This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Malware Infected - Vosteran Cleanup

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Definitely have some malware issues.  Vosteran has been uninstalled, but I'm sure is still around.  New tabs open up when clicking on links on web pages and we are getting pop-ups like crazy.  Browsers very slow.  Thanks in advance for the help.

 

Logs:

 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2015-01-24 18:33:48
—————————–
18:33:48.972    OS Version: Windows x64 6.2.9200
18:33:48.973    Number of processors: 4 586 0x3A09
18:33:48.974    ComputerName: MOMMERS  UserName: Kira
18:33:53.708    Initialize success
18:33:54.353    VM: initialized successfully
18:33:54.354    VM: Intel CPU supported
18:40:53.842    VM: disk I/O iaStorA.sys
18:42:31.657    AVAST engine defs: 15012401
18:48:39.551    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000002f
18:48:39.553    Disk 0 Vendor: WDC_WD5000LPVT-22G33T0 01.01A01 Size: 476940MB BusType: 11
18:48:39.556    Disk 1  \Device\Harddisk1\DR1 -> \Device\00000030
18:48:39.559    Disk 1 Vendor: SATA_SSD S5FAM018 Size: 19087MB BusType: 11
18:48:39.672    Disk 0 MBR read successfully
18:48:39.675    Disk 0 MBR scan
18:48:39.774    Disk 0 unknown MBR code
18:48:39.777    Disk 0 Partition 1 00     EE          GPT           2097151 MB offset 1
18:48:39.974    Disk 0 scanning C:\WINDOWS\system32\drivers
18:49:03.023    Service scanning
18:49:39.830    Modules scanning
18:49:39.838    Disk 0 trace - called modules:
18:49:39.859    ntoskrnl.exe CLASSPNP.SYS disk.sys storport.sys hal.dll iaStorA.sys
18:49:39.863    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xffffe001b5786060]
18:49:39.867    3 CLASSPNP.SYS[fffff8007000227b] -> nt!IofCallDriver -> \Device\0000002f[0xffffe001b3a1c7f0]
18:49:41.330    AVAST engine scan C:\WINDOWS
18:49:45.182    AVAST engine scan C:\WINDOWS\system32
18:55:26.528    AVAST engine scan C:\WINDOWS\system32\drivers
18:56:03.401    AVAST engine scan C:\Users\Kira
19:39:39.220    File: C:\Users\Kira\AppData\Local\Temp\__tmp_2d00d7ea  **INFECTED** Win32:Malware-gen
19:54:55.358    AVAST engine scan C:\ProgramData
19:55:00.609    File: C:\ProgramData\2355320829\BITA3DF.tmp  **INFECTED** Win32:Malware-gen
20:01:53.952    Disk 0 statistics 4453913/0/0 @ 0.66 MB/s
20:01:53.972    Scan finished successfully
20:17:39.542    Disk 0 MBR has been saved successfully to "C:\Users\Kira\Desktop\Clean Up\aswMBR\MBR.dat"
20:17:39.565    The log file has been saved successfully to "C:\Users\Kira\Desktop\Clean Up\aswMBR\aswMBR.txt"

 

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-01-2015 01
Ran by [removed] (administrator) on MOMMERS on 24-01-2015 20:21:46
Running from C:\Users\[removed]\Desktop\Clean Up\FRST64
[removed] Platform: Windows 8.1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\AdminService.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Dritek System Inc.) C:\Program Files (x86)\Acer\Device Control\DeviceCtrlSvc64.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Condusiv Technologies) C:\Program Files\Condusiv Technologies\ExpressCache\ExpressCache.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Instant Service\Sleep Memory Optimizer\FFSService.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(LeapFrog Enterprises, Inc.) C:\Program Files (x86)\LeapFrog\LeapFrog Connect\CommandService.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
(Dritek System INC.) C:\Windows\RfBtnSvc64.exe
(Atheros) C:\Program Files (x86)\Qualcomm Atheros\Ath_WlanAgent.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(acer) C:\Program Files (x86)\Acer\WTTouchApplicationSuite\AcerRing\AcerRing.exe
() C:\Program Files (x86)\Acer Incorporated\HID Monitor\HIDMonitor.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Adobe Systems) C:\Program Files\Adobe\Adobe Photoshop Lightroom 5.3\lightroom.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDTouch.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_YATIHSA.EXE
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe
(Dritek System Inc.) C:\Program Files (x86)\RadioController\RfBtnHelper.exe
(Dolby Laboratories Inc.) C:\Dolby PCEE4\pcee4.exe
(Dritek System Inc.) C:\Program Files (x86)\Acer\Device Control\ADevCtrl64.exe
(Dritek System Inc.) C:\Program Files (x86)\Acer\Device Control\AdWmiSvc64.exe
(Dropbox, Inc.) C:\Users\Kira\AppData\Roaming\Dropbox\bin\Dropbox.exe
(LeapFrog Enterprises, Inc.) C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe
(CyberLink) C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe
(Qualcomm Atheros) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtTray.exe
(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe
() C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\ActivateDesktop.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe Photoshop Lightroom 5.3\Support\DynamicLinkSupport\dynamiclink\CS6\dynamiclinkmanager.exe
(Adobe Systems, Incorporated) C:\Program Files\Adobe\Adobe Photoshop Lightroom 5.3\Support\DynamicLinkMediaServer\dynamiclinkmediaserver\1.0\dynamiclinkmediaserver.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe Photoshop Lightroom 5.3\Support\DynamicLinkMediaServer\dynamiclinkmediaserver\1.0\32\Adobe QT32 Server.exe
() C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe
() C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Theft Shield\USecuAppClient.exe
(Egis Technology Inc.) C:\Program Files\EgisTec IPS\PmmUpdate.exe
(Egis Technology Inc.) C:\Program Files\EgisTec IPS\EgisUpdate.exe
(Microsoft Corporation) C:\Windows\System32\Taskmgr.exe
(acer) C:\Program Files (x86)\Acer\WTTouchApplicationSuite\PhotoViewer\PhotoViewer.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_296.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_296.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\…\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2873744 2012-11-20] (ELAN Microelectronics Corp.)
HKLM\…\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12503184 2012-06-10] (Realtek Semiconductor)
HKLM\…\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1212048 2012-06-07] (Realtek Semiconductor)
HKLM\…\Run: [BtPreLoad] => C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtPreLoad.exe [64640 2012-11-09] ()
HKLM-x32\…\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [277504 2012-08-16] (Intel Corporation)
HKLM-x32\…\Run: [LManager] => [X]
HKLM-x32\…\Run: [RadioController] => C:\Program Files (x86)\RadioController\RfBtnHelper.exe [111216 2013-02-22] (Dritek System Inc.)
HKLM-x32\…\Run: [Dolby Home Theater v4] => C:\Dolby PCEE4\pcee4.exe [508256 2012-04-23] (Dolby Laboratories Inc.)
HKLM-x32\…\Run: [ADevCtrl] => C:\Program Files (x86)\Acer\Device Control\ADevCtrl64.exe [347248 2012-09-26] (Dritek System Inc.)
HKLM-x32\…\Run: [Norton Online Backup] => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [2994880 2012-08-15] (Symantec Corporation)
HKLM-x32\…\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\…\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
HKLM-x32\…\Run: [BrowserPlugInHelper] => C:\Program Files (x86)\Wondershare\Video Converter Ultimate\BrowserPlugInHelper.exe [1969440 2013-06-18] ()
HKLM-x32\…\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\…\Run: [Monitor] => C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe [118272 2014-07-11] (LeapFrog Enterprises, Inc.)
HKLM-x32\…\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2351201714-3478538817-3848901743-1001\…\Run: [EPLTarget\P0000000000000000] => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIHSA.EXE [241280 2013-03-10] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-2351201714-3478538817-3848901743-1001\…\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.)
HKU\S-1-5-21-2351201714-3478538817-3848901743-1001\…\Run: [GoogleChromeAutoLaunch_82456ACC06A7292895434703ADA84C9D] => "C:\Users\Kira\AppData\Local\Vosteran\Application\vosteran.exe" –auto-launch-at-startup –profile-directory="Default"
HKU\S-1-5-21-2351201714-3478538817-3848901743-1001\…\MountPoints2: {b131bdff-48de-11e4-bed0-089e01848867} - "E:\WIN\setup.exe"
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Acer Backup Manager Tray.lnk
ShortcutTarget: Acer Backup Manager Tray.lnk -> C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe (NTI Corporation)
Startup: C:\Users\Kira\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Kira\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Kira\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\StormWatch.lnk
ShortcutTarget: StormWatch.lnk -> C:\Program Files (x86)\StormWatch\StormWatch.exe (No File)
Startup: C:\Users\Kira\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\StormWatchApp.lnk
ShortcutTarget: StormWatchApp.lnk -> C:\Program Files (x86)\StormWatch\StormWatchApp.exe (No File)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-2351201714-3478538817-3848901743-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://Vosteran.com/?f=1&a;=vst_dnldstr_14_50_ch&cd;=2XzuyEtN2Y1L1Qzu0FyE0ByB0EtB0AtA0B0DtCtC0EyEtB0FtN0D0Tzu0StCtDyByCtN1L2XzutAtFyCtFtCtDtFyBtN1L1CzutCyEtBzytDyD1V1BtN1L1G1B1V1N2Y1L1Qzu2SyByCyD0BtD0Dzy0EtGyDyBzytBtGzzyD0E0DtG0Ezy0BzztGyE0D0E0BzzyC0ByE0BtCyByD2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0DzyyB0AyBtDyByCtGyD0DzyzztGyE0F0AtCtGzztC0DzztG0FyD0EyC0EyEtAtDzz0AzyyD2Q&cr;=531242758&ir;=
HKU\S-1-5-21-2351201714-3478538817-3848901743-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer13.msn.com
HKU\S-1-5-21-2351201714-3478538817-3848901743-1001\Software\Microsoft\Internet Explorer\Main,DisableRequiresActiveXPrompt = xfinitytv.comcast.net
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
SearchScopes: HKLM -> DefaultScope {492C118E-8F2A-438F-B5B5-19E2C7BDF8CB} URL = http://Vosteran.com/results.php?f=4&q;={searchTerms}&a;=vst_dnldstr_14_50_ch&cd;=2XzuyEtN2Y1L1Qzu0FyE0ByB0EtB0AtA0B0DtCtC0EyEtB0FtN0D0Tzu0StCtDyByCtN1L2XzutAtFyCtFtCtDtFyBtN1L1CzutCyEtBzytDyD1V1BtN1L1G1B1V1N2Y1L1Qzu2SyByCyD0BtD0Dzy0EtGyDyBzytBtGzzyD0E0DtG0Ezy0BzztGyE0D0E0BzzyC0ByE0BtCyByD2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0DzyyB0AyBtDyByCtGyD0DzyzztGyE0F0AtCtGzztC0DzztG0FyD0EyC0EyEtAtDzz0AzyyD2Q&cr;=531242758&ir;=
SearchScopes: HKLM -> {492C118E-8F2A-438F-B5B5-19E2C7BDF8CB} URL = http://Vosteran.com/results.php?f=4&q;={searchTerms}&a;=vst_dnldstr_14_50_ch&cd;=2XzuyEtN2Y1L1Qzu0FyE0ByB0EtB0AtA0B0DtCtC0EyEtB0FtN0D0Tzu0StCtDyByCtN1L2XzutAtFyCtFtCtDtFyBtN1L1CzutCyEtBzytDyD1V1BtN1L1G1B1V1N2Y1L1Qzu2SyByCyD0BtD0Dzy0EtGyDyBzytBtGzzyD0E0DtG0Ezy0BzztGyE0D0E0BzzyC0ByE0BtCyByD2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0DzyyB0AyBtDyByCtGyD0DzyzztGyE0F0AtCtGzztC0DzztG0FyD0EyC0EyEtAtDzz0AzyyD2Q&cr;=531242758&ir;=
SearchScopes: HKU\S-1-5-21-2351201714-3478538817-3848901743-1001 -> DefaultScope {492C118E-8F2A-438F-B5B5-19E2C7BDF8CB} URL = http://Vosteran.com/results.php?f=4&q;={searchTerms}&a;=vst_dnldstr_14_50_ch&cd;=2XzuyEtN2Y1L1Qzu0FyE0ByB0EtB0AtA0B0DtCtC0EyEtB0FtN0D0Tzu0StCtDyByCtN1L2XzutAtFyCtFtCtDtFyBtN1L1CzutCyEtBzytDyD1V1BtN1L1G1B1V1N2Y1L1Qzu2SyByCyD0BtD0Dzy0EtGyDyBzytBtGzzyD0E0DtG0Ezy0BzztGyE0D0E0BzzyC0ByE0BtCyByD2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0DzyyB0AyBtDyByCtGyD0DzyzztGyE0F0AtCtGzztC0DzztG0FyD0EyC0EyEtAtDzz0AzyyD2Q&cr;=531242758&ir;=
SearchScopes: HKU\S-1-5-21-2351201714-3478538817-3848901743-1001 -> {492C118E-8F2A-438F-B5B5-19E2C7BDF8CB} URL = http://Vosteran.com/results.php?f=4&q;={searchTerms}&a;=vst_dnldstr_14_50_ch&cd;=2XzuyEtN2Y1L1Qzu0FyE0ByB0EtB0AtA0B0DtCtC0EyEtB0FtN0D0Tzu0StCtDyByCtN1L2XzutAtFyCtFtCtDtFyBtN1L1CzutCyEtBzytDyD1V1BtN1L1G1B1V1N2Y1L1Qzu2SyByCyD0BtD0Dzy0EtGyDyBzytBtGzzyD0E0DtG0Ezy0BzztGyE0D0E0BzzyC0ByE0BtCyByD2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0DzyyB0AyBtDyByCtGyD0DzyzztGyE0F0AtCtGzztC0DzztG0FyD0EyC0EyEtAtDzz0AzyyD2Q&cr;=531242758&ir;=
SearchScopes: HKU\S-1-5-21-2351201714-3478538817-3848901743-1001 -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL =
BHO: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations)
BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
BHO-x32: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
DPF: HKLM-x32 {BEA7310D-06C4-4339-A784-DC3804819809} http://images3.pnimedia.com/ProductAssets/costcous/activex/v3_0_0_7/PhotoCenter_ActiveX_Control.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\Kira\AppData\Roaming\Mozilla\Firefox\Profiles\lkwufyjq.default
FF SelectedSearchEngine: Vosteran
FF Homepage: www.google.com
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_16_0_0_296.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_296.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF user.js: detected! => C:\Users\Kira\AppData\Roaming\Mozilla\Firefox\Profiles\lkwufyjq.default\user.js
FF SearchPlugin: C:\Users\Kira\AppData\Roaming\Mozilla\Firefox\Profiles\lkwufyjq.default\searchplugins\Vosteran.xml
FF Extension: buyfast - C:\Users\Kira\AppData\Roaming\Mozilla\Firefox\Profiles\lkwufyjq.default\Extensions\[removed] [2014-12-23]
FF Extension: rocketdeal - C:\Users\Kira\AppData\Roaming\Mozilla\Firefox\Profiles\lkwufyjq.default\Extensions\[removed] [2014-12-23]
FF Extension: broWWseandusHop - C:\Users\Kira\AppData\Roaming\Mozilla\Firefox\Profiles\lkwufyjq.default\Extensions\[removed] [2015-01-12]
FF Extension: buyanedbroWse - C:\Users\Kira\AppData\Roaming\Mozilla\Firefox\Profiles\lkwufyjq.default\Extensions\[removed] [2015-01-12]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-01-18]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[removed]
FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[removed] [2013-06-23]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[removed]
FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[removed] [2013-06-23]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[removed]
FF Extension: Content Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[removed] [2013-06-23]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[removed]
FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[removed] [2013-06-23]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[removed]
FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[removed] [2013-06-23]
FF HKLM-x32\…\Firefox\Extensions: [{8D150B8F-EFE8-45a3-A4A3-053020F48FAC}] - C:\Program Files (x86)\Wondershare\Video Converter Ultimate\SVRFirefoxExt
FF Extension: Wondershare Video Converter Ultimate - C:\Program Files (x86)\Wondershare\Video Converter Ultimate\SVRFirefoxExt [2013-07-02]
FF HKLM-x32\…\Thunderbird\Extensions: [[removed]] - C:\Program Files\McAfee\MSK
FF HKU\S-1-5-21-2351201714-3478538817-3848901743-1001\…\Firefox\Extensions: [{8D150B8F-EFE8-45a3-A4A3-053020F48FAC}] - C:\Program Files (x86)\Wondershare\Video Converter Ultimate\SVRFirefoxExt

Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Profile: C:\Users\Kira\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Wondershare Video Converter Ultimate) - C:\Users\Kira\AppData\Local\Google\Chrome\User Data\Default\Extensions\chgdeabpmphfhkoemjjglmilajldekbp [2013-11-29]
CHR Extension: (Kaspersky URL Advisor) - C:\Users\Kira\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj [2013-11-29]
CHR Extension: (Picture Downloader Professional) - C:\Users\Kira\AppData\Local\Google\Chrome\User Data\Default\Extensions\eodejnpnekkneapkicljnillpeodnlak [2015-01-11]
CHR Extension: (Safe Money) - C:\Users\Kira\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh [2013-11-29]
CHR Extension: (Virtual Keyboard) - C:\Users\Kira\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh [2013-11-29]
CHR Extension: (Skype Click to Call) - C:\Users\Kira\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2014-02-16]
CHR Extension: (Anti-Banner) - C:\Users\Kira\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman [2013-11-29]
CHR Extension: (firee2iyOu) - C:\ProgramData\cbhbifjoljdgibolbeacopepgejplgab\ [2013-11-29]
CHR HKLM\…\Chrome\Extension: [oilkkkefbalmbfppgjmgjoefbclebkce] - No Path
CHR HKLM\…\Chrome\Extension: [Ìÿ] - No Path
CHR HKU\S-1-5-21-2351201714-3478538817-3848901743-1001\…\Chrome\Extension: [oilkkkefbalmbfppgjmgjoefbclebkce] - No Path
CHR HKU\S-1-5-21-2351201714-3478538817-3848901743-1001\…\Chrome\Extension: [Ìÿ] - No Path
CHR HKLM-x32\…\Chrome\Extension: [chgdeabpmphfhkoemjjglmilajldekbp] - C:\Program Files (x86)\Wondershare\Video Converter Ultimate\SVRChromePlugin.crx [2013-07-02]
CHR HKLM-x32\…\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\urladvisor.crx [2012-08-18]
CHR HKLM-x32\…\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\online_banking_chrome.crx [2012-08-18]
CHR HKLM-x32\…\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\content_blocker_chrome.crx [2012-08-18]
CHR HKLM-x32\…\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\virtkbd.crx [2012-08-18]
CHR HKLM-x32\…\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]
CHR HKLM-x32\…\Chrome\Extension: [oilkkkefbalmbfppgjmgjoefbclebkce] - No Path
CHR HKLM-x32\…\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\ab.crx [2012-08-18]
CHR HKLM-x32\…\Chrome\Extension: [Ìÿ] - No Path
StartMenuInternet: Google Chrome - chrome.exe

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AtherosSvc; C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe [231040 2012-11-09] (Qualcomm Atheros Commnucations)
S3 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356128 2013-10-16] (Kaspersky Lab ZAO)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
R2 CCDMonitorService; C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe [2449552 2012-10-25] (Acer Incorporated)
S3 DeviceFastLaneService; C:\Program Files\Acer\Acer Device Fast-lane\DeviceFastLaneSvc.exe [469648 2012-11-16] (Acer Incorporated)
R2 DsiDeviceControlService; C:\Program Files (x86)\Acer\Device Control\DeviceCtrlSvc64.exe [68688 2012-04-23] (Dritek System Inc.)
R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [658064 2012-10-23] (Acer Incorporated)
R2 ExpressCache; C:\Program Files\Condusiv Technologies\ExpressCache\ExpressCache.exe [102224 2012-08-17] (Condusiv Technologies)
R2 FFSOpzSvc; C:\Program Files\Acer\Acer Instant Service\Sleep Memory Optimizer\FFSService.exe [161384 2012-03-12] (Acer Incorporated)
R2 IAStorDataMgrSvc; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [7168 2012-08-16] (Intel Corporation) [File not signed]
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128896 2012-07-17] (Intel Corporation)
S3 irstrtsv; C:\Windows\SysWOW64\irstrtsv.exe [193576 2012-07-29] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-17] (Intel Corporation)
R2 LeapFrog Connect Device Service; C:\Program Files (x86)\LeapFrog\LeapFrog Connect\CommandService.exe [7241728 2014-07-11] (LeapFrog Enterprises, Inc.) [File not signed]
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [3943104 2012-08-15] (Symantec Corporation)
R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [259136 2012-11-02] (NTI Corporation)
R2 RfButtonDriverService; C:\Windows\RfBtnSvc64.exe [96880 2013-02-22] (Dritek System INC.)
S2 SWUpdater; C:\Program Files (x86)\StormWatch\SWUpdaterSvc.exe [17584 2014-11-21] (Weather Protector LLC)
S3 USecuAppSvc; C:\Program Files\Acer\Acer Theft Shield\USecuAppSvc.exe [345744 2012-11-12] (Acer Incorporated)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-21] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-21] (Microsoft Corporation)
R2 ZAtheros Wlan Agent; C:\Program Files (x86)\Qualcomm Atheros\Ath_WlanAgent.exe [81536 2012-11-09] (Atheros)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R3 AcerKBVDMini; C:\Windows\System32\drivers\AcerKBVD.sys [15632 2012-06-05] (Acer Incorporated)
S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [76952 2012-11-09] (Qualcomm Atheros)
S3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation)
R1 ccSet_NARA; C:\Windows\system32\drivers\NARAx64\0401000.00E\ccSetx64.sys [168608 2012-05-25] (Symantec Corporation)
R1 excfs; C:\Windows\System32\DRIVERS\excfs.sys [23376 2012-08-17] (Condusiv Technologies)
R0 excsd; C:\Windows\System32\DRIVERS\excsd.sys [103248 2012-08-17] (Condusiv Technologies)
S3 FlyUsb; C:\Windows\System32\drivers\FlyUsb.sys [24576 2013-06-21] (LeapFrog)
R3 irstrtdv; C:\Windows\System32\drivers\irstrtdv.sys [43800 2012-07-29] (Intel Corporation)
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2013-12-11] (Kaspersky Lab ZAO)
S0 klelam; C:\Windows\System32\DRIVERS\klelam.sys [29616 2012-07-27] (Kaspersky Lab)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [625760 2013-10-16] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\system32\DRIVERS\klim6.sys [30304 2013-12-11] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\system32\DRIVERS\klkbdflt.sys [29280 2013-10-16] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\system32\DRIVERS\klmouflt.sys [29280 2013-10-16] (Kaspersky Lab ZAO)
R1 klwfp; C:\Windows\system32\DRIVERS\klwfp.sys [50448 2013-06-23] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\system32\DRIVERS\kneps.sys [178448 2013-06-23] (Kaspersky Lab ZAO)
R3 Ps2Kb2Hid; C:\Windows\System32\drivers\aPs2Kb2Hid.sys [26736 2013-02-22] (Dritek System Inc.)
S3 QRDCIO; C:\Windows\System32\drivers\QRDCIO.sys [9728 2009-10-20] (QUANTA)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-21] (Microsoft Corporation)
R3 WsAudio_Device; C:\Windows\system32\drivers\VirtualAudio.sys [31080 2013-03-25] (Wondershare)
U3 aswMBR; \??\C:\Users\Kira\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\Kira\AppData\Local\Temp\aswVmm.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-01-24 20:19 - 2015-01-24 20:22 - 00000000 ____D () C:\FRST
2015-01-24 19:34 - 2015-01-24 19:34 - 00000000 ___SH () C:\DkHyperbootSync
2015-01-24 18:04 - 2015-01-24 20:18 - 00000000 ____D () C:\Users\Kira\Desktop\Clean Up
2015-01-24 17:35 - 2015-01-24 17:35 - 00000000 ____D () C:\ProgramData\f5805e03000049f5
2015-01-21 10:41 - 2015-01-21 10:41 - 00007334 _____ () C:\Users\Kira\Downloads\Transaction (11).qfx
2015-01-18 15:28 - 2015-01-18 15:28 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-01-13 22:47 - 2015-01-13 22:47 - 00000000 ____D () C:\Program Files (x86)\oFiferaappa
2015-01-13 22:47 - 2015-01-13 22:47 - 00000000 ____D () C:\Program Files (x86)\niceinfrree
2015-01-13 15:11 - 2014-12-19 00:26 - 00140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys
2015-01-13 15:11 - 2014-12-11 20:04 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWbPrxy.exe
2015-01-13 15:11 - 2014-12-11 18:51 - 00075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ahcache.sys
2015-01-13 15:11 - 2014-12-08 19:50 - 00225280 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2015-01-13 15:11 - 2014-12-08 13:42 - 00535640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2015-01-13 15:11 - 2014-12-08 13:42 - 00531616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2015-01-13 15:11 - 2014-12-08 13:42 - 00448792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2015-01-13 15:11 - 2014-12-08 13:42 - 00413248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll
2015-01-13 15:11 - 2014-12-08 13:42 - 00372408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll
2015-01-13 15:11 - 2014-12-08 13:42 - 00108944 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDump.dll
2015-01-13 15:11 - 2014-12-08 13:42 - 00038264 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFaultSecure.exe
2015-01-13 15:11 - 2014-12-08 13:42 - 00033584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFaultSecure.exe
2015-01-13 15:11 - 2014-12-05 21:17 - 00360448 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
2015-01-13 15:11 - 2014-12-05 19:41 - 00391680 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll
2015-01-13 15:11 - 2014-12-05 19:35 - 00229888 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2015-01-13 15:11 - 2014-10-28 22:00 - 00465320 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe
2015-01-13 15:11 - 2014-10-28 22:00 - 00139984 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2015-01-13 15:11 - 2014-10-28 21:52 - 00500016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2015-01-13 15:11 - 2014-10-28 21:52 - 00482872 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2015-01-13 15:11 - 2014-10-28 21:52 - 00394120 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2015-01-13 15:11 - 2014-10-28 21:52 - 00272248 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2015-01-13 15:11 - 2014-10-28 21:12 - 00413136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe
2015-01-13 15:11 - 2014-10-28 21:12 - 00136296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2015-01-13 15:11 - 2014-10-28 21:07 - 00424544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2015-01-13 15:11 - 2014-10-28 21:07 - 00370424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2015-01-13 15:11 - 2014-10-28 21:07 - 00344536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
2015-01-13 15:11 - 2014-10-28 20:44 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll
2015-01-13 15:11 - 2014-10-28 19:59 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werdiagcontroller.dll
2015-01-13 15:11 - 2014-10-28 19:24 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlaapi.dll
2015-01-13 15:11 - 2014-10-28 19:02 - 00911360 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2015-01-13 15:11 - 2014-10-28 19:01 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nlaapi.dll
2015-01-11 18:39 - 2015-01-12 14:12 - 00014220 _____ () C:\Users\Kira\Documents\LostLuggage2014.xlsx
2015-01-11 08:31 - 2015-01-11 08:31 - 00000000 ____D () C:\ProgramData\cbhbifjoljdgibolbeacopepgejplgab
2015-01-11 08:30 - 2015-01-22 16:46 - 00000000 ____D () C:\ProgramData\oFiferaappa
2015-01-11 08:30 - 2015-01-22 16:46 - 00000000 ____D () C:\ProgramData\niceinfrree
2015-01-09 16:38 - 2015-01-09 16:38 - 00033227 _____ () C:\Users\Kira\Downloads\Export.QFX
2015-01-08 15:12 - 2015-01-08 15:13 - 182964399 _____ () C:\Users\Kira\Downloads\Pead Family-01.zip
2015-01-08 11:36 - 2015-01-08 11:36 - 00008692 _____ () C:\Users\Kira\Downloads\Transaction (10).qfx
2015-01-08 11:35 - 2015-01-08 11:35 - 00005074 _____ () C:\Users\Kira\Downloads\Transaction (9).qfx
2014-12-25 14:28 - 2014-12-25 14:28 - 00003886 _____ () C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-01-24 20:17 - 2013-10-02 20:46 - 00000830 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-01-24 20:11 - 2013-11-29 01:52 - 01755558 _____ () C:\WINDOWS\WindowsUpdate.log
2015-01-24 20:02 - 2013-08-22 09:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2015-01-24 19:54 - 2013-11-29 00:12 - 00000922 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-01-24 18:03 - 2013-12-01 10:19 - 02786304 ___SH () C:\Users\Kira\Downloads\Thumbs.db
2015-01-24 15:25 - 2013-03-10 13:39 - 00003600 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2351201714-3478538817-3848901743-1001
2015-01-24 15:17 - 2013-10-02 20:46 - 00003718 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2015-01-24 15:16 - 2013-11-29 02:03 - 00003918 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{DC95B162-3C86-46A8-BE3D-50EED0617A23}
2015-01-24 15:13 - 2013-08-22 09:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2015-01-22 17:18 - 2012-07-26 01:59 - 00000000 ____D () C:\WINDOWS\CbsTemp
2015-01-22 17:04 - 2013-08-04 21:55 - 00000000 ___RD () C:\Users\Kira\Dropbox
2015-01-22 17:04 - 2013-08-04 21:52 - 00000000 ____D () C:\Users\Kira\AppData\Roaming\Dropbox
2015-01-22 17:03 - 2013-11-29 02:00 - 00000000 ___DO () C:\Users\Kira\SkyDrive
2015-01-22 17:03 - 2013-11-29 00:12 - 00000918 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-01-22 16:46 - 2013-09-29 21:55 - 00025604 _____ () C:\WINDOWS\PFRO.log
2015-01-22 16:46 - 2013-09-05 09:34 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-01-22 16:46 - 2013-08-22 08:46 - 00317368 _____ () C:\WINDOWS\setupact.log
2015-01-22 16:46 - 2013-08-22 08:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2015-01-22 16:45 - 2013-08-22 07:25 - 00524288 ___SH () C:\WINDOWS\system32\config\BBI
2015-01-21 19:55 - 2013-06-14 14:12 - 00013803 _____ () C:\Users\Kira\Documents\Logpass.xlsx
2015-01-21 08:46 - 2014-01-11 19:33 - 00135680 ___SH () C:\Users\Kira\Documents\Thumbs.db
2015-01-21 08:31 - 2013-11-30 08:32 - 00000000 ____D () C:\Users\Kira\AppData\Local\Deployment
2015-01-19 15:32 - 2014-11-11 19:45 - 00714720 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-01-19 15:32 - 2014-11-11 19:45 - 00106976 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-01-18 15:11 - 2013-09-29 22:04 - 00865408 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2015-01-13 22:47 - 2014-12-22 07:40 - 00000000 ____D () C:\ProgramData\7f4605c5ff46c5a7
2015-01-13 22:47 - 2013-08-17 22:05 - 00000000 ____D () C:\WINDOWS\system32\MRT
2015-01-13 15:19 - 2013-03-11 11:42 - 113365784 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-01-13 10:06 - 2013-05-12 16:28 - 00000000 ____D () C:\Users\Kira\AppData\Roaming\Skype
2015-01-11 17:59 - 2013-08-22 09:36 - 00000000 ____D () C:\WINDOWS\system32\FxsTmp
2015-01-09 17:01 - 2013-05-02 10:45 - 00017891 _____ () C:\Users\Kira\Documents\PaymentsDue.xlsx
2014-12-31 05:14 - 2014-08-17 09:55 - 00298120 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe

==================== Files in the root of some directories =======

2014-12-13 16:11 - 2014-12-22 08:11 - 0000162 _____ () C:\Users\Kira\AppData\Roaming\WB.CFG
2014-04-25 00:09 - 2014-06-13 18:46 - 0005632 _____ () C:\Users\Kira\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-12-16 14:11 - 2014-12-17 17:11 - 0000010 _____ () C:\Users\Kira\AppData\Local\DSI.DAT
2014-12-16 14:11 - 2014-12-16 14:11 - 0022528 _____ () C:\Users\Kira\AppData\Local\dsisetup2516531872.exe
2014-12-17 17:11 - 2014-12-17 17:11 - 0022528 _____ () C:\Users\Kira\AppData\Local\dsisetup3488528592.exe
2013-02-22 15:35 - 2013-02-22 15:35 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

Some content of TEMP:
====================
C:\Users\Kira\AppData\Local\Temp\BSI.exe
C:\Users\Kira\AppData\Local\Temp\DriverSupport.exe
C:\Users\Kira\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpqkzv3v.dll
C:\Users\Kira\AppData\Local\Temp\i4jdel0.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-01-22 22:36

==================== End Of Log ============================

 

 

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 24-01-2015 01
Ran by [removed] at 2015-01-24 20:23:36
Running from C:\Users\[removed]\Desktop\Clean Up\FRST64
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Kaspersky Internet Security (Disabled - Out of date) {C3113FBF-4BCB-4461-D78D-6EDFEC9593E5}
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Kaspersky Internet Security (Disabled - Up to date) {7870DE5B-6DF1-4BEF-ED3D-55AD9712D958}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Internet Security (Disabled) {FB2ABE9A-01A4-4539-FCD2-C7EA1246D49E}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

 clear.fi SDK - Video 2 (x32 Version: 2.1.2128 - CyberLink Corp.) Hidden
 clear.fi SDK- Movie 2 (x32 Version: 2.1.2112 - CyberLink Corp.) Hidden
Acer Backup Manager (HKLM-x32\…\InstallShield_{9DDDF20E-9FD1-4434-A43E-E7889DBC9420}) (Version: 4.0.0.0071 - NTI Corporation)
Acer Device Control Lite (HKLM-x32\…\ADevCtrl) (Version: 1.10.2005.20910 - Acer Inc.)
Acer Device Fast-lane (HKLM\…\{3F62D2FD-13C1-49A2-8B5D-47623D9460D7}) (Version: 1.00.3011 - Acer Incorporated)
Acer Instant Update Service (HKLM\…\{8215A318-CC27-435E-B3EA-2E3443C8998C}) (Version: 1.00.3013 - Acer Incorporated)
Acer PicEvermore (HKLM-x32\…\InstallShield_{25F6C1CB-C8F0-4BAE-996B-9C16F97B82F3}) (Version: 1.0.0.0036 - NTI Corporation)
Acer PicEvermore (x32 Version: 1.0.0.0036 - NTI Corporation) Hidden
Acer Power Management (HKLM\…\{91F52DE4-B789-42B0-9311-A349F10E5479}) (Version: 7.00.3011 - Acer Incorporated)
Acer Recovery Management (HKLM\…\{07F2005A-8CAC-4A4B-83A2-DA98A722CA61}) (Version: 6.00.3012 - Acer Incorporated)
Acer Theft Shield (HKLM\…\{8ADB0CD2-4E5A-452F-BB3B-3A2984CAC749}) (Version: 1.01.3006 - Acer Incorporated)
Acer USB Charge Manager (HKLM\…\{07E867C5-0C48-40FF-A013-DDAF4565AD47}) (Version: 2.00.3002 - Acer Incorporated)
AcerCloud (HKLM-x32\…\{A5AD0B17-F34D-49BE-A157-C8B3D52ACD13}) (Version: 2.01.3125 - Acer Incorporated)
AcerCloud Docs (HKLM-x32\…\{CA4FE8B0-298C-4E5D-A486-F33B126D6A0A}) (Version: 1.00.3204 - Acer Incorporated)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 4.0.0.1390 - Adobe Systems Incorporated)
Adobe Flash Player 16 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 16.0.0.296 - Adobe Systems Incorporated)
Adobe Photoshop Lightroom 3.6 64-bit (HKLM\…\{D4F66BBA-D79E-4F11-9B06-70C3D75A2958}) (Version: 3.6.1 - Adobe)
Adobe Photoshop Lightroom 5.3 64-bit (HKLM\…\{2DD71ACB-552D-402C-9529-7906ACB95C30}) (Version: 5.3.1 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Agatha Christie - Death on the Nile (x32 Version: 2.2.0.98 - WildTangent) Hidden
Aloha TriPeaks (x32 Version: 2.2.0.98 - WildTangent) Hidden
Apple Application Support (HKLM-x32\…\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Backup Manager v4 (x32 Version: 4.0.0.0071 - NTI Corporation) Hidden
Bejeweled 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden
BookSmart® 3.4.4 3.4.4 (HKLM-x32\…\BookSmart® 3.4.4 3.4.4) (Version:  - Blurb, Inc)
clear.fi Media (HKLM-x32\…\{E9AF1707-3F3A-49E2-8345-4F2D629D0876}) (Version: 2.01.3112 - Acer Incorporated)
clear.fi Photo (HKLM-x32\…\{B5AD89F2-03D3-4206-8487-018298007DD0}) (Version: 2.01.3109 - Acer Incorporated)
Cradle Of Egypt Collector's Edition (x32 Version: 2.2.0.98 - WildTangent) Hidden
CyberLink MediaEspresso 6.5 (HKLM-x32\…\InstallShield_{E3739848-5329-48E3-8D28-5BBD6E8BE384}) (Version: 6.5.3318_45364 - CyberLink Corp.)
Delicious: Emily's True Love Premium Edition (x32 Version: 2.2.0.98 - WildTangent) Hidden
Dolby Home Theater v4 (HKLM-x32\…\{B26438B4-BF51-49C3-9567-7F14A5E40CB9}) (Version: 7.2.8000.13 - Dolby Laboratories Inc)
Dora's World Adventure (x32 Version: 2.2.0.95 - WildTangent) Hidden
Dritek Radio Controller (HKLM-x32\…\RadioController) (Version: 2.02.2001.0803 - Dritek System Inc.)
Dropbox (HKU\S-1-5-21-2351201714-3478538817-3848901743-1001\…\Dropbox) (Version: 3.0.3 - Dropbox, Inc.)
eBay Worldwide (HKLM-x32\…\{A694AF57-9891-4D62-824C-7E55A1361A14}) (Version: 2.3.0630 - OEM)
EPSON Scan (HKLM-x32\…\EPSON Scanner) (Version:  - Seiko Epson Corporation)
EPSON WorkForce 845 Series Printer Uninstall (HKLM\…\EPSON WorkForce 845 Series) (Version:  - SEIKO EPSON Corporation)
ETDWare PS/2-X64 11.6.16.203_WHQL (HKLM\…\Elantech) (Version: 11.6.16.203 - ELAN Microelectronic Corp.)
ExpressCache (HKLM\…\{3EA6AB5D-D434-4ACA-9609-48F1319518EF}) (Version: 1.0.94 - Condusiv Technologies)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 39.0.2171.95 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
HID Monitor (HKLM-x32\…\{1C8D89D8-6B60-4034-9934-3AE90101CB22}) (Version: 1.1.3 - Acer Incorporated)
Identity Card (HKLM-x32\…\{3D9CB654-99AD-4301-89C6-0D12A790767C}) (Version: 2.00.3004 - Acer Incorporated)
Intel(R) Control Center (HKLM-x32\…\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1008 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3316 - Intel Corporation)
Intel(R) Rapid Start Technology (HKLM-x32\…\3D073343-CEEB-4ce7-85AC-A69A7631B5D6) (Version: 2.1.0.1002 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\…\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.5.4.1001 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\…\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation)
iSEEK AnswerWorks English Runtime (HKLM-x32\…\{18A8E78B-9EF2-496E-B310-BCD8E4C1DAB3}) (Version: [removed] - Vantage Linguistics)
Jewel Match 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden
Kaspersky Internet Security 2013 (HKLM-x32\…\InstallWIX_{560985FB-4B76-4121-9189-7A2CDC7886D6}) (Version: 13.0.1.4190 - Kaspersky Lab)
Kaspersky Internet Security 2013 (x32 Version: 13.0.1.4190 - Kaspersky Lab) Hidden
Launch Manager (HKLM-x32\…\LManager) (Version: 7.0.4 - Acer Inc.)
LeapFrog Connect (HKLM-x32\…\UPCShell) (Version: 6.0.19.19317 - LeapFrog)
LeapFrog Connect (x32 Version: 6.0.19.19317 - LeapFrog) Hidden
LeapFrog LeapReader Plugin (x32 Version: 5.0.19.17305 - LeapFrog) Hidden
LeapFrog LeapReader Plugin (x32 Version: 5.2.4.18512 - LeapFrog) Hidden
LeapFrog LeapReader Plugin (x32 Version: 6.0.19.19317 - LeapFrog) Hidden
LeapFrog Tag Junior Plugin (x32 Version: 5.1.26.18340 - LeapFrog) Hidden
LeapFrog Tag Plugin (x32 Version: 6.0.19.19317 - LeapFrog) Hidden
Live Updater (HKLM-x32\…\{EE26E302-876A-48D9-9058-3129E5B99999}) (Version: 2.00.3006 - Acer Incorporated)
Microsoft Office (HKLM-x32\…\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4420.1017 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM-x32\…\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Mozilla Firefox 35.0 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 35.0 (x86 en-US)) (Version: 35.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
Mystery P.I. - Curious Case of Counterfeit Cove (x32 Version: 2.2.0.98 - WildTangent) Hidden
MyWinLocker (Version: 4.0.14.35 - Egis Technology Inc.) Hidden
MyWinLocker 4 (x32 Version: 4.0.14.35 - Egis Technology Inc.) Hidden
MyWinLocker Suite (HKLM-x32\…\InstallShield_{17DF9714-60C9-43C9-A9C2-32BCAED44CBE}) (Version: 4.0.14.24 - Egis Technology Inc.)
MyWinLocker Suite (x32 Version: 4.0.14.24 - Egis Technology Inc.) Hidden
Nicoles Online Classes (HKLM-x32\…\net.nicolesclasses.nicolesonlineclasses) (Version: 1.5.28 - UNKNOWN)
Nicoles Online Classes (x32 Version: 1.5.28 - UNKNOWN) Hidden
Norton Online Backup (HKLM-x32\…\{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}) (Version: 2.2.3.51r - Symantec Corporation)
Norton Online Backup ARA (x32 Version: 4.1.0.14 - Symantec Corporation) Hidden
NTI Media Maker 9 (HKLM-x32\…\InstallShield_{D3D5C4E8-040F-4C6F-8105-41D43CF94F44}) (Version: 9.0.2.9014 - NTI Corporation)
NTI Media Maker 9 (x32 Version: 9.0.2.9014 - NTI Corporation) Hidden
Office Addin (HKLM-x32\…\{6D2BBE1D-E600-4695-BA37-0B0E605542CC}) (Version: 2.01.3202 - Acer)
Peggle Nights (x32 Version: 2.2.0.98 - WildTangent) Hidden
Penguins! (x32 Version: 2.2.0.98 - WildTangent) Hidden
Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.98 - WildTangent) Hidden
PlayReady PC Runtime x86 (HKLM-x32\…\{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}) (Version: 1.3.0 - Microsoft Corporation)
Polar Bowler (x32 Version: 2.2.0.97 - WildTangent) Hidden
Polar Golfer (x32 Version: 2.2.0.98 - WildTangent) Hidden
Qualcomm Atheros Bluetooth Suite (64) (HKLM\…\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.0.214 - Qualcomm Atheros Communications)
Qualcomm Atheros WLAN and Bluetooth Client Installation Program (HKLM-x32\…\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 11.30 - Qualcomm Atheros)
Quicken 2013 (HKLM-x32\…\{034DD4BB-F0D6-4ECF-B064-8E39E3EF7076}) (Version: 22.1.12.7 - Intuit)
QuickTime 7 (HKLM-x32\…\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6657 - Realtek Semiconductor Corp.)
Realtek PCIE Card Reader (HKLM-x32\…\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.2.9200.28130 - Realtek Semiconductor Corp.)
Scholastic eReader Support Files (HKLM-x32\…\{3F53A950-E68B-4F0B-A072-86F146549E88}) (Version: 1.1.5179 - Scholastic)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\…\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Shared C Run-time for x64 (HKLM\…\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee)
Shredder (Version: 2.0.8.9 - Egis Technology Inc.) Hidden
Shredder (x32 Version: 2.0.8.9 - Egis Technology Inc.) Hidden
Silhouette Studio (HKLM-x32\…\{7A1096AA-9B25-4290-A3F6-B5A814976B25}) (Version: 3.0.531 - Silhouette America)
Skype Click to Call (HKLM-x32\…\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation)
Skype™ 6.11 (HKLM-x32\…\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.)
Sleep Memory Optimizer (HKLM\…\{BF63C2C3-9A5B-4366-AA5F-015292B919F0}) (Version: 1.01.3000 - Acer Incorporated)
Smart Timer (HKLM-x32\…\{89DB52FC-EA72-468F-A0C7-150AF8B7AB74}) (Version: 1.00.3007 - Acer Incorporated)
Spotify (HKLM-x32\…\Spotify) (Version: 0.8.4.99.ga249b5f1 - Spotify AB)
Tales of Lagoona (x32 Version: 2.2.0.110 - WildTangent) Hidden
Update Installer for WildTangent Games App (x32 Version:  - WildTangent) Hidden
Use the entry named LeapFrog Connect to uninstall (LeapFrog LeapReader Plugin) (HKLM-x32\…\LeapPadExplorerPlugin) (Version:  - LeapFrog)
Use the entry named LeapFrog Connect to uninstall (LeapFrog LeapReader Plugin) (HKLM-x32\…\LeapReaderPlugin) (Version:  - LeapFrog)
Use the entry named LeapFrog Connect to uninstall (LeapFrog Tag Junior Plugin) (HKLM-x32\…\TagJuniorPlugin) (Version:  - LeapFrog)
Use the entry named LeapFrog Connect to uninstall (LeapFrog Tag Plugin) (HKLM-x32\…\TagPlugin) (Version: 6.0.19.19317 - LeapFrog)
Visual Studio 2005 Tools for Office Second Edition Runtime (HKLM-x32\…\Microsoft Visual Studio 2005 Tools for Office Runtime) (Version:  - Microsoft Corporation)
Visual Studio Tools for the Office system 3.0 Runtime (HKLM-x32\…\Visual Studio Tools for the Office system 3.0 Runtime) (Version:  - Microsoft Corporation)
Visual Studio Tools for the Office system 3.0 Runtime Service Pack 1 (KB949258) (HKLM-x32\…\{8FB53850-246A-3507-8ADE-0060093FFEA6}.KB949258) (Version: 1 - Microsoft Corporation)
WildTangent Games (HKLM-x32\…\WildTangent wildgames Master Uninstall) (Version: 1.0.3.0 - WildTangent)
WildTangent Games App (x32 Version: 4.0.10.16 - WildTangent) Hidden
Windows Driver Package - LeapFrog (FlyUsb) USB  (11/05/2008 1.1.1.0) (HKLM\…\781745E87AFF80C0C1388CFF79D19ECAB2E9BB47) (Version: 11/05/2008 1.1.1.0 - LeapFrog)
Windows Driver Package - Leapfrog (Leapfrog-USBLAN) Net  (09/10/2009 02.03.05.012) (HKLM\…\8F14F2ECEDE68D26EA515B48DC25B39103C4FE8D) (Version: 09/10/2009 02.03.05.012 - Leapfrog)
Wondershare Video Converter Ultimate(Build 6.5.1.2) (HKLM-x32\…\Wondershare Video Converter Ultimate_is1) (Version: 6.5.1.2 - Wondershare Software)
Wondershare Video Editor(Build 3.1.3) (HKLM-x32\…\Wondershare Video Editor_is1) (Version:  - Wondershare Software)
WTTouchApplicationSuite (HKLM-x32\…\{D6D6EB59-35DB-4056-A0D3-01ABF7904E84}) (Version: 2.00.3009 - Acer Incorporated.)
Zuma's Revenge (x32 Version: 2.2.0.98 - WildTangent) Hidden

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-2351201714-3478538817-3848901743-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Kira\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2351201714-3478538817-3848901743-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Kira\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2351201714-3478538817-3848901743-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Kira\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2351201714-3478538817-3848901743-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Kira\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2351201714-3478538817-3848901743-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Kira\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2351201714-3478538817-3848901743-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Kira\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2351201714-3478538817-3848901743-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Kira\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2351201714-3478538817-3848901743-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Kira\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2351201714-3478538817-3848901743-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Kira\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)

==================== Restore Points  =========================

04-01-2015 23:57:45 Scheduled Checkpoint
13-01-2015 15:17:00 Windows Update
21-01-2015 09:59:42 Scheduled Checkpoint

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-08-22 07:25 - 2013-08-22 07:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {04DF74B1-84A5-4279-8100-EB2C26875AB0} - System32\Tasks\DeviceDetector => C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe [2012-09-19] (CyberLink)
Task: {118DADC8-2E54-47E1-8AEE-2817C7BC6585} - System32\Tasks\Power Management => C:\Program Files\Acer\Acer Power Management\ePowerTray.exe [2012-10-23] (Acer Incorporated)
Task: {27AF0BAC-9A96-4E62-B1E0-38F0FE88B4F7} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-01-13] (Microsoft Corporation)
Task: {28C8AB5C-4D8A-4AC8-9E15-C8F3434F9E50} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-29] (Google Inc.)
Task: {4604260F-E999-49A1-A03E-BCA96E16668E} - System32\Tasks\AcerRingSchedule => C:\Program Files\Acer\WTTouchApplicationSuite\AcerRing\AcerRing.exe
Task: {4BB89F46-A15B-4B83-AAA6-9E55A9120772} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {538BD66D-0B90-432B-B984-AC26F8EC5229} - System32\Tasks\EgisUpdate => C:\Program Files\EgisTec IPS\EgisUpdate.exe [2012-07-11] (Egis Technology Inc.)
Task: {57ABF43C-AA09-4413-B68E-51CE7AFC6CB4} - System32\Tasks\iuEmailOutlookAgent => C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe [2012-08-22] ()
Task: {5E7ECA95-B6B4-4FDE-9E51-135432803351} - System32\Tasks\{40EBC5CE-A183-4EC5-96F4-CD3CA0DB3B03} => Iexplore.exe http://ui.skype.com/ui/0/6.5.0.158/en/abandoninstall?page=tsProgressBar
Task: {6B02A8DC-2935-4086-BAAF-2A65EE5AA32B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-29] (Google Inc.)
Task: {6D5A9119-53EE-45D3-BD3E-20405C04DAAE} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {6FC2A951-EDA6-404B-B67C-CD7EBA083B3D} - System32\Tasks\iuBrowserIEAgent => C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe [2012-08-22] ()
Task: {79293D36-D044-4C84-AFF5-E23F40F4D292} - System32\Tasks\ALU => C:\Program Files (x86)\Acer\Live Updater\updater.exe [2012-11-06] ()
Task: {8DC6DB71-EF41-4241-8F0B-DB533F0820DD} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-01-24] (Adobe Systems Incorporated)
Task: {A4E65EF1-F218-491A-B0CF-809D8198EED5} - System32\Tasks\HIDMonitor => C:\Program Files\Acer Incorporated\HID Monitor\HIDMonitor.exe
Task: {AD3E97D5-344D-4F7A-B9FE-2C543619B79D} - System32\Tasks\PMMUpdate => C:\Program Files\EgisTec IPS\PMMUpdate.exe [2012-07-11] (Egis Technology Inc.)
Task: {BD148D9D-9F56-42C5-A49A-58B2E3B45CD7} - System32\Tasks\ALUAgent => C:\Program Files (x86)\Acer\Live Updater\liveupdater_agent.exe [2012-06-21] ()
Task: {D0FFBDE6-7A53-4616-89E6-B6EC98E6933E} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {E216DE99-D1C5-487A-AFC8-8689A4F1529E} - System32\Tasks\Smart Timer Task Scheduler => C:\Program Files\Smart Timer\Smart_Timer.exe [2012-06-22] (Acer Incorporated)
Task: {E2CAF192-A660-4CA5-B9B4-0B7FEEE3255E} - System32\Tasks\UpdaterEX => C:\Users\Kira\AppData\Roaming\UPDATE~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: {F4044068-4C5D-45A6-A35D-8C5470729209} - System32\Tasks\Theft Shield\AcerTheftShieldTask => C:\Program Files\Acer\Acer Theft Shield\USecuAppLauncher.exe [2012-11-12] (Acer Incorporated)
Task: {F47F6E79-2453-4619-B9ED-E56B4EF05A34} - System32\Tasks\Recovery Management\Notification => C:\Program Files\Acer\Acer Recovery Management\Notification\Notification.exe [2012-10-08] (Acer Incorporated)
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\UpdaterEX.job => C:\Users\Kira\AppData\Roaming\UPDATE~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION

==================== Loaded Modules (whitelisted) =============

2012-08-23 16:02 - 2012-08-23 16:02 - 00030640 _____ () C:\Program Files (x86)\Acer Incorporated\HID Monitor\HIDMonitor.exe
2013-09-05 00:17 - 2013-09-05 00:17 - 04300456 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2010-10-20 14:23 - 2010-10-20 14:23 - 08801632 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
2013-07-02 07:17 - 2013-03-25 09:57 - 00727952 _____ () C:\Windows\SysWOW64\WSCM64.dll
2012-06-21 20:12 - 2012-06-21 20:12 - 01407568 _____ () C:\Program Files (x86)\EgisTec MyWinLocker\x64\LIBEAY32.dll
2013-12-02 15:58 - 2013-12-02 15:58 - 00727448 _____ () C:\Program Files\Adobe\Adobe Photoshop Lightroom 5.3\AgKernel.dll
2013-12-02 15:59 - 2013-12-02 15:59 - 00332184 _____ () C:\Program Files\Adobe\Adobe Photoshop Lightroom 5.3\WFCore.dll
2013-12-02 15:59 - 2013-12-02 15:59 - 00030104 _____ () C:\Program Files\Adobe\Adobe Photoshop Lightroom 5.3\WFSQLite.dll
2013-12-02 15:59 - 2013-12-02 15:59 - 00081304 _____ () C:\Program Files\Adobe\Adobe Photoshop Lightroom 5.3\WFWeb.dll
2013-12-02 15:59 - 2013-12-02 15:59 - 00713112 _____ () C:\Program Files\Adobe\Adobe Photoshop Lightroom 5.3\WFOzClient.dll
2013-12-02 16:00 - 2013-12-02 16:00 - 00115096 _____ () C:\Program Files\Adobe\Adobe Photoshop Lightroom 5.3\moxplugins\AppManagerLR.mox
2013-12-02 16:00 - 2013-12-02 16:00 - 00246680 _____ () C:\Program Files\Adobe\Adobe Photoshop Lightroom 5.3\moxplugins\wpdmanager.mox
2013-10-03 23:42 - 2013-10-03 23:42 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2012-12-17 06:15 - 2012-03-14 03:55 - 00097872 _____ () C:\Program Files (x86)\Acer\Device Control\WlanMonitor64.dll
2012-11-09 18:06 - 2012-11-09 18:06 - 00384128 _____ () C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\ContactsApi.dll
2012-11-09 18:04 - 2012-11-09 18:04 - 00011264 _____ () C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\Modules\ActivateDesktopDebugger\ActivateDesktopDebugger.dll
2012-11-09 18:06 - 2012-11-09 18:06 - 00012928 _____ () C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\ActivateDesktop.exe
2013-12-02 15:58 - 2013-12-02 15:58 - 03505560 _____ () C:\Program Files\Adobe\Adobe Photoshop Lightroom 5.3\Support\DynamicLinkMediaServer\dynamiclinkmediaserver\1.0\DNxHDCodec.dll
2013-12-02 15:33 - 2013-12-02 15:33 - 00302592 _____ () C:\Program Files\Adobe\Adobe Photoshop Lightroom 5.3\Support\DynamicLinkMediaServer\dynamiclinkmediaserver\1.0\MOG_Framework_2.2.11.dll
2012-08-22 17:04 - 2012-08-22 17:04 - 00025232 _____ () C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe
2012-08-22 17:04 - 2012-08-22 17:04 - 00044176 _____ () C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe
2012-11-02 18:38 - 2012-11-02 18:38 - 00465384 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\sqlite3.dll
2012-11-02 18:37 - 2012-11-02 18:37 - 00125504 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\MailConverter32.dll
2012-11-02 18:38 - 2012-11-02 18:38 - 00155712 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\VolumeSnapshot.dll
2012-11-02 18:37 - 2012-11-02 18:37 - 00118336 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\Online.dll
2012-11-02 18:37 - 2012-11-02 18:37 - 01081408 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\ACE.dll
2012-11-02 18:37 - 2012-11-02 18:37 - 00052288 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\OsSettingPort.dll
2012-11-02 18:37 - 2012-11-02 18:37 - 00727616 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\OutlookShadow.dll
2014-10-30 14:25 - 2014-10-30 14:25 - 00016384 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\PSIClient\63948598d919af60addb114fdd3ccb56\PSIClient.ni.dll
2013-02-22 15:30 - 2012-06-25 11:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
2012-08-23 16:02 - 2012-08-23 16:02 - 00034736 _____ () C:\Program Files (x86)\Acer Incorporated\HID Monitor\ElanTPAPI.dll
2014-10-21 18:22 - 2014-10-21 18:22 - 00750080 _____ () C:\Users\Kira\AppData\Roaming\Dropbox\bin\libGLESv2.dll
2015-01-22 17:04 - 2015-01-22 17:04 - 00043008 _____ () c:\users\kira\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpqkzv3v.dll
2014-10-21 18:22 - 2014-10-21 18:22 - 00047616 _____ () C:\Users\Kira\AppData\Roaming\Dropbox\bin\libEGL.dll
2014-10-21 18:22 - 2014-10-21 18:22 - 00863744 _____ () C:\Users\Kira\AppData\Roaming\Dropbox\bin\plugins\platforms\qwindows.dll
2014-10-21 18:22 - 2014-10-21 18:22 - 00200704 _____ () C:\Users\Kira\AppData\Roaming\Dropbox\bin\plugins\imageformats\qjpeg.dll
2014-02-01 12:30 - 2014-02-01 12:30 - 00861184 _____ () C:\Program Files (x86)\LeapFrog\LeapFrog Connect\platforms\qwindows.dll
2013-04-21 20:44 - 2013-04-21 20:44 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2013-04-21 20:44 - 2013-04-21 20:44 - 01242952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2015-01-18 15:28 - 2015-01-18 15:28 - 03925104 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\Users\Kira\SkyDrive:ms-properties

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)


========================= Accounts: ==========================

Administrator (S-1-5-21-2351201714-3478538817-3848901743-500 - Administrator - Disabled)
Guest (S-1-5-21-2351201714-3478538817-3848901743-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2351201714-3478538817-3848901743-1003 - Limited - Enabled)
Kira (S-1-5-21-2351201714-3478538817-3848901743-1001 - Administrator - Enabled) => C:\Users\Kira

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (01/24/2015 05:07:41 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005

Error: (01/24/2015 03:16:49 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program chrome.exe version 39.0.2171.95 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 204c

Start Time: 01d0381acd6df0c5

Termination Time: 4294967295

Application Path: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

Report Id: 4dcb2e92-a40e-11e4-bedd-089e01848867

Faulting package full name:

Faulting package-relative application ID:

Error: (01/22/2015 05:18:00 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005

Error: (01/21/2015 07:55:59 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program firefox.exe version 35.0.0.5486 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: af8c

Start Time: 01d0358503f3e5a9

Termination Time: 46

Application Path: C:\Program Files (x86)\Mozilla Firefox\firefox.exe

Report Id: cb6da81c-a1d9-11e4-bedc-089e01848867

Faulting package full name:

Faulting package-relative application ID:

Error: (01/21/2015 07:55:58 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: plugin-container.exe, version: 35.0.0.5486, time stamp: 0x54af7153
Faulting module name: mozalloc.dll, version: 35.0.0.5486, time stamp: 0x54af69d4
Exception code: 0x80000003
Fault offset: 0x00001425
Faulting process id: 0xb298
Faulting application start time: 0xplugin-container.exe0
Faulting application path: plugin-container.exe1
Faulting module path: plugin-container.exe2
Report Id: plugin-container.exe3
Faulting package full name: plugin-container.exe4
Faulting package-relative application ID: plugin-container.exe5

Error: (01/20/2015 06:44:39 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005

Error: (01/20/2015 06:30:15 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: plugin-container.exe, version: 34.0.5.5443, time stamp: 0x5475dd5d
Faulting module name: mozalloc.dll, version: 34.0.5.5443, time stamp: 0x5475d664
Exception code: 0x80000003
Fault offset: 0x00001425
Faulting process id: 0x1abc
Faulting application start time: 0xplugin-container.exe0
Faulting application path: plugin-container.exe1
Faulting module path: plugin-container.exe2
Report Id: plugin-container.exe3
Faulting package full name: plugin-container.exe4
Faulting package-relative application ID: plugin-container.exe5

Error: (01/18/2015 03:32:06 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005

Error: (01/14/2015 04:18:47 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005

Error: (01/13/2015 11:27:33 PM) (Source: Chrome) (EventID: 1) (User: NT AUTHORITY)
Description: Chrome has encountered a fatal error.
ver=39.0.2171.95;lang=;guid=C8D997D07A214BD782BD821A8A7FAE94;is_machine=1;oop=1;upload=1;minidump=C:\Program Files (x86)\Google\CrashReports\88a9eea8-815e-40bf-9b81-ef9800686d71.dmp


System errors:
=============
Error: (01/24/2015 07:22:06 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the BFE service.

Error: (01/24/2015 07:21:25 PM) (Source: BTHUSB) (EventID: 17) (User: )
Description: The local Bluetooth adapter has failed in an undetermined manner and will not be used. The driver has been unloaded.

Error: (01/24/2015 04:17:47 PM) (Source: BTHUSB) (EventID: 17) (User: )
Description: The local Bluetooth adapter has failed in an undetermined manner and will not be used. The driver has been unloaded.

Error: (01/23/2015 04:05:06 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the NcdAutoSetup service.

Error: (01/22/2015 07:56:11 PM) (Source: BTHUSB) (EventID: 17) (User: )
Description: The local Bluetooth adapter has failed in an undetermined manner and will not be used. The driver has been unloaded.

Error: (01/22/2015 04:47:07 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The SWUpdaterSvc service failed to start due to the following error:
%%1053

Error: (01/22/2015 04:47:07 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the SWUpdaterSvc service to connect.

Error: (01/22/2015 04:42:57 PM) (Source: DCOM) (EventID: 10010) (User: MOMMERS)
Description: {D63B10C5-BB46-4990-A94F-E40B9D520160}

Error: (01/22/2015 04:42:57 PM) (Source: DCOM) (EventID: 10010) (User: MOMMERS)
Description: {D63B10C5-BB46-4990-A94F-E40B9D520160}

Error: (01/22/2015 04:42:57 PM) (Source: DCOM) (EventID: 10010) (User: MOMMERS)
Description: {D63B10C5-BB46-4990-A94F-E40B9D520160}


Microsoft Office Sessions:
=========================
Error: (01/24/2015 05:07:41 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005

Error: (01/24/2015 03:16:49 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: chrome.exe39.0.2171.95204c01d0381acd6df0c54294967295C:\Program Files (x86)\Google\Chrome\Application\chrome.exe4dcb2e92-a40e-11e4-bedd-089e01848867

Error: (01/22/2015 05:18:00 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005

Error: (01/21/2015 07:55:59 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: firefox.exe35.0.0.5486af8c01d0358503f3e5a946C:\Program Files (x86)\Mozilla Firefox\firefox.execb6da81c-a1d9-11e4-bedc-089e01848867

Error: (01/21/2015 07:55:58 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe35.0.0.548654af7153mozalloc.dll35.0.0.548654af69d48000000300001425b29801d035869ec05c39C:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozalloc.dllcedc9513-a1d9-11e4-bedc-089e01848867

Error: (01/20/2015 06:44:39 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005

Error: (01/20/2015 06:30:15 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe34.0.5.54435475dd5dmozalloc.dll34.0.5.54435475d66480000003000014251abc01d0331a99713289C:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozalloc.dllaaaa4131-a104-11e4-bedc-089e01848867

Error: (01/18/2015 03:32:06 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005

Error: (01/14/2015 04:18:47 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005

Error: (01/13/2015 11:27:33 PM) (Source: Chrome) (EventID: 1) (User: NT AUTHORITY)
Description: Chrome has encountered a fatal error.
ver=39.0.2171.95;lang=;guid=C8D997D07A214BD782BD821A8A7FAE94;is_machine=1;oop=1;upload=1;minidump=C:\Program Files (x86)\Google\CrashReports\88a9eea8-815e-40bf-9b81-ef9800686d71.dmp


CodeIntegrity Errors:
===================================
  Date: 2015-01-24 20:00:22.215
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-01-24 20:00:22.049
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-01-24 20:00:21.881
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-01-24 20:00:17.027
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-01-24 20:00:16.797
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-01-24 20:00:16.130
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-01-24 20:00:14.877
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-01-24 15:49:37.553
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-01-24 15:49:37.406
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-01-24 15:40:11.191
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i5-3337U CPU @ 1.80GHz
Percentage of memory in use: 73%
Total physical RAM: 5955.27 MB
Available physical RAM: 1550.21 MB
Total Pagefile: 24387.27 MB
Available Pagefile: 14920.31 MB
Total Virtual: 131072 MB
Available Virtual: 131071.8 MB

==================== Drives ================================

Drive c: (Acer) (Fixed) (Total:447.61 GB) (Free:301.25 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: A4E98678)

Partition: GPT Partition Type.

========================================================
Disk: 1 (Size: 18.6 GB) (Disk ID: 63011D65)

Partition: GPT Partition Type.

==================== End Of Log ============================

 
 
Hi and welcome

The infection has attacked Google Chrome so we will have to uninstall and redownload.

Instructions on how to backup your Favourites/Bookmarks and other data can be found below.
  • [external image: U5NwUGc.png]Backup Chrome Bookmarks
~~~~
Please download and install Revo Uninstaller Free
  • Double click Revo Uninstaller to run it.
  • From the list of programs double click on Google Chrome
  • When prompted if you want to uninstall click Yes.
  • Be sure the Moderate option is selected then click Next.
  • The program will run, If prompted again click Yes
  • when the built-in uninstaller is finished click on Next.
  • Once the program has searched for leftovers click Next.
  • Check/tick the bolded items only on the list then click Delete
  • when prompted click on Yes and then on next.
  • put a check on any folders that are found and select delete
  • when prompted select yes then on next
  • Once done click Finish.
~~~

You can download Google Chrome again from here http://www.google.com/chrome/

~~~~~

Open notepad. Please copy the contents of the quote box below. To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
Yours is located here (Running from C:\Users\[removed]\Desktop\Clean Up\FRST64)
It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)

[external image: FRSTfix.JPG]

 

start
CloseProcesses:
C:\Users\Kira\AppData\Local\Temp\__tmp_2d00d7ea
C:\ProgramData\2355320829\BITA3DF.tmp
HKU\S-1-5-21-2351201714-3478538817-3848901743-1001\…\Run: [GoogleChromeAutoLaunch_82456ACC06A7292895434703ADA84C9D] => "C:\Users\Kira\AppData\Local\Vosteran\Application\vosteran.exe" –auto-launch-at-startup –profile-directory="Default"
ShortcutTarget: StormWatch.lnk -> C:\Program Files (x86)\StormWatch\StormWatch.exe (No File)
Startup: C:\Users\Kira\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\StormWatchApp.lnk
ShortcutTarget: StormWatchApp.lnk -> C:\Program Files (x86)\StormWatch\StormWatchApp.exe (No File)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKU\S-1-5-21-2351201714-3478538817-3848901743-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://Vosteran.com/…r=531242758&ir=
SearchScopes: HKLM -> DefaultScope {492C118E-8F2A-438F-B5B5-19E2C7BDF8CB} URL = http://Vosteran.com/…r=531242758&ir=
SearchScopes: HKLM -> {492C118E-8F2A-438F-B5B5-19E2C7BDF8CB} URL = http://Vosteran.com/…r=531242758&ir=
SearchScopes: HKU\S-1-5-21-2351201714-3478538817-3848901743-1001 -> DefaultScope {492C118E-8F2A-438F-B5B5-19E2C7BDF8CB} URL = http://Vosteran.com/…r=531242758&ir=
SearchScopes: HKU\S-1-5-21-2351201714-3478538817-3848901743-1001 -> {492C118E-8F2A-438F-B5B5-19E2C7BDF8CB} URL = http://Vosteran.com/…r=531242758&ir=
SearchScopes: HKU\S-1-5-21-2351201714-3478538817-3848901743-1001 -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL =
FF SelectedSearchEngine: Vosteran
FF SearchPlugin: C:\Users\Kira\AppData\Roaming\Mozilla\Firefox\Profiles\lkwufyjq.default\searchplugins\Vosteran.xml
FF Extension: buyfast - C:\Users\Kira\AppData\Roaming\Mozilla\Firefox\Profiles\lkwufyjq.default\Extensions\[removed] [2014-12-23]
FF Extension: rocketdeal - C:\Users\Kira\AppData\Roaming\Mozilla\Firefox\Profiles\lkwufyjq.default\Extensions\[removed] [2014-12-23]
FF Extension: broWWseandusHop - C:\Users\Kira\AppData\Roaming\Mozilla\Firefox\Profiles\lkwufyjq.default\Extensions\[removed] [2015-01-12]
FF Extension: buyanedbroWse - C:\Users\Kira\AppData\Roaming\Mozilla\Firefox\Profiles\lkwufyjq.default\Extensions\[removed] [2015-01-12]
2015-01-11 08:30 - 2015-01-22 16:46 - 00000000 ____D () C:\ProgramData\oFiferaappa
2015-01-11 08:30 - 2015-01-22 16:46 - 00000000 ____D () C:\ProgramData\niceinfrree
C:\Users\Kira\AppData\Local\Temp\BSI.exe
C:\Users\Kira\AppData\Local\Temp\DriverSupport.exe
C:\Users\Kira\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpqkzv3v.dll
C:\Users\Kira\AppData\Local\Temp\i4jdel0.exe
Task: C:\WINDOWS\Tasks\UpdaterEX.job => C:\Users\Kira\AppData\Roaming\UPDATE~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
EmptyTemp:
Hosts:
End


~~~~~~~~~~~~~~~~~~~`

[external image: BY4dvz9.png]AdwCleaner
  • Please download AdwCleaner and save the file to your Desktop.
  • Right-Click AdwCleaner.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Follow the prompts.
  • Click Scan.
  • Upon completion, click Report. A log (AdwCleaner[R0].txt) will open. Briefly check the log for anything you know to be legitimate.
  • Ensure anything you know to be legitimate does not have a checkmark, and click Clean.
  • Follow the prompts and allow your computer to reboot.
  • After rebooting, a log (AdwCleaner[S0].txt) will open. Copy the contents of the log and paste in your next reply.
  • – File and registry key backups are made for anything removed using this tool. Should a legitimate entry be removed (otherwise known as a 'false-positive'), simple steps can be taken to restore the entry. Please do not overly concern yourself with the contents of AdwCleaner[R0].txt.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


    [external image: thisisujrt.gif]
    Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Post the contents of JRT.txt into your next message.
    please post
    Fixlog.txt
    C:\AdwCleaner.txt
    JRT.txt

Hi Juliet, thanks for your help.

 

Ok, I followed your instructions, but I don't see where a fixlog.txt file is created in your instructions.  It seems to me there was maybe a missing step in the 2nd group of instructions (after uninstall and re-install of Chrome) because I created the fixlist file but didn't run a program that would create a fixlog file.  The other 2 logs are below.

 

 

# AdwCleaner v4.109 - Report created 25/01/2015 at 23:50:45
# Updated 24/01/2015 by Xplode
# Database : 2015-01-25.1 [Live]
# Operating System : Windows 8.1  (64 bits)
# Username : Kira - MOMMERS
# Running from : C:\Users\Kira\Desktop\Clean Up\AdwClean\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****

[#] Service Deleted : SWUpdater

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\offersoft
Folder Deleted : C:\ProgramData\7f4605c5ff46c5a7
Folder Deleted : C:\ProgramData\f5805e03000049f5
Folder Deleted : C:\Program Files (x86)\StormWatch
Folder Deleted : C:\Program Files (x86)\offersoft
Folder Deleted : C:\Users\Kira\AppData\Local\StormWatch
Folder Deleted : C:\Users\Kira\AppData\Local\Weather_Protector_LLC
Folder Deleted : C:\Users\Kira\AppData\Local\Vosteran
Folder Deleted : C:\Users\Kira\AppData\Roaming\UpdaterEX
Folder Deleted : C:\Users\Kira\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StormWatch
Folder Deleted : C:\Users\Kira\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Vosteran
File Deleted : C:\Users\Kira\AppData\Local\Temp\DriverSupport.exe
File Deleted : C:\Users\Kira\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\StormWatch.lnk
File Deleted : C:\Users\Kira\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\StormWatchApp.lnk
File Deleted : C:\Users\Kira\AppData\Roaming\Mozilla\Firefox\Profiles\lkwufyjq.default\user.js
File Deleted : C:\Users\Kira\AppData\Roaming\Mozilla\Firefox\Profiles\lkwufyjq.default\searchplugins\Vosteran.xml

***** [ Scheduled Tasks ] *****

Task Deleted : UpdaterEX

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\oilkkkefbalmbfppgjmgjoefbclebkce
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1663C10B-0D55-438D-8496-19A3DBAEC0E4}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E993643-8FBC-44FE-BC85-D318495C4D96}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A43DE495-3D00-47D4-9D2C-303115707939}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{492C118E-8F2A-438F-B5B5-19E2C7BDF8CB}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{492C118E-8F2A-438F-B5B5-19E2C7BDF8CB}
Key Deleted : HKCU\Software\InstallCore
Key Deleted : HKCU\Software\UpdaterEX
Key Deleted : HKCU\Software\StormWatchApp
Key Deleted : HKCU\Software\Vosteran Browser
Key Deleted : HKCU\Software\Vosteran
Key Deleted : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKCU\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
Key Deleted : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Key Deleted : HKLM\SOFTWARE\StormWatch
Key Deleted : HKLM\SOFTWARE\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
Key Deleted : HKLM\SOFTWARE\{12A61307-94CD-4F8E-94BC-918E511FAA81}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\delta.com
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\howsweeteats.com
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\vacationtimesharerentals.com
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\veoh.com
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\vosteran.com
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.howsweeteats.com

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17416


-\\ Mozilla Firefox v35.0 (x86 en-US)

[lkwufyjq.default\prefs.js] - Line Deleted : user_pref("browser.search.hiddenOneOffs", "Vosteran,DuckDuckGo");
[lkwufyjq.default\prefs.js] - Line Deleted : user_pref("browser.search.selectedEngine", "Vosteran");
[lkwufyjq.default\prefs.js] - Line Deleted : user_pref("extensions.srchvstrn.hmpgUrl", "hxxp://Vosteran.com/?f=1&a=vst_dnldstr_14_50_ch&cd=2XzuyEtN2Y1L1Qzu0FyE0ByB0EtB0AtA0B0DtCtC0EyEtB0FtN0D0Tzu0StCtDyByCtN1L2XzutAtFyCtFtCtDtFyBtN1L1CzutCyEtBzy[…]
[lkwufyjq.default\prefs.js] - Line Deleted : user_pref("extensions.srchvstrn.newTabUrl", "hxxp://Vosteran.com/?f=2&a=vst_dnldstr_14_50_ch&cd=2XzuyEtN2Y1L1Qzu0FyE0ByB0EtB0AtA0B0DtCtC0EyEtB0FtN0D0Tzu0StCtDyByCtN1L2XzutAtFyCtFtCtDtFyBtN1L1CzutCyEtB[…]
[lkwufyjq.default\prefs.js] - Line Deleted : user_pref("extensions.srchvstrn.prtnrId", "WSE_Vosteran");
[lkwufyjq.default\prefs.js] - Line Deleted : user_pref("extensions.srchvstrn.srchPrvdr", "Vosteran");
[lkwufyjq.default\prefs.js] - Line Deleted : user_pref("extensions.srchvstrn.tlbrSrchUrl", "hxxp://Vosteran.com/?f=3&a=vst_dnldstr_14_50_ch&cd=2XzuyEtN2Y1L1Qzu0FyE0ByB0EtB0AtA0B0DtCtC0EyEtB0FtN0D0Tzu0StCtDyByCtN1L2XzutAtFyCtFtCtDtFyBtN1L1CzutCyE[…]

-\\ Google Chrome v40.0.2214.91

[C:\Users\Kira\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms}
[C:\Users\Kira\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}

*************************

AdwCleaner[R0].txt - [5815 octets] - [25/01/2015 23:40:21]
AdwCleaner[S0].txt - [5537 octets] - [25/01/2015 23:50:45]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5597 octets] ##########

 

 

 

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.1 (12.28.2014:1)
OS: Windows 8.1 x64
Ran by [removed] on Mon 01/26/2015 at  0:00:04.60
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\browserpluginhelper



~~~ Registry Keys



~~~ Files



~~~ Folders



~~~ FireFox

Successfully deleted the following from C:\Users\Kira\AppData\Roaming\mozilla\firefox\profiles\lkwufyjq.default\prefs.js

user_pref("BKHEHrM", "Dzt4WGZMDe4TDyVLBSYPW6mGWfJ7gfsYDftIoiZ6Ae4UB6CKC7lIhS4IB7qZDyVLBS4OCMlMscIYhy0TDe8VBNnKg70LA7VVujJPhSZ8CMEKAe4UhfZohSYSgeqVgM0LAGsPoS9FXzF8CMEKAe4UhfZoh
user_pref("D", "Dzt4WGZMDe4TDyVLBSYPW6mGWfJ7gfsYDftIoiZ6Ae4UB6CKC7lIhS4IB7qZDyVLBS4OCMlMscIYhy0TDe8VBNnKg70LA7VVujJPhSZ8CMEKAe4UhfZohSYSgeqVgM0LAGsPoS9FXzF8CMEKAe4UhfZohSYSD7x
user_pref("Omdz4", "Dzt4WGZMDe4TDyVLBSYPW6mGWfJ7gfsYDftIoiZ6Ae4UB6CKC7lIhS4IB7qZDyVLBS4OCMlMscIYhy0TDe8VBNnKg70LA7VVujJPhSZ8CMEKAe4UhfZohSYSgeqVgM0LAGsPoS9FXzF8CMEKAe4UhfZohSY
user_pref("Rq", "Dzt4WGZMDe4TDyVLBSYPW6mGWfJ7gfsYDftIoiZ6Ae4UB6CKC7lIhS4IB7qZDyVLBS4OCMlMscIYhy0TDe8VBNnKg70LA7VVujJPhSZ8CMEKAe4UhfZohSYSgeqVgM0LAGsPoS9FXzF8CMEKAe4UhfZohSYSD7
user_pref("yG88c", "Azm9CdOLv7DGB6lEC6m4Byl8C7wKAe4MBG0HWe4TrS1/Cj8OhVO4B7hFlftQD9hGAeZxnelKrztQgkDGhyxxDw8FjwmVqdVdjVkEByFGjkqqBw4OhdVyCem6m6tkC9hGiztsCePRjkt3CllLANC4CMPHm6t
Emptied folder: C:\Users\Kira\AppData\Roaming\mozilla\firefox\profiles\lkwufyjq.default\minidumps [6 files]



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Mon 01/26/2015 at  0:02:38.24
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 

This will create the fixlist.txt

Yours is located here (Running from C:\Users\[removed]\Desktop\Clean Up\FRST64)


Open notepad. Please copy the contents of the quote box below. To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
Yours is located here (Running from C:\Users\[removed]\Desktop\Clean Up\FRST64)
It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)

[external image: FRSTfix.JPG]

 

start
CloseProcesses:
C:\Users\Kira\AppData\Local\Temp\__tmp_2d00d7ea
C:\ProgramData\2355320829\BITA3DF.tmp
HKU\S-1-5-21-2351201714-3478538817-3848901743-1001\…\Run: [GoogleChromeAutoLaunch_82456ACC06A7292895434703ADA84C9D] => "C:\Users\Kira\AppData\Local\Vosteran\Application\vosteran.exe" –auto-launch-at-startup –profile-directory="Default"
ShortcutTarget: StormWatch.lnk -> C:\Program Files (x86)\StormWatch\StormWatch.exe (No File)
Startup: C:\Users\Kira\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\StormWatchApp.lnk
ShortcutTarget: StormWatchApp.lnk -> C:\Program Files (x86)\StormWatch\StormWatchApp.exe (No File)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKU\S-1-5-21-2351201714-3478538817-3848901743-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://Vosteran.com/…r=531242758&ir=
SearchScopes: HKLM -> DefaultScope {492C118E-8F2A-438F-B5B5-19E2C7BDF8CB} URL = http://Vosteran.com/…r=531242758&ir=
SearchScopes: HKLM -> {492C118E-8F2A-438F-B5B5-19E2C7BDF8CB} URL = http://Vosteran.com/…r=531242758&ir=
SearchScopes: HKU\S-1-5-21-2351201714-3478538817-3848901743-1001 -> DefaultScope {492C118E-8F2A-438F-B5B5-19E2C7BDF8CB} URL = http://Vosteran.com/…r=531242758&ir=
SearchScopes: HKU\S-1-5-21-2351201714-3478538817-3848901743-1001 -> {492C118E-8F2A-438F-B5B5-19E2C7BDF8CB} URL = http://Vosteran.com/…r=531242758&ir=
SearchScopes: HKU\S-1-5-21-2351201714-3478538817-3848901743-1001 -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL =
FF SelectedSearchEngine: Vosteran
FF SearchPlugin: C:\Users\Kira\AppData\Roaming\Mozilla\Firefox\Profiles\lkwufyjq.default\searchplugins\Vosteran.xml
FF Extension: buyfast - C:\Users\Kira\AppData\Roaming\Mozilla\Firefox\Profiles\lkwufyjq.default\Extensions\[removed] [2014-12-23]
FF Extension: rocketdeal - C:\Users\Kira\AppData\Roaming\Mozilla\Firefox\Profiles\lkwufyjq.default\Extensions\[removed] [2014-12-23]
FF Extension: broWWseandusHop - C:\Users\Kira\AppData\Roaming\Mozilla\Firefox\Profiles\lkwufyjq.default\Extensions\[removed] [2015-01-12]
FF Extension: buyanedbroWse - C:\Users\Kira\AppData\Roaming\Mozilla\Firefox\Profiles\lkwufyjq.default\Extensions\[removed] [2015-01-12]
2015-01-11 08:30 - 2015-01-22 16:46 - 00000000 ____D () C:\ProgramData\oFiferaappa
2015-01-11 08:30 - 2015-01-22 16:46 - 00000000 ____D () C:\ProgramData\niceinfrree
C:\Users\Kira\AppData\Local\Temp\BSI.exe
C:\Users\Kira\AppData\Local\Temp\DriverSupport.exe
C:\Users\Kira\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpqkzv3v.dll
C:\Users\Kira\AppData\Local\Temp\i4jdel0.exe
Task: C:\WINDOWS\Tasks\UpdaterEX.job => C:\Users\Kira\AppData\Roaming\UPDATE~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
EmptyTemp:
Hosts:
End


~~~~~~~~~~~~~~~~~~~`

How's your computer now?

I had to leave town unexpectedly and won't have access to the PC for a couple of days.  Just wanted to give you a heads up and to make sure the thread didn't get closed.  Thanks!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI