.xml => Moved successfully.
C:\Users\Chad\AppData\Roaming\Mozilla\Firefox\Profiles\sv1ctv5q.default\Extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com => Moved successfully.
C:\Users\Chad\AppData\Roaming\Mozilla\Firefox\Profiles\sv1ctv5q.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}(72) => Moved successfully.
C:\Users\Chad\AppData\Roaming\Mozilla\Firefox\Profiles\sv1ctv5q.default\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} => Moved successfully.
HKLM\Software\Mozilla\Firefox\Extensions\\{0329E7D6-6F54-462D-93F6-F5C3118BADF2} => Value deleted successfully.
HKCU\Software\Mozilla\Firefox\Extensions\\{6559F149-A8B8-4101-BF51-B328E3352ADB} => Value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
C:\ProgramData\TEMP => ":CD060F93" ADS removed successfully.
C:\Windows\System32\SearchProtect => Moved successfully.
C:\Users\Chad\AppData\Local\Tuguu_SL => Moved successfully.
C:\Program Files\SearchProtect => Moved successfully.
C:\Program Files\Optimizer Pro => Moved successfully.
C:\Users\Chad\Documents\Optimizer Pro => Moved successfully.
C:\Users\Chad\AppData\Roaming\VOPackage => Moved successfully.
C:\Users\Chad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage => Moved successfully.

==== End of Fixlog ====



#14 TB-Psychotic

TB-Psychotic

  • Malware Response Team
  • 6,349 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:07 AM

Posted 21 March 2014 - 06:38 AM

what about the MBAM log?


Proud Member of UNITE & TB
 
My help is free, however, if you want to support my fight against malware, click here --> btn_donate_SM.gif <--(no worries, every little bit helps)

#15 union410

union410
  • Topic Starter

  • Members
  • 39 posts
  • OFFLINE
  •  
  • Local time:07:07 PM

Posted 22 March 2014 - 12:49 AM

I finally was able to run the full system scan. It found 30 errors that I checked and had fixed, but once it was complete I got an error saying that Notepad unexpectedly closed. I couldn't copy and paste, and now I can't find that log in either of the two places you said they would be. Should I run another full scan?






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users