This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Everything Freezes [Solved]

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Greetings,

 

This is my daughter's machine.  I have an account on the box that I never use…  till now.  When we log on to her account, things go OK for a short time, but within a minute or two everything comes to a grinding halt and a hard boot is the only way out.  I tried to run malwarebyte's antimalwhere and it finds about half dozen toolbar nasties but it then it stops like everything else.  Everything seems to be OK here on Dad's account, so I hope we can clean things up from here.  Thanks for your help.

 

OTL logfile created on: 9/23/2014 1:59:01 PM - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Dad\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
2.96 Gb Total Physical Memory | 1.78 Gb Available Physical Memory | 60.20% Memory free
6.12 Gb Paging File | 5.03 Gb Available in Paging File | 82.18% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 218.20 Gb Total Space | 120.81 Gb Free Space | 55.37% Space Free | Partition Type: NTFS
Drive D: | 7.39 Gb Total Space | 7.21 Gb Free Space | 97.47% Space Free | Partition Type: FAT32
Drive E: | 14.65 Gb Total Space | 7.78 Gb Free Space | 53.12% Space Free | Partition Type: NTFS
 
Computer Name: RACHIE | User Name: Dad | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2014/09/23 13:58:08 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Dad\Desktop\OTL.exe
PRC - [2014/09/18 19:37:44 | 000,275,568 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2014/09/04 06:50:02 | 000,064,704 | —- | M] (Adobe Systems Incorporated) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2014/08/26 04:13:14 | 002,640,408 | —- | M] () – C:\Program Files\AVG SafeGuard toolbar\vprot.exe
PRC - [2014/08/22 12:44:44 | 000,022,192 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2014/08/22 12:44:40 | 000,288,120 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft Security Client\NisSrv.exe
PRC - [2014/08/22 12:41:00 | 000,974,432 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2014/08/12 06:21:19 | 001,820,184 | —- | M] (AVG Secure Search) – C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe
PRC - [2014/08/12 06:21:16 | 000,159,768 | —- | M] () – C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\loggingserver.exe
PRC - [2014/05/14 13:07:08 | 000,067,584 | —- | M] (PasswordBox, Inc.) – C:\Program Files\PasswordBox\pbbtnService.exe
PRC - [2013/10/09 10:58:16 | 003,275,136 | —- | M] (Skype Technologies S.A.) – C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
PRC - [2011/12/14 09:04:11 | 000,116,608 | —- | M] (SUPERAntiSpyware.com) – C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
PRC - [2010/11/28 00:30:28 | 001,737,200 | —- | M] (UltraVNC) – C:\Program Files\UltraVNC\winvnc.exe
PRC - [2009/06/03 13:46:38 | 000,206,064 | —- | M] (SupportSoft, Inc.) – C:\Program Files\Dell Support Center\bin\sprtcmd.exe
PRC - [2009/06/03 13:46:38 | 000,201,968 | —- | M] (SupportSoft, Inc.) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe
PRC - [2009/04/11 00:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
PRC - [2009/03/31 09:00:24 | 000,483,428 | —- | M] (IDT, Inc.) – C:\Program Files\IDT\WDM\sttray.exe
PRC - [2009/03/31 09:00:18 | 000,254,042 | —- | M] (IDT, Inc.) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\stacsv.exe
PRC - [2009/03/31 09:00:04 | 000,081,920 | —- | M] (Andrea Electronics Corporation) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\AEstSrv.exe
PRC - [2008/05/07 16:41:14 | 000,354,840 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2014/09/18 19:36:55 | 003,734,640 | —- | M] () – C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2014/09/11 05:40:51 | 005,465,088 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\846057ebe7a3cb80edc3f73d35b4830a\System.Xml.ni.dll
MOD - [2014/09/11 05:38:30 | 007,977,984 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System\0ab7bdcd7b8bdf70f983be2c324ea3b8\System.ni.dll
MOD - [2014/09/11 05:38:04 | 011,496,960 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\3444fbefcbd532181c499150ace644a4\mscorlib.ni.dll
MOD - [2014/08/26 04:13:14 | 002,640,408 | —- | M] () – C:\Program Files\AVG SafeGuard toolbar\vprot.exe
MOD - [2014/08/12 06:21:21 | 000,519,704 | —- | M] () – C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\log4cplusU.dll
 
 
========== Services (SafeList) ==========
 
SRV - File not found [On_Demand | Stopped] – C:\Users\Rachel\AppData\Local\Temp\MKLUYHTMC.exe – (MKLUYHTMC)
SRV - File not found [On_Demand | Stopped] – C:\Users\Rachel\AppData\Local\Temp\EE.exe – (EE)
SRV - File not found [On_Demand | Stopped] – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe – (ACDaemon)
SRV - [2014/09/18 19:37:41 | 000,114,288 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2014/09/10 07:43:40 | 000,267,440 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2014/09/04 06:50:02 | 000,064,704 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2014/08/22 12:44:44 | 000,022,192 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Client\MsMpEng.exe – (MsMpSvc)
SRV - [2014/08/22 12:44:40 | 000,288,120 | —- | M] (Microsoft Corporation) [On_Demand | Running] – c:\Program Files\Microsoft Security Client\NisSrv.exe – (NisSrv)
SRV - [2014/08/12 06:21:19 | 001,820,184 | —- | M] (AVG Secure Search) [Auto | Running] – C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe – (vToolbarUpdater18.1.9)
SRV - [2014/05/14 13:07:08 | 000,067,584 | —- | M] (PasswordBox, Inc.) [Auto | Running] – C:\Program Files\PasswordBox\pbbtnService.exe – (PasswordBox)
SRV - [2013/10/09 10:58:16 | 003,275,136 | —- | M] (Skype Technologies S.A.) [Auto | Running] – C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe – (Skype C2C Service)
SRV - [2011/12/14 09:04:11 | 000,116,608 | —- | M] (SUPERAntiSpyware.com) [Auto | Running] – C:\Program Files\SUPERAntiSpyware\SASCORE.EXE – (!SASCORE)
SRV - [2010/11/28 00:30:28 | 001,737,200 | —- | M] (UltraVNC) [Auto | Running] – C:\Program Files\UltraVNC\winvnc.exe – (uvnc_service)
SRV - [2009/07/27 16:50:51 | 000,016,680 | —- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] – C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe – (GoToAssist)
SRV - [2009/06/03 13:46:38 | 000,201,968 | —- | M] (SupportSoft, Inc.) [Auto | Running] – C:\Program Files\Dell Support Center\bin\sprtsvc.exe – (sprtsvc_DellSupportCenter)
SRV - [2009/03/31 09:00:18 | 000,254,042 | —- | M] (IDT, Inc.) [Auto | Running] – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\stacsv.exe – (STacSV)
SRV - [2009/03/31 09:00:04 | 000,081,920 | —- | M] (Andrea Electronics Corporation) [Auto | Running] – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\AEstSrv.exe – (AESTFilters)
SRV - [2008/05/07 16:41:14 | 000,354,840 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe – (IAANTMON)
SRV - [2008/01/20 20:33:00 | 000,272,952 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\nwlnkfwd.sys – (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\nwlnkflt.sys – (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\ipinip.sys – (IpInIp)
DRV - [2014/09/23 11:37:44 | 000,110,296 | —- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] – C:\Windows\System32\drivers\MBAMSwissArmy.sys – (MBAMSwissArmy)
DRV - [2014/09/22 02:58:05 | 000,039,464 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{43A7FBC9-5392-4C53-A540-8A0BF8C5444D}\MpKsl20a05873.sys – (MpKsl20a05873)
DRV - [2014/08/12 06:21:22 | 000,042,784 | —- | M] (AVG Technologies) [Kernel | System | Running] – C:\Windows\System32\drivers\avgtpx86.sys – (avgtp)
DRV - [2014/07/17 18:05:08 | 000,095,920 | —- | M] (Microsoft Corporation) [Kernel | Auto | Running] – C:\Windows\System32\drivers\NisDrvWFP.sys – (NisDrv)
DRV - [2011/12/14 09:04:06 | 000,067,664 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS – (SASKUTIL)
DRV - [2011/12/14 09:04:06 | 000,012,880 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS – (SASDIFSV)
DRV - [2011/03/31 16:30:56 | 000,012,096 | —- | M] (UVNC BVBA) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\mv2.sys – (mv2)
DRV - [2009/03/31 09:00:26 | 000,398,336 | —- | M] (IDT, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\stwrt.sys – (STHDA)
DRV - [2009/03/31 08:18:30 | 000,192,048 | —- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\Apfiltr.sys – (ApfiltrService)
DRV - [2008/12/30 20:00:04 | 000,144,128 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\CtClsFlt.sys – (CtClsFlt)
DRV - [2008/12/21 12:32:18 | 000,018,424 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\bcm42rly.sys – (BCM42RLY)
DRV - [2008/01/20 20:32:51 | 000,220,672 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\e1e6032.sys – (e1express)
DRV - [2006/11/02 01:36:43 | 002,028,032 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\atikmdag.sys – (R300)
DRV - [2005/08/17 08:47:48 | 000,073,696 | —- | M] (MCCI) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\sscdserd.sys – (sscdserd)
DRV - [2005/08/17 08:46:26 | 000,093,872 | —- | M] (MCCI) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\sscdmdm.sys – (sscdmdm)
DRV - [2005/08/17 08:46:20 | 000,008,272 | —- | M] (MCCI) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\sscdmdfl.sys – (sscdmdfl)
DRV - [2005/08/17 08:45:00 | 000,058,352 | —- | M] (MCCI) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\sscdbus.sys – (sscdbus)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope = {E22F17D0-EFB4-41D3-9DD0-3EFFE67EA251}
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/USCON/1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:32.0.2
FF - user.js - File not found
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\18.1.9\\npsitesafety.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.45.2: C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8051.1204: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.9.799\ [2014/08/26 04:15:02 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\PasswordBox\Firefox [2013/11/21 05:31:34 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 32.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 32.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2014/09/18 19:36:42 | 000,000,000 | —D | M]
 
[2014/09/23 11:43:12 | 000,000,000 | —D | M] (No name found) – C:\Users\Dad\AppData\Roaming\Mozilla\Extensions
[2014/09/23 13:58:18 | 000,000,000 | —D | M] (No name found) – C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\hwzfzqyy.default\extensions
[2014/09/18 19:36:39 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2014/09/18 19:36:39 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2014/09/18 19:36:38 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\browser\extensions
[2014/09/18 19:36:38 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2014/09/18 19:37:45 | 000,000,000 | —D | M] (Default) – C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
 
O1 HOSTS File: ([2011/05/30 17:55:15 | 000,601,001 | —- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts:     
O1 - Hosts: 127.0.0.1    localhost
O1 - Hosts:     
O1 - Hosts: 127.0.0.1    fr.a2dfp.net
O1 - Hosts: 127.0.0.1    m.fr.a2dfp.net
O1 - Hosts: 127.0.0.1    ad.a8.net
O1 - Hosts: 127.0.0.1    asy.a8ww.net
O1 - Hosts: 127.0.0.1    abcstats.com
O1 - Hosts: 127.0.0.1    a.abv.bg
O1 - Hosts: 127.0.0.1    adserver.abv.bg
O1 - Hosts: 127.0.0.1    adv.abv.bg
O1 - Hosts: 127.0.0.1    bimg.abv.bg
O1 - Hosts: 127.0.0.1    ca.abv.bg
O1 - Hosts: 127.0.0.1    www2.a-counter.kiev.ua
O1 - Hosts: 127.0.0.1    track.acclaimnetwork.com
O1 - Hosts: 127.0.0.1    accuserveadsystem.com
O1 - Hosts: 127.0.0.1    www.accuserveadsystem.com
O1 - Hosts: 127.0.0.1    achmedia.com
O1 - Hosts: 127.0.0.1    aconti.net
O1 - Hosts: 127.0.0.1    secure.aconti.net
O1 - Hosts: 127.0.0.1    www.aconti.net #[Dialer.Aconti]
O1 - Hosts: 127.0.0.1    am1.activemeter.com
O1 - Hosts: 127.0.0.1    www.activemeter.com #[Tracking.Cookie]
O1 - Hosts: 127.0.0.1    ads.activepower.net
O1 - Hosts: 127.0.0.1    stat.active24stats.nl #[Tracking.Cookie]
O1 - Hosts: 16261 more lines…
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (PasswordBox Helper) - {5DB69B97-934B-451D-94DB-32EF802A01CD} - C:\Program Files\PasswordBox\Application\pbbtn.dll (PasswordBox, Inc.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (AVG SafeGuard toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG SafeGuard toolbar\18.1.9.799\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (AVG SafeGuard toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG SafeGuard toolbar\18.1.9.799\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search)
O4 - HKLM..\Run: [dellsupportcenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [vProt] C:\Program Files\AVG SafeGuard toolbar\vprot.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 10.45.2)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 10.45.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{181E5132-7639-4926-A018-8B94B50B015E}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4B54D63F-5208-440F-B047-E343E8C7B180}: DhcpNameServer = 75.75.75.75 75.75.76.76 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D638745A-CD6F-4D6D-A326-9EC024EC80F7}: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\18.1.9\ViProtocol.dll (AVG Secure Search)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll) - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 15:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2004/04/30 16:01:00 | 000,000,053 | -HS- | M] () - E:\AUTORUN.INF – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
NetSvcs: FastUserSwitchingCompatibility -  File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla -  File not found
NetSvcs: Ntmssvc -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: SRService -  File not found
NetSvcs: WmdmPmSp -  File not found
NetSvcs: LogonHours -  File not found
NetSvcs: PCAudit -  File not found
NetSvcs: helpsvc -  File not found
NetSvcs: uploadmgr -  File not found
 
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2014/09/23 13:58:07 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Dad\Desktop\OTL.exe
[2014/09/23 11:42:53 | 000,000,000 | —D | C] – C:\Users\Dad\AppData\Roaming\Mozilla
[2014/09/23 11:42:53 | 000,000,000 | —D | C] – C:\Users\Dad\AppData\Local\Mozilla
[2014/09/23 11:32:27 | 000,000,000 | —D | C] – C:\Users\Dad\AppData\Local\AVG SafeGuard toolbar
[2014/09/23 11:30:55 | 000,000,000 | —D | C] – C:\Users\Dad\AppData\Local\SupportSoft
[2014/09/23 11:30:14 | 000,000,000 | R–D | C] – C:\Users\Dad\Searches
[2014/09/23 11:30:14 | 000,000,000 | R–D | C] – C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2014/09/23 11:30:01 | 000,000,000 | —D | C] – C:\Users\Dad\AppData\Roaming\Identities
[2014/09/23 11:29:58 | 000,000,000 | R–D | C] – C:\Users\Dad\Contacts
[2014/09/23 11:29:56 | 000,000,000 | —D | C] – C:\Users\Dad\AppData\Local\VirtualStore
[2014/09/23 11:29:24 | 000,000,000 | -HSD | C] – C:\Users\Dad\AppData\Local\Temporary Internet Files
[2014/09/23 11:29:24 | 000,000,000 | -HSD | C] – C:\Users\Dad\Templates
[2014/09/23 11:29:24 | 000,000,000 | -HSD | C] – C:\Users\Dad\Start Menu
[2014/09/23 11:29:24 | 000,000,000 | -HSD | C] – C:\Users\Dad\SendTo
[2014/09/23 11:29:24 | 000,000,000 | -HSD | C] – C:\Users\Dad\Recent
[2014/09/23 11:29:24 | 000,000,000 | -HSD | C] – C:\Users\Dad\PrintHood
[2014/09/23 11:29:24 | 000,000,000 | -HSD | C] – C:\Users\Dad\NetHood
[2014/09/23 11:29:24 | 000,000,000 | -HSD | C] – C:\Users\Dad\Documents\My Videos
[2014/09/23 11:29:24 | 000,000,000 | -HSD | C] – C:\Users\Dad\Documents\My Pictures
[2014/09/23 11:29:24 | 000,000,000 | -HSD | C] – C:\Users\Dad\Documents\My Music
[2014/09/23 11:29:24 | 000,000,000 | -HSD | C] – C:\Users\Dad\My Documents
[2014/09/23 11:29:24 | 000,000,000 | -HSD | C] – C:\Users\Dad\Local Settings
[2014/09/23 11:29:24 | 000,000,000 | -HSD | C] – C:\Users\Dad\AppData\Local\History
[2014/09/23 11:29:24 | 000,000,000 | -HSD | C] – C:\Users\Dad\Cookies
[2014/09/23 11:29:24 | 000,000,000 | -HSD | C] – C:\Users\Dad\Application Data
[2014/09/23 11:29:24 | 000,000,000 | -HSD | C] – C:\Users\Dad\AppData\Local\Application Data
[2014/09/23 11:29:23 | 000,000,000 | –SD | C] – C:\Users\Dad\AppData\Roaming\Microsoft
[2014/09/23 11:29:23 | 000,000,000 | R–D | C] – C:\Users\Dad\Videos
[2014/09/23 11:29:23 | 000,000,000 | R–D | C] – C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2014/09/23 11:29:23 | 000,000,000 | R–D | C] – C:\Users\Dad\Saved Games
[2014/09/23 11:29:23 | 000,000,000 | R–D | C] – C:\Users\Dad\Pictures
[2014/09/23 11:29:23 | 000,000,000 | R–D | C] – C:\Users\Dad\Music
[2014/09/23 11:29:23 | 000,000,000 | R–D | C] – C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2014/09/23 11:29:23 | 000,000,000 | R–D | C] – C:\Users\Dad\Links
[2014/09/23 11:29:23 | 000,000,000 | R–D | C] – C:\Users\Dad\Favorites
[2014/09/23 11:29:23 | 000,000,000 | R–D | C] – C:\Users\Dad\Downloads
[2014/09/23 11:29:23 | 000,000,000 | R–D | C] – C:\Users\Dad\Documents
[2014/09/23 11:29:23 | 000,000,000 | R–D | C] – C:\Users\Dad\Desktop
[2014/09/23 11:29:23 | 000,000,000 | R–D | C] – C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2014/09/23 11:29:23 | 000,000,000 | -H-D | C] – C:\Users\Dad\AppData
[2014/09/23 11:29:23 | 000,000,000 | —D | C] – C:\Users\Dad\AppData\Local\Temp
[2014/09/23 11:29:23 | 000,000,000 | —D | C] – C:\Users\Dad\AppData\Local\SoftThinks
[2014/09/23 11:29:23 | 000,000,000 | —D | C] – C:\Users\Dad\AppData\Local\Microsoft Help
[2014/09/23 11:29:23 | 000,000,000 | —D | C] – C:\Users\Dad\AppData\Local\Microsoft
[2014/09/23 11:29:23 | 000,000,000 | —D | C] – C:\Users\Dad\AppData\Local\Google
[2014/09/22 17:56:14 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2014/09/22 17:56:12 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Skype
[2014/09/19 15:53:02 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Toontown Rewritten
[2014/09/18 19:36:37 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2014/09/11 05:17:12 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2014/09/11 05:17:10 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2014/09/11 05:17:09 | 000,607,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2014/09/11 05:17:09 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2014/09/11 05:17:08 | 000,353,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2014/09/11 05:17:06 | 000,223,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2014/09/11 05:17:06 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2014/09/11 05:17:06 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2014/09/11 05:17:02 | 001,810,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2014/09/11 05:17:02 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2014/09/11 05:17:01 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2014/09/11 05:16:58 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2014/08/28 05:00:32 | 002,054,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2014/08/27 06:15:33 | 000,000,000 | —D | C] – C:\Program Files\AVG Security Toolbar
[2014/08/27 06:15:17 | 000,000,000 | —D | C] – C:\ProgramData\Avg_Update_0814tb
 
========== Files - Modified Within 30 Days ==========
 
[2014/09/23 13:58:08 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Dad\Desktop\OTL.exe
[2014/09/23 13:54:03 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014/09/23 13:54:02 | 000,000,408 | —- | M] () – C:\Windows\tasks\AVG-Secure-Search-Update_1013b_rmv.job
[2014/09/23 13:54:02 | 000,000,358 | —- | M] () – C:\Windows\tasks\AVG-Secure-Search-Update_1013b_rel.job
[2014/09/23 13:53:48 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2014/09/23 13:53:48 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2014/09/23 13:53:34 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2014/09/23 13:53:32 | 3181,760,512 | -HS- | M] () – C:\hiberfil.sys
[2014/09/23 12:31:00 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3176256395-2519655851-1769987202-1000UA.job
[2014/09/23 11:59:16 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/09/23 11:37:44 | 000,110,296 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\MBAMSwissArmy.sys
[2014/09/23 00:11:00 | 000,000,886 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014/09/22 18:31:59 | 000,002,337 | —- | M] () – C:\Users\Public\Desktop\Skype.lnk
[2014/09/22 00:41:56 | 000,231,568 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MpSigStub.exe
[2014/09/21 16:31:00 | 000,000,860 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3176256395-2519655851-1769987202-1000Core.job
[2014/09/19 15:53:02 | 000,000,672 | —- | M] () – C:\Users\Public\Desktop\Toontown Rewritten.lnk
[2014/09/11 05:02:13 | 000,002,155 | —- | M] () – C:\Windows\epplauncher.mif
[2014/09/10 07:43:39 | 000,701,104 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2014/09/10 07:43:39 | 000,071,344 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2014/08/30 12:02:39 | 000,595,684 | —- | M] () – C:\Windows\System32\perfh009.dat
[2014/08/30 12:02:39 | 000,101,350 | —- | M] () – C:\Windows\System32\perfc009.dat
[2014/08/28 05:19:50 | 000,298,792 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
 
========== Files Created - No Company Name ==========
 
[2014/09/23 11:30:17 | 000,000,911 | —- | C] () – C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2014/09/23 11:30:13 | 000,000,906 | —- | C] () – C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
[2014/09/23 11:29:58 | 000,000,877 | —- | C] () – C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
[2014/09/23 11:29:23 | 000,000,258 | —- | C] () – C:\Users\Dad\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2014/09/23 11:29:23 | 000,000,240 | —- | C] () – C:\Users\Dad\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2014/09/23 11:28:45 | 3181,760,512 | -HS- | C] () – C:\hiberfil.sys
[2014/09/22 17:56:14 | 000,002,337 | —- | C] () – C:\Users\Public\Desktop\Skype.lnk
[2014/09/19 15:53:02 | 000,000,672 | —- | C] () – C:\Users\Public\Desktop\Toontown Rewritten.lnk
[2013/10/13 07:45:39 | 000,003,749 | —- | C] () – C:\Program Files\Mozilla Firefoxsafeguard-secure-search.xml
[2009/09/25 19:28:41 | 000,000,258 | RHS- | C] () – C:\ProgramData\ntuser.pol
 
========== ZeroAccess Check ==========
 
[2006/11/02 06:51:16 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2014/03/25 07:26:04 | 011,587,584 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/04/11 00:28:19 | 000,614,912 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/04/11 00:28:25 | 000,347,648 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
========== Custom Scans ==========
 
< %USERPROFILE%\..|smtmp;true;true;true /FP >
 
< %temp%\smtmp\*.* /s > >
 
< MD5 for: EXPLORER.EXE  >
[2009/04/11 13:16:17 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2009/04/11 13:16:16 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2009/04/11 13:16:16 | 002,927,616 | —- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2009/04/11 00:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\explorer.exe
[2009/04/11 00:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe
[2009/04/11 13:16:17 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2008/01/20 20:34:05 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe
 
< MD5 for: EXPLORER.EXE.MUI  >
[2006/11/02 06:38:53 | 000,036,864 | —- | M] (Microsoft Corporation) MD5=192DD053B43250E264383CDC3D564A18 – C:\Windows\en-US\explorer.exe.mui
[2006/11/02 06:38:53 | 000,036,864 | —- | M] (Microsoft Corporation) MD5=192DD053B43250E264383CDC3D564A18 – C:\Windows\winsxs\x86_microsoft-windows-explorer.resources_31bf3856ad364e35_6.0.6000.16386_en-us_03bbc52176b6ba20\explorer.exe.mui
 
< MD5 for: EXPLORER.EXE-D5E97654.PF  >
[2014/09/21 15:06:00 | 000,132,498 | —- | M] () MD5=8B0D1B7AA062A26E0325677DFA4841DE – C:\Windows\Prefetch\EXPLORER.EXE-D5E97654.pf
 
< MD5 for: IEXPLORE.BAT  >
[2013/10/15 16:05:47 | 000,031,414 | —- | M] () MD5=75C9C20DD9839BF287B43B0E179822DC – C:\Users\Rachel\AppData\Local\Temp\jrt\iexplore.bat
 
< MD5 for: IEXPLORE.EXE  >
[2014/08/15 08:58:33 | 000,757,968 | —- | M] (Microsoft Corporation) MD5=00E16998DA2563CD214B824D3C4F9762 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20691_none_58e7868705006e6e\iexplore.exe
[2012/05/17 17:21:54 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=0129BB16161C2FD9A6B19111AB047198 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16446_none_5898f8e3ebb5c47b\iexplore.exe
[2011/07/23 05:02:27 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=04D1DC458C723B291179F8449ACC281D – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19120_none_12355fcb2fdc2111\iexplore.exe
[2013/10/13 04:49:16 | 000,757,488 | —- | M] (Microsoft Corporation) MD5=06085B62BC7E0C8E2605CEA38774D956 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16520_none_58a898e5ebaaf1b6\iexplore.exe
[2009/04/11 13:10:03 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=0844F5B9CB3BB85A917D347EF1565B6C – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16809_none_2d84c7c91ccfce35\iexplore.exe
[2014/06/09 10:40:29 | 000,758,000 | —- | M] (Microsoft Corporation) MD5=08ED70F000508724BAF881AA07C21BE1 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16561_none_587e597febca7ad1\iexplore.exe
[2014/05/12 07:24:30 | 000,750,392 | —- | M] (MalwareBytes) MD5=09882E8EDD1144E6EF1AF6D1F98305EE – C:\Program Files\Malwarebytes Anti-Malware\Chameleon\Windows\iexplore.exe
[2012/11/13 20:56:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=0D286C0FE561D1A7EB30E83A0FF305B2 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16457_none_588f2941ebbcf9c3\iexplore.exe
[2013/07/31 04:18:24 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=10C1F2EC48D524AE10229AACD37B172A – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20617_none_594407a304ba26f0\iexplore.exe
[2014/02/23 00:00:18 | 000,757,488 | —- | M] (Microsoft Corporation) MD5=10EB5C0E376727E21198B14E2F1637F7 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16540_none_5892f90debbb2998\iexplore.exe
[2013/07/24 20:48:45 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=139C8953AC56A9E559C7DEF07BC45ED7 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20613_none_5940067b04bdc194\iexplore.exe
[2009/11/21 00:42:38 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=1B6362BB14FCEB9E76BCF9A953B04788 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18865_none_120f459f2ff7e1f8\iexplore.exe
[2009/07/18 06:16:49 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=1D5A01AA2DE47C052AF46D7EBCB003A3 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16890_none_2d1a75e31d20e59f\iexplore.exe
[2009/07/18 15:39:09 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=1D8163DBFECAEDB9C48C5F55084BC491 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18294_none_2f04b5b11a43dbec\iexplore.exe
[2009/07/27 19:14:45 | 000,636,072 | —- | M] (Microsoft Corporation) MD5=1DD66A2851DACDEC32EAE8F9A8865ABD – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.21023_none_2df29b2236034119\iexplore.exe
[2012/08/24 01:34:41 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=22CC6CDBA678790046693654C3B212E4 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16450_none_5888273bebc34862\iexplore.exe
[2010/02/23 09:06:13 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=25DB705A7DC85C208B3CF2D20F118AA7 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.22995_none_127872a6492dd595\iexplore.exe
[2012/05/17 16:59:46 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=268982F1FD671A077C6A2AF41E351436 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20551_none_5912c45104e00183\iexplore.exe
[2012/10/08 02:37:24 | 000,748,704 | —- | M] (Microsoft Corporation) MD5=270A1342BD5AF95CA25A586B4C2F1522 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16455_none_588d28adebbec715\iexplore.exe
[2009/04/11 00:27:44 | 000,636,080 | —- | M] (Microsoft Corporation) MD5=2C5168C856455CC43C4B4E1CC1920001 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6002.18005_none_314d791517204c15\iexplore.exe
[2013/10/13 03:43:05 | 000,757,488 | —- | M] (Microsoft Corporation) MD5=2D64E29ADB5DEB40446796A9C42417E3 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20631_none_5928660f04cfc6c8\iexplore.exe
[2009/08/26 23:23:17 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=2E48756F12C21F46895036AC089AAD97 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18828_none_123d862d2fd4be39\iexplore.exe
[2013/02/21 22:10:00 | 000,757,376 | —- | M] (Microsoft Corporation) MD5=32732CEDE2A1106B736EF3D84054EE04 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16476_none_5878891febce184e\iexplore.exe
[2014/02/23 00:26:53 | 000,757,488 | —- | M] (Microsoft Corporation) MD5=32FC0953B384A11B4AB422E56E2BDBCD – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20651_none_5912c63704dffeaa\iexplore.exe
[2013/05/28 21:32:47 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=33E62E4EFC2ACA8EC63A8926F26D3889 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20606_none_594dd74504b2f1a8\iexplore.exe
[2012/06/02 03:08:27 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=34B01BBD8F00B6B9C9248DC4F1E3CD01 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16447_none_5899f92debb4ddd2\iexplore.exe
[2010/01/02 08:58:26 | 000,638,216 | —- | M] (Microsoft Corporation) MD5=3D8DA00B028DEA9517066F1CECBFC4A2 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.22973_none_128c11ea491f6b05\iexplore.exe
[2013/04/04 16:47:49 | 000,757,360 | —- | M] (Microsoft Corporation) MD5=3F00BE80B9CEA20B7FE7363D15EDDB94 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16483_none_586ab855ebd8e83a\iexplore.exe
[2013/02/21 22:10:31 | 000,757,360 | —- | M] (Microsoft Corporation) MD5=4145E2B5663F6FACC08EFDB17B658BB2 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20586_none_58f755ff04f3d409\iexplore.exe
[2014/03/07 16:55:11 | 000,757,488 | —- | M] (Microsoft Corporation) MD5=41F24930153D42287D157B93A859E6F3 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20656_none_5917c7a904db7d5d\iexplore.exe
[2013/11/14 17:18:24 | 000,757,488 | —- | M] (Microsoft Corporation) MD5=43E6F2A7FB182F2D7CB0CE5B8F1005CF – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16526_none_58ae9aa1eba589c0\iexplore.exe
[2013/09/22 04:59:54 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=45BDA923BE52906D1460BCB13AC2AB7A – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16514_none_58b769f9eb9f3b21\iexplore.exe
[2014/02/05 03:08:15 | 000,757,488 | —- | M] (Microsoft Corporation) MD5=48600DAC5AF3A53B6F430528209E4830 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16533_none_58a0c9d7ebb059ac\iexplore.exe
[2010/05/04 00:32:18 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=48A6109E8DF0365195298CC527B7426A – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23019_none_12d2cb5048e98eab\iexplore.exe
[2010/09/08 00:26:34 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=4A719476A6393B1DCACFEB4F3AC6599C – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23067_none_129abb204913e7b2\iexplore.exe
[2009/07/22 00:04:09 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=4B5AEA50CE77FBA4C2D169622DC9B489 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.22903_none_12d7c15e48e6a76e\iexplore.exe
[2011/07/23 05:42:34 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=4D08A4234D645EFCB30605CC0BFA87F4 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23216_none_12cfce3e48ec3cf4\iexplore.exe
[2013/07/24 20:42:37 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=57EC630DBD5F0713E77CB3540AB80A8E – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16502_none_58c03951eb98ec82\iexplore.exe
[2010/11/02 00:03:13 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=5AB037B17F8A87D052F5A88E0D29A3C8 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18999_none_11f2d8e9300c984e\iexplore.exe
[2008/01/20 20:33:22 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=5B92133D3E7FB2644677686305E29E81 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18000_none_2f62000919fe80c9\iexplore.exe
[2010/05/04 00:00:35 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=5C9B1062EA7A44E8F6BFDE994B68C7AA – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18928_none_123d88132fd4bb60\iexplore.exe
[2012/08/24 01:49:25 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=62188720CE27B982B4285C03163C9FB3 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20557_none_5918c60d04da998d\iexplore.exe
[2013/05/16 17:34:33 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=67EE46FD4D3B56531C5DD1BDC149275A – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16490_none_585ce78bebe3b826\iexplore.exe
[2014/08/15 08:54:16 | 000,757,968 | —- | M] (Microsoft Corporation) MD5=6864C18818EB22D03A2D37C8C5586925 – C:\Program Files\Internet Explorer\iexplore.exe
[2014/08/15 08:54:16 | 000,757,968 | —- | M] (Microsoft Corporation) MD5=6864C18818EB22D03A2D37C8C5586925 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16575_none_58778abbebcefc1e\iexplore.exe
[2013/01/08 16:42:06 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=698EB1E5F8C66344D97C00B5699E871D – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16464_none_58815877ebc7c9af\iexplore.exe
[2014/07/24 11:48:06 | 000,757,968 | —- | M] (Microsoft Corporation) MD5=6EBFCE26DF05178D3AAB32A6A2E08380 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20674_none_5900273d04ed8291\iexplore.exe
[2014/03/07 18:04:01 | 000,757,488 | —- | M] (Microsoft Corporation) MD5=7116680C2C62709EE81BDDC69EF26B93 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16545_none_5897fa7febb6a84b\iexplore.exe
[2010/06/26 00:06:48 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=7420BE0E7D3D1320054F7ACA0594953D – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18943_none_1222e6c92fe9748f\iexplore.exe
[2014/07/24 12:11:52 | 000,757,976 | —- | M] (Microsoft Corporation) MD5=76F9BA272D99BB7859695A4F9207178E – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16563_none_58805a13ebc8ad7f\iexplore.exe
[2010/12/18 01:19:44 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=7852371DA9EFBC17B645558E23780EAC – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23111_none_12cacae648f0c11a\iexplore.exe
[2014/05/28 10:49:40 | 000,758,000 | —- | M] (Microsoft Corporation) MD5=7BA5B7DEDE25D44F3E664D5BA067E3CD – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16555_none_588d2a93ebbec43c\iexplore.exe
[2009/08/27 07:31:08 | 000,638,216 | —- | M] (Microsoft Corporation) MD5=7DD482E4A2E3CBB0A72F718C342F5B75 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.22918_none_12d1f2e448ea4212\iexplore.exe
[2011/05/28 01:09:20 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=7EE10C5413AD7ED1AF9E8FAE1B58FC3E – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23181_none_127f1b72492984b1\iexplore.exe
[2009/07/18 06:16:45 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=7FCF4E704A48D95202F3E7A1E1A21412 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.21089_none_2db7bd56362e80c9\iexplore.exe
[2010/01/02 00:40:20 | 000,638,216 | —- | M] (Microsoft Corporation) MD5=88BD42DAE7CFFEB256CA7145A15E4843 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18882_none_11f6a4e9300acdd5\iexplore.exe
[2009/07/27 19:14:40 | 000,636,072 | —- | M] (Microsoft Corporation) MD5=8BA2B7A05F88BE0D45237A0994AD8366 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22389_none_2f9e23da3354de78\iexplore.exe
[2011/08/14 11:50:55 | 000,748,336 | —- | M] (Microsoft Corporation) MD5=904E13BA41AF2E353A32CF351CA53639 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16421_none_58a99749ebaa0de6\iexplore.exe
[2010/11/02 01:13:47 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=92A17B0A89D14815AACC62CD190B6CE3 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23091_none_127449a04931a37b\iexplore.exe
[2012/06/28 19:00:47 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=93569D46D79F9756ED077156496AFE23 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16448_none_589af977ebb3f729\iexplore.exe
[2011/02/22 01:18:28 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=9CE5543464432CA73134F170FA2BF823 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23143_none_12ac5bb64907479b\iexplore.exe
[2009/07/27 19:14:40 | 000,636,072 | —- | M] (Microsoft Corporation) MD5=9E6C1527D9A2C64BFD780AA23075380F – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18226_none_2f5265b91a094b03\iexplore.exe
[2010/02/23 00:39:16 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=9F52FBE99C749E3F32C75124F09F1B03 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18904_none_124f26c32fc81e22\iexplore.exe
[2013/02/01 22:19:03 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=A285E1965C115031DA02B777EE9D7689 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20580_none_58f1544304f93bff\iexplore.exe
[2014/05/28 10:50:31 | 000,758,000 | —- | M] (Microsoft Corporation) MD5=A2FCB57FF0C63599E910996B82488A00 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20666_none_590cf7bd04e3994e\iexplore.exe
[2013/05/16 16:27:11 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=A8732CEDB2C0EE7AFC08F867A47BB3EC – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20600_none_5947d58904b8599e\iexplore.exe
[2013/07/31 04:39:59 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=AA9CBDCD4675A48755DDA3A73BE3E283 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16506_none_58c43a79eb9551de\iexplore.exe
[2009/03/08 15:09:24 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18702_none_124d22632fc9f126\iexplore.exe
[2010/12/18 00:28:35 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=B988D7F127B94BD5BF8356FE81B985C4 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19019_none_1249306b2fcbec08\iexplore.exe
[2012/06/02 02:51:58 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=BE967C74B89577B78FB57C061E12B04C – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20553_none_5914c4e504de3431\iexplore.exe
[2013/04/04 15:55:02 | 000,757,360 | —- | M] (Microsoft Corporation) MD5=C036AB1ED8BAC04FE4A349BA263077BB – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20593_none_58e9853504fea3f5\iexplore.exe
[2011/02/22 00:21:12 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=C1D36A2CBE0CEC4DF593DB1288CF586E – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19048_none_1227c05d2fe52684\iexplore.exe
[2014/02/05 04:01:30 | 000,757,488 | —- | M] (Microsoft Corporation) MD5=C24DA744AD59EF3A87380F0A75D2E580 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20644_none_5920970104d52ebe\iexplore.exe
[2009/07/21 15:53:43 | 000,638,216 | —- | M] (Microsoft Corporation) MD5=C33BD196A0301F9B23D9A003D30ED8B0 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18813_none_124354a72fd12395\iexplore.exe
[2012/10/08 02:22:05 | 000,748,704 | —- | M] (Microsoft Corporation) MD5=CECB15F834FC2B4B150449717ADE18DD – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20562_none_5908f4af04e736cb\iexplore.exe
[2010/09/08 00:02:42 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=D5A730DFDEAE005373E62BC2A866E3BB – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18975_none_120477992ffffb10\iexplore.exe
[2013/02/01 22:19:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=DDE5A0DFAF7C6370FB36402D7A746ED3 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16470_none_58728763ebd38044\iexplore.exe
[2009/11/21 09:05:17 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=E7F8DF50E483D165BB01F367D3519AA7 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.22956_none_12a4b2a0490c7f28\iexplore.exe
[2009/07/27 19:14:45 | 000,636,072 | —- | M] (Microsoft Corporation) MD5=EA4BE33726155F89D89A3FE7142878E0 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16830_none_2d5b556b1cf03df9\iexplore.exe
[2012/06/28 17:35:27 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=EB4105348272018D096FEB655CD1608C – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20554_none_5915c52f04dd4d88\iexplore.exe
[2014/06/09 10:40:32 | 000,758,000 | —- | M] (Microsoft Corporation) MD5=EB42437D005E26062759E6235CA9AEB4 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20672_none_58fe26a904ef4fe3\iexplore.exe
[2009/07/18 05:55:42 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=EBEE9E4421F35CD861107DDA0266FBB1 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22475_none_2fa4f48433505a52\iexplore.exe
[2011/05/28 00:09:21 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=ED65737D70FDEAC29F738E77D2496EE5 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19088_none_11fc80ad30059648\iexplore.exe
[2013/05/28 20:24:32 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=EE12BA876C4190532A4085994BA9B616 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16496_none_5862e947ebde5030\iexplore.exe
[2013/01/08 15:32:42 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=F05982E56ABD835AA8DF260EEC873E5B – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20573_none_58ff250d04ee6c13\iexplore.exe
[2010/06/26 00:52:42 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=F05B3A2C6CB319DD1377AD566CF5ECE5 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23040_none_12a958f24909fe6f\iexplore.exe
[2009/04/11 13:10:03 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=F0B1CA517977BA2FF6DA33F1B966C488 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20996_none_2daa146a36391d73\iexplore.exe
[2012/11/13 20:19:28 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=F691418EE9A6344AEB5C1B0518FBF8AE – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20565_none_590bf58d04e482d0\iexplore.exe
[2013/09/22 06:14:29 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=F87E95A127E83277B9AE500D7A18C998 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20625_none_5937372304c41033\iexplore.exe
[2013/11/14 17:20:23 | 000,757,488 | —- | M] (Microsoft Corporation) MD5=FA58195587EC371699D9641C3E275856 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20637_none_592e67cb04ca5ed2\iexplore.exe
 
< MD5 for: IEXPLORE.EXE.HU.KDMP  >
[2009/09/22 17:23:42 | 023,081,834 | —- | M] () MD5=02991FFB83786A389715817F47DAAAFD – C:\Users\Rachel\AppData\Local\Microsoft\Windows\WER\ReportQueue\Report057a840e\iexplore.exe.hu.kdmp
 
< MD5 for: IEXPLORE.EXE.MUI  >
[2006/11/02 06:38:50 | 000,016,384 | —- | M] (Microsoft Corporation) MD5=3CCDDDBC49DEACA370F39A9F0E146A1B – C:\Windows\winsxs\x86_microsoft-windows-i..texplorer.resources_31bf3856ad364e35_6.0.6000.16386_en-us_3b55b11a57da5590\iexplore.exe.mui
[2011/08/14 11:50:57 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2011/08/14 11:50:57 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.1.8112.16421_en-us_52562cc123574ecd\iexplore.exe.mui
[2009/03/08 15:27:11 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Windows\winsxs\x86_microsoft-windows-i..texplorer.resources_31bf3856ad364e35_8.0.6001.18702_en-us_207795706a90d6c1\iexplore.exe.mui
 
< MD5 for: IEXPLORE.EXE.XML  >
[2009/09/22 17:23:42 | 000,004,602 | —- | M] () MD5=8835CF4512B46CADAB7313E43276CFF1 – C:\Users\Rachel\AppData\Local\Microsoft\Windows\WER\ReportQueue\Report057a840e\iexplore.exe.xml
 
< MD5 for: SERVICES  >
[2006/09/18 15:41:30 | 000,017,244 | —- | M] () MD5=9F534244B7F8F55D5C0BB498D8D481E7 – C:\Windows\System32\drivers\etc\services
[2006/09/18 15:41:30 | 000,017,244 | —- | M] () MD5=9F534244B7F8F55D5C0BB498D8D481E7 – C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.0.6000.16386_none_024e4071fa6fea95\services
 
< MD5 for: SERVICES.CFG  >
[2014/09/04 06:50:22 | 000,559,515 | —- | M] () MD5=704FFA2F886780380DB96EF03E5FC512 – C:\Program Files\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2011/06/06 13:55:30 | 000,584,045 | R— | M] () MD5=B82DD53FA8C260DDD7FDC42182DB816E – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\services.cfg
 
< MD5 for: SERVICES.DAT  >
[2014/02/20 00:17:07 | 000,004,182 | —- | M] () MD5=78103C8B94CFA4006452BA74BE99DD51 – C:\Users\Rachel\AppData\Local\Temp\jrt\services.dat
 
< MD5 for: SERVICES.EXE  >
[2008/01/20 20:34:36 | 000,279,040 | —- | M] (Microsoft Corporation) MD5=2B336AB6286D6C81FA02CBAB914E3C6C – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.exe
[2009/04/11 00:27:59 | 000,279,552 | —- | M] (Microsoft Corporation) MD5=D4E6D91C1349B7BFB3599A6ADA56851B – C:\Windows\System32\services.exe
[2009/04/11 00:27:59 | 000,279,552 | —- | M] (Microsoft Corporation) MD5=D4E6D91C1349B7BFB3599A6ADA56851B – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.exe
 
< MD5 for: SERVICES.EXE.MUI  >
[2006/11/02 06:38:29 | 000,017,920 | —- | M] (Microsoft Corporation) MD5=1626EACF0E7E59F85C59DDDD27C4169C – C:\Windows\System32\en-US\services.exe.mui
[2006/11/02 06:38:29 | 000,017,920 | —- | M] (Microsoft Corporation) MD5=1626EACF0E7E59F85C59DDDD27C4169C – C:\Windows\winsxs\x86_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.0.6000.16386_en-us_67c6851b290a1ced\services.exe.mui
 
< MD5 for: SERVICES.JS  >
[2014/07/25 09:27:32 | 000,003,147 | —- | M] () MD5=2FD91762B4C2F6ED25428D709A8B3A84 – C:\Program Files\PasswordBox\Firefox\resources\passwordbox\lib\services.js
 
< MD5 for: SERVICES.LNK  >
[2008/01/20 20:56:43 | 000,001,688 | —- | M] () MD5=D33B2F379CED5E32AF2F9199CE4EE94A – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2008/01/20 20:56:43 | 000,001,688 | —- | M] () MD5=D33B2F379CED5E32AF2F9199CE4EE94A – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
 
< MD5 for: SERVICES.MOF  >
[2006/09/18 15:46:11 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\System32\wbem\services.mof
[2006/09/18 15:46:11 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.mof
[2006/09/18 15:46:11 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.mof
 
< MD5 for: SERVICES.MSC  >
[2006/11/02 06:39:04 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\System32\en-US\services.msc
[2006/09/18 15:29:40 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\System32\services.msc
[2006/11/02 06:39:04 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.0.6000.16386_en-us_a2085506ff73b6e0\services.msc
[2006/09/18 15:29:40 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.0.6001.18000_none_cf63e2a445bae4e3\services.msc
 
< MD5 for: SERVICES.PNG  >
[2009/04/22 12:36:48 | 000,001,509 | —- | M] () MD5=F4EC3ABEAE15FA9BB42D721E9D543F44 – C:\Program Files\Dell Support Center\HWDiag\bin\Images\icons\png\24_24\services.png
 
< MD5 for: SERVICES.VIM  >
[2010/10/27 09:44:14 | 000,000,459 | —- | M] () MD5=193ED9B27B25456FBE50E6111B8E6770 – C:\Program Files\Vim\vim73\ftplugin\services.vim
[2010/10/27 09:42:50 | 000,001,865 | —- | M] () MD5=A17575F0BA54E8FB1148DDFC2361D776 – C:\Program Files\Vim\vim73\syntax\services.vim
 
< MD5 for: WINLOGON.EXE  >
[2014/05/12 07:24:30 | 000,750,392 | —- | M] (MalwareBytes) MD5=09882E8EDD1144E6EF1AF6D1F98305EE – C:\Program Files\Malwarebytes Anti-Malware\Chameleon\Windows\winlogon.exe
[2009/04/11 00:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\System32\winlogon.exe
[2009/04/11 00:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2008/01/20 20:34:38 | 000,314,880 | —- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
 
< MD5 for: WINLOGON.EXE.MUI  >
[2008/01/20 20:35:28 | 000,028,672 | —- | M] (Microsoft Corporation) MD5=26AC28BF50DC112BAA794A83E08588F0 – C:\Windows\System32\en-US\winlogon.exe.mui
[2008/01/20 20:35:28 | 000,028,672 | —- | M] (Microsoft Corporation) MD5=26AC28BF50DC112BAA794A83E08588F0 – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.0.6001.18000_en-us_caf8918b0416723a\winlogon.exe.mui
[2006/11/02 06:38:26 | 000,028,672 | —- | M] (Microsoft Corporation) MD5=A1D2856F3EC3C86EBBF1442B0245A8B3 – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.0.6000.16386_en-us_c8c1cf8f072b6166\winlogon.exe.mui
 
< MD5 for: WINLOGON.MOF  >
[2006/09/18 15:41:56 | 000,002,794 | —- | M] () MD5=545C578F290B9CDD280966939935B9EA – C:\Windows\System32\wbem\winlogon.mof
[2006/09/18 15:41:56 | 000,002,794 | —- | M] () MD5=545C578F290B9CDD280966939935B9EA – C:\Windows\winsxs\x86_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.0.6000.16386_none_7e0207d478fccc94\winlogon.mof
 
< %SYSTEMDRIVE%\*.* >
[2006/09/18 15:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/11 00:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2006/09/18 15:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2009/07/27 19:18:16 | 000,003,673 | RH– | M] () – C:\dell.sdr
[2012/08/15 05:26:08 | 000,000,000 | —- | M] () – C:\extensions.sqlite
[2014/09/23 13:53:32 | 3181,760,512 | -HS- | M] () – C:\hiberfil.sys
[2014/09/23 13:53:31 | 3495,567,360 | -HS- | M] () – C:\pagefile.sys
 
< %systemroot%\Fonts\*.com >
[2006/11/02 06:35:34 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 06:35:34 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 06:35:34 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2010/05/23 16:18:12 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
 
< %systemroot%\Fonts\*.dll >
 
< %systemroot%\Fonts\*.ini >
[2006/09/18 15:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
 
< %systemroot%\Fonts\*.ini2 >
 
< %systemroot%\Fonts\*.exe >
 
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/01/20 20:32:37 | 000,089,600 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\HPZPPLHN.DLL
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\msonpppr.dll
 
< %systemroot%\REPAIR\*.bak1 >
 
< %systemroot%\REPAIR\*.ini >
 
< %systemroot%\system32\*.jpg >
 
< %systemroot%\*.jpg >
 
< %systemroot%\*.png >
 
< %systemroot%\*.scr >
[2008/12/04 21:55:20 | 000,307,560 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
 
< %systemroot%\*._sy >
 
< %APPDATA%\Adobe\Update\*.* >
 
< %ALLUSERSPROFILE%\Favorites\*.* >
 
< %APPDATA%\Microsoft\*.* >
 
< %PROGRAMFILES%\*.* >
[2008/01/20 20:57:01 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
[2014/06/25 01:25:37 | 000,003,749 | —- | M] () – C:\Program Files\Mozilla Firefoxsafeguard-secure-search.xml
 
< %APPDATA%\Update\*.* >
 
< %systemroot%\*. /mp /s >
 
< dir "%systemdrive%\*" /S /A:L /C >
 Volume in drive C is OS
 Volume Serial Number is 8603-5F18
 Directory of C:\
08/15/2009  08:01 AM         Documents and Settings [C:\Users]
               0 File(s)              0 bytes
 Directory of C:\ProgramData
08/15/2009  08:01 AM         Application Data [C:\ProgramData]
08/15/2009  08:01 AM         Desktop [C:\Users\Public\Desktop]
08/15/2009  08:01 AM         Documents [C:\Users\Public\Documents]
08/15/2009  08:01 AM         Favorites [C:\Users\Public\Favorites]
08/15/2009  08:01 AM         Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
08/15/2009  08:01 AM         Templates [C:\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Users
08/15/2009  08:01 AM         All Users [C:\ProgramData]
08/15/2009  08:01 AM         Default User [C:\Users\Default]
               0 File(s)              0 bytes
 Directory of C:\Users\All Users
08/15/2009  08:01 AM         Application Data [C:\ProgramData]
08/15/2009  08:01 AM         Desktop [C:\Users\Public\Desktop]
08/15/2009  08:01 AM         Documents [C:\Users\Public\Documents]
08/15/2009  08:01 AM         Favorites [C:\Users\Public\Favorites]
08/15/2009  08:01 AM         Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
08/15/2009  08:01 AM         Templates [C:\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Users\Dad
09/23/2014  11:29 AM         Application Data [C:\Users\Dad\AppData\Roaming]
09/23/2014  11:29 AM         Cookies [C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Cookies]
09/23/2014  11:29 AM         Local Settings [C:\Users\Dad\AppData\Local]
09/23/2014  11:29 AM         My Documents [C:\Users\Dad\Documents]
09/23/2014  11:29 AM         NetHood [C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
09/23/2014  11:29 AM         PrintHood [C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
09/23/2014  11:29 AM         Recent [C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Recent]
09/23/2014  11:29 AM         SendTo [C:\Users\Dad\AppData\Roaming\Microsoft\Windows\SendTo]
09/23/2014  11:29 AM         Start Menu [C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu]
09/23/2014  11:29 AM         Templates [C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Users\Dad\AppData\Local
09/23/2014  11:29 AM         Application Data [C:\Users\Dad\AppData\Local]
09/23/2014  11:29 AM         History [C:\Users\Dad\AppData\Local\Microsoft\Windows\History]
09/23/2014  11:29 AM         Temporary Internet Files [C:\Users\Dad\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Dad\Documents
09/23/2014  11:29 AM         My Music [C:\Users\Dad\Music]
09/23/2014  11:29 AM         My Pictures [C:\Users\Dad\Pictures]
09/23/2014  11:29 AM         My Videos [C:\Users\Dad\Videos]
               0 File(s)              0 bytes
 Directory of C:\Users\Default
08/15/2009  08:01 AM         Application Data [C:\Users\Default\AppData\Roaming]
08/15/2009  08:01 AM         Cookies [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies]
08/15/2009  08:01 AM         Local Settings [C:\Users\Default\AppData\Local]
08/15/2009  08:01 AM         My Documents [C:\Users\Default\Documents]
08/15/2009  08:01 AM         NetHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
08/15/2009  08:01 AM         PrintHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
08/15/2009  08:01 AM         Recent [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
08/15/2009  08:01 AM         SendTo [C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
08/15/2009  08:01 AM         Start Menu [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
08/15/2009  08:01 AM         Templates [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Users\Default\AppData\Local
08/15/2009  08:01 AM         Application Data [C:\Users\Default\AppData\Local]
08/15/2009  08:01 AM         History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
08/15/2009  08:01 AM         Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default\Documents
08/15/2009  08:01 AM         My Music [C:\Users\Default\Music]
08/15/2009  08:01 AM         My Pictures [C:\Users\Default\Pictures]
08/15/2009  08:01 AM         My Videos [C:\Users\Default\Videos]
               0 File(s)              0 bytes
 Directory of C:\Users\Public\Documents
08/15/2009  08:01 AM         My Music [C:\Users\Public\Music]
08/15/2009  08:01 AM         My Pictures [C:\Users\Public\Pictures]
08/15/2009  08:01 AM         My Videos [C:\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Users\Rachel
08/15/2009  08:04 AM         Application Data [C:\Users\Rachel\AppData\Roaming]
08/15/2009  08:04 AM         Cookies [C:\Users\Rachel\AppData\Roaming\Microsoft\Windows\Cookies]
08/15/2009  08:04 AM         Local Settings [C:\Users\Rachel\AppData\Local]
08/15/2009  08:04 AM         My Documents [C:\Users\Rachel\Documents]
08/15/2009  08:04 AM         NetHood [C:\Users\Rachel\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
08/15/2009  08:04 AM         PrintHood [C:\Users\Rachel\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
08/15/2009  08:04 AM         Recent [C:\Users\Rachel\AppData\Roaming\Microsoft\Windows\Recent]
08/15/2009  08:04 AM         SendTo [C:\Users\Rachel\AppData\Roaming\Microsoft\Windows\SendTo]
08/15/2009  08:04 AM         Start Menu [C:\Users\Rachel\AppData\Roaming\Microsoft\Windows\Start Menu]
08/15/2009  08:04 AM         Templates [C:\Users\Rachel\AppData\Roaming\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Users\Rachel\AppData\Local
08/15/2009  08:04 AM         Application Data [C:\Users\Rachel\AppData\Local]
08/15/2009  08:04 AM         History [C:\Users\Rachel\AppData\Local\Microsoft\Windows\History]
08/15/2009  08:04 AM         Temporary Internet Files [C:\Users\Rachel\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Rachel\Documents
08/15/2009  08:04 AM         My Music [C:\Users\Rachel\Music]
08/15/2009  08:04 AM         My Pictures [C:\Users\Rachel\Pictures]
08/15/2009  08:04 AM         My Videos [C:\Users\Rachel\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows\System32\config\systemprofile
07/27/2009  04:48 PM         Application Data [C:\Windows\system32\config\systemprofile\AppData\Roaming]
07/27/2009  04:48 PM         Cookies [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies]
07/27/2009  04:48 PM         Local Settings [C:\Windows\system32\config\systemprofile\AppData\Local]
               0 File(s)              0 bytes
 Directory of C:\Windows\System32\config\systemprofile\AppData\Local
07/27/2009  04:48 PM         Application Data [C:\Windows\system32\config\systemprofile\AppData\Local]
07/27/2009  04:48 PM         History [C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History]
07/27/2009  04:48 PM         Temporary Internet Files [C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
     Total Files Listed:
               0 File(s)              0 bytes
              72 Dir(s)  127,876,943,872 bytes free
 
< %systemroot%\System32\config\*.sav >
[2008/01/20 21:31:11 | 015,716,352 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/20 21:31:01 | 000,102,400 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/20 21:31:12 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 04:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 04:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV
 
< %PROGRAMFILES%\bak. /s >
 
< %systemroot%\system32\bak. /s >
 
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
 
< %systemroot%\system32\config\systemprofile\*.dat /x >
 
< %systemroot%\*.config >
 
< %systemroot%\system32\*.db >
 
< %PROGRAMFILES%\Internet Explorer\*.dat >
 
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2008/01/20 20:56:27 | 000,000,146 | -HS- | M] () – C:\Users\Dad\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
 
< %USERPROFILE%\Desktop\*.exe >
[2014/09/23 13:58:08 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Dad\Desktop\OTL.exe
 
< %PROGRAMFILES%\Common Files\*.* >
 
< %systemroot%\*.src >
 
< %systemroot%\install\*.* >
 
< %systemroot%\system32\DLL\*.* >
 
< %systemroot%\system32\HelpFiles\*.* >
 
< %systemroot%\system32\rundll\*.* >
 
< %systemroot%\winn32\*.* >
 
< %systemroot%\Java\*.* >
 
< %systemroot%\system32\test\*.* >
 
< %systemroot%\system32\Rundll32\*.* >
 
< %systemroot%\AppPatch\Custom\*.* >
 
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
 
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2014-09-11 11:18:43
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:5D432CE3
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:5C321E34

< End of report >
 

 

 

 

 

 

 

OTL Extras logfile created on: 9/23/2014 1:59:03 PM - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Dad\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
2.96 Gb Total Physical Memory | 1.78 Gb Available Physical Memory | 60.20% Memory free
6.12 Gb Paging File | 5.03 Gb Available in Paging File | 82.18% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 218.20 Gb Total Space | 120.81 Gb Free Space | 55.37% Space Free | Partition Type: NTFS
Drive D: | 7.39 Gb Total Space | 7.21 Gb Free Space | 97.47% Space Free | Partition Type: FAT32
Drive E: | 14.65 Gb Total Space | 7.78 Gb Free Space | 53.12% Space Free | Partition Type: NTFS
 
Computer Name: RACHIE | User Name: Dad | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 1
"AntiSpywareOverride" = 1
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00A0E299-C07D-481A-95C7-E7B85F5A4914}" = rport=3702 | protocol=17 | dir=out | app=%systemroot%\system32\p2phost.exe |
"{05188834-E1B5-4A29-87B1-885B65BF35A8}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{16C92901-D6F9-4AE0-AB37-8A0B880C8523}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{1D3F05BD-4DED-4C85-8AB1-BB01ADF11D18}" = lport=137 | protocol=17 | dir=in | app=system |
"{1D9B90E1-6ACC-4AEE-A1BB-2F8D2D2BE43F}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{1E124378-482C-4FC3-AD83-313CED439729}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{20011E7B-B499-44A6-9750-EAB2DE240EC6}" = rport=138 | protocol=17 | dir=out | app=system |
"{223B67D3-2911-465E-928A-A5CCB331A373}" = lport=139 | protocol=6 | dir=in | app=system |
"{267F9F52-2A65-4D71-9560-016A9F8D0D71}" = rport=3540 | protocol=17 | dir=out | svc=pnrpsvc | app=%systemroot%\system32\svchost.exe |
"{270C5039-3D1C-4200-9333-086A674E87BD}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{31D8C675-051E-4570-990D-D42230DEF803}" = lport=138 | protocol=17 | dir=in | app=system |
"{31E21C2C-183F-49D4-A4AD-5751F3CAA4C8}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{35705F20-4A3C-44A1-83B5-C46BE354880C}" = rport=3540 | protocol=17 | dir=out | svc=pnrpsvc | app=%systemroot%\system32\svchost.exe |
"{380B884C-27E6-4F44-92B5-DC5C56C40DC6}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{3F1EF64F-D310-4E63-BBE4-E5965AF11C6F}" = lport=2869 | protocol=6 | dir=in | app=system |
"{42D85F08-E29A-4FAF-9AD8-017596EF1CE0}" = lport=445 | protocol=6 | dir=in | app=system |
"{5493FE0B-C8CE-415C-9D21-4EA0D5D9CA77}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{5C14DAF3-D791-478E-970B-6576956DDEA2}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{6A2815D0-A87C-4640-8429-C93E95944EC6}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{8E8E2F59-4553-4636-89E9-A294C2711932}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{8F67BD22-FA90-4FA9-86EA-B7B272B90ABB}" = lport=54925 | protocol=17 | dir=in | name=brothernetwork scanner |
"{8FB04044-52D0-41DA-8435-926D1210034D}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{90E2E5AA-45E5-46B5-B647-232F38C665FD}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{917C6716-A327-459E-A99D-F16EE15F5A59}" = lport=3540 | protocol=17 | dir=in | svc=pnrpsvc | app=%systemroot%\system32\svchost.exe |
"{95F9ACB3-9C1C-4859-9CD8-3D74267DF88C}" = rport=137 | protocol=17 | dir=out | app=system |
"{A2817614-BBBC-41B9-A1B0-18CFAB33DEE7}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{AE6E51A8-8BCC-4BA6-B7B8-F5FC8D0CF071}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{B0CE9CA7-7717-4DBA-B92C-9406EE196D1A}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{B51D6029-116C-4E67-A330-AFB8CBDC2312}" = rport=10243 | protocol=6 | dir=out | app=system |
"{CA69359B-73C2-45EB-ACA2-E65E7BDA7BBA}" = rport=3702 | protocol=17 | dir=out | app=%systemroot%\system32\p2phost.exe |
"{DB903644-36CD-4F85-9090-D0AED87AF936}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{DC175B57-0552-45E9-9782-DAA855987C92}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{DF6C68A1-93AD-4FD0-941C-8D3D106FB477}" = rport=445 | protocol=6 | dir=out | app=system |
"{E2BAD25B-9F27-4E0B-A345-A979B2DF56FF}" = lport=3702 | protocol=17 | dir=in | app=%systemroot%\system32\p2phost.exe |
"{E2CEC8CF-E6E9-4AD8-A948-E64D91C73A4C}" = lport=2869 | protocol=6 | dir=in | app=system |
"{E3430C09-1D42-4135-B90E-AB9EA40B38BE}" = rport=139 | protocol=6 | dir=out | app=system |
"{E480E884-9105-40BF-87E0-5EBB0103D8BB}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{E5D84C2F-9D52-4A31-BC6C-75807E774857}" = lport=3540 | protocol=17 | dir=in | svc=pnrpsvc | app=%systemroot%\system32\svchost.exe |
"{E784E375-72D8-4E58-A418-C5054BACBCE5}" = lport=3702 | protocol=17 | dir=in | app=%systemroot%\system32\p2phost.exe |
"{E9A940FB-602D-473E-8829-0326435C7744}" = lport=10243 | protocol=6 | dir=in | app=system |
"{F1893331-2A69-48AD-B8FA-E64C01D95D9F}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{FE7FF748-B07C-4A67-AF5D-D9C95878DE78}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00307AB9-9457-494B-B30C-B93ADDF43B1F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{038C37F2-9A5A-4A39-BFAB-CC2403B3747C}" = protocol=6 | dir=out | app=%systemroot%\system32\p2phost.exe |
"{07EFFDF3-E836-49FF-9DA9-E8D1024B24E1}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{098A8538-BCEA-461E-AD10-E5EF68814D5D}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{0CB3F5CC-E873-444F-A841-9299619B8E39}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{0ED3965E-D3C7-417B-86B6-2C0BE559619A}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{1716B900-3E4B-4A9A-B980-20C586648138}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{1A20A825-A4BC-4170-ACF0-9E3084204077}" = protocol=6 | dir=in | app=c:\program files\dell video chat\dellvideochat.exe |
"{34DF4871-7412-45C6-851D-08E834CDD96C}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{3803185B-A2C6-4AA9-B378-86B083DF19AF}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{39C5A448-C0DF-44F4-9EE8-0BA4235750F0}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{3B767B32-08CC-4836-B96D-5B300C7FBC74}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{4FB2E289-8A91-4756-866F-E6253A4BDC61}" = protocol=6 | dir=in | app=c:\users\rachel\downloads\an_introduction_to_book_history_pdf_epub_zip_downloader.exe |
"{52624152-9F5D-4109-8667-46D80C040667}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{52DFC82B-B2FE-4B02-922C-6C2339601FEA}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe |
"{5628CCC9-BE1B-4FA9-98F3-EA2248AB85D8}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{57724F82-5F53-48A4-8BA0-8AD66AB774DA}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{5974584C-EBB5-44E2-A011-C00A54221A69}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{5F3983A5-51F5-4A92-8632-BA3B0FACC69B}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{6066E56E-2E9B-4B6B-9B67-DA9AD75EAF87}" = protocol=6 | dir=in | app=%systemroot%\system32\p2phost.exe |
"{6CC88CF1-27CE-4A1E-8D81-D59EF145310D}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{92B4EFF2-B9AA-4E9A-A86B-B694727A1930}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{99571E85-2407-46EE-8D9E-BCAECBC6946E}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{9D7184E0-06CD-45CF-A0CC-01C9B5B8E05B}" = dir=in | app=c:\program files\cyberlink\powerdvd dx\pdvddxsrv.exe |
"{A75F164E-A6C8-42B9-AC83-1B9CF4491130}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{A8FBF4ED-53AF-4F74-98FC-B140EF845BCB}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{AB7DFDFA-DED3-462C-A601-3256736827AA}" = protocol=6 | dir=out | app=%systemroot%\system32\p2phost.exe |
"{ADB94CAD-C0D3-4C99-9E2A-15067B924044}" = protocol=6 | dir=in | app=c:\program files\brother\brmfl08b\faxrx.exe |
"{B47AB355-1A85-4384-9D69-CFB26E1B559D}" = protocol=17 | dir=in | app=c:\program files\brother\brmfl08b\faxrx.exe |
"{B86D2107-923B-46BD-B381-4BC379CE5A04}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{B953194A-FA2A-4F82-8FF6-962EC5EE993D}" = dir=in | app=c:\program files\cyberlink\powerdvd dx\powerdvd.exe |
"{CEF2963F-74D2-4274-80C0-74AD89A0AF9C}" = protocol=17 | dir=in | app=c:\program files\dell video chat\dellvideochat.exe |
"{DE9E32D2-C067-4F81-9B08-C168A3C34FD1}" = protocol=6 | dir=in | app=c:\program files\ultravnc\winvnc.exe |
"{E0F82EBF-F763-494D-9D79-A6C82CAC2AAD}" = protocol=6 | dir=out | app=system |
"{E2DEEF10-CF9E-49FC-BDAA-185945D1642D}" = protocol=17 | dir=in | app=c:\program files\ultravnc\winvnc.exe |
"{ED05EE88-C863-4857-A229-D12997F42FAC}" = protocol=17 | dir=in | app=c:\users\rachel\downloads\an_introduction_to_book_history_pdf_epub_zip_downloader.exe |
"{F06C7C91-65D1-4322-90CC-B4392BBFA1E5}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{F5103444-0083-485B-95E7-5E6178AA5B39}" = protocol=6 | dir=in | app=%systemroot%\system32\p2phost.exe |
"TCP Query User{9A2A3730-F145-4DA9-9697-4EA38908A5CC}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{AA94EBBD-5AB2-45B5-8650-865E52C396A0}C:\program files\mozilla firefox\plugin-container.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\plugin-container.exe |
"UDP Query User{BE09DD0C-A29F-4BCA-9509-39B7E8052534}C:\program files\mozilla firefox\plugin-container.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\plugin-container.exe |
"UDP Query User{D3C5142F-3913-4259-9570-D822B7E936C2}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{020D8396-D6D9-4B53-A9A1-83C47E2E27AA}" = Windows Live Call
"{04B83666-3A62-452B-85D3-70F8117F2329}_is1" = CamStudio 2.7.2
"{053C30EA-D4C6-47A0-8537-8D231D9BE873}" = DELL0703
"{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Creator Data
"{095B1DCF-5E8B-47EC-9B18-481918A731DB}" = Microsoft Default Manager
"{09760D42-E223-42AD-8C3E-55B47D0DDAC3}" = Roxio Creator DE
"{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
"{107F27B7-8EE4-4B3A-9CE5-497B120369DC}" = Microsoft Security Client
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Creator Tools
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}" = Skype™ 6.20
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java(TM) 6 Update 13
"{26A24AE4-039D-4CA4-87B4-2F83217040FF}" = Java 7 Update 45
"{2BC2781A-F7F6-452E-95EB-018A522F1B2C}" = PaperPort Image Printer
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{308B6AEA-DE50-4666-996D-0FA461719D6B}" = Apple Mobile Device Support
"{3138EAD3-700B-4A10-B617-B3F8096EE30D}" = Dell Edoc Viewer
"{415B2719-AD3A-4944-B404-C472DB6085B3}" = Cisco EAP-FAST Module
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4AB8B41B-3AF1-46BE-99B0-0ACD3B300C0A}" = Junk Mail filter update
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{63C1109E-D977-49ED-BCE3-D00D0BF187D6}" = Windows Live Mail
"{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}" = Live! Cam Avatar Creator
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}" = Cisco PEAP Module
"{67635FB6-2F63-4FFB-830B-D4C01597EBA4}" = Microsoft Office Suite Activation Assistant
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD DX
"{6A92E5C5-0578-443D-91F3-92ECE5F2CAE2}" = Windows Live Writer
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}" = Roxio Creator Audio
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{7A8FF745-BBC5-482B-88E4-18D3178249A9}" = ScanSoft PaperPort 11
"{83770D14-21B9-44B3-8689-F7B523F94560}" = Cisco LEAP Module
"{881F5DE8-9367-4B81-A325-E91BBC6472F9}" = iTunes
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Dell Touchpad
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.12)
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Creator Copy
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{B935C985-A17F-484B-8470-09E4FC27DC26}" = Dell-eBay
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C4972073-2BFE-475D-8441-564EA97DA161}" = QuickSet
"{C6640705-7479-4EE5-BC86-879F05F65E74}" = Google Drive
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF56E507-A96E-4973-B7FB-E49542AE5875}" = QuickShare
"{D9461574-5FC0-4641-BBDC-D1038B196F55}" = Brother MFL-Pro Suite MFC-490CW
"{D9D754A1-EAC5-406C-A28B-C49B1E846711}" = Windows Live Essentials
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software)
"{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Creator DE
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F69E83CF-B440-43F8-89E6-6EA80712109B}" = Windows Live Communications Platform
"{F73A5B18-EB75-4B2C-B32D-9457576E2417}" = Windows Live Photo Gallery
"{FC79C71B-C087-4B93-9B0D-9FE68A199FA4}" = Brother MFC-490CW
"{FDD810CA-D5E3-40E9-AB7B-36440B0D41EF}" = Windows Live Sync
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 15 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 15 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Advanced Audio FX Engine" = Advanced Audio FX Engine
"Any Video Converter 5_is1" = Any Video Converter 5 5.0.2
"AVG SafeGuard toolbar" = AVG SafeGuard toolbar
"Blackboard IM" = Blackboard IM 4.1.0-C
"Broadcom 802.11 Application" = Dell Wireless WLAN Card Utility
"Cisco Connect" = Cisco Connect
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Dell Video Chat" = Dell Video Chat
"Dell Webcam Central" = Dell Webcam Central
"Free Audio Converter_is1" = Free Audio Converter version 5.0.29.925
"Free AVI Video Converter_is1" = Free AVI Video Converter version 5.0.21.1212
"GoToAssist" = GoToAssist 8.0.0.514
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"Malwarebytes Anti-Malware_is1" = Malwarebytes Anti-Malware version 2.0.2.1012
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Client" = Microsoft Security Essentials
"Mozilla Firefox 32.0.2 (x86 en-US)" = Mozilla Firefox 32.0.2 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"NDT- Driver Education_is1" = Help For the Teenager Who Wants to Drive
"SpywareBlaster_is1" = SpywareBlaster 4.5
"Toontown Rewritten" = Toontown Rewritten
"Ultravnc2_is1" = UltraVnc
"Uninstall_is1" = Uninstall 1.0.0.1
"VentureAfrica" = Venture Africa (remove only)
"Vim 7.3" = Vim 7.3 (self-installing)
"WinLiveSuite_Wave3" = Windows Live Essentials
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 9/23/2014 1:48:58 AM | Computer Name = Rachie | Source = WinMgmt | ID = 10
Description =
 
Error - 9/23/2014 2:04:23 AM | Computer Name = Rachie | Source = WinMgmt | ID = 10
Description =
 
Error - 9/23/2014 12:34:02 PM | Computer Name = Rachie | Source = EventSystem | ID = 4609
Description =
 
Error - 9/23/2014 12:34:52 PM | Computer Name = Rachie | Source = WinMgmt | ID = 10
Description =
 
Error - 9/23/2014 1:01:30 PM | Computer Name = Rachie | Source = EventSystem | ID = 4609
Description =
 
Error - 9/23/2014 1:02:08 PM | Computer Name = Rachie | Source = WinMgmt | ID = 10
Description =
 
Error - 9/23/2014 1:25:53 PM | Computer Name = Rachie | Source = WinMgmt | ID = 10
Description =
 
Error - 9/23/2014 1:30:34 PM | Computer Name = Rachie | Source = WinMgmt | ID = 10
Description =
 
Error - 9/23/2014 2:18:44 PM | Computer Name = Rachie | Source = WinMgmt | ID = 10
Description =
 
Error - 9/23/2014 3:55:01 PM | Computer Name = Rachie | Source = WinMgmt | ID = 10
Description =
 
[ Broadcom Wireless LAN Events ]
Error - 4/25/2014 7:20:49 PM | Computer Name = Rachie | Source = WLAN-Tray | ID = 0
Description = 17:20:49, Fri, Apr 25, 14 Error - Unable to gain access to user store

 
Error - 4/26/2014 4:11:52 PM | Computer Name = Rachie | Source = WLAN-Tray | ID = 0
Description = 14:11:52, Sat, Apr 26, 14 Error - Unable to gain access to user store

 
Error - 5/17/2014 10:22:05 AM | Computer Name = Rachie | Source = WLAN-Tray | ID = 0
Description = 08:22:05, Sat, May 17, 14 Error - Unable to gain access to user store

 
Error - 5/20/2014 6:22:38 PM | Computer Name = Rachie | Source = WLAN-Tray | ID = 0
Description = 16:22:38, Tue, May 20, 14 Error - Unable to gain access to user store

 
Error - 5/22/2014 11:42:55 PM | Computer Name = Rachie | Source = WLAN-Tray | ID = 0
Description = 21:42:55, Thu, May 22, 14 Error - Unable to gain access to user store

 
Error - 5/23/2014 1:28:50 AM | Computer Name = Rachie | Source = WLAN-Tray | ID = 0
Description = 23:28:49, Thu, May 22, 14 Error - Unable to gain access to user store

 
Error - 7/27/2014 2:30:17 PM | Computer Name = Rachie | Source = WLAN-Tray | ID = 0
Description = 12:30:16, Sun, Jul 27, 14 Error - Unable to gain access to user store

 
Error - 7/30/2014 11:54:32 PM | Computer Name = Rachie | Source = WLAN-Tray | ID = 0
Description = 21:54:31, Wed, Jul 30, 14 Error - Unable to gain access to user store

 
Error - 8/6/2014 10:05:57 AM | Computer Name = Rachie | Source = WLAN-Tray | ID = 0
Description = 08:05:55, Wed, Aug 06, 14 Error - Unable to gain access to user store

 
Error - 9/21/2014 5:00:47 PM | Computer Name = Rachie | Source = WLAN-Tray | ID = 0
Description = 15:00:46, Sun, Sep 21, 14 Error - Unable to gain access to user store

 
[ OSession Events ]
Error - 12/13/2012 8:20:38 AM | Computer Name = Rachie | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
 12.0.6665.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 478301
 seconds with 600 seconds of active time.  This session ended with a crash.
 
Error - 3/16/2013 1:06:42 PM | Computer Name = Rachie | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 139590
 seconds with 4260 seconds of active time.  This session ended with a crash.
 
Error - 3/16/2013 1:07:06 PM | Computer Name = Rachie | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 11
 seconds with 0 seconds of active time.  This session ended with a crash.
 
Error - 3/16/2013 1:42:17 PM | Computer Name = Rachie | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 4
 seconds with 0 seconds of active time.  This session ended with a crash.
 
Error - 3/13/2014 7:19:22 AM | Computer Name = Rachie | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
 12.0.6683.5002, Microsoft Office Version: 12.0.6612.1000. This session lasted 127485
 seconds with 660 seconds of active time.  This session ended with a crash.
 
[ System Events ]
Error - 3/23/2014 12:21:27 AM | Computer Name = Rachie | Source = Service Control Manager | ID = 7000
Description =
 
Error - 3/23/2014 11:46:01 AM | Computer Name = Rachie | Source = EventLog | ID = 6008
Description = The previous system shutdown at 9:43:58 AM on 3/23/2014 was unexpected.
 
Error - 3/23/2014 11:47:46 AM | Computer Name = Rachie | Source = Service Control Manager | ID = 7000
Description =
 
Error - 3/23/2014 11:47:46 AM | Computer Name = Rachie | Source = Service Control Manager | ID = 7000
Description =
 
Error - 3/23/2014 8:23:04 PM | Computer Name = Rachie | Source = EventLog | ID = 6008
Description = The previous system shutdown at 6:21:42 PM on 3/23/2014 was unexpected.
 
Error - 3/23/2014 8:24:57 PM | Computer Name = Rachie | Source = Service Control Manager | ID = 7000
Description =
 
Error - 3/23/2014 8:24:57 PM | Computer Name = Rachie | Source = Service Control Manager | ID = 7000
Description =
 
Error - 3/23/2014 11:25:43 PM | Computer Name = Rachie | Source = EventLog | ID = 6008
Description = The previous system shutdown at 9:22:58 PM on 3/23/2014 was unexpected.
 
Error - 3/23/2014 11:27:24 PM | Computer Name = Rachie | Source = Service Control Manager | ID = 7000
Description =
 
Error - 3/23/2014 11:27:24 PM | Computer Name = Rachie | Source = Service Control Manager | ID = 7000
Description =
 
 
< End of report >
 

 

Hi calebsnake,

My name is OCD. I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • Copy and Paste logs directly into the reply window. DO NOT attach the logs unless specifically instructed to do so.

IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.

DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

Please stay with this topic until I let you know that your system appears to be "All Clear"

Important: All tools MUST be run from the Desktop.

=========================

[external image: bullseye_zpse9eaf36e.gif] Uninstall via Programs and Features

Click Start > Control Panel > Programs and Features. Locate and select the following that are present on the list and click the Remove button:

  • AVG SafeGuard toolbar

=========================

[external image: bullseye_zpse9eaf36e.gif] Run OTL.exe

    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    PRC - [2014/08/26 04:13:14 | 002,640,408 | —- | M] () – C:\Program Files\AVG SafeGuard toolbar\vprot.exe
    PRC - [2014/08/12 06:21:19 | 001,820,184 | —- | M] (AVG Secure Search) – C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe
    PRC - [2014/08/12 06:21:16 | 000,159,768 | —- | M] () – C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\loggingserver.exe
    MOD - [2014/08/26 04:13:14 | 002,640,408 | —- | M] () – C:\Program Files\AVG SafeGuard toolbar\vprot.exe
    MOD - [2014/08/12 06:21:21 | 000,519,704 | —- | M] () – C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\log4cplusU.dll
    SRV - File not found [On_Demand | Stopped] – C:\Users\Rachel\AppData\Local\Temp\MKLUYHTMC.exe – (MKLUYHTMC)
    SRV - File not found [On_Demand | Stopped] – C:\Users\Rachel\AppData\Local\Temp\EE.exe – (EE)
    SRV - [2014/08/12 06:21:19 | 001,820,184 | —- | M] (AVG Secure Search) [Auto | Running] – C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe – (vToolbarUpdater18.1.9)
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.9.799\ [2014/08/26 04:15:02 | 000,000,000 | —D | M]
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O2 - BHO: (AVG SafeGuard toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG SafeGuard toolbar\18.1.9.799\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search)
    O3 - HKLM\..\Toolbar: (AVG SafeGuard toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG SafeGuard toolbar\18.1.9.799\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search)
    O4 - HKLM..\Run: [vProt] C:\Program Files\AVG SafeGuard toolbar\vprot.exe ()
    O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\18.1.9\ViProtocol.dll (AVG Secure Search)
    [2014/09/23 11:32:27 | 000,000,000 | —D | C] – C:\Users\Dad\AppData\Local\AVG SafeGuard toolbar
    [2014/08/27 06:15:33 | 000,000,000 | —D | C] – C:\Program Files\AVG Security Toolbar
    [2014/09/23 13:54:02 | 000,000,408 | —- | M] () – C:\Windows\tasks\AVG-Secure-Search-Update_1013b_rmv.job
    [2014/09/23 13:54:02 | 000,000,358 | —- | M] () – C:\Windows\tasks\AVG-Secure-Search-Update_1013b_rel.job
    [2013/10/13 07:45:39 | 000,003,749 | —- | C] () – C:\Program Files\Mozilla Firefoxsafeguard-secure-search.xml
    
    :Files
    C:\Users\Rachel\AppData\Local\Temp\MKLUYHTMC.exe
    C:\Users\Rachel\AppData\Local\Temp\EE.exe
    C:\Program Files\Common Files\AVG Secure Search
    ipconfig /flushdns /c
    
    :Services
    vToolbarUpdater18.1.9
    MKLUYHTMC
    EE
    
    :Commands
    [purity]
    [createrestorepoint]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done

=========================

[external image: bullseye_zpse9eaf36e.gif] Security Check

Download Security Check by screen317 from here or here.

  • Save it to your Desktop.
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

=========================

[external image: bullseye_zpse9eaf36e.gif] aswMBR

Download aswMBR.exe and save it to your desktop.

    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click Scan
  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.

=========================

[external image: bullseye_zpse9eaf36e.gif] Re-run OTL, but this time place a check mark in the box that reads Scan All Users.

[external image: OTLGUIallusers_zps57e4ec2f.gif]

=========================

In your next post please provide the following:


  • OTL fix log
  • checkup.txt
  • aswMBR.txt
  • new OTL.txt

Thanks OCD!

I was unable to complete the aswMBR scan.  The "Dad" user is beginning to display the same behavior as my daughter's
user - slowing down then freezing,

 

aswMBR kept either blue screening or freezing at the point where it was scanning a file called "Magnify.exe" in the systems folder.  I don't know if that is significant.  During the service scanning phase it did flag a service running out of the MS antimalware definitions directories.  On one of the aswMBR runs, I clicked the "save" button after the services scan and was able to get a partial log plus the MBR.dat file.

 

It seems like the malware knows we are after it… creepy!

 

I saved the files off on a thumb drive.  The box isn't performing long enough to get all this stuff together for a post.  So I carried the files to another box.

 

Thanks for your help.

 

OTL fix

 

All processes killed
========== OTL ==========
No active process named vprot.exe was found!
No active process named ToolbarUpdater.exe was found!
No active process named loggingserver.exe was found!
Service MKLUYHTMC stopped successfully!
Service MKLUYHTMC deleted successfully!
File C:\Users\Rachel\AppData\Local\Temp\MKLUYHTMC.exe not found.
Service EE stopped successfully!
Service EE deleted successfully!
File C:\Users\Rachel\AppData\Local\Temp\EE.exe not found.
Error: No service named vToolbarUpdater18.1.9 was found to stop!
Service\Driver key vToolbarUpdater18.1.9 not found.
File C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe not found.
Registry value HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar not found.
File C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.9.799\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}\ not found.
File C:\Program Files\AVG SafeGuard toolbar\18.1.9.799\AVG SafeGuard toolbar_toolbar.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{95B7759C-8C7F-4BF1-B163-73684A933233} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}\ not found.
File C:\Program Files\AVG SafeGuard toolbar\18.1.9.799\AVG SafeGuard toolbar_toolbar.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\vProt not found.
File C:\Program Files\AVG SafeGuard toolbar\vprot.exe not found.
File C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\18.1.9\ViProtocol.dll not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\viprotocol\ not found.
File C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\18.1.9\ViProtocol.dll not found.
Folder C:\Users\Dad\AppData\Local\AVG SafeGuard toolbar\ not found.
C:\Program Files\AVG Security Toolbar folder moved successfully.
C:\Windows\Tasks\AVG-Secure-Search-Update_1013b_rmv.job moved successfully.
C:\Windows\Tasks\AVG-Secure-Search-Update_1013b_rel.job moved successfully.
C:\Program Files\Mozilla Firefoxsafeguard-secure-search.xml moved successfully.
========== FILES ==========
File\Folder C:\Users\Rachel\AppData\Local\Temp\MKLUYHTMC.exe not found.
File\Folder C:\Users\Rachel\AppData\Local\Temp\EE.exe not found.
File\Folder C:\Program Files\Common Files\AVG Secure Search not found.
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Dad\Desktop\cmd.bat deleted successfully.
C:\Users\Dad\Desktop\cmd.txt deleted successfully.
========== SERVICES/DRIVERS ==========
Error: No service named vToolbarUpdater18.1.9 was found to stop!
Service\Driver key vToolbarUpdater18.1.9 not found.
Error: No service named MKLUYHTMC was found to stop!
Service\Driver key MKLUYHTMC not found.
Error: No service named EE was found to stop!
Service\Driver key EE not found.
========== COMMANDS ==========
Restore point Set: OTL Restore Point
 
[EMPTYTEMP]
 
User: All Users
 
User: Dad
->Temp folder emptied: 2728232 bytes
->Temporary Internet Files folder emptied: 4245913 bytes
->FireFox cache emptied: 9985571 bytes
->Flash cache emptied: 662 bytes
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Public
 
User: Rachel
->Temp folder emptied: 8833347226 bytes
->Temporary Internet Files folder emptied: 1302311653 bytes
->Java cache emptied: 1738099 bytes
->FireFox cache emptied: 437964440 bytes
->Google Chrome cache emptied: 37085513 bytes
->Flash cache emptied: 11381 bytes
 
User: TEMP
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 606777869 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 10,716.00 mb
 
 
OTL by OldTimer - Version 3.2.69.0 log created on 09242014_055631

Files\Folders moved on Reboot…
File\Folder C:\Windows\temp\TMP00000069E397F3863BAF5335 not found!

PendingFileRenameOperations files…

Registry entries deleted on Reboot…
 

 

 

 

 

checkup.txt

 

 Results of screen317's Security Check version 0.99.87  
 Windows Vista Service Pack 2 x86 (UAC is enabled)  
 Internet Explorer 9  
 Internet Explorer 8  
``````````````Antivirus/Firewall Check:``````````````
 Windows Firewall Enabled!  
Microsoft Security Essentials   
 Antivirus up to date!  
`````````Anti-malware/Other Utilities Check:`````````
 MVPS Hosts File  
 SpywareBlaster 4.5    
 SUPERAntiSpyware     
 Java(TM) 6 Update 13  
 Java 7 Update 45  
 Java version out of Date!
 Adobe Flash Player     15.0.0.152  
 Adobe Reader 9 Adobe Reader out of Date!
 Adobe Reader 10.1.12 Adobe Reader out of Date!  
 Mozilla Firefox (32.0.2)
````````Process Check: objlist.exe by Laurent````````  
 Microsoft Security Essentials MSMpEng.exe
 Microsoft Security Essentials msseces.exe
`````````````````System Health check`````````````````
 Total Fragmentation on Drive C: 0 %
````````````````````End of Log``````````````````````

 

 

 

aswMBR.txt
 

aswMBR version 1.0.1.2041 Copyright© 2014 AVAST Software
Run date: 2014-09-24 07:16:25
—————————–
07:16:25.658    OS Version: Windows 6.0.6002 Service Pack 2
07:16:25.658    Number of processors: 2 586 0x170A
07:16:25.659    ComputerName: RACHIE  UserName: Dad
07:16:52.797    Initialize success
07:16:52.870    VM: initialized successfully
07:16:52.907    VM: Intel CPU virtualization not supported
07:19:28.451    AVAST engine defs: 14092400
07:24:13.774    The log file has been saved successfully to "C:\Users\Dad\Desktop\aswMBR.txt"


aswMBR version 1.0.1.2041 Copyright© 2014 AVAST Software
Run date: 2014-09-24 07:53:13
—————————–
07:53:13.046    OS Version: Windows 6.0.6002 Service Pack 2
07:53:13.047    Number of processors: 2 586 0x170A
07:53:13.048    ComputerName: RACHIE  UserName: Dad
07:53:15.386    Initialize success
07:53:15.435    VM: initialized successfully
07:53:15.462    VM: Intel CPU virtualization not supported
07:54:23.712    AVAST engine defs: 14092400
07:54:30.931    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
07:54:30.935    Disk 0 Vendor: TOSHIBA_ FG00 Size: 238475MB BusType: 3
07:54:31.100    Disk 0 MBR read successfully
07:54:31.105    Disk 0 MBR scan
07:54:31.133    Disk 0 Windows VISTA default MBR code
07:54:31.138    Disk 0 Partition 1 00     DE Dell Utility Dell 8.0       39 MB offset 63
07:54:31.177    Disk 0 Partition 2 00     07    HPFS/NTFS NTFS        15000 MB offset 81920
07:54:31.214    Disk 0 Partition 3 80 (A) 07    HPFS/NTFS NTFS       223434 MB offset 30801920
07:54:31.290    Disk 0 scanning sectors +488395120
07:54:31.549    Disk 0 scanning C:\Windows\system32\drivers
07:55:06.590    Service scanning
07:55:35.976    Service MpKslaf92ad89 c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{43A7FBC9-5392-4C53-A540-8A0BF8C5444D}\MpKslaf92ad89.sys **LOCKED** 32
07:55:42.069    Disk 0 MBR has been saved successfully to "C:\Users\Dad\Desktop\MBR.dat"
07:55:42.106    The log file has been saved successfully to "C:\Users\Dad\Desktop\aswMBR.txt"



new OTL scan

 

OTL logfile created on: 9/24/2014 8:01:27 AM - Run 2
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Dad\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
2.96 Gb Total Physical Memory | 2.01 Gb Available Physical Memory | 67.95% Memory free
6.12 Gb Paging File | 5.27 Gb Available in Paging File | 86.07% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 218.20 Gb Total Space | 128.99 Gb Free Space | 59.12% Space Free | Partition Type: NTFS
Drive E: | 14.65 Gb Total Space | 7.78 Gb Free Space | 53.12% Space Free | Partition Type: NTFS
 
Computer Name: RACHIE | User Name: Dad | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2014/09/23 13:58:08 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Dad\Desktop\OTL.exe
PRC - [2014/09/04 06:50:02 | 000,064,704 | —- | M] (Adobe Systems Incorporated) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2014/08/22 12:44:44 | 000,022,192 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2014/08/22 12:44:40 | 000,288,120 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft Security Client\NisSrv.exe
PRC - [2014/08/22 12:41:00 | 000,974,432 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2014/05/14 13:07:08 | 000,067,584 | —- | M] (PasswordBox, Inc.) – C:\Program Files\PasswordBox\pbbtnService.exe
PRC - [2013/10/09 10:58:16 | 003,275,136 | —- | M] (Skype Technologies S.A.) – C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
PRC - [2011/12/14 09:04:11 | 000,116,608 | —- | M] (SUPERAntiSpyware.com) – C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
PRC - [2010/11/28 00:30:28 | 001,737,200 | —- | M] (UltraVNC) – C:\Program Files\UltraVNC\winvnc.exe
PRC - [2009/06/03 13:46:42 | 001,025,264 | —- | M] (SupportSoft, Inc.) – C:\Program Files\Dell Support Center\gs_agent\dsc.exe
PRC - [2009/06/03 13:46:38 | 000,206,064 | —- | M] (SupportSoft, Inc.) – C:\Program Files\Dell Support Center\bin\sprtcmd.exe
PRC - [2009/06/03 13:46:38 | 000,201,968 | —- | M] (SupportSoft, Inc.) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe
PRC - [2009/04/11 00:28:11 | 000,217,088 | —- | M] (Microsoft Corporation) – C:\Windows\System32\WerFault.exe
PRC - [2009/04/11 00:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
PRC - [2009/03/31 09:00:24 | 000,483,428 | —- | M] (IDT, Inc.) – C:\Program Files\IDT\WDM\sttray.exe
PRC - [2009/03/31 09:00:18 | 000,254,042 | —- | M] (IDT, Inc.) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\stacsv.exe
PRC - [2009/03/31 09:00:04 | 000,081,920 | —- | M] (Andrea Electronics Corporation) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\AEstSrv.exe
PRC - [2008/05/07 16:41:14 | 000,354,840 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2014/09/11 05:40:51 | 005,465,088 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\846057ebe7a3cb80edc3f73d35b4830a\System.Xml.ni.dll
MOD - [2014/09/11 05:38:30 | 007,977,984 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System\0ab7bdcd7b8bdf70f983be2c324ea3b8\System.ni.dll
MOD - [2014/09/11 05:38:04 | 011,496,960 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\3444fbefcbd532181c499150ace644a4\mscorlib.ni.dll
 
 
========== Services (SafeList) ==========
 
SRV - File not found [On_Demand | Stopped] – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe – (ACDaemon)
SRV - [2014/09/18 19:37:41 | 000,114,288 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2014/09/10 07:43:40 | 000,267,440 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2014/09/04 06:50:02 | 000,064,704 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2014/08/22 12:44:44 | 000,022,192 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Client\MsMpEng.exe – (MsMpSvc)
SRV - [2014/08/22 12:44:40 | 000,288,120 | —- | M] (Microsoft Corporation) [On_Demand | Running] – c:\Program Files\Microsoft Security Client\NisSrv.exe – (NisSrv)
SRV - [2014/05/14 13:07:08 | 000,067,584 | —- | M] (PasswordBox, Inc.) [Auto | Running] – C:\Program Files\PasswordBox\pbbtnService.exe – (PasswordBox)
SRV - [2013/10/09 10:58:16 | 003,275,136 | —- | M] (Skype Technologies S.A.) [Auto | Running] – C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe – (Skype C2C Service)
SRV - [2011/12/14 09:04:11 | 000,116,608 | —- | M] (SUPERAntiSpyware.com) [Auto | Running] – C:\Program Files\SUPERAntiSpyware\SASCORE.EXE – (!SASCORE)
SRV - [2010/11/28 00:30:28 | 001,737,200 | —- | M] (UltraVNC) [Auto | Running] – C:\Program Files\UltraVNC\winvnc.exe – (uvnc_service)
SRV - [2009/07/27 16:50:51 | 000,016,680 | —- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] – C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe – (GoToAssist)
SRV - [2009/06/03 13:46:38 | 000,201,968 | —- | M] (SupportSoft, Inc.) [Auto | Running] – C:\Program Files\Dell Support Center\bin\sprtsvc.exe – (sprtsvc_DellSupportCenter)
SRV - [2009/03/31 09:00:18 | 000,254,042 | —- | M] (IDT, Inc.) [Auto | Running] – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\stacsv.exe – (STacSV)
SRV - [2009/03/31 09:00:04 | 000,081,920 | —- | M] (Andrea Electronics Corporation) [Auto | Running] – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\AEstSrv.exe – (AESTFilters)
SRV - [2008/05/07 16:41:14 | 000,354,840 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe – (IAANTMON)
SRV - [2008/01/20 20:33:00 | 000,272,952 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\nwlnkfwd.sys – (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\nwlnkflt.sys – (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\ipinip.sys – (IpInIp)
DRV - [2014/09/24 07:53:16 | 000,039,464 | —- | M] () [Kernel | System | Stopped] – c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{43A7FBC9-5392-4C53-A540-8A0BF8C5444D}\MpKslaf92ad89.sys – (MpKslaf92ad89)
DRV - [2014/09/24 07:31:30 | 000,039,464 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{43A7FBC9-5392-4C53-A540-8A0BF8C5444D}\MpKslf721a017.sys – (MpKslf721a017)
DRV - [2014/09/24 07:16:54 | 000,039,464 | —- | M] () [Kernel | System | Stopped] – c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{43A7FBC9-5392-4C53-A540-8A0BF8C5444D}\MpKsl7af8a1f9.sys – (MpKsl7af8a1f9)
DRV - [2014/09/24 06:54:53 | 000,039,464 | —- | M] () [Kernel | System | Stopped] – c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{43A7FBC9-5392-4C53-A540-8A0BF8C5444D}\MpKsla6af8de8.sys – (MpKsla6af8de8)
DRV - [2014/09/23 11:37:44 | 000,110,296 | —- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] – C:\Windows\System32\drivers\MBAMSwissArmy.sys – (MBAMSwissArmy)
DRV - [2014/07/17 18:05:08 | 000,095,920 | —- | M] (Microsoft Corporation) [Kernel | Auto | Running] – C:\Windows\System32\drivers\NisDrvWFP.sys – (NisDrv)
DRV - [2011/12/14 09:04:06 | 000,067,664 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS – (SASKUTIL)
DRV - [2011/12/14 09:04:06 | 000,012,880 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS – (SASDIFSV)
DRV - [2011/03/31 16:30:56 | 000,012,096 | —- | M] (UVNC BVBA) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\mv2.sys – (mv2)
DRV - [2009/03/31 09:00:26 | 000,398,336 | —- | M] (IDT, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\stwrt.sys – (STHDA)
DRV - [2009/03/31 08:18:30 | 000,192,048 | —- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\Apfiltr.sys – (ApfiltrService)
DRV - [2008/12/30 20:00:04 | 000,144,128 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\CtClsFlt.sys – (CtClsFlt)
DRV - [2008/12/21 12:32:18 | 000,018,424 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\bcm42rly.sys – (BCM42RLY)
DRV - [2008/01/20 20:32:51 | 000,220,672 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\e1e6032.sys – (e1express)
DRV - [2006/11/02 01:36:43 | 002,028,032 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\atikmdag.sys – (R300)
DRV - [2005/08/17 08:47:48 | 000,073,696 | —- | M] (MCCI) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\sscdserd.sys – (sscdserd)
DRV - [2005/08/17 08:46:26 | 000,093,872 | —- | M] (MCCI) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\sscdmdm.sys – (sscdmdm)
DRV - [2005/08/17 08:46:20 | 000,008,272 | —- | M] (MCCI) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\sscdmdfl.sys – (sscdmdfl)
DRV - [2005/08/17 08:45:00 | 000,058,352 | —- | M] (MCCI) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\sscdbus.sys – (sscdbus)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope = {E22F17D0-EFB4-41D3-9DD0-3EFFE67EA251}
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-3176256395-2519655851-1769987202-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
IE - HKU\S-1-5-21-3176256395-2519655851-1769987202-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/USCON/1
IE - HKU\S-1-5-21-3176256395-2519655851-1769987202-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:32.0.2
FF - user.js - File not found
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.45.2: C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8051.1204: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\PasswordBox\Firefox [2013/11/21 05:31:34 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 32.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 32.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2014/09/18 19:36:42 | 000,000,000 | —D | M]
 
[2014/09/23 11:43:12 | 000,000,000 | —D | M] (No name found) – C:\Users\Dad\AppData\Roaming\Mozilla\Extensions
[2014/09/24 06:26:18 | 000,000,000 | —D | M] (No name found) – C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\hwzfzqyy.default\extensions
[2014/09/18 19:36:39 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2014/09/18 19:36:39 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2014/09/18 19:36:38 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\browser\extensions
[2014/09/18 19:36:38 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2014/09/18 19:37:45 | 000,000,000 | —D | M] (Default) – C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
 
O1 HOSTS File: ([2011/05/30 17:55:15 | 000,601,001 | —- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts:     
O1 - Hosts: 127.0.0.1    localhost
O1 - Hosts:     
O1 - Hosts: 127.0.0.1    fr.a2dfp.net
O1 - Hosts: 127.0.0.1    m.fr.a2dfp.net
O1 - Hosts: 127.0.0.1    ad.a8.net
O1 - Hosts: 127.0.0.1    asy.a8ww.net
O1 - Hosts: 127.0.0.1    abcstats.com
O1 - Hosts: 127.0.0.1    a.abv.bg
O1 - Hosts: 127.0.0.1    adserver.abv.bg
O1 - Hosts: 127.0.0.1    adv.abv.bg
O1 - Hosts: 127.0.0.1    bimg.abv.bg
O1 - Hosts: 127.0.0.1    ca.abv.bg
O1 - Hosts: 127.0.0.1    www2.a-counter.kiev.ua
O1 - Hosts: 127.0.0.1    track.acclaimnetwork.com
O1 - Hosts: 127.0.0.1    accuserveadsystem.com
O1 - Hosts: 127.0.0.1    www.accuserveadsystem.com
O1 - Hosts: 127.0.0.1    achmedia.com
O1 - Hosts: 127.0.0.1    aconti.net
O1 - Hosts: 127.0.0.1    secure.aconti.net
O1 - Hosts: 127.0.0.1    www.aconti.net #[Dialer.Aconti]
O1 - Hosts: 127.0.0.1    am1.activemeter.com
O1 - Hosts: 127.0.0.1    www.activemeter.com #[Tracking.Cookie]
O1 - Hosts: 127.0.0.1    ads.activepower.net
O1 - Hosts: 127.0.0.1    stat.active24stats.nl #[Tracking.Cookie]
O1 - Hosts: 16261 more lines…
O2 - BHO: (PasswordBox Helper) - {5DB69B97-934B-451D-94DB-32EF802A01CD} - C:\Program Files\PasswordBox\Application\pbbtn.dll (PasswordBox, Inc.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [dellsupportcenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 10.45.2)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 10.45.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{181E5132-7639-4926-A018-8B94B50B015E}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4B54D63F-5208-440F-B047-E343E8C7B180}: DhcpNameServer = 75.75.75.75 75.75.76.76 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D638745A-CD6F-4D6D-A326-9EC024EC80F7}: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll) - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 15:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2004/04/30 16:01:00 | 000,000,053 | -HS- | M] () - E:\AUTORUN.INF – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2014/09/24 06:53:52 | 005,185,536 | —- | C] (AVAST Software) – C:\Users\Dad\Desktop\aswMBR.exe
[2014/09/24 05:56:31 | 000,000,000 | —D | C] – C:\_OTL
[2014/09/23 18:55:44 | 000,000,000 | -HSD | C] – C:\found.001
[2014/09/23 14:32:26 | 000,000,000 | —D | C] – C:\Users\Dad\AppData\Roaming\Macromedia
[2014/09/23 14:32:26 | 000,000,000 | —D | C] – C:\Users\Dad\AppData\Local\Macromedia
[2014/09/23 14:32:26 | 000,000,000 | —D | C] – C:\Users\Dad\AppData\Roaming\Adobe
[2014/09/23 13:58:07 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Dad\Desktop\OTL.exe
[2014/09/23 11:42:53 | 000,000,000 | —D | C] – C:\Users\Dad\AppData\Roaming\Mozilla
[2014/09/23 11:42:53 | 000,000,000 | —D | C] – C:\Users\Dad\AppData\Local\Mozilla
[2014/09/23 11:30:55 | 000,000,000 | —D | C] – C:\Users\Dad\AppData\Local\SupportSoft
[2014/09/23 11:30:14 | 000,000,000 | R–D | C] – C:\Users\Dad\Searches
[2014/09/23 11:30:14 | 000,000,000 | R–D | C] – C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2014/09/23 11:30:01 | 000,000,000 | —D | C] – C:\Users\Dad\AppData\Roaming\Identities
[2014/09/23 11:29:58 | 000,000,000 | R–D | C] – C:\Users\Dad\Contacts
[2014/09/23 11:29:56 | 000,000,000 | —D | C] – C:\Users\Dad\AppData\Local\VirtualStore
[2014/09/23 11:29:24 | 000,000,000 | -HSD | C] – C:\Users\Dad\AppData\Local\Temporary Internet Files
[2014/09/23 11:29:24 | 000,000,000 | -HSD | C] – C:\Users\Dad\Templates
[2014/09/23 11:29:24 | 000,000,000 | -HSD | C] – C:\Users\Dad\Start Menu
[2014/09/23 11:29:24 | 000,000,000 | -HSD | C] – C:\Users\Dad\SendTo
[2014/09/23 11:29:24 | 000,000,000 | -HSD | C] – C:\Users\Dad\Recent
[2014/09/23 11:29:24 | 000,000,000 | -HSD | C] – C:\Users\Dad\PrintHood
[2014/09/23 11:29:24 | 000,000,000 | -HSD | C] – C:\Users\Dad\NetHood
[2014/09/23 11:29:24 | 000,000,000 | -HSD | C] – C:\Users\Dad\Documents\My Videos
[2014/09/23 11:29:24 | 000,000,000 | -HSD | C] – C:\Users\Dad\Documents\My Pictures
[2014/09/23 11:29:24 | 000,000,000 | -HSD | C] – C:\Users\Dad\Documents\My Music
[2014/09/23 11:29:24 | 000,000,000 | -HSD | C] – C:\Users\Dad\My Documents
[2014/09/23 11:29:24 | 000,000,000 | -HSD | C] – C:\Users\Dad\Local Settings
[2014/09/23 11:29:24 | 000,000,000 | -HSD | C] – C:\Users\Dad\AppData\Local\History
[2014/09/23 11:29:24 | 000,000,000 | -HSD | C] – C:\Users\Dad\Cookies
[2014/09/23 11:29:24 | 000,000,000 | -HSD | C] – C:\Users\Dad\Application Data
[2014/09/23 11:29:24 | 000,000,000 | -HSD | C] – C:\Users\Dad\AppData\Local\Application Data
[2014/09/23 11:29:23 | 000,000,000 | –SD | C] – C:\Users\Dad\AppData\Roaming\Microsoft
[2014/09/23 11:29:23 | 000,000,000 | R–D | C] – C:\Users\Dad\Videos
[2014/09/23 11:29:23 | 000,000,000 | R–D | C] – C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2014/09/23 11:29:23 | 000,000,000 | R–D | C] – C:\Users\Dad\Saved Games
[2014/09/23 11:29:23 | 000,000,000 | R–D | C] – C:\Users\Dad\Pictures
[2014/09/23 11:29:23 | 000,000,000 | R–D | C] – C:\Users\Dad\Music
[2014/09/23 11:29:23 | 000,000,000 | R–D | C] – C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2014/09/23 11:29:23 | 000,000,000 | R–D | C] – C:\Users\Dad\Links
[2014/09/23 11:29:23 | 000,000,000 | R–D | C] – C:\Users\Dad\Favorites
[2014/09/23 11:29:23 | 000,000,000 | R–D | C] – C:\Users\Dad\Downloads
[2014/09/23 11:29:23 | 000,000,000 | R–D | C] – C:\Users\Dad\Documents
[2014/09/23 11:29:23 | 000,000,000 | R–D | C] – C:\Users\Dad\Desktop
[2014/09/23 11:29:23 | 000,000,000 | R–D | C] – C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2014/09/23 11:29:23 | 000,000,000 | -H-D | C] – C:\Users\Dad\AppData
[2014/09/23 11:29:23 | 000,000,000 | —D | C] – C:\Users\Dad\AppData\Local\Temp
[2014/09/23 11:29:23 | 000,000,000 | —D | C] – C:\Users\Dad\AppData\Local\SoftThinks
[2014/09/23 11:29:23 | 000,000,000 | —D | C] – C:\Users\Dad\AppData\Local\Microsoft Help
[2014/09/23 11:29:23 | 000,000,000 | —D | C] – C:\Users\Dad\AppData\Local\Microsoft
[2014/09/23 11:29:23 | 000,000,000 | —D | C] – C:\Users\Dad\AppData\Local\Google
[2014/09/22 17:56:14 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2014/09/22 17:56:12 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Skype
[2014/09/19 15:53:02 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Toontown Rewritten
[2014/09/18 19:36:37 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2014/09/11 05:17:12 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2014/09/11 05:17:10 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2014/09/11 05:17:09 | 000,607,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2014/09/11 05:17:09 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2014/09/11 05:17:08 | 000,353,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2014/09/11 05:17:06 | 000,223,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2014/09/11 05:17:06 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2014/09/11 05:17:06 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2014/09/11 05:17:02 | 001,810,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2014/09/11 05:17:02 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2014/09/11 05:17:01 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2014/09/11 05:16:58 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2014/08/28 05:00:32 | 002,054,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2014/08/27 06:15:17 | 000,000,000 | —D | C] – C:\ProgramData\Avg_Update_0814tb
 
========== Files - Modified Within 30 Days ==========
 
[2014/09/24 07:58:39 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014/09/24 07:58:15 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2014/09/24 07:58:15 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2014/09/24 07:58:02 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2014/09/24 07:57:59 | 3181,760,512 | -HS- | M] () – C:\hiberfil.sys
[2014/09/24 07:57:58 | 218,327,979 | —- | M] () – C:\Windows\MEMORY.DMP
[2014/09/24 07:56:05 | 000,000,593 | —- | M] () – C:\Users\Dad\_viminfo
[2014/09/24 07:55:42 | 000,000,512 | —- | M] () – C:\Users\Dad\Desktop\MBR.dat
[2014/09/24 07:31:00 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3176256395-2519655851-1769987202-1000UA.job
[2014/09/24 07:14:07 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/09/24 06:53:56 | 005,185,536 | —- | M] (AVAST Software) – C:\Users\Dad\Desktop\aswMBR.exe
[2014/09/24 06:24:53 | 000,854,417 | —- | M] () – C:\Users\Dad\Desktop\SecurityCheck.exe
[2014/09/24 06:11:48 | 000,000,886 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014/09/24 05:53:53 | 000,000,905 | —- | M] () – C:\Users\Dad\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2014/09/23 19:04:10 | 000,595,684 | —- | M] () – C:\Windows\System32\perfh009.dat
[2014/09/23 19:04:10 | 000,101,350 | —- | M] () – C:\Windows\System32\perfc009.dat
[2014/09/23 16:30:59 | 000,000,860 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3176256395-2519655851-1769987202-1000Core.job
[2014/09/23 13:58:08 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Dad\Desktop\OTL.exe
[2014/09/23 11:37:44 | 000,110,296 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\MBAMSwissArmy.sys
[2014/09/22 18:31:59 | 000,002,337 | —- | M] () – C:\Users\Public\Desktop\Skype.lnk
[2014/09/22 00:41:56 | 000,231,568 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MpSigStub.exe
[2014/09/19 15:53:02 | 000,000,672 | —- | M] () – C:\Users\Public\Desktop\Toontown Rewritten.lnk
[2014/09/11 05:02:13 | 000,002,155 | —- | M] () – C:\Windows\epplauncher.mif
[2014/09/10 07:43:39 | 000,701,104 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2014/09/10 07:43:39 | 000,071,344 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2014/08/28 05:19:50 | 000,298,792 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
 
========== Files Created - No Company Name ==========
 
[2014/09/24 07:56:05 | 000,000,593 | —- | C] () – C:\Users\Dad\_viminfo
[2014/09/24 07:55:42 | 000,000,512 | —- | C] () – C:\Users\Dad\Desktop\MBR.dat
[2014/09/24 06:26:18 | 000,854,417 | —- | C] () – C:\Users\Dad\Desktop\SecurityCheck.exe
[2014/09/24 05:53:53 | 000,000,905 | —- | C] () – C:\Users\Dad\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2014/09/23 11:30:17 | 000,000,911 | —- | C] () – C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2014/09/23 11:30:13 | 000,000,906 | —- | C] () – C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
[2014/09/23 11:29:58 | 000,000,877 | —- | C] () – C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
[2014/09/23 11:29:23 | 000,000,258 | —- | C] () – C:\Users\Dad\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2014/09/23 11:29:23 | 000,000,240 | —- | C] () – C:\Users\Dad\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2014/09/23 11:28:45 | 3181,760,512 | -HS- | C] () – C:\hiberfil.sys
[2014/09/22 17:56:14 | 000,002,337 | —- | C] () – C:\Users\Public\Desktop\Skype.lnk
[2014/09/19 15:53:02 | 000,000,672 | —- | C] () – C:\Users\Public\Desktop\Toontown Rewritten.lnk
[2009/09/25 19:28:41 | 000,000,258 | RHS- | C] () – C:\ProgramData\ntuser.pol
 
========== ZeroAccess Check ==========
 
[2006/11/02 06:51:16 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2014/03/25 07:26:04 | 011,587,584 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/04/11 00:28:19 | 000,614,912 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/04/11 00:28:25 | 000,347,648 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:5D432CE3
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:5C321E34

< End of report >
 

Attachments:

Hi calebsnake ,

If you have trouble downloading these tools directly to the infected computer, just download them to a USB drive and transfer them to the Desktop (of the infected machine) before running. :thumbup:

[external image: bullseye_zpse9eaf36e.gif] Please download AdwCleaner by Xplode and save to your Desktop.

    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • Click on the Scan button.
  • AdwCleaner will begin…be patient as the scan may take some time to complete.
  • After the scan has finished, click on the Report button…a log file (AdwCleaner[R0].txt) will open in Notepad for review.
  • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
  • Copy and paste the contents of that log file in your next reply.
  • A copy of all log files are saved in the C:\AdwCleaner folder which was created when running the tool.

=========================

[external image: bullseye_zpse9eaf36e.gif] ComboFix

Refer to the ComboFix User's Guide

  • Download ComboFix from the following location:

    Link

    * IMPORTANT !!! Place ComboFix.exe on your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.
    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

    ———————————————————————————————
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.

    ———————————————————————————————
    NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.

    =========================

    In your next post please provide the following:
    • AdwCleaner[R0].txt
    • ComboFix.txt

Well that all took awhile.  Adwcleaner hung, but It looks like we got some output.  Combofix hung too, several times.  I had to rename it before it would even load the last few times.  I forget how many times I ran it before it would go to completion.  The final time, it was saying to wait for the log to open, which it never did… and there isn't one at C:\Combofix.txt.  And this is kind of a pattern with this whatever it is…  as soon as a program wants to touch the disk, like editing a file, the machine comes to a halt.

 

Only after the combofix completed the machine seems OK surface-wise.  I'm making this post from the infected box, user Dad.  I haven't been able to do that since my first post.  Anyway, here is the AdwCleaner log.  We can remove anything that is even remotely suspicious.  Your call OCD.  Thanks.

 

# AdwCleaner v3.310 - Report created 24/09/2014 at 10:11:18
# Updated 12/09/2014 by Xplode
# Operating System : Windows Vista (TM) Home Basic Service Pack 2 (32 bits)
# Username : Dad - RACHIE
# Running from : C:\Users\Dad\Desktop\AdwCleaner.exe
# Option : Scan

***** [ Services ] *****


***** [ Files / Folders ] *****

File Found : C:\Program Files\Mozilla Firefox\browser\searchplugins\safeguard-secure-search.xml
File Found : C:\Users\Rachel\AppData\Roaming\Mozilla\Firefox\Profiles\6ajir0qc.default\searchplugins\ask-search.xml
Folder Found : C:\Program Files\Common Files\DVDVideoSoft\TB
Folder Found : C:\Users\Rachel\AppData\LocalLow\AVG SafeGuard toolbar
Folder Found : C:\Users\Rachel\AppData\Roaming\VOPackage

***** [ Scheduled Tasks ] *****

Task Found : MySearchDial

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Found : HKLM\SOFTWARE\Classes\AppID\{C292AD0A-C11F-479B-B8DB-743E72D283B0}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{408CFAD9-8F13-4747-8EC7-770A339C7237}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{07CAC314-E962-4F78-89AB-DD002F2490EE}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\5E8031606EB60A64C882918F8FF38DD4
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3152E1F19977892449DC968802CE8964
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
Key Found : HKLM\SOFTWARE\YourFileDownloader

***** [ Browsers ] *****

-\\ Internet Explorer v9.0.8112.16575


-\\ Mozilla Firefox v32.0.2 (x86 en-US)

[ File : C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\hwzfzqyy.default\prefs.js ]


[ File : C:\Users\Rachel\AppData\Roaming\Mozilla\Firefox\Profiles\6ajir0qc.default\prefs.js ]

Line Found : user_pref("extensions.helperbar.DockingPositionDown", false);
Line Found : user_pref("extensions.helperbar.Visibility", false);
Line Found : user_pref("extensions.helperbar.countryiso", "us");
Line Found : user_pref("extensions.helperbar.downloadprovider", "quickoc");
Line Found : user_pref("extensions.helperbar.installationid", "e616c65a-4dbe-3448-ea09-259a9bb59472");
Line Found : user_pref("extensions.helperbar.installdate", "13/10/2013");
Line Found : user_pref("extensions.helperbar.publisher", "quickoc");
Line Found : user_pref("extensions.irmysearch.aflt", "ir_14_10_FF");
Line Found : user_pref("extensions.irmysearch.cd", "2XzuyEtN2Y1L1QzutDtDtByDyCyEyEyC0F0CyDtCyD0FtCzztN0D0Tzu0SyBzyyBtN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyB0F0CtBtDyDyEtBtGzy0FtAzyt[…]
Line Found : user_pref("extensions.irmysearch.cr", "1285315362");
Line Found : user_pref("extensions.irmysearch.instlRef", "140305_a");
Line Found : user_pref("extensions.mysearchdial.cntry", "US");
Line Found : user_pref("extensions.mysearchdial.dpkLst", "3654782829,1334533236,1121012847,231756876,1895130307,603719297,4288797614,3754950497,426401714,3046281807,752626116,1657571787,3224935090,2597085128,18285[…]
Line Found : user_pref("extensions.mysearchdial.hdrMd5", "");
Line Found : user_pref("extensions.mysearchdial.lastB", "hxxps://www.google.com/");
Line Found : user_pref("extensions.mysearchdial.lastVrsnTs", "");
Line Found : user_pref("extensions.mysearchdial.pnu_base", "{\"newVrsn\":\"90\",\"lastVrsn\":\"90\",\"vrsnLoad\":\"\",\"showMsg\":\"false\",\"showSilent\":\"false\",\"msgTs\":0,\"lstMsgTs\":\"0\"}");
Line Found : user_pref("extensions.mysearchdial.sg", "{smplGrp}");

*************************

AdwCleaner[R0].txt - [4324 octets] - [24/09/2014 10:11:18]

########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [4384 octets] ##########
 

Hi calebsnake,

[external image: bullseye_zpse9eaf36e.gif] rkill

Do not reboot your computer after running rkill as the malware programs will start again.

Please download and run the following tool to help allow other programs to run. (courtesy of BleepingComputer.com)
There are 5 different versions. If one of them won't run then download and try to run the other one.
  • Windows XP : Double click on the icon to run it.
  • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
You only need to get one of them to run, not all of them.
  • rkill.exe
  • rkill.com
  • rkill.scr
  • WiNlOgOn.exe
  • uSeRiNiT.exe
Do not reboot your computer after running rkill as the malware programs will start again.

=========================

[external image: bullseye_zpse9eaf36e.gif] Rerun ComboFix

Refer to the ComboFix User's Guide
  • Rename it to calebsnake before saving it to your desktop.

    * IMPORTANT !!! Save the renamed ComboFix.exe (calebsnakeCF) to your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.
    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

    ———————————————————————————————
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.

    ———————————————————————————————
NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.

=========================

In your next post please provide the following:
  • Combofix.txt

Rkill found and stop two processes, but combofix hung at phase 9.  So I ran combofix in safe mode with networking and it completed.  Then I booted back into normal mode and ran rkill, and then combofix and it again completed.  Shortly afterwards, the machine froze again.  But at least I has have some combofix logs to show.

 

The first log is from the safe mode run.  The second log is from the normal boot, then rkill.

 

Safe Mode:

 

ComboFix 14-09-22.01 - Dad 09/25/2014   8:06.5.2 - x86 NETWORK
Microsoft® Windows Vista™ Home Basic   6.0.6002.2.1252.1.1033.18.3034.2514 [GMT -6:00]
Running from: c:\users\[removed]\Desktop\alloc.exe
AV: Microsoft Security Essentials *Disabled/Updated* {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}
SP: Microsoft Security Essentials *Disabled/Updated* {F4542E20-6399-F3B9-D5A7-4EE87964D00C}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((   Files Created from 2014-08-25 to 2014-09-25  )))))))))))))))))))))))))))))))
.
.
2014-09-25 14:13 . 2014-09-25 14:13    ——–    d—–w-    c:\users\Rachel\AppData\Local\temp
2014-09-25 14:13 . 2014-09-25 14:13    ——–    d—–w-    c:\users\Default\AppData\Local\temp
2014-09-25 14:04 . 2014-09-25 14:05    ——–    d—–w-    C:\alloc
2014-09-25 13:59 . 2014-09-25 13:59    ——–    d—–w-    C:\XomboFix
2014-09-24 22:43 . 2014-09-09 01:24    8806800    —-a-w-    c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6F76CC83-0EA8-43C0-B1C6-3738300A209B}\mpengine.dll
2014-09-24 21:32 . 2014-09-24 21:32    ——–    d—–w-    C:\found.003
2014-09-24 17:40 . 2014-09-24 17:40    ——–    d—–w-    C:\found.002
2014-09-24 16:10 . 2014-09-24 16:47    ——–    d—–w-    C:\AdwCleaner
2014-09-24 11:56 . 2014-09-24 11:56    ——–    d—–w-    C:\_OTL
2014-09-24 00:55 . 2014-09-24 00:55    ——–    d—–w-    C:\found.001
2014-09-23 21:33 . 2014-09-16 17:50    908840    ——w-    c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C6C8375B-AEFD-4E40-81C0-A6D48C48A455}\gapaengine.dll
2014-09-23 17:29 . 2014-09-24 21:53    ——–    d—–w-    c:\users\Dad
2014-09-22 23:56 . 2014-09-22 23:56    ——–    d—–w-    c:\program files\Common Files\Skype
2014-09-22 08:53 . 2014-09-09 01:24    8806800    —-a-w-    c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-09-11 11:16 . 2014-08-15 14:36    1427968    —-a-w-    c:\windows\system32\inetcpl.cpl
2014-09-04 12:50 . 2014-09-04 12:50    188304    —-a-w-    c:\program files\Internet Explorer\Plugins\nppdf32.dll
2014-08-30 15:43 . 2014-09-06 03:02    ——–    d—–w-    c:\users\Rachel\AppData\Roaming\VOPackage
2014-08-28 11:00 . 2014-08-22 23:26    2054656    —-a-w-    c:\windows\system32\win32k.sys
2014-08-28 11:00 . 2014-08-23 01:03    297984    —-a-w-    c:\windows\system32\gdi32.dll
2014-08-27 12:15 . 2014-08-27 12:15    ——–    d—–w-    c:\programdata\Avg_Update_0814tb
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-09-24 22:43 . 2013-01-09 15:46    701104    —-a-w-    c:\windows\system32\FlashPlayerApp.exe
2014-09-24 22:43 . 2011-05-30 22:10    71344    —-a-w-    c:\windows\system32\FlashPlayerCPLApp.cpl
2014-09-23 17:37 . 2014-07-07 23:29    110296    —-a-w-    c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-09-22 06:41 . 2009-10-06 22:32    231568    ——w-    c:\windows\system32\MpSigStub.exe
2014-09-16 17:50 . 2011-04-03 13:25    908840    ——w-    c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2014-07-18 00:05 . 2014-07-18 00:05    231800    —-a-w-    c:\windows\system32\drivers\MpFilter.sys
2014-07-18 00:05 . 2010-10-25 03:25    95920    —-a-w-    c:\windows\system32\drivers\NisDrvWFP.sys
2014-07-08 00:46 . 2014-08-15 20:11    2048    —-a-w-    c:\windows\system32\tzres.dll
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2014-08-08 16:34    579400    —-a-w-    c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2014-08-08 16:34    579400    —-a-w-    c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2014-08-08 16:34    579400    —-a-w-    c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2014-08-08 16:34    579400    —-a-w-    c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2014-08-08 16:34    579400    —-a-w-    c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2014-08-08 16:34    579400    —-a-w-    c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-06-03 206064]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2014-08-22 974432]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2014-08-21 959176]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2009-03-31 483428]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-12-14 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21    548352    —-a-w-    c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2009-07-27 22:50    10536    —-a-w-    c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=c:\windows\pss\Kodak EasyShare software.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^Users^Rachel^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dell Dock.lnk]
path=c:\users\Rachel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk
backup=c:\windows\pss\Dell Dock.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2014-08-21 16:30    959176    —-a-w-    c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe [BU]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ajoweget]
c:\users\Rachel\AppData\Local\orakugomukedom.dll [BU]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
2009-03-31 14:18    217088    —-a-w-    c:\program files\DellTPad\Apoint.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcSoft Connection Service]
c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [BU]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BrMfcWnd]
2008-05-29 18:49    1085440    ——w-    c:\program files\Brother\Brmfcmon\BrMfcWnd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Broadcom Wireless Manager UI]
2008-12-21 18:34    3810304    —-a-w-    c:\windows\System32\WLTRAY.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ControlCenter3]
2007-12-21 23:57    86016    ——w-    c:\program files\Brother\ControlCenter3\BrCtrCen.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell Webcam Central]
2009-01-09 18:49    405639    ——w-    c:\program files\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dellsupportcenter]
2009-06-03 19:46    206064    —-a-w-    c:\program files\Dell Support Center\bin\sprtcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2009-03-31 16:55    173592    —-a-w-    c:\windows\System32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
2008-05-07 22:41    178712    —-a-w-    c:\program files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2009-03-31 16:55    141848    —-a-w-    c:\windows\System32\igfxtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndexSearch]
2007-10-12 01:01    46368    —-a-w-    c:\program files\ScanSoft\PaperPort\IndexSearch.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-12-14 00:16    421160    —-a-w-    c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware (reboot)]
c:\program files\Malwarebytes' Anti-Malware\mbam.exe [BU]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Default Manager]
2009-04-24 16:05    250192    —-a-w-    c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSC]
2014-08-22 18:41    974432    —-a-w-    c:\program files\Microsoft Security Client\msseces.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PaperPort PTD]
2007-10-12 01:03    29984    —-a-w-    c:\program files\ScanSoft\PaperPort\pptd40nt.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVDDXSrv]
2009-02-05 02:26    128232    ——w-    c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
2009-03-31 16:55    150552    —-a-w-    c:\windows\System32\igfxpers.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PPort11reminder]
2007-08-31 15:01    328992    —-a-w-    c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickSet]
2009-03-26 23:26    1735760    —-a-w-    c:\program files\Dell\QuickSet\quickset.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-30 00:38    421888    —-a-w-    c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2009-04-11 06:28    1233920    —-a-w-    c:\program files\Windows Sidebar\sidebar.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
2006-10-25 15:03    210472    —-a-w-    c:\program files\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2011-12-14 15:04    4617600    —-a-w-    c:\program files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SysTrayApp]
2009-03-31 15:00    483428    —-a-w-    c:\program files\IDT\WDM\sttray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2008-01-21 02:35    202240    —-a-w-    c:\program files\Windows Media Player\wmpnscfg.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiSpywareOverride"=dword:00000001
.
R2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\aestsrv.exe [2009-03-31 81920]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [2011-12-14 116608]
.
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - ECACHE
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork    REG_MULTI_SZ       PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation    REG_MULTI_SZ       FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2014-09-25 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-01-09 22:43]
.
2014-09-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-10-23 16:10]
.
2014-09-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-10-23 16:10]
.
2014-09-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3176256395-2519655851-1769987202-1000Core.job
- c:\users\Rachel\AppData\Local\Google\Update\GoogleUpdate.exe [2014-08-23 20:06]
.
2014-09-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3176256395-2519655851-1769987202-1000UA.job
- c:\users\Rachel\AppData\Local\Google\Update\GoogleUpdate.exe [2014-08-23 20:06]
.
.
——- Supplementary Scan ——-
.
mStart Page = hxxp://www.google.com
TCP: DhcpNameServer = 75.75.75.75 75.75.76.76 192.168.1.1
FF - ProfilePath - c:\users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\hwzfzqyy.default\
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-Uninstall_is1 - c:\program files\Common Files\DVDVideoSoft\unins000.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2014-09-25 08:13
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …  
.
scanning hidden autostart entries …
.
scanning hidden files …  
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2014-09-25  08:14:57
ComboFix-quarantined-files.txt  2014-09-25 14:14
.
Pre-Run: 181,200,158,720 bytes free
Post-Run: 181,110,759,424 bytes free
.
- - End Of File - - 877BC9AADAC2A10859EB4C7147CB405A
CDB4DE4BBD714F152979DA2DCBEF57EB
 

 

 

 

 

 

Normal mode w/Rkill:
 

ComboFix 14-09-22.01 - Dad 09/25/2014   8:24.5.2 - x86
Microsoft® Windows Vista™ Home Basic   6.0.6002.2.1252.1.1033.18.3034.2031 [GMT -6:00]
Running from: c:\users\[removed]\Desktop\alloc.exe
AV: Microsoft Security Essentials *Disabled/Updated* {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}
SP: Microsoft Security Essentials *Disabled/Updated* {F4542E20-6399-F3B9-D5A7-4EE87964D00C}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((   Files Created from 2014-08-25 to 2014-09-25  )))))))))))))))))))))))))))))))
.
.
2014-09-25 14:31 . 2014-09-25 14:31    ——–    d—–w-    c:\users\TEMP\AppData\Local\temp
2014-09-25 14:31 . 2014-09-25 14:31    ——–    d—–w-    c:\users\Rachel\AppData\Local\temp
2014-09-25 14:31 . 2014-09-25 14:31    ——–    d—–w-    c:\users\Default\AppData\Local\temp
2014-09-25 14:04 . 2014-09-25 14:05    ——–    d—–w-    C:\alloc
2014-09-25 13:59 . 2014-09-25 13:59    ——–    d—–w-    C:\XomboFix
2014-09-24 22:43 . 2014-09-09 01:24    8806800    —-a-w-    c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6F76CC83-0EA8-43C0-B1C6-3738300A209B}\mpengine.dll
2014-09-24 21:32 . 2014-09-24 21:32    ——–    d—–w-    C:\found.003
2014-09-24 17:40 . 2014-09-24 17:40    ——–    d—–w-    C:\found.002
2014-09-24 16:10 . 2014-09-24 16:47    ——–    d—–w-    C:\AdwCleaner
2014-09-24 11:56 . 2014-09-24 11:56    ——–    d—–w-    C:\_OTL
2014-09-24 00:55 . 2014-09-24 00:55    ——–    d—–w-    C:\found.001
2014-09-23 21:33 . 2014-09-16 17:50    908840    ——w-    c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C6C8375B-AEFD-4E40-81C0-A6D48C48A455}\gapaengine.dll
2014-09-23 17:29 . 2014-09-24 21:53    ——–    d—–w-    c:\users\Dad
2014-09-22 23:56 . 2014-09-22 23:56    ——–    d—–w-    c:\program files\Common Files\Skype
2014-09-22 08:53 . 2014-09-09 01:24    8806800    —-a-w-    c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-09-11 11:16 . 2014-08-15 14:36    1427968    —-a-w-    c:\windows\system32\inetcpl.cpl
2014-09-04 12:50 . 2014-09-04 12:50    188304    —-a-w-    c:\program files\Internet Explorer\Plugins\nppdf32.dll
2014-08-30 15:43 . 2014-09-06 03:02    ——–    d—–w-    c:\users\Rachel\AppData\Roaming\VOPackage
2014-08-28 11:00 . 2014-08-22 23:26    2054656    —-a-w-    c:\windows\system32\win32k.sys
2014-08-28 11:00 . 2014-08-23 01:03    297984    —-a-w-    c:\windows\system32\gdi32.dll
2014-08-27 12:15 . 2014-08-27 12:15    ——–    d—–w-    c:\programdata\Avg_Update_0814tb
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-09-24 22:43 . 2013-01-09 15:46    701104    —-a-w-    c:\windows\system32\FlashPlayerApp.exe
2014-09-24 22:43 . 2011-05-30 22:10    71344    —-a-w-    c:\windows\system32\FlashPlayerCPLApp.cpl
2014-09-23 17:37 . 2014-07-07 23:29    110296    —-a-w-    c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-09-22 06:41 . 2009-10-06 22:32    231568    ——w-    c:\windows\system32\MpSigStub.exe
2014-09-16 17:50 . 2011-04-03 13:25    908840    ——w-    c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2014-07-18 00:05 . 2014-07-18 00:05    231800    —-a-w-    c:\windows\system32\drivers\MpFilter.sys
2014-07-18 00:05 . 2010-10-25 03:25    95920    —-a-w-    c:\windows\system32\drivers\NisDrvWFP.sys
2014-07-08 00:46 . 2014-08-15 20:11    2048    —-a-w-    c:\windows\system32\tzres.dll
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2014-08-08 16:34    579400    —-a-w-    c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2014-08-08 16:34    579400    —-a-w-    c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2014-08-08 16:34    579400    —-a-w-    c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2014-08-08 16:34    579400    —-a-w-    c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2014-08-08 16:34    579400    —-a-w-    c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2014-08-08 16:34    579400    —-a-w-    c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-06-03 206064]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2014-08-22 974432]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2014-08-21 959176]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2009-03-31 483428]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-12-14 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21    548352    —-a-w-    c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2009-07-27 22:50    10536    —-a-w-    c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=c:\windows\pss\Kodak EasyShare software.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^Users^Rachel^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dell Dock.lnk]
path=c:\users\Rachel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk
backup=c:\windows\pss\Dell Dock.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2014-08-21 16:30    959176    —-a-w-    c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe [BU]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ajoweget]
c:\users\Rachel\AppData\Local\orakugomukedom.dll [BU]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
2009-03-31 14:18    217088    —-a-w-    c:\program files\DellTPad\Apoint.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcSoft Connection Service]
c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [BU]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BrMfcWnd]
2008-05-29 18:49    1085440    ——w-    c:\program files\Brother\Brmfcmon\BrMfcWnd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Broadcom Wireless Manager UI]
2008-12-21 18:34    3810304    —-a-w-    c:\windows\System32\WLTRAY.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ControlCenter3]
2007-12-21 23:57    86016    ——w-    c:\program files\Brother\ControlCenter3\BrCtrCen.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell Webcam Central]
2009-01-09 18:49    405639    ——w-    c:\program files\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dellsupportcenter]
2009-06-03 19:46    206064    —-a-w-    c:\program files\Dell Support Center\bin\sprtcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2009-03-31 16:55    173592    —-a-w-    c:\windows\System32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
2008-05-07 22:41    178712    —-a-w-    c:\program files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2009-03-31 16:55    141848    —-a-w-    c:\windows\System32\igfxtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndexSearch]
2007-10-12 01:01    46368    —-a-w-    c:\program files\ScanSoft\PaperPort\IndexSearch.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-12-14 00:16    421160    —-a-w-    c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware (reboot)]
c:\program files\Malwarebytes' Anti-Malware\mbam.exe [BU]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Default Manager]
2009-04-24 16:05    250192    —-a-w-    c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSC]
2014-08-22 18:41    974432    —-a-w-    c:\program files\Microsoft Security Client\msseces.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PaperPort PTD]
2007-10-12 01:03    29984    —-a-w-    c:\program files\ScanSoft\PaperPort\pptd40nt.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVDDXSrv]
2009-02-05 02:26    128232    ——w-    c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
2009-03-31 16:55    150552    —-a-w-    c:\windows\System32\igfxpers.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PPort11reminder]
2007-08-31 15:01    328992    —-a-w-    c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickSet]
2009-03-26 23:26    1735760    —-a-w-    c:\program files\Dell\QuickSet\quickset.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-30 00:38    421888    —-a-w-    c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2009-04-11 06:28    1233920    —-a-w-    c:\program files\Windows Sidebar\sidebar.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
2006-10-25 15:03    210472    —-a-w-    c:\program files\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2011-12-14 15:04    4617600    —-a-w-    c:\program files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SysTrayApp]
2009-03-31 15:00    483428    —-a-w-    c:\program files\IDT\WDM\sttray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2008-01-21 02:35    202240    —-a-w-    c:\program files\Windows Media Player\wmpnscfg.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiSpywareOverride"=dword:00000001
.
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [2011-12-14 116608]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\aestsrv.exe [2009-03-31 81920]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork    REG_MULTI_SZ       PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation    REG_MULTI_SZ       FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2014-09-25 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-01-09 22:43]
.
2014-09-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-10-23 16:10]
.
2014-09-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-10-23 16:10]
.
2014-09-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3176256395-2519655851-1769987202-1000Core.job
- c:\users\Rachel\AppData\Local\Google\Update\GoogleUpdate.exe [2014-08-23 20:06]
.
2014-09-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3176256395-2519655851-1769987202-1000UA.job
- c:\users\Rachel\AppData\Local\Google\Update\GoogleUpdate.exe [2014-08-23 20:06]
.
.
——- Supplementary Scan ——-
.
mStart Page = hxxp://www.google.com
TCP: DhcpNameServer = 75.75.75.75 75.75.76.76 192.168.1.1
FF - ProfilePath - c:\users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\hwzfzqyy.default\
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2014-09-25 08:31
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …  
.
scanning hidden autostart entries …
.
scanning hidden files …  
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2014-09-25  08:33:35
ComboFix-quarantined-files.txt  2014-09-25 14:33
ComboFix2.txt  2014-09-25 14:14
.
Pre-Run: 178,022,232,064 bytes free
Post-Run: 177,975,988,224 bytes free
.
- - End Of File - - E2F6A2256F6BFACBF5EB6094EF47A8B5
CDB4DE4BBD714F152979DA2DCBEF57EB
 

Hi calebsnake,

Do you recall when you first started noticing the issues you have been encountering? Any change is software or hardware around that time?

If you cannot get these tools to run, go ahead and try them in Safe Mode.

[external image: bullseye_zpse9eaf36e.gif] Re- run AdwCleaner

It should be on your desktop
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • Click on the Scan button.
  • AdwCleaner will begin to scan your computer like it did before.
  • After the scan has finished…
  • This time, click on the Clean button.
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
  • After rebooting, a log file report (AdwCleaner[S0].txt) will open automatically.
  • Copy and paste the contents of that log file in your next reply.
  • A copy of that log file will also be saved in the C:\AdwCleaner folder.
=========================

[external image: bullseye_zpse9eaf36e.gif] Junkware Removal Tool

Download Junkware Removal Tool to your desktop.
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • Shut down your protection software now to avoid potential conflicts.
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
=========================

[external image: bullseye_zpse9eaf36e.gif] Download Farbar Recovery Scan Tool and save to your desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
  • Right click and select "Run as Administrator" to run it. When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply
=========================

In your next post please provide the following:
  • AdwCleaner[S0].txt
  • JRT.txt
  • FRST.txt
  • Don't post the Addition.txt, but hold onto it.

Hi OCD, Thanks,

 

My daughter says no about recent hardware or software.  But she has had that AVG tool bar that you didn't like for quite some time.  Some other questionable stuff from time to time that I have maybe only partially removed.  She is the "machine gets infected" one in the family, although I don't believe she'd download pirated software intentionally.

 

Getting on the internet seems to freeze up her machine more quickly I noticed and thought I'd mention.  Here are the scans:

 

adwCleaner

 

# AdwCleaner v3.310 - Report created 25/09/2014 at 20:21:10
# Updated 12/09/2014 by Xplode
# Operating System : Windows Vista (TM) Home Basic Service Pack 2 (32 bits)
# Username : Dad - RACHIE
# Running from : C:\Users\Dad\Desktop\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\Program Files\Common Files\DVDVideoSoft\TB
Folder Deleted : C:\Users\Rachel\AppData\LocalLow\AVG SafeGuard toolbar
Folder Deleted : C:\Users\Rachel\AppData\Roaming\VOPackage
File Deleted : C:\Users\Rachel\AppData\Roaming\Mozilla\Firefox\Profiles\6ajir0qc.default\searchplugins\ask-search.xml
File Deleted : C:\Program Files\Mozilla Firefox\browser\searchplugins\safeguard-secure-search.xml

***** [ Scheduled Tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C292AD0A-C11F-479B-B8DB-743E72D283B0}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{408CFAD9-8F13-4747-8EC7-770A339C7237}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{07CAC314-E962-4F78-89AB-DD002F2490EE}
Key Deleted : HKLM\SOFTWARE\YourFileDownloader
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3152E1F19977892449DC968802CE8964
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\5E8031606EB60A64C882918F8FF38DD4

***** [ Browsers ] *****

-\\ Internet Explorer v9.0.8112.16575


-\\ Mozilla Firefox v32.0.2 (x86 en-US)

[ File : C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\hwzfzqyy.default\prefs.js ]


[ File : C:\Users\Rachel\AppData\Roaming\Mozilla\Firefox\Profiles\6ajir0qc.default\prefs.js ]

Line Deleted : user_pref("extensions.helperbar.DockingPositionDown", false);
Line Deleted : user_pref("extensions.helperbar.Visibility", false);
Line Deleted : user_pref("extensions.helperbar.countryiso", "us");
Line Deleted : user_pref("extensions.helperbar.downloadprovider", "quickoc");
Line Deleted : user_pref("extensions.helperbar.installationid", "e616c65a-4dbe-3448-ea09-259a9bb59472");
Line Deleted : user_pref("extensions.helperbar.installdate", "13/10/2013");
Line Deleted : user_pref("extensions.helperbar.publisher", "quickoc");
Line Deleted : user_pref("extensions.irmysearch.aflt", "ir_14_10_FF");
Line Deleted : user_pref("extensions.irmysearch.cd", "2XzuyEtN2Y1L1QzutDtDtByDyCyEyEyC0F0CyDtCyD0FtCzztN0D0Tzu0SyBzyyBtN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyB0F0CtBtDyDyEtBtGzy0FtAzyt[…]
Line Deleted : user_pref("extensions.irmysearch.cr", "1285315362");
Line Deleted : user_pref("extensions.irmysearch.instlRef", "140305_a");
Line Deleted : user_pref("extensions.mysearchdial.cntry", "US");
Line Deleted : user_pref("extensions.mysearchdial.dpkLst", "3654782829,1334533236,1121012847,231756876,1895130307,603719297,4288797614,3754950497,426401714,3046281807,752626116,1657571787,3224935090,2597085128,18285[…]
Line Deleted : user_pref("extensions.mysearchdial.hdrMd5", "");
Line Deleted : user_pref("extensions.mysearchdial.lastB", "hxxps://www.google.com/");
Line Deleted : user_pref("extensions.mysearchdial.lastVrsnTs", "");
Line Deleted : user_pref("extensions.mysearchdial.pnu_base", "{\"newVrsn\":\"90\",\"lastVrsn\":\"90\",\"vrsnLoad\":\"\",\"showMsg\":\"false\",\"showSilent\":\"false\",\"msgTs\":0,\"lstMsgTs\":\"0\"}");
Line Deleted : user_pref("extensions.mysearchdial.sg", "{smplGrp}");

*************************

AdwCleaner[R0].txt - [4464 octets] - [24/09/2014 10:11:18]
AdwCleaner[R1].txt - [4444 octets] - [25/09/2014 20:19:19]
AdwCleaner[S0].txt - [4414 octets] - [25/09/2014 20:21:10]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4474 octets] ##########
 

 

 

 

 

JRT

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.2.0 (09.22.2014:1)
OS: Windows Vista (TM) Home Basic x86
Ran by [removed] on Thu 09/25/2014 at 21:07:44.43
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\update mega browse
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\util mega browse



~~~ Files



~~~ Folders



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Thu 09/25/2014 at 21:09:11.19
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 

 

 

 

FRST

 

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 26-09-2014
Ran by [removed] (administrator) on RACHIE on 25-09-2014 21:19:18
Running from C:\Users\[removed]\Desktop
[removed] Platform: Microsoft® Windows Vistaâ„¢ Home Basic  Service Pack 2 (X86) OS Language: English (United States)
Internet Explorer Version 9
Boot Mode: Safe Mode (with Networking)
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\…\Run: [dellsupportcenter] => C:\Program Files\Dell Support Center\bin\sprtcmd.exe [206064 2009-06-03] (SupportSoft, Inc.)
HKLM\…\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [974432 2014-08-22] (Microsoft Corporation)
HKLM\…\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM\…\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray.exe [483428 2009-03-31] (IDT, Inc.)
Winlogon\Notify\!SASWinLogon: C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
Winlogon\Notify\GoToAssist: C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
ShellIconOverlayIdentifiers: GDriveBlacklistedOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google)
ShellIconOverlayIdentifiers: GDriveSharedEditOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google)
ShellIconOverlayIdentifiers: GDriveSharedOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google)
ShellIconOverlayIdentifiers: GDriveSharedViewOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google)
ShellIconOverlayIdentifiers: GDriveSyncedOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google)
ShellIconOverlayIdentifiers: GDriveSyncingOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/USCON/1
BHO: PasswordBox Helper -> {5DB69B97-934B-451D-94DB-32EF802A01CD} -> C:\Program Files\PasswordBox\Application\pbbtn.dll (PasswordBox, Inc.)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
ShellExecuteHooks: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [113024 2011-12-14] (SuperAdBlocker.com)
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\hwzfzqyy.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @java.com/DTPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=14.0.8051.1204 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\McSiteAdvisor.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\safeguard-secure-search.xml
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-09-25]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-09-25]
FF HKLM\…\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-04-11]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\PasswordBox\Firefox
FF Extension: PasswordBox - C:\Program Files\PasswordBox\Firefox [2013-11-21]

Chrome:
=======

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [116608 2011-12-14] (SUPERAntiSpyware.com) [File not signed]
S2 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\aestsrv.exe [81920 2009-03-31] (Andrea Electronics Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22192 2014-08-22] (Microsoft Corporation)
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [288120 2014-08-22] (Microsoft Corporation)
S2 PasswordBox; C:\Program Files\PasswordBox\pbbtnService.exe [67584 2014-05-14] (PasswordBox, Inc.) [File not signed]
S2 Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3275136 2013-10-09] (Skype Technologies S.A.)
S2 sprtsvc_DellSupportCenter; C:\Program Files\Dell Support Center\bin\sprtsvc.exe [201968 2009-06-03] (SupportSoft, Inc.)
S2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\STacSV.exe [254042 2009-03-31] (IDT, Inc.)
S2 wltrysvc; C:\Windows\System32\bcmwltry.exe [2809856 2008-12-21] (Dell Inc.) [File not signed]
S3 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [X]
S2 yksvc; RUNDLL32.EXE ykx32coinst,serviceStartProc [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 BCM42RLY; C:\Windows\System32\drivers\BCM42RLY.sys [18424 2008-12-21] (Broadcom Corporation)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [110296 2014-09-23] (Malwarebytes Corporation)
S0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [231800 2014-07-17] (Microsoft Corporation)
S1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-12-14] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-12-14] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-20] (Microsoft Corporation)
S3 catchme; \??\C:\Users\Dad\AppData\Local\Temp\catchme.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S1 MpKsl7af8a1f9; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{43A7FBC9-5392-4C53-A540-8A0BF8C5444D}\MpKsl7af8a1f9.sys [X]
S1 MpKsla6af8de8; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{43A7FBC9-5392-4C53-A540-8A0BF8C5444D}\MpKsla6af8de8.sys [X]
S1 MpKslaf92ad89; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{43A7FBC9-5392-4C53-A540-8A0BF8C5444D}\MpKslaf92ad89.sys [X]
S1 MpKslf721a017; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{43A7FBC9-5392-4C53-A540-8A0BF8C5444D}\MpKslf721a017.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]

==================== NetSvcs (Whitelisted) ===================


(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-09-25 21:19 - 2014-09-25 21:20 - 00011808 _____ () C:\Users\Dad\Desktop\FRST.txt
2014-09-25 21:19 - 2014-09-25 21:19 - 00000000 ____D () C:\FRST
2014-09-25 21:18 - 2014-09-25 21:18 - 01100288 _____ (Farbar) C:\Users\Dad\Downloads\FRST.exe
2014-09-25 21:18 - 2014-09-25 21:18 - 01100288 _____ (Farbar) C:\Users\Dad\Desktop\FRST.exe
2014-09-25 21:16 - 2014-09-25 21:16 - 02108928 _____ (Farbar) C:\Users\Dad\Downloads\FRST64.exe
2014-09-25 21:09 - 2014-09-25 21:09 - 00000900 _____ () C:\Users\Dad\Desktop\JRT.txt
2014-09-25 21:06 - 2014-09-25 21:06 - 00024764 _____ () C:\Users\Dad\Desktop\nN4KnGh4.htm
2014-09-25 21:05 - 2014-09-25 21:05 - 01024790 _____ (Thisisu) C:\Users\Dad\Desktop\JRT.exe
2014-09-25 20:55 - 2014-09-25 20:55 - 00016143 _____ () C:\ComboFix.txt
2014-09-25 08:48 - 2014-09-25 08:48 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-09-25 08:04 - 2014-09-25 08:05 - 00000000 ____D () C:\alloc
2014-09-25 08:04 - 2014-09-25 08:04 - 05579290 ____R (Swearware) C:\Users\Dad\Desktop\alloc.exe
2014-09-25 07:59 - 2014-09-25 07:59 - 00000000 ____D () C:\XomboFix
2014-09-25 07:42 - 2014-09-25 06:04 - 01944824 _____ (Bleeping Computer, LLC) C:\Users\Dad\Desktop\rkill.scr
2014-09-25 06:07 - 2014-09-25 21:10 - 00001458 _____ () C:\Users\Dad\Desktop\Rkill.txt
2014-09-25 06:06 - 2014-09-25 06:04 - 01944824 _____ (Bleeping Computer, LLC) C:\Users\Dad\Desktop\uSeRiNiT.exe
2014-09-24 15:32 - 2014-09-24 15:32 - 00000000 ____D () C:\found.003
2014-09-24 12:06 - 2014-09-25 20:40 - 05580995 ____R (Swearware) C:\Users\Dad\Desktop\ComboFix2.exe
2014-09-24 11:40 - 2014-09-24 11:40 - 00000000 ____D () C:\found.002
2014-09-24 10:49 - 2014-09-25 20:55 - 00000000 ____D () C:\Qoobox
2014-09-24 10:49 - 2011-06-26 00:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-09-24 10:49 - 2010-11-07 11:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-09-24 10:49 - 2009-04-19 22:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-09-24 10:49 - 2000-08-30 18:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-09-24 10:49 - 2000-08-30 18:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-09-24 10:49 - 2000-08-30 18:00 - 00098816 _____ () C:\Windows\sed.exe
2014-09-24 10:49 - 2000-08-30 18:00 - 00080412 _____ () C:\Windows\grep.exe
2014-09-24 10:49 - 2000-08-30 18:00 - 00068096 _____ () C:\Windows\zip.exe
2014-09-24 10:48 - 2014-09-24 16:09 - 00000000 ____D () C:\Windows\erdnt
2014-09-24 10:10 - 2014-09-25 20:21 - 00000000 ____D () C:\AdwCleaner
2014-09-24 10:10 - 2014-09-24 10:10 - 05579290 ____R (Swearware) C:\Users\Dad\Desktop\XomboFix.exe
2014-09-24 10:10 - 2014-09-24 10:10 - 05579290 _____ (Swearware) C:\Users\Dad\Downloads\ComboFix.exe
2014-09-24 10:09 - 2014-09-24 10:02 - 01373475 _____ () C:\Users\Dad\Desktop\AdwCleaner.exe
2014-09-24 08:37 - 2014-09-24 08:37 - 00000000 ____D () C:\Users\Dad\AppData\Local\Adobe
2014-09-24 08:34 - 2014-09-24 08:34 - 00004096 ____H () C:\Users\Dad\Desktop\.OTLFix.txt.txt.swp
2014-09-24 08:28 - 2014-09-24 08:28 - 00012288 ____H () C:\Users\Dad\Desktop\.post.txt.txt.swp
2014-09-24 08:26 - 2014-09-24 08:28 - 00000138 _____ () C:\Users\Dad\Desktop\post.txt.txt
2014-09-24 08:10 - 2014-09-24 08:10 - 00063982 _____ () C:\Users\Dad\Desktop\OTL.Txt
2014-09-24 07:58 - 2014-09-24 07:58 - 00143728 _____ () C:\Windows\Minidump\Mini092414-02.dmp
2014-09-24 07:56 - 2014-09-24 15:53 - 00002109 _____ () C:\Users\Dad\_viminfo
2014-09-24 07:56 - 2014-09-24 07:56 - 00012288 ____H () C:\Users\Dad\Desktop\.aswMBR.txt.swp
2014-09-24 07:55 - 2014-09-24 07:55 - 00000512 _____ () C:\Users\Dad\Desktop\MBR.dat
2014-09-24 07:28 - 2014-09-24 07:28 - 00143728 _____ () C:\Windows\Minidump\Mini092414-01.dmp
2014-09-24 07:24 - 2014-09-24 07:55 - 00002133 _____ () C:\Users\Dad\Desktop\aswMBR.txt
2014-09-24 06:53 - 2014-09-24 06:53 - 05185536 _____ (AVAST Software) C:\Users\Dad\Desktop\aswMBR.exe
2014-09-24 06:50 - 2014-09-24 06:50 - 00001109 _____ () C:\Users\Dad\Desktop\checkup.txt
2014-09-24 06:26 - 2014-09-24 06:24 - 00854417 _____ () C:\Users\Dad\Desktop\SecurityCheck.exe
2014-09-24 06:24 - 2014-09-24 06:24 - 00854417 _____ () C:\Users\Dad\Downloads\SecurityCheck.exe
2014-09-24 06:23 - 2014-09-24 06:24 - 00005004 _____ () C:\Users\Dad\Desktop\OTLFix.txt.txt
2014-09-24 05:56 - 2014-09-24 05:56 - 00000000 ____D () C:\_OTL
2014-09-23 18:55 - 2014-09-23 18:55 - 00000000 ____D () C:\found.001
2014-09-23 14:32 - 2014-09-24 08:37 - 00000000 ____D () C:\Users\Dad\AppData\Roaming\Adobe
2014-09-23 14:32 - 2014-09-23 14:32 - 00000000 ____D () C:\Users\Dad\AppData\Roaming\Macromedia
2014-09-23 14:32 - 2014-09-23 14:32 - 00000000 ____D () C:\Users\Dad\AppData\Local\Macromedia
2014-09-23 13:58 - 2014-09-23 13:58 - 00602112 _____ (OldTimer Tools) C:\Users\Dad\Desktop\OTL.exe
2014-09-23 12:36 - 2014-09-23 12:36 - 00602112 _____ (OldTimer Tools) C:\Users\Rachel\Downloads\OTL.exe
2014-09-23 12:36 - 2014-09-23 12:36 - 00602112 _____ (OldTimer Tools) C:\Users\Rachel\Downloads\59D9.tmp
2014-09-23 11:42 - 2014-09-23 11:43 - 00000000 ____D () C:\Users\Dad\AppData\Roaming\Mozilla
2014-09-23 11:42 - 2014-09-23 11:42 - 00000000 ____D () C:\Users\Dad\AppData\Local\Mozilla
2014-09-23 11:31 - 2014-09-23 11:31 - 00070640 _____ () C:\Users\Dad\AppData\Local\GDIPFONTCACHEV1.DAT
2014-09-23 11:30 - 2014-09-23 13:54 - 00000906 _____ () C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2014-09-23 11:30 - 2014-09-23 11:30 - 00000911 _____ () C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-09-23 11:30 - 2014-09-23 11:30 - 00000000 ____D () C:\Users\Dad\AppData\Local\SupportSoft
2014-09-23 11:29 - 2014-09-24 15:53 - 00000000 ____D () C:\Users\Dad
2014-09-23 11:29 - 2014-09-23 11:29 - 00000877 _____ () C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
2014-09-23 11:29 - 2014-09-23 11:29 - 00000020 ___SH () C:\Users\Dad\ntuser.ini
2014-09-23 11:29 - 2014-09-23 11:29 - 00000000 ____D () C:\Users\Dad\AppData\Local\VirtualStore
2014-09-23 11:29 - 2012-10-31 23:16 - 00000000 ____D () C:\Users\Dad\AppData\LocalGoogle
2014-09-23 11:29 - 2012-10-31 23:16 - 00000000 ____D () C:\Users\Dad\AppData\Local\Google
2014-09-23 11:29 - 2011-04-04 05:04 - 00000000 ____D () C:\Users\Dad\AppData\Local\Microsoft Help
2014-09-23 11:29 - 2009-07-27 17:09 - 00000000 ____D () C:\Users\Dad\AppData\Local\SoftThinks
2014-09-23 11:29 - 2008-01-20 20:56 - 00000000 ___RD () C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-09-23 11:29 - 2008-01-20 20:56 - 00000000 ___RD () C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-09-22 17:56 - 2014-09-25 18:31 - 00002337 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-09-22 17:56 - 2014-09-22 17:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-09-22 17:56 - 2014-09-22 17:56 - 00000000 ____D () C:\Program Files\Common Files\Skype
2014-09-20 16:12 - 2014-09-20 16:12 - 07665103 _____ () C:\Users\Rachel\Downloads\hum 1st lecture (compressed) (1).pptx
2014-09-19 15:53 - 2014-09-19 15:53 - 00000672 _____ () C:\Users\Public\Desktop\Toontown Rewritten.lnk
2014-09-19 15:52 - 2014-09-19 15:52 - 08682361 _____ (The TTR Team) C:\Users\Rachel\Downloads\TTRBetaInstaller-v1.1.3.exe
2014-09-12 19:01 - 2014-09-12 19:01 - 07665103 _____ () C:\Users\Rachel\Downloads\hum 1st lecture (compressed).pptx
2014-09-11 05:17 - 2014-08-15 08:42 - 01810432 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-09-11 05:17 - 2014-08-15 08:37 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-09-11 05:17 - 2014-08-15 08:35 - 01802240 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-09-11 05:17 - 2014-08-15 08:35 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-09-11 05:17 - 2014-08-15 08:35 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-09-11 05:17 - 2014-08-15 08:35 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-09-11 05:17 - 2014-08-15 08:35 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-09-11 05:17 - 2014-08-15 08:35 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-09-11 05:17 - 2014-08-15 08:35 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-09-11 05:17 - 2014-08-15 08:35 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-09-11 05:17 - 2014-08-15 08:35 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-09-11 05:17 - 2014-08-15 08:35 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-09-11 05:17 - 2014-08-15 08:34 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-09-11 05:17 - 2014-08-15 08:34 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-09-11 05:17 - 2014-08-15 08:34 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-09-11 05:17 - 2014-08-15 08:34 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-09-11 05:17 - 2014-08-15 08:34 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-09-11 05:16 - 2014-08-15 08:51 - 12363264 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-09-11 05:16 - 2014-08-15 08:42 - 09739776 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-09-11 05:16 - 2014-08-15 08:37 - 01137664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-09-11 05:16 - 2014-08-15 08:36 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-09-04 18:49 - 2014-09-04 18:49 - 13680323 _____ () C:\Users\Rachel\Downloads\Green_Action_fund_photos.zip
2014-09-01 11:00 - 2014-09-01 11:01 - 00057344 _____ () C:\Users\Rachel\Downloads\JTA-Instructor List Fall 2014 v.3.xls
2014-08-30 09:41 - 2014-08-30 09:42 - 02592136 _____ (http://yourfiledownloader.net) C:\Users\Rachel\Downloads\An_Introduction_to_Book_History_pdf_epub_zip_downloader.exe
2014-08-30 09:40 - 2014-08-30 09:40 - 00001772 _____ () C:\Users\Rachel\Downloads\[kickass.to]david.finkelstein.introduction.to.book.history.2005.torrent
2014-08-28 22:09 - 2014-08-28 22:21 - 00000002 _____ () C:\Users\Rachel\Documents\Succession-2.txt
2014-08-28 05:00 - 2014-08-22 19:03 - 00297984 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-28 05:00 - 2014-08-22 17:26 - 02054656 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-27 06:15 - 2014-08-27 06:15 - 00000000 ____D () C:\ProgramData\Avg_Update_0814tb
2014-08-26 22:33 - 2014-08-26 22:34 - 05921280 _____ () C:\Users\Rachel\Downloads\GES3050.Lec01.ppt
2014-08-26 21:53 - 2014-08-26 21:53 - 00929130 _____ () C:\Users\Rachel\Downloads\olkowski slides(1).zip

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-09-25 21:13 - 2009-07-27 11:23 - 01230128 _____ () C:\Windows\WindowsUpdate.log
2014-09-25 21:02 - 2008-01-20 21:02 - 01001028 _____ () C:\Windows\PFRO.log
2014-09-25 20:53 - 2006-11-02 04:23 - 00000215 _____ () C:\Windows\system.ini
2014-09-25 20:43 - 2013-01-09 09:46 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-09-25 20:36 - 2012-10-23 10:10 - 00000882 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-09-25 20:36 - 2006-11-02 06:58 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-09-25 20:36 - 2006-11-02 06:45 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-09-25 20:36 - 2006-11-02 06:45 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-09-25 20:27 - 2012-05-03 21:03 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-09-25 20:22 - 2006-11-02 06:58 - 00032582 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-09-25 20:21 - 2012-11-24 21:05 - 00000000 ____D () C:\Program Files\Common Files\DVDVideoSoft
2014-09-25 18:32 - 2012-09-06 15:48 - 00000000 ____D () C:\Users\Rachel\AppData\Roaming\Skype
2014-09-25 18:31 - 2009-09-27 10:55 - 00006756 _____ () C:\Users\Rachel\AppData\Local\d3d9caps.dat
2014-09-25 08:30 - 2014-08-23 16:26 - 00000912 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3176256395-2519655851-1769987202-1000UA.job
2014-09-25 08:14 - 2006-11-02 05:18 - 00000000 ___RD () C:\Users\Public
2014-09-25 06:11 - 2012-10-23 10:10 - 00000886 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-09-24 16:43 - 2013-01-09 09:46 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-09-24 16:43 - 2011-05-30 16:10 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-09-24 16:31 - 2014-08-23 16:26 - 00000860 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3176256395-2519655851-1769987202-1000Core.job
2014-09-24 16:05 - 2006-11-02 04:22 - 46923776 _____ () C:\Windows\system32\config\software.bak
2014-09-24 16:05 - 2006-11-02 04:22 - 37486592 _____ () C:\Windows\system32\config\COMPON~3.bak
2014-09-24 16:05 - 2006-11-02 04:22 - 19660800 _____ () C:\Windows\system32\config\system.bak
2014-09-24 16:05 - 2006-11-02 04:22 - 00262144 _____ () C:\Windows\system32\config\security.bak
2014-09-24 16:05 - 2006-11-02 04:22 - 00262144 _____ () C:\Windows\system32\config\sam.bak
2014-09-24 16:05 - 2006-11-02 04:22 - 00262144 _____ () C:\Windows\system32\config\default.bak
2014-09-24 16:03 - 2009-08-15 08:22 - 00000000 ____D () C:\Users\Rachel\AppData\Roaming\Adobe
2014-09-24 15:56 - 2006-11-02 04:33 - 00690960 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-24 07:58 - 2014-02-06 00:21 - 00000000 ____D () C:\Windows\Minidump
2014-09-24 07:57 - 2014-02-06 00:21 - 218327979 _____ () C:\Windows\MEMORY.DMP
2014-09-23 19:03 - 2012-10-23 10:11 - 00000000 ___RD () C:\Users\Rachel\Google Drive
2014-09-23 18:22 - 2010-05-28 12:46 - 00002587 _____ () C:\Users\Rachel\Desktop\Word.lnk
2014-09-23 12:17 - 2009-08-15 08:07 - 00000906 _____ () C:\Users\Rachel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2014-09-23 11:37 - 2014-07-07 17:29 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-09-22 17:56 - 2012-09-06 15:48 - 00000000 ___RD () C:\Program Files\Skype
2014-09-22 17:56 - 2012-09-06 15:48 - 00000000 ____D () C:\ProgramData\Skype
2014-09-22 00:41 - 2009-10-06 16:32 - 00231568 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-09-21 21:56 - 2014-06-26 22:15 - 00000226 _____ () C:\Users\Rachel\BullseyeCoverageError.txt
2014-09-20 15:50 - 2014-08-20 19:01 - 00000000 ____D () C:\Users\Rachel\Documents\My Kindle Content
2014-09-16 21:17 - 2013-01-23 15:32 - 00002425 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
2014-09-16 21:17 - 2013-01-23 15:31 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2014-09-11 05:48 - 2006-11-02 05:18 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-09-11 05:15 - 2013-08-15 05:05 - 00000000 ____D () C:\Windows\system32\MRT
2014-09-11 05:02 - 2012-05-01 05:01 - 00001788 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
2014-09-11 05:02 - 2011-04-03 08:36 - 00002155 _____ () C:\Windows\epplauncher.mif
2014-09-11 05:02 - 2006-11-02 04:24 - 98758480 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2014-09-11 05:01 - 2011-04-03 07:19 - 00000000 ____D () C:\Program Files\Microsoft Security Client
2014-09-10 09:42 - 2014-08-23 16:27 - 00002049 _____ () C:\Users\Rachel\Desktop\Google Chrome.lnk
2014-09-05 21:23 - 2013-10-06 20:20 - 00000000 ____D () C:\Windows\Sun
2014-08-28 20:32 - 2013-11-21 05:31 - 00000000 ____D () C:\Program Files\PasswordBox
2014-08-28 05:19 - 2006-11-02 06:44 - 00298792 _____ () C:\Windows\system32\FNTCACHE.DAT

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-09-25 20:42

==================== End Of Log ============================
 

Hi calebsnake,

Not really seeing anything that would be causing all the issues you are experiencing.

[external image: bullseye_zpse9eaf36e.gif] FRST Fix Script

Open notepad. Please copy the contents of the code box below. To do this highlight the contents of the box and right click on it. Paste this into the open notepad. Save it on the desktop as fixlist.txt
 
Start
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\safeguard-secure-search.xml
CMD:netsh int ipv4 reset reset.log
CMD:netsh int ipv6 reset reset.log
CMD:ipconfig /flushdns /c
End
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

Run FRST and press the Fix button just once and wait.
The tool will make a log (Fixlog.txt) please post it to your reply.

=========================

[external image: bullseye_zpse9eaf36e.gif] Reboot into Normal Mode (if possible)

=========================

[external image: bullseye_zpse9eaf36e.gif] Farbar Service Scanner

Please download Farbar Service Scanner and save it to your desktop.
  • Right click and select "Run as Administrator"
  • Make sure the following options are checked:
    • Internet Services
    • System Restore
    • Security Center
    • Windows Update
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.
=========================

Let's check and see if you have a hard drive problem.

[external image: bullseye_zpse9eaf36e.gif] Chkdsk in Vista/7

You must run the command prompt as an administrator or in an "elevated mode".
  • Start menu, in the search bar type "cmd"
  • Right-click the cmd icon, select "run as administrator"
    • If you have user account control (UAC) set up it may prompt you to accept that action.
  • Then type in "chkdsk /r" (make note of the space between chkdsk and /)
=========================

[external image: bullseye_zpse9eaf36e.gif] To view results log:
  • Open the Start Menu, and type eventvwr.msc in the search box and press enter.
  • If prompted by UAC, then click on Yes (Windows 7) or Continue (Vista).
  • In the left pane of Event Viewer, double click on Windows Logs to expand it, then right click on Application and click on Find.
  • Copy and paste Chkdsk into the line, and click on Find Next.
  • You will now see the system log for the scan results of Check Disk (chkdsk).
  • In the right had menu select copy, open notepad and paste the chkdsk results into notepad
  • Post in your next reply.
=========================

In your next post please provide the following:
  • Fixlog.txt
  • FSS.txt
  • chkdsk results

Hi OCD,

 

The chkdsk is taking some time.  We are stuck in the file data verification phase ( 4 of 5).  I had read on the internet that this can take as long as 72 hours to complete.  We are willing to wait, unless you have a different recomendation.

Hi OCD,
 
Next morning and we are still at 61485 246256 files processed - right where we were last night. Shall we exercise more patience or spend $89 on spin _ rite or get a new hard-drive?
Hi calebsnake,

Go ahead and exit out of chkdsk since it appears to be hanging. I wouldn't necessarily say a new hard drive is in order at this stage.

[external image: bullseye_zpse9eaf36e.gif] Download DevDiag, and save it to your Desktop:
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • At the options screen, please type 2 and hit Enter.
  • The tool will take a few moments to scan. When finished, a report should pop-up, also available on your Desktop (DevDiag.txt).
  • Please do not copy/paste the report into your next reply. Instead, Attach it by clicking Add Reply, and scrolling down to the Attachments section.
=========================

In your next post please provide the following:
  • DevDiag.txt

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI