This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Email seems to be hacked. [Solved]

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, my email seems to be hacked and used by others as i kept recieving updates/warning from gamesite that i don't play. Recently my junk mail has also recieved lots of spams. My twitter also had random post created or retweet not by me. Basically any social media registered with this email seems to be get spams. I am wondering if my PC is keylogged or something.

I tried to run hijackthis and it says "for some reason your system denied write access to the hosts file. If any hijacked domains are in this file, HijackThis may NOT be able to fix this." I followed the instruction given to delete it from the host, however couldn't find any hijackthis in host.

This is the logfile generated:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 3:42:22 PM, on 11/9/2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16450)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
C:\Program Files (x86)\Portrait Displays\Pivot Software\wpCtrl.exe
C:\Program Files (x86)\Razer\Diamondback 3G\razerhid.exe
C:\Program Files (x86)\Razer\Razer Lycosa\razerhid.exe
C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\AVG\AVG2013\avgui.exe
C:\Program Files (x86)\Razer\Razer Lycosa\razertra.exe
C:\Program Files (x86)\Portrait Displays\Pivot Software\floater.exe
C:\Program Files (x86)\AVG Secure Search\vprot.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Razer\Diamondback 3G\razertra.exe
C:\Program Files (x86)\Razer\Diamondback 3G\razerofa.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_4_402_287_ActiveX.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\iTunes\iTunes.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\SyncServer.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\Kennethzzz\Desktop\HiJackThis.exe
C:\Windows\SysWOW64\DllHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.neopets.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 210.158.6.201:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: 816A0193-8207-5FB3-45AD-B8CAB0E15A24 Class - {816A0193-8207-5FB3-45AD-B8CAB0E15A24} - C:\Program Files (x86)\Funshion Online\Funshion\FunshionAddr\funshionAddr.dll (file missing)
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\13.2.0.5\AVG Secure Search_toolbar.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\13.2.0.5\AVG Secure Search_toolbar.dll
O4 - HKLM\..\Run: [PivotSoftware] "C:\Program Files (x86)\Portrait Displays\Pivot Software\wpctrl.exe"
O4 - HKLM\..\Run: [DT PHL] C:\Program Files (x86)\Common Files\Portrait Displays\Shared\DT_startup.exe -PHL
O4 - HKLM\..\Run: [Diamondback] C:\Program Files (x86)\Razer\Diamondback 3G\razerhid.exe
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [Lycosa] "C:\Program Files (x86)\Razer\Razer Lycosa\razerhid.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLY
O4 - HKLM\..\Run: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe"
O4 - HKLM\..\Run: [ROC_ROC_NT] "C:\Program Files (x86)\AVG Secure Search\ROC_ROC_NT.exe" / /PROMPT /CMPID=ROC_NT
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\RunOnce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-uninstallati…t;ver=10.0.1427
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
O4 - HKCU\..\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: ShopperReports - Compare product prices - {DB38E21A-0133-419d-92AD-ECDFD5244D6D} - (no file)
O9 - Extra button: ShopperReports - Compare travel rates - {EB620C54-E229-4942-87CE-E717109FC8C6} - (no file)
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\13.2.0\ViProtocol.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2013\avgfws.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files (x86)\Common Files\Portrait Displays\Shared\DTSRVC.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Portrait Displays SDK Service (PdiService) - Portrait Displays, Inc. - C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: vToolbarUpdater13.2.0 - Unknown owner - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\13.2.0\ToolbarUpdater.exe
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 14943 bytes

Hi, my email seems to be hacked and used by others as i kept recieving updates/warning from gamesite that i don't play. Recently my junk mail has also recieved lots of spams. My twitter also had random post created or retweet not by me. Basically any social media registered with this email seems to be get spams. I am wondering if my PC is keylogged or something.

Sounds like your email and twitter have been compromised. If you use the same password for both accounts, I would recommend changing each password to something different once we are done cleaning.

I tried to run hijackthis and it says "for some reason your system denied write access to the hosts file. If any hijacked domains are in this file, HijackThis may NOT be able to fix this." I followed the instruction given to delete it from the host, however couldn't find any hijackthis in host.

HijackThis is quite obsolete now so let's run the following scans.

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments,  attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
===================================================

Please download aswMBR.exe and save it to your desktop. 

Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)

Click Scan
  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review.
  • Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat.
  • Right click that file and select Send To>Compressed (zipped) file.
  • Attach that zipped file in your next reply as well.
Hi, thanks for the reply!

DDS (Ver_2012-11-07.01) - NTFS_AMD64
Internet Explorer: 9.0.8112.16450 BrowserJavaVersion: 1.6.0_37
Run by [removed] at 9:36:39 on 2012-11-11
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4095.2332 [GMT 8:00]
.
AV: AVG Internet Security 2013 *Enabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: AVG Internet Security 2013 *Enabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
FW: AVG Internet Security 2013 *Enabled* {36AFA1E1-4CDC-7EF8-11EE-C77C3581ABA2}
.
============== Running Processes ===============
.
C:\PROGRA~2\AVG\AVG2013\avgrsa.exe
C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\AVG\AVG2013\avgfws.exe
C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe
C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files (x86)\Common Files\Portrait Displays\Shared\DTSRVC.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\13.2.0\ToolbarUpdater.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\AVG\AVG2013\avgnsa.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\AVG\AVG2013\avgemca.exe
C:\FGUARD\FGKey64.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
C:\Program Files (x86)\Portrait Displays\Pivot Software\wpCtrl.exe
C:\Program Files (x86)\Razer\Diamondback 3G\razerhid.exe
C:\Program Files (x86)\Razer\Razer Lycosa\razerhid.exe
C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
C:\Program Files (x86)\Portrait Displays\Pivot Software\floater.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\AVG\AVG2013\avgui.exe
C:\Program Files (x86)\AVG Secure Search\vprot.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe
C:\Program Files (x86)\Razer\Razer Lycosa\razertra.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Razer\Diamondback 3G\razertra.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\Razer\Diamondback 3G\razerofa.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM64.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_4_402_287_ActiveX.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.neopets.com/
uProxyServer = 210.158.6.201:8080
mWinlogon: Userinit = userinit.exe
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO: 816A0193-8207-5FB3-45AD-B8CAB0E15A24 Class: {816A0193-8207-5FB3-45AD-B8CAB0E15A24} -
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\13.2.0.5\AVG Secure Search_toolbar.dll
BHO: Adobe PDF Conversion Toolbar Helper: {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: SmartSelect Class: {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
TB: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\13.2.0.5\AVG Secure Search_toolbar.dll
EB: {BDEA95CF-F0E6-41E0-BD3D-B00F39A4E939} -
uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
uRun: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
uRun: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe
uRun: [AdobeBridge]
mRun: [PivotSoftware] "C:\Program Files (x86)\Portrait Displays\Pivot Software\wpctrl.exe"
mRun: [DT PHL] C:\Program Files (x86)\Common Files\Portrait Displays\Shared\DT_startup.exe -PHL
mRun: [Diamondback] C:\Program Files (x86)\Razer\Diamondback 3G\razerhid.exe
mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
mRun: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
mRun: [Lycosa] "C:\Program Files (x86)\Razer\Razer Lycosa\razerhid.exe"
mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun: [NPSStartup]
mRunOnce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-uninstallati…t;ver=10.0.1427
uPolicies-Explorer: NoDriveTypeAutoRun = dword:255
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:255
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~3\Office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {DB38E21A-0133-419d-92AD-ECDFD5244D6D} - {3E2DFD6A-4E20-4d4c-AA8B-E1F9DBEF3C80} -
IE: {EB620C54-E229-4942-87CE-E717109FC8C6} - {714E0876-FCEE-49ce-A429-B9AD8AEFCB56} -
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
TCP: NameServer = 192.168.1.254
TCP: Interfaces\{CDB2491B-BF44-4ED3-8AD8-E17C5DE90B2C} : DHCPNameServer = [removed] [removed]
TCP: Interfaces\{E59D75B8-8D77-421D-BAD1-B272E5A23556} : DHCPNameServer = 192.168.1.254
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\13.2.0\ViProtocol.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck -
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
x64-BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
x64-Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
x64-Run: [FG_Monitor] C:\FGUARD\FGKey64.exe /Start
x64-Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} -
x64-Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} -
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} -
x64-SSODL: WebCheck -
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Kennethzzz\AppData\Roaming\Mozilla\Firefox\Profiles\74k3yzr0.default\
FF - prefs.js: browser.search.selectedEngine - AVG Secure Search
FF - prefs.js: browser.startup.homepage - www.neopets.com
FF - component: C:\Program Files (x86)\AVG\AVG10\Firefox4\components\avgssff4.dll
FF - plugin: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\AhnLab\ASP\Components\aosmgr\conflict_221\npaosmgr.dll
FF - plugin: C:\Program Files (x86)\AhnLab\ASP\MyKeyDefense 2.5\npmkd25aos.dll
FF - plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\13.2.0\npsitesafety.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\NOS\bin\np_gp.dll
FF - plugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
FF - plugin: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_287.dll
FF - plugin: C:\Windows\SysWOW64\npdeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
FF - ExtSQL: 2012-09-22 11:51; avg@toolbar; C:\ProgramData\AVG Secure Search\FireFoxExt\13.2.0.5
FF - ExtSQL: 2012-10-21 16:43; {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}; C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSHA;AVGIDSHA;C:\Windows\System32\drivers\avgidsha.sys [2012-10-15 63328]
R0 Avgloga;AVG Logging Driver;C:\Windows\System32\drivers\avgloga.sys [2012-9-21 225120]
R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\drivers\avgmfx64.sys [2012-10-5 111456]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\drivers\avgrkx64.sys [2012-9-14 40800]
R1 Avgfwfd;AVG network filter service;C:\Windows\System32\drivers\avgfwd6a.sys [2011-5-23 50296]
R1 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\drivers\avgidsdrivera.sys [2012-10-22 154464]
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\drivers\avgldx64.sys [2012-10-2 185696]
R1 Avgtdia;AVG TDI Driver;C:\Windows\System32\drivers\avgtdia.sys [2012-9-21 200032]
R1 avgtp;avgtp;C:\Windows\System32\drivers\avgtpx64.sys [2012-9-22 30568]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\System32\drivers\dtsoftbus01.sys [2011-2-8 254528]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2012-3-9 235520]
R2 avgfws;AVG Firewall;C:\Program Files (x86)\AVG\AVG2013\avgfws.exe [2012-11-2 1340976]
R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [2012-11-6 5814392]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [2012-10-22 196664]
R2 FGUARD64;FGUARD64;C:\FGUARD\FGUARD64.SYS [2012-1-26 69752]
R2 PdiService;Portrait Displays SDK Service;C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe [2011-2-7 90112]
R2 vToolbarUpdater13.2.0;vToolbarUpdater13.2.0;C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\13.2.0\ToolbarUpdater.exe [2012-11-5 711112]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2011-12-6 95248]
R3 DKRtWrt;DKRtWrt;C:\Windows\System32\drivers\DKRtWrt.sys [2011-2-8 51120]
R3 Lycosa;Lycosa Keyboard;C:\Windows\System32\drivers\Lycosa.sys [2011-5-11 28928]
R3 Razerlow;Razer Pro|Solutions;C:\Windows\System32\drivers\DB3G.sys [2005-11-7 21120]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2009-6-11 187392]
R3 VKbms;Virtual HID Minidriver;C:\Windows\System32\drivers\VKbms.sys [2011-5-11 13312]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 Mkd2Nadr;Mkd2Nadr;C:\Windows\System32\drivers\Mkd2Nadr.sys [2011-3-22 106040]
S3 Mkd3kfNt;Mkd3kfNt;C:\Windows\System32\drivers\mkd3kfnt.sys [2011-3-22 180280]
S3 Netaapl;Apple Mobile Device Ethernet Service;C:\Windows\System32\drivers\netaapl64.sys [2010-4-19 22528]
S3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-3-4 59392]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-7-9 52736]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2011-2-8 1255736]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2012-11-10 14:09:27 ——– d—–w- C:\Users\Kennethzzz\AppData\Local\{4EB3374D-5216-4691-8FBF-8DADDBE5053F}
2012-11-10 02:09:03 ——– d—–w- C:\Users\Kennethzzz\AppData\Local\{1B351BBA-5EA5-4CE4-8D67-FCE0743F0D6F}
2012-11-09 14:08:39 ——– d—–w- C:\Users\Kennethzzz\AppData\Local\{DFE1A6BE-854F-4E5A-8D91-209B5650701E}
2012-11-09 02:08:15 ——– d—–w- C:\Users\Kennethzzz\AppData\Local\{AB7679BB-E0C7-4D22-B6A8-EAC66AE821C1}
2012-11-08 14:07:52 ——– d—–w- C:\Users\Kennethzzz\AppData\Local\{75B6B208-32F3-4539-B3D5-78EA7F895029}
2012-11-08 02:07:28 ——– d—–w- C:\Users\Kennethzzz\AppData\Local\{3A5DF9BE-54E6-431E-A729-24F5DF8522E3}
2012-11-07 13:21:18 ——– d—–w- C:\Users\Kennethzzz\AppData\Local\{D56E1AB0-178C-4666-9707-57820DD91A8C}
2012-11-07 01:21:07 ——– d—–w- C:\Users\Kennethzzz\AppData\Local\{9421CC08-CA63-4FD6-A87A-2BA74128B141}
2012-11-06 11:34:29 ——– d—–w- C:\Users\Kennethzzz\AppData\Local\{739AD0C7-6C91-4FAB-8358-A0FF322B02B0}
2012-11-05 23:34:05 ——– d—–w- C:\Users\Kennethzzz\AppData\Local\{00AAC094-1A7C-45FE-8C80-7474CEA8F63E}
2012-11-05 10:45:50 ——– d—–w- C:\Users\Kennethzzz\AppData\Local\{9D612D53-0C24-4E68-90C7-85FDC0E37861}
2012-11-04 15:16:56 ——– d—–w- C:\Users\Kennethzzz\AppData\Local\{749E6922-EAF0-4F64-B493-4C3CAF21BAEE}
2012-11-04 03:16:44 ——– d—–w- C:\Users\Kennethzzz\AppData\Local\{21A2B77B-D496-4B0F-A58C-43FDBF0F2BBD}
2012-11-03 15:16:17 ——– d—–w- C:\Users\Kennethzzz\AppData\Local\{F240CC39-2E36-45D4-8B15-115406CCA929}
2012-11-03 03:15:52 ——– d—–w- C:\Users\Kennethzzz\AppData\Local\{9F4F4AAC-FC07-47F8-99AE-6E9798A8F411}
2012-11-02 11:45:44 ——– d—–w- C:\Users\Kennethzzz\AppData\Local\{71E0570C-9AEA-4F45-9D6B-FA906C768F8F}
2012-11-01 23:45:20 ——– d—–w- C:\Users\Kennethzzz\AppData\Local\{BC63E4E7-2665-4936-8AA9-9F28B5291D18}
2012-11-01 10:35:03 ——– d—–w- C:\Users\Kennethzzz\AppData\Local\{F61E7356-A7E3-4C71-92A3-AFAF2EB6E846}
2012-10-31 11:53:51 ——– d—–w- C:\Users\Kennethzzz\AppData\Local\{16FB456B-EF48-42F8-AFED-819021730BCB}
2012-10-30 23:53:28 ——– d—–w- C:\Users\Kennethzzz\AppData\Local\{B9F6107C-D562-4A55-BC2E-1D4A2D3E54CE}
2012-10-30 11:53:04 ——– d—–w- C:\Users\Kennethzzz\AppData\Local\{03D42C8D-89FA-4E37-BCFA-D7A153D875E7}
2012-10-29 23:52:40 ——– d—–w- C:\Users\Kennethzzz\AppData\Local\{361C74C2-3ECD-46AB-8CFD-727B229991D1}
2012-10-29 09:52:47 ——– d—–w- C:\Users\Kennethzzz\AppData\Local\{07EDA131-47A9-4793-90D0-8937D5A9FBB2}
2012-10-28 23:45:13 ——– d—–w- C:\Users\Kennethzzz\AppData\Local\{C6291F91-637A-400D-AACF-023C4234BAF6}
2012-10-28 04:29:08 ——– d—–w- C:\Users\Kennethzzz\AppData\Local\{793D3E73-DA92-4F0C-BD26-FA949D8C93D9}
2012-10-27 16:28:40 ——– d—–w- C:\Users\Kennethzzz\AppData\Local\{5003A178-B7CE-4311-A036-E46A1593140F}
2012-10-27 04:28:16 ——– d—–w- C:\Users\Kennethzzz\AppData\Local\{4413E45B-C66C-4BB3-8626-9BC0BF8A93A3}
2012-10-26 04:27:42 ——– d—–w- C:\Users\Kennethzzz\AppData\Local\{2D4848C5-19D0-4BFE-86B1-E2DEEAE5D9EA}
2012-10-25 11:44:37 ——– d—–w- C:\Users\Kennethzzz\AppData\Local\{512D19AD-4C10-45E0-BB53-FF36EED15BB4}
2012-10-24 23:44:12 ——– d—–w- C:\Users\Kennethzzz\AppData\Local\{857D172E-EABE-4CEF-94C1-3A12517DC807}
2012-10-24 19:12:26 94208 —-a-w- C:\Windows\SysWow64\QuickTimeVR.qtx
2012-10-24 19:12:26 69632 —-a-w- C:\Windows\SysWow64\QuickTime.qts
2012-10-24 10:40:55 ——– d—–w- C:\Users\Kennethzzz\AppData\Local\{F937F675-5649-43E9-A65E-2DCDE68EAA73}
2012-10-23 10:46:15 ——– d—–w- C:\Users\Kennethzzz\AppData\Local\{336A0724-0846-4330-9243-7979A31A3C64}
2012-10-22 14:52:48 ——– d—–w- C:\Users\Kennethzzz\AppData\Local\{41BE90D1-6464-4311-8CE6-11A909584133}
2012-10-22 05:02:44 154464 —-a-w- C:\Windows\System32\drivers\avgidsdrivera.sys
2012-10-21 01:51:58 ——– d—–w- C:\Users\Kennethzzz\AppData\Local\{7DF96CBC-D8D6-440B-A02F-AFE308F46773}
2012-10-20 06:42:54 ——– d—–w- C:\Users\Kennethzzz\AppData\Local\{7E800134-6B67-4937-941E-BD88D7000A85}
2012-10-19 11:56:18 ——– d—–w- C:\Users\Kennethzzz\AppData\Local\{64F4536F-2DE8-43D3-9B9E-AE07E293077D}
2012-10-18 23:55:53 ——– d—–w- C:\Users\Kennethzzz\AppData\Local\{9C0EA9A3-C878-4A18-B9AD-3347FAEE824D}
2012-10-18 11:45:47 ——– d—–w- C:\Users\Kennethzzz\AppData\Local\{9DFF48DB-24F6-4CE0-A9D8-D8954948FC7D}
2012-10-17 23:45:18 ——– d—–w- C:\Users\Kennethzzz\AppData\Local\{8F2B0162-CB68-4091-84B3-28ED8BD61C17}
2012-10-17 10:26:33 ——– d—–w- C:\Users\Kennethzzz\AppData\Local\{DDD721C6-6785-49F8-9A5A-08738AAC9DE4}
2012-10-16 14:37:40 ——– d—–w- C:\Users\Kennethzzz\AppData\Local\{4EA85758-069B-459C-A279-E4019D36B1AA}
2012-10-15 23:38:22 ——– d—–w- C:\Users\Kennethzzz\AppData\Local\{A51048F8-5708-47EF-9B71-D305C9EA2609}
2012-10-15 14:53:24 ——– d—–w- C:\Users\Kennethzzz\AppData\Local\{7F3E9B19-85FB-4DFD-B49D-34CF652CD50A}
2012-10-14 19:48:50 63328 —-a-w- C:\Windows\System32\drivers\avgidsha.sys
2012-10-14 15:09:45 ——– d—–w- C:\Users\Kennethzzz\AppData\Local\{E7C8DB3D-6F1E-409B-8CB1-B5BC359D4487}
2012-10-14 03:09:32 ——– d—–w- C:\Users\Kennethzzz\AppData\Local\{16D5D4CC-56B8-4C96-9E4F-33B9FA83C52C}
2012-10-13 12:47:22 ——– d—–w- C:\Users\Kennethzzz\AppData\Local\{0E1FF668-301A-48D1-81DF-1EB1FBA9BF8A}
2012-10-13 00:46:58 ——– d—–w- C:\Users\Kennethzzz\AppData\Local\{C852E588-0A46-4BA9-86AE-93668A539E7F}
2012-10-12 11:44:32 ——– d—–w- C:\Users\Kennethzzz\AppData\Local\{31B48BE8-CA46-48EE-899C-5EA6EC7081DC}
.
==================== Find3M ====================
.
2012-11-05 13:44:53 30568 —-a-w- C:\Windows\System32\drivers\avgtpx64.sys
2012-10-10 00:11:05 73656 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-10-10 00:11:05 696760 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-10-04 19:32:50 111456 —-a-w- C:\Windows\System32\drivers\avgmfx64.sys
2012-10-01 19:30:38 185696 —-a-w- C:\Windows\System32\drivers\avgldx64.sys
2012-09-24 07:32:24 477168 —-a-w- C:\Windows\SysWow64\npdeployJava1.dll
2012-09-24 07:32:20 473072 —-a-w- C:\Windows\SysWow64\deployJava1.dll
2012-09-20 19:46:04 200032 —-a-w- C:\Windows\System32\drivers\avgtdia.sys
2012-09-20 19:46:00 225120 —-a-w- C:\Windows\System32\drivers\avgloga.sys
2012-09-14 19:19:29 2048 —-a-w- C:\Windows\System32\tzres.dll
2012-09-14 18:28:53 2048 —-a-w- C:\Windows\SysWow64\tzres.dll
2012-09-13 19:05:18 40800 —-a-w- C:\Windows\System32\drivers\avgrkx64.sys
2012-09-04 02:39:32 50296 —-a-w- C:\Windows\System32\drivers\avgfwd6a.sys
2012-08-31 18:19:35 1659760 —-a-w- C:\Windows\System32\drivers\ntfs.sys
2012-08-30 18:03:45 5559664 —-a-w- C:\Windows\System32\ntoskrnl.exe
2012-08-30 17:12:02 3968880 —-a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2012-08-30 17:12:02 3914096 —-a-w- C:\Windows\SysWow64\ntoskrnl.exe
2012-08-24 18:05:07 220160 —-a-w- C:\Windows\System32\wintrust.dll
2012-08-24 16:57:48 172544 —-a-w- C:\Windows\SysWow64\wintrust.dll
2012-08-24 10:31:32 2312704 —-a-w- C:\Windows\System32\jscript9.dll
2012-08-24 10:21:18 1392128 —-a-w- C:\Windows\System32\wininet.dll
2012-08-24 10:20:11 1494528 —-a-w- C:\Windows\System32\inetcpl.cpl
2012-08-24 10:14:45 173056 —-a-w- C:\Windows\System32\ieUnatt.exe
2012-08-24 10:13:29 599040 —-a-w- C:\Windows\System32\vbscript.dll
2012-08-24 10:09:42 2382848 —-a-w- C:\Windows\System32\mshtml.tlb
2012-08-24 06:59:17 1800704 —-a-w- C:\Windows\SysWow64\jscript9.dll
2012-08-24 06:51:27 1129472 —-a-w- C:\Windows\SysWow64\wininet.dll
2012-08-24 06:51:02 1427968 —-a-w- C:\Windows\SysWow64\inetcpl.cpl
2012-08-24 06:47:26 142848 —-a-w- C:\Windows\SysWow64\ieUnatt.exe
2012-08-24 06:47:12 420864 —-a-w- C:\Windows\SysWow64\vbscript.dll
2012-08-24 06:43:58 2382848 —-a-w- C:\Windows\SysWow64\mshtml.tlb
2012-08-22 18:12:50 1913200 —-a-w- C:\Windows\System32\drivers\tcpip.sys
2012-08-22 18:12:40 950128 —-a-w- C:\Windows\System32\drivers\ndis.sys
2012-08-22 18:12:40 376688 —-a-w- C:\Windows\System32\drivers\netio.sys
2012-08-22 18:12:33 288624 —-a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS
2012-08-21 21:01:00 245760 —-a-w- C:\Windows\System32\OxpsConverter.exe
2012-08-21 05:01:20 33240 —-a-w- C:\Windows\System32\drivers\GEARAspiWDM.sys
2012-08-21 05:01:20 125872 —-a-w- C:\Windows\System32\GEARAspi64.dll
2012-08-21 05:01:20 106928 —-a-w- C:\Windows\SysWow64\GEARAspi.dll
2012-08-20 18:48:44 362496 —-a-w- C:\Windows\System32\wow64win.dll
2012-08-20 18:48:44 243200 —-a-w- C:\Windows\System32\wow64.dll
2012-08-20 18:48:44 13312 —-a-w- C:\Windows\System32\wow64cpu.dll
2012-08-20 18:48:43 215040 —-a-w- C:\Windows\System32\winsrv.dll
2012-08-20 18:48:37 16384 —-a-w- C:\Windows\System32\ntvdm64.dll
2012-08-20 18:48:35 424448 —-a-w- C:\Windows\System32\KernelBase.dll
2012-08-20 18:46:22 338432 —-a-w- C:\Windows\System32\conhost.exe
2012-08-20 17:40:21 14336 —-a-w- C:\Windows\SysWow64\ntvdm64.dll
2012-08-20 17:38:44 44032 —-a-w- C:\Windows\apppatch\acwow64.dll
2012-08-20 17:38:26 25600 —-a-w- C:\Windows\SysWow64\setup16.exe
2012-08-20 17:37:19 5120 —-a-w- C:\Windows\SysWow64\wow32.dll
2012-08-20 17:37:18 274944 —-a-w- C:\Windows\SysWow64\KernelBase.dll
2012-08-20 15:38:21 7680 —-a-w- C:\Windows\SysWow64\instnm.exe
2012-08-20 15:38:20 2048 —-a-w- C:\Windows\SysWow64\user.exe
2012-08-20 15:33:28 6144 —ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2012-08-20 15:33:28 4608 —ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2012-08-20 15:33:28 3584 —ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2012-08-20 15:33:28 3072 —ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
.
============= FINISH: 9:37:08.35 ===============




aswMBR version 0.9.9.1707 Copyright© 2011 AVAST Software
Run date: 2012-11-11 09:39:24
—————————–
09:39:24.594 OS Version: Windows x64 6.1.7601 Service Pack 1
09:39:24.594 Number of processors: 2 586 0x170A
09:39:24.594 ComputerName: KENNETHZZZ-PC UserName: Kennethzzz
09:39:26.388 Initialize success
09:39:46.677 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-2
09:39:46.677 Disk 0 Vendor: Hitachi_HDP725050GLA360 GM4OA5CA Size: 476940MB BusType: 3
09:39:46.770 Disk 0 MBR read successfully
09:39:46.770 Disk 0 MBR scan
09:39:46.770 Disk 0 Windows 7 default MBR code
09:39:46.786 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
09:39:46.786 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 476838 MB offset 206848
09:39:46.817 Disk 0 scanning C:\Windows\system32\drivers
09:40:01.871 Service scanning
09:40:23.524 Modules scanning
09:40:23.524 Disk 0 trace - called modules:
09:40:23.539 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys ataport.SYS pciide.sys PCIIDEX.SYS hal.dll atapi.sys
09:40:23.555 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004919710]
09:40:23.555 3 CLASSPNP.SYS[fffff8800193943f] -> nt!IofCallDriver -> [0xfffffa80043f2b20]
09:40:24.054 5 ACPI.sys[fffff88000d697a1] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-2[0xfffffa800446c680]
09:40:24.054 Scan finished successfully
09:40:53.492 Disk 0 MBR has been saved successfully to "C:\Users\Kennethzzz\Desktop\MBR.dat"
09:40:53.507 The log file has been saved successfully to "C:\Users\Kennethzzz\Desktop\aswMBR.txt"
Hello,

Please do the following

Refer to the ComboFix User's Guide

  • Download ComboFix from one of these locations:

    Link 1
    Link 2

    * IMPORTANT !!! Place ComboFix.exe on your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.
    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


    ———————————————————————————————
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.

    ———————————————————————————————


NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.
Thanks for the reply. Here is the log:

ComboFix 12-11-09.02 - Kennethzzz 11/11/2012 16:17:22.1.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4095.2112 [GMT 8:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: AVG Internet Security 2013 *Disabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
FW: AVG Internet Security 2013 *Disabled* {36AFA1E1-4CDC-7EF8-11EE-C77C3581ABA2}
SP: AVG Internet Security 2013 *Disabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\ShoppingReport2
c:\program files (x86)\ShoppingReport2\Uninst.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-10-11 to 2012-11-11 )))))))))))))))))))))))))))))))
.
.
2012-11-11 08:24 . 2012-11-11 08:24 ——– d—–w- c:\users\Default\AppData\Local\temp
2012-11-10 05:45 . 2012-11-10 05:45 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin7.dll
2012-11-10 05:45 . 2012-11-10 05:45 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin6.dll
2012-11-10 05:45 . 2012-11-10 05:45 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin5.dll
2012-11-10 05:45 . 2012-11-10 05:45 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin4.dll
2012-11-10 05:45 . 2012-11-10 05:45 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin3.dll
2012-11-10 05:45 . 2012-11-10 05:45 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin2.dll
2012-11-10 05:45 . 2012-11-10 05:45 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin.dll
2012-11-10 05:44 . 2012-11-10 05:45 ——– d—–w- c:\program files (x86)\QuickTime
2012-10-24 19:12 . 2012-10-24 19:12 94208 —-a-w- c:\windows\SysWow64\QuickTimeVR.qtx
2012-10-24 19:12 . 2012-10-24 19:12 69632 —-a-w- c:\windows\SysWow64\QuickTime.qts
2012-10-22 05:02 . 2012-10-22 05:02 154464 —-a-w- c:\windows\system32\drivers\avgidsdrivera.sys
2012-10-21 08:44 . 2012-10-21 08:44 ——– d—–w- c:\program files (x86)\Common Files\Java
2012-10-14 19:48 . 2012-10-14 19:48 63328 —-a-w- c:\windows\system32\drivers\avgidsha.sys
2012-10-13 00:52 . 2012-10-13 00:52 ——– d—–w- c:\users\Default\AppData\Roaming\TuneUp Software
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-11-05 13:44 . 2012-09-22 03:51 30568 —-a-w- c:\windows\system32\drivers\avgtpx64.sys
2012-10-10 16:15 . 2011-02-07 16:13 65309168 —-a-w- c:\windows\system32\MRT.exe
2012-10-10 00:11 . 2012-03-29 23:51 696760 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-10-10 00:11 . 2011-05-16 14:40 73656 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-10-04 19:32 . 2012-10-04 19:32 111456 —-a-w- c:\windows\system32\drivers\avgmfx64.sys
2012-10-01 19:30 . 2012-10-01 19:30 185696 —-a-w- c:\windows\system32\drivers\avgldx64.sys
2012-09-24 07:32 . 2012-08-13 15:35 477168 —-a-w- c:\windows\SysWow64\npdeployJava1.dll
2012-09-24 07:32 . 2011-07-28 14:12 473072 —-a-w- c:\windows\SysWow64\deployJava1.dll
2012-09-20 19:46 . 2012-09-20 19:46 200032 —-a-w- c:\windows\system32\drivers\avgtdia.sys
2012-09-20 19:46 . 2012-09-20 19:46 225120 —-a-w- c:\windows\system32\drivers\avgloga.sys
2012-09-18 16:58 . 2012-09-22 01:57 9308616 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{94B1DA15-BDB6-4D8E-BE75-6212E6B7B92E}\mpengine.dll
2012-09-14 19:19 . 2012-10-10 11:02 2048 —-a-w- c:\windows\system32\tzres.dll
2012-09-14 18:28 . 2012-10-10 11:02 2048 —-a-w- c:\windows\SysWow64\tzres.dll
2012-09-13 19:05 . 2012-09-13 19:05 40800 —-a-w- c:\windows\system32\drivers\avgrkx64.sys
2012-09-04 02:39 . 2011-05-22 17:03 50296 —-a-w- c:\windows\system32\drivers\avgfwd6a.sys
2012-08-31 18:19 . 2012-10-10 11:05 1659760 —-a-w- c:\windows\system32\drivers\ntfs.sys
2012-08-30 18:03 . 2012-10-10 11:05 5559664 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-08-30 17:12 . 2012-10-10 11:05 3968880 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe
2012-08-30 17:12 . 2012-10-10 11:05 3914096 —-a-w- c:\windows\SysWow64\ntoskrnl.exe
2012-08-24 18:05 . 2012-10-10 11:03 220160 —-a-w- c:\windows\system32\wintrust.dll
2012-08-24 16:57 . 2012-10-10 11:03 172544 —-a-w- c:\windows\SysWow64\wintrust.dll
2012-08-24 11:15 . 2012-09-22 11:32 17810944 —-a-w- c:\windows\system32\mshtml.dll
2012-08-24 10:39 . 2012-09-22 11:32 10925568 —-a-w- c:\windows\system32\ieframe.dll
2012-08-24 10:31 . 2012-09-22 11:32 2312704 —-a-w- c:\windows\system32\jscript9.dll
2012-08-24 10:22 . 2012-09-22 11:32 1346048 —-a-w- c:\windows\system32\urlmon.dll
2012-08-24 10:21 . 2012-09-22 11:32 1392128 —-a-w- c:\windows\system32\wininet.dll
2012-08-24 10:20 . 2012-09-22 11:32 1494528 —-a-w- c:\windows\system32\inetcpl.cpl
2012-08-24 10:18 . 2012-09-22 11:32 237056 —-a-w- c:\windows\system32\url.dll
2012-08-24 10:17 . 2012-09-22 11:32 85504 —-a-w- c:\windows\system32\jsproxy.dll
2012-08-24 10:14 . 2012-09-22 11:32 173056 —-a-w- c:\windows\system32\ieUnatt.exe
2012-08-24 10:14 . 2012-09-22 11:32 816640 —-a-w- c:\windows\system32\jscript.dll
2012-08-24 10:13 . 2012-09-22 11:32 599040 —-a-w- c:\windows\system32\vbscript.dll
2012-08-24 10:12 . 2012-09-22 11:32 2144768 —-a-w- c:\windows\system32\iertutil.dll
2012-08-24 10:11 . 2012-09-22 11:32 729088 —-a-w- c:\windows\system32\msfeeds.dll
2012-08-24 10:10 . 2012-09-22 11:32 96768 —-a-w- c:\windows\system32\mshtmled.dll
2012-08-24 10:09 . 2012-09-22 11:32 2382848 —-a-w- c:\windows\system32\mshtml.tlb
2012-08-24 10:04 . 2012-09-22 11:32 248320 —-a-w- c:\windows\system32\ieui.dll
2012-08-24 06:59 . 2012-09-22 11:32 1800704 —-a-w- c:\windows\SysWow64\jscript9.dll
2012-08-24 06:51 . 2012-09-22 11:32 1129472 —-a-w- c:\windows\SysWow64\wininet.dll
2012-08-24 06:51 . 2012-09-22 11:32 1427968 —-a-w- c:\windows\SysWow64\inetcpl.cpl
2012-08-24 06:47 . 2012-09-22 11:32 142848 —-a-w- c:\windows\SysWow64\ieUnatt.exe
2012-08-24 06:47 . 2012-09-22 11:32 420864 —-a-w- c:\windows\SysWow64\vbscript.dll
2012-08-24 06:43 . 2012-09-22 11:32 2382848 —-a-w- c:\windows\SysWow64\mshtml.tlb
2012-08-22 18:12 . 2012-09-12 09:59 1913200 —-a-w- c:\windows\system32\drivers\tcpip.sys
2012-08-22 18:12 . 2012-09-12 09:59 950128 —-a-w- c:\windows\system32\drivers\ndis.sys
2012-08-22 18:12 . 2012-09-12 09:59 376688 —-a-w- c:\windows\system32\drivers\netio.sys
2012-08-22 18:12 . 2012-09-12 09:59 288624 —-a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2012-08-21 21:01 . 2012-09-25 23:44 245760 —-a-w- c:\windows\system32\OxpsConverter.exe
2012-08-21 05:01 . 2012-09-15 05:55 33240 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2012-08-21 05:01 . 2011-02-07 16:21 125872 —-a-w- c:\windows\system32\GEARAspi64.dll
2012-08-21 05:01 . 2011-02-07 16:21 106928 —-a-w- c:\windows\SysWow64\GEARAspi.dll
2012-08-20 18:48 . 2012-10-10 11:05 362496 —-a-w- c:\windows\system32\wow64win.dll
2012-08-20 18:48 . 2012-10-10 11:05 243200 —-a-w- c:\windows\system32\wow64.dll
2012-08-20 18:48 . 2012-10-10 11:05 13312 —-a-w- c:\windows\system32\wow64cpu.dll
2012-08-20 18:48 . 2012-10-10 11:05 215040 —-a-w- c:\windows\system32\winsrv.dll
2012-08-20 18:48 . 2012-10-10 11:05 16384 —-a-w- c:\windows\system32\ntvdm64.dll
2012-08-20 18:48 . 2012-10-10 11:05 424448 —-a-w- c:\windows\system32\KernelBase.dll
2012-08-20 18:48 . 2012-10-10 11:05 1162240 —-a-w- c:\windows\system32\kernel32.dll
2012-08-20 18:46 . 2012-10-10 11:05 338432 —-a-w- c:\windows\system32\conhost.exe
2012-08-20 18:38 . 2012-10-10 11:05 4608 —ha-w- c:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2012-08-20 18:38 . 2012-10-10 11:05 3584 —ha-w- c:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2012-08-20 18:38 . 2012-10-10 11:05 3072 —ha-w- c:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2012-08-20 18:38 . 2012-10-10 11:05 4608 —ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2012-08-20 18:38 . 2012-10-10 11:05 3072 —ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2012-08-20 18:38 . 2012-10-10 11:05 4096 —ha-w- c:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2012-08-20 18:38 . 2012-10-10 11:05 6144 —ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2012-08-20 18:38 . 2012-10-10 11:05 4096 —ha-w- c:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2012-08-20 18:38 . 2012-10-10 11:05 4096 —ha-w- c:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2012-08-20 18:38 . 2012-10-10 11:05 3584 —ha-w- c:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2012-08-20 18:38 . 2012-10-10 11:05 3584 —ha-w- c:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2012-08-20 18:38 . 2012-10-10 11:05 3584 —ha-w- c:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2012-08-20 18:38 . 2012-10-10 11:05 3584 —ha-w- c:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2012-08-20 18:38 . 2012-10-10 11:05 3584 —ha-w- c:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2012-08-20 18:38 . 2012-10-10 11:05 3072 —ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2012-08-20 18:38 . 2012-10-10 11:05 3072 —ha-w- c:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2012-08-20 18:38 . 2012-10-10 11:05 4096 —ha-w- c:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2012-08-20 18:38 . 2012-10-10 11:05 3072 —ha-w- c:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2012-08-20 18:38 . 2012-10-10 11:05 3072 —ha-w- c:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2012-08-20 18:38 . 2012-10-10 11:05 3072 —ha-w- c:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2012-08-20 18:38 . 2012-10-10 11:05 5120 —ha-w- c:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2012-08-20 18:38 . 2012-10-10 11:05 3584 —ha-w- c:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2012-08-20 18:38 . 2012-10-10 11:05 3072 —ha-w- c:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2012-08-20 18:38 . 2012-10-10 11:05 3072 —ha-w- c:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2012-08-20 18:38 . 2012-10-10 11:05 3072 —ha-w- c:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2012-08-20 18:38 . 2012-10-10 11:05 3072 —ha-w- c:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2012-08-20 18:38 . 2012-10-10 11:05 3072 —ha-w- c:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2012-08-20 18:38 . 2012-10-10 11:05 3072 —ha-w- c:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2012-08-20 17:40 . 2012-10-10 11:05 14336 —-a-w- c:\windows\SysWow64\ntvdm64.dll
2012-08-20 17:38 . 2012-10-10 11:05 44032 —-a-w- c:\windows\apppatch\acwow64.dll
2012-08-20 17:38 . 2012-10-10 11:05 25600 —-a-w- c:\windows\SysWow64\setup16.exe
2012-08-20 17:37 . 2012-10-10 11:05 5120 —-a-w- c:\windows\SysWow64\wow32.dll
2012-08-20 17:37 . 2012-10-10 11:05 274944 —-a-w- c:\windows\SysWow64\KernelBase.dll
2012-08-20 17:32 . 2012-10-10 11:05 4608 —ha-w- c:\windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
2012-08-20 17:32 . 2012-10-10 11:05 4096 —ha-w- c:\windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
2012-08-20 17:32 . 2012-10-10 11:05 4096 —ha-w- c:\windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
2012-08-20 17:32 . 2012-10-10 11:05 4096 —ha-w- c:\windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
2012-08-20 17:32 . 2012-10-10 11:05 4096 —ha-w- c:\windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
2012-08-20 17:32 . 2012-10-10 11:05 3584 —ha-w- c:\windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
2012-08-20 17:32 . 2012-10-10 11:05 3584 —ha-w- c:\windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
2012-08-20 17:32 . 2012-10-10 11:05 3584 —ha-w- c:\windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2012-11-05 13:44 1796552 —-a-w- c:\program files (x86)\AVG Secure Search\13.2.0.5\AVG Secure Search_toolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files (x86)\AVG Secure Search\13.2.0.5\AVG Secure Search_toolbar.dll" [2012-11-05 1796552]
.
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"iCloudServices"="c:\program files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe" [2012-08-29 59280]
"HydraVisionDesktopManager"="c:\program files (x86)\ATI Technologies\HydraVision\HydraDM.exe" [2008-12-01 380928]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AMD AVT"="start AMD Accelerated Video Transcoding device initialization" [X]
"PivotSoftware"="c:\program files (x86)\Portrait Displays\Pivot Software\wpctrl.exe" [2007-02-09 694008]
"DT PHL"="c:\program files (x86)\Common Files\Portrait Displays\Shared\DT_startup.exe" [2008-06-21 81920]
"Diamondback"="c:\program files (x86)\Razer\Diamondback 3G\razerhid.exe" [2007-08-01 147456]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-07-22 402432]
"Lycosa"="c:\program files (x86)\Razer\Razer Lycosa\razerhid.exe" [2011-03-21 233984]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-10-11 59280]
"TkBellExe"="c:\program files (x86)\Real\RealPlayer\Update\realsched.exe" [2011-12-06 296056]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"Adobe Acrobat Speed Launcher"="c:\program files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [2012-07-27 36800]
"Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [2012-07-27 823224]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-03-08 636032]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-09-09 421776]
"AVG_UI"="c:\program files (x86)\AVG\AVG2013\avgui.exe" [2012-11-06 3143800]
"vProt"="c:\program files (x86)\AVG Secure Search\vprot.exe" [2012-11-05 997320]
"ROC_ROC_NT"="c:\program files (x86)\AVG Secure Search\ROC_ROC_NT.exe" [2012-09-22 856160]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-09-17 254896]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-24 421888]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"="start http://www.avg.com/ww.special-uninstallati...10.0.1427" [?]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 Mkd2Nadr;Mkd2Nadr;c:\windows\system32\drivers\Mkd2Nadr.sys [2009-03-12 106040]
R3 Mkd3kfNt;Mkd3kfNt;c:\windows\system32\drivers\Mkd3kfNt.sys [2009-08-18 180280]
R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl64.sys [2010-04-19 22528]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 TFsExDisk;TFsExDisk;c:\windows\System32\Drivers\TFsExDisk.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-19 59392]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-02-08 1255736]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 AVGIDSHA;AVGIDSHA;c:\windows\system32\DRIVERS\avgidsha.sys [2012-10-14 63328]
S0 Avgloga;AVG Logging Driver;c:\windows\system32\DRIVERS\avgloga.sys [2012-09-20 225120]
S0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys [2012-10-04 111456]
S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys [2012-09-13 40800]
S1 Avgfwfd;AVG network filter service;c:\windows\system32\DRIVERS\avgfwd6a.sys [2012-09-04 50296]
S1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdrivera.sys [2012-10-22 154464]
S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys [2012-10-01 185696]
S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys [2012-09-20 200032]
S1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx64.sys [2012-11-05 30568]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2011-02-08 254528]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-03-09 235520]
S2 avgfws;AVG Firewall;c:\program files (x86)\AVG\AVG2013\avgfws.exe [2012-11-01 1340976]
S2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG2013\avgidsagent.exe [2012-11-06 5814392]
S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG2013\avgwdsvc.exe [2012-10-22 196664]
S2 FGUARD64;FGUARD64;c:\fguard\FGUARD64.SYS [2008-01-04 69752]
S2 PdiService;Portrait Displays SDK Service;c:\program files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe [2008-06-21 90112]
S2 vToolbarUpdater13.2.0;vToolbarUpdater13.2.0;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\13.2.0\ToolbarUpdater.exe [2012-11-05 711112]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2011-12-05 95248]
S3 DKRtWrt;DKRtWrt;c:\windows\system32\DRIVERS\DKRtWrt.sys [2009-10-20 51120]
S3 Lycosa;Lycosa Keyboard;c:\windows\system32\drivers\Lycosa.sys [2010-09-08 28928]
S3 Razerlow;Razer Pro|Solutions;c:\windows\system32\drivers\DB3G.sys [2005-11-06 21120]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-06-10 187392]
S3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-07-09 52736]
S3 VKbms;Virtual HID Minidriver;c:\windows\system32\DRIVERS\VKbms.sys [2010-09-30 13312]
.
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - WS2IFSL
.
Contents of the 'Scheduled Tasks' folder
.
2012-11-11 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-29 00:11]
.
2012-10-13 c:\windows\Tasks\ReclaimerUpdateFiles_Kennethzzz.job
- c:\users\Kennethzzz\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.20\agent\rnupgagent.exe [2012-10-03 00:03]
.
2012-11-11 c:\windows\Tasks\ReclaimerUpdateXML_Kennethzzz.job
- c:\users\Kennethzzz\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.20\agent\rnupgagent.exe [2012-10-03 00:03]
.
2012-11-11 c:\windows\Tasks\RNUpgradeHelperLogonPrompt_Kennethzzz.job
- c:\users\Kennethzzz\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.20\agent\rnupgagent.exe [2012-10-03 00:03]
.
.
——— X64 Entries ———–
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-09-16 497648]
"FG_Monitor"="c:\fguard\FGKey64.exe" [2008-01-04 129864]
.
——- Supplementary Scan ——-
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.neopets.com/
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
uInternet Settings,ProxyServer = 210.158.6.201:8080
IE: Append Link Target to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~3\Office12\EXCEL.EXE/3000
IE: {{DB38E21A-0133-419d-92AD-ECDFD5244D6D} - {3E2DFD6A-4E20-4d4c-AA8B-E1F9DBEF3C80} -
IE: {{EB620C54-E229-4942-87CE-E717109FC8C6} - {714E0876-FCEE-49ce-A429-B9AD8AEFCB56} -
TCP: DhcpNameServer = 192.168.1.254
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\13.2.0\ViProtocol.dll
FF - ProfilePath - c:\users\Kennethzzz\AppData\Roaming\Mozilla\Firefox\Profiles\74k3yzr0.default\
FF - prefs.js: browser.search.selectedEngine - AVG Secure Search
FF - prefs.js: browser.startup.homepage - www.neopets.com
FF - ExtSQL: 2012-09-22 11:51; avg@toolbar; c:\programdata\AVG Secure Search\FireFoxExt\13.2.0.5
FF - ExtSQL: 2012-10-21 16:43; {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}; c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{816A0193-8207-5FB3-45AD-B8CAB0E15A24} - c:\program files (x86)\Funshion Online\Funshion\FunshionAddr\funshionAddr.dll
Wow6432Node-HKCU-Run-MobileDocuments - c:\program files (x86)\Common Files\Apple\Internet Services\ubd.exe
Wow6432Node-HKCU-Run-AdobeBridge - (no file)
Wow6432Node-HKLM-Run-NPSStartup - (no file)
Wow6432Node-HKLM-Run- - (no file)
AddRemove-dBpoweramp Music Converter - c:\windows\system32\SpoonUninstall.exe
AddRemove-Funshion - c:\program files (x86)\Funshion Online\Funshion\Uninstall.exe
AddRemove-ShoppingReport2 - c:\program files (x86)\ShoppingReport2\Uninst.exe
.
.
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-425539337-467667197-772877830-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.Email.1"
.
[HKEY_USERS\S-1-5-21-425539337-467667197-772877830-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.VCard.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Windows CE Services]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
———————— Other Running Processes ————————
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Common Files\Portrait Displays\Shared\DTSRVC.exe
.
**************************************************************************
.
Completion time: 2012-11-11 16:32:54 - machine was rebooted
ComboFix-quarantined-files.txt 2012-11-11 08:32
.
Pre-Run: 41,608,327,168 bytes free
Post-Run: 41,557,463,040 bytes free
.
- - End Of File - - 7302AF25425DA5736ECCB8F06165AEF5
Hi D3stinY,

Did you add this proxy server: 210.158.6.201:8080?

===================================================

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
===================================================

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 7 Update 9.
  • After the download completes, close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Double click the Java setup file you just downloaded and follow the prompts to begin the installation.
Now to Clean out the Java cache:

Go into the Control Panel and double-click the Java Icon. [external image: Posted Image]
  • Under Temporary Internet Files, click the Settings… button
  • click the Delete Files button.
  • There are three options in the window to clear the cache - Leave all 3 Checked
    • Downloaded Applets
      Downloaded Applications
      Other Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Settings
  • Click OK to leave the Java Control Panel.
===================================================

Flash Player is out of date
  • Outdated versions of Flash are vulnerable to malware infections.
  • Please uninstall old versions of Flash Player by following the instructions here.
  • Next, click here to download the latest version of Flash Player.
  • Uncheck "Yes, install Google Toolbar - optional" if you do not want to install Google Toolbar.
  • Click Download Now then double click on the setup file to start the installation.
===================================================

Update Adobe Reader
Earlier versions of Adobe Reader have known security flaws so it is recommended that you update your copy
  • Go to Start > Control Panel > Add/Remove Programs
  • Remove ALL instances of Adobe Reader
  • Re-boot your computer if required.
  • Once ALL versions of Adobe Reader have been uninstalled, visit: <> and download the latest version of Adobe Reader.
  • Make sure you uncheck Yes, install McAfee Security Scan Plus - optional if prompted.
Alternative Option: after uninstalling Adobe Reader, you could try downloading and installing SlimPDF Reader from >here< SlimPDF Reader comes with no bloatware and loads extremely quickly.
Hi, I cant remember clearly if i did add this proxy server: [removed]:8080. Most likely it is an annoymous ip used to bypass some website in the past. I checked the internet settings and it was unchecked. I am also having problem with the Anti-Malware scan. Scanning part was ok, but when i tried to delete the 400+ checked items, it seems to hang there after a few seconds. It doesn't looks like it is trying to delete or running in background even though the program is still responsive. I have attach an image of the screen.

Attachments:

Hi, After a few try, I figure that it might be better to delete portion by portion. Wierd thing is after delete a portion, I went back to rescan so that i can delete away the next portion, surprising it show 0 error to be fix. So here's the log: Malwarebytes Anti-Malware 1.65.1.1000 www.malwarebytes.org Database version: v2012.11.12.02 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 Kennethzzz :: KENNETHZZZ-PC [administrator] 11/12/2012 5:48:31 PM mbam-log-2012-11-12 (17-48-31).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 209029 Time elapsed: 57 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) I have also uninstall and install the latest versions as per your instruction for those programs.
Hi D3stinY, That is very odd. Would you mind opening MalwareBytes, clicking the "logs" tab and pasting the log from the previous scan (when there were 400 detections).
Malwarebytes Anti-Malware 1.65.1.1000 www.malwarebytes.org Database version: v2012.11.12.02 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 Kennethzzz :: KENNETHZZZ-PC [administrator] 11/12/2012 4:44:06 PM mbam-log-2012-11-12 (16-44-06).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 209002 Time elapsed: 4 minute(s), 3 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 26 HKCR\AppID\{1DD31B76-C57E-49ba-94BC-BF53F0C82CD4} (PUP.Funshion) -> No action taken. HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1DD31B76-C57E-49ba-94BC-BF53F0C82CD4} (PUP.Funshion) -> No action taken. HKCR\CLSID\{11CC93E4-0BE6-4f8f-82AA-D577FB955B05} (PUP.Funshion) -> No action taken. HKCR\AddressSearch.JsObject.1 (PUP.Funshion) -> No action taken. HKCR\AddressSearch.JsObject (PUP.Funshion) -> No action taken. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11CC93E4-0BE6-4F8F-82AA-D577FB955B05} (PUP.Funshion) -> No action taken. HKCR\CLSID\{91878E42-FC03-4785-B513-1F9E613D1027} (PUP.Funshion) -> No action taken. HKCR\TypeLib\{D02E3AB9-7796-40cb-BDFC-20D834FE1F75} (PUP.Funshion) -> No action taken. HKCR\Interface\{FCB380C4-D350-44BE-8791-50216F4747AC} (PUP.Funshion) -> No action taken. HKCR\ASBarBroker.BDBroker.1 (PUP.Funshion) -> No action taken. HKCR\ASBarBroker.BDBroker (PUP.Funshion) -> No action taken. HKCR\CLSID\{FBEDBA6C-44A2-43b9-BD49-20EB6E0C4E86} (PUP.Funshion) -> No action taken. HKCR\AddressSearch.SnavHttpProtocol.1 (PUP.Funshion) -> No action taken. HKCR\AddressSearch.SnavHttpProtocol (PUP.Funshion) -> No action taken. HKCR\fsp (PUP.Funshion) -> No action taken. HKCR\Funshion Task (PUP.Funshion) -> No action taken. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Funshion (PUP.Funshion) -> No action taken. HKCR\Typelib\{B035BA6B-57CD-4F72-B545-65BE465FCAF6} (Adware.ShoppingReport2) -> Quarantined and deleted successfully. HKCR\Typelib\{D44FD6F0-9746-484E-B5C4-C66688393872} (Adware.ShoppingReport2) -> Quarantined and deleted successfully. HKCR\Interface\{0EB3F101-224A-4B2B-9E5B-DF720857529C} (Adware.ShoppingReport2) -> Quarantined and deleted successfully. HKCR\Typelib\{F244A744-534D-4A46-855F-C0C7E9F27DAA} (Adware.ShoppingReport2) -> Quarantined and deleted successfully. HKCR\Interface\{030C9927-10FC-4169-97A2-55BECD5D88D8} (Adware.ShoppingReport2) -> Quarantined and deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{DB38E21A-0133-419d-92AD-ECDFD5244D6D} (Adware.ShoppingReport2) -> Quarantined and deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EB620C54-E229-4942-87CE-E717109FC8C6} (Adware.ShoppingReport2) -> Quarantined and deleted successfully. HKLM\SOFTWARE\ShoppingReport2 (Adware.ShoppingReport2) -> Quarantined and deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ShoppingReport2 (Adware.Hotbar) -> Quarantined and deleted successfully. Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 75 C:\Users\Kennethzzz\funshion (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\backup (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\Baiduflash (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\Baiduflash\subflash (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\Cacheflash (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flash (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashStamp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\historyTorrent (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\ini (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\Q10-第9集 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\倩女幽魂-MP4(110602) (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\即使这样也不是我做的 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\尼基塔第二季 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\明日香高工进行曲 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\明日香高工进行曲-第1集 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\明日香高工进行曲-第2集 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\明日香高工进行曲-第3集 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\明日香高工进行曲-第4集 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\杰茜驾到第一季 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第三季-001 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第三季-002 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第三季-003 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第三季-004 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第三季-005 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第三季-006 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第三季-007 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第三季-008 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第三季-009 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第三季-010 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第三季-011 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第三季-012 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第三季-013 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第三季-014 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第三季-015 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第三季-016 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第三季-017 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第三季-018 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第三季-019 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第三季-020 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第六季 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第四季-001 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第四季-002 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第四季-003 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第四季-004 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第四季-005 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第四季-006 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第四季-007 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第四季-008 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第四季-009 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第四季-010 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第四季-011 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第四季-012 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第四季-013 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第四季-014 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第四季-015 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第四季-016 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第四季-017 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第四季-018 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第四季-019 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第四季-020 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第四季-021 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第四季-022 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第四季-023 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第四季-024 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈的浪漫史第六季-001 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\记得我们有约 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\贾斯汀·比伯~永不言败 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\青春期 (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\screensave (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\Seed (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\update (PUP.Funshion) -> No action taken. Files Detected: 344 C:\Users\Kennethzzz\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Funshion.lnk (PUP.Funshion) -> No action taken. C:\Windows\System32\funshion.ini (PUP.Funshion) -> No action taken. C:\Windows\SysWOW64\funshion.ini (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion.ini (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\history.txt (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\install.ini (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\KENNETHZZZ-PC_info.ini (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\Cacheflash\blankFs.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\Cacheflash\donghuanew_18.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flash\980EF71B_C41B_511C_2591_1C44D72C2CEC.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\024A09BE_5877_EE97_8614_94A4C37E5353.date1332287066.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\05E206EF_1479_B3E0_BC94_9F3253E68853.date1332287066.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\082D5EBB_C3C3_1385_4EF1_2034CADA7FA9.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\096F7A60_3434_4250_0C0F_052C734E5BAE.date1330254517.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\09A8E755_0B2C_0375_4217_52F3917F9262.date1332287066.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\0BCF526F_AC0B_CC11_615B_A3A384CFFBFC.date1329879503.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\0DA1C7E0_28E9_CE7E_BF93_AF99DCE54963.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\10238FA9_D811_EF38_A0BA_92A511B38828.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\11464FA0_FAF1_5726_C269_01F6AF27007C.date1332287066.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\13294436.date1332287066.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\13CB5C4E_51FF_B197_F531_C1961B55DCC4.date1330350861.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\187965.date1332287066.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\2331F0C3_A003_4740_8775_8B6307227885.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\2B93547D_1CE7_0F4B_BF65_23634988ACA4.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\2BC19848_90FE_CF0E_FA9B_54514A6DA275.flv (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\2FE7C3EE_6542_6CA8_69CF_6DA35DA0F7A1.date1332287066.flv (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\345EA342_918D_B1E8_8C2D_1633979B57C0.date1330001942.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\36999540_E739_EE00_8F91_641F7C1C0F93.flv (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\398DF0AD_D6B2_4B0D_F4A4_0997D97430F3.date1331043382.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\3AE32716_9926_DA46_DAB7_4DD9E773024D.date1332326343.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\40E240E9_FFF2_44DC_146B_29D03C1F9736.date1330254517.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\4211F87F_3C31_6F87_9DEF_DC1AA10184B6.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\42EDF2D9_EEEC_1E01_8DF6_54505C3846B5.date1329949599.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\4558234C_830D_BEFE_76C8_BAA28289E2C5.date1332287066.flv (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\465EBE9A_89B0_6A52_E064_3AEBD2922024.date1331043382.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\4C05280E_DA06_3623_2433_F7507175AB74.date1332287066.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\4DAB2DDB_D0D2_81B5_1D4B_2D66BA166C4B.date1330350861.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\4EF54027_881B_A03D_20B6_B433A10796FA.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\59EDF712_61FF_09CE_AD62_38C450D135B6.date1332287066.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\6539C18F_9D89_C25F_EF96_632247D405BC.date1332287066.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\66D204D2_3A0D_88FD_6B97_40C7E586B226.date1332287066.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\6ECE1638_AEEA_6EFA_EFE6_7D82BEB0C4EF.date1331289691.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\70D482F2_CA5E_B830_0EF3_B6BC6D51121F.date1331289691.flv (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\72B5C3C4_EFFF_C940_06C4_1BC6CB6B1D53.date1332413524.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\7A2D297D_A00A_97FE_8163_544FE5DC7DD4.flv (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\7A48B911_FEC7_FE34_C1C4_27E6A6B49CDE.date1329879503.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\7CC0B252_C80D_8F97_1AFF_A2D3893E23DF.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\7D80FF6E_F484_360C_D18F_CF25481F4016.date1331043382.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\80443D1E_81EC_0FBE_BFC4_B5614A1FDC79.date1329879503.flv (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\80BF1408_398E_C39F_6923_8CDEB6DC3D5A.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\83A6F2D7_826B_2293_4364_BE4DDCC7B202.flv (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\8778456A_8AF5_7F70_D801_CE6CD6D6708D.date1331043382.flv (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\8A8FB6FF_26B2_19D9_EE62_7402A212696C.flv (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\8AB83F62_F063_CF32_FBDB_165BE89DEEF9.date1332287066.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\8AD5FC77_3686_D8CC_DA83_954E47D5703A.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\90C7C395_B7C2_8113_82F6_1876008FA721.date1331043382.flv (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\94C93D65_59FD_FF44_07BE_B3A84C40FBFC.date1331043382.flv (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\961D18C0_49B4_6664_183E_10B6BFE11677.date1329879503.flv (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\9A79E7EE_914E_F3E5_0AE8_C332AF34A8D4.flv (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\9AC938C8_9EE3_E691_8C32_718B98CCFD85.date1332287066.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\A6B9CEBF_23FD_B526_18BB_58B3FC776112.date1330001942.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\A8BDA0C7_0F80_A610_336B_11033FE03B2F.date1332287066.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\ABF7910B_7C47_9B3F_288A_F0CDFC28DE32.date1332373676.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\AC07BD7A_765F_C581_F508_EF71F52B0343.date1332287066.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\ACF846A9_0B5C_6BFB_14C1_049460B81C42.date1331043382.flv (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\BFBE7108_8F13_0C60_D0EC_34D5066CD30F.date1332287066.flv (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\C2D3B20C_69AB_F4B2_39D6_77BCA3D8CE6A.date1331289691.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\C73E5452_77B4_8649_003B_84BB0A131139.date1332287066.flv (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\C8946D70_045F_6D45_FD25_939BFE2F4FF1.date1331043382.flv (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\CBD4DE4D_E9BD_3C47_B328_FA8A35CFBDB6.date1332326342.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\CBEC5017_CCFC_4112_BA7B_EEE0E8985936.date1331043382.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\CCAA6614_5DE6_F1D6_1777_857692921324.date1330254517.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\CCD98DD4_D045_7E1E_72C3_884AF7883898.date1331043382.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\CEA45BFA_D8E9_3E0B_C43F_B3A370733A42.date1332326342.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\D3F32094_CEBD_88A6_23B1_441A78AAC5DD.date1331043382.flv (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\D71F6E3C_0CAC_45B9_20A0_CD5F6E04182F.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\F1855728_EB19_B032_37AE_3B7CEA8B925A.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\F776E3BB_3CED_91D7_58A7_09A767AF7DEA.date1330254517.flv (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\F8BEED23_988E_4A45_A2C7_735578CB78C2.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashNew\FBE9C8A4_947D_5AAA_D481_B51ECBE54E80.date1329879502.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashStamp\297DF161_AA3C_4DF5_4FB2_3812C12362EB.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashStamp\4A09DE59_E6C7_9C1C_A734_78161EFFB51C.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashStamp\65605056_73C9_505E_D647_AFAC0D498A88.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashStamp\7F5C6812_18F9_0429_93A4_D3E7450561AE.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashStamp\85B59D17_E7FD_81C7_2373_6DB32CD0DAA0.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashStamp\A559E26C_11D0_9DC2_3674_3EE96401592A.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashStamp\BAE85BE3_FDA5_723F_4BB9_81736D77E413.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashStamp\BEF6FC6F_547E_92EC_5B03_5F3FF763365F.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashStamp\blank.gif (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\cache\flashStamp\D97435B9_2303_A0FC_768A_0387DAC9718A.swf (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1305775636_18277256_1287700066_638.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1305775636_18277256_1287700066_638.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1306129696_18277256_1287700066_776.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1306129696_18277256_1287700066_776.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1306149377_23811438_1306124343_239.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1306149377_23811438_1306124343_239.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1306656696_18277256_1287700067_109.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1306656696_18277256_1287700067_109.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1307114833_18277256_1287700067_793.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1307114833_18277256_1287700067_793.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1307116712_18277256_1287700068_289.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1307116712_18277256_1287700068_289.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1307260316_20080446_1307007410_658.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1307260316_20080446_1307007410_658.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1307261927_18277256_1287700069_725.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1307261927_18277256_1287700069_725.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308016724_18277256_1287700069_913.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308016724_18277256_1287700069_913.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308125695_18277256_1292221350_629.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308125695_18277256_1292221350_629.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308204574_18277256_1287700070_244.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308204574_18277256_1287700070_244.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308207207_18277256_1287700070_548.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308207207_18277256_1287700070_548.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308366845_18277256_1287700071_638.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308366845_18277256_1287700071_638.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308368251_18277256_1287700071_802.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308368251_18277256_1287700071_802.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308406987_18277256_1287700072_388.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308406987_18277256_1287700072_388.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308490769_18277256_1287700072_439.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308490769_18277256_1287700072_439.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308492217_18277256_1287700073_934.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308492217_18277256_1287700073_934.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308494586_18277256_1287700073_984.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308494586_18277256_1287700073_984.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308496023_18277256_1287700074_184.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308496023_18277256_1287700074_184.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308498117_18277256_1287700075_282.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308498117_18277256_1287700075_282.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308501510_18277256_1287700076_566.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308501510_18277256_1287700076_566.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308538304_18277256_1287700076_773.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308538304_18277256_1287700076_773.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308542458_18277256_1287700065_326.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308542458_18277256_1287700065_326.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308546118_18277256_1285217298_345.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308546118_18277256_1285217298_345.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308558282_6634280_1287991966_767.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308558282_6634280_1287991966_767.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308560037_6634280_1287991967_680.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308560037_6634280_1287991967_680.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308562856_6634280_1287991970_903.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308562856_6634280_1287991970_903.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308569432_6634280_1287991973_619.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308569432_6634280_1287991973_619.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308570738_6634280_1287991974_200.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308570738_6634280_1287991974_200.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308574549_6634280_1287991976_993.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308574549_6634280_1287991976_993.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308580387_6634280_1287991976_783.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308580387_6634280_1287991976_783.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308657258_6634280_1287991977_477.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308657258_6634280_1287991977_477.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308660603_6634280_1287991977_463.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308660603_6634280_1287991977_463.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308666371_6634280_1287991978_243.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308666371_6634280_1287991978_243.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308668828_6634280_1287991978_123.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308668828_6634280_1287991978_123.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308754902_6634280_1287991982_872.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308754902_6634280_1287991982_872.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308756653_6634280_1287991983_677.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308756653_6634280_1287991983_677.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308758694_6634280_1287991984_169.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308758694_6634280_1287991984_169.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308828561_6634280_1287991984_410.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308828561_6634280_1287991984_410.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308830263_6634280_1287991985_607.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308830263_6634280_1287991985_607.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308840073_6634280_1287991985_595.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308840073_6634280_1287991985_595.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308915263_6634280_1287991986_334.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308915263_6634280_1287991986_334.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308916662_6634280_1287991986_250.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1308916662_6634280_1287991986_250.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1309186267_6634280_1287991987_665.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1309186267_6634280_1287991987_665.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1309274475_6634280_1287991989_249.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1309274475_6634280_1287991989_249.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1309352479_6634280_1287991990_474.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1309352479_6634280_1287991990_474.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1309527617_6634280_1287991990_125.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1309527617_6634280_1287991990_125.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1309530945_6634280_1287991965_444.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1309530945_6634280_1287991965_444.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1310397745_20080446_1303787248_805.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1310397745_20080446_1303787248_805.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1310472380_18524595_1304488548_959.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1310472380_18524595_1304488548_959.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1310516891_23811438_1305688189_777.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1310516891_23811438_1305688189_777.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1310656687_24272712_1306900539_493.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1310656687_24272712_1306900539_493.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1310882028_24570037_1307503938_782.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1310882028_24570037_1307503938_782.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1310882028_2ac002684cb6a51.json (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1311521448_24570037_1308109616_176.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1311521448_24570037_1308109616_176.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1311607653_24570037_1308888312_26.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1311607653_24570037_1308888312_26.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1311780823_24272712_1309495491_519.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1311780823_24272712_1309495491_519.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1314705438_4629932_1204007426_488.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1314705438_4629932_1204007426_488.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1314705500_18524595_1285731078_754.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1314705500_18524595_1285731078_754.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1314705500_3ce09774d33fe50.json (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1314802384_18524595_1286437543_324.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1314802384_18524595_1286437543_324.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1315112926_24272712_1311323933_433.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1315112926_24272712_1311323933_433.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1315144398_18524595_1286960425_886.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1315144398_18524595_1286960425_886.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1315494420_18524595_1287539517_357.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1315494420_18524595_1287539517_357.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1318126202_24570037_1317115178_848.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1318126202_24570037_1317115178_848.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1318126202_8a3ff8c7a0d8637.json (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1320281019_19bed4debc7ecf4.json (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1320281019_23623226_1315640554_124.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1320281019_23623226_1315640554_124.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1320334007_24570037_1317360660_357.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1320334007_24570037_1317360660_357.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1320767282_20080446_1317882651_14.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1320767282_20080446_1317882651_14.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1323012769_24272712_1317191624_533.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1323012769_24272712_1317191624_533.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1323012769_a168c4f510be919.json (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1323606506_24570037_1320313927_262.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1323606506_24570037_1320313927_262.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1323608474_24570037_1320897369_102.dat (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\control\1323608474_24570037_1320897369_102.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\ini\httpfile.ini (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\ini\temp_config.ini (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\Install Latest Funshion.lnk (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\Start Funshion.lnk (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\Q10-第9集\Q10-第9集.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\倩女幽魂-MP4(110602)\倩女幽魂A.mp4.fc! (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\倩女幽魂-MP4(110602)\倩女幽魂B.mp4.fc! (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\即使这样也不是我做的\即使这样也不是我做的A.rmvb.fc! (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\即使这样也不是我做的\即使这样也不是我做的B.rmvb.fc! (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\尼基塔第二季\尼基塔第二季-第1集.mp4.fc! (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\明日香高工进行曲\明日香高工进行曲-第5集.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\明日香高工进行曲\明日香高工进行曲-第6集.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\明日香高工进行曲\明日香高工进行曲-第7集.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\明日香高工进行曲\明日香高工进行曲-第8集.rmvb.fc! (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\明日香高工进行曲-第1集\明日香高工进行曲-第1集.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\明日香高工进行曲-第2集\明日香高工进行曲-第2集.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\明日香高工进行曲-第3集\明日香高工进行曲-第3集.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\明日香高工进行曲-第4集\明日香高工进行曲-第4集.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\杰茜驾到第一季\一女三男第一季-第1集.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\杰茜驾到第一季\杰茜驾到-第3集.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\杰茜驾到第一季\杰茜驾到第一季-第2集.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\杰茜驾到第一季\杰茜驾到第一季-第4集.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\杰茜驾到第一季\杰茜驾到第一季-第5集.rmvb.fc! (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第三季-001\老爸老妈浪漫史第三季-001.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第三季-002\老爸老妈浪漫史第三季-002.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第三季-003\老爸老妈浪漫史第三季-003.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第三季-004\老爸老妈浪漫史第三季-004.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第三季-005\老爸老妈浪漫史第三季-005.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第三季-006\老爸老妈浪漫史第三季-006.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第三季-007\老爸老妈浪漫史第三季-007.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第三季-008\老爸老妈浪漫史第三季-008.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第三季-009\老爸老妈浪漫史第三季-009.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第三季-010\老爸老妈浪漫史第三季-010.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第三季-011\老爸老妈浪漫史第三季-011.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第三季-012\老爸老妈浪漫史第三季-012.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第三季-013\老爸老妈浪漫史第三季-013.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第三季-014\老爸老妈浪漫史第三季-014.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第三季-015\老爸老妈浪漫史第三季-015.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第三季-016\老爸老妈浪漫史第三季-016.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第三季-017\老爸老妈浪漫史第三季-017.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第三季-018\老爸老妈浪漫史第三季-018.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第三季-019\老爸老妈浪漫史第三季-019.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第三季-020\老爸老妈浪漫史第三季-020.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第六季\老爸老妈浪漫史第六季-002.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第六季\老爸老妈浪漫史第六季-004.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第六季\老爸老妈浪漫史第六季-005.rmvb.fc! (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第六季\老爸老妈的浪漫史第六季-003.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第四季-001\老爸老妈浪漫史第四季-001.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第四季-002\老爸老妈浪漫史第四季-002.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第四季-003\老爸老妈浪漫史第四季-003.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第四季-004\老爸老妈浪漫史第四季-004.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第四季-005\老爸老妈浪漫史第四季-005.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第四季-006\老爸老妈浪漫史第四季-006.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第四季-007\老爸老妈浪漫史第四季-007.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第四季-008\老爸老妈浪漫史第四季-008.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第四季-009\老爸老妈浪漫史第四季-009.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第四季-010\老爸老妈浪漫史第四季-010.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第四季-011\老爸老妈浪漫史第四季-011.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第四季-012\老爸老妈浪漫史第四季-012.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第四季-013\老爸老妈浪漫史第四季-013.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第四季-014\老爸老妈浪漫史第四季-014.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第四季-015\老爸老妈浪漫史第四季-015.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第四季-016\老爸老妈浪漫史第四季-016.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第四季-017\老爸老妈浪漫史第四季-017.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第四季-018\老爸老妈浪漫史第四季-018.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第四季-019\老爸老妈浪漫史第四季-019.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第四季-020\老爸老妈浪漫史第四季-020.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第四季-021\老爸老妈浪漫史第四季-021.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第四季-022\老爸老妈浪漫史第四季-022.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第四季-023\老爸老妈浪漫史第四季-023.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈浪漫史第四季-024\老爸老妈浪漫史第四季-024.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\老爸老妈的浪漫史第六季-001\老爸老妈的浪漫史第六季-001.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\记得我们有约\记得我们有约-第1集.rmvb.fc! (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\贾斯汀·比伯~永不言败\贾斯汀·比伯~永不言败.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\media\青春期\青春期.rmvb (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\Seed\18277256_1296273195_805.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\Seed\18277256_1298693865_69.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\Seed\18277256_1302337011_63.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\Seed\18277256_1308122732_683.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\Seed\18524595_1285731078_754.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\Seed\18524595_1286437543_324.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\Seed\18524595_1286960425_886.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\Seed\18524595_1287539517_357.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\Seed\18524595_1308553624_469.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\Seed\19bed4debc7ecf4.json (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\Seed\20080446_1317882651_14.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\Seed\24272712_1309495491_519.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\Seed\24272712_1311323933_433.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\Seed\24570037_1308109616_176.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\Seed\24570037_1308888312_26.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\Seed\24570037_1317115178_848.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\Seed\24570037_1317360660_357.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\Seed\24570037_1320897369_102.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\Seed\3ce09774d33fe50.json (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\Seed\4629932_1204007426_488.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\Seed\6634280_1286078233_196.fsp (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\Seed\8a3ff8c7a0d8637.json (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\Seed\ea7907a371c492c.json (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\update\AdLinkParamFile.fax (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\update\ad_define.fai (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\update\ad_define.fai.bak (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\update\ad_material.fax (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\update\flashnew.json (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\update\flashParam.txt (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\update\flashParam.txt.bak (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\update\localad.fax (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\update\Pop Game.lnk (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\update\popwind.json (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\update\Shopping Sites.lnk (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\update\StampPolicy.txt (PUP.Funshion) -> No action taken. C:\Users\Kennethzzz\funshion\update\updatexmlfile.txt (PUP.Funshion) -> No action taken. (end)
I need you to run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start.  The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button.  The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\Program Files\ESET\log.txt into your next reply.
the contents of the C:\Program Files\ESET\log.txt shows: ESETSmartInstaller@High as CAB hook log: OnlineScanner64.ocx - registred OK OnlineScanner.ocx - registred OK The scan shows 1 threat: C:\Qoobox\Quarantine\C\Program Files (x86)\ShoppingReport2\Uninst.exe.vir Win32/Adware.Toolbar.Shopper application Are this the logs require?
I'm not sure. Still recieve alot of spam mails, but most probably is because my email was used by the hacker in the past, can't be help i guess. At least twitter seems to be looking fine now, with no random retweet or post after I change the pw. Is my computer clean now?
Hi D3stinY,

Receiving spam emails doesn't necessarily mean you were hacked. If your email was sending spam emails to other people, then it would likely have been compromised.

Your logs appear to be clean, so we can clean up the tools we used and send you on your way!

===================================================

Delete aswMBR and DDS from your desktop.

===================================================

Follow these steps to uninstall Combofix

* Click START
* Now type ComboFix /Uninstall in the searchbox and hit ENTER. Note the space between the X and the /, it needs to be there.
(Note: There is a space between the ..X and the /U that needs to be there.)

[external image: Posted Image]

===================================================

Here are some tips to reduce the potential for spyware infection in the future:

Updates
  • It is very important that you keep your Operating System and applications up to date so that you will be less susceptible to malware.
  • It's a good idea to have Windows Update automatically download and install updates as they become available.
  • Secunia Online Software Inspector is a great tool that will tell you which of your applications are outdated and vulnerable to attack.
Run Anti-Virus Software
  • For an excellent list of free anti virus software, free online virus scanners, free spyware detection/removal and free firewalls, click here.
  • IMPORTANT! Please make sure you only have ONE firewall and ONE real-time antivirus installed on your system.
  • When using "on demand" scanners, first update the detection signature files, then disconnect from the internet and disable your resident security program before running the scan.
  • Once complete, remember to re-engage your resident security before going online.
Passwords
  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection.
  • Refer to this Microsoft article
    Strong passwords: How to create and use them and consider a password keeper, to keep all your passwords safe.
Spyware Protection
  • This is a good time to set up protection against further attacks. In light of your recent problem, I'm sure you'd like to avoid any future infections. Please read these well written articles:
  • How to Prevent Malware by miekiemoes
  • PC Safety and Security–What Do I Need?
Additional Software
  • To help protect your computer in the future I recommend that you get the following free programs if you do not already have them:
  • SpywareBlaster prevents the installation of ActiveX-based malware, blocks cookies, and restricts the actions of "bad" sites. See tutorial here
  • MVPS HOSTS FILE replaces your current HOSTS file with one that will restrict known ad sites from serving you unsolicited advertisements.
  • Google Chrome is a great alternative to Internet Explorer and Firefox.
Follow these steps, keep your antivirus program and antispyware programs updated, and scan with them on a regular basis. By doing so, your potential for being infected again will reduce dramatically. 

Hopefully this should take care of your problems! Good luck.

Do you have any further questions? 

**Please respond one more time to confirm your problem is resolved so I can close this thread.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI