Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

MBam not catching Adware cause, Adware getting worse


  • This topic is locked This topic is locked
13 replies to this topic

#1 HawkZ28

HawkZ28

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:04:11 AM

Posted 03 June 2015 - 01:47 PM

Long time lurker, first time poster.

 

I used my wifes computer last night for the first time in a couple weeks, and noticed that when I'd click the scoll bar or really anything on the screen in Chrome, it would generate a new tab for an ad.  Also, when I was searching for a belt for our eXmark, it would show a drop down box from the top from Foxydeal or something like that, even on eBay.  

 

I checked the ad/remove programs for any new programs, and found nothing.  Looked in the C: program folders for anything new or suspicious and didn't see anything.  I have ran 2 full scans with Malwarebytesarrow-10x10.png Premium with no luck.  We also run MBam Anti Exploit. Since they didn't pick up anything, I dl'd HJT.  HJT said that it couldn't modify host files and I needed to do it if anything came up, but I think I'm missing something.  I'm probably not reading the logfile correctly.  

 

Thanks in advance for the help!  

 

Computer is running Win 8.1.  Below is the logfile:

 

Logfile of Trend Microarrow-10x10.png HijackThis v2.0.5
Scan saved at 1:15:29 PM, on 6/3/2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17416)
CHROME: 1.5.1383.0
 
Boot mode: Normal
 
Running processes:
C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperAgent.exe
C:\Program Files (x86)\Motorola Mobility\MotoCast\MotoCast.exe
C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
C:\Program Files (x86) Malwarebytesarrow-10x10.png Anti-Exploit\mbae.exe
C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe
C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\MotoCast-thumbnailer.exe
C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Dell Update\DellUpTray.exe
C:\Users\Alisha Downloadsarrow-10x10.png\HijackThis.exe
 
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://dell13.msn.com/?pc=DCJB
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://dell13.msn.com/?pc=DCJB
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
O4 - HKLM\..\Run: Malwarebytesarrow-10x10.png Anti-Exploit] C:\Program Files (x86) Malwarebytesarrow-10x10.png Anti-Exploit\mbae.exe
O4 - HKLM\..\Run: [AgentMonitor] C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe
O4 - HKLM\..\Run: Adobearrow-10x10.png ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [EPLTarget\P0000000000000000] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATILBE.EXE /EPT "EPLTarget\P0000000000000000" /M "XP-310 Series"
O4 - HKCU\..\Run: [EPLTarget\P0000000000000001] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATILBE.EXE /EPT "EPLTarget\P0000000000000001" /M "XP-310 Series"
O4 - HKCU\..\Run: [Google Update] "C:\Users\Alisha\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [MotoCast] "C:\Program Files (x86)\Motorola Mobility\MotoCast\MotoLauncher.lnk"
O4 - HKLM\..\Policies\Explorer\Run: [BtvStack] "C:\Program Files (x86) Dell Wirelessarrow-10x10.png\Bluetooth Suite\BtvStack.exe"
O4 - HKUS\S-1-5-21-2865801210-255665649-1679975380-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run: [EPLTarget\P0000000000000000] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATILBE.EXE /EPT "EPLTarget\P0000000000000000" /M "XP-310 Series" (User '?')
O4 - HKUS\S-1-5-21-2865801210-255665649-1679975380-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run: [EPLTarget\P0000000000000001] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATILBE.EXE /EPT "EPLTarget\P0000000000000001" /M "XP-310 Series" (User '?')
O4 - HKUS\S-1-5-21-2865801210-255665649-1679975380-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run: [Google Update] "C:\Users\Alisha\AppData\Local\Google\Update\GoogleUpdate.exe" /c (User '?')
O4 - HKUS\S-1-5-21-2865801210-255665649-1679975380-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run: [MotoCast] "C:\Program Files (x86)\Motorola Mobility\MotoCast\MotoLauncher.lnk" (User '?')
O4 - S-1-5-21-2865801210-255665649-1679975380-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 Startup: Epson all-in-one Registration.lnk = Alisha\AppData\Roaming\Leadertech\PowerRegister\Epson all-in-one Registration.exe (User '?')
O4 - Startup: Epson all-in-one Registration.lnk = Alisha\AppData\Roaming\Leadertech\PowerRegister\Epson all-in-one Registration.exe
O4 - Global Startup: Virtual Router Manager.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: *.dell.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{B38AA017-B810-47AC-BE24-B1D95D92D7BF}: NameServer = 8.8.8.8,8.8.4.4
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AtherosSvc - Windows ® Win 7 DDK provider - C:\Program Files (x86) Dell Wirelessarrow-10x10.png\Bluetooth Suite\adminservice.exe
O23 - Service: Intel® Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: Dell Data Vault (DellDataVault) - Dell Inc. - C:\Program Files\Dell\DellDataVault\DellDataVault.exe
O23 - Service: Dell Data Vault Wizard (DellDataVaultWiz) - Dell Inc. - C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe
O23 - Service: Dell Digital Delivery Service (DellDigitalDelivery) - Dell Products, LP. - c:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe
O23 - Service: Dell Update Service (DellUpdate) - Dell Inc. - C:\Program Files (x86)\Dell Update\DellUpService.exe
O23 - Service: DeviceMonitorService - Nero AG - C:\Program Files (x86)\Motorola Media Link\Lite\NServiceEntry.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: EpsonCustomerParticipation - SEIKO EPSON CORPORATION - C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe
O23 - Service: Epson Scanner Service (EpsonScanSvc) - Unknown owner - C:\Windows\system32\EscSvc64.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel® Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel® HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\Windows\system32\igfxCUIService.exe (file missing)
O23 - Service: Intel® Capability Licensing Service Interface - Intel® Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel® Capability Licensing Service TCP IP Interface - Intel® Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel® Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
O23 - Service: Malwarebytesarrow-10x10.png Anti-Exploit Service (MbaeSvc) - Malwarebytesarrow-10x10.png Corporation - C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: MotoHelper Service (MotoHelper) - Unknown owner - C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperService.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - CyberLink - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SoftThinks Agent Service (SftService) - SoftThinks SAS - C:\Program Files (x86)\Dell Backup and Recoveryarrow-10x10.png\sftservice.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Dell SupportAssist Agent (SupportAssistAgent) - Dell Inc. - C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VirtualRouterService (Virtual Router) - Chris Pietschmann (http://pietschsoft.com) - C:\Program Files (x86)\Virtual Router\VirtualRouterService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles% Windows Defenderarrow-10x10.png\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES% Windows Media Playerarrow-10x10.png\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Wyse PocketCloud (WysePocketCloud) - Unknown owner - C:\Program Files (x86)\Wyse\PocketCloud\PocketCloudService.exe
O23 - Service: Wyse RemoteAccess (WyseRemoteAccess) - DELLarrow-10x10.png Inc. - C:\Program Files (x86)\Wyse\PocketCloud\WyseRemoteAccess.exe
 
--
End of file - 12090 bytes
 


BC AdBot (Login to Remove)

 


#2 deeprybka

deeprybka

  • Malware Response Team
  • 5,198 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Germany
  • Local time:11:11 AM

Posted 03 June 2015 - 02:04 PM

Hi & :welcome: to Bleeping Computer Forums!
My name is Jürgen and I will be assisting you with your Malware related problems. :warrior:

Before we move on, please read the following points carefully: :exclame:
  • My native language isn't English. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.
  • Please read my instructions completely. If there is anything that you do not understand kindly ask before proceeding.
  • Perform everything in the correct order. Sometimes one step requires the previous one.
  • If you have any problems while you are follow my instructions, Stop there and tell me the exact nature of your problem.
  • If you have illegal/cracked software, cracks, keygens, etc. on the system, please remove or uninstall them now!
  • Do not run any other scans without instruction or Add/ Remove Software unless I tell you to do so. This would change the output of our tools and could be confusing for me.
  • Post all Logfiles as a reply rather than as an attachment unless I specifically ask you. If you can not post all logfiles in one reply, feel free to use more posts.
  • If I don't hear from you within 5 days from this initial or any subsequent post, then this thread will be closed.
  • If I don't reply within 24 hours please PM me!
  • Stay with me. I will give you some advice about prevention after the cleanup process. Absence of symptoms does not always mean the computer is clean.
Step 1

Please run a FRST scan. This will help us diagnose your problem.

frst.pngfrstscan.png
Please download Farbar Recovery Scan Tool and save it to your Desktop.
(If you are not sure which version (32-/64-bit) applies to your system, download and try to start both of them as just the right one will run.)
  • Start FRST with administator privileges.
  • Make sure the option Addition.txt is checked and press the Scan button.
  • When finished, FRST will produce two logs (FRST.txt and Addition.txt) in the same directory the tool was run from.
  • Please copy and paste these logs in your next reply.

regards,
deeprybka
:busy:
Neminem laede, immo omnes, quantum potes, iuva. Arthur Schopenhauer
 
unite_blue.png
asap.png

#3 HawkZ28

HawkZ28
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:04:11 AM

Posted 03 June 2015 - 10:06 PM

Thank you so much for the help and response!  Per your directions, I downloaded FRST, ensured that addition.txt was checked, and hit scan.  I did get the following error message once I opened it to run:

 

Application Error

Exception EAccessViolation in module ERUNT.exe at 00003A62.  Access violation at address 00403A62 in module 'ERUNT.exe'. Read of address 0069005C.

 

I saved the screenshot in a word file, but I can't upload.  

 

I clicked "OK", and hit scan.  Below are the results:

 

FRST- Notepad

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:03-06-2015
Ran by Alisha (administrator) on ALISHAHAWKINSPC on 03-06-2015 21:49:59
Running from C:\Users\Alisha\Desktop
Loaded Profiles: Alisha (Available Profiles: Alisha)
Platform: Windows 8.1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Windows ® Win 7 DDK provider) C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\AdminService.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Nero AG) C:\Program Files (x86)\Motorola Media Link\Lite\NServiceEntry.exe
(SEIKO EPSON CORPORATION) C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe
(Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
(Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
() C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperService.exe
(Dell Inc.) C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Chris Pietschmann (http://pietschsoft.com)) C:\Program Files (x86)\Virtual Router\VirtualRouterService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
() C:\Program Files (x86)\Wyse\PocketCloud\PocketCloudService.exe
(DELL Inc.) C:\Program Files (x86)\Wyse\PocketCloud\WyseRemoteAccess.exe
() C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperAgent.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
() C:\Windows\System32\igfxTray.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Qualcomm®Atheros®) C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtvStack.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
() C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\ActivateDesktop.exe
(Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe
() C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(Dell Inc.) C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(SoftThinks SAS) C:\Program Files (x86)\Dell Backup and Recovery\SftService.exe
(Dell Inc.) C:\Program Files\Dell\DellDataVault\DellDataVault.exe
(Dell Inc.) C:\Program Files (x86)\Dell Update\DellUpService.exe
(Dell Inc.) C:\Program Files (x86)\Dell Update\DellUpTray.exe
(SoftThinks - Dell) C:\Program Files (x86)\Dell Backup and Recovery\Components\DBRUpdate\DBRUpd.exe
(SoftThinks - Dell) C:\Program Files (x86)\Dell Backup and Recovery\Toaster.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
() C:\Program Files (x86)\Dell Backup and Recovery\Components\Shell\DBRCrawler.exe
() C:\Program Files (x86)\ClockworkMod\Tether\win32\adb.exe
(PC-Doctor, Inc.) C:\Program Files\Dell\SupportAssist\imstrayicon.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7202520 2013-08-19] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1321688 2013-08-07] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_PushButton] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1321688 2013-08-07] (Realtek Semiconductor)
HKLM\...\Run: [QuickSet] => c:\Program Files\Dell\QuickSet\QuickSet.exe [5762408 2013-06-03] (Dell Inc.)
HKLM\...\Run: [IgfxTray] => C:\Windows\system32\igfxtray.exe [392592 2015-03-31] ()
HKLM\...\Run: [HotKeysCmds] => "C:\Windows\system32\hkcmd.exe"
HKLM\...\Run: [Persistence] => "C:\Windows\system32\igfxpers.exe"
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-30] (Intel Corporation)
HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [1065024 2014-05-02] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [Malwarebytes Anti-Exploit] => C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe [2618680 2015-04-08] (Malwarebytes Corporation)
HKLM-x32\...\Run: [AgentMonitor] => C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe [401280 2014-06-20] ()
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
Winlogon\Notify\igfxcui: igfxdev.dll [X]
HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtvStack.exe [132736 2013-10-30] (Qualcomm®Atheros®)
HKU\S-1-5-21-2865801210-255665649-1679975380-1001\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\x64\3\E_IATILBE.EXE [297024 2014-12-02] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-2865801210-255665649-1679975380-1001\...\Run: [EPLTarget\P0000000000000001] => C:\Windows\system32\spool\DRIVERS\x64\3\E_IATILBE.EXE [297024 2014-12-02] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-2865801210-255665649-1679975380-1001\...\Run: [Google Update] => C:\Users\Alisha\AppData\Local\Google\Update\GoogleUpdate.exe [107912 2014-10-12] (Google Inc.)
HKU\S-1-5-21-2865801210-255665649-1679975380-1001\...\Run: [MotoCast] => C:\Program Files (x86)\Motorola Mobility\MotoCast\MotoLauncher.lnk [2069 2015-03-04] ()
HKU\S-1-5-21-2865801210-255665649-1679975380-1001\...\MountPoints2: {090591f6-dadf-11e3-825a-9cd21e35c6ac} - "E:\MotoCastSetup.exe" -a
HKU\S-1-5-21-2865801210-255665649-1679975380-1001\...\MountPoints2: {3e44ef56-7e93-11e4-8290-9cd21e35c6ac} - "G:\MotoCastSetup.exe" -a
HKU\S-1-5-21-2865801210-255665649-1679975380-1001\...\MountPoints2: {47e27efb-8dd8-11e4-8296-9cd21e35c6ac} - "F:\InnoTabSetup.exe" 
HKU\S-1-5-21-2865801210-255665649-1679975380-1001\...\MountPoints2: {4a00c77e-b722-11e4-82a4-9cd21e35c6ac} - "F:\MotoCastSetup.exe" -a
HKU\S-1-5-21-2865801210-255665649-1679975380-1001\...\MountPoints2: {7454ca40-4077-11e4-8263-9cd21e35c6ac} - "E:\MotoCastSetup.exe" -a
HKU\S-1-5-21-2865801210-255665649-1679975380-1001\...\MountPoints2: {abeb6465-0895-11e4-825d-9cd21e35c6ac} - "E:\VZW_Software_upgrade_assistant.exe" 
HKU\S-1-5-21-2865801210-255665649-1679975380-1001\...\MountPoints2: {ad87cf83-ed5e-11e4-82af-9cd21e35c6ac} - "F:\MotoCastSetup.exe" -a
HKU\S-1-5-21-2865801210-255665649-1679975380-1001\...\MountPoints2: {bbf5dd46-d412-11e4-82a8-9cd21e35c6ac} - "E:\VerizonWirelessUpgradeAssistantSetup.exe" -a
Startup: C:\Users\Alisha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Epson all-in-one Registration.lnk [2014-05-11]
ShortcutTarget: Epson all-in-one Registration.lnk -> C:\Users\Alisha\AppData\Roaming\Leadertech\PowerRegister\Epson all-in-one Registration.exe (Leader Technologies/Epson)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Virtual Router Manager.lnk [2015-03-26]
ShortcutTarget: Virtual Router Manager.lnk -> C:\Windows\Installer\{BE905C46-2B34-4D73-AEE1-769ED138E0FF}\_118D1A4EFFA6998C3492EB.exe ()
ShellIconOverlayIdentifiers: [DBARFileBackuped] -> {831cebdd-6baf-4432-be76-9e0989c14aef} => C:\Windows\system32\mscoree.dll [2013-08-22] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [DBARFileNotBackuped] -> {275e4fd7-21ef-45cf-a836-832e5d2cc1b3} => C:\Windows\system32\mscoree.dll [2013-08-22] (Microsoft Corporation)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKU\S-1-5-21-2865801210-255665649-1679975380-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://dell13.msn.com/?pc=DCJB
HKU\S-1-5-21-2865801210-255665649-1679975380-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://dell13.msn.com/?pc=DCJB
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\.DEFAULT -> DefaultScope {7F595587-C0D2-4359-B315-BDA9DD524B45} URL = 
SearchScopes: HKU\.DEFAULT -> {7F595587-C0D2-4359-B315-BDA9DD524B45} URL = 
SearchScopes: HKU\S-1-5-21-2865801210-255665649-1679975380-1001 -> {7F595587-C0D2-4359-B315-BDA9DD524B45} URL = 
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-25] (Oracle Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-25] (Oracle Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.43.1
Tcpip\..\Interfaces\{B38AA017-B810-47AC-BE24-B1D95D92D7BF}: [NameServer] 8.8.8.8,8.8.4.4
 
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_239.dll [2014-12-01] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_239.dll [2014-12-01] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-12-11] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-12-11] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-01-25] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-25] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-25] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-25] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-01] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2865801210-255665649-1679975380-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Alisha\AppData\Local\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-25] (Google Inc.)
FF Plugin HKU\S-1-5-21-2865801210-255665649-1679975380-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Alisha\AppData\Local\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-25] (Google Inc.)
 
Chrome: 
=======
CHR Profile: C:\Users\Alisha\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Alisha\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-12-01]
CHR Extension: (Google Docs) - C:\Users\Alisha\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-12-01]
CHR Extension: (Google Drive) - C:\Users\Alisha\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-12-01]
CHR Extension: (YouTube) - C:\Users\Alisha\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-12-01]
CHR Extension: (Google Cast) - C:\Users\Alisha\AppData\Local\Google\Chrome\User Data\Default\Extensions\boadgeojelhgndaghljhdicfkmllpafd [2014-12-01]
CHR Extension: (Adblock Plus) - C:\Users\Alisha\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-12-07]
CHR Extension: (Google Search) - C:\Users\Alisha\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-12-01]
CHR Extension: (FLV Player) - C:\Users\Alisha\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhogabmliblgpadclikpkjfnnipeebjm [2014-12-01]
CHR Extension: (Google Sheets) - C:\Users\Alisha\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-12-01]
CHR Extension: (Bookmark Manager) - C:\Users\Alisha\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-04-26]
CHR Extension: (Flash Player) - C:\Users\Alisha\AppData\Local\Google\Chrome\User Data\Default\Extensions\jdpbajmogfhlafbipjjklkdhloplicgc [2014-12-01]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Alisha\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-18]
CHR Extension: (Google Wallet) - C:\Users\Alisha\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-12-01]
CHR Extension: (Gmail) - C:\Users\Alisha\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-12-01]
 
==================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AtherosSvc; C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\adminservice.exe [317568 2013-10-30] (Windows ® Win 7 DDK provider) [File not signed]
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-28] (Microsoft Corporation)
R2 DellDataVault; C:\Program Files\Dell\DellDataVault\DellDataVault.exe [2557136 2015-02-26] (Dell Inc.)
R2 DellDataVaultWiz; C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe [201936 2015-02-26] (Dell Inc.)
R2 DellUpdate; C:\Program Files (x86)\Dell Update\DellUpService.exe [232152 2015-05-20] (Dell Inc.)
R2 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [144560 2012-05-17] (Seiko Epson Corporation)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-30] (Intel Corporation)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [344976 2015-03-31] (Intel Corporation)
R2 Intel® Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel® Corporation) [File not signed]
S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel® Corporation)
R2 MbaeSvc; C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe [656184 2015-04-08] (Malwarebytes Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-04-14] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
R2 MotoHelper; C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperService.exe [214896 2012-02-01] ()
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [253776 2013-07-30] (CyberLink)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [246488 2013-06-18] (Realtek Semiconductor)
R2 SftService; C:\Program Files (x86)\Dell Backup and Recovery\sftservice.exe [1924328 2014-09-18] (SoftThinks SAS)
R2 SupportAssistAgent; C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [19288 2015-03-04] (Dell Inc.)
R2 Virtual Router; C:\Program Files (x86)\Virtual Router\VirtualRouterService.exe [12288 2013-02-10] (Chris Pietschmann (http://pietschsoft.com)) [File not signed]
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-03] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-03] (Microsoft Corporation)
R2 WysePocketCloud; C:\Program Files (x86)\Wyse\PocketCloud\PocketCloudService.exe [16176 2013-08-22] ()
R2 WyseRemoteAccess; C:\Program Files (x86)\Wyse\PocketCloud\WyseRemoteAccess.exe [1785344 2013-08-19] (DELL Inc.) [File not signed]
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 athr; C:\Windows\system32\DRIVERS\athwbx.sys [3858944 2013-10-17] (Qualcomm Atheros Communications, Inc.)
R3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2013-10-30] (Qualcomm Atheros)
R3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [91712 2013-03-05] (CyberLink)
R3 DDDriver; C:\Windows\system32\drivers\DDDriver64Dcsa.sys [23760 2015-02-26] (Dell Computer Corporation)
R3 DellProf; C:\Windows\system32\drivers\DellProf.sys [23312 2015-02-26] (Dell Computer Corporation)
R3 DellRbtn; C:\Windows\System32\drivers\DellRbtn.sys [10752 2013-01-24] (OSR Open Systems Resources, Inc.)
R1 ESProtectionDriver; C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.sys [63064 2015-04-08] ()
S3 iscFlash; C:\Users\Alisha\AppData\Local\Temp\7zSB2C5.tmp\iscflashx64.sys [60680 2013-07-30] (Insyde Software)
R1 mbamchameleon; C:\Windows\system32\drivers\mbamchameleon.sys [107736 2015-04-14] (Malwarebytes Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [136408 2015-06-03] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2015-04-14] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\System32\drivers\TeeDriverx64.sys [100312 2013-12-11] (Intel Corporation)
S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [30448 2013-09-06] (Synaptics Incorporated)
R3 SmbDrvI; C:\Windows\System32\drivers\Smb_driver_Intel.sys [34544 2013-09-06] (Synaptics Incorporated)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-03] (Microsoft Corporation)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-06-03 21:49 - 2015-06-03 21:50 - 00021258 _____ C:\Users\Alisha\Desktop\FRST.txt
2015-06-03 21:49 - 2015-06-03 21:50 - 00000000 ____D C:\FRST
2015-06-03 21:47 - 2015-06-03 21:47 - 02108928 _____ (Farbar) C:\Users\Alisha\Desktop\FRST64.exe
2015-06-03 13:28 - 2015-06-03 13:28 - 00388608 _____ (Trend Micro Inc.) C:\Users\Alisha\Downloads\HijackThis (1).exe
2015-06-03 13:15 - 2015-06-03 13:15 - 00012092 _____ C:\Users\Alisha\Downloads\hijackthis.log
2015-06-03 13:12 - 2015-06-03 13:12 - 00388608 _____ (Trend Micro Inc.) C:\Users\Alisha\Downloads\HijackThis.exe
2015-06-02 23:23 - 2015-06-02 23:23 - 00000000 ____D C:\Program Files (x86)\Dell Update
2015-06-02 23:20 - 2015-06-02 23:20 - 00000000 ___RD C:\Users\Alisha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
2015-05-25 22:38 - 2015-04-09 19:34 - 02256896 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2015-05-25 22:38 - 2015-04-09 19:11 - 01943040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
2015-05-25 22:38 - 2015-03-19 20:56 - 00080384 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ahcache.sys
2015-05-25 22:38 - 2015-03-10 20:49 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\sdbinst.exe
2015-05-25 22:38 - 2015-03-10 20:09 - 00021504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sdbinst.exe
2015-05-25 22:38 - 2015-03-05 21:47 - 01696256 _____ (Microsoft Corporation) C:\Windows\system32\wevtsvc.dll
2015-05-25 22:38 - 2015-03-03 20:32 - 00172544 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Input.Inking.dll
2015-05-25 22:38 - 2015-03-03 20:12 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Input.Inking.dll
2015-05-25 22:38 - 2015-01-29 19:53 - 02819584 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers.dll
2015-05-25 22:37 - 2015-04-01 17:22 - 02985984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dbgeng.dll
2015-05-25 22:37 - 2015-04-01 17:20 - 04417536 _____ (Microsoft Corporation) C:\Windows\system32\dbgeng.dll
2015-05-25 22:37 - 2015-03-31 22:45 - 01491456 _____ (Microsoft Corporation) C:\Windows\system32\dbghelp.dll
2015-05-25 22:37 - 2015-03-31 21:31 - 01207296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dbghelp.dll
2015-05-25 22:37 - 2015-03-17 12:26 - 00467776 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\USBHUB3.SYS
2015-05-25 22:37 - 2015-03-12 21:02 - 00316416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\udfs.sys
2015-05-25 22:37 - 2015-03-12 20:11 - 02162176 _____ (Microsoft Corporation) C:\Windows\system32\SRH.dll
2015-05-25 22:37 - 2015-03-12 19:39 - 01812992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SRH.dll
2015-05-25 22:37 - 2015-02-17 18:19 - 00186368 _____ (Microsoft Corporation) C:\Windows\system32\dpapisrv.dll
2015-05-25 22:36 - 2015-04-02 19:35 - 00445440 _____ (Microsoft Corporation) C:\Windows\system32\PhotoMetadataHandler.dll
2015-05-25 22:36 - 2015-04-02 19:14 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PhotoMetadataHandler.dll
2015-05-25 22:36 - 2015-03-12 23:03 - 00239424 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\sdbus.sys
2015-05-25 22:36 - 2015-03-12 23:03 - 00154432 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\dumpsd.sys
2015-05-25 22:36 - 2015-03-12 19:29 - 00410017 _____ C:\Windows\system32\ApnDatabase.xml
2015-05-25 22:36 - 2015-03-08 21:02 - 00057856 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\bthhfenum.sys
2015-05-25 22:36 - 2015-03-05 22:08 - 02067968 _____ (Microsoft Corporation) C:\Windows\system32\wpdshext.dll
2015-05-25 22:36 - 2015-03-05 21:43 - 01969664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wpdshext.dll
2015-05-14 23:51 - 2015-04-30 15:35 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-05-14 23:51 - 2015-04-30 15:35 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-05-14 23:10 - 2015-04-08 17:55 - 00410128 _____ (Microsoft Corporation) C:\Windows\system32\services.exe
2015-05-14 23:10 - 2015-03-30 00:47 - 00561928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-05-14 23:10 - 2015-03-26 22:27 - 00445440 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2015-05-14 23:10 - 2015-03-26 21:50 - 00324096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2015-05-14 23:10 - 2015-03-26 21:48 - 01441792 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-05-14 23:09 - 2015-04-30 18:05 - 00429568 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-05-14 23:09 - 2015-04-30 17:48 - 00358912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-05-14 23:09 - 2015-04-21 12:14 - 24971776 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-05-14 23:09 - 2015-04-21 11:50 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-05-14 23:09 - 2015-04-21 11:50 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-05-14 23:09 - 2015-04-21 11:49 - 02885120 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-05-14 23:09 - 2015-04-21 11:37 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-05-14 23:09 - 2015-04-21 11:35 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-05-14 23:09 - 2015-04-21 11:31 - 06025728 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-05-14 23:09 - 2015-04-21 11:24 - 19691008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-05-14 23:09 - 2015-04-21 11:13 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2015-05-14 23:09 - 2015-04-21 11:11 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-05-14 23:09 - 2015-04-21 11:09 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-05-14 23:09 - 2015-04-21 11:08 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-05-14 23:09 - 2015-04-21 11:07 - 00145408 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2015-05-14 23:09 - 2015-04-21 11:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-05-14 23:09 - 2015-04-21 11:04 - 02278400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-05-14 23:09 - 2015-04-21 10:59 - 01032704 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2015-05-14 23:09 - 2015-04-21 10:58 - 00664576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-05-14 23:09 - 2015-04-21 10:52 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2015-05-14 23:09 - 2015-04-21 10:49 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-05-14 23:09 - 2015-04-21 10:49 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-05-14 23:09 - 2015-04-21 10:49 - 00374272 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-05-14 23:09 - 2015-04-21 10:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-05-14 23:09 - 2015-04-21 10:40 - 14401536 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-05-14 23:09 - 2015-04-21 10:38 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-05-14 23:09 - 2015-04-21 10:37 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2015-05-14 23:09 - 2015-04-21 10:36 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-05-14 23:09 - 2015-04-21 10:32 - 00880128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2015-05-14 23:09 - 2015-04-21 10:31 - 04305920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-05-14 23:09 - 2015-04-21 10:28 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2015-05-14 23:09 - 2015-04-21 10:27 - 02352128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-05-14 23:09 - 2015-04-21 10:26 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-05-14 23:09 - 2015-04-21 10:26 - 00327168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-05-14 23:09 - 2015-04-21 10:25 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-05-14 23:09 - 2015-04-21 10:17 - 12828672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-05-14 23:09 - 2015-04-21 10:15 - 01547264 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-05-14 23:09 - 2015-04-21 10:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-05-14 23:09 - 2015-04-21 10:02 - 01882112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-05-14 23:09 - 2015-04-21 09:58 - 01310208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-05-14 23:09 - 2015-04-21 09:56 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-05-14 23:09 - 2015-04-13 17:48 - 04180480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-05-14 23:09 - 2015-04-09 20:00 - 01996800 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-05-14 23:09 - 2015-04-09 19:50 - 01387008 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-05-14 23:09 - 2015-04-09 19:26 - 01560576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-06-03 21:39 - 2015-03-04 22:40 - 00000000 ____D C:\Users\Alisha\AppData\Roaming\MotoCast
2015-06-03 21:17 - 2014-11-14 22:05 - 00000000 ____D C:\ProgramData\Malwarebytes Anti-Exploit
2015-06-03 21:12 - 2014-03-05 13:37 - 01694251 _____ C:\Windows\WindowsUpdate.log
2015-06-03 21:11 - 2014-05-11 20:11 - 00000951 _____ C:\Windows\Tasks\EPSON XP-310 Series Update {E744DC98-AD53-447E-90B3-7A3927BD5DCA}.job
2015-06-03 21:11 - 2014-05-11 20:11 - 00000765 _____ C:\Windows\Tasks\EPSON XP-310 Series Invitation {E744DC98-AD53-447E-90B3-7A3927BD5DCA}.job
2015-06-03 21:07 - 2014-05-11 20:07 - 00000951 _____ C:\Windows\Tasks\EPSON XP-310 Series Update {6FBC8136-D0FB-4BFE-8C07-43602C8FFBDF}.job
2015-06-03 21:07 - 2014-05-11 20:07 - 00000765 _____ C:\Windows\Tasks\EPSON XP-310 Series Invitation {6FBC8136-D0FB-4BFE-8C07-43602C8FFBDF}.job
2015-06-03 21:03 - 2014-12-01 22:47 - 00000938 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-06-03 21:00 - 2013-08-22 10:36 - 00000000 ____D C:\Windows\system32\sru
2015-06-03 20:36 - 2014-10-12 16:14 - 00000944 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2865801210-255665649-1679975380-1001UA.job
2015-06-03 14:14 - 2013-08-22 10:20 - 00000000 ____D C:\Windows\CbsTemp
2015-06-03 14:09 - 2015-04-14 00:58 - 00000000 ___SD C:\Windows\SysWOW64\GWX
2015-06-03 14:08 - 2015-04-14 00:58 - 00000000 ___SD C:\Windows\system32\GWX
2015-06-03 14:04 - 2014-04-01 19:58 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2865801210-255665649-1679975380-1001
2015-06-03 13:46 - 2014-07-17 18:46 - 00080384 ___SH C:\Users\Alisha\Desktop\Thumbs.db
2015-06-03 13:35 - 2014-10-12 16:14 - 00000892 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2865801210-255665649-1679975380-1001Core.job
2015-06-03 13:13 - 2014-04-01 19:52 - 00000000 ____D C:\Users\Alisha\AppData\Local\VirtualStore
2015-06-03 13:03 - 2014-11-14 21:37 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-06-02 23:28 - 2014-03-05 13:49 - 00000000 ____D C:\Program Files (x86)\Dell Backup and Recovery
2015-06-02 23:23 - 2014-03-05 13:44 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell
2015-06-02 23:21 - 2015-03-04 22:45 - 00000000 ____D C:\Users\Alisha\.gstreamer-0.10
2015-06-02 23:21 - 2014-04-01 22:43 - 00000000 ___DO C:\Users\Alisha\SkyDrive
2015-06-02 23:20 - 2015-03-26 18:05 - 00000733 _____ C:\Windows\system32\Drivers\etc\hosts.ics
2015-06-02 23:20 - 2014-12-01 22:47 - 00000934 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-06-02 23:20 - 2014-03-05 13:50 - 00000000 ____D C:\Temp
2015-06-02 23:19 - 2013-08-22 09:46 - 00054051 _____ C:\Windows\setupact.log
2015-06-02 23:19 - 2013-08-22 09:45 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-06-02 23:19 - 2013-08-22 09:44 - 00490624 _____ C:\Windows\system32\FNTCACHE.DAT
2015-06-02 23:18 - 2014-03-05 13:06 - 00081096 _____ C:\Windows\PFRO.log
2015-06-02 23:18 - 2013-08-22 08:25 - 00262144 ___SH C:\Windows\system32\config\BBI
2015-06-02 21:05 - 2013-08-22 10:36 - 00000000 ____D C:\Windows\AppReadiness
2015-05-26 22:21 - 2014-03-05 13:22 - 00865408 _____ C:\Windows\system32\PerfStringBackup.INI
2015-05-26 22:11 - 2013-08-22 10:36 - 00000000 ___RD C:\Windows\ImmersiveControlPanel
2015-05-26 22:10 - 2014-04-04 18:55 - 00000000 ____D C:\Windows\system32\MRT
2015-05-26 22:05 - 2014-04-04 18:55 - 140425016 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-05-25 23:04 - 2014-12-01 22:48 - 00002205 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-05-25 13:30 - 2014-10-12 16:14 - 00003892 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2865801210-255665649-1679975380-1001UA
2015-05-25 13:30 - 2014-10-12 16:14 - 00003512 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2865801210-255665649-1679975380-1001Core
2015-05-25 12:58 - 2014-12-01 22:47 - 00003910 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-05-25 12:58 - 2014-12-01 22:47 - 00003674 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-05-21 16:18 - 2013-08-22 10:36 - 00000000 ____D C:\Windows\system32\FxsTmp
2015-05-17 12:48 - 2013-08-22 10:36 - 00000000 ____D C:\Windows\rescache
2015-05-17 11:54 - 2014-04-08 20:40 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2015-05-17 11:29 - 2013-08-22 08:36 - 00000000 ____D C:\Windows\system32\AdvancedInstallers
2015-05-14 23:55 - 2014-04-04 18:28 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-05-14 23:41 - 2013-08-22 14:12 - 00000000 ____D C:\Program Files\Windows Journal
2015-05-05 12:59 - 2014-07-10 19:54 - 00792568 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-05-05 12:59 - 2014-07-10 19:54 - 00178168 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
 
==================== Files in the root of some directories =======
 
2014-03-05 13:09 - 2014-03-05 13:09 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2014-03-05 13:43 - 2014-03-05 13:44 - 0000121 _____ () C:\ProgramData\{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}.log
2014-03-05 13:39 - 2014-03-05 13:40 - 0000106 _____ () C:\ProgramData\{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}.log
2014-03-05 13:40 - 2014-03-05 13:42 - 0000111 _____ () C:\ProgramData\{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}.log
2014-03-05 13:42 - 2014-03-05 13:43 - 0000108 _____ () C:\ProgramData\{B46BEA36-0B71-4A4E-AE41-87241643FA0A}.log
2014-03-05 13:39 - 2014-03-05 13:39 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
 
Some files in TEMP:
====================
C:\Users\Alisha\AppData\Local\Temp\COMAP.EXE
C:\Users\Alisha\AppData\Local\Temp\InnoTab_US_Eng_Setup.exe
C:\Users\Alisha\AppData\Local\Temp\install_flashplayer16x32au_gtbd_awe_aih.exe
C:\Users\Alisha\AppData\Local\Temp\jre-8u31-windows-au.exe
C:\Users\Alisha\AppData\Local\Temp\MotoCast_Installer_1.2.7.exe
C:\Users\Alisha\AppData\Local\Temp\ose00000.exe
C:\Users\Alisha\AppData\Local\Temp\ose00001.exe
C:\Users\Alisha\AppData\Local\Temp\sqlite-3.6.20-sqlitejdbc.dll
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-05-25 23:17
 
==================== End of log ============================
 
 
 
 
 
 
 
 
 
 
 
 
Addition- Notepad
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version:03-06-2015
Ran by Alisha at 2015-06-03 21:51:45
Running from C:\Users\Alisha\Desktop
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-2865801210-255665649-1679975380-500 - Administrator - Disabled)
Alisha (S-1-5-21-2865801210-255665649-1679975380-1001 - Administrator - Enabled) => C:\Users\Alisha
Guest (S-1-5-21-2865801210-255665649-1679975380-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2865801210-255665649-1679975380-1003 - Limited - Enabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.239 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.11) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.11 - Adobe Systems Incorporated)
Amazon 1Button App (HKLM-x32\...\{0A7D6F3C-F2AB-48ED-BE23-99791BFF87D6}) (Version: 1.0.0.4 - Amazon)
ChromecastApp (HKU\S-1-5-21-2865801210-255665649-1679975380-1001\...\{079ede36-133d-44b0-8053-c7c1fa8d2e0d}_is1) (Version: 1.5.1383.0 - Google Inc.)
CyberLink Media Suite Essentials (HKLM-x32\...\InstallShield_{8F14AA37-5193-4A14-BD5B-BDF9B361AEF7}) (Version: 10.0 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Dell Backup and Recovery (HKLM-x32\...\{0ED7EE95-6A97-47AA-AD73-152C08A15B04}) (Version: 1.7.5.63 - Dell Inc.)
Dell Data Vault (Version: 4.2.2.0 - Dell Inc.) Hidden
Dell Digital Delivery (HKLM-x32\...\{03A9F528-A754-460F-B2C1-AC125A147114}) (Version: 2.8.5000.0 - Dell Products, LP)
Dell Product Registration (HKLM-x32\...\{2A0F2CC5-3065-492C-8380-B03AA7106B1A}) (Version: 1.16.1 - Dell Inc.)
Dell SupportAssist (HKLM\...\PC-Doctor for Windows) (Version: 1.0.6584.81 - Dell)
Dell SupportAssistAgent (HKLM-x32\...\{287348C8-8B47-4C36-AF28-441A3B7D8722}) (Version: 1.0.2.57295 - Dell)
Dell Touchpad (HKLM\...\SynTPDeinstKey) (Version: 17.0.13.0 - Synaptics Incorporated)
Dell Update (HKLM-x32\...\{3FB000F3-7444-41C1-A0A6-53E8FD0B7D9C}) (Version: 1.6.1007.0 - Dell Inc.)
Dell WLAN and Bluetooth Client Installation (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 10.0 - Dell Inc.)
Epson Customer Participation (HKLM\...\{814FA673-A085-403C-9545-747FC1495069}) (Version: 1.6.3.0 - SEIKO EPSON CORPORATION)
Epson Event Manager (HKLM-x32\...\{0F13C24A-FFE2-4CD0-8E0B-DC804E0A0E0B}) (Version: 3.10.0035 - Seiko Epson Corporation)
EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version:  - Seiko Epson Corporation)
EPSON XP-310 Series Printer Uninstall (HKLM\...\EPSON XP-310 Series) (Version:  - SEIKO EPSON Corporation)
EpsonNet Print (HKLM-x32\...\{3E31400D-274E-4647-916C-2CACC3741799}) (Version: 2.6.0 - SEIKO EPSON CORPORATION)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 43.0.2357.81 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.27.5 - Google Inc.) Hidden
Intel® Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1011 - Intel Corporation)
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.23.1766 - Intel Corporation)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.14.4156 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.2.1000 - Intel Corporation)
Java 8 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
Learning Lodge™ (HKLM-x32\...\VTechDownloadManager) (Version:  - VTech)
Malwarebytes Anti-Exploit version 1.06.1.1019 (HKLM\...\Malwarebytes Anti-Exploit_is1) (Version: 1.06.1.1019 - Malwarebytes)
Malwarebytes Anti-Malware version 2.1.6.1022 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (HKLM-x32\...\{D1D37853-0004-3E36-A7AA-74F4EEA35F64}) (Version: 4.5.50930 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 SDK (HKLM-x32\...\{19A5926D-66E1-46FC-854D-163AA10A52D3}) (Version: 4.5.51641 - Microsoft Corporation)
Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4454.1510 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-00CA-0000-0000-0000000FF1CE}_SMALLBUSINESSR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office Small Business 2007 (HKLM-x32\...\SMALLBUSINESSR) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
MotoCast (HKLM-x32\...\{5401CEE8-3C2D-4835-A802-213306537FF4}) (Version: 1.2.7 - Motorola Mobility)
MotoHelper 2.1.40 Driver 5.5.0 (HKLM-x32\...\MotoHelper) (Version: 2.1.40 - Motorola)
MotoHelper MergeModules (x32 Version: 1.2.0 - Motorola) Hidden
MOTOROLA MEDIA LINK (x32 Version: 1.7.0147.0 - Motorola) Hidden
Motorola Mobile Drivers Installation 5.5.0 (Version: 5.5.0 - Motorola Inc.) Hidden
Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Photo Story 3 for Windows (HKLM-x32\...\{4F41AD68-89F2-4262-A32C-2F70B01FCE9E}) (Version: 3.0.1115.11 - Microsoft Corporation)
PocketCloud (HKLM-x32\...\{D9752C7D-A595-4687-A0D5-362E9C311C55}) (Version: 2.7.14 - Wyse Technology)
Qualcomm Atheros Bluetooth Suite (64) (HKLM\...\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.1.308 - Qualcomm Atheros Communications)
Quickset64 (HKLM\...\{87CF757E-C1F1-4D22-865C-00C6950B5258}) (Version: 10.15.021 - Dell Inc.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7023 - Realtek Semiconductor Corp.)
Software Updater (HKLM-x32\...\{FA7EE274-7370-43B7-9A45-A39B17CCCDC5}) (Version: 4.3.3 - SEIKO EPSON CORPORATION)
Tether (HKLM-x32\...\{C5C67EA4-16FA-473C-B274-904A71162DE4}) (Version: 1.0.1 - ClockworkMod)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-00CA-0000-0000-0000000FF1CE}_SMALLBUSINESSR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
VCM Suite (HKLM-x32\...\{fa26b9e4-ffc8-4de1-8626-a2946fff7483}) (Version: 2.24.904 - HP Tuners)
Virtual Router v1.0 (HKLM-x32\...\{BE905C46-2B34-4D73-AEE1-769ED138E0FF}) (Version: 1.0 - Chris Pietschmann)
VTech Download Agent Library (x32 Version: 1.00.0000 - VTech) Hidden
Windows Driver Package - Dell Inc (DellRbtn) HIDClass  (07/31/2012 1.4) (HKLM\...\DFFC4013304EDB1027D2BAEBE06DF2A4BD2608D3) (Version: 07/31/2012 1.4 - Dell Inc)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-2865801210-255665649-1679975380-1001_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\Alisha\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-2865801210-255665649-1679975380-1001_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\Alisha\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-2865801210-255665649-1679975380-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\Windows\system32\igfxEM.exe (Intel Corporation)
CustomCLSID: HKU\S-1-5-21-2865801210-255665649-1679975380-1001_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\Alisha\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-2865801210-255665649-1679975380-1001_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\Alisha\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-2865801210-255665649-1679975380-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Alisha\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll (Google Inc.)
 
==================== Restore Points =========================
 
25-04-2015 06:04:01 Scheduled Checkpoint
04-05-2015 10:14:05 Scheduled Checkpoint
08-05-2015 00:25:49 Windows Update
14-05-2015 23:39:39 Windows Update
26-05-2015 21:57:58 Windows Modules Installer
26-05-2015 21:59:16 Windows Modules Installer
03-06-2015 14:04:56 Windows Update
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2013-08-22 08:25 - 2013-08-22 08:25 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {05A1D556-C045-4C0C-BB5D-240991AA11D3} - System32\Tasks\CLVDLauncher => C:\Program Files (x86)\CyberLink\Power2Go8\CLVDLauncher.exe [2013-03-22] (CyberLink Corp.)
Task: {07216683-416F-49B5-9E31-E0D48569A39B} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2865801210-255665649-1679975380-1001UA => C:\Users\Alisha\AppData\Local\Google\Update\GoogleUpdate.exe [2014-10-12] (Google Inc.)
Task: {0C569ACD-AD93-40DD-8A4B-09E6243EA20B} - System32\Tasks\Dell\Dell System Registration => C:\Program Files (x86)\System Registration\prodreg.exe [2012-07-09] (Dell, Inc.)
Task: {169B1AA9-4373-4868-831E-3A1BF5AA8108} - System32\Tasks\Synaptics TouchPad Enhancements => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2013-09-06] (Synaptics Incorporated)
Task: {1F8A02CC-2FEB-4F43-BE38-F98E46D94E4C} - System32\Tasks\MotoCast Update => C:\Program Files (x86)\Motorola Mobility\MotoCast\LiveUpdate\MotoCastUpdate.exe [2012-02-09] ()
Task: {26858AEF-0F5B-4F60-B524-09A2CBF3B095} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\Logon => C:\Windows\system32\GWX\GWX.exe [2015-05-06] (Microsoft Corporation)
Task: {2A416A1B-53F6-4D51-BA04-1E92A87DC1D5} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {2E8FF2CF-F961-44B1-9A32-6E3EA5BC272E} - System32\Tasks\MotoHelper Initial Update => C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperUpdate.exe [2012-02-01] ()
Task: {35E45FC3-D930-4785-ABF8-AA8BBD814998} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-05-06] (Microsoft Corporation)
Task: {3A1E1EB4-A025-4FCC-A3E1-2D3E0A76B146} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-05-06] (Microsoft Corporation)
Task: {3B16D840-7297-4853-A1B6-69CD381CE9B9} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => schtasks
Task: {4F48014D-8965-4C39-BC2E-264FE1949E09} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2015-05-26] (Microsoft Corporation)
Task: {52114C94-6EED-4175-A239-684F4BDDCA4D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-01] (Google Inc.)
Task: {580457A4-275D-444D-9605-2DE89A5E8CF3} - System32\Tasks\MotoHelper Routing => C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperUpdate.exe [2012-02-01] ()
Task: {6581B9F6-2657-4E80-8563-67520F4DD49B} - System32\Tasks\CLMLSvc_P2G8 => C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [2013-03-04] (CyberLink)
Task: {7352C13B-CC65-463B-B3EE-9F4381BCCAB3} - System32\Tasks\EPSON XP-310 Series Invitation {6FBC8136-D0FB-4BFE-8C07-43602C8FFBDF} => C:\Windows\system32\spool\DRIVERS\x64\3\E_ITSLBE.EXE [2014-12-02] (SEIKO EPSON CORPORATION)
Task: {76DD90E6-F69D-4248-96A7-20CFEB8EEBB7} - System32\Tasks\PocketCloudVirtualChannel => C:\Program Files (x86)\Wyse\PocketCloud\WPCRDPVirtualChannelServer.exe [2013-08-22] ()
Task: {937CEF45-AECB-4DBA-93B3-A8746F6436F9} - System32\Tasks\SystemToolsDailyTest => uaclauncher.exe
Task: {99B05D0D-C343-4546-9594-11FEDA6FAA64} - System32\Tasks\Dell SupportAssistAgent AutoUpdate => C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssist.exe [2015-03-04] (Dell Inc.)
Task: {9E6272DA-7474-4391-B885-4220D6E091E7} - System32\Tasks\PCDEventLauncherTask => C:\Program Files\Dell\SupportAssist\sessionchecker.exe [2015-03-20] (PC-Doctor, Inc.)
Task: {B10DFF49-6A50-48A6-BB38-48E51CD72355} - System32\Tasks\EPSON XP-310 Series Invitation {E744DC98-AD53-447E-90B3-7A3927BD5DCA} => C:\Windows\system32\spool\DRIVERS\x64\3\E_ITSLBE.EXE [2014-12-02] (SEIKO EPSON CORPORATION)
Task: {B929A1E5-02A5-4FD4-8FB0-AD89E8BE059C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-01] (Google Inc.)
Task: {BBF0FB44-DBA7-4E4C-B697-F331D00B6E7F} - System32\Tasks\EPSON XP-310 Series Update {E744DC98-AD53-447E-90B3-7A3927BD5DCA} => C:\Windows\system32\spool\DRIVERS\x64\3\E_ITSLBE.EXE [2014-12-02] (SEIKO EPSON CORPORATION)
Task: {C5FE68FA-702C-4669-9FA0-611DD19D9FC2} - System32\Tasks\MotoHelper Update => C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperUpdate.exe [2012-02-01] ()
Task: {C670EEF8-A9DC-4980-87F2-6EEB57FAAB1F} - System32\Tasks\PCDoctorBackgroundMonitorTask => C:\Program Files\Dell\SupportAssist\uaclauncher.exe [2015-03-20] (PC-Doctor, Inc.)
Task: {CB673BC5-AE8E-46D8-B440-53598178A810} - System32\Tasks\PocketCloudUpdater => C:\Program
Task: {D41D555B-21CD-43E9-920D-4E30F78FC1F1} - System32\Tasks\EPSON XP-310 Series Update {6FBC8136-D0FB-4BFE-8C07-43602C8FFBDF} => C:\Windows\system32\spool\DRIVERS\x64\3\E_ITSLBE.EXE [2014-12-02] (SEIKO EPSON CORPORATION)
Task: {E81FDC34-C690-4D59-86DF-CD696E72F46C} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle => C:\Windows\system32\GWX\GWX.exe [2015-05-06] (Microsoft Corporation)
Task: {EB60B79D-A6CD-48EA-8FA2-EE2491560353} - System32\Tasks\PocketCloud => C:\Program Files (x86)\Wyse\PocketCloud\PocketCloudDesktopApp.exe [2013-08-22] ()
Task: {FE8A9C6C-DFEC-4A35-A567-90BBDD8DE7E0} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2865801210-255665649-1679975380-1001Core => C:\Users\Alisha\AppData\Local\Google\Update\GoogleUpdate.exe [2014-10-12] (Google Inc.)
Task: C:\Windows\Tasks\EPSON XP-310 Series Invitation {6FBC8136-D0FB-4BFE-8C07-43602C8FFBDF}.job => C:\Windows\system32\spool\DRIVERS\x64\3\E_ITSLBE.EXE
Task: C:\Windows\Tasks\EPSON XP-310 Series Invitation {E744DC98-AD53-447E-90B3-7A3927BD5DCA}.job => C:\Windows\system32\spool\DRIVERS\x64\3\E_ITSLBE.EXE
Task: C:\Windows\Tasks\EPSON XP-310 Series Update {6FBC8136-D0FB-4BFE-8C07-43602C8FFBDF}.job => C:\Windows\system32\spool\DRIVERS\x64\3\E_ITSLBE.EXE:/EXE:{6FBC8136-D0FB-4BFE-8C07-43602C8FFBDF} /F:UpdateWORKGROUP\ALISHAHAWKINSPC$
Searches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi
Task: C:\Windows\Tasks\EPSON XP-310 Series Update {E744DC98-AD53-447E-90B3-7A3927BD5DCA}.job => C:\Windows\system32\spool\DRIVERS\x64\3\E_ITSLBE.EXE:/EXE:{E744DC98-AD53-447E-90B3-7A3927BD5DCA} /F:UpdateWORKGROUP\ALISHAHAWKINSPC$
Searches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2865801210-255665649-1679975380-1001Core.job => C:\Users\Alisha\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2865801210-255665649-1679975380-1001UA.job => C:\Users\Alisha\AppData\Local\Google\Update\GoogleUpdate.exe
 
==================== Loaded Modules (Whitelisted) ==============
 
2012-02-01 16:55 - 2012-02-01 16:55 - 00214896 _____ () C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperService.exe
2013-08-22 14:40 - 2013-08-22 14:40 - 00016176 _____ () C:\Program Files (x86)\Wyse\PocketCloud\PocketCloudService.exe
2013-08-22 14:40 - 2013-08-22 14:40 - 00040240 _____ () C:\Program Files (x86)\Wyse\PocketCloud\AetherServiceLib.dll
2013-08-22 14:40 - 2013-08-22 14:40 - 00046384 _____ () C:\Program Files (x86)\Wyse\PocketCloud\AetherHelperLib.dll
2012-02-01 16:55 - 2012-02-01 16:55 - 00784240 _____ () C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperAgent.exe
2014-01-25 02:22 - 2015-03-31 19:02 - 00392592 _____ () C:\Windows\system32\igfxTray.exe
2013-10-30 02:11 - 2013-10-30 02:11 - 00011264 _____ () C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\Modules\ActivateDesktopDebugger\ActivateDesktopDebugger.dll
2013-10-30 02:07 - 2013-10-30 02:07 - 00086016 _____ () C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\Modules\Map\MAP.dll
2013-10-30 02:15 - 2013-10-30 02:15 - 00012928 _____ () C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\ActivateDesktop.exe
2014-10-12 20:50 - 2014-06-20 01:42 - 00401280 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe
2014-09-18 13:37 - 2014-07-02 21:55 - 00487144 _____ () C:\Program Files (x86)\Dell Backup and Recovery\Components\Shell\DBRCrawler.exe
2015-02-15 00:12 - 2015-02-15 00:12 - 01009664 _____ () C:\Program Files (x86)\ClockworkMod\Tether\win32\adb.exe
2015-03-31 17:18 - 2015-02-25 17:22 - 00107256 _____ () C:\Program Files\Dell\SupportAssist\libCSharpCommonCS.dll
2015-03-31 17:18 - 2015-02-25 17:22 - 00545528 _____ () C:\Program Files\Dell\SupportAssist\libAsapiCSharp.dll
2012-02-07 17:54 - 2012-02-07 17:54 - 00128336 _____ () C:\Program Files (x86)\Motorola Media Link\Lite\liveupdatetactics.dll
2012-02-07 17:53 - 2012-02-07 17:53 - 00023872 _____ () C:\Program Files (x86)\Motorola Media Link\Lite\DbAccess.dll
2012-02-07 17:56 - 2012-02-07 17:56 - 00465632 _____ () C:\Program Files (x86)\Motorola Media Link\Lite\sqlite3.dll
2012-02-07 17:54 - 2012-02-07 17:54 - 00045368 _____ () C:\Program Files (x86)\Motorola Media Link\Lite\NAdvLog.dll
2012-02-07 17:54 - 2012-02-07 17:54 - 00034128 _____ () C:\Program Files (x86)\Motorola Media Link\Lite\NFileCacheDBAccess.dll
2014-10-12 20:50 - 2014-03-04 06:20 - 00117760 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\QtSolutions_SOAP-2.7.dll
2014-10-12 20:50 - 2014-04-21 21:14 - 00065536 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\QHttpServer.dll
2014-10-12 20:50 - 2014-05-06 00:39 - 00861184 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\platforms\qwindows.dll
2014-10-12 20:50 - 2014-05-06 00:38 - 00021504 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qgif.dll
2014-10-12 20:50 - 2014-05-06 00:38 - 00020992 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qico.dll
2014-10-12 20:50 - 2014-05-06 00:38 - 00204800 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qjpeg.dll
2014-10-12 20:50 - 2014-05-06 05:44 - 00218112 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qmng.dll
2014-10-12 20:50 - 2014-05-06 00:58 - 00015872 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qsvg.dll
2014-10-12 20:50 - 2014-05-06 05:44 - 00015360 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qtga.dll
2014-10-12 20:50 - 2014-05-06 05:44 - 00307712 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qtiff.dll
2014-10-12 20:50 - 2014-05-06 05:44 - 00014848 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qwbmp.dll
2014-10-12 20:50 - 2014-05-06 01:31 - 00015872 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\sensors\qtsensors_dummy.dll
2014-10-12 20:50 - 2014-05-06 00:38 - 00036352 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\bearer\qgenericbearer.dll
2014-10-12 20:50 - 2014-05-06 00:38 - 00038912 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\bearer\qnativewifibearer.dll
2014-03-05 13:40 - 2013-03-04 22:40 - 00626240 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll
2013-03-05 14:41 - 2013-03-05 14:41 - 00015424 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll
2014-11-01 01:11 - 2013-12-11 00:27 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\ACE.dll
2014-09-18 13:37 - 2014-07-30 17:37 - 01906464 _____ () C:\Program Files (x86)\Dell Backup and Recovery\Components\Restore\STRestoreAPI.dll
2014-03-05 13:50 - 2012-11-26 01:19 - 01153384 _____ () C:\Program Files (x86)\Dell Backup and Recovery\Components\Restore\libxml2.dll
2014-09-18 13:37 - 2012-11-25 23:19 - 00117608 _____ () C:\Program Files (x86)\Dell Backup and Recovery\Components\Restore\zlib1.dll
2015-05-25 23:04 - 2015-05-22 15:22 - 01281864 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.81\libglesv2.dll
2015-05-25 23:04 - 2015-05-22 15:22 - 00080712 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.81\libegl.dll
2015-05-25 23:04 - 2015-05-22 15:22 - 14982472 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.81\PepperFlash\pepflashplayer.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\Users\Alisha\SkyDrive:ms-properties
 
==================== Safe Mode (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\S-1-5-21-2865801210-255665649-1679975380-1001\...\dell.com -> dell.com
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-2865801210-255665649-1679975380-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Alisha\AppData\Roaming\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
DNS Servers: 192.168.43.1
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-2865801210-255665649-1679975380-1001\...\StartupApproved\StartupFolder: => "Epson all-in-one Registration.lnk"
HKU\S-1-5-21-2865801210-255665649-1679975380-1001\...\StartupApproved\Run: => "DellSystemDetect"
HKU\S-1-5-21-2865801210-255665649-1679975380-1001\...\StartupApproved\Run: => "EPLTarget\P0000000000000001"
HKU\S-1-5-21-2865801210-255665649-1679975380-1001\...\StartupApproved\Run: => "EPLTarget\P0000000000000000"
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{4E3728B5-1B29-4EBD-A896-A424E623324F}] => (Allow) C:\Program Files (x86)\Wyse\PocketCloud\PocketCloudDesktopApp.exe
FirewallRules: [{8DB03FA5-AC62-4034-AA3C-C0DC08865DEB}] => (Allow) C:\Program Files (x86)\Wyse\PocketCloud\AetherWindowsService.exe
FirewallRules: [{DA9B0D20-26AC-49A7-BB72-0E62172A6B6B}] => (Allow) C:\Program Files (x86)\Wyse\PocketCloud\WyseRemoteAccess.exe
FirewallRules: [{0D2570BF-5011-4F70-AD47-EC403F02A2E6}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDirector10\PDR10.EXE
FirewallRules: [{A771B84F-E5EA-4F29-BA3E-CFE0682E81DC}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Movie\PowerDVD Cinema\PowerDVDCinema12.exe
FirewallRules: [{7DBFF034-7066-49F1-A967-AC79B70A0D2B}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{118D55EF-4ED3-45B6-9FE5-B3F0082B6344}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{C8195367-5DB1-4932-8A96-A0D622DC9A23}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{059ADF16-D45D-44D2-BA00-9360EC5B642F}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{EAB1CD5E-358D-46FE-AD12-EDD1C85360D8}] => (Allow) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
FirewallRules: [{556A6C2F-7067-47F6-8D87-B2ADF3CD6390}] => (Allow) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
FirewallRules: [{98150325-F29F-44D6-B283-72F0396D48F5}] => (Allow) C:\Users\Alisha\AppData\Local\Temp\WZSE0.TMP\Common\EpsonNet Setup\ENEasyApp.exe
FirewallRules: [{69F9F9A2-6EEF-4471-B335-33EFE5B64AEB}] => (Allow) C:\Users\Alisha\AppData\Local\Temp\WZSE0.TMP\Common\EpsonNet Setup\ENEasyApp.exe
FirewallRules: [TCP Query User{7D10B507-42F8-461F-B2DD-AEFD2A9A3340}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Block) C:\program files (x86)\epson software\event manager\eeventmanager.exe
FirewallRules: [UDP Query User{0DA4704D-FAA9-4987-BABC-DAD9BA58EF1D}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Block) C:\program files (x86)\epson software\event manager\eeventmanager.exe
FirewallRules: [{597D86C5-61A6-4A32-A16F-BBF3C26B6532}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{9318D2C0-FF20-47A2-8842-B91811226ADA}] => (Allow) LPort=2869
FirewallRules: [{FDC86236-6B05-44F1-9E41-444E2C444375}] => (Allow) LPort=1900
FirewallRules: [{304C4D6C-DA71-4F21-89A5-05E16E5E0E42}] => (Allow) C:\Program Files (x86)\Motorola Media Link\Lite\mml.exe
FirewallRules: [{33929B37-2E48-4EA2-9ED7-82A3AC51FE0B}] => (Allow) C:\Program Files (x86)\Motorola Mobility\MotoCast\motocast.exe
FirewallRules: [{23B613CB-ECC2-464B-9CEB-3B9C12A1BBC1}] => (Allow) C:\Program Files (x86)\Motorola Mobility\MotoCast\motocast.exe
FirewallRules: [{7161A6B8-6EE8-4ACD-8315-604CBA28B394}] => (Allow) C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\MotoCast-thumbnailer.exe
FirewallRules: [{7927E5C8-5863-4FD5-942C-DEADEC642B08}] => (Allow) C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\MotoCast-thumbnailer.exe
FirewallRules: [{FB9401A9-18C4-4014-B4E2-7B07C955C746}] => (Allow) C:\Program Files (x86)\ClockworkMod\Tether\win32\node.exe
FirewallRules: [{4D93A2F9-8406-4EE4-86D4-3EC3863B86A5}] => (Allow) C:\Program Files (x86)\ClockworkMod\Tether\win32\node.exe
FirewallRules: [{41B0D44B-52C7-493D-863B-0BE3F6EF144D}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{155A0723-F0CF-421A-982D-CC07F176E5F1}] => (Allow) %systemroot%\system32\alg.exe
FirewallRules: [{7C7F6A7A-A4F4-4D5B-8942-F835F4DD254F}] => (Allow) C:\Program Files (x86)\ClockworkMod\Tether\win32\node.exe
FirewallRules: [{11A3F797-3BD6-47B2-A20A-EB3F8A64C616}] => (Allow) C:\Program Files (x86)\ClockworkMod\Tether\win32\node.exe
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (06/03/2015 01:56:32 PM) (Source: MsiInstaller) (EventID: 1013) (User: ALISHAHAWKINSPC)
Description: Product: Dell Update -- A newer version of Dell Update is already installed.
 
Error: (05/26/2015 09:57:24 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: Failed to create restore point (Process = C:\Windows\system32\svchost.exe -k netsvcs; Description = Windows Update; Error = 0x81000101).
 
Error: (05/17/2015 11:53:54 AM) (Source: MsiInstaller) (EventID: 1024) (User: ALISHAHAWKINSPC)
Description: Product: Adobe Reader XI (11.0.10) - Update '{AC76BA86-7AD7-0000-2550-7A8C40011011}' could not be installed. Error code 1625. Windows Installer can create logs to help troubleshoot issues with installing software packages. Use the following link for instructions on turning on logging support: http://go.microsoft.com/fwlink/?LinkId=23127
 
Error: (05/06/2015 11:22:41 AM) (Source: MsiInstaller) (EventID: 1013) (User: ALISHAHAWKINSPC)
Description: Product: Dell Update -- A newer version of Dell Update is already installed.
 
Error: (05/04/2015 03:43:16 PM) (Source: MsiInstaller) (EventID: 1013) (User: ALISHAHAWKINSPC)
Description: Product: Dell Update -- A newer version of Dell Update is already installed.
 
Error: (05/04/2015 10:08:24 AM) (Source: MsiInstaller) (EventID: 1013) (User: ALISHAHAWKINSPC)
Description: Product: Dell Update -- A newer version of Dell Update is already installed.
 
Error: (05/01/2015 11:08:58 PM) (Source: MsiInstaller) (EventID: 1013) (User: ALISHAHAWKINSPC)
Description: Product: Dell Update -- A newer version of Dell Update is already installed.
 
Error: (04/27/2015 10:15:37 PM) (Source: MsiInstaller) (EventID: 1013) (User: ALISHAHAWKINSPC)
Description: Product: Dell Update -- A newer version of Dell Update is already installed.
 
Error: (04/26/2015 08:45:26 PM) (Source: MsiInstaller) (EventID: 1013) (User: ALISHAHAWKINSPC)
Description: Product: Dell Update -- A newer version of Dell Update is already installed.
 
Error: (04/14/2015 00:48:14 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: Explorer.EXE, version: 6.3.9600.17667, time stamp: 0x54c6f7c2
Faulting module name: igdusc64.dll, version: 10.18.14.4156, time stamp: 0x5429991c
Exception code: 0xc0000005
Fault offset: 0x0000000000057904
Faulting process id: 0x454
Faulting application start time: 0xExplorer.EXE0
Faulting application path: Explorer.EXE1
Faulting module path: Explorer.EXE2
Report Id: Explorer.EXE3
Faulting package full name: Explorer.EXE4
Faulting package-relative application ID: Explorer.EXE5
 
 
System errors:
=============
Error: (06/02/2015 10:24:54 PM) (Source: ipnathlp) (EventID: 1233) (User: )
Description: 
 
Error: (06/02/2015 10:07:47 PM) (Source: ipnathlp) (EventID: 1233) (User: )
Description: 
 
Error: (06/02/2015 09:57:32 PM) (Source: ipnathlp) (EventID: 1233) (User: )
Description: 
 
Error: (06/02/2015 09:19:50 PM) (Source: ipnathlp) (EventID: 1233) (User: )
Description: 
 
Error: (06/02/2015 09:07:43 PM) (Source: ipnathlp) (EventID: 1233) (User: )
Description: 
 
Error: (06/02/2015 09:05:43 PM) (Source: ipnathlp) (EventID: 1233) (User: )
Description: 
 
Error: (06/02/2015 09:04:41 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Spooler service.
 
Error: (06/02/2015 09:04:11 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Spooler service.
 
Error: (05/28/2015 06:50:42 PM) (Source: ipnathlp) (EventID: 1233) (User: )
Description: 
 
Error: (05/28/2015 06:50:11 PM) (Source: ipnathlp) (EventID: 1233) (User: )
Description: 
 
 
Microsoft Office:
=========================
 
CodeIntegrity Errors:
===================================
  Date: 2015-06-03 14:11:55.201
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-05-17 12:20:06.412
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-05-08 00:29:59.050
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-05-06 11:28:56.375
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-05-04 10:19:46.836
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-05-02 05:27:01.402
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-04-25 07:10:54.342
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\d3d10_1.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-04-25 07:10:53.935
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\d3d10_1.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-04-25 07:10:32.431
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\d3d10_1.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-04-25 07:10:32.157
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\d3d10_1.dll because the set of per-page image hashes could not be found on the system.
 
 
==================== Memory info =========================== 
 
Processor: Intel® Core™ i3-4010U CPU @ 1.70GHz
Percentage of memory in use: 63%
Total physical RAM: 3976.96 MB
Available physical RAM: 1440.33 MB
Total Pagefile: 4808.96 MB
Available Pagefile: 1357.26 MB
Total Virtual: 131072 MB
Available Virtual: 131071.8 MB
 
==================== Drives ================================
 
Drive c: (OS) (Fixed) (Total:456.6 GB) (Free:382.81 GB) NTFS
Drive d: (110404_1741) (CDROM) (Total:3.95 GB) (Free:0 GB) UDF
Drive e: (ESP) (Fixed) (Total:0.48 GB) (Free:0.46 GB) FAT32
Drive x: (WINRETOOLS) (Fixed) (Total:0.48 GB) (Free:0.19 GB) NTFS
Drive y: (PBR Image) (Fixed) (Total:8.03 GB) (Free:0.74 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: BB003CCA)
 
Partition: GPT Partition Type.
 
==================== End of log ============================


#4 deeprybka

deeprybka

  • Malware Response Team
  • 5,198 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Germany
  • Local time:11:11 AM

Posted 04 June 2015 - 01:23 AM

Hi there,

Step 1

Please download adwcleaner.png AdwCleaner (by Xplode) and save it to your Desktop.
  • Double click on AdwCleaner.exe to run the tool.
    Vista/Windows 7/8 users right-click and select "Run As Administrator"
  • Click on the Scan button.
  • After the scan has finished, click on the Clean button.
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • After rebooting, a log file (that is saved in C:\AdwCleaner[S#].txt) will open automatically.
    Copy and paste the contents of that logfile in your next reply.

regards,
deeprybka
:busy:
Neminem laede, immo omnes, quantum potes, iuva. Arthur Schopenhauer
 
unite_blue.png
asap.png

#5 HawkZ28

HawkZ28
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:04:11 AM

Posted 04 June 2015 - 06:20 PM

THANKS for the help Jurgen!  I followed your directions, and after rebooting, and coming to this page and trying to click in the box I'm currently typing in, a new tab was opened for a PC Support site ironically :)

 

Here's the ADW log file:

 

AdwCleaner[SO] - Notepad

 

# AdwCleaner v4.206 - Logfile created 04/06/2015 at 18:12:28
# Updated 01/06/2015 by Xplode
# Database : 2015-05-31.5 [Local]
# Operating system : Windows 8.1  (x64)
# Username : Alisha - ALISHAHAWKINSPC
# Running from : C:\Users\Alisha\Desktop\AdwCleaner.exe
# Option : Cleaning
 
***** [ Services ] *****
 
 
***** [ Files / Folders ] *****
 
Folder Deleted : C:\Users\Alisha\AppData\Local\DownloadManager
 
***** [ Scheduled tasks ] *****
 
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{26B19FA4-E8A1-4A1B-A163-1A1E46F830DD}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0A7D6F3C-F2AB-48ED-BE23-99791BFF87D6}
Key Deleted : HKLM\SOFTWARE\Classes\Installer\Features\C3F6D7A0BA2FDE84EB329997B1FF786D
Key Deleted : HKLM\SOFTWARE\Classes\Installer\Products\C3F6D7A0BA2FDE84EB329997B1FF786D
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\C3F6D7A0BA2FDE84EB329997B1FF786D
 
***** [ Web browsers ] *****
 
-\\ Internet Explorer v11.0.9600.17416
 
 
-\\ Google Chrome v43.0.2357.81
 
 
*************************
 
AdwCleaner[R0].txt - [1291 bytes] - [04/06/2015 17:57:11]
AdwCleaner[S0].txt - [1224 bytes] - [04/06/2015 18:12:28]
 
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1283  bytes] ##########


#6 deeprybka

deeprybka

  • Malware Response Team
  • 5,198 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Germany
  • Local time:11:11 AM

Posted 05 June 2015 - 01:12 PM

Please do the following:

Step 1

Temporary disable your AntiVirus and AntiSpyware protection - instructions here.

zoek.jpg

Please download 51a612a8b27e2-Zoek.pngZOEK by Smeenk and save it to your desktop (preferred version is the *.exe one)
  • Right-click on 51a612a8b27e2-Zoek.png icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
  • Wait patiently until the main console will appear, it may take a minute or two.
  • In the main box please paste in the following script:
    standardsearch;
    emptyfolderscheck;delete
    chrdefaults; 
    iedefaults;
    shortcutfix;
    autoclean;
    emptyclsid;
    
  • Make sure that Scan All Users option is checked.
  • Push Run Script and wait patiently. The scan may take a couple of minutes.
  • When the scan completes, a zoek-results logfile should open in notepad.
  • If a reboot is needed, it will be opened after it. You may also find it at your main drive (usually C:\ drive)
Post its content into your next reply.

Step 2

Please downloadesetlogo.pngOnline Scanner and save it to your Desktop.
  • Disable the realtime-protection of your antivirus and anti-malware programs because they might interfere with the scan.
  • Start installer.pngwith administartor privileges.
  • Select the option Yes, I accept the Terms of Use and click on Start.
  • Choose the following settings:
settings.png
  • Click on Start. The virus signature database will begin to download. This may take some time.
  • When completed the Online Scan will begin automatically.
    Note: This scan might take a long time! Please be patient.
  • When completed, click on Finish.
  • A log filelog.pngis created at logpath.png
    Copy and paste the content of this log file in your next reply.
esetlog.png

Note: Do not forget to re-enable your antivirus application after running the above scan!
eset.gif
regards,
deeprybka
:busy:
Neminem laede, immo omnes, quantum potes, iuva. Arthur Schopenhauer
 
unite_blue.png
asap.png

#7 deeprybka

deeprybka

  • Malware Response Team
  • 5,198 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Germany
  • Local time:11:11 AM

Posted 08 June 2015 - 02:47 PM

Hi,

3 Day Inactivity

this is the third day since my last post. Are you still there?

If you need more time, just let me know.

If you do not post within 48 hours, this thread will be closed due to inactivity.
regards,
deeprybka
:busy:
Neminem laede, immo omnes, quantum potes, iuva. Arthur Schopenhauer
 
unite_blue.png
asap.png

#8 HawkZ28

HawkZ28
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:04:11 AM

Posted 08 June 2015 - 10:47 PM

My apologies for the delay- I had to spend the weekend rebuilding my parents shed for my Mom, and had to get caught up on mowing several accounts- by the time I got home both nights I was physically exhausted. 

 

Here's the results of the Zoek scan. It did require a reboot.  I'll download ESET next and post the results of that seperately.  THANKS again for the help!

 

zoek- results- notepad

 

 
Zoek.exe v5.0.0.0 Updated 04-May-2015
Tool run by Alisha on Mon 06/08/2015 at 17:03:20.22.
Microsoft Windows 8.1 6.3.9600  x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Alisha\Desktop\zoek.exe [Scan all users] [Script inserted] 
 
==== System Restore Info ======================
 
6/8/2015 5:05:01 PM Zoek.exe System Restore Point Created Successfully.
 
==== Empty Folders Check ======================
 
C:\Users\Alisha\AppData\Local\softthinks deleted successfully
 
==== Deleting CLSID Registry Keys ======================
 
 
==== Deleting CLSID Registry Values ======================
 
 
==== Running Processes ======================
 
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Motorola Media Link\Lite\NServiceEntry.exe
C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe
C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperService.exe
C:\Program Files (x86)\Wyse\PocketCloud\WyseRemoteAccess.exe
C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperAgent.exe
C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe
C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe
C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Dell Update\DellUpService.exe
C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Dell Update\DellUpTray.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
C:\Program Files (x86)\Dell Backup and Recovery\sftservice.exe
C:\Program Files (x86)\Dell Backup and Recovery\COMPONENTS\DBRUPDATE\DBRUPD.EXE
C:\Program Files (x86)\Dell Backup and Recovery\TOASTER.EXE
C:\Windows\sysWOW64\wbem\wmiprvse.exe
C:\Windows\sysWOW64\wbem\wmiprvse.exe
C:\Program Files (x86)\Dell Customer Connect\OTBSurvey.exe
C:\Users\Alisha\Desktop\zoek.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\SysWOW64\cmd.exe
 
==== Deleting Services ======================
 
 
==== Deleting Files \ Folders ======================
 
C:\Users\Alisha\.android deleted
C:\PROGRA~3\Package Cache deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted
"C:\Windows\Installer\286dca.msi" deleted
 
==== System Specs ======================
 
Operating System: Microsoft Windows 8.1 6.3.9600  64-bit
Manufacturer: Dell Inc. - Model: Inspiron 3537
Install Date: 4/1/2014 7:52:05 PM
Last Boot: 6/4/2015 6:13:53 PM
Processor: Intel® Core™ i3-4010U CPU @ 1.70GHz
Number of Processors: 4
Work Station
Bootmode: Normal boot
Total RAM: 3976 MB (free 2281 MB - 57)
Computername: ALISHAHAWKINSPC
Domain: WORKGROUP
User: Alisha (Administrator account)
Local Disk:        C:\ - NTFS - 456 GB (free 382 GB)
CD \ DVD Drive:    D:\ 
Local Disk:        E:\ - FAT32 - 0 GB (free 0 GB)
Local Disk:        X:\ - NTFS - 0 GB (free 0 GB)
Local Disk:        Y:\ - NTFS - 8 GB (free 0 GB)
Bootdevice: \Device\HarddiskVolume1
Windows update: 
Country: United States 
Language: ENU 
 
==== System Specs (Software) ======================
 
Anti-Virus: Windows Defender On-access scanning disabled (Outdated)
Anti-Spyware: Windows Defender disabled (Outdated)
Default Browser: Google Chrome 43.0.2357.81
Internet Explorer Version: 11.0.9600.17801 
Google Chrome version: 43.0.2357.81
Adobe Reader version: 11.0.11.18
Sun Java version: 1.8.0_31 (32-bit) 
Sun Java version: 1.8.0_31 (64-bit) 
Flash Player version: 15.0.0.239
 
==== Files Recently Created / Modified ======================
 
====== C:\Windows ====
====== C:\Users\Alisha\AppData\Local\Temp ====
====== Java Cache =====
====== C:\Windows\SysWOW64 =====
2015-05-26 03:38:08 0FDCB0931B57280D59942556A6706372 21504 ----a-w- C:\Windows\SysWOW64\sdbinst.exe
2015-05-26 03:38:03 3250046189DF6429ECD93D9B483C62C7 1943040 ----a-w- C:\Windows\SysWOW64\dwmcore.dll
2015-05-26 03:38:02 CB07788DF1639ED547F645403BECD759 141824 ----a-w- C:\Windows\SysWOW64\Windows.UI.Input.Inking.dll
2015-05-26 03:37:57 69304975B8DF00BDC9567AAAF97791F2 1812992 ----a-w- C:\Windows\SysWOW64\SRH.dll
2015-05-26 03:37:54 697177C5242095DBDB3A3B52DD27C400 1207296 ----a-w- C:\Windows\SysWOW64\dbghelp.dll
2015-05-26 03:37:54 3C2B9089839D283DD6F91CF5F0748D1D 2985984 ----a-w- C:\Windows\SysWOW64\dbgeng.dll
2015-05-26 03:36:58 95AB9B30166221ED22E43290D47198CD 364544 ----a-w- C:\Windows\SysWOW64\PhotoMetadataHandler.dll
2015-05-26 03:36:15 032D9982B72E4F9A9B62A43B4CEDB072 1969664 ----a-w- C:\Windows\SysWOW64\wpdshext.dll
====== C:\Windows\SysWOW64\drivers =====
====== C:\Windows\Sysnative =====
2015-05-26 03:38:14 4658D596725A71521971054D3AF1DCD0 2819584 ----a-w- C:\Windows\Sysnative\SettingsHandlers.dll
2015-05-26 03:38:08 952D277678FC177CA8549B92A01C4C2C 24576 ----a-w- C:\Windows\Sysnative\sdbinst.exe
2015-05-26 03:38:04 3DB29814EA5A2091425200B58E25BA15 2256896 ----a-w- C:\Windows\Sysnative\dwmcore.dll
2015-05-26 03:38:02 7E36F0698777668A09DD316E59807E0E 172544 ----a-w- C:\Windows\Sysnative\Windows.UI.Input.Inking.dll
2015-05-26 03:38:01 0F5DF8F08C138D9E1DE88984FEAA1B96 1696256 ----a-w- C:\Windows\Sysnative\wevtsvc.dll
2015-05-26 03:37:57 8442CC9A31FC381255B98D615E49EF82 2162176 ----a-w- C:\Windows\Sysnative\SRH.dll
2015-05-26 03:37:55 48CC2698381AA1F6FBE0D78507281B40 4417536 ----a-w- C:\Windows\Sysnative\dbgeng.dll
2015-05-26 03:37:54 161156327265FB02A820506B98DA7A07 1491456 ----a-w- C:\Windows\Sysnative\dbghelp.dll
2015-05-26 03:37:47 053EF531F55B508343BB3CA91386C1C7 186368 ----a-w- C:\Windows\Sysnative\dpapisrv.dll
2015-05-26 03:36:59 B023C38663271E79FC2A9B63F6FE6417 445440 ----a-w- C:\Windows\Sysnative\PhotoMetadataHandler.dll
2015-05-26 03:36:16 0BB6089A1AEE468209FE22E29E6B87BD 2067968 ----a-w- C:\Windows\Sysnative\wpdshext.dll
2015-05-26 03:36:14 9D17F78BB04A3EF67426AFD087660188 410017 ----a-w- C:\Windows\Sysnative\ApnDatabase.xml
====== C:\Windows\Sysnative\drivers =====
2015-05-26 03:38:05 FE14D249D39368CA62D8DA6BC94AC694 80384 ----a-w- C:\Windows\Sysnative\drivers\ahcache.sys
2015-05-26 03:37:49 95B0179BDA907252025DEEA183699FB3 467776 -c--a-w- C:\Windows\Sysnative\drivers\USBHUB3.SYS
2015-05-26 03:37:01 C61EAF8E1E4B2F62BA4FDF457440B2C6 316416 ----a-w- C:\Windows\Sysnative\drivers\udfs.sys
2015-05-26 03:36:49 272A62B660A48AEF366F8A1836CED19F 57856 -c--a-w- C:\Windows\Sysnative\drivers\bthhfenum.sys
2015-05-26 03:36:17 C54B6B2170BF628FD42F799A66956D75 239424 -c--a-w- C:\Windows\Sysnative\drivers\sdbus.sys
2015-05-26 03:36:17 95E295FD19F80B3AD33629B5AEFEC9C7 154432 -c--a-w- C:\Windows\Sysnative\drivers\dumpsd.sys
2015-05-15 04:10:17 5E5AB950693F2C6D6ACBEE3A74697ED7 561928 ----a-w- C:\Windows\Sysnative\drivers\cng.sys
====== C:\Windows\Tasks ======
====== C:\Windows\Temp ======
======= C:\Program Files =====
======= C:\PROGRA~2 =====
2015-06-08 21:59:27 -------- d-----w- C:\PROGRA~2\Dell Customer Connect
2015-06-03 04:23:02 -------- d-----w- C:\PROGRA~2\Dell Update
======= C: =====
====== C:\Users\Alisha\AppData\Roaming ======
2015-06-04 23:15:47 -------- d-----r- C:\Users\Alisha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
2015-06-04 03:08:55 -------- d-----w- C:\Users\Alisha\AppData\Local\GWX
====== C:\Users\Alisha ======
2015-06-04 22:55:34 D56605A4F5CE2DBEBA1540304827B394 2231296 ----a-w- C:\Users\Alisha\Desktop\AdwCleaner.exe
2015-06-04 02:47:13 9C56E6D473AA2E836F5EFA06CEA60855 2108928 ----a-w- C:\Users\Alisha\Desktop\FRST64.exe
2015-06-03 04:19:54 -------- d-----w- C:\Windows\serviceprofiles\Localservice\winhttp
 
====== C: exe-files ==
2015-06-04 22:55:34 D56605A4F5CE2DBEBA1540304827B394 2231296 ----a-w- C:\Users\Alisha\Desktop\AdwCleaner.exe
2015-06-04 02:47:13 9C56E6D473AA2E836F5EFA06CEA60855 2108928 ----a-w- C:\Users\Alisha\Desktop\FRST64.exe
2015-06-03 18:35:33 B94C770978AD994F419D92FE24FD3F0F 360240 ----a-w- C:\Windows\System32\GWX\GWXUXWorker.exe
2015-06-03 18:35:33 9FCD33F6C4765C8EAEEA7E152D1E2E75 401408 ----a-w- C:\Windows\System32\GWX\GWXUX.exe
2015-06-03 18:35:33 0AD060F08BC0008DA1B0FECA0015F270 475648 ----a-w- C:\Windows\System32\GWX\GWX.exe
2015-06-03 18:35:32 2B0C2B239CE5603F7F7FD57F54E841C8 666624 ----a-w- C:\Windows\System32\GWX\GWXConfigManager.exe
2015-06-03 03:43:18 B1798BC27E40983B12FEFD0D85C05B3F 873800 ----a-w- C:\Users\Alisha\AppData\Local\Google\Chrome\User Data\SwReporter\3.21.0\software_reporter_tool.exe
=== C: other files ==
2015-06-03 18:56:17 EC1656105774D0E4FEF80CEB21087E18 21049 ----a-w- C:\ProgramData\PCDr\6584\AddOnDownloaderCache\zipped\c749e834-df0f-483e-9946-33435f37c240.zip
2015-06-03 18:56:16 4717F713D1E774C80283D5D7B8364517 13741 ----a-w- C:\ProgramData\PCDr\6584\AddOnDownloaderCache\zipped\4628ddf8-b4cb-4445-b869-56cb92eae20b.zip
2015-06-03 18:56:16 3613BDE818035A54A09A2D173BB9B037 19534 ----a-w- C:\ProgramData\PCDr\6584\AddOnDownloaderCache\zipped\a3597d54-6702-4158-82a7-161727372d0f.zip
2015-06-03 18:56:16 27FB7D3E15F7A1941E67D568C9515961 16654 ----a-w- C:\ProgramData\PCDr\6584\AddOnDownloaderCache\zipped\4e3bd962-072e-42a0-8ffb-faf4fbf06230.zip
2015-06-03 18:56:15 9C52F7E032EFF526DC04AF86508E7ADE 15370 ----a-w- C:\ProgramData\PCDr\6584\AddOnDownloaderCache\zipped\873c94c8-114d-4d39-a36a-14d636c6e7f3.zip
2015-06-03 18:56:15 8A5342D104C0B3A8103EAF3682379BCC 47723 ----a-w- C:\ProgramData\PCDr\6584\AddOnDownloaderCache\zipped\2ed4ce9e-0dff-4595-a0aa-f3e3b671fddc.zip
2015-06-03 18:56:15 6E9449BA8183BB4D515A08209D945F2D 51922 ----a-w- C:\ProgramData\PCDr\6584\AddOnDownloaderCache\zipped\ff34f184-7b2d-4b07-9131-b1349888b6e5.zip
2015-06-03 18:56:14 7EB4119B0A444FB77A789BF3CAD61F8E 62152 ----a-w- C:\ProgramData\PCDr\6584\AddOnDownloaderCache\zipped\48db0c93-e691-44fc-9c6b-a61e60525cfe.zip
2015-06-03 18:56:13 7822092FEB4F847B5030D53507442E50 68742 ----a-w- C:\ProgramData\PCDr\6584\AddOnDownloaderCache\zipped\5d051b98-7605-4cfa-8547-334cf523870e.zip
 
==== Startup Registry Enabled ======================
 
[HKEY_USERS\S-1-5-21-2865801210-255665649-1679975380-1001\Software\Microsoft\Windows\CurrentVersion\Run]
"EPLTarget\P0000000000000000"="C:\Windows\system32\spool\DRIVERS\x64\3\E_IATILBE.EXE /EPT EPLTarget\P0000000000000000 /M XP-310 Series"
"EPLTarget\P0000000000000001"="C:\Windows\system32\spool\DRIVERS\x64\3\E_IATILBE.EXE /EPT EPLTarget\P0000000000000001 /M XP-310 Series"
"Google Update"="C:\Users\Alisha\AppData\Local\Google\Update\GoogleUpdate.exe /c"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EEventManager"="C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
"Malwarebytes Anti-Exploit"="C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe"
"AgentMonitor"="C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe"
"Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
 
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"EPLTarget\P0000000000000000"="C:\Windows\system32\spool\DRIVERS\x64\3\E_IATILBE.EXE /EPT EPLTarget\P0000000000000000 /M XP-310 Series"
"EPLTarget\P0000000000000001"="C:\Windows\system32\spool\DRIVERS\x64\3\E_IATILBE.EXE /EPT EPLTarget\P0000000000000001 /M XP-310 Series"
"Google Update"="C:\Users\Alisha\AppData\Local\Google\Update\GoogleUpdate.exe /c"
 
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"BtvStack"="C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtvStack.exe"
 
==== Startup Registry Enabled x64 ======================
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s"
"RtHDVBg"="C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /MAXX4P1"
"RtHDVBg_PushButton"="C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /IM"
"QuickSet"="c:\Program Files\Dell\QuickSet\QuickSet.exe"
"IgfxTray"="C:\Windows\system32\igfxtray.exe"
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe"
"Persistence"="C:\Windows\system32\igfxpers.exe"
"IAStorIcon"="C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIconLaunch.exe C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe 60"
 
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"BtvStack"="C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtvStack.exe"
 
==== Startup Folders ======================
 
2014-05-12 01:16:42 1268 ----a-w- C:\Users\Alisha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Epson all-in-one Registration.lnk
2015-03-27 01:16:31 2635 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Virtual Router Manager.lnk
 
==== Task Scheduler Jobs ======================
 
C:\Windows\tasks\EPSON XP-310 Series Invitation {6FBC8136-D0FB-4BFE-8C07-43602C8FFBDF}.job --a-------- C:\Windows\system32\spool\DRIVERS\x64\3\E_ITSLBE.exe [12/02/2014 05:46 AM]
C:\Windows\tasks\EPSON XP-310 Series Invitation {E744DC98-AD53-447E-90B3-7A3927BD5DCA}.job --a-------- C:\Windows\system32\spool\DRIVERS\x64\3\E_ITSLBE.exe [12/02/2014 05:46 AM]
C:\Windows\tasks\EPSON XP-310 Series Update {6FBC8136-D0FB-4BFE-8C07-43602C8FFBDF}.job --a-------- C:\Windows\system32\spool\DRIVERS\x64\3\E_ITSLBE.exe [12/02/2014 05:46 AM]
C:\Windows\tasks\EPSON XP-310 Series Update {E744DC98-AD53-447E-90B3-7A3927BD5DCA}.job --a-------- C:\Windows\system32\spool\DRIVERS\x64\3\E_ITSLBE.exe [12/02/2014 05:46 AM]
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [12/01/2014 10:47 PM]
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [12/01/2014 10:47 PM]
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2865801210-255665649-1679975380-1001Core.job --a-------- C:\Users\Alisha\AppData\Local\Google\Update\GoogleUpdate.exe [10/12/2014 04:14 PM]
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2865801210-255665649-1679975380-1001UA.job --a-------- C:\Users\Alisha\AppData\Local\Google\Update\GoogleUpdate.exe [10/12/2014 04:14 PM]
 
==== Other Scheduled Tasks ======================
 
"C:\Windows\SysNative\tasks\Adobe Acrobat Update Task" [C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe]
"C:\Windows\SysNative\tasks\CLMLSvc_P2G8" [C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe]
"C:\Windows\SysNative\tasks\CLVDLauncher" [C:\Program Files (x86)\CyberLink\Power2Go8\CLVDLauncher.exe]
"C:\Windows\SysNative\tasks\Dell SupportAssistAgent AutoUpdate" [C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssist.exe]
"C:\Windows\SysNative\tasks\EPSON XP-310 Series Invitation {6FBC8136-D0FB-4BFE-8C07-43602C8FFBDF}" [C:\Windows\system32\spool\DRIVERS\x64\3\E_ITSLBE.EXE]
"C:\Windows\SysNative\tasks\EPSON XP-310 Series Invitation {E744DC98-AD53-447E-90B3-7A3927BD5DCA}" [C:\Windows\system32\spool\DRIVERS\x64\3\E_ITSLBE.EXE]
"C:\Windows\SysNative\tasks\EPSON XP-310 Series Update {6FBC8136-D0FB-4BFE-8C07-43602C8FFBDF}" [C:\Windows\system32\spool\DRIVERS\x64\3\E_ITSLBE.EXE]
"C:\Windows\SysNative\tasks\EPSON XP-310 Series Update {E744DC98-AD53-447E-90B3-7A3927BD5DCA}" [C:\Windows\system32\spool\DRIVERS\x64\3\E_ITSLBE.EXE]
"C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe]
"C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe]
"C:\Windows\SysNative\tasks\GoogleUpdateTaskUserS-1-5-21-2865801210-255665649-1679975380-1001Core" [C:\Users\Alisha\AppData\Local\Google\Update\GoogleUpdate.exe]
"C:\Windows\SysNative\tasks\GoogleUpdateTaskUserS-1-5-21-2865801210-255665649-1679975380-1001UA" [C:\Users\Alisha\AppData\Local\Google\Update\GoogleUpdate.exe]
"C:\Windows\SysNative\tasks\MotoCast Update" ["C:\Program Files (x86)\Motorola Mobility\MotoCast\LiveUpdate\MotoCastUpdate.exe"]
"C:\Windows\SysNative\tasks\MotoHelper Initial Update" ["C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperUpdate.exe"]
"C:\Windows\SysNative\tasks\MotoHelper Routing" ["C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperUpdate.exe"]
"C:\Windows\SysNative\tasks\MotoHelper Update" ["C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperUpdate.exe"]
"C:\Windows\SysNative\tasks\PCDEventLauncherTask" ["C:\Program Files\Dell\SupportAssist\sessionchecker.exe"]
"C:\Windows\SysNative\tasks\PCDoctorBackgroundMonitorTask" ["C:\Program Files\Dell\SupportAssist\uaclauncher.exe"]
"C:\Windows\SysNative\tasks\PocketCloud" [C:\Program Files (x86)\Wyse\PocketCloud\PocketCloudDesktopApp.exe]
"C:\Windows\SysNative\tasks\PocketCloudUpdater" [C:\Program]
"C:\Windows\SysNative\tasks\PocketCloudVirtualChannel" [C:\Program Files (x86)\Wyse\PocketCloud\WPCRDPVirtualChannelServer.exe]
"C:\Windows\SysNative\tasks\Synaptics TouchPad Enhancements" ["C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"]
"C:\Windows\SysNative\tasks\SystemToolsDailyTest" ["uaclauncher.exe"]
"C:\Windows\SysNative\tasks\Dell\Dell System Registration" [C:\Program Files (x86)\System Registration\prodreg.exe]
 
==== Chromium Look ======================
 
Google Slides - Alisha\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek
Google Docs - Alisha\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake
Google Drive - Alisha\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf
YouTube - Alisha\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo
Google Cast - Alisha\AppData\Local\Google\Chrome\User Data\Default\Extensions\boadgeojelhgndaghljhdicfkmllpafd
selector is not a valid CSS selector - Alisha\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb
Google Search - Alisha\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf
FLV Player - Alisha\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhogabmliblgpadclikpkjfnnipeebjm
Google Sheets - Alisha\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap
Bookmark Manager - Alisha\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik
Flash Player - Alisha\AppData\Local\Google\Chrome\User Data\Default\Extensions\jdpbajmogfhlafbipjjklkdhloplicgc
Chrome Hotword Shared Module - Alisha\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg
Google Wallet - Alisha\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
Gmail - Alisha\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia
 
==== Set IE to Default ======================
 
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
 
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
 
==== All HKCU SearchScopes ======================
 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{B7B00D46-3BBA-432E-8D77-8DE30E19C64B}"
{012E1000-F331-11DB-8314-0800200C9A66} Google  Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing  Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
{7F595587-C0D2-4359-B315-BDA9DD524B45} Unknown  Url="Not_Found"
 
==== Reset Google Chrome ======================
 
C:\Users\Alisha\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Alisha\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully
C:\Users\Alisha\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Alisha\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully
 
==== Deleting CLSID Registry Keys ======================
 
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes\{7F595587-C0D2-4359-B315-BDA9DD524B45} deleted successfully
HKEY_USERS\S-1-5-21-2865801210-255665649-1679975380-1001\Software\Microsoft\Internet Explorer\SearchScopes\{7F595587-C0D2-4359-B315-BDA9DD524B45} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{7F595587-C0D2-4359-B315-BDA9DD524B45} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{7F595587-C0D2-4359-B315-BDA9DD524B45} deleted successfully
 
==== Deleting CLSID Registry Values ======================
 
 
==== shortcuts on All Users Desktop ======================
 
C:\Users\Public\Desktop\Adobe Reader XI.lnk - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe 
C:\Users\Public\Desktop\EPSON Scan.lnk - C:\Windows\twain_32\escndv\escndv.exe 
C:\Users\Public\Desktop\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe 
C:\Users\Public\Desktop\Learning Lodge™.lnk -  
 
==== shortcuts in All Users Start Menu ======================
 
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk - C:\Windows\Installer\{AC76BA86-7AD7-1033-7B44-AB0000000001}\SC_Reader.ico 
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ClockworkMod\Tether.lnk - C:\Windows\Installer\{C5C67EA4-16FA-473C-B274-904A71162DE4}\_3F1225F1C620FFC4E14FB0.exe 
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell\Dell Customer Connect.lnk - C:\Program Files (x86)\Dell Customer Connect\OTBSurveyTrayApp.exe 
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell\Dell Update.lnk - C:\Program Files (x86)\Dell Update\DellUpTray.exe 
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell\SupportAssist\PC Checkup.lnk - C:\Program Files\Dell\SupportAssist\pcdlauncher.exe -startingpage pccheckup -lloc pccheckup
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell\SupportAssist\SupportAssist.lnk - C:\Program Files\Dell\SupportAssist\pcdlauncher.exe -lloc dsc
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe 
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Exploit\Malwarebytes Anti-Exploit.lnk - C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe 
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Exploit\Uninstall Malwarebytes Anti-Exploit.lnk - C:\Program Files (x86)\Malwarebytes Anti-Exploit\unins000.exe 
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Malwarebytes Anti-Malware Notifications.lnk - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe 
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Malwarebytes Anti-Malware.lnk - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe 
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Uninstall Malwarebytes Anti-Malware.lnk - C:\Program Files (x86)\Malwarebytes Anti-Malware\unins000.exe 
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Tools\Malwarebytes Anti-Malware Chameleon.lnk - C:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\chameleon.chm 
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp\Virtual Router Manager.lnk - C:\Windows\Installer\{BE905C46-2B34-4D73-AEE1-769ED138E0FF}\_118D1A4EFFA6998C3492EB.exe /min
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Virtual Router\Virtual Router Manager.lnk - C:\Windows\Installer\{BE905C46-2B34-4D73-AEE1-769ED138E0FF}\_83B54E4F1B8BB4A43AE5AB.exe 
 
==== shortcuts in Quick Launch ======================
 
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -  
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -  
C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -  
C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -  
 
==== Deleting Registry Keys ======================
 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\472EE7AF07377B34A9543AB971CCDC5C deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{FA7EE274-7370-43B7-9A45-A39B17CCCDC5} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\472EE7AF07377B34A9543AB971CCDC5C deleted successfully
 
==== HijackThis Entries ======================
 
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Exploit] C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe
O4 - HKLM\..\Run: [AgentMonitor] C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [EPLTarget\P0000000000000000] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATILBE.EXE /EPT "EPLTarget\P0000000000000000" /M "XP-310 Series"
O4 - HKCU\..\Run: [EPLTarget\P0000000000000001] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATILBE.EXE /EPT "EPLTarget\P0000000000000001" /M "XP-310 Series"
O4 - HKCU\..\Run: [Google Update] "C:\Users\Alisha\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [MotoCast] "C:\Program Files (x86)\Motorola Mobility\MotoCast\MotoLauncher.lnk"
O4 - HKLM\..\Policies\Explorer\Run: [BtvStack] "C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtvStack.exe"
O4 - Startup: Epson all-in-one Registration.lnk = Alisha\AppData\Roaming\Leadertech\PowerRegister\Epson all-in-one Registration.exe
O4 - Global Startup: Virtual Router Manager.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: *.dell.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{B38AA017-B810-47AC-BE24-B1D95D92D7BF}: NameServer = 8.8.8.8,8.8.4.4
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AtherosSvc - Windows ® Win 7 DDK provider - C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\adminservice.exe
O23 - Service: Intel® Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: Dell Customer Connect - Dell Inc. - C:\Program Files (x86)\Dell Customer Connect\OTBSurvey.exe
O23 - Service: Dell Data Vault (DellDataVault) - Dell Inc. - C:\Program Files\Dell\DellDataVault\DellDataVault.exe
O23 - Service: Dell Data Vault Wizard (DellDataVaultWiz) - Dell Inc. - C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe
O23 - Service: Dell Digital Delivery Service (DellDigitalDelivery) - Dell Products, LP. - c:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe
O23 - Service: Dell Update Service (DellUpdate) - Dell Inc. - C:\Program Files (x86)\Dell Update\DellUpService.exe
O23 - Service: DeviceMonitorService - Nero AG - C:\Program Files (x86)\Motorola Media Link\Lite\NServiceEntry.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: EpsonCustomerParticipation - SEIKO EPSON CORPORATION - C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe
O23 - Service: Epson Scanner Service (EpsonScanSvc) - Unknown owner - C:\Windows\system32\EscSvc64.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel® Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel® HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\Windows\system32\igfxCUIService.exe (file missing)
O23 - Service: Intel® Capability Licensing Service Interface - Intel® Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel® Capability Licensing Service TCP IP Interface - Intel® Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel® Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
O23 - Service: Malwarebytes Anti-Exploit Service (MbaeSvc) - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: MotoHelper Service (MotoHelper) - Unknown owner - C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperService.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - CyberLink - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SoftThinks Agent Service (SftService) - SoftThinks SAS - C:\Program Files (x86)\Dell Backup and Recovery\sftservice.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Dell SupportAssist Agent (SupportAssistAgent) - Dell Inc. - C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VirtualRouterService (Virtual Router) - Chris Pietschmann (http://pietschsoft.com) - C:\Program Files (x86)\Virtual Router\VirtualRouterService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Wyse PocketCloud (WysePocketCloud) - Unknown owner - C:\Program Files (x86)\Wyse\PocketCloud\PocketCloudService.exe
O23 - Service: Wyse RemoteAccess (WyseRemoteAccess) - DELL Inc. - C:\Program Files (x86)\Wyse\PocketCloud\WyseRemoteAccess.exe
 
==== Empty IE Cache ======================
 
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Alisha\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\Alisha\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\Alisha\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\Users\Alisha\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
 
==== Empty FireFox Cache ======================
 
No FireFox Profiles found
 
==== Empty Chrome Cache ======================
 
C:\Users\Alisha\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
 
==== Empty All Flash Cache ======================
 
Flash Cache Emptied Successfully
 
==== Empty All Java Cache ======================
 
Java Cache cleared successfully
 
==== C:\zoek_backup content ======================
 
C:\zoek_backup (files=29 folders=60 296909545 bytes)
 
==== Empty Temp Folders ======================
 
C:\Users\Alisha\AppData\Local\Temp will be emptied at reboot
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
 
==== After Reboot ======================
 
==== Empty Temp Folders ======================
 
C:\Windows\Temp successfully emptied
C:\Users\Alisha\AppData\Local\Temp successfully emptied
 
==== Empty Recycle Bin ======================
 
C:\$RECYCLE.BIN successfully emptied
 
==== EOF on Mon 06/08/2015 at 22:39:23.56 ======================


#9 deeprybka

deeprybka

  • Malware Response Team
  • 5,198 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Germany
  • Local time:11:11 AM

Posted 09 June 2015 - 03:13 AM

I'll download ESET next and post the results of that seperately.  THANKS again for the help!


You are welcome! OK. :)
regards,
deeprybka
:busy:
Neminem laede, immo omnes, quantum potes, iuva. Arthur Schopenhauer
 
unite_blue.png
asap.png

#10 HawkZ28

HawkZ28
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:04:11 AM

Posted 09 June 2015 - 06:52 AM

Here is the ESET log.  It found 1 item.  

 

ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=65b0ea733bc3af428807ad330903f514
# end=init
# utc_time=2015-06-09 03:49:42
# local_time=2015-06-08 10:49:42 (-0600, Central Daylight Time)
# country="United States"
# osver=6.2.9200 NT 
Update Init
Update Download
esets_scanner_update returned -1 esets_gle=41221
Update Finalize
Updated modules version: 0
Old modules - leave modules
Update Init
Update Download
esets_scanner_update returned -1 esets_gle=41221
Update Finalize
Updated modules version: 0
Old modules - delete modules
Update Init
Update Download
Update Init
Update Download
esets_scanner_update returned -1 esets_gle=41221
Update Finalize
Updated modules version: 0
Old modules - leave modules
Update Init
Update Download
esets_scanner_update returned -1 esets_gle=45315
Update Finalize
Updated modules version: 0
Old modules - delete modules
Update Init
Update Download
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=65b0ea733bc3af428807ad330903f514
# end=init
# utc_time=2015-06-09 03:58:05
# local_time=2015-06-08 10:58:05 (-0600, Central Daylight Time)
# country="United States"
# osver=6.2.9200 NT 
Update Init
Update Download
Update Finalize
Updated modules version: 24236
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=65b0ea733bc3af428807ad330903f514
# end=updated
# utc_time=2015-06-09 04:00:43
# local_time=2015-06-08 11:00:43 (-0600, Central Daylight Time)
# country="United States"
# osver=6.2.9200 NT 
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7777
# api_version=3.1.1
# EOSSerial=65b0ea733bc3af428807ad330903f514
# engine=24236
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2015-06-09 05:23:44
# local_time=2015-06-09 12:23:44 (-0600, Central Daylight Time)
# country="United States"
# lang=1033
# osver=6.2.9200 NT 
# compatibility_mode_1=''
# compatibility_mode=5893 16776573 100 94 0 10823416 0 0
# scanned=95391
# found=1
# cleaned=0
# scan_time=4980
sh=25B9F4013FB34153FFA27E460D4B8594C79FE337 ft=1 fh=15384691e6094ee0 vn="a variant of Win32/HiddenStart.A potentially unsafe application" ac=I fn="C:\Program Files (x86)\Dell Backup and Recovery\Components\DBRUpdate\hstart.exe"
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=65b0ea733bc3af428807ad330903f514
# end=init
# utc_time=2015-06-09 05:24:44
# local_time=2015-06-09 12:24:44 (-0600, Central Daylight Time)
# country="United States"
# osver=6.2.9200 NT 
Update Init
Update Download
Update Finalize
Updated modules version: 24239
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=65b0ea733bc3af428807ad330903f514
# end=updated
# utc_time=2015-06-09 05:25:45
# local_time=2015-06-09 12:25:45 (-0600, Central Daylight Time)
# country="United States"
# osver=6.2.9200 NT 
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7777
# api_version=3.1.1
# EOSSerial=65b0ea733bc3af428807ad330903f514
# engine=24239
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2015-06-09 06:46:45
# local_time=2015-06-09 01:46:45 (-0600, Central Daylight Time)
# country="United States"
# lang=1033
# osver=6.2.9200 NT 
# compatibility_mode_1=''
# compatibility_mode=5893 16776573 100 94 0 10828397 0 0
# scanned=221904
# found=1
# cleaned=0
# scan_time=4859
sh=25B9F4013FB34153FFA27E460D4B8594C79FE337 ft=1 fh=15384691e6094ee0 vn="a variant of Win32/HiddenStart.A potentially unsafe application" ac=I fn="C:\Program Files (x86)\Dell Backup and Recovery\Components\DBRUpdate\hstart.exe"


#11 deeprybka

deeprybka

  • Malware Response Team
  • 5,198 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Germany
  • Local time:11:11 AM

Posted 09 June 2015 - 11:45 AM

This looks very good. No more active malware has been found. :)

lesestoff.png

Can you please tell me which problems still persist now?
regards,
deeprybka
:busy:
Neminem laede, immo omnes, quantum potes, iuva. Arthur Schopenhauer
 
unite_blue.png
asap.png

#12 HawkZ28

HawkZ28
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:04:11 AM

Posted 10 June 2015 - 10:44 PM

So far so good!  I don't see the highlighted search words in paragraphs, and my browser doesn't seem to get hijacked.  

 

What exactly was the malware?  Just curious so I know what to tell my wife as to possibilities of her laptop getting infected.  

 

THANKS so much again for all your help!  



#13 deeprybka

deeprybka

  • Malware Response Team
  • 5,198 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Germany
  • Local time:11:11 AM

Posted 11 June 2015 - 02:53 AM

Some Adware. You should pay more attention when installing software because often, a software installer includes optional installs. Be very careful what you agree to install.

Step 1

frst.pngfrstscan.png

Start FRST with administator privileges.
  • Make sure the following option is checked: addition.png
  • Press the Scan button.
  • When finished, FRST will produce two logs (FRST.txt and Addition.txt) in the same directory the tool was run from.
    Please copy and paste these logs in your next reply.

regards,
deeprybka
:busy:
Neminem laede, immo omnes, quantum potes, iuva. Arthur Schopenhauer
 
unite_blue.png
asap.png

#14 deeprybka

deeprybka

  • Malware Response Team
  • 5,198 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Germany
  • Local time:11:11 AM

Posted 16 June 2015 - 03:14 AM

Due to the lack of feedback, this topic is now closed.

In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days.

Please include a link to your topic in the Private Message. Thank you.
regards,
deeprybka
:busy:
Neminem laede, immo omnes, quantum potes, iuva. Arthur Schopenhauer
 
unite_blue.png
asap.png




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users