This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

NOD32 detects problem with mbr sector of the 2. physical disk [Solved]

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

As the title said, NOD32 detected a problem with the MBR sector of the 2. physical disk a couple days ago and blocked it, but it is unable to clean it from my computer. I've never seen this sort of virus before so I hoped it was a false alert and that it would fix itself after a couple days, but now I'm a tad worried.

I've looked for a solution in the internet and have found others who share my problem, but advice varies. Some say it is a false alert, others claimed it is a very difficult problem. Those in the latter also offered several solutions, but also warned that it might harm my computer. Some even told me that the only solution is a reformat, which I have absolutely no experience with. I also found a thread in this very forum that was resolved, but it looks very specialized so I doubt I could follow the steps taken without destroying my computer.

So I hope you guys can offer a more detailed insight to this problem and maybe help me fix it.

Here is my HJT file:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 3:05:39 AM, on 7/12/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16635)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Users\Jason\AppData\Local\Akamai\netsession_win.exe
C:\Users\Jason\AppData\Roaming\SearchProtect\bin\cltmng.exe
C:\Users\Jason\AppData\Local\Akamai\netsession_win.exe
C:\Program Files (x86)\Creative\THX TruStudio PC\THXAudioCP\THXAudio.exe
C:\Program Files (x86)\PC Tools Firewall Plus\FirewallGUI.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe
C:\Users\Jason\Downloads\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.gateway.com/rdr.aspx?b=ACG…55v1k5k4711r508
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.gateway.com/rdr.aspx?b=ACG…55v1k5k4711r508
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: uTorrentControl_v6 Toolbar - {96f454ea-9d38-474f-b504-56193e00c1a5} - C:\Program Files (x86)\uTorrentControl_v6\prxtbuTor.dll
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Partner BHO Class - {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - C:\ProgramData\Partner\Partner.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: uTorrentControl_v6 - {96f454ea-9d38-474f-b504-56193e00c1a5} - C:\Program Files (x86)\uTorrentControl_v6\prxtbuTor.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: uTorrentControl_v6 Toolbar - {96f454ea-9d38-474f-b504-56193e00c1a5} - C:\Program Files (x86)\uTorrentControl_v6\prxtbuTor.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [THX Audio Control Panel] "C:\Program Files (x86)\Creative\THX TruStudio PC\THXAudioCP\THXAudio.exe" /r
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [00PCTFW] "C:\Program Files (x86)\PC Tools Firewall Plus\FirewallGUI.exe" -s
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [vProt] "C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe"
O4 - HKLM\..\Run: [SearchProtectAll] C:\Program Files (x86)\SearchProtect\bin\cltmng.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Akamai NetSession Interface] "C:\Users\Jason\AppData\Local\Akamai\netsession_win.exe"
O4 - HKCU\..\Run: [SearchProtect] C:\Users\Jason\AppData\Roaming\SearchProtect\bin\cltmng.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - .DEFAULT User Startup: Best Buy pc app.lnk = C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\14.0.1\ViProtocol.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Search Protect by Conduit Updater (CltMngSvc) - Conduit - C:\Program Files (x86)\SearchProtect\bin\CltMngSvc.exe
O23 - Service: Creative ALchemy AL6 Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PC Tools Firewall Plus (PCToolsFirewallPlus) - Unknown owner - C:\Program Files (x86)\PC Tools Firewall Plus\FWService.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: USBS3S4Detection - Unknown owner - C:\OEM\USBDECTION\USBS3S4Detection.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: vToolbarUpdater14.0.1 - Unknown owner - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\14.0.1\ToolbarUpdater.exe
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XMouseButton Launcher - Highresolution Enterprises - C:\Program Files\Highresolution Enterprises\X-Mouse Button Control\XMouseButtonSvc.exe

–
End of file - 12756 bytes

Thanks in advance.

Sidenote: I don't know if this is related or not, but recently, youtube have gotten very slow for me. After 2 or 3 minutes of watching a video, it would suddenly stop loading and won't start again until I refresh. Sometimes, not even. I don't have this problem with other video sites though so I've just assumed it is just their server problem.
Hi there,
my name is Marius and I will be assisting you with your Malware related problems.

Before we move on, please read the following points carefully.
  • First, read my instructions completely. If there is anything that you do not understand kindly ask before proceeding.
  • Perform everything in the correct order. Sometimes one step requires the previous one.
  • If you have any problems while you are follow my instructions, Stop there and tell me the exact nature of your problem.
  • Do not run any other scans without instruction or Add/ Remove Software unless I tell you to do so. This would change the output of our tools and could be confusing for me.
  • Post all Logfiles as a reply rather than as an attachment unless I specifically ask you. If you can not post all logfiles in one reply, feel free to use more posts.
  • If I don't hear from you within 3 days from this initial or any subsequent post, then this thread will be closed.
  • Stay with me. I will give you some advice about prevention after the cleanup process. Absence of symptoms does not always mean the computer is clean.
  • My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.




Download DDS and save it to your desktop from here or here or
here.

Disable any script blocker, and then double click dds.scr to run the tool.

When done, DDS will open two (2) logs
DDS.txt
Attach.txt
Save both reports to your desktop.




Please download Malwarebytes Anti-Rootkit from here Malwarebytes : Malwarebytes Anti-Rootkit and save it to your desktop.

Be sure to print out and follow the instructions provided on that same page.

Caution: This is a beta version so please be sure to read the disclaimer and back up any important data before using.

  • Double click the mbar.zip file to open it, then 'Extract all files'.
  • Double click the mbar folder to open it, then double click mbar.exe to start the tool.
Check for Updates, then Scan your system for malware

If malware is found, do NOT press the Cleanup button yet. Click EXIT.

I'd like to see the log first so I can see what it sees. You'll find the log in that mbar folder as MBAR-log-***.txt . Please attach that to your next reply.
Alright, I've done both task. Malwarebytes Anti-Rootkit said that it didn't find any malware or root-kit in my system. Here are the two reports from the DDS. Report 1: DDS (Ver_2012-11-20.01) - NTFS_AMD64 Internet Explorer: 10.0.9200.16635 BrowserJavaVersion: 10.25.2 Run by [removed] at 12:04:28 on 2013-07-12 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.8183.6011 [GMT -7:00] . AV: ESET NOD32 Antivirus 4.0 *Enabled/Outdated* {CB0F8167-5331-BA19-698E-64816B6801A5} SP: ESET NOD32 Antivirus 4.0 *Enabled/Outdated* {706E6083-750B-B597-533E-5FF310EF4B18} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: PC Tools Firewall Plus *Disabled* {175D0B73-9F8F-2CA9-8BF1-62277A276DC9} . ============== Running Processes =============== . C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\atieclxx.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\WLANExt.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Windows\system32\taskhost.exe C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe C:\Windows\System32\rundll32.exe C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Microsoft LifeChat\LifeChat.exe C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Users\Jason\AppData\Local\Akamai\netsession_win.exe C:\Users\Jason\AppData\Roaming\SearchProtect\bin\cltmng.exe C:\Program Files (x86)\SearchProtect\bin\CltMngSvc.exe C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe C:\Program Files (x86)\PC Tools Firewall Plus\FWService.exe C:\Users\Jason\AppData\Local\Akamai\netsession_win.exe C:\Program Files (x86)\Creative\THX TruStudio PC\THXAudioCP\THXAudio.exe C:\Program Files (x86)\PC Tools Firewall Plus\FirewallGUI.exe C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe C:\Program Files (x86)\iTunes\iTunesHelper.exe C:\OEM\USBDECTION\USBS3S4Detection.exe C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\14.0.1\ToolbarUpdater.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\Highresolution Enterprises\X-Mouse Button Control\XMouseButtonSvc.exe C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE C:\Program Files\iPod\bin\iPodService.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\System32\WUDFHost.exe C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Users\Jason\Desktop\mbar-1.06.0.1004\mbar\mbar.exe C:\Windows\System32\cscript.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://homepage.gateway.com/rdr.aspx?b=ACGW&l=0409&m=fx6840&r=17361210z306p0455v1k5k4711r508 uDefault_Page_URL = hxxp://homepage.gateway.com/rdr.aspx?b=ACGW&l=0409&m=fx6840&r=17361210z306p0455v1k5k4711r508 uProxyOverride = ;*.local uURLSearchHooks: uTorrentControl_v6 Toolbar: {96f454ea-9d38-474f-b504-56193e00c1a5} - C:\Program Files (x86)\uTorrentControl_v6\prxtbuTor.dll mURLSearchHooks: uTorrentControl_v6 Toolbar: {96f454ea-9d38-474f-b504-56193e00c1a5} - C:\Program Files (x86)\uTorrentControl_v6\prxtbuTor.dll mWinlogon: Userinit = userinit.exe, BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll BHO: Partner BHO Class: {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - C:\ProgramData\Partner\Partner.dll BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: uTorrentControl_v6 Toolbar: {96f454ea-9d38-474f-b504-56193e00c1a5} - C:\Program Files (x86)\uTorrentControl_v6\prxtbuTor.dll BHO: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll TB: uTorrentControl_v6 Toolbar: {96f454ea-9d38-474f-b504-56193e00c1a5} - C:\Program Files (x86)\uTorrentControl_v6\prxtbuTor.dll TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" uRun: [Akamai NetSession Interface] "C:\Users\Jason\AppData\Local\Akamai\netsession_win.exe" uRun: [SearchProtect] C:\Users\Jason\AppData\Roaming\SearchProtect\bin\cltmng.exe mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun mRun: [THX Audio Control Panel] "C:\Program Files (x86)\Creative\THX TruStudio PC\THXAudioCP\THXAudio.exe" /r mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" mRun: [00PCTFW] "C:\Program Files (x86)\PC Tools Firewall Plus\FirewallGUI.exe" -s mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mRun: [vProt] "C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe" mRun: [SearchProtectAll] C:\Program Files (x86)\SearchProtect\bin\cltmng.exe mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" uPolicies-Explorer: NoDriveTypeAutoRun = dword:145 mPolicies-Explorer: NoActiveDesktop = dword:1 mPolicies-Explorer: NoActiveDesktopChanges = dword:1 mPolicies-System: ConsentPromptBehaviorAdmin = dword:0 mPolicies-System: ConsentPromptBehaviorUser = dword:3 mPolicies-System: EnableLUA = dword:0 mPolicies-System: EnableUIADesktopToggle = dword:0 mPolicies-System: PromptOnSecureDesktop = dword:0 mPolicies-Explorer: NoDriveTypeAutoRun = dword:145 IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} TCP: NameServer = 10.0.1.1 TCP: Interfaces\{7649F34A-F143-4238-925F-4136BE11F2E9} : DHCPNameServer = 10.0.1.1 TCP: Interfaces\{91CB4F3E-B6D6-47CE-8F7B-8A3551D63FD1} : DHCPNameServer = 10.0.1.1 TCP: Interfaces\{91CB4F3E-B6D6-47CE-8F7B-8A3551D63FD1}\2375942554431353 : DHCPNameServer = 192.168.1.254 Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\14.0.1\ViProtocol.dll SSODL: WebCheck - mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.71\Installer\chrmstp.exe" –configure-user-settings –verbose-logging –system-level –multi-install –chrome x64-BHO: Partner BHO Class: {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - C:\ProgramData\Partner\Partner64.dll x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll x64-Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s x64-Run: [RunDLLEntry_THXCfg] C:\Windows\System32\RunDLL32.exe C:\Windows\System32\THXCfg64.dll,RunDLLEntry THXCfg64 x64-Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice x64-Run: [LifeChat] "C:\Program Files\Microsoft LifeChat\LifeChat.exe" x64-Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" x64-Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - x64-SSODL: WebCheck - . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\Jason\AppData\Roaming\Mozilla\Firefox\Profiles\9twe287k.default\ FF - prefs.js: browser.startup.homepage - about:home FF - prefs.js: network.proxy.type - 0 FF - plugin: C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL FF - plugin: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll FF - plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\14.0.1\npsitesafety.dll FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrlui.dll FF - plugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll FF - plugin: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll FF - plugin: C:\Windows\SysWOW64\npdeployJava1.dll FF - plugin: C:\Windows\SysWOW64\npmproxy.dll FF - ExtSQL: 2013-06-09 00:46; {96f454ea-9d38-474f-b504-56193e00c1a5}; C:\Users\Jason\AppData\Roaming\Mozilla\Firefox\Profiles\9twe287k.default\extensions\{96f454ea-9d38-474f-b504-56193e00c1a5} . ============= SERVICES / DRIVERS =============== . R1 avgtp;avgtp;C:\Windows\System32\drivers\avgtpx64.sys [2013-6-5 37720] R1 pctgntdi;pctgntdi;C:\Windows\System32\drivers\pctgntdi64.sys [2011-9-25 334976] R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2010-3-30 202752] R2 CltMngSvc;Search Protect by Conduit Updater;C:\Program Files (x86)\SearchProtect\bin\CltMngSvc.exe [2013-5-7 97056] R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2012-1-4 822624] R2 ekrn;ESET Service;C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2009-9-11 735960] R2 epfwwfpr;epfwwfpr;C:\Windows\System32\drivers\epfwwfpr.sys [2009-9-11 123200] R2 PCToolsFirewallPlus;PC Tools Firewall Plus;C:\Program Files (x86)\PC Tools Firewall Plus\FWService.exe [2011-9-25 286000] R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-1 508776] R2 USBS3S4Detection;USBS3S4Detection;C:\OEM\USBDECTION\USBS3S4Detection.exe [2009-12-13 76320] R2 vToolbarUpdater14.0.1;vToolbarUpdater14.0.1;C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\14.0.1\ToolbarUpdater.exe [2013-6-5 945480] R2 XMouseButton Launcher;XMouseButton Launcher;C:\Program Files\Highresolution Enterprises\X-Mouse Button Control\XMouseButtonSvc.exe [2012-6-23 87040] R3 Linksys_adapter_H;Linksys Adapter Network Driver;C:\Windows\System32\drivers\AE2500w764.sys [2011-7-16 1254464] R3 mbamchameleon;mbamchameleon;C:\Windows\System32\drivers\mbamchameleon.sys [2013-7-12 36680] R3 mbamswissarmy;mbamswissarmy;C:\Windows\System32\drivers\mbamswissarmy.sys [2013-7-12 162008] R3 MBfilt;MBfilt;C:\Windows\System32\drivers\MBfilt64.sys [2010-9-21 32344] R3 PCTFW-PacketFilter;PCTools Firewall - Packet filter driver;C:\Windows\System32\drivers\pctNdis-PacketFilter64.sys [2011-9-25 119688] R3 pctNdisMP;PC Tools Driver;C:\Windows\System32\drivers\pctNdis64.sys [2011-9-25 79000] R3 pctplfw;pctplfw;C:\Windows\System32\drivers\pctplfw64.sys [2011-9-25 179976] R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2010-7-27 346144] R3 Sftfs;Sftfs;C:\Windows\System32\drivers\Sftfslh.sys [2011-10-1 764264] R3 Sftplay;Sftplay;C:\Windows\System32\drivers\Sftplaylh.sys [2011-10-1 268648] R3 Sftredir;Sftredir;C:\Windows\System32\drivers\Sftredirlh.sys [2011-10-1 25960] R3 Sftvol;Sftvol;C:\Windows\System32\drivers\Sftvollh.sys [2011-10-1 22376] R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-1 219496] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S3 Andbus;LGE Android Platform Composite USB Device;C:\Windows\System32\drivers\lgandbus64.sys [2010-8-2 19456] S3 AndDiag;LGE Android Platform USB Serial Port;C:\Windows\System32\drivers\lganddiag64.sys [2010-8-2 27648] S3 AndGps;LGE Android Platform USB GPS NMEA Port;C:\Windows\System32\drivers\lgandgps64.sys [2010-8-2 27136] S3 ANDModem;LGE Android Platform USB Modem;C:\Windows\System32\drivers\lgandmodem64.sys [2010-8-2 33792] S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2010-9-21 79360] S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2010-9-21 79360] S3 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys [2010-12-30 48488] S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-9-23 1493352] S3 pctNdis;PC Tools Firewall Intermediate Filter Service;C:\Windows\System32\drivers\pctNdis64.sys [2011-9-25 79000] S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-7-1 59392] S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-9-28 53760] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-12-14 1255736] S3 WDC_SAM;WD SCSI Pass Thru driver;C:\Windows\System32\drivers\wdcsam64.sys [2008-5-6 14464] S3 WUSB54GSCv2.NTamd64;Compact Wireless-G USB Network Adapter with SpeedBooster Service;C:\Windows\System32\drivers\WUSB54GSCV2_AMD64.sys [2010-12-13 253944] S4 Partner Service;Partner Service;C:\ProgramData\Partner\Partner.exe [2010-7-27 332272] S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184] . =============== Created Last 30 ================ . 2013-07-12 18:40:46 ——– d—–w- C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2013-07-12 18:40:45 162008 —-a-w- C:\Windows\System32\drivers\mbamswissarmy.sys 2013-07-12 18:39:59 36680 —-a-w- C:\Windows\System32\drivers\mbamchameleon.sys 2013-07-11 09:29:54 1011712 —-a-w- C:\Program Files\Windows Defender\MpSvc.dll 2013-07-11 09:29:53 9216 —-a-w- C:\Program Files (x86)\Windows Defender\MpAsDesc.dll 2013-07-11 09:29:53 571904 —-a-w- C:\Program Files\Windows Defender\MpClient.dll 2013-07-11 09:29:53 54784 —-a-w- C:\Program Files (x86)\Windows Defender\MpOAV.dll 2013-07-11 09:29:53 4608 —-a-w- C:\Program Files (x86)\Windows Defender\MsMpLics.dll 2013-07-11 09:29:53 392704 —-a-w- C:\Program Files (x86)\Windows Defender\MpClient.dll 2013-07-11 09:29:53 314880 —-a-w- C:\Program Files\Windows Defender\MpCommu.dll 2013-07-11 09:24:54 624128 —-a-w- C:\Windows\System32\qedit.dll 2013-07-11 09:24:54 509440 —-a-w- C:\Windows\SysWow64\qedit.dll 2013-07-11 09:24:54 1887744 —-a-w- C:\Windows\System32\WMVDECOD.DLL 2013-07-11 09:24:54 1620480 —-a-w- C:\Windows\SysWow64\WMVDECOD.DLL 2013-07-11 09:24:43 3153920 —-a-w- C:\Windows\System32\win32k.sys 2013-07-11 09:24:42 936448 —-a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\ink\journal.dll 2013-07-11 09:24:42 1732608 —-a-w- C:\Program Files\Windows Journal\NBDoc.DLL 2013-07-11 09:24:42 1402880 —-a-w- C:\Program Files\Windows Journal\JNWDRV.dll 2013-07-11 09:24:42 1393152 —-a-w- C:\Program Files\Windows Journal\JNTFiltr.dll 2013-07-11 09:24:42 1367040 —-a-w- C:\Program Files\Common Files\Microsoft Shared\ink\journal.dll 2013-07-11 09:19:41 1643520 —-a-w- C:\Windows\System32\DWrite.dll 2013-07-11 09:19:41 1247744 —-a-w- C:\Windows\SysWow64\DWrite.dll 2013-07-11 02:59:08 ——– d—–w- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-07-11 02:59:08 ——– d—–w- C:\Program Files\iTunes 2013-07-11 02:59:08 ——– d—–w- C:\Program Files\iPod 2013-07-11 02:59:08 ——– d—–w- C:\Program Files (x86)\iTunes 2013-07-11 02:55:29 159744 —-a-w- C:\Program Files\Internet Explorer\Plugins\npqtplugin5.dll 2013-07-11 02:55:29 159744 —-a-w- C:\Program Files\Internet Explorer\Plugins\npqtplugin4.dll 2013-07-11 02:55:29 159744 —-a-w- C:\Program Files\Internet Explorer\Plugins\npqtplugin3.dll 2013-07-11 02:55:29 159744 —-a-w- C:\Program Files\Internet Explorer\Plugins\npqtplugin2.dll 2013-07-11 02:55:29 159744 —-a-w- C:\Program Files\Internet Explorer\Plugins\npqtplugin.dll 2013-07-11 02:55:29 159744 —-a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll 2013-07-11 02:55:29 159744 —-a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll 2013-07-11 02:55:29 159744 —-a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll 2013-07-11 02:55:29 159744 —-a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll 2013-07-11 02:55:29 159744 —-a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll 2013-07-04 02:05:07 0 —-a-w- C:\Windows\SysWow64\shoE8B3.tmp 2013-07-03 06:02:55 74136 —-a-w- C:\Program Files (x86)\Mozilla Firefox\breakpadinjector.dll 2013-07-03 06:02:55 263576 —-a-w- C:\Program Files (x86)\Mozilla Firefox\browser\components\browsercomps.dll 2013-07-03 06:02:55 2106216 —-a-w- C:\Program Files (x86)\Mozilla Firefox\D3DCompiler_43.dll 2013-07-03 06:02:55 116120 —-a-w- C:\Program Files (x86)\Mozilla Firefox\crashreporter.exe 2013-07-03 06:02:54 19352 —-a-w- C:\Program Files (x86)\Mozilla Firefox\AccessibleMarshal.dll 2013-06-19 03:31:21 96168 —-a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll 2013-06-15 07:27:51 ——– d—–w- C:\Users\Jason\AppData\Local\AVG Secure Search . ==================== Find3M ==================== . 2013-06-13 04:48:23 867240 —-a-w- C:\Windows\SysWow64\npdeployJava1.dll 2013-06-13 04:48:17 789416 —-a-w- C:\Windows\SysWow64\deployJava1.dll 2013-06-11 23:43:37 1767936 —-a-w- C:\Windows\SysWow64\wininet.dll 2013-06-11 23:43:00 2877440 —-a-w- C:\Windows\SysWow64\jscript9.dll 2013-06-11 23:42:58 61440 —-a-w- C:\Windows\SysWow64\iesetup.dll 2013-06-11 23:42:58 109056 —-a-w- C:\Windows\SysWow64\iesysprep.dll 2013-06-11 23:26:20 2241024 —-a-w- C:\Windows\System32\wininet.dll 2013-06-11 23:25:16 3958784 —-a-w- C:\Windows\System32\jscript9.dll 2013-06-11 23:25:13 67072 —-a-w- C:\Windows\System32\iesetup.dll 2013-06-11 23:25:13 136704 —-a-w- C:\Windows\System32\iesysprep.dll 2013-06-11 22:51:45 71680 —-a-w- C:\Windows\SysWow64\RegisterIEPKEYs.exe 2013-06-11 22:50:58 89600 —-a-w- C:\Windows\System32\RegisterIEPKEYs.exe 2013-06-11 18:19:15 71048 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2013-06-11 18:19:15 692104 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe 2013-06-11 18:19:09 9089416 —-a-w- C:\Windows\SysWow64\FlashPlayerInstaller.exe 2013-06-07 03:22:18 2706432 —-a-w- C:\Windows\System32\mshtml.tlb 2013-06-07 02:37:52 2706432 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2013-06-06 06:29:07 37720 —-a-w- C:\Windows\System32\drivers\avgtpx64.sys 2013-05-13 05:51:01 184320 —-a-w- C:\Windows\System32\cryptsvc.dll 2013-05-13 05:51:00 1464320 —-a-w- C:\Windows\System32\crypt32.dll 2013-05-13 05:51:00 139776 —-a-w- C:\Windows\System32\cryptnet.dll 2013-05-13 05:50:40 52224 —-a-w- C:\Windows\System32\certenc.dll 2013-05-13 04:45:55 140288 —-a-w- C:\Windows\SysWow64\cryptsvc.dll 2013-05-13 04:45:55 1160192 —-a-w- C:\Windows\SysWow64\crypt32.dll 2013-05-13 04:45:55 103936 —-a-w- C:\Windows\SysWow64\cryptnet.dll 2013-05-13 03:43:55 1192448 —-a-w- C:\Windows\System32\certutil.exe 2013-05-13 03:08:10 903168 —-a-w- C:\Windows\SysWow64\certutil.exe 2013-05-13 03:08:06 43008 —-a-w- C:\Windows\SysWow64\certenc.dll 2013-05-10 05:49:27 30720 —-a-w- C:\Windows\System32\cryptdlg.dll 2013-05-10 03:20:54 24576 —-a-w- C:\Windows\SysWow64\cryptdlg.dll 2013-05-08 06:39:01 1910632 —-a-w- C:\Windows\System32\drivers\tcpip.sys 2013-05-08 06:10:12 770384 —-a-w- C:\Windows\SysWow64\msvcr100.dll 2013-05-08 06:10:12 421200 —-a-w- C:\Windows\SysWow64\msvcp100.dll 2013-05-01 10:59:12 94208 —-a-w- C:\Windows\SysWow64\QuickTimeVR.qtx 2013-05-01 10:59:12 69632 —-a-w- C:\Windows\SysWow64\QuickTime.qts 2013-04-26 05:51:36 751104 —-a-w- C:\Windows\System32\win32spl.dll 2013-04-26 04:55:21 492544 —-a-w- C:\Windows\SysWow64\win32spl.dll 2013-04-25 23:30:32 1505280 —-a-w- C:\Windows\SysWow64\d3d11.dll 2013-04-17 07:02:06 1230336 —-a-w- C:\Windows\SysWow64\WindowsCodecs.dll 2013-04-17 06:24:46 1424384 —-a-w- C:\Windows\System32\WindowsCodecs.dll 2004-01-29 23:40:00 3202560 —-a-w- C:\Program Files\dogwaffle.exe 2004-01-07 19:00:34 12800 —-a-w- C:\Program Files\Grid_pm.exe 2004-01-03 20:28:32 8192 —-a-w- C:\Program Files\ExploreTempDir_pm.exe 2003-12-20 22:49:38 10240 —-a-w- C:\Program Files\Sepia_pf.exe 2003-11-29 23:47:34 52224 —-a-w- C:\Program Files\Store_Alpha_pm.exe 2003-11-25 21:25:50 39424 —-a-w- C:\Program Files\Zoom_pf.exe 2003-11-13 21:15:44 11776 —-a-w- C:\Program Files\Key_Shrink_pb.exe 2003-11-13 20:48:06 12288 —-a-w- C:\Program Files\Key_Grow_pb.exe 2003-06-06 04:01:02 231424 —-a-w- C:\Program Files\VBTablet.dll 2002-12-29 22:29:56 9216 —-a-w- C:\Program Files\ChangeDPI_px.exe 2002-11-10 22:13:32 12288 —-a-w- C:\Program Files\Clipboard_Import_pb.exe 2002-11-03 20:33:44 14848 —-a-w- C:\Program Files\Paint_on_alpha_pm.exe 2002-11-03 20:24:32 9216 —-a-w- C:\Program Files\printerPrefs_generic_px.exe 2002-11-01 22:13:20 8704 —-a-w- C:\Program Files\KeyToLuminance_pb.exe 2002-11-01 22:11:34 8192 —-a-w- C:\Program Files\KeyInvert_pb.exe 2002-11-01 22:10:34 8704 —-a-w- C:\Program Files\KeyToBlack_pb.exe 2002-09-23 18:29:08 22528 —-a-w- C:\Program Files\MotionBlur_pf.exe 2002-09-20 11:40:00 22016 —-a-w- C:\Program Files\print_generic_px.exe 2002-09-20 11:11:34 9216 —-a-w- C:\Program Files\ScaleAlpha_pm.exe 2002-09-05 11:01:34 15360 —-a-w- C:\Program Files\Store_Brush_pb.exe 2002-09-05 09:44:46 28160 —-a-w- C:\Program Files\Store_Buffer_pm.exe 2002-09-03 11:27:02 11776 —-a-w- C:\Program Files\Clipboard_Export_pb.exe 2002-02-09 15:53:04 11264 —-a-w- C:\Program Files\AverageFrames_pm.exe 2002-02-08 19:06:36 11264 —-a-w- C:\Program Files\FrameFromClipboard_pm.exe 2002-01-25 21:36:44 9728 —-a-w- C:\Program Files\cellular_pf.exe 2002-01-25 02:25:20 10752 —-a-w- C:\Program Files\Mysticvision_pf.exe 2002-01-25 02:20:50 9728 —-a-w- C:\Program Files\Minimize_pf.exe 2002-01-25 02:19:34 10240 —-a-w- C:\Program Files\Maximize_pf.exe 2002-01-23 01:18:58 10240 —-a-w- C:\Program Files\Crystalize_pf.exe 2002-01-21 12:37:30 11264 —-a-w- C:\Program Files\iff_px.exe 2002-01-21 11:42:24 12288 —-a-w- C:\Program Files\Median_pf.exe 2001-06-11 09:54:32 10240 —-a-w- C:\Program Files\OptimizedPaletteTest_pf.exe 2001-06-11 09:45:40 11776 —-a-w- C:\Program Files\12_bit_dither_pf.exe 2001-06-09 14:18:04 10240 —-a-w- C:\Program Files\PaletteToWells_pm.exe 2001-06-06 19:06:16 11264 —-a-w- C:\Program Files\OptimizedPalette_pf.exe 2001-05-27 23:33:46 9728 —-a-w- C:\Program Files\Gradient_To_VB_pm.exe 2001-04-08 18:33:34 11776 —-a-w- C:\Program Files\Globe_pf.exe 2001-03-11 22:58:22 9216 —-a-w- C:\Program Files\Alpha_Grow_pm.exe 2001-03-11 22:54:12 9216 —-a-w- C:\Program Files\Alpha_Shrink_pm.exe 2000-11-19 23:02:22 10752 —-a-w- C:\Program Files\Mirrage_pf.exe 2000-11-19 22:55:44 12288 —-a-w- C:\Program Files\MaxMin_pf.exe 2000-11-19 22:54:46 10752 —-a-w- C:\Program Files\Mosaic_pf.exe 2000-11-19 22:35:12 15360 —-a-w- C:\Program Files\MinMax_pf.exe 2000-11-05 16:54:34 10752 —-a-w- C:\Program Files\bmp_save_pb.exe 2000-11-05 07:05:58 12800 —-a-w- C:\Program Files\bmp_load_pb.exe 1998-06-24 07:00:00 203576 —-a-w- C:\Program Files\RICHTX32.OCX . ============= FINISH: 12:05:07.52 =============== Report 2: . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2012-11-20.01) . Microsoft Windows 7 Home Premium Boot Device: \Device\HarddiskVolume2 Install Date: 12/13/2010 4:07:28 PM System Uptime: 7/11/2013 9:49:30 PM (15 hours ago) . Motherboard: Gateway | | FX6840 Processor: Intel® Core™ i7 CPU 870 @ 2.93GHz | CPU 1 | 2934/133mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 715 GiB total, 545.456 GiB free. D: is CDROM () E: is Removable F: is Removable G: is Removable H: is Removable I: is Removable J: is FIXED (NTFS) - 195 GiB total, 169.395 GiB free. . ==== Disabled Device Manager Items ============= . Class GUID: {36fc9e60-c465-11cf-8056-444553540000} Description: USB Mass Storage Device Device ID: USB\VID_1949&PID_0004\B0231701243405J5 Manufacturer: Compatible USB storage device Name: USB Mass Storage Device PNP Device ID: USB\VID_1949&PID_0004\B0231701243405J5 Service: USBSTOR . Class GUID: {36fc9e60-c465-11cf-8056-444553540000} Description: USB Mass Storage Device Device ID: USB\VID_1058&PID_0748\575837314137325537333233 Manufacturer: Compatible USB storage device Name: USB Mass Storage Device PNP Device ID: USB\VID_1058&PID_0748\575837314137325537333233 Service: USBSTOR . Class GUID: {4d36e96f-e325-11ce-bfc1-08002be10318} Description: Microsoft PS/2 Mouse Device ID: ACPI\PNP0F03\4&DAE4155&0 Manufacturer: Microsoft Name: Microsoft PS/2 Mouse PNP Device ID: ACPI\PNP0F03\4&DAE4155&0 Service: i8042prt . ==== System Restore Points =================== . RP210: 7/10/2013 4:55:39 AM - Scheduled Checkpoint RP211: 7/11/2013 3:00:23 AM - Windows Update . ==== Installed Programs ====================== . Update for Microsoft Office 2007 (KB2508958) µTorrent 7-Zip 9.20 A Game of Thrones version 0.4.6 Acrobat.com Adobe Community Help Adobe Digital Editions Adobe Flash Player 11 Plugin Adobe Reader 9.5.5 MUI Advertising Center AirPort Akamai NetSession Interface AMD DnD V1.0.20 Apple Application Support Apple Mobile Device Support Apple Software Update ATI AVIVO64 Codecs ATI Catalyst Install Manager Auto Clicker by Shocker Bandisoft MPEG-1 Decoder Best Buy pc app Bonjour calibre Catalyst Control Center - Branding Catalyst Control Center Core Implementation Catalyst Control Center Graphics Full Existing Catalyst Control Center Graphics Full New Catalyst Control Center Graphics Light Catalyst Control Center Graphics Previews Vista Catalyst Control Center InstallProxy Catalyst Control Center Localization All ccc-core-static ccc-utility64 CCC Help Chinese Standard CCC Help Chinese Traditional CCC Help Czech CCC Help Danish CCC Help Dutch CCC Help English CCC Help Finnish CCC Help French CCC Help German CCC Help Greek CCC Help Hungarian CCC Help Italian CCC Help Japanese CCC Help Korean CCC Help Norwegian CCC Help Polish CCC Help Portuguese CCC Help Russian CCC Help Spanish CCC Help Swedish CCC Help Thai CCC Help Turkish CCleaner Crusader Kings II CyberLink PowerDVD 9 D3DX10 Diablo III DomDomSoft Manga Downloader (remove only) ESET NOD32 Antivirus Explorer Suite III Gateway InfoCentre Gateway Recovery Management Gateway ScreenSaver GIMP 2.8.0 Google Chrome Google Toolbar for Internet Explorer Google Update Helper Hotkey Utility Identity Card ImagXpress Intel® Matrix Storage Manager iTunes Java 7 Update 25 Java Auto Updater Junk Mail filter update K-Lite Codec Pack 6.6.0 (Full) League of Legends LG United Mobile Drivers Malwarebytes Anti-Malware version 1.75.0.1300 Mass Effect Mass Effect 2 Mesh Runtime Messenger Companion Microsoft .NET Framework 4 Client Profile Microsoft Application Error Reporting Microsoft Choice Guard Microsoft LifeChat Microsoft Office 2007 Service Pack 3 (SP3) Microsoft Office 2010 Microsoft Office Click-to-Run 2010 Microsoft Office Excel MUI (English) 2007 Microsoft Office File Validation Add-In Microsoft Office Home and Student 2007 Microsoft Office Office 64-bit Components 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) Microsoft Office Shared 64-bit MUI (English) 2007 Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Starter 2010 - English Microsoft Office Word MUI (English) 2007 Microsoft Silverlight Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 Microsoft_VC80_ATL_x86 Microsoft_VC80_CRT_x86 Microsoft_VC80_MFC_x86 Microsoft_VC80_MFCLOC_x86 Microsoft_VC90_ATL_x86 Microsoft_VC90_CRT_x86 Microsoft_VC90_MFC_x86 More Crusader Kings II Depots Mozilla Firefox 22.0 (x86 en-US) Mozilla Maintenance Service MSVCRT MSVCRT_amd64 MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) Nero 9 Essentials Nero ControlCenter Nero DiscSpeed Nero DiscSpeed Help Nero DriveSpeed Nero DriveSpeed Help Nero Express Help Nero InfoTool Nero InfoTool Help Nero Installer Nero Online Upgrade Nero StartSmart Nero StartSmart Help Nero StartSmart OEM NeroExpress neroxml Nexon Game Manager Notepad++ NVIDIA PhysX Pando Media Booster Path of Exile PC Tools Firewall Plus 7.0 project dogwaffle QuickTime Real Alternative 1.9.0 Realtek Ethernet Controller Driver For Windows 7 Realtek High Definition Audio Driver Search Protect by conduit Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841) Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708) Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121) Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405) Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827) Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449) Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019) Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595) Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642) Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576) Security Update for Microsoft .NET Framework 4 Client Profile (KB2835393) Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628) Security Update for Microsoft Office 2007 suites (KB2596615) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2687309) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2687311) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2687499) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2760416) 32-Bit Edition Security Update for Microsoft Office Excel 2007 (KB2687307) 32-Bit Edition Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition Security Update for Microsoft Office Word 2007 (KB2760421) 32-Bit Edition Sid Meier's Civilization V StarCraft II Steam THX TruStudio PC Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2473228) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) Update for Microsoft Office 2007 Help for Common Features (KB963673) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition Update for Microsoft Office Excel 2007 Help (KB963678) Update for Microsoft Office OneNote 2007 Help (KB963670) Update for Microsoft Office Powerpoint 2007 Help (KB963669) Update for Microsoft Office Script Editor Help (KB963671) Update for Microsoft Office Word 2007 Help (KB963665) uTorrentControl_v6 Toolbar Vindictus Visual C++ 2008 Runtime (x64) Wilbur 1.80 (32-bit) Windows Live Communications Platform Windows Live Essentials Windows Live Family Safety Windows Live ID Sign-in Assistant Windows Live Installer Windows Live Language Selector Windows Live Mail Windows Live Mesh Windows Live Mesh ActiveX Control for Remote Connections Windows Live Messenger Windows Live Messenger Companion Core Windows Live MIME IFilter Windows Live Movie Maker Windows Live Photo Common Windows Live Photo Gallery Windows Live PIMT Platform Windows Live Remote Client Windows Live Remote Client Resources Windows Live Remote Service Windows Live Remote Service Resources Windows Live SOXE Windows Live SOXE Definitions Windows Live Sync Windows Live Upload Tool Windows Live UX Platform Windows Live UX Platform Language Pack Windows Live Writer Windows Live Writer Resources WinRAR 4.20 (32-bit) X-Mouse Button Control 2.5 . ==== Event Viewer Messages From Past Week ======== . 7/9/2013 2:19:23 AM, Error: volsnap [36] - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit. 7/5/2013 9:59:33 AM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000000a (0x0000000000000000, 0x0000000000000002, 0x0000000000000000, 0xfffff80002e95e42). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 070513-21325-01. 7/10/2013 7:58:15 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Apple Mobile Device service, but this action failed with the following error: An instance of the service is already running. 7/10/2013 7:57:15 PM, Error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 7/10/2013 7:57:01 PM, Error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. . ==== End Of File ===========================
Please read and follow these instructions carefully. We do not want it to fix anything yet (if found), we need to see a report first.

Download TDSSKiller.exe and save it to your desktop
  • Execute TDSSKiller.exe by doubleclicking on it.
  • Press Start Scan
  • If Malicious objects are found, do NOT select Cure. Change the action to Skip, and save the log.
  • Once complete, a log will be produced at the root drive which is typically C:\ ,for example, C:\TDSSKiller.log.txt

Please post the contents of that log in your next reply.
Sorry for the late response. Internet went down all night.

I just scanned it, but I ouldn't find anything again. On another note, the warnings stopped for some reason. See image for detail.

Is it possible for a virus to hide in one of my external HDD? Otherwise, I'm stumped.

http://postimg.org/image/uvz48ls0j/
Combofix

Combofix should only be run when adviced by a team member!

Link


Important - Save the file to your desktop!


  • Deactivate any and all of your antivirus programs /spyware scanners - they can prevent CF from doing its work.
  • Run Combofix.exe

When finished, Combofix creates a log file named C:\Combofix.txt. Please post its content in your next reply.

Note: When receiving an error message containing ""Illegal operation attempted on a registry key that has been marked for deletion" simply restart your computer to fix this.
Alright, I turned off my firewall and disabled most (if not all) of my NOD32 protection. Here is the log: ComboFix 13-07-15.01 - Jason 07/16/2013 3:05.1.8 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.8183.6135 [GMT -7:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: ESET NOD32 Antivirus 4.0 *Disabled/Outdated* {CB0F8167-5331-BA19-698E-64816B6801A5} FW: PC Tools Firewall Plus *Disabled* {175D0B73-9F8F-2CA9-8BF1-62277A276DC9} SP: ESET NOD32 Antivirus 4.0 *Disabled/Outdated* {706E6083-750B-B597-533E-5FF310EF4B18} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\windows\SysWow64\Packet.dll c:\windows\SysWow64\pthreadVC.dll c:\windows\SysWow64\WanPacket.dll c:\windows\SysWow64\wpcap.dll . . ((((((((((((((((((((((((( Files Created from 2013-06-16 to 2013-07-16 ))))))))))))))))))))))))))))))) . . 2013-07-16 10:17 . 2013-07-16 10:17 ——– d—–w- c:\windows\system32\config\systemprofile\AppData\Local\temp 2013-07-16 10:17 . 2013-07-16 10:17 ——– d—–w- c:\users\Default\AppData\Local\temp 2013-07-13 10:00 . 2013-07-13 10:01 ——– d—–w- c:\windows\system32\MRT 2013-07-12 18:40 . 2013-07-12 19:16 ——– d—–w- c:\programdata\Malwarebytes' Anti-Malware (portable) 2013-07-11 09:29 . 2013-05-27 05:50 1011712 —-a-w- c:\program files\Windows Defender\MpSvc.dll 2013-07-11 09:29 . 2013-05-27 05:50 571904 —-a-w- c:\program files\Windows Defender\MpClient.dll 2013-07-11 09:29 . 2013-05-27 05:50 314880 —-a-w- c:\program files\Windows Defender\MpCommu.dll 2013-07-11 09:29 . 2013-05-27 04:57 4608 —-a-w- c:\program files (x86)\Windows Defender\MsMpLics.dll 2013-07-11 09:29 . 2013-05-27 04:57 54784 —-a-w- c:\program files (x86)\Windows Defender\MpOAV.dll 2013-07-11 09:29 . 2013-05-27 04:57 392704 —-a-w- c:\program files (x86)\Windows Defender\MpClient.dll 2013-07-11 09:29 . 2013-05-27 03:15 9216 —-a-w- c:\program files (x86)\Windows Defender\MpAsDesc.dll 2013-07-11 09:24 . 2013-06-04 06:00 624128 —-a-w- c:\windows\system32\qedit.dll 2013-07-11 09:24 . 2013-06-04 04:53 509440 —-a-w- c:\windows\SysWow64\qedit.dll 2013-07-11 09:24 . 2013-05-06 06:03 1887744 —-a-w- c:\windows\system32\WMVDECOD.DLL 2013-07-11 09:24 . 2013-05-06 04:56 1620480 —-a-w- c:\windows\SysWow64\WMVDECOD.DLL 2013-07-11 09:24 . 2013-06-05 03:34 3153920 —-a-w- c:\windows\system32\win32k.sys 2013-07-11 09:24 . 2013-04-10 05:48 1732608 —-a-w- c:\program files\Windows Journal\NBDoc.DLL 2013-07-11 09:24 . 2013-04-10 05:46 1402880 —-a-w- c:\program files\Windows Journal\JNWDRV.dll 2013-07-11 09:24 . 2013-04-10 05:46 1393152 —-a-w- c:\program files\Windows Journal\JNTFiltr.dll 2013-07-11 09:24 . 2013-04-10 05:46 1367040 —-a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll 2013-07-11 09:24 . 2013-04-10 05:03 936448 —-a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll 2013-07-11 09:19 . 2013-04-09 23:34 1247744 —-a-w- c:\windows\SysWow64\DWrite.dll 2013-07-11 09:19 . 2013-04-02 22:51 1643520 —-a-w- c:\windows\system32\DWrite.dll 2013-07-11 02:59 . 2013-07-11 02:59 ——– d—–w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-07-11 02:59 . 2013-07-11 02:59 ——– d—–w- c:\program files\iTunes 2013-07-11 02:59 . 2013-07-11 02:59 ——– d—–w- c:\program files (x86)\iTunes 2013-07-11 02:59 . 2013-07-11 02:59 ——– d—–w- c:\program files\iPod 2013-07-11 02:55 . 2013-07-11 02:55 159744 —-a-w- c:\program files\Internet Explorer\Plugins\npqtplugin5.dll 2013-07-11 02:55 . 2013-07-11 02:55 159744 —-a-w- c:\program files\Internet Explorer\Plugins\npqtplugin4.dll 2013-07-11 02:55 . 2013-07-11 02:55 159744 —-a-w- c:\program files\Internet Explorer\Plugins\npqtplugin3.dll 2013-07-11 02:55 . 2013-07-11 02:55 159744 —-a-w- c:\program files\Internet Explorer\Plugins\npqtplugin2.dll 2013-07-11 02:55 . 2013-07-11 02:55 159744 —-a-w- c:\program files\Internet Explorer\Plugins\npqtplugin.dll 2013-07-11 02:55 . 2013-07-11 02:55 ——– d—–w- c:\program files (x86)\QuickTime 2013-07-04 02:05 . 2013-07-04 02:05 0 —-a-w- c:\windows\SysWow64\shoE8B3.tmp 2013-06-19 03:31 . 2013-06-13 04:47 96168 —-a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-06-24 07:57 . 2010-12-14 18:44 78277128 —-a-w- c:\windows\system32\MRT.exe 2013-06-13 04:48 . 2012-08-07 06:35 867240 —-a-w- c:\windows\SysWow64\npdeployJava1.dll 2013-06-13 04:48 . 2011-03-28 09:10 789416 —-a-w- c:\windows\SysWow64\deployJava1.dll 2013-06-11 18:19 . 2012-11-13 21:18 71048 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-06-11 18:19 . 2012-11-13 21:18 692104 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-06-11 18:19 . 2013-06-11 18:19 9089416 —-a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe 2013-06-06 06:29 . 2013-06-06 06:29 37720 —-a-w- c:\windows\system32\drivers\avgtpx64.sys 2013-05-21 07:30 . 2010-06-24 19:33 22240 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2013-05-13 05:51 . 2013-06-12 10:04 184320 —-a-w- c:\windows\system32\cryptsvc.dll 2013-05-13 05:51 . 2013-06-12 10:04 1464320 —-a-w- c:\windows\system32\crypt32.dll 2013-05-13 05:51 . 2013-06-12 10:04 139776 —-a-w- c:\windows\system32\cryptnet.dll 2013-05-13 05:50 . 2013-06-12 10:04 52224 —-a-w- c:\windows\system32\certenc.dll 2013-05-13 04:45 . 2013-06-12 10:04 140288 —-a-w- c:\windows\SysWow64\cryptsvc.dll 2013-05-13 04:45 . 2013-06-12 10:04 1160192 —-a-w- c:\windows\SysWow64\crypt32.dll 2013-05-13 04:45 . 2013-06-12 10:04 103936 —-a-w- c:\windows\SysWow64\cryptnet.dll 2013-05-13 03:43 . 2013-06-12 10:04 1192448 —-a-w- c:\windows\system32\certutil.exe 2013-05-13 03:08 . 2013-06-12 10:04 903168 —-a-w- c:\windows\SysWow64\certutil.exe 2013-05-13 03:08 . 2013-06-12 10:04 43008 —-a-w- c:\windows\SysWow64\certenc.dll 2013-05-10 05:49 . 2013-06-12 10:05 30720 —-a-w- c:\windows\system32\cryptdlg.dll 2013-05-10 03:20 . 2013-06-12 10:05 24576 —-a-w- c:\windows\SysWow64\cryptdlg.dll 2013-05-08 06:39 . 2013-06-12 10:05 1910632 —-a-w- c:\windows\system32\drivers\tcpip.sys 2013-05-08 06:10 . 2011-01-07 22:39 770384 —-a-w- c:\windows\SysWow64\msvcr100.dll 2013-05-08 06:10 . 2011-01-07 22:39 421200 —-a-w- c:\windows\SysWow64\msvcp100.dll 2013-05-01 10:59 . 2013-05-01 10:59 94208 —-a-w- c:\windows\SysWow64\QuickTimeVR.qtx 2013-05-01 10:59 . 2013-05-01 10:59 69632 —-a-w- c:\windows\SysWow64\QuickTime.qts 2013-04-30 10:02 . 2013-04-30 10:02 905728 —-a-w- c:\windows\system32\mshtmlmedia.dll 2013-04-30 10:02 . 2013-04-30 10:02 81408 —-a-w- c:\windows\system32\icardie.dll 2013-04-30 10:02 . 2013-04-30 10:02 762368 —-a-w- c:\windows\system32\ieapfltr.dll 2013-04-30 10:02 . 2013-04-30 10:02 73728 —-a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2013-04-30 10:02 . 2013-04-30 10:02 719360 —-a-w- c:\windows\SysWow64\mshtmlmedia.dll 2013-04-30 10:02 . 2013-04-30 10:02 61952 —-a-w- c:\windows\SysWow64\tdc.ocx 2013-04-30 10:02 . 2013-04-30 10:02 523264 —-a-w- c:\windows\SysWow64\vbscript.dll 2013-04-30 10:02 . 2013-04-30 10:02 48640 —-a-w- c:\windows\SysWow64\mshtmler.dll 2013-04-30 10:02 . 2013-04-30 10:02 452096 —-a-w- c:\windows\system32\dxtmsft.dll 2013-04-30 10:02 . 2013-04-30 10:02 441856 —-a-w- c:\windows\system32\html.iec 2013-04-30 10:02 . 2013-04-30 10:02 38400 —-a-w- c:\windows\SysWow64\imgutil.dll 2013-04-30 10:02 . 2013-04-30 10:02 361984 —-a-w- c:\windows\SysWow64\html.iec 2013-04-30 10:02 . 2013-04-30 10:02 281600 —-a-w- c:\windows\system32\dxtrans.dll 2013-04-30 10:02 . 2013-04-30 10:02 270848 —-a-w- c:\windows\system32\iedkcs32.dll 2013-04-30 10:02 . 2013-04-30 10:02 235008 —-a-w- c:\windows\system32\url.dll 2013-04-30 10:02 . 2013-04-30 10:02 23040 —-a-w- c:\windows\SysWow64\licmgr10.dll 2013-04-30 10:02 . 2013-04-30 10:02 226304 —-a-w- c:\windows\system32\elshyph.dll 2013-04-30 10:02 . 2013-04-30 10:02 216064 —-a-w- c:\windows\system32\msls31.dll 2013-04-30 10:02 . 2013-04-30 10:02 197120 —-a-w- c:\windows\system32\msrating.dll 2013-04-30 10:02 . 2013-04-30 10:02 185344 —-a-w- c:\windows\SysWow64\elshyph.dll 2013-04-30 10:02 . 2013-04-30 10:02 158720 —-a-w- c:\windows\SysWow64\msls31.dll 2013-04-30 10:02 . 2013-04-30 10:02 150528 —-a-w- c:\windows\SysWow64\iexpress.exe 2013-04-30 10:02 . 2013-04-30 10:02 1441280 —-a-w- c:\windows\SysWow64\inetcpl.cpl 2013-04-30 10:02 . 2013-04-30 10:02 1400416 —-a-w- c:\windows\system32\ieapfltr.dat 2013-04-30 10:02 . 2013-04-30 10:02 138752 —-a-w- c:\windows\SysWow64\wextract.exe 2013-04-30 10:02 . 2013-04-30 10:02 137216 —-a-w- c:\windows\SysWow64\ieUnatt.exe 2013-04-30 10:02 . 2013-04-30 10:02 12800 —-a-w- c:\windows\SysWow64\mshta.exe 2013-04-30 10:02 . 2013-04-30 10:02 110592 —-a-w- c:\windows\SysWow64\IEAdvpack.dll 2013-04-30 10:02 . 2013-04-30 10:02 1054720 —-a-w- c:\windows\system32\MsSpellCheckingFacility.exe 2013-04-30 10:02 . 2013-04-30 10:02 97280 —-a-w- c:\windows\system32\mshtmled.dll 2013-04-30 10:02 . 2013-04-30 10:02 92160 —-a-w- c:\windows\system32\SetIEInstalledDate.exe 2013-04-30 10:02 . 2013-04-30 10:02 77312 —-a-w- c:\windows\system32\tdc.ocx 2013-04-30 10:02 . 2013-04-30 10:02 62976 —-a-w- c:\windows\system32\pngfilt.dll 2013-04-30 10:02 . 2013-04-30 10:02 599552 —-a-w- c:\windows\system32\vbscript.dll 2013-04-30 10:02 . 2013-04-30 10:02 52224 —-a-w- c:\windows\system32\msfeedsbs.dll 2013-04-30 10:02 . 2013-04-30 10:02 51200 —-a-w- c:\windows\system32\imgutil.dll 2013-04-30 10:02 . 2013-04-30 10:02 48640 —-a-w- c:\windows\system32\mshtmler.dll 2013-04-30 10:02 . 2013-04-30 10:02 27648 —-a-w- c:\windows\system32\licmgr10.dll 2013-04-30 10:02 . 2013-04-30 10:02 247296 —-a-w- c:\windows\system32\webcheck.dll 2013-04-30 10:02 . 2013-04-30 10:02 173568 —-a-w- c:\windows\system32\ieUnatt.exe 2013-04-30 10:02 . 2013-04-30 10:02 167424 —-a-w- c:\windows\system32\iexpress.exe 2013-04-30 10:02 . 2013-04-30 10:02 1509376 —-a-w- c:\windows\system32\inetcpl.cpl 2013-04-30 10:02 . 2013-04-30 10:02 149504 —-a-w- c:\windows\system32\occache.dll 2013-04-30 10:02 . 2013-04-30 10:02 144896 —-a-w- c:\windows\system32\wextract.exe 2013-04-30 10:02 . 2013-04-30 10:02 13824 —-a-w- c:\windows\system32\mshta.exe 2013-04-30 10:02 . 2013-04-30 10:02 136192 —-a-w- c:\windows\system32\iepeers.dll 2013-04-30 10:02 . 2013-04-30 10:02 135680 —-a-w- c:\windows\system32\IEAdvpack.dll 2013-04-30 10:02 . 2013-04-30 10:02 12800 —-a-w- c:\windows\system32\msfeedssync.exe 2013-04-30 10:02 . 2013-04-30 10:02 102912 —-a-w- c:\windows\system32\inseng.dll 2013-04-26 05:51 . 2013-06-12 10:05 751104 —-a-w- c:\windows\system32\win32spl.dll 2013-04-26 04:55 . 2013-06-12 10:05 492544 —-a-w- c:\windows\SysWow64\win32spl.dll 2013-04-25 23:30 . 2013-06-12 10:04 1505280 —-a-w- c:\windows\SysWow64\d3d11.dll 2004-01-29 23:40 . 2012-05-19 09:04 3202560 —-a-w- c:\program files\dogwaffle.exe 2004-01-07 19:00 . 2012-05-19 09:04 12800 —-a-w- c:\program files\Grid_pm.exe 2004-01-03 20:28 . 2012-05-19 09:04 8192 —-a-w- c:\program files\ExploreTempDir_pm.exe 2003-12-20 22:49 . 2012-05-19 09:04 10240 —-a-w- c:\program files\Sepia_pf.exe 2003-11-29 23:47 . 2012-05-19 09:04 52224 —-a-w- c:\program files\Store_Alpha_pm.exe 2003-11-25 21:25 . 2012-05-19 09:04 39424 —-a-w- c:\program files\Zoom_pf.exe 2003-11-13 21:15 . 2012-05-19 09:04 11776 —-a-w- c:\program files\Key_Shrink_pb.exe 2003-11-13 20:48 . 2012-05-19 09:04 12288 —-a-w- c:\program files\Key_Grow_pb.exe 2003-06-06 04:01 . 2012-05-19 09:04 231424 —-a-w- c:\program files\VBTablet.dll 2002-12-29 22:29 . 2012-05-19 09:04 9216 —-a-w- c:\program files\ChangeDPI_px.exe 2002-11-10 22:13 . 2012-05-19 09:04 12288 —-a-w- c:\program files\Clipboard_Import_pb.exe 2002-11-03 20:33 . 2012-05-19 09:04 14848 —-a-w- c:\program files\Paint_on_alpha_pm.exe 2002-11-03 20:24 . 2012-05-19 09:04 9216 —-a-w- c:\program files\printerPrefs_generic_px.exe 2002-11-01 22:13 . 2012-05-19 09:04 8704 —-a-w- c:\program files\KeyToLuminance_pb.exe 2002-11-01 22:11 . 2012-05-19 09:04 8192 —-a-w- c:\program files\KeyInvert_pb.exe 2002-11-01 22:10 . 2012-05-19 09:04 8704 —-a-w- c:\program files\KeyToBlack_pb.exe 2002-09-23 18:29 . 2012-05-19 09:04 22528 —-a-w- c:\program files\MotionBlur_pf.exe 2002-09-20 11:40 . 2012-05-19 09:04 22016 —-a-w- c:\program files\print_generic_px.exe 2002-09-20 11:11 . 2012-05-19 09:04 9216 —-a-w- c:\program files\ScaleAlpha_pm.exe 2002-09-05 11:01 . 2012-05-19 09:04 15360 —-a-w- c:\program files\Store_Brush_pb.exe 2002-09-05 09:44 . 2012-05-19 09:04 28160 —-a-w- c:\program files\Store_Buffer_pm.exe 2002-09-03 11:27 . 2012-05-19 09:04 11776 —-a-w- c:\program files\Clipboard_Export_pb.exe 2002-02-09 15:53 . 2012-05-19 09:04 11264 —-a-w- c:\program files\AverageFrames_pm.exe . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{96f454ea-9d38-474f-b504-56193e00c1a5}"= "c:\program files (x86)\uTorrentControl_v6\prxtbuTor.dll" [2013-05-16 231712] . [HKEY_CLASSES_ROOT\clsid\{96f454ea-9d38-474f-b504-56193e00c1a5}] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}] 2010-07-28 03:33 433648 —-a-w- c:\programdata\Partner\Partner.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{96f454ea-9d38-474f-b504-56193e00c1a5}] 2013-05-16 12:13 231712 —-a-w- c:\program files (x86)\uTorrentControl_v6\prxtbuTor.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{96f454ea-9d38-474f-b504-56193e00c1a5}"= "c:\program files (x86)\uTorrentControl_v6\prxtbuTor.dll" [2013-05-16 231712] . [HKEY_CLASSES_ROOT\clsid\{96f454ea-9d38-474f-b504-56193e00c1a5}] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-07-28 39408] "Akamai NetSession Interface"="c:\users\Jason\AppData\Local\Akamai\netsession_win.exe" [2013-06-05 4489472] "SearchProtect"="c:\users\Jason\AppData\Roaming\SearchProtect\bin\cltmng.exe" [2013-05-08 2852640] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-02-26 98304] "THX Audio Control Panel"="c:\program files (x86)\Creative\THX TruStudio PC\THXAudioCP\THXAudio.exe" [2010-01-22 1016320] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2013-05-08 41056] "00PCTFW"="c:\program files (x86)\PC Tools Firewall Plus\FirewallGUI.exe" [2011-04-07 2672600] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-22 59720] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816] "vProt"="c:\program files (x86)\AVG SafeGuard toolbar\vprot.exe" [2013-06-06 1100616] "SearchProtectAll"="c:\program files (x86)\SearchProtect\bin\cltmng.exe" [2013-05-08 2852640] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2013-05-01 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-05-31 152392] . c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Best Buy pc app.lnk - c:\programdata\Best Buy pc app\ClickOnceSetup.exe "c:\programdata\Best Buy pc app\Best Buy pc app.application" [2010-6-24 9216] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux4"=wdmaud.drv . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R3 Andbus;LGE Android Platform Composite USB Device;c:\windows\system32\DRIVERS\lgandbus64.sys;c:\windows\SYSNATIVE\DRIVERS\lgandbus64.sys [x] R3 AndDiag;LGE Android Platform USB Serial Port;c:\windows\system32\DRIVERS\lganddiag64.sys;c:\windows\SYSNATIVE\DRIVERS\lganddiag64.sys [x] R3 AndGps;LGE Android Platform USB GPS NMEA Port;c:\windows\system32\DRIVERS\lgandgps64.sys;c:\windows\SYSNATIVE\DRIVERS\lgandgps64.sys [x] R3 ANDModem;LGE Android Platform USB Modem;c:\windows\system32\DRIVERS\lgandmodem64.sys;c:\windows\SYSNATIVE\DRIVERS\lgandmodem64.sys [x] R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [x] R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [x] R3 pctNdis;PC Tools Firewall Intermediate Filter Service;c:\windows\system32\DRIVERS\pctNdis64.sys;c:\windows\SYSNATIVE\DRIVERS\pctNdis64.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys;c:\windows\SYSNATIVE\DRIVERS\wdcsam64.sys [x] R3 WUSB54GSCv2.NTamd64;Compact Wireless-G USB Network Adapter with SpeedBooster Service;c:\windows\system32\DRIVERS\WUSB54GSCV2_AMD64.sys;c:\windows\SYSNATIVE\DRIVERS\WUSB54GSCV2_AMD64.sys [x] R4 Partner Service;Partner Service;c:\programdata\Partner\Partner.exe;c:\programdata\Partner\Partner.exe [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x] S1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx64.sys;c:\windows\SYSNATIVE\drivers\avgtpx64.sys [x] S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys;c:\windows\SYSNATIVE\DRIVERS\ehdrv.sys [x] S1 pctgntdi;pctgntdi;c:\windows\System32\drivers\pctgntdi64.sys;c:\windows\SYSNATIVE\drivers\pctgntdi64.sys [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x] S2 CltMngSvc;Search Protect by Conduit Updater;c:\program files (x86)\SearchProtect\bin\CltMngSvc.exe;c:\program files (x86)\SearchProtect\bin\CltMngSvc.exe [x] S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x] S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [x] S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys;c:\windows\SYSNATIVE\DRIVERS\epfwwfpr.sys [x] S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x] S2 USBS3S4Detection;USBS3S4Detection;c:\oem\USBDECTION\USBS3S4Detection.exe;c:\oem\USBDECTION\USBS3S4Detection.exe [x] S2 vToolbarUpdater14.0.1;vToolbarUpdater14.0.1;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\14.0.1\ToolbarUpdater.exe;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\14.0.1\ToolbarUpdater.exe [x] S2 XMouseButton Launcher;XMouseButton Launcher;c:\program files\Highresolution Enterprises\X-Mouse Button Control\XMouseButtonSvc.exe;c:\program files\Highresolution Enterprises\X-Mouse Button Control\XMouseButtonSvc.exe [x] S3 Linksys_adapter_H;Linksys Adapter Network Driver;c:\windows\system32\DRIVERS\AE2500w764.sys;c:\windows\SYSNATIVE\DRIVERS\AE2500w764.sys [x] S3 MBfilt;MBfilt;c:\windows\system32\drivers\MBfilt64.sys;c:\windows\SYSNATIVE\drivers\MBfilt64.sys [x] S3 PCTFW-PacketFilter;PCTools Firewall - Packet filter driver;c:\windows\system32\drivers\pctNdis-PacketFilter64.sys;c:\windows\SYSNATIVE\drivers\pctNdis-PacketFilter64.sys [x] S3 pctNdisMP;PC Tools Driver;c:\windows\system32\DRIVERS\pctNdis64.sys;c:\windows\SYSNATIVE\DRIVERS\pctNdis64.sys [x] S3 pctplfw;pctplfw;c:\windows\System32\drivers\pctplfw64.sys;c:\windows\SYSNATIVE\drivers\pctplfw64.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x] S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x] S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x] S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x] S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x] . . — Other Services/Drivers In Memory — . *Deregistered* - pctESPInject . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-07-13 00:01 1173456 —-a-w- c:\program files (x86)\Google\Chrome\Application\28.0.1500.72\Installer\chrmstp.exe . Contents of the 'Scheduled Tasks' folder . 2013-07-16 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-11-13 18:19] . 2013-07-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-12-14 01:40] . 2013-07-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-12-14 01:40] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}] 2010-07-28 03:33 750064 —-a-w- c:\programdata\Partner\Partner64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-10-13 186904] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-02-09 10060320] "RunDLLEntry_THXCfg"="c:\windows\system32\THXCfg64.dll" [2009-09-30 17920] "egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-09-11 2716216] "LifeChat"="c:\program files\Microsoft LifeChat\LifeChat.exe" [2009-09-25 371712] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-02-23 500208] . ——- Supplementary Scan ——- . uStart Page = hxxp://homepage.gateway.com/rdr.aspx?b=ACGW&l=0409&m=fx6840&r=17361210z306p0455v1k5k4711r508 uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = ;*.local IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 10.0.1.1 Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\14.0.1\ViProtocol.dll FF - ProfilePath - c:\users\Jason\AppData\Roaming\Mozilla\Firefox\Profiles\9twe287k.default\ FF - prefs.js: browser.startup.homepage - about:home FF - prefs.js: network.proxy.type - 0 FF - ExtSQL: 2013-06-09 00:46; {96f454ea-9d38-474f-b504-56193e00c1a5}; c:\users\Jason\AppData\Roaming\Mozilla\Firefox\Profiles\9twe287k.default\extensions\{96f454ea-9d38-474f-b504-56193e00c1a5} . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) Toolbar-Locked - (no file) . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-4084180699-1339970569-2533701502-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.Email.1" . [HKEY_USERS\S-1-5-21-4084180699-1339970569-2533701502-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.VCard.1" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2013-07-16 03:20:52 ComboFix-quarantined-files.txt 2013-07-16 10:20 . Pre-Run: 580,215,926,784 bytes free Post-Run: 580,014,039,040 bytes free . - - End Of File - - 90877E6062C938A81F0F36B61EF4739B D41D8CD98F00B204E9800998ECF8427E
Looks good!

Quick Scan with Malwarebytes Antimalware

  • If not existing, please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.

If the program is already installed:
  • Run Malwarebytes Antimalware
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location.
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Post that log back here.



Scan with ESET Online Scan

Please go to here to run the online scannner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked
  • Click on Advanced Settings and ensure these options are ticked:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Click Scan
  • Wait for the scan to finish
  • If any threats were found, click the 'List of found threats' , then click Export to text file….
  • Save it to your desktop, then please copy and paste that log as a reply to this topic.
Okay, I've done the first, but in the second, it says I have to install a program to get a one time scan. Should I do it? Also, here's the log from Anti-Malware: Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Database version: v2013.07.11.05 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16635 Jason :: JASON-PC [administrator] 7/17/2013 1:28:00 PM mbam-log-2013-07-17 (13-28-00).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 229871 Time elapsed: 3 minute(s), 25 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)
Alright, here's what the scan found: C:\Program Files (x86)\Mozilla Firefox\browser\nsprotector.js Win32/Conduit.SearchProtect.A application C:\Program Files (x86)\SearchProtect\bin\ChromeModule.dll a variant of Win32/Conduit.SearchProtect.C application C:\Program Files (x86)\SearchProtect\bin\cltmng.exe a variant of Win32/Conduit.SearchProtect.B application C:\Program Files (x86)\SearchProtect\bin\FirefoxModule.dll a variant of Win32/Conduit.SearchProtect.C application C:\Program Files (x86)\SearchProtect\bin\InternetExplorerModule.dll a variant of Win32/Conduit.SearchProtect.C application C:\Program Files (x86)\SearchProtect\bin\SPHook32.dll probably a variant of Win32/Conduit.SearchProtect.C application C:\Program Files (x86)\SearchProtect\ffprotect\application.js Win32/Conduit.SearchProtect.A application C:\Program Files (x86)\SearchProtect\ffprotect\nsprotector.js Win32/Conduit.SearchProtect.A application C:\Users\Jason\AppData\Roaming\SearchProtect\bin\ChromeModule.dll a variant of Win32/Conduit.SearchProtect.C application C:\Users\Jason\AppData\Roaming\SearchProtect\bin\cltmng.exe a variant of Win32/Conduit.SearchProtect.B application C:\Users\Jason\AppData\Roaming\SearchProtect\bin\FirefoxModule.dll a variant of Win32/Conduit.SearchProtect.C application C:\Users\Jason\AppData\Roaming\SearchProtect\bin\InternetExplorerModule.dll a variant of Win32/Conduit.SearchProtect.C application C:\Users\Jason\AppData\Roaming\SearchProtect\bin\SPHook32.dll probably a variant of Win32/Conduit.SearchProtect.C application C:\Users\Jason\AppData\Roaming\SearchProtect\ffprotect\application.js Win32/Conduit.SearchProtect.A application C:\Users\Jason\AppData\Roaming\SearchProtect\ffprotect\nsprotector.js Win32/Conduit.SearchProtect.A application C:\Users\Jason\Downloads\Random\cbsidlm-tr1_7-Auto_Clicker_by_Shocker-SEO2-75742161.exe multiple threats C:\Users\Jason\Downloads\Random\cbsidlm-tr1_9-XMouse_Button_Control-SEO2-75362562.exe multiple threats Operating memory multiple threats

C:\Users\Jason\Downloads\Random\cbsidlm-tr1_7-Auto_Clicker_by_Shocker-SEO2-75742161.exe multiple threats
C:\Users\Jason\Downloads\Random\cbsidlm-tr1_9-XMouse_Button_Control-SEO2-75362562.exe multiple threats


Delete these files!


Then we can do the cleanup - if you are facing any issues, report that immediately.

Delete junk with adwCleaner


Please download AdwCleaner to your desktop.


  • Run adwcleaner.exe.
  • Hit delete.
  • When the run is finished, it will open up a text file.
  • Please post its contents within your next reply.
  • You´ll find the log file at C:\AdwCleaner[S1].txt also.

SecurityCheck

Please download SecurityCheck: LINK1 LINK2

  • Save it to your desktop, start it and follow the instructions in the window.
  • After the scan finished the (checkup.txt) will open. Copy its content to your thread.
adwCleaner:

# AdwCleaner v2.306 - Logfile created 07/21/2013 at 20:27:10
# Updated 19/07/2013 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : Jason - JASON-PC
# Boot Mode : Normal
# Running from : C:\Users\Jason\Desktop\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

Deleted on reboot : C:\Program Files (x86)\Common Files\AVG Secure Search
Folder Deleted : C:\Program Files (x86)\Conduit
Folder Deleted : C:\Program Files (x86)\SearchProtect
Folder Deleted : C:\Program Files (x86)\uTorrentControl_v6
Folder Deleted : C:\ProgramData\Partner
Folder Deleted : C:\Users\Jason\AppData\Local\AVG Secure Search
Folder Deleted : C:\Users\Jason\AppData\Local\Conduit
Folder Deleted : C:\Users\Jason\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Jason\AppData\LocalLow\PriceGong
Folder Deleted : C:\Users\Jason\AppData\LocalLow\uTorrentControl_v6
Folder Deleted : C:\Users\Jason\AppData\Roaming\Mozilla\Firefox\Profiles\9twe287k.default\extensions\{96f454ea-9d38-474f-b504-56193e00c1a5}
Folder Deleted : C:\Users\Jason\AppData\Roaming\SearchProtect

***** [Registry] *****

Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKCU\Software\AppDataLow\Software\uTorrentControl_v6
Key Deleted : HKCU\Software\AppDataLow\Toolbar
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{96F454EA-9D38-474F-B504-56193E00C1A5}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{96F454EA-9D38-474F-B504-56193E00C1A5}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CD90659F-D5B2-4104-9504-7CA36E6532DF}
Key Deleted : HKCU\Software\SearchProtect
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKLM\Software\AVG Security Toolbar
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{28A88B70-D874-4F73-BBBA-9B2B222FB7D6}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\kt_bho_dll.dll
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Key Deleted : HKLM\SOFTWARE\Classes\kt_bho.KettleBho
Key Deleted : HKLM\SOFTWARE\Classes\kt_bho.KettleBho.1
Key Deleted : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\viprotocol
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3289075
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{86676E13-D6D8-4652-9FCF-F2047F1FB000}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{CD90659F-D5B2-4104-9504-7CA36E6532DF}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Deleted : HKLM\Software\SearchProtect
Key Deleted : HKLM\Software\uTorrentControl_v6
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{96F454EA-9D38-474F-B504-56193E00C1A5}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{CD90659F-D5B2-4104-9504-7CA36E6532DF}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{954B5FD1-8196-402D-A632-57938BDB0A33}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BF9091BE-197D-46AB-B0C2-9EFFCCF624CE}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{96F454EA-9D38-474F-B504-56193E00C1A5}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\uTorrentControl_v6 Toolbar
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{96F454EA-9D38-474F-B504-56193E00C1A5}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{96F454EA-9D38-474F-B504-56193E00C1A5}]
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [searchprotect]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{96F454EA-9D38-474F-B504-56193E00C1A5}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [SearchProtectAll]
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{96F454EA-9D38-474F-B504-56193E00C1A5}]

***** [Internet Browsers] *****

-\\ Internet Explorer v10.0.9200.16635

[OK] Registry is clean.

-\\ Mozilla Firefox v22.0 (en-US)

File : C:\Users\Jason\AppData\Roaming\Mozilla\Firefox\Profiles\9twe287k.default\prefs.js

Deleted : user_pref("CT3289075.FF19Solved", "true");
Deleted : user_pref("CT3289075.UserID", "UN26561008171729720");
Deleted : user_pref("CT3289075.installDate", "9/6/2013 0:46:45");
Deleted : user_pref("CT3289075.installSessionId", "-1");
Deleted : user_pref("CT3289075.installSp", "TRUE");
Deleted : user_pref("CT3289075.installerVersion", "1.4.2.3");
Deleted : user_pref("CT3289075.searchRevert", "FALSE");
Deleted : user_pref("CT3289075.searchUserMode", "2");
Deleted : user_pref("CT3289075.versionFromInstaller", "10.16.2.9");
Deleted : user_pref("extensions.addonfox.addit.remoteInstallItems", "{ \"software\": {\"107\": {\"id\": \"107\[…]

-\\ Google Chrome v28.0.1500.72

File : C:\Users\Jason\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[S1].txt - [386 octets] - [21/07/2013 20:25:45]
AdwCleaner[S2].txt - [318 octets] - [21/07/2013 20:26:47]
AdwCleaner[S3].txt - [8815 octets] - [21/07/2013 20:27:10]

########## EOF - C:\AdwCleaner[S3].txt - [8875 octets] ##########







SecurityCheck:

Results of screen317's Security Check version 0.99.70
Windows 7 Service Pack 1 x64 (UAC is disabled!)
Internet Explorer 10
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Disabled!
ESET NOD32 Antivirus 4.0
Antivirus out of date!
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware version 1.75.0.1300
Java 7 Update 25
Adobe Flash Player 11.7.700.224
Adobe Reader 9 Adobe Reader out of Date!
Mozilla Firefox (22.0)
Google Chrome 28.0.1500.71
Google Chrome 28.0.1500.72
````````Process Check: objlist.exe by Laurent````````
ESET NOD32 Antivirus egui.exe
ESET NOD32 Antivirus ekrn.exe
PC Tools Firewall Plus FWService.exe
PC Tools Firewall Plus FirewallGUI.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 1%
````````````````````End of Log``````````````````````
Your system is clean! :)


Adobe Reader out of date

Your Adobe Reader is outdated. We will fix this.


  • Get the actual software from here. Important: Uncheck any optional software (for example Google Chrome, etc.) offered.
  • Run setup and follow the instructions.
  • Click upon Start–>control panel–>add/remove programs.
  • Search for and remove any older reader versions.


Also, update your ESET NOD32.



Uninstall our tools using delfix

Please follow these steps in order:

  • In the case we used Defogger to turn off your CD emulation software. You can start it again and use the Enable button.
  • In the case we used Combofix. Deactivate your antivirus software once more, then rename the combofix.exe to uninstall.exe and run it one last time. You shall be noted that Combofix has been removed.
  • In any case please download delfix to your desktop.
    • Close all other programms and start delfix.
    • Please check all the boxes and run the tool.
    • delfix will now delete all found traces of our removal process
  • If there is still something left please delete it manualy.




How to protect yourself

  • System Updates
    Beeing up to date is very important. Please be sure to activate automatic updates in your control panel.
    Windows XP | Windows Vista |
    Windows 7 | windows 8
  • Protection
    What you need is one (not more) good virus scanner with backgroud protection. Additionally I recommend a special malwarescanner that you run from time to time.
    Personally I am using the avast! Antivirus Free Edition and Malwarebytes Anti-Malware. They offer you good protection for free use. But please remember: You get only the full protection if you use the payed versions of your security software.
  • Up to date Software
    Stay up to date with all the programs you use. Some of those really have to have an eye on are: your browser(s) including add-ons and plug-ins, Java, Flash Player, your virus scanner, and basically every software you use often. These link may help you to check:
    • Secunia Online Software Inspector - Checks if your software has updates available.
    • Filehippo Update Checkere - This tool also scans your computer for outdated software.
    • Mozilla: Check your plugins - The webpage will tell you if you have outdated plugins in your Firefox browser.
  • Backups
    There are chances for an emergency every day. So be prepared. Back up your data on a regular basis. If you burn it to DVDs from time to time, use a cloud-drive or a professional network backup system is your choice.
  • Brains
    It's no joke! You really need one of those things. :) It is very important not just to click anywhere it is colored or flashing while you surfing on the web. Do not click an OK button on any popping window without reading what it says. While installing software always choose the custom mode, read what those windows says and uncheck adware that will be installed along the software you want.
Thanks, Psychotic! Sorry about my slow replies. I tend to procrastinate a bit and made this whole process take longer than it have to be. As for the advices. I think I hit most of those points already. My NOD32 anti-vrius is out-dated, I know, but I planned to keep it until at least the end of this year. Even out-dated, it's better than most free anti-virus programs out there. I would like to have a back-up of my system though, for emergencies, but I think I can find a guide elsewhere for the step-by-step process. Anyways, my computer seems to be healthy now. Again, thanks for all the help!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI