This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help with Oyodomo. [Closed]

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi All, Hoping someone on this forum can help me out. I've been getting Oyodomo pop ups for the last two weeks and its driving me insane. Is there a fix for this ?????

:welcome:

Hello rm69,

my name is Jo and I will help you with your computer problems.


Please be advised that I am currently in training, so my responses will need to be approved by one of our experts before I post them. This is only to ensure you are receiving accurate instructions. It may cause a delay in my replies.


Please follow these guidelines:
  • Logs can take a while to research, so please be patient.
  • Read and follow the instructions in the sequence they are posted.
  • print or copy & save instructions.
  • Do not install / uninstall any applications, unless otherwise instructed.
  • Use only that tools you have been instructed to use.
  • Copy and Paste the log files inside your post, unless otherwise instructed.
  • Ask for clarification, if you have any questions.
  • Stay with this topic ‘til you get the “all clean” post.
  • My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.
I will return as soon as possible with more instructions.
Hello rm69,


1. Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

2. Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.

3. Please download Malwarebytes Anti-Rootkit and save it to your desktop.
  • Be sure to print out and follow the instructions provided on that same page.
  • Caution: This is a beta version so please be sure to read the disclaimer and back up all your data before using.
  • Scan your system for malware
  • If malware is found, please go to the MBAR folder and then copy/paste the contents of the MBAR-log-***.txt file to your next reply.
If there is no malware found, please let me know as well.
Results of screen317's Security Check version 0.99.73
Windows Vista Service Pack 2 x86 (UAC is enabled)
Internet Explorer 9
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
Microsoft Security Essentials
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Java 7 Update 9
Java version out of Date!
Adobe Flash Player 11.8.800.168
Adobe Reader 9 Adobe Reader out of Date!
Mozilla Firefox (23.0.1)
````````Process Check: objlist.exe by Laurent````````
Microsoft Security Essentials MSMpEng.exe
Microsoft Security Essentials msseces.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 0 %
````````````````````End of Log``````````````````````
OTL logfile created on: 26/09/2013 21:25:06 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\The Maffeys\Downloads
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1.93 Gb Total Physical Memory | 0.80 Gb Available Physical Memory | 41.46% Memory free
4.11 Gb Paging File | 2.63 Gb Available in Paging File | 63.92% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 139.04 Gb Total Space | 26.59 Gb Free Space | 19.12% Space Free | Partition Type: NTFS

Computer Name: THEMAFFEYS-PC | User Name: The Maffeys | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\The Maffeys\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Users\The Maffeys\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd)
PRC - C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe (Adobe Systems, Inc.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - c:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe (LeapFrog Enterprises, Inc.)
PRC - C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe (LeapFrog Enterprises, Inc.)
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files\Common Files\Adobe\Updater6\Adobe_Updater.exe (Adobe Systems Incorporated)
PRC - C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe (Freemake)
PRC - C:\Program Files\Serviio\bin\ServiioConsole.exe ()
PRC - C:\Program Files\Serviio\bin\ServiioService.exe ()
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\eMachines\eMachines Power Management\ePowerSvc.exe (Acer Incorporated)


========== Modules (No Company Name) ==========

MOD - C:\Windows\System32\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll ()
MOD - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
MOD - C:\Program Files\Serviio\bin\ServiioConsole.exe ()


========== Services (SafeList) ==========

SRV - (Norton Internet Security) – C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe /s Norton Internet Security /m C:\Program Files\Norton Internet Security\Engine\16.0.0.125\diMaster.dll /prefetch:1 File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (NisSrv) – c:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV - (LeapFrog Connect Device Service) – C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe (LeapFrog Enterprises, Inc.)
SRV - (SkypeUpdate) – C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (Freemake Improver) – C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe (Freemake)
SRV - (Serviio) – C:\Program Files\Serviio\bin\ServiioService.exe ()
SRV - (ZuneWlanCfgSvc) – C:\Program Files\Zune\ZuneWlanCfgSvc.exe (Microsoft Corporation)
SRV - (WMZuneComm) – C:\Program Files\Zune\WMZuneComm.exe (Microsoft Corporation)
SRV - (ZuneNetworkSvc) – C:\Program Files\Zune\ZuneNss.exe (Microsoft Corporation)
SRV - (ePowerSvc) – C:\Program Files\eMachines\eMachines Power Management\ePowerSvc.exe (Acer Incorporated)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (SRTSPX) – C:\Windows\system32\drivers\NIS\1000000.07D\SRTSPX.SYS File not found
DRV - (SRTSP) – C:\Windows\system32\drivers\NIS\1000000.07D\SRTSP.SYS File not found
DRV - (NwlnkFwd) – system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – system32\DRIVERS\nwlnkflt.sys File not found
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20080829.024\NAVEX15.SYS File not found
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20080829.024\NAVENG.SYS File not found
DRV - (IpInIp) – system32\DRIVERS\ipinip.sys File not found
DRV - (NisDrv) – C:\Windows\System32\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV - (ssadbus) – C:\Windows\System32\drivers\ssadbus.sys (MCCI Corporation)
DRV - (WinUSB) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (L1C) – C:\Windows\System32\drivers\L1C60x86.sys (Atheros Communications, Inc.)
DRV - (FlyUsb) – C:\Windows\System32\drivers\FlyUsb.sys (LeapFrog)
DRV - (DritekPortIO) – C:\Program Files\Launch Manager\DPortIO.sys (Dritek System Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.emachines.com/rdr.aspx?b=A…0912&m;=e525
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.emachines.com/rdr.aspx?b=A…0912&m;=e525
IE - HKLM\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7ACEW
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2504091

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.emachines.com/rdr.aspx?b=A…0912&m;=e525
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
IE - HKCU\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://www2.delta-search.com/?q={searchTer…57&tsp;=4998
IE - HKCU\..\SearchScopes\{190E454D-64F1-4A16-B4BC-56D135A4B875}: "URL" = http://www.google.com/search?q={searchTerm…amp;rlz=1I7ACEW
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = https://isearch.avg.com/search?cid={D4575A4…q={searchTerms}
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2504091
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "www.google.co.uk"
FF - prefs.js..extensions.enabledAddons: %7B0113D088-8ED1-468C-B225-585A9C53B5E3%7D:1.0
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:23.0.1


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Plus Web Player Plug-In,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8051.1204: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2013/07/09 22:31:02 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/08/17 13:25:50 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Fookgle\FF\ [2012/10/26 22:32:38 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/08/17 13:25:50 | 000,000,000 | —D | M]

[2013/07/09 22:33:31 | 000,000,000 | —D | M] (No name found) – C:\Users\The Maffeys\AppData\Roaming\Mozilla\Extensions
[2013/09/26 20:28:54 | 000,000,000 | —D | M] (No name found) – C:\Users\The Maffeys\AppData\Roaming\Mozilla\Firefox\Profiles\z2bu19bv.default\extensions
[2013/07/09 22:33:31 | 000,000,000 | —D | M] (TopArcadeHits) – C:\Users\The Maffeys\AppData\Roaming\Mozilla\Firefox\Profiles\z2bu19bv.default\extensions\{0113D088-8ED1-468C-B225-585A9C53B5E3}
[2013/09/07 21:31:19 | 000,000,000 | —D | M] (BrowseFox) – C:\Users\The Maffeys\AppData\Roaming\Mozilla\Firefox\Profiles\z2bu19bv.default\extensions\[removed]
[2013/07/09 22:25:21 | 000,006,548 | —- | M] () – C:\Users\The Maffeys\AppData\Roaming\Mozilla\Firefox\Profiles\z2bu19bv.default\searchplugins\babylon.xml
[2013/07/09 22:25:49 | 000,001,294 | —- | M] () – C:\Users\The Maffeys\AppData\Roaming\Mozilla\Firefox\Profiles\z2bu19bv.default\searchplugins\delta.xml
[2013/08/17 13:25:48 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\Extensions
[2013/08/17 13:25:46 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\browser\extensions
[2013/08/17 13:26:21 | 000,000,000 | —D | M] (Default) – C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

O1 HOSTS File: ([2006/09/18 22:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Fookgle) - {6CF597EF-88EF-455B-AC5E-33D8309718C3} - C:\Program Files\Fookgle\Fookgle.dll File not found
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (TopArcadeHits Games) - {A7A9D7E7-E0C0-4202-9F13-6A06BD073CDA} - C:\Users\The Maffeys\AppData\Local\TopArcadeHits\Toparcadehits.dll ()
O2 - BHO: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Vuze Remote Toolbar) - {BA14329E-9550-4989-B3F2-9732E92D17CC} - C:\Program Files\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
O4 - HKLM..\Run: [DivXMediaServer] C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe (DivX, LLC)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [Monitor] C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe (LeapFrog Enterprises, Inc.)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Spotify] C:\Users\The Maffeys\AppData\Roaming\Spotify\Spotify.exe (Spotify Ltd)
O4 - HKCU..\Run: [Spotify Web Helper] C:\Users\The Maffeys\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd)
O4 - Startup: C:\Users\The Maffeys\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Serviio.lnk = C:\Program Files\Serviio\bin\ServiioConsole.exe ()
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5E7DB2C7-F3F2-41BD-B032-53EB6ABCB3CA}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\eM1_Wide.bmp
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\eM1_Wide.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 22:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{83c2cad9-f913-11e2-8d0a-00235a8d1e68}\Shell - "" = AutoRun
O33 - MountPoints2\{83c2cad9-f913-11e2-8d0a-00235a8d1e68}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a
O33 - MountPoints2\{89235ee2-1963-11e3-8c98-00235a8d1e68}\Shell - "" = AutoRun
O33 - MountPoints2\{89235ee2-1963-11e3-8c98-00235a8d1e68}\Shell\AutoRun\command - "" = F:\laucher.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2013/09/24 08:02:39 | 000,000,000 | —D | C] – C:\Users\The Maffeys\AppData\Roaming\Azureus
[2013/09/20 16:35:39 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Client
[2013/09/20 16:32:59 | 000,221,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\netio.sys
[2013/09/13 03:06:52 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2013/09/13 03:06:50 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2013/09/13 03:06:50 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2013/09/13 03:06:49 | 000,607,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2013/09/13 03:06:49 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2013/09/13 03:06:48 | 001,800,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2013/09/13 03:06:48 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2013/09/13 03:06:46 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2013/09/12 22:12:39 | 002,049,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2013/09/07 21:34:27 | 000,000,000 | —D | C] – C:\Users\The Maffeys\AppData\Roaming\InfraRecorder
[2013/09/03 20:34:06 | 000,000,000 | —D | C] – C:\Users\The Maffeys\Desktop\New Folder
[2013/08/28 08:03:54 | 001,548,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMVDECOD.DLL
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/09/26 21:24:00 | 000,000,304 | —- | M] () – C:\Windows\tasks\DSite.job
[2013/09/26 21:08:15 | 000,000,288 | —- | M] () – C:\Windows\tasks\TopArcadeHits.job
[2013/09/26 20:47:17 | 000,000,110 | —- | M] () – C:\.dir
[2013/09/26 20:36:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/09/26 20:24:49 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/09/26 20:24:49 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/09/26 20:24:28 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/09/26 09:00:32 | 002,237,968 | —- | M] (Kaspersky Lab ZAO) – C:\Users\The Maffeys\Desktop\TDSSKiller.exe
[2013/09/26 07:27:30 | 000,000,113 | —- | M] () – C:\Users\The Maffeys\AppData\Roaming\WB.CFG
[2013/09/26 07:27:30 | 000,000,005 | —- | M] () – C:\Users\The Maffeys\AppData\Roaming\WBPU-TTL.DAT
[2013/09/24 17:14:49 | 000,609,196 | —- | M] () – C:\Windows\System32\perfh009.dat
[2013/09/24 17:14:49 | 000,108,672 | —- | M] () – C:\Windows\System32\perfc009.dat
[2013/09/24 14:15:44 | 000,088,576 | —- | M] () – C:\Users\The Maffeys\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/09/23 11:12:37 | 000,000,303 | —- | M] () – C:\Users\The Maffeys\Documents\The Maffeys - Shortcut.lnk
[2013/09/22 20:36:29 | 000,692,616 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2013/09/22 20:36:28 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2013/09/22 16:49:29 | 000,305,320 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2013/09/22 11:08:29 | 000,000,966 | —- | M] () – C:\Users\Public\Desktop\Microsoft Works.lnk
[2013/09/20 16:40:32 | 000,002,154 | —- | M] () – C:\Windows\epplauncher.mif
[2013/09/09 09:45:52 | 1540,864,632 | —- | M] () – C:\Users\The Maffeys\Desktop\The Little Mermaid[1989]DvDrip[Eng]-Stealthmaster …..loud.avi
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/09/23 11:12:37 | 000,000,303 | —- | C] () – C:\Users\The Maffeys\Documents\The Maffeys - Shortcut.lnk
[2013/09/20 16:40:32 | 000,002,154 | —- | C] () – C:\Windows\epplauncher.mif
[2013/09/20 16:37:52 | 000,001,788 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2013/09/09 09:41:19 | 1540,864,632 | —- | C] () – C:\Users\The Maffeys\Desktop\The Little Mermaid[1989]DvDrip[Eng]-Stealthmaster …..loud.avi
[2013/09/09 09:28:26 | 735,504,384 | —- | C] () – C:\Users\The Maffeys\Desktop\The Little Mermaid[1989]DvDrip[Eng]-Stealthmaster.avi
[2013/07/27 14:06:02 | 000,000,113 | —- | C] () – C:\Users\The Maffeys\AppData\Roaming\WB.CFG
[2013/07/10 19:22:37 | 000,000,005 | —- | C] () – C:\Users\The Maffeys\AppData\Roaming\WBPU-TTL.DAT
[2013/07/09 22:26:56 | 000,645,632 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2013/07/09 22:26:56 | 000,240,640 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2013/07/09 22:26:33 | 000,178,688 | —- | C] () – C:\Windows\System32\unrar.dll
[2013/07/09 22:26:31 | 000,715,038 | —- | C] () – C:\Windows\unins000.exe
[2013/07/09 22:26:31 | 000,216,064 | —- | C] ( ) – C:\Windows\System32\lagarith.dll
[2013/07/09 22:26:31 | 000,001,795 | —- | C] () – C:\Windows\unins000.dat
[2012/12/25 18:34:34 | 000,000,679 | —- | C] () – C:\Users\The Maffeys\AppData\Local\cookies.ini
[2012/11/25 13:50:55 | 000,000,680 | —- | C] () – C:\Users\The Maffeys\AppData\Local\d3d9caps.dat
[2012/09/17 21:07:50 | 000,088,576 | —- | C] () – C:\Users\The Maffeys\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/09/17 12:43:02 | 000,017,408 | —- | C] () – C:\Users\The Maffeys\AppData\Local\WebpageIcons.db
[2012/09/14 22:10:06 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2012/09/14 22:08:02 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin

========== ZeroAccess Check ==========

[2006/11/02 13:51:16 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
"ThreadingModel" = Both
"" = C:\$Recycle.Bin\S-1-5-21-2252879165-1410815983-246096844-1000\$13e25703617c253be44b1886dcbcf2ee\n.

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 18:47:00 | 011,586,048 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/04/10 23:28:20 | 000,614,912 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/04/10 23:28:26 | 000,347,648 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2013/07/25 22:28:49 | 000,000,000 | —D | M] – C:\Users\The Maffeys\AppData\Roaming\AVG2013
[2013/09/25 11:47:16 | 000,000,000 | —D | M] – C:\Users\The Maffeys\AppData\Roaming\Azureus
[2013/07/09 22:24:54 | 000,000,000 | —D | M] – C:\Users\The Maffeys\AppData\Roaming\Babylon
[2013/07/09 22:26:35 | 000,000,000 | —D | M] – C:\Users\The Maffeys\AppData\Roaming\CDXReader
[2013/07/09 22:24:57 | 000,000,000 | —D | M] – C:\Users\The Maffeys\AppData\Roaming\DSite
[2012/10/30 21:40:21 | 000,000,000 | —D | M] – C:\Users\The Maffeys\AppData\Roaming\DVDVideoSoft
[2013/09/25 14:08:31 | 000,000,000 | —D | M] – C:\Users\The Maffeys\AppData\Roaming\igdhbblpcellaljokkpfhcjlagemhgjl
[2013/09/07 21:42:34 | 000,000,000 | —D | M] – C:\Users\The Maffeys\AppData\Roaming\InfraRecorder
[2012/11/28 23:38:18 | 000,000,000 | —D | M] – C:\Users\The Maffeys\AppData\Roaming\InterVideo
[2013/07/09 22:26:43 | 000,000,000 | —D | M] – C:\Users\The Maffeys\AppData\Roaming\LavFilters
[2012/12/29 12:11:12 | 000,000,000 | —D | M] – C:\Users\The Maffeys\AppData\Roaming\OpenCandy
[2012/09/19 22:13:39 | 000,000,000 | —D | M] – C:\Users\The Maffeys\AppData\Roaming\Serif
[2013/09/25 14:06:08 | 000,000,000 | —D | M] – C:\Users\The Maffeys\AppData\Roaming\Spotify
[2012/09/14 12:57:27 | 000,000,000 | —D | M] – C:\Users\The Maffeys\AppData\Roaming\TuneUp Software
[2013/07/09 22:26:57 | 000,000,000 | —D | M] – C:\Users\The Maffeys\AppData\Roaming\Ultimate Codec Packages

========== Purity Check ==========



< End of report >
I have now scanned the computer using malwarebytes and found 14 counts of malware, please see the report : ————————————— Malwarebytes Anti-Rootkit BETA 1.07.0.1005 © Malwarebytes Corporation 2011-2012 OS version: 6.0.6002 Windows Vista Service Pack 2 x86 Account is Administrative Internet Explorer version: 9.0.8112.16421 File system is: NTFS Disk drives: C:\ DRIVE_FIXED CPU speed: 2.194000 GHz Memory total: 2073284608, free: 812679168 Downloaded database version: v2013.09.26.07 Downloaded database version: v2013.09.23.01 ======================================= Initializing… ———— Kernel report ———— 09/26/2013 21:50:51 ———— Loaded modules ———– \SystemRoot\system32\ntkrnlpa.exe \SystemRoot\system32\hal.dll \SystemRoot\system32\kdcom.dll \SystemRoot\system32\mcupdate_GenuineIntel.dll \SystemRoot\system32\PSHED.dll \SystemRoot\system32\BOOTVID.dll \SystemRoot\system32\CLFS.SYS \SystemRoot\system32\CI.dll \SystemRoot\system32\drivers\Wdf01000.sys \SystemRoot\system32\drivers\WDFLDR.SYS \SystemRoot\system32\drivers\acpi.sys \SystemRoot\system32\drivers\WMILIB.SYS \SystemRoot\system32\drivers\msisadrv.sys \SystemRoot\system32\drivers\pci.sys \SystemRoot\System32\drivers\partmgr.sys \SystemRoot\system32\DRIVERS\compbatt.sys \SystemRoot\system32\DRIVERS\BATTC.SYS \SystemRoot\system32\drivers\volmgr.sys \SystemRoot\System32\drivers\volmgrx.sys \SystemRoot\System32\drivers\mountmgr.sys \SystemRoot\System32\Drivers\UBHelper.sys \SystemRoot\system32\drivers\atapi.sys \SystemRoot\system32\drivers\ataport.SYS \SystemRoot\system32\drivers\msahci.sys \SystemRoot\system32\drivers\PCIIDEX.SYS \SystemRoot\system32\drivers\fltmgr.sys \SystemRoot\system32\drivers\fileinfo.sys \SystemRoot\system32\DRIVERS\MpFilter.sys \SystemRoot\System32\Drivers\ksecdd.sys \SystemRoot\system32\drivers\ndis.sys \SystemRoot\system32\drivers\msrpc.sys \SystemRoot\system32\drivers\NETIO.SYS \SystemRoot\System32\drivers\tcpip.sys \SystemRoot\System32\drivers\fwpkclnt.sys \SystemRoot\System32\Drivers\Ntfs.sys \SystemRoot\system32\drivers\volsnap.sys \SystemRoot\System32\Drivers\spldr.sys \SystemRoot\System32\Drivers\mup.sys \SystemRoot\System32\drivers\ecache.sys \SystemRoot\system32\drivers\disk.sys \SystemRoot\system32\drivers\CLASSPNP.SYS \SystemRoot\system32\drivers\crcdisk.sys \SystemRoot\system32\DRIVERS\tunnel.sys \SystemRoot\system32\DRIVERS\tunmp.sys \SystemRoot\system32\DRIVERS\intelppm.sys \SystemRoot\system32\DRIVERS\igdkmd32.sys \SystemRoot\System32\drivers\dxgkrnl.sys \SystemRoot\System32\drivers\watchdog.sys \SystemRoot\system32\DRIVERS\usbuhci.sys \SystemRoot\system32\DRIVERS\USBPORT.SYS \SystemRoot\system32\DRIVERS\usbehci.sys \SystemRoot\system32\DRIVERS\HDAudBus.sys \SystemRoot\system32\DRIVERS\bcmwl6.sys \SystemRoot\system32\DRIVERS\L1C60x86.sys \SystemRoot\system32\DRIVERS\CmBatt.sys \SystemRoot\system32\DRIVERS\i8042prt.sys \SystemRoot\system32\DRIVERS\DKbFltr.sys \SystemRoot\system32\DRIVERS\kbdclass.sys \SystemRoot\system32\DRIVERS\SynTP.sys \SystemRoot\system32\DRIVERS\USBD.SYS \SystemRoot\system32\DRIVERS\mouclass.sys \SystemRoot\system32\DRIVERS\cdrom.sys \SystemRoot\system32\DRIVERS\NTIDrvr.sys \SystemRoot\system32\DRIVERS\wmiacpi.sys \SystemRoot\system32\DRIVERS\msiscsi.sys \SystemRoot\system32\DRIVERS\storport.sys \SystemRoot\system32\DRIVERS\TDI.SYS \SystemRoot\system32\DRIVERS\rasl2tp.sys \SystemRoot\system32\DRIVERS\ndistapi.sys \SystemRoot\system32\DRIVERS\ndiswan.sys \SystemRoot\system32\DRIVERS\raspppoe.sys \SystemRoot\system32\DRIVERS\raspptp.sys \SystemRoot\system32\DRIVERS\rassstp.sys \SystemRoot\system32\DRIVERS\termdd.sys \SystemRoot\system32\DRIVERS\swenum.sys \SystemRoot\system32\DRIVERS\ks.sys \SystemRoot\system32\DRIVERS\mssmbios.sys \SystemRoot\system32\DRIVERS\umbus.sys \SystemRoot\system32\DRIVERS\usbhub.sys \SystemRoot\System32\Drivers\NDProxy.SYS \SystemRoot\system32\drivers\RTKVHDA.sys \SystemRoot\system32\drivers\portcls.sys \SystemRoot\system32\drivers\drmk.sys \SystemRoot\System32\Drivers\Fs_Rec.SYS \SystemRoot\System32\Drivers\Null.SYS \SystemRoot\System32\Drivers\Beep.SYS \SystemRoot\System32\drivers\vga.sys \SystemRoot\System32\drivers\VIDEOPRT.SYS \SystemRoot\System32\DRIVERS\RDPCDD.sys \SystemRoot\system32\drivers\rdpencdd.sys \SystemRoot\System32\Drivers\Msfs.SYS \SystemRoot\System32\Drivers\Npfs.SYS \SystemRoot\System32\DRIVERS\rasacd.sys \SystemRoot\system32\DRIVERS\tdx.sys \SystemRoot\system32\DRIVERS\smb.sys \SystemRoot\System32\DRIVERS\netbt.sys \SystemRoot\system32\drivers\afd.sys \SystemRoot\system32\DRIVERS\pacer.sys \SystemRoot\system32\DRIVERS\netbios.sys \SystemRoot\system32\DRIVERS\wanarp.sys \SystemRoot\system32\DRIVERS\rdbss.sys \??\C:\PROGRA~1\LAUNCH~1\DPortIO.sys \SystemRoot\system32\drivers\nsiproxy.sys \SystemRoot\System32\Drivers\dfsc.sys \SystemRoot\System32\Drivers\crashdmp.sys \SystemRoot\System32\Drivers\dump_dumpata.sys \SystemRoot\System32\Drivers\dump_msahci.sys \SystemRoot\System32\win32k.sys \SystemRoot\System32\drivers\Dxapi.sys \SystemRoot\System32\TSDDD.dll \SystemRoot\System32\cdd.dll \SystemRoot\System32\ATMFD.DLL \SystemRoot\system32\drivers\luafv.sys \SystemRoot\system32\drivers\WudfPf.sys \SystemRoot\system32\DRIVERS\lltdio.sys \SystemRoot\system32\DRIVERS\nwifi.sys \SystemRoot\system32\DRIVERS\ndisuio.sys \SystemRoot\system32\DRIVERS\rspndr.sys \SystemRoot\system32\drivers\spsys.sys \SystemRoot\system32\drivers\HTTP.sys \SystemRoot\System32\DRIVERS\srvnet.sys \SystemRoot\system32\DRIVERS\bowser.sys \SystemRoot\System32\drivers\mpsdrv.sys \SystemRoot\system32\drivers\mrxdav.sys \SystemRoot\system32\DRIVERS\mrxsmb.sys \SystemRoot\system32\DRIVERS\mrxsmb10.sys \SystemRoot\system32\DRIVERS\mrxsmb20.sys \SystemRoot\System32\DRIVERS\srv2.sys \SystemRoot\System32\DRIVERS\srv.sys \SystemRoot\system32\DRIVERS\NisDrvWFP.sys \SystemRoot\system32\drivers\peauth.sys \SystemRoot\System32\Drivers\secdrv.SYS \SystemRoot\System32\drivers\tcpipreg.sys \SystemRoot\system32\DRIVERS\cdfs.sys \SystemRoot\system32\DRIVERS\monitor.sys \??\C:\Windows\system32\drivers\mbamchameleon.sys \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys \Windows\System32\ntdll.dll ———– End ———– Done! <<<1>>> Upper Device Name: \Device\Harddisk0\DR0 Upper Device Object: 0xffffffff84b3c968 Upper Device Driver Name: \Driver\disk\ Lower Device Name: \Device\Ide\IdeDeviceP0T0L0-0\ Lower Device Object: 0xffffffff84003390 Lower Device Driver Name: \Driver\atapi\ <<<2>>> Physical Sector Size: 512 Drive: 0, DevicePointer: 0xffffffff84b3c968, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\ ——— Disk Stack —— DevicePointer: 0xffffffff84b3c5e8, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xffffffff84b3c968, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\ DevicePointer: 0xffffffff840043a8, DeviceName: Unknown, DriverName: \Driver\ACPI\ DevicePointer: 0xffffffff84003390, DeviceName: \Device\Ide\IdeDeviceP0T0L0-0\, DriverName: \Driver\atapi\ ———— End ———- Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\ Upper DeviceData: 0x0, 0x0, 0x0 Lower DeviceData: 0x0, 0x0, 0x0 <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes <<<2>>> <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers… <<<2>>> <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Done! Drive 0 Scanning MBR on drive 0… Inspecting partition table: MBR Signature: 55AA Disk Signature: A6D43AF1 Partition information: Partition 0 type is Other (0x27) Partition is NOT ACTIVE. Partition starts at LBA: 63 Numsec = 20980827 Partition 1 type is Primary (0x7) Partition is ACTIVE. Partition starts at LBA: 20981760 Numsec = 291596288 Partition is not bootable Partition 2 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition 3 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Disk Size: 160041885696 bytes Sector size: 512 bytes Scanning physical sectors of unpartitioned space on drive 0 (1-62-312561808-312581808)… Done! Infected: C:\$Recycle.Bin\S-1-5-21-2252879165-1410815983-246096844-1000\$13e25703617c253be44b1886dcbcf2ee\@ –> [Trojan.Siredef.C] Infected: C:\Users\The Maffeys\AppData\Local\Temp\SetupToparcadehits.exe –> [Adware.GameVance] Infected: C:\Users\The Maffeys\AppData\Local\Temp\M6CDr4Tr.exe.part –> [Adware.AdBundle] Infected: C:\Users\The Maffeys\AppData\Local\TopArcadeHits\uninstaller.exe –> [Adware.GameVance] Infected: C:\Users\The Maffeys\AppData\Local\TopArcadeHits\updater.exe –> [Adware.GameVance] Infected: C:\Users\The Maffeys\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TopArcadeHits\Play Toparcadehits Online.url –> [Adware.GameVance] Infected: C:\Users\The Maffeys\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TopArcadeHits –> [Adware.GameVance] Infected: C:\Users\The Maffeys\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TopArcadeHits\Uninstall Toparcadehits.lnk –> [Adware.GameVance] Infected: HKCU\SOFTWARE\CLASSES\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9} –> [Hijack.Trojan.Siredef.C] Infected: HKCU\SOFTWARE\CLASSES\CLSID\{FBEB8A05-BEEE-4442-804E-409D6C4515E9}\INPROCSERVER32| –> [Trojan.Zaccess] Infected: HKCU\SOFTWARE\CLASSES\CLSID\{FBEB8A05-BEEE-4442-804E-409D6C4515E9}\INPROCSERVER32 –> [Trojan.Zaccess] Infected: C:\$Recycle.Bin\S-1-5-21-2252879165-1410815983-246096844-1000\$13e25703617c253be44b1886dcbcf2ee\U –> [Trojan.Siredef.C] Infected: C:\$Recycle.Bin\S-1-5-21-2252879165-1410815983-246096844-1000\$13e25703617c253be44b1886dcbcf2ee\L –> [Trojan.Siredef.C] Infected: C:\$Recycle.Bin\S-1-5-21-2252879165-1410815983-246096844-1000\$13e25703617c253be44b1886dcbcf2ee –> [Trojan.Siredef.C] Scan finished
Hello rm69,

2013/09/26 09:00:32 | 002,237,968 | —- | M] (Kaspersky Lab ZAO) – C:\Users\The Maffeys\Desktop\TDSSKiller.exe

Looks like you ran TDSSKiller.exe already.
If yes, please post the log.


You posted OTL log run 2.
From run 1 there should be an Extras.Txt, please post.


Please download Farbar Recovery Scan Tool and save it to your USB.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

  • Use "Computer" to find the USB / Flash drive.
  • Double-click to run FSRT. When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
OTL Extras logfile created on: 26/09/2013 09:24:42 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\The Maffeys\Downloads
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1.93 Gb Total Physical Memory | 0.83 Gb Available Physical Memory | 43.01% Memory free
4.11 Gb Paging File | 2.75 Gb Available in Paging File | 66.85% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 139.04 Gb Total Space | 23.72 Gb Free Space | 17.06% Space Free | Partition Type: NTFS

Computer Name: THEMAFFEYS-PC | User Name: The Maffeys | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1B8F34A9-22EE-4DFB-BE1E-4D376F6407C7}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{598D04FD-E1B6-4D3D-8768-DBD9CFBBDD61}" = lport=2869 | protocol=6 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{173622E8-0FA7-4FC9-97F5-A995938DCDB3}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{1CC5CEA2-BB2F-4097-85A5-E6ED82EC8BBE}" = protocol=6 | dir=in | app=c:\program files\serviio\bin\serviioservice.exe |
"{214E2A2E-6BA7-4BA3-916D-03F28F91AF1D}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{2AC90CBC-1F9F-4B81-A34D-C6A72F871696}" = protocol=17 | dir=in | app=c:\program files\hp\hp deskjet 1050 j410 series\bin\usbsetup.exe |
"{30CBA16F-65C4-475D-BA45-029BFC2BA0BC}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgmfapx.exe |
"{3422212B-8641-4CC2-A4E3-DBFEF2129CFC}" = protocol=6 | dir=in | app=c:\program files\serviio\bin\serviioconsole.exe |
"{370E04D7-DACA-45CA-848F-522C78C8237F}" = protocol=6 | dir=in | app=c:\program files\serviio\bin\serviioservice.exe |
"{3BF1818B-96AB-4DED-AB80-24FEB17E85D8}" = protocol=6 | dir=in | app=c:\program files\vuze\azureus.exe |
"{4185E36B-F532-4B1F-AAFF-4904F1DAA65E}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe |
"{6E4D5C95-83B0-4535-AA33-C4817ACD753D}" = protocol=6 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\backupsvc.exe |
"{7358E245-20F3-458E-9FD8-9500919CC6E4}" = protocol=17 | dir=in | app=c:\program files\vuze\azureus.exe |
"{77AB5826-B4DD-4AAC-9048-2686F22836AB}" = protocol=17 | dir=in | app=c:\program files\serviio\bin\serviioservice.exe |
"{7958F54B-0301-495E-B3D3-D86E3E7419C1}" = protocol=6 | dir=in | app=c:\program files\serviio\bin\serviioconsole.exe |
"{7EF3F82A-F659-4B55-9078-E2D907AC0637}" = protocol=6 | dir=in | app=c:\program files\hp\hp deskjet 1050 j410 series\bin\usbsetup.exe |
"{81F2BD88-FF90-41B3-BA9B-20D24AC6E530}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{998DF8A7-A43F-4B18-8FBA-8EB38DFDA19C}" = protocol=17 | dir=in | app=c:\program files\serviio\bin\serviioservice.exe |
"{A38E5C6F-0197-4F7B-AB61-77A7480B2F86}" = protocol=17 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\schedulersvc.exe |
"{A3F34F13-BE11-47D8-B3D2-724CCF3879D3}" = protocol=6 | dir=in | app=c:\program files\serviio\bin\serviioconsole.exe |
"{C16344C9-C30B-4B7E-9849-72FF938B975A}" = dir=in | app=c:\program files\leapfrog\leapfrog connect\leapfrogconnect.exe |
"{CCE1D5E7-8503-490A-8A22-C9D7E4CB0983}" = protocol=6 | dir=in | app=c:\program files\serviio\bin\serviioservice.exe |
"{CD1944BE-4E3F-4530-990E-D94A6075B134}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{D00E9EDE-184E-465B-8467-2AC7E7823531}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{EA18EA89-31C8-4EC7-8DDD-E00C4BC9EDD9}" = protocol=17 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\backupsvc.exe |
"{F62ED929-1AC1-4C64-8094-2D093F254B3C}" = protocol=17 | dir=in | app=c:\program files\serviio\bin\serviioservice.exe |
"{F657C741-4FC1-41DF-8524-D67FF341B1CA}" = protocol=6 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\schedulersvc.exe |
"{F9D405E1-F57F-44C4-8403-D3B1A9487573}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgmfapx.exe |
"TCP Query User{2C6050DE-43AD-41EF-8288-884FB4C8234A}C:\program files\vuze\jre\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\vuze\jre\bin\javaw.exe |
"TCP Query User{773C43E5-026A-4A9F-886B-9644CE0EF366}C:\program files\winamp\winamp.exe" = protocol=6 | dir=in | app=c:\program files\winamp\winamp.exe |
"TCP Query User{DC8FD007-19A3-4848-B40A-637C897A5169}C:\users\the maffeys\appdata\roaming\spotify\spotify.exe" = protocol=6 | dir=in | app=c:\users\the maffeys\appdata\roaming\spotify\spotify.exe |
"UDP Query User{69FCF09A-0EF4-4192-BEA6-0182E97A1DC2}C:\program files\vuze\jre\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\vuze\jre\bin\javaw.exe |
"UDP Query User{90E88695-863F-4869-9559-1704CECBDD63}C:\users\the maffeys\appdata\roaming\spotify\spotify.exe" = protocol=17 | dir=in | app=c:\users\the maffeys\appdata\roaming\spotify\spotify.exe |
"UDP Query User{ED01A914-3578-4EAC-BBA5-679F2643E65B}C:\program files\winamp\winamp.exe" = protocol=17 | dir=in | app=c:\program files\winamp\winamp.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{020D8396-D6D9-4B53-A9A1-83C47E2E27AA}" = Windows Live Call
"{07EEE598-5F21-4B57-B40B-46592625B3D9}" = Zune Language Pack (PTB)
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
"{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now Standard
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8
"{25A3CCFF-4811-47A7-B82E-2CE24A06156F}" = LeapFrog Tag Plugin
"{26A24AE4-039D-4CA4-87B4-2F83217009FF}" = Java 7 Update 9
"{2A9DFFD8-4E09-4B91-B957-454805B0D7C4}" = Zune Language Pack (CHS)
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.® AR81Family Gigabit/Fast Ethernet Driver
"{3589A659-F732-4E65-A89A-5438C332E59D}" = Zune Language Pack (ELL)
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3DB0448D-AD82-4923-B305-D001E521A964}" = eMachines Power Management
"{403CB875-F674-46D4-B03A-DC14EE976B54}" = LeapFrog Tag Junior Plugin
"{40C4903E-EDFB-4CAE-A611-41FEBA585921}" = VTech Download Agent Library
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4AB8B41B-3AF1-46BE-99B0-0ACD3B300C0A}" = Junk Mail filter update
"{51C839E1-2BE4-4E77-A1BA-CCEA5DAFA741}" = Zune Language Pack (KOR)
"{57C51D56-B287-4C11-9192-EC3C46EF76A4}" = Zune Language Pack (RUS)
"{59D268DF-CCA9-44C5-8F96-2E51BB34C829}" = Microsoft Security Client
"{5C90D8CF-F12A-41C6-9007-3B651A1F0D78}" = HP Deskjet 1050 J410 series Help
"{5C93E291-A1CC-4E51-85C6-E194209FCDB4}" = Zune Language Pack (PTG)
"{5DEFD397-4012-46C3-B6DA-E8013E660772}" = Zune Language Pack (NOR)
"{617E7009-0C50-4178-B0E2-F9D66DC8A582}" = Serif PhotoPlus X5
"{63C1109E-D977-49ED-BCE3-D00D0BF187D6}" = Windows Live Mail
"{6740BCB0-5863-47F4-80F4-44F394DE4FE2}" = Zune Language Pack (NLD)
"{67E03279-F703-408F-B4BF-46B5FC8D70CD}" = Microsoft Works
"{6A92E5C5-0578-443D-91F3-92ECE5F2CAE2}" = Windows Live Writer
"{6B33492E-FBBC-4EC3-8738-09E16E395A10}" = Zune Language Pack (ESP)
"{6EB931CD-A7DA-4A44-B74A-89C8EB50086F}" = Zune Language Pack (SVE)
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{76BA306B-2AA0-47C0-AB6B-F313AB56C136}" = Zune Language Pack (MSL)
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = eMachines Recovery Management
"{8960A0A1-BB5A-479E-92CF-65AB9D684B43}" = Zune Language Pack (PLK)
"{8B112338-2B08-4851-AF84-E7CAD74CEB32}" = Zune Language Pack (DAN)
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{92ECE3F9-591E-4C12-8A62-B9FCE38BF646}" = Zune Language Pack (IND)
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B75648B-6C30-4A0D-9DE6-0D09D20AF5A5}" = Zune
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A5A53EA8-A11E-49F0-BDF5-AE536426A31A}" = Zune Language Pack (CHT)
"{A8F2E50B-86E2-4D96-9BD2-9758BCC6F9B3}" = Zune Language Pack (CSY)
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{B4870774-5F3A-46D9-9DFE-06FB5599E26B}" = Zune Language Pack (FIN)
"{BE236D9A-52EC-4A17-82DA-84B5EAD31E3E}" = Zune Language Pack (DEU)
"{C1845647-AAD6-4126-9335-4922BA3B0423}" = QuickShare
"{C5D37FFA-7483-410B-982B-91E93FD3B7DA}" = Zune Language Pack (ITA)
"{C68D33B1-0204-4EBE-BC45-A6E432B1D13A}" = Zune Language Pack (FRA)
"{C6BE19C6-B102-4038-B2A6-1C313872DBB4}" = Zune Language Pack (HUN)
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D8A781C9-3892-4E2E-9320-480CF896CFBB}" = Zune Language Pack (JPN)
"{D9D754A1-EAC5-406C-A28B-C49B1E846711}" = Windows Live Essentials
"{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader
"{DCF0D853-BC4E-4EE6-A011-6B9BC84CF8F9}" = LeapFrog Connect
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{EA17F4FC-FDBF-4CF8-A529-2D983132D053}" = Skype™ 6.0
"{ECB35FFA-B010-45C5-9AB5-665AC7E27EE2}" = HP Deskjet 1050 J410 series Basic Device Software
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F2CB8C3C-9C9E-4FAB-9067-655601C5F748}" = Windows Mobile Device Updater Component
"{F59AC46C-10C3-4023-882C-4212A92283B3}_is1" = Lagarith Lossless Codec (1.3.27)
"{F69E83CF-B440-43F8-89E6-6EA80712109B}" = Windows Live Communications Platform
"{F73A5B18-EB75-4B2C-B32D-9457576E2417}" = Windows Live Photo Gallery
"{FDD810CA-D5E3-40E9-AB7B-36440B0D41EF}" = Windows Live Sync
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"8461-7759-5462-8226" = Vuze
"8F14F2ECEDE68D26EA515B48DC25B39103C4FE8D" = Windows Driver Package - Leapfrog (Leapfrog-USBLAN) Net (09/10/2009 02.03.05.012)
"AbiWord2" = AbiWord 2.8.6
"Adobe AIR" = Adobe AIR
"Adobe Digital Editions 2.0" = Adobe Digital Editions 2.0
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"DC-Bass Source" = DC-Bass Source 1.3.0
"DivX Setup" = DivX Setup
"Freemake Video Converter_is1" = Freemake Video Converter version 3.2.1
"HDMI" = Intel® Graphics Media Accelerator Driver
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HP Photo Creations" = HP Photo Creations
"InstallShield_{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now 5
"InstallShield_{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8
"Kobo" = Kobo
"LAME_is1" = LAME v3.99.3 (for Windows)
"LManager" = Launch Manager
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Security Client" = Microsoft Security Essentials
"Mozilla Firefox 23.0.1 (x86 en-US)" = Mozilla Firefox 23.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"OpenSource Flash Video Splitter" = OpenSource Flash Video Splitter 1.0.0.5
"Serviio" = Serviio
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TagJuniorPlugin" = Use the entry named LeapFrog Connect to uninstall (LeapFrog Tag Junior Plugin)
"TagPlugin" = Use the entry named LeapFrog Connect to uninstall (LeapFrog Tag Plugin)
"UPCShell" = LeapFrog Connect
"VLC media player" = VLC media player 2.0.3
"vsfilter_is1" = DirectVobSub 2.40.4209
"VTechDownloadManager" = Learning Lodge Navigator
"Vuze_Remote Toolbar" = Vuze Remote Toolbar
"WinLiveSuite_Wave3" = Windows Live Essentials
"Xvid Video Codec 1.3.2" = Xvid Video Codec
"Zune" = Zune

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"DSite" = Update for Ultimate Codec
"Spotify" = Spotify
"Ultimate Codec Packages" = Ultimate Codec Packages

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 14/09/2013 09:17:13 | Computer Name = TheMaffeys-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 14/09/2013 09:17:25 | Computer Name = TheMaffeys-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 14/09/2013 09:17:25 | Computer Name = TheMaffeys-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 14/09/2013 09:17:26 | Computer Name = TheMaffeys-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 14/09/2013 09:17:26 | Computer Name = TheMaffeys-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 14/09/2013 09:17:26 | Computer Name = TheMaffeys-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 14/09/2013 09:17:26 | Computer Name = TheMaffeys-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 14/09/2013 09:17:32 | Computer Name = TheMaffeys-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 14/09/2013 09:17:32 | Computer Name = TheMaffeys-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 14/09/2013 09:17:32 | Computer Name = TheMaffeys-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 14/09/2013 09:17:32 | Computer Name = TheMaffeys-PC | Source = Windows Search Service | ID = 3013
Description =

[ System Events ]
Error - 15/09/2012 16:17:29 | Computer Name = TheMaffeys-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 10:00:29 on 15/09/2012 was unexpected.

Error - 15/09/2012 16:18:23 | Computer Name = TheMaffeys-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 15/09/2012 16:18:23 | Computer Name = TheMaffeys-PC | Source = Service Control Manager | ID = 7006
Description =

Error - 15/09/2012 16:18:23 | Computer Name = TheMaffeys-PC | Source = Service Control Manager | ID = 7006
Description =

Error - 15/09/2012 16:19:08 | Computer Name = TheMaffeys-PC | Source = Service Control Manager | ID = 7026
Description =

Error - 15/09/2012 17:47:35 | Computer Name = TheMaffeys-PC | Source = Service Control Manager | ID = 7006
Description =

Error - 15/09/2012 17:50:27 | Computer Name = TheMaffeys-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 15/09/2012 17:50:27 | Computer Name = TheMaffeys-PC | Source = Service Control Manager | ID = 7006
Description =

Error - 15/09/2012 17:50:27 | Computer Name = TheMaffeys-PC | Source = Service Control Manager | ID = 7006
Description =

Error - 15/09/2012 17:50:47 | Computer Name = TheMaffeys-PC | Source = Service Control Manager | ID = 7026
Description =


< End of report >
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 27-09-2013
Ran by [removed] (administrator) on THEMAFFEYS-PC on 27-09-2013 20:27:10
Running from C:\Users\[removed]\Downloads
Microsoft® Windows Vista™ Home Basic Service Pack 2 (X86) OS Language: English(US)
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(Microsoft Corporation) c:\Program Files\Microsoft Security Client\MsMpEng.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Acer Incorporated) C:\Program Files\eMachines\eMachines Power Management\ePowerSvc.exe
(Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
(LeapFrog Enterprises, Inc.) C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe
(NewTech Infosystems, Inc.) C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
() C:\Program Files\Serviio\bin\ServiioService.exe
() C:\Program Files\Serviio\bin\ServiioService.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) c:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(LeapFrog Enterprises, Inc.) C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe
() C:\Program Files\DivX\DivX Update\DivXUpdate.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Spotify Ltd) C:\Users\The Maffeys\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
() C:\Program Files\Serviio\bin\ServiioConsole.exe
(Microsoft Corporation) C:\Windows\system32\wuauclt.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\Updater6\Adobe_Updater.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe
(Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe
(Malwarebytes Corp.) C:\Users\The Maffeys\Downloads\mbar-1.07.0.1005.exe
(Microsoft Corporation) C:\Windows\system32\cmd.exe
(Malwarebytes Corporation) C:\Users\The Maffeys\Desktop\mbar\mbar.exe

==================== Registry (Whitelisted) ==================

HKLM\…\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation)
HKLM\…\Run: [Monitor] - C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe [103936 2013-06-26] (LeapFrog Enterprises, Inc.)
HKLM\…\Run: [DivXMediaServer] - C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-05-20] (DivX, LLC)
HKLM\…\Run: [DivXUpdate] - C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1263952 2013-02-13] ()
HKLM\…\Run: [MSC] - c:\Program Files\Microsoft Security Client\msseces.exe [995184 2013-07-18] (Microsoft Corporation)
HKCU\…\Run: [Spotify] - C:\Users\The Maffeys\AppData\Roaming\Spotify\Spotify.exe [4728320 2013-09-20] (Spotify Ltd)
HKCU\…\Run: [Spotify Web Helper] - C:\Users\The Maffeys\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1140736 2013-09-20] (Spotify Ltd)
HKCU\…409d6c4515e9\InprocServer32: [Default-shell32] C:\$Recycle.Bin\S-1-5-21-2252879165-1410815983-246096844-1000\$13e25703617c253be44b1886dcbcf2ee\n. ATTENTION! ====> ZeroAccess/Alureon?
MountPoints2: {83c2cad9-f913-11e2-8d0a-00235a8d1e68} - F:\LaunchU3.exe -a
MountPoints2: {89235ee2-1963-11e3-8c98-00235a8d1e68} - F:\laucher.exe
HKU\Default\…\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\Default\…\RunOnce: [ScrSav] -
HKU\Default User\…\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\Default User\…\RunOnce: [ScrSav] -
Startup: C:\Users\The Maffeys\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Serviio.lnk
ShortcutTarget: Serviio.lnk -> C:\Program Files\Serviio\bin\ServiioConsole.exe ()

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.emachines.com/rdr.aspx?b=A…0912&m=e525
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.emachines.com/rdr.aspx?b=A…0912&m=e525
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.emachines.com/rdr.aspx?b=A…0912&m=e525
URLSearchHook: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
SearchScopes: HKLM - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2504091
SearchScopes: HKCU - DefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www2.delta-search.com/?q={searchTer…57&tsp=4998
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www2.delta-search.com/?q={searchTer…57&tsp=4998
SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL =
SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = https://isearch.avg.com/search?cid={D4575A4…q={searchTerms}
SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2504091
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: QuickShare WidgetEngine - {31ad400d-1b06-4e33-a59a-90c2c140cba0} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
BHO: DivX Plus Web Player HTML5 - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Fookgle - {6CF597EF-88EF-455B-AC5E-33D8309718C3} - C:\Program Files\Fookgle\Fookgle.dll No File
BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: TopArcadeHits Games - {A7A9D7E7-E0C0-4202-9F13-6A06BD073CDA} - C:\Users\The Maffeys\AppData\Local\TopArcadeHits\Toparcadehits.dll ()
BHO: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
Toolbar: HKLM - QuickShare Widget - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
Toolbar: HKCU - No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File
Toolbar: HKCU -Vuze Remote Toolbar - {BA14329E-9550-4989-B3F2-9732E92D17CC} - C:\Program Files\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1

FireFox:
========
FF ProfilePath: C:\Users\The Maffeys\AppData\Roaming\Mozilla\Firefox\Profiles\z2bu19bv.default
FF user.js: detected! => C:\Users\The Maffeys\AppData\Roaming\Mozilla\Firefox\Profiles\z2bu19bv.default\user.js
FF Homepage: www.google.co.uk
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF Plugin: @divx.com/DivX Plus Web Player Plug-In,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @java.com/DTPlugin,version=10.9.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.9.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/WLPG,version=14.0.8051.1204 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF SearchPlugin: C:\Users\The Maffeys\AppData\Roaming\Mozilla\Firefox\Profiles\z2bu19bv.default\searchplugins\babylon.xml
FF SearchPlugin: C:\Users\The Maffeys\AppData\Roaming\Mozilla\Firefox\Profiles\z2bu19bv.default\searchplugins\delta.xml
FF Extension: TopArcadeHits - C:\Users\The Maffeys\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\{0113D088-8ED1-468C-B225-585A9C53B5E3}
FF Extension: BrowseFox - C:\Users\The Maffeys\AppData\Roaming\Mozilla\Firefox\Profiles\z2bu19bv.default\Extensions\[removed]
FF Extension: TopArcadeHits - C:\Users\The Maffeys\AppData\Roaming\Mozilla\Firefox\Profiles\z2bu19bv.default\Extensions\{0113D088-8ED1-468C-B225-585A9C53B5E3}
FF HKLM\…\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF HKLM\…\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF HKCU\…\Firefox\Extensions: [[removed]] - C:\Program Files\Fookgle\FF\
FF Extension: No Name - C:\Program Files\Fookgle\FF\

========================== Services (Whitelisted) =================

R2 ePowerSvc; C:\Program Files\eMachines\eMachines Power Management\ePowerSvc.exe [653856 2009-02-06] (Acer Incorporated)
R2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [100864 2012-09-07] (Freemake)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22216 2013-07-18] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [295376 2013-07-18] (Microsoft Corporation)
R2 NTISchedulerSvc; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [144632 2008-09-23] (NewTech Infosystems, Inc.)
R2 Serviio; C:\Program Files\Serviio\bin\ServiioService.exe [279552 2012-08-09] ()
S2 Norton Internet Security; "C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe" /s "Norton Internet Security" /m "C:\Program Files\Norton Internet Security\Engine\16.0.0.125\diMaster.dll" /prefetch:1

==================== Drivers (Whitelisted) ====================

R0 CLFS; C:\Windows\System32\CLFS.sys [245736 2009-04-10] (Microsoft Corporation)
R1 DritekPortIO; C:\PROGRA~1\LAUNCH~1\DPortIO.sys [20112 2006-11-02] (Dritek System Inc.)
S3 FlyUsb; C:\Windows\System32\DRIVERS\FlyUsb.sys [19456 2007-06-18] (LeapFrog)
R3 L1C; C:\Windows\System32\DRIVERS\L1C60x86.sys [49664 2009-01-15] (Atheros Communications, Inc.)
R3 mbamchameleon; C:\Windows\system32\drivers\mbamchameleon.sys [77528 2013-09-26] (MalwareBytes)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [105176 2013-09-26] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [211560 2013-06-18] (Microsoft Corporation)
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20080829.024\NAVENG.SYS [x]
S3 NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20080829.024\NAVEX15.SYS [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
S1 SRTSP; \??\C:\Windows\system32\drivers\NIS\1000000.07D\SRTSP.SYS [x]
S1 SRTSPX; \??\C:\Windows\system32\drivers\NIS\1000000.07D\SRTSPX.SYS [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-09-27 20:24 - 2013-09-27 20:24 - 00000000 ____D C:\FRST
2013-09-27 20:23 - 2013-09-27 20:23 - 01086861 _____ (Farbar) C:\Users\The Maffeys\Downloads\FRST.exe
2013-09-26 21:50 - 2013-09-26 21:52 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-09-26 21:50 - 2013-09-26 21:50 - 00105176 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2013-09-26 21:50 - 2013-09-26 21:50 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-09-26 21:49 - 2013-09-26 21:49 - 00077528 _____ (MalwareBytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2013-09-26 21:48 - 2013-09-26 21:49 - 00000000 ____D C:\Users\The Maffeys\Desktop\mbar
2013-09-26 21:47 - 2013-09-26 21:47 - 12907592 _____ (Malwarebytes Corp.) C:\Users\The Maffeys\Downloads\mbar-1.07.0.1005.exe
2013-09-26 21:15 - 2013-09-26 21:15 - 00891144 _____ C:\Users\The Maffeys\Downloads\SecurityCheck.exe
2013-09-26 09:18 - 2013-09-26 21:33 - 00049966 _____ C:\Users\The Maffeys\Downloads\OTL.Txt
2013-09-26 09:18 - 2013-09-26 09:34 - 00044262 _____ C:\Users\The Maffeys\Downloads\Extras.Txt
2013-09-26 09:03 - 2013-09-26 09:03 - 00602112 _____ (OldTimer Tools) C:\Users\The Maffeys\Downloads\OTL.exe
2013-09-26 08:59 - 2013-09-26 08:59 - 02218636 _____ C:\Users\The Maffeys\Downloads\tdsskiller.zip
2013-09-24 08:02 - 2013-09-25 11:47 - 00000000 ____D C:\Users\The Maffeys\AppData\Roaming\Azureus
2013-09-23 11:12 - 2013-09-23 11:12 - 00000303 _____ C:\Users\The Maffeys\Documents\The Maffeys - Shortcut.lnk
2013-09-22 10:57 - 2013-09-22 10:57 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help
2013-09-22 10:57 - 2013-09-22 10:57 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help
2013-09-20 16:40 - 2013-09-20 16:40 - 00002154 _____ C:\Windows\epplauncher.mif
2013-09-20 16:35 - 2013-09-20 16:37 - 00000000 ____D C:\Program Files\Microsoft Security Client
2013-09-20 16:32 - 2010-04-05 21:00 - 00221568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2013-09-20 16:24 - 2013-09-20 16:24 - 11233112 _____ (Microsoft Corporation) C:\Users\The Maffeys\Downloads\mseinstall.exe
2013-09-13 03:06 - 2013-07-31 11:30 - 12335104 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-09-13 03:06 - 2013-07-31 11:05 - 09738752 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-09-13 03:06 - 2013-07-31 11:00 - 01800704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-09-13 03:06 - 2013-07-31 10:53 - 01104896 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-09-13 03:06 - 2013-07-31 10:52 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-09-13 03:06 - 2013-07-31 10:52 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-09-13 03:06 - 2013-07-31 10:51 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-09-13 03:06 - 2013-07-31 10:49 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-09-13 03:06 - 2013-07-31 10:48 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-09-13 03:06 - 2013-07-31 10:48 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-09-13 03:06 - 2013-07-31 10:48 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-09-13 03:06 - 2013-07-31 10:47 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-09-13 03:06 - 2013-07-31 10:46 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-09-13 03:06 - 2013-07-31 10:45 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-09-13 03:06 - 2013-07-31 10:45 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-09-13 03:06 - 2013-07-31 10:42 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-09-12 22:12 - 2013-08-08 02:45 - 02049536 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-09-12 22:12 - 2013-07-16 05:35 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\themeui.dll
2013-09-09 09:41 - 2013-09-09 09:45 - 1540864632 _____ C:\Users\The Maffeys\Desktop\The Little Mermaid[1989]DvDrip[Eng]-Stealthmaster …..loud.avi
2013-09-09 09:28 - 2012-10-18 12:09 - 735504384 _____ C:\Users\The Maffeys\Desktop\The Little Mermaid[1989]DvDrip[Eng]-Stealthmaster.avi
2013-09-07 21:40 - 2013-09-07 21:40 - 00000000 ____D C:\Users\The Maffeys\Downloads\New Folder
2013-09-07 21:34 - 2013-09-07 21:42 - 00000000 ____D C:\Users\The Maffeys\AppData\Roaming\InfraRecorder
2013-09-07 21:32 - 2013-09-07 21:32 - 04151536 _____ C:\Users\The Maffeys\Downloads\ir053.exe
2013-09-07 21:27 - 2013-09-07 21:27 - 00232760 _____ (Firser) C:\Users\The Maffeys\Downloads\InfraRecorder.exe
2013-09-07 21:22 - 2013-09-07 21:27 - 47602016 _____ C:\Users\The Maffeys\Downloads\ubuntu-13.04-desktop-i386.iso.part
2013-09-07 11:26 - 2013-09-07 11:27 - 01158555 _____ (pendrivelinux.com) C:\Users\The Maffeys\Downloads\Universal-USB-Installer-1.9.4.1(2).exe
2013-09-07 11:26 - 2013-09-07 11:26 - 01158555 _____ (pendrivelinux.com) C:\Users\The Maffeys\Downloads\Universal-USB-Installer-1.9.4.1(1).exe
2013-09-07 11:25 - 2013-09-07 11:25 - 01158555 _____ (pendrivelinux.com) C:\Users\The Maffeys\Downloads\Universal-USB-Installer-1.9.4.1.exe
2013-09-03 20:34 - 2013-09-03 21:01 - 00000000 ____D C:\Users\The Maffeys\Desktop\New Folder
2013-08-28 08:03 - 2013-08-02 03:48 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL

==================== One Month Modified Files and Folders =======

2013-09-27 20:24 - 2013-09-27 20:24 - 00000000 ____D C:\FRST
2013-09-27 20:24 - 2013-07-09 22:24 - 00000304 _____ C:\Windows\Tasks\DSite.job
2013-09-27 20:23 - 2013-09-27 20:23 - 01086861 _____ (Farbar) C:\Users\The Maffeys\Downloads\FRST.exe
2013-09-27 19:42 - 2012-10-11 19:53 - 00000110 _____ C:\.dir
2013-09-27 19:36 - 2012-09-26 08:46 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-09-27 19:25 - 2012-09-14 11:39 - 01424672 _____ C:\Windows\WindowsUpdate.log
2013-09-27 19:20 - 2013-07-27 14:06 - 00000113 _____ C:\Users\The Maffeys\AppData\Roaming\WB.CFG
2013-09-27 19:20 - 2013-07-10 19:22 - 00000005 _____ C:\Users\The Maffeys\AppData\Roaming\WBPU-TTL.DAT
2013-09-27 19:07 - 2013-07-09 22:33 - 00000288 _____ C:\Windows\Tasks\TopArcadeHits.job
2013-09-27 19:05 - 2006-11-02 13:45 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-27 19:05 - 2006-11-02 13:45 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-26 21:52 - 2013-09-26 21:50 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-09-26 21:50 - 2013-09-26 21:50 - 00105176 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2013-09-26 21:50 - 2013-09-26 21:50 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-09-26 21:49 - 2013-09-26 21:49 - 00077528 _____ (MalwareBytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2013-09-26 21:49 - 2013-09-26 21:48 - 00000000 ____D C:\Users\The Maffeys\Desktop\mbar
2013-09-26 21:47 - 2013-09-26 21:47 - 12907592 _____ (Malwarebytes Corp.) C:\Users\The Maffeys\Downloads\mbar-1.07.0.1005.exe
2013-09-26 21:33 - 2013-09-26 09:18 - 00049966 _____ C:\Users\The Maffeys\Downloads\OTL.Txt
2013-09-26 21:15 - 2013-09-26 21:15 - 00891144 _____ C:\Users\The Maffeys\Downloads\SecurityCheck.exe
2013-09-26 09:34 - 2013-09-26 09:18 - 00044262 _____ C:\Users\The Maffeys\Downloads\Extras.Txt
2013-09-26 09:03 - 2013-09-26 09:03 - 00602112 _____ (OldTimer Tools) C:\Users\The Maffeys\Downloads\OTL.exe
2013-09-26 09:00 - 2013-02-11 18:51 - 02237968 _____ (Kaspersky Lab ZAO) C:\Users\The Maffeys\Desktop\TDSSKiller.exe
2013-09-26 08:59 - 2013-09-26 08:59 - 02218636 _____ C:\Users\The Maffeys\Downloads\tdsskiller.zip
2013-09-25 14:08 - 2013-07-09 22:33 - 00000000 ____D C:\Users\The Maffeys\AppData\Roaming\igdhbblpcellaljokkpfhcjlagemhgjl
2013-09-25 14:06 - 2013-08-25 21:35 - 00000000 ____D C:\Users\The Maffeys\AppData\Roaming\Spotify
2013-09-25 14:02 - 2006-11-02 13:58 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-09-25 11:47 - 2013-09-24 08:02 - 00000000 ____D C:\Users\The Maffeys\AppData\Roaming\Azureus
2013-09-25 09:45 - 2012-09-17 19:57 - 00000000 ____D C:\Users\The Maffeys\AppData\Roaming\vlc
2013-09-24 17:14 - 2006-11-02 11:33 - 00703388 _____ C:\Windows\system32\PerfStringBackup.INI
2013-09-24 14:15 - 2012-09-17 21:07 - 00088576 _____ C:\Users\The Maffeys\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-09-24 03:13 - 2009-03-11 15:11 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-09-23 13:18 - 2006-11-02 13:58 - 00032642 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-09-23 13:02 - 2012-09-14 22:13 - 00000000 ____D C:\Program Files\Vuze
2013-09-23 11:12 - 2013-09-23 11:12 - 00000303 _____ C:\Users\The Maffeys\Documents\The Maffeys - Shortcut.lnk
2013-09-22 20:36 - 2012-09-26 08:45 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-09-22 20:36 - 2012-09-26 08:45 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-09-22 16:49 - 2006-11-02 13:44 - 00305320 _____ C:\Windows\system32\FNTCACHE.DAT
2013-09-22 16:48 - 2008-01-21 04:02 - 00190050 _____ C:\Windows\PFRO.log
2013-09-22 11:08 - 2009-03-11 15:19 - 00000966 _____ C:\Users\Public\Desktop\Microsoft Works.lnk
2013-09-22 11:08 - 2009-03-11 15:12 - 00000000 ____D C:\Program Files\Microsoft Works
2013-09-22 11:06 - 2012-09-14 10:53 - 00070688 _____ C:\Users\The Maffeys\AppData\Local\GDIPFONTCACHEV1.DAT
2013-09-22 10:57 - 2013-09-22 10:57 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help
2013-09-22 10:57 - 2013-09-22 10:57 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help
2013-09-22 10:54 - 2006-11-02 12:18 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2013-09-20 16:40 - 2013-09-20 16:40 - 00002154 _____ C:\Windows\epplauncher.mif
2013-09-20 16:38 - 2013-02-24 13:45 - 00000000 ____D C:\Users\The Maffeys\AbiSuite
2013-09-20 16:37 - 2013-09-20 16:35 - 00000000 ____D C:\Program Files\Microsoft Security Client
2013-09-20 16:24 - 2013-09-20 16:24 - 11233112 _____ (Microsoft Corporation) C:\Users\The Maffeys\Downloads\mseinstall.exe
2013-09-13 03:06 - 2013-08-15 03:18 - 00000000 ____D C:\Windows\system32\MRT
2013-09-13 03:02 - 2006-11-02 11:24 - 76725432 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2013-09-12 22:08 - 2013-08-25 21:35 - 00000000 ____D C:\Users\The Maffeys\AppData\Local\Spotify
2013-09-09 22:57 - 2013-04-12 13:31 - 00003975 _____ C:\Windows\setupact.log
2013-09-09 09:45 - 2013-09-09 09:41 - 1540864632 _____ C:\Users\The Maffeys\Desktop\The Little Mermaid[1989]DvDrip[Eng]-Stealthmaster …..loud.avi
2013-09-07 21:42 - 2013-09-07 21:34 - 00000000 ____D C:\Users\The Maffeys\AppData\Roaming\InfraRecorder
2013-09-07 21:40 - 2013-09-07 21:40 - 00000000 ____D C:\Users\The Maffeys\Downloads\New Folder
2013-09-07 21:32 - 2013-09-07 21:32 - 04151536 _____ C:\Users\The Maffeys\Downloads\ir053.exe
2013-09-07 21:27 - 2013-09-07 21:27 - 00232760 _____ (Firser) C:\Users\The Maffeys\Downloads\InfraRecorder.exe
2013-09-07 21:27 - 2013-09-07 21:22 - 47602016 _____ C:\Users\The Maffeys\Downloads\ubuntu-13.04-desktop-i386.iso.part
2013-09-07 11:27 - 2013-09-07 11:26 - 01158555 _____ (pendrivelinux.com) C:\Users\The Maffeys\Downloads\Universal-USB-Installer-1.9.4.1(2).exe
2013-09-07 11:26 - 2013-09-07 11:26 - 01158555 _____ (pendrivelinux.com) C:\Users\The Maffeys\Downloads\Universal-USB-Installer-1.9.4.1(1).exe
2013-09-07 11:25 - 2013-09-07 11:25 - 01158555 _____ (pendrivelinux.com) C:\Users\The Maffeys\Downloads\Universal-USB-Installer-1.9.4.1.exe
2013-09-03 21:01 - 2013-09-03 20:34 - 00000000 ____D C:\Users\The Maffeys\Desktop\New Folder
2013-08-29 13:24 - 2013-07-25 22:19 - 00000000 ____D C:\Users\The Maffeys\AppData\Local\Avg2013
2013-08-29 13:24 - 2012-09-14 12:34 - 00000000 ____D C:\ProgramData\MFAData
2013-08-29 13:19 - 2013-07-25 22:24 - 00000000 ___HD C:\$AVG
2013-08-29 13:19 - 2013-07-25 22:24 - 00000000 ____D C:\ProgramData\AVG2013

ZeroAccess:
C:\$Recycle.Bin\S-1-5-21-2252879165-1410815983-246096844-1000\$13e25703617c253be44b1886dcbcf2ee

Some content of TEMP:
====================
C:\Users\The Maffeys\AppData\Local\Temp\FreemakeVideoConverter_3.2.1.1.exe
C:\Users\The Maffeys\AppData\Local\Temp\i4jdel0.exe
C:\Users\The Maffeys\AppData\Local\Temp\i4jdel1.exe
C:\Users\The Maffeys\AppData\Local\Temp\i4jdel2.exe
C:\Users\The Maffeys\AppData\Local\Temp\InstallFlashPlayer.exe
C:\Users\The Maffeys\AppData\Local\Temp\jre-7u15-windows-i586-iftw.exe
C:\Users\The Maffeys\AppData\Local\Temp\jre-7u17-windows-i586-iftw.exe
C:\Users\The Maffeys\AppData\Local\Temp\MSNF63D.exe
C:\Users\The Maffeys\AppData\Local\Temp\pyl7728.tmp.exe
C:\Users\The Maffeys\AppData\Local\Temp\RtkBtMnt.exe
C:\Users\The Maffeys\AppData\Local\Temp\SetupToparcadehits.exe
C:\Users\The Maffeys\AppData\Local\Temp\uninst1.exe


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-09-25 14:09

==================== End Of Log ============================
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 27-09-2013
Ran by [removed] at 2013-09-27 20:28:45
Running from C:\Users\[removed]\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}

==================== Installed Programs ======================

AbiWord 2.8.6 (Version: 2.8.6)
Acrobat.com (Version: 0.0.0)
Acrobat.com (Version: 1.1.377)
Adobe AIR (Version: 1.0.4990)
Adobe AIR (Version: 1.0.8.4990)
Adobe Digital Editions 2.0 (Version: 2.0)
Adobe Flash Player 11 ActiveX (Version: 11.8.800.175)
Adobe Flash Player 11 Plugin (Version: 11.8.800.168)
Adobe Reader 9 (Version: 9.0.0)
Atheros Communications Inc.® AR81Family Gigabit/Fast Ethernet Driver (Version: 1.0.0.7)
Choice Guard (Version: 1.2.87.0)
Compatibility Pack for the 2007 Office system (Version: 12.0.6612.1000)
DC-Bass Source 1.3.0
DirectVobSub 2.40.4209 (Version: 2.40.4209)
DivX Setup (Version: 2.6.1.8)
eMachines Power Management (Version: 4.00.3004)
eMachines Recovery Management (Version: 4.00.3001)
Freemake Video Converter version 3.2.1 (Version: 3.2.1)
HP Deskjet 1050 J410 series Basic Device Software (Version: 22.0.334.0)
HP Deskjet 1050 J410 series Help (Version: 140.0.66.66)
HP Photo Creations (Version: 1.0.0.3341)
Intel® Graphics Media Accelerator Driver
Java 7 Update 9 (Version: 7.0.90)
Java Auto Updater (Version: 2.1.9.0)
Junk Mail filter update (Version: 14.0.8050.1202)
Kobo (Version: 3.1.5)
Lagarith Lossless Codec (1.3.27)
LAME v3.99.3 (for Windows)
Launch Manager (Version: 2.0.00)
LeapFrog Connect (Version: 5.0.20.17316)
LeapFrog Tag Junior Plugin (Version: 5.0.19.17305)
LeapFrog Tag Plugin (Version: 5.0.19.17305)
Learning Lodge Navigator
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6012.5000)
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office Excel MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Home and Student 2007 (Version: 12.0.6612.1000)
Microsoft Office OneNote MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office PowerPoint MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office PowerPoint Viewer 2007 (English) (Version: 12.0.6612.1000)
Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (Spanish) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proofing (English) 2007 (Version: 12.0.4518.1014)
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Shared MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Shared Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Suite Activation Assistant (Version: 2.9)
Microsoft Office Word MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Security Client (Version: 4.3.0216.0)
Microsoft Security Essentials (Version: 4.3.216.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (Version: 9.0.21022)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Works (Version: 9.7.0621)
Mozilla Firefox 23.0.1 (x86 en-US) (Version: 23.0.1)
Mozilla Maintenance Service (Version: 23.0.1)
MSVCRT (Version: 14.0.1468.721)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
NTI Backup Now 5 (Version: 5.1.2.616)
NTI Backup Now Standard (Version: 5.1.2.616)
NTI Media Maker 8 (Version: 8.0.12.6509)
OpenSource Flash Video Splitter 1.0.0.5 (Version: 1.0.0.5)
QuickShare (Version: 1.6.1.635)
Realtek High Definition Audio Driver (Version: 6.0.1.5789)
Realtek USB 2.0 Card Reader (Version: 6.0.6000.20125)
Serif PhotoPlus X5 (Version: 15.0.1.011)
Serviio
Skype™ 6.0 (Version: 6.0.126)
Spotify (HKCU Version: 0.9.4.169.gc0399df6)
Synaptics Pointing Device Driver (Version: 12.1.3.1)
Ultimate Codec Packages
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB2836940) (Version: 1)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (Version: 1)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
Update for Ultimate Codec
Use the entry named LeapFrog Connect to uninstall (LeapFrog Tag Junior Plugin)
Use the entry named LeapFrog Connect to uninstall (LeapFrog Tag Plugin) (Version: 5.0.19.17305)
VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0)
VLC media player 2.0.3 (Version: 2.0.3)
VTech Download Agent Library (Version: 1.00.0000)
Vuze (Version: 4.7)
Vuze Remote Toolbar (Version: 6.9.0.16)
Windows Driver Package - Leapfrog (Leapfrog-USBLAN) Net (09/10/2009 02.03.05.012) (Version: 09/10/2009 02.03.05.012)
Windows Live Call (Version: 14.0.8050.1202)
Windows Live Communications Platform (Version: 14.0.8050.1202)
Windows Live Essentials (Version: 14.0.8050.1202)
Windows Live ID Sign-in Assistant (Version: 6.500.3165.0)
Windows Live Mail (Version: 14.0.8050.1202)
Windows Live Messenger (Version: 14.0.8050.1202)
Windows Live Photo Gallery (Version: 14.0.8051.1204)
Windows Live Sync (Version: 14.0.8050.1202)
Windows Live Upload Tool (Version: 14.0.8014.1029)
Windows Live Writer (Version: 14.0.8050.1202)
Windows Mobile Device Updater Component (Version: 04.08.2345.00)
Xvid Video Codec (Version: 1.3.2)
Zune (Version: 04.08.2345.00)
Zune Language Pack (CHS) (Version: 04.08.2345.00)
Zune Language Pack (CHT) (Version: 04.08.2345.00)
Zune Language Pack (CSY) (Version: 04.08.2345.00)
Zune Language Pack (DAN) (Version: 04.08.2345.00)
Zune Language Pack (DEU) (Version: 04.08.2345.00)
Zune Language Pack (ELL) (Version: 04.08.2345.00)
Zune Language Pack (ESP) (Version: 04.08.2345.00)
Zune Language Pack (FIN) (Version: 04.08.2345.00)
Zune Language Pack (FRA) (Version: 04.08.2345.00)
Zune Language Pack (HUN) (Version: 04.08.2345.00)
Zune Language Pack (IND) (Version: 04.08.2345.00)
Zune Language Pack (ITA) (Version: 04.08.2345.00)
Zune Language Pack (JPN) (Version: 04.08.2345.00)
Zune Language Pack (KOR) (Version: 04.08.2345.00)
Zune Language Pack (MSL) (Version: 04.08.2345.00)
Zune Language Pack (NLD) (Version: 04.08.2345.00)
Zune Language Pack (NOR) (Version: 04.08.2345.00)
Zune Language Pack (PLK) (Version: 04.08.2345.00)
Zune Language Pack (PTB) (Version: 04.08.2345.00)
Zune Language Pack (PTG) (Version: 04.08.2345.00)
Zune Language Pack (RUS) (Version: 04.08.2345.00)
Zune Language Pack (SVE) (Version: 04.08.2345.00)

==================== Restore Points =========================

24-09-2013 02:01:10 Windows Update
25-09-2013 06:47:14 Scheduled Checkpoint
26-09-2013 08:09:05 OTL Restore Point - 26/09/2013 09:09:05
26-09-2013 08:26:15 OTL Restore Point - 26/09/2013 09:26:15
27-09-2013 18:19:44 Windows Update

==================== Hosts content: ==========================

2006-11-02 11:23 - 2006-09-18 22:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
::1 localhost

==================== Scheduled Tasks (whitelisted) =============

Task: {18DFD9FC-082E-4E9B-8285-5F21D2B4EDAE} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {4322AC8D-1BA6-428C-906A-0597B497B17D} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-22] (Adobe Systems Incorporated)
Task: {5640A690-318D-4F60-9DF2-4C0A34DBBCFA} - System32\Tasks\DSite => C:\Users\THEMAF~1\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE [2013-07-09] ()
Task: {5916F864-469C-4391-8604-E4EA141A2699} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-21] ()
Task: {5ED0DDB1-7329-4666-A0D7-08A62980C645} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-12] (Microsoft Corporation)
Task: {7C5A51E8-1AD7-48C6-8879-257A8A9609F5} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {7D69AE72-1CA4-4F88-911F-CE091D7E6427} - System32\Tasks\{60EEBD4B-11DB-4138-89F9-FB2FDC3A6CA2} => Iexplore.exe http://www.skype.com/go/downloading?source…p;LastError=404
Task: {8B0E6FAB-F43A-4988-AF0A-A21646C212F0} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {913CA0E0-2F06-4AD3-B7AB-9DC0E5EC16ED} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Signature Update => c:\program files\windows defender\MpCmdRun.exe [2008-01-21] (Microsoft Corporation)
Task: {9ED703A9-5FFD-40D5-895A-4385EE1509DE} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-21] (Microsoft Corporation)
Task: {9EDDC20B-307F-4E95-B43D-DCC7766DF930} - System32\Tasks\Acer\Burn Notification => C:\Program Files\eMachines\eMachines Recovery Management\NotificationCenter\Notification.exe [2008-12-09] ()
Task: {E099EE9E-9701-41F1-A486-D42677AF2E64} - System32\Tasks\TopArcadeHits => C:\Users\The Maffeys\AppData\Local\TopArcadeHits\updater.exe [2013-07-09] ()
Task: {F1952EC3-FD3F-431F-91CE-108912EAB45C} - System32\Tasks\FinishInstall igdhbblpcellaljokkpfhcjlagemhgjl => C:\Users\The Maffeys\AppData\Roaming\igdhbblpcellaljokkpfhcjlagemhgjl\MinibarChrome.exe [2013-07-09] (Sien SA)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\DSite.job => C:\Users\THEMAF~1\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE
Task: C:\Windows\Tasks\TopArcadeHits.job => C:\Users\The Maffeys\AppData\Local\TopArcadeHits\updater.exe

==================== Loaded Modules (whitelisted) =============

2013-02-13 03:38 - 2013-02-13 03:38 - 00100688 _____ () C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll
2013-08-17 13:25 - 2013-08-17 13:26 - 03551640 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll
2013-09-11 15:36 - 2013-09-11 15:36 - 16177544 _____ () C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll

==================== Alternate Data Streams (whitelisted) =========


==================== Safe Mode (whitelisted) ===================


==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (09/25/2013 02:07:27 PM) (Source: Windows Search Service) (User: )
Description: The entry in the hash map cannot be updated.

Context: Application, SystemIndex Catalog


Details:
A device attached to the system is not functioning. (0x8007001f)

Error: (09/25/2013 02:07:27 PM) (Source: Windows Search Service) (User: )
Description: The entry in the hash map cannot be updated.

Context: Application, SystemIndex Catalog


Details:
A device attached to the system is not functioning. (0x8007001f)

Error: (09/25/2013 02:07:26 PM) (Source: Windows Search Service) (User: )
Description: The entry in the hash map cannot be updated.

Context: Application, SystemIndex Catalog


Details:
A device attached to the system is not functioning. (0x8007001f)

Error: (09/25/2013 02:07:26 PM) (Source: Windows Search Service) (User: )
Description: The entry in the hash map cannot be updated.

Context: Application, SystemIndex Catalog


Details:
A device attached to the system is not functioning. (0x8007001f)

Error: (09/25/2013 02:07:24 PM) (Source: Windows Search Service) (User: )
Description: The entry in the hash map cannot be updated.

Context: Application, SystemIndex Catalog


Details:
A device attached to the system is not functioning. (0x8007001f)

Error: (09/25/2013 02:07:24 PM) (Source: Windows Search Service) (User: )
Description: The entry in the hash map cannot be updated.

Context: Application, SystemIndex Catalog


Details:
A device attached to the system is not functioning. (0x8007001f)

Error: (09/25/2013 02:07:23 PM) (Source: Windows Search Service) (User: )
Description: The entry in the hash map cannot be updated.

Context: Application, SystemIndex Catalog


Details:
A device attached to the system is not functioning. (0x8007001f)

Error: (09/25/2013 02:07:23 PM) (Source: Windows Search Service) (User: )
Description: The entry in the hash map cannot be updated.

Context: Application, SystemIndex Catalog


Details:
A device attached to the system is not functioning. (0x8007001f)

Error: (09/25/2013 02:07:21 PM) (Source: Windows Search Service) (User: )
Description: The entry in the hash map cannot be updated.

Context: Application, SystemIndex Catalog


Details:
A device attached to the system is not functioning. (0x8007001f)

Error: (09/25/2013 02:07:21 PM) (Source: Windows Search Service) (User: )
Description: The entry in the hash map cannot be updated.

Context: Application, SystemIndex Catalog


Details:
A device attached to the system is not functioning. (0x8007001f)


System errors:
=============
Error: (09/27/2013 08:28:36 PM) (Source: mbamchameleon) (User: )
Description: Mbamchameleon Failed to obtain file name information - C0000022

Error: (09/27/2013 08:28:36 PM) (Source: mbamchameleon) (User: )
Description: Mbamchameleon Failed to obtain file name information - C0000022

Error: (09/27/2013 08:28:36 PM) (Source: mbamchameleon) (User: )
Description: Mbamchameleon Failed to obtain file name information - C0000022

Error: (09/27/2013 08:28:36 PM) (Source: mbamchameleon) (User: )
Description: Mbamchameleon Failed to obtain file name information - C0000022

Error: (09/27/2013 08:28:36 PM) (Source: mbamchameleon) (User: )
Description: Mbamchameleon Failed to obtain file name information - C0000022

Error: (09/27/2013 08:28:36 PM) (Source: mbamchameleon) (User: )
Description: Mbamchameleon Failed to obtain file name information - C0000022

Error: (09/27/2013 08:28:36 PM) (Source: mbamchameleon) (User: )
Description: Mbamchameleon Failed to obtain file name information - C0000022

Error: (09/27/2013 08:28:36 PM) (Source: mbamchameleon) (User: )
Description: Mbamchameleon Failed to obtain file name information - C0000022

Error: (09/27/2013 08:28:36 PM) (Source: mbamchameleon) (User: )
Description: Mbamchameleon Failed to obtain file name information - C0000022

Error: (09/27/2013 08:28:36 PM) (Source: mbamchameleon) (User: )
Description: Mbamchameleon Failed to obtain file name information - C0000022


Microsoft Office Sessions:
=========================

CodeIntegrity Errors:
===================================
Date: 2013-09-27 20:28:11.760
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

Date: 2013-09-27 20:28:11.549
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

Date: 2013-09-27 20:28:11.327
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

Date: 2013-09-27 20:28:11.097
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

Date: 2013-09-27 20:28:10.864
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

Date: 2013-09-27 20:28:10.642
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

Date: 2013-09-27 20:28:10.410
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

Date: 2013-09-27 20:28:10.175
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

Date: 2013-09-27 20:27:45.378
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

Date: 2013-09-27 20:27:45.168
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.


==================== Memory info ===========================

Percentage of memory in use: 65%
Total physical RAM: 1977.24 MB
Available physical RAM: 682.52 MB
Total Pagefile: 4207.79 MB
Available Pagefile: 2516.77 MB
Total Virtual: 2047.88 MB
Available Virtual: 1909.15 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:139.04 GB) (Free:24.33 GB) NTFS ==>[Drive with boot components (obtained from BCD)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 149 GB) (Disk ID: A6D43AF1)
Partition 1: (Not Active) - (Size=10 GB) - (Type=27)
Partition 2: (Active) - (Size=139 GB) - (Type=07 NTFS)

==================== End Of Log ============================
Hello rm69,

your computer appears to have been infected by malware with a backdoor (ZeroAccess). These programs have the ability to steal passwords and other information from your system. If you use your computer for sensitive purposes such as internet banking then I recommend you take the following steps immediately:
Use another, uninfected computer to change all your internet passwords, especially ones with financial implications such as banks, paypal, ebay, etc. You should also change the passwords for any other site you use.
Call your bank(s), credit card company or any other institution which may be affected and advise them that your login/password or credit card information may have been stolen and ask what steps to take with regard to your account.
Consider what other private information could possibly have been taken from your computer and take appropriate steps.

This infection can almost certainly be cleaned, but as the malware could be configured to run any program a remote attacker requires, it will be impossible to be 100% sure that the machine is clean, if this is unacceptable to you then you should consider reformatting the system partition and reinstalling Windows as this is the only 100% sure answer.

If you wish to reformat then please let me know in your next response, I'll now continue with instructions for cleaning.

————————————

Jo, i have tried to copy and past the TDSS scan results but unable to do so ??

We can skip TDSS scan results.
————————————

Open notepad. Please copy the contents of the code box below. To do this highlight the contents of the box and right click on it. Paste this into the open notepad. Save it on the flash drive as fixlist.txt

HKCU\…409d6c4515e9\InprocServer32: [Default-shell32] C:\$Recycle.Bin\S-1-5-21-2252879165-1410815983-246096844-1000\$13e25703617c253be44b1886dcbcf2ee\n. ATTENTION! ====> ZeroAccess/Alureon? 
SearchScopes: HKLM - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2504091 
SearchScopes: HKCU - DefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www2.delta-search.com/?q={searchTer…57&tsp=4998 
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www2.delta-search.com/?q={searchTer…57&tsp=4998 
SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2504091 
BHO: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File 
BHO: Fookgle - {6CF597EF-88EF-455B-AC5E-33D8309718C3} - C:\Program Files\Fookgle\Fookgle.dll No File 
BHO: TopArcadeHits Games - {A7A9D7E7-E0C0-4202-9F13-6A06BD073CDA} - C:\Users\The Maffeys\AppData\Local\TopArcadeHits\Toparcadehits.dll () 
BHO: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.) 
Toolbar: HKLM - Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.) 
Toolbar: HKCU - No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File 
Toolbar: HKCU -Vuze Remote Toolbar - {BA14329E-9550-4989-B3F2-9732E92D17CC} - C:\Program Files\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.) 
FF SearchPlugin: C:\Users\The Maffeys\AppData\Roaming\Mozilla\Firefox\Profiles\z2bu19bv.default\searchplugins\babylon.xml 
FF SearchPlugin: C:\Users\The Maffeys\AppData\Roaming\Mozilla\Firefox\Profiles\z2bu19bv.default\searchplugins\delta.xml 
FF Extension: TopArcadeHits - C:\Users\The Maffeys\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\{0113D088-8ED1-468C-B225-585A9C53B5E3} 
FF Extension: TopArcadeHits - C:\Users\The Maffeys\AppData\Roaming\Mozilla\Firefox\Profiles\z2bu19bv.default\Extensions\{0113D088-8ED1-468C-B225-585A9C53B5E3} 
FF HKCU\…\Firefox\Extensions: [[removed]] - C:\Program Files\Fookgle\FF\ 
FF Extension: No Name - C:\Program Files\Fookgle\FF\ 
2013-09-27 20:24 - 2013-07-09 22:24 - 00000304 _____ C:\Windows\Tasks\DSite.job 
2013-09-27 19:07 - 2013-07-09 22:33 - 00000288 _____ C:\Windows\Tasks\TopArcadeHits.job 
2013-09-25 14:08 - 2013-07-09 22:33 - 00000000 ____D C:\Users\The Maffeys\AppData\Roaming\igdhbblpcellaljokkpfhcjlagemhgjl 
C:\$Recycle.Bin\S-1-5-21-2252879165-1410815983-246096844-1000\$13e25703617c253be44b1886dcbcf2ee 
C:\Users\The Maffeys\AppData\Local\Temp\FreemakeVideoConverter_3.2.1.1.exe 
C:\Users\The Maffeys\AppData\Local\Temp\i4jdel0.exe 
C:\Users\The Maffeys\AppData\Local\Temp\i4jdel1.exe 
C:\Users\The Maffeys\AppData\Local\Temp\i4jdel2.exe 
C:\Users\The Maffeys\AppData\Local\Temp\InstallFlashPlayer.exe 
C:\Users\The Maffeys\AppData\Local\Temp\jre-7u15-windows-i586-iftw.exe 
C:\Users\The Maffeys\AppData\Local\Temp\jre-7u17-windows-i586-iftw.exe 
C:\Users\The Maffeys\AppData\Local\Temp\MSNF63D.exe 
C:\Users\The Maffeys\AppData\Local\Temp\pyl7728.tmp.exe 
C:\Users\The Maffeys\AppData\Local\Temp\RtkBtMnt.exe 
C:\Users\The Maffeys\AppData\Local\Temp\SetupToparcadehits.exe 
C:\Users\The Maffeys\AppData\Local\Temp\uninst1.exe

NOTICE: This script was written specifically for this user, for use on that particular machine.
Running this on another machine may cause damage to your operating system


Run FRST again like we did before but this time press the Fix button just once and wait.
The tool will make a log on the flash drive (Fixlog.txt) please post it to your reply.
Also boot the computer into normal mode and let me know how things are looking.

————————————

Run Malwarebytes Anti-Rootkit again: Right-click mbar.exe and select Run As Administrator
  • Scan your system for malware
  • If malware is found, click on the Cleanup button to remove any threats and reboot if prompted to do so.
  • Wait while the system shuts down and the cleanup process is performed.
  • then please go to the MBAR folder and then copy/paste the contents of the MBAR-log-***.txt file to your next reply.
If there is no malware found, please let me know as well.
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 27-09-2013
Ran by [removed] at 2013-09-30 19:04:09 Run:1
Running from C:\Users\[removed]\Downloads
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
HKCU\…409d6c4515e9\InprocServer32: [Default-shell32] C:\$Recycle.Bin\S-1-5-21-2252879165-1410815983-246096844-1000\$13e25703617c253be44b1886dcbcf2ee\n. ATTENTION! ====> ZeroAccess/Alureon?
SearchScopes: HKLM - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2504091
SearchScopes: HKCU - DefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www2.delta-search.com/?q={searchTer…57&tsp=4998
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www2.delta-search.com/?q={searchTer…57&tsp=4998
SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2504091
BHO: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Fookgle - {6CF597EF-88EF-455B-AC5E-33D8309718C3} - C:\Program Files\Fookgle\Fookgle.dll No File
BHO: TopArcadeHits Games - {A7A9D7E7-E0C0-4202-9F13-6A06BD073CDA} - C:\Users\The Maffeys\AppData\Local\TopArcadeHits\Toparcadehits.dll ()
BHO: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
Toolbar: HKLM - Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
Toolbar: HKCU - No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File
Toolbar: HKCU -Vuze Remote Toolbar - {BA14329E-9550-4989-B3F2-9732E92D17CC} - C:\Program Files\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
FF SearchPlugin: C:\Users\The Maffeys\AppData\Roaming\Mozilla\Firefox\Profiles\z2bu19bv.default\searchplugins\babylon.xml
FF SearchPlugin: C:\Users\The Maffeys\AppData\Roaming\Mozilla\Firefox\Profiles\z2bu19bv.default\searchplugins\delta.xml
FF Extension: TopArcadeHits - C:\Users\The Maffeys\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\{0113D088-8ED1-468C-B225-585A9C53B5E3}
FF Extension: TopArcadeHits - C:\Users\The Maffeys\AppData\Roaming\Mozilla\Firefox\Profiles\z2bu19bv.default\Extensions\{0113D088-8ED1-468C-B225-585A9C53B5E3}
FF HKCU\…\Firefox\Extensions: [[removed]] - C:\Program Files\Fookgle\FF\
FF Extension: No Name - C:\Program Files\Fookgle\FF\
2013-09-27 20:24 - 2013-07-09 22:24 - 00000304 _____ C:\Windows\Tasks\DSite.job
2013-09-27 19:07 - 2013-07-09 22:33 - 00000288 _____ C:\Windows\Tasks\TopArcadeHits.job
2013-09-25 14:08 - 2013-07-09 22:33 - 00000000 ____D C:\Users\The Maffeys\AppData\Roaming\igdhbblpcellaljokkpfhcjlagemhgjl
C:\$Recycle.Bin\S-1-5-21-2252879165-1410815983-246096844-1000\$13e25703617c253be44b1886dcbcf2ee
C:\Users\The Maffeys\AppData\Local\Temp\FreemakeVideoConverter_3.2.1.1.exe
C:\Users\The Maffeys\AppData\Local\Temp\i4jdel0.exe
C:\Users\The Maffeys\AppData\Local\Temp\i4jdel1.exe
C:\Users\The Maffeys\AppData\Local\Temp\i4jdel2.exe
C:\Users\The Maffeys\AppData\Local\Temp\InstallFlashPlayer.exe
C:\Users\The Maffeys\AppData\Local\Temp\jre-7u15-windows-i586-iftw.exe
C:\Users\The Maffeys\AppData\Local\Temp\jre-7u17-windows-i586-iftw.exe
C:\Users\The Maffeys\AppData\Local\Temp\MSNF63D.exe
C:\Users\The Maffeys\AppData\Local\Temp\pyl7728.tmp.exe
C:\Users\The Maffeys\AppData\Local\Temp\RtkBtMnt.exe
C:\Users\The Maffeys\AppData\Local\Temp\SetupToparcadehits.exe
C:\Users\The Maffeys\AppData\Local\Temp\uninst1.exe
*****************

HKCU\Software\Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9} => Key deleted successfully. If the key returned, move the associated file, reboot and list the key for deletion.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b} => Key not found.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB} => Key deleted successfully.
HKCR\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB} => Key not found.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6CF597EF-88EF-455B-AC5E-33D8309718C3} => Key deleted successfully.
HKCR\CLSID\{6CF597EF-88EF-455B-AC5E-33D8309718C3} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A7A9D7E7-E0C0-4202-9F13-6A06BD073CDA} => Key deleted successfully.
HKCR\CLSID\{A7A9D7E7-E0C0-4202-9F13-6A06BD073CDA} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ba14329e-9550-4989-b3f2-9732e92d17cc} => Key deleted successfully.
HKCR\CLSID\{ba14329e-9550-4989-b3f2-9732e92d17cc} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{ba14329e-9550-4989-b3f2-9732e92d17cc} => Value deleted successfully.
HKCR\CLSID\{ba14329e-9550-4989-b3f2-9732e92d17cc} => Key not found.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} => Value deleted successfully.
HKCR\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} => Key deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{BA14329E-9550-4989-B3F2-9732E92D17CC} => Value deleted successfully.
HKCR\CLSID\{BA14329E-9550-4989-B3F2-9732E92D17CC} => Key not found.
C:\Users\The Maffeys\AppData\Roaming\Mozilla\Firefox\Profiles\z2bu19bv.default\searchplugins\babylon.xml => Moved successfully.
C:\Users\The Maffeys\AppData\Roaming\Mozilla\Firefox\Profiles\z2bu19bv.default\searchplugins\delta.xml => Moved successfully.
C:\Users\The Maffeys\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\{0113D088-8ED1-468C-B225-585A9C53B5E3} => Moved successfully.
C:\Users\The Maffeys\AppData\Roaming\Mozilla\Firefox\Profiles\z2bu19bv.default\Extensions\{0113D088-8ED1-468C-B225-585A9C53B5E3} => Moved successfully.
HKCU\Software\Mozilla\Firefox\Extensions\\[removed] => Value deleted successfully.
C:\Program Files\Fookgle\FF\ => Moved successfully.
C:\Windows\Tasks\DSite.job => Moved successfully.
C:\Windows\Tasks\TopArcadeHits.job => Moved successfully.
C:\Users\The Maffeys\AppData\Roaming\igdhbblpcellaljokkpfhcjlagemhgjl => Moved successfully.
C:\$Recycle.Bin\S-1-5-21-2252879165-1410815983-246096844-1000\$13e25703617c253be44b1886dcbcf2ee => Directory moved successfully.
C:\Users\The Maffeys\AppData\Local\Temp\FreemakeVideoConverter_3.2.1.1.exe => Moved successfully.
C:\Users\The Maffeys\AppData\Local\Temp\i4jdel0.exe => Moved successfully.
C:\Users\The Maffeys\AppData\Local\Temp\i4jdel1.exe => Moved successfully.
C:\Users\The Maffeys\AppData\Local\Temp\i4jdel2.exe => Moved successfully.
C:\Users\The Maffeys\AppData\Local\Temp\InstallFlashPlayer.exe => Moved successfully.
C:\Users\The Maffeys\AppData\Local\Temp\jre-7u15-windows-i586-iftw.exe => Moved successfully.
C:\Users\The Maffeys\AppData\Local\Temp\jre-7u17-windows-i586-iftw.exe => Moved successfully.
C:\Users\The Maffeys\AppData\Local\Temp\MSNF63D.exe => Moved successfully.
C:\Users\The Maffeys\AppData\Local\Temp\pyl7728.tmp.exe => Moved successfully.
C:\Users\The Maffeys\AppData\Local\Temp\RtkBtMnt.exe => Moved successfully.
C:\Users\The Maffeys\AppData\Local\Temp\SetupToparcadehits.exe => Moved successfully.
C:\Users\The Maffeys\AppData\Local\Temp\uninst1.exe => Moved successfully.

==== End of Fixlog ====
————————————— Malwarebytes Anti-Rootkit BETA 1.07.0.1005 © Malwarebytes Corporation 2011-2012 OS version: 6.0.6002 Windows Vista Service Pack 2 x86 Account is Administrative Internet Explorer version: 9.0.8112.16421 File system is: NTFS Disk drives: C:\ DRIVE_FIXED CPU speed: 2.194000 GHz Memory total: 2073284608, free: 812679168 Downloaded database version: v2013.09.26.07 Downloaded database version: v2013.09.23.01 ======================================= Initializing… ———— Kernel report ———— 09/26/2013 21:50:51 ———— Loaded modules ———– \SystemRoot\system32\ntkrnlpa.exe \SystemRoot\system32\hal.dll \SystemRoot\system32\kdcom.dll \SystemRoot\system32\mcupdate_GenuineIntel.dll \SystemRoot\system32\PSHED.dll \SystemRoot\system32\BOOTVID.dll \SystemRoot\system32\CLFS.SYS \SystemRoot\system32\CI.dll \SystemRoot\system32\drivers\Wdf01000.sys \SystemRoot\system32\drivers\WDFLDR.SYS \SystemRoot\system32\drivers\acpi.sys \SystemRoot\system32\drivers\WMILIB.SYS \SystemRoot\system32\drivers\msisadrv.sys \SystemRoot\system32\drivers\pci.sys \SystemRoot\System32\drivers\partmgr.sys \SystemRoot\system32\DRIVERS\compbatt.sys \SystemRoot\system32\DRIVERS\BATTC.SYS \SystemRoot\system32\drivers\volmgr.sys \SystemRoot\System32\drivers\volmgrx.sys \SystemRoot\System32\drivers\mountmgr.sys \SystemRoot\System32\Drivers\UBHelper.sys \SystemRoot\system32\drivers\atapi.sys \SystemRoot\system32\drivers\ataport.SYS \SystemRoot\system32\drivers\msahci.sys \SystemRoot\system32\drivers\PCIIDEX.SYS \SystemRoot\system32\drivers\fltmgr.sys \SystemRoot\system32\drivers\fileinfo.sys \SystemRoot\system32\DRIVERS\MpFilter.sys \SystemRoot\System32\Drivers\ksecdd.sys \SystemRoot\system32\drivers\ndis.sys \SystemRoot\system32\drivers\msrpc.sys \SystemRoot\system32\drivers\NETIO.SYS \SystemRoot\System32\drivers\tcpip.sys \SystemRoot\System32\drivers\fwpkclnt.sys \SystemRoot\System32\Drivers\Ntfs.sys \SystemRoot\system32\drivers\volsnap.sys \SystemRoot\System32\Drivers\spldr.sys \SystemRoot\System32\Drivers\mup.sys \SystemRoot\System32\drivers\ecache.sys \SystemRoot\system32\drivers\disk.sys \SystemRoot\system32\drivers\CLASSPNP.SYS \SystemRoot\system32\drivers\crcdisk.sys \SystemRoot\system32\DRIVERS\tunnel.sys \SystemRoot\system32\DRIVERS\tunmp.sys \SystemRoot\system32\DRIVERS\intelppm.sys \SystemRoot\system32\DRIVERS\igdkmd32.sys \SystemRoot\System32\drivers\dxgkrnl.sys \SystemRoot\System32\drivers\watchdog.sys \SystemRoot\system32\DRIVERS\usbuhci.sys \SystemRoot\system32\DRIVERS\USBPORT.SYS \SystemRoot\system32\DRIVERS\usbehci.sys \SystemRoot\system32\DRIVERS\HDAudBus.sys \SystemRoot\system32\DRIVERS\bcmwl6.sys \SystemRoot\system32\DRIVERS\L1C60x86.sys \SystemRoot\system32\DRIVERS\CmBatt.sys \SystemRoot\system32\DRIVERS\i8042prt.sys \SystemRoot\system32\DRIVERS\DKbFltr.sys \SystemRoot\system32\DRIVERS\kbdclass.sys \SystemRoot\system32\DRIVERS\SynTP.sys \SystemRoot\system32\DRIVERS\USBD.SYS \SystemRoot\system32\DRIVERS\mouclass.sys \SystemRoot\system32\DRIVERS\cdrom.sys \SystemRoot\system32\DRIVERS\NTIDrvr.sys \SystemRoot\system32\DRIVERS\wmiacpi.sys \SystemRoot\system32\DRIVERS\msiscsi.sys \SystemRoot\system32\DRIVERS\storport.sys \SystemRoot\system32\DRIVERS\TDI.SYS \SystemRoot\system32\DRIVERS\rasl2tp.sys \SystemRoot\system32\DRIVERS\ndistapi.sys \SystemRoot\system32\DRIVERS\ndiswan.sys \SystemRoot\system32\DRIVERS\raspppoe.sys \SystemRoot\system32\DRIVERS\raspptp.sys \SystemRoot\system32\DRIVERS\rassstp.sys \SystemRoot\system32\DRIVERS\termdd.sys \SystemRoot\system32\DRIVERS\swenum.sys \SystemRoot\system32\DRIVERS\ks.sys \SystemRoot\system32\DRIVERS\mssmbios.sys \SystemRoot\system32\DRIVERS\umbus.sys \SystemRoot\system32\DRIVERS\usbhub.sys \SystemRoot\System32\Drivers\NDProxy.SYS \SystemRoot\system32\drivers\RTKVHDA.sys \SystemRoot\system32\drivers\portcls.sys \SystemRoot\system32\drivers\drmk.sys \SystemRoot\System32\Drivers\Fs_Rec.SYS \SystemRoot\System32\Drivers\Null.SYS \SystemRoot\System32\Drivers\Beep.SYS \SystemRoot\System32\drivers\vga.sys \SystemRoot\System32\drivers\VIDEOPRT.SYS \SystemRoot\System32\DRIVERS\RDPCDD.sys \SystemRoot\system32\drivers\rdpencdd.sys \SystemRoot\System32\Drivers\Msfs.SYS \SystemRoot\System32\Drivers\Npfs.SYS \SystemRoot\System32\DRIVERS\rasacd.sys \SystemRoot\system32\DRIVERS\tdx.sys \SystemRoot\system32\DRIVERS\smb.sys \SystemRoot\System32\DRIVERS\netbt.sys \SystemRoot\system32\drivers\afd.sys \SystemRoot\system32\DRIVERS\pacer.sys \SystemRoot\system32\DRIVERS\netbios.sys \SystemRoot\system32\DRIVERS\wanarp.sys \SystemRoot\system32\DRIVERS\rdbss.sys \??\C:\PROGRA~1\LAUNCH~1\DPortIO.sys \SystemRoot\system32\drivers\nsiproxy.sys \SystemRoot\System32\Drivers\dfsc.sys \SystemRoot\System32\Drivers\crashdmp.sys \SystemRoot\System32\Drivers\dump_dumpata.sys \SystemRoot\System32\Drivers\dump_msahci.sys \SystemRoot\System32\win32k.sys \SystemRoot\System32\drivers\Dxapi.sys \SystemRoot\System32\TSDDD.dll \SystemRoot\System32\cdd.dll \SystemRoot\System32\ATMFD.DLL \SystemRoot\system32\drivers\luafv.sys \SystemRoot\system32\drivers\WudfPf.sys \SystemRoot\system32\DRIVERS\lltdio.sys \SystemRoot\system32\DRIVERS\nwifi.sys \SystemRoot\system32\DRIVERS\ndisuio.sys \SystemRoot\system32\DRIVERS\rspndr.sys \SystemRoot\system32\drivers\spsys.sys \SystemRoot\system32\drivers\HTTP.sys \SystemRoot\System32\DRIVERS\srvnet.sys \SystemRoot\system32\DRIVERS\bowser.sys \SystemRoot\System32\drivers\mpsdrv.sys \SystemRoot\system32\drivers\mrxdav.sys \SystemRoot\system32\DRIVERS\mrxsmb.sys \SystemRoot\system32\DRIVERS\mrxsmb10.sys \SystemRoot\system32\DRIVERS\mrxsmb20.sys \SystemRoot\System32\DRIVERS\srv2.sys \SystemRoot\System32\DRIVERS\srv.sys \SystemRoot\system32\DRIVERS\NisDrvWFP.sys \SystemRoot\system32\drivers\peauth.sys \SystemRoot\System32\Drivers\secdrv.SYS \SystemRoot\System32\drivers\tcpipreg.sys \SystemRoot\system32\DRIVERS\cdfs.sys \SystemRoot\system32\DRIVERS\monitor.sys \??\C:\Windows\system32\drivers\mbamchameleon.sys \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys \Windows\System32\ntdll.dll ———– End ———– Done! <<<1>>> Upper Device Name: \Device\Harddisk0\DR0 Upper Device Object: 0xffffffff84b3c968 Upper Device Driver Name: \Driver\disk\ Lower Device Name: \Device\Ide\IdeDeviceP0T0L0-0\ Lower Device Object: 0xffffffff84003390 Lower Device Driver Name: \Driver\atapi\ <<<2>>> Physical Sector Size: 512 Drive: 0, DevicePointer: 0xffffffff84b3c968, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\ ——— Disk Stack —— DevicePointer: 0xffffffff84b3c5e8, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xffffffff84b3c968, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\ DevicePointer: 0xffffffff840043a8, DeviceName: Unknown, DriverName: \Driver\ACPI\ DevicePointer: 0xffffffff84003390, DeviceName: \Device\Ide\IdeDeviceP0T0L0-0\, DriverName: \Driver\atapi\ ———— End ———- Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\ Upper DeviceData: 0x0, 0x0, 0x0 Lower DeviceData: 0x0, 0x0, 0x0 <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes <<<2>>> <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers… <<<2>>> <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Done! Drive 0 Scanning MBR on drive 0… Inspecting partition table: MBR Signature: 55AA Disk Signature: A6D43AF1 Partition information: Partition 0 type is Other (0x27) Partition is NOT ACTIVE. Partition starts at LBA: 63 Numsec = 20980827 Partition 1 type is Primary (0x7) Partition is ACTIVE. Partition starts at LBA: 20981760 Numsec = 291596288 Partition is not bootable Partition 2 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition 3 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Disk Size: 160041885696 bytes Sector size: 512 bytes Scanning physical sectors of unpartitioned space on drive 0 (1-62-312561808-312581808)… Done! Infected: C:\$Recycle.Bin\S-1-5-21-2252879165-1410815983-246096844-1000\$13e25703617c253be44b1886dcbcf2ee\@ –> [Trojan.Siredef.C] Infected: C:\Users\The Maffeys\AppData\Local\Temp\SetupToparcadehits.exe –> [Adware.GameVance] Infected: C:\Users\The Maffeys\AppData\Local\Temp\M6CDr4Tr.exe.part –> [Adware.AdBundle] Infected: C:\Users\The Maffeys\AppData\Local\TopArcadeHits\uninstaller.exe –> [Adware.GameVance] Infected: C:\Users\The Maffeys\AppData\Local\TopArcadeHits\updater.exe –> [Adware.GameVance] Infected: C:\Users\The Maffeys\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TopArcadeHits\Play Toparcadehits Online.url –> [Adware.GameVance] Infected: C:\Users\The Maffeys\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TopArcadeHits –> [Adware.GameVance] Infected: C:\Users\The Maffeys\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TopArcadeHits\Uninstall Toparcadehits.lnk –> [Adware.GameVance] Infected: HKCU\SOFTWARE\CLASSES\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9} –> [Hijack.Trojan.Siredef.C] Infected: HKCU\SOFTWARE\CLASSES\CLSID\{FBEB8A05-BEEE-4442-804E-409D6C4515E9}\INPROCSERVER32| –> [Trojan.Zaccess] Infected: HKCU\SOFTWARE\CLASSES\CLSID\{FBEB8A05-BEEE-4442-804E-409D6C4515E9}\INPROCSERVER32 –> [Trojan.Zaccess] Infected: C:\$Recycle.Bin\S-1-5-21-2252879165-1410815983-246096844-1000\$13e25703617c253be44b1886dcbcf2ee\U –> [Trojan.Siredef.C] Infected: C:\$Recycle.Bin\S-1-5-21-2252879165-1410815983-246096844-1000\$13e25703617c253be44b1886dcbcf2ee\L –> [Trojan.Siredef.C] Infected: C:\$Recycle.Bin\S-1-5-21-2252879165-1410815983-246096844-1000\$13e25703617c253be44b1886dcbcf2ee –> [Trojan.Siredef.C] Scan finished User declined to cleanup malware. ————————————— Malwarebytes Anti-Rootkit BETA 1.07.0.1005 © Malwarebytes Corporation 2011-2012 OS version: 6.0.6002 Windows Vista Service Pack 2 x86 Account is Administrative Internet Explorer version: 9.0.8112.16421 File system is: NTFS Disk drives: C:\ DRIVE_FIXED, E:\ DRIVE_FIXED CPU speed: 2.194000 GHz Memory total: 2073284608, free: 1081638912 ======================================= Initializing… ———— Kernel report ———— 09/30/2013 19:20:01 ———— Loaded modules ———– \SystemRoot\system32\ntkrnlpa.exe \SystemRoot\system32\hal.dll \SystemRoot\system32\kdcom.dll \SystemRoot\system32\mcupdate_GenuineIntel.dll \SystemRoot\system32\PSHED.dll \SystemRoot\system32\BOOTVID.dll \SystemRoot\system32\CLFS.SYS \SystemRoot\system32\CI.dll \SystemRoot\system32\drivers\Wdf01000.sys \SystemRoot\system32\drivers\WDFLDR.SYS \SystemRoot\system32\drivers\acpi.sys \SystemRoot\system32\drivers\WMILIB.SYS \SystemRoot\system32\drivers\msisadrv.sys \SystemRoot\system32\drivers\pci.sys \SystemRoot\System32\drivers\partmgr.sys \SystemRoot\system32\DRIVERS\compbatt.sys \SystemRoot\system32\DRIVERS\BATTC.SYS \SystemRoot\system32\drivers\volmgr.sys \SystemRoot\System32\drivers\volmgrx.sys \SystemRoot\System32\drivers\mountmgr.sys \SystemRoot\System32\Drivers\UBHelper.sys \SystemRoot\system32\drivers\atapi.sys \SystemRoot\system32\drivers\ataport.SYS \SystemRoot\system32\drivers\msahci.sys \SystemRoot\system32\drivers\PCIIDEX.SYS \SystemRoot\system32\drivers\fltmgr.sys \SystemRoot\system32\drivers\fileinfo.sys \SystemRoot\system32\DRIVERS\MpFilter.sys \SystemRoot\System32\Drivers\ksecdd.sys \SystemRoot\system32\drivers\ndis.sys \SystemRoot\system32\drivers\msrpc.sys \SystemRoot\system32\drivers\NETIO.SYS \SystemRoot\System32\drivers\tcpip.sys \SystemRoot\System32\drivers\fwpkclnt.sys \SystemRoot\System32\Drivers\Ntfs.sys \SystemRoot\system32\drivers\volsnap.sys \SystemRoot\System32\Drivers\spldr.sys \SystemRoot\System32\Drivers\mup.sys \SystemRoot\System32\drivers\ecache.sys \SystemRoot\system32\drivers\disk.sys \SystemRoot\system32\drivers\CLASSPNP.SYS \SystemRoot\system32\drivers\crcdisk.sys \SystemRoot\system32\DRIVERS\tunnel.sys \SystemRoot\system32\DRIVERS\tunmp.sys \SystemRoot\system32\DRIVERS\intelppm.sys \SystemRoot\system32\DRIVERS\igdkmd32.sys \SystemRoot\System32\drivers\dxgkrnl.sys \SystemRoot\System32\drivers\watchdog.sys \SystemRoot\system32\DRIVERS\usbuhci.sys \SystemRoot\system32\DRIVERS\USBPORT.SYS \SystemRoot\system32\DRIVERS\usbehci.sys \SystemRoot\system32\DRIVERS\HDAudBus.sys \SystemRoot\system32\DRIVERS\bcmwl6.sys \SystemRoot\system32\DRIVERS\L1C60x86.sys \SystemRoot\system32\DRIVERS\CmBatt.sys \SystemRoot\system32\DRIVERS\i8042prt.sys \SystemRoot\system32\DRIVERS\DKbFltr.sys \SystemRoot\system32\DRIVERS\kbdclass.sys \SystemRoot\system32\DRIVERS\SynTP.sys \SystemRoot\system32\DRIVERS\USBD.SYS \SystemRoot\system32\DRIVERS\mouclass.sys \SystemRoot\system32\DRIVERS\cdrom.sys \SystemRoot\system32\DRIVERS\NTIDrvr.sys \SystemRoot\system32\DRIVERS\wmiacpi.sys \SystemRoot\system32\DRIVERS\msiscsi.sys \SystemRoot\system32\DRIVERS\storport.sys \SystemRoot\system32\DRIVERS\TDI.SYS \SystemRoot\system32\DRIVERS\rasl2tp.sys \SystemRoot\system32\DRIVERS\ndistapi.sys \SystemRoot\system32\DRIVERS\ndiswan.sys \SystemRoot\system32\DRIVERS\raspppoe.sys \SystemRoot\system32\DRIVERS\raspptp.sys \SystemRoot\system32\DRIVERS\rassstp.sys \SystemRoot\system32\DRIVERS\termdd.sys \SystemRoot\system32\DRIVERS\swenum.sys \SystemRoot\system32\DRIVERS\ks.sys \SystemRoot\system32\DRIVERS\mssmbios.sys \SystemRoot\system32\DRIVERS\umbus.sys \SystemRoot\system32\DRIVERS\usbhub.sys \SystemRoot\System32\Drivers\NDProxy.SYS \SystemRoot\system32\drivers\RTKVHDA.sys \SystemRoot\system32\drivers\portcls.sys \SystemRoot\system32\drivers\drmk.sys \SystemRoot\System32\Drivers\Fs_Rec.SYS \SystemRoot\System32\Drivers\Null.SYS \SystemRoot\System32\Drivers\Beep.SYS \SystemRoot\System32\drivers\vga.sys \SystemRoot\System32\drivers\VIDEOPRT.SYS \SystemRoot\System32\DRIVERS\RDPCDD.sys \SystemRoot\system32\drivers\rdpencdd.sys \SystemRoot\System32\Drivers\Msfs.SYS \SystemRoot\System32\Drivers\Npfs.SYS \SystemRoot\System32\DRIVERS\rasacd.sys \SystemRoot\system32\DRIVERS\tdx.sys \SystemRoot\system32\DRIVERS\smb.sys \SystemRoot\System32\DRIVERS\netbt.sys \SystemRoot\system32\drivers\afd.sys \SystemRoot\system32\DRIVERS\pacer.sys \SystemRoot\system32\DRIVERS\netbios.sys \SystemRoot\system32\DRIVERS\wanarp.sys \SystemRoot\system32\DRIVERS\rdbss.sys \??\C:\PROGRA~1\LAUNCH~1\DPortIO.sys \SystemRoot\system32\drivers\nsiproxy.sys \SystemRoot\System32\Drivers\dfsc.sys \SystemRoot\system32\DRIVERS\USBSTOR.SYS \SystemRoot\System32\Drivers\crashdmp.sys \SystemRoot\System32\Drivers\dump_dumpata.sys \SystemRoot\System32\Drivers\dump_msahci.sys \SystemRoot\System32\win32k.sys \SystemRoot\System32\drivers\Dxapi.sys \SystemRoot\system32\DRIVERS\monitor.sys \SystemRoot\System32\TSDDD.dll \SystemRoot\System32\cdd.dll \SystemRoot\System32\ATMFD.DLL \SystemRoot\system32\drivers\luafv.sys \SystemRoot\system32\drivers\WudfPf.sys \SystemRoot\system32\DRIVERS\lltdio.sys \SystemRoot\system32\DRIVERS\nwifi.sys \SystemRoot\system32\DRIVERS\ndisuio.sys \SystemRoot\system32\DRIVERS\rspndr.sys \SystemRoot\system32\drivers\HTTP.sys \SystemRoot\System32\DRIVERS\srvnet.sys \SystemRoot\system32\DRIVERS\bowser.sys \SystemRoot\System32\drivers\mpsdrv.sys \SystemRoot\system32\drivers\mrxdav.sys \SystemRoot\system32\DRIVERS\mrxsmb.sys \SystemRoot\system32\DRIVERS\mrxsmb10.sys \SystemRoot\system32\DRIVERS\mrxsmb20.sys \SystemRoot\System32\DRIVERS\srv2.sys \SystemRoot\System32\DRIVERS\srv.sys \SystemRoot\system32\drivers\spsys.sys \SystemRoot\system32\DRIVERS\NisDrvWFP.sys \SystemRoot\system32\drivers\peauth.sys \SystemRoot\System32\Drivers\secdrv.SYS \SystemRoot\System32\drivers\tcpipreg.sys \SystemRoot\system32\DRIVERS\cdfs.sys \??\C:\Windows\system32\drivers\mbamchameleon.sys \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys \Windows\System32\ntdll.dll ———– End ———– Done! <<<1>>> Upper Device Name: \Device\Harddisk1\DR1 Upper Device Object: 0xffffffff857d27d0 Upper Device Driver Name: \Driver\disk\ Lower Device Name: \Device\00000062\ Lower Device Object: 0xffffffff857cd030 Lower Device Driver Name: \Driver\USBSTOR\ <<<1>>> Upper Device Name: \Device\Harddisk0\DR0 Upper Device Object: 0xffffffff84f54600 Upper Device Driver Name: \Driver\disk\ Lower Device Name: \Device\Ide\IdeDeviceP0T0L0-0\ Lower Device Object: 0xffffffff84009230 Lower Device Driver Name: \Driver\atapi\ <<<2>>> Physical Sector Size: 512 Drive: 0, DevicePointer: 0xffffffff84f54600, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\ ——— Disk Stack —— DevicePointer: 0xffffffff84f542e8, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xffffffff84f54600, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\ DevicePointer: 0xffffffff8400c3a8, DeviceName: Unknown, DriverName: \Driver\ACPI\ DevicePointer: 0xffffffff84009230, DeviceName: \Device\Ide\IdeDeviceP0T0L0-0\, DriverName: \Driver\atapi\ ———— End ———- Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\ Upper DeviceData: 0x0, 0x0, 0x0 Lower DeviceData: 0x0, 0x0, 0x0 <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes <<<2>>> <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers… <<<2>>> <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Done! Drive 0 Scanning MBR on drive 0… Inspecting partition table: MBR Signature: 55AA Disk Signature: A6D43AF1 Partition information: Partition 0 type is Other (0x27) Partition is NOT ACTIVE. Partition starts at LBA: 63 Numsec = 20980827 Partition 1 type is Primary (0x7) Partition is ACTIVE. Partition starts at LBA: 20981760 Numsec = 291596288 Partition is not bootable Partition 2 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition 3 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Disk Size: 160041885696 bytes Sector size: 512 bytes Scanning physical sectors of unpartitioned space on drive 0 (1-62-312561808-312581808)… Done! Physical Sector Size: 512 Drive: 1, DevicePointer: 0xffffffff857d27d0, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\disk\ ——— Disk Stack —— DevicePointer: 0xffffffff85e73908, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xffffffff857d27d0, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\disk\ DevicePointer: 0xffffffff857cd030, DeviceName: \Device\00000062\, DriverName: \Driver\USBSTOR\ ———— End ———- Alternate DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\disk\ Upper DeviceData: 0x0, 0x0, 0x0 Lower DeviceData: 0x0, 0x0, 0x0 Drive 1 Scanning MBR on drive 1… Inspecting partition table: MBR Signature: 55AA Disk Signature: F09BD54F Partition information: Partition 0 type is Primary (0x7) Partition is NOT ACTIVE. Partition starts at LBA: 2048 Numsec = 1953521072 Partition 1 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition 2 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition 3 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Disk Size: 1000204886016 bytes Sector size: 512 bytes Done! Infected: C:\Users\The Maffeys\AppData\Local\Temp\M6CDr4Tr.exe.part –> [Adware.AdBundle] Infected: C:\Users\The Maffeys\AppData\Local\TopArcadeHits\uninstaller.exe –> [Adware.GameVance] Infected: C:\Users\The Maffeys\AppData\Local\TopArcadeHits\updater.exe –> [Adware.GameVance] Infected: C:\Users\The Maffeys\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TopArcadeHits\Play Toparcadehits Online.url –> [Adware.GameVance] Infected: C:\Users\The Maffeys\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TopArcadeHits –> [Adware.GameVance] Infected: C:\Users\The Maffeys\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TopArcadeHits\Uninstall Toparcadehits.lnk –> [Adware.GameVance] Scan finished Creating System Restore point… Cleaning up… Removal scheduling successful. System shutdown needed. System shutdown occurred ======================================= Removal queue found; removal started Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR_0_i.mbam… Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\Bootstrap_0_1_20981760_i.mbam… Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR_0_r.mbam… Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR_1_i.mbam… Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR_1_r.mbam… Removal finished ————————————— Malwarebytes Anti-Rootkit BETA 1.07.0.1005 © Malwarebytes Corporation 2011-2012 OS version: 6.0.6002 Windows Vista Service Pack 2 x86 Account is Administrative Internet Explorer version: 9.0.8112.16421 File system is: NTFS Disk drives: C:\ DRIVE_FIXED CPU speed: 2.194000 GHz Memory total: 2073284608, free: 1204031488 =======================================

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI