Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Think I am infected


  • Please log in to reply
17 replies to this topic

#1 vbbikerbums

vbbikerbums

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:57 PM

Posted 28 November 2015 - 09:27 PM

I have hit a wall.
 
I recently noticied I can no longer install new files, can't run things as admin, or access any services. I can do everything in safemode but as soon as I reboot into normal mode I am completly stuck.
 
I have run SFC /scannow, malware bytes, registry repair, tdsskiller, advanced systemcare, and despite finding numerous things wrong and correcting them once I go back to normal mode I am again stuck and the propblem is not going away. I am at a loss on how to fix this. I am ready to find the furthers back restore point and that will be my last ditch effort. Any help is greatly appreciated!
 
I'm using Windows 7 Ultimate

Edit: Moved topic from Virus, Trojan, Spyware, and Malware Removal Logs to the more appropriate forum. ~ Animal

BC AdBot (Login to Remove)

 


#2 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,679 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:10:57 PM

Posted 28 November 2015 - 11:05 PM

Welcome aboard p22002758.gif

 

p22002970.gif Download Security Check from here or here and save it to your Desktop.

  • Double-click SecurityCheck.exe
  • Follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.


NOTE 1. If one of your security applications (e.g., third-party firewall) requests permission to allow DIG.EXE access the Internet, allow it to do so.
NOTE 2. SecurityCheck may produce some false warning(s), so leave the results reading to me.
NOTE 3. If you receive UNSUPPORTED OPERATING SYSTEM! ABORTED! message restart computer and Security Check should run

p22002970.gif Please download Farbar Service Scanner (FSS) and run it on the computer with the issue.
  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center/Action Center
    • Windows Update
    • Windows Defender
    • Other Services
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.


p22002970.gif Please download MiniToolBox and run it.

Checkmark following boxes:
  • Report IE Proxy Settings
  • Report FF Proxy Settings
  • List content of Hosts
  • List IP configuration
  • List Winsock Entries
  • List last 10 Event Viewer log
  • List Installed Programs
  • List Devices (do NOT change any settings here)
  • List Users, Partitions and Memory size
  • List Restore Points

Click Go and post the result.

p22002970.gif Please download Malwarebytes Anti-Malware (MBAM) to your desktop.
NOTE. If you already have MBAM 2.0 installed scroll down.

  • Double-click mb3-setup-1878.1878-3.5.1.2522.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to the following:

    • Launch Malwarebytes Anti-Malware
    • A 14 day trial of the Premium features is pre-selected. You may deselect this if you wish, and it will not diminish the scanning and removal capabilities of the program.

  • Click Finish.
  • On the Dashboard, click the 'Update Now >>' link
  • After the update completes, click the 'Scan Now >>' button.
  • Or, on the Dashboard, click the Scan Now >> button.
  • If an update is available, click the Update Now button.
  • A Threat Scan will begin.
  • When the scan is complete, if there have been detections, click Apply Actions to allow MBAM to clean what was detected.
  • In most cases, a restart will be required.
  • Wait for the prompt to restart the computer to appear, then click on Yes.



If you already have MBAM 2.0 installed:

  • On the Dashboard, click the 'Update Now >>' link
  • After the update completes, click the 'Scan Now >>' button.
  • Or, on the Dashboard, click the Scan Now >> button.
  • If an update is available, click the Update Now button.
  • A Threat Scan will begin.
  • When the scan is complete, if there have been detections, click Apply Actions to allow MBAM to clean what was detected.
  • In most cases, a restart will be required.
  • Wait for the prompt to restart the computer to appear, then click on Yes.


How to get logs:
(Export log to save as txt)


  • After the restart once you are back at your desktop, open MBAM once more.
  • Click on the History tab > Application Logs.
  • Double click on the Scan Log which shows the Date and time of the scan just performed.
  • Click 'Export'.
  • Click 'Text file (*.txt)'
  • In the Save File dialog box which appears, click on Desktop.
  • In the File name: box type a name for your scan log.
  • A message box named 'File Saved' should appear stating "Your file has been successfully exported".
  • Click Ok
  • Attach that saved log to your next reply.



(Copy to clipboard for pasting into forum replies or tickets)

  • After the restart once you are back at your desktop, open MBAM once more.
  • Click on the History tab > Application Logs.
  • Double click on the Scan Log which shows the Date and time of the scan just performed.
  • Click 'Copy to Clipboard'
  • Paste the contents of the clipboard into your reply.


p22002970.gifDownload 51a5f31352b88-icon_MBAR.pngMalwarebytes Anti-Rootkit (MBAR) to your desktop.
  • Warning! Malwarebytes Anti-Rootkit needs to be run from an account with administrator rights.
  • Double click on downloaded file. OK self extracting prompt.
  • MBAR will start. Click "Next" to continue.
  • Click in the following screen "Update" to obtain the latest malware definitions.
  • Once the update is complete select "Next" and click "Scan".
  • When the scan is finished and no malware has been found select "Exit".
  • If malware was detected, make sure to check all the items and click "Cleanup". Reboot your computer.
  • Open the MBAR folder located on your Desktop and paste the content of the following files in your next reply:
  • "mbar-log-{date} (xx-xx-xx).txt"
  • "system-log.txt"


NOTE. If you see This version requires you to completely exit the Anti Malware application message right click on the Malwarebytes Anti-Malware icon in the system tray and click on Exit.

p22002970.gif Please download Rkill (courtesy of BleepingComputer.com) to your desktop.
There are 2 different versions. If one of them won't run then download and try to run the other one.
You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

rKill.exe: http://www.bleepingcomputer.com/download/rkill/dl/10/
iExplore.exe (renamed rKill.exe): http://www.bleepingcomputer.com/download/rkill/dl/11/

  • Double-click on the Rkill desktop icon to run the tool.
  • If using Windows Vista, 7 or 8 right-click on it and choose Run As Administrator.
  • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
  • If not, delete the file, then download and use the one provided in Link 2.
  • Do not reboot until instructed.
  • If the tool does not run from any of the links provided, please let me know.


If normal mode still doesn't work, run the tool from safe mode.

When the scan is done Notepad will open with rKill log.
Post it in your next reply.

NOTE. rKill.txt log will also be present on your desktop.

NOTE Do NOT wrap your logs in "quote" or "code" brackets.
Do NOT use spoilers.
Do NOT edit your reply to post additional logs. Create new reply. I'll not get any email notifications about edits so I won't know you posted something new.


My Website

p4433470.gif

My help doesn't cost a penny, but if you'd like to consider a donation, click p22001735.gif


 


#3 vbbikerbums

vbbikerbums
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:57 PM

Posted 29 November 2015 - 07:04 AM

I can only install and run these programs while in safe mode

 

Rkill Log

 

 

Rkill 2.8.2 by Lawrence Abrams (Grinler)
Copyright 2008-2015 BleepingComputer.com
More Information about Rkill can be found at this link:
 
Program started at: 11/29/2015 06:03:43 PM in x64 mode. (Safe Mode)
Windows Version: Windows 7 Ultimate Service Pack 1
 
Checking for Windows services to stop:
 
 * No malware services found to stop.
 
Checking for processes to terminate:
 
 * No malware processes found to kill.
 
Checking Registry for malware related settings:
 
 * No issues found in the Registry.
 
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
 
Performing miscellaneous checks:
 
 * No issues found.
 
Checking Windows Service Integrity: 
 
 * COM+ Event System (EventSystem) is not Running.
   Startup Type set to: Automatic
 
 * Security Center (wscsvc) is not Running.
   Startup Type set to: Automatic (Delayed Start)
 
 * Windows Update (wuauserv) is not Running.
   Startup Type set to: Automatic (Delayed Start)
 
 * Appinfo [Missing Service]
 
Searching for Missing Digital Signatures: 
 
 * No issues found.
 
Checking HOSTS File: 
 
 * HOSTS file entries found: 
 
  127.0.0.1       localhost
 
Program finished at: 11/29/2015 06:09:33 PM
Execution time: 0 hours(s), 5 minute(s), and 49 seconds(s)
 
Security Check Log
 Results of screen317's Security Check version 1.013 --- 11/28/15  
 Windows 7 Service Pack 1 x64 (UAC is enabled)  
 Internet Explorer 11  
``````````````Antivirus/Firewall Check:`````````````` 
 Windows Security Center service is not running! This report may not be accurate! 
 Windows Firewall Enabled!  
McAfee VirusScan Enterprise   
 Antivirus up to date!  (On Access scanning disabled!) 
`````````Anti-malware/Other Utilities Check:````````` 
 Java version 32-bit out of Date! 
 Adobe Flash Player 19.0.0.245  
 Mozilla Firefox 41.0.2 Firefox out of Date!  
````````Process Check: objlist.exe by Laurent````````  
 McAfee VirusScan Enterprise ScnCfg32.Exe  
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive C:  
````````````````````End of Log`````````````````````` 
 
 

FARBAR Log

Farbar Service Scanner Version: 10-06-2014

Ran by Brad (administrator) on 29-11-2015 at 18:15:02

Running from "C:\Users\Brad\Downloads"

Microsoft Windows 7 Ultimate  Service Pack 1 (X64)

Boot Mode: Network

****************************************************************

 

Internet Services:

============

 

Connection Status:

==============

Localhost is accessible.

LAN connected.

Google IP is accessible.

Google.com is accessible.

Yahoo.com is accessible.

 

 

Windows Firewall:

=============

 

Firewall Disabled Policy: 

==================

 

 

System Restore:

============

SDRSVC Service is not running. Checking service configuration:

The start type of SDRSVC service is OK.

The ImagePath of SDRSVC service is OK.

The ServiceDll of SDRSVC service is OK.

 

VSS Service is not running. Checking service configuration:

The start type of VSS service is OK.

The ImagePath of VSS service is OK.

 

 

System Restore Disabled Policy: 

========================

 

 

Action Center:

============

 

wscsvc Service is not running. Checking service configuration:

The start type of wscsvc service is OK.

The ImagePath of wscsvc service is OK.

The ServiceDll of wscsvc service is OK.

 

 

Windows Update:

============

wuauserv Service is not running. Checking service configuration:

The start type of wuauserv service is OK.

The ImagePath of wuauserv service is OK.

The ServiceDll of wuauserv service is OK.

 

BITS Service is not running. Checking service configuration:

The start type of BITS service is set to Demand. The default start type is Auto.

The ImagePath of BITS service is OK.

The ServiceDll of BITS service is OK.

 

EventSystem Service is not running. Checking service configuration:

The start type of EventSystem service is OK.

The ImagePath of EventSystem service is OK.

The ServiceDll of EventSystem service is OK.

 

 

Windows Autoupdate Disabled Policy: 

============================

 

 

Windows Defender:

==============

 

Other Services:

==============

 

 

File Check:

========

C:\Windows\System32\nsisvc.dll => File is digitally signed

C:\Windows\System32\drivers\nsiproxy.sys => File is digitally signed

C:\Windows\System32\dhcpcore.dll => File is digitally signed

C:\Windows\System32\drivers\afd.sys => File is digitally signed

C:\Windows\System32\drivers\tdx.sys => File is digitally signed

C:\Windows\System32\Drivers\tcpip.sys => File is digitally signed

C:\Windows\System32\dnsrslvr.dll => File is digitally signed

C:\Windows\System32\mpssvc.dll => File is digitally signed

C:\Windows\System32\bfe.dll => File is digitally signed

C:\Windows\System32\drivers\mpsdrv.sys => File is digitally signed

C:\Windows\System32\SDRSVC.dll => File is digitally signed

C:\Windows\System32\vssvc.exe => File is digitally signed

C:\Windows\System32\wscsvc.dll => File is digitally signed

C:\Windows\System32\wbem\WMIsvc.dll => File is digitally signed

C:\Windows\System32\wuaueng.dll => File is digitally signed

C:\Windows\System32\qmgr.dll => File is digitally signed

C:\Windows\System32\es.dll => File is digitally signed

C:\Windows\System32\cryptsvc.dll => File is digitally signed

C:\Program Files\Windows Defender\MpSvc.dll => File is digitally signed

C:\Windows\System32\ipnathlp.dll => File is digitally signed

C:\Windows\System32\iphlpsvc.dll => File is digitally signed

C:\Windows\System32\svchost.exe => File is digitally signed

C:\Windows\System32\rpcss.dll => File is digitally signed

 

 

**** End of log ****



#4 vbbikerbums

vbbikerbums
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:57 PM

Posted 29 November 2015 - 07:06 AM

MINI TOOLBOX LOG

MiniToolBox by Farbar  Version: 02-11-2015

Ran by Brad (administrator) on 29-11-2015 at 18:21:26

Running from "C:\Users\Brad\Downloads"

Microsoft Windows 7 Ultimate  Service Pack 1 (X64)

Model: MS-7593 Manufacturer: MSI

Boot Mode: Network

***************************************************************************

 

========================= IE Proxy Settings: ============================== 

 

Proxy is not enabled.

No Proxy Server is set.

 

========================= FF Proxy Settings: ============================== 

 

========================= IP Configuration: ================================

 

Realtek PCIe GBE Family Controller = Local Area Connection 2 (Connected)

 

 

# ----------------------------------

# IPv4 Configuration

# ----------------------------------

pushd interface ipv4

 

reset

set global defaultcurhoplimit=64 icmpredirects=enabled

 

 

popd

# End of IPv4 configuration

 

 

 

Windows IP Configuration

 

   Host Name . . . . . . . . . . . . : Brad-PC

   Primary Dns Suffix  . . . . . . . : 

   Node Type . . . . . . . . . . . . : Hybrid

   IP Routing Enabled. . . . . . . . : No

   WINS Proxy Enabled. . . . . . . . : No

   DNS Suffix Search List. . . . . . : kornet

 

Ethernet adapter Local Area Connection 2:

 

   Connection-specific DNS Suffix  . : kornet

   Description . . . . . . . . . . . : Realtek PCIe GBE Family Controller

   Physical Address. . . . . . . . . : 40-61-86-F2-C6-4E

   DHCP Enabled. . . . . . . . . . . : Yes

   Autoconfiguration Enabled . . . . : Yes

   IPv6 Address. . . . . . . . . . . : 2002:de67:805a:0:4c83:610f:5734:94b7(Preferred) 

   Temporary IPv6 Address. . . . . . : 2002:de67:805a:0:b00e:98cb:8e5e:e622(Preferred) 

   Link-local IPv6 Address . . . . . : fe80::4c83:610f:5734:94b7%12(Preferred) 

   IPv4 Address. . . . . . . . . . . : 192.168.1.145(Preferred) 

   Subnet Mask . . . . . . . . . . . : 255.255.255.0

   Lease Obtained. . . . . . . . . . : Sunday, November 29, 2015 4:31:22 PM

   Lease Expires . . . . . . . . . . : Monday, November 30, 2015 4:31:22 PM

   Default Gateway . . . . . . . . . : fe80::c2c1:c0ff:fe04:4241%12

                                       192.168.1.1

   DHCP Server . . . . . . . . . . . : 192.168.1.1

   DHCPv6 IAID . . . . . . . . . . . : 306209158

   DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-13-2E-B1-3C-00-24-8C-FB-A5-27

   DNS Servers . . . . . . . . . . . : 168.126.63.1

                                       168.126.63.2

                                       192.168.1.1

   NetBIOS over Tcpip. . . . . . . . : Enabled

Server:  kns.kornet.net

Address:  168.126.63.1

 

Name:    kdn.ktguide.com

Address:  218.38.137.8

Aliases:  google.com.kornet

 

 

Pinging google.com [59.18.34.153] with 32 bytes of data:

Reply from 59.18.34.153: bytes=32 time=5ms TTL=56

Reply from 59.18.34.153: bytes=32 time=4ms TTL=56

 

Ping statistics for 59.18.34.153:

    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Approximate round trip times in milli-seconds:

    Minimum = 4ms, Maximum = 5ms, Average = 4ms

Server:  kns.kornet.net

Address:  168.126.63.1

 

Name:    kdn.ktguide.com

Address:  218.38.137.8

Aliases:  yahoo.com.kornet

 

 

Pinging yahoo.com [98.139.183.24] with 32 bytes of data:

Reply from 98.139.183.24: bytes=32 time=194ms TTL=46

Reply from 98.139.183.24: bytes=32 time=195ms TTL=46

 

Ping statistics for 98.139.183.24:

    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Approximate round trip times in milli-seconds:

    Minimum = 194ms, Maximum = 195ms, Average = 194ms

 

Pinging 127.0.0.1 with 32 bytes of data:

Reply from 127.0.0.1: bytes=32 time<1ms TTL=64

Reply from 127.0.0.1: bytes=32 time<1ms TTL=64

 

Ping statistics for 127.0.0.1:

    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Approximate round trip times in milli-seconds:

    Minimum = 0ms, Maximum = 0ms, Average = 0ms

===========================================================================

Interface List

 12...40 61 86 f2 c6 4e ......Realtek PCIe GBE Family Controller

  1...........................Software Loopback Interface 1

===========================================================================

 

IPv4 Route Table

===========================================================================

Active Routes:

Network Destination        Netmask          Gateway       Interface  Metric

          0.0.0.0          0.0.0.0      192.168.1.1    192.168.1.145     10

        127.0.0.0        255.0.0.0         On-link         127.0.0.1    306

        127.0.0.1  255.255.255.255         On-link         127.0.0.1    306

  127.255.255.255  255.255.255.255         On-link         127.0.0.1    306

      192.168.1.0    255.255.255.0         On-link     192.168.1.145    266

    192.168.1.145  255.255.255.255         On-link     192.168.1.145    266

    192.168.1.255  255.255.255.255         On-link     192.168.1.145    266

        224.0.0.0        240.0.0.0         On-link         127.0.0.1    306

        224.0.0.0        240.0.0.0         On-link     192.168.1.145    266

  255.255.255.255  255.255.255.255         On-link         127.0.0.1    306

  255.255.255.255  255.255.255.255         On-link     192.168.1.145    266

===========================================================================

Persistent Routes:

  None

 

IPv6 Route Table

===========================================================================

Active Routes:

 If Metric Network Destination      Gateway

 12   4106 ::/0                     fe80::c2c1:c0ff:fe04:4241

  1    306 ::1/128                  On-link

 12     18 2002:de67:805a::/64      On-link

 12    266 2002:de67:805a:0:4c83:610f:5734:94b7/128

                                    On-link

 12    266 2002:de67:805a:0:b00e:98cb:8e5e:e622/128

                                    On-link

 12    266 fe80::/64                On-link

 12    266 fe80::4c83:610f:5734:94b7/128

                                    On-link

  1    306 ff00::/8                 On-link

 12    266 ff00::/8                 On-link

===========================================================================

Persistent Routes:

  None

========================= Winsock entries =====================================

 

Catalog5 01 C:\Windows\SysWOW64\NLAapi.dll [52224] (Microsoft Corporation)

Catalog5 02 C:\Windows\SysWOW64\napinsp.dll [52224] (Microsoft Corporation)

Catalog5 03 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)

Catalog5 04 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)

Catalog5 05 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [134528] (Microsoft Corporation)

Catalog5 06 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [134528] (Microsoft Corporation)

Catalog5 07 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)

Catalog5 08 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)

Catalog5 09 C:\Windows\SysWOW64\winrnr.dll [20992] (Microsoft Corporation)

Catalog9 01 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)

Catalog9 02 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)

Catalog9 03 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)

Catalog9 04 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)

Catalog9 05 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)

Catalog9 06 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)

Catalog9 07 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)

Catalog9 08 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)

Catalog9 09 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)

Catalog9 10 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)

x64-Catalog5 01 C:\Windows\System32\NLAapi.dll [70656] (Microsoft Corporation)

x64-Catalog5 02 C:\Windows\System32\napinsp.dll [68096] (Microsoft Corporation)

x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)

x64-Catalog5 04 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)

x64-Catalog5 05 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [168304] (Microsoft Corporation)

x64-Catalog5 06 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [168304] (Microsoft Corporation)

x64-Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [132968] (Apple Inc.)

x64-Catalog5 08 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)

x64-Catalog5 09 C:\Windows\System32\winrnr.dll [28672] (Microsoft Corporation)

x64-Catalog9 01 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)

x64-Catalog9 02 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)

x64-Catalog9 03 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)

x64-Catalog9 04 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)

x64-Catalog9 05 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)

x64-Catalog9 06 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)

x64-Catalog9 07 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)

x64-Catalog9 08 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)

x64-Catalog9 09 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)

x64-Catalog9 10 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)

 

========================= Event log errors: ===============================

 

Application errors:

==================

Error: (11/29/2015 04:31:32 PM) (Source: Winlogon) (User: )

Description: Windows license activation failed. Error 0x00000000.

 

Error: (11/29/2015 04:31:32 PM) (Source: Software Protection Platform Service) (User: )

Description: License Activation (slui.exe) failed with the following error code:

0x8007043C

 

Error: (11/29/2015 11:35:23 AM) (Source: Winlogon) (User: )

Description: Windows license activation failed. Error 0x00000000.

 

Error: (11/29/2015 11:35:22 AM) (Source: Software Protection Platform Service) (User: )

Description: License Activation (slui.exe) failed with the following error code:

0x8007043C

 

Error: (11/29/2015 10:54:58 AM) (Source: ESENT) (User: )

Description: taskhost (1892) WebCacheLocal: Error -1811 (0xfffff8ed) occurred while opening logfile C:\Users\Brad\AppData\Local\Microsoft\Windows\WebCache\V01.log.

 

Error: (11/29/2015 10:50:28 AM) (Source: Microsoft Security Client Setup) (User: Brad-PC)

Description: HRESULT:0x8004FF11

Description:Can’t install Microsoft Security Essentials on a computer running in safe mode. Your computer is currently running in safe mode. To install Security Essentials, your computer must be running in normal mode. Please restart your computer in normal mode, and then try to run the Security Essentials Setup Wizard again. Error code:0x8004FF11.

 

Error: (11/29/2015 10:03:13 AM) (Source: Winlogon) (User: )

Description: Windows license activation failed. Error 0x00000000.

 

Error: (11/29/2015 10:03:13 AM) (Source: Software Protection Platform Service) (User: )

Description: License Activation (slui.exe) failed with the following error code:

0x8007043C

 

Error: (11/29/2015 09:59:39 AM) (Source: VSS) (User: )

Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x00000214,(null),0,REG_BINARY,00000000020DED40.72).  hr = 0x80070005, Access is denied.

.

 

Error: (11/29/2015 09:59:39 AM) (Source: VSS) (User: )

Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x00000338,(null),0,REG_BINARY,000000000BCCDFE0.72).  hr = 0x80070005, Access is denied.

.

 

 

Operation:

   BackupShutdown Event

 

Context:

   Execution Context: Writer

   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}

   Writer Name: System Writer

   Writer Instance ID: {3f2d452b-3a46-4589-afa2-50d1fe40c7cc}

 

 

System errors:

=============

Error: (11/29/2015 06:13:08 PM) (Source: DCOM) (User: )

Description: 1084defragsvc{D20A3293-3341-4AE8-9AAF-8E397CB63C34}

 

Error: (11/29/2015 05:29:46 PM) (Source: Schannel) (User: NT AUTHORITY)

Description: The following fatal alert was generated: 10. The internal error state is 10.

 

Error: (11/29/2015 05:29:45 PM) (Source: Schannel) (User: NT AUTHORITY)

Description: The following fatal alert was generated: 10. The internal error state is 10.

 

Error: (11/29/2015 04:49:07 PM) (Source: DCOM) (User: )

Description: 1084wuauserv{9B1F122C-2982-4E91-AA8B-E071D54F2A4D}

 

Error: (11/29/2015 04:38:13 PM) (Source: DCOM) (User: )

Description: 1084MSIServer{000C101C-0000-0000-C000-000000000046}

 

Error: (11/29/2015 04:33:28 PM) (Source: Service Control Manager) (User: )

Description: The PnP-X IP Bus Enumerator service depends on the Function Discovery Provider Host service which failed to start because of the following error: 

%%1068

 

Error: (11/29/2015 04:32:22 PM) (Source: DCOM) (User: )

Description: 1068fdPHost{D3DCB472-7261-43CE-924B-0704BD730D5F}

 

Error: (11/29/2015 04:32:22 PM) (Source: DCOM) (User: )

Description: 1068fdPHost{145B4335-FE2A-4927-A040-7C35AD3180EF}

 

Error: (11/29/2015 04:32:07 PM) (Source: Service Control Manager) (User: )

Description: The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error: 

%%1068

 

Error: (11/29/2015 04:32:06 PM) (Source: DCOM) (User: )

Description: 1084WSearch{9E175B6D-F52A-11D8-B9A5-505054503030}

 

 

Microsoft Office Sessions:

=========================

 

CodeIntegrity Errors:

===================================

  Date: 2015-11-28 20:37:56.691

  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

 

  Date: 2015-11-28 20:37:56.574

  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

 

  Date: 2015-07-16 14:19:00.992

  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

 

  Date: 2015-07-16 14:19:00.899

  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

 

  Date: 2015-07-16 14:12:10.586

  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

 

  Date: 2015-07-16 14:12:10.232

  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

 

  Date: 2015-07-16 14:09:27.605

  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

 

  Date: 2015-07-16 14:09:27.524

  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

 

  Date: 2015-07-16 14:08:47.324

  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

 

  Date: 2015-07-16 14:08:47.243

  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

 

 

=========================== Installed Programs ============================

 

64 Bit HP CIO Components Installer (HKLM\...\{FF21C3E6-97FD-474F-9518-8DCBE94C2854}) (Version: 7.2.8 - Hewlett-Packard) Hidden

Acrobat.com (HKLM-x32\...\{C86E7C99-E4AD-79C7-375B-1AEF9A91EC2B}) (Version: 0.0.0 - Adobe Systems Incorporated) Hidden

Acrobat.com (HKLM-x32\...\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.2.443 - Adobe Systems Incorporated)

Adobe Acrobat 9.5.5 - CPSID_83708 (HKLM-x32\...\{AC76BA86-1033-F400-7760-000000000004}_955) (Version:  - Adobe Systems Incorporated)

Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.2.0.2070 - Adobe Systems Incorporated)

Adobe Anchor Service x64 CS4 (HKLM\...\{887797BF-37A5-4199-B0C9-0D38D6196E9A}) (Version: 2.0 - Adobe Systems Incorporated) Hidden

Adobe CMaps x64 CS4 (HKLM\...\{90BA8112-80B3-4617-A3C1-BD2771B60F74}) (Version: 2.0 - Adobe Systems Incorporated) Hidden

Adobe Creative Suite 4 Master Collection (HKLM-x32\...\Adobe_b2d6abde968e6f277ddbfd501383e02) (Version: 4.0 - Adobe Systems Incorporated)

Adobe CSI CS4 x64 (HKLM\...\{8DAA31EB-6830-4006-A99F-4DF8AB24714F}) (Version: 1 - Adobe Systems Incorporated) Hidden

Adobe Drive CS4 x64 (HKLM\...\{A3454894-144A-4D80-B605-C128FE0D7329}) (Version: 1 - Adobe Systems Incorporated) Hidden

Adobe Flash Player 19 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 19.0.0.245 - Adobe Systems Incorporated)

Adobe Flash Player 19 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 19.0.0.245 - Adobe Systems Incorporated)

Adobe Fonts All x64 (HKLM\...\{6631325A-9B1B-4EE7-8E64-8CC4A6F10643}) (Version: 2.0 - Adobe Systems Incorporated) Hidden

Adobe InDesign CS4 Icon Handler x64 (HKLM\...\{B37A99DD-88E2-4ED0-80B4-1E054AB354BF}) (Version: 6.0 - Adobe Systems Incorporated) Hidden

Adobe Linguistics CS4 x64 (HKLM\...\{8875A1C0-6308-4790-8CF6-D34E89880052}) (Version: 4.0.0 - Adobe Systems Incorporated) Hidden

Adobe Media Player (HKLM-x32\...\com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.1 - Adobe Systems Incorporated)

Adobe PDF Library Files x64 CS4 (HKLM\...\{DFFABE78-8173-4E97-9C5C-22FB26192FC5}) (Version: 9.0 - Adobe Systems Incorporated) Hidden

Adobe Photoshop CS4 (64 Bit) (HKLM\...\{D40172D6-CE2D-4B72-BF5F-26A04A900B7B}) (Version: 11.0 - Adobe Systems Incorporated) Hidden

Adobe Photoshop Lightroom 3.6 64-bit (HKLM\...\{D4F66BBA-D79E-4F11-9B06-70C3D75A2958}) (Version: 3.6.1 - Adobe)

Adobe Type Support x64 CS4 (HKLM\...\{8C8D673B-20FB-43E6-BCB7-9B3F78F2E762}) (Version: 9.0 - Adobe Systems Incorporated) Hidden

Adobe WinSoft Linguistics Plugin x64 (HKLM\...\{295CFB7C-A57E-4313-93E7-68E7CE1D0332}) (Version: 1.1 - Adobe Systems Incorporated) Hidden

Advanced SystemCare 9 (HKLM-x32\...\Advanced SystemCare_is1) (Version: 9.0.3 - IObit)

Alcor Micro Smart Card Reader Driver (HKLM-x32\...\{F24F876B-7D71-4BD6-88E9-614D3BB84210}) (Version: 1.7.2.0 - ) Hidden

Alcor Micro Smart Card Reader Driver (HKLM-x32\...\SZCCID) (Version: 1.7.2.0 - )

Apple Application Support (32-bit) (HKLM-x32\...\{7FE25256-B7C1-480D-B736-10A67A833AEA}) (Version: 3.2 - Apple Inc.)

Apple Application Support (64-bit) (HKLM\...\{B255D495-4734-4E9B-B4F5-96702FD4A7B9}) (Version: 3.2 - Apple Inc.)

Apple Mobile Device Support (HKLM\...\{5D61F006-168C-4B8B-B7FD-F113C10AE0E4}) (Version: 8.2.1.3 - Apple Inc.)

Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)

Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)

Belkin F5U249 Driver and Icon (HKLM-x32\...\{E33A4D86-8941-41CB-9DF7-466FACB3ADF2}) (Version: 1.0 - BELKIN)

Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)

Bonjour Print Services (HKLM\...\{0DA20600-6130-443B-9D4B-F30520315FA6}) (Version: 2.0.2.0 - Apple Inc.)

BufferChm (HKLM-x32\...\{FA0FF682-CC70-4C57-93CD-E276F3E7537E}) (Version: 140.0.212.000 - Hewlett-Packard) Hidden

C310 (HKLM-x32\...\{FE651900-D014-482F-AEBC-2928F57D1FB0}) (Version: 140.0.304.000 - Hewlett-Packard) Hidden

CameraHelperMsi (HKLM-x32\...\{15634701-BACE-4449-8B25-1567DA8C9FD3}) (Version: 13.50.854.0 - Logitech) Hidden

Cisco Connect (HKLM-x32\...\Cisco Connect) (Version: 1.3.11006.1 - Cisco Consumer Products LLC)

CM Installer (HKLM-x32\...\{E8F42777-958D-4C14-9A42-8DCA1929FD26}) (Version: 1.0.0.0 - Cyanogen Inc.)

Common (HKLM-x32\...\{C6017EEA-9E51-4129-84BA-EFA9520E69D8}) (Version: 14.0.0.342 - Corel Corporation) Hidden

Connect (HKLM-x32\...\{B29AD377-CC12-490A-A480-1452337C618D}) (Version: 1.0.0.1 - Adobe Systems Incorporated) Hidden

Contents (HKLM-x32\...\{CC4C7E9B-4B26-4D8D-8076-40CF708A9FA4}) (Version: 14.0.0.342 - Corel Corporation) Hidden

CopyTrans Suite Remove Only (HKCU\...\CopyTrans Suite) (Version: 2.15 - WindSolutions)

Corel DVD MovieFactory (HKLM-x32\...\{50F68032-B5B7-4513-9116-C978DBD8F27A}) (Version: 7.0.0 - Corel Corporation) Hidden

Corel DVD MovieFactory 7 SE (HKLM-x32\...\InstallShield_{50F68032-B5B7-4513-9116-C978DBD8F27A}) (Version: 7.0.0 - Corel Corporation)

Corel VideoStudio Pro X4 (HKLM-x32\...\_{AA902C31-B49D-4608-BCCF-2519EB77722D}) (Version: 14.0.0.342 - Corel Corporation)

Defaulttab (HKLM-x32\...\DefaultTab) (Version: 2.6.1.0 - Search Results, LLC)

Destinations (HKLM-x32\...\{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}) (Version: 140.0.77.000 - Hewlett-Packard) Hidden

DeviceDiscovery (HKLM-x32\...\{1458BB78-1DC5-4BC0-B9A3-2B644F5A8105}) (Version: 140.0.212.000 - Hewlett-Packard) Hidden

DeviceIO (HKLM-x32\...\{D07F85DE-22F1-4FB4-B3D1-402FD22C4870}) (Version: 14.0.0.342 - Corel Corporation) Hidden

Diablo III (HKLM-x32\...\Diablo III) (Version:  - Blizzard Entertainment)

Dump Truck (HKLM-x32\...\Dump Truck) (Version: 1.2.2.933 - Golden Frog, Inc.)

EA Download Manager (HKLM-x32\...\EADM) (Version: 7.2.0.32 - Electronic Arts, Inc.)

EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version:  - )

erLT (HKLM-x32\...\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}) (Version: 1.20.138.34 - Logitech, Inc.) Hidden

Giganews Accelerator (HKLM-x32\...\{E7300AF3-DD5B-4E86-A291-7631BE0C62C7}) (Version: 1.0.108 - Giganews)

Glary Utilities 5.24 (HKLM-x32\...\Glary Utilities 5) (Version: 5.24.0.43 - Glarysoft Ltd)

Google Earth (HKLM-x32\...\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google)

Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.28.15 - Google Inc.) Hidden

Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden

GPBaseService2 (HKLM-x32\...\{BB3447F6-9553-4AA9-960E-0DB5310C5779}) (Version: 140.0.211.000 - Hewlett-Packard) Hidden

HitmanPro 3.7 (HKLM\...\HitmanPro37) (Version: 3.7.10.251 - SurfRight B.V.)

HP Customer Participation Program 14.0 (HKLM\...\HPExtendedCapabilities) (Version: 14.0 - HP)

HP Imaging Device Functions 14.0 (HKLM\...\HP Imaging Device Functions) (Version: 14.0 - HP)

HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.11502 - HP Photo Creations Powered by RocketLife)

HP Photosmart Prem C310 All-In-One Driver Software 14.0 Rel. 7 (HKLM\...\{4E484899-4F93-4086-88BA-56BDDF47A776}) (Version: 14.0 - HP)

HP Print Projects 1.0 (HKLM\...\HP Print Projects) (Version: 1.0 - HP)

HP Smart Web Printing 4.60 (HKLM\...\HP Smart Web Printing) (Version: 4.60 - HP)

HP Solution Center 14.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 14.0 - HP)

HP Support Solutions Framework (HKLM-x32\...\{FC3C2B77-6800-48C6-A15D-9D1031130C16}) (Version: 11.51.0049 - Hewlett-Packard Company)

HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)

HPAppStudio (HKLM-x32\...\{565E7B0E-B76B-4EAD-9753-F1E72A5CF12E}) (Version: 140.0.95.000 - Hewlett-Packard) Hidden

HPDiagnosticAlert (HKLM-x32\...\{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}) (Version: 1.00.0000 - Microsoft) Hidden

HPPhotoGadget (HKLM-x32\...\{CAE4213F-F797-439D-BD9E-79B71D115BE3}) (Version: 140.0.524.000 - Hewlett-Packard) Hidden

hpPrintProjects (HKLM-x32\...\{C75CDBA2-3C86-481e-BD10-BDDA758F9DFF}) (Version: 130.0.313.000 - Hewlett-Packard) Hidden

HPProductAssistant (HKLM-x32\...\{150B6201-E9E6-4DFB-960E-CCBD53FBDDED}) (Version: 140.0.212.000 - Hewlett-Packard) Hidden

HPSSupply (HKLM-x32\...\{AC35A885-0F8F-4857-B7DA-6E8DFB43E6B3}) (Version: 140.0.211.000 - Hewlett-Packard) Hidden

hpWLPGInstaller (HKLM-x32\...\{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}) (Version: 130.0.313.000 - Hewlett-Packard) Hidden

ICA (HKLM-x32\...\{AA902C31-B49D-4608-BCCF-2519EB77722D}) (Version: 14.0.0.342 - Corel Corporation) Hidden

iCloud (HKLM\...\{709A2D23-C25E-47B5-9268-CB6FEE648504}) (Version: 4.1.1.53 - Apple Inc.)

IObit Uninstaller (HKLM-x32\...\IObitUninstall) (Version: 5.1.0.20 - IObit)

IPM_VS_Pro (HKLM-x32\...\{A567895C-1D23-48ED-BE83-FB3ED7D30442}) (Version: 13.0 - Corel Corporation) Hidden

ISCOM (HKLM-x32\...\{D68897FC-7E8D-4849-819A-726B2489713C}) (Version: 14.0.0.342 - Corel Corporation) Hidden

iTunes (HKLM\...\{6CF1A7E2-8001-4870-9F18-3C6CDD6FE9E3}) (Version: 12.2.1.16 - Apple Inc.)

KB905474 (1.5.708) (HKLM-x32\...\WGA + OGA Patch_is1) (Version:  - )

kuler (HKLM-x32\...\{098727E1-775A-4450-B573-3F441F1CA243}) (Version: 2.0 - Adobe Systems Incorporated) Hidden

Logitech Harmony Remote Software 7 (HKLM-x32\...\{5C6F884D-680C-448B-B4C9-22296EE1B206}) (Version: 7.7.0.0 - Logitech)

Logitech Vid HD (HKLM-x32\...\Logitech Vid) (Version: 7.2 (7230) - Logitech Inc..)

Logitech Webcam Software (HKLM-x32\...\{D40EB009-0499-459c-A8AF-C9C110766215}) (Version: 2.0 - Logitech Inc.)

LogMeIn (HKLM-x32\...\{D3AE96EE-2876-4B3F-847C-D3A4AD689E43}) (Version: 4.1.1578 - LogMeIn, Inc.)

LWS VideoEffects (HKLM\...\{138A4072-9E64-46BD-B5F9-DB2BB395391F}) (Version: 13.30.1379.0 - Logitech) Hidden

Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)

MarketResearch (HKLM-x32\...\{D360FA88-17C8-4F14-B67F-13AAF9607B12}) (Version: 140.0.212.000 - Hewlett-Packard) Hidden

McAfee Agent (HKLM-x32\...\{AA951B10-7089-4D60-B288-516E641F48E6}) (Version: 4.0.0.1496 - McAfee, Inc.)

McAfee VirusScan Enterprise (HKLM-x32\...\{147BCE03-C0F1-4C9F-8157-6A89B6D2D973}) (Version: 8.7.0 - McAfee, Inc.)

Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30320 - Microsoft Corporation)

Microsoft .NET Framework 4 Extended (HKLM\...\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation)

Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)

Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)

Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)

Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)

Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)

Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)

Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)

Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)

Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM-x32\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)

Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)

Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)

Mimo (HKLM-x32\...\Mimo) (Version: 0.2.5 - Mimo, Inc.)

Mozilla Firefox 41.0.2 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 41.0.2 (x86 en-US)) (Version: 41.0.2 - Mozilla)

Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 41.0.2.5765 - Mozilla)

MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)

MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)

MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)

MSXML 4.0 SP3 Parser (KB2721691) (HKLM-x32\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation)

MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)

MSXML 4.0 SP3 Parser (KB973685) (HKLM-x32\...\{859DFA95-E4A6-48CD-B88E-A3E483E89B44}) (Version: 4.30.2107.0 - Microsoft Corporation)

NEF Codec (HKLM-x32\...\{D6506521-0959-4FA3-875F-E2E28830B0D2}) (Version: 1.00.0000 - Nikon)

NETGEAR WNDA3100v2 wireless USB 2.0 adapter (HKLM-x32\...\{3C7839E7-21F4-49E0-B4D5-AC8ED818CCB0}) (Version: 1.03.000 - NETGEAR)

Network64 (HKLM\...\{48C0866E-57EB-444C-8371-8E4321066BC3}) (Version: 140.0.215.000 - Hewlett-Packard) Hidden

Network64 (HKLM\...\{6BFAB6C1-6D46-46DB-A538-A269907C9F2F}) (Version: 140.0.221.000 - Hewlett-Packard) Hidden

NewsBin for Giganews (HKLM-x32\...\NewsBinGN) (Version: 5.57 - DJI Interprises, LLC)

Newsbin Pro (HKLM\...\Newsbin6) (Version: 6.55 - DJI Interprises, LLC)

Newzbin2 Browser 1.1.0.829 (HKLM-x32\...\Newzbin2 Browser) (Version: 1.1.0.829 - Newzbin2)

Nostromo (HKLM-x32\...\{548C7B77-8B04-427E-ACD0-D0E6E6E59BCF}) (Version: 3.2.4 - Belkin International)

NVIDIA 3D Vision Controller Driver 310.70 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 310.70 - NVIDIA Corporation)

NVIDIA 3D Vision Driver 311.06 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 311.06 - NVIDIA Corporation)

NVIDIA Graphics Driver 311.06 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 311.06 - NVIDIA Corporation)

NVIDIA PhysX System Software 9.12.1031 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.12.1031 - NVIDIA Corporation)

NVIDIA Update 1.11.3 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.11.3 - NVIDIA Corporation)

PDF Settings CS4 (HKLM-x32\...\{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}) (Version: 9.0 - Adobe Systems Incorporated) Hidden

Photobucket Backup (HKLM-x32\...\{98813202-6C6E-4ABE-A128-6E8FB3368BE0}) (Version: 1.0.7.2104 - Photobucket)

Photomatix Pro version 3.2.9 (HKLM-x32\...\PhotomatixPro3x32_is1) (Version: 3.2.9 - HDRsoft Sarl)

Photoshop Camera Raw (HKLM-x32\...\{CC75AB5C-2110-4A7F-AF52-708680D22FE8}) (Version: 5.0 - Adobe Systems Incorporated) Hidden

Photoshop Camera Raw_x64 (HKLM\...\{2D74E972-5A85-44DC-9193-8A302BA8C181}) (Version: 5.0 - Adobe Systems Incorporated) Hidden

Pixel Bender Toolkit (HKLM-x32\...\{43509E18-076E-40FE-AF38-CA5ED400A5A9}) (Version: 1.0 - Adobe Systems Incorporated) Hidden

PS_AIO_07_C310_SW_Min (HKLM-x32\...\{582BA1F1-FAB4-41AD-A5E3-4A9535343461}) (Version: 140.0.304.000 - Hewlett-Packard) Hidden

PureHD (HKLM-x32\...\{B87FAC24-973D-4A4F-AFC4-555FB95B32DB}) (Version: 14.0.0.342 - Corel Corporation) Hidden

PVSonyDll (HKLM\...\{3D3E663D-4E7E-4577-A560-7ECDDD45548A}) (Version: 1.00.0001 - NVIDIA Corporation) Hidden

QuickPar 0.9 (HKLM-x32\...\QuickPar) (Version: 0.9 - Peter B. Clements)

QuickTime 7 (HKLM-x32\...\{627FFC10-CE0A-497F-BA2B-208CAC638010}) (Version: 7.77.80.95 - Apple Inc.)

QuickTransfer (HKLM-x32\...\{E517094C-06B6-419F-8FFD-EF4F57972130}) (Version: 140.0.98.000 - Hewlett-Packard) Hidden

Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6013 - Realtek Semiconductor Corp.)

Registry Repair 4.1.0.388 (HKLM-x32\...\Registry Repair) (Version: 4.1.0.388 - Glarysoft Ltd)

Remote Control USB Driver (HKLM-x32\...\{8471021C-F529-43DE-84DF-3612E10F58C4}) (Version: 2.3.2.317 - )

Safari (HKLM-x32\...\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.)

Samsung Kies (HKLM-x32\...\{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.5.0.12114_1 - Samsung Electronics Co., Ltd.) Hidden

Samsung Kies (HKLM-x32\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.5.0.12114_1 - Samsung Electronics Co., Ltd.)

Samsung Kies3 (HKLM-x32\...\{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.14083.9 - Samsung Electronics Co., Ltd.) Hidden

Samsung Kies3 (HKLM-x32\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.14083.9 - Samsung Electronics Co., Ltd.)

Scan (HKLM-x32\...\{06A1D88C-E102-4527-AF70-29FFD7AF215A}) (Version: 140.0.80.000 - Hewlett-Packard) Hidden

Setup (HKLM-x32\...\{D8D9BCF5-0F5F-4D3F-8427-64B7632F93BE}) (Version: 14.0.0.342 - Corel Corporation) Hidden

Share (HKLM-x32\...\{B84ECBE1-6ED5-4E86-B4AB-DF46D342411F}) (Version: 14.0.0.342 - Corel Corporation) Hidden

Share64 (HKLM\...\{8BB347A7-68B5-4E46-9FCC-17F6172BA9E1}) (Version: 14.0.0.342 - Corel Corporation) Hidden

Shop for HP Supplies (HKLM\...\Shop for HP Supplies) (Version: 14.0 - HP)

Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.5.0.9082 - Microsoft Corporation)

Skype™ 6.18 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.18.106 - Skype Technologies S.A.)

SmartSound Common Data (HKLM-x32\...\{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}) (Version: 1.1.0 - SmartSound Software Inc.) Hidden

SmartSound Common Data (HKLM-x32\...\InstallShield_{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}) (Version: 1.1.0 - SmartSound Software Inc.)

SmartSound Quicktracks 5 (HKLM-x32\...\{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}) (Version: 5.1.6 - SmartSound Software Inc.) Hidden

SmartSound Quicktracks 5 (HKLM-x32\...\InstallShield_{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}) (Version: 5.1.6 - SmartSound Software Inc.)

SmartWebPrinting (HKLM-x32\...\{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}) (Version: 140.0.186.000 - Hewlett-Packard) Hidden

SolutionCenter (HKLM-x32\...\{BC5DD87B-0143-4D14-AAE6-97109614DC6B}) (Version: 140.0.214.000 - Hewlett-Packard) Hidden

Status (HKLM-x32\...\{5B025634-7D5B-4B8D-BE2A-7943C1CF2D5D}) (Version: 140.0.256.000 - Hewlett-Packard) Hidden

Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)

Suite Shared Configuration CS4 (HKLM-x32\...\{842B4B72-9E8F-4962-B3C1-1C422A5C4434}) (Version: 1.0 - Adobe Systems Incorporated) Hidden

Surfing Protection (HKLM-x32\...\IObit Surfing Protection_is1) (Version: 1.3 - IObit)

System Requirements Lab (HKLM-x32\...\SystemRequirementsLab) (Version:  - )

Toolbox (HKLM-x32\...\{292F0F52-B62D-4E71-921B-89A682402201}) (Version: 140.0.428.000 - Hewlett-Packard) Hidden

TrayApp (HKLM-x32\...\{CD31E63D-47FD-491C-8117-CF201D0AFAB5}) (Version: 140.0.212.000 - Hewlett-Packard) Hidden

UltraISO Premium V9.36 (HKLM-x32\...\UltraISO_is1) (Version:  - )

Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)

USB 2.0 Multimedia Reader/Writer (HKLM-x32\...\{247A11CA-F5CE-4DD6-85E2-64850E64E064}) (Version: 0.2.5.0 - Standard Microsystems Corporation)

VIO (HKLM-x32\...\{C4778408-3268-45CE-AE15-772D1739A1F1}) (Version: 14.0.0.342 - Corel Corporation) Hidden

VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN)

VSClassic (HKLM-x32\...\{3990E632-42C3-4A25-ADFF-1101E3D6DD47}) (Version: 14.0.0.342 - Corel Corporation) Hidden

VSPro (HKLM-x32\...\{B0125BEB-6731-43FA-88DA-B64D7BD3AD2D}) (Version: 14.0.0.342 - Corel Corporation) Hidden

WD Discovery Software (HKLM-x32\...\{99341ACA-2A86-4235-A636-02A2A9820987}) (Version: 1.80 - Western Digital)

WD Link (HKLM-x32\...\WD Link) (Version: 1.00.03 - Western Digital)

WD My Cloud (HKLM\...\{8F19C800-80A5-4636-B560-39A58112D45B}) (Version: 1.0.4.37 - Western Digital Technologies, Inc.)

WD SmartWare Drive Manager (HKLM\...\{5E2D7D76-30DE-4DDE-B416-9B0B925EBFEC}) (Version: 1.4.0.9 - Western Digital)

WebReg (HKLM-x32\...\{8EE94FD8-5F52-4463-A340-185D16328158}) (Version: 140.0.212.017 - Hewlett-Packard) Hidden

Windows Live ID Sign-in Assistant (HKLM\...\{9B48B0AC-C813-4174-9042-476A887592C7}) (Version: 6.500.3165.0 - Microsoft Corporation)

Windows Media Encoder 9 Series (HKLM-x32\...\Windows Media Encoder 9) (Version:  - )

WinPatrol (HKLM\...\{84481A87-2316-4923-8FAB-3BA8CA29323D}) (Version: 30.0.2014.0 - BillP Studios)

WinRAR archiver (HKLM\...\WinRAR archiver) (Version:  - )

 

========================= Devices: ================================

 

Name: Teredo Tunneling Pseudo-Interface

Description: Microsoft Teredo Tunneling Adapter

Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}

Manufacturer: Microsoft

Service: tunnel

Device ID: ROOT\*TEREDO\0000

Problem: : This device cannot start. (Code10)

Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.

On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

 

Name: Security Processor Loader Driver

Description: Security Processor Loader Driver

Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}

Manufacturer: 

Service: spldr

Device ID: ROOT\LEGACY_SPLDR\0000

Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)

Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.

Devices stay in this state if they have been prepared for removal.

After you remove the device, this error disappears.Remove the device, and this error should be resolved.

 

Name: McAfee Inc. mfehidk

Description: McAfee Inc. mfehidk

Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}

Manufacturer: 

Service: mfehidk

Device ID: ROOT\LEGACY_MFEHIDK\0000

Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)

Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.

Devices stay in this state if they have been prepared for removal.

After you remove the device, this error disappears.Remove the device, and this error should be resolved.

 

Name: Photosmart Prem C310 series

Description: Photosmart Prem C310 series

Class Guid: {4d36e971-e325-11ce-bfc1-08002be10318}

Manufacturer: HP

Service: 

Device ID: ROOT\MULTIFUNCTION\0000

Problem: : This device is disabled. (Code 22)

Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

 

 

========================= Memory info: ===================================

 

Percentage of memory in use: 37%

Total physical RAM: 9207.12 MB

Available physical RAM: 5797.86 MB

Total Virtual: 18412.44 MB

Available Virtual: 15489.85 MB

 

========================= Partitions: =====================================

 

1 Drive c: () (Fixed) (Total:931.41 GB) (Free:273.48 GB) NTFS

3 Drive f: (Old HP Drive) (Fixed) (Total:142.07 GB) (Free:43.65 GB) NTFS

4 Drive h: (TOSHIBA EXT) (Fixed) (Total:931.41 GB) (Free:879.47 GB) NTFS

6 Drive z: (Public) (Network) (Total:2746.24 GB) (Free:1937.67 GB) NTFS

 

========================= Users: ========================================

 

User accounts for \\BRAD-PC

 

Administrator            Brad                     Guest                    

LogMeInRemoteUser        UpdatusUser              

 

========================= Restore Points ==================================

 

20-11-2015 15:00:03 Scheduled Checkpoint

28-11-2015 00:07:13 Windows Defender Checkpoint

28-11-2015 12:10:23 Checkpoint by HitmanPro

29-11-2015 00:58:18 Checkpoint by HitmanPro

 

**** End of log ****



#5 vbbikerbums

vbbikerbums
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:57 PM

Posted 29 November 2015 - 07:09 AM

Malware Bytes Most recent (Clean)

Malwarebytes Anti-Malware

www.malwarebytes.org

 

Scan Date: 11/29/2015

Scan Time: 6:17 PM

Logfile: MalwareBytes Log.txt

Administrator: Yes

 

Version: 2.2.0.1024

Malware Database: v2015.11.29.01

Rootkit Database: v2015.11.26.01

License: Trial

Malware Protection: Disabled

Malicious Website Protection: Disabled

Self-protection: Enabled

 

OS: Windows 7 Service Pack 1

CPU: x64

File System: NTFS

User: Brad

 

Scan Type: Threat Scan

Result: Completed

Objects Scanned: 497873

Time Elapsed: 2 hr, 0 min, 46 sec

 

Memory: Enabled

Startup: Enabled

Filesystem: Enabled

Archives: Enabled

Rootkits: Disabled

Heuristics: Enabled

PUP: Enabled

PUM: Enabled

 

Processes: 0

(No malicious items detected)

 

Modules: 0

(No malicious items detected)

 

Registry Keys: 0

(No malicious items detected)

 

Registry Values: 0

(No malicious items detected)

 

Registry Data: 0

(No malicious items detected)

 

Folders: 0

(No malicious items detected)

 

Files: 0

(No malicious items detected)

 

Physical Sectors: 0

(No malicious items detected)

 

 

(end)

 

 

Malware Bytes Root Kit

No Malware found

 

McAfee On Demand Scan Nothing found

 

FYI...this is like the 5th time running things I found up to 7500 issues the firs tiem running everything. I uninstalled Vuze Torrent and think that was the source



#6 vbbikerbums

vbbikerbums
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:57 PM

Posted 29 November 2015 - 07:30 AM

I rebooted back into normal mode and I still have the same issues I have had from the beginning, no admin rights, and everything needs admin to run or install.



#7 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,679 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:10:57 PM

Posted 29 November 2015 - 05:47 PM

I still would like to see MBAR logs.


My Website

p4433470.gif

My help doesn't cost a penny, but if you'd like to consider a donation, click p22001735.gif


 


#8 vbbikerbums

vbbikerbums
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:57 PM

Posted 30 November 2015 - 02:54 AM

MBAR System Log

 

 

---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.09.3.1001
 
© Malwarebytes Corporation 2011-2012
 
OS version: 6.1.7601 Windows 7 Service Pack 1 x64
 
System is currently in a safe mode
 
Account is Administrative
 
Internet Explorer version: 11.0.9600.18097
 
File system is: NTFS
Disk drives: C:\ DRIVE_FIXED, F:\ DRIVE_FIXED
CPU speed: 2.673000 GHz
Memory total: 9654362112, free: 6683664384
 
Downloaded database version: v2015.11.29.01
Downloaded database version: v2015.11.26.01
Downloaded database version: v2015.11.22.02
=======================================
Initializing...
Driver version: 0.3.0.4
------------ Kernel report ------------
     11/29/2015 17:58:15
------------ Loaded modules -----------
\SystemRoot\system32\ntoskrnl.exe
\SystemRoot\system32\hal.dll
\SystemRoot\system32\kdcom.dll
\SystemRoot\system32\mcupdate_GenuineIntel.dll
\SystemRoot\system32\PSHED.dll
\SystemRoot\system32\CLFS.SYS
\SystemRoot\system32\CI.dll
\SystemRoot\system32\drivers\Wdf01000.sys
\SystemRoot\system32\drivers\WDFLDR.SYS
\SystemRoot\system32\drivers\ACPI.sys
\SystemRoot\system32\drivers\WMILIB.SYS
\SystemRoot\system32\drivers\msisadrv.sys
\SystemRoot\system32\drivers\pci.sys
\SystemRoot\system32\drivers\vdrvroot.sys
\SystemRoot\System32\drivers\partmgr.sys
\SystemRoot\system32\drivers\volmgr.sys
\SystemRoot\System32\drivers\volmgrx.sys
\SystemRoot\system32\drivers\pciide.sys
\SystemRoot\system32\drivers\PCIIDEX.SYS
\SystemRoot\System32\drivers\mountmgr.sys
\SystemRoot\system32\drivers\vmbus.sys
\SystemRoot\system32\drivers\winhv.sys
\SystemRoot\system32\drivers\atapi.sys
\SystemRoot\system32\drivers\ataport.SYS
\SystemRoot\system32\drivers\amdxata.sys
\SystemRoot\system32\drivers\fltmgr.sys
\SystemRoot\system32\drivers\fileinfo.sys
\SystemRoot\System32\Drivers\PxHlpa64.sys
\SystemRoot\System32\Drivers\Ntfs.sys
\SystemRoot\System32\Drivers\msrpc.sys
\SystemRoot\System32\Drivers\ksecdd.sys
\SystemRoot\System32\Drivers\cng.sys
\SystemRoot\System32\drivers\pcw.sys
\SystemRoot\System32\Drivers\Fs_Rec.sys
\SystemRoot\system32\drivers\ndis.sys
\SystemRoot\system32\drivers\NETIO.SYS
\SystemRoot\System32\Drivers\ksecpkg.sys
\SystemRoot\System32\drivers\tcpip.sys
\SystemRoot\System32\drivers\fwpkclnt.sys
\SystemRoot\system32\DRIVERS\scmndisp.sys
\SystemRoot\system32\drivers\vmstorfl.sys
\SystemRoot\system32\drivers\volsnap.sys
\SystemRoot\System32\drivers\rdyboost.sys
\SystemRoot\System32\Drivers\mup.sys
\SystemRoot\System32\drivers\hwpolicy.sys
\SystemRoot\System32\DRIVERS\fvevol.sys
\SystemRoot\system32\DRIVERS\disk.sys
\SystemRoot\system32\DRIVERS\CLASSPNP.SYS
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\System32\Drivers\Beep.SYS
\SystemRoot\System32\drivers\vga.sys
\SystemRoot\System32\drivers\VIDEOPRT.SYS
\SystemRoot\System32\drivers\watchdog.sys
\SystemRoot\system32\drivers\rdpencdd.sys
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\system32\DRIVERS\tdx.sys
\SystemRoot\system32\DRIVERS\TDI.SYS
\SystemRoot\system32\drivers\mfetdik.sys
\SystemRoot\System32\DRIVERS\netbt.sys
\SystemRoot\system32\drivers\afd.sys
\SystemRoot\system32\drivers\ws2ifsl.sys
\SystemRoot\system32\DRIVERS\wfplwf.sys
\SystemRoot\system32\DRIVERS\pacer.sys
\SystemRoot\system32\DRIVERS\vwififlt.sys
\SystemRoot\system32\DRIVERS\netbios.sys
\SystemRoot\system32\DRIVERS\rdbss.sys
\SystemRoot\system32\drivers\nsiproxy.sys
\SystemRoot\system32\drivers\csc.sys
\SystemRoot\System32\Drivers\dfsc.sys
\SystemRoot\system32\DRIVERS\usbuhci.sys
\SystemRoot\system32\DRIVERS\USBPORT.SYS
\SystemRoot\system32\DRIVERS\usbehci.sys
\SystemRoot\system32\drivers\HDAudBus.sys
\SystemRoot\system32\DRIVERS\Rt64win7.sys
\SystemRoot\system32\drivers\1394ohci.sys
\SystemRoot\system32\drivers\cdrom.sys
\SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
\SystemRoot\system32\drivers\wmiacpi.sys
\SystemRoot\system32\DRIVERS\blbdrive.sys
\SystemRoot\system32\drivers\CompositeBus.sys
\SystemRoot\system32\drivers\mssmbios.sys
\SystemRoot\system32\DRIVERS\AgileVpn.sys
\SystemRoot\system32\DRIVERS\rasl2tp.sys
\SystemRoot\system32\DRIVERS\ndistapi.sys
\SystemRoot\system32\DRIVERS\ndiswan.sys
\SystemRoot\system32\DRIVERS\raspppoe.sys
\SystemRoot\system32\DRIVERS\raspptp.sys
\SystemRoot\system32\DRIVERS\rassstp.sys
\SystemRoot\system32\DRIVERS\rdpbus.sys
\SystemRoot\system32\drivers\termdd.sys
\SystemRoot\system32\DRIVERS\kbdclass.sys
\SystemRoot\system32\DRIVERS\mouclass.sys
\SystemRoot\system32\drivers\swenum.sys
\SystemRoot\system32\drivers\ks.sys
\SystemRoot\system32\DRIVERS\umbus.sys
\SystemRoot\system32\DRIVERS\usbhub.sys
\SystemRoot\System32\Drivers\NDProxy.SYS
\SystemRoot\system32\DRIVERS\usbccgp.sys
\SystemRoot\system32\DRIVERS\USBD.SYS
\SystemRoot\system32\DRIVERS\usbprint.sys
\SystemRoot\system32\DRIVERS\dot4usb.sys
\SystemRoot\system32\DRIVERS\Dot4.sys
\SystemRoot\system32\DRIVERS\USBSTOR.SYS
\SystemRoot\system32\DRIVERS\hidusb.sys
\SystemRoot\system32\DRIVERS\HIDCLASS.SYS
\SystemRoot\system32\DRIVERS\HIDPARSE.SYS
\SystemRoot\system32\DRIVERS\kbdhid.sys
\SystemRoot\system32\DRIVERS\mouhid.sys
\SystemRoot\System32\Drivers\crashdmp.sys
\SystemRoot\System32\Drivers\dump_dumpata.sys
\SystemRoot\System32\Drivers\dump_atapi.sys
\SystemRoot\System32\Drivers\dump_dumpfve.sys
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\drivers\Dxapi.sys
\SystemRoot\System32\drivers\dxg.sys
\SystemRoot\System32\TSDDD.dll
\SystemRoot\System32\framebuf.dll
\SystemRoot\System32\ATMFD.DLL
\SystemRoot\system32\DRIVERS\nwifi.sys
\SystemRoot\system32\DRIVERS\ndisuio.sys
\SystemRoot\system32\DRIVERS\bowser.sys
\SystemRoot\System32\drivers\mpsdrv.sys
\SystemRoot\system32\DRIVERS\mrxsmb.sys
\SystemRoot\system32\DRIVERS\mrxsmb10.sys
\SystemRoot\system32\DRIVERS\mrxsmb20.sys
\??\C:\Windows\system32\drivers\mbamchameleon.sys
\??\C:\Windows\system32\drivers\MBAMSwissArmy.sys
\Windows\System32\ntdll.dll
\Windows\System32\smss.exe
\Windows\System32\apisetschema.dll
----------- End -----------
Done!
 
Scan started
Database versions:
  main:    v2015.11.29.01
  rootkit: v2015.11.26.01
 
<<<2>>>
Physical Sector Size: 512
Drive: 1, DevicePointer: 0xfffffa8008989060, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa8008989b90, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa8008989060, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa80086d7580, DeviceName: Unknown, DriverName: \Driver\ACPI\
DevicePointer: 0xfffffa80086db060, DeviceName: \Device\Ide\IdeDeviceP3T0L0-6\, DriverName: \Driver\atapi\
------------ End ----------
Alternate DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers...
Done!
Physical Sector Size: 512
Drive: 0, DevicePointer: 0xfffffa800892e790, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa800892e2c0, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa800892e790, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa80078b5e40, DeviceName: Unknown, DriverName: \Driver\ACPI\
DevicePointer: 0xfffffa80086d1060, DeviceName: \Device\Ide\IdeDeviceP1T1L0-3\, DriverName: \Driver\atapi\
------------ End ----------
Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
Drive 0
Scanning MBR on drive 0...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: 1549F232
 
Partition information:
 
    Partition 0 type is Primary (0x7)
    Partition is ACTIVE.
    Partition starts at LBA: 14621040  Numsec = 297939600
    Partition is not bootable
    Partition file system is NTFS
 
    Partition 1 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
    Partition is not bootable
 
    Partition 2 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
    Partition is not bootable
 
    Partition 3 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
    Partition is not bootable
 
Disk Size: 160041885696 bytes
Sector size: 512 bytes
 
Done!
Drive 1
This is a System drive
Scanning MBR on drive 1...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: 3776BBD3
 
Partition information:
 
    Partition 0 type is Primary (0x7)
    Partition is ACTIVE.
    Partition starts at LBA: 2048  Numsec = 204800
    Partition is bootable
    Partition file system is NTFS
 
    Partition 1 type is Primary (0x7)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 206848  Numsec = 1953314816
    Partition is not bootable
    Partition file system is NTFS
 
    Partition 2 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
    Partition is not bootable
 
    Partition 3 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
    Partition is not bootable
 
Disk Size: 1000204886016 bytes
Sector size: 512 bytes
 
Done!
Physical Sector Size: 0
Drive: 2, DevicePointer: 0xfffffa8009a1f790, DeviceName: \Device\Harddisk2\DR2\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa800887d8e0, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa8009a1f790, DeviceName: \Device\Harddisk2\DR2\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa80099a1660, DeviceName: \Device\0000007b\, DriverName: \Driver\USBSTOR\
------------ End ----------
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scan finished
=======================================
 
 
Removal queue found; removal started
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\VBR-0-0-14621040-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-r.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-1-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\VBR-1-0-2048-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\VBR-1-1-206848-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-1-r.mbam...
Removal finished
---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.09.3.1001
 
© Malwarebytes Corporation 2011-2012
 
OS version: 6.1.7601 Windows 7 Service Pack 1 x64
 
System is currently in a safe mode
 
Account is Administrative
 
Internet Explorer version: 11.0.9600.18097
 
File system is: NTFS
Disk drives: C:\ DRIVE_FIXED, F:\ DRIVE_FIXED
CPU speed: 2.673000 GHz
Memory total: 9654362112, free: 7231320064
 
=======================================

Malwarebytes Anti-Rootkit BETA 1.9.3.1001
www.malwarebytes.org
 
Database version:
  main:    v2015.11.29.01
  rootkit: v2015.11.26.01
 
Windows 7 Service Pack 1 x64 NTFS (Safe Mode/Networking)
Internet Explorer 11.0.9600.18097
Brad :: BRAD-PC [administrator]
 
11/29/2015 5:58:33 PM
mbar-log-2015-11-29 (17-58-33).txt
 
Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled: 
Objects scanned: 498401
Time elapsed: 2 hour(s), 49 minute(s), 2 second(s)
 
Memory Processes Detected: 0
(No malicious items detected)
 
Memory Modules Detected: 0
(No malicious items detected)
 
Registry Keys Detected: 0
(No malicious items detected)
 
Registry Values Detected: 0
(No malicious items detected)
 
Registry Data Items Detected: 0
(No malicious items detected)
 
Folders Detected: 0
(No malicious items detected)
 
Files Detected: 0
(No malicious items detected)
 
Physical Sectors Detected: 0
(No malicious items detected)
 
(end)
 
Sorry so many logs thought I attached these


#9 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,679 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:10:57 PM

Posted 30 November 2015 - 04:12 PM

p22002970.gif Download Temp File Cleaner (TFC)
Alternate download: http://www.itxassociates.com/OT-Tools/TFC.exe
Double click on TFC.exe to run the program.
Click on Start button to begin cleaning process.
TFC will close all running programs, and it may ask you to restart computer.

p22002970.gif Please download AdwCleaner by Xplode onto your desktop.

  • Close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
  • Click on Scan button.
  • When the scan has finished click on Clean button.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the contents of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.


p22002970.gif Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.


p22002970.gif Download Sophos Free Virus Removal Tool and save it to your desktop.
  • Double click the icon and select Run
  • Click Next
  • Select I accept the terms in this license agreement, then click Next twice
  • Click Install
  • Click Finish to launch the program
  • Once the virus database has been updated click Start Scanning
  • If any threats are found click Details, then View log file... (bottom left hand corner)
  • Copy and paste the results in your reply
  • Close the Notepad document, close the Threat Details screen, then click Start cleanup
  • Click Exit to close the program


My Website

p4433470.gif

My help doesn't cost a penny, but if you'd like to consider a donation, click p22001735.gif


 


#10 vbbikerbums

vbbikerbums
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:57 PM

Posted 01 December 2015 - 03:02 AM

ADW Log

 

 

# AdwCleaner v5.023 - Logfile created 01/12/2015 at 07:01:15
# Updated 30/11/2015 by Xplode
# Database : 2015-11-30.1 [Server]
# Operating system : Windows 7 Ultimate Service Pack 1 (x64)
# Username : Brad - BRAD-PC
# Running from : C:\Users\Brad\Downloads\adwcleaner_5.023.exe
# Option : Scan
 
***** [ Services ] *****
 
Service Found : YahooAUService
 
***** [ Folders ] *****
 
Folder Found : C:\Program Files (x86)\Industriya
Folder Found : C:\Program Files (x86)\myfree codec
Folder Found : C:\ProgramData\dtdata
Folder Found : C:\Users\Brad\AppData\Local\MalwareProtectionLive
Folder Found : C:\Users\Brad\AppData\LocalLow\HPAppData
Folder Found : C:\Users\Brad\AppData\LocalLow\Industriya
Folder Found : C:\Users\Brad\AppData\Roaming\BitLord
Folder Found : C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\ConduitEngine
Folder Found : C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\Extensions\ascsurfingprotection@iobit.com
 
***** [ Files ] *****
 
File Found : C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\user.js
 
***** [ DLL ] *****
 
 
***** [ Shortcuts ] *****
 
 
***** [ Scheduled tasks ] *****
 
Task Found : Default2Check
Task Found : DefaultCheck
Task Found : DefaultReg
 
***** [ Registry ] *****
 
Key Found : HKCU\Software\MICROSOFT\INTERNET EXPLORER\DOMSTORAGE\superfish.com
Key Found : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.superfish.com
Key Found : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.superfish.com
Key Found : HKLM\SOFTWARE\CLASSES\dream.capture.1
Key Found : HKLM\SOFTWARE\CLASSES\dream.capture
Key Found : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Key Found : HKCU\Software\InstalledBrowserExtensions
Key Found : HKCU\Software\PrivitizeVPNInstallDates
Key Found : HKCU\Software\YahooPartnerToolbar
Key Found : HKCU\Software\AppDataLow\Toolbar
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DefaultTab
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}
Key Found : HKU\.DEFAULT\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\Sense
Data Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [Tabs] - hxxp://searchou.com/?id=2060a92e000000000000406186f2c64e
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{987D262D-900B-4D74-B5EF-D8A83947A79C}
Key Found : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\istart.webssearches.com
Key Found : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\mystart.com
Key Found : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\reimagenetwork.com
 
***** [ Web browsers ] *****
 
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.CBOpenMAMSettings.enc", "MA==");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"true\"}");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.FirstTime", "true");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.FirstTimeFF3", "true");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.LAST_CLIENT_STATS_SUBMIT_2.enc", "MTM3NjYwNDEwOQ==");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.LOCAL_COOKIE_STATS_LAST_SUBMIT_6.enc", "MTM3NjYwNDEyMg==");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.LOCAL_COOKIE_STATS_STATS_SITE_IRRELEVANT.enc", "NA==");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.LOCAL_COOKIE_STATS_STATS_SITE_SUPPORTED.enc", "MQ==");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.LOCAL_COOKIE_THROTTLE_BASEadd_stats|0|LOCAL_COOKIE_STATS_STATS_SITE_IRRELEVANT.enc", "MTM3NjYwNDMyNw==");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.LOCAL_COOKIE_THROTTLE_BASEadd_stats|0|LOCAL_COOKIE_STATS_STATS_SITE_SUPPORTED.enc", "MTM3NjYwNDI2OQ==");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.LoginRevertSettingsEnabled", true);
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.PG_ENABLE", "dHJ1ZQ==");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.PG_ENABLE.enc", "dHJ1ZQ==");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.RevertSettingsEnabled", true);
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.SF_JUST_INSTALLED.enc", "RkFMU0U=");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.SF_STATUS.enc", "RU5BQkxFRA==");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.SF_USER_ID.enc", "Y2lkXzE1ODIwMTMxODE0OTYwMjk2NDc=");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.SearchAppState.enc", "Mw==");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.SearchAppTracking.enc", "MQ==");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.UserID", "UN45750963846935397");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091._key_cl_active.enc", "ODIxNjBiM2QtMzhlNy00Y2FkLWEzZTItZTgxN2RlYWM5ZTIz");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091._key_edilia__uID.enc", "ZTAyY2UyNTAtZDEwMS00MWQ1LWIyYjQtMzNkY2M3ZDY1N2Ux");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.acp_personal.appstate.enc", "ZW5hYmxl");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.addressBarTakeOverEnabledInHidden", "true");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.autoDisableScopes", -1);
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.cb_experience_000", "%BD%BB");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.cb_experience_000.enc", "NzU=");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.cb_firstuse0100", "%B7");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.cb_firstuse0100.enc", "MQ==");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.cb_user_id_000.enc", "Q0I1MTczNDQ2Nzg3NjVfMTM2MjE2ODk1OTk0NF9GaXJlZm94");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.cbcountry_001.enc", "UFI=");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.cbfirsttime.enc", "U3VuIERlYyAzMCAyMDEyIDIxOjEzOjE2IEdNVC0wNDAwIChTQSBXZXN0ZXJuIFN0YW5kYXJkIFRpbWUp");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.countryCode", "KR");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.defaultSearch", "false");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.discover-experiments-photopop", "ā%A8%F4%E7%F3%EB%A8%C0%A8%F6%EE%F5%FA%F5%F6%F5%F6%E5%F4%E7%A8%B2%A8%FC%EB%F8%F9%EF%F5%F4%A8%C0%B7%B6ă");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.discover-experiments-photopop.enc", "eyJuYW1lIjoicGhvdG9wb3BfbmEiLCJ2ZXJzaW9uIjoxMH0=");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.discover-periodic-reports", "ā%A8%F6%EF%F4%ED%E5%B6%A8%C0%E1%B7%B9%BE%BA%B7%B7%BB%B9%B6%B6%BD%B7%B6%B2%B7%BA%BA%B6%B6%B6%B6%B6%E3ă");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.discover-periodic-reports.enc", "eyJwaW5nXzAiOlsxMzg0MTE1MzAwNzEwLDE0NDAwMDAwXX0=");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.discover-user-id", "%A8%EB%B6%BE%B7%B9%B9%EC%E9%B3%BE%BC%BD%BB%B3%BA%EA%BD%BA%B3%BF%BF%BF%BC%B3%E8%BB%EB%B9%B9%B6%EC%B7%B8%E7%E8%B9%A8");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.discover-user-id.enc", "ImUwODEzM2ZjLTg2NzUtNGQ3NC05OTk2LWI1ZTMzMGYxMmFiMyI=");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.embeddedsData", "[{\"appId\":\"129079840422026594\",\"apiPermissions\":{\"crossDomainAjax\":true,\"getMainFrameTitle\":true,\"getMainFrameUrl\":true,\"getSearchTerm\":true,\"insta[...]
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.enableAlerts", "always");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.enableFix404ByUser", "FALSE");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.enableSearchFromAddressBar", "true");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.firstTimeDialogOpened", "true");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.fixPageNotFoundError", "true");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.fixPageNotFoundErrorByUser", "true");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.fixPageNotFoundErrorInHidden", "true");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.fixUrls", true);
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.ground-country-code", "%A8%DB%D9%A8");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.ground-country-code.enc", "IlVTIg==");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.hxxp___www_socialgrowthtechnologies_com_couponbuddy_v001.APP_WIN_FEATURES.enc", "b3BlbnBvc2l0aW9uPW9mZnNldDo1MDs1MCxzYXZlbG9jYXRpb249MCxyZXNpemFibGU9bm8sc2Nyb2xsYmFycz1ubyx0aXRsZW[...]
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.impression_counter", "%B7");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.impression_counter.enc", "MQ==");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.impression_session_counter", "%B6");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.impression_session_counter.enc", "MA==");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.impression_session_id", "%A8%E7%BF%BD%B8%E8%BA%BC%EC%B3%B6%BF%B7%B9%B3%BA%BB%BA%EB%B3%BF%BF%EC%EC%B3%EA%BD%BC%BD%E7%EA%B7%BC%EB%EB%E8%E7%A8");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.impression_session_id.enc", "ImE5NzJiNDZmLTA5MTMtNDU0ZS05OWZmLWQ3NjdhZDE2ZWViYSI=");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.impression_session_last_active", "%B7%B9%BE%BA%B7%B7%BC%BC%BB%B7%BF%BC%BD");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.impression_session_last_active.enc", "MTM4NDExNjY1MTk2Nw==");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.installId", "conduitinstallerstub.exe");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.installType", "conduitnsisintegration");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.isCheckedStartAsHidden", true);
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.isFirstTimeToolbarLoading", "false");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.isNewTabEnabled", false);
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.isPerformedSmartBarTransition", "true");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.lastVersion", "10.22.2.530");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.mam_gk_appStateReportTime", "%B7%B9%BF%B8%B9%B7%BF%BA%BC%BC%BB%BB%B8");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.mam_gk_appStateReportTime.enc", "MTM5MjMxOTQ2NjU1Mg==");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.mam_gk_appState_Clarity_Active", "%F5%F4");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.mam_gk_appState_Clarity_Active.enc", "b24=");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.mam_gk_appState_CouponBuddy.enc", "b24=");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.mam_gk_appState_Easytobook.enc", "b24=");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.mam_gk_appState_Easytobook_targeted.enc", "b24=");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.mam_gk_appState_PriceGong.enc", "b24=");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.mam_gk_appsConfig.enc", "eyJBcHBzQ29uZmlndXJhdGlvbiI6W3siaWQiOiJDbGFyaXR5X0FjdGl2ZSIsInVybCI6Imh0dHA6Ly9zdG9yYWdlLmNvbmR1aXQuY29tL21hbS8zcmRwYXJ0eWFwcHMvY2xhcml0eVJheS9jcl9hY3Rpdm[...]
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.mam_gk_appsDefaultEnabled", "%F4%FB%F2%F2");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.mam_gk_appsDefaultEnabled.enc", "bnVsbA==");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.mam_gk_calledSetupService.enc", "MQ==");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.mam_gk_currentVersion", "%B7%B4%B7%B9%B4%B6%B4%B7%BD");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.mam_gk_currentVersion.enc", "MS4xMy4wLjE3");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.mam_gk_existingUsersRecoveryDone.enc", "MQ==");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.mam_gk_first_time", "%B7");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.mam_gk_first_time.enc", "MQ==");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.mam_gk_globalKeysMigratedToLocalStorage", "%B7");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.mam_gk_globalKeysMigratedToLocalStorage.enc", "MQ==");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.mam_gk_lastLoginTime", "%B7%B9%BF%B8%B9%B7%BF%BA%BC%BD%BF%BF%BB");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.mam_gk_lastLoginTime.enc", "MTM5MjMxOTQ2Nzk5NQ==");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.mam_gk_localization.enc", "eyJkaWFsb2dPSyI6eyJUZXh0IjoiT0sifSwiZG1ib3gxIjp7IlRleHQiOiJEZWFsXHJcbm9mIHRoZSBkYXkifSwiZG1ib3gyIjp7IlRleHQiOiJGcmVlXHJcblNoaXBtZW50In0sImRtYnVsbGV0MSI6[...]
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.mam_gk_pgUnloadedOnce.enc", "dHJ1ZQ==");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.mam_gk_settings1.10.2.5.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImludGVydmFsIjoyNDAsInN0YW1wIjoiMzVfMCIsImlzVGVzdCI6dHJ1ZSwiVXNlckNvdW50cnlDb2RlIjoiVVMiLCJpc1dlbGNvbWVFeHBl[...]
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.mam_gk_settings1.10.4.0.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImN1cnJlbnREYXRlIjoiMjAxMzEwMjUiLCJpbnRlcnZhbCI6MjQwLCJzdGFtcCI6IjEwMDlfMSIsImlzVGVzdCI6dHJ1ZSwiVXNlckNvdW50[...]
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.mam_gk_settings1.11.4.2", "ā%A8%D9%FA%E7%FA%FB%F9%A8%C0%A8%F9%FB%E9%E9%EB%EB%EA%EB%EA%A8%B2%A8%CA%E7%FA%E7%A8%C0ā%A8%E9%FB%F8%F8%EB%F4%FA%CA%E7%FA%EB%A8%C0%A8%B8%B6%B7%B[...]
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.mam_gk_settings1.11.4.2.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImN1cnJlbnREYXRlIjoiMjAxMzExMTIiLCJpbnRlcnZhbCI6MjQwLCJzdGFtcCI6IjEwNDNfMCIsImlzVGVzdCI6dHJ1ZSwiVXNlckNvdW50[...]
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.mam_gk_settings1.13.0.17", "ā%A8%D9%FA%E7%FA%FB%F9%A8%C0%A8%F9%FB%E9%E9%EB%EB%EA%EB%EA%A8%B2%A8%CA%E7%FA%E7%A8%C0ā%A8%E9%FB%F8%F8%EB%F4%FA%CA%E7%FA%EB%A8%C0%A8%B8%B6%B7%[...]
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.mam_gk_settings1.13.0.17.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImN1cnJlbnREYXRlIjoiMjAxNDAyMTMiLCJpbnRlcnZhbCI6MjQwLCJzdGFtcCI6IjU0XzAiLCJSVEsiOiJINHNJQUFBQUFBQUVBT3k5QjJ[...]
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.mam_gk_settings1.4.4.6.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImludGVydmFsIjoyNDAsInN0YW1wIjoiMjQ5XzAiLCJpc1Rlc3QiOnRydWUsImlzV2VsY29tZUV4cGVyaWVuY2VFbmFibGVkQnlEZWZhdWx0I[...]
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.mam_gk_settings1.6.0.1.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImludGVydmFsIjoyNDAsInN0YW1wIjoiMjY3XzEiLCJpc1Rlc3QiOnRydWUsImlzV2VsY29tZUV4cGVyaWVuY2VFbmFibGVkQnlEZWZhdWx0I[...]
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.mam_gk_settings1.8.0.4.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImludGVydmFsIjoyNDAsInN0YW1wIjoiNTRfMCIsImlzVGVzdCI6dHJ1ZSwiVXNlckNvdW50cnlDb2RlIjoiUFIiLCJpc1dlbGNvbWVFeHBlc[...]
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.mam_gk_showCloseButton.enc", "dHJ1ZQ==");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.mam_gk_showWelcomeGadget", "%EC%E7%F2%F9%EB");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.mam_gk_showWelcomeGadget.enc", "ZmFsc2U=");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.mam_gk_stamp", "%BB%BA%E5%B6");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.mam_gk_stamp.enc", "NTRfMA==");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.mam_gk_userBornDate", "%D4%B5%C7");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.mam_gk_userBornDate.enc", "Ti9B");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.mam_gk_userId", "%E7%BD%EC%BA%E7%E8%EA%E9%B3%BD%BD%EB%BC%B3%BA%BF%B8%EC%B3%E7%BA%BF%B6%B3%B8%E8%BD%EA%E7%BF%EA%E9%BC%EA%BD%BD");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.mam_gk_userId.enc", "YTdmNGFiZGMtNzdlNi00OTJmLWE0OTAtMmI3ZGE5ZGM2ZDc3");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.mam_gk_user_approval_interacted", "%B7");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.mam_gk_user_approval_interacted.enc", "MQ==");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.mam_gk_welcomeDialogMode", "%B7");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.mam_gk_welcomeDialogMode.enc", "MQ==");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.migrateAppsAndComponents", true);
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.navigationAliasesJson", "{\"EB_SEARCH_TERM\":\"\",\"EB_MAIN_FRAME_URL\":\"about%3Asessionrestore\",\"EB_MAIN_FRAME_TITLE\":\"Restore%20Session\",\"EB_TOOLBAR_SUB_DOMAIN\":\"hxxp:/[...]
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.newSettings", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.openThankYouPage", "false");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.openUninstallPage", "false");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.price-gong.bornDate", "{\"dataType\":\"string\",\"data\":\"{\\\"Response\\\":\\\"12\\\\/31\\\\/2012 04\\\"}\"}");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.price-gong.isManagedApp", "true");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.response_cache.enc", "eyJjaGFubmVsIjp7ImxpbmsiOiJodHRwOi8vaW1hZ2VzLnNlYXJjaC55YWhvby5jb20veWhzL3NlYXJjaDtfeWx0PUEwUERvVngzN0g5U0oxd0FBWDJKemJrRj9wPWdhbGF4eStzMytjYXJkK2Nhc2VzJmZyP[...]
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.revertSettingsEnabled", "false");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.search.searchAppId", "129079840422026594");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.search.searchCount", "1");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.searchInNewTabEnabled", "false");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.searchInNewTabEnabledByUser", "false");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.searchInNewTabEnabledInHidden", "true");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.searchSuggestEnabledByUser", "false");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\"}");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"data\":\"CT2504091\"}");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"string\",\"data\":\"hxxp://VuzeRemote.OurToolbar.com//xpi\"}");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"string\",\"data\":\"Vuze Remote \"}");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data\":\"true\"}");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.serviceLayer_service_usage_toolbarUsageCount", "{\"dataType\":\"number\",\"data\":\"2\"}");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.serviceLayer_services_Configuration_lastUpdate", "1392290662887");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1392290662162");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.serviceLayer_services_appTracking_lastUpdate", "1357498227898");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.serviceLayer_services_appsMetadata_lastUpdate", "1392290661563");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1392290661635");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.serviceLayer_services_location_lastUpdate", "1376604222674");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.serviceLayer_services_login_10.13.40.15_lastUpdate", "1360281534840");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.serviceLayer_services_login_10.14.370.524_lastUpdate", "1364707551877");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.serviceLayer_services_login_10.14.42.7_lastUpdate", "1361573190434");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.serviceLayer_services_login_10.14.65.43_lastUpdate", "1363760775145");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.serviceLayer_services_login_10.15.0.562_lastUpdate", "1369091860481");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.serviceLayer_services_login_10.15.2.523_lastUpdate", "1368768217967");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.serviceLayer_services_login_10.16.2.509_lastUpdate", "1376604221615");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.serviceLayer_services_login_10.16.9.506_lastUpdate", "1382657024233");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.serviceLayer_services_login_10.21.1.507_lastUpdate", "1384115173476");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.serviceLayer_services_login_10.22.2.530_lastUpdate", "1392319463949");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1392290661596");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.serviceLayer_services_searchAPI_lastUpdate", "1392290662002");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.serviceLayer_services_serviceMap_lastUpdate", "1392290661575");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.serviceLayer_services_setupAPI_lastUpdate", "1363731851662");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.serviceLayer_services_toolbarContextMenu_lastUpdate", "1392290661855");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.serviceLayer_services_toolbarSettings_lastUpdate", "1392326662571");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.serviceLayer_services_translation_lastUpdate", "1392290661680");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.serviceLayer_services_userApps_lastUpdate", "1367630976508");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.settingsINI", true);
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.shouldFirstTimeDialog", "false");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.showToolbarPermission", "false");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.smartbar.CTID", "CT2504091");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.smartbar.Uninstall", "0");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.smartbar.toolbarName", "Vuze Remote ");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.startPage", "false");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.toolbarBornServerTime", "31-12-2012");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.toolbarCurrentServerTime", "13-2-2014");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.toolbarLoginClientTime", "Wed Mar 20 2013 17:43:14 GMT-0400 (SA Western Standard Time)");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.url_history0001", "%EE%FA%FA%F6%F9%C0%B5%B5%FD%FD%FD%B4%ED%F5%F5%ED%F2%EB%B4%E9%F5%F3%C0%C0%C0%E9%F2%EF%E9%F1%EE%E7%F4%EA%F2%EB%F8%C0%C0%C0%B7%B9%BE%BA%B7%B7%BE%BF%BC%B9%B9%BA%BC%[...]
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091.url_history0001.enc", "aHR0cHM6Ly93d3cuZ29vZ2xlLmNvbTo6OmNsaWNraGFuZGxlcjo6OjEzODQxMTg5NjMzNDYsLCxodHRwczovL3d3dy5nb29nbGUuY29tOjo6Y2xpY2toYW5kbGVyOjo6MTM4NDExODk2MzM1NCwsLGh0dHBz[...]
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CT2504091_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1392290658518,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}]");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2504091/CT2504091", "\"da1707ab4f62f5f59212fd2f6bea88322\"");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/US", "\"0\"");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2504091", "\"1326306883\"");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\"803651ba7facb1:0\"");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.engine.conduit-services.com/DLG.pkg?ver=3.3.3.2", "\"807dc126dd28cc1:0\"");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.13.0.6", "\"0d648794549cd1:14f1\"");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2504091", "\"84df7a85bec3b2a3dd055a4bedea5adc\"");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "634356118310000000");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=3/13/2011 11:17:11 AM", "634356118310000000");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en-us", "\"4be6dcf5c20c0cd98a0ae8a1b386d47e\"");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CommunityToolbar.EngineOwner", "ConduitEngine");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CommunityToolbar.EngineOwnerGuid", "engine@conduit.com");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CommunityToolbar.EngineOwnerToolbarId", "conduitengine");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CommunityToolbar.IsEngineShown", true);
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true);
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CommunityToolbar.OriginalEngineOwner", "ConduitEngine");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "engine@conduit.com");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "conduitengine");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "chrome://browser-region/locale/region.properties");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CommunityToolbar.ToolbarsList", "ConduitEngine");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CommunityToolbar.ToolbarsList2", "");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CommunityToolbar.alert.alertDialogsGetterLastCheckTime", "Sat Apr 23 2011 16:52:14 GMT+0900 (Korea Standard Time)");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CommunityToolbar.alert.alertInfoInterval", 1440);
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Sun Jun 26 2011 21:34:39 GMT+0900 (Korea Standard Time)");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CommunityToolbar.alert.locale", "en");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440);
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Sun Jun 26 2011 21:34:31 GMT+0900 (Korea Standard Time)");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1305622559");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CommunityToolbar.alert.showTrayIcon", false);
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CommunityToolbar.alert.userId", "8571d5f3-e8dc-4deb-bb93-b5a6dfe8d6bf");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CommunityToolbar.globalUserId", "d07350a8-5bca-4bfd-8758-5f9e613352f5");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("ConduitEngine.AppTrackingLastCheckTime", "Sat Apr 30 2011 15:15:17 GMT+0900 (Korea Standard Time)");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("ConduitEngine.CTID", "ConduitEngine");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("ConduitEngine.DialogsGetterLastCheckTime", "Sat Jun 25 2011 21:34:32 GMT+0900 (Korea Standard Time)");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("ConduitEngine.FirstServerDate", "04/23/2011 10");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("ConduitEngine.FirstTime", true);
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("ConduitEngine.FirstTimeFF3", true);
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("ConduitEngine.HasUserGlobalKeys", true);
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("ConduitEngine.Initialize", true);
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("ConduitEngine.InitializeCommonPrefs", true);
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("ConduitEngine.InstalledDate", "Sat Apr 23 2011 16:52:15 GMT+0900 (Korea Standard Time)");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("ConduitEngine.IsMulticommunity", false);
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("ConduitEngine.IsOpenThankYouPage", false);
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("ConduitEngine.IsOpenUninstallPage", true);
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("ConduitEngine.LanguagePackLastCheckTime", "Sun Jun 26 2011 21:34:32 GMT+0900 (Korea Standard Time)");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("ConduitEngine.LastLogin_3.3.3.2", "Mon Jun 27 2011 16:08:57 GMT+0900 (Korea Standard Time)");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("ConduitEngine.SearchFromAddressBarIsInit", true);
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("ConduitEngine.SettingsLastCheckTime", "Mon Jun 27 2011 16:08:57 GMT+0900 (Korea Standard Time)");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("ConduitEngine.UserID", "UN93777252440371874");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("ConduitEngine.componentAlertEnabled", false);
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("ConduitEngine.engineLocale", "en-US");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("ConduitEngine.enngineContextMenuLastCheckTime", "Sun Jun 26 2011 21:34:32 GMT+0900 (Korea Standard Time)");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("ConduitEngine.globalFirstTimeInfoLastCheckTime", "Mon Jun 27 2011 14:08:57 GMT+0900 (Korea Standard Time)");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("ConduitEngine.initDone", true);
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("ConduitEngine.isAppTrackingManagerOn", true);
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("ConduitEngine.usagesFlag", 1);
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("browser.search.hiddenOneOffs", "Bing,eBay,Search The Web (privitize),Twitter");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("extensions.enabledItems", "{AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.0.0.6906,{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20,{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21,{340c2bbc-ce74-4362-[...]
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("extensions.privitize.hmpgUrl", "hxxp://searchou.com/?id=2060a92e000000000000406186f2c64e");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("extensions.privitize.kw_url", "hxxp://searchou.com/?q={searchTerms}&id=2060a92e000000000000406186f2c64e");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("extensions.privitize.newTabUrl", "hxxp://searchou.com/?id=2060a92e000000000000406186f2c64e");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("extensions.privitize.srchPrvdr", "Search The Web (privitize)");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("extensions.privitize.tlbrSrchUrl", "hxxp://searchou.com/?id=2060a92e000000000000406186f2c64e&q=");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("plugin.state.npconduitfirefoxplugin", 2);
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("smartbar.machineId", "BVAE6F155XE4MK97CCBNX7ZW2DZV241OGNKES6EGOE66UMQFD11LL3GBZI+WXRY/Y0TWUW2G+QKRRNC43XHNAA");
[C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js] [Preference] Found : user_pref("startpage.ntsearch_url", "hxxps://kr.search.yahoo.com/search?fr=spigot-nt-ff&ei=utf-8&ilc=12&type=994519&p={searchTerms}");
 
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [51027 bytes] ##########


#11 vbbikerbums

vbbikerbums
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:57 PM

Posted 01 December 2015 - 03:05 AM

Junkware Removal Log

 

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.1 (11.24.2015)
Operating System: Windows 7 Ultimate x64 
Ran by Brad (Limited) on Tue 12/01/2015 at 17:03:20.69
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
File System: 4 
 
Successfully deleted: C:\ProgramData\esellerate (Folder) 
Successfully deleted: C:\ProgramData\productdata (Folder) 
Successfully deleted: C:\Users\Brad\AppData\Local\crashrpt (Folder) 
Successfully deleted: C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\extensions\staged (Folder) 
 
Deleted the following from C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\406pe53h.default\prefs.js
user_pref(browser.search.order.1, WhiteSmoke Search);
user_pref(extensions.privitize.admin, false);
user_pref(extensions.privitize.aflt, orgnl);
user_pref(extensions.privitize.appId, {301966DF-A84B-4255-AAB9-574B5CE237E4});
user_pref(extensions.privitize.autoRvrt, false);
user_pref(extensions.privitize.dfltLng, );
user_pref(extensions.privitize.dfltSrch, true);
user_pref(extensions.privitize.dnsErr, true);
user_pref(extensions.privitize.excTlbr, true);
user_pref(extensions.privitize.ffxUnstlRst, false);
user_pref(extensions.privitize.hmpg, true);
user_pref(extensions.privitize.hpOld0, www.google.com/ig);
user_pref(extensions.privitize.id, 2060a92e000000000000406186f2c64e);
user_pref(extensions.privitize.instlDay, 15810);
user_pref(extensions.privitize.instlRef, );
user_pref(extensions.privitize.newTab, true);
user_pref(extensions.privitize.prdct, privitize);
user_pref(extensions.privitize.prtnrId, privitize);
user_pref(extensions.privitize.rvrt, false);
user_pref(extensions.privitize.smplGrp, none);
user_pref(extensions.privitize.tlbrId, base);
user_pref(extensions.privitize.vrsn, 1.8.16.22);
user_pref(extensions.privitize.vrsnTs, 1.8.16.2221:30:23);
user_pref(extensions.privitize.vrsni, 1.8.16.22);
 
 
 
Registry: 2 
 
Successfully deleted: HKLM\SYSTEM\CurrentControlSet\services\wStLibG64 (Registry Key) 
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{C7576B9D-B442-46bc-AF74-080A9E723E01} (Registry Key)
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Tue 12/01/2015 at 17:04:50.01
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


#12 vbbikerbums

vbbikerbums
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:57 PM

Posted 01 December 2015 - 03:20 AM

I am unable to run spophos in safe mode.i Safe mose is the only way I can install and run any of these programs. In standard boot mode I have a UAC shield on them all and I am blocked out of accessing them despit being an admin. I get a message C:\users\brad\downloads\sophos virus removal tool.exe    "The specified service does not exist as an installed service". I get this message with every program or service I try to run in standard mode.



#13 vbbikerbums

vbbikerbums
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:57 PM

Posted 01 December 2015 - 07:47 AM

I was poking around in safe mode and was somehow able to get  into a new profile at start up to normal mode. so instead of Brad, with admin privileges, I logged into administrator and I'm actually able to use everything in normal mode. I installed Sophos and its running now but going very slow. Ill post thr logs when finished.



#14 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,679 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:10:57 PM

Posted 01 December 2015 - 11:33 AM

Good news :)

It looks like infection corrupted your original profile so you may want to delete your old profile and use new one.


My Website

p4433470.gif

My help doesn't cost a penny, but if you'd like to consider a donation, click p22001735.gif


 


#15 vbbikerbums

vbbikerbums
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:57 PM

Posted 01 December 2015 - 04:43 PM

Sophos Log

 

 

2015-12-01 12:03:23.606 Sophos Virus Removal Tool version 2.5.5
2015-12-01 12:03:23.606 Copyright © 2009-2014 Sophos Limited. All rights reserved.
 
2015-12-01 12:03:23.606 This tool will scan your computer for viruses and other threats. If it finds any, it will give you the option to remove them.
 
2015-12-01 12:03:23.606 Windows version 6.1 SP 1.0 Service Pack 1 build 7601 SM=0x100 PT=0x1 WOW64
2015-12-01 12:03:23.606 Checking for updates...
2015-12-01 12:03:26.019 Update progress: proxy server not available
2015-12-01 12:03:45.926 Option all = no
2015-12-01 12:03:45.926 Option recurse = yes
2015-12-01 12:03:45.927 Option archive = no
2015-12-01 12:03:45.927 Option service = yes
2015-12-01 12:03:45.927 Option confirm = yes
2015-12-01 12:03:45.927 Option sxl = yes
2015-12-01 12:03:45.928 Option max-data-age = 35
2015-12-01 12:03:45.928 Option EnableSafeClean = yes
2015-12-01 12:03:48.201 Option vdl-logging = yes
2015-12-01 12:03:48.207 Customer ID: 094260ca9b3af99f9d4a3909fc47a743
2015-12-01 12:03:48.207 Machine ID: 113ae303b3834f15a2303c0b4ba0c657
2015-12-01 12:03:48.237 Component SVRTcli.exe version 2.5.5
2015-12-01 12:03:48.238 Component control.dll version 2.5.5
2015-12-01 12:03:48.238 Component SVRTservice.exe version 2.5.5
2015-12-01 12:03:48.238 Component engine\osdp.dll version 1.44.1.2230
2015-12-01 12:03:48.238 Component engine\veex.dll version 3.63.0.2230
2015-12-01 12:03:48.239 Component engine\savi.dll version 9.0.0.2230
2015-12-01 12:03:48.239 Component rkdisk.dll version 1.5.30.0
2015-12-01 12:03:48.239 Version info: Product version 2.5.5
2015-12-01 12:03:48.240 Version info: Detection engine 3.63.0
2015-12-01 12:03:48.240 Version info: Detection data 5.21
2015-12-01 12:03:48.240 Version info: Build date 11/10/2015
2015-12-01 12:03:48.240 Version info: Data files added 226
2015-12-01 12:03:48.240 Version info: Last successful update (not yet updated)
2015-12-01 12:13:30.241 Downloading updates...
2015-12-01 12:13:30.243 Update progress: [I96736] Looking for package C1A903B2-E63E-483b-982D-04BB9C457C60 1.0 
2015-12-01 12:13:30.243 Update progress: [I49502] Found supplement SAVIW32 LATEST 
2015-12-01 12:13:30.243 Update progress: [I49502] Found supplement IDE522 LATEST 
2015-12-01 12:13:30.243 Update progress: [I49502] Found supplement IDE523 LATEST 
2015-12-01 12:13:30.243 Update progress: [I49502] Found supplement IDE524 LATEST 
2015-12-01 12:13:30.243 Update progress: [I19463] Syncing product C1A903B2-E63E-483b-982D-04BB9C457C60 1
2015-12-01 12:13:30.243 Update progress: [I19463] Syncing product SAVIW32 62
2015-12-01 12:13:39.517 Update progress: [I19463] Syncing product IDE522 134
2015-12-01 12:13:44.876 Installing updates...
2015-12-01 12:13:45.493 Error level 1
2015-12-01 12:13:45.506 Update progress: [I19463] Syncing product IDE523 94
2015-12-01 12:13:45.506 Update progress: [I19463] Syncing product IDE524 1
2015-12-01 12:13:58.102 Update successful
2015-12-01 12:14:41.720 Option all = no
2015-12-01 12:14:41.720 Option recurse = yes
2015-12-01 12:14:41.720 Option archive = no
2015-12-01 12:14:41.720 Option service = yes
2015-12-01 12:14:41.720 Option confirm = yes
2015-12-01 12:14:41.720 Option sxl = yes
2015-12-01 12:14:41.722 Option max-data-age = 35
2015-12-01 12:14:41.722 Option EnableSafeClean = yes
2015-12-01 12:14:41.772 Option vdl-logging = yes
2015-12-01 12:14:41.775 Customer ID: 094260ca9b3af99f9d4a3909fc47a743
2015-12-01 12:14:41.775 Machine ID: 113ae303b3834f15a2303c0b4ba0c657
2015-12-01 12:14:41.775 Component SVRTcli.exe version 2.5.5
2015-12-01 12:14:41.776 Component control.dll version 2.5.5
2015-12-01 12:14:41.776 Component SVRTservice.exe version 2.5.5
2015-12-01 12:14:41.776 Component engine\osdp.dll version 1.44.1.2230
2015-12-01 12:14:41.776 Component engine\veex.dll version 3.63.0.2230
2015-12-01 12:14:41.776 Component engine\savi.dll version 9.0.0.2230
2015-12-01 12:14:41.776 Component rkdisk.dll version 1.5.30.0
2015-12-01 12:14:41.777 Version info: Product version 2.5.5
2015-12-01 12:14:41.777 Version info: Detection engine 3.63.0
2015-12-01 12:14:41.777 Version info: Detection data 5.21
2015-12-01 12:14:41.777 Version info: Build date 11/10/2015
2015-12-01 12:14:41.777 Version info: Data files added 226
2015-12-01 12:14:41.777 Version info: Last successful update 12/1/2015 9:13:58 PM
 
2015-12-01 16:45:03.670 Could not open C:\hiberfil.sys
2015-12-01 16:45:19.129 Could not open C:\pagefile.sys
2015-12-01 17:24:21.680 Could not open C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}
2015-12-01 17:24:21.680 Could not open C:\System Volume Information\{f30dc04a-981d-11e5-bf7b-406186f2c64e}{3808876b-c176-4e48-b7ae-04046e6cc752}
2015-12-01 18:10:40.425 >>> Virus 'Troj/Agent-INJ' found in file C:\Users\Brad\Documents\Adobe.Creative.Suite.4.Master.Collection.RETAIL\Adobe Correct CS4 kegen and full actvation\CS4 keygen.exe
2015-12-01 18:10:40.426 >>> Virus 'Troj/Agent-INJ' found in file HKU\S-1-5-21-1081769995-3551560481-2068115922-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect
2015-12-01 18:10:40.426 >>> Virus 'Troj/Agent-INJ' found in file HKU\S-1-5-21-1081769995-3551560481-2068115922-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect
2015-12-01 18:10:40.426 >>> Virus 'Troj/Agent-INJ' found in file HKU\S-1-5-21-1081769995-3551560481-2068115922-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1609
2015-12-01 18:10:40.426 >>> Virus 'Troj/Agent-INJ' found in file HKU\S-1-5-21-1081769995-3551560481-2068115922-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1609
2015-12-01 18:10:40.426 >>> Virus 'Troj/Agent-INJ' found in file HKU\S-1-5-21-1081769995-3551560481-2068115922-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1406
2015-12-01 18:10:40.426 >>> Virus 'Troj/Agent-INJ' found in file HKU\S-1-5-21-1081769995-3551560481-2068115922-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1406
2015-12-01 18:10:40.426 >>> Virus 'Troj/Agent-INJ' found in file HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect
2015-12-01 18:18:48.898 Could not open C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb
2015-12-01 18:18:48.898 Could not open C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb
2015-12-01 18:18:55.196 Could not open C:\Windows\System32\config\RegBack\DEFAULT
2015-12-01 18:18:55.198 Could not open C:\Windows\System32\config\RegBack\SAM
2015-12-01 18:18:55.199 Could not open C:\Windows\System32\config\RegBack\SECURITY
2015-12-01 18:18:55.201 Could not open C:\Windows\System32\config\RegBack\SOFTWARE
2015-12-01 18:18:55.229 Could not open C:\Windows\System32\config\RegBack\SYSTEM
2015-12-01 19:03:40.275 >>> Virus 'Mal/Generic-E' found in file F:\Program Files\UltraISO\Ultraiso Premium Edition Patch.exe
2015-12-01 19:03:40.275 >>> Virus 'Mal/Generic-E' found in file HKU\S-1-5-21-1081769995-3551560481-2068115922-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect
2015-12-01 19:03:40.276 >>> Virus 'Mal/Generic-E' found in file HKU\S-1-5-21-1081769995-3551560481-2068115922-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect
2015-12-01 19:03:40.276 >>> Virus 'Mal/Generic-E' found in file HKU\S-1-5-21-1081769995-3551560481-2068115922-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1609
2015-12-01 19:03:40.276 >>> Virus 'Mal/Generic-E' found in file HKU\S-1-5-21-1081769995-3551560481-2068115922-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1609
2015-12-01 19:03:40.276 >>> Virus 'Mal/Generic-E' found in file HKU\S-1-5-21-1081769995-3551560481-2068115922-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1406
2015-12-01 19:03:40.277 >>> Virus 'Mal/Generic-E' found in file HKU\S-1-5-21-1081769995-3551560481-2068115922-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1406
2015-12-01 19:03:40.277 >>> Virus 'Mal/Generic-E' found in file HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect
2015-12-01 19:03:43.879 Could not open LOGICAL:000C:00000000
2015-12-01 19:03:43.881 Could not open M:\
2015-12-01 19:03:44.267 Could not open PHYSICAL:0082:0000:0000:0001
2015-12-01 19:03:44.327 The following items will be cleaned up:
2015-12-01 19:03:44.327 Troj/Agent-INJ
2015-12-01 19:03:44.327 Mal/Generic-E





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users