This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Internet Explorer, Windows Live Mail, Hard Drive, Files and Documents

24 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Please download AdwCleaner by Xplode and save to your Desktop.
  • Double click on AdwCleaner.exe to run the tool.
    Vista/Windows 7/8 users right-click and select Run As Administrator.
  • Click on the Scan button.
  • AdwCleaner will begin…be patient as the scan may take some time to complete.
  • After the scan has finished, click on the Report button…a logfile (AdwCleaner[R0].txt) will open in Notepad for review.
  • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.
# AdwCleaner v3.005 - Report created 28/09/2013 at 00:29:05 # Updated 22/09/2013 by Xplode # Operating System : Windows 7 Home Premium Service Pack 1 (64 bits) # Username : dogonit23 - DOGONIT23-HP # Running from : C:\Users\dogonit23\Desktop\Extras\Fix\AdwCleaner.exe # Option : Scan ***** [ Services ] ***** ***** [ Files / Folders ] ***** File Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eBay.lnk File Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eBay.lnk File Found : C:\Users\dogonit23\AppData\Roaming\Mozilla\Firefox\Profiles\qfgmkrbu.default\user.js Folder Found C:\ProgramData\Uniblue\DriverScanner Folder Found C:\Users\dogonit23\AppData\Roaming\OpenCandy ***** [ Shortcuts ] ***** ***** [ Registry ] ***** Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{898EA8C8-E7FF-479B-8935-AEC46303B9E5} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Found : HKCU\Software\SmartBar Key Found : [x64] HKCU\Software\SmartBar Key Found : HKLM\SOFTWARE\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5} Key Found : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113} Key Found : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5} Key Found : HKLM\SOFTWARE\Microsoft\Tracing\QuickShare_RASAPI32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\QuickShare_RASMANCS Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5} Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113} Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Value Found : HKCU\Software\Microsoft\Internet Explorer\Main [Backup.old.Start Page] Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}] Value Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}] ***** [ Browsers ] ***** -\\ Internet Explorer v10.0.9200.16686 -\\ Mozilla Firefox v23.0.1 (en-US) [ File : C:\Users\dogonit23\AppData\Roaming\Mozilla\Firefox\Profiles\qfgmkrbu.default\prefs.js ] ************************* AdwCleaner[R0].txt - [4348 octets] - [13/09/2013 12:18:27] AdwCleaner[R1].txt - [4408 octets] - [13/09/2013 12:43:24] AdwCleaner[R2].txt - [2941 octets] - [28/09/2013 00:29:05] AdwCleaner[S0].txt - [3959 octets] - [13/09/2013 12:44:46] ########## EOF - C:\AdwCleaner\AdwCleaner[R2].txt - [3061 octets] ##########
Hi,

Double click on AdwCleaner.exe to run the tool again.
  • Click on the Scan button.
  • AdwCleaner will begin to scan your computer like it did before.
  • After the scan has finished…
    <-insert any special instructions here for what to uncheck OR remove this line if there are none->
  • This time click on the Clean button.
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
  • After rebooting, a logfile report (AdwCleaner[S0].txt) will open automatically.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of that logfile will also be saved in the C:\AdwCleaner folder.
===================================================

Please download Junkware Removal Tool to your desktop.
  • Shutdown your antivirus to avoid any conflicts.
  • Right-mouse click JRT.exe and select Run as administrator
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message
===================================================

On your next reply please post :
Adwcleaner log
JRT log


Please STOP and let me know if you have any problems in performing with the steps above or any questions you may have.
# AdwCleaner v3.005 - Report created 28/09/2013 at 18:25:51 # Updated 22/09/2013 by Xplode # Operating System : Windows 7 Home Premium Service Pack 1 (64 bits) # Username : dogonit23 - DOGONIT23-HP # Running from : C:\Users\dogonit23\Desktop\Extras\Fix\AdwCleaner.exe # Option : Clean ***** [ Services ] ***** ***** [ Files / Folders ] ***** Folder Deleted : C:\ProgramData\Uniblue\DriverScanner Folder Deleted : C:\Users\dogonit23\AppData\Roaming\OpenCandy File Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eBay.lnk File Deleted : C:\Users\dogonit23\AppData\Roaming\Mozilla\Firefox\Profiles\qfgmkrbu.default\user.js ***** [ Shortcuts ] ***** ***** [ Registry ] ***** Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [Backup.old.Start Page] Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\QuickShare_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\QuickShare_RASMANCS Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{898EA8C8-E7FF-479B-8935-AEC46303B9E5} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5} Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}] Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5} Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113} Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Value Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}] Key Deleted : HKCU\Software\SmartBar Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} ***** [ Browsers ] ***** -\\ Internet Explorer v10.0.9200.16686 -\\ Mozilla Firefox v23.0.1 (en-US) [ File : C:\Users\dogonit23\AppData\Roaming\Mozilla\Firefox\Profiles\qfgmkrbu.default\prefs.js ] ************************* AdwCleaner[R0].txt - [4348 octets] - [13/09/2013 12:18:27] AdwCleaner[R1].txt - [4408 octets] - [13/09/2013 12:43:24] AdwCleaner[R2].txt - [3165 octets] - [28/09/2013 00:29:05] AdwCleaner[R3].txt - [3334 octets] - [28/09/2013 18:12:01] AdwCleaner[R4].txt - [3394 octets] - [28/09/2013 18:16:38] AdwCleaner[S0].txt - [3959 octets] - [13/09/2013 12:44:46] AdwCleaner[S1].txt - [3229 octets] - [28/09/2013 18:25:51] ########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [3289 octets] ########## ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.0.3 (09.27.2013:1) OS: Windows 7 Home Premium x64 Ran by [removed] on Sat 09/28/2013 at 19:01:45.80 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{48A789BF-F6D6-4930-9C8B-77855A63EDE1} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\adawarebp Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{329DF456-2B9A-1254-3222-23D6BB4C8442} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{4408C5D3-D063-47B7-F412-10B06D154E1C} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{5B79D585-7A5A-4418-B472-F710C358C633} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{A9C475D2-0D39-C58A-F73C-57614B472EAC} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{ec29edf6-ad3c-4e1c-a087-d6cb81400c43} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{48A789BF-F6D6-4930-9C8B-77855A63EDE1} ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\Users\dogonit23\appdata\local\adawarebp" Successfully deleted: [Folder] "C:\Program Files (x86)\secure speed dial" ~~~ FireFox Successfully deleted: [File] C:\user.js Emptied folder: C:\Users\dogonit23\AppData\Roaming\mozilla\firefox\profiles\qfgmkrbu.default\minidumps [3 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on Sat 09/28/2013 at 19:11:45.99 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
ComboFix messed up my computer again. I could only complete stage 4 and on stage 5 after 30 minutes I just stopped it. When I tried using IE to write to you it wouldn't start like the last time I used CF. So I just turned off my computer and went to sleep.
Sometimes it takes ComboFix more than 30 minutes to complete the scan. It would be a good idea to leave it maximum 2 hours before force stop manually. Most likely at stage 4 it is still doing something behind. Leave it until the whole night if possible. If the next morning CF still hanging at stage 4, force close it and try running it under safe mode.
OK, took a while to get through stage 5, but finished finally. Here is the report….


ComboFix 13-09-28.02 - dogonit23 09/29/2013 14:22:44.5.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3835.2850 [GMT -7:00]
Running from: c:\users\[removed]\Desktop\Extras\Fix\ComboFix.exe
AV: Lavasoft Ad-Aware *Disabled/Updated* {E0D97DD4-42BA-B3F2-A5A7-22E9ACE81FC7}
AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
FW: Lavasoft Ad-Aware *Disabled* {D8E2FCF1-08D5-B2AA-8EF8-8BDC523B58BC}
SP: IObit Malware Fighter *Enabled/Updated* {A751AC20-3B48-5237-898A-78C4436BB78D}
SP: Lavasoft Ad-Aware *Disabled/Updated* {5BB89C30-6480-BC7C-9F17-199BD76F557A}
SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2013-08-28 to 2013-09-29 )))))))))))))))))))))))))))))))
.
.
2013-09-29 22:01 . 2013-09-29 22:01 ——– d—–w- c:\users\Public\AppData\Local\temp
2013-09-29 22:01 . 2013-09-29 22:01 ——– d—–w- c:\users\Default\AppData\Local\temp
2013-09-29 22:01 . 2013-09-29 22:01 ——– d—–w- c:\users\Administrator\AppData\Local\temp
2013-09-29 19:01 . 2013-09-29 19:01 ——– d—–w- c:\users\dogonit23\AppData\Roaming\com.aligmarketing.slf
2013-09-29 19:01 . 2013-09-29 19:01 ——– d—–w- c:\program files (x86)\slf
2013-09-29 17:07 . 2013-09-05 05:32 9694160 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{92BBE67E-BEF1-446E-813E-B21B1496B4F3}\mpengine.dll
2013-09-29 02:01 . 2013-09-29 02:01 ——– d—–w- c:\windows\ERUNT
2013-09-28 07:02 . 2013-09-05 05:32 9694160 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-09-26 06:19 . 2013-09-26 06:19 ——– d—–w- C:\FRST
2013-09-24 22:37 . 2013-09-24 22:39 ——– d—–w- c:\users\dogonit23\AppData\Local\FreeScreenSharing
2013-09-24 03:09 . 2013-09-24 03:11 ——– d—–w- c:\users\dogonit23\AppData\Roaming\VDownloader
2013-09-24 03:01 . 2013-09-24 07:41 ——– d—–w- c:\users\dogonit23\AppData\Local\VDownloader
2013-09-24 03:01 . 2010-01-26 18:11 444283 —-a-w- c:\program files\Common Files\WinPcapNmap.exe
2013-09-24 03:00 . 2013-09-29 04:58 ——– d—–w- c:\program files\VDownloader
2013-09-21 03:46 . 2013-09-24 18:16 ——– d—–w- c:\programdata\Spybot - Search & Destroy
2013-09-21 03:44 . 2013-09-25 12:17 ——– d—–w- c:\program files (x86)\Spybot - Search & Destroy 2
2013-09-20 19:10 . 2013-09-29 01:25 ——– d—–w- c:\programdata\Uniblue
2013-09-20 06:08 . 2013-09-20 06:08 ——– d—–w- c:\users\dogonit23\AppData\Roaming\IsolatedStorage
2013-09-20 06:08 . 2013-09-20 06:08 ——– d—–w- c:\programdata\IsolatedStorage
2013-09-20 06:06 . 2013-09-20 06:06 ——– d—–w- c:\users\dogonit23\AppData\Roaming\EasyEmailSender
2013-09-20 06:06 . 2013-09-20 06:06 ——– d—–w- C:\temp
2013-09-20 06:06 . 2013-09-20 06:06 ——– d—–w- c:\program files (x86)\EasyEmailSender
2013-09-20 05:58 . 2013-09-20 05:58 ——– d—–w- c:\users\dogonit23\AppData\Local\Downloaded Installations
2013-09-19 05:06 . 2013-09-19 05:06 ——– d-sh–w- c:\windows\ftpcache
2013-09-19 05:05 . 2013-09-19 05:06 ——– d—–w- c:\program files (x86)\FLV-Media Player
2013-09-18 10:02 . 2013-09-18 10:02 ——– d—–w- c:\program files (x86)\Microsoft CAPICOM 2.1.0.2
2013-09-17 09:04 . 2013-05-23 01:49 17720 —-a-w- c:\windows\system32\drivers\SmartDefragDriver.sys
2013-09-16 19:03 . 2013-09-16 19:03 ——– d—–w- c:\program files (x86)\AdminSystem.NET
2013-09-15 09:33 . 2013-09-15 09:33 ——– d—–w- c:\programdata\RegInOut
2013-09-15 09:12 . 2013-09-15 09:12 ——– d—–w- c:\programdata\GlarySoft
2013-09-15 00:19 . 2013-04-18 03:20 26432 —-a-w- c:\windows\system32\RegistryDefragBootTime.exe
2013-09-14 23:58 . 2013-09-02 09:09 117024 —-a-w- c:\windows\system32\BootDefrag.exe
2013-09-14 23:58 . 2013-09-14 23:58 ——– d—–w- c:\users\dogonit23\AppData\Roaming\GlarySoft
2013-09-14 23:58 . 2013-09-19 23:45 ——– d—–w- c:\program files (x86)\Glary Utilities 3
2013-09-14 23:44 . 2013-09-15 09:33 ——– d—–w- c:\program files (x86)\RegInOut System Utilities
2013-09-14 23:08 . 2013-08-16 00:31 268968 —-a-w- c:\windows\SysWow64\sqlite3.dll
2013-09-14 23:07 . 2013-09-14 23:07 ——– d—–w- c:\programdata\{CED89F1A-945F-46EC-B23C-5EAF6D2DB12A}
2013-09-14 23:07 . 2013-09-14 23:08 ——– d—–w- c:\programdata\IObit
2013-09-14 23:06 . 2013-09-17 09:04 ——– d—–w- c:\users\dogonit23\AppData\Roaming\IObit
2013-09-14 23:06 . 2013-09-17 09:04 ——– d—–w- c:\program files (x86)\IObit
2013-09-13 19:14 . 2013-09-29 01:26 ——– d—–w- C:\AdwCleaner
2013-09-13 08:31 . 2013-08-10 05:22 1084928 —-a-w- c:\program files\Common Files\Microsoft Shared\VGX\VGX.dll
2013-09-13 08:31 . 2013-08-10 03:59 817664 —-a-w- c:\program files (x86)\Common Files\Microsoft Shared\VGX\VGX.dll
2013-09-13 08:31 . 2013-08-10 05:21 53248 —-a-w- c:\windows\system32\jsproxy.dll
2013-09-13 08:31 . 2013-08-10 03:59 1767936 —-a-w- c:\windows\SysWow64\wininet.dll
2013-09-13 08:31 . 2013-08-10 05:22 2241024 —-a-w- c:\windows\system32\wininet.dll
2013-09-13 08:31 . 2013-08-10 05:20 15404544 —-a-w- c:\windows\system32\ieframe.dll
2013-09-13 08:31 . 2013-08-10 05:21 19246592 —-a-w- c:\windows\system32\mshtml.dll
2013-09-12 01:14 . 2013-08-05 02:25 155584 —-a-w- c:\windows\system32\drivers\ataport.sys
2013-09-12 01:14 . 2013-08-02 01:59 3968960 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe
2013-09-12 01:14 . 2013-08-02 01:59 3913664 —-a-w- c:\windows\SysWow64\ntoskrnl.exe
2013-09-12 01:14 . 2013-08-02 02:23 5550528 —-a-w- c:\windows\system32\ntoskrnl.exe
2013-09-12 01:14 . 2013-08-02 02:15 1732032 —-a-w- c:\windows\system32\ntdll.dll
2013-09-12 01:14 . 2013-08-02 02:13 424448 —-a-w- c:\windows\system32\KernelBase.dll
2013-09-12 01:14 . 2013-08-02 01:51 1292192 —-a-w- c:\windows\SysWow64\ntdll.dll
2013-09-12 01:06 . 2013-08-08 01:20 3155456 —-a-w- c:\windows\system32\win32k.sys
2013-09-12 01:06 . 2013-07-26 02:24 14172672 —-a-w- c:\windows\system32\shell32.dll
2013-09-12 01:06 . 2013-07-26 02:24 197120 —-a-w- c:\windows\system32\shdocvw.dll
2013-09-09 06:55 . 2013-09-09 06:55 ——– d—–w- c:\users\dogonit23\AppData\Local\Geckofx
2013-09-06 18:46 . 2013-09-06 17:21 965008 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6C1C8E88-806D-40E1-A05F-836CF1B04488}\gapaengine.dll
2013-09-04 01:40 . 2013-09-13 20:43 ——– d—–w- c:\users\dogonit23\7 Minute Research
2013-09-02 21:03 . 2013-09-02 22:10 ——– d—–w- c:\users\dogonit23\AppData\Local\xheader-data
2013-09-02 21:03 . 2013-09-02 21:03 205717 —-a-w- c:\windows\XHeader Uninstaller.exe
2013-09-02 21:02 . 2013-09-02 21:02 ——– d—–w- c:\program files (x86)\XHeader
2013-09-02 21:02 . 2013-09-02 21:02 ——– d—–w- c:\program files (x86)\Common Files\Thraex Software
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-09-23 17:13 . 2013-05-07 21:30 692616 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-09-23 17:13 . 2013-05-07 21:30 71048 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-09-13 08:25 . 2013-05-07 19:01 79143768 —-a-w- c:\windows\system32\MRT.exe
2013-08-30 20:37 . 2013-08-30 20:37 163273 —-a-w- c:\windows\Nexus Toolbar Uninstaller.exe
2013-08-23 17:59 . 2013-05-21 18:09 941720 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2013-08-06 19:39 . 2013-08-06 19:39 47496 —-a-w- c:\windows\system32\sbbd.exe
2013-08-06 19:39 . 2013-08-06 19:39 14456 —-a-w- c:\windows\system32\drivers\gfibto.sys
2013-08-02 01:48 . 2013-09-12 01:13 44032 —-a-w- c:\windows\apppatch\acwow64.dll
2013-07-25 09:25 . 2013-08-14 17:39 1888768 —-a-w- c:\windows\system32\WMVDECOD.DLL
2013-07-25 08:57 . 2013-08-14 17:39 1620992 —-a-w- c:\windows\SysWow64\WMVDECOD.DLL
2013-07-19 01:58 . 2013-08-14 17:39 2048 —-a-w- c:\windows\system32\tzres.dll
2013-07-19 01:41 . 2013-08-14 17:39 2048 —-a-w- c:\windows\SysWow64\tzres.dll
2013-07-09 05:52 . 2013-08-14 17:39 224256 —-a-w- c:\windows\system32\wintrust.dll
2013-07-09 05:51 . 2013-08-14 17:40 1217024 —-a-w- c:\windows\system32\rpcrt4.dll
2013-07-09 05:46 . 2013-08-14 17:40 1472512 —-a-w- c:\windows\system32\crypt32.dll
2013-07-09 05:46 . 2013-08-14 17:39 184320 —-a-w- c:\windows\system32\cryptsvc.dll
2013-07-09 05:46 . 2013-08-14 17:39 139776 —-a-w- c:\windows\system32\cryptnet.dll
2013-07-09 04:52 . 2013-08-14 17:40 663552 —-a-w- c:\windows\SysWow64\rpcrt4.dll
2013-07-09 04:52 . 2013-08-14 17:39 175104 —-a-w- c:\windows\SysWow64\wintrust.dll
2013-07-09 04:46 . 2013-08-14 17:40 1166848 —-a-w- c:\windows\SysWow64\crypt32.dll
2013-07-09 04:46 . 2013-08-14 17:39 140288 —-a-w- c:\windows\SysWow64\cryptsvc.dll
2013-07-09 04:46 . 2013-08-14 17:39 103936 —-a-w- c:\windows\SysWow64\cryptnet.dll
2013-07-06 06:03 . 2013-08-14 17:36 1910208 —-a-w- c:\windows\system32\drivers\tcpip.sys
2013-07-03 17:34 . 2013-07-03 17:34 1054720 —-a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2013-07-03 17:33 . 2013-07-03 17:33 226304 —-a-w- c:\windows\system32\elshyph.dll
2013-07-03 17:33 . 2013-07-03 17:33 185344 —-a-w- c:\windows\SysWow64\elshyph.dll
2013-07-03 17:33 . 2013-07-03 17:33 158720 —-a-w- c:\windows\SysWow64\msls31.dll
2013-07-03 17:33 . 2013-07-03 17:33 719360 —-a-w- c:\windows\SysWow64\mshtmlmedia.dll
2013-07-03 17:33 . 2013-07-03 17:33 150528 —-a-w- c:\windows\SysWow64\iexpress.exe
2013-07-03 17:33 . 2013-07-03 17:33 138752 —-a-w- c:\windows\SysWow64\wextract.exe
2013-07-03 17:33 . 2013-07-03 17:33 523264 —-a-w- c:\windows\SysWow64\vbscript.dll
2013-07-03 17:33 . 2013-07-03 17:33 137216 —-a-w- c:\windows\SysWow64\ieUnatt.exe
2013-07-03 17:33 . 2013-07-03 17:33 73728 —-a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2013-07-03 17:33 . 2013-07-03 17:33 61952 —-a-w- c:\windows\SysWow64\tdc.ocx
2013-07-03 17:33 . 2013-07-03 17:33 48640 —-a-w- c:\windows\SysWow64\mshtmler.dll
2013-07-03 17:33 . 2013-07-03 17:33 38400 —-a-w- c:\windows\SysWow64\imgutil.dll
2013-07-03 17:33 . 2013-07-03 17:33 361984 —-a-w- c:\windows\SysWow64\html.iec
2013-07-03 17:33 . 2013-07-03 17:33 12800 —-a-w- c:\windows\SysWow64\mshta.exe
2013-07-03 17:33 . 2013-07-03 17:33 110592 —-a-w- c:\windows\SysWow64\IEAdvpack.dll
2013-07-03 17:33 . 2013-07-03 17:33 23040 —-a-w- c:\windows\SysWow64\licmgr10.dll
2013-07-03 17:33 . 2013-07-03 17:33 1441280 —-a-w- c:\windows\SysWow64\inetcpl.cpl
2013-07-03 17:33 . 2013-07-03 17:33 81408 —-a-w- c:\windows\system32\icardie.dll
2013-07-03 17:33 . 2013-07-03 17:33 762368 —-a-w- c:\windows\system32\ieapfltr.dll
2013-07-03 17:33 . 2013-07-03 17:33 452096 —-a-w- c:\windows\system32\dxtmsft.dll
2013-07-03 17:33 . 2013-07-03 17:33 441856 —-a-w- c:\windows\system32\html.iec
2013-07-03 17:33 . 2013-07-03 17:33 281600 —-a-w- c:\windows\system32\dxtrans.dll
2013-07-03 17:33 . 2013-07-03 17:33 216064 —-a-w- c:\windows\system32\msls31.dll
2013-07-03 17:33 . 2013-07-03 17:33 197120 —-a-w- c:\windows\system32\msrating.dll
2013-07-03 17:33 . 2013-07-03 17:33 1400416 —-a-w- c:\windows\system32\ieapfltr.dat
2013-07-03 17:33 . 2013-07-03 17:33 905728 —-a-w- c:\windows\system32\mshtmlmedia.dll
2013-07-03 17:33 . 2013-07-03 17:33 27648 —-a-w- c:\windows\system32\licmgr10.dll
2013-07-03 17:33 . 2013-07-03 17:33 270848 —-a-w- c:\windows\system32\iedkcs32.dll
2013-07-03 17:33 . 2013-07-03 17:33 247296 —-a-w- c:\windows\system32\webcheck.dll
2013-07-03 17:33 . 2013-07-03 17:33 235008 —-a-w- c:\windows\system32\url.dll
2013-07-03 17:33 . 2013-07-03 17:33 1509376 —-a-w- c:\windows\system32\inetcpl.cpl
2013-07-03 17:33 . 2013-07-03 17:33 102912 —-a-w- c:\windows\system32\inseng.dll
2013-07-03 17:33 . 2013-07-03 17:33 97280 —-a-w- c:\windows\system32\mshtmled.dll
2013-07-03 17:33 . 2013-07-03 17:33 599552 —-a-w- c:\windows\system32\vbscript.dll
2013-07-03 17:33 . 2013-07-03 17:33 173568 —-a-w- c:\windows\system32\ieUnatt.exe
2013-07-03 17:33 . 2013-07-03 17:33 167424 —-a-w- c:\windows\system32\iexpress.exe
2013-07-03 17:33 . 2013-07-03 17:33 144896 —-a-w- c:\windows\system32\wextract.exe
2013-07-03 17:33 . 2013-07-03 17:33 149504 —-a-w- c:\windows\system32\occache.dll
2013-07-03 17:33 . 2013-07-03 17:33 62976 —-a-w- c:\windows\system32\pngfilt.dll
2013-07-03 17:33 . 2013-07-03 17:33 52224 —-a-w- c:\windows\system32\msfeedsbs.dll
2013-07-03 17:33 . 2013-07-03 17:33 51200 —-a-w- c:\windows\system32\imgutil.dll
2013-07-03 17:33 . 2013-07-03 17:33 13824 —-a-w- c:\windows\system32\mshta.exe
2013-07-03 17:33 . 2013-07-03 17:33 136192 —-a-w- c:\windows\system32\iepeers.dll
2013-07-03 17:33 . 2013-07-03 17:33 12800 —-a-w- c:\windows\system32\msfeedssync.exe
2013-07-03 17:33 . 2013-07-03 17:33 135680 —-a-w- c:\windows\system32\IEAdvpack.dll
2013-07-03 17:33 . 2013-07-03 17:33 92160 —-a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-07-03 17:33 . 2013-07-03 17:33 77312 —-a-w- c:\windows\system32\tdc.ocx
2013-07-03 17:33 . 2013-07-03 17:33 48640 —-a-w- c:\windows\system32\mshtmler.dll
2013-07-01 22:43 . 2013-07-01 22:43 49152 —-a-r- c:\windows\SysWow64\inetwh32.dll
2013-07-01 22:43 . 2013-07-01 22:43 1044480 —-a-r- c:\windows\SysWow64\roboex32.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RoboForm"="c:\program files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2013-05-05 160328]
"IDMan"="c:\program files (x86)\Internet Download Manager\IDMan.exe" [2012-11-24 3540416]
"FreeScreenSharing"="c:\users\dogonit23\AppData\Local\FreeScreenSharing\FreeScreenSharing.exe" [2013-06-26 2266104]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-09-30 98304]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2013-05-08 41056]
"IObit Malware Fighter"="c:\program files (x86)\IObit\IObit Malware Fighter\IMF.exe" [2013-08-17 1549120]
.
c:\users\dogonit23\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Nexus Toolbar.lnk - c:\nexustoolbar\NexusToolbar.exe [2012-5-16 937984]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk * \0BootDefrag.exe\0\0sdnclean64.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ad-Aware Service]
@="Ad-Aware Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]
@="Service"
.
R0 BootDefragDriver;BootDefragDriver;c:\windows\System32\drivers\BootDefragDriver.sys;c:\windows\SYSNATIVE\drivers\BootDefragDriver.sys [x]
R2 CLKMSVC10_C6F09094;CyberLink Product - 2011/01/03 00:55;c:\program files (x86)\Hewlett-Packard\Media\DVD\Kernel\HDDVD\NavFilter\kmsvc.exe;c:\program files (x86)\Hewlett-Packard\Media\DVD\Kernel\HDDVD\NavFilter\kmsvc.exe [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 IMFservice;IMF Service;c:\program files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe;c:\program files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [x]
R2 SBAMSvc;Ad-Aware;c:\program files (x86)\Ad-Aware Antivirus\SBAMSvc.exe;c:\program files (x86)\Ad-Aware Antivirus\SBAMSvc.exe [x]
R2 SecureUpdateSvc;SecureUpdate;c:\program files (x86)\Secure Speed Dial\IE\SecureUpdate.exe;c:\program files (x86)\Secure Speed Dial\IE\SecureUpdate.exe [x]
R2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 EsgScanner;EsgScanner;c:\windows\system32\DRIVERS\EsgScanner.sys;c:\windows\SYSNATIVE\DRIVERS\EsgScanner.sys [x]
R3 netw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys;c:\windows\SYSNATIVE\DRIVERS\netw5v64.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTAZL6.SYS [x]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTDPV6.SYS [x]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTCNXT6.SYS [x]
R3 SystemExplorerHelpService;System Explorer Service;c:\program files (x86)\System Explorer\service\SystemExplorerService64.exe;c:\program files (x86)\System Explorer\service\SystemExplorerService64.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 UrlFilter;UrlFilter;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys;c:\windows\SYSNATIVE\DRIVERS\yk62x64.sys [x]
R4 FileMonitor;FileMonitor;c:\program files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys;c:\program files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys [x]
S0 gfibto;gfibto;c:\windows\system32\drivers\gfibto.sys;c:\windows\SYSNATIVE\drivers\gfibto.sys [x]
S0 SmartDefragDriver;SmartDefragDriver;c:\windows\System32\Drivers\SmartDefragDriver.sys;c:\windows\SYSNATIVE\Drivers\SmartDefragDriver.sys [x]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [x]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [x]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [x]
S2 Ad-Aware Service;Ad-Aware Service;c:\program files (x86)\Ad-Aware Antivirus\AdAwareService.exe;c:\program files (x86)\Ad-Aware Antivirus\AdAwareService.exe [x]
S2 AdvancedSystemCareService6;Advanced SystemCare Service 6;c:\program files (x86)\IObit\Advanced SystemCare 6\ASCService.exe;c:\program files (x86)\IObit\Advanced SystemCare 6\ASCService.exe [x]
S2 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\AESTSr64.exe;c:\program files\IDT\WDM\AESTSr64.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x]
S2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [x]
S2 HP Wireless Assistant Service;HP Wireless Assistant Service;c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe;c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [x]
S2 HPClientSvc;HP Client Services;c:\program files\Hewlett-Packard\HP Client Services\HPClientServices.exe;c:\program files\Hewlett-Packard\HP Client Services\HPClientServices.exe [x]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [x]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe;c:\windows\SYSNATIVE\Hpservice.exe [x]
S2 HPWMISVC;HPWMISVC;c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe;c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [x]
S2 IDMWFP;IDMWFP;c:\windows\system32\DRIVERS\idmwfp.sys;c:\windows\SYSNATIVE\DRIVERS\idmwfp.sys [x]
S2 NitroReaderDriverReadSpool3;NitroPDFReaderDriverCreatorReadSpool3;c:\program files\Common Files\Nitro\Reader\3.0\NitroPDFReaderDriverService3x64.exe;c:\program files\Common Files\Nitro\Reader\3.0\NitroPDFReaderDriverService3x64.exe [x]
S2 NOBU;Norton Online Backup;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE [x]
S2 RoxioNow Service;RoxioNow Service;c:\program files (x86)\Roxio\RoxioNow Player\RNowSvc.exe;c:\program files (x86)\Roxio\RoxioNow Player\RNowSvc.exe [x]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x]
S2 SpyHunter 4 Service;SpyHunter 4 Service;c:\progra~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE;c:\progra~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE [x]
S3 clwvd;HP Webcam Splitter;c:\windows\system32\DRIVERS\clwvd.sys;c:\windows\SYSNATIVE\DRIVERS\clwvd.sys [x]
S3 RegFilter;RegFilter;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys [x]
.
.
— Other Services/Drivers In Memory —
.
*Deregistered* - CLKMDRV10_C6F09094
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-09-21 09:56 1177552 —-a-w- c:\program files (x86)\Google\Chrome\Application\29.0.1547.76\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-09-20 c:\windows\Tasks\GlaryInitialize 3.job
- c:\program files (x86)\Glary Utilities 3\Initialize.exe [2013-09-02 09:06]
.
2013-09-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-08-11 21:45]
.
2013-09-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-08-11 21:45]
.
2013-09-02 c:\windows\Tasks\HPCeeScheduleForDOGONIT23-HP$.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 05:15]
.
2013-09-28 c:\windows\Tasks\HPCeeScheduleFordogonit23.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 05:15]
.
.
——— X64 Entries ———–
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00Zecter]
@="{D25B32FE-CB96-491A-98FF-AD59DA382D69}"
[HKEY_CLASSES_ROOT\CLSID\{D25B32FE-CB96-491A-98FF-AD59DA382D69}]
2010-09-23 04:53 2210304 —-a-w- c:\program files (x86)\Hewlett-Packard\HP CloudDrive\ShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\01Zecter]
@="{EB24CA6D-F315-4A81-AC1A-C79CFD77F3F5}"
[HKEY_CLASSES_ROOT\CLSID\{EB24CA6D-F315-4A81-AC1A-C79CFD77F3F5}]
2010-09-23 04:53 2210304 —-a-w- c:\program files (x86)\Hewlett-Packard\HP CloudDrive\ShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\02Zecter]
@="{B3C78E40-6B64-47C3-AE34-60B770881EB8}"
[HKEY_CLASSES_ROOT\CLSID\{B3C78E40-6B64-47C3-AE34-60B770881EB8}]
2010-09-23 04:53 2210304 —-a-w- c:\program files (x86)\Hewlett-Packard\HP CloudDrive\ShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\03Zecter]
@="{622AFE52-33F6-4D9F-9966-E0BC52D7D69D}"
[HKEY_CLASSES_ROOT\CLSID\{622AFE52-33F6-4D9F-9966-E0BC52D7D69D}]
2010-09-23 04:53 2210304 —-a-w- c:\program files (x86)\Hewlett-Packard\HP CloudDrive\ShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\04Zecter]
@="{855156F0-2A0F-11DE-8C30-0800200C9A66}"
[HKEY_CLASSES_ROOT\CLSID\{855156F0-2A0F-11DE-8C30-0800200C9A66}]
2010-09-23 04:53 2210304 —-a-w- c:\program files (x86)\Hewlett-Packard\HP CloudDrive\ShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\IDM Shell Extension]
@="{CDC95B92-E27C-4745-A8C5-64A52A78855D}"
[HKEY_CLASSES_ROOT\CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D}]
2012-11-15 23:07 23496 —-a-w- c:\program files (x86)\Internet Download Manager\IDMShellExt64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2010-09-14 487424]
"HPWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe" [2010-07-21 8192]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-06-21 1356240]
"VDownloader"="c:\program files\VDownloader\VDownloader.exe" [2013-09-20 880640]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{1984DD45-52CF-49cd-AB77-18F378FEA264}"= "c:\program files\Stardock\Fences Pro\FencesMenu64.dll" [2010-09-16 464744]
.
——- Supplementary Scan ——-
.
uStart Page = https://www.google.com/
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Customize Menu - file://c:\program files (x86)\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Download all links with IDM - c:\program files (x86)\Internet Download Manager\IEGetAll.htm
IE: Download with IDM - c:\program files (x86)\Internet Download Manager\IEExt.htm
IE: Fill Forms - file://c:\program files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://c:\program files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: Save Page As PDF … - file://c:\program files (x86)\Nitro PDF\PDF Download\nitroweb.htm
Trusted Zone: blackhatteam.com\www
Trusted Zone: samsungsetup.com\www
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\dogonit23\AppData\Roaming\Mozilla\Firefox\Profiles\qfgmkrbu.default\
FF - prefs.js: browser.startup.homepage - hxxp://google.com/
FF - prefs.js: network.proxy.gopher -
FF - prefs.js: network.proxy.gopher_port - 0
FF - prefs.js: network.proxy.type - 0
FF - ExtSQL: 2013-09-14 09:07; [removed]; c:\users\dogonit23\AppData\Roaming\Mozilla\Firefox\Profiles\qfgmkrbu.default\extensions\[removed]
FF - ExtSQL: 2013-09-16 00:42; [removed]; c:\users\dogonit23\AppData\Roaming\Mozilla\Firefox\Profiles\qfgmkrbu.default\extensions\[removed]
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-AccelerateTab_is1 - c:\program files (x86)\Secure Speed Dial\unins000.exe
.
.
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-2034785586-1586066431-309787569-1001_Classes\Wow6432Node\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):e1,fa,26,9e,16,71,f9,40,fb,15,d5,77,ea,07,30,a7,39,d2,1c,7a,28,
fd,86,24,4d,fb,97,24,cb,1f,d2,c7,f2,4f,81,c0,31,5f,7c,c0,00,00,00,00,00,00,\
.
[HKEY_USERS\S-1-5-21-2034785586-1586066431-309787569-1001_Classes\Wow6432Node\CLSID\{ecad5a90-57d9-4d3e-aa6b-72489e80ca18}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"Model"=dword:000000bf
"Therad"=dword:00000009
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a,
1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_175_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_175_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_175_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_175_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2013-09-29 15:06:20
ComboFix-quarantined-files.txt 2013-09-29 22:06
ComboFix2.txt 2013-09-20 23:13
ComboFix3.txt 2013-09-16 11:22
.
Pre-Run: 250,883,309,568 bytes free
Post-Run: 251,110,576,128 bytes free
.
- - End Of File - - B1FDCFEA8C11AFD18F7BEE4CFEB055A0
0BA2A85985CC2D6245F7E3F7BC450923
I need to see the quarantined files from ComboFix. Look for it under C:\Qoobox\ComboFix-quarantined-files.txt Could you kindly explain why you are still retaining two AV? How is your computer running after ComboFix run?
Computer still running pretty slow. Not sure, but would you suggest me upgrading to more RAM? I have 4GB that runs at full capacity a lot of the time. Computer seriously lags… As for the AV, I have the M Sec Essentials and AdAware which I run separately but does not run all the time. Only the Security Essentials run from startup. Here is the report you asked for… 2013-09-25 10:12:34 . 2013-09-25 10:12:34 1,092 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Legacy_NPF.reg.dat 2013-09-24 03:10:23 . 2013-09-24 18:26:28 71,245 —-a-w- C:\Qoobox\Quarantine\C\Users\dogonit23\AppData\Local\Google\Chrome\User Data\Default\Preferences.vir 2013-09-16 11:22:13 . 2013-09-16 11:22:13 512 —-a-w- C:\Qoobox\Quarantine\MBR_HardDisk0.mbr 2013-09-16 11:20:42 . 2013-09-16 11:20:42 80 —-a-w- C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-SynTPEnh.reg.dat 2013-09-16 11:20:24 . 2013-09-16 11:20:24 377 —-a-w- C:\Qoobox\Quarantine\Registry_backups\HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47}.reg.dat 2013-09-16 11:20:14 . 2013-09-16 11:20:14 230 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Wow6432Node-HKU-Default-RunOnce-SPReview.reg.dat 2013-09-16 11:13:15 . 2013-09-29 21:57:43 4,939 —-a-w- C:\Qoobox\Quarantine\Registry_backups\tcpip.reg 2013-09-16 10:56:18 . 2013-09-29 21:20:49 459 —-a-w- C:\Qoobox\Quarantine\catchme.log 2013-05-05 03:18:34 . 2013-04-06 00:56:45 61,304 —-a-w- C:\Qoobox\Quarantine\C\Users\dogonit23\g2mdlhlpx (2).exe.vir 2012-05-15 23:32:07 . 2012-05-15 23:32:07 361,984 —-a-w- C:\Qoobox\Quarantine\C\Windows\SysWOW64\aosmtp.dll.vir 2011-02-09 00:46:12 . 2013-07-30 17:22:33 60,864 —-a-w- C:\Qoobox\Quarantine\C\Users\dogonit23\g2mdlhlpx.exe.vir 2007-11-07 16:03:18 . 2007-11-07 16:03:18 562,688 —-a-w- C:\Qoobox\Quarantine\C\install.exe.vir
Doesn't hurt to upgrade more RAM, but I wonder it will solve the lagging issue? RAM is cheap now, so if you want you could buy one. Go on Task Manager > Performance tab > Click Resource Monitor > Click Memory tab Check which of the processes uses the most amount of RAM under Working Set column. I'd like to do a test. Would you mind removing Ad-aware temporarily just to see if things improve. Let me know your findings.
OK, I have uninstalled AdAware. It was not set to run on startup, so not sure what it will help deleting it. Seems that many promote this tool as a vital part of keeping computer clean…? Deleting it shows no improvement in performance, but I have not restarted my computer yet which might help. Anyway, I checked the memory processes and the ones that stand out the most are my Window Live Mail and Internet Explorer. WLM takes up most resources, and of course depending on how many windows I have open in IE it comes in a close second.
I wish there was a better solution to Windows Live Mail… I miss Outlook Express! I heard about Thunderbird, but it would be a nightmare to transfer all my folders and accounts from WLM to Thunderbird I think. Also when I tried Thunderbird it was somewhat slow too.
I was trying to rule out the possibility of security softwares interfering with each other because the log indicates Adaware services are running behind background even though you did not set it to run during startup. Not sure why WLM is eating so much of your resources though.

Please run this to check for things that the logs may not show or I could have otherwise missed.

Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean
===================================================

Go here and click 'ESET Online Scanner'.

  • If you are not using Internet Explorer, double-click esetsmartinstaller_enu.exe to install it, then click 'Run'.
  • Turn off the real-time scanner of any existing antivirus program while performing the online scan.
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • If using Internet Explorer, allow the ActiveX control to install when asked.
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings and ensure these options are ticked:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Next to 'Current scan targets: Operating memory, Local drives', click the Change.. button.
  • Tick all the boxes that correspond to your external/inserted drives.
  • Click Start
  • Wait for the scan to finish.
  • When the scan is done, if it shows a screen that says "Threats found!", click "List of found threats", and then click "Export to text file…"
  • Save that text file to your desktop, and then copy/paste the contents in your next reply. Please do not attach it.
===================================================

Malwarebytes' Anti-Malware
Download Malwarebytes' Anti-Malware here and save to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program. (Note to Vista users, please right-click and select Run as Administrator.)
  • At the end, be sure a checkmark is placed next to:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please copy and paste the log back into your next reply
Note:
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
  • Or via the Logs tab when Malwarebytes' Anti-Malware is started.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so. Failure to reboot will prevent MBAM from removing all the malware.


===================================================

On your next reply please post :
ESET log
MBAM log


Please STOP and let me know if you have any problems in performing with the steps above or any questions you may have.
Here's the two logs…. ESET took about 16 hours… ESET C:\C - Old Drive\Documents and Settings\rkoblasa\Application Data\Sun\Java\Deployment\cache\6.0\2\13e6bc2-3f81db1b Java/Agent.X trojan C:\C - Old Drive\Documents and Settings\rkoblasa\Application Data\Sun\Java\Deployment\cache\6.0\33\7ffc20e1-10471f44 Java/Agent.X trojan C:\Program Files (x86)\RegInOut System Utilities\bridge.dll a variant of Win32/Adware.AntiMalwarePro.AD application C:\Program Files (x86)\RegInOut System Utilities\RegInOut.exe a variant of Win32/Adware.PCFresher.A application C:\Users\dogonit23\AppData\Local\Microsoft\Windows Live Mail\Cox (dogonit23)\Inbox\10C87E23-0000DC4F.eml PHP/Obfuscated.F application C:\Users\dogonit23\AppData\Local\Microsoft\Windows Live Mail\Cox (dogonit23)\Inbox\43EB253D-0000C9BC.eml PHP/Obfuscated.F application C:\Users\dogonit23\AppData\Local\Microsoft\Windows Live Mail\Cox (dogonit23)\Learning\2E3930CC-00000103.eml PHP/Obfuscated.F application C:\Users\dogonit23\AppData\Local\Microsoft\Windows Live Mail\Cox (ourliv 419\Inbox\52C4102B-0000046D.eml PHP/Obfuscated.F application C:\Users\dogonit23\AppData\Local\Microsoft\Windows Live Mail\Cox (ourliv 419\Inbox\555A1CB3-00000537.eml PHP/Obfuscated.F application C:\Users\dogonit23\AppData\Local\Microsoft\Windows Live Mail\Cox (rkoblasa)\Inbox\4982183F-0000044C.eml PHP/Obfuscated.F application C:\Users\dogonit23\AppData\Local\Microsoft\Windows Live Mail\Cox (rkoblasa)\Inbox\7CB43E42-000003D9.eml PHP/Obfuscated.F application C:\Users\dogonit23\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\#1 (1)\Mail Box\12805BF0-577C6929.eml PHP/Kryptik.AB trojan C:\Users\dogonit23\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\#1 (1)\Mail Box\198D32CC-E3EFD80B.eml PHP/Obfuscated.F application C:\Users\dogonit23\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\#1 (1)\Mail Box\19D61BF2-97034D50.eml PHP/Kryptik.AB trojan C:\Users\dogonit23\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\#1 (1)\Mail Box\3867346B-FA9D66C1.eml PHP/Kryptik.AB trojan C:\Users\dogonit23\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\#1 (1)\Mail Box\3A727D63-340A6AEA.eml PHP/Kryptik.AB trojan C:\Users\dogonit23\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\#1 (1)\Mail Box\3D750F65-A5939AE0.eml PHP/Kryptik.AB trojan C:\Users\dogonit23\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\#1 (1)\Mail Box\6356569B-3BF20375.eml PHP/Obfuscated.F application C:\Users\dogonit23\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\#1 (1)\Mail Box\6FF86831-F56C047B.eml PHP/Kryptik.AB trojan C:\Users\dogonit23\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\#1 (1)\Mail Box\73746FBB-F868C2F6.eml PHP/Kryptik.AB trojan C:\Users\dogonit23\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\#1 (1)\Mails\Deposit of Koblasa S_[2013-04-05 11 30 48].eml PHP/Obfuscated.F application C:\Users\dogonit23\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\#1 (1)\Mails\How to rock your lea_[2013-04-16 20 22 34].eml PHP/Obfuscated.F application C:\Users\dogonit23\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\#1 (1)\Mails\[ASPIRE] It Spoke to_[2012-12-20 09 00 00].eml PHP/Obfuscated.F application C:\Users\dogonit23\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\#1 (1) (1)\Mails\10 free copies of In_[2012-12-14 19 51 19].eml PHP/Obfuscated.F application C:\Users\dogonit23\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\#1 (1) (1)\Mails\Affiliate Newsletter_[2012-12-14 16 28 11].eml PHP/Obfuscated.F application C:\Users\dogonit23\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\#1 (1) (1)\Mails\DC Fawcett?s Live Tr_[2012-09-27 03 12 28].eml PHP/Obfuscated.F application C:\Users\dogonit23\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\#1 (1) (1)\Mails\How to Make Your Dre_[2012-09-13 09 23 18].eml PHP/Obfuscated.F application C:\Users\dogonit23\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\#1 (1) (1)\Mails\How To Sell 100 Kind_[2012-08-28 11 07 39].eml PHP/Obfuscated.F application C:\Users\dogonit23\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\#1 (1) (1)\Mails\How-To Hub next ste_[2010-03-16 18 34 18]_128.eml PHP/Kryptik.AB trojan C:\Users\dogonit23\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\#1 (1) (1)\Mails\JP's Bonus to CB Pre_[2010-07-29 07 46 04].eml PHP/Kryptik.AB trojan C:\Users\dogonit23\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\#1 (1) (1)\Mails\JUST 8 HOURS to Laun_[2013-04-12 03 13 30]_335.eml PHP/Obfuscated.F application C:\Users\dogonit23\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\#1 (1) (1)\Mails\Make an extra $200-$_[2012-12-19 08 24 07].eml PHP/Obfuscated.F application C:\Users\dogonit23\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\#1 (1) (1)\Mails\NEW keyword research_[2012-07-13 14 38 41]_442.eml PHP/Obfuscated.F application C:\Users\dogonit23\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\#1 (1) (1)\Mails\Please confirm your _[2010-05-17 13 36 02].eml PHP/Kryptik.AB trojan C:\Users\dogonit23\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\#1 (1) (1)\Mails\Re ## LIVE TRAINING_[2010-05-13 14 00 43]_519.eml PHP/Obfuscated.F application C:\Users\dogonit23\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\#1 (1) (1)\Mails\Ryan Activate Your A_[2010-05-10 17 01 03]_788.eml PHP/Kryptik.AB trojan C:\Users\dogonit23\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\#1 (1) (1)\Mails\RYAN, you're not goi_[2009-12-23 10 12 44].eml PHP/Kryptik.AB trojan C:\Users\dogonit23\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\#1 (1) (1)\Mails\Starting IN 39 MINUT_[2012-10-09 19 04 40].eml PHP/Obfuscated.F application C:\Users\dogonit23\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\#1 (1) (1)\Mails\This expires tonight_[2013-01-22 08 54 00].eml PHP/Obfuscated.F application C:\Users\dogonit23\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\#1 (1) (1)\Mails\Try MyPoints Search _[2012-09-04 14 17 32].eml PHP/Obfuscated.F application C:\Users\dogonit23\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\#1 (1) (1)\Mails\Very Last ChanceMess_[2010-05-01 01 34 08].eml PHP/Kryptik.AB trojan C:\Users\dogonit23\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\#1 (1) (1)\Mails\Welcome To SEO Givea_[2009-11-12 17 53 02]_462.eml PHP/Obfuscated.F application C:\Users\dogonit23\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\#1 (1) (1)\Mails\Your DVD has been re_[2011-01-28 09 05 42].eml PHP/Kryptik.AB trojan C:\Users\dogonit23\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\#1 (1) (1)\Mails\[Weekly Update] What_[2013-02-10 10 34 59].eml PHP/Obfuscated.F application C:\Users\dogonit23\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\Imported Folder\Local Folders\OLD MAIL\1E7A6F2B-0000B3D4.eml PHP/Obfuscated.F application C:\Users\dogonit23\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\Imported Folder\Local Folders\OLD MAIL\39DE17F8-00010D99.eml PHP/Obfuscated.F application C:\Users\dogonit23\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\Imported Folder\Local Folders\OLD MAIL\40A23CDC-0000B443.eml PHP/Obfuscated.F application C:\Users\dogonit23\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\Imported Folder\Local Folders\OLD MAIL\46310EED-000114D5.eml PHP/Obfuscated.F application C:\Users\dogonit23\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\Imported Folder\Local Folders\OLD MAIL\5C43758A-00014BDF.eml PHP/Obfuscated.F application C:\Users\dogonit23\Desktop\Extras\Fix\baidu-pc-faster.exe Win32/SoftonicDownloader.E application C:\Users\dogonit23\Desktop\Software Downloads\cbsidlm-tr1_10a-Windows_Doctor-SEO-10746668_2.exe Win32/DownloadAdmin.G application C:\Users\dogonit23\Desktop\Software Downloads\Internet Video Downloader setup.exe Win32/Toolbar.Zugo application C:\Users\dogonit23\Desktop\Software Downloads\intunemp3_2562.exe a variant of Win32/InstallIQ.A application C:\Users\dogonit23\Desktop\Software Downloads\polderbits_access_key_downloader_133a.exe a variant of Win32/YourFileDownloader application C:\Users\dogonit23\Desktop\Software Downloads\polderbits_sound_recorder_and_editor_9.0_keygen.rar_downloader_us_224.exe a variant of Win32/ExpressFiles.B application C:\Users\dogonit23\Desktop\Software Downloads\reginout_setup.exe multiple threats C:\Users\dogonit23\Desktop\Software Downloads\skypelogview.zip a variant of Win32/SkypeLogView.A application C:\Users\dogonit23\Desktop\Software Downloads\VDownloaderInstallerIC.exe a variant of Win32/InstallCore.CF application C:\Users\dogonit23\Desktop\Software Downloads\Internet Download Manager\idm 6.15 build 5\idm patch by crackdom.exe a variant of Win32/HackTool.Patcher.U application C:\Users\dogonit23\Desktop\Software Downloads\Registry Booster\registrybooster.exe Win32/RegistryBooster application C:\Users\dogonit23\Desktop\Software Downloads\skypelogview\SkypeLogView.exe a variant of Win32/SkypeLogView.A application C:\Users\dogonit23\Documents\ElmFord Backup\Data\StorageSync\Drive_C\Documents and Settings\Desktop\Unused\registryfix.exe a variant of Win32/Adware.ErrorClean application C:\Users\dogonit23\Documents\ElmFord Backup\DOCUMENTS\Recovered\rkoblasa\Local Settings\Temporary Internet Files\Content.IE5\1VRRM3OD\optin_confirm[1].htm JS/TrojanDownloader.HackLoad.AG trojan C:\Users\dogonit23\Documents\ElmFord Backup\DOCUMENTS\Recovered\rkoblasa\Local Settings\Temporary Internet Files\Content.IE5\VCIPI098\SGS[1].htm JS/TrojanDownloader.HackLoad.AG trojan C:\Users\dogonit23\Documents\ElmFord Backup\DOCUMENTS\Recovered\rkoblasa\Local Settings\Temporary Internet Files\Content.IE5\XUTD07K9\SSS[1].htm JS/TrojanDownloader.HackLoad.AG trojan MBAM Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Database version: v2013.10.01.09 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16686 dogonit23 :: DOGONIT23-HP [administrator] 10/1/2013 3:52:27 PM mbam-log-2013-10-01 (15-52-27).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 215212 Time elapsed: 9 minute(s), 30 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI