This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Win32.Downloader.gen - and here is another one [Solved]

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi - like others I am encountering an issue with Win32.Downloader.gen. This is identified when I run Spybot and Spybot does not remove. Thanks in advance for any assistance.

OTL logfile created on: 7/22/2013 11:57:11 AM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Owner\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16635)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

6.00 Gb Total Physical Memory | 4.30 Gb Available Physical Memory | 71.60% Memory free
12.00 Gb Paging File | 9.93 Gb Available in Paging File | 82.81% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 688.53 Gb Total Space | 369.44 Gb Free Space | 53.66% Space Free | Partition Type: NTFS
Drive D: | 2.70 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: OWNER-PC | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Owner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe (Infowatch)
PRC - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe (Kaspersky Lab ZAO)
PRC - C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\BUFFALO\NASNAVI\NasNavi.exe (BUFFALO INC.)
PRC - C:\Program Files (x86)\BUFFALO\NASNAVI\nassvc.exe (BUFFALO INC.)
PRC - C:\Program Files (x86)\BUFFALO\NASNAVI\nassche.exe (BUFFALO INC.)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe ()
PRC - C:\Program Files (x86)\ScanSoft\OmniPageSE4\OpWareSE4.exe (Nuance Communications, Inc.)
PRC - C:\Program Files (x86)\Globe Software\StatBar\StatBar.exe (Globe Software)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\dblite.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (MozillaMaintenance) – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (MBAMService) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (nvUpdatusService) – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (Stereo Service) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (CSObjectsSrv) – C:\Program Files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe (Infowatch)
SRV - (AVP) – C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe (Kaspersky Lab ZAO)
SRV - (AdobeActiveFileMonitor11.0) – C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
SRV - (NasPmService) – C:\Program Files (x86)\BUFFALO\NASNAVI\nassvc.exe (BUFFALO INC.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (IJPLMSVC) – C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe ()


========== Driver Services (SafeList) ==========

DRV:64bit: - (KLIF) – C:\Windows\SysNative\drivers\klif.sys (Kaspersky Lab ZAO)
DRV:64bit: - (kneps) – C:\Windows\SysNative\drivers\kneps.sys (Kaspersky Lab ZAO)
DRV:64bit: - (kltdi) – C:\Windows\SysNative\drivers\kltdi.sys (Kaspersky Lab ZAO)
DRV:64bit: - (DigiartyVirtualCDBus) – C:\Windows\SysNative\drivers\DigiartyVirtualCDBus.sys (Digiarty Software, Inc.)
DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (Point64) – C:\Windows\SysNative\drivers\point64.sys (Microsoft Corporation)
DRV:64bit: - (NuidFltr) – C:\Windows\SysNative\drivers\nuidfltr.sys (Microsoft Corporation)
DRV:64bit: - (dc3d) – C:\Windows\SysNative\drivers\dc3d.sys (Microsoft Corporation)
DRV:64bit: - (klmouflt) – C:\Windows\SysNative\drivers\klmouflt.sys (Kaspersky Lab)
DRV:64bit: - (klkbdflt) – C:\Windows\SysNative\drivers\klkbdflt.sys (Kaspersky Lab)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (PxHlpa64) – C:\Windows\SysNative\drivers\PxHlpa64.sys (Corel Corporation)
DRV:64bit: - (KLIM6) – C:\Windows\SysNative\drivers\klim6.sys (Kaspersky Lab ZAO)
DRV:64bit: - (kl1) – C:\Windows\SysNative\drivers\kl1.sys (Kaspersky Lab ZAO)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (CSCrySec) – C:\Windows\SysNative\drivers\CSCrySec.sys (Infowatch)
DRV:64bit: - (CSVirtualDiskDrv) – C:\Windows\SysNative\drivers\CSVirtualDiskDrv.sys (Infowatch)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbGD) – C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (StillCam) – C:\Windows\SysNative\drivers\serscan.sys (Microsoft Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (netr28x) – C:\Windows\SysNative\drivers\netr28x.sys (Ralink Technology, Corp.)
DRV:64bit: - (MTsensor) – C:\Windows\SysNative\drivers\ASACPI.sys ()
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{D5CD4868-A817-45C4-B6E6-CE46F211F9C1}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 31 94 AD DA 39 7E CD 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://searchab.com/?aff=7&uid=28b827a…q={searchTerms}
IE - HKCU\..\SearchScopes\{D5CD4868-A817-45C4-B6E6-CE46F211F9C1}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..CT3272718.browser.search.defaultthis.engineName: "true"
FF - prefs.js..browser.search.defaultengine: "Privitize VPN"
FF - prefs.js..browser.search.defaultenginename: "Privitize VPN"
FF - prefs.js..browser.search.defaultenginename,S: S", ""
FF - prefs.js..browser.search.defaultthis.engineName: "MixiDJ Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT3272718&SearchSource=3&q={searchTerms}&CUI=UN97115770330297288"
FF - prefs.js..browser.search.order.1: "Privitize VPN"
FF - prefs.js..browser.search.order.1,S: S", ""
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.selectedEngine,S: S", ""
FF - prefs.js..browser.startup.homepage: "http://www.cnn.com/"
FF - prefs.js..extensions.enabledAddons: %7B6005d9b1-d115-485a-a92a-3f6453ca3fe2%7D:2.4
FF - prefs.js..extensions.enabledAddons: %7BD4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389%7D:0.9.10
FF - prefs.js..extensions.enabledAddons: support%40lastpass.com:2.0.20
FF - prefs.js..extensions.enabledAddons: %7Ba0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7%7D:20130515
FF - prefs.js..extensions.enabledAddons: %7Ba7c6cf7f-112c-4500-a7ea-39801a327e5f%7D:2.0.16
FF - prefs.js..extensions.enabledAddons: %7B0545b830-f0aa-4d7e-8820-50a4629a56fe%7D:19.0
FF - prefs.js..extensions.enabledAddons: anti_banner%40kaspersky.com:13.0.2.600
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:22.0
FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT3272718&SearchSource=2&CUI=UN97115770330297288&UM=UM_ID&q="
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: ""
FF - prefs.js..sweetim.toolbar.previous.browser.search.selectedEngine: ""
FF - prefs.js..browser.startup.homepage: ""
FF - prefs.js..sweetim.toolbar.previous.keyword.URL: ""
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.10.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@logitech.com/HarmonyRemote,version=1.0.0: C:\Program Files (x86)\Logitech\Harmony Remote Driver\NprtHarmonyPlugin.dll (Logitech Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@kaspersky.com/Kaspersky PURE: C:\PROGRA~2\KASPER~1\KASPER~1.0\KASPER~2\npkpmAutofill.dll (Kaspersky Lab)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\[removed] [2013/07/15 07:43:00 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\[removed] [2013/07/15 07:43:00 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\[removed] [2013/07/15 07:43:00 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\[removed] [2013/07/15 07:42:59 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\[removed] [2013/07/15 07:43:00 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 22.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 22.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.6\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2013/05/19 17:10:03 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.6\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{72CA2996-F580-47DF-98FF-0B853D09CEC8}: C:\Users\Owner\AppData\Roaming\Kaspersky Lab\Password Manager\kpmAutofill [2013/03/12 11:22:36 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 22.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 22.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 17.0.6\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2013/05/19 17:10:03 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 17.0.6\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Thunderbird\Extensions\\{72CA2996-F580-47DF-98FF-0B853D09CEC8}: C:\Users\Owner\AppData\Roaming\Kaspersky Lab\Password Manager\kpmAutofill [2013/03/12 11:22:36 | 000,000,000 | —D | M]

[2012/08/23 17:38:11 | 000,000,000 | —D | M] (No name found) – C:\Users\Owner\AppData\Roaming\Mozilla\Extensions
[2013/07/22 09:56:52 | 000,000,000 | —D | M] (No name found) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\iddrhb70.default\extensions
[2013/06/29 08:25:48 | 000,000,000 | —D | M] ("ColorfulTabs") – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\iddrhb70.default\extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe}
[2013/05/23 15:53:11 | 000,000,000 | —D | M] (WOT) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\iddrhb70.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2013/05/09 20:53:32 | 000,000,000 | —D | M] (MixiDJ) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\iddrhb70.default\extensions\{c0c2693d-2ee8-47b4-9df7-b67a0ee31988}
[2013/01/01 11:45:31 | 000,000,000 | —D | M] (Zoomex) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\iddrhb70.default\extensions\[removed]
[2013/02/01 07:35:37 | 000,000,000 | —D | M] (MagniPic) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\iddrhb70.default\extensions\[removed]
[2013/02/01 07:37:50 | 000,000,000 | —D | M] (MagniPic) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\iddrhb70.default\extensions\[removed]
[2013/03/05 15:29:52 | 000,000,000 | —D | M] ("Coupon Companion Plugin") – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\iddrhb70.default\extensions\[removed]
[2013/04/25 14:41:29 | 000,000,000 | —D | M] (LastPass) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\iddrhb70.default\extensions\[removed]
[2013/03/05 15:29:51 | 000,000,000 | —D | M] (No name found) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\iddrhb70.default\extensions\[removed]\chrome
[2013/03/05 15:29:51 | 000,000,000 | —D | M] (No name found) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\iddrhb70.default\extensions\[removed]\defaults
[2013/03/05 15:29:51 | 000,000,000 | —D | M] (No name found) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\iddrhb70.default\extensions\[removed]\locale
[2013/03/05 15:29:51 | 000,000,000 | —D | M] (No name found) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\iddrhb70.default\extensions\[removed]\skin
[2013/03/05 15:29:51 | 000,000,000 | —D | M] (No name found) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\iddrhb70.default\extensions\[removed]\chrome\content\extensionCode
[2012/12/13 08:12:58 | 001,261,578 | —- | M] () (No name found) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\iddrhb70.default\extensions\[removed]
[2013/06/26 14:11:59 | 000,221,999 | —- | M] () (No name found) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\iddrhb70.default\extensions\[removed]
[2012/12/14 11:32:02 | 000,260,260 | —- | M] () (No name found) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\iddrhb70.default\extensions\{6005d9b1-d115-485a-a92a-3f6453ca3fe2}.xpi
[2013/06/19 17:12:53 | 000,868,738 | —- | M] () (No name found) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\iddrhb70.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}.xpi
[2012/12/14 11:32:03 | 000,292,116 | —- | M] () (No name found) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\iddrhb70.default\extensions\{ad48108d-92a6-4eb9-87e4-978aca1dbae4}.xpi
[2013/07/19 20:42:02 | 003,410,514 | —- | M] () (No name found) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\iddrhb70.default\extensions\{c0c588b6-b11d-4898-af00-079fed05aa32}.xpi
[2012/08/23 18:28:08 | 002,966,066 | —- | M] () (No name found) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\iddrhb70.default\extensions\{c7b3cf78-9cbc-47b9-ba47-bb84a56069dd}.xpi
[2013/07/22 09:56:52 | 000,818,491 | —- | M] () (No name found) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\iddrhb70.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2012/12/14 11:32:03 | 000,434,392 | —- | M] () (No name found) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\iddrhb70.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi
[2013/02/01 07:37:20 | 000,002,090 | —- | M] () – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\iddrhb70.default\searchplugins\Searchab.xml
[2013/07/09 08:14:28 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2013/07/09 08:14:32 | 000,000,000 | —D | M] (Default) – C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2013/07/15 07:42:59 | 000,000,000 | —D | M] (Anti-Banner) – C:\PROGRAM FILES (X86)\KASPERSKY LAB\KASPERSKY PURE 3.0\FFEXT\[removed]

========== Chrome ==========

CHR - homepage: http://searchab.com/?aff=7&uid=28b827a…c2-002618c0767e
CHR - homepage: http://searchab.com/?aff=7&uid=28b827a…c2-002618c0767e
CHR - Extension: No name found = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\
CHR - Extension: No name found = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: No name found = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: No name found = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\jneaojaoiajhnemidnjhoempalnidbhj\1.21.11_0\crossrider
CHR - Extension: No name found = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\jneaojaoiajhnemidnjhoempalnidbhj\1.21.11_0\
CHR - Extension: No name found = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\keammfpldbfmgllfliepgdpoboocoeie\1\
CHR - Extension: No name found = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\loihdcgfdfchcdpaonlpdfpbjlkjgeag\1\
CHR - Extension: No name found = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\oapikbmhhnkcdkakfpddfpenfjfcojen\3.2_0\
CHR - Extension: No name found = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2013/06/13 08:00:15 | 000,449,637 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 123fporn.info
O1 - Hosts: 15435 more lines…
O2:64bit: - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
O2:64bit: - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
O2:64bit: - BHO: (Safe Money Plugin) - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
O2:64bit: - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
O2 - BHO: (Coupon Companion Plugin) - {11111111-1111-1111-1111-110211181104} - C:\Program Files (x86)\Coupon Companion Plugin\Coupon Companion Plugin.dll (215 Apps)
O2 - BHO: (Kaspersky Passsword Manager Toolbar) - {215BA832-75A3-426E-A4FC-7C5B58CE6A10} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\Kaspersky Password Manager\spIEBho.dll (Kaspersky Lab)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
O2 - BHO: (Zoomex) - {71FD612F-034A-B6E5-9A53-70282A57076C} - C:\ProgramData\Zoomex\50e309218bdfb.dll ()
O2 - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
O2 - BHO: (Safe Money Plugin) - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
O2 - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
O2 - BHO: (no name) - {E78E4949-965A-23B9-075E-FB733D83D01D} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Kaspersky Passsword Manager Toolbar) - {215BA832-75A3-426E-A4FC-7C5B58CE6A10} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\Kaspersky Password Manager\spIEBho.dll (Kaspersky Lab)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4:64bit: - HKLM..\Run: [CanonSolutionMenu] C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4:64bit: - HKLM..\Run: [IntelliPoint] c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [IntelliType Pro] c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (Microsoft Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVP] C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe (Kaspersky Lab ZAO)
O4 - HKLM..\Run: [OpwareSE4] C:\Program Files (x86)\ScanSoft\OmniPageSE4\OpwareSE4.exe (Nuance Communications, Inc.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [StatBar] C:\Program Files (x86)\Globe Software\StatBar\StatBar.exe (Globe Software)
O4 - Startup: C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\BUFFALO NAS Navigator2.lnk = C:\Program Files (x86)\BUFFALO\NASNAVI\NasNavi.exe (BUFFALO INC.)
O4 - Startup: C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\NAS Scheduler.lnk = C:\Program Files (x86)\BUFFALO\NASNAVI\nassche.exe (BUFFALO INC.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 60
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O8:64bit: - Extra context menu item: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\ie_banner_deny.htm ()
O8:64bit: - Extra context menu item: Kaspersky PURE - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\Kaspersky Password Manager\spIEBho.dll (Kaspersky Lab)
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\ie_banner_deny.htm ()
O8 - Extra context menu item: Kaspersky PURE - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\Kaspersky Password Manager\spIEBho.dll (Kaspersky Lab)
O9:64bit: - Extra Button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
O9:64bit: - Extra Button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found
O9 - Extra Button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
O9 - Extra Button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.135 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{865A67BD-A43D-49EB-A348-609B85B868B8}: DhcpNameServer = 192.168.1.135 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{982DD18C-CE11-4DEB-84E3-A6A6E6DEAD29}: DhcpNameServer = 192.168.1.135 75.75.75.75 75.75.76.76
O18:64bit: - Protocol\Handler\belarc - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\BelarcAdvisor\System\BAVoilaX.dll (Belarc, Inc.)
O20 - AppInit_DLLs: (c:\progra~2\zoomex\sprote~1.dll) - c:\Program Files (x86)\ZoomEx\sprotector.dll ()
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012/09/21 03:15:38 | 000,000,073 | R— | M] () - D:\AUTORUN.INF – [ CDFS ]
O32 - AutoRun File - [2012/09/21 03:15:38 | 000,175,208 | R— | M] (Adobe Systems Incorporated) - D:\AutoPlay.exe – [ CDFS ]
O32 - AutoRun File - [2012/09/21 03:15:21 | 000,000,000 | —D | M] - D:\Autoplay – [ CDFS ]
O33 - MountPoints2\{9626daab-6c8f-11e2-ab3c-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{9626daab-6c8f-11e2-ab3c-806e6f6e6963}\Shell\AutoRun\command - "" = D:\AutoPlay.exe – [2012/09/21 03:15:38 | 000,175,208 | R— | M] (Adobe Systems Incorporated)
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/07/22 11:43:37 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Owner\Desktop\OTL.exe
[2013/07/11 07:19:38 | 000,000,000 | —D | C] – C:\ProgramData\regid.1986-12.com.adobe
[2013/07/11 03:07:44 | 000,526,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/07/11 03:07:44 | 000,391,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/07/11 03:07:43 | 000,136,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2013/07/11 03:07:43 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2013/07/11 03:07:43 | 000,089,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013/07/11 03:07:43 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013/07/11 03:07:43 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2013/07/11 03:07:43 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2013/07/11 03:07:43 | 000,051,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013/07/11 03:07:43 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2013/07/11 03:07:43 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2013/07/11 03:07:41 | 000,855,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/07/11 03:07:41 | 000,690,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/07/11 03:07:41 | 000,603,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/07/11 03:07:40 | 003,958,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/07/10 07:39:28 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe
[2013/07/10 07:34:42 | 000,056,336 | —- | C] (Corel Corporation) – C:\Windows\SysNative\drivers\PxHlpa64.sys
[2013/07/10 07:34:42 | 000,011,376 | —- | C] (Corel Corporation) – C:\Windows\SysNative\drivers\cdralw2k.sys
[2013/07/10 07:34:42 | 000,010,864 | —- | C] (Corel Corporation) – C:\Windows\SysNative\drivers\cdr4_xp.sys
[2013/07/10 07:34:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Sonic Shared
[2013/07/10 07:34:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\PX Storage Engine
[2013/07/10 07:23:16 | 001,887,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WMVDECOD.DLL
[2013/07/10 07:23:15 | 001,620,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WMVDECOD.DLL
[2013/07/10 07:23:13 | 000,624,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\qedit.dll
[2013/07/10 07:23:13 | 000,509,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\qedit.dll
[2013/07/10 07:22:42 | 001,643,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[2013/07/09 08:14:27 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox

========== Files - Modified Within 30 Days ==========

[2013/07/22 11:50:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/07/22 11:43:41 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Owner\Desktop\OTL.exe
[2013/07/22 09:17:10 | 000,028,144 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/07/22 09:17:10 | 000,028,144 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/07/22 09:09:07 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/07/22 09:09:00 | 536,174,591 | -HS- | M] () – C:\hiberfil.sys
[2013/07/15 07:42:49 | 000,620,128 | —- | M] (Kaspersky Lab ZAO) – C:\Windows\SysNative\drivers\klif.sys
[2013/07/15 07:42:49 | 000,178,448 | —- | M] (Kaspersky Lab ZAO) – C:\Windows\SysNative\drivers\kneps.sys
[2013/07/15 07:42:49 | 000,090,208 | —- | M] (Kaspersky Lab ZAO) – C:\Windows\SysNative\drivers\klflt.sys
[2013/07/15 07:42:49 | 000,054,368 | —- | M] (Kaspersky Lab ZAO) – C:\Windows\SysNative\drivers\kltdi.sys
[2013/07/11 03:31:30 | 001,949,200 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/07/11 03:12:35 | 000,792,712 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/07/11 03:12:35 | 000,660,068 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/07/11 03:12:35 | 000,120,996 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/07/10 07:34:48 | 000,001,896 | —- | M] () – C:\Users\Public\Desktop\Adobe Photoshop Elements 11.lnk

========== Files Created - No Company Name ==========

[2013/07/10 07:34:48 | 000,001,912 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop Elements 11.lnk
[2013/07/10 07:34:48 | 000,001,896 | —- | C] () – C:\Users\Public\Desktop\Adobe Photoshop Elements 11.lnk
[2013/03/24 17:59:47 | 000,000,227 | —- | C] () – C:\Windows\PowerReg.dat
[2013/03/24 17:59:41 | 000,045,568 | —- | C] () – C:\Windows\UniFish3.exe
[2013/03/19 19:43:36 | 000,000,424 | —- | C] () – C:\Windows\MAXLINK.INI
[2012/08/19 14:17:50 | 000,772,214 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI

========== ZeroAccess Check ==========

[2009/07/14 00:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2013/02/27 01:52:56 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/02/27 00:55:05 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 21:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 23:24:25 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 21:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2013/07/09 09:12:21 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\Azureus
[2013/06/03 11:27:59 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\BDlot
[2013/06/19 17:35:42 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\Canon
[2012/10/05 12:39:56 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\Digiarty
[2012/12/31 11:45:33 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\EAC
[2012/12/31 11:26:12 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\FairStars CD Ripper
[2013/03/23 08:13:37 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\GameFly
[2013/06/20 07:13:58 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\ImgBurn
[2012/08/23 20:04:26 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\NASNaviator2
[2013/01/25 12:19:28 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\PFStaticIP
[2013/02/10 15:05:53 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\player
[2013/03/19 19:43:26 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\ScanSoft
[2013/02/01 11:45:26 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\Strongvault
[2013/04/20 12:30:43 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\TAC
[2013/01/01 11:48:29 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\TFP
[2012/08/24 14:43:42 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\Thunderbird

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.ADML >
[2011/04/12 04:17:31 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\winsxs\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_7ef5713984067904\Explorer.adml

< MD5 for: EXPLORER.ADMX >
[2009/06/10 16:53:55 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_71af9b5b0a86e6b7\Explorer.admx

< MD5 for: EXPLORER.EXE >
[2011/02/26 01:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011/02/25 02:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/02/25 02:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 02:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 23:24:25 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010/11/20 23:24:11 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe

< MD5 for: EXPLORER.EXE.MUI >
[2011/04/12 04:17:19 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\en-US\explorer.exe.mui
[2011/04/12 04:17:19 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\winsxs\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_61e778c48d52d19b\explorer.exe.mui
[2011/04/12 04:17:21 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\SysWOW64\en-US\explorer.exe.mui
[2011/04/12 04:17:21 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\winsxs\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_6c3c2316c1b39396\explorer.exe.mui

< MD5 for: IEXPLORE.EXE >
[2013/01/08 21:53:45 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=0100BCF23941C83462E4A70F94C3392E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16464_none_0d2c5bc980874648\iexplore.exe
[2012/11/13 22:56:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=0D286C0FE561D1A7EB30E83A0FF305B2 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16457_none_178ed6e5b4dd3857\iexplore.exe
[2012/08/19 03:02:22 | 000,754,784 | —- | M] (Microsoft Corporation) MD5=1223ACBFC1093852DFF039E189599BBD – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16448_none_0d45fcc9807373c2\iexplore.exe
[2013/05/17 00:10:41 | 000,763,544 | —- | M] (Microsoft Corporation) MD5=1423FF1BFD2ECD9CFC8C17EA4F98B20F – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16490_none_0d07eadd80a334bf\iexplore.exe
[2012/08/24 03:34:41 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=22CC6CDBA678790046693654C3B212E4 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16450_none_1787d4dfb4e386f6\iexplore.exe
[2013/02/22 03:04:50 | 000,763,520 | —- | M] (Microsoft Corporation) MD5=25B53709A37C3FD814B68EA0A92D18F9 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16476_none_0d238c71808d94e7\iexplore.exe
[2012/10/08 04:37:24 | 000,748,704 | —- | M] (Microsoft Corporation) MD5=270A1342BD5AF95CA25A586B4C2F1522 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16455_none_178cd651b4df05a9\iexplore.exe
[2013/06/12 00:41:27 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=2A5F565327BFD679EC5F790DC15BBF25 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20742_none_0a0343986c500b78\iexplore.exe
[2012/08/24 07:23:44 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=2D53C5F71653EF94E7829846405D4ED2 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16450_none_0d332a8d8082c4fb\iexplore.exe
[2013/06/11 20:23:57 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=30E7CA4620500FE012EB464F0E1DE91E – C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2013/06/11 20:23:57 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=30E7CA4620500FE012EB464F0E1DE91E – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16635_none_20da757e52a1c35e\iexplore.exe
[2013/02/22 00:10:00 | 000,757,376 | —- | M] (Microsoft Corporation) MD5=32732CEDE2A1106B736EF3D84054EE04 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16476_none_177836c3b4ee56e2\iexplore.exe
[2013/04/04 18:47:49 | 000,757,360 | —- | M] (Microsoft Corporation) MD5=3F00BE80B9CEA20B7FE7363D15EDDB94 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16483_none_176a65f9b4f926ce\iexplore.exe
[2013/02/22 00:10:31 | 000,757,360 | —- | M] (Microsoft Corporation) MD5=4145E2B5663F6FACC08EFDB17B658BB2 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20586_none_17f703a2ce14129d\iexplore.exe
[2012/10/08 08:29:46 | 000,754,848 | —- | M] (Microsoft Corporation) MD5=49442BA6DCE4B4E3C1CB0AB193FE29AD – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16455_none_0d382bff807e43ae\iexplore.exe
[2012/08/24 06:49:07 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=5A150AFABB25BEA50CEDC8650A7B8A9E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20557_none_0dc3c95e999a1626\iexplore.exe
[2012/08/24 03:49:25 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=62188720CE27B982B4285C03163C9FB3 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20557_none_181873b0cdfad821\iexplore.exe
[2013/05/16 19:34:33 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=67EE46FD4D3B56531C5DD1BDC149275A – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16490_none_175c952fb503f6ba\iexplore.exe
[2013/01/08 18:42:06 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=698EB1E5F8C66344D97C00B5699E871D – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16464_none_1781061bb4e80843\iexplore.exe
[2013/06/21 16:40:26 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=774C18BA997F40DA7F5A9A4AF822F49C – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16618_none_168386401e431b98\iexplore.exe
[2013/02/02 04:09:12 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=7C2923004FFC497E54F38E835F108EE8 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20580_none_0d9c579499b8b898\iexplore.exe
[2010/11/20 23:24:43 | 000,695,056 | —- | M] (Microsoft Corporation) MD5=86257731DDB311FBC283534CC0091634 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1196a9003b674a92\iexplore.exe
[2012/08/19 03:02:22 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=93569D46D79F9756ED077156496AFE23 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16448_none_179aa71bb4d435bd\iexplore.exe
[2013/06/11 22:28:00 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=98C6F2A9A981A54222602B87C6310BDE – C:\Program Files\Internet Explorer\iexplore.exe
[2013/06/11 22:28:00 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=98C6F2A9A981A54222602B87C6310BDE – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16635_none_1685cb2c1e410163\iexplore.exe
[2013/05/16 21:46:47 | 000,763,544 | —- | M] (Microsoft Corporation) MD5=A1397D2A4924C390E55D146FB45FDF7C – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20600_none_0df2d8da9977d637\iexplore.exe
[2013/04/04 21:55:57 | 000,763,504 | —- | M] (Microsoft Corporation) MD5=A1B0DEC3BB845C6369F97BC1A3542A07 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16483_none_0d15bba7809864d3\iexplore.exe
[2013/02/02 00:19:03 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=A285E1965C115031DA02B777EE9D7689 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20580_none_17f101e6ce197a93\iexplore.exe
[2013/05/16 18:27:11 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=A8732CEDB2C0EE7AFC08F867A47BB3EC – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20600_none_1847832ccdd89832\iexplore.exe
[2013/02/02 03:37:58 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=A8EBEBCD9F5C49475194099FCD276992 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16470_none_0d1d8ab58092fcdd\iexplore.exe
[2012/11/15 23:08:58 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=AC4957E154F750DF54F36ADC8E3E040D – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20565_none_0db6f8de99a3ff69\iexplore.exe
[2013/02/22 03:17:45 | 000,763,520 | —- | M] (Microsoft Corporation) MD5=B21A57AA4CB928059A0C0C58A9E77A02 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20586_none_0da2595099b350a2\iexplore.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2013/04/04 17:55:02 | 000,757,360 | —- | M] (Microsoft Corporation) MD5=C036AB1ED8BAC04FE4A349BA263077BB – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20593_none_17e932d8ce1ee289\iexplore.exe
[2013/04/04 20:40:37 | 000,763,504 | —- | M] (Microsoft Corporation) MD5=C4A4F4AD91677DA1659A9ADE63746B8B – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20593_none_0d94888699be208e\iexplore.exe
[2010/11/20 23:25:08 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1beb53526fc80c8d\iexplore.exe
[2013/06/12 03:51:43 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=CA88A25280B1D85ED0BC26B042ABBCCF – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20742_none_ffae994637ef497d\iexplore.exe
[2012/10/08 04:22:05 | 000,748,704 | —- | M] (Microsoft Corporation) MD5=CECB15F834FC2B4B150449717ADE18DD – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20562_none_1808a252ce07755f\iexplore.exe
[2013/06/21 16:40:26 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=CEE28BCBC3251595396EE7FDA2B5F3CF – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16618_none_20d8309252a3dd93\iexplore.exe
[2013/02/02 00:19:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=DDE5A0DFAF7C6370FB36402D7A746ED3 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16470_none_17723507b4f3bed8\iexplore.exe
[2013/01/08 20:51:57 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=EF1F6F41FB2C9BBB484B21017F380201 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20573_none_0daa285e99ade8ac\iexplore.exe
[2013/01/08 17:32:42 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=F05982E56ABD835AA8DF260EEC873E5B – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20573_none_17fed2b0ce0eaaa7\iexplore.exe
[2012/10/08 07:09:10 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=F61714ABCF9BF0CEF0A6249AD4FD490B – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20562_none_0db3f80099a6b364\iexplore.exe
[2012/11/13 22:19:28 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=F691418EE9A6344AEB5C1B0518FBF8AE – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20565_none_180ba330ce04c164\iexplore.exe
[2012/11/14 03:11:18 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=FD0D2E1FAEBAE5031BE2EB8000D973F1 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16457_none_0d3a2c93807c765c\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2012/08/19 03:02:22 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_07013012b816cb66\iexplore.exe.mui
[2012/08/19 03:02:22 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_1155da64ec778d61\iexplore.exe.mui
[2013/06/21 16:40:27 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2013/06/21 16:40:26 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2013/06/21 16:40:26 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.2.9200.16521_en-us_103c8b6555e6a67e\iexplore.exe.mui
[2013/06/21 16:40:27 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.2.9200.16521_en-us_1a9135b78a476879\iexplore.exe.mui
[2009/07/13 22:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_0b433e7773148b79\iexplore.exe.mui
[2009/07/13 22:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_1597e8c9a7754d74\iexplore.exe.mui

< MD5 for: SERVICES >
[2009/06/10 17:00:26 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\services

< MD5 for: SERVICES.CFG >
[2013/05/10 03:57:30 | 000,558,879 | —- | M] () MD5=3679F8D3253DC110D1D8F2AE115EE00C – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2011/06/06 12:55:30 | 000,584,045 | R— | M] () MD5=B82DD53FA8C260DDD7FDC42182DB816E – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\services.cfg

< MD5 for: SERVICES.ESM >
[2013/03/12 08:59:56 | 000,008,731 | —- | M] () MD5=A481BF1A869654B9C4B5BC8ADD636782 – C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\Kaspersky Password Manager\services.esm
[2013/03/12 08:59:56 | 000,008,731 | —- | M] () MD5=A481BF1A869654B9C4B5BC8ADD636782 – C:\Users\Owner\AppData\Local\Temp\services.esm

< MD5 for: SERVICES.EXE >
[2009/07/13 21:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009/07/13 21:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2011/04/12 04:17:17 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\SysNative\en-US\services.exe.mui
[2011/04/12 04:17:17 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\winsxs\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_c5f238be3fa63468\services.exe.mui

< MD5 for: SERVICES.LNK >
[2009/07/14 00:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOF >
[2009/06/10 16:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\SysNative\wbem\services.mof
[2009/06/10 16:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.mof

< MD5 for: SERVICES.MSC >
[2011/04/12 04:17:16 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\en-US\services.msc
[2009/06/10 16:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\services.msc
[2011/04/12 04:17:18 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\en-US\services.msc
[2009/06/10 17:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\services.msc
[2011/04/12 04:17:16 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_003408aa160fce5b\services.msc
[2009/06/10 16:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_2b58d44b5f6beb8a\services.msc
[2011/04/12 04:17:18 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 17:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc

< MD5 for: SERVICES.PTXML >
[2009/07/13 16:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\SysNative\wdi\perftrack\Services.ptxml
[2009/07/13 16:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\Services.ptxml

< MD5 for: SERVICES.SBS >
[2011/03/01 03:58:44 | 000,034,818 | —- | M] () MD5=62AFD4B2025CE6D4706B36F4C4808F9B – C:\Program Files (x86)\Spybot - Search & Destroy\Includes\Services.sbs

< MD5 for: WINLOGON.ADML >
[2011/04/12 04:17:31 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_f0f9032ef6930070\WinLogon.adml

< MD5 for: WINLOGON.ADMX >
[2009/06/10 17:04:41 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_d7024e6992f3424d\WinLogon.admx

< MD5 for: WINLOGON.EXE >
[2010/11/20 23:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/20 23:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2011/04/12 04:17:16 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\SysNative\en-US\winlogon.exe.mui
[2011/04/12 04:17:16 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_291e96fa1ab5fc7b\winlogon.exe.mui

< MD5 for: WINLOGON.MFL >
[2011/04/12 04:17:17 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\SysNative\wbem\en-US\winlogon.mfl
[2011/04/12 04:17:17 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_84afd4fd38ffd276\winlogon.mfl

< MD5 for: WINLOGON.MOF >
[2009/07/13 16:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\SysNative\wbem\winlogon.mof
[2009/07/13 16:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_dc2dbb778f98e40f\winlogon.mof

< %SYSTEMDRIVE%\*.* >
[2013/02/09 08:54:10 | 000,000,009 | —- | M] () – C:\END
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 08:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 08:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 08:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2013/07/22 09:09:00 | 536,174,591 | -HS- | M] () – C:\hiberfil.sys
[2007/11/07 08:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 08:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 08:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 08:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 08:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 08:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 08:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 08:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 08:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2013/07/22 09:09:06 | 2146,557,951 | -HS- | M] () – C:\pagefile.sys
[2007/11/07 08:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 08:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 08:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI

< %systemroot%\Fonts\*.com >
[2009/07/14 01:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 16:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< dir "%systemdrive%\*" /S /A:L /C >
Volume in drive C has no label.
Volume Serial Number is 4260-19CA
Directory of C:\
07/14/2009 01:08 AM Documents and Settings [C:\Users]
0 File(s) 0 bytes
Directory of C:\ProgramData
07/14/2009 01:08 AM Application Data [C:\ProgramData]
07/14/2009 01:08 AM Desktop [C:\Users\Public\Desktop]
07/14/2009 01:08 AM Documents [C:\Users\Public\Documents]
07/14/2009 01:08 AM Favorites [C:\Users\Public\Favorites]
07/14/2009 01:08 AM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009 01:08 AM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users
07/14/2009 01:08 AM All Users [C:\ProgramData]
07/14/2009 01:08 AM Default User [C:\Users\Default]
0 File(s) 0 bytes
Directory of C:\Users\All Users
07/14/2009 01:08 AM Application Data [C:\ProgramData]
07/14/2009 01:08 AM Desktop [C:\Users\Public\Desktop]
07/14/2009 01:08 AM Documents [C:\Users\Public\Documents]
07/14/2009 01:08 AM Favorites [C:\Users\Public\Favorites]
07/14/2009 01:08 AM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009 01:08 AM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default
07/14/2009 01:08 AM Application Data [C:\Users\Default\AppData\Roaming]
07/14/2009 01:08 AM Cookies [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies]
07/14/2009 01:08 AM Local Settings [C:\Users\Default\AppData\Local]
07/14/2009 01:08 AM My Documents [C:\Users\Default\Documents]
07/14/2009 01:08 AM NetHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
07/14/2009 01:08 AM PrintHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
07/14/2009 01:08 AM Recent [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
07/14/2009 01:08 AM SendTo [C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
07/14/2009 01:08 AM Start Menu [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
07/14/2009 01:08 AM Templates [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default\AppData\Local
07/14/2009 01:08 AM Application Data [C:\Users\Default\AppData\Local]
07/14/2009 01:08 AM History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009 01:08 AM Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Default\Documents
07/14/2009 01:08 AM My Music [C:\Users\Default\Music]
07/14/2009 01:08 AM My Pictures [C:\Users\Default\Pictures]
07/14/2009 01:08 AM My Videos [C:\Users\Default\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Owner
08/15/2012 05:35 PM Application Data [C:\Users\Owner\AppData\Roaming]
08/15/2012 05:35 PM Cookies [C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Cookies]
08/15/2012 05:35 PM Local Settings [C:\Users\Owner\AppData\Local]
08/15/2012 05:35 PM My Documents [C:\Users\Owner\Documents]
08/15/2012 05:35 PM NetHood [C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
08/15/2012 05:35 PM PrintHood [C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
08/15/2012 05:35 PM Recent [C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Recent]
08/15/2012 05:35 PM SendTo [C:\Users\Owner\AppData\Roaming\Microsoft\Windows\SendTo]
08/15/2012 05:35 PM Start Menu [C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu]
08/15/2012 05:35 PM Templates [C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Owner\AppData\Local
08/15/2012 05:35 PM Application Data [C:\Users\Owner\AppData\Local]
08/15/2012 05:35 PM History [C:\Users\Owner\AppData\Local\Microsoft\Windows\History]
08/15/2012 05:35 PM Temporary Internet Files [C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Owner\Documents
08/15/2012 05:35 PM My Music [C:\Users\Owner\Music]
08/15/2012 05:35 PM My Pictures [C:\Users\Owner\Pictures]
08/15/2012 05:35 PM My Videos [C:\Users\Owner\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Public\Documents
07/14/2009 01:08 AM My Music [C:\Users\Public\Music]
07/14/2009 01:08 AM My Pictures [C:\Users\Public\Pictures]
07/14/2009 01:08 AM My Videos [C:\Users\Public\Videos]
0 File(s) 0 bytes
Directory of C:\Users\UpdatusUser
12/01/2012 10:29 PM Application Data [C:\Users\UpdatusUser\AppData\Roaming]
12/01/2012 10:29 PM Cookies [C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Cookies]
12/01/2012 10:29 PM Local Settings [C:\Users\UpdatusUser\AppData\Local]
12/01/2012 10:29 PM My Documents [C:\Users\UpdatusUser\Documents]
12/01/2012 10:29 PM NetHood [C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
12/01/2012 10:29 PM PrintHood [C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
12/01/2012 10:29 PM Recent [C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Recent]
12/01/2012 10:29 PM SendTo [C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\SendTo]
12/01/2012 10:29 PM Start Menu [C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu]
12/01/2012 10:29 PM Templates [C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\UpdatusUser\AppData\Local
12/01/2012 10:29 PM Application Data [C:\Users\UpdatusUser\AppData\Local]
12/01/2012 10:29 PM History [C:\Users\UpdatusUser\AppData\Local\Microsoft\Windows\History]
12/01/2012 10:29 PM Temporary Internet Files [C:\Users\UpdatusUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\UpdatusUser\Documents
12/01/2012 10:29 PM My Music [C:\Users\UpdatusUser\Music]
12/01/2012 10:29 PM My Pictures [C:\Users\UpdatusUser\Pictures]
12/01/2012 10:29 PM My Videos [C:\Users\UpdatusUser\Videos]
0 File(s) 0 bytes
Total Files Listed:
0 File(s) 0 bytes
66 Dir(s) 398,461,845,504 bytes free

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/08/19 14:27:10 | 000,000,221 | -HS- | M] () – C:\Users\Owner\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2012/02/07 16:29:20 | 003,267,848 | —- | M] (LotSoft ) – C:\Users\Owner\Desktop\bdlot-dvd-iso-master-setup.exe
[2013/07/22 11:43:41 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Owner\Desktop\OTL.exe
[2013/01/04 10:10:14 | 000,032,782 | —- | M] () – C:\Users\Owner\Desktop\Start Tor Browser.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< End of report >

OTL Extras logfile created on: 7/22/2013 11:45:09 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Owner\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16635)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

6.00 Gb Total Physical Memory | 4.35 Gb Available Physical Memory | 72.43% Memory free
12.00 Gb Paging File | 9.91 Gb Available in Paging File | 82.58% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 688.53 Gb Total Space | 369.44 Gb Free Space | 53.66% Space Free | Partition Type: NTFS
Drive D: | 2.70 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: OWNER-PC | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html[@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – Reg Error: Value error.

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 – ()
"C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 – ()

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 – ()
"C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 – ()


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0A9AC965-ECD1-452D-960B-DDA0ABF25472}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{0F345FDA-9394-41E9-9FCF-4C9BFEFC0E63}" = lport=2869 | protocol=6 | dir=in | app=system |
"{1E2875B5-019C-4888-B709-1B307B3707E4}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{2949B5CC-DBFD-4F6E-9852-6C24B3E39727}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=c:\windows\system32\svchost.exe |
"{30BD9BF7-B2A9-411E-8F25-B3B2CD181666}" = lport=10243 | protocol=6 | dir=in | app=system |
"{31FF81A6-FFC8-41BF-811A-DF5B7BB001C0}" = lport=139 | protocol=6 | dir=in | app=system |
"{38B49ED9-7BE2-4C2C-B143-F89034EB7CF5}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{41D1646D-1C82-42FC-9A1C-EE84D5F77FE0}" = rport=2869 | protocol=6 | dir=out | app=system |
"{4ACE9CFA-0913-49CF-A5A9-45354ADB4827}" = lport=445 | protocol=6 | dir=in | app=system |
"{5687D41F-1EE8-461F-92F1-4ABA9F354C14}" = rport=137 | protocol=17 | dir=out | app=system |
"{5C8383A7-77C0-480E-9CB1-CA997AB56E6B}" = lport=2869 | protocol=6 | dir=in | app=system |
"{61176521-16BA-4EB6-9397-CF5206034D9E}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=c:\windows\system32\spoolsv.exe |
"{62F082B9-6316-4D47-99C1-CD913BF4E183}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{6651DA65-4F54-47E8-819F-12E8A16FFFC6}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{6702590E-9178-4B33-8FFF-3B10F05905AF}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{7C1756E6-6B0B-446F-BF99-8F03C6FF86AD}" = rport=445 | protocol=6 | dir=out | app=system |
"{80154292-1425-436E-AA4C-0F62818021A1}" = lport=51978 | protocol=17 | dir=in | app=c:\program files (x86)\vuze\azureus.exe |
"{84B6A293-CCE9-452D-83BE-3840DAF1CA3D}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=file and printer sharing (spooler service - rpc-epmap) |
"{885E0027-5451-4715-8DDC-B79E23A7CACA}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{97FE05BE-A7F2-4B19-A6E8-9DE7D4BC1944}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{A2A3D767-C2D0-4360-8413-A6FD50F6EC9D}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{A4030815-C50C-49F7-95EF-78E0C2BD7274}" = lport=51978 | protocol=6 | dir=in | app=c:\program files (x86)\vuze\azureus.exe |
"{A6A6BA67-94E3-4A7B-9339-3E8BA886DA2C}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{BAC52806-A132-4938-9672-2409AE39B6CD}" = rport=138 | protocol=17 | dir=out | app=system |
"{C3079597-4E81-4837-80A3-61ACBB883823}" = lport=138 | protocol=17 | dir=in | app=system |
"{DB974E94-5BA0-4AC1-A74C-8B5E61B5F068}" = rport=139 | protocol=6 | dir=out | app=system |
"{E51B1917-AF25-41C9-9F52-3A1763290CE4}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{E6D37FED-91B2-4DAC-A07B-A45915D44250}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{E7AD99CC-BD14-4EC0-93F9-2A80FD036A65}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{EBB378E0-A1F9-4EFF-859A-138801A390E9}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{F1E9A97A-946E-4E1F-BD55-E6BDCA8833EC}" = rport=10243 | protocol=6 | dir=out | app=system |
"{F2D33D00-C92C-420A-A20F-7FF322080D4F}" = lport=137 | protocol=17 | dir=in | app=system |
"{F63CCEBA-A456-40BC-8A66-5CB8EB343521}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=c:\windows\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{09951CCB-C7A9-4372-97CB-7B119948F507}" = protocol=58 | dir=in | app=system |
"{120D86B5-B470-4401-A7D9-07D3C747CC83}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{1B910447-A919-4DB6-BA30-F1D2EC62355F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{2509B882-0C82-4F85-9EE3-4F102EC4E0A2}" = protocol=17 | dir=in | app=c:\program files (x86)\buffalo\nasnavi\nasnavi.exe |
"{2CFA1C59-8AB4-476D-BE3F-6538F0B194FD}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the walking dead\walkingdead101.exe |
"{36C276BD-880E-4908-BD41-C59166088D11}" = protocol=6 | dir=out | app=system |
"{3A4BAE03-4A1E-4201-8475-AFC4EC7BE788}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{3A8C60B2-E111-4648-AB84-F5A7D9412FF6}" = protocol=1 | dir=out | name=file and printer sharing (echo request - icmpv4-out) |
"{3CF75AE8-CECA-4127-8E86-C8CA426F9232}" = protocol=17 | dir=in | app=c:\program files (x86)\vuze\azureus.exe |
"{3FF0723A-1021-4BA4-BB24-EC9F052010B7}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{41364BE2-CD4A-4ED1-8B7B-5BC3223478AB}" = protocol=58 | dir=in | name=@hnetcfg.dll,-148 |
"{422BE8DC-3892-414C-A23C-B59CC6A57425}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{48276916-8884-4C44-ACF6-74876818E5A3}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{580F2430-AA85-4A9A-B75C-5A5E6F1B4FA5}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{5E6D614E-C8D8-4E6E-8E50-D3808D36324A}" = protocol=6 | dir=in | app=c:\program files (x86)\buffalo\nasnavi\nasnavi.exe |
"{622FCB3A-0A13-459A-8F17-B1CD4FB9BB57}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{6DECB2CD-8935-4676-A9AF-7FBD1A98DF49}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{70EAF94F-EED8-4947-A0C6-29E2B74B1C35}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{73678E5B-E309-4159-99E9-3404BCFA939C}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{79A9D392-5E7D-4B3A-A431-D40561474DE0}" = protocol=6 | dir=in | app=c:\program files (x86)\vuze\azureus.exe |
"{8ACEB029-89CF-4CFA-A350-A4072FC47ECD}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{91E95C6E-7A7C-4DB8-8D60-91F01BEC98C0}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{9DB5BF6B-EBA1-4A87-A740-BACBF9C917B7}" = protocol=58 | dir=out | name=file and printer sharing (echo request - icmpv6-out) |
"{9E51C331-5509-4D5C-B458-0AE401F1F8BF}" = protocol=58 | dir=in | name=file and printer sharing (echo request - icmpv6-in) |
"{9FD06274-7826-4068-99D9-C02D1A093966}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{A736EDE0-DB11-410D-B706-B175B8BACE6F}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{AA0D2FC5-C5E8-4E1F-B2EC-DD07AD99C2C2}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{AA5F540C-0C81-4983-8EAD-2466B46EEA79}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{AFA42423-3873-4CCF-923D-87D6D8E3E1B7}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{AFB31983-FBAC-41C8-9BFD-AA96D06F63CA}" = protocol=58 | dir=out | name=@iphlpsvc.dll,-503 |
"{BC5DF711-CD62-47F1-8AB0-64C348AE60CD}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the walking dead\walkingdead101.exe |
"{C6EC0FB3-CF0F-455D-8AD5-B939849FBF91}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{D6D17572-D5A8-48D9-A7D9-4436F38F46A3}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{E611D681-C68A-4A08-84BD-5B7646D7CAEC}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{EA385D7B-0B28-49B4-A13E-94D2800FE442}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{ED16057E-EC50-4C01-A8EA-EC32491CE455}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{F0E9ECE6-A324-4D34-8AF0-D8A3359F7562}" = protocol=1 | dir=in | name=file and printer sharing (echo request - icmpv4-in) |
"{F74E46EE-C61F-41C5-9FFD-B851D124E1DC}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{FC3DC530-825F-475C-A8BF-4BD0EA682659}" = dir=out | app=%programfiles% (x86)\vuze\azureus64.exe |
"{FCEB2C8E-0F20-4762-AD72-F86249E299FD}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{FF21323B-5893-4B68-9F35-7F4B2CCFD3B8}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"TCP Query User{39DB891E-EA51-4FE6-A3F1-16C108A6CBC4}C:\program files (x86)\buffalo\nasnavi\nasnavi.exe" = protocol=6 | dir=in | app=c:\program files (x86)\buffalo\nasnavi\nasnavi.exe |
"TCP Query User{C99C5843-F09F-4AD7-95F4-17D6744591B7}C:\program files (x86)\vuze\azureus.exe" = protocol=6 | dir=in | app=c:\program files (x86)\vuze\azureus.exe |
"UDP Query User{B8721215-E40B-4B73-8B7B-EA0013820313}C:\program files (x86)\vuze\azureus.exe" = protocol=17 | dir=in | app=c:\program files (x86)\vuze\azureus.exe |
"UDP Query User{F8DC86B1-FFFB-4CAC-AF2A-17686314F95B}C:\program files (x86)\buffalo\nasnavi\nasnavi.exe" = protocol=17 | dir=in | app=c:\program files (x86)\buffalo\nasnavi\nasnavi.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{003EF63E-096E-01BE-E355-414CDBDDD4C8}" = ZoomEx
"{0225AD21-F3E2-4916-BFF3-65D3F9052582}" = iTunes
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP970_series" = Canon MP970 series
"{2F72F540-1F60-4266-9506-952B21D6640D}" = Apple Mobile Device Support
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{7AB6F8D7-7804-4662-BE8C-1AFCCD602D9F}" = Microsoft Mouse and Keyboard Center
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 311.06
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 311.06
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 311.06
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.11.3
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"CanonMyPrinter" = Canon My Printer
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Mouse and Keyboard Center" = Microsoft Mouse and Keyboard Center
"ZoomEx" =

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0134A1A1-C283-4A47-91A1-92F19F960372}" = Adobe Creative Suite 2
"{1111706F-666A-4037-7777-211328764D10}" = JavaFX 2.1.1
"{1D181764-DCD0-41B8-AA7B-0A599F027A72}" = Adobe Photoshop Elements 11
"{236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{45C56AA7-ED1B-4800-A97F-EDDF3F3520B1}" = Apple Application Support
"{53820F89-063F-10D7-7457-06C201F4CBF0}" =
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5C6F884D-680C-448B-B4C9-22296EE1B206}" = Logitech Harmony Remote Software 7
"{5E33D30D-D896-4D92-B033-5F45819B2937}" = Strongvault Online Backup
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{634F79E1-2A41-4C40-9E8D-89EC740AC9D6}" = Logitech Harmony Remote Software
"{65CB4C08-C47B-4A7E-A6A4-50C06ADA5FC6}" = Adobe AIR
"{786C5747-1033-0000-B58E-000000000001}" = Adobe Stock Photos 1.0
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{80F19EAA-44C4-47C2-AE87-1C7628E858D6}" = Logitech Harmony Remote Software 7
"{8471021C-F529-43DE-84DF-3612E10F58C4}" = Remote Control USB Driver
"{85309D89-7BE9-4094-BB17-24999C6118FC}" = ArcSoft PhotoStudio 5.5
"{8EDBA74D-0686-4C99-BFDD-F894678E5B39}" = Adobe Common File Installer
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002A-0409-1000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0116-0409-1000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{98CE8819-87AA-4814-8167-ADDDD513485F}" = PSE11 STI Installer
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9CF819A8-4071-4B2F-B5E2-DDD89B562205}_is1" = TAudioConverter version 0.8.4
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.7)
"{B2F3DBD9-A9D2-4838-B45D-C917DAB32BC3}" = ScanSoft OmniPage SE 4
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B74D4E10-1033-0000-0000-000000000001}" = Adobe Bridge 1.0
"{C49DAA9C-5BA8-459A-8244-E57B69DF0F04}" = Suite Specific
"{D0702EE9-9DE4-419A-9C6C-4730B1C985BA}" = Kaspersky PURE 3.0
"{D1B455C8-C170-44fe-8A90-31263B5153C2}_is1" = Aiseesoft Blu-ray Ripper 6.3.62
"{D4D065E1-3ABF-41D0-B385-FC6F027F4D00}" = Elements 11 Organizer
"{E9787678-1033-0000-8E67-000000000001}" = Adobe Help Center 1.0
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"7-Zip" = 7-Zip 9.22beta
"8461-7759-5462-8226" = Vuze
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Photoshop Elements 11" = Adobe Photoshop Elements 11
"AudioLabel" = AudioLabel
"BDlot DVD ISO Master_is1" = BDlot DVD ISO Master 3.0.2
"Belarc Advisor" = Belarc Advisor 8.3
"Canon MP970 series User Registration" = Canon MP970 series User Registration
"Canon_IJ_Network_Scan_UTILITY" = Canon IJ Network Scan Utility
"Canon_IJ_Network_UTILITY" = Canon IJ Network Tool
"CANONIJPLM100" = PIXMA Extended Survey Program
"CanonSolutionMenu" = Canon Utilities Solution Menu
"Cisco Connect" = Cisco Connect
"Coupon Companion Plugin" = Coupon Companion Plugin
"Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX
"Exact Audio Copy" = Exact Audio Copy 1.0beta3
"FLAC" = FLAC 1.2.1b (remove only)
"GameFly" = GameFly
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"ImgBurn" = ImgBurn
"InstallWIX_{D0702EE9-9DE4-419A-9C6C-4730B1C985BA}" = Kaspersky PURE 3.0
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300
"Mozilla Firefox 22.0 (x86 en-US)" = Mozilla Firefox 22.0 (x86 en-US)
"Mozilla Thunderbird 17.0.6 (x86 en-US)" = Mozilla Thunderbird 17.0.6 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MP Navigator EX 1.0" = Canon MP Navigator EX 1.0
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"RollerCoaster Tycoon Setup" = Roll
"SP_5dec30d7" =
"StatBar_is1" = StatBar 2.406
"UN060501" = BUFFALO NAS Navigator2
"WinX DVD Ripper Platinum_is1" = WinX DVD Ripper Platinum 6.9.2

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 7/11/2013 2:38:42 PM | Computer Name = Owner-PC | Source = WinMgmt | ID = 10
Description =

Error - 7/15/2013 7:21:22 AM | Computer Name = Owner-PC | Source = WinMgmt | ID = 10
Description =

Error - 7/15/2013 7:44:06 AM | Computer Name = Owner-PC | Source = Customer Experience Improvement Program | ID = 1008
Description =

Error - 7/15/2013 7:52:08 AM | Computer Name = Owner-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files (x86)\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program
files (x86)\spybot - search & destroy\DelZip179.dll" on line 8. The value "*" of
attribute "language" in element "assemblyIdentity" is invalid.

Error - 7/17/2013 8:13:09 AM | Computer Name = Owner-PC | Source = WinMgmt | ID = 10
Description =

Error - 7/17/2013 8:36:16 AM | Computer Name = Owner-PC | Source = Customer Experience Improvement Program | ID = 1008
Description =

Error - 7/17/2013 8:44:31 AM | Computer Name = Owner-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files (x86)\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program
files (x86)\spybot - search & destroy\DelZip179.dll" on line 8. The value "*" of
attribute "language" in element "assemblyIdentity" is invalid.

Error - 7/19/2013 8:32:07 PM | Computer Name = Owner-PC | Source = WinMgmt | ID = 10
Description =

Error - 7/22/2013 9:09:16 AM | Computer Name = Owner-PC | Source = WinMgmt | ID = 10
Description =

Error - 7/22/2013 9:39:49 AM | Computer Name = Owner-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files (x86)\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program
files (x86)\spybot - search & destroy\DelZip179.dll" on line 8. The value "*" of
attribute "language" in element "assemblyIdentity" is invalid.

[ System Events ]
Error - 7/22/2013 9:09:19 AM | Computer Name = Owner-PC | Source = ipnathlp | ID = 34001
Description =

Error - 7/22/2013 9:09:19 AM | Computer Name = Owner-PC | Source = ipnathlp | ID = 30013
Description =

Error - 7/22/2013 9:09:20 AM | Computer Name = Owner-PC | Source = ipnathlp | ID = 31004
Description =

Error - 7/22/2013 9:09:20 AM | Computer Name = Owner-PC | Source = ipnathlp | ID = 30013
Description =

Error - 7/22/2013 9:09:53 AM | Computer Name = Owner-PC | Source = ipnathlp | ID = 31004
Description =

Error - 7/22/2013 9:11:20 AM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7038
Description = The nvUpdatusService service was unable to log on as .\UpdatusUser
with the currently configured password due to the following error: %%1330 To ensure
that the service is configured properly, use the Services snap-in in Microsoft
Management Console (MMC).

Error - 7/22/2013 9:11:20 AM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7000
Description = The NVIDIA Update Service Daemon service failed to start due to the
following error: %%1069

Error - 7/22/2013 9:24:24 AM | Computer Name = Owner-PC | Source = ipnathlp | ID = 31004
Description =

Error - 7/22/2013 10:12:35 AM | Computer Name = Owner-PC | Source = ipnathlp | ID = 31004
Description =

Error - 7/22/2013 11:47:18 AM | Computer Name = Owner-PC | Source = ipnathlp | ID = 31004
Description =


< End of report >


logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:33:08 PM, on 7/22/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16635)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\Globe Software\StatBar\StatBar.exe
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
C:\Program Files (x86)\BUFFALO\NASNAVI\NasNavi.exe
C:\Program Files (x86)\BUFFALO\NASNAVI\nassche.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe
C:\Program Files (x86)\ScanSoft\OmniPageSE4\OpWareSE4.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\Owner\Downloads\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: CrossriderApp0021804 - {11111111-1111-1111-1111-110211181104} - C:\Program Files (x86)\Coupon Companion Plugin\Coupon Companion Plugin.dll
O2 - BHO: Kaspersky Passsword Manager Toolbar - {215BA832-75A3-426E-A4FC-7C5B58CE6A10} - C:\PROGRA~2\KASPER~1\KASPER~1.0\KASPER~2\spIEBho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: ContentBlockerBrowserHelperObject - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll
O2 - BHO: Zoomex - {71FD612F-034A-B6E5-9A53-70282A57076C} - C:\ProgramData\Zoomex\50e309218bdfb.dll
O2 - BHO: VirtualKeyboardBrowserHelperObject - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
O2 - BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\OnlineBanking\online_banking_bho.dll
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\UrlAdvisor\klwtbbho.dll
O2 - BHO: MagniPic - {E78E4949-965A-23B9-075E-FB733D83D01D} - (no file)
O3 - Toolbar: Kaspersky Passsword Manager Toolbar - {215BA832-75A3-426E-A4FC-7C5B58CE6A10} - C:\PROGRA~2\KASPER~1\KASPER~1.0\KASPER~2\spIEBho.dll
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files (x86)\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files (x86)\ScanSoft\OmniPageSE4\OpwareSE4.exe"
O4 - HKCU\..\Run: [StatBar] C:\Program Files (x86)\Globe Software\StatBar\StatBar.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: BUFFALO NAS Navigator2.lnk = C:\Program Files (x86)\BUFFALO\NASNAVI\NasNavi.exe
O4 - Startup: NAS Scheduler.lnk = C:\Program Files (x86)\BUFFALO\NASNAVI\nassche.exe
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\ie_banner_deny.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Kaspersky PURE - res://C:\PROGRA~2\KASPER~1\KASPER~1.0\KASPER~2\spIEBho.dll/616
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\UrlAdvisor\klwtbbho.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O20 - AppInit_DLLs: c:\progra~2\zoomex\sprote~1.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Active File Monitor V11 (AdobeActiveFileMonitor11.0) - Adobe Systems Incorporated - C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Kaspersky Anti-Virus Service (AVP) - Kaspersky Lab ZAO - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CryptoStorage control service (CSObjectsSrv) - Infowatch - C:\Program Files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: NAS PM Service (NasPmService) - BUFFALO INC. - C:\Program Files (x86)\BUFFALO\NASNAVI\nassvc.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 11241 bytes
Hi there,
my name is Marius and I will be assisting you with your Malware related problems.

Before we move on, please read the following points carefully.
  • First, read my instructions completely. If there is anything that you do not understand kindly ask before proceeding.
  • Perform everything in the correct order. Sometimes one step requires the previous one.
  • If you have any problems while you are follow my instructions, Stop there and tell me the exact nature of your problem.
  • Do not run any other scans without instruction or Add/ Remove Software unless I tell you to do so. This would change the output of our tools and could be confusing for me.
  • Post all Logfiles as a reply rather than as an attachment unless I specifically ask you. If you can not post all logfiles in one reply, feel free to use more posts.
  • If I don't hear from you within 3 days from this initial or any subsequent post, then this thread will be closed.
  • Stay with me. I will give you some advice about prevention after the cleanup process. Absence of symptoms does not always mean the computer is clean.
  • My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.



Scan with Gmer rootkit scanner

Please download Gmer from here by clicking on the "Download EXE" Button.
  • Double click on the randomly named GMER.exe. If asked to allow gmer.sys driver to load, please consent.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Show All ( should be unchecked by default )
  • Leave everything else as it is.
  • Close all other running programs as well as your Browser.
  • Click the Scan button & wait for it to finish.
  • Once done click on the Save.. button, and in the File name area, type in "ark.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop.
  • Please post the content of the ark.txt here.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Hi, Marius - thanks for the help. I ran the GMER program and the results are listed below:

GMER 2.1.19163 - http://www.gmer.net
Rootkit scan 2013-07-23 09:10:44
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 ST3750528AS rev.CC44 698.64GB
Running: 44z5dg3o.exe; Driver: C:\Users\Owner\AppData\Local\Temp\kgloapow.sys


—- Threads - GMER 2.1 —-

Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [4316:4696] 000007fefbcd2a7c

—- Files - GMER 2.1 —-

File C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HA1G1DEB\clients[1].txt 1 bytes

—- EOF - GMER 2.1 —-
Combofix

Combofix should only be run when adviced by a team member!

Link


Important - Save the file to your desktop!


  • Deactivate any and all of your antivirus programs /spyware scanners - they can prevent CF from doing its work.
  • Run Combofix.exe

When finished, Combofix creates a log file named C:\Combofix.txt. Please post its content in your next reply.

Note: When receiving an error message containing ""Illegal operation attempted on a registry key that has been marked for deletion" simply restart your computer to fix this.
Marius - I ran the Combofix program and here are the results: ComboFix 13-07-22.01 - Owner 07/23/2013 10:13:52.2.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.6143.4699 [GMT -4:00] Running from: c:\users\[removed]\Downloads\ComboFix.exe SP: Spybot - Search and Destroy *Disabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((( Files Created from 2013-06-23 to 2013-07-23 ))))))))))))))))))))))))))))))) . . 2013-07-23 14:19 . 2013-07-23 14:19 ——– d—–w- c:\users\UpdatusUser\AppData\Local\temp 2013-07-23 14:19 . 2013-07-23 14:19 ——– d—–w- c:\users\Default\AppData\Local\temp 2013-07-23 11:54 . 2013-07-02 08:34 9460976 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{95A92BB6-97E2-47F4-B629-3EAEECF4D03C}\mpengine.dll 2013-07-22 19:10 . 2013-07-22 19:10 ——– d—–w- c:\program files (x86)\FileHippo.com 2013-07-22 14:52 . 2013-07-22 17:02 ——– d—–w- c:\program files (x86)\Mozilla Thunderbird 2013-07-11 11:19 . 2013-07-11 11:19 ——– d—–w- c:\programdata\regid.1986-12.com.adobe 2013-07-10 11:39 . 2013-07-10 11:39 ——– d—–w- c:\program files\Common Files\Adobe 2013-07-10 11:34 . 2012-08-10 07:01 56336 ——w- c:\windows\system32\drivers\PxHlpa64.sys 2013-07-10 11:34 . 2012-04-24 07:01 11376 ——w- c:\windows\system32\drivers\cdralw2k.sys 2013-07-10 11:34 . 2012-04-24 07:01 10864 ——w- c:\windows\system32\drivers\cdr4_xp.sys 2013-07-10 11:34 . 2013-07-10 11:34 ——– d—–w- c:\program files (x86)\Common Files\Sonic Shared 2013-07-10 11:34 . 2013-07-10 11:34 ——– d—–w- c:\program files (x86)\Common Files\PX Storage Engine 2013-07-10 11:23 . 2013-05-06 06:03 1887744 —-a-w- c:\windows\system32\WMVDECOD.DLL 2013-07-10 11:23 . 2013-05-06 04:56 1620480 —-a-w- c:\windows\SysWow64\WMVDECOD.DLL 2013-07-10 11:23 . 2013-06-04 06:00 624128 —-a-w- c:\windows\system32\qedit.dll 2013-07-10 11:23 . 2013-06-04 04:53 509440 —-a-w- c:\windows\SysWow64\qedit.dll 2013-07-10 11:23 . 2013-05-27 05:50 1011712 —-a-w- c:\program files\Windows Defender\MpSvc.dll 2013-07-10 11:23 . 2013-05-27 05:50 571904 —-a-w- c:\program files\Windows Defender\MpClient.dll 2013-07-10 11:23 . 2013-05-27 05:50 314880 —-a-w- c:\program files\Windows Defender\MpCommu.dll 2013-07-10 11:23 . 2013-05-27 04:57 4608 —-a-w- c:\program files (x86)\Windows Defender\MsMpLics.dll 2013-07-10 11:23 . 2013-05-27 04:57 54784 —-a-w- c:\program files (x86)\Windows Defender\MpOAV.dll 2013-07-10 11:23 . 2013-05-27 04:57 392704 —-a-w- c:\program files (x86)\Windows Defender\MpClient.dll 2013-07-10 11:23 . 2013-05-27 03:15 9216 —-a-w- c:\program files (x86)\Windows Defender\MpAsDesc.dll 2013-07-10 11:22 . 2013-06-05 03:34 3153920 —-a-w- c:\windows\system32\win32k.sys 2013-07-10 11:22 . 2013-04-10 05:48 1732608 —-a-w- c:\program files\Windows Journal\NBDoc.DLL 2013-07-10 11:22 . 2013-04-10 05:46 1393152 —-a-w- c:\program files\Windows Journal\JNTFiltr.dll 2013-07-10 11:22 . 2013-04-10 05:46 1367040 —-a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll 2013-07-10 11:22 . 2013-04-10 05:46 1402880 —-a-w- c:\program files\Windows Journal\JNWDRV.dll 2013-07-10 11:22 . 2013-04-10 05:03 936448 —-a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll 2013-07-10 11:22 . 2013-04-09 23:34 1247744 —-a-w- c:\windows\SysWow64\DWrite.dll 2013-07-10 11:22 . 2013-04-02 22:51 1643520 —-a-w- c:\windows\system32\DWrite.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-07-11 07:08 . 2012-08-19 17:22 78185248 —-a-w- c:\windows\system32\MRT.exe 2013-06-21 20:40 . 2013-06-21 20:40 1054720 —-a-w- c:\windows\system32\MsSpellCheckingFacility.exe 2013-06-21 20:40 . 2013-06-21 20:40 97280 —-a-w- c:\windows\system32\mshtmled.dll 2013-06-21 20:40 . 2013-06-21 20:40 92160 —-a-w- c:\windows\system32\SetIEInstalledDate.exe 2013-06-21 20:40 . 2013-06-21 20:40 905728 —-a-w- c:\windows\system32\mshtmlmedia.dll 2013-06-21 20:40 . 2013-06-21 20:40 81408 —-a-w- c:\windows\system32\icardie.dll 2013-06-21 20:40 . 2013-06-21 20:40 77312 —-a-w- c:\windows\system32\tdc.ocx 2013-06-21 20:40 . 2013-06-21 20:40 762368 —-a-w- c:\windows\system32\ieapfltr.dll 2013-06-21 20:40 . 2013-06-21 20:40 73728 —-a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2013-06-21 20:40 . 2013-06-21 20:40 719360 —-a-w- c:\windows\SysWow64\mshtmlmedia.dll 2013-06-21 20:40 . 2013-06-21 20:40 62976 —-a-w- c:\windows\system32\pngfilt.dll 2013-06-21 20:40 . 2013-06-21 20:40 61952 —-a-w- c:\windows\SysWow64\tdc.ocx 2013-06-21 20:40 . 2013-06-21 20:40 599552 —-a-w- c:\windows\system32\vbscript.dll 2013-06-21 20:40 . 2013-06-21 20:40 523264 —-a-w- c:\windows\SysWow64\vbscript.dll 2013-06-21 20:40 . 2013-06-21 20:40 52224 —-a-w- c:\windows\system32\msfeedsbs.dll 2013-06-21 20:40 . 2013-06-21 20:40 51200 —-a-w- c:\windows\system32\imgutil.dll 2013-06-21 20:40 . 2013-06-21 20:40 48640 —-a-w- c:\windows\SysWow64\mshtmler.dll 2013-06-21 20:40 . 2013-06-21 20:40 48640 —-a-w- c:\windows\system32\mshtmler.dll 2013-06-21 20:40 . 2013-06-21 20:40 452096 —-a-w- c:\windows\system32\dxtmsft.dll 2013-06-21 20:40 . 2013-06-21 20:40 441856 —-a-w- c:\windows\system32\html.iec 2013-06-21 20:40 . 2013-06-21 20:40 38400 —-a-w- c:\windows\SysWow64\imgutil.dll 2013-06-21 20:40 . 2013-06-21 20:40 361984 —-a-w- c:\windows\SysWow64\html.iec 2013-06-21 20:40 . 2013-06-21 20:40 281600 —-a-w- c:\windows\system32\dxtrans.dll 2013-06-21 20:40 . 2013-06-21 20:40 27648 —-a-w- c:\windows\system32\licmgr10.dll 2013-06-21 20:40 . 2013-06-21 20:40 270848 —-a-w- c:\windows\system32\iedkcs32.dll 2013-06-21 20:40 . 2013-06-21 20:40 247296 —-a-w- c:\windows\system32\webcheck.dll 2013-06-21 20:40 . 2013-06-21 20:40 235008 —-a-w- c:\windows\system32\url.dll 2013-06-21 20:40 . 2013-06-21 20:40 23040 —-a-w- c:\windows\SysWow64\licmgr10.dll 2013-06-21 20:40 . 2013-06-21 20:40 226304 —-a-w- c:\windows\system32\elshyph.dll 2013-06-21 20:40 . 2013-06-21 20:40 216064 —-a-w- c:\windows\system32\msls31.dll 2013-06-21 20:40 . 2013-06-21 20:40 197120 —-a-w- c:\windows\system32\msrating.dll 2013-06-21 20:40 . 2013-06-21 20:40 185344 —-a-w- c:\windows\SysWow64\elshyph.dll 2013-06-21 20:40 . 2013-06-21 20:40 173568 —-a-w- c:\windows\system32\ieUnatt.exe 2013-06-21 20:40 . 2013-06-21 20:40 167424 —-a-w- c:\windows\system32\iexpress.exe 2013-06-21 20:40 . 2013-06-21 20:40 158720 —-a-w- c:\windows\SysWow64\msls31.dll 2013-06-21 20:40 . 2013-06-21 20:40 1509376 —-a-w- c:\windows\system32\inetcpl.cpl 2013-06-21 20:40 . 2013-06-21 20:40 150528 —-a-w- c:\windows\SysWow64\iexpress.exe 2013-06-21 20:40 . 2013-06-21 20:40 149504 —-a-w- c:\windows\system32\occache.dll 2013-06-21 20:40 . 2013-06-21 20:40 144896 —-a-w- c:\windows\system32\wextract.exe 2013-06-21 20:40 . 2013-06-21 20:40 1441280 —-a-w- c:\windows\SysWow64\inetcpl.cpl 2013-06-21 20:40 . 2013-06-21 20:40 1400416 —-a-w- c:\windows\system32\ieapfltr.dat 2013-06-21 20:40 . 2013-06-21 20:40 138752 —-a-w- c:\windows\SysWow64\wextract.exe 2013-06-21 20:40 . 2013-06-21 20:40 13824 —-a-w- c:\windows\system32\mshta.exe 2013-06-21 20:40 . 2013-06-21 20:40 137216 —-a-w- c:\windows\SysWow64\ieUnatt.exe 2013-06-21 20:40 . 2013-06-21 20:40 136192 —-a-w- c:\windows\system32\iepeers.dll 2013-06-21 20:40 . 2013-06-21 20:40 135680 —-a-w- c:\windows\system32\IEAdvpack.dll 2013-06-21 20:40 . 2013-06-21 20:40 12800 —-a-w- c:\windows\SysWow64\mshta.exe 2013-06-21 20:40 . 2013-06-21 20:40 12800 —-a-w- c:\windows\system32\msfeedssync.exe 2013-06-21 20:40 . 2013-06-21 20:40 110592 —-a-w- c:\windows\SysWow64\IEAdvpack.dll 2013-06-21 20:40 . 2013-06-21 20:40 102912 —-a-w- c:\windows\system32\inseng.dll 2013-06-21 11:11 . 2013-06-03 15:28 276256 —-a-w- c:\windows\system32\drivers\DigiartyVirtualCDBus.sys 2013-06-11 19:50 . 2012-08-19 18:52 71048 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-06-11 19:50 . 2012-08-19 18:52 692104 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-05-13 05:51 . 2013-06-12 10:37 184320 —-a-w- c:\windows\system32\cryptsvc.dll 2013-05-13 05:51 . 2013-06-12 10:37 1464320 —-a-w- c:\windows\system32\crypt32.dll 2013-05-13 05:51 . 2013-06-12 10:37 139776 —-a-w- c:\windows\system32\cryptnet.dll 2013-05-13 05:50 . 2013-06-12 10:37 52224 —-a-w- c:\windows\system32\certenc.dll 2013-05-13 04:45 . 2013-06-12 10:37 140288 —-a-w- c:\windows\SysWow64\cryptsvc.dll 2013-05-13 04:45 . 2013-06-12 10:37 1160192 —-a-w- c:\windows\SysWow64\crypt32.dll 2013-05-13 04:45 . 2013-06-12 10:37 103936 —-a-w- c:\windows\SysWow64\cryptnet.dll 2013-05-13 03:43 . 2013-06-12 10:37 1192448 —-a-w- c:\windows\system32\certutil.exe 2013-05-13 03:08 . 2013-06-12 10:37 903168 —-a-w- c:\windows\SysWow64\certutil.exe 2013-05-13 03:08 . 2013-06-12 10:37 43008 —-a-w- c:\windows\SysWow64\certenc.dll 2013-05-10 05:49 . 2013-06-12 10:37 30720 —-a-w- c:\windows\system32\cryptdlg.dll 2013-05-10 03:20 . 2013-06-12 10:37 24576 —-a-w- c:\windows\SysWow64\cryptdlg.dll 2013-05-08 06:39 . 2013-06-12 10:37 1910632 —-a-w- c:\windows\system32\drivers\tcpip.sys 2013-05-02 06:06 . 2010-11-21 03:27 278800 ——w- c:\windows\system32\MpSigStub.exe 2013-04-29 20:48 . 2013-04-29 20:48 163504 —-a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10144.bin 2013-04-26 05:51 . 2013-06-12 10:37 751104 —-a-w- c:\windows\system32\win32spl.dll 2013-04-26 04:55 . 2013-06-12 10:37 492544 —-a-w- c:\windows\SysWow64\win32spl.dll 2013-04-25 23:30 . 2013-06-12 10:37 1505280 —-a-w- c:\windows\SysWow64\d3d11.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{71FD612F-034A-B6E5-9A53-70282A57076C}] 2013-01-01 16:04 118272 —-a-w- c:\programdata\Zoomex\50e309218bdfb.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "StatBar"="c:\program files (x86)\Globe Software\StatBar\StatBar.exe" [2003-07-25 335872] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "SSBkgdUpdate"="c:\program files (x86)\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472] "OpwareSE4"="c:\program files (x86)\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400] . c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ BUFFALO NAS Navigator2.lnk - c:\program files (x86)\BUFFALO\NASNAVI\NasNavi.exe /startup [2010-8-25 1902048] NAS Scheduler.lnk - c:\program files (x86)\BUFFALO\NASNAVI\nassche.exe [2012-8-23 206128] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) "AppInit_DLLs"=c:\progra~2\ZoomEx\sprotector.dll . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R3 DigiartyVirtualCDBus;Digiarty Virtual Driver;c:\windows\system32\drivers\DigiartyVirtualCDBus.sys;c:\windows\SYSNATIVE\drivers\DigiartyVirtualCDBus.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x] S2 AdobeActiveFileMonitor11.0;Adobe Active File Monitor V11;c:\program files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe;c:\program files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe [x] S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [x] S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x] S2 NasPmService;NAS PM Service;c:\program files (x86)\BUFFALO\NASNAVI\nassvc.exe;c:\program files (x86)\BUFFALO\NASNAVI\nassvc.exe [x] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x] S3 dc3d;MS Hardware Device Detection Driver;c:\windows\system32\DRIVERS\dc3d.sys;c:\windows\SYSNATIVE\DRIVERS\dc3d.sys [x] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x] S3 netr28x;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28x.sys;c:\windows\SYSNATIVE\DRIVERS\netr28x.sys [x] S3 Point64;Microsoft Mouse and Keyboard Center Filter Driver;c:\windows\system32\DRIVERS\point64.sys;c:\windows\SYSNATIVE\DRIVERS\point64.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] . . — Other Services/Drivers In Memory — . *NewlyCreated* - WS2IFSL . Contents of the 'Scheduled Tasks' folder . 2013-07-23 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-19 19:50] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IntelliType Pro"="c:\program files\Microsoft Mouse and Keyboard Center\itype.exe" [2012-11-02 1464944] "IntelliPoint"="c:\program files\Microsoft Mouse and Keyboard Center\ipoint.exe" [2012-11-02 2076272] "CanonSolutionMenu"="c:\program files (x86)\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-15 644696] . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = about:blank mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~3\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.1.135 75.75.75.75 75.75.76.76 TCP: Interfaces\{982DD18C-CE11-4DEB-84E3-A6A6E6DEAD29}: DhcpNameServer = 192.168.1.135 75.75.75.75 75.75.76.76 FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\iddrhb70.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3272718&SearchSource=3&q={searchTerms}&CUI=UN97115770330297288 FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.cnn.com/ FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3272718&SearchSource=2&CUI=UN97115770330297288&UM=UM_ID&q= . - - - - ORPHANS REMOVED - - - - . BHO-{E78E4949-965A-23B9-075E-FB733D83D01D} - (no file) AddRemove-Exact Audio Copy - c:\program files (x86)\Exact Audio Copy\uninst.exe AddRemove-ImgBurn - c:\program files (x86)\ImgBurn\uninstall.exe AddRemove-{53820F89-063F-10D7-7457-06C201F4CBF0} - c:\programdata\Zoomex\uninstall.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2013-07-23 10:21:14 ComboFix-quarantined-files.txt 2013-07-23 14:21 ComboFix2.txt 2013-07-23 14:06 . Pre-Run: 399,766,302,720 bytes free Post-Run: 399,640,662,016 bytes free . - - End Of File - - 9452DF787DA929C63A6327E98698828C A36C5E4F47E84449FF07ED3517B43A31
Combofix scripting

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Download the attached CFScript.txt and save it to the location where Combofix is.


[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.




Full System Scan with Malwarebytes Antimalware

  • If not existing, please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.

If the program is already installed:
  • Run Malwarebytes Antimalware
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform fullscan, place a checkmark on all hard drives, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location.
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Post that log back here.

Attachments:

Marius - here are the results of the Combo Fix with CF Script added. I will post the Malwarebytes report separately. ComboFix 13-07-24.02 - Owner 07/24/2013 6:38.3.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.6143.4663 [GMT -4:00] Running from: c:\users\[removed]\Downloads\ComboFix.exe Command switches used :: c:\users\Owner\Desktop\CFScript.txt SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\progra~2\ZoomEx c:\progra~2\ZoomEx\sprotector.dll c:\progra~2\ZoomEx\uninstall.exe c:\programdata\Zoomex c:\programdata\Zoomex\50e309218bdfb.dll c:\programdata\Zoomex\50e309218bdfb.tlb c:\programdata\Zoomex\data\Zoomex.dat c:\programdata\Zoomex\oapikbmhhnkcdkakfpddfpenfjfcojen.crx c:\programdata\Zoomex\settings.ini . . ((((((((((((((((((((((((( Files Created from 2013-06-24 to 2013-07-24 ))))))))))))))))))))))))))))))) . . 2013-07-24 10:45 . 2013-07-24 10:45 ——– d—–w- c:\users\UpdatusUser\AppData\Local\temp 2013-07-24 10:45 . 2013-07-24 10:45 ——– d—–w- c:\users\Default\AppData\Local\temp 2013-07-23 14:40 . 2013-07-23 14:42 ——– d—–w- c:\windows\system32\MRT 2013-07-23 11:54 . 2013-07-02 08:34 9460976 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{95A92BB6-97E2-47F4-B629-3EAEECF4D03C}\mpengine.dll 2013-07-22 19:10 . 2013-07-22 19:10 ——– d—–w- c:\program files (x86)\FileHippo.com 2013-07-22 14:52 . 2013-07-22 17:02 ——– d—–w- c:\program files (x86)\Mozilla Thunderbird 2013-07-11 11:19 . 2013-07-11 11:19 ——– d—–w- c:\programdata\regid.1986-12.com.adobe 2013-07-10 11:39 . 2013-07-10 11:39 ——– d—–w- c:\program files\Common Files\Adobe 2013-07-10 11:34 . 2012-08-10 07:01 56336 ——w- c:\windows\system32\drivers\PxHlpa64.sys 2013-07-10 11:34 . 2012-04-24 07:01 11376 ——w- c:\windows\system32\drivers\cdralw2k.sys 2013-07-10 11:34 . 2012-04-24 07:01 10864 ——w- c:\windows\system32\drivers\cdr4_xp.sys 2013-07-10 11:34 . 2013-07-10 11:34 ——– d—–w- c:\program files (x86)\Common Files\Sonic Shared 2013-07-10 11:34 . 2013-07-10 11:34 ——– d—–w- c:\program files (x86)\Common Files\PX Storage Engine 2013-07-10 11:23 . 2013-05-06 06:03 1887744 —-a-w- c:\windows\system32\WMVDECOD.DLL 2013-07-10 11:23 . 2013-05-06 04:56 1620480 —-a-w- c:\windows\SysWow64\WMVDECOD.DLL 2013-07-10 11:23 . 2013-06-04 06:00 624128 —-a-w- c:\windows\system32\qedit.dll 2013-07-10 11:23 . 2013-06-04 04:53 509440 —-a-w- c:\windows\SysWow64\qedit.dll 2013-07-10 11:23 . 2013-05-27 05:50 1011712 —-a-w- c:\program files\Windows Defender\MpSvc.dll 2013-07-10 11:23 . 2013-05-27 05:50 571904 —-a-w- c:\program files\Windows Defender\MpClient.dll 2013-07-10 11:23 . 2013-05-27 05:50 314880 —-a-w- c:\program files\Windows Defender\MpCommu.dll 2013-07-10 11:23 . 2013-05-27 04:57 4608 —-a-w- c:\program files (x86)\Windows Defender\MsMpLics.dll 2013-07-10 11:23 . 2013-05-27 04:57 54784 —-a-w- c:\program files (x86)\Windows Defender\MpOAV.dll 2013-07-10 11:23 . 2013-05-27 04:57 392704 —-a-w- c:\program files (x86)\Windows Defender\MpClient.dll 2013-07-10 11:23 . 2013-05-27 03:15 9216 —-a-w- c:\program files (x86)\Windows Defender\MpAsDesc.dll 2013-07-10 11:22 . 2013-06-05 03:34 3153920 —-a-w- c:\windows\system32\win32k.sys 2013-07-10 11:22 . 2013-04-10 05:48 1732608 —-a-w- c:\program files\Windows Journal\NBDoc.DLL 2013-07-10 11:22 . 2013-04-10 05:46 1393152 —-a-w- c:\program files\Windows Journal\JNTFiltr.dll 2013-07-10 11:22 . 2013-04-10 05:46 1367040 —-a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll 2013-07-10 11:22 . 2013-04-10 05:46 1402880 —-a-w- c:\program files\Windows Journal\JNWDRV.dll 2013-07-10 11:22 . 2013-04-10 05:03 936448 —-a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll 2013-07-10 11:22 . 2013-04-09 23:34 1247744 —-a-w- c:\windows\SysWow64\DWrite.dll 2013-07-10 11:22 . 2013-04-02 22:51 1643520 —-a-w- c:\windows\system32\DWrite.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-06-24 04:57 . 2012-08-19 17:22 78277128 —-a-w- c:\windows\system32\MRT.exe 2013-06-21 20:40 . 2013-06-21 20:40 1054720 —-a-w- c:\windows\system32\MsSpellCheckingFacility.exe 2013-06-21 20:40 . 2013-06-21 20:40 97280 —-a-w- c:\windows\system32\mshtmled.dll 2013-06-21 20:40 . 2013-06-21 20:40 92160 —-a-w- c:\windows\system32\SetIEInstalledDate.exe 2013-06-21 20:40 . 2013-06-21 20:40 905728 —-a-w- c:\windows\system32\mshtmlmedia.dll 2013-06-21 20:40 . 2013-06-21 20:40 81408 —-a-w- c:\windows\system32\icardie.dll 2013-06-21 20:40 . 2013-06-21 20:40 77312 —-a-w- c:\windows\system32\tdc.ocx 2013-06-21 20:40 . 2013-06-21 20:40 762368 —-a-w- c:\windows\system32\ieapfltr.dll 2013-06-21 20:40 . 2013-06-21 20:40 73728 —-a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2013-06-21 20:40 . 2013-06-21 20:40 719360 —-a-w- c:\windows\SysWow64\mshtmlmedia.dll 2013-06-21 20:40 . 2013-06-21 20:40 62976 —-a-w- c:\windows\system32\pngfilt.dll 2013-06-21 20:40 . 2013-06-21 20:40 61952 —-a-w- c:\windows\SysWow64\tdc.ocx 2013-06-21 20:40 . 2013-06-21 20:40 599552 —-a-w- c:\windows\system32\vbscript.dll 2013-06-21 20:40 . 2013-06-21 20:40 523264 —-a-w- c:\windows\SysWow64\vbscript.dll 2013-06-21 20:40 . 2013-06-21 20:40 52224 —-a-w- c:\windows\system32\msfeedsbs.dll 2013-06-21 20:40 . 2013-06-21 20:40 51200 —-a-w- c:\windows\system32\imgutil.dll 2013-06-21 20:40 . 2013-06-21 20:40 48640 —-a-w- c:\windows\SysWow64\mshtmler.dll 2013-06-21 20:40 . 2013-06-21 20:40 48640 —-a-w- c:\windows\system32\mshtmler.dll 2013-06-21 20:40 . 2013-06-21 20:40 452096 —-a-w- c:\windows\system32\dxtmsft.dll 2013-06-21 20:40 . 2013-06-21 20:40 441856 —-a-w- c:\windows\system32\html.iec 2013-06-21 20:40 . 2013-06-21 20:40 38400 —-a-w- c:\windows\SysWow64\imgutil.dll 2013-06-21 20:40 . 2013-06-21 20:40 361984 —-a-w- c:\windows\SysWow64\html.iec 2013-06-21 20:40 . 2013-06-21 20:40 281600 —-a-w- c:\windows\system32\dxtrans.dll 2013-06-21 20:40 . 2013-06-21 20:40 27648 —-a-w- c:\windows\system32\licmgr10.dll 2013-06-21 20:40 . 2013-06-21 20:40 270848 —-a-w- c:\windows\system32\iedkcs32.dll 2013-06-21 20:40 . 2013-06-21 20:40 247296 —-a-w- c:\windows\system32\webcheck.dll 2013-06-21 20:40 . 2013-06-21 20:40 235008 —-a-w- c:\windows\system32\url.dll 2013-06-21 20:40 . 2013-06-21 20:40 23040 —-a-w- c:\windows\SysWow64\licmgr10.dll 2013-06-21 20:40 . 2013-06-21 20:40 226304 —-a-w- c:\windows\system32\elshyph.dll 2013-06-21 20:40 . 2013-06-21 20:40 216064 —-a-w- c:\windows\system32\msls31.dll 2013-06-21 20:40 . 2013-06-21 20:40 197120 —-a-w- c:\windows\system32\msrating.dll 2013-06-21 20:40 . 2013-06-21 20:40 185344 —-a-w- c:\windows\SysWow64\elshyph.dll 2013-06-21 20:40 . 2013-06-21 20:40 173568 —-a-w- c:\windows\system32\ieUnatt.exe 2013-06-21 20:40 . 2013-06-21 20:40 167424 —-a-w- c:\windows\system32\iexpress.exe 2013-06-21 20:40 . 2013-06-21 20:40 158720 —-a-w- c:\windows\SysWow64\msls31.dll 2013-06-21 20:40 . 2013-06-21 20:40 1509376 —-a-w- c:\windows\system32\inetcpl.cpl 2013-06-21 20:40 . 2013-06-21 20:40 150528 —-a-w- c:\windows\SysWow64\iexpress.exe 2013-06-21 20:40 . 2013-06-21 20:40 149504 —-a-w- c:\windows\system32\occache.dll 2013-06-21 20:40 . 2013-06-21 20:40 144896 —-a-w- c:\windows\system32\wextract.exe 2013-06-21 20:40 . 2013-06-21 20:40 1441280 —-a-w- c:\windows\SysWow64\inetcpl.cpl 2013-06-21 20:40 . 2013-06-21 20:40 1400416 —-a-w- c:\windows\system32\ieapfltr.dat 2013-06-21 20:40 . 2013-06-21 20:40 138752 —-a-w- c:\windows\SysWow64\wextract.exe 2013-06-21 20:40 . 2013-06-21 20:40 13824 —-a-w- c:\windows\system32\mshta.exe 2013-06-21 20:40 . 2013-06-21 20:40 137216 —-a-w- c:\windows\SysWow64\ieUnatt.exe 2013-06-21 20:40 . 2013-06-21 20:40 136192 —-a-w- c:\windows\system32\iepeers.dll 2013-06-21 20:40 . 2013-06-21 20:40 135680 —-a-w- c:\windows\system32\IEAdvpack.dll 2013-06-21 20:40 . 2013-06-21 20:40 12800 —-a-w- c:\windows\SysWow64\mshta.exe 2013-06-21 20:40 . 2013-06-21 20:40 12800 —-a-w- c:\windows\system32\msfeedssync.exe 2013-06-21 20:40 . 2013-06-21 20:40 110592 —-a-w- c:\windows\SysWow64\IEAdvpack.dll 2013-06-21 20:40 . 2013-06-21 20:40 102912 —-a-w- c:\windows\system32\inseng.dll 2013-06-21 11:11 . 2013-06-03 15:28 276256 —-a-w- c:\windows\system32\drivers\DigiartyVirtualCDBus.sys 2013-06-11 19:50 . 2012-08-19 18:52 71048 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-06-11 19:50 . 2012-08-19 18:52 692104 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-05-13 05:51 . 2013-06-12 10:37 184320 —-a-w- c:\windows\system32\cryptsvc.dll 2013-05-13 05:51 . 2013-06-12 10:37 1464320 —-a-w- c:\windows\system32\crypt32.dll 2013-05-13 05:51 . 2013-06-12 10:37 139776 —-a-w- c:\windows\system32\cryptnet.dll 2013-05-13 05:50 . 2013-06-12 10:37 52224 —-a-w- c:\windows\system32\certenc.dll 2013-05-13 04:45 . 2013-06-12 10:37 140288 —-a-w- c:\windows\SysWow64\cryptsvc.dll 2013-05-13 04:45 . 2013-06-12 10:37 1160192 —-a-w- c:\windows\SysWow64\crypt32.dll 2013-05-13 04:45 . 2013-06-12 10:37 103936 —-a-w- c:\windows\SysWow64\cryptnet.dll 2013-05-13 03:43 . 2013-06-12 10:37 1192448 —-a-w- c:\windows\system32\certutil.exe 2013-05-13 03:08 . 2013-06-12 10:37 903168 —-a-w- c:\windows\SysWow64\certutil.exe 2013-05-13 03:08 . 2013-06-12 10:37 43008 —-a-w- c:\windows\SysWow64\certenc.dll 2013-05-10 05:49 . 2013-06-12 10:37 30720 —-a-w- c:\windows\system32\cryptdlg.dll 2013-05-10 03:20 . 2013-06-12 10:37 24576 —-a-w- c:\windows\SysWow64\cryptdlg.dll 2013-05-08 06:39 . 2013-06-12 10:37 1910632 —-a-w- c:\windows\system32\drivers\tcpip.sys 2013-05-02 06:06 . 2010-11-21 03:27 278800 ——w- c:\windows\system32\MpSigStub.exe 2013-04-29 20:48 . 2013-04-29 20:48 163504 —-a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10144.bin 2013-04-26 05:51 . 2013-06-12 10:37 751104 —-a-w- c:\windows\system32\win32spl.dll 2013-04-26 04:55 . 2013-06-12 10:37 492544 —-a-w- c:\windows\SysWow64\win32spl.dll 2013-04-25 23:30 . 2013-06-12 10:37 1505280 —-a-w- c:\windows\SysWow64\d3d11.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "StatBar"="c:\program files (x86)\Globe Software\StatBar\StatBar.exe" [2003-07-25 335872] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "SSBkgdUpdate"="c:\program files (x86)\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472] "OpwareSE4"="c:\program files (x86)\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400] . c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ BUFFALO NAS Navigator2.lnk - c:\program files (x86)\BUFFALO\NASNAVI\NasNavi.exe /startup [2010-8-25 1902048] NAS Scheduler.lnk - c:\program files (x86)\BUFFALO\NASNAVI\nassche.exe [2012-8-23 206128] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R3 DigiartyVirtualCDBus;Digiarty Virtual Driver;c:\windows\system32\drivers\DigiartyVirtualCDBus.sys;c:\windows\SYSNATIVE\drivers\DigiartyVirtualCDBus.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x] S2 AdobeActiveFileMonitor11.0;Adobe Active File Monitor V11;c:\program files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe;c:\program files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe [x] S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [x] S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x] S2 NasPmService;NAS PM Service;c:\program files (x86)\BUFFALO\NASNAVI\nassvc.exe;c:\program files (x86)\BUFFALO\NASNAVI\nassvc.exe [x] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x] S3 dc3d;MS Hardware Device Detection Driver;c:\windows\system32\DRIVERS\dc3d.sys;c:\windows\SYSNATIVE\DRIVERS\dc3d.sys [x] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x] S3 netr28x;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28x.sys;c:\windows\SYSNATIVE\DRIVERS\netr28x.sys [x] S3 Point64;Microsoft Mouse and Keyboard Center Filter Driver;c:\windows\system32\DRIVERS\point64.sys;c:\windows\SYSNATIVE\DRIVERS\point64.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] . . Contents of the 'Scheduled Tasks' folder . 2013-07-24 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-19 19:50] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IntelliType Pro"="c:\program files\Microsoft Mouse and Keyboard Center\itype.exe" [2012-11-02 1464944] "IntelliPoint"="c:\program files\Microsoft Mouse and Keyboard Center\ipoint.exe" [2012-11-02 2076272] "CanonSolutionMenu"="c:\program files (x86)\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-15 644696] . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = about:blank mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~3\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.1.135 75.75.75.75 75.75.76.76 TCP: Interfaces\{982DD18C-CE11-4DEB-84E3-A6A6E6DEAD29}: DhcpNameServer = 192.168.1.135 75.75.75.75 75.75.76.76 FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\iddrhb70.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.cnn.com/ . - - - - ORPHANS REMOVED - - - - . BHO-{71FD612F-034A-B6E5-9A53-70282A57076C} - c:\programdata\Zoomex\50e309218bdfb.dll BHO-{E78E4949-965A-23B9-075E-FB733D83D01D} - (no file) AddRemove-Exact Audio Copy - c:\program files (x86)\Exact Audio Copy\uninst.exe AddRemove-ImgBurn - c:\program files (x86)\ImgBurn\uninstall.exe AddRemove-SP_5dec30d7 - c:\program files (x86)\ZoomEx\uninstall.exe AddRemove-{53820F89-063F-10D7-7457-06C201F4CBF0} - c:\programdata\Zoomex\uninstall.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2013-07-24 06:53:57 ComboFix-quarantined-files.txt 2013-07-24 10:53 ComboFix2.txt 2013-07-23 14:21 ComboFix3.txt 2013-07-23 14:06 . Pre-Run: 400,616,484,864 bytes free Post-Run: 400,278,831,104 bytes free . - - End Of File - - FEA5E2FC0FF870AEAEB6A7EE1DA3EB87 A36C5E4F47E84449FF07ED3517B43A31
Here are the results from Malwarebytes Anti-Malware: Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Database version: v2013.07.24.04 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16635 Owner :: OWNER-PC [administrator] 7/24/2013 7:36:26 AM mbam-log-2013-07-24 (07-36-26).txt Scan type: Full scan (C:\|D:\|E:\|) Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 405339 Time elapsed: 35 minute(s), 52 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)
Scan with ESET Online Scan

Please go to here to run the online scannner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked
  • Click on Advanced Settings and ensure these options are ticked:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Click Scan
  • Wait for the scan to finish
  • If any threats were found, click the 'List of found threats' , then click Export to text file….
  • Save it to your desktop, then please copy and paste that log as a reply to this topic.
Marius - here are the results from the EST On-line scan: C:\ProgramData\Premium\ZoomEx\run953A.tmp Win32/GenUpdater application C:\Qoobox\Quarantine\C\ProgramData\Zoomex\50e309218bdfb.dll.vir Win32/Adware.MultiPlug.G application C:\Qoobox\Quarantine\C\ProgramData\Zoomex\oapikbmhhnkcdkakfpddfpenfjfcojen.crx.vir Win32/Adware.MultiPlug.H application C:\Qoobox\Quarantine\C\ProgramData\Zoomex\settings.ini.vir Win32/Adware.MultiPlug.F application C:\Qoobox\Quarantine\C\PROGRA~2\ZoomEx\sprotector.dll.vir Win32/SProtector.A application C:\Users\All Users\Premium\ZoomEx\run953A.tmp Win32/GenUpdater application C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\keammfpldbfmgllfliepgdpoboocoeie\1\510bae4baede03.42203859.js Win32/Adware.MultiPlug.H application C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\loihdcgfdfchcdpaonlpdfpbjlkjgeag\1\510baecfd73ea1.32631836.js Win32/Adware.MultiPlug.H application C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\oapikbmhhnkcdkakfpddfpenfjfcojen\3.2_0\50e309218bbd77.15569009.js Win32/Adware.MultiPlug.H application C:\Users\Owner\AppData\Local\Torch\User Data\Default\Extensions\oapikbmhhnkcdkakfpddfpenfjfcojen\3.2_0\50e309218bbd77.15569009.js Win32/Adware.MultiPlug.H application C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\iddrhb70.default\extensions\[removed]\content\bg.js Win32/Adware.MultiPlug.H application
Combofix

Combofix should only be run when adviced by a team member!

Link


Important - Save the file to your desktop!


  • Deactivate any and all of your antivirus programs /spyware scanners - they can prevent CF from doing its work.
  • Run Combofix.exe

When finished, Combofix creates a log file named C:\Combofix.txt. Please post its content in your next reply.

Note: When receiving an error message containing ""Illegal operation attempted on a registry key that has been marked for deletion" simply restart your computer to fix this.




Then we can do the cleanup - if you are facing any issues, report that immediately.

Delete junk with adwCleaner


Please download AdwCleaner to your desktop.


  • Run adwcleaner.exe.
  • Hit delete.
  • When the run is finished, it will open up a text file.
  • Please post its contents within your next reply.
  • You´ll find the log file at C:\AdwCleaner[S1].txt also.

SecurityCheck

Please download SecurityCheck: LINK1 LINK2

  • Save it to your desktop, start it and follow the instructions in the window.
  • After the scan finished the (checkup.txt) will open. Copy its content to your thread.

Attachments:

Marius - this is the report from the ComboFix run that just completed. I am going to run the adwCleaner now. ComboFix 13-07-24.03 - Owner 07/25/2013 7:37.4.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.6143.4698 [GMT -4:00] Running from: c:\users\[removed]\Downloads\ComboFix.exe SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((( Files Created from 2013-06-25 to 2013-07-25 ))))))))))))))))))))))))))))))) . . 2013-07-25 11:44 . 2013-07-25 11:44 ——– d—–w- c:\users\UpdatusUser\AppData\Local\temp 2013-07-25 11:44 . 2013-07-25 11:44 ——– d—–w- c:\users\Default\AppData\Local\temp 2013-07-23 11:54 . 2013-07-02 08:34 9460976 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{95A92BB6-97E2-47F4-B629-3EAEECF4D03C}\mpengine.dll 2013-07-22 19:10 . 2013-07-22 19:10 ——– d—–w- c:\program files (x86)\FileHippo.com 2013-07-22 14:52 . 2013-07-22 17:02 ——– d—–w- c:\program files (x86)\Mozilla Thunderbird 2013-07-11 11:19 . 2013-07-11 11:19 ——– d—–w- c:\programdata\regid.1986-12.com.adobe 2013-07-10 11:39 . 2013-07-10 11:39 ——– d—–w- c:\program files\Common Files\Adobe 2013-07-10 11:34 . 2012-08-10 07:01 56336 ——w- c:\windows\system32\drivers\PxHlpa64.sys 2013-07-10 11:34 . 2012-04-24 07:01 11376 ——w- c:\windows\system32\drivers\cdralw2k.sys 2013-07-10 11:34 . 2012-04-24 07:01 10864 ——w- c:\windows\system32\drivers\cdr4_xp.sys 2013-07-10 11:34 . 2013-07-10 11:34 ——– d—–w- c:\program files (x86)\Common Files\Sonic Shared 2013-07-10 11:34 . 2013-07-10 11:34 ——– d—–w- c:\program files (x86)\Common Files\PX Storage Engine 2013-07-10 11:23 . 2013-05-06 06:03 1887744 —-a-w- c:\windows\system32\WMVDECOD.DLL 2013-07-10 11:23 . 2013-05-06 04:56 1620480 —-a-w- c:\windows\SysWow64\WMVDECOD.DLL 2013-07-10 11:23 . 2013-06-04 06:00 624128 —-a-w- c:\windows\system32\qedit.dll 2013-07-10 11:23 . 2013-06-04 04:53 509440 —-a-w- c:\windows\SysWow64\qedit.dll 2013-07-10 11:23 . 2013-05-27 05:50 1011712 —-a-w- c:\program files\Windows Defender\MpSvc.dll 2013-07-10 11:23 . 2013-05-27 05:50 571904 —-a-w- c:\program files\Windows Defender\MpClient.dll 2013-07-10 11:23 . 2013-05-27 05:50 314880 —-a-w- c:\program files\Windows Defender\MpCommu.dll 2013-07-10 11:23 . 2013-05-27 04:57 4608 —-a-w- c:\program files (x86)\Windows Defender\MsMpLics.dll 2013-07-10 11:23 . 2013-05-27 04:57 54784 —-a-w- c:\program files (x86)\Windows Defender\MpOAV.dll 2013-07-10 11:23 . 2013-05-27 04:57 392704 —-a-w- c:\program files (x86)\Windows Defender\MpClient.dll 2013-07-10 11:23 . 2013-05-27 03:15 9216 —-a-w- c:\program files (x86)\Windows Defender\MpAsDesc.dll 2013-07-10 11:22 . 2013-06-05 03:34 3153920 —-a-w- c:\windows\system32\win32k.sys 2013-07-10 11:22 . 2013-04-10 05:48 1732608 —-a-w- c:\program files\Windows Journal\NBDoc.DLL 2013-07-10 11:22 . 2013-04-10 05:46 1393152 —-a-w- c:\program files\Windows Journal\JNTFiltr.dll 2013-07-10 11:22 . 2013-04-10 05:46 1367040 —-a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll 2013-07-10 11:22 . 2013-04-10 05:46 1402880 —-a-w- c:\program files\Windows Journal\JNWDRV.dll 2013-07-10 11:22 . 2013-04-10 05:03 936448 —-a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll 2013-07-10 11:22 . 2013-04-09 23:34 1247744 —-a-w- c:\windows\SysWow64\DWrite.dll 2013-07-10 11:22 . 2013-04-02 22:51 1643520 —-a-w- c:\windows\system32\DWrite.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-06-24 04:57 . 2012-08-19 17:22 78277128 —-a-w- c:\windows\system32\MRT.exe 2013-06-21 20:40 . 2013-06-21 20:40 1054720 —-a-w- c:\windows\system32\MsSpellCheckingFacility.exe 2013-06-21 20:40 . 2013-06-21 20:40 97280 —-a-w- c:\windows\system32\mshtmled.dll 2013-06-21 20:40 . 2013-06-21 20:40 92160 —-a-w- c:\windows\system32\SetIEInstalledDate.exe 2013-06-21 20:40 . 2013-06-21 20:40 905728 —-a-w- c:\windows\system32\mshtmlmedia.dll 2013-06-21 20:40 . 2013-06-21 20:40 81408 —-a-w- c:\windows\system32\icardie.dll 2013-06-21 20:40 . 2013-06-21 20:40 77312 —-a-w- c:\windows\system32\tdc.ocx 2013-06-21 20:40 . 2013-06-21 20:40 762368 —-a-w- c:\windows\system32\ieapfltr.dll 2013-06-21 20:40 . 2013-06-21 20:40 73728 —-a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2013-06-21 20:40 . 2013-06-21 20:40 719360 —-a-w- c:\windows\SysWow64\mshtmlmedia.dll 2013-06-21 20:40 . 2013-06-21 20:40 62976 —-a-w- c:\windows\system32\pngfilt.dll 2013-06-21 20:40 . 2013-06-21 20:40 61952 —-a-w- c:\windows\SysWow64\tdc.ocx 2013-06-21 20:40 . 2013-06-21 20:40 599552 —-a-w- c:\windows\system32\vbscript.dll 2013-06-21 20:40 . 2013-06-21 20:40 523264 —-a-w- c:\windows\SysWow64\vbscript.dll 2013-06-21 20:40 . 2013-06-21 20:40 52224 —-a-w- c:\windows\system32\msfeedsbs.dll 2013-06-21 20:40 . 2013-06-21 20:40 51200 —-a-w- c:\windows\system32\imgutil.dll 2013-06-21 20:40 . 2013-06-21 20:40 48640 —-a-w- c:\windows\SysWow64\mshtmler.dll 2013-06-21 20:40 . 2013-06-21 20:40 48640 —-a-w- c:\windows\system32\mshtmler.dll 2013-06-21 20:40 . 2013-06-21 20:40 452096 —-a-w- c:\windows\system32\dxtmsft.dll 2013-06-21 20:40 . 2013-06-21 20:40 441856 —-a-w- c:\windows\system32\html.iec 2013-06-21 20:40 . 2013-06-21 20:40 38400 —-a-w- c:\windows\SysWow64\imgutil.dll 2013-06-21 20:40 . 2013-06-21 20:40 361984 —-a-w- c:\windows\SysWow64\html.iec 2013-06-21 20:40 . 2013-06-21 20:40 281600 —-a-w- c:\windows\system32\dxtrans.dll 2013-06-21 20:40 . 2013-06-21 20:40 27648 —-a-w- c:\windows\system32\licmgr10.dll 2013-06-21 20:40 . 2013-06-21 20:40 270848 —-a-w- c:\windows\system32\iedkcs32.dll 2013-06-21 20:40 . 2013-06-21 20:40 247296 —-a-w- c:\windows\system32\webcheck.dll 2013-06-21 20:40 . 2013-06-21 20:40 235008 —-a-w- c:\windows\system32\url.dll 2013-06-21 20:40 . 2013-06-21 20:40 23040 —-a-w- c:\windows\SysWow64\licmgr10.dll 2013-06-21 20:40 . 2013-06-21 20:40 226304 —-a-w- c:\windows\system32\elshyph.dll 2013-06-21 20:40 . 2013-06-21 20:40 216064 —-a-w- c:\windows\system32\msls31.dll 2013-06-21 20:40 . 2013-06-21 20:40 197120 —-a-w- c:\windows\system32\msrating.dll 2013-06-21 20:40 . 2013-06-21 20:40 185344 —-a-w- c:\windows\SysWow64\elshyph.dll 2013-06-21 20:40 . 2013-06-21 20:40 173568 —-a-w- c:\windows\system32\ieUnatt.exe 2013-06-21 20:40 . 2013-06-21 20:40 167424 —-a-w- c:\windows\system32\iexpress.exe 2013-06-21 20:40 . 2013-06-21 20:40 158720 —-a-w- c:\windows\SysWow64\msls31.dll 2013-06-21 20:40 . 2013-06-21 20:40 1509376 —-a-w- c:\windows\system32\inetcpl.cpl 2013-06-21 20:40 . 2013-06-21 20:40 150528 —-a-w- c:\windows\SysWow64\iexpress.exe 2013-06-21 20:40 . 2013-06-21 20:40 149504 —-a-w- c:\windows\system32\occache.dll 2013-06-21 20:40 . 2013-06-21 20:40 144896 —-a-w- c:\windows\system32\wextract.exe 2013-06-21 20:40 . 2013-06-21 20:40 1441280 —-a-w- c:\windows\SysWow64\inetcpl.cpl 2013-06-21 20:40 . 2013-06-21 20:40 1400416 —-a-w- c:\windows\system32\ieapfltr.dat 2013-06-21 20:40 . 2013-06-21 20:40 138752 —-a-w- c:\windows\SysWow64\wextract.exe 2013-06-21 20:40 . 2013-06-21 20:40 13824 —-a-w- c:\windows\system32\mshta.exe 2013-06-21 20:40 . 2013-06-21 20:40 137216 —-a-w- c:\windows\SysWow64\ieUnatt.exe 2013-06-21 20:40 . 2013-06-21 20:40 136192 —-a-w- c:\windows\system32\iepeers.dll 2013-06-21 20:40 . 2013-06-21 20:40 135680 —-a-w- c:\windows\system32\IEAdvpack.dll 2013-06-21 20:40 . 2013-06-21 20:40 12800 —-a-w- c:\windows\SysWow64\mshta.exe 2013-06-21 20:40 . 2013-06-21 20:40 12800 —-a-w- c:\windows\system32\msfeedssync.exe 2013-06-21 20:40 . 2013-06-21 20:40 110592 —-a-w- c:\windows\SysWow64\IEAdvpack.dll 2013-06-21 20:40 . 2013-06-21 20:40 102912 —-a-w- c:\windows\system32\inseng.dll 2013-06-21 11:11 . 2013-06-03 15:28 276256 —-a-w- c:\windows\system32\drivers\DigiartyVirtualCDBus.sys 2013-06-11 19:50 . 2012-08-19 18:52 71048 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-06-11 19:50 . 2012-08-19 18:52 692104 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-05-13 05:51 . 2013-06-12 10:37 184320 —-a-w- c:\windows\system32\cryptsvc.dll 2013-05-13 05:51 . 2013-06-12 10:37 1464320 —-a-w- c:\windows\system32\crypt32.dll 2013-05-13 05:51 . 2013-06-12 10:37 139776 —-a-w- c:\windows\system32\cryptnet.dll 2013-05-13 05:50 . 2013-06-12 10:37 52224 —-a-w- c:\windows\system32\certenc.dll 2013-05-13 04:45 . 2013-06-12 10:37 140288 —-a-w- c:\windows\SysWow64\cryptsvc.dll 2013-05-13 04:45 . 2013-06-12 10:37 1160192 —-a-w- c:\windows\SysWow64\crypt32.dll 2013-05-13 04:45 . 2013-06-12 10:37 103936 —-a-w- c:\windows\SysWow64\cryptnet.dll 2013-05-13 03:43 . 2013-06-12 10:37 1192448 —-a-w- c:\windows\system32\certutil.exe 2013-05-13 03:08 . 2013-06-12 10:37 903168 —-a-w- c:\windows\SysWow64\certutil.exe 2013-05-13 03:08 . 2013-06-12 10:37 43008 —-a-w- c:\windows\SysWow64\certenc.dll 2013-05-10 05:49 . 2013-06-12 10:37 30720 —-a-w- c:\windows\system32\cryptdlg.dll 2013-05-10 03:20 . 2013-06-12 10:37 24576 —-a-w- c:\windows\SysWow64\cryptdlg.dll 2013-05-08 06:39 . 2013-06-12 10:37 1910632 —-a-w- c:\windows\system32\drivers\tcpip.sys 2013-05-02 06:06 . 2010-11-21 03:27 278800 ——w- c:\windows\system32\MpSigStub.exe 2013-04-29 20:48 . 2013-04-29 20:48 163504 —-a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10144.bin . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{71FD612F-034A-B6E5-9A53-70282A57076C}] c:\programdata\Zoomex\50e309218bdfb.dll [BU] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "StatBar"="c:\program files (x86)\Globe Software\StatBar\StatBar.exe" [2003-07-25 335872] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "SSBkgdUpdate"="c:\program files (x86)\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472] "OpwareSE4"="c:\program files (x86)\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400] . c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ BUFFALO NAS Navigator2.lnk - c:\program files (x86)\BUFFALO\NASNAVI\NasNavi.exe /startup [2010-8-25 1902048] NAS Scheduler.lnk - c:\program files (x86)\BUFFALO\NASNAVI\nassche.exe [2012-8-23 206128] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R3 DigiartyVirtualCDBus;Digiarty Virtual Driver;c:\windows\system32\drivers\DigiartyVirtualCDBus.sys;c:\windows\SYSNATIVE\drivers\DigiartyVirtualCDBus.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x] S2 AdobeActiveFileMonitor11.0;Adobe Active File Monitor V11;c:\program files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe;c:\program files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe [x] S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [x] S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x] S2 NasPmService;NAS PM Service;c:\program files (x86)\BUFFALO\NASNAVI\nassvc.exe;c:\program files (x86)\BUFFALO\NASNAVI\nassvc.exe [x] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x] S3 dc3d;MS Hardware Device Detection Driver;c:\windows\system32\DRIVERS\dc3d.sys;c:\windows\SYSNATIVE\DRIVERS\dc3d.sys [x] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x] S3 netr28x;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28x.sys;c:\windows\SYSNATIVE\DRIVERS\netr28x.sys [x] S3 Point64;Microsoft Mouse and Keyboard Center Filter Driver;c:\windows\system32\DRIVERS\point64.sys;c:\windows\SYSNATIVE\DRIVERS\point64.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] . . Contents of the 'Scheduled Tasks' folder . 2013-07-25 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-19 19:50] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IntelliType Pro"="c:\program files\Microsoft Mouse and Keyboard Center\itype.exe" [2012-11-02 1464944] "IntelliPoint"="c:\program files\Microsoft Mouse and Keyboard Center\ipoint.exe" [2012-11-02 2076272] "CanonSolutionMenu"="c:\program files (x86)\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-15 644696] . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = about:blank mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~3\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.1.135 75.75.75.75 75.75.76.76 TCP: Interfaces\{982DD18C-CE11-4DEB-84E3-A6A6E6DEAD29}: DhcpNameServer = 192.168.1.135 75.75.75.75 75.75.76.76 FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\iddrhb70.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.cnn.com/ . - - - - ORPHANS REMOVED - - - - . BHO-{E78E4949-965A-23B9-075E-FB733D83D01D} - (no file) AddRemove-Exact Audio Copy - c:\program files (x86)\Exact Audio Copy\uninst.exe AddRemove-ImgBurn - c:\program files (x86)\ImgBurn\uninstall.exe AddRemove-SP_5dec30d7 - c:\program files (x86)\ZoomEx\uninstall.exe AddRemove-{53820F89-063F-10D7-7457-06C201F4CBF0} - c:\programdata\Zoomex\uninstall.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2013-07-25 07:52:03 ComboFix-quarantined-files.txt 2013-07-25 11:52 ComboFix2.txt 2013-07-24 10:54 ComboFix3.txt 2013-07-23 14:21 ComboFix4.txt 2013-07-23 14:06 . Pre-Run: 400,118,140,928 bytes free Post-Run: 402,857,746,432 bytes free . - - End Of File - - 5CBE167DB9EBC1490D12091B356135DD A36C5E4F47E84449FF07ED3517B43A31
Marius - here are the results from adwCleaner: # AdwCleaner v2.306 - Logfile created 07/25/2013 at 07:59:12 # Updated 19/07/2013 by Xplode # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits) # User : Owner - OWNER-PC # Boot Mode : Normal # Running from : C:\Users\Owner\Downloads\adwcleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** File Deleted : C:\END File Deleted : C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\iddrhb70.default\searchplugins\Searchab.xml Folder Deleted : C:\Program Files (x86)\Conduit Folder Deleted : C:\Program Files (x86)\Coupon Companion Plugin Folder Deleted : C:\ProgramData\clsoft ltd Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zoomex Folder Deleted : C:\ProgramData\Premium Folder Deleted : C:\Users\Owner\AppData\Local\Coupon Companion Plugin Folder Deleted : C:\Users\Owner\AppData\LocalLow\Conduit Folder Deleted : C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\iddrhb70.default\CT3272718 Folder Deleted : C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\iddrhb70.default\extensions\{c0c2693d-2ee8-47b4-9df7-b67a0ee31988} Folder Deleted : C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\iddrhb70.default\jetpack Folder Deleted : C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\iddrhb70.default\Smartbar ***** [Registry] ***** Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar Key Deleted : HKCU\Software\AppDataLow\SProtector Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\grusskartencenter.com Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\grusskartencenter.com Key Deleted : HKCU\Software\PrivitizeVPNInstallDates Key Deleted : HKCU\Software\StartSearch Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3272718 Key Deleted : HKLM\Software\Conduit Key Deleted : HKLM\Software\SP Global Key Deleted : HKLM\Software\SProtector Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{71FD612F-034A-B6E5-9A53-70282A57076C} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{71FD612F-034A-B6E5-9A53-70282A57076C} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E78E4949-965A-23B9-075E-FB733D83D01D} ***** [Internet Browsers] ***** -\\ Internet Explorer v10.0.9200.16635 [OK] Registry is clean. -\\ Mozilla Firefox v22.0 (en-US) File : C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\iddrhb70.default\prefs.js Deleted : user_pref("CT3272718.1000082.isPlayDisplay", "true"); Deleted : user_pref("CT3272718.1000082.state", "{\"state\":\"stopped\",\"text\":\"Californi…\",\"description[…] Deleted : user_pref("CT3272718.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}"); Deleted : user_pref("CT3272718.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"tru[…] Deleted : user_pref("CT3272718.FirstTime", "true"); Deleted : user_pref("CT3272718.FirstTimeFF3", "true"); Deleted : user_pref("CT3272718.LAST_CLIENT_STATS_SUBMIT_2.enc", "MTM2MDUyMzMxOQ=="); Deleted : user_pref("CT3272718.LOCAL_COOKIE_STATS_LAST_SUBMIT_6.enc", "MTM2MDUyMzMyMw=="); Deleted : user_pref("CT3272718.LOCAL_COOKIE_STATS_STATS_SITE_IRRELEVANT.enc", "Mg=="); Deleted : user_pref("CT3272718.LOCAL_COOKIE_STATS_STATS_SITE_SUPPORTED.enc", "MQ=="); Deleted : user_pref("CT3272718.LoginRevertSettingsEnabled", true); Deleted : user_pref("CT3272718.PG_ENABLE", "dHJ1ZQ=="); Deleted : user_pref("CT3272718.PG_ENABLE.enc", "dHJ1ZQ=="); Deleted : user_pref("CT3272718.RevertSettingsEnabled", true); Deleted : user_pref("CT3272718.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT327[…] Deleted : user_pref("CT3272718.TopHitsConfig.enc", "ew0KICAgICJzcHJpdGVVcmwiOiAiaHR0cDovL2NhcDEuY29uZHVpdC1hcH[…] Deleted : user_pref("CT3272718.UserID", "UN97115770330297288"); Deleted : user_pref("CT3272718.YTbyClickFavorites.enc", "W10="); Deleted : user_pref("CT3272718.YTbyClickRecent.enc", "W10="); Deleted : user_pref("CT3272718.acp_personal.appstate.enc", "ZW5hYmxl"); Deleted : user_pref("CT3272718.addressBarTakeOverEnabledInHidden", "true"); Deleted : user_pref("CT3272718.autoDisableScopes", -1); Deleted : user_pref("CT3272718.browser.search.defaultthis.engineName", "true"); Deleted : user_pref("CT3272718.cbfirsttime.enc", "U3VuIEZlYiAxMCAyMDEzIDE0OjA0OjIxIEdNVC0wNTAwIChFYXN0ZXJuIFN0[…] Deleted : user_pref("CT3272718.defaultSearch", "true"); Deleted : user_pref("CT3272718.enableAlerts", "always"); Deleted : user_pref("CT3272718.enableFix404ByUser", "FALSE"); Deleted : user_pref("CT3272718.enableSearchFromAddressBar", "true"); Deleted : user_pref("CT3272718.firstTimeDialogOpened", "true"); Deleted : user_pref("CT3272718.fixPageNotFoundError", "true"); Deleted : user_pref("CT3272718.fixPageNotFoundErrorByUser", "true"); Deleted : user_pref("CT3272718.fixPageNotFoundErrorInHidden", "true"); Deleted : user_pref("CT3272718.fixUrls", true); Deleted : user_pref("CT3272718.homepageuserchanged", true); Deleted : user_pref("CT3272718.installDate", "9/2/2013 7:53:35"); Deleted : user_pref("CT3272718.installId", "aaa_cid119"); Deleted : user_pref("CT3272718.installType", "conduitnsisintegration"); Deleted : user_pref("CT3272718.isCheckedStartAsHidden", true); Deleted : user_pref("CT3272718.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}"); Deleted : user_pref("CT3272718.isFirstTimeToolbarLoading", "false"); Deleted : user_pref("CT3272718.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}"); Deleted : user_pref("CT3272718.keyword", "true"); Deleted : user_pref("CT3272718.lastNewTabSettings", "{\"isEnabled\":false,\"newTabUrl\":\"hxxp://search.condui[…] Deleted : user_pref("CT3272718.lastVersion", "10.14.65.43"); Deleted : user_pref("CT3272718.mam_gk_ACplus_appState.enc", "b24="); Deleted : user_pref("CT3272718.mam_gk_CouponBuddy_appState.enc", "b24="); Deleted : user_pref("CT3272718.mam_gk_PriceGong_appState.enc", "b24="); Deleted : user_pref("CT3272718.mam_gk_appsData.enc", "eyJhcHBzIjpbeyJpZCI6IlByaWNlR29uZyIsInVybCI6Imh0dHA6Ly9w[…] Deleted : user_pref("CT3272718.mam_gk_appsDefaultEnabled.enc", "bnVsbA=="); Deleted : user_pref("CT3272718.mam_gk_configuration.enc", "eyJjb25maWd1cmF0aW9uIjpbeyJpZCI6IlByaWNlR29uZyIsImN[…] Deleted : user_pref("CT3272718.mam_gk_currentVersion.enc", "MS4yLjAuMTI="); Deleted : user_pref("CT3272718.mam_gk_eventsCache.enc", "eyJmN2VkNzJiMi00ZDAyLTQyNTMtOWVjYi1iNzgwMzQ2YzU4MzkiO[…] Deleted : user_pref("CT3272718.mam_gk_first_time.enc", "MQ=="); Deleted : user_pref("CT3272718.mam_gk_gadgetOpen.enc", "MQ=="); Deleted : user_pref("CT3272718.mam_gk_installer_preapproved.enc", "ZmFsc2U="); Deleted : user_pref("CT3272718.mam_gk_lastLoginTime.enc", "MTM2MDUyMzA1MjQ0Nw=="); Deleted : user_pref("CT3272718.mam_gk_localization.enc", "eyJnYWRnZXRDb250ZW50UG9saWN5Ijp7IlRleHQiOiJDb250ZW50[…] Deleted : user_pref("CT3272718.mam_gk_pgUnloadedOnce.enc", "dHJ1ZQ=="); Deleted : user_pref("CT3272718.mam_gk_settings1.2.0.12.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImludGVy[…] Deleted : user_pref("CT3272718.mam_gk_showCloseButton.enc", "dHJ1ZQ=="); Deleted : user_pref("CT3272718.mam_gk_showWelcomeGadget.enc", "ZmFsc2U="); Deleted : user_pref("CT3272718.mam_gk_userId.enc", "Njg3ZWNjNjEtMjdkNy00ZDJmLWIwNTktMjgxMmM4MmVmYmMy"); Deleted : user_pref("CT3272718.mam_gk_user_apps_selection.enc", ""); Deleted : user_pref("CT3272718.migrateAppsAndComponents", true); Deleted : user_pref("CT3272718.navigationAliasesJson", "{\"EB_SEARCH_TERM\":\"\",\"EB_MAIN_FRAME_URL\":\"about[…] Deleted : user_pref("CT3272718.openThankYouPage", "false"); Deleted : user_pref("CT3272718.openUninstallPage", "true"); Deleted : user_pref("CT3272718.revertSettingsEnabled", "false"); Deleted : user_pref("CT3272718.search.searchAppId", "130004885110157816"); Deleted : user_pref("CT3272718.search.searchCount", "0"); Deleted : user_pref("CT3272718.searchInNewTabEnabledByUser", "true"); Deleted : user_pref("CT3272718.searchInNewTabEnabledInHidden", "true"); Deleted : user_pref("CT3272718.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}"); Deleted : user_pref("CT3272718.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"d[…] Deleted : user_pref("CT3272718.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\[…] Deleted : user_pref("CT3272718.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"d[…] Deleted : user_pref("CT3272718.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"strin[…] Deleted : user_pref("CT3272718.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"strin[…] Deleted : user_pref("CT3272718.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data[…] Deleted : user_pref("CT3272718.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1360523048194"); Deleted : user_pref("CT3272718.serviceLayer_services_appsMetadata_lastUpdate", "1360523048097"); Deleted : user_pref("CT3272718.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1360523047959"); Deleted : user_pref("CT3272718.serviceLayer_services_login_10.14.42.7_lastUpdate", "1360690672189"); Deleted : user_pref("CT3272718.serviceLayer_services_login_10.14.65.43_lastUpdate", "1360703216111"); Deleted : user_pref("CT3272718.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1360523047901"); Deleted : user_pref("CT3272718.serviceLayer_services_searchAPI_lastUpdate", "1360523037386"); Deleted : user_pref("CT3272718.serviceLayer_services_serviceMap_lastUpdate", "1360676270263"); Deleted : user_pref("CT3272718.serviceLayer_services_toolbarContextMenu_lastUpdate", "1360523047846"); Deleted : user_pref("CT3272718.serviceLayer_services_toolbarSettings_lastUpdate", "1360697871132"); Deleted : user_pref("CT3272718.serviceLayer_services_translation_lastUpdate", "1360676270638"); Deleted : user_pref("CT3272718.settingsINI", true); Deleted : user_pref("CT3272718.shouldFirstTimeDialog", "false"); Deleted : user_pref("CT3272718.smartbar.CTID", "CT3272718"); Deleted : user_pref("CT3272718.smartbar.Uninstall", "0"); Deleted : user_pref("CT3272718.smartbar.homepage", "true"); Deleted : user_pref("CT3272718.smartbar.isHidden", true); Deleted : user_pref("CT3272718.smartbar.toolbarName", "MixiDJ "); Deleted : user_pref("CT3272718.startPage", "true"); Deleted : user_pref("CT3272718.toolbarBornServerTime", "10-2-2013"); Deleted : user_pref("CT3272718.toolbarCurrentServerTime", "13-2-2013"); Deleted : user_pref("CT3272718.toolbarDisabled", "true"); Deleted : user_pref("CT3272718.url_history0001.enc", "aHR0cHM6Ly93d3cuZ29vZ2xlLmNvbTo6OmNsaWNraGFuZGxlcjo6OjEz[…] Deleted : user_pref("CT3272718_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\"[…] Deleted : user_pref("Smartbar.ConduitHomepagesList", ""); Deleted : user_pref("Smartbar.ConduitSearchEngineList", ""); Deleted : user_pref("Smartbar.ConduitSearchUrlList", ""); Deleted : user_pref("Smartbar.SearchFromAddressBarSavedUrl", "hxxp://searchab.com/?aff=7&uid=28b827a3-542a-11e[…] Deleted : user_pref("Smartbar.keywordURLSelectedCTID", "CT3272718"); Deleted : user_pref("aol_toolbar.default.homepage.check", false); Deleted : user_pref("aol_toolbar.default.search.check", false); Deleted : user_pref("browser.search.defaultthis.engineName", "MixiDJ Customized Web Search"); Deleted : user_pref("ct3272718.UserID", "UN97115770330297288"); Deleted : user_pref("extensions.50e309218bd17.scode", "(function(){try{if('aol.com,mail.google.com,premiumrepo[…] Deleted : user_pref("extensions.BabylonToolbar.prtkDS", 0); Deleted : user_pref("extensions.BabylonToolbar.prtkHmpg", 0); Deleted : user_pref("smartbar.conduitHomepageList", "hxxp://search.conduit.com/?ctid=CT3272718&SearchSource=13[…] Deleted : user_pref("smartbar.conduitSearchAddressUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT[…] Deleted : user_pref("smartbar.machineId", "ACKS/UL7VJYEBPCVUEPUOH7VEJI67ZORVPHKS4JBQ3IIBWH98PM8USG1HBL8BRIFXX1[…] Deleted : user_pref("smartbar.originalHomepage", "hxxp://www.cnn.com/"); Deleted : user_pref("smartbar.originalSearchAddressUrl", "hxxp://searchab.com/?aff=7&uid=28b827a3-542a-11e2-96[…] Deleted : user_pref("smartbar.originalSearchEngine", "Google"); Deleted : user_pref("surfcanyon.inst_id", "39780631138443623031348751843405354"); Deleted : user_pref("surfcanyon.inst_timestamp", "1355499129820"); Deleted : user_pref("surfcanyon.last_seen_splash", "343"); Deleted : user_pref("surfcanyon.partner_code", "MZ"); Deleted : user_pref("sweetim.toolbar.previous.browser.search.defaultenginename", ""); Deleted : user_pref("sweetim.toolbar.previous.browser.search.selectedEngine", ""); Deleted : user_pref("sweetim.toolbar.previous.browser.startup.homepage", ""); Deleted : user_pref("sweetim.toolbar.previous.keyword.URL", ""); Deleted : user_pref("sweetim.toolbar.scripts.1.domain-blacklist", ".*"); Deleted : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_DS", "1"); Deleted : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_HP", "1"); Deleted : user_pref("sweetim.toolbar.searchguard.enable", "false"); -\\ Google Chrome v [Unable to get version] File : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] File is clean. ************************* AdwCleaner[S1].txt - [13804 octets] - [25/07/2013 07:59:12] ########## EOF - C:\AdwCleaner[S1].txt - [13865 octets] ##########
And this is the Security Check:

Results of screen317's Security Check version 0.99.71
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 10
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Disabled!
Kaspersky PURE 3.0
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware version 1.75.0.1300
JavaFX 2.1.1
Java version out of Date!
Adobe Flash Player 11.7.700.224
Adobe Reader XI
Mozilla Firefox (22.0)
Mozilla Thunderbird (17.0.7)
````````Process Check: objlist.exe by Laurent````````
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbamgui.exe
Malwarebytes' Anti-Malware mbamscheduler.exe
Kaspersky Lab Kaspersky PURE 3.0 avp.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 0%
````````````````````End of Log``````````````````````
Rats, I´ve posted the wrong instructions:


Combofix scripting

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Download the attached CFScript.txt and save it to the location where Combofix is.


[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

Attachments:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI