Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Ran scans with multiple software - viruses/malware galore!


  • This topic is locked This topic is locked
7 replies to this topic

#1 trendsetter

trendsetter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:05:26 PM

Posted 06 June 2015 - 09:21 AM

I have run scans with Norton Security Suite and Malwarebytes and I get several detected objects. It says they were removed, but everytime I run another scan with Malwarebytes, I keep getting a different set of detected objects. I'm not sure what else to do? I don't mind doing a clean install of Windows 7 Enterprise, but I no longer have the CD/key, etc. Below are my Farbar logs.

 

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 06-06-2015
Ran by D (administrator) on LI-PC on 06-06-2015 10:10:19
Running from C:\Users\D\Desktop
Loaded Profiles: D &  (Available Profiles: D)
Platform: Microsoft Windows 7 Enterprise  Service Pack 1 (X86) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Symantec Corporation) C:\Program Files\Norton Security Suite\Engine\21.7.0.11\n360.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\TeamViewer_Service.exe
(Symantec Corporation) C:\Program Files\Norton Security Suite\Engine\21.7.0.11\n360.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\TeamViewer.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\tv_w32.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\cmd.exe
(Symantec Corporation) C:\Program Files\Norton Security Suite\Engine\21.7.0.11\conathst.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Kaspersky Lab ZAO) C:\Users\D\Downloads\KVRT.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_17_0_0_188.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_17_0_0_188.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\RunOnce: [{8F5135D2-2815-49B0-B035-FBDE35EE11EC}] => cmd.exe /C start /D "C:\Users\D\AppData\Local\Temp" /B {8F5135D2-2815-49B0-B035-FBDE35EE11EC}.cmd
HKLM\...\Policies\Explorer: [NoSetActiveDesktop] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [280576 2013-03-22] (Microsoft Corporation)
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Winlogon: [Shell] C:\Windows\Explorer.exe [2616320 2011-02-25] (Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-19\...\Winlogon: [Shell] C:\Windows\Explorer.exe [2616320 2011-02-25] (Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Winlogon: [Shell] C:\Windows\Explorer.exe [2616320 2011-02-25] (Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-20\...\Winlogon: [Shell] C:\Windows\Explorer.exe [2616320 2011-02-25] (Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Winlogon: [Shell] C:\Windows\Explorer.exe [2616320 2011-02-25] (Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-21-4231112004-1192876706-404484655-1003\...\Run: [GoogleChromeAutoLaunch_1F815B1FE5A747F5ACFE511B39491701] => C:\Program Files\Google\Chrome\Application\chrome.exe [813896 2015-05-22] (Google Inc.)
HKU\S-1-5-21-4231112004-1192876706-404484655-1003\...\Winlogon: [Shell] C:\Windows\Explorer.exe [2616320 2011-02-25] (Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-21-4231112004-1192876706-404484655-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [GoogleChromeAutoLaunch_1F815B1FE5A747F5ACFE511B39491701] => C:\Program Files\Google\Chrome\Application\chrome.exe [813896 2015-05-22] (Google Inc.)
HKU\S-1-5-21-4231112004-1192876706-404484655-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Winlogon: [Shell] C:\Windows\Explorer.exe [2616320 2011-02-25] (Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [280576 2013-03-22] (Microsoft Corporation)
HKU\S-1-5-18\...\Winlogon: [Shell] C:\Windows\Explorer.exe [2616320 2011-02-25] (Microsoft Corporation) <==== ATTENTION
ShellIconOverlayIdentifiers: [OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files\Norton Security Suite\Engine\21.7.0.11\buShell.dll [2015-03-06] (Symantec Corporation)
ShellIconOverlayIdentifiers: [OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files\Norton Security Suite\Engine\21.7.0.11\buShell.dll [2015-03-06] (Symantec Corporation)
ShellIconOverlayIdentifiers: [OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files\Norton Security Suite\Engine\21.7.0.11\buShell.dll [2015-03-06] (Symantec Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hao.qq.com/?unc=Af31006&s=o400493_1
HKU\S-1-5-21-4231112004-1192876706-404484655-1003\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
BHO: 应用宝一键安装插件 -> {50F4150A-48B2-417A-BE4C-C83F580FB904} -> C:\Program Files\Common Files\Tencent\QQPhoneManager\2.0.201.3196\npQQPhoneManagerExt.dll [2014-03-05] (腾讯公司)
BHO: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files\Norton Security Suite\Engine\21.7.0.11\coIEPlg.dll [2015-03-05] (Symantec Corporation)
BHO: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files\Norton Security Suite\Engine\21.7.0.11\IPS\IPSBHO.DLL [2015-03-04] (Symantec Corporation)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-06-01] (Oracle Corporation)
BHO: QQMiniDL Helper Class -> {C9C7334B-5657-41e1-8F79-F6AACECA05F4} -> C:\Program Files\Common Files\Tencent\QQMiniDL\60\Browser\QQIEHelper01.dll No File
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-06-01] (Oracle Corporation)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\21.7.0.11\coIEPlg.dll [2015-03-05] (Symantec Corporation)
Toolbar: HKU\S-1-5-21-4231112004-1192876706-404484655-1003 -> Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\21.7.0.11\coIEPlg.dll [2015-03-05] (Symantec Corporation)
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76

FireFox:
========
FF ProfilePath: C:\Users\D\AppData\Roaming\Mozilla\Firefox\Profiles\zymk0v7e.default
FF DefaultSearchEngine.US: Google
FF Homepage: www.google.com
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_188.dll [2015-06-01] ()
FF Plugin: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-06-01] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-06-01] (Oracle Corporation)
FF Plugin: @kingsfot.com/npkws -> C:\Program Files\Kingsoft\kingsoft antivirus\npkws.dll No File
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin: @qq.com/npAndroidAssistant -> C:\Program Files\Common Files\Tencent\QQPhoneManager\2.0.201.3196\npQQPhoneManagerExt.dll [2014-03-05] (腾讯公司)
FF Plugin: @qq.com/npqscall,version=1.0.0 -> %commonprogramfiles%\tencent\NPQSCALL\npqscall.dll No File
FF Plugin: @qq.com/QQPhotoDrawEx -> C:\Program Files\Tencent\Qzone\npQQPhotoDrawEx.dll [2013-08-13] ()
FF Plugin: @qq.com/QzoneMusic -> C:\Program Files\Tencent\QQMusic\1144.2015.2.5.9.54.2\QzoneMusic\npQzoneMusic.dll No File
FF Plugin: @qq.com/TXSSO -> C:\Program Files\Common Files\Tencent\TXSSO\1.2.3.5\Bin\npSSOAxCtrlForPTLogin.dll [2014-12-07] (Tencent)
FF Plugin: @tencent.com/npQQMailWebKit,version=1.0.0.1 -> C:\Program Files\QQMailPlugin\npQQMailWebKit.dll [2013-04-25] (Tencent)
FF Plugin: @tencent.com/nptxftnWebKit,version=1.0.0.1 -> C:\Program Files\QQMailPlugin\nptxftnWebKit.dll [2013-04-08] (Tencent Technology (Shenzhen) Company Limited)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-06-01] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-06-01] (Google Inc.)
FF SearchPlugin: C:\Users\D\AppData\Roaming\Mozilla\Firefox\Profiles\zymk0v7e.default\searchplugins\safesearch.xml [2015-06-06]
FF Extension: AdBlock for Firefox - C:\Users\D\AppData\Roaming\Mozilla\Firefox\Profiles\zymk0v7e.default\Extensions\jid1-NIfFY2CA8fy1tg@jetpack.xpi [2015-06-06]
FF HKLM\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.1.0.18\coFFPlgn
FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.1.0.18\coFFPlgn [2015-06-06]

Chrome:
=======
CHR Profile: C:\Users\D\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\D\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-06-03]
CHR Extension: (Google Docs) - C:\Users\D\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-06-03]
CHR Extension: (Google Drive) - C:\Users\D\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-06-03]
CHR Extension: (YouTube) - C:\Users\D\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-06-03]
CHR Extension: (Google Search) - C:\Users\D\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-06-03]
CHR Extension: (Google Sheets) - C:\Users\D\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-06-03]
CHR Extension: (AdBlock) - C:\Users\D\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-06-06]
CHR Extension: (Bookmark Manager) - C:\Users\D\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-06-05]
CHR Extension: (Norton Identity Safe) - C:\Users\D\AppData\Local\Google\Chrome\User Data\Default\Extensions\iikflkcanblccfahdhdonehdalibjnif [2015-06-03]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\D\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-06-03]
CHR Extension: (Norton Security Toolbar) - C:\Users\D\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk [2015-06-03]
CHR Extension: (Google Wallet) - C:\Users\D\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-06-03]
CHR Extension: (Gmail) - C:\Users\D\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-06-03]
CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - https://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files\Norton Security Suite\Engine\21.7.0.11\Exts\Chrome.crx [2015-06-02]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 N360; C:\Program Files\Norton Security Suite\Engine\21.7.0.11\N360.exe [265000 2015-03-26] (Symantec Corporation)
R2 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [5491984 2015-05-20] (TeamViewer GmbH)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

U0 8542CA6D; C:\Windows\System32\drivers\8542CA6D.sys [135264 2015-06-06] (Kaspersky Lab ZAO)
R1 BHDrvx86; C:\Program Files\Norton Security Suite\NortonData\21.1.0.18\Definitions\BASHDefs\20150601.001\BHDrvx86.sys [1172696 2015-05-21] (Symantec Corporation)
R1 ccSet_N360; C:\Windows\system32\drivers\N360\1507000.00B\ccSetx86.sys [127064 2013-09-25] (Symantec Corporation)
R1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [380720 2015-06-01] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [113456 2015-06-01] (Symantec Corporation)
R1 IDSVix86; C:\Program Files\Norton Security Suite\NortonData\21.1.0.18\Definitions\IPSDefs\20150605.001\IDSvix86.sys [514776 2015-05-29] (Symantec Corporation)
R1 kissfly2; C:\Windows\system32\drivers\kissfly2.sys [26896 2014-01-30] (Kingsoft Corporation)
S3 knbdrv; C:\Windows\system32\drivers\KNBDrv.sys [148784 2015-03-18] (Kingsoft Corporation)
S3 ksapi; C:\Windows\system32\drivers\ksapi.sys [85352 2015-03-18] (Kingsoft Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2015-06-06] (Malwarebytes Corporation)
R3 NAVENG; C:\Program Files\Norton Security Suite\NortonData\21.1.0.18\Definitions\VirusDefs\20150605.017\NAVENG.SYS [95704 2015-06-01] (Symantec Corporation)
R3 NAVEX15; C:\Program Files\Norton Security Suite\NortonData\21.1.0.18\Definitions\VirusDefs\20150605.017\NAVEX15.SYS [1636696 2015-06-01] (Symantec Corporation)
R3 SRTSP; C:\Windows\System32\Drivers\N360\1507000.00B\SRTSP.SYS [664792 2014-08-25] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\N360\1507000.00B\SRTSPX.SYS [32984 2014-08-25] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\N360\1507000.00B\SYMDS.SYS [367704 2013-09-09] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\N360\1507000.00B\SYMEFA.SYS [936152 2014-08-25] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT.SYS [142936 2015-06-01] (Symantec Corporation)
R1 SymIM; C:\Windows\System32\DRIVERS\SymIMv.sys [63576 2013-09-09] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\N360\1507000.00B\Ironx86.SYS [209624 2014-08-06] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\N360\1507000.00B\SYMNETS.SYS [447704 2014-08-25] (Symantec Corporation)
S3 TesSafe; C:\Windows\system32\TesSafe.sys [503064 2014-01-30] (TENCENT)
S3 QMInject; \??\C:\Program Files\Tencent\QQPCMgr\7.6.8696.225\QMInject.sys [X]
S1 QMUdisk; \??\C:\Program Files\Tencent\QQPCMgr\10.8.16193.218\QMUdisk.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 TS888; \??\C:\Program Files\Tencent\QQPCMgr\10.8.16193.218\TS888.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-06-06 10:10 - 2015-06-06 10:13 - 00016363 _____ C:\Users\D\Desktop\FRST.txt
2015-06-06 10:07 - 2015-06-06 10:10 - 00000000 ____D C:\FRST
2015-06-06 10:07 - 2015-06-06 10:07 - 01147392 _____ (Farbar) C:\Users\D\Desktop\frst.exe
2015-06-06 09:39 - 2015-06-06 09:39 - 00135264 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\8542CA6D.sys
2015-06-06 09:38 - 2015-06-06 09:40 - 00000000 ____D C:\KVRT_Data
2015-06-06 09:35 - 2015-06-06 09:36 - 106025632 _____ (Kaspersky Lab ZAO) C:\Users\D\Downloads\KVRT.exe
2015-06-05 17:22 - 2015-06-06 09:05 - 00000000 ____D C:\Program Files\Mozilla Firefox
2015-06-03 03:07 - 2015-01-30 23:33 - 02744320 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2015-06-03 03:07 - 2015-01-30 23:33 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2015-06-03 03:07 - 2015-01-30 20:48 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2015-06-03 03:07 - 2014-12-11 13:47 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-06-02 10:08 - 2014-09-04 21:52 - 05703168 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2015-06-02 09:46 - 2012-08-23 10:44 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys
2015-06-02 09:46 - 2012-08-23 07:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll
2015-06-02 09:45 - 2013-10-01 20:42 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2015-06-02 09:45 - 2013-10-01 20:32 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2015-06-02 09:45 - 2013-10-01 20:30 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2015-06-02 09:45 - 2013-10-01 20:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2015-06-02 09:45 - 2013-10-01 20:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2015-06-02 09:45 - 2013-10-01 19:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2015-06-02 09:45 - 2013-10-01 19:45 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2015-06-02 09:45 - 2013-10-01 19:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2015-06-02 09:45 - 2013-10-01 18:53 - 00350208 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2015-06-02 09:45 - 2013-10-01 18:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2015-06-02 09:42 - 2015-03-13 23:04 - 01372160 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2015-06-02 09:42 - 2015-03-13 23:04 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\dwmapi.dll
2015-06-02 09:35 - 2015-04-10 23:07 - 00054656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\stream.sys
2015-06-02 09:31 - 2015-04-27 15:11 - 03989440 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-06-02 09:31 - 2015-04-27 15:11 - 03934144 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-06-02 09:31 - 2015-04-27 15:08 - 01307648 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-06-02 09:31 - 2015-04-27 15:05 - 00851456 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2015-06-02 09:31 - 2015-04-27 15:05 - 00635392 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2015-06-02 09:31 - 2015-04-27 15:04 - 00641536 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2015-06-02 09:31 - 2015-04-27 14:00 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2015-06-02 09:30 - 2015-04-27 15:11 - 00137664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-06-02 09:30 - 2015-04-27 15:11 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-06-02 09:30 - 2015-04-27 15:05 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-06-02 09:30 - 2015-04-27 15:05 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-06-02 09:30 - 2015-04-27 15:05 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-06-02 09:30 - 2015-04-27 15:05 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-06-02 09:30 - 2015-04-27 15:05 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-06-02 09:30 - 2015-04-27 15:05 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\sechost.dll
2015-06-02 09:30 - 2015-04-27 15:05 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-06-02 09:30 - 2015-04-27 15:05 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-06-02 09:30 - 2015-04-27 15:05 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-06-02 09:30 - 2015-04-27 15:05 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-06-02 09:30 - 2015-04-27 15:04 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-06-02 09:30 - 2015-04-27 15:04 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-06-02 09:30 - 2015-04-27 15:04 - 00364544 _____ (Microsoft Corporation) C:\Windows\system32\tracerpt.exe
2015-06-02 09:30 - 2015-04-27 15:04 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-06-02 09:30 - 2015-04-27 15:04 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\logman.exe
2015-06-02 09:30 - 2015-04-27 15:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-06-02 09:30 - 2015-04-27 15:04 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\typeperf.exe
2015-06-02 09:30 - 2015-04-27 15:04 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-06-02 09:30 - 2015-04-27 15:04 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\relog.exe
2015-06-02 09:30 - 2015-04-27 15:04 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-06-02 09:30 - 2015-04-27 15:04 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-06-02 09:30 - 2015-04-27 15:03 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-06-02 09:30 - 2015-04-27 15:03 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\diskperf.exe
2015-06-02 09:30 - 2015-04-27 15:01 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-06-02 09:30 - 2015-04-27 15:01 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-06-02 09:30 - 2015-04-27 14:59 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-06-02 09:30 - 2015-04-27 14:59 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-06-02 09:04 - 2015-06-02 09:04 - 00000000 __SHD C:\Users\D\AppData\Local\EmieUserList
2015-06-02 09:04 - 2015-06-02 09:04 - 00000000 __SHD C:\Users\D\AppData\Local\EmieSiteList
2015-06-02 09:04 - 2015-06-02 09:04 - 00000000 __SHD C:\Users\D\AppData\Local\EmieBrowserModeList
2015-06-01 23:34 - 2015-06-01 23:36 - 00000000 ____D C:\NPE
2015-06-01 19:04 - 2015-06-02 09:36 - 00000000 ____D C:\Users\D\AppData\Local\NPE
2015-06-01 17:21 - 2015-06-01 17:21 - 00000000 ____D C:\Program Files\GPLGS
2015-06-01 17:20 - 2015-06-06 09:22 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-06-01 17:20 - 2015-06-01 17:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CutePDF
2015-06-01 17:20 - 2015-06-01 17:20 - 00000000 ____D C:\Program Files\Acro Software
2015-06-01 17:20 - 2013-10-23 15:23 - 00089136 _____ C:\Windows\system32\cpwmon2k.dll
2015-06-01 17:19 - 2015-06-02 15:42 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2015-06-01 17:19 - 2015-06-01 17:19 - 02395080 _____ (Acro Software Inc. ) C:\Users\D\Downloads\CuteWriter.exe
2015-06-01 17:19 - 2015-06-01 17:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-06-01 17:19 - 2015-04-14 09:37 - 00092888 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-06-01 17:19 - 2015-04-14 09:37 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-06-01 17:19 - 2015-04-14 09:37 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-06-01 17:14 - 2015-06-01 17:15 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\D\Downloads\mbam-setup-2.1.6.1022.exe
2015-06-01 15:29 - 2015-06-01 15:40 - 00000000 ____D C:\Program Files\CDBurnerXP
2015-06-01 15:29 - 2015-06-01 15:29 - 00001805 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk
2015-06-01 15:29 - 2015-06-01 15:29 - 00000000 ____D C:\Users\D\AppData\Roaming\Canneverbe Limited
2015-06-01 15:29 - 2015-06-01 15:29 - 00000000 ____D C:\ProgramData\Canneverbe Limited
2015-06-01 15:21 - 2015-06-01 15:21 - 00000000 ____D C:\Users\D\AppData\Local\TeamViewer
2015-06-01 14:59 - 2015-06-04 03:13 - 00000000 ____D C:\Program Files\TeamViewer
2015-06-01 14:59 - 2015-06-01 14:59 - 00000961 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 10.lnk
2015-06-01 14:49 - 2015-06-01 14:49 - 05650240 _____ (Canneverbe Limited ) C:\Users\D\Downloads\cdbxp_setup_4.5.5.5642.exe
2015-06-01 14:43 - 2015-06-01 14:43 - 08006912 _____ (TeamViewer GmbH) C:\Users\D\Downloads\TeamViewer_Setup_en.exe
2015-06-01 14:36 - 2015-06-01 14:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2015-06-01 14:36 - 2015-06-01 14:36 - 00000000 ____D C:\Program Files\7-Zip
2015-06-01 14:35 - 2015-06-01 15:29 - 00065592 _____ C:\Users\D\AppData\Local\GDIPFONTCACHEV1.DAT
2015-06-01 14:35 - 2015-06-01 14:35 - 01110476 _____ C:\Users\D\Downloads\7z920.exe
2015-06-01 14:28 - 2015-06-01 14:28 - 00000000 ____D C:\ProgramData\Sun
2015-06-01 14:28 - 2015-06-01 14:28 - 00000000 ____D C:\Program Files\Common Files\Java
2015-06-01 14:28 - 2015-06-01 14:27 - 00096352 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2015-06-01 14:27 - 2015-06-01 14:30 - 00000000 ____D C:\ProgramData\Oracle
2015-06-01 14:27 - 2015-06-01 14:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-06-01 14:27 - 2015-06-01 14:27 - 00000000 ____D C:\Program Files\Java
2015-06-01 14:25 - 2015-06-01 14:30 - 00000000 ____D C:\Users\D\AppData\Local\Adobe
2015-06-01 14:24 - 2015-06-01 14:25 - 00561248 _____ (Oracle Corporation) C:\Users\D\Downloads\jxpiinstall.exe
2015-06-01 14:24 - 2015-06-01 14:24 - 00000000 ____D C:\Users\D\AppData\Roaming\Macromedia
2015-06-01 14:24 - 2015-06-01 14:24 - 00000000 ____D C:\Users\D\AppData\Local\Macromedia
2015-06-01 13:27 - 2015-06-01 13:28 - 00000000 ____D C:\d4d81666e9f4f42b527910515a
2015-06-01 13:14 - 2015-06-01 13:14 - 00000000 ____D C:\Users\D\AppData\Roaming\Mozilla
2015-06-01 13:14 - 2015-06-01 13:14 - 00000000 ____D C:\Users\D\AppData\Local\Mozilla
2015-06-01 13:14 - 2015-06-01 13:14 - 00000000 ____D C:\Users\D\AppData\Local\Apple
2015-06-01 13:03 - 2015-06-01 13:03 - 00000000 ____D C:\Users\D\AppData\Local\Google
2015-06-01 13:02 - 2015-06-01 13:03 - 00000000 ____D C:\Users\D
2015-06-01 13:02 - 2015-06-01 13:02 - 00001373 _____ C:\Users\D\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-06-01 13:02 - 2015-06-01 13:02 - 00000020 ___SH C:\Users\D\ntuser.ini
2015-06-01 13:02 - 2015-06-01 13:02 - 00000000 ____D C:\Users\D\AppData\Roaming\Adobe
2015-06-01 13:02 - 2015-06-01 13:02 - 00000000 ____D C:\Users\D\AppData\Local\VirtualStore
2015-06-01 13:02 - 2012-03-01 04:00 - 00000000 ____D C:\Users\D\AppData\Local\Microsoft Help
2015-06-01 13:02 - 2009-07-14 00:42 - 00000000 ___RD C:\Users\D\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-06-01 13:02 - 2009-07-14 00:37 - 00000000 ___RD C:\Users\D\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-06-01 12:54 - 2015-05-01 09:16 - 00102608 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-06-01 12:49 - 2015-06-01 12:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-06-01 12:49 - 2013-09-09 22:47 - 00063576 ____R (Symantec Corporation) C:\Windows\system32\Drivers\SymIMV.sys
2015-06-01 12:48 - 2015-06-01 12:48 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-06-01 12:37 - 2015-06-01 12:45 - 00000000 ____D C:\Windows\system32\MRT
2015-06-01 12:19 - 2015-03-22 23:06 - 00860160 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-06-01 12:19 - 2015-03-22 23:06 - 00630784 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-06-01 12:19 - 2015-03-22 23:06 - 00576000 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-06-01 12:19 - 2015-03-22 23:06 - 00331264 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-06-01 12:19 - 2015-03-22 23:06 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-06-01 12:19 - 2015-03-22 23:06 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-06-01 12:19 - 2015-03-22 23:06 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-06-01 12:19 - 2015-03-22 22:59 - 00896000 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-06-01 12:19 - 2015-03-04 00:16 - 00249784 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2015-06-01 12:19 - 2015-03-04 00:10 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll
2015-06-01 12:19 - 2015-01-28 23:02 - 02311168 _____ (Microsoft Corporation) C:\Windows\system32\wpdshext.dll
2015-06-01 12:15 - 2015-04-21 21:48 - 00342736 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-06-01 12:15 - 2015-04-21 12:25 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-06-01 12:15 - 2015-04-21 12:25 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-06-01 12:15 - 2015-04-21 12:24 - 19691008 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-06-01 12:15 - 2015-04-21 12:11 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-06-01 12:15 - 2015-04-21 12:10 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-06-01 12:15 - 2015-04-21 12:09 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-06-01 12:15 - 2015-04-21 12:08 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-06-01 12:15 - 2015-04-21 12:04 - 02278400 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-06-01 12:15 - 2015-04-21 12:03 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-06-01 12:15 - 2015-04-21 12:02 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-06-01 12:15 - 2015-04-21 12:00 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-06-01 12:15 - 2015-04-21 11:58 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-06-01 12:15 - 2015-04-21 11:58 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-06-01 12:15 - 2015-04-21 11:57 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-06-01 12:15 - 2015-04-21 11:51 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-06-01 12:15 - 2015-04-21 11:48 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-06-01 12:15 - 2015-04-21 11:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-06-01 12:15 - 2015-04-21 11:39 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-06-01 12:15 - 2015-04-21 11:38 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-06-01 12:15 - 2015-04-21 11:36 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-06-01 12:15 - 2015-04-21 11:26 - 00688640 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-06-01 12:15 - 2015-04-21 11:26 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-06-01 12:15 - 2015-04-21 11:25 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-06-01 12:15 - 2015-04-21 11:24 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-06-01 12:15 - 2015-04-21 11:17 - 12828672 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-06-01 12:15 - 2015-04-21 11:02 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-06-01 12:15 - 2015-04-21 10:58 - 01310208 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-06-01 12:15 - 2015-04-21 10:56 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-06-01 12:14 - 2015-06-01 15:15 - 00000000 ____D C:\Program Files\Common Files\Symantec Shared
2015-06-01 12:14 - 2015-06-01 12:14 - 00142936 _____ (Symantec Corporation) C:\Windows\system32\Drivers\SYMEVENT.SYS
2015-06-01 12:14 - 2015-06-01 12:14 - 00008194 _____ C:\Windows\system32\Drivers\SYMEVENT.CAT
2015-06-01 12:14 - 2015-04-21 12:11 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-06-01 12:14 - 2015-04-21 11:58 - 00664576 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-06-01 12:14 - 2015-04-21 11:31 - 04305920 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-06-01 12:13 - 2015-03-24 23:00 - 03088384 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-06-01 12:13 - 2015-03-24 23:00 - 02020864 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-06-01 12:13 - 2015-03-24 23:00 - 00566784 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-06-01 12:13 - 2015-03-24 23:00 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-06-01 12:13 - 2015-03-24 23:00 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-06-01 12:13 - 2015-03-24 23:00 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-06-01 12:13 - 2015-03-24 23:00 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-06-01 12:13 - 2015-03-24 23:00 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-06-01 12:13 - 2015-03-24 23:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-06-01 12:13 - 2015-03-24 23:00 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-06-01 12:13 - 2015-03-24 23:00 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-06-01 12:12 - 2015-06-02 09:34 - 00000000 ____D C:\Windows\system32\Drivers\N360
2015-06-01 12:12 - 2015-06-02 09:33 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Security Suite
2015-06-01 12:12 - 2015-06-01 12:12 - 00000000 ____D C:\Program Files\Norton Security Suite
2015-06-01 12:12 - 2015-05-04 21:12 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-06-01 12:12 - 2015-04-19 22:56 - 01250816 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-06-01 12:12 - 2015-04-19 22:56 - 00909312 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-06-01 12:12 - 2015-04-19 22:03 - 02382336 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-06-01 12:12 - 2015-04-17 22:56 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2015-06-01 12:12 - 2015-04-12 23:19 - 00259072 _____ (Microsoft Corporation) C:\Windows\system32\services.exe
2015-06-01 12:12 - 2015-04-07 23:14 - 00216064 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll
2015-06-01 12:12 - 2015-04-07 23:14 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\jnwmon.dll
2015-06-01 12:12 - 2015-03-05 00:06 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-06-01 12:12 - 2015-03-04 00:11 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\shimeng.dll
2015-06-01 12:12 - 2015-03-04 00:10 - 00295936 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll
2015-06-01 12:12 - 2015-03-04 00:10 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\aelupsvc.dll
2015-06-01 12:12 - 2015-03-04 00:10 - 00020992 _____ (Microsoft Corporation) C:\Windows\system32\sdbinst.exe
2015-06-01 12:12 - 2015-02-24 23:03 - 00514560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2015-06-01 12:11 - 2015-03-09 23:08 - 01237504 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-06-01 12:11 - 2015-03-09 23:05 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2015-06-01 12:11 - 2015-02-18 03:06 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2015-06-01 11:59 - 2015-06-06 09:05 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2015-06-01 11:59 - 2015-06-01 11:59 - 00001077 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-06-01 11:59 - 2015-06-01 11:59 - 00000000 ____D C:\ProgramData\Mozilla
2015-06-01 11:56 - 2015-06-01 23:30 - 00000000 ____D C:\ProgramData\Norton
2015-06-01 11:56 - 2015-06-01 11:56 - 00000000 ____D C:\Users\Public\Downloads\Norton

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-06-06 10:02 - 2009-07-14 00:34 - 00022208 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-06-06 10:02 - 2009-07-14 00:34 - 00022208 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-06-06 09:42 - 2012-02-12 22:31 - 00000886 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-06-06 09:34 - 2012-12-07 22:28 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-06-06 09:09 - 2012-02-11 15:41 - 01865127 _____ C:\Windows\WindowsUpdate.log
2015-06-06 09:06 - 2012-02-12 22:31 - 00000882 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-06-06 09:05 - 2015-03-15 21:42 - 00029896 _____ C:\Windows\PFRO.log
2015-06-06 09:05 - 2015-03-15 21:42 - 00001916 _____ C:\Windows\setupact.log
2015-06-06 09:05 - 2009-07-14 03:20 - 00000000 ____D C:\Windows\CSC
2015-06-06 09:05 - 2009-07-14 00:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-06-04 04:20 - 2009-07-13 22:37 - 00000000 ____D C:\Windows\rescache
2015-06-03 13:00 - 2012-02-11 14:11 - 00000000 ____D C:\Users\li
2015-06-03 12:58 - 2012-12-20 22:28 - 00000000 ____D C:\Windows\system32\appmgmt
2015-06-02 09:59 - 2012-02-11 14:13 - 00782510 _____ C:\Windows\system32\PerfStringBackup.INI
2015-06-02 09:55 - 2009-07-13 22:37 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-06-01 23:34 - 2015-03-15 21:42 - 00297016 _____ C:\Windows\system32\FNTCACHE.DAT
2015-06-01 23:09 - 2009-07-13 22:37 - 00000000 ____D C:\Windows\AppCompat
2015-06-01 15:05 - 2009-07-13 22:37 - 00000000 ____D C:\Windows\Microsoft.NET
2015-06-01 14:28 - 2012-12-07 22:28 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-06-01 14:27 - 2012-02-11 14:28 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-06-01 13:54 - 2015-01-01 00:58 - 00000000 ____D C:\Program Files\QuickTime
2015-06-01 13:39 - 2015-01-01 00:58 - 00000000 ____D C:\ProgramData\Apple Computer
2015-06-01 13:39 - 2015-01-01 00:57 - 00000000 ____D C:\Program Files\Common Files\Apple
2015-06-01 13:35 - 2012-12-20 23:20 - 00000000 ____D C:\Program Files\WinRAR
2015-06-01 13:24 - 2009-07-13 22:37 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2015-06-01 13:00 - 2012-02-11 15:00 - 00000000 ____D C:\Program Files\Tencent
2015-06-01 12:58 - 2014-12-11 14:10 - 00000000 ____D C:\Windows\system32\appraiser
2015-06-01 12:58 - 2014-05-23 20:15 - 00000000 ___SD C:\Windows\system32\CompatTel
2015-06-01 12:58 - 2009-07-14 03:20 - 00000000 ____D C:\Program Files\Windows Journal
2015-06-01 12:58 - 2009-07-13 22:37 - 00000000 ____D C:\Windows\system32\AdvancedInstallers
2015-06-01 12:54 - 2012-02-29 11:39 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-06-01 12:12 - 2012-02-11 16:34 - 00001945 _____ C:\Windows\epplauncher.mif
2015-06-01 12:03 - 2012-12-20 22:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVS4YOU
2015-06-01 12:03 - 2012-12-20 22:58 - 00000000 ____D C:\Program Files\Common Files\AVSMedia
2015-06-01 12:03 - 2012-12-20 22:57 - 00000000 ____D C:\Program Files\AVS4YOU
2015-06-01 11:48 - 2009-07-13 22:37 - 00000000 ____D C:\Windows\system32\NDF
2015-06-01 11:25 - 2014-12-25 13:31 - 00004398 _____ C:\unintall.log
2015-06-01 11:19 - 2015-02-11 04:28 - 00030392 _____ (Tencent) C:\Windows\system32\Drivers\TS888.sys

==================== Files in the root of some directories =======

2013-12-07 10:34 - 2013-12-28 00:21 - 0000058 _____ () C:\ProgramData\Update.ini

Some files in TEMP:
====================
C:\Users\D\AppData\Local\Temp\converter.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-06-03 03:03

==================== End of log ============================

Attached Files


Edited by trendsetter, 06 June 2015 - 09:24 AM.


BC AdBot (Login to Remove)

 


#2 nasdaq

nasdaq

  • Malware Response Team
  • 40,227 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:05:26 PM

Posted 08 June 2015 - 10:27 AM

Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

Open notepad (Start =>All Programs => Accessories => Notepad). Please copy the entire contents of the code box below.


start

CreateRestorePoint:
CloseProcesses:

HKLM\...\RunOnce: [{8F5135D2-2815-49B0-B035-FBDE35EE11EC}] => cmd.exe /C start /D "C:\Users\D\AppData\Local\Temp" /B {8F5135D2-2815-49B0-B035-FBDE35EE11EC}.cmd
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Winlogon: [Shell] C:\Windows\Explorer.exe [2616320 2011-02-25] (Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-19\...\Winlogon: [Shell] C:\Windows\Explorer.exe [2616320 2011-02-25] (Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Winlogon: [Shell] C:\Windows\Explorer.exe [2616320 2011-02-25] (Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-20\...\Winlogon: [Shell] C:\Windows\Explorer.exe [2616320 2011-02-25] (Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Winlogon: [Shell] C:\Windows\Explorer.exe [2616320 2011-02-25] (Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-21-4231112004-1192876706-404484655-1003\...\Winlogon: [Shell] C:\Windows\Explorer.exe [2616320 2011-02-25] (Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-21-4231112004-1192876706-404484655-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Winlogon: [Shell] C:\Windows\Explorer.exe [2616320 2011-02-25] (Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-18\...\Winlogon: [Shell] C:\Windows\Explorer.exe [2616320 2011-02-25] (Microsoft Corporation) <==== ATTENTION
BHO: QQMiniDL Helper Class -> {C9C7334B-5657-41e1-8F79-F6AACECA05F4} -> C:\Program Files\Common Files\Tencent\QQMiniDL\60\Browser\QQIEHelper01.dll No File
FF Plugin: @kingsfot.com/npkws -> C:\Program Files\Kingsoft\kingsoft antivirus\npkws.dll No File
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @qq.com/npqscall,version=1.0.0 -> %commonprogramfiles%\tencent\NPQSCALL\npqscall.dll No File
FF Plugin: @qq.com/QzoneMusic -> C:\Program Files\Tencent\QQMusic\1144.2015.2.5.9.54.2\QzoneMusic\npQzoneMusic.dll No File
FF SearchPlugin: C:\Users\D\AppData\Roaming\Mozilla\Firefox\Profiles\zymk0v7e.default\searchplugins\safesearch.xml [2015-06-06]
CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - https://clients2.google.com/service/update2/crx
U0 8542CA6D; C:\Windows\System32\drivers\8542CA6D.sys [135264 2015-06-06] (Kaspersky Lab ZAO)
S3 QMInject; \??\C:\Program Files\Tencent\QQPCMgr\7.6.8696.225\QMInject.sys [X]
S1 QMUdisk; \??\C:\Program Files\Tencent\QQPCMgr\10.8.16193.218\QMUdisk.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 TS888; \??\C:\Program Files\Tencent\QQPCMgr\10.8.16193.218\TS888.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
C:\Windows\System32\drivers\8542CA6D.sys
HKU\.DEFAULT\Software\Classes\.exe: exefile =>  <===== ATTENTION!
HKU\S-1-5-21-4231112004-1192876706-404484655-1003\Software\Classes\.exe: exefile =>  <===== ATTENTION!

End
Save the files as fixlist.txt in the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the Farbar log you have submitted.

Run FRST and click Fix only once and wait.

Restart the computer normally to reset the registry.

The tool will create a log (Fixlog.txt) please post it to your reply.
===

Please download AdwCleaner by Xplode onto your Desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click the Scan button and wait for the process to complete.
  • Click the Report button and the report will open in Notepad.
IMPORTANT
  • If you click the Clean button all items listed in the report will be removed.
If you find some false positive items or programs that you wish to keep, Close the AdwCleaner windows.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click the Scan button and wait for the process to complete.
  • Check off the element(s) you wish to keep.
  • Click on the Clean button follow the prompts.
  • A log file will automatically open after the scan has finished.
  • Please post the content of that log file with your next answer.
  • You can find the log file at C:\AdwCleaner[Sn].txt (n is a number).
===

How is the computer running now?

#3 trendsetter

trendsetter
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:05:26 PM

Posted 12 June 2015 - 05:40 PM

Fix result of Farbar Recovery Scan Tool (x86) Version: 08-06-2015
Ran by D at 2015-06-12 18:15:42 Run:1
Running from C:\Users\D\Desktop
Loaded Profiles: D (Available Profiles: D)
Boot Mode: Normal

==============================================

fixlist content:
*****************
start

CreateRestorePoint:
CloseProcesses:

HKLM\...\RunOnce: [{8F5135D2-2815-49B0-B035-FBDE35EE11EC}] => cmd.exe /C start /D "C:\Users\D\AppData\Local\Temp" /B {8F5135D2-2815-49B0-B035-FBDE35EE11EC}.cmd
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Winlogon: [Shell] C:\Windows\Explorer.exe [2616320 2011-02-25] (Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-19\...\Winlogon: [Shell] C:\Windows\Explorer.exe [2616320 2011-02-25] (Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Winlogon: [Shell] C:\Windows\Explorer.exe [2616320 2011-02-25] (Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-20\...\Winlogon: [Shell] C:\Windows\Explorer.exe [2616320 2011-02-25] (Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Winlogon: [Shell] C:\Windows\Explorer.exe [2616320 2011-02-25] (Microsoft Corporation)
<==== ATTENTION
HKU\S-1-5-21-4231112004-1192876706-404484655-1003\...\Winlogon: [Shell] C:\Windows\Explorer.exe [2616320 2011-02-25] (Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-21-4231112004-1192876706-404484655-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Winlogon: [Shell] C:\Windows\Explorer.exe [2616320 2011-02-25] (Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-18\...\Winlogon: [Shell] C:\Windows\Explorer.exe [2616320 2011-02-25] (Microsoft Corporation) <==== ATTENTION
BHO: QQMiniDL Helper Class -> {C9C7334B-5657-41e1-8F79-F6AACECA05F4} -> C:\Program Files\Common Files\Tencent\QQMiniDL\60\Browser\QQIEHelper01.dll No File
FF Plugin: @kingsfot.com/npkws -> C:\Program Files\Kingsoft\kingsoft antivirus\npkws.dll No File
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @qq.com/npqscall,version=1.0.0 -> %commonprogramfiles%\tencent\NPQSCALL\npqscall.dll No File
FF Plugin: @qq.com/QzoneMusic -> C:\Program
Files\Tencent\QQMusic\1144.2015.2.5.9.54.2\QzoneMusic\npQzoneMusic.dll No File
FF SearchPlugin: C:\Users\D\AppData\Roaming\Mozilla\Firefox\Profiles\zymk0v7e.default\searchplugins\safesearch.xml [2015-06-06]
CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - https://clients2.google.com/service/update2/crx
U0 8542CA6D; C:\Windows\System32\drivers\8542CA6D.sys [135264 2015-06-06] (Kaspersky Lab ZAO)
S3 QMInject; \??\C:\Program Files\Tencent\QQPCMgr\7.6.8696.225\QMInject.sys [X]
S1 QMUdisk; \??\C:\Program Files\Tencent\QQPCMgr\10.8.16193.218\QMUdisk.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 TS888; \??\C:\Program Files\Tencent\QQPCMgr\10.8.16193.218\TS888.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
C:\Windows\System32\drivers\8542CA6D.sys
HKU\.DEFAULT\Software\Classes\.exe: exefile =>  <=====
ATTENTION!
HKU\S-1-5-21-4231112004-1192876706-404484655-1003\Software\Classes\.exe: exefile =>  <===== ATTENTION!

End
*****************

Restore point was successfully created.
Processes closed successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\\{8F5135D2-2815-49B0-B035-FBDE35EE11EC} => value not found.
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell => value not found.
HKU\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell => value could not remove.
HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell => value not found.
HKU\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell => value could not remove.
HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell => value not found.
<==== ATTENTION => Error: No automatic fix found for this entry.
HKU\S-1-5-21-4231112004-1192876706-404484655-1003\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell => value could not remove.
HKU\S-1-5-21-4231112004-1192876706-404484655-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell => value not found.
HKU\S-1-5-18\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell => value could not remove.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C9C7334B-5657-41e1-8F79-F6AACECA05F4} => key could not remove.
HKCR\CLSID\{C9C7334B-5657-41e1-8F79-F6AACECA05F4} => key not found.
"HKLM\Software\MozillaPlugins\@kingsfot.com/npkws" => key removed successfully.
"HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE" => key removed successfully.
"HKLM\Software\MozillaPlugins\@qq.com/npqscall,version=1.0.0" => key removed successfully.
"HKLM\Software\MozillaPlugins\@qq.com/QzoneMusic" => key removed successfully.
FF Plugin: @qq.com/QzoneMusic -> C:\Program not found.
Files\Tencent\QQMusic\1144.2015.2.5.9.54.2\QzoneMusic\npQzoneMusic.dll No File => Error: No automatic fix found for this entry.
C:\Users\D\AppData\Roaming\Mozilla\Firefox\Profiles\zymk0v7e.default\searchplugins\safesearch.xml => moved successfully.
"HKLM\SOFTWARE\Google\Chrome\Extensions\iikflkcanblccfahdhdonehdalibjnif" => key removed successfully.
8542CA6D => Service not found.
QMInject => Service could not remove
QMUdisk => Service could not remove
Synth3dVsc => Service could not remove
TS888 => Service could not remove
tsusbhub => Service could not remove
VGPU => Service could not remove
"C:\Windows\System32\drivers\8542CA6D.sys" => File/Folder not found.
"HKU\.DEFAULT\Software\Classes\.exe" => key removed successfully.
ATTENTION! => Error: No automatic fix found for this entry.
"HKU\S-1-5-21-4231112004-1192876706-404484655-1003\Software\Classes\.exe" => key removed successfully.


The system needed a reboot.

==== End of Fixlog 18:18:56 ====



#4 trendsetter

trendsetter
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:05:26 PM

Posted 12 June 2015 - 05:45 PM

# AdwCleaner v4.206 - Logfile created 12/06/2015 at 18:38:45
# Updated 01/06/2015 by Xplode
# Database : 2015-06-09.1 [Server]
# Operating system : Windows 7 Enterprise Service Pack 1 (x86)
# Username : D - LI-PC
# Running from : C:\Users\D\Downloads\adwcleaner_4.206.exe
# Option : Scan

***** [ Services ] *****

Service Found : TS888
Service Found : QMUdisk

***** [ Files / Folders ] *****

Folder Found : C:\Program Files\Common Files\tencent
Folder Found : C:\Program Files\KingSoft
Folder Found : C:\Program Files\tencent
Folder Found : C:\ProgramData\KingSoft
Folder Found : C:\ProgramData\tencent
Folder Found : C:\ProgramData\TXQMPC
Folder Found : C:\Users\D\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg
Folder Found : C:\Windows\system32\config\systemprofile\AppData\Roaming\tencent
Folder Found : C:\Windows\system32\tencent

***** [ Scheduled tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Found : HKLM\SOFTWARE\Classes\AppID\{6517DD27-EA6F-4947-9DEA-F9C487BB1020}
Key Found : HKLM\SOFTWARE\Classes\AppID\DownloadProxy.EXE
Key Found : HKLM\SOFTWARE\Classes\CLSID\{70DE12EA-79F4-46BC-9812-86DB50A2FD64}
Key Found : HKLM\SOFTWARE\Classes\Interface\{6B3732AA-F6D4-4F16-9E22-49EDC52C9514}
Key Found : HKLM\SOFTWARE\Classes\Interface\{E7270EC6-0113-4A78-B610-E501D0A9E48E}
Key Found : HKLM\SOFTWARE\CLASSES\METNSD
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{6517DD27-EA6F-4947-9DEA-F9C487BB1020}
Key Found : HKLM\SOFTWARE\MozillaPlugins\@qq.com/TXSSO
Key Found : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\QQPCRTP
Key Found : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\QQPCRTP
Value Found : HKLM\SYSTEM\CurrentControlSet\Services\sharedaccess\Parameters\FirewallPolicy\FirewallRules [TCP Query User{16F4B5C3-94AD-4496-9870-FCE4F7C87A21}C:\program files\common files\tencent\qqdownload\121\tencentdl.exe]
Value Found : HKLM\SYSTEM\CurrentControlSet\Services\sharedaccess\Parameters\FirewallPolicy\FirewallRules [TCP Query User{A79542F3-FA62-4B46-8511-0E10BBE25FD3}C:\program files\tencent\qqlive\qqlive.exe]
Value Found : HKLM\SYSTEM\CurrentControlSet\Services\sharedaccess\Parameters\FirewallPolicy\FirewallRules [UDP Query User{BD701A10-79E5-45C3-A4FB-B98B3EA7CD2B}C:\program files\tencent\qqlive\qqlive.exe]
Value Found : HKLM\SYSTEM\CurrentControlSet\Services\sharedaccess\Parameters\FirewallPolicy\FirewallRules [UDP Query User{FC0A2EDE-DC22-462D-9F33-13F7CFFCC623}C:\program files\common files\tencent\qqdownload\121\tencentdl.exe]

***** [ Web browsers ] *****

-\\ Internet Explorer v11.0.9600.17801


-\\ Mozilla Firefox v38.0.5 (x86 en-US)


-\\ Google Chrome v43.0.2357.124


*************************

AdwCleaner[R0].txt - [2777 bytes] - [12/06/2015 18:38:45]

########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [2836 bytes] ##########
 



#5 nasdaq

nasdaq

  • Malware Response Team
  • 40,227 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:05:26 PM

Posted 13 June 2015 - 08:11 AM

Looking good.

How is the computer running now?

#6 trendsetter

trendsetter
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:05:26 PM

Posted 13 June 2015 - 10:25 AM

It was running decent before, it was just full of viruses/malware. What is safe to clean from the AdwCleaner results? Anything else I should run?

Thanks for your help! :thumbsup:


Edited by trendsetter, 13 June 2015 - 10:25 AM.


#7 nasdaq

nasdaq

  • Malware Response Team
  • 40,227 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:05:26 PM

Posted 13 June 2015 - 12:53 PM

If all is well.

To learn more about how to protect yourself while on the internet read this little guide best security practices keep safe.
http://www.bleepingcomputer.com/forums/t/407147/answers-to-common-security-questions-best-practices/
===

#8 nasdaq

nasdaq

  • Malware Response Team
  • 40,227 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:05:26 PM

Posted 19 June 2015 - 08:52 AM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users