This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

i.trkjmp.com - random links redirect from website [Solved]

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

On website I have found random blue links that are not typically there when I check with different device. The initial url that pops up is i.trkjmp.com then it switch over to a website that correlates to the the random blue link word. I disabled shockwave flash plug in on Firefox and seems to have fix issue so far. Run Malware bytes nothing found Kaspersky nothing found SuperAntispyware found the following and removed today: Trojan.Agent/Gen-FakeAlert[Local] C:USERSEXIGOAPPDATALOCALTEMP7ZS47F2SETUPHPOAPD01.EXE C:USERSEXIGOAPPDATALOCALTEMP7ZS6310SETUPHPOAPD01.EXE Additional 201 adware tracking cookies were also removed Adware.Tracking Cookie account.goodgamestudios.com [ C:USERSEXIGOAPPDATAROAMINGMACROMEDIAFLASH PLAYER#SHAREDOBJECTSC745NPE8 ] core.insightexpressai.com [ C:USERSEXIGOAPPDATAROAMINGMACROMEDIAFLASH PLAYER#SHAREDOBJECTSC745NPE8 ] ds.serving-sys.com [ C:USERSEXIGOAPPDATAROAMINGMACROMEDIAFLASH PLAYER#SHAREDOBJECTSC745NPE8 ] media.mtvnservices.com [ C:USERSEXIGOAPPDATAROAMINGMACROMEDIAFLASH PLAYER#SHAREDOBJECTSC745NPE8 ] msnbcmedia.msn.com [ C:USERSEXIGOAPPDATAROAMINGMACROMEDIAFLASH PLAYER#SHAREDOBJECTSC745NPE8 ] secure-us.imrworldwide.com [ C:USERSEXIGOAPPDATAROAMINGMACROMEDIAFLASH PLAYER#SHAREDOBJECTSC745NPE8 ] www.cellartracker.com [ C:USERSEXIGOAPPDATAROAMINGMACROMEDIAFLASH PLAYER#SHAREDOBJECTSC745NPE8 ] .ru4.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .doubleclick.net [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .zedo.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .realmedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .realmedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .invitemedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .atdmt.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .media6degrees.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] ad.yieldmanager.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] ad.yieldmanager.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] ad.yieldmanager.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .imrworldwide.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .imrworldwide.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .serving-sys.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .serving-sys.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .ru4.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .revsci.net [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .media.adfrontiers.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .insightexpressai.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .insightexpressai.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .insightexpressai.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .insightexpressai.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .zedo.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .zedo.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .revsci.net [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .atwola.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .dmtracker.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .insightexpressai.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .interclick.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .interclick.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .a1.interclick.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] www.googleadservices.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .ticketsnow.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .ticketsnow.112.2o7.net [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .invitemedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .solvemedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .solvemedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .serving-sys.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .burstnet.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .ru4.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] www.googleadservices.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .adtechus.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .atwola.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .advertising.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] sftrack.searchforce.net [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .apmebf.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .mediaplex.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .bs.serving-sys.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .amazon-adsystem.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .ru4.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] www.googleadservices.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .atdmt.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .c.atdmt.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .c.atdmt.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .ar.atwola.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .atwola.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .ar.atwola.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .questionmarket.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .questionmarket.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .questionmarket.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .legolas-media.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .legolas-media.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .ads.pointroll.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .pointroll.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .a1.interclick.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .yieldmanager.net [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .interclick.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .fastclick.net [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .ad.mlnadvertising.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .at.atwola.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .at.atwola.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .tacoda.at.atwola.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .tacoda.at.atwola.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .tacoda.at.atwola.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .invitemedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .2o7.net [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .2o7.net [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .adserver.adtechus.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .collective-media.net [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] ad.yieldmanager.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .ads.pointroll.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .2o7.net [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .zedo.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] statse.webtrendslive.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .invitemedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .invitemedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .invitemedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .invitemedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .collective-media.net [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .adxpose.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] consumercenter.gogecapital.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] consumercenter.gogecapital.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .gemoneysusgogecapitalcc.112.2o7.net [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .gemoneysusmb2.112.2o7.net [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .mediaforge.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .2o7.net [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .mediaforge.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .mediaforge.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .specificclick.net [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .ru4.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .saymedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .saymedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .saymedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .saymedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] ad.yieldmanager.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] ad.yieldmanager.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] ad.yieldmanager.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .adinterax.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .adinterax.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .a1.interclick.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .a1.interclick.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .a1.interclick.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .a1.interclick.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .a1.interclick.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .interclick.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .lucidmedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .traveladvertising.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .media.adfrontiers.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .realmedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .realmedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .network.realmedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .network.realmedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .network.realmedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .mediaplex.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .ru4.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .2o7.net [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .ru4.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .oracle.112.2o7.net [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .advertising.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .advertising.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .advertising.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .2o7.net [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .2o7.net [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .eyeviewads.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .interclick.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .invitemedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] www.googleadservices.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .tribalfusion.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .pointroll.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .ads.pointroll.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .ads.pointroll.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .ads.pointroll.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .ads.pointroll.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .ads.pointroll.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .ads.pointroll.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .doubleclick.net [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .invitemedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .advertising.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .advertising.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .casalemedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .lfstmedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] network.realmedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .burstnet.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .clickfuse.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .traveladvertising.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .traveladvertising.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .clickfuse.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .zedo.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .realmedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] network.realmedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .ru4.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .ru4.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .ru4.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .ru4.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .media6degrees.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .media6degrees.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .media6degrees.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .media6degrees.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .media6degrees.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .media6degrees.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .media6degrees.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] ad.yieldmanager.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .ru4.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .serving-sys.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .serving-sys.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .serving-sys.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .kontera.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .casalemedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .casalemedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .casalemedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .casalemedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .casalemedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .casalemedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .casalemedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .technoratimedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .technoratimedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .technoratimedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .technoratimedia.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .revsci.net [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .revsci.net [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .revsci.net [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] .statcounter.com [ C:USERSEXIGOAPPDATAROAMINGMOZILLAFIREFOXPROFILESI52SED3G.DEFAULTCOOKIES .SQLITE ] alwarebytes Anti-Malware 1.70.0.1100 www.malwarebytes.org Database version: v2013.03.05.12 Windows Vista Service Pack 2 x64 NTFS Internet Explorer 8.0.6001.19400 Exigo :: EXIGO-PC [administrator] 3/5/2013 1:03:06 PM mbam-log-2013-03-05 (13-03-06).txt Scan type: Full scan (C:|) Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 404073 Time elapsed: 1 hour(s), 47 minute(s), 36 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)
Hi brians2,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

How about getting me a log so I can have a better look at what is going on:

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and the click UPLOAD.
Good day Tomk Thanks for your help, I do appreciate you time. I have posted DDS log and attached attach log as requested. Had to run 3 times, I forgot about different antispyware and malware apps. DDS (Ver_2012-11-20.01) - NTFS_AMD64 Internet Explorer: 8.0.6001.19400 BrowserJavaVersion: 10.13.2 Run by [removed] at 11:09:54 on 2013-03-08 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2042.634 [GMT -5:00] . AV: Kaspersky Anti-Virus *Enabled/Updated* {56547CC9-C9B2-849D-8FEF-A496150D6A06} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Kaspersky Anti-Virus *Enabled/Updated* {ED359D2D-EF88-8B13-B55F-9FE46E8A20BB} . ============== Running Processes =============== . C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_15f4e438\STacSV64.exe C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\atieclxx.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_15f4e438\AESTSr64.exe C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Windows\system32\svchost.exe -k bthsvcs C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe C:\Program Files (x86)\Common Files\Nuance\dgnsvc.exe C:\Windows\SysWOW64\PnkBstrA.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files (x86)\TightVNC\tvnserver.exe C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Windows\system32\SearchIndexer.exe C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\Program Files\IDT\WDM\sttray64.exe C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files (x86)\SugarSync\SugarSyncManager.exe C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe C:\Program Files (x86)\Common Files\Apple\Internet Services\BookmarkDAV_client.exe C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files (x86)\Mouse Setting\Mouse Setting Software\4.0\ACQTMAPP.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files (x86)\TightVNC\tvnserver.exe C:\Program Files (x86)\Linksys Wireless-G Print Server\PSDiagnosticM.exe C:\Program Files (x86)\iTunes\iTunesHelper.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Program Files\iPod\bin\iPodService.exe C:\Windows\SysWOW64\RunDll32.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files (x86)\Microsoft Office\OFFICE11\OUTLOOK.EXE C:\Program Files (x86)\Microsoft Office\OFFICE11\WINWORD.EXE C:\Windows\splwow64.exe C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\SyncServer.exe C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\System32\cscript.exe . ============== Pseudo HJT Report =============== . uStart Page = about:blank uDefault_Page_URL = hxxp://www.dell.com mDefault_Page_URL = hxxp://www.dell.com mWinlogon: Userinit = userinit.exe, BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll BHO: IEVkbdBHO Class: {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\ievkbd.dll BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll BHO: FilterBHO Class: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll TB: StartNow Toolbar: {5911488E-9D1E-40ec-8CBB-06B231CC153F} - TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll uRun: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe uRun: [SugarSync] "C:\Program Files (x86)\SugarSync\SugarSyncManager.exe" -startInTray -usedelay=true uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" uRun: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe -scheduler uRun: [EPSON NX125 NX127 Series] C:\Windows\System32\spool\DRIVERS\x64\3\E_IATIGGA.EXE /FU "C:\Windows\TEMP\E_S5BDA.tmp" /EF "HKCU" uRun: [Facebook Update] "C:\Users\Exigo\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver uRun: [StartNow Search Protect] "C:\Program Files (x86)\StartNow Toolbar\search_protect.exe" /RELAY /REPORT /PROTECT uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe uRun: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe uRun: [ApplePhotoStreams] C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe uRun: [com.apple.dav.bookmarks.daemon] C:\Program Files (x86)\Common Files\Apple\Internet Services\BookmarkDAV_client.exe mRun: [StartCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun mRun: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe" mRun: [DNS7reminder] "C:\Program Files (x86)\Nuance\NaturallySpeaking11\Ereg\Ereg.exe" -r "C:\ProgramData\Nuance\NaturallySpeaking11\Ereg.ini mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [ACQTMOUSE] "C:\Program Files (x86)\Mouse Setting\Mouse Setting Software\4.0\ACQTMAPP.exe" mRun: [StartNowToolbarHelper] "C:\Program Files (x86)\StartNow Toolbar\ToolbarHelper.exe" mRun: [tvncontrol] "C:\Program Files (x86)\TightVNC\tvnserver.exe" -controlservice -slave mRun: [PSDiagnosticM] "C:\Program Files (x86)\Linksys Wireless-G Print Server\PSDiagnosticM.exe" mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BLUETO~1.LNK - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe mPolicies-Explorer: NoActiveDesktop = dword:1 mPolicies-Explorer: NoActiveDesktopChanges = dword:1 mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0 mPolicies-Explorer: NoDriveTypeAutoRun = dword:28 mPolicies-System: EnableUIADesktopToggle = dword:0 mPolicies-System: SoftwareSASGeneration = dword:1 IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\OFFICE11\EXCEL.EXE/3000 IE: Send image to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm IE: Send page to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll . INFO: HKCU has more than 50 listed domains. If you wish to scan all of them, select the 'Force scan all domains' option. . . INFO: HKLM has more than 50 listed domains. If you wish to scan all of them, select the 'Force scan all domains' option. . TCP: NameServer = 167.206.254.1 167.206.254.2 TCP: Interfaces\{E29B23B5-60AC-4E5C-BAFF-E892E1E1E0CB} : DHCPNameServer = [removed] [removed] LSA: Security Packages = kerberos msv1_0 schannel wdigest tspkg x64-mDefault_Page_URL = hxxp://www.dell.com x64-BHO: IEVkbdBHO Class: {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\ievkbd.dll x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll x64-BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg64.dll x64-BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll x64-BHO: FilterBHO Class: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\klwtbbho.dll x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll x64-Run: [Windows Defender] C:\Program Files (x86)\Windows Defender\MSASCui.exe -hide x64-Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe x64-Run: [QuickSet] C:\Program Files\Dell\QuickSet\QuickSet.exe x64-Run: [SysTrayApp] C:\Program Files (x86)\IDT\WDM\sttray64.exe x64-Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" x64-mPolicies-Explorer: NoActiveDesktop = dword:1 x64-mPolicies-Explorer: NoActiveDesktopChanges = dword:1 x64-mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0 x64-mPolicies-Explorer: NoDriveTypeAutoRun = dword:28 x64-mPolicies-System: EnableUIADesktopToggle = dword:0 x64-mPolicies-System: SoftwareSASGeneration = dword:1 x64-IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\klwtbbho.dll x64-IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm x64-IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\klwtbbho.dll . INFO: x64-HKLM has more than 50 listed domains. If you wish to scan all of them, select the 'Force scan all domains' option. . x64-DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab x64-DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab x64-Notify: klogon - C:\Windows\System32\klogon.dll Hosts: 127.0.0.1 www.spywareinfo.com . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\Exigo\AppData\Roaming\Mozilla\Firefox\Profiles\i52sed3g.default\ FF - prefs.js: browser.startup.homepage - about:home FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?pc=Z180&form=ZGAADF&install_date=20111104&q= FF - prefs.js: network.proxy.type - 0 FF - component: C:\Program Files (x86)\Mozilla Firefox\extensions\[removed]\components\kavlinkfilter.dll FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrlui.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_171.dll FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll FF - plugin: C:\Windows\SysWOW64\npmproxy.dll FF - ExtSQL: 2013-03-05 13:18; {e4a8a97b-f2ed-450b-b12d-ee082ba24781}; C:\Users\Exigo\AppData\Roaming\Mozilla\Firefox\Profiles\i52sed3g.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi FF - ExtSQL: !HIDDEN! 2011-03-04 11:35; {20a82645-c095-46ed-80e3-08825760534b}; C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension . ============= SERVICES / DRIVERS =============== . R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2012-12-15 56336] R1 kl2;kl2;C:\Windows\System32\drivers\kl2.sys [2010-6-9 11864] R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\System32\drivers\klim6.sys [2010-4-22 27736] R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928] R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368] R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2012-7-11 140672] R2 AdobeActiveFileMonitor11.0;Adobe Active File Monitor V11;C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe [2012-9-23 171600] R2 AESTFilters;Andrea ST Filters Service;C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_15f4e438\AESTSr64.exe [2011-2-27 89600] R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2011-2-27 202752] R2 AVP;Kaspersky Anti-Virus Service;C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe [2010-11-2 365336] R2 DragonSvc;Dragon Service;C:\Program Files (x86)\Common Files\Nuance\dgnsvc.exe [2010-9-24 296808] R2 FontCache;Windows Font Cache Service;C:\Windows\System32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 27648] R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2011-3-5 1153368] R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdLH6.sys [2011-11-9 90128] R3 k57nd60a;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;C:\Windows\System32\drivers\k57nd60a.sys [2011-2-27 252928] R3 klmouflt;Kaspersky Lab KLMOUFLT;C:\Windows\System32\drivers\klmouflt.sys [2009-11-2 22544] R3 NETwNv64;___ Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\System32\drivers\NETwNv64.sys [2011-9-2 8388096] R3 OA008Ufd;Creative Camera OA008 Upper Filter Driver;C:\Windows\System32\drivers\OA008Ufd.sys [2011-2-27 158592] R3 OA008Vid;Creative Camera OA008 Function Driver;C:\Windows\System32\drivers\OA008Vid.sys [2011-2-27 310784] R3 scnuhst20;SC NUSB Host 20;C:\Windows\System32\drivers\scnuhst20.sys [2012-7-6 15872] R3 SCNUHUB20;SC NUSB Hub 20;C:\Windows\System32\drivers\scnuhub20.sys [2012-7-6 37376] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\System32\drivers\btwl2cap.sys [2011-3-4 36392] S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files (x86)\steam\steamapps\common\dragon age ultimate edition\bin_ship\DAUpdaterSvc.Service.exe –> c:\program files (x86)\steam\steamapps\common\dragon age ultimate edition\bin_ship\DAUpdaterSvc.Service.exe [?] S3 NETw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\System32\drivers\NETw5v64.sys [2011-2-27 4735488] S3 PerfHost;Performance Counter DLL Host;C:\Windows\SysWOW64\perfhost.exe [2008-1-20 19968] S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-9-28 53760] S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2011-3-4 89920] . =============== File Associations =============== . FileExt: .js: JSFile=C:\Windows\SysWOW64\WScript.exe "%1" %* FileExt: .jse: JSEFile=C:\Windows\SysWOW64\WScript.exe "%1" %* . =============== Created Last 30 ================ . . ==================== Find3M ==================== . 2013-03-07 22:09:07 71024 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2013-03-07 22:09:07 691568 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe 2013-02-15 08:15:34 70004024 —-a-w- C:\Windows\System32\mrt.exe 2013-02-02 20:10:08 95648 —-a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll 2013-02-02 20:10:07 861088 —-a-w- C:\Windows\SysWow64\npDeployJava1.dll 2013-02-02 20:10:07 782240 —-a-w- C:\Windows\SysWow64\deployJava1.dll 2013-02-02 20:10:07 262560 —-a-w- C:\Windows\SysWow64\javaws.exe 2013-02-02 20:10:07 174496 —-a-w- C:\Windows\SysWow64\javaw.exe 2013-02-02 20:10:07 174496 —-a-w- C:\Windows\SysWow64\java.exe 2013-01-17 06:28:58 273840 ——w- C:\Windows\System32\MpSigStub.exe 2013-01-05 13:48:44 1147392 —-a-w- C:\Windows\System32\wininet.dll 2013-01-05 13:48:27 1489408 —-a-w- C:\Windows\System32\urlmon.dll 2013-01-05 13:48:27 108032 —-a-w- C:\Windows\System32\url.dll 2013-01-05 13:46:30 243712 —-a-w- C:\Windows\System32\occache.dll 2013-01-05 13:44:42 1062912 —-a-w- C:\Windows\System32\mstime.dll 2013-01-05 13:44:20 98304 —-a-w- C:\Windows\System32\mshtmled.dll 2013-01-05 13:44:20 9331200 —-a-w- C:\Windows\System32\mshtml.dll 2013-01-05 13:44:18 743424 —-a-w- C:\Windows\System32\msfeeds.dll 2013-01-05 13:44:18 71680 —-a-w- C:\Windows\System32\msfeedsbs.dll 2013-01-05 13:43:26 56832 —-a-w- C:\Windows\System32\licmgr10.dll 2013-01-05 13:43:11 31744 —-a-w- C:\Windows\System32\jsproxy.dll 2013-01-05 13:43:00 1538560 —-a-w- C:\Windows\System32\inetcpl.cpl 2013-01-05 13:42:28 219136 —-a-w- C:\Windows\System32\ieui.dll 2013-01-05 13:42:28 132096 —-a-w- C:\Windows\System32\iesysprep.dll 2013-01-05 13:42:27 77312 —-a-w- C:\Windows\System32\iesetup.dll 2013-01-05 13:42:27 2356736 —-a-w- C:\Windows\System32\iertutil.dll 2013-01-05 13:42:22 72192 —-a-w- C:\Windows\System32\iernonce.dll 2013-01-05 13:42:20 252416 —-a-w- C:\Windows\System32\iepeers.dll 2013-01-05 13:42:20 12509184 —-a-w- C:\Windows\System32\ieframe.dll 2013-01-05 13:42:11 459776 —-a-w- C:\Windows\System32\iedkcs32.dll 2013-01-05 11:59:52 916480 —-a-w- C:\Windows\SysWow64\wininet.dll 2013-01-05 11:59:33 1212928 —-a-w- C:\Windows\SysWow64\urlmon.dll 2013-01-05 11:59:32 105984 —-a-w- C:\Windows\SysWow64\url.dll 2013-01-05 11:57:59 479232 —-a-w- C:\Windows\System32\html.iec 2013-01-05 11:57:43 206848 —-a-w- C:\Windows\SysWow64\occache.dll 2013-01-05 11:55:52 611840 —-a-w- C:\Windows\SysWow64\mstime.dll 2013-01-05 11:55:25 67072 —-a-w- C:\Windows\SysWow64\mshtmled.dll 2013-01-05 11:55:25 6010368 —-a-w- C:\Windows\SysWow64\mshtml.dll 2013-01-05 11:55:21 630272 —-a-w- C:\Windows\SysWow64\msfeeds.dll 2013-01-05 11:55:21 55296 —-a-w- C:\Windows\SysWow64\msfeedsbs.dll 2013-01-05 11:54:47 43520 —-a-w- C:\Windows\SysWow64\licmgr10.dll 2013-01-05 11:54:34 25600 —-a-w- C:\Windows\SysWow64\jsproxy.dll 2013-01-05 11:54:23 1469440 —-a-w- C:\Windows\SysWow64\inetcpl.cpl 2013-01-05 11:54:07 164352 —-a-w- C:\Windows\SysWow64\ieui.dll 2013-01-05 11:54:07 109056 —-a-w- C:\Windows\SysWow64\iesysprep.dll 2013-01-05 11:54:06 71680 —-a-w- C:\Windows\SysWow64\iesetup.dll 2013-01-05 11:54:06 2004992 —-a-w- C:\Windows\SysWow64\iertutil.dll 2013-01-05 11:54:05 55808 —-a-w- C:\Windows\SysWow64\iernonce.dll 2013-01-05 11:54:05 184320 —-a-w- C:\Windows\SysWow64\iepeers.dll 2013-01-05 11:54:05 11111424 —-a-w- C:\Windows\SysWow64\ieframe.dll 2013-01-05 11:53:59 387584 —-a-w- C:\Windows\SysWow64\iedkcs32.dll 2013-01-05 10:33:42 162816 —-a-w- C:\Windows\System32\ieUnatt.exe 2013-01-05 10:33:29 70656 —-a-w- C:\Windows\System32\ie4uinit.exe 2013-01-05 10:32:20 12288 —-a-w- C:\Windows\System32\msfeedssync.exe 2013-01-05 10:32:00 1638912 —-a-w- C:\Windows\System32\mshtml.tlb 2013-01-05 10:23:06 385024 —-a-w- C:\Windows\SysWow64\html.iec 2013-01-05 08:47:17 133632 —-a-w- C:\Windows\SysWow64\ieUnatt.exe 2013-01-05 08:46:53 174080 —-a-w- C:\Windows\SysWow64\ie4uinit.exe 2013-01-05 08:45:43 13312 —-a-w- C:\Windows\SysWow64\msfeedssync.exe 2013-01-05 08:44:46 1638912 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2013-01-05 05:37:50 4695400 —-a-w- C:\Windows\System32\ntoskrnl.exe 2013-01-04 11:31:10 1423720 —-a-w- C:\Windows\System32\drivers\tcpip.sys 2013-01-04 01:59:24 2773504 —-a-w- C:\Windows\System32\win32k.sys 2012-12-16 13:31:20 48128 —-a-w- C:\Windows\System32\atmlib.dll 2012-12-16 13:12:54 34304 —-a-w- C:\Windows\SysWow64\atmlib.dll 2012-12-16 11:08:21 368128 —-a-w- C:\Windows\System32\atmfd.dll 2012-12-16 10:50:29 293376 —-a-w- C:\Windows\SysWow64\atmfd.dll 2012-12-14 21:49:28 24176 —-a-w- C:\Windows\System32\drivers\mbam.sys . ============= FINISH: 11:11:34.78 ===============

Attachments:

sorry here is correct dds log DDS (Ver_2012-11-20.01) - NTFS_AMD64 Internet Explorer: 8.0.6001.19400 BrowserJavaVersion: 10.13.2 Run by [removed] at 11:42:04 on 2013-03-08 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2042.711 [GMT -5:00] . AV: Kaspersky Anti-Virus *Disabled/Updated* {56547CC9-C9B2-849D-8FEF-A496150D6A06} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Kaspersky Anti-Virus *Disabled/Updated* {ED359D2D-EF88-8B13-B55F-9FE46E8A20BB} . ============== Running Processes =============== . C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_15f4e438\STacSV64.exe C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\atieclxx.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_15f4e438\AESTSr64.exe C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Windows\system32\svchost.exe -k bthsvcs C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe C:\Program Files (x86)\Common Files\Nuance\dgnsvc.exe C:\Windows\SysWOW64\PnkBstrA.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files (x86)\TightVNC\tvnserver.exe C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Windows\system32\SearchIndexer.exe C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\Program Files\IDT\WDM\sttray64.exe C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files (x86)\SugarSync\SugarSyncManager.exe C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe C:\Program Files (x86)\Common Files\Apple\Internet Services\BookmarkDAV_client.exe C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files (x86)\Mouse Setting\Mouse Setting Software\4.0\ACQTMAPP.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files (x86)\TightVNC\tvnserver.exe C:\Program Files (x86)\Linksys Wireless-G Print Server\PSDiagnosticM.exe C:\Program Files (x86)\iTunes\iTunesHelper.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Program Files\iPod\bin\iPodService.exe C:\Windows\SysWOW64\RunDll32.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files (x86)\Microsoft Office\OFFICE11\OUTLOOK.EXE C:\Program Files (x86)\Microsoft Office\OFFICE11\WINWORD.EXE C:\Windows\splwow64.exe C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\SyncServer.exe C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Windows\SysWOW64\NOTEPAD.EXE C:\Windows\SysWOW64\NOTEPAD.EXE C:\Windows\System32\svchost.exe -k swprv C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\System32\cscript.exe . ============== Pseudo HJT Report =============== . uStart Page = about:blank uDefault_Page_URL = hxxp://www.dell.com mDefault_Page_URL = hxxp://www.dell.com mWinlogon: Userinit = userinit.exe, BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll BHO: IEVkbdBHO Class: {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\ievkbd.dll BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll BHO: FilterBHO Class: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll TB: StartNow Toolbar: {5911488E-9D1E-40ec-8CBB-06B231CC153F} - TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll uRun: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe uRun: [SugarSync] "C:\Program Files (x86)\SugarSync\SugarSyncManager.exe" -startInTray -usedelay=true uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" uRun: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe -scheduler uRun: [EPSON NX125 NX127 Series] C:\Windows\System32\spool\DRIVERS\x64\3\E_IATIGGA.EXE /FU "C:\Windows\TEMP\E_S5BDA.tmp" /EF "HKCU" uRun: [Facebook Update] "C:\Users\Exigo\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver uRun: [StartNow Search Protect] "C:\Program Files (x86)\StartNow Toolbar\search_protect.exe" /RELAY /REPORT /PROTECT uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe uRun: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe uRun: [ApplePhotoStreams] C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe uRun: [com.apple.dav.bookmarks.daemon] C:\Program Files (x86)\Common Files\Apple\Internet Services\BookmarkDAV_client.exe mRun: [StartCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun mRun: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe" mRun: [DNS7reminder] "C:\Program Files (x86)\Nuance\NaturallySpeaking11\Ereg\Ereg.exe" -r "C:\ProgramData\Nuance\NaturallySpeaking11\Ereg.ini mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [ACQTMOUSE] "C:\Program Files (x86)\Mouse Setting\Mouse Setting Software\4.0\ACQTMAPP.exe" mRun: [StartNowToolbarHelper] "C:\Program Files (x86)\StartNow Toolbar\ToolbarHelper.exe" mRun: [tvncontrol] "C:\Program Files (x86)\TightVNC\tvnserver.exe" -controlservice -slave mRun: [PSDiagnosticM] "C:\Program Files (x86)\Linksys Wireless-G Print Server\PSDiagnosticM.exe" mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BLUETO~1.LNK - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe mPolicies-Explorer: NoActiveDesktop = dword:1 mPolicies-Explorer: NoActiveDesktopChanges = dword:1 mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0 mPolicies-Explorer: NoDriveTypeAutoRun = dword:28 mPolicies-System: EnableUIADesktopToggle = dword:0 mPolicies-System: SoftwareSASGeneration = dword:1 IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\OFFICE11\EXCEL.EXE/3000 IE: Send image to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm IE: Send page to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll . INFO: HKCU has more than 50 listed domains. If you wish to scan all of them, select the 'Force scan all domains' option. . . INFO: HKLM has more than 50 listed domains. If you wish to scan all of them, select the 'Force scan all domains' option. . TCP: NameServer = 167.206.254.1 167.206.254.2 TCP: Interfaces\{E29B23B5-60AC-4E5C-BAFF-E892E1E1E0CB} : DHCPNameServer = [removed] [removed] LSA: Security Packages = kerberos msv1_0 schannel wdigest tspkg x64-mDefault_Page_URL = hxxp://www.dell.com x64-BHO: IEVkbdBHO Class: {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\ievkbd.dll x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll x64-BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg64.dll x64-BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll x64-BHO: FilterBHO Class: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\klwtbbho.dll x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll x64-Run: [Windows Defender] C:\Program Files (x86)\Windows Defender\MSASCui.exe -hide x64-Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe x64-Run: [QuickSet] C:\Program Files\Dell\QuickSet\QuickSet.exe x64-Run: [SysTrayApp] C:\Program Files (x86)\IDT\WDM\sttray64.exe x64-Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" x64-mPolicies-Explorer: NoActiveDesktop = dword:1 x64-mPolicies-Explorer: NoActiveDesktopChanges = dword:1 x64-mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0 x64-mPolicies-Explorer: NoDriveTypeAutoRun = dword:28 x64-mPolicies-System: EnableUIADesktopToggle = dword:0 x64-mPolicies-System: SoftwareSASGeneration = dword:1 x64-IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\klwtbbho.dll x64-IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm x64-IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\klwtbbho.dll . INFO: x64-HKLM has more than 50 listed domains. If you wish to scan all of them, select the 'Force scan all domains' option. . x64-DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab x64-DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab x64-Notify: klogon - C:\Windows\System32\klogon.dll Hosts: 127.0.0.1 www.spywareinfo.com . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\Exigo\AppData\Roaming\Mozilla\Firefox\Profiles\i52sed3g.default\ FF - prefs.js: browser.startup.homepage - about:home FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?pc=Z180&form=ZGAADF&install_date=20111104&q= FF - prefs.js: network.proxy.type - 0 FF - component: C:\Program Files (x86)\Mozilla Firefox\extensions\[removed]\components\kavlinkfilter.dll FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrlui.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_171.dll FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll FF - plugin: C:\Windows\SysWOW64\npmproxy.dll FF - ExtSQL: 2013-03-05 13:18; {e4a8a97b-f2ed-450b-b12d-ee082ba24781}; C:\Users\Exigo\AppData\Roaming\Mozilla\Firefox\Profiles\i52sed3g.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi FF - ExtSQL: !HIDDEN! 2011-03-04 11:35; {20a82645-c095-46ed-80e3-08825760534b}; C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension . ============= SERVICES / DRIVERS =============== . R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2012-12-15 56336] R1 kl2;kl2;C:\Windows\System32\drivers\kl2.sys [2010-6-9 11864] R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\System32\drivers\klim6.sys [2010-4-22 27736] R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928] R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368] R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2012-7-11 140672] R2 AdobeActiveFileMonitor11.0;Adobe Active File Monitor V11;C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe [2012-9-23 171600] R2 AESTFilters;Andrea ST Filters Service;C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_15f4e438\AESTSr64.exe [2011-2-27 89600] R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2011-2-27 202752] R2 AVP;Kaspersky Anti-Virus Service;C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe [2010-11-2 365336] R2 DragonSvc;Dragon Service;C:\Program Files (x86)\Common Files\Nuance\dgnsvc.exe [2010-9-24 296808] R2 FontCache;Windows Font Cache Service;C:\Windows\System32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 27648] R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2011-3-5 1153368] R2 tvnserver;TightVNC Server;C:\Program Files (x86)\TightVNC\tvnserver.exe [2011-8-3 828944] R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdLH6.sys [2011-11-9 90128] R3 k57nd60a;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;C:\Windows\System32\drivers\k57nd60a.sys [2011-2-27 252928] R3 klmouflt;Kaspersky Lab KLMOUFLT;C:\Windows\System32\drivers\klmouflt.sys [2009-11-2 22544] R3 NETwNv64;___ Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\System32\drivers\NETwNv64.sys [2011-9-2 8388096] R3 OA008Ufd;Creative Camera OA008 Upper Filter Driver;C:\Windows\System32\drivers\OA008Ufd.sys [2011-2-27 158592] R3 OA008Vid;Creative Camera OA008 Function Driver;C:\Windows\System32\drivers\OA008Vid.sys [2011-2-27 310784] R3 scnuhst20;SC NUSB Host 20;C:\Windows\System32\drivers\scnuhst20.sys [2012-7-6 15872] R3 SCNUHUB20;SC NUSB Hub 20;C:\Windows\System32\drivers\scnuhub20.sys [2012-7-6 37376] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 Updater Service for StartNow Toolbar;Updater Service for StartNow Toolbar;C:\Program Files (x86)\StartNow Toolbar\ToolbarUpdaterService.exe –> C:\Program Files (x86)\StartNow Toolbar\ToolbarUpdaterService.exe [?] S3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\System32\drivers\btwl2cap.sys [2011-3-4 36392] S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files (x86)\steam\steamapps\common\dragon age ultimate edition\bin_ship\DAUpdaterSvc.Service.exe –> c:\program files (x86)\steam\steamapps\common\dragon age ultimate edition\bin_ship\DAUpdaterSvc.Service.exe [?] S3 NETw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\System32\drivers\NETw5v64.sys [2011-2-27 4735488] S3 PerfHost;Performance Counter DLL Host;C:\Windows\SysWOW64\perfhost.exe [2008-1-20 19968] S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-9-28 53760] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-3-18 1020768] S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2011-3-4 89920] . =============== File Associations =============== . FileExt: .js: JSFile=C:\Windows\SysWOW64\WScript.exe "%1" %* FileExt: .jse: JSEFile=C:\Windows\SysWOW64\WScript.exe "%1" %* . =============== Created Last 30 ================ . . ==================== Find3M ==================== . 2013-03-07 22:09:07 71024 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2013-03-07 22:09:07 691568 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe 2013-02-15 08:15:34 70004024 —-a-w- C:\Windows\System32\mrt.exe 2013-02-02 20:10:08 95648 —-a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll 2013-02-02 20:10:07 861088 —-a-w- C:\Windows\SysWow64\npDeployJava1.dll 2013-02-02 20:10:07 782240 —-a-w- C:\Windows\SysWow64\deployJava1.dll 2013-02-02 20:10:07 262560 —-a-w- C:\Windows\SysWow64\javaws.exe 2013-02-02 20:10:07 174496 —-a-w- C:\Windows\SysWow64\javaw.exe 2013-02-02 20:10:07 174496 —-a-w- C:\Windows\SysWow64\java.exe 2013-01-17 06:28:58 273840 ——w- C:\Windows\System32\MpSigStub.exe 2013-01-05 13:48:44 1147392 —-a-w- C:\Windows\System32\wininet.dll 2013-01-05 13:48:27 1489408 —-a-w- C:\Windows\System32\urlmon.dll 2013-01-05 13:48:27 108032 —-a-w- C:\Windows\System32\url.dll 2013-01-05 13:46:30 243712 —-a-w- C:\Windows\System32\occache.dll 2013-01-05 13:44:42 1062912 —-a-w- C:\Windows\System32\mstime.dll 2013-01-05 13:44:20 98304 —-a-w- C:\Windows\System32\mshtmled.dll 2013-01-05 13:44:20 9331200 —-a-w- C:\Windows\System32\mshtml.dll 2013-01-05 13:44:18 743424 —-a-w- C:\Windows\System32\msfeeds.dll 2013-01-05 13:44:18 71680 —-a-w- C:\Windows\System32\msfeedsbs.dll 2013-01-05 13:43:26 56832 —-a-w- C:\Windows\System32\licmgr10.dll 2013-01-05 13:43:11 31744 —-a-w- C:\Windows\System32\jsproxy.dll 2013-01-05 13:43:00 1538560 —-a-w- C:\Windows\System32\inetcpl.cpl 2013-01-05 13:42:28 219136 —-a-w- C:\Windows\System32\ieui.dll 2013-01-05 13:42:28 132096 —-a-w- C:\Windows\System32\iesysprep.dll 2013-01-05 13:42:27 77312 —-a-w- C:\Windows\System32\iesetup.dll 2013-01-05 13:42:27 2356736 —-a-w- C:\Windows\System32\iertutil.dll 2013-01-05 13:42:22 72192 —-a-w- C:\Windows\System32\iernonce.dll 2013-01-05 13:42:20 252416 —-a-w- C:\Windows\System32\iepeers.dll 2013-01-05 13:42:20 12509184 —-a-w- C:\Windows\System32\ieframe.dll 2013-01-05 13:42:11 459776 —-a-w- C:\Windows\System32\iedkcs32.dll 2013-01-05 11:59:52 916480 —-a-w- C:\Windows\SysWow64\wininet.dll 2013-01-05 11:59:33 1212928 —-a-w- C:\Windows\SysWow64\urlmon.dll 2013-01-05 11:59:32 105984 —-a-w- C:\Windows\SysWow64\url.dll 2013-01-05 11:57:59 479232 —-a-w- C:\Windows\System32\html.iec 2013-01-05 11:57:43 206848 —-a-w- C:\Windows\SysWow64\occache.dll 2013-01-05 11:55:52 611840 —-a-w- C:\Windows\SysWow64\mstime.dll 2013-01-05 11:55:25 67072 —-a-w- C:\Windows\SysWow64\mshtmled.dll 2013-01-05 11:55:25 6010368 —-a-w- C:\Windows\SysWow64\mshtml.dll 2013-01-05 11:55:21 630272 —-a-w- C:\Windows\SysWow64\msfeeds.dll 2013-01-05 11:55:21 55296 —-a-w- C:\Windows\SysWow64\msfeedsbs.dll 2013-01-05 11:54:47 43520 —-a-w- C:\Windows\SysWow64\licmgr10.dll 2013-01-05 11:54:34 25600 —-a-w- C:\Windows\SysWow64\jsproxy.dll 2013-01-05 11:54:23 1469440 —-a-w- C:\Windows\SysWow64\inetcpl.cpl 2013-01-05 11:54:07 164352 —-a-w- C:\Windows\SysWow64\ieui.dll 2013-01-05 11:54:07 109056 —-a-w- C:\Windows\SysWow64\iesysprep.dll 2013-01-05 11:54:06 71680 —-a-w- C:\Windows\SysWow64\iesetup.dll 2013-01-05 11:54:06 2004992 —-a-w- C:\Windows\SysWow64\iertutil.dll 2013-01-05 11:54:05 55808 —-a-w- C:\Windows\SysWow64\iernonce.dll 2013-01-05 11:54:05 184320 —-a-w- C:\Windows\SysWow64\iepeers.dll 2013-01-05 11:54:05 11111424 —-a-w- C:\Windows\SysWow64\ieframe.dll 2013-01-05 11:53:59 387584 —-a-w- C:\Windows\SysWow64\iedkcs32.dll 2013-01-05 10:33:42 162816 —-a-w- C:\Windows\System32\ieUnatt.exe 2013-01-05 10:33:29 70656 —-a-w- C:\Windows\System32\ie4uinit.exe 2013-01-05 10:32:20 12288 —-a-w- C:\Windows\System32\msfeedssync.exe 2013-01-05 10:32:00 1638912 —-a-w- C:\Windows\System32\mshtml.tlb 2013-01-05 10:23:06 385024 —-a-w- C:\Windows\SysWow64\html.iec 2013-01-05 08:47:17 133632 —-a-w- C:\Windows\SysWow64\ieUnatt.exe 2013-01-05 08:46:53 174080 —-a-w- C:\Windows\SysWow64\ie4uinit.exe 2013-01-05 08:45:43 13312 —-a-w- C:\Windows\SysWow64\msfeedssync.exe 2013-01-05 08:44:46 1638912 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2013-01-05 05:37:50 4695400 —-a-w- C:\Windows\System32\ntoskrnl.exe 2013-01-04 11:31:10 1423720 —-a-w- C:\Windows\System32\drivers\tcpip.sys 2013-01-04 01:59:24 2773504 —-a-w- C:\Windows\System32\win32k.sys 2012-12-16 13:31:20 48128 —-a-w- C:\Windows\System32\atmlib.dll 2012-12-16 13:12:54 34304 —-a-w- C:\Windows\SysWow64\atmlib.dll 2012-12-16 11:08:21 368128 —-a-w- C:\Windows\System32\atmfd.dll 2012-12-16 10:50:29 293376 —-a-w- C:\Windows\SysWow64\atmfd.dll 2012-12-14 21:49:28 24176 —-a-w- C:\Windows\System32\drivers\mbam.sys . ============= FINISH: 11:42:22.65 ===============
That looks pretty good. Let's run ComboFix and then clean up any dross that might be left.

Download ComboFix from here: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
ComboFix 13-03-07.03 - Exigo 03/08/2013 13:03:44.1.2 - x64 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2042.533 [GMT -5:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: Kaspersky Anti-Virus *Disabled/Updated* {56547CC9-C9B2-849D-8FEF-A496150D6A06} SP: Kaspersky Anti-Virus *Disabled/Updated* {ED359D2D-EF88-8B13-B55F-9FE46E8A20BB} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Exigo\AppData\Roaming\Mozilla\Firefox\Profiles\i52sed3g.default\searchplugins\bing-zugo.xml c:\users\Exigo\Documents\~WRL0078.tmp c:\users\Exigo\Documents\~WRL0243.tmp c:\users\Exigo\Documents\~WRL0331.tmp c:\users\Exigo\Documents\~WRL1836.tmp c:\users\Exigo\Documents\~WRL2096.tmp c:\users\Exigo\Documents\~WRL2568.tmp c:\windows\SysWow64\URTTemp c:\windows\SysWow64\URTTemp\regtlib.exe . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . . ——-\Service_Updater Service for StartNow Toolbar . . ((((((((((((((((((((((((( Files Created from 2013-02-08 to 2013-03-08 ))))))))))))))))))))))))))))))) . . 2013-03-08 18:18 . 2013-03-08 18:18 ——– d—–w- c:\users\Default\AppData\Local\temp 2013-03-08 12:13 . 2013-02-08 00:28 9162192 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B569DFF8-321E-405C-ADB2-73D91C322705}\mpengine.dll 2013-02-15 22:31 . 2013-02-15 22:31 186432 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\nppdf32.dll 2013-02-14 16:56 . 2013-01-04 11:31 1423720 —-a-w- c:\windows\system32\drivers\tcpip.sys 2013-02-14 16:56 . 2013-01-02 11:08 1027584 —-a-w- c:\program files\Common Files\Microsoft Shared\vgx\VGX.dll 2013-02-14 16:56 . 2013-01-02 07:37 759296 —-a-w- c:\program files (x86)\Common Files\Microsoft Shared\vgx\VGX.dll 2013-02-14 16:56 . 2013-01-04 01:59 2773504 —-a-w- c:\windows\system32\win32k.sys 2013-02-14 16:55 . 2013-01-05 13:44 9331200 —-a-w- c:\windows\system32\mshtml.dll 2013-02-14 16:55 . 2013-01-05 13:42 12509184 —-a-w- c:\windows\system32\ieframe.dll 2013-02-14 16:55 . 2013-01-05 13:42 2356736 —-a-w- c:\windows\system32\iertutil.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-03-07 22:09 . 2012-06-01 13:26 691568 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-03-07 22:09 . 2011-05-16 13:57 71024 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-02-15 08:15 . 2006-11-02 12:35 70004024 —-a-w- c:\windows\system32\mrt.exe 2013-02-02 20:10 . 2013-02-02 20:10 95648 —-a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2013-02-02 20:10 . 2012-06-21 12:49 861088 —-a-w- c:\windows\SysWow64\npDeployJava1.dll 2013-02-02 20:10 . 2011-03-04 16:39 782240 —-a-w- c:\windows\SysWow64\deployJava1.dll 2013-01-17 06:28 . 2011-03-04 17:54 273840 ——w- c:\windows\system32\MpSigStub.exe 2012-12-16 13:31 . 2012-12-22 08:01 48128 —-a-w- c:\windows\system32\atmlib.dll 2012-12-16 13:12 . 2012-12-22 08:01 34304 —-a-w- c:\windows\SysWow64\atmlib.dll 2012-12-16 11:08 . 2012-12-22 08:01 368128 —-a-w- c:\windows\system32\atmfd.dll 2012-12-16 10:50 . 2012-12-22 08:01 293376 —-a-w- c:\windows\SysWow64\atmfd.dll 2012-12-14 21:49 . 2011-03-05 15:06 24176 —-a-w- c:\windows\system32\drivers\mbam.sys . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SpybotSD TeaTimer"="c:\program files (x86)\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] "SugarSync"="c:\program files (x86)\SugarSync\SugarSyncManager.exe" [2013-01-24 11184480] "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-03-07 39408] "ISUSPM"="c:\programdata\FLEXnet\Connect\11\ISUSPM.exe" [2010-09-24 222496] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2012-12-04 5629312] "iCloudServices"="c:\program files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe" [2012-12-17 59872] "ApplePhotoStreams"="c:\program files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe" [2012-12-17 59872] "com.apple.dav.bookmarks.daemon"="c:\program files (x86)\Common Files\Apple\Internet Services\BookmarkDAV_client.exe" [2012-12-17 59872] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-01-22 98304] "AVP"="c:\program files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe" [2010-11-03 365336] "DNS7reminder"="c:\program files (x86)\Nuance\NaturallySpeaking11\Ereg\Ereg.exe" [2007-04-16 259624] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352] "ACQTMOUSE"="c:\program files (x86)\Mouse Setting\Mouse Setting Software\4.0\ACQTMAPP.exe" [2008-08-01 501760] "tvncontrol"="c:\program files (x86)\TightVNC\tvnserver.exe" [2011-08-03 828944] "PSDiagnosticM"="c:\program files (x86)\Linksys Wireless-G Print Server\PSDiagnosticM.exe" [2009-06-19 505128] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-12-12 152544] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-11-17 1066536] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) "SoftwareSASGeneration"= 1 (0x1) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc] @="Service" . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus] "DisableMonitoring"=dword:00000001 . S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2012-07-11 140672] S2 AdobeActiveFileMonitor11.0;Adobe Active File Monitor V11;c:\program files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe [2012-09-23 171600] S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_15f4e438\AESTSr64.exe [2009-03-20 89600] . . — Other Services/Drivers In Memory — . *NewlyCreated* - WS2IFSL . HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs Themes . Contents of the 'Scheduled Tasks' folder . 2013-03-08 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-01 22:09] . 2013-03-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-07 18:59] . 2013-03-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-07 18:59] . 2011-03-05 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job - c:\program files (x86)\Spybot - Search & Destroy\SpybotSD.exe [2011-03-05 20:31] . 2013-03-08 c:\windows\Tasks\Spybot - Search & Destroy Updater - Scheduled Task.job - c:\program files (x86)\Spybot - Search & Destroy\SDUpdate.exe [2011-03-05 20:31] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncBackedUp] @="{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472}" [HKEY_CLASSES_ROOT\CLSID\{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472}] 2013-01-24 07:48 482144 —-a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncPending] @="{62CCD8E3-9C21-41E1-B55E-1E26DFC68511}" [HKEY_CLASSES_ROOT\CLSID\{62CCD8E3-9C21-41E1-B55E-1E26DFC68511}] 2013-01-24 07:48 482144 —-a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncRoot] @="{A759AFF6-5851-457D-A540-F4ECED148351}" [HKEY_CLASSES_ROOT\CLSID\{A759AFF6-5851-457D-A540-F4ECED148351}] 2013-01-24 07:48 482144 —-a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncShared] @="{1574C9EF-7D58-488F-B358-8B78C1538F51}" [HKEY_CLASSES_ROOT\CLSID\{1574C9EF-7D58-488F-B358-8B78C1538F51}] 2013-01-24 07:48 482144 —-a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-11-26 1657128] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-06-16 499608] . ——- Supplementary Scan ——- . uStart Page = about:blank uLocal Page = c:\windows\system32\blank.htm mDefault_Page_URL = hxxp://www.dell.com mLocal Page = c:\windows\SysWOW64\blank.htm IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\OFFICE11\EXCEL.EXE/3000 IE: Send image to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm IE: Send page to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm TCP: DhcpNameServer = [removed] [removed] FF - ProfilePath - c:\users\Exigo\AppData\Roaming\Mozilla\Firefox\Profiles\i52sed3g.default\ FF - prefs.js: browser.startup.homepage - about:home FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?pc=Z180&form=ZGAADF&install_date=20111104&q= FF - prefs.js: network.proxy.type - 0 FF - ExtSQL: 2013-03-05 13:18; {e4a8a97b-f2ed-450b-b12d-ee082ba24781}; c:\users\Exigo\AppData\Roaming\Mozilla\Firefox\Profiles\i52sed3g.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi FF - ExtSQL: !HIDDEN! 2011-03-04 11:35; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension . - - - - ORPHANS REMOVED - - - - . Toolbar-{5911488E-9D1E-40ec-8CBB-06B231CC153F} - c:\program files (x86)\StartNow Toolbar\Toolbar32.dll Wow6432Node-HKCU-Run-Facebook Update - c:\users\Exigo\AppData\Local\Facebook\Update\FacebookUpdate.exe Wow6432Node-HKCU-Run-StartNow Search Protect - c:\program files (x86)\StartNow Toolbar\search_protect.exe Wow6432Node-HKLM-Run-StartNowToolbarHelper - c:\program files (x86)\StartNow Toolbar\ToolbarHelper.exe SafeBoot-WudfPf SafeBoot-WudfRd HKLM-Run-SysTrayApp - c:\program files (x86)\IDT\WDM\sttray64.exe AddRemove-don't take it personally, babe, it just ain't your story - c:\program files (x86)\don't take it personally AddRemove-ESN Sonar-0.70.0 - c:\program files (x86)\Battlelog Web Plugins\Sonar\esnsonar_uninstall.exe AddRemove-PunkBusterSvc - c:\program files (x86)\Steam\steamapps\common\Assassins Creed Brotherhood\pbsvc.exe AddRemove-StartNow Toolbar - c:\program files (x86)\StartNow Toolbar\StartNowToolbarUninstall.exe AddRemove-{B5E6D105-DFB4-46B4-88BF-9DC52686DBE7}_is1 - c:\program files (x86)\Steam\steamapps\common\medieval ii total war\mods\Broken_Crescent_kingdoms\unins000.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-219705432-3252208987-4262155305-1000\Software\SecuROM\License information*] "datasecu"=hex:c0,e9,08,51,cd,ac,51,6e,54,65,ef,9b,1c,0f,4e,81,c6,1f,c6,e2,bc, 7a,6d,40,3f,1c,0d,1b,5b,f6,d2,33,fc,7c,b8,d1,56,fc,21,6f,d0,10,00,52,1b,e7,\ "rkeysecu"=hex:6d,83,00,fd,94,57,e5,65,5a,4d,71,bb,a7,b9,72,29 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_171_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_171_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_171_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_171_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_171.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_171.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_171.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_171.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}] @Denied: (A 2) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0] @="Shockwave Flash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}] @Denied: (A 2) (Everyone) @="" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0] @="FlashBroker" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes] "SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59, 00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\ . ———————— Other Running Processes ———————— . c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\Common Files\Nuance\dgnsvc.exe c:\windows\SysWOW64\PnkBstrA.exe c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe c:\windows\SysWOW64\RunDll32.exe c:\program files (x86)\Common Files\Java\Java Update\jucheck.exe . ************************************************************************** . Completion time: 2013-03-08 13:41:58 - machine was rebooted ComboFix-quarantined-files.txt 2013-03-08 18:41 . Pre-Run: 299,911,245,824 bytes free Post-Run: 300,278,140,928 bytes free . - - End Of File - - 9069AD7BB0A539F9038DBFEE57F5FAB3
Awesome. That took care of all the adware I saw.

Let's get an online scan to have a look for things I can't see.

Go here to run an online scanner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish

Also, please let me know how things seem to be working.
Hope these aren't too nasty? C:\Users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43\13eb6b6b-18bddd28 a variant of Java/TrojanDownloader.Agent.NDJ trojan C:\Users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55\51d1c3f7-1fc93e9e a variant of Java/TrojanDownloader.OpenStream.NCE trojan C:\Users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63\304979ff-2cd01e37 multiple threats C:\Users\Exigo\Downloads\APB_Reloaded_Installer.exe Win32/OpenCandy application C:\Users\Exigo\Downloads\Calhoun HS Sports Boosters 2012 Golf Outing pdf(1).exe Win32/InstalleRex.E.Gen application C:\Users\Exigo\Downloads\Calhoun HS Sports Boosters 2012 Golf Outing pdf.exe Win32/InstalleRex.E.Gen application C:\Users\Exigo\Downloads\PlayFLV(1).exe Win32/TrojanDownloader.Adload.NIQ trojan C:\Users\Exigo\Downloads\PlayFLV.exe Win32/TrojanDownloader.Adload.NIQ trojan C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\55VD0P0Q\updater-startnow-200-2.5-d[1].exe a variant of Win32/Toolbar.Zugo application C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\55VD0P0Q\updater-startnow-200-2.5-d[1].exe a variant of Win32/Toolbar.Zugo application
Everything appears to be running ok. No more random blue hyperlinks. Webpages load well, apps-ie word, excel open fine.
Those infected downloads are probably what started your problems:

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    File::
    C:\Users\Exigo\Downloads\APB_Reloaded_Installer.exe 
    C:\Users\Exigo\Downloads\Calhoun HS Sports Boosters 2012 Golf Outing pdf(1).exe 
    C:\Users\Exigo\Downloads\Calhoun HS Sports Boosters 2012 Golf Outing pdf.exe 
    C:\Users\Exigo\Downloads\PlayFLV(1).exe 
    C:\Users\Exigo\Downloads\PlayFLV.exe 
    C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\55VD0P0Q\updater-startnow-200-2.5-d[1].exe 
    C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\55VD0P0Q\updater-startnow-200-2.5-d[1].exe 
    Folder::
    C:\Users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
ComboFix 13-03-10.02 - Exigo 03/10/2013 13:05:43.2.2 - x64 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2042.702 [GMT -4:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\Exigo\Desktop\CFScript.txt AV: Kaspersky Anti-Virus *Disabled/Updated* {56547CC9-C9B2-849D-8FEF-A496150D6A06} SP: Kaspersky Anti-Virus *Disabled/Updated* {ED359D2D-EF88-8B13-B55F-9FE46E8A20BB} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . FILE :: "c:\users\Exigo\Downloads\APB_Reloaded_Installer.exe" "c:\users\Exigo\Downloads\Calhoun HS Sports Boosters 2012 Golf Outing pdf(1).exe" "c:\users\Exigo\Downloads\Calhoun HS Sports Boosters 2012 Golf Outing pdf.exe" "c:\users\Exigo\Downloads\PlayFLV(1).exe" "c:\users\Exigo\Downloads\PlayFLV.exe" "c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\55VD0P0Q\updater-startnow-200-2.5-d[1].exe" "c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\55VD0P0Q\updater-startnow-200-2.5-d[1].exe" . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0\532b51c0-28d0a946 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0\532b51c0-28d0a946.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11\12762e8b-6c886d06 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11\12762e8b-6c886d06.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11\4792d4b-77c1ceee c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11\4792d4b-77c1ceee.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12\171d130c-1cd1b1fd c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12\171d130c-1cd1b1fd.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12\3c28044c-28f7c1b1 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12\3c28044c-28f7c1b1.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12\4db9990c-1b304816 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12\4db9990c-1b304816.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13\52bc730d-69ec03ca c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13\52bc730d-69ec03ca.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13\52bc730d-706b0272 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13\52bc730d-706b0272.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13\68b154cd-1c5fba9f c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13\68b154cd-1c5fba9f.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14\3bc1b4e-13e6fe30 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14\3bc1b4e-13e6fe30.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\15\360e8b0f-7f2adb07 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\15\360e8b0f-7f2adb07.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\533cc850-42ecbd48 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\533cc850-42ecbd48.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\57e76190-45943e03 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\57e76190-45943e03.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\74bac490-26fb8f76 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\74bac490-26fb8f76.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\7b8a5350-21bde734 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\7b8a5350-21bde734.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\7ef9f550-536261c3 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\7ef9f550-536261c3.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\61fa3d11-181ad4a8 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\61fa3d11-181ad4a8.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\d59d251-122da4f5 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\d59d251-122da4f5.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18\3d518612-12838d60 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18\3d518612-12838d60.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19\29ebdd13-727cd5d3 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19\29ebdd13-727cd5d3.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19\69cc3853-104e32ef c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19\69cc3853-104e32ef.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2\5a38a7c2-7f4347be c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2\5a38a7c2-7f4347be.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20\279bffd4-36933ce6 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20\279bffd4-36933ce6.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20\40b36cd4-2bec5084 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20\40b36cd4-2bec5084.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20\62b1f2d4-63f8562f c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20\62b1f2d4-63f8562f.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25\7010a1d9-7f5acfff c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25\7010a1d9-7f5acfff.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\26\716a051a-2724c625 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\26\716a051a-2724c625.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27\5c78191b-2e0e01f6 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27\5c78191b-2e0e01f6.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28\26b0251c-6fa12773 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28\26b0251c-6fa12773.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28\32ccd61c-1ad62235 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28\32ccd61c-1ad62235.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28\5309a69c-7ab3922f c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28\5309a69c-7ab3922f.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29\32a8ba1d-5e2e404a c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29\32a8ba1d-5e2e404a.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3\520f91c3-33c3bfb9 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3\520f91c3-33c3bfb9.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30\13c8259e-114b894d c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30\13c8259e-114b894d.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30\13c8259e-12e066f5 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30\13c8259e-12e066f5.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30\60f58fde-40de2f9b c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30\60f58fde-40de2f9b.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31\111e5e1f-1749665b c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31\111e5e1f-1749665b.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31\790c545f-6dce903e c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31\790c545f-6dce903e.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32\29739120-6a2b30b1 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32\29739120-6a2b30b1.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32\524312e0-516996d2 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32\524312e0-516996d2.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32\524312e0-629444dc c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32\524312e0-629444dc.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\7e22ef61-3e2c8338 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\7e22ef61-3e2c8338.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\7e22ef61-78f55ecb c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\7e22ef61-78f55ecb.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\34\618f7e2-4a43b327 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\34\618f7e2-4a43b327.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36\546effe4-5ae840c1 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36\546effe4-5ae840c1.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37\39e9c725-70027e61 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37\39e9c725-70027e61.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37\74973ee5-3481f725 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37\74973ee5-3481f725.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38\56a51ee6-14c66996 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38\56a51ee6-14c66996.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39\120daf27-655706c0 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39\120daf27-655706c0.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39\7702d9a7-1b7d3c35 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39\7702d9a7-1b7d3c35.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4\741599c4-570ac6c5 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4\741599c4-570ac6c5.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40\1e434aa8-4cb33a39 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40\1e434aa8-4cb33a39.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40\1e434aa8-7c8cf735 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40\1e434aa8-7c8cf735.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40\24958828-6beb7ec0 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40\24958828-6beb7ec0.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40\785a4d68-13f739c8 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40\785a4d68-13f739c8.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41\2fcb83e9-1b6af6d7 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41\2fcb83e9-1b6af6d7.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42\245b39ea-73703967 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42\245b39ea-73703967.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43\13eb6b6b-18bddd28 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43\13eb6b6b-18bddd28.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43\5c2df5ab-357c0109 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43\5c2df5ab-357c0109.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43\5c2df5ab-7d52cde9 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43\5c2df5ab-7d52cde9.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46\611aee2e-6b3127ff c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46\611aee2e-6b3127ff.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46\73c78dae-21547048 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46\73c78dae-21547048.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47\a2019ef-171a87ea c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47\a2019ef-171a87ea.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47\a2019ef-54b77a99 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47\a2019ef-54b77a99.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48\1944c670-13a7cea4 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48\1944c670-13a7cea4.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48\23fc14f0-76fe100a c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48\23fc14f0-76fe100a.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48\38c71130-2385595e c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48\38c71130-2385595e.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48\4c716570-34bc27c6 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48\4c716570-34bc27c6.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49\2930faf1-3a2f678f c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49\2930faf1-3a2f678f.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5\45eeac45-53c23023 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5\45eeac45-53c23023.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5\45eeac45-5a9839ea c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5\45eeac45-5a9839ea.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5\e61ea05-286f9234 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5\e61ea05-286f9234.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50\7ca4c5b2-391704a8 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50\7ca4c5b2-391704a8.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51\7f4949b3-12b998b3 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51\7f4949b3-12b998b3.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52\61773234-5764c375 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52\61773234-5764c375.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52\7b7b5174-21461ee0 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52\7b7b5174-21461ee0.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52\7b7b5174-5a418f03 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52\7b7b5174-5a418f03.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53\344e9c75-238ee06c c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53\344e9c75-238ee06c.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54\60d03236-6d6c1a49 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54\60d03236-6d6c1a49.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55\51d1c3f7-1fc93e9e c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55\51d1c3f7-1fc93e9e.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56\33dcb938-542f0721 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56\33dcb938-542f0721.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56\4966c78-2467c677 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56\4966c78-2467c677.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56\72814438-192b984c c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56\72814438-192b984c.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\149d93f9-7339dee8 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\149d93f9-7339dee8.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\6c019739-33b1f17a c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\6c019739-33b1f17a.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\718a9779-2e3b8de0 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\718a9779-2e3b8de0.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\7836a5f9-7957a5f6 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\7836a5f9-7957a5f6.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58\41d630fa-3497b635 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58\41d630fa-3497b635.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59\23176efb-1c1042ec c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59\23176efb-1c1042ec.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59\2f5fe1fb-7b2a33f3 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59\2f5fe1fb-7b2a33f3.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6\579f0086-2da49acb c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6\579f0086-2da49acb.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60\a25923c-1c6ad642 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60\a25923c-1c6ad642.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63\304979ff-2cd01e37 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63\304979ff-2cd01e37.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7\15e0d207-6a266fe9 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7\15e0d207-6a266fe9.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\3177f4c8-2be60a82 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\3177f4c8-2be60a82.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\45130888-14b0bf42 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\45130888-14b0bf42.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\6f2b1608-6421b7de c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\6f2b1608-6421b7de.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9\1421a189-24eb8418 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9\1421a189-24eb8418.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9\721dfe89-3fab5877 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9\721dfe89-3fab5877.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9\721dfe89-731906b7 c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9\721dfe89-731906b7.idx c:\users\Exigo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\lastAccessed c:\users\Exigo\Downloads\APB_Reloaded_Installer.exe c:\users\Exigo\Downloads\Calhoun HS Sports Boosters 2012 Golf Outing pdf(1).exe c:\users\Exigo\Downloads\Calhoun HS Sports Boosters 2012 Golf Outing pdf.exe c:\users\Exigo\Downloads\PlayFLV(1).exe c:\users\Exigo\Downloads\PlayFLV.exe c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\55VD0P0Q\updater-startnow-200-2.5-d[1].exe . . ((((((((((((((((((((((((( Files Created from 2013-02-10 to 2013-03-10 ))))))))))))))))))))))))))))))) . . 2013-03-10 17:21 . 2013-03-10 17:21 ——– d—–w- c:\users\Exigo\AppData\Local\temp 2013-03-10 17:21 . 2013-03-10 17:21 ——– d—–w- c:\users\Default\AppData\Local\temp 2013-03-09 16:32 . 2013-03-09 16:32 ——– d—–w- c:\program files (x86)\ESET 2013-03-08 12:13 . 2013-02-08 00:28 9162192 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B569DFF8-321E-405C-ADB2-73D91C322705}\mpengine.dll 2013-02-15 22:31 . 2013-02-15 22:31 186432 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\nppdf32.dll 2013-02-14 16:56 . 2013-01-04 11:31 1423720 —-a-w- c:\windows\system32\drivers\tcpip.sys 2013-02-14 16:56 . 2013-01-02 11:08 1027584 —-a-w- c:\program files\Common Files\Microsoft Shared\vgx\VGX.dll 2013-02-14 16:56 . 2013-01-02 07:37 759296 —-a-w- c:\program files (x86)\Common Files\Microsoft Shared\vgx\VGX.dll 2013-02-14 16:56 . 2013-01-04 01:59 2773504 —-a-w- c:\windows\system32\win32k.sys 2013-02-14 16:55 . 2013-01-05 13:44 9331200 —-a-w- c:\windows\system32\mshtml.dll 2013-02-14 16:55 . 2013-01-05 13:42 12509184 —-a-w- c:\windows\system32\ieframe.dll 2013-02-14 16:55 . 2013-01-05 13:42 2356736 —-a-w- c:\windows\system32\iertutil.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-03-07 22:09 . 2012-06-01 13:26 691568 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-03-07 22:09 . 2011-05-16 13:57 71024 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-02-15 08:15 . 2006-11-02 12:35 70004024 —-a-w- c:\windows\system32\mrt.exe 2013-02-02 20:10 . 2013-02-02 20:10 95648 —-a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2013-02-02 20:10 . 2012-06-21 12:49 861088 —-a-w- c:\windows\SysWow64\npDeployJava1.dll 2013-02-02 20:10 . 2011-03-04 16:39 782240 —-a-w- c:\windows\SysWow64\deployJava1.dll 2013-01-17 06:28 . 2011-03-04 17:54 273840 ——w- c:\windows\system32\MpSigStub.exe 2012-12-16 13:31 . 2012-12-22 08:01 48128 —-a-w- c:\windows\system32\atmlib.dll 2012-12-16 13:12 . 2012-12-22 08:01 34304 —-a-w- c:\windows\SysWow64\atmlib.dll 2012-12-16 11:08 . 2012-12-22 08:01 368128 —-a-w- c:\windows\system32\atmfd.dll 2012-12-16 10:50 . 2012-12-22 08:01 293376 —-a-w- c:\windows\SysWow64\atmfd.dll 2012-12-14 21:49 . 2011-03-05 15:06 24176 —-a-w- c:\windows\system32\drivers\mbam.sys . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{5911488E-9D1E-40ec-8CBB-06B231CC153F}"= "c:\program files (x86)\StartNow Toolbar\Toolbar32.dll" [BU] . [HKEY_CLASSES_ROOT\clsid\{5911488e-9d1e-40ec-8cbb-06b231cc153f}] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SpybotSD TeaTimer"="c:\program files (x86)\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] "SugarSync"="c:\program files (x86)\SugarSync\SugarSyncManager.exe" [2013-01-24 11184480] "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-03-07 39408] "ISUSPM"="c:\programdata\FLEXnet\Connect\11\ISUSPM.exe" [2010-09-24 222496] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2012-12-04 5629312] "iCloudServices"="c:\program files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe" [2012-12-17 59872] "ApplePhotoStreams"="c:\program files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe" [2012-12-17 59872] "com.apple.dav.bookmarks.daemon"="c:\program files (x86)\Common Files\Apple\Internet Services\BookmarkDAV_client.exe" [2012-12-17 59872] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-01-22 98304] "AVP"="c:\program files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe" [2010-11-03 365336] "DNS7reminder"="c:\program files (x86)\Nuance\NaturallySpeaking11\Ereg\Ereg.exe" [2007-04-16 259624] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352] "ACQTMOUSE"="c:\program files (x86)\Mouse Setting\Mouse Setting Software\4.0\ACQTMAPP.exe" [2008-08-01 501760] "tvncontrol"="c:\program files (x86)\TightVNC\tvnserver.exe" [2011-08-03 828944] "PSDiagnosticM"="c:\program files (x86)\Linksys Wireless-G Print Server\PSDiagnosticM.exe" [2009-06-19 505128] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-12-12 152544] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-11-17 1066536] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) "SoftwareSASGeneration"= 1 (0x1) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc] @="Service" . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus] "DisableMonitoring"=dword:00000001 . S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2012-07-11 140672] S2 AdobeActiveFileMonitor11.0;Adobe Active File Monitor V11;c:\program files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe [2012-09-23 171600] S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_15f4e438\AESTSr64.exe [2009-03-20 89600] . . HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs Themes . Contents of the 'Scheduled Tasks' folder . 2013-03-10 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-01 22:09] . 2013-03-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-07 18:59] . 2013-03-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-07 18:59] . 2011-03-05 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job - c:\program files (x86)\Spybot - Search & Destroy\SpybotSD.exe [2011-03-05 20:31] . 2013-03-09 c:\windows\Tasks\Spybot - Search & Destroy Updater - Scheduled Task.job - c:\program files (x86)\Spybot - Search & Destroy\SDUpdate.exe [2011-03-05 20:31] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncBackedUp] @="{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472}" [HKEY_CLASSES_ROOT\CLSID\{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472}] 2013-01-24 07:48 482144 —-a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncPending] @="{62CCD8E3-9C21-41E1-B55E-1E26DFC68511}" [HKEY_CLASSES_ROOT\CLSID\{62CCD8E3-9C21-41E1-B55E-1E26DFC68511}] 2013-01-24 07:48 482144 —-a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncRoot] @="{A759AFF6-5851-457D-A540-F4ECED148351}" [HKEY_CLASSES_ROOT\CLSID\{A759AFF6-5851-457D-A540-F4ECED148351}] 2013-01-24 07:48 482144 —-a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncShared] @="{1574C9EF-7D58-488F-B358-8B78C1538F51}" [HKEY_CLASSES_ROOT\CLSID\{1574C9EF-7D58-488F-B358-8B78C1538F51}] 2013-01-24 07:48 482144 —-a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-11-26 1657128] "SysTrayApp"="c:\program files (x86)\IDT\WDM\sttray64.exe" [BU] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-06-16 499608] . ——- Supplementary Scan ——- . uStart Page = about:blank uLocal Page = c:\windows\system32\blank.htm mDefault_Page_URL = hxxp://www.dell.com mLocal Page = c:\windows\SysWOW64\blank.htm IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\OFFICE11\EXCEL.EXE/3000 IE: Send image to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm IE: Send page to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm TCP: DhcpNameServer = [removed] [removed] FF - ProfilePath - c:\users\Exigo\AppData\Roaming\Mozilla\Firefox\Profiles\i52sed3g.default\ FF - prefs.js: browser.startup.homepage - about:home FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?pc=Z180&form=ZGAADF&install_date=20111104&q= FF - prefs.js: network.proxy.type - 0 FF - ExtSQL: 2013-03-05 13:18; {e4a8a97b-f2ed-450b-b12d-ee082ba24781}; c:\users\Exigo\AppData\Roaming\Mozilla\Firefox\Profiles\i52sed3g.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi FF - ExtSQL: !HIDDEN! 2011-03-04 11:35; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension . - - - - ORPHANS REMOVED - - - - . AddRemove-don't take it personally, babe, it just ain't your story - c:\program files (x86)\don't take it personally AddRemove-ESN Sonar-0.70.0 - c:\program files (x86)\Battlelog Web Plugins\Sonar\esnsonar_uninstall.exe AddRemove-PunkBusterSvc - c:\program files (x86)\Steam\steamapps\common\Assassins Creed Brotherhood\pbsvc.exe AddRemove-StartNow Toolbar - c:\program files (x86)\StartNow Toolbar\StartNowToolbarUninstall.exe AddRemove-{B5E6D105-DFB4-46B4-88BF-9DC52686DBE7}_is1 - c:\program files (x86)\Steam\steamapps\common\medieval ii total war\mods\Broken_Crescent_kingdoms\unins000.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-219705432-3252208987-4262155305-1000\Software\SecuROM\License information*] "datasecu"=hex:c0,e9,08,51,cd,ac,51,6e,54,65,ef,9b,1c,0f,4e,81,c6,1f,c6,e2,bc, 7a,6d,40,3f,1c,0d,1b,5b,f6,d2,33,fc,7c,b8,d1,56,fc,21,6f,d0,10,00,52,1b,e7,\ "rkeysecu"=hex:6d,83,00,fd,94,57,e5,65,5a,4d,71,bb,a7,b9,72,29 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_171_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_171_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_171_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_171_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_171.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_171.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_171.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_171.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}] @Denied: (A 2) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0] @="Shockwave Flash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}] @Denied: (A 2) (Everyone) @="" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0] @="FlashBroker" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes] "SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59, 00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\ . Completion time: 2013-03-10 13:27:35 ComboFix-quarantined-files.txt 2013-03-10 17:27 ComboFix2.txt 2013-03-08 18:41 . Pre-Run: 301,356,720,128 bytes free Post-Run: 301,172,547,584 bytes free . - - End Of File - - F220DB88323BD3405BE0C37DA2225872
Log looks good :D


Time for some housekeeping
  • Click START then RUN
  • Now type ComboFix /Uninstall in the runbox and click OK.
  • Note the space between the X and the U, it needs to be there.
  • [external image: Posted Image]
The above procedure will:
  • Implement some cleanup procedures.
  • Reset System Restore.

Now to remove most of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the cleanup process. If you are asked to reboot the machine choose Yes.

You can just delete any tools or logs that are left over.


Please re-enable any security that was disabled.


The following is my standard advice for the future. Use what you can and pat yourself on the back for what you're already doing.

Please take time to read Preventing Malware - Tools and Practices for Safe Computing. Very important information for your consideration is contained therein.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein


Also: "How to prevent malware"
by miekiemoes

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:
Hi Tomk, Thanks for all your help, I am working through your recommendations. Please clarify a few things for now and I may have additional questions. 1. I typically use Firefox-are there similar steps to secure as done for IE 2. I currently use Kapersky AV- subscription runs out in 21 days. Do any of the other AV options slow down laptop less? 3. Firewall used now is Windows, should I also use a 2nd party s/w offer as well? 4. I am unable to reactivate Windows Defender. Attached screen shot of error
#1
I believe that active X is the most "unsecure" part of IE. Firefox doesn't use it. It is possible to be "more secure" with firefox using No script - but you have to be willing to work with it. Personally I use it… but most people find it annoying. The important thing to remember is that even if you typically use Firefox as your browser… your computer will still use IE. IE is embedded into windows so you need to keep it secure - even when you think you don't use it.

#2
In my opinion, Kaspersky is one of the best AV programs. I use free ones. The least obtrusive is probably Microsoft Security Essentials (MSSE). Then probably Avast!. I also use Avira.

#3
In my opinion… the windows firewall is adequate. The is especially true if you are behind a hardware firewall as is found in your router. There are others that will tell you that 3rd party firewalls are better… but I am not of that opinion.

#4
Have you tried restarting your system as suggested?
Thanks for quick response. I have rebooted and shut down a few times without success enabling Defender. I don't suppose it is a big deal but thought it worth mentioning. I do have a router FW so should be good there. And since some requests will surprise me and use IE I get that it should be updated. I need to be sure I have Java updated correctly and old versions removed. I will work on this tonight but I may need to clarify.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI