Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected, unsure of type! Lots of Pop ups with ads, video, and redirected!


  • This topic is locked This topic is locked
20 replies to this topic

#1 Vecc1982

Vecc1982

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:07:39 AM

Posted 03 April 2014 - 10:54 AM

Attached File  attach.txt   21.59KB   0 downloadsThis is a new topic as directed from a previous post. I have borrowed my friend's laptop that is infected with adware/malware? Most of the scans come out clean. I have also tried to disable Chrome plug-ins from it's beta site. I have multiple pop up ads advertising products to buy, also have pop up video commercials...when I try to exit out of it, it sometimes opens up a new window directing me to a website to buy anti virus software. I close out pretty quickly. Each time I click on something the ads cover areas of screen needed on web page forcing me to click on the X to close out which leads to alternate window. Please help!Here is log as directed from dds.com. Thanks in advance!

DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 8.0.6001.18702
Run by Seth at 11:41:30 on 2014-04-03
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1918.908 [GMT -4:00]
.
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
============== Running Processes ================
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe
C:\Program Files\DisplayLink Core Software\DisplayLinkUserAgent.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
C:\Program Files\DisplayLink Core Software\DisplayLinkUI.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Documents and Settings\Seth\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Documents and Settings\Seth\Application Data\Dropbox\bin\Dropbox.exe
C:\Program Files\Evernote\Evernote\EvernoteClipper.exe
C:\Program Files\Logitech Touch Mouse Server\iTouch-Server-Win.exe
C:\Documents and Settings\Seth\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Seth\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Seth\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Seth\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Seth\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Seth\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Seth\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Seth\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k HPService
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com
uDefault_Page_URL = hxxp://www.google.com
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll
BHO: Evernote extension: {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - c:\program files\evernote\evernote\EvernoteIE.dll
uRun: [Google Update] "c:\documents and settings\seth\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /minimized /regrun
uRun: [Adobe Reader Synchronizer] "c:\program files\adobe\reader 10.0\reader\AdobeCollabSync.exe"
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [AvastUI.exe] "c:\program files\avast software\avast\AvastUI.exe" /nogui
StartupFolder: c:\docume~1\seth\startm~1\programs\startup\dropbox.lnk - c:\documents and settings\seth\application data\dropbox\bin\Dropbox.exe
StartupFolder: c:\docume~1\seth\startm~1\programs\startup\everno~1.lnk - c:\program files\evernote\evernote\EvernoteClipper.exe
StartupFolder: c:\docume~1\seth\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech touch mouse server\iTouch-Server-Win.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Windows\System: Allow-LogonScript-NetbiosDisabled = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
IE: Clip Image - c:\program files\evernote\evernote\\evernoteieres\Clip.html?clipAction=4
IE: Clip selection - c:\program files\evernote\evernote\\evernoteieres\Clip.html?clipAction=3
IE: Clip this page - c:\program files\evernote\evernote\\evernoteieres\Clip.html?clipAction=1
IE: Clip URL - c:\program files\evernote\evernote\\evernoteieres\Clip.html?clipAction=0
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: New Note - c:\program files\evernote\evernote\\evernoteieres\NewNote.html
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - c:\program files\evernote\evernote\\evernoteieres\AddNote.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxps://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{C56C30AB-0C0E-46E0-A856-1A9E8F0C0F0D} : DHCPNameServer = 192.168.1.1
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\34.0.1847.116\installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
.
============= SERVICES / DRIVERS ===============
.
R0 aswRvrt;avast! Revert;c:\windows\system32\drivers\aswRvrt.sys [2014-3-30 49944]
R0 aswVmm;avast! VM Monitor;c:\windows\system32\drivers\aswVmm.sys [2014-3-30 180760]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2014-3-30 776976]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2014-3-30 411552]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2014-3-30 67824]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2014-3-30 50344]
R2 DisplayLinkService;DisplayLinkManager;c:\program files\displaylink core software\DisplayLinkManager.exe [2010-4-19 5096808]
R2 MBAMScheduler;MBAMScheduler;c:\program files\malwarebytes anti-malware\mbamscheduler.exe [2014-4-2 1809720]
R2 MBAMService;MBAMService;c:\program files\malwarebytes anti-malware\mbamservice.exe [2014-4-2 857912]
R3 DisplayLinkFilter;DisplayLinkFilter;c:\windows\system32\drivers\DisplayLinkFilter.sys [2010-4-19 7040]
R3 DisplayLinkGA;DisplayLinkGA;c:\windows\system32\drivers\DisplayLinkGAport.sys [2010-4-19 27776]
R3 DisplayLinkmirror;DisplayLinkmirror;c:\windows\system32\drivers\DisplayLinkmirrorport.sys [2010-4-19 24320]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2014-4-2 23256]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys [2014-4-2 107736]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2013-10-23 172192]
S3 BrYNSvc;BrYNSvc;c:\program files\browny02\BrYNSvc.exe [2012-8-8 245760]
S3 DisplayLinkUsbPort;DisplayLink USB Device;c:\windows\system32\drivers\DisplayLinkUsbPort_5.3.24474.0.sys [2012-2-2 21888]
S3 SCR3XX2K;SCR3xx USB SmartCardReader;c:\windows\system32\drivers\SCR3XX2K.sys [2012-7-31 59776]
S3 silabenm;Silicon Labs CP210x USB to UART Bridge Serial Port Enumerator Driver;c:\windows\system32\drivers\silabenm.sys [2010-6-10 47176]
S3 silabser;Silicon Labs CP210x USB to UART Bridge Driver;c:\windows\system32\drivers\silabser.sys [2011-9-28 61312]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2008-5-6 11520]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2013-7-20 754856]
.
=============== Created Last 30 ================
.
2014-04-03 15:41:09 -------- d--h--w- c:\windows\PIF
2014-04-02 19:21:34 107736 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-04-02 19:20:49 50648 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-04-02 19:20:49 23256 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-04-02 19:20:49 -------- d-----w- c:\program files\Malwarebytes Anti-Malware
2014-04-02 02:31:23 -------- d-----w- c:\program files\ESET
2014-04-02 02:15:42 -------- d-----w- c:\documents and settings\seth\application data\IDM2
2014-04-02 01:39:03 -------- d-----w- c:\windows\ERUNT
2014-04-01 00:14:54 -------- d-----w- C:\AdwCleaner
2014-03-30 21:42:39 -------- d-----w- c:\documents and settings\seth\application data\AVAST Software
2014-03-30 21:41:57 776976 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2014-03-30 21:41:57 180760 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-03-30 21:41:56 49944 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-03-30 21:41:55 67824 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-03-30 21:41:49 43152 ----a-w- c:\windows\avastSS.scr
2014-03-30 21:41:13 -------- d-----w- c:\program files\AVAST Software
2014-03-30 21:38:46 -------- d-----w- c:\documents and settings\all users\application data\AVAST Software
2014-03-27 02:21:53 13312 -c----w- c:\windows\system32\dllcache\xp_eos.exe
2014-03-27 02:21:53 13312 ------w- c:\windows\system32\xp_eos.exe
2014-03-10 16:28:28 -------- d-----w- c:\program files\DiscountLLocator
2014-03-10 16:21:25 -------- d-----w- c:\program files\dOwnlloadittkeep
2014-03-10 16:20:48 -------- d-----w- c:\program files\saver box
2014-03-10 16:13:02 -------- d-----w- c:\documents and settings\seth\application data\Malwarebytes
2014-03-10 16:12:52 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
.
==================== Find3M ====================
.
2014-02-27 04:00:13 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-02-27 04:00:13 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-02-24 11:46:36 920064 ----a-w- c:\windows\system32\wininet.dll
2014-02-24 11:45:58 43520 ------w- c:\windows\system32\licmgr10.dll
2014-02-24 11:45:57 1469440 ------w- c:\windows\system32\inetcpl.cpl
2014-02-24 11:45:42 18944 ----a-w- c:\windows\system32\corpol.dll
2014-02-24 10:54:21 385024 ------w- c:\windows\system32\html.iec
2014-02-07 02:01:37 1879040 ----a-w- c:\windows\system32\win32k.sys
2014-02-05 08:55:04 562688 ----a-w- c:\windows\system32\qedit.dll
2014-01-04 03:13:05 420864 ----a-w- c:\windows\system32\vbscript.dll
.
============= FINISH: 11:43:01.36 ===============

Edited by Vecc1982, 03 April 2014 - 10:59 AM.


BC AdBot (Login to Remove)

 


#2 fireman4it

fireman4it

    Bleepin' Fireman


  • Malware Response Team
  • 13,512 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Greenup, Ill USA
  • Local time:06:39 AM

Posted 03 April 2014 - 02:44 PM

Hello Vecc1982,
  • Welcome to Bleeping Computer.
  • My name is fireman4it and I will be helping you with your Malware problem.

    Please take note of some guidelines for this fix:
  • Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools.
  • If you do not understand any step(s) provided, please do not hesitate to ask before continuing.
  • Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean".
  • In the upper right hand corner of the topic you will see a button called Follow This Topic.I suggest you click it and select Immediate E-Mail notification and click on Follow This Topic. This way you will be advised when we respond to your topic and facilitate the cleaning of your machine.
  • Finally, please reply using the Post  button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply, unless they do not fit into the post.
Please download Farbar Recovery Scan Tool and save it to your Desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will produce a log called FRST.txt in the same directory the tool is run from.
  • Please copy and paste log back here.
  • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.

" Extinguishing Malware from the world"

The Virus, Trojan, Spyware, and Malware Removal forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.

ALL OTHER HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
Thanks-


  userbar_eis_500.gif

If I have helped you, consider making a donation to help me continue the fight against Malware! Just click btn_donate_LG.gif


#3 Vecc1982

Vecc1982
  • Topic Starter

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:07:39 AM

Posted 03 April 2014 - 09:17 PM

Hi, thank you for the assistance. Here are logs:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-03-2014 01
Ran by Seth (administrator) on ISG-SSGDELL1501 on 03-04-2014 22:16:09
Running from C:\Documents and Settings\Seth\My Documents\Downloads
Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: English(US)
Internet Explorer Version 8
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(ATI Technologies Inc.) C:\WINDOWS\system32\Ati2evxx.exe
(DisplayLink Corp.) C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe
(DisplayLink Corp.) C:\Program Files\DisplayLink Core Software\DisplayLinkUserAgent.exe
(ATI Technologies Inc.) C:\WINDOWS\system32\Ati2evxx.exe
() C:\WINDOWS\System32\WLTRYSVC.EXE
(Dell Inc.) C:\WINDOWS\System32\bcmwltry.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\WINDOWS\System32\SCardSvr.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(DisplayLink Corp.) C:\Program Files\DisplayLink Core Software\DisplayLinkUI.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Google Inc.) C:\Documents and Settings\Seth\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(Dropbox, Inc.) C:\Documents and Settings\Seth\Application Data\Dropbox\bin\Dropbox.exe
(Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files\Evernote\Evernote\EvernoteClipper.exe
(Logitech, Inc.) C:\Program Files\Logitech Touch Mouse Server\iTouch-Server-Win.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [761947 2006-03-08] (Synaptics, Inc.)
HKLM\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3854640 2014-03-30] (AVAST Software)
Winlogon\Notify\AtiExtEvent: C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
HKU\S-1-5-21-842925246-1993962763-682003330-1003\...\Run: [Google Update] - C:\Documents and Settings\Seth\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [136176 2011-12-19] (Google Inc.)
HKU\S-1-5-21-842925246-1993962763-682003330-1003\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [20587168 2013-11-18] (Skype Technologies S.A.)
HKU\S-1-5-21-842925246-1993962763-682003330-1003\...\Run: [Adobe Reader Synchronizer] - C:\Program Files\Adobe\Reader 10.0\Reader\AdobeCollabSync.exe [1261472 2012-04-04] (Adobe Systems Incorporated)
HKU\S-1-5-21-842925246-1993962763-682003330-1003\...\MountPoints2: {0c95b3b3-9bce-11e1-88f8-0015c5cffd84} - E:\TL_Bootstrap.exe
HKU\S-1-5-21-842925246-1993962763-682003330-1003\...\MountPoints2: {3a645617-5218-11e3-89c8-0015c5cffd84} - H:\MotoCastSetup.exe -a
HKU\S-1-5-21-842925246-1993962763-682003330-1003\...\MountPoints2: {4b341afa-a3b2-11e1-8900-0015c5cffd84} - E:\TL_Bootstrap.exe
HKU\S-1-5-21-842925246-1993962763-682003330-1003\...\MountPoints2: {8bf5dcc6-407c-11e1-88c0-001a921c748d} - E:\TL_Bootstrap.exe
HKU\S-1-5-21-842925246-1993962763-682003330-1003\...\MountPoints2: {8e96924e-36e5-11e1-88b7-001a921c748d} - E:\TL_Bootstrap.exe
Startup: C:\Documents and Settings\Seth\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Documents and Settings\Seth\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Documents and Settings\Seth\Start Menu\Programs\Startup\EvernoteClipper.lnk
ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
Startup: C:\Documents and Settings\Seth\Start Menu\Programs\Startup\Logitech Touch Mouse Server.lnk
ShortcutTarget: Logitech Touch Mouse Server.lnk -> C:\Program Files\Logitech Touch Mouse Server\iTouch-Server-Win.exe (Logitech, Inc.)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search
SearchScopes: HKCU - {83C7A244-F282-477C-A771-308DB0CC3BAE} URL = http://search.findwide.com/serp?guid={73673A59-C3EE-4737-8ED6-6C6CEA911CCF}&action=default_search&serpv=22&k={searchTerms}
SearchScopes: HKCU - {995E125B-ABD7-48F9-9953-8D0A7309B014} URL = http://search.yahoo.com/search?p={searchTerms}&fr=tightropetb&type=10741
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO: Evernote extension - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
Toolbar: HKCU - &Address - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
Toolbar: HKCU - &Links - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
Toolbar: HKCU - No Name - {F11C6FE2-596D-4872-8630-89B860582F0D} - No File
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 04 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

Chrome:
=======
CHR Extension: (Google Docs) - C:\Documents and Settings\Seth\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-04-03]
CHR Extension: (Google Drive) - C:\Documents and Settings\Seth\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-04-03]
CHR Extension: (YouTube) - C:\Documents and Settings\Seth\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-04-03]
CHR Extension: (Google Search) - C:\Documents and Settings\Seth\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-04-03]
CHR Extension: (avast! Online Security) - C:\Documents and Settings\Seth\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-04-03]
CHR Extension: (Google Wallet) - C:\Documents and Settings\Seth\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-04-03]
CHR Extension: (Gmail) - C:\Documents and Settings\Seth\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-04-03]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-03-30]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

========================== Services (Whitelisted) =================

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-03-30] (AVAST Software)
S3 BrYNSvc; C:\Program Files\Browny02\BrYNSvc.exe [245760 2010-01-25] (Brother Industries, Ltd.)
R2 DisplayLinkService; C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe [5096808 2010-04-19] (DisplayLink Corp.)
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-03-05] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [857912 2014-03-05] (Malwarebytes Corporation)
R2 wltrysvc; C:\WINDOWS\System32\bcmwltry.exe [1200128 2005-12-19] (Dell Inc.)

==================== Drivers (Whitelisted) ====================

R1 AmdK8; C:\WINDOWS\System32\DRIVERS\AmdK8.sys [36864 2006-07-01] (Advanced Micro Devices)
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [67824 2014-03-30] (AVAST Software)
R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [54832 2014-03-30] (AVAST Software)
R0 aswRvrt; C:\WINDOWS\system32\Drivers\aswRvrt.sys [49944 2014-03-30] ()
R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [776976 2014-03-30] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [411552 2014-03-30] (AVAST Software)
R1 aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [57672 2014-03-30] (AVAST Software)
R0 aswVmm; C:\WINDOWS\system32\Drivers\aswVmm.sys [180760 2014-03-30] ()
R3 BCM43XX; C:\WINDOWS\System32\DRIVERS\bcmwl5.sys [424320 2005-11-02] (Broadcom Corporation)
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation)
R3 DisplayLinkFilter; C:\WINDOWS\System32\DRIVERS\DisplayLinkFilter.sys [7040 2010-04-19] (DisplayLink Corp.)
R3 DisplayLinkGA; C:\WINDOWS\System32\DRIVERS\DisplayLinkGAport.sys [27776 2010-04-19] (DisplayLink Corp.)
R3 DisplayLinkmirror; C:\WINDOWS\System32\DRIVERS\DisplayLinkmirrorport.sys [24320 2010-04-19] (DisplayLink Corp.)
S3 DisplayLinkUsbPort; C:\WINDOWS\System32\DRIVERS\DisplayLinkUsbPort_5.3.24474.0.sys [21888 2012-02-02] (http://libusb-win32.sourceforge.net)
S3 HPZid412; C:\WINDOWS\System32\DRIVERS\HPZid412.sys [49920 2010-02-01] (HP)
S3 HPZipr12; C:\WINDOWS\System32\DRIVERS\HPZipr12.sys [16496 2010-02-01] (HP)
S3 HPZius12; C:\WINDOWS\System32\DRIVERS\HPZius12.sys [21568 2010-02-01] (HP)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [23256 2014-03-05] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [107736 2014-04-03] (Malwarebytes Corporation)
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation)
S3 SCR3XX2K; C:\WINDOWS\System32\DRIVERS\SCR3XX2K.sys [59776 2012-07-31] (Identive)
S3 silabenm; C:\WINDOWS\System32\DRIVERS\silabenm.sys [47176 2010-06-10] (Silicon Laboratories)
S3 silabser; C:\WINDOWS\System32\DRIVERS\silabser.sys [61312 2011-09-28] (Silicon Laboratories)
R3 STHDA; C:\WINDOWS\System32\drivers\sthda.sys [1171464 2006-07-27] (SigmaTel, Inc.)
U2 CertPropSvc;
S4 IntelIde; No ImagePath
S2 mdmxsdk; system32\DRIVERS\mdmxsdk.sys [X]
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation)
S3 UIUSys; system32\DRIVERS\UIUSYS.SYS [X]
U1 WS2IFSL;
U3 aswMBR; \??\C:\DOCUME~1\Seth\LOCALS~1\Temp\aswMBR.sys [X]
U3 mbr; \??\C:\DOCUME~1\Seth\LOCALS~1\Temp\mbr.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-04-03 22:15 - 2014-04-03 22:16 - 00000000 ____D () C:\FRST
2014-04-03 11:43 - 2014-04-03 11:46 - 00022107 _____ () C:\Documents and Settings\Seth\Desktop\attach.txt
2014-04-03 11:43 - 2014-04-03 11:46 - 00011265 _____ () C:\Documents and Settings\Seth\Desktop\dds.txt
2014-04-03 11:41 - 2014-04-03 11:41 - 00002855 _____ () C:\Documents and Settings\Seth\Desktop\Shortcut to dds.com.pif
2014-04-03 11:41 - 2014-04-03 11:41 - 00000000 ___HD () C:\WINDOWS\PIF
2014-04-03 09:32 - 2014-04-03 09:32 - 00001813 _____ () C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
2014-04-03 09:32 - 2014-04-03 09:32 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Google Chrome
2014-04-03 09:29 - 2014-04-03 13:34 - 00000882 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-03 09:29 - 2014-04-03 09:34 - 00000878 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-03 09:28 - 2014-04-03 09:31 - 00000000 ____D () C:\Program Files\Google
2014-04-02 21:24 - 2014-04-02 21:29 - 00000178 ___SH () C:\Documents and Settings\Administrator\ntuser.ini
2014-04-02 21:24 - 2014-04-02 21:24 - 00000000 __SHD () C:\Documents and Settings\Administrator\IETldCache
2014-04-02 21:24 - 2014-04-02 21:24 - 00000000 ____D () C:\Documents and Settings\Administrator
2014-04-02 21:24 - 2012-03-31 03:08 - 00000000 ____D () C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft Help
2014-04-02 21:24 - 2012-02-13 11:56 - 00000000 ____D () C:\Documents and Settings\Administrator\Application Data\Macromedia
2014-04-02 21:24 - 2011-12-19 17:03 - 00001599 _____ () C:\Documents and Settings\Administrator\Start Menu\Programs\Remote Assistance.lnk
2014-04-02 21:24 - 2011-12-19 17:03 - 00000792 _____ () C:\Documents and Settings\Administrator\Start Menu\Programs\Windows Media Player.lnk
2014-04-02 21:24 - 2011-12-19 17:03 - 00000000 ___RD () C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories
2014-04-02 20:00 - 2014-04-02 20:02 - 00002816 _____ () C:\Documents and Settings\Seth\Desktop\Rkill.txt
2014-04-02 19:12 - 2014-04-02 19:12 - 00001057 _____ () C:\Malware report.txt
2014-04-02 15:21 - 2014-04-03 12:20 - 00107736 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-04-02 15:20 - 2014-04-02 15:20 - 00000777 _____ () C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-02 15:20 - 2014-04-02 15:20 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-04-02 15:20 - 2014-04-02 15:20 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware
2014-04-02 15:20 - 2014-03-05 09:26 - 00050648 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2014-04-02 15:20 - 2014-03-05 09:26 - 00023256 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2014-04-01 22:31 - 2014-04-01 22:31 - 00000000 ____D () C:\Program Files\ESET
2014-04-01 22:15 - 2014-04-01 22:15 - 00000000 ____D () C:\Documents and Settings\Seth\Application Data\IDM2
2014-04-01 21:48 - 2014-04-01 21:48 - 00001740 _____ () C:\Documents and Settings\Seth\Desktop\JRT.txt
2014-04-01 21:39 - 2014-04-01 21:39 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-04-01 21:29 - 2014-04-01 21:29 - 00090112 _____ () C:\WINDOWS\Minidump\Mini040114-01.dmp
2014-03-31 20:14 - 2014-04-03 10:46 - 00000000 ____D () C:\AdwCleaner
2014-03-30 17:42 - 2014-04-03 05:42 - 00000360 ____H () C:\WINDOWS\Tasks\avast! Emergency Update.job
2014-03-30 17:42 - 2014-03-30 17:42 - 00001733 _____ () C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
2014-03-30 17:42 - 2014-03-30 17:42 - 00000000 ____D () C:\Documents and Settings\Seth\Application Data\AVAST Software
2014-03-30 17:42 - 2014-03-30 17:42 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Avast
2014-03-30 17:41 - 2014-03-30 17:41 - 00776976 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2014-03-30 17:41 - 2014-03-30 17:41 - 00411552 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2014-03-30 17:41 - 2014-03-30 17:41 - 00271264 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2014-03-30 17:41 - 2014-03-30 17:41 - 00180760 _____ () C:\WINDOWS\system32\Drivers\aswVmm.sys
2014-03-30 17:41 - 2014-03-30 17:41 - 00067824 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2014-03-30 17:41 - 2014-03-30 17:41 - 00057672 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswTdi.sys
2014-03-30 17:41 - 2014-03-30 17:41 - 00054832 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr.sys
2014-03-30 17:41 - 2014-03-30 17:41 - 00049944 _____ () C:\WINDOWS\system32\Drivers\aswRvrt.sys
2014-03-30 17:41 - 2014-03-30 17:41 - 00043152 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2014-03-30 17:41 - 2014-03-30 17:41 - 00000000 ____D () C:\Program Files\AVAST Software
2014-03-30 17:38 - 2014-03-30 17:39 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\AVAST Software
2014-03-30 17:18 - 2014-04-02 22:44 - 00000220 _____ () C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job
2014-03-30 17:18 - 2014-03-31 14:12 - 00000214 _____ () C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job
2014-03-28 10:29 - 2014-03-28 10:29 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2934207$
2014-03-28 10:23 - 2014-03-28 10:29 - 00006826 _____ () C:\WINDOWS\KB2934207.log
2014-03-26 22:32 - 2014-03-26 22:33 - 00130999 _____ () C:\WINDOWS\KB2925418-IE8.log
2014-03-26 22:32 - 2014-03-26 22:32 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2930275$
2014-03-26 22:32 - 2014-03-26 22:32 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2929961$
2014-03-26 22:21 - 2014-02-25 21:59 - 00013312 ____N (Microsoft Corporation) C:\WINDOWS\system32\xp_eos.exe
2014-03-26 22:21 - 2014-02-25 21:59 - 00013312 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\xp_eos.exe
2014-03-21 13:00 - 2014-03-26 22:32 - 00130813 _____ () C:\WINDOWS\KB2930275.log
2014-03-21 13:00 - 2014-03-26 22:32 - 00127460 _____ () C:\WINDOWS\KB2929961.log
2014-03-10 14:44 - 2014-03-10 14:44 - 00003312 ____N () C:\bootex.log
2014-03-10 12:28 - 2014-03-10 12:28 - 00000000 ____D () C:\Program Files\DiscountLLocator
2014-03-10 12:21 - 2014-03-10 12:21 - 00000000 ____D () C:\Program Files\dOwnlloadittkeep
2014-03-10 12:20 - 2014-03-10 12:20 - 00000000 ____D () C:\Program Files\saver box
2014-03-10 12:13 - 2014-03-10 12:13 - 00000000 ____D () C:\Documents and Settings\Seth\Application Data\Malwarebytes
2014-03-10 12:12 - 2014-04-02 15:20 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Malwarebytes

