Spyware / Malware / Virus Removal
Powershell stops working - Malware [Closed]
3 min read
rshuffler
Topic Starter
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-01-2015
Ran by [removed] (administrator) on INTERNATIONALST on 11-01-2015 11:25:37
Running from C:\Users\[removed]\Downloads
[removed]
Platform: Microsoft Windows 7 Enterprise Service Pack 1 (X86) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(Microsoft Corporation) C:\Windows\System32\audiodg.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Andrea Electronics Corporation) C:\Windows\System32\AEADISRV.EXE
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\Program Files\biforder\inspasio.exe
() C:\Windows\System32\Compatibility Verifier\compatibilitychecksvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
(Analog Devices, Inc.) C:\Program Files\Analog Devices\Core\smax4pnp.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPStart.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
() C:\Users\HP\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe
(Microsoft Corporation) C:\Windows\System32\wscript.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
() C:\Program Files\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
() C:\Windows\System32\Compatibility Verifier\compatibilitycheck.exe
() C:\Windows\System32\Compatibility Verifier\compatibilitycheck.exe
() C:\Windows\System32\Compatibility Verifier\compatibilitycheck.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(AVAST Software) C:\Users\HP\Downloads\aswMBR.exe
(Microsoft Corporation) C:\Windows\System32\wextract.exe
(Microsoft Corporation) C:\Windows\System32\logagent.exe
(Microsoft Corporation) C:\Windows\System32\dvdupgrd.exe
(Microsoft Corporation) C:\Windows\System32\cmmon32.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\System32\wextract.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\regsvr32.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
() C:\Windows\System32\Compatibility Verifier\compatibilitycheck.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [GrooveMonitor] => C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\…\Run: [SoundMAXPnP] => C:\Program Files\Analog Devices\Core\smax4pnp.exe [1183744 2007-02-21] (Analog Devices, Inc.)
HKLM\…\Run: [SynTPStart] => C:\Program Files\Synaptics\SynTP\SynTPStart.exe [102400 2007-09-15] (Synaptics, Inc.)
HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2419440 2013-08-28] (Synaptics Incorporated)
HKLM\…\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\…\Run: [AdobeAAMUpdater-1.0] => C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [557768 2014-09-19] (Adobe Systems Incorporated)
HKLM\…\Run: [Adobe Creative Cloud] => C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2694320 2014-10-01] (Adobe Systems Incorporated)
HKLM\…\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle Corporation)
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
HKLM\…\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKLM\…\Run: [gatvhse] => C:\Windows\system32\regsvr32.exe /s "C:\Windows\TEMP\xodeckl.dll" <===== ATTENTION
HKU\S-1-5-21-149010795-3013192795-5993443-1000\…\Run: [GoogleDriveSync] => "C:\Program Files\Google\Drive\googledrivesync.exe" /autostart
HKU\S-1-5-21-149010795-3013192795-5993443-1000\…\Run: [F217B4E389515BBEB70D850165311A2AC9CFEA46._service_run] => C:\Program Files\Google\Chrome\Application\chrome.exe [856904 2014-12-05] (Google Inc.)
HKU\S-1-5-21-149010795-3013192795-5993443-1000\…\Run: [Amazon Cloud Player] => C:\Users\HP\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe [3140608 2014-01-14] ()
HKU\S-1-5-21-149010795-3013192795-5993443-1000\…\Run: [DW7] => "C:\Program Files\The Weather Channel\The Weather Channel App\TWCApp.exe"
HKU\S-1-5-21-149010795-3013192795-5993443-1000\…\Run: [Microsofts] => wscript.exe //B "C:\Users\HP\AppData\Local\Temp\Microsofts.vbs" <===== ATTENTION
HKU\S-1-5-21-149010795-3013192795-5993443-1000\…\MountPoints2: {96f36ffb-1752-11e3-bbd2-984771969db5} - D:\Startme.exe
HKU\S-1-5-21-149010795-3013192795-5993443-1000\…A8F59079A8D5}\localserver32: rundll32.exe javascript:"\..\mshtml.dll,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf> (the data entry has 243 more characters). <==== Poweliks!
HKU\S-1-5-18\…\RunOnce: [FlashPlayerUpdate] => C:\Windows\system32\Macromed\Flash\FlashUtil32_15_0_0_246_Plugin.exe [855216 2014-12-10] (Adobe Systems Incorporated)
HKU\S-1-5-18\…A8F59079A8D5}\localserver32: <==== ATTENTION!
Startup: C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsofts.vbs ()
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x86.dll ()
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x86.dll ()
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x86.dll ()
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=en&pid=NIS&pvid=20.4.0.40
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=5.5&ar=msnhome
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=5.5&ar=msnhome
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=en&pid=NIS&pvid=20.4.0.40
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/spbasic.htm
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=5.5&ar=msnhome
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=en&pid=NIS&pvid=20.4.0.40
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/spbasic.htm
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=5.5&ar=msnhome
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=en&pid=NIS&pvid=20.4.0.40
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/spbasic.htm
HKU\S-1-5-21-149010795-3013192795-5993443-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-149010795-3013192795-5993443-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
HKU\S-1-5-21-149010795-3013192795-5993443-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=5.5&ar=msnhome
HKU\S-1-5-21-149010795-3013192795-5993443-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-149010795-3013192795-5993443-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/spbasic.htm
SearchScopes: HKLM -> DefaultScope {9485DB7F-ABAD-471E-A583-62D0915E84DF} URL =
SearchScopes: HKLM -> {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://start.sweetpacks.com/?src=6&q={searchTerms}&st=12&crg=3.5000006.10042&barid={658B37B2-8F86-11E2-857A-AFD0B6715CB3}
SearchScopes: HKU\.DEFAULT -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL =
SearchScopes: HKU\S-1-5-21-149010795-3013192795-5993443-1000 -> DefaultScope {9485DB7F-ABAD-471E-A583-62D0915E84DF} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3153924&CUI=UN53164740343441277&UM=2
SearchScopes: HKU\S-1-5-21-149010795-3013192795-5993443-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-149010795-3013192795-5993443-1000 -> {9485DB7F-ABAD-471E-A583-62D0915E84DF} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3153924&CUI=UN53164740343441277&UM=2
SearchScopes: HKU\S-1-5-21-149010795-3013192795-5993443-1000 -> {EEE6C360-6118-11DC-9C72-001320C79847} URL =
BHO: Lyrics Shout -> {533B3693-0C31-429D-9109-9D66A77E913F} -> C:\Program Files\LyricsShout\lshout.dll No File
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File
Toolbar: HKU\S-1-5-21-149010795-3013192795-5993443-1000 -> No Name - {EEE6C35B-6118-11DC-9C72-001320C79847} - No File
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_246.dll ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1200112.dll (Adobe Systems, Inc.)
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems)
FF HKLM\…\Firefox\Extensions: [{C4CFC0DE-134F-4466-B2A2-FF7C59A8BFAD}] - C:\Program Files\Updater By SweetPacks\Firefox
Chrome:
=======
CHR HomePage: Default -> hxxp://search.conduit.com/?ctid=CT3153924&SearchSource=48&CUI=UN36492685611081523&UM=2
CHR StartupUrls: Default -> "https://www.google.com/"
CHR Profile: C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (My Cloud CookBook) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\aejckjfbpmikajpelkgimkmkfbcfnacg [2013-05-04]
CHR Extension: (Angry Birds) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj [2013-03-14]
CHR Extension: (Google Docs) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-03-14]
CHR Extension: (Google Drive) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-03-14]
CHR Extension: (TV) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\beobeededemalmllhkmnkinmfembdimh [2013-05-04]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-15]
CHR Extension: (YouTube) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-03-14]
CHR Extension: (Guitarist's Reference) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\cddaabhppoebkmalboinjhgofbhdbcgk [2013-05-04]
CHR Extension: (Google Search) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-03-14]
CHR Extension: (Autodesk Homestyler) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdmmkfaghgcicheaimnpffeeekheafkb [2013-05-04]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2014-11-16]
CHR Extension: (Google Maps) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2013-05-04]
CHR Extension: (Google Wallet) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-21]
CHR Extension: (Gmail) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-03-14]
CHR Extension: (Learn Spanish - Qué Onda) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\pmcdjmebmeoobmdghjbjhbifoocbcmaj [2013-05-04]
CHR HKLM\…\Chrome\Extension: [eihlgbnhhkigaajnpjohgjldcmdhjiol] - C:\Users\HP\AppData\Local\CRE\eihlgbnhhkigaajnpjohgjldcmdhjiol.crx [Not Found]
CHR HKLM\…\Chrome\Extension: [jnidgldcbakaidffpjinopjbmobecifb] - C:\Users\HP\AppData\Local\CRE\jnidgldcbakaidffpjinopjbmobecifb.crx [Not Found]
CHR HKLM\…\Chrome\Extension: [jonjajmpblmjkhjemkalbddhodlehkfg] - C:\Users\HP\AppData\Local\CRE\jonjajmpblmjkhjemkalbddhodlehkfg.crx [2013-11-05]
CHR HKLM\…\Chrome\Extension: [kbemlhjodpfopddibpbppifmogphpmil] - C:\Users\HP\AppData\Local\CRE\kbemlhjodpfopddibpbppifmogphpmil.crx [Not Found]
CHR HKLM\…\Chrome\Extension: [ogccgbmabaphcakpiclgcnmcnimhokcj] - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847}\SweetNT.crx [2013-03-17]
CHR HKU\S-1-5-21-149010795-3013192795-5993443-1000\…\Chrome\Extension: [eihlgbnhhkigaajnpjohgjldcmdhjiol] - C:\Users\HP\AppData\Local\CRE\eihlgbnhhkigaajnpjohgjldcmdhjiol.crx [Not Found]
CHR HKU\S-1-5-21-149010795-3013192795-5993443-1000\…\Chrome\Extension: [jnidgldcbakaidffpjinopjbmobecifb] - C:\Users\HP\AppData\Local\CRE\jnidgldcbakaidffpjinopjbmobecifb.crx [Not Found]
CHR HKU\S-1-5-21-149010795-3013192795-5993443-1000\…\Chrome\Extension: [jonjajmpblmjkhjemkalbddhodlehkfg] - C:\Users\HP\AppData\Local\CRE\jonjajmpblmjkhjemkalbddhodlehkfg.crx [2013-11-05]
CHR HKU\S-1-5-21-149010795-3013192795-5993443-1000\…\Chrome\Extension: [kbemlhjodpfopddibpbppifmogphpmil] - C:\Users\HP\AppData\Local\CRE\kbemlhjodpfopddibpbppifmogphpmil.crx [Not Found]
CHR HKU\S-1-5-21-149010795-3013192795-5993443-1000\…\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - No Path
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 inspasio; C:\Program Files\biforder\inspasio.exe [626688 2014-10-07] () [File not signed]
R2 Verifies and fixes application compatibility issues; C:\Windows\system32\Compatibility Verifier\compatibilitychecksvc.exe [87208 2014-12-13] ()
S3 COMSysApp; %SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
S2 CouponarificService; C:\Program Files\08F60977-C840-42C6-A2D3-06E8FE3787F5\xtloowpkjv.exe [X]
S2 Level Quality Watcher; C:\Program Files\Level Quality Watcher\v1.01\levelqualitywatcher32.exe run options=01110010000000000000000000000000 sourceguid=F5D333A8-C748-4686-AE0A-9E008F670C22 [X]
S2 sarconsogulpe; C:\Program Files\sarconsogulpe\sarconsogulpe.exe run options=00001009990000000000000000000000 sourceguid=F5D333A8-C748-4686-AE0A-9E008F670C22 [X]
S2 updater; C:\Program Files\mediainformationaccess\updater.exe run options=0000000777000000000000000000000 source=mia [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S2 DgiVecp; C:\Windows\system32\Drivers\DgiVecp.sys [38400 2009-03-02] (Samsung Electronics Co., Ltd.) [File not signed]
R1 netfilter; C:\Windows\System32\drivers\netfilter.sys [36048 2014-11-19] (NetFilterSDK.com)
S3 netr28u; C:\Windows\System32\DRIVERS\netr28u.sys [807936 2009-09-15] (Ralink Technology Corp.)
R2 SSPORT; C:\Windows\system32\Drivers\SSPORT.sys [5120 2009-03-02] (Samsung Electronics) [File not signed]
S3 wisdpen; C:\Windows\System32\DRIVERS\wisdpen.sys [37232 2011-01-04] (Wacom Technology)
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
U3 aswMBR; \??\C:\Users\HP\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\HP\AppData\Local\Temp\aswVmm.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-11 11:25 - 2015-01-11 11:37 - 00021774 _____ () C:\Users\HP\Downloads\FRST.txt
2015-01-11 11:24 - 2015-01-11 11:30 - 00000000 ____D () C:\FRST
2015-01-11 11:14 - 2015-01-11 11:14 - 01115648 _____ (Farbar) C:\Users\HP\Downloads\FRST.exe
2015-01-11 11:07 - 2015-01-11 11:08 - 05198336 _____ (AVAST Software) C:\Users\HP\Downloads\aswMBR.exe
2015-01-09 20:53 - 2015-01-09 20:53 - 00089330 _____ () C:\Users\HP\Desktop\Basic Setup.html
2015-01-09 20:53 - 2015-01-09 20:53 - 00000000 ____D () C:\Users\HP\Desktop\Basic Setup_files
2015-01-06 14:36 - 2015-01-06 14:36 - 00367832 _____ () C:\Windows\Minidump\010615-52073-01.dmp
2014-12-30 12:49 - 2014-12-30 12:49 - 00501952 _____ () C:\Windows\Minidump\123014-46925-01.dmp
2014-12-29 16:18 - 2014-12-29 16:19 - 00237617 _____ () C:\Users\HP\Downloads\GShufflerTitleD24898
2014-12-29 16:18 - 2014-12-29 16:18 - 00183441 _____ () C:\Users\HP\Downloads\GShufflerDPD24898
2014-12-27 11:51 - 2014-12-27 12:08 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-12-27 11:50 - 2014-12-27 11:50 - 00001066 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-12-27 11:50 - 2014-12-27 11:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-12-27 11:48 - 2014-12-27 11:48 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-12-27 11:48 - 2014-11-21 06:14 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-12-27 11:48 - 2014-11-21 06:14 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-12-27 11:48 - 2014-11-21 06:14 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-12-27 11:46 - 2014-12-27 11:46 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\HP\Downloads\mbam-setup-2.0.4.1028.exe
2014-12-20 16:37 - 2014-12-12 22:33 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-12-14 19:18 - 2014-12-14 19:18 - 00233736 _____ () C:\Windows\Minidump\121414-34772-01.dmp
2014-12-13 11:08 - 2014-12-13 12:34 - 00000000 ____D () C:\Windows\system32\Compatibility Verifier
2014-12-12 14:39 - 2014-12-12 14:39 - 00143448 _____ () C:\Windows\Minidump\121214-26020-01.dmp
2014-12-12 12:01 - 2014-12-12 12:02 - 13352808 _____ (Microsoft Corporation) C:\Users\HP\Downloads\NDP20SP2-KB979744-x64.exe
2014-12-12 12:01 - 2014-12-12 12:02 - 06417256 _____ (Microsoft Corporation) C:\Users\HP\Downloads\NDP20SP2-KB979744-x86.exe
2014-12-12 11:58 - 2014-12-12 11:58 - 16331112 _____ (Microsoft Corporation) C:\Users\HP\Downloads\NDP20SP2-KB979744-IA64.exe
2014-12-12 11:57 - 2014-12-12 11:57 - 00002617 _____ () C:\Users\HP\Downloads\download (1).dlm
2014-12-12 11:51 - 2014-12-12 11:52 - 00002618 _____ () C:\Users\HP\Downloads\download.dlm
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-11 11:44 - 2014-12-10 19:16 - 00000886 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-01-11 11:37 - 2014-12-02 18:18 - 34691590 _____ () C:\Windows\system32\debug.log
2015-01-11 11:09 - 2013-03-14 12:13 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-01-11 10:24 - 2013-03-07 00:03 - 02081941 _____ () C:\Windows\WindowsUpdate.log
2015-01-11 10:02 - 2013-03-14 14:47 - 00000000 ____D () C:\Users\HP\AppData\Local\Adobe
2015-01-11 10:01 - 2014-12-10 19:26 - 00004648 _____ () C:\Windows\setupact.log
2015-01-11 10:01 - 2014-12-10 19:15 - 00000882 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-01-11 10:01 - 2009-07-13 23:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-01-10 13:23 - 2013-03-14 14:57 - 00000000 ____D () C:\Users\HP\Documents\RSHUFFLER PERSONAL
2015-01-09 11:55 - 2014-12-02 18:20 - 00000112 _____ () C:\ProgramData\Y7s3uJx.dat
2015-01-07 23:30 - 2009-07-13 23:34 - 00017040 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-01-07 23:30 - 2009-07-13 23:34 - 00017040 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-01-06 14:36 - 2013-04-13 07:27 - 289385682 _____ () C:\Windows\MEMORY.DMP
2015-01-06 14:36 - 2013-04-13 07:27 - 00000000 ____D () C:\Windows\Minidump
2015-01-06 04:36 - 2013-04-14 07:08 - 00249488 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2015-01-05 21:32 - 2013-03-20 11:05 - 00000000 ____D () C:\Temp
2015-01-02 11:53 - 2014-11-30 13:30 - 00615424 _____ () C:\Users\HP\Downloads\Ultimate_Financial_Model.xls
2014-12-27 12:25 - 2009-07-13 21:37 - 00000000 ____D () C:\Windows\system32\LogFiles
2014-12-27 12:06 - 2010-11-20 16:48 - 01726352 _____ () C:\Windows\PFRO.log
2014-12-27 11:52 - 2013-05-17 12:19 - 00000000 ____D () C:\Users\HP\AppData\Local\CrashDumps
2014-12-13 12:30 - 2009-07-13 23:53 - 00032580 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
Files to move or delete:
====================
C:\ProgramData\Y7s3uJx.dat
Some content of TEMP:
====================
C:\Users\HP\AppData\Local\Temp\1371786419_Cloud_Backup_Setup.exe
C:\Users\HP\AppData\Local\Temp\BackupSetup.exe
C:\Users\HP\AppData\Local\Temp\CreativeCloudSet-Up.exe
C:\Users\HP\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe
C:\Users\HP\AppData\Local\Temp\jre-7u67-windows-i586-iftw.exe
C:\Users\HP\AppData\Local\Temp\jre-7u71-windows-i586-iftw.exe
C:\Users\HP\AppData\Local\Temp\lowproc.exe
C:\Users\HP\AppData\Local\Temp\mgsqlite3.dll
C:\Users\HP\AppData\Local\Temp\nscBF0D.exe
C:\Users\HP\AppData\Local\Temp\nseF0CA.exe
C:\Users\HP\AppData\Local\Temp\nspBE34.exe
C:\Users\HP\AppData\Local\Temp\nss1A78.exe
C:\Users\HP\AppData\Local\Temp\nst280C.exe
C:\Users\HP\AppData\Local\Temp\oi_{0BBE0FC9-4E6F-4426-AAAF-4DBBF1B0FE89}.exe
C:\Users\HP\AppData\Local\Temp\safeguard.exe
C:\Users\HP\AppData\Local\Temp\Shortcut_bundlesweetimsetup.exe
C:\Users\HP\AppData\Local\Temp\SpOrder.dll
C:\Users\HP\AppData\Local\Temp\stubhelper.dll
C:\Users\HP\AppData\Local\Temp\tbConn.dll
C:\Users\HP\AppData\Local\Temp\The_Weather_Channel_Application.exe
C:\Users\HP\AppData\Local\Temp\UNINSTALL.EXE
C:\Users\HP\AppData\Local\Temp\vcredist_x86.exe
C:\Users\HP\AppData\Local\Temp\WiseUpdX.exe
C:\Users\HP\AppData\Local\Temp\WSSetup.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-01-10 02:21
==================== End Of Log ============================
----------------
Hi there,
my name is Marius and I will assist you with your malware related problems.
Before we move on, please read the following points carefully.
- First, read my instructions completely. If there is anything that you do not understand kindly ask before proceeding.
- Perform everything in the correct order. Sometimes one step requires the previous one.
- If you have any problems while following my instructions, Stop there and tell me the exact nature of your problem.
- Do not run any other scans without instruction or add/remove software unless I tell you to do so. This would change the output of our tools and could be confusing for me.
- Post all logfiles as a reply rather than as an attachment unless I specifically ask you. If you can not post all logfiles in one reply, feel free to use more posts.
- If I don't hear from you within 3 days from this initial or any subsequent post, then this thread will be closed.
- Stay with me. I will give you some advice about prevention after the cleanup process. Absence of symptoms does not always mean the computer is clean.
- My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.
- Important: To help me reviewing your logs, please post them in code boxes. You can create them by clicking on the <>-symbol on top of the reply window.
Please post the addition.txt as well
rshuffler
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 11-01-2015
Ran by [removed] at 2015-01-11 11:51:46
Running from C:\Users\[removed]\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe AIR (HKLM\…\Adobe AIR) (Version: 3.6.0.6090 - Adobe Systems Incorporated)
Adobe Creative Cloud (HKLM\…\Adobe Creative Cloud) (Version: 2.8.0.447 - Adobe Systems Incorporated)
Adobe Flash Player 15 ActiveX (HKLM\…\Adobe Flash Player ActiveX) (Version: 15.0.0.246 - Adobe Systems Incorporated)
Adobe Flash Player 15 Plugin (HKLM\…\Adobe Flash Player Plugin) (Version: 15.0.0.246 - Adobe Systems Incorporated)
Adobe Illustrator CC 2014 (32 Bit) (HKLM\…\{8913FAF3-5BFE-45BA-AF57-67AF4BA67898}) (Version: 18.1.1 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) (HKLM\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.0 (HKLM\…\Adobe Shockwave Player) (Version: 12.0.0.112 - Adobe Systems, Inc.)
Adobe Touch App Plugins (HKLM\…\{1EC083EE-5B76-4A2A-B95A-CAF460AA29D6}) (Version: 1.0 - Adobe Systems Incorporated)
Amazon Cloud Player (HKU\S-1-5-21-149010795-3013192795-5993443-1000\…\Amazon Amazon Cloud Player) (Version: 2.3.0.422 - Amazon Services LLC)
Apple Application Support (HKLM\…\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{235EBB33-3DA1-46DF-AADE-9955123409CB}) (Version: 8.0.5.6 - Apple Inc.)
Apple Software Update (HKLM\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Bonjour (HKLM\…\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
Cisco Connect (HKLM\…\Cisco Connect) (Version: 1.4.12263.1 - Cisco Consumer Products LLC)
Compatibility Verifier version 1.0 (HKLM\…\{7AF56C9C-F827-41A9-9998-047116F688A4}_is1) (Version: 1.0 - Computer Techtronics, LTD.)
EPSON Scan (HKLM\…\EPSON Scanner) (Version: - )
Google Chrome (HKLM\…\Google Chrome) (Version: 39.0.2171.95 - Google Inc.)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Intel(R) Graphics Media Accelerator Driver (HKLM\…\HDMI) (Version: 8.15.10.1930 - Intel Corporation)
iTunes (HKLM\…\{5D928931-D1D2-4A93-A82D-BF60D0E7CFA5}) (Version: 12.0.1.26 - Apple Inc.)
Java 7 Update 71 (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F03217071FF}) (Version: 7.0.710 - Oracle)
Java 8 Update 25 (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation)
Kies mini (HKLM\…\InstallShield_{EE43894E-FDCF-4A8C-BCD6-3AAA9A48B486}) (Version: 1.00.0000 - Samsung Electronics Co., Ltd.)
Kies mini (Version: 1.00.0000 - Samsung Electronics Co., Ltd.) Hidden
Microsoft .NET Framework 4.5.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\…\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office Enterprise 2007 (HKLM\…\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Home and Student 2010 (HKLM\…\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Mozilla Thunderbird 24.4.0 (x86 en-US) (HKLM\…\Mozilla Thunderbird 24.4.0 (x86 en-US)) (Version: 24.4.0 - Mozilla)
QuickTime 7 (HKLM\…\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
Rhapsody (HKLM\…\Rhapsody) (Version: - )
SAMSUNG USB Driver for Mobile Phones (HKLM\…\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.3.1800.0 - SAMSUNG Electronics Co., Ltd.)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM\…\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 17.0.8.21 - Synaptics Incorporated)
Update for 2007 Microsoft Office System (KB967642) (HKLM\…\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-149010795-3013192795-5993443-1000_Classes\CLSID\{1383A31C-26AC-4d88-91F1-EEAD77D81FA6}\InprocServer32 -> C:\Users\HP\AppData\Roaming\Smilebox\MP3Writer.dll No File
CustomCLSID: HKU\S-1-5-21-149010795-3013192795-5993443-1000_Classes\CLSID\{3CCC052E-BDEE-408A-BEA7-90914EF2964B}\InprocServer32 -> C:\Users\HP\AppData\Roaming\Smilebox\MP4Splitter.ax No File
CustomCLSID: HKU\S-1-5-21-149010795-3013192795-5993443-1000_Classes\CLSID\{4665E44B-8B9A-4515-A086-E94ECE374608}\InprocServer32 -> C:\Users\HP\AppData\Roaming\Smilebox\CoreAAC.ax No File
CustomCLSID: HKU\S-1-5-21-149010795-3013192795-5993443-1000_Classes\CLSID\{61F47056-E400-43D3-AF1E-AB7DFFD4C4AD}\InprocServer32 -> C:\Users\HP\AppData\Roaming\Smilebox\MP4Splitter.ax No File
CustomCLSID: HKU\S-1-5-21-149010795-3013192795-5993443-1000_Classes\CLSID\{6AC7C19E-8CA0-4E3D-9A9F-2881DE29E0AC}\InprocServer32 -> C:\Users\HP\AppData\Roaming\Smilebox\CoreAAC.ax No File
CustomCLSID: HKU\S-1-5-21-149010795-3013192795-5993443-1000_Classes\CLSID\{919AB5F1-1C34-47a2-9C02-17128222C7CF}\InprocServer32 -> C:\Users\HP\AppData\Roaming\Smilebox\MP3Encoder.dll No File
CustomCLSID: HKU\S-1-5-21-149010795-3013192795-5993443-1000_Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\localserver32 -> rundll32.exe javascript:"\..\mshtml.dll,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf> (the data entry has 251 more characters). <==== Poweliks?
CustomCLSID: HKU\S-1-5-21-149010795-3013192795-5993443-1000_Classes\CLSID\{BBFC1A2A-D3A2-4610-847D-26592022F86E}\InprocServer32 -> C:\Users\HP\AppData\Roaming\Smilebox\CoreAAC.ax No File
CustomCLSID: HKU\S-1-5-21-149010795-3013192795-5993443-1000_Classes\CLSID\{D3D9D58B-45B5-48AB-B199-B8C40560AEC7}\InprocServer32 -> C:\Users\HP\AppData\Roaming\Smilebox\MP4Splitter.ax No File
CustomCLSID: HKU\S-1-5-21-149010795-3013192795-5993443-1000_Classes\CLSID\{E2B98EEA-EE55-4E9B-A8C1-6E5288DF785A}\InprocServer32 -> C:\Users\HP\AppData\Roaming\Smilebox\MP4Splitter.ax No File
==================== Restore Points =========================
20-12-2014 16:35:26 Windows Update
22-12-2014 09:34:04 Windows Update
26-12-2014 19:02:11 Windows Update
30-12-2014 12:52:45 Windows Update
07-01-2015 14:13:55 Windows Update
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-13 21:04 - 2009-06-10 16:39 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {1298D8FC-4E9D-402A-BFE7-958E8D77C548} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {13D19BC2-DAC1-4400-BB55-4853B302CED8} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-149010795-3013192795-5993443-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe
Task: {48163477-1954-4B57-A0D0-734A71032B3F} - System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-149010795-3013192795-5993443-1000 => C:\Program Files\RealNetworks\RealDownloader\recordingmanager.exe
Task: {5B3EAA51-2003-474F-93DF-DD79F85DB65E} - System32\Tasks\RunAsStdUser Task => C:\Users\HP\AppData\Local\teeveewatchSA\bin\1.0.10.0\TeeveeWatchSA.exe
Task: {680C9F57-229D-4673-96D9-2F62BA88F613} - System32\Tasks\AdobeAAMUpdater-1.0-INTERNATIONALST-HP => C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2014-09-19] (Adobe Systems Incorporated)
Task: {68FD324F-2120-4214-8E96-0866E15994EC} - System32\Tasks\BuzzSocialPoints_DNS_Checker => C:\Windows\BuzzSocialPointsChecker\BSP_li.exe <==== ATTENTION
Task: {76293ADB-E033-4362-8B6D-AB549B99595C} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-149010795-3013192795-5993443-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe
Task: {8C153443-C614-4C22-A68D-CA62A4B3627C} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-149010795-3013192795-5993443-1000 => C:\Program Files\RealNetworks\RealDownloader\realupgrade.exe
Task: {9DE06A47-CB36-49AD-9560-B75E5A371B86} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-12-10] (Google Inc.)
Task: {ADE270BA-87EA-45C8-BA5B-91E9682D04BB} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-12-10] (Google Inc.)
Task: {AE30EEF9-65E3-4D95-B65C-036BF18B4117} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-12-10] (Adobe Systems Incorporated)
Task: {B2E63513-457A-4D62-BD84-C7EBD2D5D8F5} - System32\Tasks\{90CE9467-9AC0-4BA8-B8C4-1DF7412164F3} => pcalua.exe -a C:\Users\HP\Downloads\NDP20SP2-KB979744-IA64.exe -d C:\Users\HP\Downloads
Task: {BDB29C9A-862F-4244-B9B5-C67E431BC66E} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {BE39DFCF-9138-4AEB-BB6F-2449CD37FA29} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {E66B3266-31D6-4537-ADE7-A5EF0CA4E477} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-149010795-3013192795-5993443-1000 => C:\Program Files\RealNetworks\RealDownloader\realupgrade.exe
Task: {EB9E5E73-82CC-4D2D-804C-B18BEE9847F1} - System32\Tasks\Amazon Music Helper => C:\Users\HP\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe [2014-01-14] ()
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2013-03-20 11:05 - 2006-12-04 00:25 - 00022723 _____ () C:\Windows\System32\CLPA1l3.DLL
2014-01-20 13:17 - 2014-01-20 13:17 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2014-10-11 13:05 - 2014-10-11 13:05 - 01044776 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2014-10-07 06:10 - 2014-10-07 06:11 - 00626688 _____ () C:\Program Files\biforder\inspasio.exe
2014-12-13 11:08 - 2014-12-13 08:07 - 00087208 _____ () C:\Windows\system32\Compatibility Verifier\compatibilitychecksvc.exe
2014-09-26 14:40 - 2014-09-26 14:40 - 01029280 _____ () C:\Program Files\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x86.dll
2014-09-28 21:01 - 2014-09-28 21:01 - 36730032 _____ () C:\Program Files\Adobe\Adobe Creative Cloud\CEF\libcef.dll
2014-02-09 13:09 - 2014-01-14 14:46 - 03140608 _____ () C:\Users\HP\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe
2014-09-26 14:40 - 2014-09-26 14:40 - 06237856 _____ () C:\Program Files\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
2014-12-10 19:17 - 2014-12-05 20:50 - 01077064 _____ () C:\Program Files\Google\Chrome\Application\39.0.2171.95\libglesv2.dll
2014-12-10 19:17 - 2014-12-05 20:50 - 00211272 _____ () C:\Program Files\Google\Chrome\Application\39.0.2171.95\libegl.dll
2014-12-10 19:17 - 2014-12-05 20:50 - 09009480 _____ () C:\Program Files\Google\Chrome\Application\39.0.2171.95\pdf.dll
2014-12-10 19:17 - 2014-12-05 20:50 - 01677128 _____ () C:\Program Files\Google\Chrome\Application\39.0.2171.95\ffmpegsumo.dll
2014-09-28 21:01 - 2014-09-28 21:01 - 00746160 _____ () C:\Program Files\Adobe\Adobe Creative Cloud\CEF\libglesv2.dll
2014-09-28 21:01 - 2014-09-28 21:01 - 00136368 _____ () C:\Program Files\Adobe\Adobe Creative Cloud\CEF\libegl.dll
2014-12-13 11:08 - 2014-12-11 09:20 - 39582208 _____ () C:\Windows\system32\Compatibility Verifier\compatibilitycheck.exe
2014-12-13 11:08 - 2014-10-20 10:42 - 01359360 _____ () C:\Windows\system32\Compatibility Verifier\libglesv2.dll
2014-12-13 11:08 - 2014-10-20 10:42 - 00212992 _____ () C:\Windows\system32\Compatibility Verifier\libegl.dll
2014-12-13 11:08 - 2014-10-20 10:42 - 00984576 _____ () C:\Windows\system32\Compatibility Verifier\ffmpegsumo.dll
2014-12-10 19:17 - 2014-12-05 20:50 - 14913352 _____ () C:\Program Files\Google\Chrome\Application\39.0.2171.95\PepperFlash\pepflashplayer.dll
2014-12-10 16:10 - 2014-12-10 16:10 - 16841392 _____ () C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_246.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
========================= Accounts: ==========================
Administrator (S-1-5-21-149010795-3013192795-5993443-500 - Administrator - Disabled)
Guest (S-1-5-21-149010795-3013192795-5993443-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-149010795-3013192795-5993443-1002 - Limited - Enabled)
HP (S-1-5-21-149010795-3013192795-5993443-1000 - Administrator - Enabled) => C:\Users\HP
==================== Faulty Device Manager Devices =============
Name: Ethernet Controller
Description: Ethernet Controller
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: DgiVecp
Description: DgiVecp
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: DgiVecp
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (01/11/2015 11:44:51 AM) (Source: Software Protection Platform Service) (EventID: 8193) (User: )
Description: License Activation Scheduler (sppuinotify.dll) failed with the following error code:
0x80070005
Error: (01/11/2015 11:19:54 AM) (Source: Software Protection Platform Service) (EventID: 8193) (User: )
Description: License Activation Scheduler (sppuinotify.dll) failed with the following error code:
0x80070005
Error: (01/11/2015 10:02:48 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/11/2015 10:01:45 AM) (Source: Winlogon) (EventID: 4103) (User: )
Description: Windows license activation failed. Error 0x80070005.
Error: (01/10/2015 02:49:11 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: compatibilitycheck.exe, version: 0.0.0.0, time stamp: 0x5489a749
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x00000000
Faulting process id: 0xad0
Faulting application start time: 0xcompatibilitycheck.exe0
Faulting application path: compatibilitycheck.exe1
Faulting module path: compatibilitycheck.exe2
Report Id: compatibilitycheck.exe3
Error: (01/10/2015 02:36:54 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: compatibilitycheck.exe, version: 0.0.0.0, time stamp: 0x5489a749
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x00000000
Faulting process id: 0x16b8
Faulting application start time: 0xcompatibilitycheck.exe0
Faulting application path: compatibilitycheck.exe1
Faulting module path: compatibilitycheck.exe2
Report Id: compatibilitycheck.exe3
Error: (01/10/2015 01:55:08 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 2808
Error: (01/10/2015 01:55:08 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 2808
Error: (01/10/2015 01:55:08 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (01/10/2015 01:55:06 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1466
System errors:
=============
Error: (01/11/2015 11:19:53 AM) (Source: DCOM) (EventID: 10001) (User: )
Description: C:\Windows\System32\slui.exe -Embedding5{F87B28F1-DA9A-4F35-8EC0-800EFCF26B83}
Error: (01/11/2015 10:06:35 AM) (Source: DCOM) (EventID: 10001) (User: )
Description: C:\Windows\System32\slui.exe -Embedding5{F87B28F1-DA9A-4F35-8EC0-800EFCF26B83}
Error: (01/11/2015 10:03:00 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
Error: (01/11/2015 10:01:16 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
cdrom
Error: (01/11/2015 10:01:16 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The updater service failed to start due to the following error:
%%2
Error: (01/11/2015 10:01:16 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The sarconsogulpe service failed to start due to the following error:
%%2
Error: (01/11/2015 10:01:16 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Level Quality Watcher service failed to start due to the following error:
%%2
Error: (01/11/2015 10:01:15 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The DgiVecp service failed to start due to the following error:
%%20
Error: (01/11/2015 10:01:15 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The CouponarificService service failed to start due to the following error:
%%2
Error: (01/10/2015 03:06:42 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF}
Microsoft Office Sessions:
=========================
==================== Memory info ===========================
Processor: AMD E-300 APU with Radeon™ HD Graphics
Percentage of memory in use: 74%
Total physical RAM: 3574.87 MB
Available physical RAM: 922.85 MB
Total Pagefile: 7148.02 MB
Available Pagefile: 3305.06 MB
Total Virtual: 2047.88 MB
Available Virtual: 1902.88 MB
==================== Drives ================================
Drive c: (New Volume) (Fixed) (Total:465.76 GB) (Free:367.67 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: BD566855)
Partition 1: (Active) - (Size=465.8 GB) - (Type=07 NTFS)
==================== End Of Log ============================
----------------
Fix with FRST (normal mode)
WARNING: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
- Download the attached fixlist.txt and save it to the location where FRST is saved to.
- Run FRST.exe (on 64bit, run FRST64.exe) and press the Fix button just once and wait.
- The tool will make a log (Fixlog.txt) which you find where you saved FRST. Please post it to your reply.
Full System Scan with Malwarebytes Antimalware
- If not existing, please download Malwarebytes Anti-Malware to your desktop.
- Double-click the downloaded setup file and follow the prompts to install the program.
- At the end, be sure a checkmark is placed next to the following:
- Launch Malwarebytes Anti-Malware
- A 14 day trial of the Premium features is pre-selected. You may deselect this if you wish, and it will not diminish the scanning and removal capabilities of the program.
- Click Finish.
If the program is already installed:
- Run Malwarebytes Antimalware
- On the Dashboard, click the 'Update Now >>' link
- After the update completes, click the 'Scan Now >>' button.
- Or, on the Dashboard, click the Scan Now >> button.
- If an update is available, click the Update Now button.
- A Threat Scan will begin.
- When the scan is complete, if there have been detections, click Apply Actions to allow MBAM to clean what was detected.
- In most cases, a restart will be required.
- Wait for the prompt to restart the computer to appear, then click on Yes.
- After the restart once you are back at your desktop, open MBAM once more.
- Click on the History tab > Application Logs.
- Double click on the scan log which shows the Date and time of the scan just performed.
- Click 'Copy to Clipboard'
- Paste the contents of the clipboard into your reply.
----------------
Due to inactivity this topic will be closed.
If you need help please start a new thread.
New members follow the instructions here http://forums.whatthetech.com/you_Infected_t106388.html and start a new topic
If you need help please start a new thread.
New members follow the instructions here http://forums.whatthetech.com/you_Infected_t106388.html and start a new topic
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI