This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Malware, Adware in Windows 7 [Solved]

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My little brother downloaded a bunch of stuff recently and I noticed some adware in all of the browsers. Ran MBAM, but still a lot of stuff running in Task Manager that I don't recognize.

 

aswMBR version 1.0.1.2041 Copyright© 2014 AVAST Software
Run date: 2014-10-13 20:04:35
—————————–
20:04:35.094    OS Version: Windows x64 6.1.7601 Service Pack 1
20:04:35.094    Number of processors: 4 586 0x502
20:04:35.095    ComputerName: ATHLONX4-PC  UserName: AthlonX4
20:04:36.174    Initialize success
20:04:36.258    VM: initialized successfully
20:04:36.342    VM: Amd CPU supported 
20:04:54.092    VM: supported disk I/O storport.sys
20:09:41.376    AVAST engine defs: 14101301
20:09:53.237    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000067
20:09:53.243    Disk 0 Vendor: ST375064 3.AE Size: 715404MB BusType: 11
20:09:53.377    Disk 0 MBR read successfully
20:09:53.384    Disk 0 MBR scan
20:09:53.462    Disk 0 Windows 7 default MBR code
20:09:53.465    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS          100 MB offset 2048
20:09:53.473    Disk 0 default boot code
20:09:53.504    Disk 0 Partition 2 00     07    HPFS/NTFS NTFS       371387 MB offset 206848
20:09:53.546    Disk 0 Partition 3 00     07    HPFS/NTFS NTFS       343914 MB offset 760807424
20:09:53.729    Disk 0 scanning C:\Windows\system32\drivers
20:10:08.412    Service scanning
20:10:38.779    Modules scanning
20:10:38.792    Disk 0 trace - called modules:
20:10:38.818    ntoskrnl.exe CLASSPNP.SYS disk.sys amd_xata.sys storport.sys hal.dll amd_sata.sys 
20:10:38.823    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004a31060]
20:10:38.828    3 CLASSPNP.SYS[fffff880013b843f] -> nt!IofCallDriver -> [0xfffffa80047c1ac0]
20:10:38.834    5 amd_xata.sys[fffff8800114ad00] -> nt!IofCallDriver -> \Device\00000067[0xfffffa80039f49c0]
20:10:39.945    AVAST engine scan C:\Windows
20:10:42.736    AVAST engine scan C:\Windows\system32
20:15:23.854    AVAST engine scan C:\Windows\system32\drivers
20:15:41.931    AVAST engine scan C:\Users\AthlonX4
20:34:07.534    File: C:\Users\AthlonX4\AppData\Local\Temp\9brCaFffmy.exe  **INFECTED** Win32:Adware-gen [Adw]
20:37:03.607    File: C:\Users\AthlonX4\AppData\Local\Temp\VuuPC.exe  **INFECTED** Win32:Dropper-gen [Drp]
20:50:55.734    File: C:\Users\AthlonX4\Downloads\lol_a_plus_v1_2_downloader.exe  **INFECTED** Win32:Adware-gen [Adw]
20:56:37.045    AVAST engine scan C:\ProgramData
21:00:58.286    Scan finished successfully
21:03:06.401    Disk 0 MBR has been saved successfully to "C:\Users\AthlonX4\Desktop\MBR.dat"
21:03:06.462    The log file has been saved successfully to "C:\Users\AthlonX4\Desktop\aswMBR.txt"
 
 
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-10-2014 02
Ran by [removed] (administrator) on ATHLONX4-PC on 13-10-2014 21:03:59
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Foxit Corporation) C:\Program Files (x86)\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe
(Hi-Rez Studios) C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(AVAST Software) C:\Users\AthlonX4\Desktop\aswMBR.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1331288 2014-08-22] (Microsoft Corporation)
HKLM\…\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation)
HKLM-x32\…\Run: [KeePass 2 PreLoad] => C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe [1960448 2013-04-05] (Dominik Reichl)
HKLM-x32\…\Run: [RIMBBLaunchAgent.exe] => C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe [90448 2011-11-02] (Research In Motion Limited)
HKLM-x32\…\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\…\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-08-16] (Apple Inc.)
HKLM-x32\…\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642304 2013-04-30] (Advanced Micro Devices, Inc.)
HKLM-x32\…\Run: [AMD AVT] => C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe [20992 2012-03-19] ()
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
HKU\S-1-5-21-3478498415-794229227-1261764834-1000\…\Run: [Facebook Update] => C:\Users\AthlonX4\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2014-04-15] (Facebook Inc.)
HKU\S-1-5-21-3478498415-794229227-1261764834-1000\…\Run: [MK LOL] => C:\Program Files (x86)\MKJogo\MK IM\Bin\MKIM.exe [1092296 2014-10-05] ()
HKU\S-1-5-21-3478498415-794229227-1261764834-1000\…\Run: [HitsBlender] => C:\Program Files (x86)\HitsBlender\hitsblender.exe [1596472 2014-10-13] ()
HKU\S-1-5-21-3478498415-794229227-1261764834-1000\…\MountPoints2: {2be1db6c-08cb-11e3-9bec-001cf09f0e76} - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL E:\drivers\setup.exe
HKU\S-1-5-21-3478498415-794229227-1261764834-1000\…\MountPoints2: {5358d9e2-d87c-11e2-af39-90fba64bf37d} - J:\INSTALL.EXE
HKU\S-1-5-21-3478498415-794229227-1261764834-1000\…\MountPoints2: {ca287faf-b868-11e3-8e8d-001cf09f0e76} - E:\HTC_Sync_Manager_PC.exe
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {2E00D31D-D171-423D-836D-1A4D7EA7F1A9} URL = 
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = 
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: intu-tt2012 - {02F985EF-502B-4597-993F-6BF9E004C138} - C:\Program Files (x86)\TurboTax 2012\ic2012pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
Handler-x32: intu-tt2013 - {9FF5EC07-1645-43BF-828F-C73CFA7BC1AF} - C:\Program Files (x86)\TurboTax 2013\ic2013pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\..\Interfaces\{7A85FAD4-B38F-4092-BB3D-A3D46DB8847A}: [NameServer] 192.168.0.1
 
FireFox:
========
FF ProfilePath: C:\Users\AthlonX4\AppData\Roaming\Mozilla\Firefox\Profiles\9njvwb2g.default
FF SelectedSearchEngine: Astromenda
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @esn/npbattlelog,version=2.4.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.4.0\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll No File
FF Plugin-x32: @videolan.org/vlc,version=2.0.7 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin HKCU: @nsroblox.roblox.com/launcher -> C:\Users\AthlonX4\AppData\Local\Roblox\Versions\version-e66ffbb509ce4483\\NPRobloxProxy.dll ( ROBLOX Corporation)
FF Plugin HKCU: @nsroblox.roblox.com/launcher64 -> C:\Users\AthlonX4\AppData\Local\Roblox\Versions\version-e66ffbb509ce4483\\NPRobloxProxy64.dll ( ROBLOX Corporation)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\AthlonX4\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\AthlonX4\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF user.js: detected! => C:\Users\AthlonX4\AppData\Roaming\Mozilla\Firefox\Profiles\9njvwb2g.default\user.js
FF Extension: 1-Click YouTube Video Downloader - C:\Users\AthlonX4\AppData\Roaming\Mozilla\Firefox\Profiles\9njvwb2g.default\Extensions\[removed] [2013-07-20]
FF HKCU\…\Firefox\Extensions: [{065AE54A-C4EC-DDF1-946A-2A571D1C6A41}] - C:\Program Files (x86)\ver1BlockAndSurf\180.xpi
FF StartMenuInternet: FIREFOX.EXE - firefox.exe
 
Chrome: 
=======
CHR Profile: C:\Users\AthlonX4\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (PriceLess) - C:\Users\AthlonX4\AppData\Local\Google\Chrome\User Data\Default\Extensions\abdjjfhfjceapcnapdhbkimaojpadfde [2014-10-13]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\AthlonX4\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-07-24]
CHR Extension: (Video Downloader professional) - C:\Users\AthlonX4\AppData\Local\Google\Chrome\User Data\Default\Extensions\elicpjhcidhpjomhibiffojpinpmmpil [2014-03-21]
CHR Extension: (Google Play Music) - C:\Users\AthlonX4\AppData\Local\Google\Chrome\User Data\Default\Extensions\fahmaaghhglfmonjliepjlchgpgfmobi [2014-10-13]
CHR Extension: (AdBlock) - C:\Users\AthlonX4\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2013-11-13]
CHR Extension: (Google Wallet) - C:\Users\AthlonX4\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22]
CHR Extension: (PriceLess) - C:\Users\AthlonX4\AppData\Local\Google\Chrome\User Data\Default\Extensions\abdjjfhfjceapcnapdhbkimaojpadfde\5.2 [2014-10-13]
CHR StartMenuInternet: Google Chrome - chrome.exe
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
 
==================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2013-04-30] (Advanced Micro Devices, Inc.) [File not signed]
R2 FoxitCloudUpdateService; C:\Program Files (x86)\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe [242728 2014-07-01] (Foxit Corporation)
U2 HiPatchService; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [9216 2014-08-22] (Hi-Rez Studios) [File not signed]
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-10-01] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [968504 2014-10-01] (Malwarebytes Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2009-05-14] (Hewlett-Packard) [File not signed]
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [368624 2014-08-22] (Microsoft Corporation)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2009-05-14] (Hewlett-Packard) [File not signed]
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-08-19] ()
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [453120 2010-11-20] (Microsoft Corporation)
S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X]
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AODDriver4.1; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [53888 2012-03-05] (Advanced Micro Devices)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-06-18] (DT Soft Ltd)
S3 HtcVCom32; C:\Windows\System32\DRIVERS\HtcVComV64.sys [121800 2010-03-08] (QUALCOMM Incorporated)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-10-01] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2014-10-13] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-10-01] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [269008 2014-07-17] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [125584 2014-07-17] (Microsoft Corporation)
S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [74752 2011-07-25] (Research In Motion Limited)
R3 RimVSerPort; C:\Windows\System32\DRIVERS\RimSerial_AMD64.sys [44032 2011-07-20] (Research in Motion Ltd)
S3 usbrndis6; C:\Windows\System32\DRIVERS\usb80236.sys [19968 2013-02-12] (Microsoft Corporation)
R2 webinstrNew; C:\Windows\system32\Drivers\webinstrNew.sys [56504 2014-10-13] (Corsica)
S4 nvlddmkm; system32\DRIVERS\nvlddmkm.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
U3 aswMBR; \??\C:\Users\AthlonX4\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\AthlonX4\AppData\Local\Temp\aswVmm.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
==================== One Month Created Files and Folders ========
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2014-10-13 21:03 - 2014-10-13 21:04 - 00015443 _____ () C:\Users\AthlonX4\Desktop\FRST.txt
2014-10-13 21:03 - 2014-10-13 21:04 - 00000000 ____D () C:\FRST
2014-10-13 21:03 - 2014-10-13 21:03 - 00002532 _____ () C:\Users\AthlonX4\Desktop\aswMBR.txt
2014-10-13 21:03 - 2014-10-13 21:03 - 00000512 _____ () C:\Users\AthlonX4\Desktop\MBR.dat
2014-10-13 20:04 - 2014-10-13 20:04 - 02110464 _____ (Farbar) C:\Users\AthlonX4\Desktop\FRST64.exe
2014-10-13 20:03 - 2014-10-13 20:03 - 05185536 _____ (AVAST Software) C:\Users\AthlonX4\Desktop\aswMBR.exe
2014-10-13 19:18 - 2014-10-13 19:57 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-10-13 19:18 - 2014-10-13 19:18 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-10-13 19:18 - 2014-10-13 19:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-10-13 19:18 - 2014-10-13 19:18 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-10-13 19:18 - 2014-10-01 11:11 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-10-13 19:18 - 2014-10-01 11:11 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-10-13 19:18 - 2014-10-01 11:11 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-10-13 19:13 - 2014-10-13 19:14 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\AthlonX4\Downloads\mbam-setup-2.0.3.1025.exe
2014-10-13 17:54 - 2014-10-13 17:54 - 00000045 _____ () C:\Users\AthlonX4\AppData\Roaming\WB.CFG
2014-10-13 16:56 - 2014-10-13 17:16 - 00000378 _____ () C:\Windows\Tasks\APSnotifierPP1.job
2014-10-13 16:56 - 2014-10-13 17:07 - 00000376 _____ () C:\Windows\Tasks\APSnotifierPP3.job
2014-10-13 16:56 - 2014-10-13 17:07 - 00000376 _____ () C:\Windows\Tasks\APSnotifierPP2.job
2014-10-13 16:56 - 2014-10-13 16:57 - 00001238 _____ () C:\Users\AthlonX4\AppData\Roaming\aps.scan.quick.results
2014-10-13 16:56 - 2014-10-13 16:56 - 00612152 _____ (CMI Limited) C:\Users\AthlonX4\AppData\Local\nsxFD83.tmp
2014-10-13 16:56 - 2014-10-13 16:56 - 00002834 _____ () C:\Windows\System32\Tasks\APSnotifierPP1
2014-10-13 16:56 - 2014-10-13 16:56 - 00002832 _____ () C:\Windows\System32\Tasks\APSnotifierPP3
2014-10-13 16:56 - 2014-10-13 16:56 - 00002832 _____ () C:\Windows\System32\Tasks\APSnotifierPP2
2014-10-13 16:56 - 2014-10-13 16:56 - 00000000 ____D () C:\Users\AthlonX4\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnyProtect PC Backup
2014-10-13 16:56 - 2014-10-13 16:56 - 00000000 ____D () C:\Users\AthlonX4\AppData\Roaming\ap_movie
2014-10-13 16:56 - 2014-10-13 16:56 - 00000000 ____D () C:\Users\AthlonX4\AppData\Roaming\AnyProtectEx
2014-10-13 16:56 - 2014-10-13 16:56 - 00000000 ____D () C:\Program Files (x86)\AnyProtectEx
2014-10-13 16:56 - 2014-10-13 16:56 - 00000000 _____ () C:\Users\AthlonX4\AppData\Roaming\aps.scan.results
2014-10-13 16:55 - 2014-10-13 16:55 - 00056504 _____ (Corsica) C:\Windows\system32\Drivers\webinstrNew.sys
2014-10-13 16:55 - 2014-10-13 16:55 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_webinstrNew_01009.Wdf
2014-10-13 16:15 - 2014-10-13 19:59 - 00000000 ____D () C:\Users\AthlonX4\AppData\Local\HitsBlender
2014-10-13 16:15 - 2014-10-13 19:55 - 00000000 ____D () C:\Users\AthlonX4\AppData\Roaming\Systweak
2014-10-13 16:15 - 2014-10-13 19:55 - 00000000 ____D () C:\ProgramData\Systweak
2014-10-13 16:15 - 2014-10-13 16:15 - 00003026 _____ () C:\Windows\System32\Tasks\RegClean Pro_UPDATES
2014-10-13 16:15 - 2014-10-13 16:15 - 00000000 ____D () C:\Users\AthlonX4\AppData\Local\cache
2014-10-13 16:15 - 2014-10-06 16:36 - 00020296 _____ () C:\Windows\system32\roboot64.exe
2014-10-13 16:14 - 2014-10-13 16:55 - 00000600 __RSH () C:\ProgramData\ntuser.pol
2014-10-13 16:14 - 2014-10-13 16:15 - 00000004 _____ () C:\end
2014-10-13 16:14 - 2014-10-13 16:14 - 00003118 _____ () C:\Windows\System32\Tasks\Update Service HitsBlender
2014-10-13 16:14 - 2014-10-13 16:14 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Torch
2014-10-13 16:14 - 2014-10-13 16:14 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Google
2014-10-13 16:14 - 2014-10-13 16:14 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Comodo
2014-10-13 16:14 - 2014-10-13 16:14 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Chromatic Browser
2014-10-13 16:14 - 2014-10-13 16:14 - 00000000 ____D () C:\Users\HomeGroupUser$
2014-10-13 16:14 - 2014-10-13 16:14 - 00000000 ____D () C:\Users\Guest\AppData\Local\Torch
2014-10-13 16:14 - 2014-10-13 16:14 - 00000000 ____D () C:\Users\Guest\AppData\Local\Google
2014-10-13 16:14 - 2014-10-13 16:14 - 00000000 ____D () C:\Users\Guest\AppData\Local\Comodo
2014-10-13 16:14 - 2014-10-13 16:14 - 00000000 ____D () C:\Users\Guest\AppData\Local\Chromatic Browser
2014-10-13 16:14 - 2014-10-13 16:14 - 00000000 ____D () C:\Users\Guest
2014-10-13 16:14 - 2014-10-13 16:14 - 00000000 ____D () C:\Users\AthlonX4\AppData\Local\Torch
2014-10-13 16:14 - 2014-10-13 16:14 - 00000000 ____D () C:\Users\AthlonX4\AppData\Local\Comodo
2014-10-13 16:14 - 2014-10-13 16:14 - 00000000 ____D () C:\Users\AthlonX4\AppData\Local\Chromatic Browser
2014-10-13 16:14 - 2014-10-13 16:14 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Torch
2014-10-13 16:14 - 2014-10-13 16:14 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google
2014-10-13 16:14 - 2014-10-13 16:14 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo
2014-10-13 16:14 - 2014-10-13 16:14 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Chromatic Browser
2014-10-13 16:14 - 2014-10-13 16:14 - 00000000 ____D () C:\Users\Administrator
2014-10-13 16:14 - 2014-10-13 16:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\HitsBlender
2014-10-13 16:14 - 2014-10-13 16:14 - 00000000 ____D () C:\ProgramData\HitsBlender
2014-10-13 16:14 - 2014-10-13 16:14 - 00000000 ____D () C:\ProgramData\c4ca3d2e5a673ccf
2014-10-13 16:14 - 2014-10-13 16:14 - 00000000 ____D () C:\Program Files (x86)\HitsBlenderUpdater
2014-10-13 16:14 - 2014-10-13 16:14 - 00000000 ____D () C:\Program Files (x86)\HitsBlender
2014-10-13 16:12 - 2014-10-13 16:13 - 03611152 _____ (http://yourfile-downloader.com) C:\Users\AthlonX4\Downloads\lol_a_plus_v1_2_downloader.exe
2014-10-08 13:17 - 2014-10-08 13:33 - 00000000 ____D () C:\Users\AthlonX4\Downloads\Boardwalk Empire S05E04 HDTV x264-KILLERS[ettv]
2014-10-08 13:17 - 2014-10-08 13:28 - 00000000 ____D () C:\Users\AthlonX4\Downloads\Boardwalk Empire S05E05 HDTV x264-KILLERS[ettv]
2014-10-05 19:23 - 2014-10-05 19:24 - 19278536 _____ () C:\Users\AthlonX4\Downloads\MKLOL2.0.0.21 (1).exe
2014-10-05 18:57 - 2014-10-05 19:06 - 00000000 ____D () C:\Users\AthlonX4\Documents\MK-LOL
2014-10-05 18:57 - 2014-10-05 18:57 - 00000058 _____ () C:\Windows\JQHApp.dat
2014-10-05 18:57 - 2014-10-05 18:57 - 00000000 ____D () C:\Users\AthlonX4\Documents\MKJogo
2014-10-05 18:56 - 2014-10-05 18:56 - 00000000 ____D () C:\Users\AthlonX4\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MKJogo
2014-10-05 18:56 - 2014-10-05 18:56 - 00000000 ____D () C:\Program Files (x86)\MKJogo
2014-10-05 18:55 - 2014-10-05 18:55 - 19278536 _____ () C:\Users\AthlonX4\Downloads\MKLOL2.0.0.21.exe
2014-10-04 10:02 - 2014-10-04 10:05 - 65456922 _____ () C:\Users\AthlonX4\Downloads\ei_win_1.0.1_2492 (1).zip
2014-09-30 17:07 - 2014-09-24 22:08 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2014-09-30 17:07 - 2014-09-24 21:40 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2014-09-26 20:38 - 2014-09-26 20:38 - 00001066 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-09-24 08:18 - 2014-09-09 18:11 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-09-24 08:18 - 2014-09-09 17:47 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-09-20 10:20 - 2014-09-20 11:41 - 1998326696 _____ () C:\Users\AthlonX4\Downloads\HoNClient-3.2.7 (1).exe
2014-09-19 20:36 - 2014-09-19 20:36 - 00000000 ____D () C:\Users\AthlonX4\AppData\Local\Chromium
2014-09-19 20:11 - 2014-09-19 20:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bloodline Champions
2014-09-19 20:08 - 2014-09-19 20:08 - 00000000 ____D () C:\Program Files (x86)\Stunlock Studios
2014-09-19 19:55 - 2014-09-19 20:08 - 363876296 _____ (Stunlock Studios ) C:\Users\AthlonX4\Downloads\BloodlineChampionsInstaller.exe
2014-09-19 09:46 - 2014-09-19 09:46 - 01792008 _____ () C:\Users\AthlonX4\Downloads\setup-network-utilities (2).exe
2014-09-18 21:47 - 2014-10-05 14:55 - 00000000 ____D () C:\ProgramData\boost_interprocess
2014-09-18 16:28 - 2014-09-18 16:28 - 05910648 _____ () C:\Users\AthlonX4\Downloads\TL-WDR3500_V1_130909.zip
2014-09-18 16:24 - 2014-09-26 14:46 - 00000728 _____ () C:\Users\AthlonX4\Desktop\Router Settings.txt
2014-09-17 21:53 - 2014-09-17 21:54 - 00000000 ____D () C:\Users\AthlonX4\Downloads\Alt-J - This Is All Yours (2014) CD RIP [MP3 @ 320 KBPS]
2014-09-17 21:51 - 2014-09-17 21:52 - 00000000 ____D () C:\Users\AthlonX4\Downloads\The Rural Alberta Advantage - Mended With Gold (2014)
2014-09-14 12:53 - 2014-09-14 12:53 - 00000000 ____D () C:\Users\AthlonX4\AppData\Roaming\PFStaticIP
2014-09-14 12:52 - 2014-09-14 12:53 - 00000000 ____D () C:\Users\AthlonX4\AppData\Roaming\PortForward.com
2014-09-14 12:52 - 2014-09-14 12:52 - 00000000 ____D () C:\Users\AthlonX4\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Portforward.com
2014-09-14 12:52 - 2014-09-14 12:52 - 00000000 ____D () C:\Program Files (x86)\Portforward.com
2014-09-14 12:51 - 2014-09-14 12:51 - 01697368 _____ () C:\Users\AthlonX4\Downloads\setup-network-utilities.exe
2014-09-14 12:51 - 2014-09-14 12:51 - 01697368 _____ () C:\Users\AthlonX4\Downloads\setup-network-utilities (1).exe
 
==================== One Month Modified Files and Folders =======
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2014-10-13 21:04 - 2013-06-18 21:09 - 00000902 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-10-13 20:52 - 2014-04-15 14:47 - 00000940 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3478498415-794229227-1261764834-1000UA.job
2014-10-13 20:24 - 2013-06-25 19:59 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-10-13 20:20 - 2013-06-26 11:06 - 00000000 ____D () C:\Users\AthlonX4\AppData\Roaming\KeePass
2014-10-13 20:09 - 2009-07-14 00:45 - 00026576 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-10-13 20:09 - 2009-07-14 00:45 - 00026576 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-10-13 19:59 - 2013-06-15 08:46 - 01851548 _____ () C:\Windows\WindowsUpdate.log
2014-10-13 19:56 - 2013-06-18 21:09 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-10-13 19:56 - 2010-11-20 23:47 - 00477968 _____ () C:\Windows\PFRO.log
2014-10-13 19:56 - 2009-07-14 01:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-10-13 19:56 - 2009-07-14 00:51 - 00326388 _____ () C:\Windows\setupact.log
2014-10-13 19:56 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\SchCache
2014-10-13 19:18 - 2013-07-14 19:46 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-10-13 16:14 - 2013-06-18 21:09 - 00000000 ____D () C:\Users\AthlonX4\AppData\Local\Google
2014-10-13 16:14 - 2013-06-18 21:09 - 00000000 ____D () C:\Program Files (x86)\Google
2014-10-13 16:14 - 2009-07-13 23:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-10-13 16:14 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2014-10-13 14:52 - 2014-04-15 14:47 - 00000918 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3478498415-794229227-1261764834-1000Core.job
2014-10-12 11:59 - 2014-01-13 20:32 - 00000000 ____D () C:\Users\AthlonX4\AppData\Roaming\Awesomium
2014-10-11 22:53 - 2013-06-18 22:53 - 00328431 _____ () C:\Windows\DirectX.log
2014-10-11 16:41 - 2014-07-09 18:04 - 00001354 _____ () C:\Users\AthlonX4\Desktop\ROBLOX Player.lnk
2014-10-11 16:41 - 2014-07-09 18:02 - 00001173 _____ () C:\Users\AthlonX4\Desktop\ROBLOX Studio 2013.lnk
2014-10-11 16:41 - 2014-07-09 18:02 - 00000000 ____D () C:\Users\AthlonX4\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox
2014-10-11 16:11 - 2013-06-26 09:13 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-10-09 15:47 - 2013-06-29 20:36 - 00000000 ____D () C:\Users\AthlonX4\AppData\Roaming\vlc
2014-10-08 16:13 - 2013-06-26 10:53 - 00000000 ____D () C:\Users\AthlonX4\AppData\Roaming\uTorrent
2014-09-29 15:56 - 2009-07-14 01:13 - 00819102 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-26 20:38 - 2013-06-26 10:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2014-09-24 17:00 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\rescache
2014-09-23 17:24 - 2013-06-25 19:59 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-09-23 17:24 - 2013-06-15 23:23 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-09-23 17:24 - 2013-06-15 23:23 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-09-22 02:42 - 2010-11-20 23:27 - 00278152 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-09-17 22:01 - 2013-08-09 18:06 - 00498688 ___SH () C:\Users\AthlonX4\Documents\Thumbs.db
2014-09-13 08:33 - 2009-07-14 01:08 - 00032634 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
 
Some content of TEMP:
====================
C:\Users\AthlonX4\AppData\Local\Temp\13-1-legacy_vista_win7_win8_64_dd_ccc.exe
C:\Users\AthlonX4\AppData\Local\Temp\13-9-legacy_vista_win7_64_dd_ccc_whql.exe
C:\Users\AthlonX4\AppData\Local\Temp\9brCaFffmy.exe
C:\Users\AthlonX4\AppData\Local\Temp\Checkupdate.exe
C:\Users\AthlonX4\AppData\Local\Temp\Foxit Reader Updater.exe
C:\Users\AthlonX4\AppData\Local\Temp\Foxit Updater.exe
C:\Users\AthlonX4\AppData\Local\Temp\gcapi_dll.dll
C:\Users\AthlonX4\AppData\Local\Temp\gtapi_signed.dll
C:\Users\AthlonX4\AppData\Local\Temp\HiPatchSelfUpdateWindow.exe
C:\Users\AthlonX4\AppData\Local\Temp\HiRezLauncherControls.dll
C:\Users\AthlonX4\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe
C:\Users\AthlonX4\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe
C:\Users\AthlonX4\AppData\Local\Temp\jre-7u55-windows-i586-iftw.exe
C:\Users\AthlonX4\AppData\Local\Temp\jre-7u65-windows-i586-iftw.exe
C:\Users\AthlonX4\AppData\Local\Temp\jre-7u67-windows-i586-iftw.exe
C:\Users\AthlonX4\AppData\Local\Temp\networkme1.exe
C:\Users\AthlonX4\AppData\Local\Temp\nvStInst.exe
C:\Users\AthlonX4\AppData\Local\Temp\sonarinst.exe
C:\Users\AthlonX4\AppData\Local\Temp\swt-win32-3349.dll
C:\Users\AthlonX4\AppData\Local\Temp\SYxurltIJ9.exe
C:\Users\AthlonX4\AppData\Local\Temp\vlc-2.1.5-win32.exe
C:\Users\AthlonX4\AppData\Local\Temp\VuuPC.exe
C:\Users\AthlonX4\AppData\Local\Temp\zaaU1.dll
C:\Users\AthlonX4\AppData\Local\Temp\zaaU1.exe
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2014-10-06 19:10
 
==================== End Of Log ============================
 
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 12-10-2014 02
Ran by [removed] at 2014-10-13 21:04:58
Running from C:\Users\[removed]\Desktop
Boot Mode: Normal
==========================================================
 
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Microsoft Security Essentials (Enabled - Up to date) {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}
AS: Microsoft Security Essentials (Enabled - Up to date) {F4542E20-6399-F3B9-D5A7-4EE87964D00C}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
µTorrent (HKCU\…\uTorrent) (Version: 3.4.1.31139 - BitTorrent Inc.)
64 Bit HP CIO Components Installer (Version: 6.2.2 - Hewlett-Packard) Hidden
Adobe Digital Editions 3.0 (HKLM-x32\…\Adobe Digital Editions 3.0) (Version: 3.0.1 - Adobe Systems Incorporated)
Adobe Flash Player 15 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 15.0.0.167 - Adobe Systems Incorporated)
Adobe Flash Player 15 Plugin (HKLM-x32\…\Adobe Flash Player Plugin) (Version: 15.0.0.152 - Adobe Systems Incorporated)
AMD Accelerated Video Transcoding (Version: 12.5.100.30429 - Advanced Micro Devices, Inc.) Hidden
AMD APP SDK Runtime (Version: 10.0.937.2 - Advanced Micro Devices Inc.) Hidden
AMD Catalyst Install Manager (HKLM\…\{37FCE154-7F59-74F0-3A35-BF503CEB230B}) (Version: 8.0.877.0 - Advanced Micro Devices, Inc.)
AMD Drag and Drop Transcoding (Version: 2.00.0000 - Advanced Micro Devices, Inc.) Hidden
AMD Fuel (Version: 2013.0429.2313.39747 - Advanced Micro Devices, Inc.) Hidden
AMD Media Foundation Decoders (Version: 1.0.80430.0002 - Advanced Micro Devices, Inc.) Hidden
AMD VISION Engine Control Center (x32 Version: 2013.0429.2313.39747 - Advanced Micro Devices, Inc.) Hidden
AnyProtect (HKLM-x32\…\AnyProtect) (Version: 1.0.0.1 - CMI Limited) <==== ATTENTION
Apple Application Support (HKLM-x32\…\{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}) (Version: 2.3.4 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{2F72F540-1F60-4266-9506-952B21D6640D}) (Version: 6.1.0.13 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Bastion (HKLM-x32\…\Steam App 107100) (Version:  - Supergiant Games)
Battlefield 3™ (HKLM-x32\…\{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: 1.6.0.0 - Electronic Arts)
Battlelog Web Plugins (HKLM-x32\…\Battlelog Web Plugins) (Version: 2.4.0 - EA Digital Illusions CE AB)
BioShock 2 (HKLM-x32\…\Steam App 8850) (Version:  - 2K Marin)
BioShock Infinite (HKLM-x32\…\Steam App 8870) (Version:  - Irrational Games)
BIT.TRIP BEAT (HKLM-x32\…\Steam App 63700) (Version:  - Gaijin Games)
BIT.TRIP CORE (HKLM-x32\…\Steam App 205060) (Version:  - Gaijin Games)
BIT.TRIP FATE (HKLM-x32\…\Steam App 205080) (Version:  - Gaijin Games)
BIT.TRIP RUNNER (HKLM-x32\…\Steam App 63710) (Version:  - Gaijin Games)
BlackBerry Device Manager 7.0 (HKLM-x32\…\BlackBerry_HandheldManager) (Version: 7.0.0.40 - Research In Motion Ltd.)
BlackBerry Device Manager 7.0 (x32 Version: 7.0.0.40 - Research In Motion Ltd.) Hidden
Bloodline Champions (HKLM-x32\…\{81E58F0A-E24E-4132-98C2-6BA39899692E}_is1) (Version: 2.4.1.0 - Stunlock Studios)
Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Call of Duty: Black Ops II - Multiplayer (HKLM-x32\…\Steam App 202990) (Version:  - )
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Graphics Previews Common (x32 Version: 2013.0429.2313.39747 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2013.0429.2313.39747 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2013.0429.2313.39747 - Advanced Micro Devices, Inc.) Hidden
Cave Story+ (HKLM-x32\…\Steam App 200900) (Version:  - Nicalis)
CCC Help Chinese Standard (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Traditional (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden
CCC Help Czech (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden
CCC Help Danish (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden
CCC Help Dutch (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden
CCC Help English (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden
CCC Help Finnish (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden
CCC Help French (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden
CCC Help German (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden
CCC Help Greek (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden
CCC Help Hungarian (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden
CCC Help Italian (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden
CCC Help Japanese (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden
CCC Help Korean (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden
CCC Help Norwegian (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden
CCC Help Polish (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden
CCC Help Portuguese (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden
CCC Help Russian (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden
CCC Help Spanish (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden
CCC Help Swedish (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden
CCC Help Thai (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden
CCC Help Turkish (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden
ccc-utility64 (Version: 2013.0429.2313.39747 - Advanced Micro Devices, Inc.) Hidden
Cities XL Platinum (HKLM-x32\…\Cities XL Platinum_is1) (Version:  - )
Comical 0.8 (HKLM-x32\…\Comical_is1) (Version:  - James Athey)
DAEMON Tools Lite (HKLM-x32\…\DAEMON Tools Lite) (Version: 4.45.4.0315 - DT Soft Ltd)
DGE-530T Ethernet Controller All-In-One Windows Driver (HKLM-x32\…\{3DA3BCBA-191C-47FB-9710-2B2DD9A5C257}) (Version: 1.12.0013 - D-Link)
DJ_SF_06_D1600_SW_Min (x32 Version: 140.0.690.000 - Hewlett-Packard) Hidden
Dustforce (HKLM-x32\…\Steam App 65300) (Version:  - Hitbox Team)
Electronic Super Joy (HKLM-x32\…\Steam App 244870) (Version:  - Michael Todd Games)
ESET Online Scanner v3 (HKLM-x32\…\ESET Online Scanner) (Version:  - )
Facebook Video Calling 3.1.0.521 (HKLM-x32\…\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited)
Far Cry 2 (HKLM-x32\…\{F2835483-37F2-4123-B4FE-0E77D58447F2}) (Version: 1.00.00 - Ubisoft)
foobar2000 v1.2.8 (HKLM-x32\…\foobar2000) (Version: 1.2.8 - Peter Pawlowski)
Forged By Chaos (HKLM-x32\…\ForgedByChaos) (Version:  - )
Foxit Cloud (HKLM-x32\…\{41914D8B-9D6E-4764-A1F9-BC43FB6782C1}_is1) (Version: 1.7.140.701 - Foxit Corporation)
Foxit Reader (HKLM-x32\…\Foxit Reader_is1) (Version: 6.2.1.618 - Foxit Corporation)
FTL version 1.03.3 (HKLM-x32\…\{20E23A40-38E5-4DD6-B738-BC8097AE66B6}_is1) (Version: 1.03.3 - Subset Games)
FTL: Faster Than Light (HKLM-x32\…\Steam App 212680) (Version:  - Subset Games)
GIMP 2.8.6 (HKLM\…\GIMP-2_is1) (Version: 2.8.6 - The GIMP Team)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 37.0.2062.124 - Google Inc.)
Google Earth Plug-in (HKLM-x32\…\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden
Guacamelee! Gold Edition (HKLM-x32\…\Steam App 214770) (Version:  - DrinkBox Studios)
GunZ 2: The Second Duel (HKLM-x32\…\Steam App 242720) (Version:  - MAIET Entertainment)
Half-Life 2 (HKLM-x32\…\Steam App 220) (Version:  - Valve)
Half-Life 2: Episode One (HKLM-x32\…\Steam App 380) (Version:  - Valve)
Half-Life 2: Episode Two (HKLM-x32\…\Steam App 420) (Version:  - Valve)
Heroes of Newerth (HKLM-x32\…\hon) (Version: 2.3.0 - S2 Games)
Hi-Rez Studios Authenticate and Update Service (HKLM-x32\…\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}) (Version: 3.0.0.0 - Hi-Rez Studios)
HitsBlender (HKCU\…\HitsBlender) (Version: 1.14.38 - http://www.hitsblender.com)
Hotline Miami (HKLM-x32\…\Steam App 219150) (Version:  - Dennaton Games)
HP Deskjet D1600 Printer Driver 14.0 Rel. 6 (HKLM\…\{96178C0A-BAF9-4E49-A2A5-CDE76722105B}) (Version: 14.0 - HP)
InfiniteCrisis_410193F41CAE (HKLM-x32\…\InfiniteCrisis_410193F41CAE) (Version:  - Turbine, Inc)
iTunes (HKLM\…\{427174C0-096E-40D9-9684-9C109BEE2CBF}) (Version: 11.0.5.5 - Apple Inc.)
Java 7 Update 67 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F03217067FF}) (Version: 7.0.670 - Oracle)
Java Auto Updater (x32 Version: 2.1.67.1 - Oracle, Inc.) Hidden
KeePass Password Safe 2.22 (HKLM-x32\…\KeePassPasswordSafe2_is1) (Version:  - Dominik Reichl)
League of Legends (HKLM-x32\…\League of Legends 3.0.0) (Version: 3.0.0 - Riot Games)
League of Legends (x32 Version: 3.0.0 - Riot Games) Hidden
Malwarebytes Anti-Malware version 2.0.3.1025 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.0.3.1025 - Malwarebytes Corporation)
Mark of the Ninja (HKLM-x32\…\Mark of the Ninja_is1) (Version:  - )
Mark of the Ninja (HKLM-x32\…\Steam App 214560) (Version:  - Klei Entertainment)
Marvell Miniport Driver (HKLM-x32\…\Marvell Miniport Driver) (Version: 11.45.4.3 - Marvell)
Microsoft .NET Framework 4.5.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Security Client (Version: 4.6.0305.0 - Microsoft Corporation) Hidden
Microsoft Security Essentials (HKLM\…\Microsoft Security Client) (Version: 4.6.305.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\…\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 (HKLM-x32\…\{8e70e4e1-06d7-470b-9f74-a51bef21088e}) (Version: 11.0.51106.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.51106 (x32 Version: 11.0.51106 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.51106 (x32 Version: 11.0.51106 - Microsoft Corporation) Hidden
Microsoft Xbox 360 Accessories 1.2 (HKLM\…\{D9C50188-12D5-4D3E-8F00-682346C2AA5F}) (Version: 1.20.146.0 - Microsoft)
Microsoft XNA Framework Redistributable 3.1 (HKLM-x32\…\{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}) (Version: 3.1.10527.0 - Microsoft Corporation)
MK LOL (HKCU\…\MK LOL) (Version:  - )
Mozilla Firefox 29.0.1 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 29.0.1 (x86 en-US)) (Version: 29.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
NVIDIA Install Application (Version: 2.1002.124.810 - NVIDIA Corporation) Hidden
NVIDIA PhysX (HKLM-x32\…\{80407BA7-7763-4395-AB98-5233F1B34E65}) (Version: 9.13.1220 - NVIDIA Corporation)
OpenAL (HKLM-x32\…\OpenAL) (Version:  - )
OpenOffice.org 3.4.1 (HKLM-x32\…\{9F1F2AEA-C72A-4DD6-991E-C5506A5625E4}) (Version: 3.41.9593 - Apache Software Foundation)
Origin (HKLM-x32\…\Origin) (Version: 9.3.1.4482 - Electronic Arts, Inc.)
Panzar (HKLM-x32\…\{4FF82163-423A-43CE-898D-3B60D19A5E8F}_is1) (Version: 1.0 - Panzar)
PDF ePub DRM Removal (HKLM-x32\…\PDFDRM) (Version: 1.4.1 - eBook Converter)
PeaZip 5.0 (WIN64) (HKLM\…\{5A2BC38A-406C-4A5B-BF45-6991F9A05325}_is1) (Version:  - Giorgio Tani)
Plants vs. Zombies™ (HKLM-x32\…\{5E6536C2-E79A-49CF-83EA-817AD81F9FC8}) (Version: 1.2.0.1093 - Electronic Arts, Inc.)
Port Forward Network Utilities 2.0.1 (HKLM-x32\…\Port Forward Network Utilities) (Version: 2.0.1 - Portforward.com)
Portal (HKLM-x32\…\Steam App 400) (Version:  - Valve)
Portal 2 (HKLM-x32\…\Steam App 620) (Version:  - Valve)
Prime World version 9.16.2 (HKLM-x32\…\{F6F3C462-2729-4555-8A95-CC317A90F8FF}_is1) (Version: 9.16.2 - Nival)
PunkBuster Services (HKLM-x32\…\PunkBusterSvc) (Version: 0.991 - Even Balance, Inc.)
Recuva (HKLM\…\Recuva) (Version: 1.51 - Piriform)
ROBLOX Player for AthlonX4 (HKCU\…\{373B1718-8CC5-4567-8EE2-9033AD08A680}) (Version:  - ROBLOX Corporation)
ROBLOX Studio 2013 for AthlonX4 (HKCU\…\{2922D6F1-2865-4EFA-97A9-94EEAB3AFA14}) (Version:  - ROBLOX Corporation)
Rogue Legacy (HKLM-x32\…\Steam App 241600) (Version:  - Cellar Door Games)
Saints Row: The Third (HKLM-x32\…\Steam App 55230) (Version:  - Volition)
Scrolls (HKLM-x32\…\Scrolls 1.0.0) (Version: 1.0.0 - Mojang)
Scrolls (x32 Version: 1.0.0 - Mojang) Hidden
Skype™ 6.5 (HKLM-x32\…\{1845470B-EB14-4ABC-835B-E36C693DC07D}) (Version: 6.5.158 - Skype Technologies S.A.)
Smashmuck Champions (HKLM-x32\…\Smashmuck Champions) (Version:  - )
Smite (HKLM-x32\…\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF017}) (Version: 1.0.2326.4 - Hi-Rez Studios)
Spec Ops The Line (HKLM-x32\…\Spec Ops The Line_is1) (Version:  - )
Steam (HKLM-x32\…\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
Strife (HKLM-x32\…\Strife) (Version:  - S2 Games)
Super Meat Boy (HKLM-x32\…\Steam App 40800) (Version:  - Team Meat)
Team Fortress 2 (HKLM-x32\…\Steam App 440) (Version:  - Valve)
The Banner Saga (HKLM-x32\…\Steam App 237990) (Version:  - Stoic)
The Sims™ 3 (HKLM-x32\…\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.67.2 - Electronic Arts)
The Sims™ 3 High-End Loft Stuff (HKLM-x32\…\{71828142-5A24-4BD0-97E7-976DA08CE6CF}) (Version: 3.13.1 - Electronic Arts)
The Walking Dead (HKLM-x32\…\Steam App 207610) (Version:  - )
Titanfall™ (HKLM-x32\…\{347EE0C3-0690-48F6-A231-53853C2A80D6}) (Version: 1.0.4.11 - Electronic Arts)
Titanfall™-Beta (HKLM-x32\…\{E933BD1A-9B05-42A3-A1CF-3DA81C72E454}) (Version: 1.0.0.0 - Electronic Arts)
Toolbox (x32 Version: 140.0.428.000 - Hewlett-Packard) Hidden
Tribes Ascend (HKLM-x32\…\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF010}) (Version: 1.0.1268.1 - Hi-Rez Studios)
TurboTax 2012 (HKLM-x32\…\{726DDC29-79B3-41B4-BDBF-97DF25BF1EA8}) (Version: 1.00.0000 - Intuit Canada)
TurboTax 2013 (HKLM-x32\…\{1E0FF98D-4AE4-46CC-B624-E771ABD5EA11}) (Version: 1.00.0000 - Intuit Canada)
Unity Web Player (HKCU\…\UnityWebPlayer) (Version:  - Unity Technologies ApS)
Update Service HitsBlender (HKCU\…\Update Service HitsBlender) (Version: 1.14.38 - http://www.hitsblender.com)
Vessel (HKLM-x32\…\Vessel_is1) (Version:  - )
VLC media player (HKLM-x32\…\VLC media player) (Version: 2.1.5 - VideoLAN)
WhoCrashed 4.02 (HKLM\…\WhoCrashed_is1) (Version:  - Resplendence Software Projects Sp.)
 
==================== Custom CLSID (selected items): ==========================
 
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
 
CustomCLSID: HKU\S-1-5-21-3478498415-794229227-1261764834-1000_Classes\CLSID\{DEE03C2B-0C0C-41A9-9877-FD4B4D7B6EA3}\InprocServer32 -> C:\Users\AthlonX4\AppData\Local\Roblox\Versions\version-e66ffbb509ce4483\RobloxProxy64.dll (ROBLOX Corporation)
 
==================== Restore Points  =========================
 
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 22:34 - 2009-06-10 17:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
 
==================== Scheduled Tasks (whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
 
Task: {13CD7321-7838-47CF-B4DF-004CCD05C215} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-23] (Adobe Systems Incorporated)
Task: {18FBE4AE-B14E-4584-AD76-C57F09E6194A} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3478498415-794229227-1261764834-1000Core => C:\Users\AthlonX4\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-04-15] (Facebook Inc.)
Task: {246599A1-3E01-4F84-8B38-B9BF8A56E65A} - \BlockAndSurf Update No Task File <==== ATTENTION
Task: {2B716B13-3F00-4339-A656-A71EAEFACCEA} - \RegClean Pro_DEFAULT No Task File <==== ATTENTION
Task: {34EE09F1-DA78-41A9-85DA-615AE51ADB38} - \Update Service YourFileDownloader No Task File <==== ATTENTION
Task: {4E8BEF54-10DC-4E6D-A934-745B4FEC0103} - \RegClean Pro No Task File <==== ATTENTION
Task: {57DAEA40-E8BD-4D54-8664-EBD7F43A4BFA} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3478498415-794229227-1261764834-1000UA => C:\Users\AthlonX4\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-04-15] (Facebook Inc.)
Task: {5B469382-0887-4F49-82ED-5C2852AC19A1} - \Advanced-System Protector_startup No Task File <==== ATTENTION
Task: {60E9E589-B3C0-4B5B-AA89-A71C7DA51B68} - System32\Tasks\APSnotifierPP1 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe [2014-10-13] (AnyProtect.com) <==== ATTENTION
Task: {6954AED3-427F-409D-848D-186F98A72B97} - System32\Tasks\APSnotifierPP3 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe [2014-10-13] (AnyProtect.com) <==== ATTENTION
Task: {82E56BAA-350A-45C0-92E2-4DBD1983DD55} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: {87182DA2-137A-4D80-9FFD-42A530910D4D} - System32\Tasks\Update Service HitsBlender => C:\Program Files (x86)\HitsBlenderUpdater\HitsBlenderUpdater.exe [2014-10-13] (Blisbury LLP.)
Task: {8C734488-7E68-4C0E-B08E-F2B42A19517B} - System32\Tasks\RegClean Pro_UPDATES => C:\Program Files (x86)\RCP\RegCleanPro.exe <==== ATTENTION
Task: {9F9771BC-9D59-4043-8188-B11E2E90716E} - \WSE_Astromenda No Task File <==== ATTENTION
Task: {C2A9420B-6C79-4F9A-9CB2-F0BD24273C31} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: {DB78C641-F7C6-4D6D-8A20-347288A091A8} - System32\Tasks\APSnotifierPP2 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe [2014-10-13] (AnyProtect.com) <==== ATTENTION
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\APSnotifierPP1.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP2.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP3.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3478498415-794229227-1261764834-1000Core.job => C:\Users\AthlonX4\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3478498415-794229227-1261764834-1000UA.job => C:\Users\AthlonX4\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Loaded Modules (whitelisted) =============
 
2013-06-24 17:14 - 2013-08-19 19:22 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2013-04-30 00:25 - 2013-04-30 00:25 - 00103424 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
2013-06-18 16:49 - 2013-06-18 16:49 - 00016384 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll
2013-04-30 00:08 - 2013-04-30 00:08 - 00369152 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
2013-04-21 21:44 - 2013-04-21 21:44 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2013-04-21 21:44 - 2013-04-21 21:44 - 01242952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2014-09-24 22:09 - 2014-09-23 00:06 - 01098056 _____ () C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.124\libglesv2.dll
2014-09-24 22:09 - 2014-09-23 00:06 - 00174408 _____ () C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.124\libegl.dll
2014-09-24 22:09 - 2014-09-23 00:07 - 08577864 _____ () C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.124\pdf.dll
2014-09-24 22:09 - 2014-09-23 00:07 - 00331592 _____ () C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.124\ppGoogleNaClPluginChrome.dll
2014-09-24 22:09 - 2014-09-23 00:06 - 01660232 _____ () C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.124\ffmpegsumo.dll
 
==================== Alternate Data Streams (whitelisted) =========
 
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
 
 
==================== Safe Mode (whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
 
==================== EXE Association (whitelisted) =============
 
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
 
 
==================== MSCONFIG/TASK MANAGER disabled items =========
 
(Currently there is no automatic fix for this section.)
 
MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
 
========================= Accounts: ==========================
 
Administrator (S-1-5-21-3478498415-794229227-1261764834-500 - Administrator - Disabled)
AthlonX4 (S-1-5-21-3478498415-794229227-1261764834-1000 - Administrator - Enabled) => C:\Users\AthlonX4
Guest (S-1-5-21-3478498415-794229227-1261764834-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3478498415-794229227-1261764834-1003 - Limited - Enabled)
 
==================== Faulty Device Manager Devices =============
 
Name: Standard PS/2 Keyboard
Description: Standard PS/2 Keyboard
Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard keyboards)
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
 
Name: Microsoft PS/2 Mouse
Description: Microsoft PS/2 Mouse
Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
 
Name: USB Wireless 802.11 b/g Adaptor
Description: USB Wireless 802.11 b/g Adaptor
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Lite-On
Service: netr7364
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (10/13/2014 07:57:59 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (10/13/2014 07:55:36 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 512) (User: )
Description: The Cryptographic Services service failed to initialize the VSS backup "System Writer" object.
 
 
Details:
Could not query the status of the EventSystem service.
 
System Error:
A system shutdown is in progress.
.
 
Error: (10/13/2014 07:18:39 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (10/13/2014 07:04:18 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program majmbot_gentleca.tmp version 51.52.0.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: 1038
 
Start Time: 01cfe739ebeaf465
 
Termination Time: 16
 
Application Path: C:\Users\AthlonX4\AppData\Local\Temp\is-L8IF4.tmp\majmbot_gentleca.tmp
 
Report Id:
 
Error: (10/13/2014 07:01:32 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (10/13/2014 07:00:44 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program Explorer.EXE version 6.1.7601.17567 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: 6e0
 
Start Time: 01cfe73964d65e82
 
Termination Time: 980
 
Application Path: C:\Windows\Explorer.EXE
 
Report Id: c07f31e0-532c-11e4-bbd4-001cf09f0e76
 
Error: (10/13/2014 05:19:50 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program IEXPLORE.EXE version 11.0.9600.17280 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: 13c8
 
Start Time: 01cfe72b688c64f2
 
Termination Time: 10
 
Application Path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
 
Report Id:
 
Error: (10/13/2014 05:08:52 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (10/13/2014 04:23:52 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (10/13/2014 03:39:48 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
 
 
System errors:
=============
Error: (10/13/2014 07:58:48 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Google Update Service (gupdate) service failed to start due to the following error: 
%%2
 
Error: (10/13/2014 07:54:50 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
%%1068
 
Error: (10/13/2014 07:54:50 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
%%1068
 
Error: (10/13/2014 07:54:50 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
%%1068
 
Error: (10/13/2014 07:52:42 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
%%1068
 
Error: (10/13/2014 07:52:42 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
%%1068
 
Error: (10/13/2014 07:52:42 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
%%1068
 
Error: (10/13/2014 07:47:42 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
%%1068
 
Error: (10/13/2014 07:47:42 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
%%1068
 
Error: (10/13/2014 07:47:42 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
%%1068
 
 
Microsoft Office Sessions:
=========================
Error: (10/13/2014 07:57:59 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (10/13/2014 07:55:36 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 512) (User: )
Description: 
Details:
Could not query the status of the EventSystem service.
 
System Error:
A system shutdown is in progress.
 
Error: (10/13/2014 07:18:39 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (10/13/2014 07:04:18 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: majmbot_gentleca.tmp51.52.0.0103801cfe739ebeaf46516C:\Users\AthlonX4\AppData\Local\Temp\is-L8IF4.tmp\majmbot_gentleca.tmp
 
Error: (10/13/2014 07:01:32 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (10/13/2014 07:00:44 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Explorer.EXE6.1.7601.175676e001cfe73964d65e82980C:\Windows\Explorer.EXEc07f31e0-532c-11e4-bbd4-001cf09f0e76
 
Error: (10/13/2014 05:19:50 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: IEXPLORE.EXE11.0.9600.1728013c801cfe72b688c64f210C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
 
Error: (10/13/2014 05:08:52 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (10/13/2014 04:23:52 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (10/13/2014 03:39:48 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestc:\program files (x86)\ESET\eset online scanner\ESETSmartInstaller.exe
 
 
==================== Memory info =========================== 
 
Processor: AMD Athlon™ II X4 635 Processor
Percentage of memory in use: 65%
Total physical RAM: 4094.29 MB
Available physical RAM: 1426.93 MB
Total Pagefile: 8186.76 MB
Available Pagefile: 5026.23 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:362.68 GB) (Free:24.62 GB) NTFS
Drive x: (Storage) (Fixed) (Total:335.85 GB) (Free:270.63 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 698.6 GB) (Disk ID: FE6840BD)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=362.7 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=335.9 GB) - (Type=07 NTFS)
 
==================== End Of Log ============================

 

Hi there,
my name is Marius and I will assist you with your malware related problems.

Before we move on, please read the following points carefully.

  • First, read my instructions completely. If there is anything that you do not understand kindly ask before proceeding.
  • Perform everything in the correct order. Sometimes one step requires the previous one.
  • If you have any problems while following my instructions, Stop there and tell me the exact nature of your problem.
  • Do not run any other scans without instruction or add/remove software unless I tell you to do so. This would change the output of our tools and could be confusing for me.
  • Post all logfiles as a reply rather than as an attachment unless I specifically ask you. If you can not post all logfiles in one reply, feel free to use more posts.
  • If I don't hear from you within 3 days from this initial or any subsequent post, then this thread will be closed.
  • Stay with me. I will give you some advice about prevention after the cleanup process. Absence of symptoms does not always mean the computer is clean.
  • My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.
  • Important: To help me reviewing your logs, please post them in code boxes. You can create them by clicking on the <>-symbol on top of the reply window.

 

 

 

 

Going over your logs I noticed that you have uTorrent installed.

  • Avoid gaming sites, pirated software, cracking tools, keygens, and peer-to-peer (P2P) file sharing programs.
  • They are a security risk which can make your computer susceptible to a wide variety of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites.
  • Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and malicious Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users.
  • The best way to reduce the risk of infection is to avoid these types of web sites and not use any P2P applications.

It is pretty much certain that if you continue to use P2P programs, you will get infected again.
I would recommend that you uninstall uTorrent, however that choice is up to you. If you choose to remove these programs, you can do so via Start > Control Panel > Add/Remove Programs.
If you wish to keep it, please do not use it until your computer is cleaned.

 

 

 

 

 

We need to remove some programs with Revo Uninstaller Free:


Note: Revo Uninstaller is more thorough in deleting programs on your computer than using the Add/Remove option in Windows. Since it is a more powerful tool, please be sure to follow the instructions carefully.
Note: If the program you want to uninstall is not listed by Revo, let me know and we will try an altenate method of removal.

  • Please download and install Revo Uninstaller Free
    note: there is no need to click anything on that page, the download will start automatically
  • Double click Revo Uninstaller to run it
  • From the list of programs double click on the listed program(s), or anything similar, to remove it:
    AnyProtect
    
    HitsBlender
  • When prompted if you want to uninstall click Yes
  • Be sure the Moderate option is selected then click Next
  • The program will run, If prompted again click Yes
  • When the built-in uninstaller is finished click on Next
  • Once the program has searched for leftovers click Next
  • Check the items in bold only on the list then click Delete
    note: you may have to expand some folders by clicking the "+" mark
  • When prompted click on Yes and then on Next
  • Put a check on any folders that are found and select Delete
  • When prompted select Yes then Next
  • Once done click Finish

 

 

 

 

Fix with FRST (normal mode)

WARNING: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
 

  • Download the attached fixlist.txt and save it to the location where FRST is saved to.
  • Run FRST.exe (on 64bit, run FRST64.exe) and press the Fix button just once and wait.
  • The tool will make a log (Fixlog.txt) which you find where you saved FRST. Please post it to your reply.

 

 

 

 

 

Full System Scan with Malwarebytes Antimalware
 

  • If not existing, please download Malwarebytes Anti-Malware to your desktop.
  • Double-click the downloaded setup file and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to the following:
    • Launch Malwarebytes Anti-Malware
    • A 14 day trial of the Premium features is pre-selected. You may deselect this if you wish, and it will not diminish the scanning and removal capabilities of the program.
  • Click Finish.

If the program is already installed:

  • Run Malwarebytes Antimalware
  • On the Dashboard, click the 'Update Now >>' link
  • After the update completes, click the 'Scan Now >>' button.
  • Or, on the Dashboard, click the Scan Now >> button.
  • If an update is available, click the Update Now button.
  • A Threat Scan will begin.
  • When the scan is complete, if there have been detections, click Apply Actions to allow MBAM to clean what was detected.
  • In most cases, a restart will be required.
  • Wait for the prompt to restart the computer to appear, then click on Yes.

  • After the restart once you are back at your desktop, open MBAM once more.
  • Click on the History tab > Application Logs.
  • Double click on the scan log which shows the Date and time of the scan just performed.
  • Click 'Copy to Clipboard'
  • Paste the contents of the clipboard into your reply.

 

 

Attachments:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 12-10-2014 02
Ran by [removed] at 2014-10-14 10:06:07 Run:1
Running from C:\Users\[removed]\Desktop
[removed]
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
Task: {DB78C641-F7C6-4D6D-8A20-347288A091A8} - System32\Tasks\APSnotifierPP2 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe [2014-10-13] (AnyProtect.com) <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP1.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP2.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP3.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {8C734488-7E68-4C0E-B08E-F2B42A19517B} - System32\Tasks\RegClean Pro_UPDATES => C:\Program Files (x86)\RCP\RegCleanPro.exe <==== ATTENTION
Task: {9F9771BC-9D59-4043-8188-B11E2E90716E} - \WSE_Astromenda No Task File <==== ATTENTION
Task: {5B469382-0887-4F49-82ED-5C2852AC19A1} - \Advanced-System Protector_startup No Task File <==== ATTENTION
Task: {60E9E589-B3C0-4B5B-AA89-A71C7DA51B68} - System32\Tasks\APSnotifierPP1 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe [2014-10-13] (AnyProtect.com) <==== ATTENTION
Task: {6954AED3-427F-409D-848D-186F98A72B97} - System32\Tasks\APSnotifierPP3 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe [2014-10-13] (AnyProtect.com) <==== ATTENTION
Task: {246599A1-3E01-4F84-8B38-B9BF8A56E65A} - \BlockAndSurf Update No Task File <==== ATTENTION
Task: {2B716B13-3F00-4339-A656-A71EAEFACCEA} - \RegClean Pro_DEFAULT No Task File <==== ATTENTION
Task: {34EE09F1-DA78-41A9-85DA-615AE51ADB38} - \Update Service YourFileDownloader No Task File <==== ATTENTION
Task: {4E8BEF54-10DC-4E6D-A934-745B4FEC0103} - \RegClean Pro No Task File <==== ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
CHR Extension: (PriceLess) - C:\Users\AthlonX4\AppData\Local\Google\Chrome\User Data\Default\Extensions\abdjjfhfjceapcnapdhbkimaojpadfde\5.2 [2014-10-13]
CHR Extension: (PriceLess) - C:\Users\AthlonX4\AppData\Local\Google\Chrome\User Data\Default\Extensions\abdjjfhfjceapcnapdhbkimaojpadfde [2014-10-13]
SearchScopes: HKCU - DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = 
SearchScopes: HKCU - {2E00D31D-D171-423D-836D-1A4D7EA7F1A9} URL = http://www.trovi.com…rchTerms}&SSPV=
SearchScopes: HKLM - {2E00D31D-D171-423D-836D-1A4D7EA7F1A9} URL = 
HKU\S-1-5-21-3478498415-794229227-1261764834-1000\…\Run: [HitsBlender] => C:\Program Files (x86)\HitsBlender\hitsblender.exe [1596472 2014-10-13] ()
HKU\S-1-5-21-3478498415-794229227-1261764834-1000\…\MountPoints2: {2be1db6c-08cb-11e3-9bec-001cf09f0e76} - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL E:\drivers\setup.exe
HKU\S-1-5-21-3478498415-794229227-1261764834-1000\…\MountPoints2: {5358d9e2-d87c-11e2-af39-90fba64bf37d} - J:\INSTALL.EXE
HKU\S-1-5-21-3478498415-794229227-1261764834-1000\…\MountPoints2: {ca287faf-b868-11e3-8e8d-001cf09f0e76} - E:\HTC_Sync_Manager_PC.exe

R2 webinstrNew; C:\Windows\system32\Drivers\webinstrNew.sys [56504 2014-10-13] (Corsica)

2014-10-13 16:15 - 2014-10-13 19:59 - 00000000 ____D () C:\Users\AthlonX4\AppData\Local\HitsBlender
2014-10-13 16:15 - 2014-10-13 19:55 - 00000000 ____D () C:\Users\AthlonX4\AppData\Roaming\Systweak
2014-10-13 16:15 - 2014-10-13 19:55 - 00000000 ____D () C:\ProgramData\Systweak
2014-10-13 16:15 - 2014-10-13 16:15 - 00003026 _____ () C:\Windows\System32\Tasks\RegClean Pro_UPDATES
2014-10-13 16:15 - 2014-10-13 16:15 - 00000000 ____D () C:\Users\AthlonX4\AppData\Local\cache
2014-10-13 16:15 - 2014-10-06 16:36 - 00020296 _____ () C:\Windows\system32\roboot64.exe
2014-10-13 16:14 - 2014-10-13 16:55 - 00000600 __RSH () C:\ProgramData\ntuser.pol
2014-10-13 16:14 - 2014-10-13 16:15 - 00000004 _____ () C:\end
2014-10-13 16:14 - 2014-10-13 16:14 - 00003118 _____ () C:\Windows\System32\Tasks\Update Service HitsBlender
2014-10-13 16:14 - 2014-10-13 16:14 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Torch
2014-10-13 16:14 - 2014-10-13 16:14 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Google
2014-10-13 16:14 - 2014-10-13 16:14 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Comodo
2014-10-13 16:14 - 2014-10-13 16:14 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Chromatic Browser
2014-10-13 16:14 - 2014-10-13 16:14 - 00000000 ____D () C:\Users\HomeGroupUser$
2014-10-13 16:14 - 2014-10-13 16:14 - 00000000 ____D () C:\Users\Guest\AppData\Local\Torch
2014-10-13 16:14 - 2014-10-13 16:14 - 00000000 ____D () C:\Users\Guest\AppData\Local\Google
2014-10-13 16:14 - 2014-10-13 16:14 - 00000000 ____D () C:\Users\Guest\AppData\Local\Comodo
2014-10-13 16:14 - 2014-10-13 16:14 - 00000000 ____D () C:\Users\Guest\AppData\Local\Chromatic Browser
2014-10-13 16:14 - 2014-10-13 16:14 - 00000000 ____D () C:\Users\Guest
2014-10-13 16:14 - 2014-10-13 16:14 - 00000000 ____D () C:\Users\AthlonX4\AppData\Local\Torch
2014-10-13 16:14 - 2014-10-13 16:14 - 00000000 ____D () C:\Users\AthlonX4\AppData\Local\Comodo
2014-10-13 16:14 - 2014-10-13 16:14 - 00000000 ____D () C:\Users\AthlonX4\AppData\Local\Chromatic Browser
2014-10-13 16:14 - 2014-10-13 16:14 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Torch
2014-10-13 16:14 - 2014-10-13 16:14 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google
2014-10-13 16:14 - 2014-10-13 16:14 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo
2014-10-13 16:14 - 2014-10-13 16:14 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Chromatic Browser
2014-10-13 16:14 - 2014-10-13 16:14 - 00000000 ____D () C:\Users\Administrator
2014-10-13 16:14 - 2014-10-13 16:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\HitsBlender
2014-10-13 16:14 - 2014-10-13 16:14 - 00000000 ____D () C:\ProgramData\HitsBlender
2014-10-13 16:14 - 2014-10-13 16:14 - 00000000 ____D () C:\ProgramData\c4ca3d2e5a673ccf
2014-10-13 16:14 - 2014-10-13 16:14 - 00000000 ____D () C:\Program Files (x86)\HitsBlenderUpdater
2014-10-13 16:14 - 2014-10-13 16:14 - 00000000 ____D () C:\Program Files (x86)\HitsBlender
2014-10-13 16:12 - 2014-10-13 16:13 - 03611152 _____ (http://yourfile-downloader.com) C:\Users\AthlonX4\Downloads\lol_a_plus_v1_2_downloader.exe 
2014-10-13 16:56 - 2014-10-13 17:16 - 00000378 _____ () C:\Windows\Tasks\APSnotifierPP1.job
2014-10-13 16:56 - 2014-10-13 17:07 - 00000376 _____ () C:\Windows\Tasks\APSnotifierPP3.job
2014-10-13 16:56 - 2014-10-13 17:07 - 00000376 _____ () C:\Windows\Tasks\APSnotifierPP2.job
2014-10-13 16:56 - 2014-10-13 16:57 - 00001238 _____ () C:\Users\AthlonX4\AppData\Roaming\aps.scan.quick.results
2014-10-13 16:56 - 2014-10-13 16:56 - 00612152 _____ (CMI Limited) C:\Users\AthlonX4\AppData\Local\nsxFD83.tmp
2014-10-13 16:56 - 2014-10-13 16:56 - 00002834 _____ () C:\Windows\System32\Tasks\APSnotifierPP1
2014-10-13 16:56 - 2014-10-13 16:56 - 00002832 _____ () C:\Windows\System32\Tasks\APSnotifierPP3
2014-10-13 16:56 - 2014-10-13 16:56 - 00002832 _____ () C:\Windows\System32\Tasks\APSnotifierPP2
2014-10-13 16:56 - 2014-10-13 16:56 - 00000000 ____D () C:\Users\AthlonX4\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnyProtect PC Backup
2014-10-13 16:56 - 2014-10-13 16:56 - 00000000 ____D () C:\Users\AthlonX4\AppData\Roaming\ap_movie
2014-10-13 16:56 - 2014-10-13 16:56 - 00000000 ____D () C:\Users\AthlonX4\AppData\Roaming\AnyProtectEx
2014-10-13 16:56 - 2014-10-13 16:56 - 00000000 ____D () C:\Program Files (x86)\AnyProtectEx
2014-10-13 16:56 - 2014-10-13 16:56 - 00000000 _____ () C:\Users\AthlonX4\AppData\Roaming\aps.scan.results
2014-10-13 16:55 - 2014-10-13 16:55 - 00056504 _____ (Corsica) C:\Windows\system32\Drivers\webinstrNew.sys
2014-10-13 16:55 - 2014-10-13 16:55 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_webinstrNew_01009.Wdf
C:\Program Files (x86)\AnyProtectEx
C:\Program Files (x86)\RCP

EmptyTemp:
*****************

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DB78C641-F7C6-4D6D-8A20-347288A091A8}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DB78C641-F7C6-4D6D-8A20-347288A091A8}" => Key deleted successfully.
C:\Windows\System32\Tasks\APSnotifierPP2 => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\APSnotifierPP2" => Key deleted successfully.
C:\Windows\Tasks\APSnotifierPP1.job => Moved successfully.
C:\Windows\Tasks\APSnotifierPP2.job => Moved successfully.
C:\Windows\Tasks\APSnotifierPP3.job => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8C734488-7E68-4C0E-B08E-F2B42A19517B}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8C734488-7E68-4C0E-B08E-F2B42A19517B}" => Key deleted successfully.
C:\Windows\System32\Tasks\RegClean Pro_UPDATES => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RegClean Pro_UPDATES" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9F9771BC-9D59-4043-8188-B11E2E90716E}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9F9771BC-9D59-4043-8188-B11E2E90716E}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WSE_Astromenda" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{5B469382-0887-4F49-82ED-5C2852AC19A1}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5B469382-0887-4F49-82ED-5C2852AC19A1}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Advanced-System Protector_startup" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{60E9E589-B3C0-4B5B-AA89-A71C7DA51B68}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{60E9E589-B3C0-4B5B-AA89-A71C7DA51B68}" => Key deleted successfully.
C:\Windows\System32\Tasks\APSnotifierPP1 => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\APSnotifierPP1" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6954AED3-427F-409D-848D-186F98A72B97}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6954AED3-427F-409D-848D-186F98A72B97}" => Key deleted successfully.
C:\Windows\System32\Tasks\APSnotifierPP3 => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\APSnotifierPP3" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{246599A1-3E01-4F84-8B38-B9BF8A56E65A}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{246599A1-3E01-4F84-8B38-B9BF8A56E65A}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BlockAndSurf Update" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2B716B13-3F00-4339-A656-A71EAEFACCEA}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2B716B13-3F00-4339-A656-A71EAEFACCEA}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RegClean Pro_DEFAULT" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{34EE09F1-DA78-41A9-85DA-615AE51ADB38}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{34EE09F1-DA78-41A9-85DA-615AE51ADB38}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Update Service YourFileDownloader" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{4E8BEF54-10DC-4E6D-A934-745B4FEC0103}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4E8BEF54-10DC-4E6D-A934-745B4FEC0103}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RegClean Pro" => Key deleted successfully.
"HKLM\SOFTWARE\Policies\Google" => Key deleted successfully.
C:\Users\AthlonX4\AppData\Local\Google\Chrome\User Data\Default\Extensions\abdjjfhfjceapcnapdhbkimaojpadfde\5.2 => Moved successfully.
C:\Users\AthlonX4\AppData\Local\Google\Chrome\User Data\Default\Extensions\abdjjfhfjceapcnapdhbkimaojpadfde => Moved successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
"HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}" => Key deleted successfully.
"HKCR\CLSID\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}" => Key not found.
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}" => Key deleted successfully.
"HKCR\CLSID\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}" => Key not found.
HKU\S-1-5-21-3478498415-794229227-1261764834-1000\Software\Microsoft\Windows\CurrentVersion\Run\\HitsBlender => Value not found.
"HKU\S-1-5-21-3478498415-794229227-1261764834-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2be1db6c-08cb-11e3-9bec-001cf09f0e76}" => Key deleted successfully.
"HKCR\CLSID\{2be1db6c-08cb-11e3-9bec-001cf09f0e76}" => Key not found.
"HKU\S-1-5-21-3478498415-794229227-1261764834-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5358d9e2-d87c-11e2-af39-90fba64bf37d}" => Key deleted successfully.
"HKCR\CLSID\{5358d9e2-d87c-11e2-af39-90fba64bf37d}" => Key not found.
"HKU\S-1-5-21-3478498415-794229227-1261764834-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ca287faf-b868-11e3-8e8d-001cf09f0e76}" => Key deleted successfully.
"HKCR\CLSID\{ca287faf-b868-11e3-8e8d-001cf09f0e76}" => Key not found.
webinstrNew => Service stopped successfully.
webinstrNew => Service deleted successfully.
C:\Users\AthlonX4\AppData\Local\HitsBlender => Moved successfully.
C:\Users\AthlonX4\AppData\Roaming\Systweak => Moved successfully.
C:\ProgramData\Systweak => Moved successfully.
"C:\Windows\System32\Tasks\RegClean Pro_UPDATES" => File/Directory not found.
C:\Users\AthlonX4\AppData\Local\cache => Moved successfully.
C:\Windows\system32\roboot64.exe => Moved successfully.
C:\ProgramData\ntuser.pol => Moved successfully.
C:\end => Moved successfully.
C:\Windows\System32\Tasks\Update Service HitsBlender => Moved successfully.
C:\Users\HomeGroupUser$\AppData\Local\Torch => Moved successfully.
C:\Users\HomeGroupUser$\AppData\Local\Google => Moved successfully.
C:\Users\HomeGroupUser$\AppData\Local\Comodo => Moved successfully.
C:\Users\HomeGroupUser$\AppData\Local\Chromatic Browser => Moved successfully.
C:\Users\HomeGroupUser$ => Moved successfully.
C:\Users\Guest\AppData\Local\Torch => Moved successfully.
C:\Users\Guest\AppData\Local\Google => Moved successfully.
C:\Users\Guest\AppData\Local\Comodo => Moved successfully.
C:\Users\Guest\AppData\Local\Chromatic Browser => Moved successfully.
C:\Users\Guest => Moved successfully.
C:\Users\AthlonX4\AppData\Local\Torch => Moved successfully.
C:\Users\AthlonX4\AppData\Local\Comodo => Moved successfully.
C:\Users\AthlonX4\AppData\Local\Chromatic Browser => Moved successfully.
C:\Users\Administrator\AppData\Local\Torch => Moved successfully.
C:\Users\Administrator\AppData\Local\Google => Moved successfully.
C:\Users\Administrator\AppData\Local\Comodo => Moved successfully.
C:\Users\Administrator\AppData\Local\Chromatic Browser => Moved successfully.
C:\Users\Administrator => Moved successfully.
"C:\ProgramData\Microsoft\Windows\Start Menu\HitsBlender" => File/Directory not found.
C:\ProgramData\HitsBlender => Moved successfully.
C:\ProgramData\c4ca3d2e5a673ccf => Moved successfully.
C:\Program Files (x86)\HitsBlenderUpdater => Moved successfully.
"C:\Program Files (x86)\HitsBlender" => File/Directory not found.
C:\Users\AthlonX4\Downloads\lol_a_plus_v1_2_downloader.exe => Moved successfully.
"C:\Windows\Tasks\APSnotifierPP1.job" => File/Directory not found.
"C:\Windows\Tasks\APSnotifierPP3.job" => File/Directory not found.
"C:\Windows\Tasks\APSnotifierPP2.job" => File/Directory not found.
"C:\Users\AthlonX4\AppData\Roaming\aps.scan.quick.results" => File/Directory not found.
C:\Users\AthlonX4\AppData\Local\nsxFD83.tmp => Moved successfully.
"C:\Windows\System32\Tasks\APSnotifierPP1" => File/Directory not found.
"C:\Windows\System32\Tasks\APSnotifierPP3" => File/Directory not found.
"C:\Windows\System32\Tasks\APSnotifierPP2" => File/Directory not found.
"C:\Users\AthlonX4\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnyProtect PC Backup" => File/Directory not found.
C:\Users\AthlonX4\AppData\Roaming\ap_movie => Moved successfully.
C:\Users\AthlonX4\AppData\Roaming\AnyProtectEx => Moved successfully.
"C:\Program Files (x86)\AnyProtectEx" => File/Directory not found.
"C:\Users\AthlonX4\AppData\Roaming\aps.scan.results" => File/Directory not found.
C:\Windows\system32\Drivers\webinstrNew.sys => Moved successfully.
C:\Windows\system32\Drivers\Msft_Kernel_webinstrNew_01009.Wdf => Moved successfully.
"C:\Program Files (x86)\AnyProtectEx" => File/Directory not found.
"C:\Program Files (x86)\RCP" => File/Directory not found.
EmptyTemp: => Removed 4.6 GB temporary data.


The system needed a reboot. 

==== End of Fixlog ====
Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 10/14/2014
Scan Time: 10:14:57 AM
Logfile: 
Administrator: Yes

Version: 2.00.3.1025
Malware Database: v2014.10.14.09
Rootkit Database: v2014.10.11.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: AthlonX4

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 348798
Time Elapsed: 45 min, 8 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)


(end)

Scan with ESET Online Scan

Go here to run an online scannner from ESET. Windows Vista/Windows 7/Windows 8 users will need to right click on their Internet Explorer shortcut, and select Run as Administrator

  • Note: For browsers other than Internet Explorer, you will be prompted to download and install esetsmartinstaller_enu.exe. Click on the link and save the file to a convenient location. Double click on it to install and a new window will open. Follow the prompts.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan. Here's how.
  • Click the blue Run ESET Online Scanner button
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the program to install the "OnlineScanner.cab" activex control by clicking the Install button
  • Once the activex control is installed, on the next screen click on Enable detection of potentially unwanted applications
  • Click on Advanced Settings
  • Make sure that the option Remove found threats is unticked.
  • Ensure these options are ticked
    • Scan archives
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
    • Click Start
    • Wait for the scan to finish
    • When the scan is done, if it shows a screen that says "Threats found!", then click "List of found threats", and then click "Export to text file…"
    • Save that text file on your desktop. Copy and paste the contents of that log as a reply to this topic.
    • Close the ESET online scan, and let me know how things are now.

    C:\FRST\Quarantine\C\Program Files (x86)\HitsBlenderUpdater\Uninstall.exe	a variant of Win32/ExpressDownloader.K potentially unwanted application
    C:\FRST\Quarantine\C\Users\AthlonX4\AppData\Local\nsxFD83.tmp.xBAD	Win32/AnyProtect.F potentially unwanted application
    C:\FRST\Quarantine\C\Users\AthlonX4\Downloads\lol_a_plus_v1_2_downloader.exe.xBAD	a variant of Win32/ExpressDownloader.K potentially unwanted application
    C:\FRST\Quarantine\C\Windows\System32\roboot64.exe.xBAD	a variant of Win64/Systweak.A potentially unwanted application
    C:\Users\AthlonX4\Downloads\BloodlineChampionsInstaller.exe	Win32/OpenCandy potentially unsafe application
    C:\Users\AthlonX4\Downloads\rcsetup151.exe	Win32/Bundled.Toolbar.Google.D potentially unsafe application
    X:\Games\Bridgebuilder\Bridge Project version 1.dat	Win32/HackTool.Crack.BQ potentially unsafe application
    X:\Games2\The Cave w updates\The Cave.dat	a variant of Win32/HackTool.Crack.CC potentially unsafe application
    
    

    Computer seems to run fine, settings seem to be back to normal in all of my browsers.

    Then we can do the cleanup - if you are facing any issues, report that immediately.

    Delete junk with adwCleaner


    Please download AdwCleaner to your desktop.


    • Run adwcleaner.exe

    • Hit Scan and wait for the scan to finish.

    • Confirm the message but don´t uncheck anything.

    • Hit Clean

    • When the run is finished, it will open up a text file

    • Please post its contents within your next reply

    • You´ll find the log file at C:\AdwCleaner[S1].txt also




    Delete junk with JRT

    [external image: thisisujrt.gif] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.

    • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".

    • The tool will open and start scanning your system.

    • Please be patient as this can take a while to complete depending on your system's specifications.

    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.

    • Post the contents of JRT.txt into your next message.




    SecurityCheck

    Reboot your system before starting!

    Please download SecurityCheck: LINK Mirror (if the link is down)

    • Save it to your desktop, start it and follow the instructions in the window.

    • After the scan finished the (checkup.txt) will open. Copy its content to your thread (Note: Do NOT post this one into a code box!

    # AdwCleaner v4.001 - Report created 21/10/2014 at 17:51:06
    # DB v2014-10-21.1
    # Updated 20/10/2014 by Xplode
    # Operating System : Windows 7 Ultimate Service Pack 1 (64 bits)
    # Username : AthlonX4 - ATHLONX4-PC
    # Running from : C:\Users\AthlonX4\Desktop\adwcleaner_4.001.exe
    # Option : Clean
    
    ***** [ Services ] *****
    
    
    ***** [ Files / Folders ] *****
    
    Folder Deleted : C:\Users\AthlonX4\AppData\Roaming\ap_logs
    Folder Deleted : C:\Users\AthlonX4\AppData\Roaming\Mozilla\Firefox\Profiles\9njvwb2g.default\Extensions\{ad7ce998-a77b-4062-9ffb-1d0b7cb23183}
    File Deleted : C:\Users\AthlonX4\AppData\Roaming\Mozilla\Firefox\Profiles\9njvwb2g.default\user.js
    File Deleted : C:\Users\AthlonX4\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.azlyrics.com_0.localstorage
    File Deleted : C:\Users\AthlonX4\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
    
    ***** [ Scheduled Tasks ] *****
    
    
    ***** [ Shortcuts ] *****
    
    
    ***** [ Registry ] *****
    
    Value Deleted : HKCU\Software\Mozilla\Firefox\Extensions [{065AE54A-C4EC-DDF1-946A-2A571D1C6A41}]
    Key Deleted : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.superfish.com
    Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\superfish.com
    Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.superfish.com
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
    Key Deleted : HKCU\Software\BRS
    Key Deleted : HKCU\Software\genesis
    Key Deleted : HKCU\Software\RegisteredApplicationsEx
    Key Deleted : HKCU\Software\systweak
    Key Deleted : HKCU\Software\Tutorials
    Key Deleted : HKLM\SOFTWARE\InstallCore
    Key Deleted : HKLM\SOFTWARE\systweak
    Key Deleted : HKLM\SOFTWARE\Tutorials
    Key Deleted : HKLM\SOFTWARE\YourFileDownloader
    
    ***** [ Browsers ] *****
    
    -\\ Internet Explorer v11.0.9600.17344
    
    
    -\\ Mozilla Firefox v29.0.1 (en-US)
    
    
    -\\ Google Chrome v37.0.2062.124
    
    
    *************************
    
    AdwCleaner[R0].txt - [2368 octets] - [21/10/2014 17:49:11]
    AdwCleaner[S0].txt - [2099 octets] - [21/10/2014 17:51:06]
    
    ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2159 octets] ##########
    
    
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Junkware Removal Tool (JRT) by Thisisu
    Version: 6.3.3 (10.21.2014:1)
    OS: Windows 7 Ultimate x64
    Ran by [removed] on Tue 10/21/2014 at 17:55:25.29
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    
    
    
    
    ~~~ Services
    
    
    
    ~~~ Registry Values
    
    
    
    ~~~ Registry Keys
    
    
    
    ~~~ Files
    
    
    
    ~~~ Folders
    
    Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin"
    
    
    
    ~~~ FireFox
    
    Successfully deleted the following from C:\Users\AthlonX4\AppData\Roaming\mozilla\firefox\profiles\9njvwb2g.default\prefs.js
    
    user_pref("browser.search.selectedEngine", "Astromenda");
    user_pref("extensions.aB4XoVbxMrUNSy6p.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11
    user_pref("extensions.astrmndasr.hmpgUrl", "hxxp://astromenda.com/?f=1&a=ast_cmi_14_42_ie&cd=2XzuyEtN2Y1L1QzutDtDtC0C0FtDzy0FtD0EyByCtD0ByBtCtN0D0Tzu0StCtDtCyBtN1L2XzutAtFtBtF
    user_pref("extensions.astrmndasr.newTabUrl", "hxxp://astromenda.com/?f=2&a=ast_cmi_14_42_ie&cd=2XzuyEtN2Y1L1QzutDtDtC0C0FtDzy0FtD0EyByCtD0ByBtCtN0D0Tzu0StCtDtCyBtN1L2XzutAtFtB
    user_pref("extensions.astrmndasr.prtnrId", "WSE_Astromenda");
    user_pref("extensions.astrmndasr.srchPrvdr", "Astromenda");
    user_pref("extensions.astrmndasr.tlbrSrchUrl", "hxxp://astromenda.com/?f=3&a=ast_cmi_14_42_ie&cd=2XzuyEtN2Y1L1QzutDtDtC0C0FtDzy0FtD0EyByCtD0ByBtCtN0D0Tzu0StCtDtCyBtN1L2XzutAtF
    Emptied folder: C:\Users\AthlonX4\AppData\Roaming\mozilla\firefox\profiles\9njvwb2g.default\minidumps [97 files]
    
    
    
    ~~~ Event Viewer Logs were cleared
    
    
    
    
    
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Scan was completed on Tue 10/21/2014 at 17:58:36.21
    End of JRT log
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    
    
     Results of screen317's Security Check version 0.99.89  
     Windows 7 Service Pack 1 x64 (UAC is enabled)  
     Internet Explorer 11  
    ``````````````Antivirus/Firewall Check:`````````````` 
     Windows Firewall Enabled!  
    Microsoft Security Essentials   
      (On Access scanning disabled!) 
     Error obtaining update status for antivirus!  
    `````````Anti-malware/Other Utilities Check:````````` 
     Java 7 Update 67  
     Adobe Flash Player 15.0.0.152  
     Mozilla Firefox 29.0.1 Firefox out of Date!  
     Google Chrome 37.0.2062.120  
     Google Chrome 37.0.2062.124  
    ````````Process Check: objlist.exe by Laurent````````  
     Microsoft Security Essentials MSMpEng.exe 
     Microsoft Security Essentials msseces.exe 
    `````````````````System Health check````````````````` 
     Total Fragmentation on Drive C: 1% 
    ````````````````````End of Log`````````````````````` 
     
     
     
    Turned Microsoft Security Essentials real-time protection back on after the scan.
    Hi lamaroo,

    TB-Psychotic isn't available for a day or two so let's see if I can help you get back to your regularly scheduled life.

    It looks like you're pretty much done. The one thing I'd add is that it appears that your version of a couple of games, Bridge Builder and The caves, may be hacked versions. I'd delete them immediately.

    That being said, it appears we can do some housekeeping:

    We need to remove the tools we've used during cleaning your machine
    • Download Delfix from here
    • Ensure Remove disinfection tools is ticked
      Also tick:
      • Create registry backup
      • Purge system restore
      [external image: delfix.jpg]
    • Click Run
    The program will run for a few moments and then notepad will open with a log. Please paste the log in your next reply


    Also please let me know if you have any outstanding issues.
    # DelFix v10.8 - Logfile created 22/10/2014 at 14:45:58
    # Updated 29/07/2014 by Xplode
    # Username : AthlonX4 - ATHLONX4-PC
    # Operating System : Windows 7 Ultimate Service Pack 1 (64 bits)
    
    ~ Removing disinfection tools …
    
    Deleted : C:\FRST
    Deleted : C:\AdwCleaner
    Deleted : C:\Users\AthlonX4\Desktop\Addition.txt
    Deleted : C:\Users\AthlonX4\Desktop\adwcleaner_4.001.exe
    Deleted : C:\Users\AthlonX4\Desktop\aswMBR.exe
    Deleted : C:\Users\AthlonX4\Desktop\aswMBR.txt
    Deleted : C:\Users\AthlonX4\Desktop\Fixlog.txt
    Deleted : C:\Users\AthlonX4\Desktop\FRST.txt
    Deleted : C:\Users\AthlonX4\Desktop\FRST64.exe
    Deleted : C:\Users\AthlonX4\Desktop\JRT.exe
    Deleted : C:\Users\AthlonX4\Desktop\JRT.txt
    Deleted : C:\Users\AthlonX4\Desktop\MBR.dat
    Deleted : C:\Users\AthlonX4\Desktop\SecurityCheck.exe
    Deleted : HKLM\SOFTWARE\AdwCleaner
    Deleted : HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWMBR
    
    ~ Creating registry backup … OK
    
    ~ Cleaning system restore …
    
    Deleted : RP #273 [Revo Uninstaller's restore point - AnyProtect | 10/14/2014 13:56:58]
    Deleted : RP #274 [Revo Uninstaller's restore point - HitsBlender | 10/14/2014 14:00:31]
    Deleted : RP #275 [Windows Update | 10/15/2014 23:13:24]
    Deleted : RP #276 [Windows Update | 10/16/2014 22:54:17]
    Deleted : RP #277 [Windows Update | 10/21/2014 02:05:21]
    
    New restore point created !
    
    ########## - EOF - ##########
    
    

    I don't think there are any other issues. Thanks to both of you for your help.

    lamaroo,
     

    The following is my standard advice for the future.  Use what you can and pat yourself on the back for what you're already doing.

    Please take time to read Preventing Malware - Tools and Practices for Safe Computing.  Very important information for your consideration is contained therein.

    I would also suggest you read this:
    So how did I get infected in the first place?
    by Tony Klein


    Also: "How to prevent malware" 
    by miekiemoes

    Please respond back that you understand the above and let me know if you have any questions.  Otherwise, this thread will be closed Resolved.  :thumbup:
     

    Ask AI

    AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

    Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI