This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Malware on the computer, Windows Services Integrity seems compromised

28 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi. I think I have some kind of malware on my netbook (Windows 7 Starter Edition). My computer had been running very slowly and Internet Explorer and ITunes kept failing. A friend gave me a usb with some virus and malware scanning programs that she said I should run. When I plugged the usb in and put the programs on my computer, my Symantec blocked some orphan autorun thing. I ran RKill that detected some things, some Proxy Settings things and Windows Service Integrity issues. As I continued to run the other programs, the problem just got worse, to the point that I couldn't leave Google page on the internet. I did a System Restore to an earlier point in time and deleted some of the programs I was given to run and now the internet is working but I think I lost my D: drive in the process, and Malware-Bytes continues to find and delete PUPs but RKill continues to show Windows Service Integrity issues. I am also concerned with a suspicious Adobe Update message. When I hit it to update Adobe to get rid of the message, a window came up that I didn't remember ever seeing when I updated Adobe in the past, so I didn't update. I don't know what I have or don't have on the computer so I don't want to do anything at this point without some guidance. I would greatly appreciate some help.
Hi and Welcome!! acsant :)

My name is Robybel.

I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.


Vista and Windows 7 users:

These tools MUST be run from the executable. (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

Having said that….Let's get going!! ;)

=============================

Scan with OTL
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    services.exe
    /md5stop
    %systemroot%\*. /rp /s
    %systemdrive%\$Recycle.Bin|@;true;true;true /fp
    DRIVES
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.

=============================== Next =======================================


Please download aswMBR.exe and save it to your desktop.
  • Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)
  • Allow it to update where necessary
  • Click Scan

  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.

On your next reply please post :
  • OTL.txt
  • Extras.txt
  • aswMBR log

Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Hi Robybel,

Thank you so much for your help. I'm concerned that one of the programs my friend had me run was ComboFix and it was after using it that things were at their worst and so I did the System Restore and lost the D: drive. I hope things are not irreparable now.

Here are the logs.

Otl.txt

OTL logfile created on: 8/12/2013 6:12:24 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Anitta\Desktop
Starter Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16635)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1012.30 Mb Total Physical Memory | 612.05 Mb Available Physical Memory | 60.46% Memory free
1.99 Gb Paging File | 1.59 Gb Available in Paging File | 80.12% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 219.79 Gb Total Space | 173.03 Gb Free Space | 78.72% Space Free | Partition Type: NTFS

Computer Name: ANITTA-PC | User Name: Anitta | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Anitta\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Bin\Smc.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Bin\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========


========== Services (SafeList) ==========

SRV - (SDWSCService) – C:\Program Files\Spybot File not found
SRV - (SDUpdateService) – C:\Program Files\Spybot File not found
SRV - (SDScannerService) – C:\Program Files\Spybot File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware3\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – C:\Program Files\Malwarebytes' Anti-Malware3\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (SkypeUpdate) – C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (SmcService) – C:\Program Files\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Bin\Smc.exe (Symantec Corporation)
SRV - (SNAC) – C:\Program Files\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Bin\snac.exe (Symantec Corporation)
SRV - (SepMasterService) – C:\Program Files\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Bin\ccSvcHst.exe (Symantec Corporation)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (ePowerSvc) – C:\Program Files\Gateway\Gateway Power Management\ePowerSvc.exe (Acer Incorporated)
SRV - (DsiWMIService) – C:\Program Files\Launch Manager\dsiwmis.exe (Dritek System Inc.)
SRV - (BBSvc) – C:\Program Files\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (AdobeARMservice) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (GREGService) – C:\Program Files\Gateway\Registration\GREGsvc.exe (Acer Incorporated)
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_3.EXE (Symantec Corporation)
SRV - (BBUpdate) – C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (Live Updater Service) – C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe (Acer Incorporated)
SRV - (IconMan_R) – C:\Program Files\Realtek\Realtek PCIE Card Reader\RIconMan.exe (Realsil Microelectronics Inc.)
SRV - (IAStorDataMgrSvc) – C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)


========== Driver Services (SafeList) ==========

DRV - (TrueSight) – C:\Windows\system32\TrueSight.sys File not found
DRV - (NAVEX15) – C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Data\Definitions\VirusDefs\20130811.006\NAVEX15.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Data\Definitions\VirusDefs\20130811.006\NAVENG.SYS (Symantec Corporation)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (BHDrvx86) – C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Data\Definitions\BASHDefs\20130716.011\BHDrvx86.sys (Symantec Corporation)
DRV - (MBAMProtector) – C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (SymEFA) – C:\Windows\System32\drivers\SEP\0C0107DF\07DF.105\x86\SymEFA.sys (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\drivers\SEP\0C0107DF\07DF.105\x86\srtsp.sys (Symantec Corporation)
DRV - (SymDS) – C:\Windows\System32\drivers\SEP\0C0107DF\07DF.105\x86\SymDS.sys (Symantec Corporation)
DRV - (SYMNETS) – C:\Windows\System32\drivers\SEP\0C0107DF\07DF.105\x86\symnets.sys (Symantec Corporation)
DRV - (SymIRON) – C:\Windows\System32\drivers\SEP\0C0107DF\07DF.105\x86\Ironx86.sys (Symantec Corporation)
DRV - (ccSettings_{29AC8EDB-F22A-46D3-9D66-4244585EAD0A}) – C:\Windows\System32\drivers\SEP\0C0107DF\07DF.105\x86\ccSetx86.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\Windows\System32\drivers\SEP\0C0107DF\07DF.105\x86\srtspx.sys (Symantec Corporation)
DRV - (igddim32) – C:\Windows\System32\drivers\igddim32.sys (Intel Corporation)
DRV - (IntcDAud) – C:\Windows\System32\drivers\IntcDAud.sys (Intel® Corporation)
DRV - (RSPCIESTOR) – C:\Windows\System32\drivers\RtsPStor.sys (Realtek Semiconductor Corp.)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (TsUsbGD) – C:\Windows\System32\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV - (vwifimp) – C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com/?pc=MAGW
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\SearchScopes,DefaultScope = {A6ADA716-2865-4B33-AB86-FA2074DDBF9A}
IE - HKCU\..\SearchScopes\{A6ADA716-2865-4B33-AB86-FA2074DDBF9A}: "URL" = http://www.google.com/search?q={searchTerm…utputEncoding?}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@bestbuy.com/npBestBuyPcAppDetector,version=1.0: C:\ProgramData\Best Buy pc app\npBestBuyPcAppDetector.dll (Best Buy)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\amazon.com/AmazonMP3DownloaderPlugin: C:\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin1017300.dll (Amazon.com, Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/10/06 01:08:46 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/07/12 13:42:20 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/10/06 01:08:46 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/07/12 13:42:20 | 000,000,000 | —D | M]

[2012/02/23 12:10:40 | 000,000,000 | —D | M] (No name found) – C:\Users\Anitta\AppData\Roaming\Mozilla\Extensions
[2013/08/03 12:42:12 | 000,000,000 | —D | M] (No name found) – C:\Users\Anitta\AppData\Roaming\Mozilla\Firefox\Profiles\czpftlyz.default\extensions
[2012/02/23 12:10:10 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/10/06 01:08:44 | 000,266,720 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/10/06 01:08:32 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/10/06 01:08:32 | 000,002,253 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2009/06/10 17:39:37 | 000,000,824 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (Webroot Vault) - {c8d5d964-2be8-4c5b-8cf5-6e975aa88504} - C:\ProgramData\WRData\pkg\LPBar.dll File not found
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Webroot Toolbar) - {97ab88ef-346b-4179-a0b1-7445896547a5} - C:\ProgramData\WRData\pkg\LPBar.dll File not found
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [ETDCtrl] C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronics Corp.)
O4 - HKLM..\Run: [GfxServiceInstall] C:\Windows\System32\GfxCUIServiceInstall.vbs ()
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [Power Management] C:\Program Files\Gateway\Gateway Power Management\ePowerTray.exe (Acer Incorporated)
O4 - HKLM..\Run: [SDTray] C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Users\Anitta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Anitta\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra Button: Webroot - {43699cd0-e34f-11de-8a39-0800200c9a66} - C:\ProgramData\WRData\pkg\LPBar.dll File not found
O9 - Extra 'Tools' menuitem : Webroot - {43699cd0-e34f-11de-8a39-0800200c9a66} - C:\ProgramData\WRData\pkg\LPBar.dll File not found
O9 - Extra Button: @C:\Program Files\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra 'Tools' menuitem : @C:\Program Files\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://akamaicdn.webex.com/client/WBXclien…ex/ieatgpc1.cab (GpcContainer Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F729AFFD-A38F-454C-8F85-314E5F18C8EF}: DhcpNameServer = 10.0.0.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 17:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

CREATERESTOREPOINT
Unable to start System Restore Service. Error code 1084

========== Files/Folders - Created Within 30 Days ==========

[2013/08/12 06:09:14 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Anitta\Desktop\OTL.exe
[2013/08/11 18:54:03 | 002,240,864 | —- | C] (Kaspersky Lab ZAO) – C:\Users\Anitta\Desktop\iexplore.exe
[2013/08/11 16:58:58 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware3
[2013/08/11 16:58:54 | 000,022,856 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2013/08/11 16:58:54 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware3
[2013/08/11 16:58:13 | 010,284,816 | —- | C] (Malwarebytes Corporation ) – C:\Users\Anitta\Desktop\mbam-setup.exe
[2013/08/11 14:53:51 | 000,000,000 | –SD | C] – C:\ComboFix
[2013/08/11 12:30:26 | 000,000,000 | —D | C] – C:\Users\Anitta\Desktop\RK_Quarantine
[2013/08/11 08:44:34 | 000,000,000 | —D | C] – C:\Users\Anitta\Desktop\rkill
[2013/08/10 23:05:01 | 000,000,000 | —D | C] – C:\Users\Anitta\Documents\ProcAlyzer Dumps
[2013/08/10 22:21:11 | 000,000,000 | —D | C] – C:\Qoobox
[2013/08/10 22:20:53 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2013/08/10 20:54:30 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware2
[2013/08/10 20:54:28 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware2
[2013/08/01 15:17:42 | 000,000,000 | —D | C] – C:\Users\Anitta\AppData\Local\{978B3DFB-78A1-444C-BBC3-D82E6FF73D5A}
[2013/08/01 00:13:47 | 000,000,000 | —D | C] – C:\Users\Anitta\AppData\Local\{BE050325-744D-4224-8887-C747092551EB}
[2013/07/31 23:29:55 | 000,000,000 | —D | C] – C:\Users\Anitta\AppData\Roaming\dvdcss
[2013/07/31 23:25:55 | 000,000,000 | —D | C] – C:\Users\Anitta\Documents\dvdsmith
[2013/07/31 23:25:41 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDSmith Movie Backup
[2013/07/31 23:25:37 | 000,000,000 | —D | C] – C:\Program Files\DVDSmith Movie Backup
[2013/07/31 22:38:19 | 001,847,424 | —- | C] (Bleeping Computer, LLC) – C:\Users\Anitta\Desktop\rkill.com
[2013/07/31 21:13:29 | 000,000,000 | —D | C] – C:\ProgramData\DVD Shrink
[2013/07/31 20:43:32 | 000,000,000 | —D | C] – C:\Users\Anitta\AppData\Roaming\HandBrake
[2013/07/31 20:42:39 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Handbrake
[2013/07/12 18:02:57 | 009,842,040 | —- | C] (Webroot Software, Inc.) – C:\Program Files\Common Files\wruninstall.exe

========== Files - Modified Within 30 Days ==========

[2013/08/12 06:09:14 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Anitta\Desktop\OTL.exe
[2013/08/12 06:06:24 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/08/12 06:06:14 | 796,102,656 | -HS- | M] () – C:\hiberfil.sys
[2013/08/11 19:01:33 | 000,920,576 | —- | M] () – C:\Users\Anitta\Desktop\RogueKiller.exe
[2013/08/11 18:54:03 | 002,240,864 | —- | M] (Kaspersky Lab ZAO) – C:\Users\Anitta\Desktop\iexplore.exe
[2013/08/11 17:15:44 | 000,016,160 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/08/11 17:15:44 | 000,016,160 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/08/11 17:08:31 | 000,002,126 | —- | M] () – C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
[2013/08/11 17:06:01 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/08/11 16:58:59 | 000,001,081 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/08/11 16:58:14 | 010,284,816 | —- | M] (Malwarebytes Corporation ) – C:\Users\Anitta\Desktop\mbam-setup.exe
[2013/08/05 21:28:37 | 000,624,178 | —- | M] () – C:\Windows\System32\perfh009.dat
[2013/08/05 21:28:37 | 000,106,522 | —- | M] () – C:\Windows\System32\perfc009.dat
[2013/08/01 15:20:31 | 000,002,327 | —- | M] () – C:\Users\Anitta\Documents\Arcangel Idas y Vueltas.wlmp
[2013/07/31 23:25:44 | 000,001,068 | —- | M] () – C:\Users\Anitta\Desktop\DVDSmith Movie Backup.lnk
[2013/07/31 22:38:21 | 001,847,424 | —- | M] (Bleeping Computer, LLC) – C:\Users\Anitta\Desktop\rkill.com

========== Files Created - No Company Name ==========

[2013/08/11 19:01:33 | 000,920,576 | —- | C] () – C:\Users\Anitta\Desktop\RogueKiller.exe
[2013/08/11 16:58:59 | 000,001,081 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/08/01 15:20:03 | 000,002,327 | —- | C] () – C:\Users\Anitta\Documents\Arcangel Idas y Vueltas.wlmp
[2013/07/31 23:25:44 | 000,001,068 | —- | C] () – C:\Users\Anitta\Desktop\DVDSmith Movie Backup.lnk
[2013/07/11 23:14:03 | 000,002,548 | —- | C] () – C:\ProgramData\LUUnInstall.LiveUpdate
[2012/08/08 14:14:57 | 000,000,906 | —- | C] () – C:\Windows\wininit.ini
[2012/03/30 10:40:32 | 000,088,656 | —- | C] () – C:\Windows\System32\cpwmon2k.dll
[2012/02/28 10:49:42 | 000,188,200 | -H– | C] () – C:\Windows\System32\mlfcache.dat
[2012/01/20 17:45:27 | 000,039,672 | —- | C] () – C:\Windows\System32\drivers\RtPCEE3.DAT
[2012/01/20 17:45:27 | 000,033,076 | —- | C] () – C:\Windows\System32\drivers\RtPCEE4.DAT
[2012/01/20 17:45:27 | 000,001,448 | —- | C] () – C:\Windows\System32\drivers\RtHdatEx.dat
[2012/01/20 17:45:27 | 000,000,176 | —- | C] () – C:\Windows\System32\drivers\RTHDAEQ1.dat
[2012/01/20 17:45:27 | 000,000,032 | —- | C] () – C:\Windows\System32\drivers\rtkhdaud.dat
[2012/01/20 17:45:26 | 000,247,560 | —- | C] () – C:\Windows\System32\drivers\RTConvEQ.dat
[2012/01/20 17:45:26 | 000,000,520 | —- | C] () – C:\Windows\System32\drivers\RTEQEX3.dat
[2012/01/20 17:45:26 | 000,000,520 | —- | C] () – C:\Windows\System32\drivers\RTEQEX2.dat
[2012/01/20 17:45:26 | 000,000,520 | —- | C] () – C:\Windows\System32\drivers\RTEQEX1.dat
[2012/01/20 17:45:26 | 000,000,520 | —- | C] () – C:\Windows\System32\drivers\RTEQEX0.dat
[2012/01/20 17:42:24 | 000,080,416 | —- | C] () – C:\Windows\System32\RtNicProp32.dll
[2012/01/06 03:49:32 | 000,004,096 | —- | C] ( ) – C:\Windows\System32\IGFXDEVLib.dll
[2012/01/06 03:49:31 | 000,000,151 | —- | C] () – C:\Windows\System32\GfxUI.exe.config

========== ZeroAccess Check ==========

[2009/07/14 00:42:31 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/02/27 00:55:05 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 17:29:20 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/07/13 21:16:17 | 000,342,528 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2012/10/04 22:30:22 | 000,000,000 | —D | M] – C:\Users\Anitta\AppData\Roaming\Amazon
[2013/08/11 19:45:21 | 000,000,000 | —D | M] – C:\Users\Anitta\AppData\Roaming\Audacity
[2013/08/12 06:04:56 | 000,000,000 | —D | M] – C:\Users\Anitta\AppData\Roaming\Dropbox
[2013/02/05 17:34:38 | 000,000,000 | —D | M] – C:\Users\Anitta\AppData\Roaming\FreeImageConverter
[2013/07/31 20:48:35 | 000,000,000 | —D | M] – C:\Users\Anitta\AppData\Roaming\HandBrake
[2013/06/06 00:15:49 | 000,000,000 | —D | M] – C:\Users\Anitta\AppData\Roaming\SNS
[2013/04/10 11:47:05 | 000,000,000 | —D | M] – C:\Users\Anitta\AppData\Roaming\webex
[2013/06/20 10:22:25 | 000,000,000 | —D | M] – C:\Users\Anitta\AppData\Roaming\Windows Live Writer

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >

< MD5 for: EXPLORER.EXE >
[2013/05/16 10:58:12 | 003,859,928 | —- | M] (Safer-Networking Ltd.) MD5=03250DB0886A23B1F6C077C5D9F152B0 – C:\Program Files\Spybot - Search & Destroy 2\explorer.exe
[2011/07/13 21:34:17 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe
[2010/11/20 17:29:20 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe
[2011/07/13 21:34:17 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\explorer.exe
[2011/07/13 21:34:17 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe

< MD5 for: SERVICES.EXE >
[2009/07/13 21:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\System32\services.exe
[2009/07/13 21:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe

< MD5 for: SVCHOST.EXE >
[2009/07/13 21:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\System32\svchost.exe
[2009/07/13 21:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files\Malwarebytes' Anti-Malware3\Chameleon\svchost.exe

< MD5 for: USERINIT.EXE >
[2010/11/20 17:29:06 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\System32\userinit.exe
[2010/11/20 17:29:06 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe

< MD5 for: WINLOGON.EXE >
[2010/11/20 17:29:06 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\System32\winlogon.exe
[2010/11/20 17:29:06 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files\Malwarebytes' Anti-Malware3\Chameleon\winlogon.exe

< %systemroot%\*. /rp /s >

< %systemdrive%\$Recycle.Bin|@;true;true;true /fp >

========== Drive Information ==========

Physical Drives
—————

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: IDE
Media Type: Fixed hard disk media
Model: WDC WD2500BPVT-22JJ5T0
Partitions: 3
Status: OK
Status Info: 0

Partitions
—————

DeviceID: Disk #0, Partition #0
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 13.00GB
Starting Offset: 1048576
Hidden sectors: 0


DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 100.00MB
Starting Offset: 13959692288
Hidden sectors: 0


DeviceID: Disk #0, Partition #2
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 220.00GB
Starting Offset: 14064549888
Hidden sectors: 0


< End of report >

Extras.txt

OTL Extras logfile created on: 8/12/2013 6:12:24 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Anitta\Desktop
Starter Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16635)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1012.30 Mb Total Physical Memory | 612.05 Mb Available Physical Memory | 60.46% Memory free
1.99 Gb Paging File | 1.59 Gb Available in Paging File | 80.12% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 219.79 Gb Total Space | 173.03 Gb Free Space | 78.72% Space Free | Partition Type: NTFS

Computer Name: ANITTA-PC | User Name: Anitta | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot-S&D 2 Tray Icon – (Safer-Networking Ltd.)
"C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service – (Safer-Networking Ltd.)
"C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater – (Safer-Networking Ltd.)
"C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service – (Safer-Networking Ltd.)


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{77B12FA7-8999-4CDB-A3FE-D6A1F039D423}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{E678C8A2-E35A-45F3-BFDB-3A7D6F8B84C2}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{FCBD40DF-35A7-4166-97CD-C896BEFF6B8C}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1E03E396-71A7-4609-9B09-4FF51D8A9E4D}" = protocol=6 | dir=in | app=c:\program files\symantec\symantec endpoint protection\12.1.2015.2015.105\bin\snac.exe |
"{216FA9FE-646B-4710-8A63-E3201BE3C74A}" = protocol=17 | dir=in | app=c:\program files\symantec\symantec endpoint protection\12.1.2015.2015.105\bin\smc.exe |
"{2394672A-9508-41F9-9EAE-E5808DE96A11}" = protocol=17 | dir=in | app=c:\program files\symantec\symantec endpoint protection\12.1.2015.2015.105\bin\snac.exe |
"{40104204-F594-4378-855C-D264114C179C}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{50269491-D292-4452-9647-7694C55FD6DD}" = protocol=17 | dir=in | app=c:\users\anitta\appdata\roaming\dropbox\bin\dropbox.exe |
"{70B935C1-D3A8-43C5-8DB8-17E71D318913}" = protocol=6 | dir=in | app=c:\users\anitta\appdata\roaming\dropbox\bin\dropbox.exe |
"{7ABC20B6-5CCB-44D5-AA3C-8761D0191E77}" = protocol=6 | dir=in | app=c:\program files\symantec\symantec endpoint protection\12.1.2015.2015.105\bin\smc.exe |
"{9088E014-3285-42E9-A239-FB0C5E9A5951}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{9685E627-7975-4D06-BA93-2AB5D800716F}" = protocol=6 | dir=in | app=c:\program files\nakido\nakido.exe |
"{9E292140-EC62-400B-A285-55C4170F82E5}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{A05011BF-11D3-4FF4-A906-9FA3403DB196}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{A2C09099-3AEF-48F1-9D8A-01458C92369D}" = protocol=17 | dir=in | app=c:\program files\nakido\nakido.exe |
"{ECBC8913-2606-4EE2-960F-88F82E086FB6}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
"{FA2EA108-5289-4699-939E-CA5C58EDD38C}" = dir=in | app=c:\program files\windows live\mesh\moe.exe |
"{FD334918-2624-4F6C-9859-F2D3670E30A8}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"TCP Query User{9570BE56-42E0-4EC4-8C3E-133F34B5EC59}C:\users\anitta\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=6 | dir=in | app=c:\users\anitta\appdata\roaming\dropbox\bin\dropbox.exe |
"UDP Query User{8AE34BC2-34C7-419A-9168-8329969B31E0}C:\users\anitta\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=17 | dir=in | app=c:\users\anitta\appdata\roaming\dropbox\bin\dropbox.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{05E379CC-F626-4E7D-8354-463865B303BF}" = Windows Live UX Platform Language Pack
"{0A1651F1-7E0F-4613-93FE-967F5BC3C1B7}" = Windows Live Remote Service Resources
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0D261C88-454B-46FE-B43B-640E621BDA11}" = Windows Live Mail
"{17504ED4-DB08-40A8-81C2-27D8C01581DA}" = Windows Live Remote Service Resources
"{19A4A990-5343-4FF7-B3B5-6F046C091EDF}" = Windows Live Remote Client
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}" = Windows Live Remote Service
"{28921580-E4BB-11E0-9FD7-1CC1DEF07CBE}" = Evernote v. 4.5.1
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34319F1F-7CF2-4CC9-B357-1AE7D2FF3AC5}" = Windows Live
"{343666E2-A059-48AC-AD67-230BF74E2DB2}" = Apple Application Support
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3B9A92DA-6374-4872-B646-253F18624D5F}" = Windows Live Writer
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3DB0448D-AD82-4923-B305-D001E521A964}" = Gateway Power Management
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{41B72CAF-036B-4E0A-8D22-F5DF7C970434}" = Windows Live Remote Client Resources
"{423D8FBE-EC52-40FD-B2A0-8C9C8F973FD7}" = Microsoft Research AutoCollage 2008 version 1.1
"{43B43577-2514-4CE0-B14A-7E85C17C0453}" = Windows Live Essentials
"{464B3406-A4D0-4914-910F-7CA4380DCC13}" = Windows Live Remote Client Resources
"{4664ED39-C80A-48F7-93CD-EBDCAFAB6CC5}" = Windows Live Writer Resources
"{488F0347-C4A7-4374-91A7-30818BEDA710}" = Galerie de photos Windows Live
"{48C0DC5E-820A-44F2-890E-29B68EDD3C78}" = Windows Live Writer
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.3
"{4F41AD68-89F2-4262-A32C-2F70B01FCE9E}" = Photo Story 3 for Windows
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5C8BC258-A629-4DF2-97D0-E106C2A9B1BD}" = Windows Live Remote Client Resources
"{5D273F60-0525-48BA-A5FB-D0CAA4A952AE}" = Windows Live Movie Maker
"{62687B11-58B5-4A18-9BC3-9DF4CE03F194}" = Windows Live Writer Resources
"{644063FA-ABA3-42AC-A8AC-3EDC0706018B}" = Windows Live Mesh
"{64EF903E-D00A-414C-94A4-FBA368FFCDC9}" = Gateway Social Networks
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6DEC8BD5-7574-47FA-B080-492BBBE2FEA3}" = Windows Live Movie Maker
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{77477AEA-5757-47D8-8B33-939F43D82218}" = Windows Live UX Platform Language Pack
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{78DAE910-CA72-450E-AD22-772CB1A00678}" = Windows Live Mesh
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7D1C7B9F-2744-4388-B128-5C75B8BCCC84}" = Windows Live Essentials
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = Gateway Recovery Management
"{8153ED9A-C94A-426E-9880-5E6775C08B62}" = Apple Mobile Device Support
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{841F1FB4-FDF8-461C-A496-3E1CFD84C0B5}" = Windows Live Mesh
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROPLUS_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROPLUS_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROPLUS_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROPLUS_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROPLUS_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9DA3F03B-2CEE-4344-838E-117861E61FAF}" = Windows Live Mail
"{9FAE6E8D-E686-49F5-A574-0A58DFD9580C}" = Windows Live Mail
"{A0382E3C-7384-429A-9BFA-AF5888E5A193}" = Video Web Camera
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A199DB88-E22D-4CE7-90AC-B8BE396D7BF4}" = Windows Live Movie Maker
"{A41A708E-3BE6-4561-855D-44027C1CF0F8}" = Windows Live Photo Common
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AB93C51F-71F9-4A28-8134-FE1B5B9373E9}" = Windows Live Remote Service Resources
"{AC76BA86-7AD7-FFFF-7B44-AA0000000001}" = Adobe Reader X (10.1.0) MUI
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{B33B61FE-701F-425F-98AB-2B85725CBF68}" = Windows Live Photo Common
"{B3BE54A4-8DFE-4593-8E66-56AB7133B812}" = Windows Live Writer
"{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1" = Spybot - Search & Destroy
"{C1594429-8296-4652-BF54-9DBE4932A44C}" = Realtek PCIE Card Reader
"{C28D96C0-6A90-459E-A077-A6706F4EC0FC}" = Bing Bar
"{C335C87B-2D3E-4CCC-BB4B-CE60617B1A51}" = Symantec Endpoint Protection
"{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}" = Windows Live ID Sign-in Assistant
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C893D8C0-1BA0-4517-B11C-E89B65E72F70}" = Windows Live Photo Common
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{DF71ABBB-B834-41C0-BB58-80B0545D754C}" = Windows Live UX Platform Language Pack
"{DFDBE1F9-04CE-4645-BB6C-4590EABC7A9C}" = Windows Live Remote Client Resources
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E6617B44-D556-49AC-B2A3-01451E115043}" = Windows Live Remote Service Resources
"{E727A662-AF9F-4DEE-81C5-F4A1686F3DFC}" = Windows Live Writer Resources
"{E85A4EFC-82F2-4CEE-8A8E-62FDAD353A66}" = Galería fotográfica de Windows Live
"{EE171732-BEB4-4576-887D-CB62727F01CA}" = Gateway Updater
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Graphics Media Accelerator Driver
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F6D6B258-E3CA-4AAC-965A-68D3E3140A8C}" = iTunes
"{F7A46527-DF1F-4B0F-9637-98547E189442}" = Windows Live Galeria de Fotos
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel® Control Center
"{FBBC4667-2521-4E78-B1BD-8706F774549B}" = Best Buy pc app
"{FDB3B167-F4FA-461D-976F-286304A57B2A}" = Adobe AIR
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"ActiveTouchMeetingClient" = Cisco WebEx Meetings
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.17
"Audacity_is1" = Audacity 2.0.3
"CutePDF Writer Installation" = CutePDF Writer 2.8
"DVDSmith Movie Backup_is1" = DVDSmith Movie Backup 1.0.8
"Elantech" = ETDWare PS/2-X86 8.0.6.0_WHQL
"Gateway Registration" = Gateway Registration
"Gateway Screensaver" = Gateway ScreenSaver
"Gateway Welcome Center" = Welcome Center
"Identity Card" = Identity Card
"InstallShield_{64EF903E-D00A-414C-94A4-FBA368FFCDC9}" = Gateway Social Networks
"InstallShield_{A0382E3C-7384-429A-9BFA-AF5888E5A193}" = Video Web Camera
"LiveUpdate" = LiveUpdate 3.3 (Symantec Corporation)
"LManager" = Launch Manager
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox 15.0.1 (x86 en-US)" = Mozilla Firefox 15.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"PROPLUS" = Microsoft Office Professional Plus 2007
"Scrivener 1030" = Scrivener
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR 4.20 (32-bit)

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Amazon Kindle" = Amazon Kindle
"Dropbox" = Dropbox

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 8/3/2013 12:48:17 PM | Computer Name = Anitta-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 9532

Error - 8/3/2013 12:48:18 PM | Computer Name = Anitta-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 8/3/2013 12:48:18 PM | Computer Name = Anitta-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 10530

Error - 8/3/2013 12:48:18 PM | Computer Name = Anitta-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 10530

Error - 8/4/2013 12:48:22 AM | Computer Name = Anitta-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 8/4/2013 12:48:22 AM | Computer Name = Anitta-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 43214430

Error - 8/4/2013 12:48:22 AM | Computer Name = Anitta-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 43214430

Error - 8/4/2013 12:49:11 AM | Computer Name = Anitta-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 8/4/2013 12:49:11 AM | Computer Name = Anitta-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 1092

Error - 8/4/2013 12:49:11 AM | Computer Name = Anitta-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 1092

[ OSession Events ]
Error - 5/25/2012 1:21:56 PM | Computer Name = Anitta-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6661.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 1236625
seconds with 61140 seconds of active time. This session ended with a crash.

Error - 5/22/2013 3:34:10 AM | Computer Name = Anitta-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 238525
seconds with 55860 seconds of active time. This session ended with a crash.

Error - 6/2/2013 8:59:05 AM | Computer Name = Anitta-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 806143
seconds with 142560 seconds of active time. This session ended with a crash.

Error - 6/3/2013 8:44:13 PM | Computer Name = Anitta-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 128666
seconds with 23400 seconds of active time. This session ended with a crash.

Error - 6/5/2013 8:00:35 AM | Computer Name = Anitta-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 126855
seconds with 28860 seconds of active time. This session ended with a crash.

Error - 6/19/2013 10:52:48 AM | Computer Name = Anitta-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 496566
seconds with 14280 seconds of active time. This session ended with a crash.

[ Symantec Endpoint Protection Client Events ]
Error - 8/4/2013 9:26:50 PM | Computer Name = Anitta-PC | Source = Symantec Endpoint Protection Client | ID = 16711731
Description = Security Risk Found!Tracking Cookies in File: Cookie:[removed]/
by: Scheduled scan. Action: Delete succeeded. Action Description: The file was
deleted successfully.

Error - 8/6/2013 1:53:30 PM | Computer Name = Anitta-PC | Source = Symantec Endpoint Protection Client | ID = 16711731
Description = Security Risk Found!Tracking Cookies in File: Cookie:[removed]/
by: Scheduled scan. Action: Delete succeeded. Action Description: The file was
deleted successfully.

Error - 8/10/2013 7:34:54 PM | Computer Name = Anitta-PC | Source = Symantec Endpoint Protection Client | ID = 16711731
Description = Security Risk Found!Tracking Cookies in File: Cookie:[removed]/
by: Scheduled scan. Action: Delete succeeded. Action Description: The file was
deleted successfully.

Error - 8/10/2013 7:56:27 PM | Computer Name = Anitta-PC | Source = Symantec Endpoint Protection Client | ID = 16711731
Description = Security Risk Found!SecurityRisk.OrphanInf in File: d:\autorun.inf
by: Scheduled scan. Action: Quarantine succeeded. Action Description: The file
was quarantined successfully.

Error - 8/11/2013 3:53:18 PM | Computer Name = Anitta-PC | Source = Symantec Endpoint Protection Client | ID = 16711720
Description = Symantec Endpoint Protection has determined that the virus definitions
are missing on this computer. This computer will remain unprotected from viruses
until virus definitions are downloaded to this computer.Application has encountered
an error. For more information, please go to: http://www.symantec.com/techsupp/servlet/P…ld=symantec_ent


Error - 8/11/2013 4:01:47 PM | Computer Name = Anitta-PC | Source = Symantec Endpoint Protection Client | ID = 16711720
Description = Symantec Endpoint Protection has determined that the virus definitions
are missing on this computer. This computer will remain unprotected from viruses
until virus definitions are downloaded to this computer.Application has encountered
an error. For more information, please go to: http://www.symantec.com/techsupp/servlet/P…ld=symantec_ent


Error - 8/11/2013 4:04:02 PM | Computer Name = Anitta-PC | Source = Symantec Endpoint Protection Client | ID = 16711720
Description = Symantec Endpoint Protection has determined that the virus definitions
are missing on this computer. This computer will remain unprotected from viruses
until virus definitions are downloaded to this computer.Application has encountered
an error. For more information, please go to: http://www.symantec.com/techsupp/servlet/P…ld=symantec_ent


Error - 8/11/2013 4:07:07 PM | Computer Name = Anitta-PC | Source = Symantec Endpoint Protection Client | ID = 16711720
Description = Symantec Endpoint Protection has determined that the virus definitions
are missing on this computer. This computer will remain unprotected from viruses
until virus definitions are downloaded to this computer.Application has encountered
an error. For more information, please go to: http://www.symantec.com/techsupp/servlet/P…ld=symantec_ent


Error - 8/11/2013 4:10:08 PM | Computer Name = Anitta-PC | Source = Symantec Endpoint Protection Client | ID = 16711720
Description = Symantec Endpoint Protection has determined that the virus definitions
are missing on this computer. This computer will remain unprotected from viruses
until virus definitions are downloaded to this computer.Application has encountered
an error. For more information, please go to: http://www.symantec.com/techsupp/servlet/P…ld=symantec_ent


Error - 8/11/2013 4:13:05 PM | Computer Name = Anitta-PC | Source = Symantec Endpoint Protection Client | ID = 16711720
Description = Symantec Endpoint Protection has determined that the virus definitions
are missing on this computer. This computer will remain unprotected from viruses
until virus definitions are downloaded to this computer.Application has encountered
an error. For more information, please go to: http://www.symantec.com/techsupp/servlet/P…ld=symantec_ent


[ System Events ]
Error - 8/12/2013 6:21:18 AM | Computer Name = Anitta-PC | Source = Service Control Manager | ID = 7001
Description = The HomeGroup Provider service depends on the Function Discovery Provider
Host service which failed to start because of the following error: %%1068

Error - 8/12/2013 6:21:20 AM | Computer Name = Anitta-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 8/12/2013 6:21:20 AM | Computer Name = Anitta-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 8/12/2013 6:21:20 AM | Computer Name = Anitta-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 8/12/2013 6:21:20 AM | Computer Name = Anitta-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 8/12/2013 6:28:18 AM | Computer Name = Anitta-PC | Source = Service Control Manager | ID = 7001
Description = The HomeGroup Provider service depends on the Function Discovery Provider
Host service which failed to start because of the following error: %%1068

Error - 8/12/2013 6:28:20 AM | Computer Name = Anitta-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 8/12/2013 6:28:20 AM | Computer Name = Anitta-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 8/12/2013 6:28:20 AM | Computer Name = Anitta-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 8/12/2013 6:28:20 AM | Computer Name = Anitta-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068


< End of report >

AswMBR.txt

aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software
Run date: 2013-08-12 08:10:13
—————————–
08:10:13.634 OS Version: Windows 6.1.7601 Service Pack 1
08:10:13.634 Number of processors: 4 586 0x3601
08:10:13.634 ComputerName: ANITTA-PC UserName: Anitta
08:10:16.410 Initialize success
08:14:16.510 AVAST engine defs: 13081200
08:15:00.284 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0
08:15:00.284 Disk 0 Vendor: WDC_WD25 01.0 Size: 238475MB BusType: 3
08:15:00.456 Disk 0 MBR read successfully
08:15:00.471 Disk 0 MBR scan
08:15:00.534 Disk 0 Windows 7 default MBR code
08:15:00.565 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 13312 MB offset 2048
08:15:00.612 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 27265024
08:15:00.643 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 225061 MB offset 27469824
08:15:00.658 Disk 0 scanning sectors +488394752
08:15:00.846 Disk 0 scanning C:\Windows\system32\drivers
08:15:17.460 Service scanning
08:15:56.959 Modules scanning
08:16:02.403 Disk 0 trace - called modules:
08:16:02.435 ntkrnlpa.exe CLASSPNP.SYS disk.sys iaStor.sys halmacpi.dll
08:16:02.466 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x84b788f8]
08:16:02.481 3 CLASSPNP.SYS[86fa559e] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0x8442a028]
08:16:04.650 AVAST engine scan C:\Windows
08:16:09.439 AVAST engine scan C:\Windows\system32
08:21:48.240 AVAST engine scan C:\Windows\system32\drivers
08:22:20.345 AVAST engine scan C:\Users\Anitta
08:32:50.118 AVAST engine scan C:\ProgramData
08:34:54.435 Scan finished successfully
08:35:42.951 Disk 0 MBR has been saved successfully to "C:\Users\Anitta\Desktop\MBR.dat"
08:35:42.967 The log file has been saved successfully to "C:\Users\Anitta\Desktop\aswMBR.txt"

Attachments:

Hi acsant ;)

Good job :)

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

Next

AdwCleaner

  • Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Delete.
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.

Next

[external image: Posted Image] Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.


Next


  • Download RogueKiller and save it to your desktop.
  • Quit all other programs
  • Start RogueKiller.exe
  • Wait until the Prescan has finished …
  • Click on Scan
    [external image: Posted Image]
  • Wait for the end of the scan
  • A report will be created on your desktop.
  • Click on the Delete button
    [external image: Posted Image]
  • Next click on the ShortcutsFix
    [external image: Posted Image]
  • another report will be created on your desktop.

Please post: All RKreport.txt text files located on your desktop.

On your next reply please post :
  • checkup.txt
  • AdwCleaner[S1].txt
  • JRT.txt
  • All RKreport.txt

Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Hi. Thank you so much. I ran all the scans and am pasting the reports. I just want to mention that when I ran Adwcleaner the first time, it did not make a report. I thought this might have been because when it automatically rebooted, I rebooted again in safe mode with networking. I checked the C:\ folder to see if it was in there but it wasn't so I ran it again and let it reboot normally. That time, it did make the log file, so that's the one I'm pasting here. Sorry about that.

checkup.txt

Results of screen317's Security Check version 0.99.72
Windows 7 Service Pack 1 x86 (UAC is enabled)
Internet Explorer 10
``````````````Antivirus/Firewall Check:``````````````
Windows Security Center service is not running! This report may not be accurate!
Windows Firewall Enabled!
Spybot - Search and Destroy
Symantec Endpoint Protection
WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
Spybot - Search & Destroy
Malwarebytes Anti-Malware version 1.75.0.1300
Adobe Reader 10.1.0 Adobe Reader out of Date!
Mozilla Firefox 15.0.1 Firefox out of Date!
````````Process Check: objlist.exe by Laurent````````
Norton ccSvcHst.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:
````````````````````End of Log``````````````````````

Adwcleaner[S2].txt

# AdwCleaner v2.306 - Logfile created 08/12/2013 at 23:47:12
# Updated 19/07/2013 by Xplode
# Operating system : Windows 7 Starter Service Pack 1 (32 bits)
# User : Anitta - ANITTA-PC
# Boot Mode : Safe mode with networking
# Running from : C:\Users\Anitta\Desktop\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****


***** [Registry] *****


***** [Internet Browsers] *****

-\\ Internet Explorer v10.0.9200.16635

[OK] Registry is clean.

-\\ Mozilla Firefox v15.0.1 (en-US)

File : C:\Users\Anitta\AppData\Roaming\Mozilla\Firefox\Profiles\czpftlyz.default\prefs.js

[OK] File is clean.

*************************

AdwCleaner[S2].txt - [688 octets] - [12/08/2013 23:47:12]

########## EOF - C:\AdwCleaner[S2].txt - [747 octets] ##########

JRT.txt

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.4.4 (08.12.2013:1)
OS: Windows 7 Starter x86
Ran by [removed] on Tue 08/13/2013 at 0:00:12.44
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110211181104}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110211181104}



~~~ Files

Successfully deleted: [File] "C:\Windows\couponprinter.ocx"
Successfully deleted: [File] "C:\Windows\wininit.ini"



~~~ Folders

Successfully deleted: [Folder] "C:\ProgramData\best buy pc app"
Successfully deleted: [Folder] "C:\Users\Anitta\appdata\local\best buy pc app"
Successfully deleted: [Folder] "C:\Program Files\coupons"
Successfully deleted: [Empty Folder] C:\Users\Anitta\appdata\local\{1DC05A01-F29B-4788-854F-082B2DC2D451}
Successfully deleted: [Empty Folder] C:\Users\Anitta\appdata\local\{271B83C9-7F15-4E61-9906-1026F3A85779}
Successfully deleted: [Empty Folder] C:\Users\Anitta\appdata\local\{3C9CC85A-B8BA-4124-B834-F4AA0E44179D}
Successfully deleted: [Empty Folder] C:\Users\Anitta\appdata\local\{70EEDECC-492E-4D44-82B4-6CC06C1A9FB0}
Successfully deleted: [Empty Folder] C:\Users\Anitta\appdata\local\{978B3DFB-78A1-444C-BBC3-D82E6FF73D5A}
Successfully deleted: [Empty Folder] C:\Users\Anitta\appdata\local\{B4A012DF-ACF4-4FA6-A6CF-7C9E288B51F3}
Successfully deleted: [Empty Folder] C:\Users\Anitta\appdata\local\{BE050325-744D-4224-8887-C747092551EB}
Successfully deleted: [Empty Folder] C:\Users\Anitta\appdata\local\{CBEF3DB1-4FC7-43F2-90D6-8B3097C6304D}
Successfully deleted: [Empty Folder] C:\Users\Anitta\appdata\local\{CE4A702D-2BB4-4F15-B6D6-D5C79E1A8F54}
Successfully deleted: [Empty Folder] C:\Users\Anitta\appdata\local\{D244DAA4-C38C-4030-8162-4E3F98D32256}
Successfully deleted: [Empty Folder] C:\Users\Anitta\appdata\local\{F1ACA9DC-ED6C-4D22-8300-3E45781FC271}



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Tue 08/13/2013 at 0:04:12.84
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

RKreports

RogueKiller V8.6.5 [Aug 5 2013] by Tigzy
mail : tigzyRKgmailcom
Feedback : http://www.adlice.com/forum/
Website : http://www.adlice.com/softwares/roguekiller/
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Started in : Safe mode with network support
User : Anitta [Admin rights]
Mode : Scan – Date : 08/13/2013 00:10:52
| ARK || FAK || MBR |

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 2 ¤¤¤
[HJ POL] HKCU\[…]\System : DisableTaskMgr (0) -> FOUND
[HJ POL] HKCU\[…]\System : DisableRegistryTools (0) -> FOUND

¤¤¤ Scheduled tasks : 0 ¤¤¤

¤¤¤ Startup Entries : 0 ¤¤¤

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [NOT LOADED 0xc000035f] ¤¤¤

¤¤¤ External Hives: ¤¤¤

¤¤¤ Infection : ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
–> %SystemRoot%\System32\drivers\etc\hosts




¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: WDC WD2500BPVT-22JJ5T0 +++++
— User —
[MBR] 7f7e98f6098f49a09a26f7d09ae9af9f
[BSP] d610c63962135a3ed339db1d5455b01e : Windows 7/8 MBR Code
Partition table:
0 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 13312 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 27265024 | Size: 100 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 27469824 | Size: 225061 Mo
User = LL1 … OK!
User = LL2 … OK!

Finished : << RKreport[0]_S_08132013_001052.txt >>




RogueKiller V8.6.5 [Aug 5 2013] by Tigzy
mail : tigzyRKgmailcom
Feedback : http://www.adlice.com/forum/
Website : http://www.adlice.com/softwares/roguekiller/
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Started in : Safe mode with network support
User : Anitta [Admin rights]
Mode : Remove – Date : 08/13/2013 00:11:10
| ARK || FAK || MBR |

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 2 ¤¤¤
[HJ POL] HKCU\[…]\System : DisableTaskMgr (0) -> DELETED
[HJ POL] HKCU\[…]\System : DisableRegistryTools (0) -> DELETED

¤¤¤ Scheduled tasks : 0 ¤¤¤

¤¤¤ Startup Entries : 0 ¤¤¤

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [NOT LOADED 0xc000035f] ¤¤¤

¤¤¤ External Hives: ¤¤¤

¤¤¤ Infection : ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
–> %SystemRoot%\System32\drivers\etc\hosts




¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: WDC WD2500BPVT-22JJ5T0 +++++
— User —
[MBR] 7f7e98f6098f49a09a26f7d09ae9af9f
[BSP] d610c63962135a3ed339db1d5455b01e : Windows 7/8 MBR Code
Partition table:
0 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 13312 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 27265024 | Size: 100 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 27469824 | Size: 225061 Mo
User = LL1 … OK!
User = LL2 … OK!

Finished : << RKreport[0]_D_08132013_001110.txt >>
RKreport[0]_S_08132013_001052.txt



RogueKiller V8.6.5 [Aug 5 2013] by Tigzy
mail : tigzyRKgmailcom
Feedback : http://www.adlice.com/forum/
Website : http://www.adlice.com/softwares/roguekiller/
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Started in : Safe mode with network support
User : Anitta [Admin rights]
Mode : Shortcuts HJfix – Date : 08/13/2013 00:12:09
| ARK || FAK || MBR |

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Driver : [NOT LOADED 0xc000035f] ¤¤¤

¤¤¤ External Hives: ¤¤¤

¤¤¤ File attributes restored: ¤¤¤
Desktop: Success 0 / Fail 0
Quick launch: Success 0 / Fail 0
Programs: Success 0 / Fail 0
Start menu: Success 0 / Fail 0
User folder: Success 10 / Fail 0
My documents: Success 0 / Fail 0
My favorites: Success 0 / Fail 0
My pictures: Success 0 / Fail 0
My music: Success 18 / Fail 0
My videos: Success 0 / Fail 0
Local drives: Success 1 / Fail 0
Backup: [NOT FOUND]

Drives:
[C:] \Device\HarddiskVolume3 – 0x3 –> Restored

¤¤¤ Infection : ¤¤¤

Finished : << RKreport[0]_SC_08132013_001209.txt >>
RKreport[0]_D_08132013_001110.txt;RKreport[0]_S_08132013_001052.txt



Thank you!
Hi acsant ;)

Very good job ;)

Please read through these instructions to familarize yourself with what to expect when this tool runs

Refer to the ComboFix User's Guide


Download ComboFix from one of these locations:

Link 1
Link 2



* IMPORTANT- Save ComboFix.exe to your Desktop

====================================================


Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs


====================================================


Double click on combofix.exe & follow the prompts.


When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply for further review.

On your next reply please post :
  • Combofix log

Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Hi Robybel, Thank you so much for your help. I'm posting the ComboFix log below: ComboFix 13-08-14.01 - Anitta 08/14/2013 8:27.1.4 - x86 Microsoft Windows 7 Starter 6.1.7601.1.1252.1.1033.18.1012.182 [GMT -4:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: Spybot - Search and Destroy *Disabled/Outdated* {20A26C15-1AF0-7CA3-9380-FAB824A7EE0D} AV: Symantec Endpoint Protection *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF} SP: Spybot - Search and Destroy *Disabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} SP: Symantec Endpoint Protection *Disabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((( Files Created from 2013-07-14 to 2013-08-14 ))))))))))))))))))))))))))))))) . . 2013-08-14 12:44 . 2013-08-14 12:44 ——– d—–w- c:\users\Default\AppData\Local\temp 2013-08-13 04:00 . 2013-08-13 04:00 ——– d—–w- c:\windows\ERUNT 2013-08-11 20:58 . 2013-08-11 20:59 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware3 2013-08-11 20:58 . 2013-04-04 18:50 22856 —-a-w- c:\windows\system32\drivers\mbam.sys 2013-08-11 00:54 . 2013-08-11 23:44 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware2 2013-08-01 03:29 . 2013-08-01 03:30 ——– d—–w- c:\users\Anitta\AppData\Roaming\dvdcss 2013-08-01 03:25 . 2013-08-01 03:26 ——– d—–w- c:\program files\DVDSmith Movie Backup 2013-08-01 01:13 . 2013-08-01 01:17 ——– d—–w- c:\programdata\DVD Shrink 2013-08-01 00:43 . 2013-08-01 00:48 ——– d—–w- c:\users\Anitta\AppData\Roaming\HandBrake . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-07-12 22:03 . 2013-07-12 22:02 9842040 —-a-w- c:\program files\Common Files\wruninstall.exe 2013-07-12 18:17 . 2013-07-12 18:17 71048 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2013-07-12 18:17 . 2013-07-12 18:17 692104 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2013-07-12 03:28 . 2013-07-12 03:28 142496 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS 2013-07-12 03:24 . 2013-07-12 03:24 419792 —-a-w- c:\windows\system32\SymVPN.dll 2013-07-12 03:24 . 2013-07-12 03:24 32816 —-a-w- c:\windows\system32\drivers\WGX.SYS 2013-07-12 03:24 . 2013-07-12 03:24 136144 —-a-w- c:\windows\system32\FwsVpn.dll 2013-06-19 21:31 . 2011-03-29 02:36 22240 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2013-06-11 23:43 . 2013-07-11 17:29 1767936 —-a-w- c:\windows\system32\wininet.dll 2013-06-11 23:43 . 2013-07-11 17:29 2877440 —-a-w- c:\windows\system32\jscript9.dll 2013-06-11 23:42 . 2013-07-11 17:29 61440 —-a-w- c:\windows\system32\iesetup.dll 2013-06-11 23:42 . 2013-07-11 17:29 109056 —-a-w- c:\windows\system32\iesysprep.dll 2013-06-11 22:51 . 2013-07-11 17:29 71680 —-a-w- c:\windows\system32\RegisterIEPKEYs.exe 2013-06-07 02:37 . 2013-07-11 17:29 2706432 —-a-w- c:\windows\system32\mshtml.tlb 2013-06-05 03:05 . 2013-07-11 05:13 2347520 —-a-w- c:\windows\system32\win32k.sys 2013-06-04 04:53 . 2013-07-11 05:13 509440 —-a-w- c:\windows\system32\qedit.dll 2012-10-06 05:08 . 2012-10-06 05:08 266720 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 130736 —-a-w- c:\users\Anitta\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 130736 —-a-w- c:\users\Anitta\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 130736 —-a-w- c:\users\Anitta\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-12-30 135168] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-12-30 168960] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-12-30 161280] "GfxServiceInstall"="c:\windows\system32\GfxCUIServiceInstall.vbs" [2011-12-30 131] "LManager"="c:\program files\Launch Manager\LManager.exe" [2011-07-01 1103440] "ETDCtrl"="c:\program files\Elantech\ETDCtrl.exe" [2010-11-12 1812264] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2011-05-18 10082920] "Power Management"="c:\program files\Gateway\Gateway Power Management\ePowerTray.exe" [2011-08-02 715368] "APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-02 59240] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-01-16 421736] "SDTray"="c:\program files\Spybot - Search & Destroy 2\SDTray.exe" [2013-07-25 5624784] . c:\users\Anitta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\Anitta\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2013-5-24 27776968] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SDWinLogon] SDWinLogon.dll [BU] . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Best Buy pc app] c:\users\Anitta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Best Buy\Best Buy pc app.appref-ms [X] . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype] 2013-02-28 23:30 18643048 —-a-r- c:\program files\Skype\Phone\Skype.exe . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 . R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2013-02-28 161384] R3 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [2011-06-07 191752] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 51040] S0 SymDS;Symantec Data Store;c:\windows\system32\Drivers\SEP\0C0107DF\07DF.105\x86\SYMDS.SYS [2012-11-03 368288] S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\Drivers\SEP\0C0107DF\07DF.105\x86\SYMEFA.SYS [2012-11-03 927904] S1 BHDrvx86;BHDrvx86;c:\programdata\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Data\Definitions\BASHDefs\20130716.011\BHDrvx86.sys [2013-06-21 1002072] S1 ccSettings_{29AC8EDB-F22A-46D3-9D66-4244585EAD0A};Symantec Endpoint Protection 12.1.2015.2015.105 Settings Manager;c:\windows\system32\Drivers\SEP\0C0107DF\07DF.105\x86\ccSetx86.sys [2012-11-03 134304] S1 SymIRON;Symantec Iron Driver;c:\windows\system32\Drivers\SEP\0C0107DF\07DF.105\x86\Ironx86.SYS [2012-11-03 175264] S1 SYMNETS;Symantec Network Security WFP Driver;c:\windows\system32\Drivers\SEP\0C0107DF\07DF.105\x86\SYMNETS.SYS [2012-11-03 338592] S2 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\SeaPort.EXE [2011-05-13 249648] S2 DsiWMIService;Dritek WMI Service;c:\program files\Launch Manager\dsiwmis.exe [2011-07-01 353360] S2 ePowerSvc;ePower Service;c:\program files\Gateway\Gateway Power Management\ePowerSvc.exe [2011-08-02 739944] S2 GREGService;GREGService;c:\program files\Gateway\Registration\GREGsvc.exe [2011-05-30 36456] S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-11-06 13336] S2 IconMan_R;IconMan_R;c:\program files\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2011-03-07 1755136] S2 Live Updater Service;Live Updater Service;c:\program files\Gateway\Gateway Updater\UpdaterService.exe [2011-04-22 244624] S2 MBAMScheduler;MBAMScheduler;c:\program files\Malwarebytes' Anti-Malware3\mbamscheduler.exe [2013-04-04 418376] S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware3\mbamservice.exe [2013-04-04 701512] S2 SepMasterService;Symantec Endpoint Protection;c:\program files\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Bin\ccSvcHst.exe [2012-11-03 143928] S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2013-07-12 106656] S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [2010-11-12 116008] S3 igddim32;igddim32;c:\windows\system32\DRIVERS\igddim32.sys [2011-12-30 1338368] S3 igdkmd32;igdkmd32;c:\windows\system32\DRIVERS\igdkmd32.sys [2011-12-30 418816] S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2011-06-09 278528] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2013-04-04 22856] S3 RSPCIESTOR;Realtek PCIE CardReader Driver;c:\windows\system32\DRIVERS\RtsPStor.sys [2011-05-30 254056] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2011-09-29 490088] . . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS fdrespub AppIDSvc QWAVE wcncsvc . Contents of the 'Scheduled Tasks' folder . 2013-08-14 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-12 18:17] . . ——- Supplementary Scan ——- . uStart Page = hxxp://www.google.com/ uInternet Settings,ProxyOverride = *.local uInternet Settings,ProxyServer = localhost:21320 IE: E&xport to Microsoft Excel - c:\progra~1\MIF5BA~1\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 10.0.0.1 FF - ProfilePath - c:\users\Anitta\AppData\Roaming\Mozilla\Firefox\Profiles\czpftlyz.default\ . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) . . . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SepMasterService] "ImagePath"="\"c:\program files\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Bin\ccSvcHst.exe\" /s \"Symantec Endpoint Protection\" /m \"c:\program files\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Bin\sms.dll\" /prefetch:1" – . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SmcService] "ImagePath"="\"c:\program files\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Bin\Smc.exe\" /prefetch:1" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Symantec\Symantec Endpoint Protection\CurrentVersion] "SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,4f,00,46,00,\ . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ——————— DLLs Loaded Under Running Processes ——————— . - - - - - - - > 'Explorer.exe'(6032) c:\users\Anitta\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll c:\program files\Gateway\Gateway Power Management\SysHook.dll . Completion time: 2013-08-14 08:51:15 ComboFix-quarantined-files.txt 2013-08-14 12:51 . Pre-Run: 185,350,545,408 bytes free Post-Run: 185,169,305,600 bytes free . - - End Of File - - 56C8222B512E207117F28320C6CAA423 A36C5E4F47E84449FF07ED3517B43A31
Hi acsant ;)

" I see from the logs that you have two antivirus products installed. Having more than one antivirus can cause slowdowns, conflicts and crashes.
I suggest removing one of them via Programs and Features"

NEXT

Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE

ClearJavaCache

DDS::
uInternet Settings,ProxyOverride = *.local


In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
Hi. Thanks again. I was not aware that Spybot was also an anti-virus program. I've uninstalled it. Here is my ComboFix log: ComboFix 13-08-14.02 - Anitta 08/14/2013 17:46:22.2.4 - x86 Microsoft Windows 7 Starter 6.1.7601.1.1252.1.1033.18.1012.271 [GMT -4:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\Anitta\Desktop\CFScript.txt AV: Symantec Endpoint Protection *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF} SP: Symantec Endpoint Protection *Disabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\windows\wininit.ini . . ((((((((((((((((((((((((( Files Created from 2013-07-14 to 2013-08-14 ))))))))))))))))))))))))))))))) . . 2013-08-14 22:07 . 2013-08-14 22:07 ——– d—–w- c:\users\Default\AppData\Local\temp 2013-08-14 12:11 . 2013-07-09 04:50 652800 —-a-w- c:\windows\system32\rpcrt4.dll 2013-08-14 12:11 . 2013-07-09 04:52 175104 —-a-w- c:\windows\system32\wintrust.dll 2013-08-14 12:11 . 2013-07-09 04:46 140288 —-a-w- c:\windows\system32\cryptsvc.dll 2013-08-14 12:11 . 2013-07-09 04:46 1166848 —-a-w- c:\windows\system32\crypt32.dll 2013-08-14 12:11 . 2013-07-09 04:46 103936 —-a-w- c:\windows\system32\cryptnet.dll 2013-08-14 12:11 . 2013-07-09 05:03 3913664 —-a-w- c:\windows\system32\ntoskrnl.exe 2013-08-14 12:11 . 2013-07-09 05:03 3968960 —-a-w- c:\windows\system32\ntkrnlpa.exe 2013-08-14 12:11 . 2013-07-09 04:53 1289096 —-a-w- c:\windows\system32\ntdll.dll 2013-08-14 12:11 . 2013-07-06 05:05 1293760 —-a-w- c:\windows\system32\drivers\tcpip.sys 2013-08-14 12:11 . 2013-07-25 08:57 1620992 —-a-w- c:\windows\system32\WMVDECOD.DLL 2013-08-14 12:11 . 2013-07-19 01:41 2048 —-a-w- c:\windows\system32\tzres.dll 2013-08-14 12:10 . 2013-06-15 03:38 31232 —-a-w- c:\windows\system32\drivers\tssecsrv.sys 2013-08-13 04:00 . 2013-08-13 04:00 ——– d—–w- c:\windows\ERUNT 2013-08-11 20:58 . 2013-08-11 20:59 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware3 2013-08-11 20:58 . 2013-04-04 18:50 22856 —-a-w- c:\windows\system32\drivers\mbam.sys 2013-08-11 00:54 . 2013-08-11 23:44 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware2 2013-08-01 03:29 . 2013-08-01 03:30 ——– d—–w- c:\users\Anitta\AppData\Roaming\dvdcss 2013-08-01 03:25 . 2013-08-01 03:26 ——– d—–w- c:\program files\DVDSmith Movie Backup 2013-08-01 01:13 . 2013-08-01 01:17 ——– d—–w- c:\programdata\DVD Shrink 2013-08-01 00:43 . 2013-08-01 00:48 ——– d—–w- c:\users\Anitta\AppData\Roaming\HandBrake . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-07-12 22:03 . 2013-07-12 22:02 9842040 —-a-w- c:\program files\Common Files\wruninstall.exe 2013-07-12 18:17 . 2013-07-12 18:17 71048 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2013-07-12 18:17 . 2013-07-12 18:17 692104 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2013-07-12 03:28 . 2013-07-12 03:28 142496 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS 2013-07-12 03:24 . 2013-07-12 03:24 419792 —-a-w- c:\windows\system32\SymVPN.dll 2013-07-12 03:24 . 2013-07-12 03:24 32816 —-a-w- c:\windows\system32\drivers\WGX.SYS 2013-07-12 03:24 . 2013-07-12 03:24 136144 —-a-w- c:\windows\system32\FwsVpn.dll 2013-06-19 21:31 . 2011-03-29 02:36 22240 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2013-06-05 03:05 . 2013-07-11 05:13 2347520 —-a-w- c:\windows\system32\win32k.sys 2013-06-04 04:53 . 2013-07-11 05:13 509440 —-a-w- c:\windows\system32\qedit.dll 2012-10-06 05:08 . 2012-10-06 05:08 266720 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 130736 —-a-w- c:\users\Anitta\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 130736 —-a-w- c:\users\Anitta\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 130736 —-a-w- c:\users\Anitta\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-12-30 135168] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-12-30 168960] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-12-30 161280] "GfxServiceInstall"="c:\windows\system32\GfxCUIServiceInstall.vbs" [2011-12-30 131] "LManager"="c:\program files\Launch Manager\LManager.exe" [2011-07-01 1103440] "ETDCtrl"="c:\program files\Elantech\ETDCtrl.exe" [2010-11-12 1812264] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2011-05-18 10082920] "Power Management"="c:\program files\Gateway\Gateway Power Management\ePowerTray.exe" [2011-08-02 715368] "APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-02 59240] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-01-16 421736] . c:\users\Anitta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\Anitta\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2013-5-24 27776968] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Best Buy pc app] c:\users\Anitta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Best Buy\Best Buy pc app.appref-ms [X] . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype] 2013-02-28 23:30 18643048 —-a-r- c:\program files\Skype\Phone\Skype.exe . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 . R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-11-06 13336] R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2013-02-28 161384] R3 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [2011-06-07 191752] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 51040] S0 SymDS;Symantec Data Store;c:\windows\system32\Drivers\SEP\0C0107DF\07DF.105\x86\SYMDS.SYS [2012-11-03 368288] S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\Drivers\SEP\0C0107DF\07DF.105\x86\SYMEFA.SYS [2012-11-03 927904] S1 BHDrvx86;BHDrvx86;c:\programdata\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Data\Definitions\BASHDefs\20130716.011\BHDrvx86.sys [2013-06-21 1002072] S1 ccSettings_{29AC8EDB-F22A-46D3-9D66-4244585EAD0A};Symantec Endpoint Protection 12.1.2015.2015.105 Settings Manager;c:\windows\system32\Drivers\SEP\0C0107DF\07DF.105\x86\ccSetx86.sys [2012-11-03 134304] S1 SymIRON;Symantec Iron Driver;c:\windows\system32\Drivers\SEP\0C0107DF\07DF.105\x86\Ironx86.SYS [2012-11-03 175264] S1 SYMNETS;Symantec Network Security WFP Driver;c:\windows\system32\Drivers\SEP\0C0107DF\07DF.105\x86\SYMNETS.SYS [2012-11-03 338592] S2 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\SeaPort.EXE [2011-05-13 249648] S2 DsiWMIService;Dritek WMI Service;c:\program files\Launch Manager\dsiwmis.exe [2011-07-01 353360] S2 ePowerSvc;ePower Service;c:\program files\Gateway\Gateway Power Management\ePowerSvc.exe [2011-08-02 739944] S2 GREGService;GREGService;c:\program files\Gateway\Registration\GREGsvc.exe [2011-05-30 36456] S2 IconMan_R;IconMan_R;c:\program files\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2011-03-07 1755136] S2 Live Updater Service;Live Updater Service;c:\program files\Gateway\Gateway Updater\UpdaterService.exe [2011-04-22 244624] S2 MBAMScheduler;MBAMScheduler;c:\program files\Malwarebytes' Anti-Malware3\mbamscheduler.exe [2013-04-04 418376] S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware3\mbamservice.exe [2013-04-04 701512] S2 SepMasterService;Symantec Endpoint Protection;c:\program files\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Bin\ccSvcHst.exe [2012-11-03 143928] S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2013-07-12 106656] S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [2010-11-12 116008] S3 igddim32;igddim32;c:\windows\system32\DRIVERS\igddim32.sys [2011-12-30 1338368] S3 igdkmd32;igdkmd32;c:\windows\system32\DRIVERS\igdkmd32.sys [2011-12-30 418816] S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2011-06-09 278528] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2013-04-04 22856] S3 RSPCIESTOR;Realtek PCIE CardReader Driver;c:\windows\system32\DRIVERS\RtsPStor.sys [2011-05-30 254056] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2011-09-29 490088] . . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS fdrespub AppIDSvc QWAVE wcncsvc . Contents of the 'Scheduled Tasks' folder . 2013-08-14 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-12 18:17] . . ——- Supplementary Scan ——- . uStart Page = hxxp://www.google.com/ uInternet Settings,ProxyServer = localhost:8080 IE: E&xport to Microsoft Excel - c:\progra~1\MIF5BA~1\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 10.0.0.1 FF - ProfilePath - c:\users\Anitta\AppData\Roaming\Mozilla\Firefox\Profiles\czpftlyz.default\ . . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SepMasterService] "ImagePath"="\"c:\program files\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Bin\ccSvcHst.exe\" /s \"Symantec Endpoint Protection\" /m \"c:\program files\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Bin\sms.dll\" /prefetch:1" – . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SmcService] "ImagePath"="\"c:\program files\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Bin\Smc.exe\" /prefetch:1" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Symantec\Symantec Endpoint Protection\CurrentVersion] "SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,4f,00,46,00,\ . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2013-08-14 18:15:03 ComboFix-quarantined-files.txt 2013-08-14 22:14 ComboFix2.txt 2013-08-14 12:51 . Pre-Run: 187,339,624,448 bytes free Post-Run: 186,632,617,984 bytes free . - - End Of File - - E9ACC051EB021544E37DD76978510320 A36C5E4F47E84449FF07ED3517B43A31 Thank you so much for all your help!
Hi acsant

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.


Next


ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

Note: If you are using Windows Vista/7, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as MyEsetScan. Alternatively, look for report in C:\Program Files\ESET\ESET Online Scanner\log.txt. Include the contents of this report in your next reply.
  • Push the Back button.
  • Select Uninstall application on close check box and push [external image: Posted Image]
On your next reply please post :
  • MBAM log
  • ESET Report

Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Hi Robybel, I did the Malware-Bytes scan (the log is below) but I'm having trouble with ESET. It appears in a small box, doesn't take up the entire browser window, and this is fine for the initial accepting of the terms but that same small box remains for the next step, and though I see the Remove threats option and the scan archives option, the Start button doesn't appear in the box and the text that I imagine comes before the start button is cut off as well. I was wondering if I should follow the options you give for alternate browsers but I thought I should check with you first. Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Database version: v2013.08.16.02 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 10.0.9200.16660 Anitta :: ANITTA-PC [administrator] 8/16/2013 9:02:44 AM mbam-log-2013-08-16 (09-02-44).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 221055 Time elapsed: 23 minute(s), 26 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected)
Hi acsant ;)

No problem, try this

Please run the F-Secure Online Scanner
Follow the Instruction here for installation.
Accept the License Agreement.
Once the ActiveX installs,Click Full System Scan
Once the download completes, the scan will begin automatically.
The scan will take some time to finish, so please be patient.
When the scan completes, click the Automatic cleaning (recommended) button.
Click the Show Report button and Copy&Paste the entire report in your next reply.

Please let me know how your machine is running and if there are any outstanding issues.
Hi Robybel, I'm really sorry. I'm not sure I've done this correctly. The link for the instructions took my to where I can by the F-secure internet security system. So installed F-Secure Online Scanner the way I've installed the previous links you've sent. To run it, I right-clicked and selected "Run as Administrator." I disabled my antivirus so there would be no interference with scanning. The thing is that I never got any message about an Active X installation and after the scan, it only showed that no harmful objects were found and there was no "Show Report" Button. Everything is running okay. The Abode Update message and icon is gone. There are only two minor issues at this point, Internet Explorer continues to stall a bit, where I get a "[website name] is not responding" message, but after just a couple of minutes it responds again. This one is really no big deal. The other issue is that when I shut down or restart my computer, I get a message that a program needs to close, where I can either close the program or force restart. I don't know what program could be running. This, too, is not a huge deal because the force restart works fine. But if it's something that shouldn't be happening, I figured I should mention it. I truly appreciate all your help. Thanks!
Hi acsant ;)

Very good :)

Ok!! try this:

Please download Windows Repair (all in one) from here

Install the program then run it

Go to step 2 and allow it to run Disk check

[external image: Posted Image]

Once that is done then go to step 3 and allow it to run SFC

[external image: Posted Image]

On the the Start Repairs tab => Click the Start

[external image: Posted Image]

Click on the select all check box and then click on Start

DON'T use the computer while each scan is in progress.

Restart may be needed to finish the repair procedure


Next

Re-Run OTL

  • Open OTL again and click the Quick Scan button
  • Post the OTL.txt log it produces in your next reply.
Hi Robybel,

Thanks again. I ran Windows Repair and OTL. Here is the OTL log:

OTL logfile created on: 8/20/2013 10:01:55 PM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Anitta\Desktop
Starter Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16660)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1012.30 Mb Total Physical Memory | 73.51 Mb Available Physical Memory | 7.26% Memory free
1.99 Gb Paging File | 0.94 Gb Available in Paging File | 47.27% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 219.79 Gb Total Space | 172.96 Gb Free Space | 78.69% Space Free | Partition Type: NTFS

Computer Name: ANITTA-PC | User Name: Anitta | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Anitta\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\Anitta\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Program Files\Malwarebytes' Anti-Malware3\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware3\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware3\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Bin\Smc.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Bin\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files\Gateway\Gateway Power Management\ePowerTray.exe (Acer Incorporated)
PRC - C:\Program Files\Gateway\Gateway Power Management\ePowerSvc.exe (Acer Incorporated)
PRC - C:\Program Files\Gateway\Gateway Power Management\ePowerEvent.exe (Acer Incorporated)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Launch Manager\LMutilps32.exe (Dritek System Inc.)
PRC - C:\Program Files\Launch Manager\LMworker.exe (Dritek System Inc.)
PRC - C:\Program Files\Launch Manager\LManager.exe (Dritek System Inc.)
PRC - C:\Program Files\Launch Manager\dsiwmis.exe (Dritek System Inc.)
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Gateway\Registration\GREGsvc.exe (Acer Incorporated)
PRC - C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe (Acer Incorporated)
PRC - C:\Program Files\Realtek\Realtek PCIE Card Reader\RIconMan.exe (Realsil Microelectronics Inc.)
PRC - C:\Program Files\Elantech\ETDCtrlHelper.exe (ELAN Microelectronics Corp.)
PRC - C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronics Corp.)
PRC - C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - \\?\C:\Windows\System32\wbem\WMIADAP.EXE ()


========== Modules (No Company Name) ==========

MOD - C:\Users\Anitta\AppData\Roaming\Dropbox\bin\libcef.dll ()
MOD - C:\Users\Anitta\AppData\Roaming\Dropbox\bin\wxmsw28uh_vc.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()


========== Services (SafeList) ==========

SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware3\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – C:\Program Files\Malwarebytes' Anti-Malware3\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (SkypeUpdate) – C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (SmcService) – C:\Program Files\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Bin\Smc.exe (Symantec Corporation)
SRV - (SNAC) – C:\Program Files\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Bin\snac.exe (Symantec Corporation)
SRV - (SepMasterService) – C:\Program Files\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Bin\ccSvcHst.exe (Symantec Corporation)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (ePowerSvc) – C:\Program Files\Gateway\Gateway Power Management\ePowerSvc.exe (Acer Incorporated)
SRV - (DsiWMIService) – C:\Program Files\Launch Manager\dsiwmis.exe (Dritek System Inc.)
SRV - (BBSvc) – C:\Program Files\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (AdobeARMservice) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (GREGService) – C:\Program Files\Gateway\Registration\GREGsvc.exe (Acer Incorporated)
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_3.EXE (Symantec Corporation)
SRV - (BBUpdate) – C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (Live Updater Service) – C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe (Acer Incorporated)
SRV - (IconMan_R) – C:\Program Files\Realtek\Realtek PCIE Card Reader\RIconMan.exe (Realsil Microelectronics Inc.)
SRV - (IAStorDataMgrSvc) – C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)


========== Driver Services (SafeList) ==========

DRV - (TrueSight) – C:\Windows\system32\TrueSight.sys File not found
DRV - (catchme) – C:\Users\Anitta\AppData\Local\Temp\catchme.sys File not found
DRV - (NAVEX15) – C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Data\Definitions\VirusDefs\20130818.004\NAVEX15.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Data\Definitions\VirusDefs\20130818.004\NAVENG.SYS (Symantec Corporation)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (BHDrvx86) – C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Data\Definitions\BASHDefs\20130716.011\BHDrvx86.sys (Symantec Corporation)
DRV - (MBAMProtector) – C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (SymEFA) – C:\Windows\System32\drivers\SEP\0C0107DF\07DF.105\x86\SymEFA.sys (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\drivers\SEP\0C0107DF\07DF.105\x86\srtsp.sys (Symantec Corporation)
DRV - (SymDS) – C:\Windows\System32\drivers\SEP\0C0107DF\07DF.105\x86\SymDS.sys (Symantec Corporation)
DRV - (SYMNETS) – C:\Windows\System32\drivers\SEP\0C0107DF\07DF.105\x86\symnets.sys (Symantec Corporation)
DRV - (SymIRON) – C:\Windows\System32\drivers\SEP\0C0107DF\07DF.105\x86\Ironx86.sys (Symantec Corporation)
DRV - (ccSettings_{29AC8EDB-F22A-46D3-9D66-4244585EAD0A}) – C:\Windows\System32\drivers\SEP\0C0107DF\07DF.105\x86\ccSetx86.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\Windows\System32\drivers\SEP\0C0107DF\07DF.105\x86\srtspx.sys (Symantec Corporation)
DRV - (igddim32) – C:\Windows\System32\drivers\igddim32.sys (Intel Corporation)
DRV - (IntcDAud) – C:\Windows\System32\drivers\IntcDAud.sys (Intel® Corporation)
DRV - (RSPCIESTOR) – C:\Windows\System32\drivers\RtsPStor.sys (Realtek Semiconductor Corp.)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (TsUsbGD) – C:\Windows\System32\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV - (vwifimp) – C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
DRV - (Serial) – C:\Windows\System32\drivers\serial.sys (Brother Industries Ltd.)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\SearchScopes,DefaultScope = {A6ADA716-2865-4B33-AB86-FA2074DDBF9A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{A6ADA716-2865-4B33-AB86-FA2074DDBF9A}: "URL" = http://www.google.com/search?q={searchTerm…utputEncoding?}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@bestbuy.com/npBestBuyPcAppDetector,version=1.0: C:\ProgramData\Best Buy pc app\npBestBuyPcAppDetector.dll File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\amazon.com/AmazonMP3DownloaderPlugin: C:\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin1017300.dll (Amazon.com, Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/10/06 01:08:46 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/07/12 13:42:20 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/10/06 01:08:46 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/07/12 13:42:20 | 000,000,000 | —D | M]

[2012/02/23 12:10:40 | 000,000,000 | —D | M] (No name found) – C:\Users\Anitta\AppData\Roaming\Mozilla\Extensions
[2013/08/03 12:42:12 | 000,000,000 | —D | M] (No name found) – C:\Users\Anitta\AppData\Roaming\Mozilla\Firefox\Profiles\czpftlyz.default\extensions
[2012/02/23 12:10:10 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/10/06 01:08:44 | 000,266,720 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/10/06 01:08:32 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/10/06 01:08:32 | 000,002,253 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2013/08/20 21:44:05 | 000,000,855 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Webroot Vault) - {c8d5d964-2be8-4c5b-8cf5-6e975aa88504} - C:\ProgramData\WRData\pkg\LPBar.dll File not found
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Webroot Toolbar) - {97ab88ef-346b-4179-a0b1-7445896547a5} - C:\ProgramData\WRData\pkg\LPBar.dll File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [ETDCtrl] C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronics Corp.)
O4 - HKLM..\Run: [GfxServiceInstall] C:\Windows\System32\GfxCUIServiceInstall.vbs ()
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [Power Management] C:\Program Files\Gateway\Gateway Power Management\ePowerTray.exe (Acer Incorporated)
O4 - Startup: C:\Users\Anitta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Anitta\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Webroot - {43699cd0-e34f-11de-8a39-0800200c9a66} - C:\ProgramData\WRData\pkg\LPBar.dll File not found
O9 - Extra 'Tools' menuitem : Webroot - {43699cd0-e34f-11de-8a39-0800200c9a66} - C:\ProgramData\WRData\pkg\LPBar.dll File not found
O9 - Extra Button: @C:\Program Files\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra 'Tools' menuitem : @C:\Program Files\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://akamaicdn.webex.com/client/WBXclien…ex/ieatgpc1.cab (GpcContainer Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F729AFFD-A38F-454C-8F85-314E5F18C8EF}: DhcpNameServer = 10.0.0.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 17:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/08/20 22:00:32 | 000,000,000 | —D | C] – C:\Windows\SoftwareDistribution
[2013/08/20 21:56:32 | 000,000,000 | —D | C] – C:\Windows\System32\catroot2
[2013/08/20 20:17:15 | 000,000,000 | —D | C] – C:\RegBackup
[2013/08/20 19:28:54 | 000,181,064 | —- | C] (Sysinternals) – C:\Windows\PSEXESVC.EXE
[2013/08/20 19:27:22 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
[2013/08/20 19:27:15 | 000,000,000 | —D | C] – C:\Program Files\Tweaking.com
[2013/08/19 18:17:08 | 004,838,656 | —- | C] (F-Secure Corporation) – C:\Users\Anitta\Desktop\F-SecureOnlineScanner.exe
[2013/08/14 18:15:34 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2013/08/14 08:23:31 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2013/08/14 08:23:31 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2013/08/14 08:23:31 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2013/08/14 08:13:14 | 005,104,931 | R— | C] (Swearware) – C:\Users\Anitta\Desktop\ComboFix.exe
[2013/08/13 00:00:10 | 000,000,000 | —D | C] – C:\Windows\ERUNT
[2013/08/12 23:57:02 | 000,959,697 | —- | C] (Oleg N. Scherbakov) – C:\Users\Anitta\Desktop\JRT.exe
[2013/08/12 23:31:38 | 000,000,000 | —D | C] – C:\Users\Anitta\Desktop\Articles
[2013/08/12 06:35:29 | 004,745,728 | —- | C] (AVAST Software) – C:\Users\Anitta\Desktop\aswMBR.exe
[2013/08/12 06:09:14 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Anitta\Desktop\OTL.exe
[2013/08/11 18:54:03 | 002,240,864 | —- | C] (Kaspersky Lab ZAO) – C:\Users\Anitta\Desktop\iexplore.exe
[2013/08/11 16:58:58 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware3
[2013/08/11 16:58:54 | 000,022,856 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2013/08/11 16:58:54 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware3
[2013/08/11 16:58:13 | 010,284,816 | —- | C] (Malwarebytes Corporation ) – C:\Users\Anitta\Desktop\mbam-setup.exe
[2013/08/11 12:30:26 | 000,000,000 | —D | C] – C:\Users\Anitta\Desktop\RK_Quarantine
[2013/08/11 08:44:34 | 000,000,000 | —D | C] – C:\Users\Anitta\Desktop\rkill
[2013/08/10 23:05:01 | 000,000,000 | —D | C] – C:\Users\Anitta\Documents\ProcAlyzer Dumps
[2013/08/10 22:21:11 | 000,000,000 | —D | C] – C:\Qoobox
[2013/08/10 22:20:53 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2013/08/10 20:54:30 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware2
[2013/08/10 20:54:28 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware2
[2013/07/31 23:29:55 | 000,000,000 | —D | C] – C:\Users\Anitta\AppData\Roaming\dvdcss
[2013/07/31 23:25:55 | 000,000,000 | —D | C] – C:\Users\Anitta\Documents\dvdsmith
[2013/07/31 23:25:41 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDSmith Movie Backup
[2013/07/31 23:25:37 | 000,000,000 | —D | C] – C:\Program Files\DVDSmith Movie Backup
[2013/07/31 22:38:19 | 001,847,424 | —- | C] (Bleeping Computer, LLC) – C:\Users\Anitta\Desktop\rkill.com
[2013/07/31 21:13:29 | 000,000,000 | —D | C] – C:\ProgramData\DVD Shrink
[2013/07/31 20:43:32 | 000,000,000 | —D | C] – C:\Users\Anitta\AppData\Roaming\HandBrake
[2013/07/31 20:42:39 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Handbrake
[2013/07/12 18:02:57 | 009,842,040 | —- | C] (Webroot Software, Inc.) – C:\Program Files\Common Files\wruninstall.exe

========== Files - Modified Within 30 Days ==========

[2013/08/20 22:06:01 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/08/20 22:05:38 | 000,016,480 | —- | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/08/20 22:05:38 | 000,016,480 | —- | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/08/20 22:02:46 | 000,624,206 | —- | M] () – C:\Windows\System32\perfh009.dat
[2013/08/20 22:02:46 | 000,106,550 | —- | M] () – C:\Windows\System32\perfc009.dat
[2013/08/20 21:56:10 | 000,402,688 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2013/08/20 21:56:01 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/08/20 21:55:37 | 796,102,656 | -HS- | M] () – C:\hiberfil.sys
[2013/08/20 21:53:16 | 000,181,064 | —- | M] (Sysinternals) – C:\Windows\PSEXESVC.EXE
[2013/08/20 21:44:05 | 000,000,855 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2013/08/20 20:42:49 | 000,000,855 | —- | M] () – C:\Windows\System32\drivers\etc\hosts_bak_861
[2013/08/20 20:19:22 | 000,000,207 | —- | M] () – C:\Windows\tweaking.com-regbackup-ANITTA-PC-Microsoft-Windows-7-Starter-(32-bit).dat
[2013/08/20 19:40:53 | 000,003,288 | —- | M] () – C:\bootsqm.dat
[2013/08/20 19:27:38 | 000,002,124 | —- | M] () – C:\Users\Anitta\Desktop\Tweaking.com - Windows Repair (All in One).lnk
[2013/08/20 19:18:08 | 005,373,340 | —- | M] () – C:\Users\Anitta\Desktop\tweaking.com_windows_repair_aio_setup.exe
[2013/08/19 18:17:09 | 004,838,656 | —- | M] (F-Secure Corporation) – C:\Users\Anitta\Desktop\F-SecureOnlineScanner.exe
[2013/08/19 02:02:45 | 002,374,481 | —- | M] () – C:\Users\Anitta\Documents\Constructing Meaning.Beers.pdf
[2013/08/18 21:56:14 | 000,049,327 | —- | M] () – C:\Users\Anitta\Desktop\Designation_of_Beneficiary_Form.pdf
[2013/08/18 21:36:50 | 000,029,738 | —- | M] () – C:\Users\Anitta\Documents\Memo_for_Computer_Use_Policy.pdf
[2013/08/18 21:29:29 | 000,130,169 | —- | M] () – C:\Users\Anitta\Documents\direct-deposit-enrollment-only-revised-11_09.pdf
[2013/08/18 21:28:05 | 000,044,457 | —- | M] () – C:\Users\Anitta\Documents\NYS_Oath.pdf
[2013/08/18 21:26:20 | 000,032,410 | —- | M] () – C:\Users\Anitta\Documents\Agency_Shop_Agreement.pdf
[2013/08/18 21:24:52 | 000,018,741 | —- | M] () – C:\Users\Anitta\Documents\Emergency_Contacts.pdf
[2013/08/18 21:21:18 | 000,043,403 | —- | M] () – C:\Users\Anitta\Documents\Authorization_for_Release_of_Information.pdf
[2013/08/16 13:28:12 | 000,065,337 | —- | M] () – C:\Users\Anitta\Documents\Personal_Data-Affirmative_Action_Form.pdf
[2013/08/16 13:22:36 | 000,102,870 | —- | M] () – C:\Users\Anitta\Documents\Conviction_Notice-Civil_Service-OFSR-602A.pdf
[2013/08/16 13:12:57 | 000,249,651 | —- | M] () – C:\Users\Anitta\Documents\IT-2104.pdf
[2013/08/16 13:09:24 | 000,064,278 | —- | M] () – C:\Users\Anitta\Documents\W-4.pdf
[2013/08/16 13:04:01 | 000,005,345 | —- | M] () – C:\Users\Anitta\Documents\I-9.pdf
[2013/08/16 12:56:31 | 000,198,723 | —- | M] () – C:\Users\Anitta\Documents\Civil_Service_Application.pdf
[2013/08/14 18:07:42 | 000,000,027 | —- | M] () – C:\Windows\System32\drivers\etc\hosts_bak_499
[2013/08/14 17:39:57 | 005,104,931 | R— | M] (Swearware) – C:\Users\Anitta\Desktop\ComboFix.exe
[2013/08/13 00:07:53 | 000,920,576 | —- | M] () – C:\Users\Anitta\Desktop\RogueKiller.exe
[2013/08/12 23:57:02 | 000,959,697 | —- | M] (Oleg N. Scherbakov) – C:\Users\Anitta\Desktop\JRT.exe
[2013/08/12 23:39:02 | 000,666,633 | —- | M] () – C:\Users\Anitta\Desktop\adwcleaner.exe
[2013/08/12 23:33:52 | 000,891,115 | —- | M] () – C:\Users\Anitta\Desktop\SecurityCheck.exe
[2013/08/12 08:36:07 | 000,000,565 | —- | M] () – C:\Users\Anitta\Desktop\MBR.zip
[2013/08/12 08:35:42 | 000,000,512 | —- | M] () – C:\Users\Anitta\Desktop\MBR.dat
[2013/08/12 07:48:24 | 004,745,728 | —- | M] (AVAST Software) – C:\Users\Anitta\Desktop\aswMBR.exe
[2013/08/12 06:09:14 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Anitta\Desktop\OTL.exe
[2013/08/11 18:54:03 | 002,240,864 | —- | M] (Kaspersky Lab ZAO) – C:\Users\Anitta\Desktop\iexplore.exe
[2013/08/11 16:58:59 | 000,001,081 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/08/11 16:58:14 | 010,284,816 | —- | M] (Malwarebytes Corporation ) – C:\Users\Anitta\Desktop\mbam-setup.exe
[2013/08/01 15:20:31 | 000,002,327 | —- | M] () – C:\Users\Anitta\Documents\Arcangel Idas y Vueltas.wlmp
[2013/07/31 23:25:44 | 000,001,068 | —- | M] () – C:\Users\Anitta\Desktop\DVDSmith Movie Backup.lnk
[2013/07/31 22:38:21 | 001,847,424 | —- | M] (Bleeping Computer, LLC) – C:\Users\Anitta\Desktop\rkill.com

========== Files Created - No Company Name ==========

[2013/08/20 20:19:22 | 000,000,207 | —- | C] () – C:\Windows\tweaking.com-regbackup-ANITTA-PC-Microsoft-Windows-7-Starter-(32-bit).dat
[2013/08/20 19:40:53 | 000,003,288 | —- | C] () – C:\bootsqm.dat
[2013/08/20 19:27:37 | 000,002,124 | —- | C] () – C:\Users\Anitta\Desktop\Tweaking.com - Windows Repair (All in One).lnk
[2013/08/20 19:18:07 | 005,373,340 | —- | C] () – C:\Users\Anitta\Desktop\tweaking.com_windows_repair_aio_setup.exe
[2013/08/19 02:02:44 | 002,374,481 | —- | C] () – C:\Users\Anitta\Documents\Constructing Meaning.Beers.pdf
[2013/08/18 22:00:58 | 000,049,327 | —- | C] () – C:\Users\Anitta\Desktop\Designation_of_Beneficiary_Form.pdf
[2013/08/18 21:37:00 | 000,029,738 | —- | C] () – C:\Users\Anitta\Documents\Memo_for_Computer_Use_Policy.pdf
[2013/08/18 21:29:38 | 000,130,169 | —- | C] () – C:\Users\Anitta\Documents\direct-deposit-enrollment-only-revised-11_09.pdf
[2013/08/18 21:28:13 | 000,044,457 | —- | C] () – C:\Users\Anitta\Documents\NYS_Oath.pdf
[2013/08/18 21:26:31 | 000,032,410 | —- | C] () – C:\Users\Anitta\Documents\Agency_Shop_Agreement.pdf
[2013/08/18 21:25:02 | 000,018,741 | —- | C] () – C:\Users\Anitta\Documents\Emergency_Contacts.pdf
[2013/08/18 21:21:31 | 000,043,403 | —- | C] () – C:\Users\Anitta\Documents\Authorization_for_Release_of_Information.pdf
[2013/08/16 13:28:18 | 000,065,337 | —- | C] () – C:\Users\Anitta\Documents\Personal_Data-Affirmative_Action_Form.pdf
[2013/08/16 13:22:41 | 000,102,870 | —- | C] () – C:\Users\Anitta\Documents\Conviction_Notice-Civil_Service-OFSR-602A.pdf
[2013/08/16 13:13:08 | 000,249,651 | —- | C] () – C:\Users\Anitta\Documents\IT-2104.pdf
[2013/08/16 13:09:29 | 000,064,278 | —- | C] () – C:\Users\Anitta\Documents\W-4.pdf
[2013/08/16 13:04:07 | 000,005,345 | —- | C] () – C:\Users\Anitta\Documents\I-9.pdf
[2013/08/16 12:56:41 | 000,198,723 | —- | C] () – C:\Users\Anitta\Documents\Civil_Service_Application.pdf
[2013/08/14 08:23:31 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2013/08/14 08:23:31 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2013/08/14 08:23:31 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2013/08/14 08:23:31 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2013/08/14 08:23:31 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2013/08/13 00:07:53 | 000,920,576 | —- | C] () – C:\Users\Anitta\Desktop\RogueKiller.exe
[2013/08/12 23:39:02 | 000,666,633 | —- | C] () – C:\Users\Anitta\Desktop\adwcleaner.exe
[2013/08/12 23:33:52 | 000,891,115 | —- | C] () – C:\Users\Anitta\Desktop\SecurityCheck.exe
[2013/08/12 08:36:07 | 000,000,565 | —- | C] () – C:\Users\Anitta\Desktop\MBR.zip
[2013/08/12 08:35:42 | 000,000,512 | —- | C] () – C:\Users\Anitta\Desktop\MBR.dat
[2013/08/11 16:58:59 | 000,001,081 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/08/01 15:20:03 | 000,002,327 | —- | C] () – C:\Users\Anitta\Documents\Arcangel Idas y Vueltas.wlmp
[2013/07/31 23:25:44 | 000,001,068 | —- | C] () – C:\Users\Anitta\Desktop\DVDSmith Movie Backup.lnk
[2013/07/11 23:14:03 | 000,002,548 | —- | C] () – C:\ProgramData\LUUnInstall.LiveUpdate
[2012/03/30 10:40:32 | 000,088,656 | —- | C] () – C:\Windows\System32\cpwmon2k.dll
[2012/02/28 10:49:42 | 000,188,200 | —- | C] () – C:\Windows\System32\mlfcache.dat
[2012/01/20 17:45:27 | 000,039,672 | —- | C] () – C:\Windows\System32\drivers\RtPCEE3.DAT
[2012/01/20 17:45:27 | 000,033,076 | —- | C] () – C:\Windows\System32\drivers\RtPCEE4.DAT
[2012/01/20 17:45:27 | 000,001,448 | —- | C] () – C:\Windows\System32\drivers\RtHdatEx.dat
[2012/01/20 17:45:27 | 000,000,176 | —- | C] () – C:\Windows\System32\drivers\RTHDAEQ1.dat
[2012/01/20 17:45:27 | 000,000,032 | —- | C] () – C:\Windows\System32\drivers\rtkhdaud.dat
[2012/01/20 17:45:26 | 000,247,560 | —- | C] () – C:\Windows\System32\drivers\RTConvEQ.dat
[2012/01/20 17:45:26 | 000,000,520 | —- | C] () – C:\Windows\System32\drivers\RTEQEX3.dat
[2012/01/20 17:45:26 | 000,000,520 | —- | C] () – C:\Windows\System32\drivers\RTEQEX2.dat
[2012/01/20 17:45:26 | 000,000,520 | —- | C] () – C:\Windows\System32\drivers\RTEQEX1.dat
[2012/01/20 17:45:26 | 000,000,520 | —- | C] () – C:\Windows\System32\drivers\RTEQEX0.dat
[2012/01/20 17:42:24 | 000,080,416 | —- | C] () – C:\Windows\System32\RtNicProp32.dll
[2012/01/06 03:49:32 | 000,004,096 | —- | C] ( ) – C:\Windows\System32\IGFXDEVLib.dll
[2012/01/06 03:49:31 | 000,000,151 | —- | C] () – C:\Windows\System32\GfxUI.exe.config

========== ZeroAccess Check ==========

[2009/07/14 00:42:31 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/02/27 00:55:05 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\Windows\system32\wbem\fastprox.dll – [2010/11/20 17:29:20 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\Windows\system32\wbem\wbemess.dll – [2009/07/13 21:16:17 | 000,342,528 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2012/10/04 22:30:22 | 000,000,000 | —D | M] – C:\Users\Anitta\AppData\Roaming\Amazon
[2013/08/11 19:45:21 | 000,000,000 | —D | M] – C:\Users\Anitta\AppData\Roaming\Audacity
[2013/08/20 21:59:44 | 000,000,000 | —D | M] – C:\Users\Anitta\AppData\Roaming\Dropbox
[2013/02/05 17:34:38 | 000,000,000 | —D | M] – C:\Users\Anitta\AppData\Roaming\FreeImageConverter
[2013/07/31 20:48:35 | 000,000,000 | —D | M] – C:\Users\Anitta\AppData\Roaming\HandBrake
[2013/06/06 00:15:49 | 000,000,000 | —D | M] – C:\Users\Anitta\AppData\Roaming\SNS
[2013/04/10 11:47:05 | 000,000,000 | —D | M] – C:\Users\Anitta\AppData\Roaming\webex
[2013/06/20 10:22:25 | 000,000,000 | —D | M] – C:\Users\Anitta\AppData\Roaming\Windows Live Writer

========== Purity Check ==========



< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI