Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Com Surrogate Processes


  • This topic is locked This topic is locked
20 replies to this topic

#1 compcrewnpt

compcrewnpt

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:04:44 PM

Posted 27 August 2014 - 05:11 PM

*Need assistance to clean up com surrogate processes after virus removal making computer slow*

*No specific error messages to share*

 

Thank you for your time and expertise!

 

 

DDS (Ver_2012-11-20.01) - NTFS_AMD64 
Internet Explorer: 11.0.9600.17239
Run by Pink Pineapple at 17:28:17 on 2014-08-27
Microsoft Windows 7 Professional   6.1.7601.1.1252.1.1033.18.4015.1172 [GMT -4:00]
.
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\epson\portcommunicationservice\DeviceControlLog.exe
C:\Program Files\epson\portcommunicationservice\PCSVC.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Intel\iCLS Client\HeciServer.exe
C:\Program Files (x86)\Common Files\Intuit\Entitlement Client\v8\Server\Intuit.Spc.Map.EntitlementClient.Server.Service.exe
C:\Program Files (x86)\Intuit\QuickBooks Point of Sale 11.0\DatabaseServer\QBPOSDBService.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\taskeng.exe
c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
C:\Windows\system32\Dwm.exe
c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\VERIZONDM\bin\sprtsvc.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
C:\Program Files (x86)\Intuit\QuickBooks Point of Sale 11.0\DatabaseServer\QBDBMgr10.exe
C:\Program Files (x86)\VERIZONDM\bin\tgsrvc.exe
C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Users\Pink Pineapple\AppData\Roaming\Dayxohup\ocupdu.exe
C:\Users\Pink Pineapple\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\VERIZONDM\bin\sprtcmd.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\SearchIndexer.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\PrintIsolationHost.exe
C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Dell Backup and Recovery\sftservice.exe
C:\Program Files (x86)\Dell Backup and Recovery\COMPONENTS\DBRUPDATE\DBRUPD.EXE
C:\Program Files (x86)\Dell Backup and Recovery\TOASTER.EXE
C:\Program Files (x86)\Dell Backup and Recovery\Components\Shell\DBRCrawler.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\WUDFHost.exe
C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe
C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe
C:\Windows\syswow64\dllhost.exe
C:\Windows\syswow64\dllhost.exe
C:\Windows\syswow64\dllhost.exe
C:\Windows\syswow64\dllhost.exe
C:\Windows\syswow64\dllhost.exe
C:\Windows\syswow64\dllhost.exe
C:\Windows\syswow64\dllhost.exe
C:\Windows\syswow64\dllhost.exe
C:\Windows\syswow64\dllhost.exe
C:\Windows\syswow64\dllhost.exe
C:\Windows\syswow64\dllhost.exe
C:\Windows\syswow64\dllhost.exe
C:\Windows\syswow64\dllhost.exe
C:\Windows\syswow64\dllhost.exe
C:\Windows\syswow64\dllhost.exe
C:\Windows\syswow64\dllhost.exe
C:\Users\Pink Pineapple\AppData\Roaming\Dayxohup\ocupdu.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\syswow64\dllhost.exe
C:\Windows\syswow64\dllhost.exe
C:\Windows\syswow64\dllhost.exe
C:\Windows\syswow64\dllhost.exe
C:\Windows\syswow64\dllhost.exe
C:\Windows\syswow64\dllhost.exe
C:\Windows\syswow64\dllhost.exe
C:\Windows\syswow64\dllhost.exe
C:\Windows\syswow64\dllhost.exe
C:\Windows\syswow64\dllhost.exe
C:\Windows\syswow64\dllhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\syswow64\dllhost.exe
C:\Windows\syswow64\dllhost.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uSearch Bar = Preserve
mStart Page = about:blank
mWinlogon: Userinit = userinit.exe,
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
uRun: [Feuqilik] "C:\Users\Pink Pineapple\AppData\Roaming\Dayxohup\ocupdu.exe"
uRun: [CtrlIdentities] "C:\Users\Pink Pineapple\AppData\Roaming\Identities\CtrlIdentities.exe"
uRun: [Spotify Web Helper] "C:\Users\Pink Pineapple\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
mRun: [USB3MON] "C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [VERIZONDM] "C:\Program Files (x86)\VERIZONDM\bin\sprtcmd.exe" /P VERIZONDM
mRun: [EpsonAPD4SV] C:\Program Files (x86)\EPSON\EPSON Advanced Printer Driver 4\Tools\EAPSV\EAPSV.EXE
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: SafeKey Fill Forms - C:\Users\Pink Pineapple\AppData\LocalLow\SafeKey\context.html?cmd=fillforms
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{4D2833BF-5838-4250-B5E0-1A452C58E308} : DHCPNameServer = 192.168.1.1
Handler: qbpos - {662E7FAE-5C17-491C-AD9D-98C1F66CC6A0} - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBPOSProtocol.dll
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.143\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-mStart Page = about:blank
x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe /s
x64-Run: [RtHDVBg] "C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /MAXX4
x64-Run: [IgfxTray] "C:\Windows\System32\igfxtray.exe"
x64-Run: [HotKeysCmds] "C:\Windows\System32\hkcmd.exe"
x64-Run: [Persistence] "C:\Windows\System32\igfxpers.exe"
x64-Handler: qbpos - {662E7FAE-5C17-491C-AD9D-98C1F66CC6A0} - <orphaned>
x64-Notify: GoToAssist - C:\Program Files (x86)\Citrix\GoToAssist\896\G2AWinLogon_x64.dll
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R0 iusb3hcs;Intel® USB 3.0 Host Controller Switch Driver;C:\Windows\System32\drivers\iusb3hcs.sys [2013-11-6 20464]
R3 IntcDAud;Intel® Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2013-11-6 452088]
R3 iusb3hub;Intel® USB 3.0 Hub Driver;C:\Windows\System32\drivers\iusb3hub.sys [2013-11-6 368112]
R3 iusb3xhc;Intel® USB 3.0 eXtensible Host Controller Driver;C:\Windows\System32\drivers\iusb3xhc.sys [2013-11-6 786416]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2013-11-6 842312]
R3 TMUSB;EPSON USB Device Driver for TM/BA/EU Printers;C:\Windows\System32\drivers\TMUSB64.sys [2014-4-3 63096]
S2 EPSON_PCS_Parallel_Port_Driver;EPSON PCS Parallel Port Driver;C:\Windows\System32\drivers\pcslpt.sys [2012-11-29 21640]
S3 dmvsc;dmvsc;C:\Windows\System32\drivers\dmvsc.sys [2010-11-21 71168]
S3 InvProtectDrv;InvProtectDrv;C:\Program Files (x86)\Invincea\Enterprise\X64\InvProtectDrv64.sys [2013-7-30 34824]
S3 MBAMSwissArmy;MBAMSwissArmy;C:\Windows\System32\drivers\MBAMSwissArmy.sys [2014-8-21 122584]
S3 netvsc;netvsc;C:\Windows\System32\drivers\netvsc60.sys [2010-11-21 168448]
S3 SboxDrv;SboxDrv;C:\Program Files (x86)\Invincea\Enterprise\Sandbox\SboxDrv.sys [2013-7-30 202248]
S3 SynthVid;SynthVid;C:\Windows\System32\drivers\VMBusVideoM.sys [2010-11-21 22528]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-20 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-20 31232]
.
=============== Created Last 30 ================
.
2014-08-26 21:16:34 -------- d-----w- C:\Program Files (x86)\TeamViewer
2014-08-26 07:54:52 11319192 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{43A1A473-CECE-4E9F-8ED3-96E5D0816663}\mpengine.dll
2014-08-24 12:10:46 -------- d-----w- C:\Users\Pink Pineapple\AppData\Roaming\Dayxohup
2014-08-22 01:22:39 -------- d-----w- C:\Users\Pink Pineapple\AppData\Local\Google
2014-08-21 23:50:52 122584 ----a-w- C:\Windows\System32\drivers\MBAMSwissArmy.sys
2014-08-21 23:50:23 91352 ----a-w- C:\Windows\System32\drivers\mbamchameleon.sys
2014-08-21 23:50:23 63704 ----a-w- C:\Windows\System32\drivers\mwac.sys
2014-08-21 23:50:23 25816 ----a-w- C:\Windows\System32\drivers\mbam.sys
2014-08-21 23:50:19 -------- d-----w- C:\ProgramData\Malwarebytes
2014-08-21 23:50:19 -------- d-----w- C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-08-21 23:49:56 -------- d-----w- C:\Users\Pink Pineapple\AppData\Local\Programs
2014-08-21 23:44:04 -------- d-----w- C:\Program Files\CCleaner
2014-08-21 23:35:57 -------- d-----r- C:\Users\Pink Pineapple\Tools
2014-08-21 16:38:06 12288 --sh--r- C:\Users\Pink Pineapple\AppData\Roaming\{00006E11-3264-13A3-2FE3-29E305E1F572}.exe
2014-08-21 16:02:52 27093992 ----a-w- C:\Program Files (x86)\Common Files\lpuninstall.exe
2014-08-21 14:17:17 -------- d-----w- C:\Quarantine
2014-08-21 14:16:20 -------- d-----w- C:\mfe
2014-08-21 14:10:26 -------- d-----w- C:\Program Files\stinger
2014-08-14 07:01:00 99480 ----a-w- C:\Windows\SysWow64\infocardapi.dll
2014-08-14 07:01:00 8856 ----a-w- C:\Windows\SysWow64\icardres.dll
2014-08-14 07:01:00 8856 ----a-w- C:\Windows\System32\icardres.dll
2014-08-14 07:01:00 619672 ----a-w- C:\Windows\SysWow64\icardagt.exe
2014-08-14 07:01:00 171160 ----a-w- C:\Windows\System32\infocardapi.dll
2014-08-14 07:01:00 1389208 ----a-w- C:\Windows\System32\icardagt.exe
2014-08-14 07:00:53 35480 ----a-w- C:\Windows\SysWow64\TsWpfWrp.exe
2014-08-14 07:00:53 35480 ----a-w- C:\Windows\System32\TsWpfWrp.exe
2014-08-13 09:05:59 726528 ----a-w- C:\Program Files\Internet Explorer\ieproxy.dll
2014-08-13 09:03:59 664064 ----a-w- C:\Windows\SysWow64\rpcrt4.dll
2014-08-13 09:03:59 1216000 ----a-w- C:\Windows\System32\rpcrt4.dll
2014-08-13 09:03:58 529920 ----a-w- C:\Windows\System32\aepdu.dll
2014-08-13 09:03:58 424448 ----a-w- C:\Windows\System32\aeinv.dll
2014-08-11 23:26:36 -------- d-----w- C:\Windows\System32\MRT
2014-08-09 20:10:43 -------- d-----w- C:\ProgramData\Citrix
2014-08-09 20:06:39 -------- d-----w- C:\Program Files (x86)\Citrix
2014-08-09 20:06:27 -------- d-----w- C:\Users\Pink Pineapple\AppData\Local\Citrix
2014-08-09 20:06:26 103832 ----a-w- C:\Users\Pink Pineapple\GoToAssistDownloadHelper.exe
2014-08-09 20:06:13 -------- d-----w- C:\Users\Pink Pineapple\AppData\Local\Deployment
2014-08-09 20:06:13 -------- d-----w- C:\Users\Pink Pineapple\AppData\Local\Apps
2014-08-09 14:00:45 -------- d-----w- C:\Users\Pink Pineapple\AppData\Local\Spotify
2014-08-09 13:59:46 -------- d-----w- C:\Users\Pink Pineapple\AppData\Roaming\Spotify
2014-08-07 23:59:02 0 ----a-w- C:\Users\Pink Pineapple\AppData\Roaming\zotxxwl.dll
.
==================== Find3M  ====================
.
2014-08-05 13:20:00 270496 ------w- C:\Windows\System32\MpSigStub.exe
2014-07-25 14:02:12 2724864 ----a-w- C:\Windows\System32\mshtml.tlb
2014-07-25 14:01:41 4096 ----a-w- C:\Windows\System32\ieetwcollectorres.dll
2014-07-25 13:30:30 66048 ----a-w- C:\Windows\System32\iesetup.dll
2014-07-25 13:28:35 48640 ----a-w- C:\Windows\System32\ieetwproxystub.dll
2014-07-25 13:28:27 548352 ----a-w- C:\Windows\System32\vbscript.dll
2014-07-25 13:25:45 83968 ----a-w- C:\Windows\System32\MshtmlDac.dll
2014-07-25 13:04:40 2724864 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2014-07-25 13:00:51 139264 ----a-w- C:\Windows\System32\ieUnatt.exe
2014-07-25 13:00:25 111616 ----a-w- C:\Windows\System32\ieetwcollector.exe
2014-07-25 12:59:28 758272 ----a-w- C:\Windows\System32\jscript9diag.dll
2014-07-25 12:47:25 940032 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe
2014-07-25 12:34:49 61952 ----a-w- C:\Windows\SysWow64\iesetup.dll
2014-07-25 12:34:03 455168 ----a-w- C:\Windows\SysWow64\vbscript.dll
2014-07-25 12:33:08 51200 ----a-w- C:\Windows\SysWow64\ieetwproxystub.dll
2014-07-25 12:30:32 61952 ----a-w- C:\Windows\SysWow64\MshtmlDac.dll
2014-07-25 12:28:15 5824512 ----a-w- C:\Windows\System32\jscript9.dll
2014-07-25 12:28:05 72704 ----a-w- C:\Windows\System32\JavaScriptCollectionAgent.dll
2014-07-25 12:10:15 112128 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2014-07-25 12:08:47 597504 ----a-w- C:\Windows\SysWow64\jscript9diag.dll
2014-07-25 12:06:47 4204032 ----a-w- C:\Windows\SysWow64\jscript9.dll
2014-07-25 11:43:16 60416 ----a-w- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
2014-07-25 11:39:29 2087936 ----a-w- C:\Windows\System32\inetcpl.cpl
2014-07-25 11:39:25 1249280 ----a-w- C:\Windows\System32\mshtmlmedia.dll
2014-07-25 11:07:49 2001920 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2014-07-25 11:07:10 1068032 ----a-w- C:\Windows\SysWow64\mshtmlmedia.dll
2014-07-25 10:52:06 2266624 ----a-w- C:\Windows\System32\wininet.dll
2014-07-25 10:05:23 1792512 ----a-w- C:\Windows\SysWow64\wininet.dll
2014-07-16 03:25:04 404480 ----a-w- C:\Windows\System32\gdi32.dll
2014-07-16 03:23:41 2048 ----a-w- C:\Windows\System32\tzres.dll
2014-07-16 02:46:24 311808 ----a-w- C:\Windows\SysWow64\gdi32.dll
2014-07-16 02:46:02 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2014-07-16 02:12:11 3163648 ----a-w- C:\Windows\System32\win32k.sys
2014-07-09 02:03:23 7168 ----a-w- C:\Windows\System32\KBDYAK.DLL
2014-07-09 02:03:22 7168 ----a-w- C:\Windows\System32\KBDBASH.DLL
2014-07-09 01:31:42 7168 ----a-w- C:\Windows\SysWow64\KBDYAK.DLL
2014-07-09 01:31:41 6656 ----a-w- C:\Windows\SysWow64\KBDBASH.DLL
2014-06-18 02:18:30 692736 ----a-w- C:\Windows\System32\osk.exe
2014-06-18 01:51:32 646144 ----a-w- C:\Windows\SysWow64\osk.exe
2014-06-16 02:10:19 985536 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys
2014-06-06 10:10:34 624128 ----a-w- C:\Windows\System32\qedit.dll
2014-06-06 09:44:17 509440 ----a-w- C:\Windows\SysWow64\qedit.dll
2014-06-05 14:45:15 1460736 ----a-w- C:\Windows\System32\lsasrv.dll
2014-06-05 14:26:58 22016 ----a-w- C:\Windows\SysWow64\secur32.dll
2014-06-05 14:25:49 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
2014-06-03 10:02:37 112064 ----a-w- C:\Windows\System32\consent.exe
2014-06-03 10:02:21 504320 ----a-w- C:\Windows\System32\msihnd.dll
2014-06-03 10:02:21 3241984 ----a-w- C:\Windows\System32\msi.dll
2014-06-03 10:02:12 1941504 ----a-w- C:\Windows\System32\authui.dll
2014-06-03 09:29:50 337408 ----a-w- C:\Windows\SysWow64\msihnd.dll
2014-06-03 09:29:50 2363392 ----a-w- C:\Windows\SysWow64\msi.dll
2014-06-03 09:29:40 1805824 ----a-w- C:\Windows\SysWow64\authui.dll
2014-05-30 08:08:52 210944 ----a-w- C:\Windows\System32\wdigest.dll
2014-05-30 08:08:49 86528 ----a-w- C:\Windows\System32\TSpkg.dll
2014-05-30 08:08:47 340992 ----a-w- C:\Windows\System32\schannel.dll
2014-05-30 08:08:41 314880 ----a-w- C:\Windows\System32\msv1_0.dll
2014-05-30 08:08:41 307200 ----a-w- C:\Windows\System32\ncrypt.dll
2014-05-30 08:08:36 728064 ----a-w- C:\Windows\System32\kerberos.dll
2014-05-30 08:08:31 22016 ----a-w- C:\Windows\System32\credssp.dll
2014-05-30 07:52:51 172032 ----a-w- C:\Windows\SysWow64\wdigest.dll
2014-05-30 07:52:49 65536 ----a-w- C:\Windows\SysWow64\TSpkg.dll
2014-05-30 07:52:45 247808 ----a-w- C:\Windows\SysWow64\schannel.dll
2014-05-30 07:52:41 220160 ----a-w- C:\Windows\SysWow64\ncrypt.dll
2014-05-30 07:52:40 259584 ----a-w- C:\Windows\SysWow64\msv1_0.dll
2014-05-30 07:52:36 550912 ----a-w- C:\Windows\SysWow64\kerberos.dll
2014-05-30 07:52:30 17408 ----a-w- C:\Windows\SysWow64\credssp.dll
2014-05-30 06:45:52 497152 ----a-w- C:\Windows\System32\drivers\afd.sys
.
============= FINISH: 17:31:01.59 ===============
 

 

 

Attached Files



BC AdBot (Login to Remove)

 


#2 aharonov

aharonov

  • Malware Response Team
  • 2,441 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:44 PM

Posted 27 August 2014 - 05:23 PM

Hi again. :)

Please run the following scans:


Step 1

Please download Combofix (by sUBs) and save it to your Desktop.
  • Disable the realtime-protection of your antivirus and anti-malware programs because they might interfere with the scan.
  • Start Combofix.exe and follow its instructions.
  • Do not use the computer while the scan is running. This may cause the program to stall.
  • When finished, a log file will be displayed (that can also be found at C:\Combofix.txt).
    Please copy and paste the contents of this file into your next post.
Note: If you receive an error "Illegal operation attempted on a registry key that has been marked for deletion." after the scan, just restart the computer.
(You can find more detailed instructions in this guide on using Combofix.)



Step 2

Please download Farbar Recovery Scan Tool and save it to your Desktop.
  • Start FRST with administator privileges.
  • Make sure the option Addition.txt is checked and press the Scan button.
  • When finished, FRST will produce two logs (FRST.txt and Addition.txt) in the same directory the tool was run from.
  • Please copy and paste these logs in your next reply.


#3 compcrewnpt

compcrewnpt
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:04:44 PM

Posted 27 August 2014 - 07:13 PM

Wow!That was fast.

 

 

ComboFix 14-08-26.02 - Pink Pineapple 08/27/2014  19:53:09.1.4 - x64
Microsoft Windows 7 Professional   6.1.7601.1.1252.1.1033.18.4015.1190 [GMT -4:00]
Running from: c:\users\Pink Pineapple\Desktop\Dont Delete For Virus Removal\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Pink Pineapple\AppData\Roaming\{00006E11-3264-13A3-2FE3-29E305E1F572}.exe
c:\users\Pink Pineapple\AppData\Roaming\Identities\CtrlIdentities.exe
c:\users\Pink Pineapple\AppData\Roaming\zotxxwl.dll
c:\users\Pink Pineapple\GoToAssistDownloadHelper.exe
.
.
CLSID={AB8902B4-09CA-4bb6-B78D-A8F59079A8D5} - infected with Poweliks and removed.
You should verify if current CLSID data is correct: 
.
HKEY_CLASSES_ROOT\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}
    (Default)    REG_SZ    Thumbnail Cache Class Factory for Out of Proc Server
    AppID    REG_SZ    {AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}
.
HKEY_CLASSES_ROOT\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\InprocServer32
    (Default)    REG_SZ    c:\windows\system32\thumbcache.dll
    ThreadingModel    REG_SZ    Apartment
.
.
(((((((((((((((((((((((((   Files Created from 2014-07-27 to 2014-08-27  )))))))))))))))))))))))))))))))
.
.
2014-08-27 23:58 . 2014-08-27 23:58 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-08-26 21:16 . 2014-08-26 21:16 -------- d-----w- c:\program files (x86)\TeamViewer
2014-08-26 07:54 . 2014-08-21 03:43 11319192 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{43A1A473-CECE-4E9F-8ED3-96E5D0816663}\mpengine.dll
2014-08-24 12:10 . 2014-08-24 12:10 -------- d-----w- c:\users\Pink Pineapple\AppData\Roaming\Dayxohup
2014-08-22 01:22 . 2014-08-22 01:23 -------- d-----w- c:\users\Pink Pineapple\AppData\Local\Google
2014-08-22 01:22 . 2014-08-22 01:22 -------- d-----w- c:\program files (x86)\Google
2014-08-21 23:50 . 2014-08-22 01:32 122584 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-08-21 23:50 . 2014-05-12 11:26 63704 ----a-w- c:\windows\system32\drivers\mwac.sys
2014-08-21 23:50 . 2014-05-12 11:26 91352 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-08-21 23:50 . 2014-05-12 11:25 25816 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-08-21 23:50 . 2014-08-21 23:50 -------- d-----w- c:\program files (x86)\Malwarebytes Anti-Malware
2014-08-21 23:50 . 2014-08-21 23:50 -------- d-----w- c:\programdata\Malwarebytes
2014-08-21 23:49 . 2014-08-21 23:49 -------- d-----w- c:\users\Pink Pineapple\AppData\Local\Programs
2014-08-21 23:44 . 2014-08-21 23:44 -------- d-----w- c:\program files\CCleaner
2014-08-21 23:35 . 2014-08-22 01:21 -------- d-----r- c:\users\Pink Pineapple\Tools
2014-08-21 16:04 . 2014-08-22 01:03 -------- dc----w- c:\windows\system32\DRVSTORE
2014-08-21 16:02 . 2014-08-22 01:14 27093992 ----a-w- c:\program files (x86)\Common Files\lpuninstall.exe
2014-08-21 14:17 . 2014-08-21 14:17 -------- d-----w- C:\Quarantine
2014-08-21 14:16 . 2014-08-21 14:16 -------- d-----w- C:\mfe
2014-08-21 14:10 . 2014-08-21 14:19 -------- d-----w- c:\program files\stinger
2014-08-21 14:08 . 2014-08-22 01:11 -------- d-----w- c:\programdata\McAfee
2014-08-14 07:01 . 2014-06-30 22:24 8856 ----a-w- c:\windows\system32\icardres.dll
2014-08-14 07:01 . 2014-06-30 22:14 8856 ----a-w- c:\windows\SysWow64\icardres.dll
2014-08-14 07:01 . 2014-03-09 21:48 171160 ----a-w- c:\windows\system32\infocardapi.dll
2014-08-14 07:01 . 2014-03-09 21:48 1389208 ----a-w- c:\windows\system32\icardagt.exe
2014-08-14 07:01 . 2014-03-09 21:47 99480 ----a-w- c:\windows\SysWow64\infocardapi.dll
2014-08-14 07:01 . 2014-03-09 21:47 619672 ----a-w- c:\windows\SysWow64\icardagt.exe
2014-08-14 07:00 . 2014-06-06 06:16 35480 ----a-w- c:\windows\SysWow64\TsWpfWrp.exe
2014-08-14 07:00 . 2014-06-06 06:12 35480 ----a-w- c:\windows\system32\TsWpfWrp.exe
2014-08-13 09:05 . 2014-07-31 23:41 348856 ----a-w- c:\windows\system32\iedkcs32.dll
2014-08-13 09:03 . 2014-07-14 02:02 1216000 ----a-w- c:\windows\system32\rpcrt4.dll
2014-08-13 09:03 . 2014-07-14 01:40 664064 ----a-w- c:\windows\SysWow64\rpcrt4.dll
2014-08-13 09:03 . 2014-08-07 02:06 529920 ----a-w- c:\windows\system32\aepdu.dll
2014-08-13 09:03 . 2014-08-07 02:01 424448 ----a-w- c:\windows\system32\aeinv.dll
2014-08-11 23:26 . 2014-08-14 07:06 -------- d-----w- c:\windows\system32\MRT
2014-08-09 20:10 . 2014-08-09 20:10 -------- d-----w- c:\programdata\Citrix
2014-08-09 20:06 . 2014-08-09 20:06 -------- d-----w- c:\program files (x86)\Citrix
2014-08-09 20:06 . 2014-08-09 20:06 -------- d-----w- c:\users\Pink Pineapple\AppData\Local\Citrix
2014-08-09 20:06 . 2014-08-21 15:01 -------- d-----w- c:\users\Pink Pineapple\AppData\Local\Deployment
2014-08-09 20:06 . 2014-08-09 20:06 -------- d-----w- c:\users\Pink Pineapple\AppData\Local\Apps
2014-08-09 14:00 . 2014-08-21 02:07 -------- d-----w- c:\users\Pink Pineapple\AppData\Local\Spotify
2014-08-09 13:59 . 2014-08-25 18:28 -------- d-----w- c:\users\Pink Pineapple\AppData\Roaming\Spotify
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-08-05 13:20 . 2010-11-21 03:27 270496 ------w- c:\windows\system32\MpSigStub.exe
2014-06-18 02:18 . 2014-07-09 05:15 692736 ----a-w- c:\windows\system32\osk.exe
2014-06-18 01:51 . 2014-07-09 05:15 646144 ----a-w- c:\windows\SysWow64\osk.exe
2014-06-06 10:10 . 2014-07-09 05:15 624128 ----a-w- c:\windows\system32\qedit.dll
2014-06-06 09:44 . 2014-07-09 05:15 509440 ----a-w- c:\windows\SysWow64\qedit.dll
2014-06-05 14:45 . 2014-07-09 05:13 1460736 ----a-w- c:\windows\system32\lsasrv.dll
2014-06-05 14:26 . 2014-07-09 05:13 22016 ----a-w- c:\windows\SysWow64\secur32.dll
2014-06-05 14:25 . 2014-07-09 05:13 96768 ----a-w- c:\windows\SysWow64\sspicli.dll
2014-05-30 08:08 . 2014-07-09 05:15 210944 ----a-w- c:\windows\system32\wdigest.dll
2014-05-30 08:08 . 2014-07-09 05:15 86528 ----a-w- c:\windows\system32\TSpkg.dll
2014-05-30 08:08 . 2014-07-09 05:15 340992 ----a-w- c:\windows\system32\schannel.dll
2014-05-30 08:08 . 2014-07-09 05:15 314880 ----a-w- c:\windows\system32\msv1_0.dll
2014-05-30 08:08 . 2014-07-09 05:15 307200 ----a-w- c:\windows\system32\ncrypt.dll
2014-05-30 08:08 . 2014-07-09 05:15 728064 ----a-w- c:\windows\system32\kerberos.dll
2014-05-30 08:08 . 2014-07-09 05:15 22016 ----a-w- c:\windows\system32\credssp.dll
2014-05-30 07:52 . 2014-07-09 05:15 172032 ----a-w- c:\windows\SysWow64\wdigest.dll
2014-05-30 07:52 . 2014-07-09 05:15 65536 ----a-w- c:\windows\SysWow64\TSpkg.dll
2014-05-30 07:52 . 2014-07-09 05:15 247808 ----a-w- c:\windows\SysWow64\schannel.dll
2014-05-30 07:52 . 2014-07-09 05:15 220160 ----a-w- c:\windows\SysWow64\ncrypt.dll
2014-05-30 07:52 . 2014-07-09 05:15 259584 ----a-w- c:\windows\SysWow64\msv1_0.dll
2014-05-30 07:52 . 2014-07-09 05:15 550912 ----a-w- c:\windows\SysWow64\kerberos.dll
2014-05-30 07:52 . 2014-07-09 05:15 17408 ----a-w- c:\windows\SysWow64\credssp.dll
2014-05-30 06:45 . 2014-07-09 05:15 497152 ----a-w- c:\windows\system32\drivers\afd.sys
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown 
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Feuqilik"="c:\users\Pink Pineapple\AppData\Roaming\Dayxohup\ocupdu.exe" [2014-06-27 305220]
"Spotify Web Helper"="c:\users\Pink Pineapple\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2014-08-09 1178168]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"USB3MON"="c:\program files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2013-04-26 292848]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-09-24 926896]
"VERIZONDM"="c:\program files (x86)\VERIZONDM\bin\sprtcmd.exe" [2011-02-01 206120]
"EpsonAPD4SV"="c:\program files (x86)\EPSON\EPSON Advanced Printer Driver 4\Tools\EAPSV\EAPSV.EXE" [2011-06-07 210368]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc]
@=""
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 EPSON_PCS_Parallel_Port_Driver;EPSON PCS Parallel Port Driver;c:\windows\system32\DRIVERS\pcslpt.sys;c:\windows\SYSNATIVE\DRIVERS\pcslpt.sys [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 Intel® Capability Licensing Service TCP IP Interface;Intel® Capability Licensing Service TCP IP Interface;c:\program files\Intel\iCLS Client\SocketHeciServer.exe;c:\program files\Intel\iCLS Client\SocketHeciServer.exe [x]
R3 InvProtectDrv;InvProtectDrv;c:\program files (x86)\Invincea\Enterprise\X64\InvProtectDrv64.sys;c:\program files (x86)\Invincea\Enterprise\X64\InvProtectDrv64.sys [x]
R3 InvProtectSvc;Invincea Enterprise Service;c:\program files (x86)\Invincea\Enterprise\X64\InvProtectSvc64.exe;c:\program files (x86)\Invincea\Enterprise\X64\InvProtectSvc64.exe [x]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
R3 netvsc;netvsc;c:\windows\system32\DRIVERS\netvsc60.sys;c:\windows\SYSNATIVE\DRIVERS\netvsc60.sys [x]
R3 SboxDrv;SboxDrv;c:\program files (x86)\Invincea\Enterprise\Sandbox\SboxDrv.sys;c:\program files (x86)\Invincea\Enterprise\Sandbox\SboxDrv.sys [x]
R3 SboxSvc;SboxSvc;c:\program files (x86)\Invincea\Enterprise\Sandbox\SboxSvc.exe;c:\program files (x86)\Invincea\Enterprise\Sandbox\SboxSvc.exe [x]
R3 SynthVid;SynthVid;c:\windows\system32\DRIVERS\VMBusVideoM.sys;c:\windows\SYSNATIVE\DRIVERS\VMBusVideoM.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 iusb3hcs;Intel® USB 3.0 Host Controller Switch Driver;c:\windows\system32\DRIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hcs.sys [x]
S2 EPSON_Device_Control_Log_Service;EPSON Device Control Log Service;c:\program files\epson\portcommunicationservice\DeviceControlLog.exe;c:\program files\epson\portcommunicationservice\DeviceControlLog.exe [x]
S2 EPSON_Port_Communication_Service;EPSON Port Communication Service;c:\program files\epson\portcommunicationservice\PCSVC.exe;c:\program files\epson\portcommunicationservice\PCSVC.exe [x]
S2 Intel® Capability Licensing Service Interface;Intel® Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
S2 Intuit Entitlement Service v8;Intuit Entitlement Service v8;c:\program files (x86)\Common Files\Intuit\Entitlement Client\v8\Server\Intuit.Spc.Map.EntitlementClient.Server.Service.exe;c:\program files (x86)\Common Files\Intuit\Entitlement Client\v8\Server\Intuit.Spc.Map.EntitlementClient.Server.Service.exe [x]
S2 IntuitUpdateServiceV4;Intuit Update Service v4;c:\program files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe;c:\program files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe [x]
S2 jhi_service;Intel® Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [x]
S2 QBPOSDBServiceV11;QBPOS Database Manager v11;c:\program files (x86)\Intuit\QuickBooks Point of Sale 11.0\DatabaseServer\QBPOSDBService.exe;c:\program files (x86)\Intuit\QuickBooks Point of Sale 11.0\DatabaseServer\QBPOSDBService.exe [x]
S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell Backup and Recovery\sftservice.exe;c:\program files (x86)\Dell Backup and Recovery\sftservice.exe [x]
S2 sprtsvc_verizondm;SupportSoft Sprocket Service (verizondm);c:\program files (x86)\VERIZONDM\bin\sprtsvc.exe;c:\program files (x86)\VERIZONDM\bin\sprtsvc.exe [x]
S2 TeamViewer9;TeamViewer 9;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [x]
S2 tgsrvc_verizondm;SupportSoft Repair Service (verizondm);c:\program files (x86)\VERIZONDM\bin\tgsrvc.exe;c:\program files (x86)\VERIZONDM\bin\tgsrvc.exe [x]
S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 iusb3hub;Intel® USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x]
S3 iusb3xhc;Intel® USB 3.0 eXtensible Host Controller Driver;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x]
S3 Point64;Microsoft Mouse and Keyboard Center Filter Driver;c:\windows\system32\DRIVERS\point64.sys;c:\windows\SYSNATIVE\DRIVERS\point64.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 TMUSB;EPSON USB Device Driver for TM/BA/EU Printers;c:\windows\system32\DRIVERS\TMUSB64.SYS;c:\windows\SYSNATIVE\DRIVERS\TMUSB64.SYS [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-08-22 01:22 1104200 ----a-w- c:\program files (x86)\Google\Chrome\Application\36.0.1985.143\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2014-08-27 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-11-07 00:21]
.
2014-08-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-08-22 01:22]
.
2014-08-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-08-22 01:22]
.
2014-08-27 c:\windows\Tasks\Security Center Update - 1163631284.job
- c:\users\Pink Pineapple\AppData\Roaming\Dayxohup\ocupdu.exe [2014-06-27 10:47]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DBARFileBackuped]
@="{831cebdd-6baf-4432-be76-9e0989c14aef}"
[HKEY_CLASSES_ROOT\CLSID\{831cebdd-6baf-4432-be76-9e0989c14aef}]
2010-11-21 03:23 444752 ----a-w- c:\windows\System32\mscoree.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DBARFileNotBackuped]
@="{275e4fd7-21ef-45cf-a836-832e5d2cc1b3}"
[HKEY_CLASSES_ROOT\CLSID\{275e4fd7-21ef-45cf-a836-832e5d2cc1b3}]
2010-11-21 03:23 444752 ----a-w- c:\windows\System32\mscoree.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2013-08-20 7202520]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2013-07-29 1321688]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2013-07-19 165872]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2013-07-19 407536]
"Persistence"="c:\windows\system32\igfxpers.exe" [2013-07-19 444400]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: SafeKey Fill Forms - file://c:\users\Pink Pineapple\AppData\LocalLow\SafeKey\context.html?cmd=fillforms
TCP: DhcpNameServer = 192.168.1.1
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
Toolbar-10 - (no file)
Wow6432Node-HKCU-Run-CtrlIdentities - c:\users\Pink Pineapple\AppData\Roaming\Identities\CtrlIdentities.exe
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
Toolbar-Locked - (no file)
Toolbar-10 - (no file)
.
.
.
Completion time: 2014-08-27  20:06:12
ComboFix-quarantined-files.txt  2014-08-28 00:06
.
Pre-Run: 437,037,076,480 bytes free
Post-Run: 437,058,584,576 bytes free
.
- - End Of File - - FB8F640FBE24B38AFDCBEF8E17DAA30E
5C616939100B85E558DA92B899A0FC36


#4 compcrewnpt

compcrewnpt
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:04:44 PM

Posted 27 August 2014 - 07:22 PM

FRST:::

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-08-2014
Ran by Pink Pineapple (administrator) on PINKPINEAPPLE on 27-08-2014 20:15:31
Running from C:\Users\Pink Pineapple\Desktop\Dont Delete For Virus Removal
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal
 
The only official download link for FRST:
Download link from any site other than Bleeping Computer is unpermitted or outdated.
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(SEIKO EPSON CORPORATION) C:\Program Files\EPSON\portcommunicationservice\DeviceControlLog.exe
(SEIKO EPSON CORPORATION) C:\Program Files\EPSON\portcommunicationservice\PCSVC.exe
(Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intuit, Inc.) C:\Program Files (x86)\Common Files\Intuit\Entitlement Client\v8\Server\Intuit.Spc.Map.EntitlementClient.Server.Service.exe
(Intuit Inc.) C:\Program Files (x86)\Intuit\QuickBooks Point of Sale 11.0\DatabaseServer\QBPOSDBService.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(SupportSoft, Inc.) C:\Program Files (x86)\VERIZONDM\bin\sprtsvc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(iAnywhere Solutions, Inc.) C:\Program Files (x86)\Intuit\QuickBooks Point of Sale 11.0\DatabaseServer\QBDBMgr10.exe
(SupportSoft, Inc.) C:\Program Files (x86)\VERIZONDM\bin\tgsrvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(SupportSoft, Inc.) C:\Program Files (x86)\VERIZONDM\bin\sprtcmd.exe
(Microsoft Corporation) C:\Windows\System32\PrintIsolationHost.exe
(Intuit Inc.) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(SoftThinks SAS) C:\Program Files (x86)\Dell Backup and Recovery\SftService.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Intuit) C:\Program Files (x86)\Intuit\QuickBooks Point of Sale 11.0\QBPOSShell.exe
(Intuit Inc.) C:\Program Files (x86)\Intuit\QuickBooks Point of Sale 11.0\qbpos.exe
(Mesrosift Corporatien) C:\Users\Pink Pineapple\AppData\Roaming\Dayxohup\ocupdu.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Mesrosift Corporatien) C:\Users\Pink Pineapple\AppData\Roaming\Dayxohup\ocupdu.exe
(Mesrosift Corporatien) C:\Users\Pink Pineapple\AppData\Roaming\Dayxohup\ocupdu.exe
(Mesrosift Corporatien) C:\Users\Pink Pineapple\AppData\Roaming\Dayxohup\ocupdu.exe
(Mesrosift Corporatien) C:\Users\Pink Pineapple\AppData\Roaming\Dayxohup\ocupdu.exe
(Mesrosift Corporatien) C:\Users\Pink Pineapple\AppData\Roaming\Dayxohup\ocupdu.exe
(Mesrosift Corporatien) C:\Users\Pink Pineapple\AppData\Roaming\Dayxohup\ocupdu.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7202520 2013-08-19] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1321688 2013-07-29] (Realtek Semiconductor)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2013-04-26] (Intel Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [VERIZONDM] => C:\Program Files (x86)\VERIZONDM\bin\sprtcmd.exe [206120 2011-02-01] (SupportSoft, Inc.)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [EpsonAPD4SV] => C:\Program Files (x86)\EPSON\EPSON Advanced Printer Driver 4\Tools\EAPSV\EAPSV.EXE [210368 2011-06-07] (SEIKO EPSON CORPORATION)
Winlogon\Notify\GoToAssist: C:\Program Files (x86)\Citrix\GoToAssist\896\G2AWinLogon_x64.dll (Citrix Online, a division of Citrix Systems, Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1651070915-2918641539-3955507323-1000\...\Run: [Feuqilik] => C:\Users\Pink Pineapple\AppData\Roaming\Dayxohup\ocupdu.exe [305220 2014-06-27] (Mesrosift Corporatien)
HKU\S-1-5-21-1651070915-2918641539-3955507323-1000\...\Run: [Spotify Web Helper] => C:\Users\Pink Pineapple\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1178168 2014-08-09] (Spotify Ltd)
HKU\S-1-5-21-1651070915-2918641539-3955507323-1000\...\Run: [CtrlIdentities] => "C:\Users\Pink Pineapple\AppData\Roaming\Identities\CtrlIdentities.exe"
Startup: C:\Users\QBPOSDBSrvUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Uninstall SafeKey RunOnce.lnk
ShortcutTarget: Uninstall SafeKey RunOnce.lnk -> C:\Program Files (x86)\Common Files\lpuninstall.exe (McAfee)
ShellIconOverlayIdentifiers: DBARFileBackuped -> {831cebdd-6baf-4432-be76-9e0989c14aef} => C:\Windows\system32\mscoree.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers: DBARFileNotBackuped -> {275e4fd7-21ef-45cf-a836-832e5d2cc1b3} => C:\Windows\system32\mscoree.dll (Microsoft Corporation)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xB558DC5B98BDCF01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - DefaultScope {22512A4C-42B6-4DA7-941B-D39CAEF9A27E} URL = http://search.yahoo.com/search?fr=mcafee&type=A011US0&p={SearchTerms}
SearchScopes: HKCU - {1B46B2DF-1D2F-4B05-BD2D-D8BCDEA0F552} URL = https://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {22512A4C-42B6-4DA7-941B-D39CAEF9A27E} URL = http://search.yahoo.com/search?fr=mcafee&type=A011US0&p={SearchTerms}
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
Handler: qbpos - {662E7FAE-5C17-491C-AD9D-98C1F66CC6A0} -  No File
Handler-x32: qbpos - {662E7FAE-5C17-491C-AD9D-98C1F66CC6A0} - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBPOSProtocol.dll (Intuit Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
 
FireFox:
========
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
Chrome: 
=======
CHR Profile: C:\Users\Pink Pineapple\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Pink Pineapple\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-08-21]
CHR Extension: (Google Drive) - C:\Users\Pink Pineapple\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-08-21]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Pink Pineapple\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-08-25]
CHR Extension: (YouTube) - C:\Users\Pink Pineapple\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-08-21]
CHR Extension: (Google Search) - C:\Users\Pink Pineapple\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-08-21]
CHR Extension: (Google Wallet) - C:\Users\Pink Pineapple\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-08-21]
CHR Extension: (Gmail) - C:\Users\Pink Pineapple\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-08-21]
 
==================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 EPSON_Device_Control_Log_Service; C:\Program Files\epson\portcommunicationservice\DeviceControlLog.exe [395776 2012-11-29] (SEIKO EPSON CORPORATION) [File not signed]
R2 EPSON_Port_Communication_Service; C:\Program Files\epson\portcommunicationservice\PCSVC.exe [586240 2012-11-29] (SEIKO EPSON CORPORATION) [File not signed]
R2 Intel® Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel® Corporation) [File not signed]
S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel® Corporation)
R2 Intuit Entitlement Service v8; C:\Program Files (x86)\Common Files\Intuit\Entitlement Client\v8\Server\Intuit.Spc.Map.EntitlementClient.Server.Service.exe [24680 2011-12-23] (Intuit, Inc.)
S3 InvProtectSvc; C:\Program Files (x86)\Invincea\Enterprise\X64\InvProtectSvc64.exe [2947856 2013-07-30] (Invincea, Inc.)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [169432 2013-08-21] (Intel Corporation)
R2 QBPOSDBServiceV11; C:\Program Files (x86)\Intuit\QuickBooks Point of Sale 11.0\DatabaseServer\QBPOSDBService.exe [3127296 2014-06-11] (Intuit Inc.) [File not signed]
S3 SboxSvc; C:\Program Files (x86)\Invincea\Enterprise\Sandbox\SboxSvc.exe [124616 2013-07-30] ()
R2 SftService; C:\Program Files (x86)\Dell Backup and Recovery\sftservice.exe [1915920 2013-11-21] (SoftThinks SAS)
R2 sprtsvc_verizondm; C:\Program Files (x86)\VERIZONDM\bin\sprtsvc.exe [206120 2011-02-01] (SupportSoft, Inc.)
R2 tgsrvc_verizondm; C:\Program Files (x86)\VERIZONDM\bin\tgsrvc.exe [185640 2011-02-01] (SupportSoft, Inc.)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
S2 EPSON_PCS_Parallel_Port_Driver; C:\Windows\system32\DRIVERS\pcslpt.sys [21640 2012-11-29] (SEIKO EPSON CORPORATION)
R3 IntcAzAudAddService; C:\Windows\System32\drivers\RTDVHD64.sys [2192088 2013-08-23] (Realtek Semiconductor Corp.)
S3 InvProtectDrv; C:\Program Files (x86)\Invincea\Enterprise\X64\InvProtectDrv64.sys [34824 2013-07-30] ()
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-08-21] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [99288 2013-08-21] (Intel Corporation)
S3 SboxDrv; C:\Program Files (x86)\Invincea\Enterprise\Sandbox\SboxDrv.sys [202248 2013-07-30] ()
R3 TMUSB; C:\Windows\System32\DRIVERS\TMUSB64.SYS [63096 2012-03-01] (Seiko Epson Corporation)
U3 catchme; \??\C:\ComboFix\catchme.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
==================== One Month Created Files and Folders ========
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2014-08-27 20:14 - 2014-08-27 20:15 - 00000000 ____D () C:\FRST
2014-08-27 20:06 - 2014-08-27 20:06 - 00016989 _____ () C:\ComboFix.txt
2014-08-27 19:58 - 2014-08-27 19:58 - 00000000 ____D () C:\Windows\erdnt
2014-08-27 19:51 - 2011-06-26 02:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-08-27 19:51 - 2010-11-07 13:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-08-27 19:51 - 2009-04-20 00:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-08-27 19:51 - 2000-08-30 20:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-08-27 19:51 - 2000-08-30 20:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-08-27 19:51 - 2000-08-30 20:00 - 00098816 _____ () C:\Windows\sed.exe
2014-08-27 19:51 - 2000-08-30 20:00 - 00080412 _____ () C:\Windows\grep.exe
2014-08-27 19:51 - 2000-08-30 20:00 - 00068096 _____ () C:\Windows\zip.exe
2014-08-27 19:46 - 2014-08-27 20:06 - 00000000 ____D () C:\Qoobox
2014-08-27 17:32 - 2014-08-27 20:15 - 00000000 ____D () C:\Users\Pink Pineapple\Desktop\Dont Delete For Virus Removal
2014-08-27 17:15 - 2014-08-27 17:15 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
2014-08-26 17:17 - 2014-08-26 17:17 - 00001180 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 9.lnk
2014-08-26 17:17 - 2014-08-26 17:17 - 00001168 _____ () C:\Users\Public\Desktop\TeamViewer 9.lnk
2014-08-26 17:16 - 2014-08-26 17:16 - 00000000 ____D () C:\Program Files (x86)\TeamViewer
2014-08-24 08:10 - 2014-08-27 20:00 - 00000860 _____ () C:\Windows\Tasks\Security Center Update - 1163631284.job
2014-08-24 08:10 - 2014-08-24 08:10 - 00003886 _____ () C:\Windows\System32\Tasks\Security Center Update - 1163631284
2014-08-24 08:10 - 2014-08-24 08:10 - 00000000 ____D () C:\Users\Pink Pineapple\AppData\Roaming\Dayxohup
2014-08-24 08:06 - 2014-08-27 00:55 - 00000000 ____D () C:\ProgramData\Windows Genuine Advantage
2014-08-22 09:22 - 2014-08-27 17:15 - 00000981 _____ () C:\Windows\setupact.log
2014-08-22 09:22 - 2014-08-22 09:22 - 00000316 _____ () C:\Windows\PFRO.log
2014-08-22 09:22 - 2014-08-22 09:22 - 00000000 _____ () C:\Windows\setuperr.log
2014-08-21 21:23 - 2014-08-21 21:23 - 00002220 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-08-21 21:23 - 2014-08-21 21:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-08-21 21:22 - 2014-08-27 19:27 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-08-21 21:22 - 2014-08-27 08:54 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-08-21 21:22 - 2014-08-21 21:23 - 00000000 ____D () C:\Users\Pink Pineapple\AppData\Local\Google
2014-08-21 21:22 - 2014-08-21 21:22 - 00003894 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-08-21 21:22 - 2014-08-21 21:22 - 00003642 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-08-21 21:22 - 2014-08-21 21:22 - 00000000 ____D () C:\Program Files (x86)\Google
2014-08-21 21:04 - 2014-08-21 21:04 - 00000404 _____ () C:\Users\Pink Pineapple\Desktop\Local Area Connection - Shortcut.lnk
2014-08-21 19:50 - 2014-08-21 21:32 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-08-21 19:50 - 2014-08-21 19:50 - 00001108 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-08-21 19:50 - 2014-08-21 19:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-08-21 19:50 - 2014-08-21 19:50 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-08-21 19:50 - 2014-08-21 19:50 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-08-21 19:50 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-08-21 19:50 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-08-21 19:50 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-08-21 19:44 - 2014-08-21 19:44 - 00000000 ____D () C:\Program Files\CCleaner
2014-08-21 19:35 - 2014-08-21 21:21 - 00000000 ___RD () C:\Users\Pink Pineapple\Tools
2014-08-21 12:10 - 2014-08-21 21:02 - 00000000 ____D () C:\Users\Pink Pineapple\Documents\McAfee Vaults
2014-08-21 10:17 - 2014-08-21 10:17 - 00000000 ____D () C:\Quarantine
2014-08-21 10:16 - 2014-08-21 10:16 - 00000000 ____D () C:\mfe
2014-08-21 10:10 - 2014-08-21 10:19 - 00000000 ____D () C:\Program Files\stinger
2014-08-21 10:08 - 2014-08-21 21:11 - 00000000 ____D () C:\ProgramData\McAfee
2014-08-19 03:03 - 2014-05-14 12:23 - 02477536 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-08-19 03:03 - 2014-05-14 12:23 - 00700384 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-08-19 03:03 - 2014-05-14 12:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2014-08-19 03:03 - 2014-05-14 12:23 - 00058336 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-08-19 03:03 - 2014-05-14 12:23 - 00044512 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2014-08-19 03:03 - 2014-05-14 12:23 - 00038880 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2014-08-19 03:03 - 2014-05-14 12:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2014-08-19 03:03 - 2014-05-14 12:21 - 02620928 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-08-19 03:03 - 2014-05-14 12:20 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-08-19 03:03 - 2014-05-14 12:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2014-08-19 03:03 - 2014-05-14 09:23 - 00198600 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-08-19 03:03 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2014-08-19 03:03 - 2014-05-14 09:20 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-08-19 03:03 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2014-08-14 03:01 - 2014-06-30 18:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2014-08-14 03:01 - 2014-06-30 18:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll
2014-08-14 03:01 - 2014-03-09 17:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2014-08-14 03:01 - 2014-03-09 17:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2014-08-14 03:01 - 2014-03-09 17:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe
2014-08-14 03:01 - 2014-03-09 17:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll
2014-08-14 03:00 - 2014-06-06 02:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2014-08-14 03:00 - 2014-06-06 02:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2014-08-13 05:06 - 2014-07-31 19:16 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-08-13 05:06 - 2014-07-25 10:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-08-13 05:06 - 2014-07-25 09:51 - 17524224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-08-13 05:06 - 2014-07-25 09:28 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-08-13 05:06 - 2014-07-25 09:10 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-08-13 05:06 - 2014-07-25 08:34 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-08-13 05:06 - 2014-07-25 08:33 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-08-13 05:06 - 2014-07-25 08:28 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-08-13 05:06 - 2014-07-25 08:21 - 02184704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-08-13 05:06 - 2014-07-25 08:17 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-08-13 05:06 - 2014-07-25 08:08 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-08-13 05:06 - 2014-07-25 07:52 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-08-13 05:06 - 2014-07-25 07:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-08-13 05:06 - 2014-07-25 07:42 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-08-13 05:06 - 2014-07-25 07:34 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-08-13 05:06 - 2014-07-25 07:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-08-13 05:06 - 2014-07-25 07:07 - 02001920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-08-13 05:06 - 2014-07-25 06:26 - 01431040 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-08-13 05:06 - 2014-07-25 06:00 - 01169920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-08-13 05:06 - 2014-07-15 23:25 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-13 05:06 - 2014-07-15 23:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-08-13 05:06 - 2014-07-15 22:46 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-13 05:06 - 2014-07-15 22:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-08-13 05:06 - 2014-07-15 22:12 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-13 05:06 - 2014-07-08 22:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL
2014-08-13 05:06 - 2014-07-08 22:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL
2014-08-13 05:06 - 2014-07-08 22:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL
2014-08-13 05:06 - 2014-07-08 22:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL
2014-08-13 05:06 - 2014-07-08 22:03 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL
2014-08-13 05:06 - 2014-07-08 21:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDYAK.DLL
2014-08-13 05:06 - 2014-07-08 21:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTAT.DLL
2014-08-13 05:06 - 2014-07-08 21:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU1.DLL
2014-08-13 05:06 - 2014-07-08 21:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU.DLL
2014-08-13 05:06 - 2014-07-08 21:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDBASH.DLL
2014-08-13 05:06 - 2014-07-08 18:38 - 00419992 _____ () C:\Windows\system32\locale.nls
2014-08-13 05:06 - 2014-07-08 18:30 - 00419992 _____ () C:\Windows\SysWOW64\locale.nls
2014-08-13 05:06 - 2014-06-24 22:05 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-08-13 05:06 - 2014-06-24 21:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-08-13 05:06 - 2014-06-15 22:10 - 00985536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-08-13 05:06 - 2014-06-03 06:02 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-08-13 05:06 - 2014-06-03 06:02 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-08-13 05:06 - 2014-06-03 06:02 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2014-08-13 05:06 - 2014-06-03 06:02 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-08-13 05:06 - 2014-06-03 05:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-08-13 05:06 - 2014-06-03 05:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-08-13 05:06 - 2014-06-03 05:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2014-08-13 05:05 - 2014-07-31 19:41 - 00348856 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-08-13 05:05 - 2014-07-25 10:52 - 23645696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-08-13 05:05 - 2014-07-25 10:01 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-08-13 05:05 - 2014-07-25 09:30 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-08-13 05:05 - 2014-07-25 09:28 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-08-13 05:05 - 2014-07-25 09:25 - 02774528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-08-13 05:05 - 2014-07-25 09:25 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-08-13 05:05 - 2014-07-25 09:11 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-08-13 05:05 - 2014-07-25 09:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-08-13 05:05 - 2014-07-25 09:03 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-08-13 05:05 - 2014-07-25 09:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-08-13 05:05 - 2014-07-25 09:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-08-13 05:05 - 2014-07-25 08:59 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-08-13 05:05 - 2014-07-25 08:47 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-08-13 05:05 - 2014-07-25 08:40 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-08-13 05:05 - 2014-07-25 08:34 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-08-13 05:05 - 2014-07-25 08:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-08-13 05:05 - 2014-07-25 08:28 - 05824512 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-08-13 05:05 - 2014-07-25 08:19 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-08-13 05:05 - 2014-07-25 08:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-08-13 05:05 - 2014-07-25 08:17 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-08-13 05:05 - 2014-07-25 08:12 - 00438784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-08-13 05:05 - 2014-07-25 08:10 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-08-13 05:05 - 2014-07-25 08:10 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-08-13 05:05 - 2014-07-25 08:06 - 04204032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-08-13 05:05 - 2014-07-25 07:47 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-08-13 05:05 - 2014-07-25 07:39 - 02087936 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-08-13 05:05 - 2014-07-25 07:39 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-08-13 05:05 - 2014-07-25 07:36 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-08-13 05:05 - 2014-07-25 07:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-08-13 05:05 - 2014-07-25 07:23 - 13547008 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-08-13 05:05 - 2014-07-25 07:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-08-13 05:05 - 2014-07-25 07:03 - 11772928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-08-13 05:05 - 2014-07-25 06:52 - 02266624 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-08-13 05:05 - 2014-07-25 06:17 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-08-13 05:05 - 2014-07-25 06:09 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-08-13 05:05 - 2014-07-25 06:05 - 01792512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-08-13 05:03 - 2014-08-06 22:06 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-08-13 05:03 - 2014-08-06 22:01 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-08-13 05:03 - 2014-07-13 22:02 - 01216000 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2014-08-13 05:03 - 2014-07-13 21:40 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2014-08-11 19:26 - 2014-08-14 03:06 - 00000000 ____D () C:\Windows\system32\MRT
2014-08-11 19:26 - 2014-08-14 03:04 - 99218768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-08-09 16:26 - 2014-08-09 16:27 - 05155464 _____ (McAfee, Inc.) C:\Users\Pink Pineapple\Desktop\McAfeeSetup-AutoLogin_exe
2014-08-09 16:24 - 2014-08-09 16:27 - 05155464 _____ (McAfee, Inc.) C:\Users\Pink Pineapple\Downloads\McAfeeSetup-AutoLogin_exe (4)
2014-08-09 16:17 - 2014-08-09 16:17 - 00000000 _____ () C:\Users\Pink Pineapple\Desktop\McAfeeSetup-AutoLogin_exe.os40w69.partial
2014-08-09 16:10 - 2014-08-09 16:10 - 00000000 ____D () C:\ProgramData\Citrix
2014-08-09 16:06 - 2014-08-21 11:01 - 00000000 ____D () C:\Users\Pink Pineapple\AppData\Local\Deployment
2014-08-09 16:06 - 2014-08-09 16:06 - 00000000 ____D () C:\Users\Pink Pineapple\AppData\Local\Citrix
2014-08-09 16:06 - 2014-08-09 16:06 - 00000000 ____D () C:\Users\Pink Pineapple\AppData\Local\Apps\2.0
2014-08-09 16:06 - 2014-08-09 16:06 - 00000000 ____D () C:\Program Files (x86)\Citrix
2014-08-09 16:02 - 2014-08-09 16:03 - 05155464 _____ (McAfee, Inc.) C:\Users\Pink Pineapple\Downloads\McAfeeSetup-AutoLogin_exe
2014-08-09 15:58 - 2014-08-09 15:58 - 05155464 _____ (McAfee, Inc.) C:\Users\Pink Pineapple\Downloads\McAfeeSetup-AutoLogin_exe (3)
2014-08-09 15:58 - 2014-08-09 15:58 - 05155464 _____ (McAfee, Inc.) C:\Users\Pink Pineapple\Downloads\McAfeeSetup-AutoLogin_exe (2)
2014-08-09 15:57 - 2014-08-09 15:57 - 05155464 _____ (McAfee, Inc.) C:\Users\Pink Pineapple\Downloads\McAfeeSetup-AutoLogin_exe (1)
2014-08-09 15:33 - 2014-08-09 15:33 - 00002790 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-08-09 10:00 - 2014-08-20 22:07 - 00000000 ____D () C:\Users\Pink Pineapple\AppData\Local\Spotify
2014-08-09 10:00 - 2014-08-09 10:00 - 00001859 _____ () C:\Users\Pink Pineapple\Desktop\Spotify.lnk
2014-08-09 10:00 - 2014-08-09 10:00 - 00001845 _____ () C:\Users\Pink Pineapple\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2014-08-09 09:59 - 2014-08-25 14:28 - 00000000 ____D () C:\Users\Pink Pineapple\AppData\Roaming\Spotify
2014-08-07 19:59 - 2014-08-07 19:59 - 00004104 _____ () C:\Windows\System32\Tasks\{AFEF17D4-8F2C-D2BB-4A4F-4DB4B9C47D82}
2014-08-04 12:25 - 2014-08-04 12:25 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
 
==================== One Month Modified Files and Folders =======
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2014-08-27 20:15 - 2014-08-27 20:14 - 00000000 ____D () C:\FRST
2014-08-27 20:15 - 2014-08-27 17:32 - 00000000 ____D () C:\Users\Pink Pineapple\Desktop\Dont Delete For Virus Removal
2014-08-27 20:09 - 2013-11-06 22:16 - 02031500 _____ () C:\Windows\WindowsUpdate.log
2014-08-27 20:06 - 2014-08-27 20:06 - 00016989 _____ () C:\ComboFix.txt
2014-08-27 20:06 - 2014-08-27 19:46 - 00000000 ____D () C:\Qoobox
2014-08-27 20:06 - 2009-07-13 23:20 - 00000000 __RHD () C:\Users\Default
2014-08-27 20:00 - 2014-08-24 08:10 - 00000860 _____ () C:\Windows\Tasks\Security Center Update - 1163631284.job
2014-08-27 19:58 - 2014-08-27 19:58 - 00000000 ____D () C:\Windows\erdnt
2014-08-27 19:58 - 2014-04-03 11:07 - 00000000 ____D () C:\Users\Pink Pineapple
2014-08-27 19:58 - 2009-07-13 22:34 - 00000215 _____ () C:\Windows\system.ini
2014-08-27 19:40 - 2014-04-17 09:38 - 00000000 ____D () C:\Users\Pink Pineapple\AppData\Local\CrashDumps
2014-08-27 19:27 - 2014-08-21 21:22 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-08-27 19:27 - 2013-11-06 20:21 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-08-27 17:18 - 2009-07-14 01:13 - 00781790 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-08-27 17:15 - 2014-08-27 17:15 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
2014-08-27 17:15 - 2014-08-22 09:22 - 00000981 _____ () C:\Windows\setupact.log
2014-08-27 08:54 - 2014-08-21 21:22 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-08-27 07:58 - 2009-07-14 00:45 - 00031312 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-08-27 07:58 - 2009-07-14 00:45 - 00031312 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-08-27 07:57 - 2013-11-06 20:32 - 00000000 ____D () C:\Program Files (x86)\Dell Backup and Recovery
2014-08-27 07:50 - 2014-04-03 10:48 - 00058408 _____ () C:\Users\Pink Pineapple\AppData\Local\GDIPFONTCACHEV1.DAT
2014-08-27 07:47 - 2009-07-14 01:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-08-27 07:47 - 2009-07-14 00:45 - 00277560 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-08-27 00:55 - 2014-08-24 08:06 - 00000000 ____D () C:\ProgramData\Windows Genuine Advantage
2014-08-26 17:17 - 2014-08-26 17:17 - 00001180 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 9.lnk
2014-08-26 17:17 - 2014-08-26 17:17 - 00001168 _____ () C:\Users\Public\Desktop\TeamViewer 9.lnk
2014-08-26 17:16 - 2014-08-26 17:16 - 00000000 ____D () C:\Program Files (x86)\TeamViewer
2014-08-25 14:28 - 2014-08-09 09:59 - 00000000 ____D () C:\Users\Pink Pineapple\AppData\Roaming\Spotify
2014-08-24 20:15 - 2014-04-13 15:19 - 00000127 _____ () C:\Users\Pink Pineapple\Documents\reprev.opt
2014-08-24 08:10 - 2014-08-24 08:10 - 00003886 _____ () C:\Windows\System32\Tasks\Security Center Update - 1163631284
2014-08-24 08:10 - 2014-08-24 08:10 - 00000000 ____D () C:\Users\Pink Pineapple\AppData\Roaming\Dayxohup
2014-08-22 09:59 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\rescache
2014-08-22 09:22 - 2014-08-22 09:22 - 00000316 _____ () C:\Windows\PFRO.log
2014-08-22 09:22 - 2014-08-22 09:22 - 00000000 _____ () C:\Windows\setuperr.log
2014-08-21 21:32 - 2014-08-21 19:50 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-08-21 21:23 - 2014-08-21 21:23 - 00002220 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-08-21 21:23 - 2014-08-21 21:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-08-21 21:23 - 2014-08-21 21:22 - 00000000 ____D () C:\Users\Pink Pineapple\AppData\Local\Google
2014-08-21 21:22 - 2014-08-21 21:22 - 00003894 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-08-21 21:22 - 2014-08-21 21:22 - 00003642 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-08-21 21:22 - 2014-08-21 21:22 - 00000000 ____D () C:\Program Files (x86)\Google
2014-08-21 21:21 - 2014-08-21 19:35 - 00000000 ___RD () C:\Users\Pink Pineapple\Tools
2014-08-21 21:11 - 2014-08-21 10:08 - 00000000 ____D () C:\ProgramData\McAfee
2014-08-21 21:04 - 2014-08-21 21:04 - 00000404 _____ () C:\Users\Pink Pineapple\Desktop\Local Area Connection - Shortcut.lnk
2014-08-21 21:02 - 2014-08-21 12:10 - 00000000 ____D () C:\Users\Pink Pineapple\Documents\McAfee Vaults
2014-08-21 20:19 - 2014-07-09 15:38 - 00000000 ____D () C:\Program Files (x86)\Movies Toolbar
2014-08-21 19:50 - 2014-08-21 19:50 - 00001108 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-08-21 19:50 - 2014-08-21 19:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-08-21 19:50 - 2014-08-21 19:50 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-08-21 19:50 - 2014-08-21 19:50 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-08-21 19:44 - 2014-08-21 19:44 - 00000000 ____D () C:\Program Files\CCleaner
2014-08-21 11:01 - 2014-08-09 16:06 - 00000000 ____D () C:\Users\Pink Pineapple\AppData\Local\Deployment
2014-08-21 10:19 - 2014-08-21 10:10 - 00000000 ____D () C:\Program Files\stinger
2014-08-21 10:17 - 2014-08-21 10:17 - 00000000 ____D () C:\Quarantine
2014-08-21 10:16 - 2014-08-21 10:16 - 00000000 ____D () C:\mfe
2014-08-21 10:16 - 2009-07-14 00:54 - 00000749 ___RH () C:\Windows\WindowsShell.Manifest
2014-08-21 10:16 - 2009-07-13 23:20 - 00000000 __RHD () C:\Users\Public\Libraries
2014-08-20 22:07 - 2014-08-09 10:00 - 00000000 ____D () C:\Users\Pink Pineapple\AppData\Local\Spotify
2014-08-14 03:27 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-08-14 03:06 - 2014-08-11 19:26 - 00000000 ____D () C:\Windows\system32\MRT
2014-08-14 03:04 - 2014-08-11 19:26 - 99218768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-08-14 03:00 - 2014-05-07 03:00 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-08-09 16:27 - 2014-08-09 16:26 - 05155464 _____ (McAfee, Inc.) C:\Users\Pink Pineapple\Desktop\McAfeeSetup-AutoLogin_exe
2014-08-09 16:27 - 2014-08-09 16:24 - 05155464 _____ (McAfee, Inc.) C:\Users\Pink Pineapple\Downloads\McAfeeSetup-AutoLogin_exe (4)
2014-08-09 16:17 - 2014-08-09 16:17 - 00000000 _____ () C:\Users\Pink Pineapple\Desktop\McAfeeSetup-AutoLogin_exe.os40w69.partial
2014-08-09 16:10 - 2014-08-09 16:10 - 00000000 ____D () C:\ProgramData\Citrix
2014-08-09 16:06 - 2014-08-09 16:06 - 00000000 ____D () C:\Users\Pink Pineapple\AppData\Local\Citrix
2014-08-09 16:06 - 2014-08-09 16:06 - 00000000 ____D () C:\Users\Pink Pineapple\AppData\Local\Apps\2.0
2014-08-09 16:06 - 2014-08-09 16:06 - 00000000 ____D () C:\Program Files (x86)\Citrix
2014-08-09 16:03 - 2014-08-09 16:02 - 05155464 _____ (McAfee, Inc.) C:\Users\Pink Pineapple\Downloads\McAfeeSetup-AutoLogin_exe
2014-08-09 16:01 - 2010-11-21 03:16 - 00000000 ___RD () C:\Users\Public\Recorded TV
2014-08-09 15:58 - 2014-08-09 15:58 - 05155464 _____ (McAfee, Inc.) C:\Users\Pink Pineapple\Downloads\McAfeeSetup-AutoLogin_exe (3)
2014-08-09 15:58 - 2014-08-09 15:58 - 05155464 _____ (McAfee, Inc.) C:\Users\Pink Pineapple\Downloads\McAfeeSetup-AutoLogin_exe (2)
2014-08-09 15:57 - 2014-08-09 15:57 - 05155464 _____ (McAfee, Inc.) C:\Users\Pink Pineapple\Downloads\McAfeeSetup-AutoLogin_exe (1)
2014-08-09 15:35 - 2011-02-10 10:25 - 00000000 ____D () C:\Windows\panther
2014-08-09 15:33 - 2014-08-09 15:33 - 00002790 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-08-09 10:00 - 2014-08-09 10:00 - 00001859 _____ () C:\Users\Pink Pineapple\Desktop\Spotify.lnk
2014-08-09 10:00 - 2014-08-09 10:00 - 00001845 _____ () C:\Users\Pink Pineapple\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2014-08-07 19:59 - 2014-08-07 19:59 - 00004104 _____ () C:\Windows\System32\Tasks\{AFEF17D4-8F2C-D2BB-4A4F-4DB4B9C47D82}
2014-08-07 19:59 - 2010-11-21 03:06 - 00000000 ____D () C:\Windows\SysWOW64\sysprep
2014-08-06 22:06 - 2014-08-13 05:03 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-08-06 22:01 - 2014-08-13 05:03 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-08-05 09:20 - 2010-11-20 23:27 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-08-04 12:25 - 2014-08-04 12:25 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2014-07-31 19:41 - 2014-08-13 05:05 - 00348856 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-07-31 19:16 - 2014-08-13 05:06 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2014-08-17 22:27
 
==================== End Of Log ============================
 
ADDITION:::
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 25-08-2014
Ran by Pink Pineapple at 2014-08-27 20:16:21
Running from C:\Users\Pink Pineapple\Desktop\Dont Delete For Virus Removal
Boot Mode: Normal
==========================================================
 
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe Flash Player 11 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 11.8.800.94 - Adobe Systems Incorporated)
Adobe Reader XI  MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AB0000000001}) (Version: 11.0.00 - Adobe Systems Incorporated)
CCleaner (HKLM\...\CCleaner) (Version: 4.16 - Piriform)
Dell Backup and Recovery - Support Software (HKLM-x32\...\{A9668246-FB70-4103-A1E3-66C9BC2EFB49}) (Version: 1.6.2.4 - Dell Inc.)
Dell Backup and Recovery (HKLM-x32\...\{0ED7EE95-6A97-47AA-AD73-152C08A15B04}) (Version: 1.6.2.4 - Dell Inc.)
Dell Client System Update (HKLM-x32\...\{04566294-A6B6-4462-9721-031073EB3694}) (Version: 1.3.0 - Dell Inc.)
Dell Edoc Viewer (HKLM\...\{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}) (Version: 1.0.0 - Dell Inc)
Dell Protected Workspace (HKLM-x32\...\{E2CAA395-66B3-4772-85E3-6134DBAB244E}) (Version: 2.3.15835 - Invincea, Inc.)
EPSON Advanced Printer Driver 4 (HKLM-x32\...\{11FF6AF6-0141-4EF8-829A-989459A1E5D8}) (Version: 4.54.0100 - SEIKO EPSON CORPORATION)
EPSON APD4 Point and Print Support (x32 Version: 4.54.0100 - SEIKO EPSON CORPORATION) Hidden
EPSON Port Communication Service (HKLM\...\{30B2BE6A-6CF6-434A-A737-8B9873033DD1}) (Version: 3.6.0 - SEIKO EPSON CORPORATION)
EPSON TM Coupon Package (HKLM-x32\...\{60ED98A7-BE97-4F26-B32E-5087337C6044}) (Version: 1.20.0000 - Seiko Epson Corporation) <==== ATTENTION
Google Chrome (HKLM-x32\...\{E2FA067B-11BC-318B-B325-31127E6243F5}) (Version: 65.240.16527 - Google, Inc.)
Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden
GoToAssist Corporate (HKLM-x32\...\GoToAssist) (Version: 10.4.0.896 - Citrix Online, a division of Citrix Systems, Inc.)
InstPortMon (x32 Version: 1.1.0.0 - InstPortMon) Hidden
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.13.1706 - Intel Corporation)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.18.10.3234 - Intel Corporation)
Intel® USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 2.5.0.19 - Intel Corporation)
Intel® Trusted Connect Service Client (Version: 1.28.487.1 - Intel Corporation) Hidden
Malwarebytes Anti-Malware version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Mouse and Keyboard Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 2.2.173.0 - Microsoft Corporation)
Microsoft Mouse and Keyboard Center (Version: 2.2.173.0 - Microsoft Corporation) Hidden
Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4454.1510 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
QuickBooks Point of Sale 2013 (HKLM-x32\...\{2F6FE8E0-A61C-4C2D-A601-F5731D8F7EF0}) (Version: 22.11.610 - Intuit Inc.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5987 - Realtek Semiconductor Corp.)
Spotify (HKCU\...\Spotify) (Version: 0.9.11.27.g2b1a638c - Spotify AB)
TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.31064 - TeamViewer)
Verizon Download Manager (HKLM-x32\...\{D547A594-AA85-4B92-80EB-47B371B98C68}) (Version: 12 - SupportSoft)
Verizon High Speed Internet (HKLM-x32\...\Verizon High Speed Internet_is1) (Version:  - Verizon)
 
==================== Custom CLSID (selected items): ==========================
 
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
 
 
==================== Restore Points  =========================
 
22-08-2014 11:03:58 Windows Update
26-08-2014 07:54:38 Windows Update
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 22:34 - 2014-08-27 19:58 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost
 
==================== Scheduled Tasks (whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
 
Task: {017D8F8D-6AC1-4F81-87CB-628F78EE2B96} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-08-21] (Google Inc.)
Task: {21623572-B1F8-440F-A7BF-5C28F6596E57} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-08-21] (Google Inc.)
Task: {69A864CD-2EA8-4BD9-B287-CF745818A807} - System32\Tasks\{AFEF17D4-8F2C-D2BB-4A4F-4DB4B9C47D82} => C:\Users\Pink Pineapple\AppData\Roaming\koulrv.dll/s "C:\Users\Pink Pineapple\AppData\Roaming\koulrv.dll"
Task: {900F2E41-DF2D-4513-BF97-8DBACBBA7622} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-11-06] (Adobe Systems Incorporated)
Task: {972AD2DB-C26B-4057-A122-335F1C109207} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2013-05-13] (Microsoft)
Task: {AB63A8E7-F433-46CF-AB5D-5B70429C6E9F} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-05-13] (Microsoft Corporation)
Task: {B5D1643D-E75A-4D91-8145-A95DDD14B21F} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-05-13] (Microsoft Corporation)
Task: {C05B7122-5244-424F-8FD0-C78BEC308D47} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-05-13] (Microsoft Corporation)
Task: {C2AD6A69-616C-43CF-917E-1013E93E3A01} - System32\Tasks\Security Center Update - 1163631284 => C:\Users\Pink Pineapple\AppData\Roaming\Dayxohup\ocupdu.exe [2014-06-27] (Mesrosift Corporatien)
Task: {CB202C73-9B5E-46F5-95F8-610B581C769B} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-05-13] (Microsoft Corporation)
Task: {DE56C21A-F377-46BC-AF35-F765D12FA602} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-07-23] (Piriform Ltd)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\Security Center Update - 1163631284.job => C:\Users\Pink Pineapple\AppData\Roaming\Dayxohup\ocupdu.exe <==== ATTENTION
 
==================== Loaded Modules (whitelisted) =============
 
2013-11-06 20:32 - 2013-08-19 12:21 - 00020256 _____ () C:\Program Files (x86)\Dell Backup and Recovery\Components\Shell\DBROverlayIcon.dll
2013-11-06 20:32 - 2013-08-19 12:21 - 00019232 _____ () C:\Program Files (x86)\Dell Backup and Recovery\Components\Shell\DBROverlayNotBackuped.dll
2013-11-06 20:32 - 2013-08-19 12:21 - 00035104 _____ () C:\Program Files (x86)\Dell Backup and Recovery\Components\Shell\DBRShellExtension.dll
2013-11-06 20:25 - 2013-08-21 19:33 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\ACE.dll
 
==================== Alternate Data Streams (whitelisted) =========
 
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
 
AlternateDataStreams: C:\Windows\SysWOW64\MSIHANDLE:3204
AlternateDataStreams: C:\Windows\SysWOW64\MSIHANDLE:3247
AlternateDataStreams: C:\Windows\SysWOW64\MSIHANDLE:3348
 
==================== Safe Mode (whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\GoToAssist => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
 
==================== EXE Association (whitelisted) =============
 
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
 
 
==================== MSCONFIG/TASK MANAGER disabled items =========
 
(Currently there is no automatic fix for this section.)
 
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (08/27/2014 07:40:32 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: svchost.exe, version: 6.1.7600.16385, time stamp: 0x4a5bc3c1
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x0000000000000000
Faulting process id: 0x1b04
Faulting application start time: 0xsvchost.exe0
Faulting application path: svchost.exe1
Faulting module path: svchost.exe2
Report Id: svchost.exe3
 
Error: (08/27/2014 05:53:22 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: QBPOSShell.exe, version: 22.0.11.610, time stamp: 0x53983258
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x00490374
Faulting process id: 0x33f0
Faulting application start time: 0xQBPOSShell.exe0
Faulting application path: QBPOSShell.exe1
Faulting module path: QBPOSShell.exe2
Report Id: QBPOSShell.exe3
 
Error: (08/27/2014 05:51:52 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: QBPOSShell.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.NullReferenceException
Stack:
   at QBPOSShell.App.OnExit(System.Windows.ExitEventArgs)
   at System.Windows.Application.DoShutdown()
   at System.Windows.Application.ShutdownImpl()
   at System.Windows.Application.ShutdownCallback(System.Object)
   at System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32)
   at MS.Internal.Threading.ExceptionFilterHelper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate)
   at System.Windows.Threading.DispatcherOperation.InvokeImpl()
   at System.Windows.Threading.DispatcherOperation.InvokeInSecurityContext(System.Object)
   at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object)
   at System.Windows.Threading.DispatcherOperation.Invoke()
   at System.Windows.Threading.Dispatcher.ProcessQueue()
   at System.Windows.Threading.Dispatcher.WndProcHook(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
   at MS.Win32.HwndWrapper.WndProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
   at MS.Win32.HwndSubclass.DispatcherCallbackOperation(System.Object)
   at System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32)
   at MS.Internal.Threading.ExceptionFilterHelper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate)
   at System.Windows.Threading.Dispatcher.LegacyInvokeImpl(System.Windows.Threading.DispatcherPriority, System.TimeSpan, System.Delegate, System.Object, Int32)
   at MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr)
   at MS.Win32.UnsafeNativeMethods.DispatchMessage(System.Windows.Interop.MSG ByRef)
   at System.Windows.Threading.Dispatcher.PushFrameImpl(System.Windows.Threading.DispatcherFrame)
   at System.Windows.Threading.Dispatcher.PushFrame(System.Windows.Threading.DispatcherFrame)
   at System.Windows.Threading.Dispatcher.Run()
   at System.Windows.Application.RunDispatcher(System.Object)
   at System.Windows.Application.RunInternal(System.Windows.Window)
   at System.Windows.Application.Run(System.Windows.Window)
   at QBPOSShell.App.Main()
 
Error: (08/27/2014 11:31:32 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: svchost.exe, version: 6.1.7600.16385, time stamp: 0x4a5bc3c1
Faulting module name: ieframe.dll, version: 11.0.9600.17239, time stamp: 0x53d23dac
Exception code: 0xc0000005
Fault offset: 0x00000000000039c3
Faulting process id: 0x10c4
Faulting application start time: 0xsvchost.exe0
Faulting application path: svchost.exe1
Faulting module path: svchost.exe2
Report Id: svchost.exe3
 
Error: (08/27/2014 09:20:42 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: svchost.exe, version: 6.1.7600.16385, time stamp: 0x4a5bc3c1
Faulting module name: MSHTML.dll, version: 11.0.9600.17239, time stamp: 0x53d26d9d
Exception code: 0xc00000fd
Fault offset: 0x00000000005d9552
Faulting process id: 0x26ac
Faulting application start time: 0xsvchost.exe0
Faulting application path: svchost.exe1
Faulting module path: svchost.exe2
Report Id: svchost.exe3
 
Error: (08/27/2014 08:05:08 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: ocupdu.exe, version: 0.4.35190.17062, time stamp: 0x53d75949
Faulting module name: Flash32_11_8_800_94.ocx, version: 11.8.800.94, time stamp: 0x51c4d6e5
Exception code: 0xc0000005
Fault offset: 0x0059e199
Faulting process id: 0x1bc0
Faulting application start time: 0xocupdu.exe0
Faulting application path: ocupdu.exe1
Faulting module path: ocupdu.exe2
Report Id: ocupdu.exe3
 
Error: (08/27/2014 07:49:07 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/27/2014 00:56:16 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: msiexec.exe, version: 1.0.0.1, time stamp: 0x01a31ab5
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x00000000
Faulting process id: 0x1804
Faulting application start time: 0xmsiexec.exe0
Faulting application path: msiexec.exe1
Faulting module path: msiexec.exe2
Report Id: msiexec.exe3
 
Error: (08/26/2014 08:14:09 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: iexplore.exe, version: 11.0.9600.17239, time stamp: 0x4a5bc6b7
Faulting module name: MSHTML.dll, version: 11.0.9600.17239, time stamp: 0x53d26078
Exception code: 0xc0000005
Fault offset: 0x00136cef
Faulting process id: 0x3d60
Faulting application start time: 0xiexplore.exe0
Faulting application path: iexplore.exe1
Faulting module path: iexplore.exe2
Report Id: iexplore.exe3
 
Error: (08/26/2014 07:55:32 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: svchost.exe, version: 6.1.7600.16385, time stamp: 0x4a5bc3c1
Faulting module name: Flash64_11_8_800_94.ocx, version: 11.8.800.94, time stamp: 0x51c4d3ca
Exception code: 0xc0000005
Fault offset: 0x00000000002ea204
Faulting process id: 0x46f0
Faulting application start time: 0xsvchost.exe0
Faulting application path: svchost.exe1
Faulting module path: svchost.exe2
Report Id: svchost.exe3
 
 
System errors:
=============
Error: (08/27/2014 07:58:19 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: The PEVSystemStart service is marked as an interactive service.  However, the system is configured to not allow interactive services.  This service may not function properly.
 
Error: (08/27/2014 07:58:02 PM) (Source: Application Popup) (EventID: 1060) (User: )
Description: \??\C:\ComboFix\catchme.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
 
Error: (08/27/2014 07:56:37 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: The PEVSystemStart service is marked as an interactive service.  However, the system is configured to not allow interactive services.  This service may not function properly.
 
Error: (08/27/2014 06:22:00 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the TeamViewer9 service.
 
Error: (08/27/2014 06:19:03 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the TeamViewer9 service.
 
Error: (08/27/2014 05:16:35 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
 
Error: (08/27/2014 01:57:44 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 43. The internal error state is 252.
 
Error: (08/27/2014 07:47:07 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The EPSON PCS Parallel Port Driver service failed to start due to the following error: 
%%20
 
Error: (08/27/2014 07:47:01 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 7:44:20 AM on ‎8/‎27/‎2014 was unexpected.
 
Error: (08/27/2014 04:23:39 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF}
 
 
Microsoft Office Sessions:
=========================
Error: (08/27/2014 07:40:32 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: svchost.exe6.1.7600.163854a5bc3c1unknown0.0.0.000000000c000000500000000000000001b0401cfc24fd504b755C:\Windows\System32\svchost.exeunknown88259dee-2e43-11e4-bd90-c81f6624b774
 
Error: (08/27/2014 05:53:22 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: QBPOSShell.exe22.0.11.61053983258unknown0.0.0.000000000c00000050049037433f001cfc23ff94edc3cC:\Program Files (x86)\Intuit\QuickBooks Point of Sale 11.0\QBPOSShell.exeunknown8ff441ac-2e34-11e4-bd90-c81f6624b774
 
Error: (08/27/2014 05:51:52 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: QBPOSShell.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.NullReferenceException
Stack:
   at QBPOSShell.App.OnExit(System.Windows.ExitEventArgs)
   at System.Windows.Application.DoShutdown()
   at System.Windows.Application.ShutdownImpl()
   at System.Windows.Application.ShutdownCallback(System.Object)
   at System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32)
   at MS.Internal.Threading.ExceptionFilterHelper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate)
   at System.Windows.Threading.DispatcherOperation.InvokeImpl()
   at System.Windows.Threading.DispatcherOperation.InvokeInSecurityContext(System.Object)
   at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object)
   at System.Windows.Threading.DispatcherOperation.Invoke()
   at System.Windows.Threading.Dispatcher.ProcessQueue()
   at System.Windows.Threading.Dispatcher.WndProcHook(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
   at MS.Win32.HwndWrapper.WndProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
   at MS.Win32.HwndSubclass.DispatcherCallbackOperation(System.Object)
   at System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32)
   at MS.Internal.Threading.ExceptionFilterHelper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate)
   at System.Windows.Threading.Dispatcher.LegacyInvokeImpl(System.Windows.Threading.DispatcherPriority, System.TimeSpan, System.Delegate, System.Object, Int32)
   at MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr)
   at MS.Win32.UnsafeNativeMethods.DispatchMessage(System.Windows.Interop.MSG ByRef)
   at System.Windows.Threading.Dispatcher.PushFrameImpl(System.Windows.Threading.DispatcherFrame)
   at System.Windows.Threading.Dispatcher.PushFrame(System.Windows.Threading.DispatcherFrame)
   at System.Windows.Threading.Dispatcher.Run()
   at System.Windows.Application.RunDispatcher(System.Object)
   at System.Windows.Application.RunInternal(System.Windows.Window)
   at System.Windows.Application.Run(System.Windows.Window)
   at QBPOSShell.App.Main()
 
Error: (08/27/2014 11:31:32 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: svchost.exe6.1.7600.163854a5bc3c1ieframe.dll11.0.9600.1723953d23dacc000000500000000000039c310c401cfc20aa67f84ddC:\Windows\System32\svchost.exeC:\Windows\System32\ieframe.dll38368ad6-2dff-11e4-bd90-c81f6624b774
 
Error: (08/27/2014 09:20:42 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: svchost.exe6.1.7600.163854a5bc3c1MSHTML.dll11.0.9600.1723953d26d9dc00000fd00000000005d955226ac01cfc1f5633a4b70C:\Windows\System32\svchost.exeC:\Windows\System32\MSHTML.dllf1774caf-2dec-11e4-bd90-c81f6624b774
 
Error: (08/27/2014 08:05:08 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: ocupdu.exe0.4.35190.1706253d75949Flash32_11_8_800_94.ocx11.8.800.9451c4d6e5c00000050059e1991bc001cfc1ee4b901425C:\Users\Pink Pineapple\AppData\Roaming\Dayxohup\ocupdu.exeC:\Windows\SysWOW64\Macromed\Flash\Flash32_11_8_800_94.ocx6312a8aa-2de2-11e4-bd90-c81f6624b774
 
Error: (08/27/2014 07:49:07 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/27/2014 00:56:16 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: msiexec.exe1.0.0.101a31ab5unknown0.0.0.000000000c000000500000000180401cfc1b3121243dfC:\ProgramData\Windows Genuine Advantage\{36438B87-8E2E-4AA0-AEC1-1EE6EC4514FB}\msiexec.exeunknown7813dc77-2da6-11e4-918f-c81f6624b774
 
Error: (08/26/2014 08:14:09 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: iexplore.exe11.0.9600.172394a5bc6b7MSHTML.dll11.0.9600.1723953d26078c000000500136cef3d6001cfc18af37a05ceC:\Program Files\Internet Explorer\iexplore.exeC:\Windows\system32\MSHTML.dll0f5f68a3-2d7f-11e4-918f-c81f6624b774
 
Error: (08/26/2014 07:55:32 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: svchost.exe6.1.7600.163854a5bc3c1Flash64_11_8_800_94.ocx11.8.800.9451c4d3cac000000500000000002ea20446f001cfc18134de9458C:\Windows\System32\svchost.exeC:\Windows\system32\Macromed\Flash\Flash64_11_8_800_94.ocx75bd82ed-2d7c-11e4-918f-c81f6624b774
 
 
CodeIntegrity Errors:
===================================
  Date: 2014-08-27 19:58:02.448
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2014-08-27 19:58:02.401
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
 
==================== Memory info =========================== 
 
Processor: Intel® Core™ i3-4130 CPU @ 3.40GHz
Percentage of memory in use: 69%
Total physical RAM: 4014.8 MB
Available physical RAM: 1242.54 MB
Total Pagefile: 9842.42 MB
Available Pagefile: 6476.38 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB
 
==================== Drives ================================
 
Drive c: (OS) (Fixed) (Total:455.52 GB) (Free:407.11 GB) NTFS
Drive e: (8GB) (Removable) (Total:7.53 GB) (Free:4.44 GB) FAT32
Drive y: (RECOVERY) (Fixed) (Total:10.2 GB) (Free:3.09 GB) NTFS ==>[System with boot components (obtained from reading drive)]
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 465.8 GB) (Disk ID: E4089CDF)
Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)
Partition 2: (Active) - (Size=10.2 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=455.5 GB) - (Type=07 NTFS)
 
========================================================
Disk: 1 (Size: 7.5 GB) (Disk ID: C3072E18)
Partition 1: (Active) - (Size=7.5 GB) - (Type=0B)
 
==================== End Of Log ============================


#5 aharonov

aharonov

  • Malware Response Team
  • 2,441 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:44 PM

Posted 28 August 2014 - 05:27 AM

Great. Combofix has deleted the infection that caused the COM Surrogate Processes. But there is another malware running on the system. Let's remove that one as well:


Step 1

Please download this attached Attached File  fixlist.txt   1.84KB   2 downloads and save it in the same directory as FRST.
  • Start FRST with Administrator privileges.
  • Press the Fix button.
  • When finished, a log file (Fixlog.txt) pops up and is saved to the same location the tool was run from.
    Please copy and paste its contents in your next reply.


Step 2

Start FRST with administator privileges.
  • Press the Scan button.
  • When finished, FRST will produce a log (FRST.txt) in the same directory the tool was run from.
    Please copy and paste this log in your next reply.


#6 compcrewnpt

compcrewnpt
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:04:44 PM

Posted 28 August 2014 - 07:09 AM

Perfect. Hopefully finishing it up today. . .



#7 aharonov

aharonov

  • Malware Response Team
  • 2,441 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:44 PM

Posted 28 August 2014 - 11:34 AM

Ok. :)

#8 compcrewnpt

compcrewnpt
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:04:44 PM

Posted 28 August 2014 - 06:30 PM

Fixlog:::

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 25-08-2014
Ran by Pink Pineapple at 2014-08-28 19:27:35 Run:1
Running from C:\Users\Pink Pineapple\Tools\temp
Boot Mode: Normal
==============================================
 
Content of fixlist:
*****************
CMD: taskkill /f /t /im ocupdu.exe
HKU\S-1-5-21-1651070915-2918641539-3955507323-1000\...\Run: [Feuqilik] => C:\Users\Pink Pineapple\AppData\Roaming\Dayxohup\ocupdu.exe [305220 2014-06-27] (Mesrosift Corporatien)
Task: C:\Windows\Tasks\Security Center Update - 1163631284.job => C:\Users\Pink Pineapple\AppData\Roaming\Dayxohup\ocupdu.exe <==== ATTENTION
Task: {C2AD6A69-616C-43CF-917E-1013E93E3A01} - System32\Tasks\Security Center Update - 1163631284 => C:\Users\Pink Pineapple\AppData\Roaming\Dayxohup\ocupdu.exe [2014-06-27] (Mesrosift Corporatien)
C:\Windows\Tasks\Security Center Update - *
C:\Windows\System32\Tasks\Security Center Update - *
2014-08-24 08:10 - 2014-08-24 08:10 - 00000000 ____D () C:\Users\Pink Pineapple\AppData\Roaming\Dayxohup
HKU\S-1-5-21-1651070915-2918641539-3955507323-1000\...\Run: [CtrlIdentities] => "C:\Users\Pink Pineapple\AppData\Roaming\Identities\CtrlIdentities.exe"
Task: {69A864CD-2EA8-4BD9-B287-CF745818A807} - System32\Tasks\{AFEF17D4-8F2C-D2BB-4A4F-4DB4B9C47D82} => C:\Users\Pink Pineapple\AppData\Roaming\koulrv.dll/s "C:\Users\Pink Pineapple\AppData\Roaming\koulrv.dll"
C:\Users\Pink Pineapple\AppData\Roaming\koulrv.dll
EmptyTemp:
*****************
 
 
=========  taskkill /f /t /im ocupdu.exe =========
 
SUCCESS: The process with PID 8200 (child process of PID 3548) has been terminated.
SUCCESS: The process with PID 1032 (child process of PID 3548) has been terminated.
SUCCESS: The process with PID 6684 (child process of PID 3548) has been terminated.
SUCCESS: The process with PID 7220 (child process of PID 3548) has been terminated.
SUCCESS: The process with PID 7440 (child process of PID 3548) has been terminated.
SUCCESS: The process with PID 3548 (child process of PID 3132) has been terminated.
 
========= End of CMD: =========
 
HKU\S-1-5-21-1651070915-2918641539-3955507323-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Feuqilik => value deleted successfully.
C:\Windows\Tasks\Security Center Update - 1163631284.job not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C2AD6A69-616C-43CF-917E-1013E93E3A01}" => Key not found.
C:\Windows\System32\Tasks\Security Center Update - 1163631284 not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Security Center Update - 1163631284" => Key not found.
"C:\Windows\Tasks\Security Center Update - *" => File/Directory not found.
"C:\Windows\System32\Tasks\Security Center Update - *" => File/Directory not found.
C:\Users\Pink Pineapple\AppData\Roaming\Dayxohup => Moved successfully.
HKU\S-1-5-21-1651070915-2918641539-3955507323-1000\Software\Microsoft\Windows\CurrentVersion\Run\\CtrlIdentities => value deleted successfully.
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}" => Key not found.
"HKCR\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}" => Key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}" => Key deleted successfully.
"HKCR\Wow6432Node\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}" => Key not found.
"HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}" => Key not found.
"HKCR\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}" => Key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{69A864CD-2EA8-4BD9-B287-CF745818A807}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{69A864CD-2EA8-4BD9-B287-CF745818A807}" => Key deleted successfully.
C:\Windows\System32\Tasks\{AFEF17D4-8F2C-D2BB-4A4F-4DB4B9C47D82} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{AFEF17D4-8F2C-D2BB-4A4F-4DB4B9C47D82}" => Key deleted successfully.
"C:\Users\Pink Pineapple\AppData\Roaming\koulrv.dll" => File/Directory not found.
EmptyTemp: => Removed 945.6 MB temporary data.
 
 
The system needed a reboot. 
 
==== End of Fixlog ====


#9 compcrewnpt

compcrewnpt
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:04:44 PM

Posted 28 August 2014 - 06:43 PM

FRST:::

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-08-2014
Ran by Pink Pineapple (administrator) on PINKPINEAPPLE on 28-08-2014 19:38:42
Running from C:\Users\Pink Pineapple\Tools\temp
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal
 
The only official download link for FRST:
Download link from any site other than Bleeping Computer is unpermitted or outdated.
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(SEIKO EPSON CORPORATION) C:\Program Files\EPSON\portcommunicationservice\DeviceControlLog.exe
(SEIKO EPSON CORPORATION) C:\Program Files\EPSON\portcommunicationservice\PCSVC.exe
(Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intuit, Inc.) C:\Program Files (x86)\Common Files\Intuit\Entitlement Client\v8\Server\Intuit.Spc.Map.EntitlementClient.Server.Service.exe
(Intuit Inc.) C:\Program Files (x86)\Intuit\QuickBooks Point of Sale 11.0\DatabaseServer\QBPOSDBService.exe
(SupportSoft, Inc.) C:\Program Files (x86)\VERIZONDM\bin\sprtsvc.exe
(iAnywhere Solutions, Inc.) C:\Program Files (x86)\Intuit\QuickBooks Point of Sale 11.0\DatabaseServer\QBDBMgr10.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(SupportSoft, Inc.) C:\Program Files (x86)\VERIZONDM\bin\tgsrvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Spotify Ltd) C:\Users\Pink Pineapple\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(SupportSoft, Inc.) C:\Program Files (x86)\VERIZONDM\bin\sprtcmd.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Windows\System32\PrintIsolationHost.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_x64.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Desktop.exe
(Mesrosift Corporatien) C:\Users\Pink Pineapple\AppData\Roaming\Dayxohup\ocupdu.exe
(Intuit Inc.) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(SoftThinks SAS) C:\Program Files (x86)\Dell Backup and Recovery\SftService.exe
(Mesrosift Corporatien) C:\Users\Pink Pineapple\AppData\Roaming\Dayxohup\ocupdu.exe
(Mesrosift Corporatien) C:\Users\Pink Pineapple\AppData\Roaming\Dayxohup\ocupdu.exe
(SoftThinks - Dell) C:\Program Files (x86)\Dell Backup and Recovery\Components\DBRUpdate\DBRUpd.exe
(SoftThinks - Dell) C:\Program Files (x86)\Dell Backup and Recovery\Toaster.exe
() C:\Program Files (x86)\Dell Backup and Recovery\Components\Shell\DBRCrawler.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7202520 2013-08-19] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1321688 2013-07-29] (Realtek Semiconductor)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2013-04-26] (Intel Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2014-05-08] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [VERIZONDM] => C:\Program Files (x86)\VERIZONDM\bin\sprtcmd.exe [206120 2011-02-01] (SupportSoft, Inc.)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [EpsonAPD4SV] => C:\Program Files (x86)\EPSON\EPSON Advanced Printer Driver 4\Tools\EAPSV\EAPSV.EXE [210368 2011-06-07] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
Winlogon\Notify\GoToAssist: C:\Program Files (x86)\Citrix\GoToAssist\896\G2AWinLogon_x64.dll (Citrix Online, a division of Citrix Systems, Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1651070915-2918641539-3955507323-1000\...\Run: [Spotify Web Helper] => C:\Users\Pink Pineapple\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1178168 2014-08-09] (Spotify Ltd)
HKU\S-1-5-21-1651070915-2918641539-3955507323-1000\...\Run: [Feuqilik] => C:\Users\Pink Pineapple\AppData\Roaming\Dayxohup\ocupdu.exe [305220 2014-08-28] (Mesrosift Corporatien)
HKU\S-1-5-21-1651070915-2918641539-3955507323-1000\...\Run: [CtrlIdentities] => C:\Users\Pink Pineapple\AppData\Roaming\Identities\CtrlIdentities.exe [278528 2014-08-28] (Daniel Pistelli)
Startup: C:\Users\QBPOSDBSrvUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Uninstall SafeKey RunOnce.lnk
ShortcutTarget: Uninstall SafeKey RunOnce.lnk -> C:\Program Files (x86)\Common Files\lpuninstall.exe (McAfee)
ShellIconOverlayIdentifiers: DBARFileBackuped -> {831cebdd-6baf-4432-be76-9e0989c14aef} => C:\Windows\system32\mscoree.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers: DBARFileNotBackuped -> {275e4fd7-21ef-45cf-a836-832e5d2cc1b3} => C:\Windows\system32\mscoree.dll (Microsoft Corporation)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
HKLM\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = 
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler: qbpos - {662E7FAE-5C17-491C-AD9D-98C1F66CC6A0} -  No File
Handler-x32: qbpos - {662E7FAE-5C17-491C-AD9D-98C1F66CC6A0} - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBPOSProtocol.dll (Intuit Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
 
FireFox:
========
FF Plugin: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
Chrome: 
=======
CHR Profile: C:\Users\Pink Pineapple\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Pink Pineapple\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-08-21]
CHR Extension: (Google Drive) - C:\Users\Pink Pineapple\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-08-21]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Pink Pineapple\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-08-25]
CHR Extension: (YouTube) - C:\Users\Pink Pineapple\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-08-21]
CHR Extension: (Google Search) - C:\Users\Pink Pineapple\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-08-21]
CHR Extension: (Google Wallet) - C:\Users\Pink Pineapple\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-08-21]
CHR Extension: (Gmail) - C:\Users\Pink Pineapple\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-08-21]
 
==================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 EPSON_Device_Control_Log_Service; C:\Program Files\epson\portcommunicationservice\DeviceControlLog.exe [395776 2012-11-29] (SEIKO EPSON CORPORATION) [File not signed]
R2 EPSON_Port_Communication_Service; C:\Program Files\epson\portcommunicationservice\PCSVC.exe [586240 2012-11-29] (SEIKO EPSON CORPORATION) [File not signed]
R2 Intel® Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel® Corporation) [File not signed]
S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel® Corporation)
R2 Intuit Entitlement Service v8; C:\Program Files (x86)\Common Files\Intuit\Entitlement Client\v8\Server\Intuit.Spc.Map.EntitlementClient.Server.Service.exe [24680 2011-12-23] (Intuit, Inc.)
S3 InvProtectSvc; C:\Program Files (x86)\Invincea\Enterprise\X64\InvProtectSvc64.exe [2947856 2013-07-30] (Invincea, Inc.)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [169432 2013-08-21] (Intel Corporation)
R2 QBPOSDBServiceV11; C:\Program Files (x86)\Intuit\QuickBooks Point of Sale 11.0\DatabaseServer\QBPOSDBService.exe [3127296 2014-06-11] (Intuit Inc.) [File not signed]
S3 SboxSvc; C:\Program Files (x86)\Invincea\Enterprise\Sandbox\SboxSvc.exe [124616 2013-07-30] ()
R2 SftService; C:\Program Files (x86)\Dell Backup and Recovery\sftservice.exe [1915920 2013-11-21] (SoftThinks SAS)
R2 sprtsvc_verizondm; C:\Program Files (x86)\VERIZONDM\bin\sprtsvc.exe [206120 2011-02-01] (SupportSoft, Inc.)
R2 tgsrvc_verizondm; C:\Program Files (x86)\VERIZONDM\bin\tgsrvc.exe [185640 2011-02-01] (SupportSoft, Inc.)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
S2 EPSON_PCS_Parallel_Port_Driver; C:\Windows\system32\DRIVERS\pcslpt.sys [21640 2012-11-29] (SEIKO EPSON CORPORATION)
R3 IntcAzAudAddService; C:\Windows\System32\drivers\RTDVHD64.sys [2192088 2013-08-23] (Realtek Semiconductor Corp.)
S3 InvProtectDrv; C:\Program Files (x86)\Invincea\Enterprise\X64\InvProtectDrv64.sys [34824 2013-07-30] ()
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-08-21] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [99288 2013-08-21] (Intel Corporation)
S3 SboxDrv; C:\Program Files (x86)\Invincea\Enterprise\Sandbox\SboxDrv.sys [202248 2013-07-30] ()
R3 TMUSB; C:\Windows\System32\DRIVERS\TMUSB64.SYS [63096 2012-03-01] (Seiko Epson Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
==================== One Month Created Files and Folders ========
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2014-08-28 19:27 - 2014-08-28 19:27 - 00000000 ____D () C:\Users\Pink Pineapple\AppData\Roaming\Dayxohup
2014-08-28 15:35 - 2014-08-28 15:40 - 31056184 _____ () C:\Users\Pink Pineapple\Downloads\QB_Component_Repair_Tool.exe
2014-08-27 20:49 - 2014-08-27 20:49 - 00319912 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-08-27 20:49 - 2014-08-27 20:49 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-08-27 20:49 - 2014-08-27 20:49 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-08-27 20:49 - 2014-08-27 20:49 - 00111016 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2014-08-27 20:49 - 2014-08-27 20:49 - 00000000 ____D () C:\Program Files\Java
2014-08-27 20:46 - 2014-08-22 22:07 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-27 20:46 - 2014-08-22 21:45 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-27 20:46 - 2014-08-22 20:59 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-27 20:45 - 2014-08-27 20:45 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-08-27 20:45 - 2014-08-27 20:45 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-08-27 20:45 - 2014-08-27 20:45 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-08-27 20:45 - 2014-08-27 20:45 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-08-27 20:45 - 2014-08-27 20:45 - 00000000 ____D () C:\ProgramData\Sun
2014-08-27 20:45 - 2014-08-27 20:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-08-27 20:45 - 2014-08-27 20:45 - 00000000 ____D () C:\Program Files (x86)\Java
2014-08-27 20:40 - 2014-08-28 19:30 - 00121386 _____ () C:\Windows\PFRO.log
2014-08-27 20:40 - 2014-08-28 19:30 - 00000280 _____ () C:\Windows\setupact.log
2014-08-27 20:40 - 2014-08-27 20:40 - 00000000 _____ () C:\Windows\setuperr.log
2014-08-27 20:14 - 2014-08-28 19:38 - 00000000 ____D () C:\FRST
2014-08-27 19:58 - 2014-08-27 19:58 - 00000000 ____D () C:\Windows\erdnt
2014-08-27 19:51 - 2011-06-26 02:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-08-27 19:51 - 2010-11-07 13:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-08-27 19:51 - 2009-04-20 00:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-08-27 19:51 - 2000-08-30 20:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-08-27 19:51 - 2000-08-30 20:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-08-27 19:51 - 2000-08-30 20:00 - 00098816 _____ () C:\Windows\sed.exe
2014-08-27 19:51 - 2000-08-30 20:00 - 00080412 _____ () C:\Windows\grep.exe
2014-08-27 19:51 - 2000-08-30 20:00 - 00068096 _____ () C:\Windows\zip.exe
2014-08-27 19:46 - 2014-08-27 20:06 - 00000000 ____D () C:\Qoobox
2014-08-27 17:15 - 2014-08-27 17:15 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
2014-08-26 17:17 - 2014-08-26 17:17 - 00001180 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 9.lnk
2014-08-26 17:17 - 2014-08-26 17:17 - 00001168 _____ () C:\Users\Public\Desktop\TeamViewer 9.lnk
2014-08-26 17:16 - 2014-08-26 17:16 - 00000000 ____D () C:\Program Files (x86)\TeamViewer
2014-08-24 08:06 - 2014-08-27 00:55 - 00000000 ____D () C:\ProgramData\Windows Genuine Advantage
2014-08-21 21:23 - 2014-08-21 21:23 - 00002220 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-08-21 21:23 - 2014-08-21 21:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-08-21 21:22 - 2014-08-28 19:30 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-08-21 21:22 - 2014-08-28 19:27 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-08-21 21:22 - 2014-08-21 21:23 - 00000000 ____D () C:\Users\Pink Pineapple\AppData\Local\Google
2014-08-21 21:22 - 2014-08-21 21:22 - 00003894 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-08-21 21:22 - 2014-08-21 21:22 - 00003642 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-08-21 21:22 - 2014-08-21 21:22 - 00000000 ____D () C:\Program Files (x86)\Google
2014-08-21 21:04 - 2014-08-21 21:04 - 00000404 _____ () C:\Users\Pink Pineapple\Desktop\Local Area Connection - Shortcut.lnk
2014-08-21 19:50 - 2014-08-21 21:32 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-08-21 19:50 - 2014-08-21 19:50 - 00001108 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-08-21 19:50 - 2014-08-21 19:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-08-21 19:50 - 2014-08-21 19:50 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-08-21 19:50 - 2014-08-21 19:50 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-08-21 19:50 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-08-21 19:50 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-08-21 19:50 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-08-21 19:44 - 2014-08-21 19:44 - 00000000 ____D () C:\Program Files\CCleaner
2014-08-21 19:35 - 2014-08-28 19:24 - 00000000 ___RD () C:\Users\Pink Pineapple\Tools
2014-08-21 12:10 - 2014-08-21 21:02 - 00000000 ____D () C:\Users\Pink Pineapple\Documents\McAfee Vaults
2014-08-21 10:17 - 2014-08-21 10:17 - 00000000 ____D () C:\Quarantine
2014-08-21 10:16 - 2014-08-21 10:16 - 00000000 ____D () C:\mfe
2014-08-21 10:10 - 2014-08-21 10:19 - 00000000 ____D () C:\Program Files\stinger
2014-08-21 10:08 - 2014-08-21 21:11 - 00000000 ____D () C:\ProgramData\McAfee
2014-08-19 03:03 - 2014-05-14 12:23 - 02477536 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-08-19 03:03 - 2014-05-14 12:23 - 00700384 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-08-19 03:03 - 2014-05-14 12:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2014-08-19 03:03 - 2014-05-14 12:23 - 00058336 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-08-19 03:03 - 2014-05-14 12:23 - 00044512 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2014-08-19 03:03 - 2014-05-14 12:23 - 00038880 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2014-08-19 03:03 - 2014-05-14 12:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2014-08-19 03:03 - 2014-05-14 12:21 - 02620928 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-08-19 03:03 - 2014-05-14 12:20 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-08-19 03:03 - 2014-05-14 12:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2014-08-19 03:03 - 2014-05-14 09:23 - 00198600 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-08-19 03:03 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2014-08-19 03:03 - 2014-05-14 09:20 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-08-19 03:03 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2014-08-14 03:01 - 2014-06-30 18:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2014-08-14 03:01 - 2014-06-30 18:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll
2014-08-14 03:01 - 2014-03-09 17:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2014-08-14 03:01 - 2014-03-09 17:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2014-08-14 03:01 - 2014-03-09 17:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe
2014-08-14 03:01 - 2014-03-09 17:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll
2014-08-14 03:00 - 2014-06-06 02:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2014-08-14 03:00 - 2014-06-06 02:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2014-08-13 05:06 - 2014-07-31 19:16 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-08-13 05:06 - 2014-07-25 10:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-08-13 05:06 - 2014-07-25 09:51 - 17524224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-08-13 05:06 - 2014-07-25 09:28 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-08-13 05:06 - 2014-07-25 09:10 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-08-13 05:06 - 2014-07-25 08:34 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-08-13 05:06 - 2014-07-25 08:33 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-08-13 05:06 - 2014-07-25 08:28 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-08-13 05:06 - 2014-07-25 08:21 - 02184704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-08-13 05:06 - 2014-07-25 08:17 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-08-13 05:06 - 2014-07-25 08:08 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-08-13 05:06 - 2014-07-25 07:52 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-08-13 05:06 - 2014-07-25 07:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-08-13 05:06 - 2014-07-25 07:42 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-08-13 05:06 - 2014-07-25 07:34 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-08-13 05:06 - 2014-07-25 07:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-08-13 05:06 - 2014-07-25 07:07 - 02001920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-08-13 05:06 - 2014-07-25 06:26 - 01431040 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-08-13 05:06 - 2014-07-25 06:00 - 01169920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-08-13 05:06 - 2014-07-15 23:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-08-13 05:06 - 2014-07-15 22:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-08-13 05:06 - 2014-07-08 22:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL
2014-08-13 05:06 - 2014-07-08 22:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL
2014-08-13 05:06 - 2014-07-08 22:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL
2014-08-13 05:06 - 2014-07-08 22:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL
2014-08-13 05:06 - 2014-07-08 22:03 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL
2014-08-13 05:06 - 2014-07-08 21:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDYAK.DLL
2014-08-13 05:06 - 2014-07-08 21:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTAT.DLL
2014-08-13 05:06 - 2014-07-08 21:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU1.DLL
2014-08-13 05:06 - 2014-07-08 21:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU.DLL
2014-08-13 05:06 - 2014-07-08 21:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDBASH.DLL
2014-08-13 05:06 - 2014-07-08 18:38 - 00419992 _____ () C:\Windows\system32\locale.nls
2014-08-13 05:06 - 2014-07-08 18:30 - 00419992 _____ () C:\Windows\SysWOW64\locale.nls
2014-08-13 05:06 - 2014-06-24 22:05 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-08-13 05:06 - 2014-06-24 21:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-08-13 05:06 - 2014-06-15 22:10 - 00985536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-08-13 05:06 - 2014-06-03 06:02 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-08-13 05:06 - 2014-06-03 06:02 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-08-13 05:06 - 2014-06-03 06:02 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2014-08-13 05:06 - 2014-06-03 06:02 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-08-13 05:06 - 2014-06-03 05:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-08-13 05:06 - 2014-06-03 05:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-08-13 05:06 - 2014-06-03 05:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2014-08-13 05:05 - 2014-07-31 19:41 - 00348856 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-08-13 05:05 - 2014-07-25 10:52 - 23645696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-08-13 05:05 - 2014-07-25 10:01 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-08-13 05:05 - 2014-07-25 09:30 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-08-13 05:05 - 2014-07-25 09:28 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-08-13 05:05 - 2014-07-25 09:25 - 02774528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-08-13 05:05 - 2014-07-25 09:25 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-08-13 05:05 - 2014-07-25 09:11 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-08-13 05:05 - 2014-07-25 09:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-08-13 05:05 - 2014-07-25 09:03 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-08-13 05:05 - 2014-07-25 09:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-08-13 05:05 - 2014-07-25 09:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-08-13 05:05 - 2014-07-25 08:59 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-08-13 05:05 - 2014-07-25 08:47 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-08-13 05:05 - 2014-07-25 08:40 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-08-13 05:05 - 2014-07-25 08:34 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-08-13 05:05 - 2014-07-25 08:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-08-13 05:05 - 2014-07-25 08:28 - 05824512 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-08-13 05:05 - 2014-07-25 08:19 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-08-13 05:05 - 2014-07-25 08:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-08-13 05:05 - 2014-07-25 08:17 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-08-13 05:05 - 2014-07-25 08:12 - 00438784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-08-13 05:05 - 2014-07-25 08:10 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-08-13 05:05 - 2014-07-25 08:10 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-08-13 05:05 - 2014-07-25 08:06 - 04204032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-08-13 05:05 - 2014-07-25 07:47 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-08-13 05:05 - 2014-07-25 07:39 - 02087936 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-08-13 05:05 - 2014-07-25 07:39 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-08-13 05:05 - 2014-07-25 07:36 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-08-13 05:05 - 2014-07-25 07:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-08-13 05:05 - 2014-07-25 07:23 - 13547008 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-08-13 05:05 - 2014-07-25 07:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-08-13 05:05 - 2014-07-25 07:03 - 11772928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-08-13 05:05 - 2014-07-25 06:52 - 02266624 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-08-13 05:05 - 2014-07-25 06:17 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-08-13 05:05 - 2014-07-25 06:09 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-08-13 05:05 - 2014-07-25 06:05 - 01792512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-08-13 05:03 - 2014-08-06 22:06 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-08-13 05:03 - 2014-08-06 22:01 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-08-13 05:03 - 2014-07-13 22:02 - 01216000 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2014-08-13 05:03 - 2014-07-13 21:40 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2014-08-11 19:26 - 2014-08-14 03:06 - 00000000 ____D () C:\Windows\system32\MRT
2014-08-11 19:26 - 2014-08-14 03:04 - 99218768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-08-09 16:26 - 2014-08-09 16:27 - 05155464 _____ (McAfee, Inc.) C:\Users\Pink Pineapple\Desktop\McAfeeSetup-AutoLogin_exe
2014-08-09 16:24 - 2014-08-09 16:27 - 05155464 _____ (McAfee, Inc.) C:\Users\Pink Pineapple\Downloads\McAfeeSetup-AutoLogin_exe (4)
2014-08-09 16:17 - 2014-08-09 16:17 - 00000000 _____ () C:\Users\Pink Pineapple\Desktop\McAfeeSetup-AutoLogin_exe.os40w69.partial
2014-08-09 16:10 - 2014-08-09 16:10 - 00000000 ____D () C:\ProgramData\Citrix
2014-08-09 16:06 - 2014-08-21 11:01 - 00000000 ____D () C:\Users\Pink Pineapple\AppData\Local\Deployment
2014-08-09 16:06 - 2014-08-09 16:06 - 00000000 ____D () C:\Users\Pink Pineapple\AppData\Local\Citrix
2014-08-09 16:06 - 2014-08-09 16:06 - 00000000 ____D () C:\Users\Pink Pineapple\AppData\Local\Apps\2.0
2014-08-09 16:06 - 2014-08-09 16:06 - 00000000 ____D () C:\Program Files (x86)\Citrix
2014-08-09 16:02 - 2014-08-09 16:03 - 05155464 _____ (McAfee, Inc.) C:\Users\Pink Pineapple\Downloads\McAfeeSetup-AutoLogin_exe
2014-08-09 15:58 - 2014-08-09 15:58 - 05155464 _____ (McAfee, Inc.) C:\Users\Pink Pineapple\Downloads\McAfeeSetup-AutoLogin_exe (3)
2014-08-09 15:58 - 2014-08-09 15:58 - 05155464 _____ (McAfee, Inc.) C:\Users\Pink Pineapple\Downloads\McAfeeSetup-AutoLogin_exe (2)
2014-08-09 15:57 - 2014-08-09 15:57 - 05155464 _____ (McAfee, Inc.) C:\Users\Pink Pineapple\Downloads\McAfeeSetup-AutoLogin_exe (1)
2014-08-09 15:33 - 2014-08-09 15:33 - 00002790 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-08-09 10:00 - 2014-08-20 22:07 - 00000000 ____D () C:\Users\Pink Pineapple\AppData\Local\Spotify
2014-08-09 10:00 - 2014-08-09 10:00 - 00001859 _____ () C:\Users\Pink Pineapple\Desktop\Spotify.lnk
2014-08-09 10:00 - 2014-08-09 10:00 - 00001845 _____ () C:\Users\Pink Pineapple\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2014-08-09 09:59 - 2014-08-25 14:28 - 00000000 ____D () C:\Users\Pink Pineapple\AppData\Roaming\Spotify
2014-08-04 12:25 - 2014-08-04 12:25 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
 
==================== One Month Modified Files and Folders =======
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2014-08-28 19:38 - 2014-08-27 20:14 - 00000000 ____D () C:\FRST
2014-08-28 19:38 - 2013-11-06 20:32 - 00000000 ____D () C:\Program Files (x86)\Dell Backup and Recovery
2014-08-28 19:37 - 2009-07-14 00:45 - 00031312 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-08-28 19:37 - 2009-07-14 00:45 - 00031312 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-08-28 19:36 - 2014-04-17 09:38 - 00000000 ____D () C:\Users\Pink Pineapple\AppData\Local\CrashDumps
2014-08-28 19:30 - 2014-08-27 20:40 - 00121386 _____ () C:\Windows\PFRO.log
2014-08-28 19:30 - 2014-08-27 20:40 - 00000280 _____ () C:\Windows\setupact.log
2014-08-28 19:30 - 2014-08-21 21:22 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-08-28 19:30 - 2009-07-14 01:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-08-28 19:29 - 2013-11-06 22:16 - 01062417 _____ () C:\Windows\WindowsUpdate.log
2014-08-28 19:27 - 2014-08-28 19:27 - 00000000 ____D () C:\Users\Pink Pineapple\AppData\Roaming\Dayxohup
2014-08-28 19:27 - 2014-08-21 21:22 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-08-28 19:24 - 2014-08-21 19:35 - 00000000 ___RD () C:\Users\Pink Pineapple\Tools
2014-08-28 19:24 - 2013-11-06 20:21 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-08-28 15:47 - 2014-04-03 10:46 - 00000000 ____D () C:\Program Files (x86)\Intuit
2014-08-28 15:40 - 2014-08-28 15:35 - 31056184 _____ () C:\Users\Pink Pineapple\Downloads\QB_Component_Repair_Tool.exe
2014-08-28 15:28 - 2009-07-14 01:32 - 00000000 ____D () C:\Windows\system32\FxsTmp
2014-08-28 03:19 - 2009-07-14 00:45 - 00269128 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-08-27 20:54 - 2013-11-06 20:31 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-08-27 20:54 - 2013-11-06 20:31 - 00000000 ____D () C:\ProgramData\Adobe
2014-08-27 20:49 - 2014-08-27 20:49 - 00319912 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-08-27 20:49 - 2014-08-27 20:49 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-08-27 20:49 - 2014-08-27 20:49 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-08-27 20:49 - 2014-08-27 20:49 - 00111016 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2014-08-27 20:49 - 2014-08-27 20:49 - 00000000 ____D () C:\Program Files\Java
2014-08-27 20:45 - 2014-08-27 20:45 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-08-27 20:45 - 2014-08-27 20:45 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-08-27 20:45 - 2014-08-27 20:45 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-08-27 20:45 - 2014-08-27 20:45 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-08-27 20:45 - 2014-08-27 20:45 - 00000000 ____D () C:\ProgramData\Sun
2014-08-27 20:45 - 2014-08-27 20:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-08-27 20:45 - 2014-08-27 20:45 - 00000000 ____D () C:\Program Files (x86)\Java
2014-08-27 20:40 - 2014-08-27 20:40 - 00000000 _____ () C:\Windows\setuperr.log
2014-08-27 20:06 - 2014-08-27 19:46 - 00000000 ____D () C:\Qoobox
2014-08-27 20:06 - 2009-07-13 23:20 - 00000000 __RHD () C:\Users\Default
2014-08-27 19:58 - 2014-08-27 19:58 - 00000000 ____D () C:\Windows\erdnt
2014-08-27 19:58 - 2014-04-03 11:07 - 00000000 ____D () C:\Users\Pink Pineapple
2014-08-27 19:58 - 2009-07-13 22:34 - 00000215 _____ () C:\Windows\system.ini
2014-08-27 17:18 - 2009-07-14 01:13 - 00781790 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-08-27 17:15 - 2014-08-27 17:15 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
2014-08-27 07:50 - 2014-04-03 10:48 - 00058408 _____ () C:\Users\Pink Pineapple\AppData\Local\GDIPFONTCACHEV1.DAT
2014-08-27 00:55 - 2014-08-24 08:06 - 00000000 ____D () C:\ProgramData\Windows Genuine Advantage
2014-08-26 17:17 - 2014-08-26 17:17 - 00001180 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 9.lnk
2014-08-26 17:17 - 2014-08-26 17:17 - 00001168 _____ () C:\Users\Public\Desktop\TeamViewer 9.lnk
2014-08-26 17:16 - 2014-08-26 17:16 - 00000000 ____D () C:\Program Files (x86)\TeamViewer
2014-08-25 14:28 - 2014-08-09 09:59 - 00000000 ____D () C:\Users\Pink Pineapple\AppData\Roaming\Spotify
2014-08-24 20:15 - 2014-04-13 15:19 - 00000127 _____ () C:\Users\Pink Pineapple\Documents\reprev.opt
2014-08-22 22:07 - 2014-08-27 20:46 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-22 21:45 - 2014-08-27 20:46 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-22 20:59 - 2014-08-27 20:46 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-22 09:59 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\rescache
2014-08-21 21:32 - 2014-08-21 19:50 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-08-21 21:23 - 2014-08-21 21:23 - 00002220 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-08-21 21:23 - 2014-08-21 21:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-08-21 21:23 - 2014-08-21 21:22 - 00000000 ____D () C:\Users\Pink Pineapple\AppData\Local\Google
2014-08-21 21:22 - 2014-08-21 21:22 - 00003894 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-08-21 21:22 - 2014-08-21 21:22 - 00003642 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-08-21 21:22 - 2014-08-21 21:22 - 00000000 ____D () C:\Program Files (x86)\Google
2014-08-21 21:11 - 2014-08-21 10:08 - 00000000 ____D () C:\ProgramData\McAfee
2014-08-21 21:04 - 2014-08-21 21:04 - 00000404 _____ () C:\Users\Pink Pineapple\Desktop\Local Area Connection - Shortcut.lnk
2014-08-21 21:02 - 2014-08-21 12:10 - 00000000 ____D () C:\Users\Pink Pineapple\Documents\McAfee Vaults
2014-08-21 20:19 - 2014-07-09 15:38 - 00000000 ____D () C:\Program Files (x86)\Movies Toolbar
2014-08-21 19:50 - 2014-08-21 19:50 - 00001108 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-08-21 19:50 - 2014-08-21 19:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-08-21 19:50 - 2014-08-21 19:50 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-08-21 19:50 - 2014-08-21 19:50 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-08-21 19:44 - 2014-08-21 19:44 - 00000000 ____D () C:\Program Files\CCleaner
2014-08-21 11:01 - 2014-08-09 16:06 - 00000000 ____D () C:\Users\Pink Pineapple\AppData\Local\Deployment
2014-08-21 10:19 - 2014-08-21 10:10 - 00000000 ____D () C:\Program Files\stinger
2014-08-21 10:17 - 2014-08-21 10:17 - 00000000 ____D () C:\Quarantine
2014-08-21 10:16 - 2014-08-21 10:16 - 00000000 ____D () C:\mfe
2014-08-21 10:16 - 2009-07-14 00:54 - 00000749 ___RH () C:\Windows\WindowsShell.Manifest
2014-08-21 10:16 - 2009-07-13 23:20 - 00000000 __RHD () C:\Users\Public\Libraries
2014-08-20 22:07 - 2014-08-09 10:00 - 00000000 ____D () C:\Users\Pink Pineapple\AppData\Local\Spotify
2014-08-14 03:27 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-08-14 03:06 - 2014-08-11 19:26 - 00000000 ____D () C:\Windows\system32\MRT
2014-08-14 03:04 - 2014-08-11 19:26 - 99218768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-08-14 03:00 - 2014-05-07 03:00 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-08-09 16:27 - 2014-08-09 16:26 - 05155464 _____ (McAfee, Inc.) C:\Users\Pink Pineapple\Desktop\McAfeeSetup-AutoLogin_exe
2014-08-09 16:27 - 2014-08-09 16:24 - 05155464 _____ (McAfee, Inc.) C:\Users\Pink Pineapple\Downloads\McAfeeSetup-AutoLogin_exe (4)
2014-08-09 16:17 - 2014-08-09 16:17 - 00000000 _____ () C:\Users\Pink Pineapple\Desktop\McAfeeSetup-AutoLogin_exe.os40w69.partial
2014-08-09 16:10 - 2014-08-09 16:10 - 00000000 ____D () C:\ProgramData\Citrix
2014-08-09 16:06 - 2014-08-09 16:06 - 00000000 ____D () C:\Users\Pink Pineapple\AppData\Local\Citrix
2014-08-09 16:06 - 2014-08-09 16:06 - 00000000 ____D () C:\Users\Pink Pineapple\AppData\Local\Apps\2.0
2014-08-09 16:06 - 2014-08-09 16:06 - 00000000 ____D () C:\Program Files (x86)\Citrix
2014-08-09 16:03 - 2014-08-09 16:02 - 05155464 _____ (McAfee, Inc.) C:\Users\Pink Pineapple\Downloads\McAfeeSetup-AutoLogin_exe
2014-08-09 16:01 - 2010-11-21 03:16 - 00000000 ___RD () C:\Users\Public\Recorded TV
2014-08-09 15:58 - 2014-08-09 15:58 - 05155464 _____ (McAfee, Inc.) C:\Users\Pink Pineapple\Downloads\McAfeeSetup-AutoLogin_exe (3)
2014-08-09 15:58 - 2014-08-09 15:58 - 05155464 _____ (McAfee, Inc.) C:\Users\Pink Pineapple\Downloads\McAfeeSetup-AutoLogin_exe (2)
2014-08-09 15:57 - 2014-08-09 15:57 - 05155464 _____ (McAfee, Inc.) C:\Users\Pink Pineapple\Downloads\McAfeeSetup-AutoLogin_exe (1)
2014-08-09 15:35 - 2011-02-10 10:25 - 00000000 ____D () C:\Windows\panther
2014-08-09 15:33 - 2014-08-09 15:33 - 00002790 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-08-09 10:00 - 2014-08-09 10:00 - 00001859 _____ () C:\Users\Pink Pineapple\Desktop\Spotify.lnk
2014-08-09 10:00 - 2014-08-09 10:00 - 00001845 _____ () C:\Users\Pink Pineapple\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2014-08-07 19:59 - 2010-11-21 03:06 - 00000000 ____D () C:\Windows\SysWOW64\sysprep
2014-08-06 22:06 - 2014-08-13 05:03 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-08-06 22:01 - 2014-08-13 05:03 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-08-05 09:20 - 2010-11-20 23:27 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-08-04 12:25 - 2014-08-04 12:25 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2014-07-31 19:41 - 2014-08-13 05:05 - 00348856 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-07-31 19:16 - 2014-08-13 05:06 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2014-08-28 03:49
 
==================== End Of Log ============================


#10 aharonov

aharonov

  • Malware Response Team
  • 2,441 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:44 PM

Posted 28 August 2014 - 06:56 PM

This malware has restored itself immediately after deletion. So we go to Recovery Environment where the malware doesn't run and therefore isn't able to protect itself.
A scan first:



Move FRST64.exe to a flash drive.
  • Plug the flashdrive into the infected PC and boot the computer into System Recovery Options as follows.
To enter System Recovery Options from the Advanced Boot Options:
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account an click Next.
Note: In case you can not enter System Recovery Options by using F8 method, you can use Windows installation disc, or make a repair disc. Any Windows installation disc or a repair disc made on another computer can be used.
To make a repair disk on Windows 7 consult: http://www.sevenforums.com/tutorials/2083-system-repair-disc-create.html




To enter System Recovery Options by using Windows installation disc:
  • Insert the installation disc.
  • Restart your computer.
  • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
  • Click Repair your computer.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account and click Next.
==========

On the System Recovery Options menu you will get the following options:

Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt


Select Command Prompt

==========


Once in the Command Prompt:
  • In the command window type in notepad and press Enter.
  • The notepad opens. Under File menu select Open.
  • Select "Computer" and find your flash drive letter and close the notepad.
  • In the command window type e:\frst (for x64 bit version type e:\frst64) and press Enter
    Note: Replace letter e with the drive letter of your flash drive.
  • The tool will start to run.
  • When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.

Edited by aharonov, 28 August 2014 - 06:57 PM.


#11 compcrewnpt

compcrewnpt
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:04:44 PM

Posted 28 August 2014 - 06:57 PM

Will do this in the morning. Thank you!


Edited by compcrewnpt, 28 August 2014 - 07:15 PM.


#12 aharonov

aharonov

  • Malware Response Team
  • 2,441 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:44 PM

Posted 28 August 2014 - 06:58 PM

That's right. See my post above. :)

#13 compcrewnpt

compcrewnpt
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:04:44 PM

Posted 29 August 2014 - 07:05 AM

FRST:::

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-08-2014
Ran by SYSTEM on MININT-1T7DRLA on 29-08-2014 07:53:42
Running from g:\frst
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Recovery
 
The current controlset is ControlSet001
ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log.
 
 
The only official download link for FRST:
Download link from any site other than Bleeping Computer is unpermitted or outdated.
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7202520 2013-08-19] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1321688 2013-07-29] (Realtek Semiconductor)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2013-04-26] (Intel Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2014-05-08] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [VERIZONDM] => C:\Program Files (x86)\VERIZONDM\bin\sprtcmd.exe [206120 2011-02-01] (SupportSoft, Inc.)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [EpsonAPD4SV] => C:\Program Files (x86)\EPSON\EPSON Advanced Printer Driver 4\Tools\EAPSV\EAPSV.EXE [210368 2011-06-07] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
Winlogon\Notify\GoToAssist: C:\Program Files (x86)\Citrix\GoToAssist\896\G2AWinLogon_x64.dll (Citrix Online, a division of Citrix Systems, Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\Pink Pineapple\...\Run: [Spotify Web Helper] => C:\Users\Pink Pineapple\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1178168 2014-08-09] (Spotify Ltd)
HKU\Pink Pineapple\...\Run: [Feuqilik] => C:\Users\Pink Pineapple\AppData\Roaming\Dayxohup\ocupdu.exe [305220 2014-08-28] (Mesrosift Corporatien)
HKU\Pink Pineapple\...\Run: [CtrlIdentities] => C:\Users\Pink Pineapple\AppData\Roaming\Identities\CtrlIdentities.exe [278528 2014-08-29] (Daniel Pistelli)
Startup: C:\Users\QBPOSDBSrvUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Uninstall SafeKey RunOnce.lnk
ShortcutTarget: Uninstall SafeKey RunOnce.lnk -> C:\Program Files (x86)\Common Files\lpuninstall.exe (McAfee)
 
==================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
S2 EPSON_Device_Control_Log_Service; C:\Program Files\epson\portcommunicationservice\DeviceControlLog.exe [395776 2012-11-29] (SEIKO EPSON CORPORATION)
S2 EPSON_Port_Communication_Service; C:\Program Files\epson\portcommunicationservice\PCSVC.exe [586240 2012-11-29] (SEIKO EPSON CORPORATION)
S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel® Corporation)
S2 Intuit Entitlement Service v8; C:\Program Files (x86)\Common Files\Intuit\Entitlement Client\v8\Server\Intuit.Spc.Map.EntitlementClient.Server.Service.exe [24680 2011-12-23] (Intuit, Inc.)
S3 InvProtectSvc; C:\Program Files (x86)\Invincea\Enterprise\X64\InvProtectSvc64.exe [2947856 2013-07-30] (Invincea, Inc.)
S2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [169432 2013-08-21] (Intel Corporation)
S2 QBPOSDBServiceV11; C:\Program Files (x86)\Intuit\QuickBooks Point of Sale 11.0\DatabaseServer\QBPOSDBService.exe [3127296 2014-06-11] (Intuit Inc.)
S3 SboxSvc; C:\Program Files (x86)\Invincea\Enterprise\Sandbox\SboxSvc.exe [124616 2013-07-30] ()
S2 SftService; C:\Program Files (x86)\Dell Backup and Recovery\sftservice.exe [1915920 2013-11-21] (SoftThinks SAS)
S2 sprtsvc_verizondm; C:\Program Files (x86)\VERIZONDM\bin\sprtsvc.exe [206120 2011-02-01] (SupportSoft, Inc.)
S2 tgsrvc_verizondm; C:\Program Files (x86)\VERIZONDM\bin\tgsrvc.exe [185640 2011-02-01] (SupportSoft, Inc.)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
S2 EPSON_PCS_Parallel_Port_Driver; C:\Windows\system32\DRIVERS\pcslpt.sys [21640 2012-11-29] (SEIKO EPSON CORPORATION)
S3 IntcAzAudAddService; C:\Windows\System32\drivers\RTDVHD64.sys [2192088 2013-08-23] (Realtek Semiconductor Corp.)
S3 InvProtectDrv; C:\Program Files (x86)\Invincea\Enterprise\X64\InvProtectDrv64.sys [34824 2013-07-30] ()
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-08-21] (Malwarebytes Corporation)
S3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [99288 2013-08-21] (Intel Corporation)
S3 SboxDrv; C:\Program Files (x86)\Invincea\Enterprise\Sandbox\SboxDrv.sys [202248 2013-07-30] ()
S3 TMUSB; C:\Windows\System32\DRIVERS\TMUSB64.SYS [63096 2012-03-01] (Seiko Epson Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
==================== One Month Created Files and Folders ========
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2014-08-28 20:04 - 2014-08-28 20:13 - 57655296 _____ () C:\Users\Pink Pineapple\Downloads\APD_407EWM.exe
2014-08-28 19:27 - 2014-08-28 19:27 - 00000000 ____D () C:\Users\Pink Pineapple\AppData\Roaming\Dayxohup
2014-08-28 15:35 - 2014-08-28 15:40 - 31056184 _____ () C:\Users\Pink Pineapple\Downloads\QB_Component_Repair_Tool.exe
2014-08-27 20:49 - 2014-08-27 20:49 - 00319912 _____ (Oracle Corporation) C:\Windows\System32\javaws.exe
2014-08-27 20:49 - 2014-08-27 20:49 - 00189352 _____ (Oracle Corporation) C:\Windows\System32\javaw.exe
2014-08-27 20:49 - 2014-08-27 20:49 - 00189352 _____ (Oracle Corporation) C:\Windows\System32\java.exe
2014-08-27 20:49 - 2014-08-27 20:49 - 00111016 _____ (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge-64.dll
2014-08-27 20:49 - 2014-08-27 20:49 - 00000000 ____D () C:\Program Files\Java
2014-08-27 20:46 - 2014-08-22 22:07 - 00404480 _____ (Microsoft Corporation) C:\Windows\System32\gdi32.dll
2014-08-27 20:46 - 2014-08-22 21:45 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-27 20:46 - 2014-08-22 20:59 - 03163648 _____ (Microsoft Corporation) C:\Windows\System32\win32k.sys
2014-08-27 20:45 - 2014-08-27 20:45 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-08-27 20:45 - 2014-08-27 20:45 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-08-27 20:45 - 2014-08-27 20:45 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-08-27 20:45 - 2014-08-27 20:45 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-08-27 20:45 - 2014-08-27 20:45 - 00000000 ____D () C:\ProgramData\Sun
2014-08-27 20:45 - 2014-08-27 20:45 - 00000000 ____D () C:\Program Files (x86)\Java
2014-08-27 20:40 - 2014-08-28 19:30 - 00121386 _____ () C:\Windows\PFRO.log
2014-08-27 20:40 - 2014-08-28 19:30 - 00000280 _____ () C:\Windows\setupact.log
2014-08-27 20:40 - 2014-08-27 20:40 - 00000000 _____ () C:\Windows\setuperr.log
2014-08-27 20:14 - 2014-08-29 07:53 - 00000000 ____D () C:\FRST
2014-08-27 19:58 - 2014-08-27 19:58 - 00000000 ____D () C:\Windows\erdnt
2014-08-27 19:51 - 2011-06-26 02:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-08-27 19:51 - 2010-11-07 13:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-08-27 19:51 - 2009-04-20 00:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-08-27 19:51 - 2000-08-30 20:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-08-27 19:51 - 2000-08-30 20:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-08-27 19:51 - 2000-08-30 20:00 - 00098816 _____ () C:\Windows\sed.exe
2014-08-27 19:51 - 2000-08-30 20:00 - 00080412 _____ () C:\Windows\grep.exe
2014-08-27 19:51 - 2000-08-30 20:00 - 00068096 _____ () C:\Windows\zip.exe
2014-08-27 19:46 - 2014-08-27 20:06 - 00000000 ____D () C:\Qoobox
2014-08-27 17:15 - 2014-08-27 17:15 - 00000000 ____H () C:\Windows\System32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
2014-08-26 17:17 - 2014-08-26 17:17 - 00001168 _____ () C:\Users\Public\Desktop\TeamViewer 9.lnk
2014-08-26 17:17 - 2014-08-26 17:17 - 00001168 _____ () C:\ProgramData\Desktop\TeamViewer 9.lnk
2014-08-26 17:16 - 2014-08-26 17:16 - 00000000 ____D () C:\Program Files (x86)\TeamViewer
2014-08-24 08:06 - 2014-08-28 21:04 - 00000000 ____D () C:\ProgramData\Windows Genuine Advantage
2014-08-21 21:23 - 2014-08-21 21:23 - 00002220 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-08-21 21:23 - 2014-08-21 21:23 - 00002220 _____ () C:\ProgramData\Desktop\Google Chrome.lnk
2014-08-21 21:22 - 2014-08-29 07:27 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-08-21 21:22 - 2014-08-28 21:27 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-08-21 21:22 - 2014-08-21 21:23 - 00000000 ____D () C:\Users\Pink Pineapple\AppData\Local\Google
2014-08-21 21:22 - 2014-08-21 21:22 - 00003894 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-08-21 21:22 - 2014-08-21 21:22 - 00003642 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-08-21 21:22 - 2014-08-21 21:22 - 00000000 ____D () C:\Program Files (x86)\Google
2014-08-21 21:04 - 2014-08-21 21:04 - 00000404 _____ () C:\Users\Pink Pineapple\Desktop\Local Area Connection - Shortcut.lnk
2014-08-21 19:50 - 2014-08-21 21:32 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\System32\Drivers\MBAMSwissArmy.sys
2014-08-21 19:50 - 2014-08-21 19:50 - 00001108 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-08-21 19:50 - 2014-08-21 19:50 - 00001108 _____ () C:\ProgramData\Desktop\Malwarebytes Anti-Malware.lnk
2014-08-21 19:50 - 2014-08-21 19:50 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-08-21 19:50 - 2014-08-21 19:50 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-08-21 19:50 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbamchameleon.sys
2014-08-21 19:50 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\System32\Drivers\mwac.sys
2014-08-21 19:50 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2014-08-21 19:44 - 2014-08-21 19:44 - 00000000 ____D () C:\Program Files\CCleaner
2014-08-21 19:35 - 2014-08-28 19:24 - 00000000 ___RD () C:\Users\Pink Pineapple\Tools
2014-08-21 12:10 - 2014-08-21 21:02 - 00000000 ____D () C:\Users\Pink Pineapple\Documents\McAfee Vaults
2014-08-21 10:17 - 2014-08-21 10:17 - 00000000 ____D () C:\Quarantine
2014-08-21 10:16 - 2014-08-21 10:16 - 00000000 ____D () C:\mfe
2014-08-21 10:10 - 2014-08-21 10:19 - 00000000 ____D () C:\Program Files\stinger
2014-08-21 10:08 - 2014-08-21 21:11 - 00000000 ____D () C:\ProgramData\McAfee
2014-08-19 03:03 - 2014-05-14 12:23 - 02477536 _____ (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2014-08-19 03:03 - 2014-05-14 12:23 - 00700384 _____ (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2014-08-19 03:03 - 2014-05-14 12:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2014-08-19 03:03 - 2014-05-14 12:23 - 00058336 _____ (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2014-08-19 03:03 - 2014-05-14 12:23 - 00044512 _____ (Microsoft Corporation) C:\Windows\System32\wups2.dll
2014-08-19 03:03 - 2014-05-14 12:23 - 00038880 _____ (Microsoft Corporation) C:\Windows\System32\wups.dll
2014-08-19 03:03 - 2014-05-14 12:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2014-08-19 03:03 - 2014-05-14 12:21 - 02620928 _____ (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2014-08-19 03:03 - 2014-05-14 12:20 - 00097792 _____ (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2014-08-19 03:03 - 2014-05-14 12:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2014-08-19 03:03 - 2014-05-14 09:23 - 00198600 _____ (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2014-08-19 03:03 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2014-08-19 03:03 - 2014-05-14 09:20 - 00036864 _____ (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2014-08-19 03:03 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2014-08-14 03:01 - 2014-06-30 18:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\System32\icardres.dll
2014-08-14 03:01 - 2014-06-30 18:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll
2014-08-14 03:01 - 2014-03-09 17:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\System32\icardagt.exe
2014-08-14 03:01 - 2014-03-09 17:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\System32\infocardapi.dll
2014-08-14 03:01 - 2014-03-09 17:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe
2014-08-14 03:01 - 2014-03-09 17:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll
2014-08-14 03:00 - 2014-06-06 02:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2014-08-14 03:00 - 2014-06-06 02:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\System32\TsWpfWrp.exe
2014-08-13 05:06 - 2014-07-31 19:16 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-08-13 05:06 - 2014-07-25 10:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2014-08-13 05:06 - 2014-07-25 09:51 - 17524224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-08-13 05:06 - 2014-07-25 09:28 - 00048640 _____ (Microsoft Corporation) C:\Windows\System32\ieetwproxystub.dll
2014-08-13 05:06 - 2014-07-25 09:10 - 00033792 _____ (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2014-08-13 05:06 - 2014-07-25 08:34 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-08-13 05:06 - 2014-07-25 08:33 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-08-13 05:06 - 2014-07-25 08:28 - 00072704 _____ (Microsoft Corporation) C:\Windows\System32\JavaScriptCollectionAgent.dll
2014-08-13 05:06 - 2014-07-25 08:21 - 02184704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-08-13 05:06 - 2014-07-25 08:17 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-08-13 05:06 - 2014-07-25 08:08 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-08-13 05:06 - 2014-07-25 07:52 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-08-13 05:06 - 2014-07-25 07:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-08-13 05:06 - 2014-07-25 07:42 - 00692736 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2014-08-13 05:06 - 2014-07-25 07:34 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-08-13 05:06 - 2014-07-25 07:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-08-13 05:06 - 2014-07-25 07:07 - 02001920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-08-13 05:06 - 2014-07-25 06:26 - 01431040 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2014-08-13 05:06 - 2014-07-25 06:00 - 01169920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-08-13 05:06 - 2014-07-15 23:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\System32\tzres.dll
2014-08-13 05:06 - 2014-07-15 22:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-08-13 05:06 - 2014-07-08 22:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\System32\KBDYAK.DLL
2014-08-13 05:06 - 2014-07-08 22:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\System32\KBDTAT.DLL
2014-08-13 05:06 - 2014-07-08 22:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\System32\KBDRU1.DLL
2014-08-13 05:06 - 2014-07-08 22:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\System32\KBDBASH.DLL
2014-08-13 05:06 - 2014-07-08 22:03 - 00006656 _____ (Microsoft Corporation) C:\Windows\System32\KBDRU.DLL
2014-08-13 05:06 - 2014-07-08 21:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDYAK.DLL
2014-08-13 05:06 - 2014-07-08 21:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTAT.DLL
2014-08-13 05:06 - 2014-07-08 21:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU1.DLL
2014-08-13 05:06 - 2014-07-08 21:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU.DLL
2014-08-13 05:06 - 2014-07-08 21:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDBASH.DLL
2014-08-13 05:06 - 2014-07-08 18:38 - 00419992 _____ () C:\Windows\System32\locale.nls
2014-08-13 05:06 - 2014-07-08 18:30 - 00419992 _____ () C:\Windows\SysWOW64\locale.nls
2014-08-13 05:06 - 2014-06-24 22:05 - 14175744 _____ (Microsoft Corporation) C:\Windows\System32\shell32.dll
2014-08-13 05:06 - 2014-06-24 21:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-08-13 05:06 - 2014-06-15 22:10 - 00985536 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys
2014-08-13 05:06 - 2014-06-03 06:02 - 03241984 _____ (Microsoft Corporation) C:\Windows\System32\msi.dll
2014-08-13 05:06 - 2014-06-03 06:02 - 01941504 _____ (Microsoft Corporation) C:\Windows\System32\authui.dll
2014-08-13 05:06 - 2014-06-03 06:02 - 00504320 _____ (Microsoft Corporation) C:\Windows\System32\msihnd.dll
2014-08-13 05:06 - 2014-06-03 06:02 - 00112064 _____ (Microsoft Corporation) C:\Windows\System32\consent.exe
2014-08-13 05:06 - 2014-06-03 05:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-08-13 05:06 - 2014-06-03 05:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-08-13 05:06 - 2014-06-03 05:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2014-08-13 05:05 - 2014-07-31 19:41 - 00348856 _____ (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2014-08-13 05:05 - 2014-07-25 10:52 - 23645696 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2014-08-13 05:05 - 2014-07-25 10:01 - 00004096 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollectorres.dll
2014-08-13 05:05 - 2014-07-25 09:30 - 00066048 _____ (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2014-08-13 05:05 - 2014-07-25 09:28 - 00548352 _____ (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2014-08-13 05:05 - 2014-07-25 09:25 - 02774528 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2014-08-13 05:05 - 2014-07-25 09:25 - 00083968 _____ (Microsoft Corporation) C:\Windows\System32\MshtmlDac.dll
2014-08-13 05:05 - 2014-07-25 09:11 - 00051200 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2014-08-13 05:05 - 2014-07-25 09:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-08-13 05:05 - 2014-07-25 09:03 - 00598016 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll
2014-08-13 05:05 - 2014-07-25 09:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2014-08-13 05:05 - 2014-07-25 09:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollector.exe
2014-08-13 05:05 - 2014-07-25 08:59 - 00758272 _____ (Microsoft Corporation) C:\Windows\System32\jscript9diag.dll
2014-08-13 05:05 - 2014-07-25 08:47 - 00940032 _____ (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
2014-08-13 05:05 - 2014-07-25 08:40 - 00452096 _____ (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll
2014-08-13 05:05 - 2014-07-25 08:34 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-08-13 05:05 - 2014-07-25 08:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-08-13 05:05 - 2014-07-25 08:28 - 05824512 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2014-08-13 05:05 - 2014-07-25 08:19 - 00195584 _____ (Microsoft Corporation) C:\Windows\System32\msrating.dll
2014-08-13 05:05 - 2014-07-25 08:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-08-13 05:05 - 2014-07-25 08:17 - 00085504 _____ (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2014-08-13 05:05 - 2014-07-25 08:12 - 00438784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-08-13 05:05 - 2014-07-25 08:10 - 00292864 _____ (Microsoft Corporation) C:\Windows\System32\dxtrans.dll
2014-08-13 05:05 - 2014-07-25 08:10 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-08-13 05:05 - 2014-07-25 08:06 - 04204032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-08-13 05:05 - 2014-07-25 07:47 - 00631808 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2014-08-13 05:05 - 2014-07-25 07:39 - 02087936 _____ (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2014-08-13 05:05 - 2014-07-25 07:39 - 01249280 _____ (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll
2014-08-13 05:05 - 2014-07-25 07:36 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-08-13 05:05 - 2014-07-25 07:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-08-13 05:05 - 2014-07-25 07:23 - 13547008 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2014-08-13 05:05 - 2014-07-25 07:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-08-13 05:05 - 2014-07-25 07:03 - 11772928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-08-13 05:05 - 2014-07-25 06:52 - 02266624 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll
2014-08-13 05:05 - 2014-07-25 06:17 - 00846336 _____ (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll
2014-08-13 05:05 - 2014-07-25 06:09 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-08-13 05:05 - 2014-07-25 06:05 - 01792512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-08-13 05:03 - 2014-08-06 22:06 - 00529920 _____ (Microsoft Corporation) C:\Windows\System32\aepdu.dll
2014-08-13 05:03 - 2014-08-06 22:01 - 00424448 _____ (Microsoft Corporation) C:\Windows\System32\aeinv.dll
2014-08-13 05:03 - 2014-07-13 22:02 - 01216000 _____ (Microsoft Corporation) C:\Windows\System32\rpcrt4.dll
2014-08-13 05:03 - 2014-07-13 21:40 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2014-08-11 19:26 - 2014-08-14 03:06 - 00000000 ____D () C:\Windows\System32\MRT
2014-08-11 19:26 - 2014-08-14 03:04 - 99218768 _____ (Microsoft Corporation) C:\Windows\System32\MRT.exe
2014-08-09 16:26 - 2014-08-09 16:27 - 05155464 _____ (McAfee, Inc.) C:\Users\Pink Pineapple\Desktop\McAfeeSetup-AutoLogin_exe
2014-08-09 16:24 - 2014-08-09 16:27 - 05155464 _____ (McAfee, Inc.) C:\Users\Pink Pineapple\Downloads\McAfeeSetup-AutoLogin_exe (4)
2014-08-09 16:17 - 2014-08-09 16:17 - 00000000 _____ () C:\Users\Pink Pineapple\Desktop\McAfeeSetup-AutoLogin_exe.os40w69.partial
2014-08-09 16:10 - 2014-08-09 16:10 - 00000000 ____D () C:\ProgramData\Citrix
2014-08-09 16:06 - 2014-08-21 11:01 - 00000000 ____D () C:\Users\Pink Pineapple\AppData\Local\Deployment
2014-08-09 16:06 - 2014-08-09 16:06 - 00000000 ____D () C:\Users\Pink Pineapple\AppData\Local\Citrix
2014-08-09 16:06 - 2014-08-09 16:06 - 00000000 ____D () C:\Users\Pink Pineapple\AppData\Local\Apps\2.0
2014-08-09 16:06 - 2014-08-09 16:06 - 00000000 ____D () C:\Program Files (x86)\Citrix
2014-08-09 16:02 - 2014-08-09 16:03 - 05155464 _____ (McAfee, Inc.) C:\Users\Pink Pineapple\Downloads\McAfeeSetup-AutoLogin_exe
2014-08-09 15:58 - 2014-08-09 15:58 - 05155464 _____ (McAfee, Inc.) C:\Users\Pink Pineapple\Downloads\McAfeeSetup-AutoLogin_exe (3)
2014-08-09 15:58 - 2014-08-09 15:58 - 05155464 _____ (McAfee, Inc.) C:\Users\Pink Pineapple\Downloads\McAfeeSetup-AutoLogin_exe (2)
2014-08-09 15:57 - 2014-08-09 15:57 - 05155464 _____ (McAfee, Inc.) C:\Users\Pink Pineapple\Downloads\McAfeeSetup-AutoLogin_exe (1)
2014-08-09 15:33 - 2014-08-09 15:33 - 00002790 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-08-09 10:00 - 2014-08-20 22:07 - 00000000 ____D () C:\Users\Pink Pineapple\AppData\Local\Spotify
2014-08-09 10:00 - 2014-08-09 10:00 - 00001859 _____ () C:\Users\Pink Pineapple\Desktop\Spotify.lnk
2014-08-09 09:59 - 2014-08-25 14:28 - 00000000 ____D () C:\Users\Pink Pineapple\AppData\Roaming\Spotify
2014-08-04 12:25 - 2014-08-04 12:25 - 00000000 ____H () C:\Windows\System32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
 
==================== One Month Modified Files and Folders =======
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2014-08-29 07:53 - 2014-08-27 20:14 - 00000000 ____D () C:\FRST
2014-08-29 07:48 - 2013-11-06 22:16 - 01080610 _____ () C:\Windows\WindowsUpdate.log
2014-08-29 07:48 - 2009-07-14 00:45 - 00031312 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-08-29 07:48 - 2009-07-14 00:45 - 00031312 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-08-29 07:27 - 2014-08-21 21:22 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-08-29 07:24 - 2013-11-06 20:21 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-08-28 21:27 - 2014-08-21 21:22 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-08-28 21:04 - 2014-08-24 08:06 - 00000000 ____D () C:\ProgramData\Windows Genuine Advantage
2014-08-28 21:04 - 2014-04-17 09:38 - 00000000 ____D () C:\Users\Pink Pineapple\AppData\Local\CrashDumps
2014-08-28 20:13 - 2014-08-28 20:04 - 57655296 _____ () C:\Users\Pink Pineapple\Downloads\APD_407EWM.exe
2014-08-28 19:38 - 2013-11-06 20:32 - 00000000 ____D () C:\Program Files (x86)\Dell Backup and Recovery
2014-08-28 19:30 - 2014-08-27 20:40 - 00121386 _____ () C:\Windows\PFRO.log
2014-08-28 19:30 - 2014-08-27 20:40 - 00000280 _____ () C:\Windows\setupact.log
2014-08-28 19:30 - 2009-07-14 01:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-08-28 19:27 - 2014-08-28 19:27 - 00000000 ____D () C:\Users\Pink Pineapple\AppData\Roaming\Dayxohup
2014-08-28 19:24 - 2014-08-21 19:35 - 00000000 ___RD () C:\Users\Pink Pineapple\Tools
2014-08-28 15:47 - 2014-04-03 10:46 - 00000000 ____D () C:\Program Files (x86)\Intuit
2014-08-28 15:40 - 2014-08-28 15:35 - 31056184 _____ () C:\Users\Pink Pineapple\Downloads\QB_Component_Repair_Tool.exe
2014-08-28 15:28 - 2009-07-14 01:32 - 00000000 ____D () C:\Windows\System32\FxsTmp
2014-08-28 03:19 - 2009-07-14 00:45 - 00269128 _____ () C:\Windows\System32\FNTCACHE.DAT
2014-08-27 20:54 - 2013-11-06 20:31 - 00000000 ____D () C:\ProgramData\Adobe
2014-08-27 20:49 - 2014-08-27 20:49 - 00319912 _____ (Oracle Corporation) C:\Windows\System32\javaws.exe
2014-08-27 20:49 - 2014-08-27 20:49 - 00189352 _____ (Oracle Corporation) C:\Windows\System32\javaw.exe
2014-08-27 20:49 - 2014-08-27 20:49 - 00189352 _____ (Oracle Corporation) C:\Windows\System32\java.exe
2014-08-27 20:49 - 2014-08-27 20:49 - 00111016 _____ (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge-64.dll
2014-08-27 20:49 - 2014-08-27 20:49 - 00000000 ____D () C:\Program Files\Java
2014-08-27 20:45 - 2014-08-27 20:45 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-08-27 20:45 - 2014-08-27 20:45 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-08-27 20:45 - 2014-08-27 20:45 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-08-27 20:45 - 2014-08-27 20:45 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-08-27 20:45 - 2014-08-27 20:45 - 00000000 ____D () C:\ProgramData\Sun
2014-08-27 20:45 - 2014-08-27 20:45 - 00000000 ____D () C:\Program Files (x86)\Java
2014-08-27 20:40 - 2014-08-27 20:40 - 00000000 _____ () C:\Windows\setuperr.log
2014-08-27 20:06 - 2014-08-27 19:46 - 00000000 ____D () C:\Qoobox
2014-08-27 20:06 - 2009-07-13 23:20 - 00000000 __RHD () C:\users\Default
2014-08-27 19:58 - 2014-08-27 19:58 - 00000000 ____D () C:\Windows\erdnt
2014-08-27 19:58 - 2014-04-03 11:07 - 00000000 ____D () C:\users\Pink Pineapple
2014-08-27 19:58 - 2009-07-13 22:34 - 00000215 _____ () C:\Windows\system.ini
2014-08-27 17:18 - 2009-07-14 01:13 - 00781790 _____ () C:\Windows\System32\PerfStringBackup.INI
2014-08-27 17:15 - 2014-08-27 17:15 - 00000000 ____H () C:\Windows\System32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
2014-08-27 07:50 - 2014-04-03 10:48 - 00058408 _____ () C:\Users\Pink Pineapple\AppData\Local\GDIPFONTCACHEV1.DAT
2014-08-26 17:17 - 2014-08-26 17:17 - 00001168 _____ () C:\Users\Public\Desktop\TeamViewer 9.lnk
2014-08-26 17:17 - 2014-08-26 17:17 - 00001168 _____ () C:\ProgramData\Desktop\TeamViewer 9.lnk
2014-08-26 17:16 - 2014-08-26 17:16 - 00000000 ____D () C:\Program Files (x86)\TeamViewer
2014-08-25 14:28 - 2014-08-09 09:59 - 00000000 ____D () C:\Users\Pink Pineapple\AppData\Roaming\Spotify
2014-08-24 20:15 - 2014-04-13 15:19 - 00000127 _____ () C:\Users\Pink Pineapple\Documents\reprev.opt
2014-08-22 22:07 - 2014-08-27 20:46 - 00404480 _____ (Microsoft Corporation) C:\Windows\System32\gdi32.dll
2014-08-22 21:45 - 2014-08-27 20:46 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-22 20:59 - 2014-08-27 20:46 - 03163648 _____ (Microsoft Corporation) C:\Windows\System32\win32k.sys
2014-08-22 09:59 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\rescache
2014-08-21 21:32 - 2014-08-21 19:50 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\System32\Drivers\MBAMSwissArmy.sys
2014-08-21 21:23 - 2014-08-21 21:23 - 00002220 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-08-21 21:23 - 2014-08-21 21:23 - 00002220 _____ () C:\ProgramData\Desktop\Google Chrome.lnk
2014-08-21 21:23 - 2014-08-21 21:22 - 00000000 ____D () C:\Users\Pink Pineapple\AppData\Local\Google
2014-08-21 21:22 - 2014-08-21 21:22 - 00003894 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-08-21 21:22 - 2014-08-21 21:22 - 00003642 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-08-21 21:22 - 2014-08-21 21:22 - 00000000 ____D () C:\Program Files (x86)\Google
2014-08-21 21:11 - 2014-08-21 10:08 - 00000000 ____D () C:\ProgramData\McAfee
2014-08-21 21:04 - 2014-08-21 21:04 - 00000404 _____ () C:\Users\Pink Pineapple\Desktop\Local Area Connection - Shortcut.lnk
2014-08-21 21:02 - 2014-08-21 12:10 - 00000000 ____D () C:\Users\Pink Pineapple\Documents\McAfee Vaults
2014-08-21 20:19 - 2014-07-09 15:38 - 00000000 ____D () C:\Program Files (x86)\Movies Toolbar
2014-08-21 19:50 - 2014-08-21 19:50 - 00001108 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-08-21 19:50 - 2014-08-21 19:50 - 00001108 _____ () C:\ProgramData\Desktop\Malwarebytes Anti-Malware.lnk
2014-08-21 19:50 - 2014-08-21 19:50 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-08-21 19:50 - 2014-08-21 19:50 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-08-21 19:44 - 2014-08-21 19:44 - 00000000 ____D () C:\Program Files\CCleaner
2014-08-21 11:01 - 2014-08-09 16:06 - 00000000 ____D () C:\Users\Pink Pineapple\AppData\Local\Deployment
2014-08-21 10:19 - 2014-08-21 10:10 - 00000000 ____D () C:\Program Files\stinger
2014-08-21 10:17 - 2014-08-21 10:17 - 00000000 ____D () C:\Quarantine
2014-08-21 10:16 - 2014-08-21 10:16 - 00000000 ____D () C:\mfe
2014-08-21 10:16 - 2009-07-14 00:54 - 00000749 ___RH () C:\Windows\WindowsShell.Manifest
2014-08-21 10:16 - 2009-07-13 23:20 - 00000000 __RHD () C:\Users\Public\Libraries
2014-08-20 22:07 - 2014-08-09 10:00 - 00000000 ____D () C:\Users\Pink Pineapple\AppData\Local\Spotify
2014-08-14 03:27 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-08-14 03:06 - 2014-08-11 19:26 - 00000000 ____D () C:\Windows\System32\MRT
2014-08-14 03:04 - 2014-08-11 19:26 - 99218768 _____ (Microsoft Corporation) C:\Windows\System32\MRT.exe
2014-08-14 03:00 - 2014-05-07 03:00 - 00000000 ___SD () C:\Windows\System32\CompatTel
2014-08-09 16:27 - 2014-08-09 16:26 - 05155464 _____ (McAfee, Inc.) C:\Users\Pink Pineapple\Desktop\McAfeeSetup-AutoLogin_exe
2014-08-09 16:27 - 2014-08-09 16:24 - 05155464 _____ (McAfee, Inc.) C:\Users\Pink Pineapple\Downloads\McAfeeSetup-AutoLogin_exe (4)
2014-08-09 16:17 - 2014-08-09 16:17 - 00000000 _____ () C:\Users\Pink Pineapple\Desktop\McAfeeSetup-AutoLogin_exe.os40w69.partial
2014-08-09 16:10 - 2014-08-09 16:10 - 00000000 ____D () C:\ProgramData\Citrix
2014-08-09 16:06 - 2014-08-09 16:06 - 00000000 ____D () C:\Users\Pink Pineapple\AppData\Local\Citrix
2014-08-09 16:06 - 2014-08-09 16:06 - 00000000 ____D () C:\Users\Pink Pineapple\AppData\Local\Apps\2.0
2014-08-09 16:06 - 2014-08-09 16:06 - 00000000 ____D () C:\Program Files (x86)\Citrix
2014-08-09 16:03 - 2014-08-09 16:02 - 05155464 _____ (McAfee, Inc.) C:\Users\Pink Pineapple\Downloads\McAfeeSetup-AutoLogin_exe
2014-08-09 16:01 - 2010-11-21 03:16 - 00000000 ___RD () C:\Users\Public\Recorded TV
2014-08-09 15:58 - 2014-08-09 15:58 - 05155464 _____ (McAfee, Inc.) C:\Users\Pink Pineapple\Downloads\McAfeeSetup-AutoLogin_exe (3)
2014-08-09 15:58 - 2014-08-09 15:58 - 05155464 _____ (McAfee, Inc.) C:\Users\Pink Pineapple\Downloads\McAfeeSetup-AutoLogin_exe (2)
2014-08-09 15:57 - 2014-08-09 15:57 - 05155464 _____ (McAfee, Inc.) C:\Users\Pink Pineapple\Downloads\McAfeeSetup-AutoLogin_exe (1)
2014-08-09 15:35 - 2011-02-10 10:25 - 00000000 ____D () C:\Windows\panther
2014-08-09 15:33 - 2014-08-09 15:33 - 00002790 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-08-09 10:00 - 2014-08-09 10:00 - 00001859 _____ () C:\Users\Pink Pineapple\Desktop\Spotify.lnk
2014-08-07 19:59 - 2010-11-21 03:06 - 00000000 ____D () C:\Windows\SysWOW64\sysprep
2014-08-06 22:06 - 2014-08-13 05:03 - 00529920 _____ (Microsoft Corporation) C:\Windows\System32\aepdu.dll
2014-08-06 22:01 - 2014-08-13 05:03 - 00424448 _____ (Microsoft Corporation) C:\Windows\System32\aeinv.dll
2014-08-05 09:20 - 2010-11-20 23:27 - 00270496 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe
2014-08-04 12:25 - 2014-08-04 12:25 - 00000000 ____H () C:\Windows\System32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2014-07-31 19:41 - 2014-08-13 05:05 - 00348856 _____ (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2014-07-31 19:16 - 2014-08-13 05:06 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
 
==================== Known DLLs (Whitelisted) ================
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
 
==================== Restore Points  =========================
 
Restore point made on: 2014-08-26 03:54:43
Restore point made on: 2014-08-28 03:00:39
Restore point made on: 2014-08-28 15:43:28
Restore point made on: 2014-08-28 15:44:52
Restore point made on: 2014-08-28 15:46:06
Restore point made on: 2014-08-28 15:46:46
Restore point made on: 2014-08-28 15:47:41
Restore point made on: 2014-08-28 15:48:12
Restore point made on: 2014-08-28 15:48:53
Restore point made on: 2014-08-28 16:16:25
Restore point made on: 2014-08-28 16:16:44
Restore point made on: 2014-08-28 16:16:59
 
==================== Memory info =========================== 
 
Percentage of memory in use: 14%
Total physical RAM: 4014.8 MB
Available physical RAM: 3415.21 MB
Total Pagefile: 4013 MB
Available Pagefile: 3404.8 MB
Total Virtual: 8192 MB
Available Virtual: 8191.89 MB
 
==================== Drives ================================
 
Drive c: (OS) (Fixed) (Total:455.52 GB) (Free:405.55 GB) NTFS
Drive d: (RECOVERY) (Fixed) (Total:10.2 GB) (Free:3.09 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive e: (Repair disc Windows 7 64-bit) (CDROM) (Total:0.16 GB) (Free:0 GB) UDF
Drive f: () (Fixed) (Total:0.04 GB) (Free:0.04 GB) FAT
Drive g: (8GB) (Removable) (Total:7.53 GB) (Free:4.43 GB) FAT32
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 465.8 GB) (Disk ID: E4089CDF)
Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)
Partition 2: (Active) - (Size=10.2 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=455.5 GB) - (Type=07 NTFS)
 
========================================================
Disk: 1 (Size: 7.5 GB) (Disk ID: C3072E18)
Partition 1: (Active) - (Size=7.5 GB) - (Type=0B)
 
 
LastRegBack: 2014-08-28 03:49
 
==================== End Of Log ============================


#14 aharonov

aharonov

  • Malware Response Team
  • 2,441 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:44 PM

Posted 29 August 2014 - 07:58 AM

Ok, now we're gonna fix these entries in Recovery Environment. Afterwards boot the computer into normal mode of Windows again and post a fresh FRST log:


Step 1

Please download this attached Attached File  fixlist.txt   479bytes   3 downloads and save it on the same flash drive as FRST.
  • Plug in the flash drive to the infected computer, enter the System Recovery Options and open FRST.
  • Press the Fix button.
  • When finished, a log file (Fixlog.txt) is saved on the flash drive.
    Please copy and paste its contents in your next reply.


Step 2

Start your computer into normal mode of Windows.
  • Move FRST back to the Desktop and start it with administator privileges.
  • Make sure the option Addition.txt (under Optional Scan) is checked.
  • Press the Scan button.
  • When finished, FRST will produce two logs (FRST.txt and Addition.txt) in the same directory the tool was run from.
    Please copy and paste these logs in your next reply.


#15 compcrewnpt

compcrewnpt
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:04:44 PM

Posted 29 August 2014 - 09:50 AM

Ok. I'll report back soon.






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users