On website I have found random blue links that are not typically there when I check with different device.
The initial url that pops up is i.trkjmp.com then it switch over to a website that correlates to the the random
blue link word. I disabled shockwave flash plug in on Firefox and seems to have fix issue so far.
Run Malware bytes nothing found
Kaspersky nothing found
SuperAntispyware found the following and removed today:
Trojan.Agent/Gen-FakeAlert[Local]
C:USERSEXIGOAPPDATALOCALTEMP7ZS47F2SETUPHPOAPD01.EXE
C:USERSEXIGOAPPDATALOCALTEMP7ZS6310SETUPHPOAPD01.EXE
Additional 201 adware tracking cookies were also removed
Adware.Tracking Cookie
account.goodgamestudios.com [ C:USERSEXIGOAPPDATAROAMINGMACROMEDIAFLASH PLAYER#SHAREDOBJECTSC745NPE8 ]
core.insightexpressai.com [ C:USERSEXIGOAPPDATAROAMINGMACROMEDIAFLASH PLAYER#SHAREDOBJECTSC745NPE8 ]
ds.serving-sys.com [ C:USERSEXIGOAPPDATAROAMINGMACROMEDIAFLASH PLAYER#SHAREDOBJECTSC745NPE8 ]
media.mtvnservices.com [ C:USERSEXIGOAPPDATAROAMINGMACROMEDIAFLASH PLAYER#SHAREDOBJECTSC745NPE8 ]
msnbcmedia.msn.com [ C:USERSEXIGOAPPDATAROAMINGMACROMEDIAFLASH PLAYER#SHAREDOBJECTSC745NPE8 ]
secure-us.imrworldwide.com [ C:USERSEXIGOAPPDATAROAMINGMACROMEDIAFLASH PLAYER#SHAREDOBJECTSC745NPE8 ]
www.cellartracker.com [ C:USERSEXIGOAPPDATAROAMINGMACROMEDIAFLASH PLAYER#SHAREDOBJECTSC745NPE8 ]
.ru4.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.doubleclick.net [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.zedo.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.realmedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.realmedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.invitemedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.atdmt.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.media6degrees.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
ad.yieldmanager.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
ad.yieldmanager.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
ad.yieldmanager.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.imrworldwide.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.imrworldwide.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.serving-sys.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.serving-sys.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.ru4.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.revsci.net [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.media.adfrontiers.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.insightexpressai.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.insightexpressai.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.insightexpressai.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.insightexpressai.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.zedo.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.zedo.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.revsci.net [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.atwola.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.dmtracker.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.insightexpressai.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.interclick.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.interclick.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.a1.interclick.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
www.googleadservices.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.ticketsnow.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.ticketsnow.112.2o7.net [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.invitemedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.solvemedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.solvemedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.serving-sys.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.burstnet.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.ru4.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
www.googleadservices.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.adtechus.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.atwola.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.advertising.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
sftrack.searchforce.net [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.apmebf.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.mediaplex.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.bs.serving-sys.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.amazon-adsystem.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.ru4.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
www.googleadservices.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.atdmt.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.c.atdmt.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.c.atdmt.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.ar.atwola.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.atwola.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.ar.atwola.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.questionmarket.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.questionmarket.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.questionmarket.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.legolas-media.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.legolas-media.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.ads.pointroll.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.pointroll.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.a1.interclick.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.yieldmanager.net [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.interclick.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.fastclick.net [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.ad.mlnadvertising.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.at.atwola.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.at.atwola.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.tacoda.at.atwola.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.tacoda.at.atwola.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.tacoda.at.atwola.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.invitemedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.2o7.net [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.2o7.net [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.adserver.adtechus.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.collective-media.net [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
ad.yieldmanager.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.ads.pointroll.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.2o7.net [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.zedo.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
statse.webtrendslive.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.invitemedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.invitemedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.invitemedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.invitemedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.collective-media.net [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.adxpose.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
consumercenter.gogecapital.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
consumercenter.gogecapital.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.gemoneysusgogecapitalcc.112.2o7.net [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.gemoneysusmb2.112.2o7.net [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.mediaforge.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.2o7.net [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.mediaforge.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.mediaforge.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.specificclick.net [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.ru4.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.saymedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.saymedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.saymedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.saymedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
ad.yieldmanager.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
ad.yieldmanager.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
ad.yieldmanager.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.adinterax.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.adinterax.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.a1.interclick.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.a1.interclick.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.a1.interclick.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.a1.interclick.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.a1.interclick.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.interclick.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.lucidmedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.traveladvertising.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.media.adfrontiers.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.realmedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.realmedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.network.realmedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.network.realmedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.network.realmedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.mediaplex.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.ru4.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.2o7.net [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.ru4.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.oracle.112.2o7.net [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.advertising.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.advertising.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.advertising.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.2o7.net [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.2o7.net [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.eyeviewads.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.interclick.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.invitemedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
www.googleadservices.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.tribalfusion.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.pointroll.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.ads.pointroll.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.ads.pointroll.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.ads.pointroll.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.ads.pointroll.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.ads.pointroll.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.ads.pointroll.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.doubleclick.net [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.invitemedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.advertising.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.advertising.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.casalemedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.lfstmedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
network.realmedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.burstnet.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.clickfuse.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.traveladvertising.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.traveladvertising.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.clickfuse.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.zedo.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.realmedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
network.realmedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.ru4.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.ru4.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.ru4.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.ru4.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.media6degrees.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.media6degrees.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.media6degrees.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.media6degrees.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.media6degrees.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.media6degrees.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.media6degrees.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
ad.yieldmanager.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.ru4.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.serving-sys.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.serving-sys.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.serving-sys.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.kontera.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.casalemedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.casalemedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.casalemedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.casalemedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.casalemedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.casalemedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.casalemedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.technoratimedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.technoratimedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.technoratimedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.technoratimedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.revsci.net [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.revsci.net [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.revsci.net [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
.statcounter.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES
.SQLITE ]
alwarebytes Anti-Malware 1.70.0.1100
www.malwarebytes.org
Database version: v2013.03.05.12
Windows Vista Service Pack 2 x64 NTFS
Internet Explorer 8.0.6001.19400
Exigo :: EXIGO-PC [administrator]
3/5/2013 1:03:06 PM
mbam-log-2013-03-05 (13-03-06).txt
Scan type: Full scan (C:|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 404073
Time elapsed: 1 hour(s), 47 minute(s), 36 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
Hi brians2,
My name is
Tomk . I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:
I will be working on your Malware issues, this may or may not, solve other issues you have with your machine. The fixes are specific to your problem and should only be used for the issues on this machine. Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear. It's often worth reading through these instructions and printing them for ease of reference. If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry. Please reply to this thread. Do not start a new topic.
How about getting me a log so I can have a better look at what is going on:
Please download DDS by sUBs from one of the following links and save it to your desktop.
Disable any script blocking protection (How to Disable your Security Programs ) Double click DDS icon to run the tool (may take up to 3 minutes to run) When done, DDS.txt will open. After a few moments, attach.txt will open in a second window. Save both reports to your desktop. —————————————————
Post the contents of the DDS.txt report in your next replyAttach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse . Browse to where you saved the file, and click Open and the click UPLOAD .
Good day Tomk
Thanks for your help, I do appreciate you time. I have posted DDS log and attached attach log as requested.
Had to run 3 times, I forgot about different antispyware and malware apps.
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 8.0.6001.19400 BrowserJavaVersion: 10.13.2
Run by [removed] at 11:09:54 on 2013-03-08
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2042.634 [GMT -5:00]
.
AV: Kaspersky Anti-Virus *Enabled/Updated* {56547CC9-C9B2-849D-8FEF-A496150D6A06}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Kaspersky Anti-Virus *Enabled/Updated* {ED359D2D-EF88-8B13-B55F-9FE46E8A20BB}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_15f4e438\STacSV64.exe
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_15f4e438\AESTSr64.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files (x86)\Common Files\Nuance\dgnsvc.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\TightVNC\tvnserver.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files (x86)\SugarSync\SugarSyncManager.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe
C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\BookmarkDAV_client.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\Mouse Setting\Mouse Setting Software\4.0\ACQTMAPP.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\TightVNC\tvnserver.exe
C:\Program Files (x86)\Linksys Wireless-G Print Server\PSDiagnosticM.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\SysWOW64\RunDll32.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files (x86)\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Windows\splwow64.exe
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\SyncServer.exe
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
uDefault_Page_URL = hxxp://www.dell.com
mDefault_Page_URL = hxxp://www.dell.com
mWinlogon: Userinit = userinit.exe,
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
BHO: IEVkbdBHO Class: {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\ievkbd.dll
BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO: FilterBHO Class: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll
TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: StartNow Toolbar: {5911488E-9D1E-40ec-8CBB-06B231CC153F} -
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
uRun: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
uRun: [SugarSync] "C:\Program Files (x86)\SugarSync\SugarSyncManager.exe" -startInTray -usedelay=true
uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
uRun: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe -scheduler
uRun: [EPSON NX125 NX127 Series] C:\Windows\System32\spool\DRIVERS\x64\3\E_IATIGGA.EXE /FU "C:\Windows\TEMP\E_S5BDA.tmp" /EF "HKCU"
uRun: [Facebook Update] "C:\Users\Exigo\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
uRun: [StartNow Search Protect] "C:\Program Files (x86)\StartNow Toolbar\search_protect.exe" /RELAY /REPORT /PROTECT
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
uRun: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
uRun: [ApplePhotoStreams] C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
uRun: [com.apple.dav.bookmarks.daemon] C:\Program Files (x86)\Common Files\Apple\Internet Services\BookmarkDAV_client.exe
mRun: [StartCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe"
mRun: [DNS7reminder] "C:\Program Files (x86)\Nuance\NaturallySpeaking11\Ereg\Ereg.exe" -r "C:\ProgramData\Nuance\NaturallySpeaking11\Ereg.ini
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [ACQTMOUSE] "C:\Program Files (x86)\Mouse Setting\Mouse Setting Software\4.0\ACQTMAPP.exe"
mRun: [StartNowToolbarHelper] "C:\Program Files (x86)\StartNow Toolbar\ToolbarHelper.exe"
mRun: [tvncontrol] "C:\Program Files (x86)\TightVNC\tvnserver.exe" -controlservice -slave
mRun: [PSDiagnosticM] "C:\Program Files (x86)\Linksys Wireless-G Print Server\PSDiagnosticM.exe"
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BLUETO~1.LNK - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0
mPolicies-Explorer: NoDriveTypeAutoRun = dword:28
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: SoftwareSASGeneration = dword:1
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
TCP: NameServer = 167.206.254.1 167.206.254.2
TCP: Interfaces\{E29B23B5-60AC-4E5C-BAFF-E892E1E1E0CB} : DHCPNameServer = [removed] [removed]
LSA: Security Packages = kerberos msv1_0 schannel wdigest tspkg
x64-mDefault_Page_URL = hxxp://www.dell.com
x64-BHO: IEVkbdBHO Class: {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\ievkbd.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg64.dll
x64-BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
x64-BHO: FilterBHO Class: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\klwtbbho.dll
x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-Run: [Windows Defender] C:\Program Files (x86)\Windows Defender\MSASCui.exe -hide
x64-Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
x64-Run: [QuickSet] C:\Program Files\Dell\QuickSet\QuickSet.exe
x64-Run: [SysTrayApp] C:\Program Files (x86)\IDT\WDM\sttray64.exe
x64-Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
x64-mPolicies-Explorer: NoActiveDesktop = dword:1
x64-mPolicies-Explorer: NoActiveDesktopChanges = dword:1
x64-mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0
x64-mPolicies-Explorer: NoDriveTypeAutoRun = dword:28
x64-mPolicies-System: EnableUIADesktopToggle = dword:0
x64-mPolicies-System: SoftwareSASGeneration = dword:1
x64-IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\klwtbbho.dll
x64-IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
x64-IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\klwtbbho.dll
.
INFO: x64-HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
x64-DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
x64-DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
x64-Notify: klogon - C:\Windows\System32\klogon.dll
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Exigo\AppData\Roaming\Mozilla\Firefox\Profiles\i52sed3g.default\
FF - prefs.js: browser.startup.homepage - about:home
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?pc=Z180&form=ZGAADF&install_date=20111104&q=
FF - prefs.js: network.proxy.type - 0
FF - component: C:\Program Files (x86)\Mozilla Firefox\extensions\[removed]\components\kavlinkfilter.dll
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrlui.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_171.dll
FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
FF - ExtSQL: 2013-03-05 13:18; {e4a8a97b-f2ed-450b-b12d-ee082ba24781}; C:\Users\Exigo\AppData\Roaming\Mozilla\Firefox\Profiles\i52sed3g.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi
FF - ExtSQL: !HIDDEN! 2011-03-04 11:35; {20a82645-c095-46ed-80e3-08825760534b}; C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
.
============= SERVICES / DRIVERS ===============
.
R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2012-12-15 56336]
R1 kl2;kl2;C:\Windows\System32\drivers\kl2.sys [2010-6-9 11864]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\System32\drivers\klim6.sys [2010-4-22 27736]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2012-7-11 140672]
R2 AdobeActiveFileMonitor11.0;Adobe Active File Monitor V11;C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe [2012-9-23 171600]
R2 AESTFilters;Andrea ST Filters Service;C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_15f4e438\AESTSr64.exe [2011-2-27 89600]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2011-2-27 202752]
R2 AVP;Kaspersky Anti-Virus Service;C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe [2010-11-2 365336]
R2 DragonSvc;Dragon Service;C:\Program Files (x86)\Common Files\Nuance\dgnsvc.exe [2010-9-24 296808]
R2 FontCache;Windows Font Cache Service;C:\Windows\System32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 27648]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2011-3-5 1153368]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdLH6.sys [2011-11-9 90128]
R3 k57nd60a;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;C:\Windows\System32\drivers\k57nd60a.sys [2011-2-27 252928]
R3 klmouflt;Kaspersky Lab KLMOUFLT;C:\Windows\System32\drivers\klmouflt.sys [2009-11-2 22544]
R3 NETwNv64;___ Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\System32\drivers\NETwNv64.sys [2011-9-2 8388096]
R3 OA008Ufd;Creative Camera OA008 Upper Filter Driver;C:\Windows\System32\drivers\OA008Ufd.sys [2011-2-27 158592]
R3 OA008Vid;Creative Camera OA008 Function Driver;C:\Windows\System32\drivers\OA008Vid.sys [2011-2-27 310784]
R3 scnuhst20;SC NUSB Host 20;C:\Windows\System32\drivers\scnuhst20.sys [2012-7-6 15872]
R3 SCNUHUB20;SC NUSB Hub 20;C:\Windows\System32\drivers\scnuhub20.sys [2012-7-6 37376]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\System32\drivers\btwl2cap.sys [2011-3-4 36392]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files (x86)\steam\steamapps\common\dragon age ultimate edition\bin_ship\DAUpdaterSvc.Service.exe –> c:\program files (x86)\steam\steamapps\common\dragon age ultimate edition\bin_ship\DAUpdaterSvc.Service.exe [?]
S3 NETw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\System32\drivers\NETw5v64.sys [2011-2-27 4735488]
S3 PerfHost;Performance Counter DLL Host;C:\Windows\SysWOW64\perfhost.exe [2008-1-20 19968]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-9-28 53760]
S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2011-3-4 89920]
.
=============== File Associations ===============
.
FileExt: .js: JSFile=C:\Windows\SysWOW64\WScript.exe "%1" %*
FileExt: .jse: JSEFile=C:\Windows\SysWOW64\WScript.exe "%1" %*
.
=============== Created Last 30 ================
.
.
==================== Find3M ====================
.
2013-03-07 22:09:07 71024 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-03-07 22:09:07 691568 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-02-15 08:15:34 70004024 —-a-w- C:\Windows\System32\mrt.exe
2013-02-02 20:10:08 95648 —-a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2013-02-02 20:10:07 861088 —-a-w- C:\Windows\SysWow64\npDeployJava1.dll
2013-02-02 20:10:07 782240 —-a-w- C:\Windows\SysWow64\deployJava1.dll
2013-02-02 20:10:07 262560 —-a-w- C:\Windows\SysWow64\javaws.exe
2013-02-02 20:10:07 174496 —-a-w- C:\Windows\SysWow64\javaw.exe
2013-02-02 20:10:07 174496 —-a-w- C:\Windows\SysWow64\java.exe
2013-01-17 06:28:58 273840 ——w- C:\Windows\System32\MpSigStub.exe
2013-01-05 13:48:44 1147392 —-a-w- C:\Windows\System32\wininet.dll
2013-01-05 13:48:27 1489408 —-a-w- C:\Windows\System32\urlmon.dll
2013-01-05 13:48:27 108032 —-a-w- C:\Windows\System32\url.dll
2013-01-05 13:46:30 243712 —-a-w- C:\Windows\System32\occache.dll
2013-01-05 13:44:42 1062912 —-a-w- C:\Windows\System32\mstime.dll
2013-01-05 13:44:20 98304 —-a-w- C:\Windows\System32\mshtmled.dll
2013-01-05 13:44:20 9331200 —-a-w- C:\Windows\System32\mshtml.dll
2013-01-05 13:44:18 743424 —-a-w- C:\Windows\System32\msfeeds.dll
2013-01-05 13:44:18 71680 —-a-w- C:\Windows\System32\msfeedsbs.dll
2013-01-05 13:43:26 56832 —-a-w- C:\Windows\System32\licmgr10.dll
2013-01-05 13:43:11 31744 —-a-w- C:\Windows\System32\jsproxy.dll
2013-01-05 13:43:00 1538560 —-a-w- C:\Windows\System32\inetcpl.cpl
2013-01-05 13:42:28 219136 —-a-w- C:\Windows\System32\ieui.dll
2013-01-05 13:42:28 132096 —-a-w- C:\Windows\System32\iesysprep.dll
2013-01-05 13:42:27 77312 —-a-w- C:\Windows\System32\iesetup.dll
2013-01-05 13:42:27 2356736 —-a-w- C:\Windows\System32\iertutil.dll
2013-01-05 13:42:22 72192 —-a-w- C:\Windows\System32\iernonce.dll
2013-01-05 13:42:20 252416 —-a-w- C:\Windows\System32\iepeers.dll
2013-01-05 13:42:20 12509184 —-a-w- C:\Windows\System32\ieframe.dll
2013-01-05 13:42:11 459776 —-a-w- C:\Windows\System32\iedkcs32.dll
2013-01-05 11:59:52 916480 —-a-w- C:\Windows\SysWow64\wininet.dll
2013-01-05 11:59:33 1212928 —-a-w- C:\Windows\SysWow64\urlmon.dll
2013-01-05 11:59:32 105984 —-a-w- C:\Windows\SysWow64\url.dll
2013-01-05 11:57:59 479232 —-a-w- C:\Windows\System32\html.iec
2013-01-05 11:57:43 206848 —-a-w- C:\Windows\SysWow64\occache.dll
2013-01-05 11:55:52 611840 —-a-w- C:\Windows\SysWow64\mstime.dll
2013-01-05 11:55:25 67072 —-a-w- C:\Windows\SysWow64\mshtmled.dll
2013-01-05 11:55:25 6010368 —-a-w- C:\Windows\SysWow64\mshtml.dll
2013-01-05 11:55:21 630272 —-a-w- C:\Windows\SysWow64\msfeeds.dll
2013-01-05 11:55:21 55296 —-a-w- C:\Windows\SysWow64\msfeedsbs.dll
2013-01-05 11:54:47 43520 —-a-w- C:\Windows\SysWow64\licmgr10.dll
2013-01-05 11:54:34 25600 —-a-w- C:\Windows\SysWow64\jsproxy.dll
2013-01-05 11:54:23 1469440 —-a-w- C:\Windows\SysWow64\inetcpl.cpl
2013-01-05 11:54:07 164352 —-a-w- C:\Windows\SysWow64\ieui.dll
2013-01-05 11:54:07 109056 —-a-w- C:\Windows\SysWow64\iesysprep.dll
2013-01-05 11:54:06 71680 —-a-w- C:\Windows\SysWow64\iesetup.dll
2013-01-05 11:54:06 2004992 —-a-w- C:\Windows\SysWow64\iertutil.dll
2013-01-05 11:54:05 55808 —-a-w- C:\Windows\SysWow64\iernonce.dll
2013-01-05 11:54:05 184320 —-a-w- C:\Windows\SysWow64\iepeers.dll
2013-01-05 11:54:05 11111424 —-a-w- C:\Windows\SysWow64\ieframe.dll
2013-01-05 11:53:59 387584 —-a-w- C:\Windows\SysWow64\iedkcs32.dll
2013-01-05 10:33:42 162816 —-a-w- C:\Windows\System32\ieUnatt.exe
2013-01-05 10:33:29 70656 —-a-w- C:\Windows\System32\ie4uinit.exe
2013-01-05 10:32:20 12288 —-a-w- C:\Windows\System32\msfeedssync.exe
2013-01-05 10:32:00 1638912 —-a-w- C:\Windows\System32\mshtml.tlb
2013-01-05 10:23:06 385024 —-a-w- C:\Windows\SysWow64\html.iec
2013-01-05 08:47:17 133632 —-a-w- C:\Windows\SysWow64\ieUnatt.exe
2013-01-05 08:46:53 174080 —-a-w- C:\Windows\SysWow64\ie4uinit.exe
2013-01-05 08:45:43 13312 —-a-w- C:\Windows\SysWow64\msfeedssync.exe
2013-01-05 08:44:46 1638912 —-a-w- C:\Windows\SysWow64\mshtml.tlb
2013-01-05 05:37:50 4695400 —-a-w- C:\Windows\System32\ntoskrnl.exe
2013-01-04 11:31:10 1423720 —-a-w- C:\Windows\System32\drivers\tcpip.sys
2013-01-04 01:59:24 2773504 —-a-w- C:\Windows\System32\win32k.sys
2012-12-16 13:31:20 48128 —-a-w- C:\Windows\System32\atmlib.dll
2012-12-16 13:12:54 34304 —-a-w- C:\Windows\SysWow64\atmlib.dll
2012-12-16 11:08:21 368128 —-a-w- C:\Windows\System32\atmfd.dll
2012-12-16 10:50:29 293376 —-a-w- C:\Windows\SysWow64\atmfd.dll
2012-12-14 21:49:28 24176 —-a-w- C:\Windows\System32\drivers\mbam.sys
.
============= FINISH: 11:11:34.78 ===============
sorry here is correct dds log
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 8.0.6001.19400 BrowserJavaVersion: 10.13.2
Run by [removed] at 11:42:04 on 2013-03-08
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2042.711 [GMT -5:00]
.
AV: Kaspersky Anti-Virus *Disabled/Updated* {56547CC9-C9B2-849D-8FEF-A496150D6A06}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Kaspersky Anti-Virus *Disabled/Updated* {ED359D2D-EF88-8B13-B55F-9FE46E8A20BB}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_15f4e438\STacSV64.exe
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_15f4e438\AESTSr64.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files (x86)\Common Files\Nuance\dgnsvc.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\TightVNC\tvnserver.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files (x86)\SugarSync\SugarSyncManager.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\BookmarkDAV_client.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\Mouse Setting\Mouse Setting Software\4.0\ACQTMAPP.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\TightVNC\tvnserver.exe
C:\Program Files (x86)\Linksys Wireless-G Print Server\PSDiagnosticM.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\SysWOW64\RunDll32.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files (x86)\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Windows\splwow64.exe
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\SyncServer.exe
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
uDefault_Page_URL = hxxp://www.dell.com
mDefault_Page_URL = hxxp://www.dell.com
mWinlogon: Userinit = userinit.exe,
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
BHO: IEVkbdBHO Class: {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\ievkbd.dll
BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO: FilterBHO Class: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll
TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: StartNow Toolbar: {5911488E-9D1E-40ec-8CBB-06B231CC153F} -
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
uRun: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
uRun: [SugarSync] "C:\Program Files (x86)\SugarSync\SugarSyncManager.exe" -startInTray -usedelay=true
uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
uRun: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe -scheduler
uRun: [EPSON NX125 NX127 Series] C:\Windows\System32\spool\DRIVERS\x64\3\E_IATIGGA.EXE /FU "C:\Windows\TEMP\E_S5BDA.tmp" /EF "HKCU"
uRun: [Facebook Update] "C:\Users\Exigo\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
uRun: [StartNow Search Protect] "C:\Program Files (x86)\StartNow Toolbar\search_protect.exe" /RELAY /REPORT /PROTECT
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
uRun: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
uRun: [ApplePhotoStreams] C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
uRun: [com.apple.dav.bookmarks.daemon] C:\Program Files (x86)\Common Files\Apple\Internet Services\BookmarkDAV_client.exe
mRun: [StartCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe"
mRun: [DNS7reminder] "C:\Program Files (x86)\Nuance\NaturallySpeaking11\Ereg\Ereg.exe" -r "C:\ProgramData\Nuance\NaturallySpeaking11\Ereg.ini
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [ACQTMOUSE] "C:\Program Files (x86)\Mouse Setting\Mouse Setting Software\4.0\ACQTMAPP.exe"
mRun: [StartNowToolbarHelper] "C:\Program Files (x86)\StartNow Toolbar\ToolbarHelper.exe"
mRun: [tvncontrol] "C:\Program Files (x86)\TightVNC\tvnserver.exe" -controlservice -slave
mRun: [PSDiagnosticM] "C:\Program Files (x86)\Linksys Wireless-G Print Server\PSDiagnosticM.exe"
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BLUETO~1.LNK - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0
mPolicies-Explorer: NoDriveTypeAutoRun = dword:28
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: SoftwareSASGeneration = dword:1
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
TCP: NameServer = 167.206.254.1 167.206.254.2
TCP: Interfaces\{E29B23B5-60AC-4E5C-BAFF-E892E1E1E0CB} : DHCPNameServer = [removed] [removed]
LSA: Security Packages = kerberos msv1_0 schannel wdigest tspkg
x64-mDefault_Page_URL = hxxp://www.dell.com
x64-BHO: IEVkbdBHO Class: {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\ievkbd.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg64.dll
x64-BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
x64-BHO: FilterBHO Class: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\klwtbbho.dll
x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-Run: [Windows Defender] C:\Program Files (x86)\Windows Defender\MSASCui.exe -hide
x64-Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
x64-Run: [QuickSet] C:\Program Files\Dell\QuickSet\QuickSet.exe
x64-Run: [SysTrayApp] C:\Program Files (x86)\IDT\WDM\sttray64.exe
x64-Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
x64-mPolicies-Explorer: NoActiveDesktop = dword:1
x64-mPolicies-Explorer: NoActiveDesktopChanges = dword:1
x64-mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0
x64-mPolicies-Explorer: NoDriveTypeAutoRun = dword:28
x64-mPolicies-System: EnableUIADesktopToggle = dword:0
x64-mPolicies-System: SoftwareSASGeneration = dword:1
x64-IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\klwtbbho.dll
x64-IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
x64-IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\klwtbbho.dll
.
INFO: x64-HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
x64-DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
x64-DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
x64-Notify: klogon - C:\Windows\System32\klogon.dll
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Exigo\AppData\Roaming\Mozilla\Firefox\Profiles\i52sed3g.default\
FF - prefs.js: browser.startup.homepage - about:home
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?pc=Z180&form=ZGAADF&install_date=20111104&q=
FF - prefs.js: network.proxy.type - 0
FF - component: C:\Program Files (x86)\Mozilla Firefox\extensions\[removed]\components\kavlinkfilter.dll
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrlui.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_171.dll
FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
FF - ExtSQL: 2013-03-05 13:18; {e4a8a97b-f2ed-450b-b12d-ee082ba24781}; C:\Users\Exigo\AppData\Roaming\Mozilla\Firefox\Profiles\i52sed3g.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi
FF - ExtSQL: !HIDDEN! 2011-03-04 11:35; {20a82645-c095-46ed-80e3-08825760534b}; C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
.
============= SERVICES / DRIVERS ===============
.
R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2012-12-15 56336]
R1 kl2;kl2;C:\Windows\System32\drivers\kl2.sys [2010-6-9 11864]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\System32\drivers\klim6.sys [2010-4-22 27736]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2012-7-11 140672]
R2 AdobeActiveFileMonitor11.0;Adobe Active File Monitor V11;C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe [2012-9-23 171600]
R2 AESTFilters;Andrea ST Filters Service;C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_15f4e438\AESTSr64.exe [2011-2-27 89600]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2011-2-27 202752]
R2 AVP;Kaspersky Anti-Virus Service;C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe [2010-11-2 365336]
R2 DragonSvc;Dragon Service;C:\Program Files (x86)\Common Files\Nuance\dgnsvc.exe [2010-9-24 296808]
R2 FontCache;Windows Font Cache Service;C:\Windows\System32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 27648]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2011-3-5 1153368]
R2 tvnserver;TightVNC Server;C:\Program Files (x86)\TightVNC\tvnserver.exe [2011-8-3 828944]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdLH6.sys [2011-11-9 90128]
R3 k57nd60a;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;C:\Windows\System32\drivers\k57nd60a.sys [2011-2-27 252928]
R3 klmouflt;Kaspersky Lab KLMOUFLT;C:\Windows\System32\drivers\klmouflt.sys [2009-11-2 22544]
R3 NETwNv64;___ Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\System32\drivers\NETwNv64.sys [2011-9-2 8388096]
R3 OA008Ufd;Creative Camera OA008 Upper Filter Driver;C:\Windows\System32\drivers\OA008Ufd.sys [2011-2-27 158592]
R3 OA008Vid;Creative Camera OA008 Function Driver;C:\Windows\System32\drivers\OA008Vid.sys [2011-2-27 310784]
R3 scnuhst20;SC NUSB Host 20;C:\Windows\System32\drivers\scnuhst20.sys [2012-7-6 15872]
R3 SCNUHUB20;SC NUSB Hub 20;C:\Windows\System32\drivers\scnuhub20.sys [2012-7-6 37376]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 Updater Service for StartNow Toolbar;Updater Service for StartNow Toolbar;C:\Program Files (x86)\StartNow Toolbar\ToolbarUpdaterService.exe –> C:\Program Files (x86)\StartNow Toolbar\ToolbarUpdaterService.exe [?]
S3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\System32\drivers\btwl2cap.sys [2011-3-4 36392]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files (x86)\steam\steamapps\common\dragon age ultimate edition\bin_ship\DAUpdaterSvc.Service.exe –> c:\program files (x86)\steam\steamapps\common\dragon age ultimate edition\bin_ship\DAUpdaterSvc.Service.exe [?]
S3 NETw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\System32\drivers\NETw5v64.sys [2011-2-27 4735488]
S3 PerfHost;Performance Counter DLL Host;C:\Windows\SysWOW64\perfhost.exe [2008-1-20 19968]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-9-28 53760]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-3-18 1020768]
S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2011-3-4 89920]
.
=============== File Associations ===============
.
FileExt: .js: JSFile=C:\Windows\SysWOW64\WScript.exe "%1" %*
FileExt: .jse: JSEFile=C:\Windows\SysWOW64\WScript.exe "%1" %*
.
=============== Created Last 30 ================
.
.
==================== Find3M ====================
.
2013-03-07 22:09:07 71024 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-03-07 22:09:07 691568 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-02-15 08:15:34 70004024 —-a-w- C:\Windows\System32\mrt.exe
2013-02-02 20:10:08 95648 —-a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2013-02-02 20:10:07 861088 —-a-w- C:\Windows\SysWow64\npDeployJava1.dll
2013-02-02 20:10:07 782240 —-a-w- C:\Windows\SysWow64\deployJava1.dll
2013-02-02 20:10:07 262560 —-a-w- C:\Windows\SysWow64\javaws.exe
2013-02-02 20:10:07 174496 —-a-w- C:\Windows\SysWow64\javaw.exe
2013-02-02 20:10:07 174496 —-a-w- C:\Windows\SysWow64\java.exe
2013-01-17 06:28:58 273840 ——w- C:\Windows\System32\MpSigStub.exe
2013-01-05 13:48:44 1147392 —-a-w- C:\Windows\System32\wininet.dll
2013-01-05 13:48:27 1489408 —-a-w- C:\Windows\System32\urlmon.dll
2013-01-05 13:48:27 108032 —-a-w- C:\Windows\System32\url.dll
2013-01-05 13:46:30 243712 —-a-w- C:\Windows\System32\occache.dll
2013-01-05 13:44:42 1062912 —-a-w- C:\Windows\System32\mstime.dll
2013-01-05 13:44:20 98304 —-a-w- C:\Windows\System32\mshtmled.dll
2013-01-05 13:44:20 9331200 —-a-w- C:\Windows\System32\mshtml.dll
2013-01-05 13:44:18 743424 —-a-w- C:\Windows\System32\msfeeds.dll
2013-01-05 13:44:18 71680 —-a-w- C:\Windows\System32\msfeedsbs.dll
2013-01-05 13:43:26 56832 —-a-w- C:\Windows\System32\licmgr10.dll
2013-01-05 13:43:11 31744 —-a-w- C:\Windows\System32\jsproxy.dll
2013-01-05 13:43:00 1538560 —-a-w- C:\Windows\System32\inetcpl.cpl
2013-01-05 13:42:28 219136 —-a-w- C:\Windows\System32\ieui.dll
2013-01-05 13:42:28 132096 —-a-w- C:\Windows\System32\iesysprep.dll
2013-01-05 13:42:27 77312 —-a-w- C:\Windows\System32\iesetup.dll
2013-01-05 13:42:27 2356736 —-a-w- C:\Windows\System32\iertutil.dll
2013-01-05 13:42:22 72192 —-a-w- C:\Windows\System32\iernonce.dll
2013-01-05 13:42:20 252416 —-a-w- C:\Windows\System32\iepeers.dll
2013-01-05 13:42:20 12509184 —-a-w- C:\Windows\System32\ieframe.dll
2013-01-05 13:42:11 459776 —-a-w- C:\Windows\System32\iedkcs32.dll
2013-01-05 11:59:52 916480 —-a-w- C:\Windows\SysWow64\wininet.dll
2013-01-05 11:59:33 1212928 —-a-w- C:\Windows\SysWow64\urlmon.dll
2013-01-05 11:59:32 105984 —-a-w- C:\Windows\SysWow64\url.dll
2013-01-05 11:57:59 479232 —-a-w- C:\Windows\System32\html.iec
2013-01-05 11:57:43 206848 —-a-w- C:\Windows\SysWow64\occache.dll
2013-01-05 11:55:52 611840 —-a-w- C:\Windows\SysWow64\mstime.dll
2013-01-05 11:55:25 67072 —-a-w- C:\Windows\SysWow64\mshtmled.dll
2013-01-05 11:55:25 6010368 —-a-w- C:\Windows\SysWow64\mshtml.dll
2013-01-05 11:55:21 630272 —-a-w- C:\Windows\SysWow64\msfeeds.dll
2013-01-05 11:55:21 55296 —-a-w- C:\Windows\SysWow64\msfeedsbs.dll
2013-01-05 11:54:47 43520 —-a-w- C:\Windows\SysWow64\licmgr10.dll
2013-01-05 11:54:34 25600 —-a-w- C:\Windows\SysWow64\jsproxy.dll
2013-01-05 11:54:23 1469440 —-a-w- C:\Windows\SysWow64\inetcpl.cpl
2013-01-05 11:54:07 164352 —-a-w- C:\Windows\SysWow64\ieui.dll
2013-01-05 11:54:07 109056 —-a-w- C:\Windows\SysWow64\iesysprep.dll
2013-01-05 11:54:06 71680 —-a-w- C:\Windows\SysWow64\iesetup.dll
2013-01-05 11:54:06 2004992 —-a-w- C:\Windows\SysWow64\iertutil.dll
2013-01-05 11:54:05 55808 —-a-w- C:\Windows\SysWow64\iernonce.dll
2013-01-05 11:54:05 184320 —-a-w- C:\Windows\SysWow64\iepeers.dll
2013-01-05 11:54:05 11111424 —-a-w- C:\Windows\SysWow64\ieframe.dll
2013-01-05 11:53:59 387584 —-a-w- C:\Windows\SysWow64\iedkcs32.dll
2013-01-05 10:33:42 162816 —-a-w- C:\Windows\System32\ieUnatt.exe
2013-01-05 10:33:29 70656 —-a-w- C:\Windows\System32\ie4uinit.exe
2013-01-05 10:32:20 12288 —-a-w- C:\Windows\System32\msfeedssync.exe
2013-01-05 10:32:00 1638912 —-a-w- C:\Windows\System32\mshtml.tlb
2013-01-05 10:23:06 385024 —-a-w- C:\Windows\SysWow64\html.iec
2013-01-05 08:47:17 133632 —-a-w- C:\Windows\SysWow64\ieUnatt.exe
2013-01-05 08:46:53 174080 —-a-w- C:\Windows\SysWow64\ie4uinit.exe
2013-01-05 08:45:43 13312 —-a-w- C:\Windows\SysWow64\msfeedssync.exe
2013-01-05 08:44:46 1638912 —-a-w- C:\Windows\SysWow64\mshtml.tlb
2013-01-05 05:37:50 4695400 —-a-w- C:\Windows\System32\ntoskrnl.exe
2013-01-04 11:31:10 1423720 —-a-w- C:\Windows\System32\drivers\tcpip.sys
2013-01-04 01:59:24 2773504 —-a-w- C:\Windows\System32\win32k.sys
2012-12-16 13:31:20 48128 —-a-w- C:\Windows\System32\atmlib.dll
2012-12-16 13:12:54 34304 —-a-w- C:\Windows\SysWow64\atmlib.dll
2012-12-16 11:08:21 368128 —-a-w- C:\Windows\System32\atmfd.dll
2012-12-16 10:50:29 293376 —-a-w- C:\Windows\SysWow64\atmfd.dll
2012-12-14 21:49:28 24176 —-a-w- C:\Windows\System32\drivers\mbam.sys
.
============= FINISH: 11:42:22.65 ===============
That looks pretty good. Let's run ComboFix and then clean up any dross that might be left.
Download ComboFix from here: http://download.bleepingcomputer.com/sUBs/ComboFix.exe
* IMPORTANT !!! Save ComboFix.exe to your Desktop
Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html
Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
[external image: Posted Image]
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
[external image: Posted Image]
Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the
C:\ComboFix.txt in your next reply.
Notes:
1.
Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2.
Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely , the connection can be manually restored by restarting your machine.
ComboFix 13-03-07.03 - Exigo 03/08/2013 13:03:44.1.2 - x64
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2042.533 [GMT -5:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: Kaspersky Anti-Virus *Disabled/Updated* {56547CC9-C9B2-849D-8FEF-A496150D6A06}
SP: Kaspersky Anti-Virus *Disabled/Updated* {ED359D2D-EF88-8B13-B55F-9FE46E8A20BB}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Exigo\AppData\Roaming\Mozilla\Firefox\Profiles\i52sed3g.default\searchplugins\bing-zugo.xml
c:\users\Exigo\Documents\~WRL0078.tmp
c:\users\Exigo\Documents\~WRL0243.tmp
c:\users\Exigo\Documents\~WRL0331.tmp
c:\users\Exigo\Documents\~WRL1836.tmp
c:\users\Exigo\Documents\~WRL2096.tmp
c:\users\Exigo\Documents\~WRL2568.tmp
c:\windows\SysWow64\URTTemp
c:\windows\SysWow64\URTTemp\regtlib.exe
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Service_Updater Service for StartNow Toolbar
.
.
((((((((((((((((((((((((( Files Created from 2013-02-08 to 2013-03-08 )))))))))))))))))))))))))))))))
.
.
2013-03-08 18:18 . 2013-03-08 18:18 ——– d—–w- c:\users\Default\AppData\Local\temp
2013-03-08 12:13 . 2013-02-08 00:28 9162192 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B569DFF8-321E-405C-ADB2-73D91C322705}\mpengine.dll
2013-02-15 22:31 . 2013-02-15 22:31 186432 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\nppdf32.dll
2013-02-14 16:56 . 2013-01-04 11:31 1423720 —-a-w- c:\windows\system32\drivers\tcpip.sys
2013-02-14 16:56 . 2013-01-02 11:08 1027584 —-a-w- c:\program files\Common Files\Microsoft Shared\vgx\VGX.dll
2013-02-14 16:56 . 2013-01-02 07:37 759296 —-a-w- c:\program files (x86)\Common Files\Microsoft Shared\vgx\VGX.dll
2013-02-14 16:56 . 2013-01-04 01:59 2773504 —-a-w- c:\windows\system32\win32k.sys
2013-02-14 16:55 . 2013-01-05 13:44 9331200 —-a-w- c:\windows\system32\mshtml.dll
2013-02-14 16:55 . 2013-01-05 13:42 12509184 —-a-w- c:\windows\system32\ieframe.dll
2013-02-14 16:55 . 2013-01-05 13:42 2356736 —-a-w- c:\windows\system32\iertutil.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-03-07 22:09 . 2012-06-01 13:26 691568 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-03-07 22:09 . 2011-05-16 13:57 71024 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-02-15 08:15 . 2006-11-02 12:35 70004024 —-a-w- c:\windows\system32\mrt.exe
2013-02-02 20:10 . 2013-02-02 20:10 95648 —-a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-02-02 20:10 . 2012-06-21 12:49 861088 —-a-w- c:\windows\SysWow64\npDeployJava1.dll
2013-02-02 20:10 . 2011-03-04 16:39 782240 —-a-w- c:\windows\SysWow64\deployJava1.dll
2013-01-17 06:28 . 2011-03-04 17:54 273840 ——w- c:\windows\system32\MpSigStub.exe
2012-12-16 13:31 . 2012-12-22 08:01 48128 —-a-w- c:\windows\system32\atmlib.dll
2012-12-16 13:12 . 2012-12-22 08:01 34304 —-a-w- c:\windows\SysWow64\atmlib.dll
2012-12-16 11:08 . 2012-12-22 08:01 368128 —-a-w- c:\windows\system32\atmfd.dll
2012-12-16 10:50 . 2012-12-22 08:01 293376 —-a-w- c:\windows\SysWow64\atmfd.dll
2012-12-14 21:49 . 2011-03-05 15:06 24176 —-a-w- c:\windows\system32\drivers\mbam.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files (x86)\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"SugarSync"="c:\program files (x86)\SugarSync\SugarSyncManager.exe" [2013-01-24 11184480]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-03-07 39408]
"ISUSPM"="c:\programdata\FLEXnet\Connect\11\ISUSPM.exe" [2010-09-24 222496]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2012-12-04 5629312]
"iCloudServices"="c:\program files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe" [2012-12-17 59872]
"ApplePhotoStreams"="c:\program files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe" [2012-12-17 59872]
"com.apple.dav.bookmarks.daemon"="c:\program files (x86)\Common Files\Apple\Internet Services\BookmarkDAV_client.exe" [2012-12-17 59872]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-01-22 98304]
"AVP"="c:\program files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe" [2010-11-03 365336]
"DNS7reminder"="c:\program files (x86)\Nuance\NaturallySpeaking11\Ereg\Ereg.exe" [2007-04-16 259624]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]
"ACQTMOUSE"="c:\program files (x86)\Mouse Setting\Mouse Setting Software\4.0\ACQTMAPP.exe" [2008-08-01 501760]
"tvncontrol"="c:\program files (x86)\TightVNC\tvnserver.exe" [2011-08-03 828944]
"PSDiagnosticM"="c:\program files (x86)\Linksys Wireless-G Print Server\PSDiagnosticM.exe" [2009-06-19 505128]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-12-12 152544]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-11-17 1066536]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"SoftwareSASGeneration"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2012-07-11 140672]
S2 AdobeActiveFileMonitor11.0;Adobe Active File Monitor V11;c:\program files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe [2012-09-23 171600]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_15f4e438\AESTSr64.exe [2009-03-20 89600]
.
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - WS2IFSL
.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
Themes
.
Contents of the 'Scheduled Tasks' folder
.
2013-03-08 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-01 22:09]
.
2013-03-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-07 18:59]
.
2013-03-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-07 18:59]
.
2011-03-05 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- c:\program files (x86)\Spybot - Search & Destroy\SpybotSD.exe [2011-03-05 20:31]
.
2013-03-08 c:\windows\Tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
- c:\program files (x86)\Spybot - Search & Destroy\SDUpdate.exe [2011-03-05 20:31]
.
.
——— X64 Entries ———–
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncBackedUp]
@="{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472}"
[HKEY_CLASSES_ROOT\CLSID\{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472}]
2013-01-24 07:48 482144 —-a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncPending]
@="{62CCD8E3-9C21-41E1-B55E-1E26DFC68511}"
[HKEY_CLASSES_ROOT\CLSID\{62CCD8E3-9C21-41E1-B55E-1E26DFC68511}]
2013-01-24 07:48 482144 —-a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncRoot]
@="{A759AFF6-5851-457D-A540-F4ECED148351}"
[HKEY_CLASSES_ROOT\CLSID\{A759AFF6-5851-457D-A540-F4ECED148351}]
2013-01-24 07:48 482144 —-a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncShared]
@="{1574C9EF-7D58-488F-B358-8B78C1538F51}"
[HKEY_CLASSES_ROOT\CLSID\{1574C9EF-7D58-488F-B358-8B78C1538F51}]
2013-01-24 07:48 482144 —-a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-11-26 1657128]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-06-16 499608]
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
uLocal Page = c:\windows\system32\blank.htm
mDefault_Page_URL = hxxp://www.dell.com
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = [removed] [removed]
FF - ProfilePath - c:\users\Exigo\AppData\Roaming\Mozilla\Firefox\Profiles\i52sed3g.default\
FF - prefs.js: browser.startup.homepage - about:home
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?pc=Z180&form=ZGAADF&install_date=20111104&q=
FF - prefs.js: network.proxy.type - 0
FF - ExtSQL: 2013-03-05 13:18; {e4a8a97b-f2ed-450b-b12d-ee082ba24781}; c:\users\Exigo\AppData\Roaming\Mozilla\Firefox\Profiles\i52sed3g.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi
FF - ExtSQL: !HIDDEN! 2011-03-04 11:35; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-{5911488E-9D1E-40ec-8CBB-06B231CC153F} - c:\program files (x86)\StartNow Toolbar\Toolbar32.dll
Wow6432Node-HKCU-Run-Facebook Update - c:\users\Exigo\AppData\Local\Facebook\Update\FacebookUpdate.exe
Wow6432Node-HKCU-Run-StartNow Search Protect - c:\program files (x86)\StartNow Toolbar\search_protect.exe
Wow6432Node-HKLM-Run-StartNowToolbarHelper - c:\program files (x86)\StartNow Toolbar\ToolbarHelper.exe
SafeBoot-WudfPf
SafeBoot-WudfRd
HKLM-Run-SysTrayApp - c:\program files (x86)\IDT\WDM\sttray64.exe
AddRemove-don't take it personally, babe, it just ain't your story - c:\program files (x86)\don't take it personally
AddRemove-ESN Sonar-0.70.0 - c:\program files (x86)\Battlelog Web Plugins\Sonar\esnsonar_uninstall.exe
AddRemove-PunkBusterSvc - c:\program files (x86)\Steam\steamapps\common\Assassins Creed Brotherhood\pbsvc.exe
AddRemove-StartNow Toolbar - c:\program files (x86)\StartNow Toolbar\StartNowToolbarUninstall.exe
AddRemove-{B5E6D105-DFB4-46B4-88BF-9DC52686DBE7}_is1 - c:\program files (x86)\Steam\steamapps\common\medieval ii total war\mods\Broken_Crescent_kingdoms\unins000.exe
.
.
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-219705432-3252208987-4262155305-1000\Software\SecuROM\License information*]
"datasecu"=hex:c0,e9,08,51,cd,ac,51,6e,54,65,ef,9b,1c,0f,4e,81,c6,1f,c6,e2,bc,
7a,6d,40,3f,1c,0d,1b,5b,f6,d2,33,fc,7c,b8,d1,56,fc,21,6f,d0,10,00,52,1b,e7,\
"rkeysecu"=hex:6d,83,00,fd,94,57,e5,65,5a,4d,71,bb,a7,b9,72,29
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_171_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_171_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_171_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_171_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_171.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_171.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_171.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_171.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@=""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@="FlashBroker"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
———————— Other Running Processes ————————
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Common Files\Nuance\dgnsvc.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe
c:\windows\SysWOW64\RunDll32.exe
c:\program files (x86)\Common Files\Java\Java Update\jucheck.exe
.
**************************************************************************
.
Completion time: 2013-03-08 13:41:58 - machine was rebooted
ComboFix-quarantined-files.txt 2013-03-08 18:41
.
Pre-Run: 299,911,245,824 bytes free
Post-Run: 300,278,140,928 bytes free
.
- - End Of File - - 9069AD7BB0A539F9038DBFEE57F5FAB3
Awesome. That took care of all the adware I saw.
Let's get an online scan to have a look for things I can't see.
Go
here to run an online scanner from
ESET.
Turn off the real time scanner of any existing antivirus program while performing the online scan Tick the box next to YES, I accept the Terms of Use. Click Start When asked, allow the activeX control to install Click Start Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked. Click on Advanced Settings, ensure the options Scan for potentially unwanted applications , Scan for potentially unsafe applications , and Enable Anti-Stealth Technology are ticked. Click Scan Wait for the scan to finish When the scan completes, press the LIST OF THREATS FOUND button Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop Include the contents of this report in your next reply. Press the BACK button. Press Finish
Also, please let me know how things seem to be working.
Hope these aren't too nasty?
C:\Users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43\13eb6b6b-18bddd28 a variant of Java/TrojanDownloader.Agent.NDJ trojan
C:\Users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55\51d1c3f7-1fc93e9e a variant of Java/TrojanDownloader.OpenStream.NCE trojan
C:\Users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63\304979ff-2cd01e37 multiple threats
C:\Users\Exigo\Downloads\APB_Reloaded_Installer.exe Win32/OpenCandy application
C:\Users\Exigo\Downloads\Calhoun HS Sports Boosters 2012 Golf Outing pdf(1).exe Win32/InstalleRex.E.Gen application
C:\Users\Exigo\Downloads\Calhoun HS Sports Boosters 2012 Golf Outing pdf.exe Win32/InstalleRex.E.Gen application
C:\Users\Exigo\Downloads\PlayFLV(1).exe Win32/TrojanDownloader.Adload.NIQ trojan
C:\Users\Exigo\Downloads\PlayFLV.exe Win32/TrojanDownloader.Adload.NIQ trojan
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\55VD0P0Q\updater-startnow-200-2.5-d[1].exe a variant of Win32/Toolbar.Zugo application
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\55VD0P0Q\updater-startnow-200-2.5-d[1].exe a variant of Win32/Toolbar.Zugo application
Everything appears to be running ok. No more random blue hyperlinks.
Webpages load well, apps-ie word, excel open fine.
Those infected downloads are probably what started your problems:
COMBOFIX-Script
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
ComboFix 13-03-10.02 - Exigo 03/10/2013 13:05:43.2.2 - x64
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2042.702 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Exigo\Desktop\CFScript.txt
AV: Kaspersky Anti-Virus *Disabled/Updated* {56547CC9-C9B2-849D-8FEF-A496150D6A06}
SP: Kaspersky Anti-Virus *Disabled/Updated* {ED359D2D-EF88-8B13-B55F-9FE46E8A20BB}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\users\Exigo\Downloads\APB_Reloaded_Installer.exe"
"c:\users\Exigo\Downloads\Calhoun HS Sports Boosters 2012 Golf Outing pdf(1).exe"
"c:\users\Exigo\Downloads\Calhoun HS Sports Boosters 2012 Golf Outing pdf.exe"
"c:\users\Exigo\Downloads\PlayFLV(1).exe"
"c:\users\Exigo\Downloads\PlayFLV.exe"
"c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\55VD0P0Q\updater-startnow-200-2.5-d[1].exe"
"c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\55VD0P0Q\updater-startnow-200-2.5-d[1].exe"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0\532b51c0-28d0a946
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0\532b51c0-28d0a946.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11\12762e8b-6c886d06
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11\12762e8b-6c886d06.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11\4792d4b-77c1ceee
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11\4792d4b-77c1ceee.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12\171d130c-1cd1b1fd
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12\171d130c-1cd1b1fd.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12\3c28044c-28f7c1b1
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12\3c28044c-28f7c1b1.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12\4db9990c-1b304816
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12\4db9990c-1b304816.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13\52bc730d-69ec03ca
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13\52bc730d-69ec03ca.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13\52bc730d-706b0272
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13\52bc730d-706b0272.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13\68b154cd-1c5fba9f
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13\68b154cd-1c5fba9f.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14\3bc1b4e-13e6fe30
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14\3bc1b4e-13e6fe30.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\15\360e8b0f-7f2adb07
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\15\360e8b0f-7f2adb07.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\533cc850-42ecbd48
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\533cc850-42ecbd48.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\57e76190-45943e03
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\57e76190-45943e03.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\74bac490-26fb8f76
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\74bac490-26fb8f76.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\7b8a5350-21bde734
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\7b8a5350-21bde734.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\7ef9f550-536261c3
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\7ef9f550-536261c3.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\61fa3d11-181ad4a8
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\61fa3d11-181ad4a8.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\d59d251-122da4f5
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\d59d251-122da4f5.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18\3d518612-12838d60
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18\3d518612-12838d60.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19\29ebdd13-727cd5d3
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19\29ebdd13-727cd5d3.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19\69cc3853-104e32ef
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19\69cc3853-104e32ef.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2\5a38a7c2-7f4347be
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2\5a38a7c2-7f4347be.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20\279bffd4-36933ce6
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20\279bffd4-36933ce6.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20\40b36cd4-2bec5084
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20\40b36cd4-2bec5084.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20\62b1f2d4-63f8562f
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20\62b1f2d4-63f8562f.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25\7010a1d9-7f5acfff
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25\7010a1d9-7f5acfff.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\26\716a051a-2724c625
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\26\716a051a-2724c625.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27\5c78191b-2e0e01f6
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27\5c78191b-2e0e01f6.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28\26b0251c-6fa12773
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28\26b0251c-6fa12773.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28\32ccd61c-1ad62235
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28\32ccd61c-1ad62235.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28\5309a69c-7ab3922f
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28\5309a69c-7ab3922f.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29\32a8ba1d-5e2e404a
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29\32a8ba1d-5e2e404a.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3\520f91c3-33c3bfb9
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3\520f91c3-33c3bfb9.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30\13c8259e-114b894d
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30\13c8259e-114b894d.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30\13c8259e-12e066f5
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30\13c8259e-12e066f5.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30\60f58fde-40de2f9b
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30\60f58fde-40de2f9b.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31\111e5e1f-1749665b
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31\111e5e1f-1749665b.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31\790c545f-6dce903e
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31\790c545f-6dce903e.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32\29739120-6a2b30b1
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32\29739120-6a2b30b1.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32\524312e0-516996d2
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32\524312e0-516996d2.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32\524312e0-629444dc
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32\524312e0-629444dc.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\7e22ef61-3e2c8338
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\7e22ef61-3e2c8338.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\7e22ef61-78f55ecb
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\7e22ef61-78f55ecb.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\34\618f7e2-4a43b327
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\34\618f7e2-4a43b327.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36\546effe4-5ae840c1
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36\546effe4-5ae840c1.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37\39e9c725-70027e61
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37\39e9c725-70027e61.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37\74973ee5-3481f725
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37\74973ee5-3481f725.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38\56a51ee6-14c66996
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38\56a51ee6-14c66996.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39\120daf27-655706c0
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39\120daf27-655706c0.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39\7702d9a7-1b7d3c35
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39\7702d9a7-1b7d3c35.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4\741599c4-570ac6c5
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4\741599c4-570ac6c5.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40\1e434aa8-4cb33a39
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40\1e434aa8-4cb33a39.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40\1e434aa8-7c8cf735
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40\1e434aa8-7c8cf735.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40\24958828-6beb7ec0
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40\24958828-6beb7ec0.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40\785a4d68-13f739c8
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40\785a4d68-13f739c8.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41\2fcb83e9-1b6af6d7
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41\2fcb83e9-1b6af6d7.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42\245b39ea-73703967
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42\245b39ea-73703967.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43\13eb6b6b-18bddd28
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43\13eb6b6b-18bddd28.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43\5c2df5ab-357c0109
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43\5c2df5ab-357c0109.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43\5c2df5ab-7d52cde9
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43\5c2df5ab-7d52cde9.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46\611aee2e-6b3127ff
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46\611aee2e-6b3127ff.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46\73c78dae-21547048
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46\73c78dae-21547048.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47\a2019ef-171a87ea
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47\a2019ef-171a87ea.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47\a2019ef-54b77a99
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47\a2019ef-54b77a99.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48\1944c670-13a7cea4
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48\1944c670-13a7cea4.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48\23fc14f0-76fe100a
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48\23fc14f0-76fe100a.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48\38c71130-2385595e
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48\38c71130-2385595e.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48\4c716570-34bc27c6
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48\4c716570-34bc27c6.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49\2930faf1-3a2f678f
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49\2930faf1-3a2f678f.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5\45eeac45-53c23023
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5\45eeac45-53c23023.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5\45eeac45-5a9839ea
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5\45eeac45-5a9839ea.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5\e61ea05-286f9234
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5\e61ea05-286f9234.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50\7ca4c5b2-391704a8
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50\7ca4c5b2-391704a8.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51\7f4949b3-12b998b3
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51\7f4949b3-12b998b3.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52\61773234-5764c375
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52\61773234-5764c375.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52\7b7b5174-21461ee0
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52\7b7b5174-21461ee0.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52\7b7b5174-5a418f03
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52\7b7b5174-5a418f03.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53\344e9c75-238ee06c
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53\344e9c75-238ee06c.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54\60d03236-6d6c1a49
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54\60d03236-6d6c1a49.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55\51d1c3f7-1fc93e9e
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55\51d1c3f7-1fc93e9e.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56\33dcb938-542f0721
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56\33dcb938-542f0721.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56\4966c78-2467c677
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56\4966c78-2467c677.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56\72814438-192b984c
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56\72814438-192b984c.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\149d93f9-7339dee8
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\149d93f9-7339dee8.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\6c019739-33b1f17a
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\6c019739-33b1f17a.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\718a9779-2e3b8de0
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\718a9779-2e3b8de0.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\7836a5f9-7957a5f6
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\7836a5f9-7957a5f6.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58\41d630fa-3497b635
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58\41d630fa-3497b635.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59\23176efb-1c1042ec
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59\23176efb-1c1042ec.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59\2f5fe1fb-7b2a33f3
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59\2f5fe1fb-7b2a33f3.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6\579f0086-2da49acb
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6\579f0086-2da49acb.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60\a25923c-1c6ad642
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60\a25923c-1c6ad642.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63\304979ff-2cd01e37
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63\304979ff-2cd01e37.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7\15e0d207-6a266fe9
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7\15e0d207-6a266fe9.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\3177f4c8-2be60a82
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\3177f4c8-2be60a82.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\45130888-14b0bf42
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\45130888-14b0bf42.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\6f2b1608-6421b7de
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\6f2b1608-6421b7de.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9\1421a189-24eb8418
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9\1421a189-24eb8418.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9\721dfe89-3fab5877
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9\721dfe89-3fab5877.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9\721dfe89-731906b7
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9\721dfe89-731906b7.idx
c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\lastAccessed
c:\users\Exigo\Downloads\APB_Reloaded_Installer.exe
c:\users\Exigo\Downloads\Calhoun HS Sports Boosters 2012 Golf Outing pdf(1).exe
c:\users\Exigo\Downloads\Calhoun HS Sports Boosters 2012 Golf Outing pdf.exe
c:\users\Exigo\Downloads\PlayFLV(1).exe
c:\users\Exigo\Downloads\PlayFLV.exe
c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\55VD0P0Q\updater-startnow-200-2.5-d[1].exe
.
.
((((((((((((((((((((((((( Files Created from 2013-02-10 to 2013-03-10 )))))))))))))))))))))))))))))))
.
.
2013-03-10 17:21 . 2013-03-10 17:21 ——– d—–w- c:\users\Exigo\AppData\Local\temp
2013-03-10 17:21 . 2013-03-10 17:21 ——– d—–w- c:\users\Default\AppData\Local\temp
2013-03-09 16:32 . 2013-03-09 16:32 ——– d—–w- c:\program files (x86)\ESET
2013-03-08 12:13 . 2013-02-08 00:28 9162192 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B569DFF8-321E-405C-ADB2-73D91C322705}\mpengine.dll
2013-02-15 22:31 . 2013-02-15 22:31 186432 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\nppdf32.dll
2013-02-14 16:56 . 2013-01-04 11:31 1423720 —-a-w- c:\windows\system32\drivers\tcpip.sys
2013-02-14 16:56 . 2013-01-02 11:08 1027584 —-a-w- c:\program files\Common Files\Microsoft Shared\vgx\VGX.dll
2013-02-14 16:56 . 2013-01-02 07:37 759296 —-a-w- c:\program files (x86)\Common Files\Microsoft Shared\vgx\VGX.dll
2013-02-14 16:56 . 2013-01-04 01:59 2773504 —-a-w- c:\windows\system32\win32k.sys
2013-02-14 16:55 . 2013-01-05 13:44 9331200 —-a-w- c:\windows\system32\mshtml.dll
2013-02-14 16:55 . 2013-01-05 13:42 12509184 —-a-w- c:\windows\system32\ieframe.dll
2013-02-14 16:55 . 2013-01-05 13:42 2356736 —-a-w- c:\windows\system32\iertutil.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-03-07 22:09 . 2012-06-01 13:26 691568 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-03-07 22:09 . 2011-05-16 13:57 71024 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-02-15 08:15 . 2006-11-02 12:35 70004024 —-a-w- c:\windows\system32\mrt.exe
2013-02-02 20:10 . 2013-02-02 20:10 95648 —-a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-02-02 20:10 . 2012-06-21 12:49 861088 —-a-w- c:\windows\SysWow64\npDeployJava1.dll
2013-02-02 20:10 . 2011-03-04 16:39 782240 —-a-w- c:\windows\SysWow64\deployJava1.dll
2013-01-17 06:28 . 2011-03-04 17:54 273840 ——w- c:\windows\system32\MpSigStub.exe
2012-12-16 13:31 . 2012-12-22 08:01 48128 —-a-w- c:\windows\system32\atmlib.dll
2012-12-16 13:12 . 2012-12-22 08:01 34304 —-a-w- c:\windows\SysWow64\atmlib.dll
2012-12-16 11:08 . 2012-12-22 08:01 368128 —-a-w- c:\windows\system32\atmfd.dll
2012-12-16 10:50 . 2012-12-22 08:01 293376 —-a-w- c:\windows\SysWow64\atmfd.dll
2012-12-14 21:49 . 2011-03-05 15:06 24176 —-a-w- c:\windows\system32\drivers\mbam.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{5911488E-9D1E-40ec-8CBB-06B231CC153F}"= "c:\program files (x86)\StartNow Toolbar\Toolbar32.dll" [BU]
.
[HKEY_CLASSES_ROOT\clsid\{5911488e-9d1e-40ec-8cbb-06b231cc153f}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files (x86)\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"SugarSync"="c:\program files (x86)\SugarSync\SugarSyncManager.exe" [2013-01-24 11184480]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-03-07 39408]
"ISUSPM"="c:\programdata\FLEXnet\Connect\11\ISUSPM.exe" [2010-09-24 222496]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2012-12-04 5629312]
"iCloudServices"="c:\program files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe" [2012-12-17 59872]
"ApplePhotoStreams"="c:\program files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe" [2012-12-17 59872]
"com.apple.dav.bookmarks.daemon"="c:\program files (x86)\Common Files\Apple\Internet Services\BookmarkDAV_client.exe" [2012-12-17 59872]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-01-22 98304]
"AVP"="c:\program files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe" [2010-11-03 365336]
"DNS7reminder"="c:\program files (x86)\Nuance\NaturallySpeaking11\Ereg\Ereg.exe" [2007-04-16 259624]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]
"ACQTMOUSE"="c:\program files (x86)\Mouse Setting\Mouse Setting Software\4.0\ACQTMAPP.exe" [2008-08-01 501760]
"tvncontrol"="c:\program files (x86)\TightVNC\tvnserver.exe" [2011-08-03 828944]
"PSDiagnosticM"="c:\program files (x86)\Linksys Wireless-G Print Server\PSDiagnosticM.exe" [2009-06-19 505128]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-12-12 152544]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-11-17 1066536]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"SoftwareSASGeneration"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2012-07-11 140672]
S2 AdobeActiveFileMonitor11.0;Adobe Active File Monitor V11;c:\program files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe [2012-09-23 171600]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_15f4e438\AESTSr64.exe [2009-03-20 89600]
.
.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
Themes
.
Contents of the 'Scheduled Tasks' folder
.
2013-03-10 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-01 22:09]
.
2013-03-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-07 18:59]
.
2013-03-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-07 18:59]
.
2011-03-05 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- c:\program files (x86)\Spybot - Search & Destroy\SpybotSD.exe [2011-03-05 20:31]
.
2013-03-09 c:\windows\Tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
- c:\program files (x86)\Spybot - Search & Destroy\SDUpdate.exe [2011-03-05 20:31]
.
.
——— X64 Entries ———–
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncBackedUp]
@="{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472}"
[HKEY_CLASSES_ROOT\CLSID\{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472}]
2013-01-24 07:48 482144 —-a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncPending]
@="{62CCD8E3-9C21-41E1-B55E-1E26DFC68511}"
[HKEY_CLASSES_ROOT\CLSID\{62CCD8E3-9C21-41E1-B55E-1E26DFC68511}]
2013-01-24 07:48 482144 —-a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncRoot]
@="{A759AFF6-5851-457D-A540-F4ECED148351}"
[HKEY_CLASSES_ROOT\CLSID\{A759AFF6-5851-457D-A540-F4ECED148351}]
2013-01-24 07:48 482144 —-a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncShared]
@="{1574C9EF-7D58-488F-B358-8B78C1538F51}"
[HKEY_CLASSES_ROOT\CLSID\{1574C9EF-7D58-488F-B358-8B78C1538F51}]
2013-01-24 07:48 482144 —-a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-11-26 1657128]
"SysTrayApp"="c:\program files (x86)\IDT\WDM\sttray64.exe" [BU]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-06-16 499608]
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
uLocal Page = c:\windows\system32\blank.htm
mDefault_Page_URL = hxxp://www.dell.com
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = [removed] [removed]
FF - ProfilePath - c:\users\Exigo\AppData\Roaming\Mozilla\Firefox\Profiles\i52sed3g.default\
FF - prefs.js: browser.startup.homepage - about:home
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?pc=Z180&form=ZGAADF&install_date=20111104&q=
FF - prefs.js: network.proxy.type - 0
FF - ExtSQL: 2013-03-05 13:18; {e4a8a97b-f2ed-450b-b12d-ee082ba24781}; c:\users\Exigo\AppData\Roaming\Mozilla\Firefox\Profiles\i52sed3g.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi
FF - ExtSQL: !HIDDEN! 2011-03-04 11:35; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-don't take it personally, babe, it just ain't your story - c:\program files (x86)\don't take it personally
AddRemove-ESN Sonar-0.70.0 - c:\program files (x86)\Battlelog Web Plugins\Sonar\esnsonar_uninstall.exe
AddRemove-PunkBusterSvc - c:\program files (x86)\Steam\steamapps\common\Assassins Creed Brotherhood\pbsvc.exe
AddRemove-StartNow Toolbar - c:\program files (x86)\StartNow Toolbar\StartNowToolbarUninstall.exe
AddRemove-{B5E6D105-DFB4-46B4-88BF-9DC52686DBE7}_is1 - c:\program files (x86)\Steam\steamapps\common\medieval ii total war\mods\Broken_Crescent_kingdoms\unins000.exe
.
.
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-219705432-3252208987-4262155305-1000\Software\SecuROM\License information*]
"datasecu"=hex:c0,e9,08,51,cd,ac,51,6e,54,65,ef,9b,1c,0f,4e,81,c6,1f,c6,e2,bc,
7a,6d,40,3f,1c,0d,1b,5b,f6,d2,33,fc,7c,b8,d1,56,fc,21,6f,d0,10,00,52,1b,e7,\
"rkeysecu"=hex:6d,83,00,fd,94,57,e5,65,5a,4d,71,bb,a7,b9,72,29
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_171_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_171_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_171_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_171_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_171.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_171.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_171.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_171.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@=""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@="FlashBroker"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
Completion time: 2013-03-10 13:27:35
ComboFix-quarantined-files.txt 2013-03-10 17:27
ComboFix2.txt 2013-03-08 18:41
.
Pre-Run: 301,356,720,128 bytes free
Post-Run: 301,172,547,584 bytes free
.
- - End Of File - - F220DB88323BD3405BE0C37DA2225872
Log looks good
Time for some housekeeping Click START then RUN Now type ComboFix /Uninstall in the runbox and click OK . Note the space between the X and the U , it needs to be there. [external image: Posted Image]
The above procedure will :
Implement some cleanup procedures. Reset System Restore.
Now to remove most of the tools that we have used in fixing your machine: Make sure you have an Internet Connection. Download OTC to your desktop and run it A list of tool components used in the cleanup of malware will be downloaded. If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so. Click Yes to begin the cleanup process and remove these components, including this application. You will be asked to reboot the machine to finish the cleanup process. If you are asked to reboot the machine choose Yes.
You can just delete any tools or logs that are left over.
Please re-enable any security that was disabled.
The following is my standard advice for the future. Use what you can and pat yourself on the back for what you're already doing.
Please take time to read
Preventing Malware - Tools and Practices for Safe Computing . Very important information for your consideration is contained therein.
I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein
Also:
"How to prevent malware"
by miekiemoes
Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved.
Hi Tomk,
Thanks for all your help, I am working through your recommendations. Please clarify a few things for now and I may have additional questions.
1. I typically use Firefox-are there similar steps to secure as done for IE
2. I currently use Kapersky AV- subscription runs out in 21 days. Do any of the other AV options slow down laptop less?
3. Firewall used now is Windows, should I also use a 2nd party s/w offer as well?
4. I am unable to reactivate Windows Defender. Attached screen shot of error
#1
I believe that active X is the most "unsecure" part of IE. Firefox doesn't use it. It is possible to be "more secure" with firefox using
No script - but you have to be willing to work with it. Personally I use it… but most people find it annoying. The important thing to remember is that even if you typically use Firefox as your browser… your computer will still use IE. IE is embedded into windows so you need to keep it secure - even when you think you don't use it.
#2
In my opinion, Kaspersky is one of the best AV programs. I use free ones. The least obtrusive is probably Microsoft Security Essentials (
MSSE ). Then probably Avast!. I also use
Avira .
#3
In my opinion… the windows firewall is adequate. The is especially true if you are behind a hardware firewall as is found in your router. There are others that will tell you that 3rd party firewalls are better… but I am not of that opinion.
#4
Have you tried restarting your system as suggested?
Thanks for quick response.
I have rebooted and shut down a few times without success enabling Defender. I don't suppose it is a big deal but thought it worth mentioning.
I do have a router FW so should be good there. And since some requests will surprise me and use IE I get that it should be updated.
I need to be sure I have Java updated correctly and old versions removed. I will work on this tonight but I may need to clarify.