==================== One Month Modified Files and Folders =======

2099-03-25 22:36 - 2011-12-19 17:08 - 00000178 ___SH () C:\Documents and Settings\Seth\ntuser.ini
2014-04-03 22:16 - 2014-04-03 22:15 - 00000000 ____D () C:\FRST
2014-04-03 22:07 - 2011-12-19 17:01 - 01519249 _____ () C:\WINDOWS\WindowsUpdate.log
2014-04-03 13:34 - 2014-04-03 09:29 - 00000882 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-03 12:39 - 2011-12-19 18:07 - 00000974 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-842925246-1993962763-682003330-1003UA.job
2014-04-03 12:20 - 2014-04-02 15:21 - 00107736 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-04-03 11:46 - 2014-04-03 11:43 - 00022107 _____ () C:\Documents and Settings\Seth\Desktop\attach.txt
2014-04-03 11:46 - 2014-04-03 11:43 - 00011265 _____ () C:\Documents and Settings\Seth\Desktop\dds.txt
2014-04-03 11:41 - 2014-04-03 11:41 - 00002855 _____ () C:\Documents and Settings\Seth\Desktop\Shortcut to dds.com.pif
2014-04-03 11:41 - 2014-04-03 11:41 - 00000000 ___HD () C:\WINDOWS\PIF
2014-04-03 10:46 - 2014-03-31 20:14 - 00000000 ____D () C:\AdwCleaner
2014-04-03 10:39 - 2011-12-19 18:07 - 00000922 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-842925246-1993962763-682003330-1003Core.job
2014-04-03 09:34 - 2014-04-03 09:29 - 00000878 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-03 09:32 - 2014-04-03 09:32 - 00001813 _____ () C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
2014-04-03 09:32 - 2014-04-03 09:32 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Google Chrome
2014-04-03 09:31 - 2014-04-03 09:28 - 00000000 ____D () C:\Program Files\Google
2014-04-03 09:18 - 2012-04-16 00:25 - 00000000 ____D () C:\Documents and Settings\Seth\Application Data\Dropbox
2014-04-03 05:42 - 2014-03-30 17:42 - 00000360 ____H () C:\WINDOWS\Tasks\avast! Emergency Update.job
2014-04-03 05:39 - 2011-12-19 17:07 - 00032654 _____ () C:\WINDOWS\SchedLgU.Txt
2014-04-02 22:45 - 2012-04-16 00:28 - 00000000 ___RD () C:\Documents and Settings\Seth\My Documents\Dropbox
2014-04-02 22:44 - 2014-03-30 17:18 - 00000220 _____ () C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job
2014-04-02 22:44 - 2012-10-26 21:55 - 00000514 ____H () C:\WINDOWS\Tasks\CodecUpdaterTask{8E04667E-3875-4B25-B503-FC3F8CE4AD4C}.job
2014-04-02 22:43 - 2004-08-04 06:00 - 00002206 _____ () C:\WINDOWS\system32\wpa.dbl
2014-04-02 22:00 - 2011-12-19 11:51 - 00572916 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-04-02 21:56 - 2011-12-20 19:19 - 00000159 _____ () C:\WINDOWS\wiadebug.log
2014-04-02 21:56 - 2011-12-20 19:19 - 00000048 _____ () C:\WINDOWS\wiaservc.log
2014-04-02 21:55 - 2011-12-19 17:07 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-04-02 21:29 - 2014-04-02 21:24 - 00000178 ___SH () C:\Documents and Settings\Administrator\ntuser.ini
2014-04-02 21:24 - 2014-04-02 21:24 - 00000000 __SHD () C:\Documents and Settings\Administrator\IETldCache
2014-04-02 21:24 - 2014-04-02 21:24 - 00000000 ____D () C:\Documents and Settings\Administrator
2014-04-02 20:02 - 2014-04-02 20:00 - 00002816 _____ () C:\Documents and Settings\Seth\Desktop\Rkill.txt
2014-04-02 19:12 - 2014-04-02 19:12 - 00001057 _____ () C:\Malware report.txt
2014-04-02 15:20 - 2014-04-02 15:20 - 00000777 _____ () C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-02 15:20 - 2014-04-02 15:20 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-04-02 15:20 - 2014-04-02 15:20 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware
2014-04-02 15:20 - 2014-03-10 12:12 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Malwarebytes
2014-04-01 22:31 - 2014-04-01 22:31 - 00000000 ____D () C:\Program Files\ESET
2014-04-01 22:15 - 2014-04-01 22:15 - 00000000 ____D () C:\Documents and Settings\Seth\Application Data\IDM2
2014-04-01 21:48 - 2014-04-01 21:48 - 00001740 _____ () C:\Documents and Settings\Seth\Desktop\JRT.txt
2014-04-01 21:39 - 2014-04-01 21:39 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-04-01 21:29 - 2014-04-01 21:29 - 00090112 _____ () C:\WINDOWS\Minidump\Mini040114-01.dmp
2014-04-01 21:29 - 2012-02-13 14:34 - 00000000 ____D () C:\WINDOWS\Minidump
2014-03-31 22:45 - 2013-04-16 11:26 - 00353043 _____ () C:\WINDOWS\iis6.log
2014-03-31 22:45 - 2013-04-16 11:26 - 00328331 _____ () C:\WINDOWS\FaxSetup.log
2014-03-31 22:45 - 2013-04-16 11:26 - 00159440 _____ () C:\WINDOWS\ocgen.log
2014-03-31 22:45 - 2013-04-16 11:26 - 00151307 _____ () C:\WINDOWS\tsoc.log
2014-03-31 22:45 - 2013-04-16 11:26 - 00109054 _____ () C:\WINDOWS\comsetup.log
2014-03-31 22:45 - 2013-04-16 11:26 - 00099554 _____ () C:\WINDOWS\msmqinst.log
2014-03-31 22:45 - 2013-04-16 11:26 - 00066457 _____ () C:\WINDOWS\ntdtcsetup.log
2014-03-31 22:45 - 2013-04-16 11:26 - 00057908 _____ () C:\WINDOWS\netfxocm.log
2014-03-31 22:45 - 2013-04-16 11:26 - 00022819 _____ () C:\WINDOWS\MedCtrOC.log
2014-03-31 22:45 - 2013-04-16 11:26 - 00018253 _____ () C:\WINDOWS\ocmsn.log
2014-03-31 22:45 - 2013-04-16 11:26 - 00016498 _____ () C:\WINDOWS\msgsocm.log
2014-03-31 22:45 - 2013-04-16 11:26 - 00016483 _____ () C:\WINDOWS\tabletoc.log
2014-03-31 22:45 - 2013-04-16 11:26 - 00001917 _____ () C:\WINDOWS\imsins.log
2014-03-31 15:17 - 2013-12-19 00:41 - 00000000 ____D () C:\Documents and Settings\Seth\Application Data\vlc
2014-03-31 15:10 - 2012-02-24 15:07 - 00018944 _____ () C:\Documents and Settings\Seth\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-03-31 14:53 - 2013-04-30 11:46 - 00185049 _____ () C:\WINDOWS\setupapi.log
2014-03-31 14:27 - 2012-02-13 11:55 - 00002315 _____ () C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader X.lnk
2014-03-31 14:12 - 2014-03-30 17:18 - 00000214 _____ () C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job
2014-03-30 17:42 - 2014-03-30 17:42 - 00001733 _____ () C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
2014-03-30 17:42 - 2014-03-30 17:42 - 00000000 ____D () C:\Documents and Settings\Seth\Application Data\AVAST Software
2014-03-30 17:42 - 2014-03-30 17:42 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Avast
2014-03-30 17:41 - 2014-03-30 17:41 - 00776976 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2014-03-30 17:41 - 2014-03-30 17:41 - 00411552 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2014-03-30 17:41 - 2014-03-30 17:41 - 00271264 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2014-03-30 17:41 - 2014-03-30 17:41 - 00180760 _____ () C:\WINDOWS\system32\Drivers\aswVmm.sys
2014-03-30 17:41 - 2014-03-30 17:41 - 00067824 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2014-03-30 17:41 - 2014-03-30 17:41 - 00057672 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswTdi.sys
2014-03-30 17:41 - 2014-03-30 17:41 - 00054832 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr.sys
2014-03-30 17:41 - 2014-03-30 17:41 - 00049944 _____ () C:\WINDOWS\system32\Drivers\aswRvrt.sys
2014-03-30 17:41 - 2014-03-30 17:41 - 00043152 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2014-03-30 17:41 - 2014-03-30 17:41 - 00000000 ____D () C:\Program Files\AVAST Software
2014-03-30 17:39 - 2014-03-30 17:38 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\AVAST Software
2014-03-30 17:38 - 2011-12-19 17:16 - 00069616 _____ () C:\Documents and Settings\Seth\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2014-03-28 12:25 - 2011-12-21 12:31 - 00000000 ____D () C:\WINDOWS\system32\NtmsData
2014-03-28 12:20 - 2011-12-19 16:59 - 00000000 ____D () C:\WINDOWS\Registration
2014-03-28 10:29 - 2014-03-28 10:29 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2934207$
2014-03-28 10:29 - 2014-03-28 10:23 - 00006826 _____ () C:\WINDOWS\KB2934207.log
2014-03-28 10:29 - 2013-04-16 11:26 - 00001374 _____ () C:\WINDOWS\imsins.BAK
2014-03-28 10:22 - 2012-01-23 01:34 - 00000000 ____D () C:\Documents and Settings\Seth\Application Data\Skype
2014-03-26 23:18 - 2012-08-12 07:56 - 00000664 _____ () C:\WINDOWS\system32\d3d9caps.dat
2014-03-26 23:16 - 2012-02-03 15:49 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-03-26 23:16 - 2011-12-19 11:50 - 00268600 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-03-26 22:33 - 2014-03-26 22:32 - 00130999 _____ () C:\WINDOWS\KB2925418-IE8.log
2014-03-26 22:33 - 2013-04-16 11:32 - 00033533 _____ () C:\WINDOWS\updspapi.log
2014-03-26 22:33 - 2012-06-30 08:47 - 00000000 ____D () C:\WINDOWS\ie8updates
2014-03-26 22:32 - 2014-03-26 22:32 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2930275$
2014-03-26 22:32 - 2014-03-26 22:32 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2929961$
2014-03-26 22:32 - 2014-03-21 13:00 - 00130813 _____ () C:\WINDOWS\KB2930275.log
2014-03-26 22:32 - 2014-03-21 13:00 - 00127460 _____ () C:\WINDOWS\KB2929961.log
2014-03-26 22:31 - 2011-12-20 10:46 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Microsoft Help
2014-03-26 22:30 - 2012-02-04 01:45 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Silverlight
2014-03-26 22:29 - 2013-08-06 16:07 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-03-26 22:23 - 2011-12-20 01:47 - 87350280 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-03-10 14:44 - 2014-03-10 14:44 - 00003312 ____N () C:\bootex.log
2014-03-10 12:59 - 2011-12-19 17:41 - 00524288 _____ () C:\WINDOWS\system32\config\ACEEvent.evt
2014-03-10 12:49 - 2011-12-20 22:20 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2478960$
2014-03-10 12:46 - 2013-06-08 19:46 - 00000000 ____D () C:\Documents and Settings\Seth\Application Data\Mozilla
2014-03-10 12:45 - 2012-09-25 01:41 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\188F1432-103A-4ffb-80F1-36B633C5C9E1
2014-03-10 12:36 - 2012-09-26 16:20 - 00000000 ____D () C:\Program Files\Freemake
2014-03-10 12:36 - 2012-09-26 16:20 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Freemake
2014-03-10 12:34 - 2014-02-14 23:35 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\dOwnlloadittkeep
2014-03-10 12:34 - 2014-02-04 16:39 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\PDFCConverter
2014-03-10 12:34 - 2014-01-28 05:39 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\saver box
2014-03-10 12:34 - 2014-01-28 05:39 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\DiscountLLocator
2014-03-10 12:28 - 2014-03-10 12:28 - 00000000 ____D () C:\Program Files\DiscountLLocator
2014-03-10 12:26 - 2012-01-11 03:35 - 00000000 ____D () C:\Program Files\Battle for Wesnoth 1.8.6
2014-03-10 12:21 - 2014-03-10 12:21 - 00000000 ____D () C:\Program Files\dOwnlloadittkeep
2014-03-10 12:21 - 2014-01-28 05:39 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\24f8985aa2446237
2014-03-10 12:20 - 2014-03-10 12:20 - 00000000 ____D () C:\Program Files\saver box
2014-03-10 12:18 - 2011-12-19 17:20 - 00000000 ____D () C:\Program Files\Dell
2014-03-10 12:13 - 2014-03-10 12:13 - 00000000 ____D () C:\Documents and Settings\Seth\Application Data\Malwarebytes
2014-03-05 09:26 - 2014-04-02 15:20 - 00050648 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2014-03-05 09:26 - 2014-04-02 15:20 - 00023256 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys

Some content of TEMP:
====================
C:\Documents and Settings\Administrator\Local Settings\Temp\Quarantine.exe
C:\Documents and Settings\Seth\Local Settings\Temp\avgnt.exe
C:\Documents and Settings\Seth\Local Settings\Temp\MotoCast_Installer_2.0031.exe
C:\Documents and Settings\Seth\Local Settings\Temp\vlc-2.1.2-win32.exe


==================== Bamital & volsnap Check =================

C:\WINDOWS\explorer.exe => MD5 is legit
C:\WINDOWS\system32\winlogon.exe => MD5 is legit
C:\WINDOWS\system32\svchost.exe => MD5 is legit
C:\WINDOWS\system32\services.exe => MD5 is legit
C:\WINDOWS\system32\User32.dll => MD5 is legit
C:\WINDOWS\system32\userinit.exe => MD5 is legit
C:\WINDOWS\system32\rpcss.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\volsnap.sys => MD5 is legit

==================== End Of Log ============================

Additional scan result of Farbar Recovery Scan Tool (x86) Version: 13-03-2014 01
Ran by Seth at 2014-04-03 22:17:18
Running from C:\Documents and Settings\Seth\My Documents\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: avast! Antivirus (Disabled - Up to date) {7591DB91-41F0-48A3-B128-1A293FD8233D}

==================== Installed Programs ======================

2007 Microsoft Office system (HKLM\...\PROHYBRIDR) (Version: 12.0.6612.1000 - Microsoft Corporation)
32 Bit HP CIO Components Installer (Version: 6.1.2 - Hewlett-Packard) Hidden
6500_E709_BasicWeb (Version: 140.0.000.000 - Hewlett-Packard) Hidden
6500_E709_Help_BasicWeb (Version: 1.00.0000 - Hewlett-Packard) Hidden
Adobe AIR (HKLM\...\Adobe AIR) (Version: 3.1.0.4880 - Adobe Systems Incorporated)
Adobe AIR (Version: 3.1.0.4880 - Adobe Systems Incorporated) Hidden
Adobe Flash Player 12 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 12.0.0.70 - Adobe Systems Incorporated)
Adobe Reader X (10.1.3) (HKLM\...\{AC76BA86-7AD7-1033-7B44-AA1000000001}) (Version: 10.1.3 - Adobe Systems Incorporated)
AMD Processor Driver (HKLM\...\{C151CE54-E7EA-4804-854B-F515368B0798}) (Version: 1.3.2. - )
Apple Application Support (HKLM\...\{63EC2120-1742-4625-AA47-C6A8AEC9C64C}) (Version: 2.2.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{D4DDFAA1-EC37-4529-AD5B-A433ADE68662}) (Version: 6.0.0.59 - Apple Inc.)
Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ATI - Software Uninstall Utility (HKLM\...\All ATI Software) (Version: 6.14.10.1014 - )
ATI Catalyst Control Center (HKLM\...\{AC6AE077-1566-4655-BE73-38A869C150DC}) (Version: 1.2.2460.36742 - )
ATI Display Driver (HKLM\...\ATI Display Driver) (Version: 8.282.2.1-060922a-036833C-Dell - )
avast! Free Antivirus (HKLM\...\Avast) (Version: 9.0.2016 - Avast Software)
Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
bpd_scan (Version: 3.00.0000 - Hewlett-Packard) Hidden
BPDSoftware_Ini (Version: 1.00.0000 - Hewlett-Packard) Hidden
Broadcom 440x 10/100 Integrated Controller (HKLM\...\{9C9D0F85-5658-4A5E-95A9-65F7DB2916EE}) (Version: 8.06.11 - Broadcom Corporation)
Brother MFL-Pro Suite MFC-6490CW (HKLM\...\{01B4AC8E-6D83-44B3-958D-2AFE57BE54DB}) (Version: 1.2.13.0 - Brother Industries, Ltd.)
Brother MFL-Pro Suite MFC-J430W (HKLM\...\{A1B36B88-AF90-43A3-8906-6DBEE89B4FBD}) (Version: 1.0.10.0 - Brother Industries, Ltd.)
BufferChm (Version: 140.0.213.000 - Hewlett-Packard) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 4.00 - Piriform)
Dell Wireless WLAN Card (HKLM\...\Broadcom 802.11b Network Adapter) (Version: 4.10.47.3 - Dell Inc.)
DisplayLink Core Software (HKLM\...\{600903EB-7940-4B06-88F2-39E9AC3E8BE1}) (Version: 5.3.24474.0 - DisplayLink Corp.)
DisplayLink Graphics (HKLM\...\{B02658B2-C991-4BE4-B11C-FB49D97FC18B}) (Version: 5.3.24566.0 - DisplayLink Corp.)
Dropbox (HKCU\...\Dropbox) (Version: 2.4.11 - Dropbox, Inc.)
ESET Online Scanner v3 (HKLM\...\ESET Online Scanner) (Version: - )
Evernote v. 5.1.2 (HKLM\...\{12FB6296-8840-11E3-86D7-00163E98E7D0}) (Version: 5.1.2.2387 - Evernote Corp.)
GIMP (HKLM\...\{46BBA993-5554-42E7-8042-E760D92A580A}) (Version: 2.6.11 - Spencer Kimball)
Google Chrome (HKCU\...\Google Chrome) (Version: 32.0.1700.76 - Google Inc.)
Google Chrome (HKLM\...\Google Chrome) (Version: 34.0.1847.116 - Google Inc.)
Google Talk Plugin (HKLM\...\{2A83AD05-56E6-3FBD-8752-B4143162EF59}) (Version: 4.9.1.16010 - Google)
Google Update Helper (Version: 1.3.23.9 - Google Inc.) Hidden
High Definition Audio Driver Package - KB835221 (HKLM\...\KB835221WXP) (Version: 20040219.000000 - Microsoft Corporation)
HP Officejet 6500 E709 Series (HKLM\...\{4C8C6D37-CA3C-4EF6-A1E5-0D188E7B6021}) (Version: 14.0 - HP)
HP Photosmart Plus B210 series Basic Device Software (HKLM\...\{6E5A0256-C1BB-4A4E-99CE-B87CC4383744}) (Version: 22.50.231.0 - Hewlett-Packard Co.)
HP Photosmart Plus B210 series Help (HKLM\...\{7F5FDEA1-D0AC-4D80-9D95-59775FCCFA40}) (Version: 140.0.54.54 - Hewlett Packard)
Logitech Touch Mouse Server 1.0 (HKLM\...\Logitech Touch Mouse Server) (Version: 1.0 - Logitech Inc.)
LOGO!Soft Comfort V6.1 (HKLM\...\LOGO!Soft Comfort V6.1) (Version: 6.1.0.0 - Siemens AG)
LOGO!Soft Comfort V7.0 (HKLM\...\LOGO!Soft Comfort V7.0 ) (Version: 7.0.0.0 - Siemens AG)
Malwarebytes Anti-Malware version 2.00.0.1000 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.00.0.1000 - Malwarebytes Corporation)
Microsoft .NET Framework 1.1 (HKLM\...\Microsoft .NET Framework 1.1 (1033)) (Version: - )
Microsoft .NET Framework 1.1 (Version: 1.1.4322 - Microsoft) Hidden
Microsoft .NET Framework 1.1 Security Update (KB2698023) (HKLM\...\M2698023) (Version: - )
Microsoft .NET Framework 1.1 Security Update (KB2833941) (HKLM\...\M2833941) (Version: - )
Microsoft .NET Framework 2.0 Service Pack 2 (HKLM\...\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}) (Version: 2.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.0 Service Pack 2 (HKLM\...\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}) (Version: 3.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft Compression Client Pack 1.0 for Windows XP (HKLM\...\MSCompPackV1) (Version: 1 - Microsoft Corporation)
Microsoft Kernel-Mode Driver Framework Feature Pack 1.9 (Version: - Microsoft Corporation) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office 2007 Service Pack 3 (SP3) (Version: - Microsoft) Hidden
Microsoft Office Access MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Access Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office File Validation Add-In (HKLM\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Outlook MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Professional Hybrid 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Spanish) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (English) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (Version: - Microsoft) Hidden
Microsoft Office Publisher MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation)
Microsoft Software Update for Web Folders (English) 12 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft User-Mode Driver Framework Feature Pack 1.0 (HKLM\...\Wudf01000) (Version: - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2721691) (HKLM\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
Network (Version: 140.0.215.000 - Hewlett-Packard) Hidden
QuickTime (HKLM\...\{0E64B098-8018-4256-BA23-C316A43AD9B0}) (Version: 7.72.80.56 - Apple Inc.)
Scan (Version: 140.0.167.000 - Hewlett-Packard) Hidden
SigmaTel Audio (HKLM\...\{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}) (Version: 5.10.4820.0 - SigmaTel)
Silicon Laboratories CP210x USB to UART Bridge (Driver Removal) (HKLM\...\SLABCOMM&10C4&EA60) (Version: - Silicon Laboratories)
Silicon Laboratories CP210x VCP Drivers for Windows XP/2003 Server/Vista/7 (HKLM\...\{E7594BB4-6A8B-466A-A08B-DD6BD0717AE1}) (Version: 6.2.00 - Silicon Laboratories, Inc.)
Skype™ 6.11 (HKLM\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 8.2.4.6 - Synaptics)
Toolbox (Version: 140.0.428.000 - Hewlett-Packard) Hidden
Tweak UI (HKLM\...\Tweak UI 2.10) (Version: - )
Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (HKLM\...\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707) (Version: 1 - Microsoft Corporation)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM\...\{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version: - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM\...\{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM\...\{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version: - Microsoft)
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (HKLM\...\{90120000-001A-0409-0000-0000000FF1CE}_PROHYBRIDR_{ED38F8A3-4F61-494E-8BCA-E3AC7760C924}) (Version: - Microsoft)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2878234) 32-Bit Edition (HKLM\...\{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{EC1934B0-AE0F-4BBD-8955-54BB3247ED9E}) (Version: - Microsoft)
Update for Windows Internet Explorer 8 (KB2598845) (HKLM\...\KB2598845-IE8) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB2345886) (HKLM\...\KB2345886) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB2467659) (HKLM\...\KB2467659) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB2541763) (HKLM\...\KB2541763) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB2641690) (HKLM\...\KB2641690) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB2661254-v2) (HKLM\...\KB2661254-v2) (Version: 2 - Microsoft Corporation)
Update for Windows XP (KB2718704) (HKLM\...\KB2718704) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB2736233) (HKLM\...\KB2736233) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB2749655) (HKLM\...\KB2749655) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB2863058) (HKLM\...\KB2863058) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB2904266) (HKLM\...\KB2904266) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB2934207) (HKLM\...\KB2934207) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB951978) (Version: 1 - Microsoft Corporation) Hidden
Update for Windows XP (KB955704) (HKLM\...\KB955704) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB955759) (HKLM\...\KB955759) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB967715) (HKLM\...\KB967715) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB968389) (HKLM\...\KB968389) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB971029) (HKLM\...\KB971029) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB971737) (HKLM\...\KB971737) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB973687) (HKLM\...\KB973687) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB973815) (HKLM\...\KB973815) (Version: 1 - Microsoft Corporation)
VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0 - DivX, Inc) Hidden
VLC media player 2.1.2 (HKLM\...\VLC media player) (Version: 2.1.2 - VideoLAN)
WebFldrs XP (Version: 9.50.7523 - Microsoft Corporation) Hidden
WebReg (Version: 140.0.213.017 - Hewlett-Packard) Hidden
Windows Driver Package - Ricoh Company Memorystick Host Controller (07/09/2005 1.00.01.12) (HKLM\...\3635FC5A3FE7DACCEF2123BDBDA808BA811B977B) (Version: 07/09/2005 1.00.01.12 - Ricoh Company)
Windows Driver Package - Ricoh Company MMC Host Controller (07/14/2005 1.00.00.06) (HKLM\...\F631A62FA5E06534A0FE3637D75AAA5B1D3E4FB7) (Version: 07/14/2005 1.00.00.06 - Ricoh Company)
Windows Driver Package - Ricoh Company xD-Picture Card/SmartMedia Host Controller (07/14/2005 1.00.02.04) (HKLM\...\452416B030C25BAA383F3DA368FECD5D48FAE727) (Version: 07/14/2005 1.00.02.04 - Ricoh Company)
Windows Genuine Advantage Notifications (KB905474) (HKLM\...\WgaNotify) (Version: 1.9.0040.0 - Microsoft Corporation)
Windows Internet Explorer 8 (HKLM\...\ie8) (Version: 20090308.140743 - Microsoft Corporation)
Windows Media Format 11 runtime (HKLM\...\Windows Media Format Runtime) (Version: - )
Windows Media Format 11 runtime (Version: - Microsoft Corporation) Hidden
Windows Media Player 11 (HKLM\...\Windows Media Player) (Version: - )
Windows Media Player 11 (Version: - Microsoft Corporation) Hidden
Windows XP Service Pack 3 (HKLM\...\Windows XP Service Pack) (Version: 20080414.031525 - Microsoft Corporation)
XPS Essentials Pack (HKLM\...\{6A69D94E-C569-4154-9643-72E94D1DDFDA}) (Version: 1.0.6000 - Microsoft Corporation)
XPS Essentials Pack 1.0 (Version: - Microsoft Corporation) Hidden

==================== Restore Points =========================

07-01-2014 22:13:50 Removed Evernote v. 4.6.6
07-01-2014 22:14:26 Installed Evernote v. 5.0.3
07-01-2014 22:42:30 Removed Evernote v. 5.0.3
07-01-2014 22:42:53 Installed Evernote v. 5.1
09-01-2014 16:21:14 System Checkpoint
13-01-2014 22:46:54 System Checkpoint
18-01-2014 03:17:38 Software Distribution Service 3.0
20-01-2014 01:47:16 System Checkpoint
28-01-2014 05:13:33 System Checkpoint
29-01-2014 22:41:19 Removed Evernote v. 5.1
29-01-2014 22:41:48 Installed Evernote v. 5.1.2
05-02-2014 16:45:01 System Checkpoint
15-02-2014 03:42:37 Software Distribution Service 3.0
16-02-2014 04:14:52 System Checkpoint
20-02-2014 01:56:55 System Checkpoint
27-02-2014 06:16:51 System Checkpoint
28-02-2014 07:16:05 System Checkpoint
04-03-2014 03:22:29 System Checkpoint
04-03-2014 03:26:39 Software Distribution Service 3.0
05-03-2014 04:03:04 System Checkpoint
10-03-2014 16:17:35 Removed QuickSet
10-03-2014 16:20:12 Removed ooVoo
10-03-2014 16:43:08 Removed iTunes
27-03-2014 02:23:35 Software Distribution Service 3.0
28-03-2014 14:22:47 Software Distribution Service 3.0
28-03-2014 14:27:34 Software Distribution Service 3.0
30-03-2014 21:41:13 avast! antivirus system restore point

==================== Hosts content: ==========================

2004-08-04 06:00 - 2004-08-04 06:00 - 00000734 ____A C:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1 localhost

==================== Scheduled Tasks (whitelisted) =============

Task: C:\WINDOWS\Tasks\avast! Emergency Update.job => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
Task: C:\WINDOWS\Tasks\CodecUpdaterTask{8E04667E-3875-4B25-B503-FC3F8CE4AD4C}.job => C:\Documents and Settings\All Users\Application Data\Premium\Codec\Codec.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-842925246-1993962763-682003330-1003Core.job => C:\Documents and Settings\Seth\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-842925246-1993962763-682003330-1003UA.job => C:\Documents and Settings\Seth\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job => C:\WINDOWS\system32\xp_eos.exe
Task: C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job => C:\WINDOWS\system32\xp_eos.exe

==================== Loaded Modules (whitelisted) =============

2011-12-19 17:28 - 2005-12-19 10:08 - 00018944 _____ () C:\WINDOWS\System32\WLTRYSVC.EXE
2011-12-19 17:28 - 2005-12-19 10:08 - 00757760 _____ () C:\WINDOWS\System32\bcm1xsup.dll
2014-04-03 22:08 - 2014-04-03 22:08 - 02189312 _____ () C:\Program Files\AVAST Software\Avast\defs\14040301\algo.dll
2011-11-02 00:26 - 2011-11-02 00:26 - 00087912 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2011-11-02 00:26 - 2011-11-02 00:26 - 01242472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2012-07-13 12:52 - 2009-02-27 16:38 - 00139264 ____R () C:\Program Files\Brother\BrUtilities\BrLogAPI.dll
2014-03-30 17:41 - 2014-03-30 17:41 - 19336120 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2004-08-04 06:00 - 2008-04-14 06:41 - 00059904 _____ () C:\WINDOWS\system32\devenum.dll
2004-08-04 06:00 - 2008-04-14 06:42 - 00014336 _____ () C:\WINDOWS\system32\msdmo.dll
2013-10-18 19:55 - 2013-10-18 19:55 - 25100288 _____ () C:\Documents and Settings\Seth\Application Data\Dropbox\bin\libcef.dll
2014-01-22 14:29 - 2014-01-22 14:29 - 00433664 _____ () C:\Program Files\Evernote\Evernote\libxml2.dll
2014-01-22 14:29 - 2014-01-22 14:29 - 00315392 _____ () C:\Program Files\Evernote\Evernote\libtidy.dll
2014-04-03 09:31 - 2014-04-01 21:57 - 00065352 _____ () C:\Program Files\Google\Chrome\Application\34.0.1847.116\chrome_elf.dll
2014-04-03 09:31 - 2014-04-01 21:57 - 04081480 _____ () C:\Program Files\Google\Chrome\Application\34.0.1847.116\pdf.dll
2014-04-03 09:32 - 2014-04-01 21:58 - 00390472 _____ () C:\Program Files\Google\Chrome\Application\34.0.1847.116\ppGoogleNaClPluginChrome.dll
2014-04-03 09:31 - 2014-04-01 21:57 - 01647432 _____ () C:\Program Files\Google\Chrome\Application\34.0.1847.116\ffmpegsumo.dll

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\Documents and Settings\All Users\Application Data\TEMP:373E1720

==================== Safe Mode (whitelisted) ===================

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"

==================== Disabled items from MSCONFIG ==============

MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: APSDaemon => "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: ATICCC => "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
MSCONFIG\startupreg: Bing Bar => "C:\Program Files\MSN Toolbar\Platform\5.0.1449.0\mswinext.exe"
MSCONFIG\startupreg: Broadcom Wireless Manager UI => C:\WINDOWS\system32\WLTRAY.exe
MSCONFIG\startupreg: BrStsMon00 => C:\Program Files\Browny02\Brother\BrStMonW.exe /AUTORUN
MSCONFIG\startupreg: ControlCenter3 => C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
MSCONFIG\startupreg: ControlCenter4 => C:\Program Files\ControlCenter4\BrCcBoot.exe /autorun
MSCONFIG\startupreg: ctfmon.exe => C:\WINDOWS\system32\ctfmon.exe
MSCONFIG\startupreg: DivXUpdate => "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
MSCONFIG\startupreg: Google Update => "C:\Documents and Settings\Seth\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
MSCONFIG\startupreg: IndexSearch => "C:\Program Files\Nuance\PaperPort\IndexSearch.exe"
MSCONFIG\startupreg: ISUSPM => C:\Documents and Settings\All Users\Application Data\FLEXnet\Connect\11\ISUSPM.exe -scheduler
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: Microsoft Default Manager => "C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
MSCONFIG\startupreg: ooVoo.exe => C:\Program Files\ooVoo\oovoo.exe /minimized
MSCONFIG\startupreg: PaperPort PTD => "C:\Program Files\Nuance\PaperPort\pptd40nt.exe"
MSCONFIG\startupreg: PDF5 Registry Controller => C:\Program Files\Nuance\PDF Viewer Plus\RegistryController.exe
MSCONFIG\startupreg: PDFHook => C:\Program Files\Nuance\PDF Viewer Plus\pdfpro5hook.exe
MSCONFIG\startupreg: PPort12reminder => "C:\Program Files\Nuance\PaperPort\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\ScanSoft\PaperPort\12\Config\Ereg\Ereg.ini"
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: SigmatelSysTrayApp => stsystra.exe

==================== Faulty Device Manager Devices =============

Name: Modem Device on High Definition Audio Bus
Description: Modem Device on High Definition Audio Bus
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: Officejet 6300 series
Description: Officejet 6300 series
Class Guid: {4D36E971-E325-11CE-BFC1-08002BE10318}
Manufacturer: HP
Service:
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

Name: Photosmart D110 series
Description: Photosmart D110 series
Class Guid: {4D36E971-E325-11CE-BFC1-08002BE10318}
Manufacturer: HP
Service:
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

Name: Photosmart Plus B210 series
Description: Photosmart Plus B210 series
Class Guid: {4D36E971-E325-11CE-BFC1-08002BE10318}
Manufacturer: HP
Service:
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

Name: Photosmart D110 series
Description: Photosmart D110 series
Class Guid: {4D36E971-E325-11CE-BFC1-08002BE10318}
Manufacturer: HP
Service:
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

Name: Officejet 7110 series
Description: Officejet 7110 series
Class Guid: {4D36E971-E325-11CE-BFC1-08002BE10318}
Manufacturer: HP
Service:
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: =========================

Application errors:
==================
Error: (02/18/2013 00:59:53 PM) (Source: Brother BrLog) (User: )
Description: STI BrtSTI: [2013/02/18 11:59:53.921]: [00000360]: GetDeviceIpAddress: GetAddressByName [BRWF07BCB2DBE4E] Error

Error: (02/18/2013 00:59:19 PM) (Source: Brother BrLog) (User: )
Description: STI BrtSTI: [2013/02/18 11:59:19.406]: [00000360]: GetDeviceIpAddress: GetAddressByName [BRWF07BCB2DBE4E] Error

Error: (02/18/2013 00:58:44 PM) (Source: Brother BrLog) (User: )
Description: STI BrtSTI: [2013/02/18 11:58:44.890]: [00000360]: GetDeviceIpAddress: GetAddressByName [BRWF07BCB2DBE4E] Error

Error: (02/18/2013 00:58:10 PM) (Source: Brother BrLog) (User: )
Description: STI BrtSTI: [2013/02/18 11:58:10.375]: [00000360]: GetDeviceIpAddress: GetAddressByName [BRWF07BCB2DBE4E] Error

Error: (02/18/2013 00:57:35 PM) (Source: Brother BrLog) (User: )
Description: STI BrtSTI: [2013/02/18 11:57:35.500]: [00000360]: GetDeviceIpAddress: GetAddressByName [BRWF07BCB2DBE4E] Error

Error: (02/18/2013 00:57:00 PM) (Source: Brother BrLog) (User: )
Description: STI BrtSTI: [2013/02/18 11:57:00.984]: [00000360]: GetDeviceIpAddress: GetAddressByName [BRWF07BCB2DBE4E] Error

Error: (02/18/2013 00:56:26 PM) (Source: Brother BrLog) (User: )
Description: STI BrtSTI: [2013/02/18 11:56:26.484]: [00000360]: GetDeviceIpAddress: GetAddressByName [BRWF07BCB2DBE4E] Error

Error: (02/18/2013 00:55:51 PM) (Source: Brother BrLog) (User: )
Description: STI BrtSTI: [2013/02/18 11:55:51.968]: [00000360]: GetDeviceIpAddress: GetAddressByName [BRWF07BCB2DBE4E] Error

Error: (02/18/2013 00:55:17 PM) (Source: Brother BrLog) (User: )
Description: STI BrtSTI: [2013/02/18 11:55:17.453]: [00000360]: GetDeviceIpAddress: GetAddressByName [BRWF07BCB2DBE4E] Error

Error: (02/18/2013 00:54:42 PM) (Source: Brother BrLog) (User: )
Description: STI BrtSTI: [2013/02/18 11:54:42.953]: [00000360]: GetDeviceIpAddress: GetAddressByName [BRWF07BCB2DBE4E] Error


System errors:
=============
Error: (06/10/2013 07:30:11 PM) (Source: 0) (User: )
Description: \Device\Harddisk1\D

Error: (06/05/2013 01:54:59 PM) (Source: Service Control Manager) (User: )
Description: The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.

Error: (06/05/2013 01:54:57 PM) (Source: Service Control Manager) (User: )
Description: The Bonjour Service service terminated unexpectedly. It has done this 1 time(s).

Error: (06/05/2013 01:54:49 PM) (Source: Service Control Manager) (User: )
Description: The Application Layer Gateway Service service terminated unexpectedly. It has done this 1 time(s).

Error: (06/05/2013 01:21:17 AM) (Source: 0) (User: )
Description: \Device\ACPIEC

Error: (05/30/2013 06:14:00 PM) (Source: 0) (User: )
Description: 3

Error: (05/28/2013 07:35:21 PM) (Source: Service Control Manager) (User: )
Description: The DisplayLinkManager service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 1628 milliseconds: Restart the service.

Error: (05/28/2013 07:35:11 PM) (Source: Service Control Manager) (User: )
Description: The Application Layer Gateway Service service terminated unexpectedly. It has done this 1 time(s).

Error: (05/28/2013 07:34:52 PM) (Source: Service Control Manager) (User: )
Description: The DisplayLinkManager service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 1000 milliseconds: Restart the service.

Error: (05/28/2013 07:34:40 PM) (Source: Service Control Manager) (User: )
Description: The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.


Microsoft Office Sessions:
=========================
Error: (06/17/2012 02:37:10 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6661.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 216 seconds with 120 seconds of active time. This session ended with a crash.


==================== Memory info ===========================

Percentage of memory in use: 56%
Total physical RAM: 1917.97 MB
Available physical RAM: 825.41 MB
Total Pagefile: 5861 MB
Available Pagefile: 4754.53 MB
Total Virtual: 2047.88 MB
Available Virtual: 1959.02 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:149.04 GB) (Free:53.47 GB) NTFS ==>[Drive with boot components (Windows XP)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows XP) (Size: 149 GB) (Disk ID: D0F4738C)

Partition: GPT Partition Type.

==================== End Of Log ============================

#4 fireman4it

fireman4it

    Bleepin' Fireman


  • Malware Response Team
  • 13,512 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Greenup, Ill USA
  • Local time:06:39 AM

Posted 05 April 2014 - 08:25 PM

1.
Download attached fixlist.txt file and save it to the Desktop.

NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

Run FRST/FRST64 and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

Attached File  fixlist.txt   933bytes   1 downloads


2.
  • Download RogueKiller on the desktop
  • Close all the running processes
  • Under Vista/Seven, right click -> Run as Administrator
  • Otherwise just double-click on RogueKiller.exe
  • When prompted, Click Scan
  • A report should open, give its content to your helper. (RKreport could also be found next to the executable)
  • If RogueKiller has been blocked, do not hesitate to try a few times more. If really won't run, rename in winlogon.exe (or winlogon.com) and try again
Things to include in your next reply::
Fixlog.txt
Roguekiller log
How is the machine running now?

" Extinguishing Malware from the world"

The Virus, Trojan, Spyware, and Malware Removal forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.

ALL OTHER HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
Thanks-


  userbar_eis_500.gif

If I have helped you, consider making a donation to help me continue the fight against Malware! Just click btn_donate_LG.gif


#5 Vecc1982

Vecc1982
  • Topic Starter

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:07:39 AM

Posted 05 April 2014 - 10:44 PM

Fixlog results:
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 13-03-2014 01
Ran by Seth at 2014-04-05 23:37:12 Run:1
Running from C:\Documents and Settings\Seth\My Documents\Downloads
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - {83C7A244-F282-477C-A771-308DB0CC3BAE} URL = http://search.findwide.com/serp?guid={73673A59-C3EE-4737-8ED6-6C6CEA911CCF}&action=default_search&serpv=22&k={searchTerms}
Toolbar: HKCU - No Name - {F11C6FE2-596D-4872-8630-89B860582F0D} - No File
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
C:\Documents and Settings\Administrator\Local Settings\Temp\Quarantine.exe
C:\Documents and Settings\Seth\Local Settings\Temp\avgnt.exe
C:\Documents and Settings\Seth\Local Settings\Temp\MotoCast_Installer_2.0031.exe
C:\Documents and Settings\Seth\Local Settings\Temp\vlc-2.1.2-win32.exe
Task: C:\WINDOWS\Tasks\CodecUpdaterTask{8E04667E-3875-4B25-B503-FC3F8CE4AD4C}.job => C:\Documents and Settings\All Users\Application Data\Premium\Codec\Codec.exe <==== ATTENTION



*****************

C:\WINDOWS\system32\GroupPolicy\Machine => Moved successfully.
C:\WINDOWS\system32\GroupPolicy\GPT.ini => Moved successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{83C7A244-F282-477C-A771-308DB0CC3BAE} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{83C7A244-F282-477C-A771-308DB0CC3BAE} => Key not found.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{F11C6FE2-596D-4872-8630-89B860582F0D} => Value deleted successfully.
HKCR\CLSID\{F11C6FE2-596D-4872-8630-89B860582F0D} => Key not found.
HKLM\SOFTWARE\Policies\Google => Key deleted successfully.
C:\Documents and Settings\Administrator\Local Settings\Temp\Quarantine.exe => Moved successfully.
C:\Documents and Settings\Seth\Local Settings\Temp\avgnt.exe => Moved successfully.
C:\Documents and Settings\Seth\Local Settings\Temp\MotoCast_Installer_2.0031.exe => Moved successfully.
C:\Documents and Settings\Seth\Local Settings\Temp\vlc-2.1.2-win32.exe => Moved successfully.
C:\WINDOWS\Tasks\CodecUpdaterTask{8E04667E-3875-4B25-B503-FC3F8CE4AD4C}.job => Moved successfully.


The system needed a reboot.

==== End of Fixlog ====

#6 Vecc1982

Vecc1982
  • Topic Starter

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:07:39 AM

Posted 05 April 2014 - 11:13 PM

RKreport:
RogueKiller V8.8.15 [Mar 27 2014] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User : Seth [Admin rights]
Mode : Scan -- Date : 04/06/2014 00:00:19
| ARK || FAK || MBR |

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 1 ¤¤¤
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Scheduled tasks : 0 ¤¤¤

¤¤¤ Startup Entries : 0 ¤¤¤

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ Browser Addons : 0 ¤¤¤

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [LOADED] ¤¤¤

¤¤¤ External Hives: ¤¤¤

¤¤¤ Infection : ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts


127.0.0.1 localhost


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) TOSHIBA MK1637GSX +++++
--- User ---
[MBR] 91e15880dc642e332fd21a2e8e373b09
[BSP] ae203e84dcb456630d870d8f3155a2b5 : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 152617 MB
User = LL1 ... OK!
User = LL2 ... OK!

Finished : << RKreport[0]_S_04062014_000019.txt >>




So far,so good...no advertisements popping up, no video! Awesome! Now, I did not fix anything on the results from rogue killer. Please let me know if I need to do anything else with it.

#7 fireman4it

fireman4it

    Bleepin' Fireman


  • Malware Response Team
  • 13,512 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Greenup, Ill USA
  • Local time:06:39 AM

Posted 06 April 2014 - 10:49 AM

Lets check for any leftovers.

 

1.

Please download AdwCleaner by Xplode and save to your Desktop.

  • Double click on AdwCleaner.exe to run the tool .
  • Click on the Scan button.
  • AdwCleaner will begin to scan your computer.
  • After the scan has finished...
  • Click on the Clean button.
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
  • After rebooting, a logfile report (AdwCleaner[S#].txt) will open automatically (where the largest value of # represents the most recent report).
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of that logfile will also be saved in the C:\AdwCleaner folder.

 

 

2.

 ESET Online Scanner

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

  • Please go >>HERE<< then click on: ESET1st.jpg

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on the ESETexe.jpg icon to install.

    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.
  • Select the option YES, I accept the Terms of Use then click on: ESETsave.jpg
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats IS checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
  • Scan for potentially unwanted applications
  • Scan for potentially unsafe applications
  • Enable Anti-Stealth Technology
  • Now click on: EOLS3.gif
  • The virus signature database... will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed make sure you first copy the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic.
  • Now click on: EOLS4.gif
    (Selecting Uninstall application on close if you so wish)


" Extinguishing Malware from the world"

The Virus, Trojan, Spyware, and Malware Removal forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.

ALL OTHER HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
Thanks-


  userbar_eis_500.gif

If I have helped you, consider making a donation to help me continue the fight against Malware! Just click btn_donate_LG.gif


#8 Vecc1982

Vecc1982
  • Topic Starter

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:07:39 AM

Posted 06 April 2014 - 03:31 PM

# AdwCleaner v3.023 - Report created 06/04/2014 at 16:21:40
# Updated 01/04/2014 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : Seth - ISG-SSGDELL1501
# Running from : C:\Documents and Settings\Seth\My Documents\Downloads\AdwCleaner (1).exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****


***** [ Browsers ] *****

-\\ Internet Explorer v8.0.6001.18702


-\\ Google Chrome v34.0.1847.116

[ File : C:\Documents and Settings\LocalService\Local Settings\Application Data\Google\Chrome\User Data\Default\preferences ]


[ File : C:\Documents and Settings\Seth\Local Settings\Application Data\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [1780 octets] - [31/03/2014 20:15:11]
AdwCleaner[R1].txt - [1840 octets] - [31/03/2014 21:40:12]
AdwCleaner[R2].txt - [1959 octets] - [31/03/2014 22:18:36]
AdwCleaner[R3].txt - [1789 octets] - [02/04/2014 14:06:38]
AdwCleaner[R4].txt - [1366 octets] - [02/04/2014 21:24:52]
AdwCleaner[R5].txt - [1758 octets] - [02/04/2014 21:50:27]
AdwCleaner[R6].txt - [1619 octets] - [03/04/2014 10:44:42]
AdwCleaner[R7].txt - [1683 octets] - [06/04/2014 16:19:45]
AdwCleaner[S0].txt - [374 octets] - [31/03/2014 21:44:42]
AdwCleaner[S1].txt - [374 octets] - [31/03/2014 22:21:21]
AdwCleaner[S2].txt - [370 octets] - [02/04/2014 14:10:05]
AdwCleaner[S3].txt - [1437 octets] - [02/04/2014 21:28:39]
AdwCleaner[S4].txt - [1743 octets] - [02/04/2014 21:53:57]
AdwCleaner[S5].txt - [1604 octets] - [06/04/2014 16:21:40]

########## EOF - C:\AdwCleaner\AdwCleaner[S5].txt - [1664 octets] ##########

#9 fireman4it

fireman4it

    Bleepin' Fireman


  • Malware Response Team
  • 13,512 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Greenup, Ill USA
  • Local time:06:39 AM

Posted 06 April 2014 - 06:16 PM

The Eset log?


" Extinguishing Malware from the world"

The Virus, Trojan, Spyware, and Malware Removal forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.

ALL OTHER HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
Thanks-


  userbar_eis_500.gif

If I have helped you, consider making a donation to help me continue the fight against Malware! Just click btn_donate_LG.gif


#10 Vecc1982

Vecc1982
  • Topic Starter

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:07:39 AM

Posted 06 April 2014 - 07:12 PM

I was waiting on scan to finish. Now trying to relocate the log. No threats were found...looking now.

#11 Vecc1982

Vecc1982
  • Topic Starter

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:07:39 AM

Posted 06 April 2014 - 07:21 PM

Not sure exactly where it went but found this where results are included as well as previous scans.
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=52cd78559699ac4397e54c74c4d588d8
# engine=17718
# end=finished
# remove_checked=true
# archives_checked=false
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-04-02 03:51:28
# local_time=2014-04-01 11:51:28 (-0500, Eastern Daylight Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=774 16777213 71 74 108570 108587 0 0
# scanned=119834
# found=1
# cleaned=1
# scan_time=4214
sh=A87B7647DC34B5B6186209377786E946B677C574 ft=1 fh=c2834f18f25710d9 vn="multiple threats (cleaned by deleting - quarantined)" ac=C fn="C:\Documents and Settings\Seth\Local Settings\Temp\{08C952AA-0039-4063-9B81-006E3DEE478D}\setup.exe"
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=52cd78559699ac4397e54c74c4d588d8
# engine=17727
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2014-04-02 05:31:18
# local_time=2014-04-02 01:31:18 (-0500, Eastern Daylight Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=774 16777213 71 74 157760 157777 0 0
# scanned=120248
# found=9
# cleaned=9
# scan_time=9830
sh=F42337E70886DB01977319E632FFB4356003050E ft=1 fh=234eac9709fa404f vn="a variant of Win32/Bundled.Toolbar.Ask.D potentially unsafe application (deleted - quarantined)" ac=C fn="C:\Documents and Settings\All Users\Documents\Aphoenix\Forms\Ours-AS, Blank, etc\OffercastInstaller_AVR_U-0087-01-PlateauLines-0805-01-en_.exe"
sh=E0E89B5610C05BA10EC3AAB43252B8326BEBF0F7 ft=1 fh=f462af6355a828a2 vn="Win32/DownloadAdmin.G potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Documents and Settings\Seth\Desktop\vlcmediaplayer-setup.exe"
sh=1B2629800C0D437E96CF023C5D1E30928A465259 ft=1 fh=9b8597e99409d24c vn="a variant of Win32/SProtector.D potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Documents and Settings\Seth\Local Settings\Temp\166b72ae.ftf.ftf"
sh=CCD90EE6E9B1ADFF9657E8F2C126BC6CB5C2EB24 ft=1 fh=91473923cd86549e vn="a variant of Win32/SProtector.E potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Documents and Settings\Seth\Local Settings\Temp\is-MPJG2.tmp\OptProCrash.dll"
sh=9663CAB5F4802FDAD8C719864F2E390BB99F195C ft=1 fh=02a711254bf91c09 vn="Win32/Bundled.Toolbar.Google.E potentially unsafe application (deleted - quarantined)" ac=C fn="C:\Documents and Settings\Seth\My Documents\Downloads\ccsetup316.exe"
sh=2E9FC5EE22DDB3588857BAEB1EC51885EB3D3C27 ft=1 fh=78aa2c558c3526a3 vn="Win32/Bundled.Toolbar.Google.E potentially unsafe application (deleted - quarantined)" ac=C fn="C:\Documents and Settings\Seth\My Documents\Downloads\ccsetup318.exe"
sh=60C77FF66F63F585FCE95C78FF44B513E2AAB9F9 ft=1 fh=17494879e4339ab3 vn="Win32/Bundled.Toolbar.Google.D potentially unsafe application (deleted - quarantined)" ac=C fn="C:\Documents and Settings\Seth\My Documents\Downloads\ccsetup400.exe"
sh=3825DE2525F8B667D79DA8787892CA15BE509A70 ft=1 fh=9c0db60505255f2f vn="Win32/OpenCandy potentially unsafe application (deleted - quarantined)" ac=C fn="C:\Documents and Settings\Seth\My Documents\Downloads\FreemakeVideoConverterSetup.exe"
sh=1B2629800C0D437E96CF023C5D1E30928A465259 ft=1 fh=9b8597e99409d24c vn="a variant of Win32/SProtector.D potentially unwanted application (deleted - quarantined)" ac=C fn="C:\WINDOWS\Temp\166b72ae.ftf.ftf"
# version=8
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=52cd78559699ac4397e54c74c4d588d8
# engine=17775
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2014-04-06 11:07:12
# local_time=2014-04-06 07:07:12 (-0500, Eastern Daylight Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=774 16777213 71 74 523514 523531 0 0
# scanned=121611
# found=0
# cleaned=0
# scan_time=8124

#12 fireman4it

fireman4it

    Bleepin' Fireman


  • Malware Response Team
  • 13,512 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Greenup, Ill USA
  • Local time:06:39 AM

Posted 07 April 2014 - 05:25 PM

How is the machine running now?


" Extinguishing Malware from the world"

The Virus, Trojan, Spyware, and Malware Removal forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.

ALL OTHER HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
Thanks-


  userbar_eis_500.gif

If I have helped you, consider making a donation to help me continue the fight against Malware! Just click btn_donate_LG.gif


#13 Vecc1982

Vecc1982
  • Topic Starter

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:07:39 AM

Posted 07 April 2014 - 06:36 PM

It's doing great. I haven't done a whole lot on it until I got the okay, but no ads or videos when browsing. What is the best way to prevent this from happening again? Also, do I need to reinstall google chrome since I changed to the beta site? And do I need to enable the plug ins I disabled?

#14 fireman4it

fireman4it

    Bleepin' Fireman


  • Malware Response Team
  • 13,512 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Greenup, Ill USA
  • Local time:06:39 AM

Posted 07 April 2014 - 10:32 PM

Hello, Vecc1982

Congratulations! You now appear clean! :cool:

 

 

do I need to reinstall google chrome since I changed to the beta site

Yes I would.

 

 

And do I need to enable the plug ins I disabled?

I would uninstall all of them and reinstall them one by one.

Are things running okay? Do you have any more questions?

System Still Slow?
You may wish to try StartupLite. Simply download this tool to your desktop and run it. It will explain any optional auto-start programs on your system, and offer the option to stop these programs from starting at startup. This will result in fewer programs running when you boot your system, and should improve preformance.
If that does not work, you can try the steps mentioned in Slow Computer/browser? Check Here First; It May Not Be Malware.

We Need to Clean Up Our Mess

 

 

  • Double click on adwcleaner.exe to run the tool.
  • Click on Uninstall.
  • Confirm with yes.

 

 

  • Download OTC by OldTimer and save it to your desktop.
  • Double click OTC_Icon.jpg icon to start the program. If you are using Vista, please right-click and choose run as administrator
  • Then Click the big CleanUp.jpg button.
  • You will get a prompt saying "Being Cleanup Process". Please select Yes.
  • Restart your computer when prompted.


Now you should Create a New Restore Point to prevent possible reinfection from an old one. Some of the malware you picked up could have been backed up, renamed and saved in System Restore. Since this is a protected directory your tools cannot access to delete these files, they sometimes can reinfect your system if you accidentally use an old restore point. Setting a new restore point AFTER cleaning your system will help prevent this and enable your computer to "roll-back" to a clean working state.

The easiest and safest way to do this is:

  • Go to Start > Programs > Accessories > System Tools and click "System Restore".
  • Choose the radio button marked "Create a Restore Point" on the first screen then click "Next". Give the R.P. a name, then click "Create". The new point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
  • Then use Disk Cleanup to remove all but the most recently created Restore Point.
  • Go to Start > Run and type: Cleanmgr
  • Click "Ok". Disk Cleanup will scan your files for several minutes, then open.
  • Click the "More Options" tab, then click the "Clean up" button under System Restore.
  • Click Ok. You will be prompted with "Are you sure you want to delete all but the most recent restore point?"
  • Click Yes, then click Ok.
  • Click Yes again when prompted with "Are you sure you want to perform these actions?"
  • Disk Cleanup will remove the files and close automatically.

Vista and Windows 7 users can refer to these links: Create a New Restore Point in Vista or Windows 7 and Disk Cleanup in Vista.

 

 

 

One of the most common questions found when cleaning malware is "how did my machine get infected?"

There are a variety of reasons, but the most common ones are that you are not practicing Safe Internet, you are not running the proper security software or that your computer's security settings are set too low.

Below I have outlined a series of categories that outline how you can increase the security of your computer to help reduce the chance of being infected again in the future.

Do not use P2P programs
Peer-to-peer or file-sharing programs (such as uTorrent, Limewire and Bitorrent) are probably the primary route of infection nowadays. These programs allow file sharing between users as the name(s) suggest.  It is almost impossible to know whether the file you’re downloading through P2P programs is safe.

It is therefore possible to be infected by downloading infected files via peer-to-peer programs and so I recommend that you do not use these programs. Should you wish to use them, they must be used with extreme care. Some further reading on this subject, along with included links, are as follows: "File-Sharing, otherwise known as Peer To Peer" and "Risks of File-Sharing Technology."

In addition, P2P programs facilitate cyber crime and help distribute pirated software, movies and other illegal material.

Practice Safe Internet
Another one of the main reasons people get infected in the first place is that they are not practicing Safe Internet. You practice Safe Internet when you educate yourself on how to properly use the Internet through the use of security tools and good practice. Knowing how you can get infected and what types of files and sites to avoid will be the most crucial step in keeping your computer malware free. The reality is that the majority of people who are infected with malware are ones who click on things they shouldn't be clicking on.  Whether these things are files or sites it doesn't really matter.  If something is out to get you, and you click on it, it most likely will. 

Below are a list of simple precautions to take to keep your computer clean and running securely:

  • If you receive an attachment from someone you do not know, DO NOT OPEN IT! Simple as that.  Opening attachments from people you do not know is a very common method for viruses or worms to infect your computer.
  • If you receive an attachment and it ends with a .exe, .com, .bat, or .pif do not open the attachment unless you know for a fact that it is clean.  For the casual computer user, you will almost never receive a valid attachment of this type.
  • If you receive an attachment from someone you know, and it looks suspicious, then it probably is.  The email could be from someone you know who is themselves infected with malware which is trying to infect everyone in their address book. A key thing to look out for here is: does the email sound as though it’s from the person you know? Often, the email may simply have a web link or a “Run this file to make your PC run fast” message in it.
  • If you are browsing the Internet and a popup appears saying that you are infected, ignore it!.  These are, as far as I am concerned, scams that are being used to scare you into purchasing a piece of software.  For an example of these types of pop-ups, or Foistware, you should read this article: Foistware, And how to avoid it.
    There are also programs that disguise themselves as Anti-Spyware or security products but are instead scams. Removal instructions for a lot of these "rogues" can be found here.
  • Another tactic to fool you on the web is when a site displays a popup that looks like a normal Windows message  or alert.  When you click on them, though, they instead bring you to another site that is trying to push a product on you, or will download a file to your PC without your knowledge.  You can check to see if it's a real alert by right-clicking on the window.  If there is a menu that comes up saying Add to Favorites... you know it's a fake. DO NOT click on these windows, instead close them by finding the open window on your http://en.wikipedia.org/wiki/Taskbar#Screenshots '>Taskbar, right click and chose close.
  • Do not visit pornographic websites.  I know this may bother some of you, but the fact is that a large amount of malware is pushed through these types of sites.  I am not saying all adult sites do this, but a lot do, as this can often form part of their funding.
  • When using an Instant Messaging program be cautious about clicking on links people send to you.  It is not uncommon for infections to send a message to everyone in the infected person's contact list that contains a link to an infection.  Instead when you receive a message that contains a link you should message back to the person asking if it is legit.
  • Stay away from Warez and Crack sites! As with Peer-2-Peer programs, in addition to the obvious copyright issues, the downloads from these sites are typically overrun with infections.
  • Be careful of what you download off of web sites and Peer-2-Peer networks. Some sites disguise malware as legitimate software to trick you into installing them and Peer-2-Peer networks are crawling with it. If you want to download files from a site, and are not sure if they are legitimate, you can use tools such as BitDefender Traffic Light, Norton Safe Web, or McAfee SiteAdvisor to look up info on the site and stay protected against malicious sites. Please be sure to only choose and install one of those tool bars.
  • DO NOT INSTALL any software without first reading the End User License Agreement, otherwise known as the EULA. A tactic that some developers use is to offer their software for free, but have spyware and other programs you do not want bundled with it. This is where they make their money.  By reading the agreement there is a good chance you can spot this and not install the software.
    Sometimes even legitimate programs will try to bundle extra, unwanted, software with the program you want - this is done to raise money for the program. Be sure to untick any boxes which may indicate that other programs will be downloaded.


Keep Windows up-to-date
Microsoft continually releases security and stability updates for its supported operating systems and you should always apply these to help keep your PC secure.



  • Windows XP users
    You should visit Windows Update to check for the latest updates to your system. The latest service pack (SP3) can be obtained directly from Microsoft here.
  • Windows Vista users
    You should run the Windows Update program from your start menu to access the latest updates to your operating system (information can be found here). The latest service pack (SP2) can be obtained directly from Microsoft here.
  • Windows 7 users
    You should run the Windows Update program from your start menu to access the latest updates to your operating system (information can be found here). The latest service pack (SP1) can be obtained directly from Microsoft here



Keep your browser secure
Most modern browsers have come on in leaps and bounds with their inbuilt, default security. The best way to keep your browser secure nowadays is simply to keep it up-to-date.

The latest versions of the three common browsers can be found below:




Use an AntiVirus Software
It is very important that your computer has an up-to-date anti-virus software on it which has a real-time agent running.  This alone can save you a lot of trouble with malware in the future. 
See this link for a listing of some online & their stand-alone antivirus programs: Virus, Spyware, and Malware Protection and Removal Resources, a couple of free Anti-Virus programs you may be interested in are Microsoft Security Essentials and Avast.

It is imperative that you update your Antivirus software at least once a week (even more if you wish).  If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.  If you use a commercial antivirus program you must make sure you keep renewing your subscription.  Otherwise, once your subscription runs out, you may not be able to update the programs virus definitions.

Use a Firewall
I can not stress how important it is that you use a Firewall on your computer.  Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly.

All versions of Windows starting from XP have an in-built firewall. With Windows XP this firewall will protect you from incoming traffic (i.e. hackers). Starting with Windows Vista, the firewall was beefed up to also protect you against outgoing traffic (i.e. malicious programs installed on your machine should be blocked from sending data, such as your bank details and passwords, out).

In addition, if you connect to the internet via a router, this will normally have a firewall in-built.

Some people will recommend installing a different firewall (instead of the Windows’ built one), this is personal choice, but the message is to definitely have one! For a tutorial on Firewalls and a listing of some available ones see this link: Understanding and Using Firewalls

Install an Anti-Malware program
Recommended, and free, Anti-Malware programs are Malwarebytes Anti-Malware and SuperAntiSpyware.

You should regularly (perhaps once a week) scan your computer with an Anti-Malware program just as you would with an antivirus software.

Make sure your applications have all of their updates
It is also possible for other programs on your computer to have security vulnerability that can allow malware to infect you.  Therefore, it is very important to check for the latest versions of commonly installed applications that are regularly patched to fix vulnerabilities (such as Adobe Reader and Java).  You can check these by visiting Secunia Software Inspector.

Follow this list and your potential for being infected again will reduce dramatically.


Edited by fireman4it, 07 April 2014 - 10:34 PM.

" Extinguishing Malware from the world"

The Virus, Trojan, Spyware, and Malware Removal forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.

ALL OTHER HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
Thanks-


  userbar_eis_500.gif

If I have helped you, consider making a donation to help me continue the fight against Malware! Just click btn_donate_LG.gif


#15 Vecc1982

Vecc1982
  • Topic Starter

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:07:39 AM

Posted 08 April 2014 - 04:16 PM

Sorry, I thought I responded to this last night but don't see it now. It is running great,maybe a tad slow loading pages but it's older. No ads or pop ups at all though! Thanks so much for all the help. What is the best way to prevent this from happening again? Also, should I reinstall Google Chrome? I still have the beta version and disabled some plug-ins when trying to fix it before. It never helped so should I enable them again?




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users