This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

CleanerPro and PC Mechanic [Solved]

26 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Svinlesha,
 

The computer seems to be running just fine – better in fact, than it has in a while.


That's good to here. :thumbup:

 

=========================

Do you want to keep Pirates and Stormfall?

 

=========================

[external image: bullseye_zpse9eaf36e.gif] FRST Fix Script

Open notepad. Please copy the contents of the code box below. To do this highlight the contents of the box and right click on it. Paste this into the open notepad. Save it on the desktop as fixlist.txt
 

Start
CloseProcesses:
C:\Users\Tim\AppData\Local\Vosteran
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
C:\Program Files (x86)\Cleaner Pro
EmptyTemp:
End

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

Run FRST and press the Fix button just once and wait.
The tool will make a log (Fixlog.txt) please post it to your reply.

=========================

[external image: bullseye_zpse9eaf36e.gif] SystemLook

Please download SystemLook from one of the links below and save it to your Desktop.

Download the version suitable to your computer.

  • 32 bit System:
    • Link 1 - 32 bit
    • Link 2 - 32 bit
  • 64 bit System:
    • Link 1 - 64 bit
    • Link 2 - 64 bit
  • Right click SystemLook.exe and select "Run as Administrator" to run it.
  • Copy the content of the following code-box into the main text-field:
    :folderfind
    *GoodGameEmpire*
    
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.

Note: The log can also be found on your Desktop entitled SystemLook.txt

=========================

In your next post please provide the following:

  • Fixlog.txt
  • SystemLook.txt

Hi OCD!!!

 

We would like to remove Pirates and Stormfall, please.

 

Fixlog text:

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 05-02-2015
Ran by [removed] at 2015-02-05 20:09:32 Run:4
Running from C:\Users\[removed]\Desktop
[removed]
Boot Mode: Normal
==============================================
 
Content of fixlist:
*****************
Start
CloseProcesses:
C:\Users\Tim\AppData\Local\Vosteran
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
C:\Program Files (x86)\Cleaner Pro
EmptyTemp:
End
*****************
 
Processes closed successfully.
"C:\Users\Tim\AppData\Local\Vosteran" => File/Directory not found.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
"C:\Program Files (x86)\Cleaner Pro" => File/Directory not found.
EmptyTemp: => Removed 61.9 MB temporary data.
 
 
The system needed a reboot. 
 
==== End of Fixlog 20:09:42 ====
 
Systemlook Text:
 
SystemLook 30.07.11 by jpshortstuff
Log created at 20:15 on 05/02/2015 by Tim
Administrator - Elevation successful
 
========== folderfind ==========
 
Searching for "*GoodGameEmpire*"
C:\AdwCleaner\Quarantine\C\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GoodGameEmpire d—— [11:21 28/01/2015]
C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GoodGameEmpire d—— [16:36 24/01/2015]
 
-= EOF =-
 
By the way, my son and I will be away for the weekend and won't be able to reply until Sonday at the earliest, and probably Monday.  Just so ya know.
 
Talk to you again soon!

 

Hi Svinlesha,
 

By the way, my son and I will be away for the weekend and won't be able to reply until Sonday at the earliest, and probably Monday.


Thank you for letting me know. I hope you guys have/had a nice weekend.

=========================

[external image: bullseye_zpse9eaf36e.gif] FRST Fix Script

Open notepad. Please copy the contents of the code box below. To do this highlight the contents of the box and right click on it. Paste this into the open notepad. Save it on the desktop as fixlist.txt
 
Start
CloseProcesses:
2015-01-24 17:36 - 2015-01-24 17:36 - 00003602 _____ () C:\Windows\System32\Tasks\Pirates WW1
2015-01-24 17:36 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Pirates946
2015-01-24 17:36 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pirates
2015-01-24 17:35 - 2015-01-29 17:23 - 00000000 ____D () C:\Users\Tim\AppData\Local\Pirates
Task: {0954B156-7016-4593-9693-815C917DFE34} - System32\Tasks\Pirates WW1 => Chrome.exe –kiosk http://plarium.com/p…blisherID=0_1_2
2015-01-24 17:34 - 2015-01-29 17:25 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\StormFall
2015-01-24 17:34 - 2015-01-24 17:34 - 00003664 _____ () C:\Windows\System32\Tasks\StormFall TW1
2015-01-24 17:34 - 2015-01-24 17:34 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StormFall
2015-01-24 17:34 - 2015-01-24 17:34 - 00000000 ____D () C:\Users\Tim\AppData\Local\StormFall
Task: {A575C369-FF15-421C-88C4-9F5D2FDA273C} - System32\Tasks\StormFall TW1 => Chrome.exe –app=http://plarium.com/p…blisherID=1_1_2 –app-window-size=1440,900 
C:\Program Files (x86)\PC Speed Up
2015-01-24 17:36 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\GGEmpire441
2015-01-24 17:36 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Local\GGEmpire
C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GoodGameEmpire
EmptyTemp:
End
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

Run FRST and press the Fix button just once and wait.
The tool will make a log (Fixlog.txt) please post it to your reply.

=========================

[external image: bullseye_zpse9eaf36e.gif] Reboot & Test

In your next post please provide the following:
  • Fixlog.txt
  • How is the computer running?

Hey OCD!

 

Here's the fixlog text:

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 08-02-2015
Ran by [removed] at 2015-02-09 18:54:17 Run:5
Running from C:\Users\[removed]\Desktop
[removed]
Boot Mode: Normal
==============================================
 
Content of fixlist:
*****************
Start
CloseProcesses:
2015-01-24 17:36 - 2015-01-24 17:36 - 00003602 _____ () C:\Windows\System32\Tasks\Pirates WW1
2015-01-24 17:36 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Pirates946
2015-01-24 17:36 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pirates
2015-01-24 17:35 - 2015-01-29 17:23 - 00000000 ____D () C:\Users\Tim\AppData\Local\Pirates
Task: {0954B156-7016-4593-9693-815C917DFE34} - System32\Tasks\Pirates WW1 => Chrome.exe –kiosk http://plarium.com/p…blisherID=0_1_2
2015-01-24 17:34 - 2015-01-29 17:25 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\StormFall
2015-01-24 17:34 - 2015-01-24 17:34 - 00003664 _____ () C:\Windows\System32\Tasks\StormFall TW1
2015-01-24 17:34 - 2015-01-24 17:34 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StormFall
2015-01-24 17:34 - 2015-01-24 17:34 - 00000000 ____D () C:\Users\Tim\AppData\Local\StormFall
Task: {A575C369-FF15-421C-88C4-9F5D2FDA273C} - System32\Tasks\StormFall TW1 => Chrome.exe –app=http://plarium.com/p…blisherID=1_1_2 –app-window-size=1440,900 
C:\Program Files (x86)\PC Speed Up
2015-01-24 17:36 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\GGEmpire441
2015-01-24 17:36 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Local\GGEmpire
C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GoodGameEmpire
EmptyTemp:
End
*****************
 
Processes closed successfully.
"C:\Windows\System32\Tasks\Pirates WW1" => File/Directory not found.
C:\Users\Tim\AppData\Roaming\Pirates946 => Moved successfully.
C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pirates => Moved successfully.
C:\Users\Tim\AppData\Local\Pirates => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0954B156-7016-4593-9693-815C917DFE34} => Key not found. 
C:\Windows\System32\Tasks\Pirates WW1 not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Pirates WW1" => Key deleted successfully.
C:\Users\Tim\AppData\Roaming\StormFall => Moved successfully.
"C:\Windows\System32\Tasks\StormFall TW1" => File/Directory not found.
C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StormFall => Moved successfully.
C:\Users\Tim\AppData\Local\StormFall => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A575C369-FF15-421C-88C4-9F5D2FDA273C} => Key not found. 
C:\Windows\System32\Tasks\StormFall TW1 not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\StormFall TW1" => Key deleted successfully.
"C:\Program Files (x86)\PC Speed Up" => File/Directory not found.
C:\Users\Tim\AppData\Roaming\GGEmpire441 => Moved successfully.
C:\Users\Tim\AppData\Local\GGEmpire => Moved successfully.
C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GoodGameEmpire => Moved successfully.
EmptyTemp: => Removed 16.6 MB temporary data.
 
 
The system needed a reboot. 
 
==== End of Fixlog 18:54:27 ====
 
The computer's running great!
 
 
Are we getting close?
Hi Svinlesha,
 

Are we getting close?


I think we are just about done. A few scans just to be sure, then some clean-up and we'll get you on your way.

[external image: bullseye_zpse9eaf36e.gif] Security Check

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Right click SecurityCheck.exe, select "Run as Administrator" and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
=========================

[external image: bullseye_zpse9eaf36e.gif] Re-run Farbar Recovery Scan Tool it should be on your desktop.
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
=========================

In your next post please provide the following:
  • checkup.txt
  • new FRST
  • Any remaining issues?

hello ocd 

 

 

here is check up 

 Results of screen317's Security Check version 0.99.96  
 Windows 7 Service Pack 1 x64 (UAC is enabled)  
 Internet Explorer 11  
``````````````Antivirus/Firewall Check:`````````````` 
avast! Antivirus   
 Antivirus up to date!   
`````````Anti-malware/Other Utilities Check:````````` 
 Cleaner Pro    
 Java 7 Update 67  
 Java version 32-bit out of Date! 
  Java 64-bit 8 Update 31  
  Adobe Flash Player 11.9.900.117 Flash Player out of Date!  
 Mozilla Firefox (35.0.1) 
 Google Chrome (40.0.2214.91) 
 Google Chrome (40.0.2214.93) 
````````Process Check: objlist.exe by Laurent````````  
 Malwarebytes Anti-Malware mbamservice.exe  
 Malwarebytes Anti-Malware mbam.exe  
 Malwarebytes Anti-Malware mbamscheduler.exe   
 AVAST Software Avast AvastSvc.exe  
 AVAST Software Avast avastui.exe  
 AVAST Software Avast ng vbox\AvastVBoxSVC.exe 
 AVAST Software Avast ng ngservice.exe 
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive C: 0 
````````````````````End of Log`````````````````````` 
 
here is FRST
 
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-02-2015
Ran by [removed] (administrator) on INET on 09-02-2015 21:04:33
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Svenska (Sverige)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Hi-Rez Studios) C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\ng\ngservice.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [Nvtmru] => "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
HKLM\…\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2352072 2014-05-30] (NVIDIA Corporation)
HKLM\…\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\…\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5227112 2015-01-28] (AVAST Software)
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\Run: [GoogleChromeAutoLaunch_77DB27ED30D96DC6FB2B344658AE2828] => "C:\Users\Tim\AppData\Local\Vosteran\Application\vosteran.exe" –no-startup-window –auto-launch-at-startup –profile-directory="Default"
AppInit_DLLs-x32: C:/PROGRA~3/{C6092~1/190~1.1/rati.dll => "C:/PROGRA~3/{C6092~1/190~1.1/rati.dll" File Not Found
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKU\S-1-5-21-3767168050-546541148-904736753-1000\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.inet.se
HKU\S-1-5-21-3767168050-546541148-904736753-1000\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.inet.se
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
 
FireFox:
========
FF ProfilePath: C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\40hu7roo.default-1422549441719
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKU\S-1-5-21-3767168050-546541148-904736753-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Tim\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-3767168050-546541148-904736753-1000: thehappycloud.com/HappyCloudPlugin -> C:\ProgramData\HappyCloud\Application\npHappyCloudPlugin.dll (The Happy Cloud)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\allaannonser-sv-SE.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\prisjakt-sv-SE.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\tyda-sv-SE.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\wikipedia-sv-SE.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-sv-SE.xml
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-01-27]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-10-22]
 
Chrome: 
=======
CHR Profile: C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Dokument) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-08-08]
CHR Extension: (Google Drive) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-08-08]
CHR Extension: (YouTube) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-08-08]
CHR Extension: (Battlefield Heroes) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\cehdakiococlfmjcbebbkjkfjhbieknh [2015-01-09]
CHR Extension: (Sök på Google) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-08-08]
CHR Extension: (Avast Online Security) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-08-08]
CHR Extension: (Google Wallet) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-08-08]
CHR Extension: (Gmail) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-08-08]
CHR HKLM-x32\…\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-12-04]
 
==================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-12-04] (AVAST Software)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4012248 2014-12-04] (Avast Software)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
U2 HiPatchService; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [9216 2014-02-28] (Hi-Rez Studios) [File not signed]
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1631008 2014-05-30] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [21055432 2014-05-30] (NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2015-01-09] ()
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-12-04] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [83280 2014-12-04] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-12-04] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-12-04] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1050432 2014-12-04] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436624 2014-12-04] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [116728 2014-12-04] (AVAST Software)
U5 ewusbnet; C:\Windows\System32\Drivers\ewusbnet.sys [243200 2009-10-21] (Huawei Technologies Co., Ltd.)
S3 hwusbdev; C:\Windows\System32\DRIVERS\ewusbdev.sys [114304 2009-10-12] (Huawei Technologies Co., Ltd.)
S3 IAMTVE; C:\Windows\system32\drivers\IAMTVE.sys [43416 2010-11-30] (Intel Corporation)
S3 IAMTXPE; C:\Windows\system32\drivers\IAMTXPE.sys [51096 2010-11-30] (Intel Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-02-09] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-11-21] (Malwarebytes Corporation)
S3 MTsensor; C:\Windows\system32\drivers\ASACPI.sys [15416 2009-05-14] ()
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20256 2014-05-30] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation)
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [271752 2014-12-04] (Avast Software)
S3 aswVmm; \??\C:\Users\Tim\AppData\Local\Temp\aswVmm.sys [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 X6va029; \??\C:\Windows\SysWOW64\Drivers\X6va029 [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
==================== One Month Created Files and Folders ========
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-02-09 21:04 - 2015-02-09 21:04 - 00014069 _____ () C:\Users\Tim\Desktop\FRST.txt
2015-02-09 20:49 - 2015-02-09 20:49 - 00852594 _____ () C:\Users\Tim\Desktop\SecurityCheck.exe
2015-02-09 20:48 - 2015-02-09 20:49 - 00852594 _____ () C:\Users\Tim\Downloads\SecurityCheck.exe
2015-02-09 19:00 - 2015-02-09 19:00 - 00000197 _____ () C:\Windows\system32\2015-02-09-18-00-09.003-AvastVBoxSVC.exe-3296.log
2015-02-09 18:54 - 2015-02-09 18:54 - 00000000 ____D () C:\Users\Tim\Desktop\FRST-OlderVersion
2015-02-09 18:51 - 2015-02-09 18:51 - 00000197 _____ () C:\Windows\system32\2015-02-09-17-51-27.042-AvastVBoxSVC.exe-4128.log
2015-02-05 20:14 - 2015-02-05 20:13 - 00165376 _____ () C:\Users\Tim\Desktop\SystemLook_x64.exe
2015-02-05 20:13 - 2015-02-05 20:13 - 00165376 _____ () C:\Users\Tim\Downloads\SystemLook_x64.exe
2015-02-05 20:12 - 2015-02-05 20:12 - 00000197 _____ () C:\Windows\system32\2015-02-05-19-12-22.006-AvastVBoxSVC.exe-3088.log
2015-02-05 20:01 - 2015-02-05 20:01 - 00000197 _____ () C:\Windows\system32\2015-02-05-19-01-15.073-AvastVBoxSVC.exe-1400.log
2015-02-03 17:20 - 2015-02-03 17:21 - 00000197 _____ () C:\Windows\system32\2015-02-03-16-20-26.044-AvastVBoxSVC.exe-3308.log
2015-02-01 15:57 - 2015-02-01 15:57 - 00000000 ____D () C:\Program Files (x86)\ESET
2015-02-01 15:54 - 2015-02-01 15:54 - 00000197 _____ () C:\Windows\system32\2015-02-01-14-54-28.088-AvastVBoxSVC.exe-3032.log
2015-02-01 15:38 - 2015-02-09 21:02 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-02-01 15:38 - 2015-02-01 15:38 - 00001104 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-02-01 15:38 - 2015-02-01 15:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-02-01 15:38 - 2015-02-01 15:38 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-02-01 15:38 - 2015-02-01 15:38 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-02-01 15:38 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-02-01 15:38 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-02-01 15:38 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-02-01 15:37 - 2015-02-01 15:37 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Tim\Desktop\mbam-setup-2.0.4.1028.exe
2015-02-01 15:36 - 2015-02-01 15:37 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Tim\Downloads\mbam-setup-2.0.4.1028.exe
2015-02-01 15:36 - 2015-02-01 15:36 - 00000197 _____ () C:\Windows\system32\2015-02-01-14-36-40.026-AvastVBoxSVC.exe-3116.log
2015-02-01 15:24 - 2015-02-01 15:25 - 00000197 _____ () C:\Windows\system32\2015-02-01-14-24-43.096-AvastVBoxSVC.exe-3052.log
2015-02-01 14:47 - 2015-02-01 14:48 - 00000197 _____ () C:\Windows\system32\2015-02-01-13-47-33.049-AvastVBoxSVC.exe-3308.log
2015-01-31 11:30 - 2015-01-31 11:30 - 00001039 _____ () C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
2015-01-31 11:30 - 2015-01-31 11:30 - 00000000 ____D () C:\Users\Tim\AppData\Local\VS Revo Group
2015-01-31 11:30 - 2015-01-31 11:30 - 00000000 ____D () C:\ProgramData\VS Revo Group
2015-01-31 11:30 - 2015-01-31 11:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro
2015-01-31 11:30 - 2015-01-31 11:30 - 00000000 ____D () C:\Program Files\VS Revo Group
2015-01-31 11:30 - 2009-12-30 10:21 - 00031800 _____ (VS Revo Group) C:\Windows\system32\Drivers\revoflt.sys
2015-01-31 11:29 - 2015-01-31 11:28 - 10801480 _____ (VS Revo Group ) C:\Users\Tim\Desktop\RevoUninProSetup.exe
2015-01-31 11:28 - 2015-01-31 11:28 - 10801480 _____ (VS Revo Group ) C:\Users\Tim\Downloads\RevoUninProSetup.exe
2015-01-31 11:23 - 2015-01-31 11:24 - 00000197 _____ () C:\Windows\system32\2015-01-31-10-23-26.018-AvastVBoxSVC.exe-3036.log
2015-01-29 18:25 - 2015-01-29 18:26 - 00000197 _____ () C:\Windows\system32\2015-01-29-17-25-57.087-AvastVBoxSVC.exe-3236.log
2015-01-29 18:17 - 2015-01-29 18:17 - 00000197 _____ () C:\Windows\system32\2015-01-29-17-17-03.025-AvastVBoxSVC.exe-2268.log
2015-01-29 17:37 - 2015-01-29 17:37 - 00000000 ____D () C:\Users\Tim\Desktop\Gammal Firefox-data
2015-01-29 17:10 - 2015-01-29 17:10 - 00000197 _____ () C:\Windows\system32\2015-01-29-16-10-08.084-AvastVBoxSVC.exe-2996.log
2015-01-28 12:48 - 2015-01-28 12:48 - 00000197 _____ () C:\Windows\system32\2015-01-28-11-48-37.047-AvastVBoxSVC.exe-3220.log
2015-01-28 12:32 - 2015-01-28 12:32 - 00000000 ____D () C:\Windows\ERUNT
2015-01-28 12:30 - 2015-01-28 12:30 - 01707939 _____ (Thisisu) C:\Users\Tim\Desktop\JRT.exe
2015-01-28 12:26 - 2015-01-28 12:26 - 00000197 _____ () C:\Windows\system32\2015-01-28-11-26-05.093-AvastVBoxSVC.exe-3520.log
2015-01-28 12:08 - 2015-02-01 15:33 - 00000000 ____D () C:\AdwCleaner
2015-01-28 12:06 - 2015-01-28 12:06 - 02194432 _____ () C:\Users\Tim\Desktop\AdwCleaner.exe
2015-01-28 12:02 - 2015-01-28 12:03 - 00000197 _____ () C:\Windows\system32\2015-01-28-11-02-45.051-AvastVBoxSVC.exe-1584.log
2015-01-27 18:40 - 2015-01-27 18:40 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-01-27 18:04 - 2015-02-09 21:04 - 00000000 ____D () C:\FRST
2015-01-27 18:02 - 2015-02-09 18:54 - 02132992 _____ (Farbar) C:\Users\Tim\Desktop\FRST64.exe
2015-01-27 17:37 - 2015-01-27 17:37 - 05198336 _____ (AVAST Software) C:\Users\Tim\Desktop\aswMBR.exe
2015-01-27 17:28 - 2015-01-27 17:28 - 00000197 _____ () C:\Windows\system32\2015-01-27-16-28-06.013-AvastVBoxSVC.exe-2452.log
2015-01-25 17:05 - 2015-01-25 17:05 - 00000197 _____ () C:\Windows\system32\2015-01-25-16-05-46.072-AvastVBoxSVC.exe-2384.log
2015-01-25 17:00 - 2015-01-25 17:00 - 00000197 _____ () C:\Windows\system32\2015-01-25-16-00-29.011-AvastVBoxSVC.exe-1428.log
2015-01-25 16:18 - 2015-01-25 16:18 - 00000197 _____ () C:\Windows\system32\2015-01-25-15-18-00.026-AvastVBoxSVC.exe-2732.log
2015-01-25 09:39 - 2015-01-25 09:39 - 00000197 _____ () C:\Windows\system32\2015-01-25-08-39-04.097-AvastVBoxSVC.exe-3736.log
2015-01-25 09:36 - 2015-01-28 12:01 - 00000008 __RSH () C:\ProgramData\ntuser.pol
2015-01-24 18:35 - 2015-01-25 17:35 - 00000057 _____ () C:\Users\Tim\AppData\Roaming\WB.CFG
2015-01-24 17:57 - 2015-01-24 17:57 - 00001238 _____ () C:\Users\Public\Desktop\World of Warcraft.lnk
2015-01-24 17:57 - 2015-01-24 17:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Warcraft
2015-01-24 17:55 - 2015-01-24 21:47 - 00000000 ____D () C:\Program Files (x86)\World of Warcraft
2015-01-24 17:51 - 2015-01-24 17:51 - 02942368 _____ (Blizzard Entertainment) C:\Users\Tim\Downloads\World-of-Warcraft-Setup-enGB.exe
2015-01-24 17:38 - 2015-01-25 00:06 - 00000000 ____D () C:\Users\Tim\AppData\Local\Battle.net
2015-01-24 17:38 - 2015-01-24 17:55 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Battle.net
2015-01-24 17:38 - 2015-01-24 17:38 - 00000000 ____D () C:\Users\Tim\AppData\Local\Blizzard Entertainment
2015-01-24 17:37 - 2015-01-24 17:38 - 00000000 ____D () C:\Program Files (x86)\Battle.net
2015-01-24 17:37 - 2015-01-24 17:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net
2015-01-24 17:37 - 2015-01-24 17:37 - 00000000 ____D () C:\ProgramData\Blizzard Entertainment
2015-01-24 17:36 - 2015-01-28 12:21 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WorldofTanks
2015-01-24 17:36 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\WorldofTanks
2015-01-24 17:36 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Local\WorldofTanks
2015-01-24 17:36 - 2015-01-24 17:36 - 00000000 ____D () C:\ProgramData\Battle.net
2015-01-24 17:35 - 2015-01-24 17:35 - 123231216 _____ (Blizzard Entertainment) C:\Users\Tim\Downloads\WorldOfWarCraftSetup.exe
2015-01-24 13:47 - 2015-01-24 13:48 - 00000197 _____ () C:\Windows\system32\2015-01-24-12-47-40.045-AvastVBoxSVC.exe-3452.log
2015-01-24 08:41 - 2015-01-24 08:41 - 00000197 _____ () C:\Windows\system32\2015-01-24-07-41-44.020-AvastVBoxSVC.exe-4040.log
2015-01-23 21:40 - 2015-01-23 21:40 - 00000197 _____ () C:\Windows\system32\2015-01-23-20-40-03.016-AvastVBoxSVC.exe-4508.log
2015-01-23 16:57 - 2015-01-23 16:58 - 00000197 _____ () C:\Windows\system32\2015-01-23-15-57-47.063-AvastVBoxSVC.exe-3636.log
2015-01-23 07:35 - 2015-01-23 07:36 - 00000197 _____ () C:\Windows\system32\2015-01-23-06-35-43.037-AvastVBoxSVC.exe-3552.log
2015-01-22 15:05 - 2015-01-22 15:06 - 00000197 _____ () C:\Windows\system32\2015-01-22-14-05-49.099-AvastVBoxSVC.exe-3720.log
2015-01-22 07:32 - 2015-01-22 07:32 - 00000197 _____ () C:\Windows\system32\2015-01-22-06-32-43.034-AvastVBoxSVC.exe-3040.log
2015-01-21 19:31 - 2015-01-21 19:32 - 00000000 ____D () C:\Users\Tim\Downloads\Slender_v0_9_7 (1)
2015-01-21 19:31 - 2015-01-21 19:31 - 00000000 ____D () C:\Users\Tim\Desktop\Slender v0.9.7
2015-01-21 19:23 - 2015-01-21 19:30 - 65812970 _____ () C:\Users\Tim\Downloads\Slender_v0_9_7 (1).zip
2015-01-21 19:08 - 2015-01-21 19:09 - 00000197 _____ () C:\Windows\system32\2015-01-21-18-08-51.048-AvastVBoxSVC.exe-3480.log
2015-01-21 19:01 - 2015-01-21 19:01 - 65812970 _____ () C:\Users\Tim\Downloads\Slender_v0_9_7.zip
2015-01-21 14:27 - 2015-01-21 14:27 - 00000197 _____ () C:\Windows\system32\2015-01-21-13-27-01.087-AvastVBoxSVC.exe-2708.log
2015-01-21 06:17 - 2015-01-21 06:18 - 00000197 _____ () C:\Windows\system32\2015-01-21-05-17-40.013-AvastVBoxSVC.exe-3284.log
2015-01-21 05:32 - 2015-01-21 05:32 - 00000197 _____ () C:\Windows\system32\2015-01-21-04-32-11.025-AvastVBoxSVC.exe-2500.log
2015-01-20 15:42 - 2015-01-20 15:43 - 00000197 _____ () C:\Windows\system32\2015-01-20-14-42-54.082-AvastVBoxSVC.exe-3380.log
2015-01-20 07:21 - 2015-01-20 07:21 - 00000197 _____ () C:\Windows\system32\2015-01-20-06-21-05.091-AvastVBoxSVC.exe-3240.log
2015-01-19 13:43 - 2015-01-19 13:44 - 00000197 _____ () C:\Windows\system32\2015-01-19-12-43-55.039-AvastVBoxSVC.exe-3832.log
2015-01-19 07:27 - 2015-01-19 07:27 - 00000197 _____ () C:\Windows\system32\2015-01-19-06-27-12.003-AvastVBoxSVC.exe-3452.log
2015-01-18 09:31 - 2015-01-18 09:31 - 00000197 _____ () C:\Windows\system32\2015-01-18-08-31-40.030-AvastVBoxSVC.exe-3352.log
2015-01-17 09:13 - 2015-01-17 09:13 - 00000197 _____ () C:\Windows\system32\2015-01-17-08-13-20.071-AvastVBoxSVC.exe-3536.log
2015-01-16 18:40 - 2015-01-16 18:40 - 00000000 __SHD () C:\Users\Tim\AppData\Local\EmieUserList
2015-01-16 18:40 - 2015-01-16 18:40 - 00000000 __SHD () C:\Users\Tim\AppData\Local\EmieSiteList
2015-01-16 18:40 - 2015-01-16 18:40 - 00000000 __SHD () C:\Users\Tim\AppData\Local\EmieBrowserModeList
2015-01-16 18:34 - 2015-01-16 18:34 - 00000222 _____ () C:\Users\Tim\Desktop\MicroVolts Surge.url
2015-01-16 17:58 - 2015-01-16 17:58 - 00000197 _____ () C:\Windows\system32\2015-01-16-16-58-01.044-AvastVBoxSVC.exe-3048.log
2015-01-16 11:45 - 2015-01-16 11:45 - 00000197 _____ () C:\Windows\system32\2015-01-16-10-45-04.007-AvastVBoxSVC.exe-3160.log
2015-01-16 07:57 - 2015-01-16 07:58 - 00000197 _____ () C:\Windows\system32\2015-01-16-06-57-44.044-AvastVBoxSVC.exe-3596.log
2015-01-15 15:19 - 2015-01-15 15:19 - 00000197 _____ () C:\Windows\system32\2015-01-15-14-19-09.002-AvastVBoxSVC.exe-2148.log
2015-01-15 06:46 - 2015-01-15 06:46 - 00000197 _____ () C:\Windows\system32\2015-01-15-05-46-18.056-AvastVBoxSVC.exe-3440.log
2015-01-15 06:42 - 2015-01-15 06:42 - 00000197 _____ () C:\Windows\system32\2015-01-15-05-42-40.094-AvastVBoxSVC.exe-2848.log
2015-01-14 16:29 - 2015-01-14 16:29 - 00000197 _____ () C:\Windows\system32\2015-01-14-15-29-36.005-AvastVBoxSVC.exe-3388.log
2015-01-14 14:43 - 2015-01-14 14:44 - 00000197 _____ () C:\Windows\system32\2015-01-14-13-43-43.031-AvastVBoxSVC.exe-2500.log
2015-01-14 07:51 - 2014-12-19 04:06 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-01-14 07:51 - 2014-12-19 02:46 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-01-14 07:51 - 2014-12-12 06:35 - 05553592 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-01-14 07:51 - 2014-12-12 06:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-01-14 07:51 - 2014-12-12 06:31 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-01-14 07:51 - 2014-12-12 06:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-01-14 07:51 - 2014-12-12 06:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-01-14 07:51 - 2014-12-12 06:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-01-14 07:51 - 2014-12-12 06:07 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-01-14 07:51 - 2014-12-11 18:47 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-01-14 07:51 - 2014-12-06 05:17 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-01-14 07:51 - 2014-12-06 04:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2015-01-14 07:51 - 2014-12-06 04:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2015-01-14 07:51 - 2012-10-03 18:44 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2015-01-14 07:51 - 2012-10-03 18:44 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
2015-01-14 07:48 - 2015-01-14 07:48 - 00000197 _____ () C:\Windows\system32\2015-01-14-06-48-14.075-AvastVBoxSVC.exe-1388.log
2015-01-13 14:37 - 2015-01-13 14:38 - 00000197 _____ () C:\Windows\system32\2015-01-13-13-37-39.065-AvastVBoxSVC.exe-3848.log
2015-01-13 07:54 - 2015-01-13 07:55 - 00000197 _____ () C:\Windows\system32\2015-01-13-06-54-26.047-AvastVBoxSVC.exe-2908.log
2015-01-12 13:45 - 2015-01-12 13:45 - 00000197 _____ () C:\Windows\system32\2015-01-12-12-45-02.016-AvastVBoxSVC.exe-3228.log
2015-01-12 07:55 - 2015-01-12 07:55 - 00000197 _____ () C:\Windows\system32\2015-01-12-06-55-17.056-AvastVBoxSVC.exe-2700.log
2015-01-11 10:10 - 2015-01-11 10:10 - 00000197 _____ () C:\Windows\system32\2015-01-11-09-10-12.019-AvastVBoxSVC.exe-2992.log
2015-01-10 17:56 - 2015-01-10 17:56 - 08229276 _____ () C:\Users\Tim\Downloads\1964_11.rar
2015-01-10 17:54 - 2015-01-10 17:54 - 00065552 _____ () C:\Users\Tim\Downloads\Zelda_1.zip
2015-01-10 17:53 - 2015-01-10 17:53 - 03029593 _____ () C:\Users\Tim\Downloads\fceux-2.2.2-win32.zip
2015-01-10 17:14 - 2015-01-10 17:14 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Unity
2015-01-10 15:36 - 2015-01-10 15:36 - 00000197 _____ () C:\Windows\system32\2015-01-10-14-36-08.039-AvastVBoxSVC.exe-3096.log
2015-01-10 09:54 - 2015-01-10 09:55 - 00000197 _____ () C:\Windows\system32\2015-01-10-08-54-54.090-AvastVBoxSVC.exe-2936.log
 
==================== One Month Modified Files and Folders =======
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-02-09 20:58 - 2014-08-08 10:44 - 00002181 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-02-09 20:58 - 2014-08-08 10:43 - 00000994 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-02-09 20:52 - 2014-08-08 10:43 - 00000990 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-02-09 20:47 - 2014-08-08 10:43 - 00003990 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-02-09 20:47 - 2014-08-08 10:43 - 00003738 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-02-09 20:46 - 2013-09-30 14:37 - 01122548 _____ () C:\Windows\WindowsUpdate.log
2015-02-09 19:04 - 2010-11-21 12:38 - 00670622 _____ () C:\Windows\system32\perfh01D.dat
2015-02-09 19:04 - 2010-11-21 12:38 - 00146498 _____ () C:\Windows\system32\perfc01D.dat
2015-02-09 19:04 - 2009-07-14 06:13 - 01602714 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-02-09 19:04 - 2009-07-14 05:45 - 00021888 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-02-09 19:04 - 2009-07-14 05:45 - 00021888 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-02-09 18:57 - 2009-07-14 05:51 - 00168513 _____ () C:\Windows\setupact.log
2015-02-09 18:56 - 2013-09-30 14:53 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-02-09 18:56 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-02-09 18:51 - 2013-11-13 07:41 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2015-02-03 17:17 - 2010-11-21 04:47 - 00103850 _____ () C:\Windows\PFRO.log
2015-02-01 17:50 - 2014-01-11 11:44 - 00000000 ____D () C:\Users\Tim\AppData\Local\PMB Files
2015-02-01 17:50 - 2014-01-11 11:44 - 00000000 ____D () C:\ProgramData\PMB Files
2015-01-28 12:00 - 2013-10-22 09:18 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-01-28 11:58 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\GroupPolicy
2015-01-27 17:28 - 2009-07-14 03:34 - 00000505 _____ () C:\Windows\win.ini
2015-01-25 16:17 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\tracing
2015-01-24 17:35 - 2013-10-22 09:18 - 00001149 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-01-24 17:17 - 2013-10-22 09:51 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\.minecraft
2015-01-24 15:45 - 2013-10-23 08:34 - 00000000 ____D () C:\Program Files (x86)\Steam
2015-01-16 19:34 - 2014-05-29 07:50 - 00000000 ____D () C:\Users\Tim\AppData\Local\Microsoft Games
2015-01-16 18:34 - 2013-10-23 09:01 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2015-01-14 08:28 - 2013-09-30 15:30 - 00000000 ____D () C:\Windows\system32\MRT
2015-01-14 08:24 - 2013-09-30 15:30 - 113365784 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-01-10 12:43 - 2015-01-09 21:01 - 00282296 _____ () C:\Windows\SysWOW64\PnkBstrB.xtr
2015-01-10 12:43 - 2015-01-09 19:25 - 00282296 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2015-01-10 10:12 - 2015-01-09 19:25 - 00282296 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0
 
==================== Files in the root of some directories =======
 
2015-01-24 18:35 - 2015-01-25 17:35 - 0000057 _____ () C:\Users\Tim\AppData\Roaming\WB.CFG
2013-11-28 18:17 - 2013-11-28 18:17 - 0000091 _____ () C:\Users\Tim\AppData\Local\fusioncache.dat
2014-10-04 13:14 - 2014-10-04 13:14 - 0000000 _____ () C:\Users\Tim\AppData\Local\{26F9D811-A740-4CF8-B01D-202083068605}
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-02-09 19:20
 
==================== End Of Log ============================
 
Last(?) remaining issue: while we were doing this a pop up appeared from malewarebytes saying that it had located vosteran, a PUP (potentially unwanted program).
 
Otherwise, the computer runs great now.  
 
 
 

 

Hi Svinlesha,

[external image: bullseye_zpse9eaf36e.gif] Uninstall via Programs and Features

Click Start > Control Panel > Programs and Features. Locate and select the following that are present on the list and click the Remove button:

  • Java 7 Update 67
  • Adobe Flash Player 11.9.900.117

=========================

[external image: bullseye_zpse9eaf36e.gif] Adobe Flash Player:

Go to http://get.adobe.com/flashplayer/?no_ab=1

  • Remove the check mark from the box "Install Google Drive"
  • Click the Download button, and follow the onscreen directions to complete the installation.

Please note, depending on your settings, you may have to temporarily disable your antivirus software for the Adobe Reader update.

=========================



Last(?) remaining issue: while we were doing this a pop up appeared from malewarebytes saying that it had located vosteran, a PUP (potentially unwanted program).

 

Please re-run MBAM, but this time do not remove the found threats. Locate the log and post in your next reply.

=========================

[external image: bullseye_zpse9eaf36e.gif] Re-run SystemLook

  • Right click SystemLook.exe and select "Run as Administrator" to run it.
  • Copy the content of the following code-box into the main text-field:
    :filefind
    *Cleaner Pro*   
    
    :folderfind
    *Cleaner Pro*   
    
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.

Note: The log can also be found on your Desktop entitled SystemLook.txt

=========================

In your next post please provide the following:

  • MBAM.txt
  • SystemLook.txt

Hej OCD!

 

Hope all is well with you and yours.  Here are the requested logs.

 

MBAM:

 

Malwarebytes Anti-Malware
www.malwarebytes.org
 
Scan Date: 2015-02-10
Scan Time: 20:24:43
Logfile: 
Administrator: Yes
 
Version: 2.00.4.1028
Malware Database: v2015.02.10.11
Rootkit Database: v2015.02.03.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
 
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Tim
 
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 326786
Time Elapsed: 7 min, 21 sec
 
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
 
Processes: 0
(No malicious items detected)
 
Modules: 0
(No malicious items detected)
 
Registry Keys: 0
(No malicious items detected)
 
Registry Values: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Folders: 0
(No malicious items detected)
 
Files: 0
(No malicious items detected)
 
Physical Sectors: 0
(No malicious items detected)
 
 
(end)
 
System Look:
 
SystemLook 30.07.11 by jpshortstuff
Log created at 20:15 on 10/02/2015 by Tim
Administrator - Elevation successful
 
========== filefind ==========
 
Searching for "*Cleaner Pro*   "
C:\FRST\Quarantine\C\ProgramData\Microsoft\Windows\Start Menu\Programs\Cleaner Pro\Cleaner Pro.lnk –a—- 988 bytes [16:35 24/01/2015] [16:35 24/01/2015] 4CFA6CA6B1AE103BB71E763BE7B30182
 
========== folderfind ==========
 
Searching for "*Cleaner Pro*   "
C:\AdwCleaner\Quarantine\C\Users\Tim\AppData\Roaming\Cleaner Pro d—— [11:21 28/01/2015]
C:\AdwCleaner\Quarantine\C\Users\Tim\AppData\Roaming\Cleaner Pro\Cleaner Pro 2.5.9 d—— [11:21 28/01/2015]
C:\FRST\Quarantine\C\Program Files (x86)\Cleaner Pro d—— [16:35 24/01/2015]
C:\FRST\Quarantine\C\ProgramData\Microsoft\Windows\Start Menu\Programs\Cleaner Pro d—— [16:35 24/01/2015]
 
-= EOF =-
 
 
Hi Svinlesha,

Your log appears to be clean.

All the Pro Cleaner items are safely located in quarantine folders so they pose no threat.

We have a few items to take care of before we get to the All Clean Speech.

= = = = = = = = = = = = = = = = = = = =

[external image: bullseye_zpse9eaf36e.gif] Remove Disinfection Tools
  • Download Delfix
  • Tick the following boxes:
    • Remove disinfection tools
    • Create registry backup
    • Purge system restore
    [external image: Delfix_zpsbce6c60b.gif]
  • Click Run
  • Any other tools and files found can simply be deleted or uninstall via the Control Panel.
= = = = = = = = = = = = = = = = = = = =


With the above items taken care of let's move on to the All Clean part of the process.

The following procedures are recommendations for helping to keep your system running smoothly. If you are currently satisfied with how your system is running some or all of these may not pertain to you. Implement what you need.

This infection appears to have been cleaned, but I can not give you any absolute guarantees. As a precaution, I would go ahead and change all of your passwords as this is especially important after an infection.

Any of the logs that you created for use in the forums or remaining tools that have not yet been removed can be deleted so they aren't cluttering up your desktop.

Here are some tips to reduce the potential for spyware infection in the future:

Make your Internet Explorer more secure - This can be done by following these simple instructions:
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate windows and frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
Make your Mozilla Firefox more secure - This can be done by adding these add-ons:Use and update an anti-virus software - I can not overemphasize the need for you to use and update your anti-virus application on a regular basis. With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

Free Anti-Virus
  • Avast Free Antivirus
  • Avira Free Antivirus 2013
  • PC Tools AntiVirus Free
  • Ad-Aware Free Antivirus +
Free Firewall
Using a third-party firewall will allow you to give/deny access for applications that want to go online. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a firewall in its default configuration can lower your risk greatly. A tutorial on firewalls can be found here.
  • Online Armor Free
  • Agnitum Outpost Firewall Free
  • Comodo Firewall
= = = = = = = = = = = = = = = = = = = =

Be prepared for CryptoLocker:

Cryptolocker Ransomware: What You Need To Know
CryptoLocker Ransomware Information Guide and FAQ

to help protect your computer in the future I recommend that you get the following free program:

CryptoPrevent install this program to lock down and prevent crypto-ransomeware

[external image: CryptoPrevent_zps7ddc3ebd.jpg]

= = = = = = = = = = = = = = = = = = = =

COMPUTER SECURITY - a short guide to staying safer online

= = = = = = = = = = = = = = = = = = = =

WOT Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites - green to go, yellow for caution and red to stop, helping you avoid the dangerous sites. WOT has an addon available for both Firefox and IE.
  • Green should be good to go
  • Yellow for caution
  • Red to stop
= = = = = = = = = = = = = = = = = = = =

P2P may be a great way to get lots of stuffs, but it is a great way to get infected as well. There's no way to tell if the file being shared is infected. Worse still, some worms spread via P2P networks, infecting you as well.

Please read these short reports on the dangers of peer-2-peer programs and file sharing.
  • FBI Cyber Education Letter
  • USAToday
  • infoworld
= = = = = = = = = = = = = = = = = = = =

Make sure you keep your Windows OS current.
  • Windows XP:
    Microsoft will no longer offer support for Windows XP beginning on April 8, 2014
    If you are running Windows XP, please take the time to read the information provided at these links.
  • Windows Vista/7 users can open the Start menu > All Programs > Windows Update > Check for Updates (in left hand task pane) to update these systems.
  • Window 8 Open Windows Update by swiping in from the right edge of the screen (or, if you're using a mouse, pointing to the lower-right corner of the screen and moving the mouse pointer up), tapping or clicking Settings, tapping or clicking Change PC settings, and then tapping or clicking Update and recovery.
Without these you are leaving the back door open.

= = = = = = = = = = = = = = = = = = = =

Consider a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers. For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.

= = = = = = = = = = = = = = = = = = = =

Finally, I strongly recommend that you read TonyKlein's good advice So how did I get infected in the first place?

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.

hello ocd thank you so much! the computer is running really good and me and my dad just want to say thank you so much :) 

 

Isaac

 

 

 

 

Hej OCD,

 

You've been fantastic, thanks again for all the help and support.  I'll be sure to drop some cash into the tip jar.

 

Take care!

 

Tim

Hello Isaac,

You are quite welcome. You and your Dad have been great through the entire process. Just remember going forward to be careful what you download and install on your computer. When in doubt, ask your Dad. :)

@Tim,
I'm glad I was able to help, and thank you for the kind words. I think by having Isaac follow along through the process will serve him well going forward.

If you have no other questions, I will go ahead and close the topic.

Thank you (Isaac & Tim), you have been a pleasure to work with. :thumbup:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI