This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Malware keeps coming back [Solved]

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello All!

 

I am a former member of the Community Feedback Forum, If you are familiar with them. I haven't had any probs for

a few years now but recently one has come up.

I got a virus from somewhere & thought I got rid of It using Malware Bytes & Avira but yesterday it came back again.

The symptoms are as follows. Many of my jpg's were corrupted as It added an extension to some files after the jpg.

The extension It added was -.gjhsaqj. Also I find some of my zip files have locks on them now which wasn't that way before.

Also many files have added docs in them all with the description underneath- HELP_DESCRIPT. Some even had the Internet Explorer symbol on It. There were 226 of these I had to delete from my files.

Yesterday my husband was trying to print a document he had typed up for work & it wouldn't let him print It. Also

It disabled my Firewall, Avira & Microsoft Update which I had to enable again. Apparently what ever It Is, Is sticking around.

Can anyone help me get rid of this? Any help would be MOST appreciated.

 

TYIA,

Marina22

 

Here Is my Hijack This Scan Report:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:59:03 AM, on 1/29/2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16599)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
C:\Program Files (x86)\AOL Desktop 9.7c\waol.exe
C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
C:\Program Files (x86)\Common Files\AOL\1352492663\ee\aolsoftware.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\AOL Desktop 9.7c\shellmon.exe
C:\Windows\SysWOW64\ctfmon.exe
C:\Program Files (x86)\Common Files\AOL\Topspeed\3.0\aoltpsd3.exe
C:\Users\Owner\AppData\Roaming\oas\oas.exe
C:\Users\Owner\AppData\Roaming\oas\oas-module
C:\Users\Owner\AppData\Roaming\oas\oas-module
C:\Users\Owner\AppData\Roaming\oas\oas-module
C:\Users\Owner\Desktop\HijackThis.exe
C:\Windows\SysWOW64\DllHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:64550
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = <-loopback>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: AOL Toolbar Loader - {3ef64538-8b54-4573-b48f-4d34b0238ab2} - C:\Program Files (x86)\AOL Toolbar\aoltb.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Logitech SetPoint - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll
O2 - BHO: Advanced SystemCare Surfing Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\PROGRA~2\IObit\SURFIN~1\BROWER~1\ASCPLU~1.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: AOL Toolbar - {ba00b7b1-0351-477a-b948-23e3ee5a73d4} - C:\Program Files (x86)\AOL Toolbar\aoltb.dll
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
O4 - HKLM\..\Run: [HostManager] C:\Program Files (x86)\Common Files\AOL\1352492663\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Avira Systray] C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files (x86)\Trojan Remover\Trjscan.exe /boot
O4 - HKCU\..\Run: [EPLTarget\P0000000000000000] C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIHWA.EXE /EPT "EPLTarget\P0000000000000000" /M "WorkForce 545"
O4 - HKCU\..\Run: [ToolwizCareFree] "C:\Program Files (x86)\ToolwizCareFree\ToolwizCares.exe" -autorun
O4 - HKCU\..\Run: [Driver Support] C:\Program Files (x86)\Driver Support\Driver Support\DriverSupport.exe /applicationMode:systemTray /showWelcome:false
O4 - HKCU\..\Run: [Online Ad Scanner] C:\Users\Owner\AppData\Roaming\OAS\oasupd.exe
O4 - HKCU\..\Run: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
O4 - HKCU\..\Run: [bnimgae] rundll32 ",bnimgae
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files (x86)\AOL Desktop 9.7c\AOL.EXE" -b
O4 - HKUS\S-1-5-18\..\Run: [EPLTarget\P0000000000000000] C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIHWA.EXE /EPT "EPLTarget\P0000000000000000" /M "WorkForce 545" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [EPLTarget\P0000000000000000] C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIHWA.EXE /EPT "EPLTarget\P0000000000000000" /M "WorkForce 545" (User 'Default user')
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~4\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{398FA4FC-D7BB-4FEF-AC5D-A241C45B9E0D}: NameServer = 208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = hsd1.il.comcast.net.
O17 - HKLM\System\CS1\Services\Tcpip\..\{398FA4FC-D7BB-4FEF-AC5D-A241C45B9E0D}: NameServer = 208.67.222.222
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = hsd1.il.comcast.net.
O17 - HKLM\System\CS2\Services\Tcpip\..\{398FA4FC-D7BB-4FEF-AC5D-A241C45B9E0D}: NameServer = 208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = hsd1.il.comcast.net.
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Protocol: WSWSVCUchrome - (no CLSID) - (no file)
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL Inc. - C:\Program Files (x86)\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Avira Service Host (Avira.OE.ServiceHost) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CyberLink Product - 2012/04/11 11:34:18 (CLKMSVC10_38F51D56) - CyberLink - C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe
O23 - Service: Coupon Printer Service (CouponPrinterService) - Coupons.com Inc. - C:\Program Files (x86)\Coupons\CouponPrinterService.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: Viewpoint Service - Viewpoint Corporation - C:\Program Files (x86)\Viewpoint\Common\ViewpointService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 14031 bytes

Hello Marina22, welcome to WhatTheTech's Malware Removal forum!
 
My username is LiquidTension, but you can call me Adam. I will be assisting you with your malware-related problems.
If you would allow me to call you by your first name I would prefer that.  :)
 
======================================================
 
Please read through the points below to ensure this process moves as quickly and efficiently as possible.

  • Please ensure you read through my instructions thoroughly, and carry out each step in the order specified.
  • Please do not run any tools or take any steps other than those I provide for you. Independent efforts may make matters worse, and will affect my ability in ascertaining the current situation and providing the best set of instructions for you.
  • Please backup important files before proceeding with my instructions. Malware removal can be unpredictable.  
  • If you come across any issues whilst following my instructions, please stop and inform me of the issue in as much detail as possible. Please do not hesitate to ask before proceeding.
  • Topics are locked if no response is made after 4 days. Please inform me if you require additional time to complete my instructions.
  • Ensure you are following this topic. Click [external image: etYzdbu.png] at the top of the page. 
     

======================================================
 

The symptoms are as follows. Many of my jpg's were corrupted as It added an extension to some files after the jpg.
The extension It added was -.gjhsaqj. Also I find some of my zip files have locks on them now which wasn't that way before.
Also many files have added docs in them all with the description underneath- HELP_DESCRIPT. Some even had the Internet Explorer symbol on It. There were 226 of these I had to delete from my files.

Unfortunately, you've fallen victim to malware known as file encrypting ransomware. This malware will encrypt your personal files and demand you pay a ransom in order to reverse the encryption. 
 
From what you've described, it sounds as if you've been infected by both CTB Locker and CryptoWall 3.0. I'm afraid to say that due to this, recovery of your files is unlikely. Whilst I won't rule anything out just yet, it's important you're aware of this possibility. Do you have backups for your files? 
 
————–
 
Please run the following diagnostic scans so I can ascertain the state of your computer.
 
STEP 1

[external image: xlK5Hdb.png] Farbar Recovery Scan Tool (FRST) Scan

  • Please download Farbar Recovery Scan Tool (x32) or Farbar Recovery Scan Tool (x64) and save the file to your Desktop.
  • Note: Download and run the version compatible with your system (32 or 64-bit). Download both if you're unsure; only one will run.
  • Right-Click FRST.exe / FRST64.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Click Yes to the disclaimer.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the programme run.
  • Upon completion, click OK, then OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy the contents of both logs and paste in your next reply. 
     

STEP 2
[external image: YARWD1t.png.pagespeed.ce.nvhmVeYDe3.png] TDSSKiller Scan

  • Please download TDSSKiller and save the file to your Desktop.
  • Right-Click TDSSKiller.exe and select [external image: xAVOiBNU.jpg.pagespeed.ic.H5HC6LkiJX.jpg] Run as administrator to run the programme.
  • Click Change parameters. Place a checkmark next to Detect TDLFS file system and Verify file digital signatures.
  • ​Click Start Scan. Do not use the computer during the scan.
  • If objects are found, change the action to skip.
  • Click Continue and close the window.
  • A log will be created and saved to the root directory (usually C:\). Attach the file in your next reply.
     

======================================================
 
STEP 3
[external image: pfNZP4A.png] Logs
In your next reply please include the following logs. Please be sure to copy and paste the requested logs, as well as provide information on any questions I may have asked.

  • FRST.txt
  • Addition.txt
  • TDSSKiller log (attached)
Hi Adam, thank you for your help. My computer wouldn't let me download the apps. It keeps stalling. I have tried to restart it &
Startup Repair came up & said it would try to fix the problem. So I'm still waiting for it to finish trying to repair the problems. If it doesn't,
I will try to restart it again. Yes, I backed up some of my important files onto a flash drive. If I can't download the apps to clean my computer,
I will have to take it to my repair man. :( I am posting this from my ipad mini. I will let you know here what happens.

Thank you again,
Marina22

Ok, so after everything blocking me from downloading & numerous restarts, I was finally able to log in to my AOL & download

Combofix ( yes, I know, but I was desperate)

It seems to have helped. The log Is below

 

 

ComboFix 15-01-29.01 - Owner 01/29/2015  20:58:13.3.8 - x64
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.1.1033.18.16301.13446 [GMT -6:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: Avira Desktop *Enabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859}
SP: Avira Desktop *Enabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\END
c:\programdata\msboofb.exe.vir
c:\users\Owner\AppData\Local\common_functions.dll
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\background.html
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\chromeCoreFilesIndex.TXT.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\crossriderManifest.json
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\extensionData\manifest.xml
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\extensionData\plugins.json
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\extensionData\plugins\1_base.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\extensionData\plugins\13_CrossriderAppUtils.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\extensionData\plugins\14_CrossriderUtils.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\extensionData\plugins\17_jQuery.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\extensionData\plugins\177_crossriderDashboard.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\extensionData\plugins\182_openUrl.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\extensionData\plugins\183_tabsWrapper.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\extensionData\plugins\19_CHAppAPIWrapper.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\extensionData\plugins\207_dbWrapper.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\extensionData\plugins\21_debug.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\extensionData\plugins\22_resources.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\extensionData\plugins\28_initializer.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\extensionData\plugins\4_jquery_1_7_1.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\extensionData\plugins\47_resources_background.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\extensionData\plugins\64_appApiMessage.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\extensionData\plugins\72_appApiValidation.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\extensionData\plugins\78_CrossriderInfo.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\extensionData\plugins\80_CHPopupAppAPI.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\extensionData\plugins\91_monetizationLoader.js.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\extensionData\plugins\97_resourceApiWrapper.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\extensionData\userCode\background.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\extensionData\userCode\extension.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\icons\actions\1.png
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\icons\icon128.png
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\icons\icon16.png
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\icons\icon48.png
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\js\api\chrome.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\js\api\cookie.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\js\api\message.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\js\api\monitor.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\js\api\pageAction.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\js\api\pageActionBG.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\js\background.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\js\lib\app_api.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\js\lib\bg_app_api.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\js\lib\consts.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\js\lib\cookie_store.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\js\lib\crossriderAPI.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\js\lib\delegate.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\js\lib\events.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\js\lib\extensionDataStore.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\js\lib\installer.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\js\lib\logFile.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\js\lib\logging.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\js\lib\onBGDocumentLoad.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\js\lib\popupResource\newPopup.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\js\lib\popupResource\popup.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\js\lib\reports.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\js\lib\storageWrapper.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\js\lib\updateManager.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\js\lib\util.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\js\lib\xhr.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\js\main.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\js\platformVersion.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\manifest.json
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\afeodekfkejjgjigfnhhifffljmhnpfn\1.26.50_0\popup.html
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\apndcppigpmgfcckcifikgnmcdjnolao
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\apndcppigpmgfcckcifikgnmcdjnolao\1.0\background.html
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\apndcppigpmgfcckcifikgnmcdjnolao\1.0\content.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\apndcppigpmgfcckcifikgnmcdjnolao\1.0\lsdb.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\apndcppigpmgfcckcifikgnmcdjnolao\1.0\manifest.json
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\apndcppigpmgfcckcifikgnmcdjnolao\1.0\Wqh8SW2.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\boemmnepglcoinjcdlfcpcbmhiecichi
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\boemmnepglcoinjcdlfcpcbmhiecichi\136\background.html
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\boemmnepglcoinjcdlfcpcbmhiecichi\136\content.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\boemmnepglcoinjcdlfcpcbmhiecichi\136\eF8oL.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\boemmnepglcoinjcdlfcpcbmhiecichi\136\lsdb.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\boemmnepglcoinjcdlfcpcbmhiecichi\136\manifest.json
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\ckpkignmciabdlklajeonapbahiimmdk
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\ckpkignmciabdlklajeonapbahiimmdk\2.1\background.html
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\ckpkignmciabdlklajeonapbahiimmdk\2.1\content.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\ckpkignmciabdlklajeonapbahiimmdk\2.1\lsdb.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\ckpkignmciabdlklajeonapbahiimmdk\2.1\manifest.json
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\ckpkignmciabdlklajeonapbahiimmdk\2.1\newtab.html
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\ckpkignmciabdlklajeonapbahiimmdk\2.1\WS703iFFx.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\feblcdldkebjffkgdpmiclaiicdobbpp
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\feblcdldkebjffkgdpmiclaiicdobbpp\5.14\background.html
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\feblcdldkebjffkgdpmiclaiicdobbpp\5.14\content.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\feblcdldkebjffkgdpmiclaiicdobbpp\5.14\l3Hv.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\feblcdldkebjffkgdpmiclaiicdobbpp\5.14\lsdb.JS.gjhsaqj
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\feblcdldkebjffkgdpmiclaiicdobbpp\5.14\manifest.json
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\afeodekfkejjgjigfnhhifffljmhnpfn
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\afeodekfkejjgjigfnhhifffljmhnpfn\000198.ldb
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\afeodekfkejjgjigfnhhifffljmhnpfn\000203.ldb
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\afeodekfkejjgjigfnhhifffljmhnpfn\000204.log
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\afeodekfkejjgjigfnhhifffljmhnpfn\CURRENT
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\afeodekfkejjgjigfnhhifffljmhnpfn\LOCK
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\afeodekfkejjgjigfnhhifffljmhnpfn\LOG
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\afeodekfkejjgjigfnhhifffljmhnpfn\LOG.old
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\afeodekfkejjgjigfnhhifffljmhnpfn\MANIFEST-000202
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\apndcppigpmgfcckcifikgnmcdjnolao
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\apndcppigpmgfcckcifikgnmcdjnolao\000003.log
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\apndcppigpmgfcckcifikgnmcdjnolao\CURRENT
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\apndcppigpmgfcckcifikgnmcdjnolao\LOCK
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\apndcppigpmgfcckcifikgnmcdjnolao\LOG
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\apndcppigpmgfcckcifikgnmcdjnolao\MANIFEST-000002
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ckpkignmciabdlklajeonapbahiimmdk
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ckpkignmciabdlklajeonapbahiimmdk\000003.log
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ckpkignmciabdlklajeonapbahiimmdk\CURRENT
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ckpkignmciabdlklajeonapbahiimmdk\LOCK
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ckpkignmciabdlklajeonapbahiimmdk\LOG
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ckpkignmciabdlklajeonapbahiimmdk\MANIFEST-000002
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\feblcdldkebjffkgdpmiclaiicdobbpp
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\feblcdldkebjffkgdpmiclaiicdobbpp\000003.log
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\feblcdldkebjffkgdpmiclaiicdobbpp\CURRENT
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\feblcdldkebjffkgdpmiclaiicdobbpp\LOCK
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\feblcdldkebjffkgdpmiclaiicdobbpp\LOG
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\feblcdldkebjffkgdpmiclaiicdobbpp\MANIFEST-000002
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_afeodekfkejjgjigfnhhifffljmhnpfn_0.localstorage
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_apndcppigpmgfcckcifikgnmcdjnolao_0.localstorage
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_boemmnepglcoinjcdlfcpcbmhiecichi_0.localstorage-journal
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_boemmnepglcoinjcdlfcpcbmhiecichi_0.localstorage
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ckpkignmciabdlklajeonapbahiimmdk_0.localstorage
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_feblcdldkebjffkgdpmiclaiicdobbpp_0.localstorage
c:\users\Owner\AppData\Local\Google\Chrome\User Data\Default\Preferences
c:\users\Owner\AppData\Local\ie_runner_app.exe
c:\users\Owner\AppData\Local\olvbesb.dll
c:\users\Owner\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll
c:\windows\SysWow64\WNLT
.
.
(((((((((((((((((((((((((   Files Created from 2014-12-28 to 2015-01-30  )))))))))))))))))))))))))))))))
.
.
2015-01-30 03:10 . 2015-01-30 03:10 ——– d—–w- c:\users\Default\AppData\Local\temp
2015-01-30 02:45 . 2015-01-30 02:44 43064 —-a-w- c:\windows\system32\drivers\avnetflt.sys
2015-01-30 02:44 . 2015-01-30 02:44 ——– d—–w- c:\users\Owner\AppData\Roaming\Avira
2015-01-30 02:43 . 2014-11-24 16:23 28600 —-a-w- c:\windows\system32\drivers\avkmgr.sys
2015-01-30 02:43 . 2014-11-24 16:23 131608 —-a-w- c:\windows\system32\drivers\avipbb.sys
2015-01-30 02:43 . 2014-11-24 16:23 119272 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2015-01-30 00:59 . 2015-01-30 00:59 ——– d—–w- c:\programdata\Licenses
2015-01-29 23:55 . 2015-01-30 00:05 ——– d—–w- c:\users\Owner\AppData\Roaming\Local Store
2015-01-29 04:57 . 2015-01-29 04:59 ——– d—–w- c:\program files (x86)\Trojan Remover
2015-01-29 04:57 . 2015-01-29 04:57 ——– d—–w- c:\users\Owner\AppData\Roaming\Simply Super Software
2015-01-29 04:57 . 2015-01-29 04:57 ——– d—–w- c:\programdata\Simply Super Software
2015-01-28 23:47 . 2015-01-29 02:17 ——– d—–w- c:\windows\FrameworkUpdate
2015-01-27 19:55 . 2015-01-29 00:11 ——– d—–w- c:\program files (x86)\SmartApp
2015-01-23 00:42 . 2015-01-23 00:42 ——– d—–w- c:\users\Owner\AppData\Roaming\IObit
2015-01-20 01:42 . 2015-01-20 01:42 ——– d—–w- c:\program files\AOL Toolbar
2015-01-20 01:41 . 2015-01-20 01:42 ——– d—–w- c:\program files (x86)\AOL Toolbar
2015-01-20 01:41 . 2015-01-20 01:41 ——– d—–w- c:\program files (x86)\Common Files\Software Update Utility
2015-01-20 01:40 . 2015-01-28 23:56 ——– d—–w- c:\program files (x86)\AOL Desktop 9.7c
2015-01-18 01:43 . 2014-12-19 01:46 141312 —-a-w- c:\windows\system32\drivers\mrxdav.sys
2015-01-18 01:37 . 2014-12-19 03:06 210432 —-a-w- c:\windows\system32\profsvc.dll
2015-01-18 01:37 . 2014-12-06 04:17 303616 —-a-w- c:\windows\system32\nlasvc.dll
2015-01-18 01:37 . 2014-12-11 17:47 87040 —-a-w- c:\windows\system32\TSWbPrxy.exe
2015-01-18 01:37 . 2014-12-12 05:35 5553592 —-a-w- c:\windows\system32\ntoskrnl.exe
2015-01-18 01:37 . 2014-12-12 05:31 503808 —-a-w- c:\windows\system32\srcore.dll
2015-01-18 01:37 . 2014-12-12 05:31 296960 —-a-w- c:\windows\system32\rstrui.exe
2015-01-18 01:37 . 2014-12-12 05:31 50176 —-a-w- c:\windows\system32\srclient.dll
2015-01-16 22:09 . 2015-01-30 02:48 ——– d—–w- C:\1d157577
2015-01-11 04:50 . 2015-01-11 04:50 ——– d—–w- C:\TDSSKiller_Quarantine
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-01-30 01:15 . 2014-12-26 17:53 129752 —-a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2015-01-29 17:14 . 2015-01-29 17:14 71680 —-a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2015-01-29 17:14 . 2015-01-29 17:14 1762816 —-a-w- c:\windows\SysWow64\wininet.dll
2015-01-29 17:14 . 2015-01-29 17:14 73728 —-a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2015-01-29 17:14 . 2015-01-29 17:14 61952 —-a-w- c:\windows\SysWow64\tdc.ocx
2015-01-29 17:14 . 2015-01-29 17:14 523264 —-a-w- c:\windows\SysWow64\vbscript.dll
2015-01-29 17:14 . 2015-01-29 17:14 138752 —-a-w- c:\windows\SysWow64\wextract.exe
2015-01-24 23:19 . 2012-11-02 15:23 71344 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2015-01-24 23:19 . 2012-11-02 15:23 701616 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2015-01-20 01:36 . 2012-11-03 20:59 58696 —-a-w- c:\windows\SysWow64\AOLParconLink.exe
2015-01-18 01:43 . 2012-11-13 15:02 113365784 —-a-w- c:\windows\system32\MRT.exe
2015-01-08 15:55 . 2010-11-21 03:27 298120 ——w- c:\windows\system32\MpSigStub.exe
2014-12-25 14:40 . 2014-12-24 12:53 129752 —-a-w- c:\windows\system32\drivers\5AB7410E.sys
2014-12-12 05:11 . 2015-01-18 01:37 3971512 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe
2014-12-12 05:11 . 2015-01-18 01:37 3916728 —-a-w- c:\windows\SysWow64\ntoskrnl.exe
2014-12-12 05:07 . 2015-01-18 01:37 43008 —-a-w- c:\windows\SysWow64\srclient.dll
2014-12-06 03:50 . 2015-01-18 01:37 52224 —-a-w- c:\windows\SysWow64\nlaapi.dll
2014-12-06 03:50 . 2015-01-18 01:37 156672 —-a-w- c:\windows\SysWow64\ncsi.dll
2014-12-04 02:50 . 2014-12-12 02:18 413184 —-a-w- c:\windows\system32\generaltel.dll
2014-12-04 02:50 . 2014-12-12 02:18 741376 —-a-w- c:\windows\system32\invagent.dll
2014-12-04 02:50 . 2014-12-12 02:18 396800 —-a-w- c:\windows\system32\devinv.dll
2014-12-04 02:50 . 2014-12-12 02:18 830976 —-a-w- c:\windows\system32\appraiser.dll
2014-12-04 02:50 . 2014-12-12 02:18 227328 —-a-w- c:\windows\system32\aepdu.dll
2014-12-04 02:50 . 2014-12-12 02:18 192000 —-a-w- c:\windows\system32\aepic.dll
2014-12-04 02:44 . 2014-12-12 02:18 1083392 —-a-w- c:\windows\system32\aeinv.dll
2014-12-02 10:26 . 2015-01-27 14:25 11870360 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{A7132A1E-2014-46C8-B3D8-2E266108F91F}\mpengine.dll
2014-12-01 23:28 . 2014-12-12 02:18 1232040 —-a-w- c:\windows\system32\aitstatic.exe
2014-11-21 12:14 . 2014-12-26 17:52 63704 —-a-w- c:\windows\system32\drivers\mwac.sys
2014-11-21 12:14 . 2014-12-26 17:52 93400 —-a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-11-21 12:14 . 2014-12-26 17:52 25816 —-a-w- c:\windows\system32\drivers\mbam.sys
2014-11-18 20:56 . 2014-11-18 20:56 1202848 —-a-w- c:\windows\SysWow64\FM20.DLL
2014-11-11 03:09 . 2014-12-12 02:18 1424384 —-a-w- c:\windows\system32\WindowsCodecs.dll
2014-11-11 03:08 . 2014-11-19 14:03 241152 —-a-w- c:\windows\system32\pku2u.dll
2014-11-11 03:08 . 2014-11-19 14:03 728064 —-a-w- c:\windows\system32\kerberos.dll
2014-11-11 02:44 . 2014-12-12 02:18 1230336 —-a-w- c:\windows\SysWow64\WindowsCodecs.dll
2014-11-11 02:44 . 2014-11-19 14:03 186880 —-a-w- c:\windows\SysWow64\pku2u.dll
2014-11-11 02:44 . 2014-11-19 14:03 550912 —-a-w- c:\windows\SysWow64\kerberos.dll
2014-11-11 01:46 . 2014-12-12 02:18 119296 —-a-w- c:\windows\system32\drivers\tdx.sys
2014-11-08 17:12 . 2014-11-08 17:12 98216 —-a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2014-11-08 03:16 . 2014-12-12 02:17 2048 —-a-w- c:\windows\system32\tzres.dll
2014-11-08 02:45 . 2014-12-12 02:17 2048 —-a-w- c:\windows\SysWow64\tzres.dll
2014-07-18 14:04 . 2014-07-18 14:10 6826808 —-a-w- c:\program files (x86)\Driver_Genius_10_Professional_US_PPC.exe
2001-07-13 12:04 . 2012-12-31 19:44 3072000 —-a-w- c:\program files\anim.exe
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2014-06-23 13:13 223432 —-a-w- c:\users\Owner\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2014-06-23 13:13 223432 —-a-w- c:\users\Owner\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2014-06-23 13:13 223432 —-a-w- c:\users\Owner\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\SkyDriveShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EPLTarget\P0000000000000000"="c:\windows\system32\spool\DRIVERS\x64\3\E_YATIHWA.EXE" [2012-07-12 241280]
"ToolwizCareFree"="c:\program files (x86)\ToolwizCareFree\ToolwizCares.exe" [2014-08-04 5274328]
"Driver Support"="c:\program files (x86)\Driver Support\Driver Support\DriverSupport.exe" [2014-08-07 5673824]
"iCloudServices"="c:\program files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe" [2014-10-17 43816]
"AOL Fast Start"="c:\program files (x86)\AOL Desktop 9.7c\AOL.EXE" [2014-09-16 72296]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"EEventManager"="c:\program files (x86)\Epson Software\Event Manager\EEventManager.exe" [2010-10-12 979328]
"HostManager"="c:\program files (x86)\Common Files\AOL\1352492663\ee\AOLSoftware.exe" [2010-03-08 41800]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2014-10-02 421888]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2014-09-27 271744]
"Avira Systray"="c:\program files (x86)\Avira\My Avira\Avira.OE.Systray.exe" [2014-12-31 126712]
"TrojanScanner"="c:\program files (x86)\Trojan Remover\Trjscan.exe" [2015-01-29 1791856]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2014-11-24 702768]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"EPLTarget\P0000000000000000"="c:\windows\system32\spool\DRIVERS\x64\3\E_YATIHWA.EXE" [2012-07-12 241280]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"TaskbarNoNotification"= 1 (0x1)
"HideSCAHealth"= 1 (0x1)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"TaskbarNoNotification"= 1 (0x1)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"TaskbarNoNotification"= 1 (0x1)
"HideSCAHealth"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
R2 Avira.OE.ServiceHost;Avira Service Host;c:\program files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe;c:\program files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [x]
R2 CLKMSVC10_38F51D56;CyberLink Product - 2012/04/11 11:34;c:\program files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe;c:\program files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 LiveUpdateSvc;LiveUpdate;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe [x]
R2 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 dc3d;MS Hardware Device Detection Driver;c:\windows\system32\DRIVERS\dc3d.sys;c:\windows\SYSNATIVE\DRIVERS\dc3d.sys [x]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
R3 netr7364;Conceptronic RT73 Wireles Driver for Vista;c:\windows\system32\DRIVERS\netr7364.sys;c:\windows\SYSNATIVE\DRIVERS\netr7364.sys [x]
R3 Point64;Microsoft Mouse and Keyboard Center Filter Driver;c:\windows\system32\DRIVERS\point64.sys;c:\windows\SYSNATIVE\DRIVERS\point64.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 SWDUMon;SWDUMon;c:\windows\system32\DRIVERS\SWDUMon.sys;c:\windows\SYSNATIVE\DRIVERS\SWDUMon.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
S0 BTOWSVF;BTOWSVF;c:\windows\System32\Drivers\BTOWSVF.sys;c:\windows\SYSNATIVE\Drivers\BTOWSVF.sys [x]
S0 KSafeDISK;KSafeDISK;c:\windows\System32\Drivers\KSafeDISK.sys;c:\windows\SYSNATIVE\Drivers\KSafeDISK.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x]
S1 BTOWSFF;BTOWSFF;c:\windows\System32\Drivers\BTOWSFF.sys;c:\windows\SYSNATIVE\Drivers\BTOWSFF.sys [x]
S2 AntiVirSchedulerService;Avira Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x]
S2 CouponPrinterService;Coupon Printer Service;c:\program files (x86)\Coupons\CouponPrinterService.exe;c:\program files (x86)\Coupons\CouponPrinterService.exe [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S2 Viewpoint Service;Viewpoint Service;c:\program files (x86)\Viewpoint\Common\ViewpointService.exe;c:\program files (x86)\Viewpoint\Common\ViewpointService.exe [x]
S3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\system32\Drivers\EtronHub3.sys;c:\windows\SYSNATIVE\Drivers\EtronHub3.sys [x]
S3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\Drivers\EtronXHCI.sys;c:\windows\SYSNATIVE\Drivers\EtronXHCI.sys [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;c:\windows\system32\DRIVERS\LEqdUsb.Sys;c:\windows\SYSNATIVE\DRIVERS\LEqdUsb.Sys [x]
S3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;c:\windows\system32\DRIVERS\LHidEqd.Sys;c:\windows\SYSNATIVE\DRIVERS\LHidEqd.Sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
.
.
— Other Services/Drivers In Memory —
.
*Deregistered* - CLKMDRV10_38F51D56
*Deregistered* - RegFilter
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2015-01-27 03:24 1086280 —-a-w- c:\program files (x86)\Google\Chrome\Application\40.0.2214.93\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2015-01-30 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-11-02 23:19]
.
2015-01-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-02-12 01:42]
.
2015-01-30 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-02-12 01:42]
.
.
——— X64 Entries ———–
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2014-06-23 13:13 262344 —-a-w- c:\users\Owner\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2014-06-23 13:13 262344 —-a-w- c:\users\Owner\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2014-06-23 13:13 262344 —-a-w- c:\users\Owner\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2014-08-27 13672152]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2014-05-19 3100440]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2014-08-27 172016]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2014-08-27 399856]
"Persistence"="c:\windows\system32\igfxpers.exe" [2014-08-27 442352]
.
——- Supplementary Scan ——-
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://msn.com/
mDefault_Search_URL = about:blank
mSearch Page = about:blank
uInternet Settings,ProxyOverride = <-loopback>
uInternet Settings,ProxyServer = http=127.0.0.1:64550
uSearchAssistant = www.google.com
TCP: DhcpNameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{398FA4FC-D7BB-4FEF-AC5D-A241C45B9E0D}: NameServer = 208.67.222.222
FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\4l2qlfqr.default-1417042319708\
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
Toolbar-10 - (no file)
Wow6432Node-HKCU-Run-bnimgae - (no file)
Wow6432Node-HKU-Default-Run-olvbesb - c:\users\Owner\AppData\Local\olvbesb.dll
Wow6432Node-HKU-Default-Run-BluetoothS - c:\users\Owner\AppData\Roaming\BtvStack.dll
Wow6432Node-HKLM-Explorer_Run-1644913992 - c:\progra~3\msboofb.exe
Wow6432Node-HKU-Default-Explorer_Run-1644913992 - c:\progra~3\msboofb.exe
Notify-olvbesb - c:\users\Owner\AppData\Local\olvbesb.dll
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
BHO-{10921475-03CE-4E04-90CE-E2E7EF20C814} - c:\program files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll
Toolbar-10 - (no file)
WebBrowser-{3FABEEE8-9237-CDE4-D1F2-6648F4D1C386} - (no file)
.
.
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
   d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,d2,76,69,e0,d7,8d,98,46,82,9c,9b,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
   d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,d2,76,69,e0,d7,8d,98,46,82,9c,9b,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_16_0_0_296_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_16_0_0_296_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_16_0_0_296_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_16_0_0_296_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_296.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.16"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_296.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_296.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_296.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
———————— Other Running Processes ————————
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
c:\program files (x86)\Common Files\AOL\ACS\AOLAcsd.exe
c:\program files (x86)\Microsoft Office\Office12\GrooveAuditService.exe
c:\program files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
c:\windows\SysWow64\perfhost.exe
c:\program files (x86)\CyberLink\Shared files\RichVideo.exe
c:\program files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\program files (x86)\AOL Desktop 9.7c\waol.exe
c:\program files (x86)\iTunes\iTunesHelper.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\AOL Desktop 9.7c\shellmon.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
.
**************************************************************************
.
Completion time: 2015-01-29  21:27:35 - machine was rebooted
ComboFix-quarantined-files.txt  2015-01-30 03:27
.
Pre-Run: 1,719,018,639,360 bytes free
Post-Run: 1,719,035,011,072 bytes free
.
- - End Of File - - 04930611860DA29BA522F7364DC7C20E
A36C5E4F47E84449FF07ED3517B43A31

Hello, 
 
In order to assist you effectively, I must stress the importance of the following from my first post:

Please do not run any tools or take any steps other than those I provide for you. Independent efforts may make matters worse, and will affect my ability in ascertaining the current situation and providing the best set of instructions for you.


I need you to download and run the programmes from Post #2 please; not the likes of ComboFix which may or may not have made matters worse.
If you are still unable to download FRST and TDSSKiller, please stop and let me know.

Ok, I was fianlly able to download the 2 apps.

 

Here is the two logs from Farber Scan:

 

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-01-2015
Ran by [removed] (administrator) on OWNER-PC on 30-01-2015 08:17:12
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 10 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(AOL Inc.) C:\Program Files (x86)\Common Files\AOL\acs\AOLacsd.exe
(SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_YATIHWA.EXE
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Coupons.com Inc.) C:\Program Files (x86)\Coupons\CouponPrinterService.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
(AOL Inc.) C:\Program Files (x86)\Common Files\AOL\1352492663\ee\aolsoftware.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Source Engine\OSE.EXE
(Microsoft Corporation) C:\Windows\SysWOW64\perfhost.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(Microsoft Corporation) C:\Windows\System32\vds.exe
(Viewpoint Corporation) C:\Program Files (x86)\Viewpoint\Common\ViewpointService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Yahoo! Inc.) C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(AOL Inc.) C:\Program Files (x86)\AOL Desktop 9.7c\waol.exe
(AOL Inc.) C:\Program Files (x86)\AOL Desktop 9.7c\shellmon.exe
(AOL Inc.) C:\Program Files (x86)\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe
(AOL Inc.) C:\Program Files (x86)\AOL Desktop 9.7c\aolbrowser.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13672152 2014-08-27] (Realtek Semiconductor)
HKLM\…\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3100440 2014-05-19] (Logitech, Inc.)
HKLM-x32\…\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [979328 2010-10-12] (SEIKO EPSON CORPORATION)
HKLM-x32\…\Run: [HostManager] => C:\Program Files (x86)\Common Files\AOL\1352492663\ee\AOLSoftware.exe [41800 2010-03-08] (AOL Inc.)
HKLM-x32\…\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation)
HKLM-x32\…\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [126712 2014-12-31] (Avira Operations GmbH & Co. KG)
HKLM-x32\…\Run: [TrojanScanner] => C:\Program Files (x86)\Trojan Remover\Trjscan.exe [1791856 2015-01-28] (Simply Super Software)
HKLM-x32\…\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768 2014-11-24] (Avira Operations GmbH & Co. KG)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
Winlogon\Notify\olvbesb-x32: C:\Users\Owner\AppData\Local\olvbesb.dll [X]
HKLM\…\Policies\Explorer\Run: [1644913992] => C:\PROGRA~3\msboofb.exe No File
HKLM\…\Policies\Explorer: [TaskbarNoNotification] 1
HKLM\…\Policies\Explorer: [HideSCAHealth] 1
HKU\S-1-5-21-3259929428-2434079444-325336261-1000\…\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIHWA.EXE [241280 2012-07-12] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-3259929428-2434079444-325336261-1000\…\Run: [ToolwizCareFree] => C:\Program Files (x86)\ToolwizCareFree\ToolwizCares.exe [5274328 2014-08-03] (Toolwiz)
HKU\S-1-5-21-3259929428-2434079444-325336261-1000\…\Run: [Driver Support] => C:\Program Files (x86)\Driver Support\Driver Support\DriverSupport.exe [5673824 2014-08-07] (PC Drivers Headquarters)
HKU\S-1-5-21-3259929428-2434079444-325336261-1000\…\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2014-10-17] (Apple Inc.)
HKU\S-1-5-21-3259929428-2434079444-325336261-1000\…\Policies\Explorer: [NolowDiskSpaceChecks] 1
HKU\S-1-5-21-3259929428-2434079444-325336261-1000\…\Policies\Explorer: [TaskbarNoNotification] 1
HKU\S-1-5-18\…\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIHWA.EXE [241280 2012-07-12] (SEIKO EPSON CORPORATION)
HKU\S-1-5-18\…\Policies\Explorer\Run: [1644913992] => C:\PROGRA~3\msboofb.exe
HKU\S-1-5-18\…\Policies\Explorer: [TaskbarNoNotification] 1
HKU\S-1-5-18\…\Policies\Explorer: [HideSCAHealth] 1
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-3259929428-2434079444-325336261-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
ProxyServer: [S-1-5-21-3259929428-2434079444-325336261-1000] => http=127.0.0.1:64550
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page = 
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=msnhome
HKU\S-1-5-21-3259929428-2434079444-325336261-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
HKU\S-1-5-21-3259929428-2434079444-325336261-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://msn.com/
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM -> {15D6AACC-F402-4335-8BD8-20BB5E8A8DB5} URL = http://www.bing.com/search?q={searchTerms}&form;=MNMTDF&pc;=MANM&src;=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = 
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> {AA4A6415-7528-45C8-876D-268325601942} URL = http://search.aol.com/aol/search?q={searchTerms}&s;_it=clireset-ie
SearchScopes: HKU\S-1-5-21-3259929428-2434079444-325336261-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = 
SearchScopes: HKU\S-1-5-21-3259929428-2434079444-325336261-1000 -> {96bd48dd-741b-41ae-ac4a-aff96ba00f7e} URL = http://search.coupons.com/search.asp?p=df&q;={searchTerms}
SearchScopes: HKU\S-1-5-21-3259929428-2434079444-325336261-1000 -> {FACC0B80-7F2E-47F4-9A38-C1ECA0662D50} URL = http://search.aol.com/aol/search?q={searchTerms}&s;_it=clireset-ie
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll No File
BHO: AOL Toolbar Loader -> {3ef64538-8b54-4573-b48f-4d34b0238ab2} -> C:\Program Files\AOL Toolbar\aoltb.dll (AOL Inc.)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll (Logitech, Inc.)
BHO: WOT Helper -> {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} -> C:\Program Files\WOT\WOT.dll ()
BHO-x32: &Yahoo;! Toolbar Helper -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
BHO-x32: AOL Toolbar Loader -> {3ef64538-8b54-4573-b48f-4d34b0238ab2} -> C:\Program Files (x86)\AOL Toolbar\aoltb.dll (AOL Inc.)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll (Logitech, Inc.)
BHO-x32: Advanced SystemCare Surfing Protection -> {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} -> C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASCPlugin_Protection.dll (IObit)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM - AOL Toolbar - {ba00b7b1-0351-477a-b948-23e3ee5a73d4} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKLM-x32 - Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
Toolbar: HKLM-x32 - AOL Toolbar - {ba00b7b1-0351-477a-b948-23e3ee5a73d4} - C:\Program Files (x86)\AOL Toolbar\aoltb.dll (AOL Inc.)
Toolbar: HKU\S-1-5-21-3259929428-2434079444-325336261-1000 -> No Name - {3FABEEE8-9237-CDE4-D1F2-6648F4D1C386} -  No File
Toolbar: HKU\S-1-5-21-3259929428-2434079444-325336261-1000 -> WOT - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
Toolbar: HKU\S-1-5-21-3259929428-2434079444-325336261-1000 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKU\S-1-5-21-3259929428-2434079444-325336261-1000 -> AOL Toolbar - {BA00B7B1-0351-477A-B948-23E3EE5A73D4} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL Inc.)
Handler: WSWSVCUchrome - No CLSID Value
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{398FA4FC-D7BB-4FEF-AC5D-A241C45B9E0D}: [NameServer] 208.67.222.222
 
FireFox:
========
FF ProfilePath: C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\4l2qlfqr.default-1417042319708
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_296.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_296.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @viewpoint.com/VMP -> C:\Program Files (x86)\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll (Viewpoint Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npunagi2.dll (America Online, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\browser\plugins\npMozCouponPrinter.dll (Coupons, Inc.)
FF SearchPlugin: C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\4l2qlfqr.default-1417042319708\searchplugins\aolsearch.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\aolsearch.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\safesearch.xml
FF Extension: AOL Toolbar - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\4l2qlfqr.default-1417042319708\Extensions\{7affbfae-c4e2-4915-8c0f-00fa3ec610a1} [2015-01-19]
FF HKLM-x32\…\Firefox\Extensions: [{635abd67-4fe9-1b23-4f01-e679fa7484c1}] - 0\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
FF HKLM-x32\…\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2014-07-18]
 
Chrome: 
=======
CHR Profile: C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (South Park) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\aoiakcboakkfknbginpmpfkcdmcmpnfm [2014-11-12]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-05-31]
CHR Extension: (YouTube) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-02-11]
CHR Extension: (Google Search) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-02-11]
CHR Extension: (Avira Browser Safety) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2014-08-12]
CHR Extension: (Services) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\flofdhbohbadcgnolfniillmboolleoh [2014-06-12]
CHR Extension: (Tab) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\gdfjhiclilbjdpeejgcgebmmihkkofji [2014-06-12]
CHR Extension: (Simple) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\joefoganpblmedgjeigepgjfikhhdnnj [2014-06-12]
CHR Extension: (Google Wallet) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-29]
CHR HKLM\…\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path
CHR HKLM-x32\…\Chrome\Extension: [eihhgekonheiliaidomffpplfhecmkag] - No Path
CHR HKLM-x32\…\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path
CHR HKLM-x32\…\Chrome\Extension: [ogccgbmabaphcakpiclgcnmcnimhokcj] - No Path
 
==================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-11-24] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-11-24] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [178424 2014-12-31] (Avira Operations GmbH & Co. KG)
S2 CLKMSVC10_38F51D56; C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [241648 2011-04-20] (CyberLink)
R2 CouponPrinterService; C:\Program Files (x86)\Coupons\CouponPrinterService.exe [179184 2014-10-15] (Coupons.com Inc.)
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2631456 2014-12-10] (IObit)
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [167936 2005-08-07] () [File not signed]
R2 Viewpoint Service; C:\Program Files (x86)\Viewpoint\Common\ViewpointService.exe [30152 2008-04-04] (Viewpoint Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-13] (Microsoft Corporation)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-11-24] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131608 2014-11-24] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-11-24] (Avira Operations GmbH & Co. KG)
R1 BTOWSFF; C:\Windows\System32\Drivers\BTOWSFF.sys [33024 2014-08-03] (Toolwiz.com)
R0 BTOWSVF; C:\Windows\System32\Drivers\BTOWSVF.sys [52480 2014-08-03] (Toolwiz.com)
R0 KSafeDISK; C:\Windows\System32\Drivers\KSafeDISK.sys [52992 2014-08-03] (Toolwiz.com)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-01-29] (Malwarebytes Corporation)
S3 SWDUMon; C:\Windows\System32\DRIVERS\SWDUMon.sys [16152 2014-07-11] ()
S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2012-12-13] (Apple, Inc.) [File not signed]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
==================== One Month Created Files and Folders ========
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-01-30 08:17 - 2015-01-30 08:17 - 00022420 _____ () C:\Users\Owner\Desktop\FRST.txt
2015-01-30 08:16 - 2015-01-30 08:17 - 00000000 ____D () C:\FRST
2015-01-30 08:16 - 2015-01-30 08:16 - 02130432 _____ (Farbar) C:\Users\Owner\Downloads\FRST64.exe
2015-01-30 08:16 - 2015-01-30 08:16 - 02130432 _____ (Farbar) C:\Users\Owner\Desktop\FRST64.exe
2015-01-30 08:14 - 2015-01-30 08:14 - 01121792 _____ (Farbar) C:\Users\Owner\Downloads\FRST.exe
2015-01-30 08:06 - 2015-01-30 08:06 - 00143360 _____ () C:\Users\Owner\Downloads\tdsskiller.zip
2015-01-30 08:04 - 2015-01-30 08:05 - 04197016 _____ (Kaspersky Lab ZAO) C:\Users\Owner\Desktop\tdsskiller.exe
2015-01-30 08:03 - 2015-01-30 08:05 - 04197016 _____ (Kaspersky Lab ZAO) C:\Users\Owner\Downloads\tdsskiller.exe
2015-01-30 08:03 - 2015-01-30 08:03 - 00012288 _____ () C:\Users\Owner\Downloads\tdsskiller 2
2015-01-29 22:02 - 2015-01-29 22:03 - 00000000 ___SD () C:\ComboFix
2015-01-29 20:45 - 2015-01-29 20:44 - 00043064 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2015-01-29 20:44 - 2015-01-29 20:44 - 00000000 ____D () C:\Users\Owner\AppData\Roaming\Avira
2015-01-29 20:43 - 2014-11-24 10:23 - 00131608 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2015-01-29 20:43 - 2014-11-24 10:23 - 00119272 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2015-01-29 20:43 - 2014-11-24 10:23 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2015-01-29 20:16 - 2015-01-29 20:16 - 00279200 _____ () C:\Windows\Minidump\012915-60902-01.dmp
2015-01-29 20:15 - 2015-01-29 20:15 - 811325993 _____ () C:\Windows\MEMORY.DMP
2015-01-29 20:14 - 2015-01-29 20:14 - 00003288 ____N () C:\bootsqm.dat
2015-01-29 18:59 - 2015-01-29 18:59 - 00000000 ____D () C:\ProgramData\Licenses
2015-01-29 17:55 - 2015-01-29 18:05 - 00000000 ____D () C:\Users\Owner\AppData\Roaming\Local Store
2015-01-29 11:14 - 2015-01-29 11:14 - 19283456 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 15400960 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 14364672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 13758976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 02861568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-01-29 11:14 - 2015-01-29 11:14 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-01-29 11:14 - 2015-01-29 11:14 - 02655232 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 02237952 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 02054656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 01762816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 01509376 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-01-29 11:14 - 2015-01-29 11:14 - 01441280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-01-29 11:14 - 2015-01-29 11:14 - 01409536 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 01400416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2015-01-29 11:14 - 2015-01-29 11:14 - 01400416 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2015-01-29 11:14 - 2015-01-29 11:14 - 01181696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 01054720 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-01-29 11:14 - 2015-01-29 11:14 - 00905728 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00762368 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00719360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00629248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00600576 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00523264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00451584 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-01-29 11:14 - 2015-01-29 11:14 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00361984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-01-29 11:14 - 2015-01-29 11:14 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00255488 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00247296 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00232960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00216064 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00204800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00185344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00173568 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-01-29 11:14 - 2015-01-29 11:14 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2015-01-29 11:14 - 2015-01-29 11:14 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00158720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00150528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2015-01-29 11:14 - 2015-01-29 11:14 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00144896 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2015-01-29 11:14 - 2015-01-29 11:14 - 00138752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2015-01-29 11:14 - 2015-01-29 11:14 - 00137216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-01-29 11:14 - 2015-01-29 11:14 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00125440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00117248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00110592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2015-01-29 11:14 - 2015-01-29 11:14 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2015-01-29 11:14 - 2015-01-29 11:14 - 00082432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00080384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2015-01-29 11:14 - 2015-01-29 11:14 - 00073728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2015-01-29 11:14 - 2015-01-29 11:14 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2015-01-29 11:14 - 2015-01-29 11:14 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2015-01-29 11:14 - 2015-01-29 11:14 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-01-29 11:14 - 2015-01-29 11:14 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00038400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2015-01-29 11:14 - 2015-01-29 11:14 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2015-01-29 11:14 - 2015-01-29 11:14 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2015-01-29 11:14 - 2015-01-29 11:14 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2015-01-29 11:12 - 2015-01-29 11:15 - 00007168 _____ () C:\Windows\IE10_main.log
2015-01-29 10:54 - 2015-01-29 10:54 - 00000000 ____D () C:\Users\Owner\AppData\Roaming\Google
2015-01-29 08:43 - 2015-01-29 08:43 - 00000000 ____D () C:\Users\Public\Documents\Logishrd
2015-01-28 22:57 - 2015-01-28 22:59 - 00000000 ____D () C:\Program Files (x86)\Trojan Remover
2015-01-28 22:57 - 2015-01-28 22:57 - 00000000 ____D () C:\Users\Owner\Documents\Simply Super Software
2015-01-28 22:57 - 2015-01-28 22:57 - 00000000 ____D () C:\Users\Owner\AppData\Roaming\Simply Super Software
2015-01-28 22:57 - 2015-01-28 22:57 - 00000000 ____D () C:\ProgramData\Simply Super Software
2015-01-28 22:57 - 2015-01-28 22:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trojan Remover
2015-01-28 22:57 - 2003-02-02 20:06 - 00153088 _____ () C:\Windows\SysWOW64\UNRAR3.dll
2015-01-28 22:57 - 2002-03-06 01:00 - 00075264 _____ () C:\Windows\SysWOW64\unacev2.dll
2015-01-28 17:47 - 2015-01-28 20:17 - 00000000 ____D () C:\Windows\FrameworkUpdate
2015-01-28 17:47 - 2015-01-28 17:47 - 00008528 _____ () C:\Users\Owner\AppData\HELP_DECRYPT.HTML
2015-01-28 17:47 - 2015-01-28 17:47 - 00000272 _____ () C:\Users\Owner\AppData\HELP_DECRYPT.URL
2015-01-28 17:46 - 2015-01-28 17:46 - 00008528 _____ () C:\Users\Owner\AppData\Local\HELP_DECRYPT.HTML
2015-01-28 17:46 - 2015-01-28 17:46 - 00000272 _____ () C:\Users\Owner\AppData\Local\HELP_DECRYPT.URL
2015-01-27 13:55 - 2015-01-28 18:11 - 00000000 ____D () C:\Program Files (x86)\SmartApp
2015-01-24 18:05 - 2015-01-24 18:05 - 00002996 _____ () C:\Windows\System32\Tasks\{BDD8CB15-6C5F-4803-9B99-87E7C2FB4F16}
2015-01-24 18:05 - 2015-01-24 18:05 - 00002996 _____ () C:\Windows\System32\Tasks\{976C70B3-B968-47F2-A94F-E8244D9219A0}
2015-01-22 18:42 - 2015-01-22 18:42 - 00000000 ____D () C:\Users\Owner\AppData\Roaming\IObit
2015-01-22 11:43 - 2015-01-22 11:48 - 00018432 ___SH () C:\Users\Owner\AppData\Thumbs.db
2015-01-21 11:09 - 2015-01-21 11:13 - 00000000 ____D () C:\Users\Owner\Documents\Fax
2015-01-19 19:42 - 2015-01-19 19:42 - 00001036 _____ () C:\Users\Public\Desktop\AOL Desktop 9.7.lnk
2015-01-19 19:42 - 2015-01-19 19:42 - 00000000 ____D () C:\Program Files\AOL Toolbar
2015-01-19 19:41 - 2015-01-19 19:42 - 00000000 ____D () C:\Program Files (x86)\AOL Toolbar
2015-01-19 19:40 - 2015-01-28 17:56 - 00000000 ____D () C:\Program Files (x86)\AOL Desktop 9.7c
2015-01-17 19:43 - 2014-12-18 19:46 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-01-17 19:37 - 2014-12-18 21:06 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-01-17 19:37 - 2014-12-11 23:35 - 05553592 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-01-17 19:37 - 2014-12-11 23:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-01-17 19:37 - 2014-12-11 23:31 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-01-17 19:37 - 2014-12-11 23:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-01-17 19:37 - 2014-12-11 23:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-01-17 19:37 - 2014-12-11 23:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-01-17 19:37 - 2014-12-11 23:07 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-01-17 19:37 - 2014-12-11 11:47 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-01-17 19:37 - 2014-12-05 22:17 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-01-17 19:37 - 2014-12-05 21:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2015-01-17 19:37 - 2014-12-05 21:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2015-01-16 16:10 - 2015-01-16 16:10 - 00008536 _____ () C:\ProgramData\HELP_DECRYPT.HTML
2015-01-16 16:10 - 2015-01-16 16:10 - 00000276 _____ () C:\ProgramData\HELP_DECRYPT.URL
2015-01-16 16:09 - 2015-01-29 20:48 - 00000000 ____D () C:\1d157577
2015-01-13 08:32 - 2015-01-17 19:24 - 00000000 ____D () C:\Users\Owner\Documents\CbBcolorfolder
2015-01-10 22:50 - 2015-01-10 22:50 - 00000000 ____D () C:\TDSSKiller_Quarantine
 
==================== One Month Modified Files and Folders =======
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-01-30 08:01 - 2013-02-11 19:42 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-01-30 08:01 - 2009-07-13 22:45 - 00024608 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-01-30 08:01 - 2009-07-13 22:45 - 00024608 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-01-30 07:57 - 2014-10-18 16:20 - 02054592 _____ () C:\Windows\WindowsUpdate.log
2015-01-30 07:51 - 2013-08-29 10:12 - 00065536 _____ () C:\Windows\system32\Ikeext.etl
2015-01-30 07:50 - 2013-02-11 19:42 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-01-30 07:49 - 2014-12-23 08:27 - 00999880 _____ () C:\Windows\setupact.log
2015-01-30 07:49 - 2014-12-23 08:27 - 00486344 _____ () C:\Windows\PFRO.log
2015-01-30 07:49 - 2009-07-13 23:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-01-29 22:10 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\tracing
2015-01-29 22:08 - 2012-11-03 14:58 - 00000000 ____D () C:\Users\Owner\AppData\Local\AOL
2015-01-29 22:06 - 2013-02-22 18:57 - 00000000 __SHD () C:\Windows\SysWOW64\AI_RecycleBin
2015-01-29 22:06 - 2013-02-22 18:57 - 00000000 __SHD () C:\AI_RecycleBin
2015-01-29 22:05 - 2012-11-13 12:07 - 00000000 ____D () C:\Program Files (x86)\Google
2015-01-29 22:02 - 2013-02-06 11:23 - 00000000 ____D () C:\Windows\erdnt
2015-01-29 21:52 - 2009-07-13 23:13 - 00782470 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-01-29 21:39 - 2013-04-13 20:44 - 00226816 ___SH () C:\Users\Owner\Documents\Thumbs.db
2015-01-29 21:19 - 2012-11-02 09:23 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-01-29 21:13 - 2009-07-13 20:34 - 00000215 _____ () C:\Windows\system.ini
2015-01-29 21:01 - 2012-04-11 12:33 - 00000000 ____D () C:\ProgramData\Temp
2015-01-29 20:54 - 2014-09-29 19:31 - 00356864 ___SH () C:\Users\Owner\Downloads\Thumbs.db
2015-01-29 20:44 - 2012-11-06 19:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-01-29 20:43 - 2012-11-06 19:47 - 00000000 ____D () C:\ProgramData\Avira
2015-01-29 20:43 - 2012-11-06 19:47 - 00000000 ____D () C:\Program Files (x86)\Avira
2015-01-29 20:16 - 2013-02-16 12:19 - 00000000 ____D () C:\Windows\Minidump
2015-01-29 19:44 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\NDF
2015-01-29 19:23 - 2013-01-11 09:39 - 00003926 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{DE660809-D05E-4624-B975-0EBAD77AF06D}
2015-01-29 19:15 - 2014-12-26 11:53 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-01-29 18:16 - 2014-12-26 16:55 - 00768194 _____ () C:\ProgramData\wgbgusf.html
2015-01-29 17:55 - 2012-11-12 13:09 - 00000000 ____D () C:\Users\Owner
2015-01-29 17:51 - 2014-11-01 19:50 - 00000000 ____D () C:\Program Files (x86)\Xero
2015-01-29 17:51 - 2012-11-02 10:10 - 00000000 ____D () C:\Program Files (x86)\Microsoft Works
2015-01-29 17:50 - 2012-11-09 13:17 - 00000000 ____D () C:\Program Files\windows xp mode
2015-01-29 17:46 - 2009-07-13 23:32 - 00000000 ____D () C:\Windows\system32\FxsTmp
2015-01-29 11:20 - 2014-09-21 15:24 - 00001415 _____ () C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-01-29 11:16 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2015-01-29 10:54 - 2012-11-07 12:54 - 00000000 ____D () C:\Users\Owner\AppData\Local\Google
2015-01-28 22:02 - 2013-01-22 09:37 - 00774592 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2015-01-28 18:07 - 2012-11-02 09:26 - 00000000 ____D () C:\Users\Owner\AppData\Local\Apple Computer
2015-01-28 17:49 - 2014-08-27 07:09 - 00000000 ____D () C:\ProgramData\ProductData
2015-01-28 17:49 - 2014-06-19 12:14 - 00000000 ____D () C:\ProgramData\Wondershare Video Converter Ultimate
2015-01-28 17:49 - 2014-05-29 18:11 - 00000000 ____D () C:\Program Files (x86)\iTunes
2015-01-28 17:49 - 2014-01-28 11:58 - 00000000 ____D () C:\Users\Owner\AppData\Local\CouponAlert_2p
2015-01-28 17:49 - 2013-09-09 14:39 - 00000000 ____D () C:\Users\Owner\AppData\Local\AOL Toolbar
2015-01-28 17:49 - 2013-04-04 21:01 - 00000000 ____D () C:\Users\Owner\AppData\Local\Lphant
2015-01-28 17:49 - 2013-02-11 12:11 - 00000000 ____D () C:\Users\Owner\AppData\Local\Microsoft Games
2015-01-28 17:49 - 2012-11-06 11:21 - 00000000 ____D () C:\Users\Owner\AppData\Roaming\Mozilla
2015-01-28 17:49 - 2012-11-03 17:36 - 00000000 ____D () C:\Users\Owner\AppData\Roaming\Epson
2015-01-28 17:49 - 2012-11-03 14:59 - 00000000 ____D () C:\Users\Owner\AppData\Roaming\AOL
2015-01-28 17:49 - 2012-11-03 08:18 - 00000000 ____D () C:\Users\Owner\AppData\Roaming\Roxio
2015-01-28 17:49 - 2012-11-02 09:26 - 00000000 ____D () C:\Users\Owner\AppData\Roaming\Apple Computer
2015-01-28 17:49 - 2012-11-02 09:23 - 00000000 ____D () C:\Users\Owner\AppData\Roaming\Adobe
2015-01-28 17:49 - 2012-10-31 14:14 - 00000000 ____D () C:\Users\Owner\AppData\Local\VirtualStore
2015-01-28 17:48 - 2014-12-26 11:52 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-01-28 17:48 - 2014-10-26 08:22 - 00000000 ____D () C:\Program Files (x86)\Cool Record Edit Pro
2015-01-28 17:48 - 2014-10-09 19:42 - 00000000 ____D () C:\Program Files (x86)\AVS4YOU
2015-01-28 17:48 - 2014-08-07 19:53 - 00000000 ____D () C:\Program Files (x86)\Sqirlz Water Reflections
2015-01-28 17:48 - 2014-07-18 08:23 - 00000000 ____D () C:\ProgramData\Logishrd
2015-01-28 17:48 - 2012-11-12 21:28 - 00000000 ____D () C:\Program Files (x86)\WavMan Pro
2015-01-28 17:48 - 2012-11-09 14:30 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2015-01-28 17:48 - 2012-11-06 09:27 - 00000000 ____D () C:\Program Files (x86)\NexusFont
2015-01-28 17:48 - 2012-11-03 14:58 - 00000000 ____D () C:\ProgramData\AOL
2015-01-28 17:47 - 2014-10-17 05:41 - 00000000 ____D () C:\Program Files\iPod
2015-01-28 17:47 - 2014-07-07 07:00 - 00000000 ____D () C:\Program Files (x86)\Audacity
2015-01-28 17:47 - 2014-06-20 07:34 - 00000000 ____D () C:\Program Files (x86)\Free Videos To DVD
2015-01-28 17:47 - 2014-03-02 08:17 - 00000000 ____D () C:\Program Files (x86)\ffdshow
2015-01-28 17:47 - 2013-03-07 16:57 - 00000000 ____D () C:\Program Files (x86)\InboxDollars
2015-01-28 17:47 - 2013-03-02 08:18 - 00000000 ____D () C:\Program Files\Microsoft Mouse and Keyboard Center
2015-01-28 17:47 - 2012-11-16 19:47 - 00001376 _____ () C:\Users\Owner\AppData\HELP_DECRYPT.TXT.gjhsaqj
2015-01-28 17:47 - 2012-11-13 09:45 - 00000000 ____D () C:\Program Files (x86)\7-Zip
2015-01-28 17:46 - 2012-11-16 19:47 - 00001376 _____ () C:\Users\Owner\AppData\Local\HELP_DECRYPT.TXT.gjhsaqj
2015-01-24 17:19 - 2012-11-02 09:23 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-01-24 17:19 - 2012-11-02 09:23 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-01-24 17:19 - 2012-11-02 09:23 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-01-23 08:31 - 2014-06-20 07:35 - 00000000 ____D () C:\Users\Owner\Documents\Movies2DVDProjects
2015-01-23 08:28 - 2013-04-19 08:52 - 00000000 ____D () C:\Users\Owner\Documents\EuphoriaScript-Regular
2015-01-22 12:06 - 2012-11-16 19:47 - 00000672 _____ () C:\sc-cleaner.TXT.gjhsaqj
2015-01-22 12:02 - 2014-07-09 18:16 - 00000000 ____D () C:\Users\Owner\AppData\Roaming\vlc
2015-01-22 11:57 - 2013-02-27 12:37 - 00000000 ____D () C:\Users\Owner\AppData\Roaming\Thinstall
2015-01-22 11:57 - 2012-11-03 17:11 - 00000000 ____D () C:\Users\Owner\AppData\Roaming\TPA Software
2015-01-22 11:53 - 2012-11-03 19:49 - 00000000 ____D () C:\Users\Owner\AppData\Roaming\Malwarebytes
2015-01-22 11:48 - 2014-09-28 15:38 - 00023552 ___SH () C:\Users\Owner\AppData\Roaming\Thumbs.db
2015-01-22 10:11 - 2014-06-12 09:55 - 00000000 ____D () C:\Program Files (x86)\Simple
2015-01-19 19:42 - 2014-05-02 11:37 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-01-19 19:42 - 2013-09-08 13:41 - 00000968 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\AOL Desktop 9.7.lnk
2015-01-19 19:42 - 2013-05-17 08:47 - 00129898 _____ () C:\install.log
2015-01-19 19:42 - 2012-11-09 14:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AOL
2015-01-19 19:36 - 2012-11-03 14:59 - 00058696 _____ (AOL Inc.) C:\Windows\SysWOW64\AOLParconLink.exe
2015-01-18 16:32 - 2014-06-12 09:56 - 00000000 ____D () C:\Users\Owner\AppData\Local\NSManager
2015-01-17 20:11 - 2014-08-12 06:15 - 00000000 ____D () C:\ProgramData\Package Cache
2015-01-17 19:47 - 2013-07-25 08:05 - 00000000 ____D () C:\Windows\system32\MRT
2015-01-17 19:43 - 2012-11-13 09:02 - 113365784 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-01-17 19:25 - 2014-08-27 07:10 - 00000000 ____D () C:\Users\Owner\AppData\Roaming\ProductData
2015-01-17 19:25 - 2014-08-27 07:08 - 00000000 ____D () C:\ProgramData\IObit
2015-01-17 19:25 - 2014-04-26 09:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ClipGrab
2015-01-17 19:25 - 2014-04-26 09:12 - 00000000 ____D () C:\Program Files (x86)\ClipGrab
2015-01-17 19:25 - 2012-11-02 09:23 - 00000000 ____D () C:\Windows\system32\Macromed
2015-01-17 19:25 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\Msdtc
2015-01-17 19:24 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\registration
2015-01-17 19:23 - 2013-02-05 21:20 - 00000000 ____D () C:\Program Files (x86)\Viewpoint
2015-01-17 19:23 - 2012-11-03 16:29 - 00000000 ____D () C:\Program Files (x86)\Jasc Software Inc
2015-01-17 19:23 - 2012-11-02 09:21 - 00000000 ____D () C:\Program Files (x86)\IObit
2015-01-16 19:04 - 2012-11-16 19:47 - 00051232 _____ () C:\TDSSKiller.3.0.0.42_16.01.2015_18.28.35_log.TXT.gjhsaqj
2015-01-16 16:10 - 2012-11-16 19:47 - 00001376 _____ () C:\ProgramData\HELP_DECRYPT.TXT.gjhsaqj
2015-01-14 18:32 - 2013-04-04 21:01 - 00000000 ____D () C:\Users\Owner\Documents\My Received Files
2015-01-10 22:55 - 2012-11-16 19:47 - 00000944 _____ () C:\TDSSKiller.3.0.0.42_10.01.2015_22.55.06_log.TXT.gjhsaqj
2015-01-10 22:50 - 2012-11-16 19:47 - 00184400 _____ () C:\TDSSKiller.3.0.0.42_10.01.2015_22.44.26_log.TXT.gjhsaqj
2015-01-10 22:36 - 2012-11-16 19:47 - 00001008 _____ () C:\TDSSKiller.3.0.0.42_10.01.2015_22.35.29_log.TXT.gjhsaqj
2015-01-09 18:26 - 2013-12-16 09:04 - 00000000 ____D () C:\Users\Owner\Documents\EMPTY FILE 1
2015-01-09 18:20 - 2014-04-15 10:30 - 00000000 ____D () C:\Users\Owner\AppData\Local\com
2015-01-08 09:55 - 2010-11-20 21:27 - 00298120 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2015-01-04 14:30 - 2009-07-13 23:08 - 00032548 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-12-31 07:15 - 2009-07-13 22:45 - 00432488 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-12-31 07:14 - 2012-11-12 13:47 - 00117432 _____ () C:\Users\Owner\AppData\Local\GDIPFONTCACHEV1.DAT
 
==================== Files in the root of some directories =======
 
2012-12-31 13:44 - 2001-07-13 06:04 - 3072000 _____ (Jasc Software Inc.) C:\Program Files\anim.exe
2014-07-18 08:10 - 2014-07-18 08:04 - 6826808 _____ (Driver-Soft Inc.                                            ) C:\Program Files (x86)\Driver_Genius_10_Professional_US_PPC.exe
2014-09-01 02:18 - 2014-09-01 02:18 - 0002086 _____ () C:\Users\Owner\AppData\Roaming\REFHBFG
2014-09-28 15:38 - 2015-01-22 11:48 - 0023552 ___SH () C:\Users\Owner\AppData\Roaming\Thumbs.db
2012-11-03 08:18 - 2014-03-05 10:23 - 0002412 _____ () C:\Users\Owner\AppData\Roaming\wklnhst.dat
2013-05-04 14:56 - 2013-05-04 15:15 - 0003584 _____ () C:\Users\Owner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-01-28 17:46 - 2015-01-28 17:46 - 0008528 _____ () C:\Users\Owner\AppData\Local\HELP_DECRYPT.HTML
2015-01-28 17:46 - 2015-01-28 17:46 - 0045504 _____ () C:\Users\Owner\AppData\Local\HELP_DECRYPT.PNG
2012-11-16 19:47 - 2015-01-28 17:46 - 0001376 _____ () C:\Users\Owner\AppData\Local\HELP_DECRYPT.TXT.gjhsaqj
2015-01-28 17:46 - 2015-01-28 17:46 - 0000272 _____ () C:\Users\Owner\AppData\Local\HELP_DECRYPT.URL
2013-08-15 18:35 - 2012-06-26 04:59 - 0940544 _____ (Apache Software Foundation) C:\Users\Owner\AppData\Local\log4cxx.dll
2014-10-16 12:57 - 2014-10-16 12:57 - 0000834 _____ () C:\Users\Owner\AppData\Local\recently-used.xbel
2015-01-16 16:10 - 2015-01-16 16:10 - 0008536 _____ () C:\ProgramData\HELP_DECRYPT.HTML
2015-01-16 16:10 - 2015-01-16 16:10 - 0045547 _____ () C:\ProgramData\HELP_DECRYPT.PNG
2012-11-16 19:47 - 2015-01-16 16:10 - 0001376 _____ () C:\ProgramData\HELP_DECRYPT.TXT.gjhsaqj
2015-01-16 16:10 - 2015-01-16 16:10 - 0000276 _____ () C:\ProgramData\HELP_DECRYPT.URL
2014-12-26 16:55 - 2015-01-29 18:16 - 0768194 _____ () C:\ProgramData\wgbgusf.html
 
Files to move or delete:
====================
C:\Users\Owner\CouponPrinter.exe
C:\Users\Owner\sf102.exe
 
 
Some content of TEMP:
====================
C:\Users\Owner\AppData\Local\Temp\avgnt.exe
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2014-06-26 14:51
 
==================== End Of Log ============================
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-01-2015
Ran by [removed] at 2015-01-30 08:17:38
Running from C:\Users\[removed]\Desktop
Boot Mode: Normal
==========================================================
 
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 13.0.0.111 - Adobe Systems Incorporated)
Adobe Flash Player 16 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 16.0.0.296 - Adobe Systems Incorporated)
Adobe Flash Player 16 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 16.0.0.296 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
AOL Toolbar (HKLM-x32\…\AOL Toolbar) (Version:  - AOL Inc.)
AOL Toolbar (HKU\S-1-5-21-3259929428-2434079444-325336261-1000\…\AOL Toolbar) (Version:  - )
AOL Uninstaller (Choose which Products to Remove) (HKLM-x32\…\AOL Uninstaller) (Version:  - AOL Inc.)
Apple Application Support (HKLM-x32\…\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}) (Version: 8.0.5.6 - Apple Inc.)
Audacity 2.0.5 (HKLM-x32\…\Audacity_is1) (Version: 2.0.5 - Audacity Team)
Avira (HKLM-x32\…\{2c18809c-4097-4b51-a4d0-3deade730ef3}) (Version: 1.1.29.22350 - Avira Operations & Co. KG)
Avira (x32 Version: 1.1.29.22350 - Avira Operations & Co. KG) Hidden
Avira Free Antivirus (HKLM-x32\…\Avira AntiVir Desktop) (Version: 14.0.7.468 - Avira)
AVS Video Editor 6.5 (HKLM-x32\…\AVS Video Editor_is1) (Version: 6.5.1.246 - Online Media Technologies Ltd.)
Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
ClipGrab 3.4.7 (HKLM-x32\…\{8A1033B0-EF33-4FB5-97A1-C47A7DCDD7E6}_is1) (Version:  - Philipp Schmieder Medien)
Compatibility Pack for the 2007 Office system (HKLM-x32\…\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Cool Record Edit Pro v8.8.3 (HKLM-x32\…\Cool Record Edit Pro_is1) (Version:  - Copyright(C) 2005-2014 CoolMedia, Inc.)
Coupon Printer for Windows (HKLM-x32\…\Coupon Printer for Windows5.0.1.3) (Version: 5.0.1.3 - Coupons.com Incorporated)
Download Updater (AOL Inc.) (HKLM-x32\…\SoftwareUpdUtility) (Version:  - AOL Inc.) <==== ATTENTION
Driver Booster (HKLM-x32\…\Driver Booster_is1) (Version: 1.5 - IObit)
Driver Support (HKLM-x32\…\{597FB4A5-DD86-4316-A410-7E8074CC2CCE}) (Version: 9.1.4.4 - PC Drivers Headquarters, LP)
Epson Event Manager (HKLM-x32\…\{FA9D303D-0FB2-49C7-9397-8E6B11EA892D}) (Version:  - )
EPSON Scan (HKLM-x32\…\EPSON Scanner) (Version:  - Seiko Epson Corporation)
EPSON WorkForce 545 Series Printer Uninstall (HKLM\…\EPSON WorkForce 545 Series) (Version:  - SEIKO EPSON Corporation)
eReg (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden
Free Videos To DVD V 4.0.0 (HKLM-x32\…\Free Videos To DVD_is1) (Version: 4.0.0.0 - Koyote soft)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
I. d. l. e . C. r. a. w. l. e. r (HKLM-x32\…\I. d. l. e . C. r. a. w. l. e. r) (Version: 98.0.0.445 - SADDLEBACK PROC LTD)
iCloud (HKLM\…\{309768A4-A2BB-4930-A5A2-8169678C9B4C}) (Version: 4.0.6.28 - Apple Inc.)
Inpaint 6.0 (HKLM\…\{2AEDC172-479F-47AE-8A48-A0524D4AED5B}_is1) (Version:  - Teorex)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.3517 - Intel Corporation)
Itibiti RTC (x32 Version: 0.0.1 - Itibiti Inc) Hidden
iTunes (HKLM\…\{2ABBBD91-91E5-4AD7-929A-FE15D1DC0576}) (Version: 12.0.1.26 - Apple Inc.)
Java 7 Update 71 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F03217071FF}) (Version: 7.0.710 - Oracle)
Junk Mail filter update (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Logitech SetPoint 6.65 (HKLM\…\SP6) (Version: 6.65.62 - Logitech)
Malwarebytes Anti-Malware version 2.0.4.1028 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Mouse and Keyboard Center (HKLM\…\Microsoft Mouse and Keyboard Center) (Version: 2.1.177.0 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-0409-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office PowerPoint Viewer 2007 (English) (HKLM-x32\…\{95120000-00AF-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3259929428-2434079444-325336261-1000\…\OneDriveSetup.exe) (Version: 17.0.4035.0328 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft VC9 runtime libraries (HKLM-x32\…\{AA027AE9-DD20-4677-AA72-D760A358320B}) (Version:  - )
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710F4C1C-CC18-4C49-8CBF-51240C89A1A2}) (Version:  - )
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Mozilla Firefox 31.0 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 31.0 (x86 en-US)) (Version: 31.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 31.0 - Mozilla)
QuickTime 7 (HKLM-x32\…\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7246 - Realtek Semiconductor Corp.)
Simple 1.0 (HKLM-x32\…\Simple) (Version: 1.0 - Simple)
Snap.Do (HKLM-x32\…\{F33C8209-E8E0-49C8-8D7E-363CD346C801}) (Version: 11.117.1.19710 - ReSoft Ltd.) <==== ATTENTION
Software Updater (HKLM-x32\…\{6DFBE8A2-CDBF-453E-B34C-32F202FCEE4C}) (Version: 4.2.1 - SEIKO EPSON CORPORATION)
Sqirlz Water Reflections (HKLM-x32\…\Sqirlz Water Reflections) (Version: 2.6 - xiberpix)
Surfing Protection (HKLM-x32\…\IObit Surfing Protection_is1) (Version: 1.2 - IObit)
Toolwiz Care (HKLM-x32\…\ToolwizCareFree) (Version: 3.1.0.5500 - ToolWiz Care)
Trojan Remover 6.9.1.2932 (HKLM-x32\…\Trojan Remover_is1) (Version: 6.9.1.2932 - Simply Super Software)
v9 uninstaller (HKLM-x32\…\v9 uninstaller) (Version:  - v9)
Visual Studio 2010 x64 Redistributables (HKLM\…\{21B133D6-5979-47F0-BE1C-F6A6B304693F}) (Version: 13.0.0.1 - AVG Technologies)
VLC media player 2.1.0 (HKLM-x32\…\VLC media player) (Version: 2.1.0 - VideoLAN)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
WOT for Internet Explorer (HKLM\…\{DCAEC601-735C-41AE-B84F-D792F09FB7D1}) (Version: 12.8.2.0 - WOT Services Oy)
Yahoo! Toolbar (HKLM-x32\…\Yahoo! Companion) (Version:  - Yahoo! Inc.)
 
==================== Custom CLSID (selected items): ==========================
 
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
 
CustomCLSID: HKU\S-1-5-21-3259929428-2434079444-325336261-1000_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\Owner\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3259929428-2434079444-325336261-1000_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\Owner\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3259929428-2434079444-325336261-1000_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\Owner\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3259929428-2434079444-325336261-1000_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\Owner\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3259929428-2434079444-325336261-1000_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Owner\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\FileSyncApi64.dll (Microsoft Corporation)
 
==================== Restore Points  =========================
 
29-01-2015 22:03:35 ComboFix created restore point
29-01-2015 22:06:03 Removed Should I Remove It
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 20:34 - 2015-01-29 21:13 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost
 
==================== Scheduled Tasks (whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
 
Task: {00FBB46A-0E22-418C-AA4D-559E424D9D9D} - System32\Tasks\{61591831-4A0C-4B83-97D3-5EEC04CCBD06} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {02540430-9BB7-4D99-B255-02B4BABEF86E} - System32\Tasks\Optimum_LogOn => C:\Program Files (x86)\Optimum PC Boost\OptimumPCBoost.exe <==== ATTENTION
Task: {08D89799-CEAA-490C-BE61-FD99B205F103} - System32\Tasks\Driver Support-RTMRules => C:\Program Files (x86)\Driver Support\Driver Support\DriverSupport.exe [2014-08-07] (PC Drivers Headquarters)
Task: {0A008589-F513-464A-9ABB-900960D40D35} - \RocketTab No Task File <==== ATTENTION
Task: {0CB99C9A-E4FF-4C06-AE1B-4A3EF96EC719} - System32\Tasks\{83E92520-9DF3-453E-84B8-EF29DA62691B} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {0F3294B1-D7AA-494C-B892-0F4EC4EF9988} - System32\Tasks\Driver Support-RTMScanRunOnce => C:\Program Files (x86)\Driver Support\Driver Support\DriverSupport.exe [2014-08-07] (PC Drivers Headquarters)
Task: {10016D23-F02F-4D08-B721-9F77B6997C55} - System32\Tasks\{2C337EC9-5C41-4AB6-A76F-9D8693CA1C79} => C:\Program Files (x86)\Jasc Software Inc\Paint Shop Pro 7\psp.exe [2001-07-13] (Jasc Software, Inc.)
Task: {122CE953-97CA-473B-A6B2-9956E3B1602C} - System32\Tasks\{1CED7CFA-2C4B-408C-98BF-361C70F509C5} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {132AAA73-44D5-462B-AA77-1EC3F16135B2} - System32\Tasks\Driver Support-RTMScan => C:\Program Files (x86)\Driver Support\Driver Support\DriverSupport.exe [2014-08-07] (PC Drivers Headquarters)
Task: {149BB75A-8C05-4DD8-9AA2-DAD532B87159} - System32\Tasks\{1975542B-357E-4DEC-8951-4A68801636F4} => C:\Users\Owner\Downloads\CouponPrinter.exe
Task: {15D96395-6500-4BD7-BB98-D4478616B880} - System32\Tasks\{24F46121-A521-4027-B46A-DDFBC8A5AF70} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {17147DEE-53AE-4452-B80F-99B0D533D9C0} - \IC Running Procedure No Task File <==== ATTENTION
Task: {17D1F95D-06E9-4D21-939C-CDDDC315B069} - System32\Tasks\{2653DBBA-5B60-47F3-AB20-3DB9376ABBD6} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {18E78768-7112-4EC4-9516-58963DBBA46D} - System32\Tasks\Optimum_Daily => C:\Program Files (x86)\Optimum PC Boost\OptimumPCBoost.exe <==== ATTENTION
Task: {1928B8C9-6A00-4536-B4ED-02A32163C444} - System32\Tasks\{B50A8EB7-E293-4EA5-88EF-EB975A0819D6} => C:\Program Files (x86)\Unlocker\Unlocker.exe
Task: {1A2E47A7-583A-4B83-84F9-84807F03CC04} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {1A9C0F84-408C-438A-9EF4-A368A9A958C6} - System32\Tasks\{3BD7749A-540A-435A-B9DD-4AEDD58D22CC} => pcalua.exe -a "C:\ProgramData\AOL Downloads\waol\0.4343.1028.1\waol-0.4343.1028.1.exe" -d C:\Users\Owner\Desktop
Task: {1AA26A32-E301-4FD6-8606-4A1DB6F31965} - System32\Tasks\{47B4CF36-A913-42C7-A85D-331963B0F3F3} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {1ADFE583-0532-48A3-ACA4-191CF9A9E3D4} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {1CE672C0-509C-4064-A6B6-A25DB404E933} - System32\Tasks\{4A965686-7CC8-47F7-A7A3-6C4AE241CDF8} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {203A4B67-334B-4706-93CB-A8EC6C7AAE8E} - System32\Tasks\{1DB427E2-985C-423B-A9F3-540492DB616A} => C:\Users\Owner\Downloads\CouponPrinter.exe
Task: {244310F0-3DD0-4E79-B558-6134CC82E601} - System32\Tasks\{6CAF3D22-CC6F-46D9-A1E2-1FF35E655CE5} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {2F5695ED-255B-4B16-936A-DBD31E56C63C} - System32\Tasks\{AE6D860C-077B-496E-8541-91CBFE4EE631} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {34E207A3-EBA4-4B4D-B5A0-2D789118948C} - System32\Tasks\{EC6740FB-AC03-4681-AB9E-BBDFEA09FB99} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {35862520-ED23-4F91-B177-A18236122E84} - System32\Tasks\LaunchApp => C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe <==== ATTENTION
Task: {4052269D-E25E-4594-8DD6-BE63D2BFDBF8} - System32\Tasks\Test TimeTrigger => C:\Users\Owner\AppData\Local\Temp\Runner.exe <==== ATTENTION
Task: {40B15FB1-63CD-4D54-9D56-C83F71DEBCCC} - System32\Tasks\{218031F7-E4A1-4AF5-B8C6-096C3F9E3EAB} => C:\Program Files (x86)\Jasc Software Inc\Paint Shop Pro 7\psp.exe [2001-07-13] (Jasc Software, Inc.)
Task: {4465369B-E70A-47A0-832B-1D474A7D6DE1} - System32\Tasks\{88C2FBD7-0DB3-4FAD-BF6D-87F760712270} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {467E8D3C-9AED-424A-B892-1E2A203B8FE2} - System32\Tasks\{0BD12BDF-CE99-4FDC-81E4-3A934224CC66} => pcalua.exe -a "C:\ProgramData\AOL Downloads\SUD4578\waol-0.4343.1028.1.exe" -d C:\Users\Owner\Desktop
Task: {4711FA90-444E-4D03-8349-64E93888BA6A} - System32\Tasks\{E214E131-9346-43D8-A762-077639F94357} => pcalua.exe -a "C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4EQMNXW8\vmp_full_installer_.exe" -d C:\Users\Owner\Desktop
Task: {474A7B96-C5C5-4615-93F7-032C415A1DCC} - System32\Tasks\PCSpeedClean_Popup => C:\Program Files (x86)\PC Speed Clean\Splash.exe
Task: {48E71030-7A56-4709-A3C9-BC15ABC0DE2B} - System32\Tasks\{4D681F21-167E-4543-B80B-14689D80E1D1} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {4D0D99BB-D893-4F89-BB53-A757B121AE28} - System32\Tasks\{4643D3E1-75D9-4A2B-BB5D-556DDB85C537} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {4E0E2CC4-B1BF-4BA6-8ED4-F0DCAF97EDA2} - \Microsoft\Windows\Maintenance\IC Update Procedure No Task File <==== ATTENTION
Task: {5151FA97-52BC-4872-A415-5BD0B967B412} - System32\Tasks\{15EC676E-6936-446B-B265-FFC2F7EA3FF0} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {527B0C13-2FE5-48EE-A846-7D0FEFDC019C} - System32\Tasks\{8A0D4B42-8C32-44BA-B4A9-AA0E2CAD23C0} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {531E9E9C-28AC-4329-B6BD-418736D01709} - System32\Tasks\{09FFA099-8C4E-4F2C-B9A0-8820AF2AD2B5} => C:\Users\Owner\Downloads\CouponPrinter.exe
Task: {54823467-2A9A-4042-B6FF-702AE5A37575} - System32\Tasks\{7F0E8740-D5FC-4DF0-A632-803BE44D159F} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {5507F091-5B30-4CCE-A312-DE1E2D50D940} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-02-11] (Google Inc.)
Task: {5517E204-C1AE-4E25-8C6C-5DE34EB752B8} - System32\Tasks\{3E517D30-BA5B-4BB6-98FE-4A7A641C2165} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {5C8FC5FD-FC7A-4DF3-9B15-11A1A5BB5055} - \RocketTab Update Task No Task File <==== ATTENTION
Task: {5D7F2D94-412C-405A-B1AE-0ABFB31A9B5B} - System32\Tasks\{68074224-678D-4E2A-9E0C-A6674DA8B177} => C:\Program Files (x86)\Unlocker\Unlocker.exe
Task: {5F02DB96-DE25-4BC6-804E-89498CCA6DA8} - System32\Tasks\{5A14B04A-7866-4CD8-9258-8C64CD773F29} => C:\Program Files (x86)\Jasc Software Inc\Paint Shop Pro 7\psp.exe [2001-07-13] (Jasc Software, Inc.)
Task: {6109EF54-662F-4ADC-9CD1-79474843348D} - System32\Tasks\{82BA4989-2E62-436C-A1C4-79D1C897F04C} => pcalua.exe -a C:\Users\Owner\AppData\Local\Temp\Temp1_R244364_RoxioBurn_v1.01_120B16F.zip\setup.exe
Task: {62C41622-8960-4167-A507-55497793BE59} - System32\Tasks\{E6E5F217-E6BD-41AF-A2F2-9F09CB87204E} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {651D6F5D-541B-44E6-B5AC-39A9DD3F403C} - System32\Tasks\{258455ED-B803-4A4F-93A1-34B127BDFB2D} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {6882A4F5-98FC-4C42-A5AA-15C3D86CE816} - System32\Tasks\{36F2116C-1265-491D-AB6D-A5A746EA3F2E} => C:\Program Files (x86)\Jasc Software Inc\Paint Shop Pro 7\psp.exe [2001-07-13] (Jasc Software, Inc.)
Task: {689B96F7-C36D-4768-B0C7-AC403B02D079} - System32\Tasks\{BDD8CB15-6C5F-4803-9B99-87E7C2FB4F16} => C:\Program Files (x86)\Jasc Software Inc\Paint Shop Pro 7\psp.exe [2001-07-13] (Jasc Software, Inc.)
Task: {699212CF-A13F-40F7-886B-849EE3E10735} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2013-01-29] (Microsoft)
Task: {6A19F92E-493D-4017-B1D9-372A105FA8D2} - System32\Tasks\ToolwizCareFree => C:\Program Files (x86)\ToolwizCareFree\ToolwizCares.exe [2014-08-03] (Toolwiz)
Task: {6AE14D4A-BA78-419B-951C-2437EA6DDB80} - System32\Tasks\{6A46DEE1-74FF-49C5-A6BE-F404552C854D} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {6BCA733C-AC35-4267-93B5-3601964602E4} - System32\Tasks\{053AED81-EF59-42F6-9364-574A55CEFB7F} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {70677101-E86A-4F52-97F8-616C237A6B7D} - \NSManager No Task File <==== ATTENTION
Task: {73705BA1-6F72-467B-B1D9-1F196933D300} - System32\Tasks\{3D58FD61-6064-4457-A26E-7691716CD26A} => C:\Program Files (x86)\AOL 9.0\aol.exe
Task: {75D8EF51-BAA2-40E5-BA9A-EBC53D19762A} - System32\Tasks\{F8415E98-B3BE-4967-A012-2C22342FF543} => C:\Program Files (x86)\Jasc Software Inc\Paint Shop Pro 7\psp.exe [2001-07-13] (Jasc Software, Inc.)
Task: {76928155-2E59-47AA-AF34-02AEA2D8A10C} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-01-29] (Microsoft Corporation)
Task: {77D2D51E-D357-4989-A7A4-BF011AB4DD5B} - System32\Tasks\{D09D5D11-02BE-4CE6-A3CC-D2CDC1F64EB0} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {7BADF2E2-C621-4434-94A7-2D9E21B1CA82} - System32\Tasks\{0857F79E-C26F-4E42-BE55-A3D400315715} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {7DCB0FC4-A856-4CFF-ABC4-2E4841E75885} - System32\Tasks\{1C318A78-3F48-44A6-9671-F0284EB24FE9} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {807849F7-6935-4E73-A558-F423EB25015F} - System32\Tasks\{BDF5A42C-CB21-45A2-BD24-A1ABBC8886F5} => C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe [2014-12-03] (Adobe Systems Incorporated)
Task: {84A52CE7-BFA4-4CE1-B624-F78D87FE0067} - System32\Tasks\{F18D6B04-4EF7-4462-BBC9-EF3EB87D8ADE} => C:\ProgramData\AOL Downloads\SUD4578\waol-0.4343.1028.1.exe [2013-04-18] (AOL Inc.)
Task: {84E02CDD-B286-4976-9E98-6F323E945AD5} - System32\Tasks\{3B0C417E-8223-49A2-AC22-921A18B0842B} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {8942407A-74BA-4808-A346-8DB1056775E8} - System32\Tasks\Driver Booster SkipUAC (Owner) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe [2014-08-06] (IObit)
Task: {8AD995B4-7289-4F96-B71D-B991B43B5E95} - System32\Tasks\SidebarExecute => C:\Program Files (x86)\Windows Sidebar\sidebar.exe [2010-11-20] (Microsoft Corporation)
Task: {8DD321DD-9889-48DE-8795-72E4B50E2957} - System32\Tasks\{B61AFCC7-E855-4523-80DB-854EFBFBB600} => pcalua.exe -a "C:\Users\Owner\Documents\My Documents\backups\Jasc Animation Shop v3.04 Crack.exe" -d "C:\Users\Owner\Documents\My Documents\backups"
Task: {91BF988E-925C-411B-9D49-27A55137CC12} - System32\Tasks\{1953AE5E-1C4D-4DFE-9727-1F350871F00C} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {942475D8-3A9B-489A-9DB3-2EAEE481B755} - System32\Tasks\{976C70B3-B968-47F2-A94F-E8244D9219A0} => C:\Program Files (x86)\Jasc Software Inc\Paint Shop Pro 7\psp.exe [2001-07-13] (Jasc Software, Inc.)
Task: {94ECC31B-9856-4DBD-ADA5-551F0BDDFA3F} - System32\Tasks\{14EFB176-7C85-4F6F-A589-B841994B8B7C} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {9B019086-B8DE-464C-B3EE-E9A99EA3D736} - System32\Tasks\{D860B9DC-5F8B-4686-9FE0-94EB1B6B5149} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {9BBB3BFE-E360-498B-A42A-F00EFFF43087} - System32\Tasks\{2BD41DB5-1622-408D-9AFE-AC879803947E} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {9DD66611-2A79-49C2-994B-505DA83ECAEC} - System32\Tasks\{2322F5D4-96A1-4E04-96A1-A9E6CF172847} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {9EAF68F8-5D5F-488B-B065-0CB96FD374B7} - System32\Tasks\{6656270B-7C76-4BA7-99C0-85F9EA55D176} => C:\Users\Owner\Downloads\CouponPrinter.exe
Task: {A0408F8A-13F4-4679-B348-CDF65E3DF206} - System32\Tasks\ShouldIRemoveIt_Notifications => C:\Program Files (x86)\Reason\Should I Remove It\ShouldIRemoveIt.exe
Task: {A05062A9-EC03-4378-BE4A-C2EB4A33A2C8} - System32\Tasks\{3EE1480B-5085-4689-A1BC-DCA7FA5E4CC4} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {A06FB55D-7EE7-4099-A2B9-72147D438F6E} - System32\Tasks\{423AF14D-5DFD-497E-A69E-00122E73FE16} => C:\Program Files (x86)\Jasc Software Inc\Paint Shop Pro 7\psp.exe [2001-07-13] (Jasc Software, Inc.)
Task: {A364BABB-962F-46CE-ABD4-7024EF3970A9} - System32\Tasks\{B90B208D-BBAD-4195-843B-B6D290DFCA8D} => pcalua.exe -a D:\AOLDNLD.exe -d D:\
Task: {AF98D158-A487-47A6-893E-6078C25BB6EC} - System32\Tasks\Driver Support-RTMUpdater => C:\Program Files (x86)\Driver Support\Driver Support\DriverSupport.exe [2014-08-07] (PC Drivers Headquarters)
Task: {B2494DBD-D3BC-4E85-A715-1302DF96CBA9} - System32\Tasks\{0AD17208-35DB-45D2-86CB-FC287E93C26E} => C:\Program Files (x86)\Jasc Software Inc\Paint Shop Pro 7\psp.exe [2001-07-13] (Jasc Software, Inc.)
Task: {BC4E2314-5284-4861-BF23-BA63CDF941EB} - System32\Tasks\{F428A962-838C-4655-B682-FD97EC80B894} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {C0B3EFDA-28D4-4AD5-BB82-CEE879703411} - System32\Tasks\{FA26F83A-F34F-439B-8BB1-1F3123F97EDB} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {CA7D2FAF-707B-4297-9E8D-30DCF9BAD449} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-01-24] (Adobe Systems Incorporated)
Task: {CBBE661D-5B9C-4224-B211-A0BDCD82A701} - System32\Tasks\{EB31CF20-7FE5-40E2-955F-89247A2ADF63} => C:\Program Files (x86)\AOL 9.0\aol.exe
Task: {CE918504-3C3D-4968-992C-1A4CBE38F538} - System32\Tasks\{02051100-F6C5-4D2D-A0A2-F7F80359385B} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {D473B51B-B530-4D95-85FA-CD0EFF24FF52} - System32\Tasks\{5AF9C177-832E-4044-A22C-FC1259396953} => C:\Program Files (x86)\Jasc Software Inc\Paint Shop Pro 7\psp.exe [2001-07-13] (Jasc Software, Inc.)
Task: {D67D7EC8-6AC7-4DBB-843E-D55D3C0963D8} - System32\Tasks\{B83E0305-76DB-4580-83C4-01E8A7BD1FA1} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {D789B35D-B67B-4B68-8399-404170363D31} - System32\Tasks\{C641C29E-FFF9-43A0-8FA7-EA6E0A2276A3} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {D97EA2ED-0055-4BB4-BA54-3DE3F47D4921} - System32\Tasks\PCSpeedClean_Start => C:\Program Files (x86)\PC Speed Clean\PCSpeedClean.exe
Task: {DD6B5E86-318C-4B45-B2D6-BFE777EBB23F} - System32\Tasks\{C80ED1D6-94E6-4208-8642-1ACE6E226045} => C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe [2014-12-03] (Adobe Systems Incorporated)
Task: {EBBC2B19-6676-4154-9E02-C4243D8991D2} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-02-11] (Google Inc.)
Task: {EE6D1CD5-B6D1-4463-98F0-DF2194281FC0} - System32\Tasks\{0DAFC39A-6D50-40CB-B9A1-C580A061F004} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {EE8B0FD1-C34A-49D4-89C3-41437ECF7A3F} - System32\Tasks\{05ADB97B-2003-46FF-8C63-D49A9F5766C8} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {F242ECFF-092C-4315-BB68-937F0B3926DF} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-01-29] (Microsoft Corporation)
Task: {F31737E5-84D5-427E-91F3-F5BE83C61491} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-01-29] (Microsoft Corporation)
Task: {F40D4B40-7F0F-4784-87AC-581F19D459FA} - System32\Tasks\{8084B7F4-0E14-4E72-8BDC-8BDC5F454073} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {F56FA8F8-6C24-44A0-BEB1-A0282C1CA7C7} - System32\Tasks\qfuzcuc => C:\Users\Owner\AppData\Local\Temp\qotxqyk.exe <==== ATTENTION
Task: {F9227C41-5649-472C-8C95-142F45B5929C} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-01-29] (Microsoft Corporation)
Task: {FDE9EF74-F3E0-4490-9F0F-F93B22B8EC1D} - System32\Tasks\{773F54BC-4E7E-4F04-A1EC-BD8D08720438} => C:\Program Files (x86)\Jasc Software Inc\Paint Shop Pro 7\psp.exe [2001-07-13] (Jasc Software, Inc.)
Task: {FF6425A2-E919-40F8-8AA9-EF1F875927AB} - System32\Tasks\{12A2DF10-56B4-4390-8335-E31946911575} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Loaded Modules (whitelisted) =============
 
2011-11-22 15:54 - 2011-01-07 02:57 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2012-11-02 10:29 - 2005-08-07 23:54 - 00167936 _____ () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
2014-10-11 12:05 - 2014-10-11 12:05 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2012-11-09 14:25 - 2009-10-28 10:38 - 00118784 _____ () c:\program files (x86)\common files\aol\1352492663\ee\services\proxyprovider\ver1_0_0_1\proxyprovider.dll
2014-01-20 13:17 - 2014-01-20 13:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-12-31 12:23 - 2014-12-31 12:23 - 00245760 _____ () C:\Program Files (x86)\Avira\My Avira\System.ComponentModel.Composition.dll
2014-10-17 05:28 - 2014-10-17 05:28 - 00169472 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\93182e9779b8be0f688fd0784df6d7fb\IsdiInterop.ni.dll
2011-11-22 15:57 - 2010-11-06 01:50 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
2014-09-16 12:17 - 2014-09-16 12:17 - 00048640 _____ () C:\Program Files (x86)\AOL Desktop 9.7c\zlib.dll
2014-09-16 12:17 - 2014-09-16 12:17 - 21151232 _____ () C:\Program Files (x86)\AOL Desktop 9.7c\libcef.dll
2014-09-16 12:17 - 2014-09-16 12:17 - 00648704 _____ () C:\Program Files (x86)\AOL Desktop 9.7c\libglesv2.dll
2014-09-16 12:17 - 2014-09-16 12:17 - 00122880 _____ () C:\Program Files (x86)\AOL Desktop 9.7c\libegl.dll
2014-09-16 12:17 - 2014-09-16 12:17 - 00094208 _____ () C:\Program Files (x86)\AOL Desktop 9.7c\Components\Tier2Svc.dll
2014-09-16 12:17 - 2014-09-16 12:17 - 00060928 _____ () C:\Program Files (x86)\AOL Desktop 9.7c\Components\DataSvcs.dll
2015-01-24 17:19 - 2015-01-24 17:19 - 16844976 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_296.dll
 
==================== Alternate Data Streams (whitelisted) =========
 
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
 
AlternateDataStreams: C:\ProgramData\Temp:CB0AACC9
 
==================== Safe Mode (whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SecureAssist => ""="service"
 
==================== EXE Association (whitelisted) =============
 
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
 
 
==================== MSCONFIG/TASK MANAGER disabled items =========
 
(Currently there is no automatic fix for this section.)
 
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: BDRegion => C:\Program Files (x86)\Cyberlink\Shared files\brs.exe
MSCONFIG\startupreg: GrooveMonitor => "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
MSCONFIG\startupreg: HotKeysCmds => C:\windows\system32\hkcmd.exe
MSCONFIG\startupreg: IgfxTray => C:\windows\system32\igfxtray.exe
MSCONFIG\startupreg: IObit Malware Fighter => "C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe" /autostart
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: Persistence => C:\windows\system32\igfxpers.exe
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: RemoteControl10 => "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
MSCONFIG\startupreg: ROC_roc_ssl_v12 => "C:\Program Files (x86)\AVG Secure Search\ROC_roc_ssl_v12.exe" / /PROMPT /CMPID=roc_ssl_v12
MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: vProt => "C:\Program Files (x86)\AVG Secure Search\vprot.exe"
 
========================= Accounts: ==========================
 
Administrator (S-1-5-21-3259929428-2434079444-325336261-500 - Administrator - Disabled)
Guest (S-1-5-21-3259929428-2434079444-325336261-501 - Limited - Enabled)
HomeGroupUser$ (S-1-5-21-3259929428-2434079444-325336261-1004 - Limited - Enabled)
Owner (S-1-5-21-3259929428-2434079444-325336261-1000 - Administrator - Enabled) => C:\Users\Owner
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (01/30/2015 07:52:39 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (01/29/2015 10:10:46 PM) (Source: RasClient) (EventID: 20227) (User: )
Description: CoId={9CEFFB1B-DB14-4135-B420-3F937D34D626}: The user Owner-PC\Owner dialed a connection named Broadband Connection which has failed. The error code returned on failure is 651.
 
Error: (01/29/2015 10:10:08 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: iexplore.exe, version: 10.0.9200.17183, time stamp: 0x546ebbc7
Faulting module name: aoltb.dll, version: 5.74.1.10053, time stamp: 0x52f4ec5d
Exception code: 0xc0000005
Fault offset: 0x00000000000fa9ff
Faulting process id: 0xf5c
Faulting application start time: 0xiexplore.exe0
Faulting application path: iexplore.exe1
Faulting module path: iexplore.exe2
Report Id: iexplore.exe3
 
Error: (01/29/2015 09:15:09 PM) (Source: Avira Antivirus) (EventID: 4122) (User: NT AUTHORITY)
Description: Unable to load file AvShadow. 
Returned error code: 0x3fa
 
Error: (01/29/2015 09:14:21 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (01/29/2015 08:53:02 PM) (Source: RasClient) (EventID: 20227) (User: )
Description: CoId={0AE46BA9-9C71-466C-82BA-21A3C7934C98}: The user Owner-PC\Owner dialed a connection named Broadband Connection which has failed. The error code returned on failure is 651.
 
Error: (01/29/2015 08:52:39 PM) (Source: RasClient) (EventID: 20227) (User: )
Description: CoId={8E7217A8-F36F-4A98-BB59-0545E2F92EC7}: The user Owner-PC\Owner dialed a connection named Broadband Connection which has failed. The error code returned on failure is 651.
 
Error: (01/29/2015 08:43:53 PM) (Source: RasClient) (EventID: 20227) (User: )
Description: CoId={0444A9E8-1476-460F-A6CA-873FEA253163}: The user Owner-PC\Owner dialed a connection named Broadband Connection which has failed. The error code returned on failure is 651.
 
Error: (01/29/2015 08:43:09 PM) (Source: System Restore) (EventID: 8209) (User: )
Description: System Restore did not run because the system was restarted, lost power, or stopped responding. Additional information: (Removed SmartApp).
 
Error: (01/29/2015 08:39:07 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
 
System errors:
=============
Error: (01/30/2015 07:51:44 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Net.Tcp Port Sharing Service service failed to start due to the following error: 
%%1053
 
Error: (01/30/2015 07:51:44 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Net.Tcp Port Sharing Service service to connect.
 
Error: (01/30/2015 07:51:13 AM) (Source: Service Control Manager) (EventID: 7003) (User: )
Description: The Net.Tcp Listener Adapter service depends the following service: was. This service might not be installed.
 
Error: (01/30/2015 07:51:13 AM) (Source: Service Control Manager) (EventID: 7003) (User: )
Description: The Net.Pipe Listener Adapter service depends the following service: was. This service might not be installed.
 
Error: (01/30/2015 07:51:13 AM) (Source: Service Control Manager) (EventID: 7003) (User: )
Description: The Net.Msmq Listener Adapter service depends the following service: msmq. This service might not be installed.
 
Error: (01/30/2015 07:51:01 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Windows Presentation Foundation Font Cache 3.0.0.0 service failed to start due to the following error: 
%%1053
 
Error: (01/30/2015 07:51:01 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Windows Presentation Foundation Font Cache 3.0.0.0 service to connect.
 
Error: (01/30/2015 07:50:12 AM) (Source: NETLOGON) (EventID: 3095) (User: )
Description: This computer is configured as a member of a workgroup, not as
a member of a domain. The Netlogon service does not need to run in this
configuration.
 
Error: (01/29/2015 09:49:01 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {3C5E2B20-B911-44E2-A2DD-9F05E7B5E775}
 
Error: (01/29/2015 09:17:13 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Windows Presentation Foundation Font Cache 3.0.0.0 service failed to start due to the following error: 
%%31
 
 
Microsoft Office Sessions:
=========================
 
CodeIntegrity Errors:
===================================
  Date: 2015-01-29 21:04:22.121
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2015-01-29 21:04:22.090
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2014-08-03 15:02:35.397
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\wanatw64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2014-08-03 15:02:35.304
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\wanatw64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2014-08-03 09:16:06.587
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\wanatw64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2014-08-03 09:16:06.556
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\wanatw64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2014-08-02 19:35:22.736
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\wanatw64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2014-08-02 19:35:22.642
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\wanatw64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2014-08-01 18:41:33.772
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\wanatw64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2014-08-01 18:41:33.740
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\wanatw64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
 
==================== Memory info =========================== 
 
Processor: Intel(R) Core(TM) i7-2600 CPU @ 3.40GHz
Percentage of memory in use: 15%
Total physical RAM: 16301.12 MB
Available physical RAM: 13697.63 MB
Total Pagefile: 32600.42 MB
Available Pagefile: 29855.88 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB
 
==================== Drives ================================
 
Drive c: (OS) (Fixed) (Total:1862.92 GB) (Free:1610.92 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 4C5BD17E)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=1862.9 GB) - (Type=07 NTFS)
 
==================== End Of Log ============================

Hello, 
 
Unfortunately, due to the nature of infections present on this machine, I must issue the following warning. 
Furthermore, you've been infected by two different file encrypting ransomware infections - CryptoWall 3.0 and CTB Locker. This makes recovery of your files extremely unlikely I'm afraid. 
 
Please let me know how you wish to proceed in regards to the backdoor warning below. 
Either way, we can still attempt recovery of your files, but I need to know now if you wish to clean the infections or reformat/reinstall. 
 

[external image: goGMWSt.gif]BACKDOOR WARNING
 
——————————
 
One or more of the identified infections is known to use a backdoor, that allows attackers to remotely control your computer, download/execute files and steal system, financial & personal information.
 
If your computer has been used for online banking, has credit card information or other sensitive data, using a non-infected computer/device you should immediately change all account information (including those used for Email, eBay, Paypal, online forums, etc).
 
Banking and credit card institutions should be notified of the possible security breach. Please read the following article for more information: How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?
 
Whilst the identified infection(s) can be removed, there is no way to guarantee the trustworthiness of your computer unless you reformat your Hard Drive and reinstall your Operating System. This is due to the nature of the infection, which allows a remote attacker to make any number of modifications. Many experts in the security community believe that once infected with this type of malware, the best course of action is to reformat/reinstall. Please read the following articles for more information.

  • When should I re-format? How should I reinstall?
  • Help: I Got Hacked. Now What Do I Do?
  • Where to draw the line? When to recommend a format and reinstall?
You now have the choice between cleaning the infection(s) present or reformatting your computer. Ultimately, the decision is personal, and what you're most comfortable with. Once you've read the articles linked above, let me know if you have any questions, and how you wish to proceed.

I will reformat obviously because it sounds like even If I get rid of the Malware, whatever they use to Infiltrate my system would still be there.

The question is do you think together you & I can really do this? Or should I take this In to my repair guy & explain what happened & let him fix it?

In other words, Adam, how difficult would this be. I have my Microsoft disc to reinstall. What else could I need. I guess I need to read the links above to get my head around this.

Thank you again,

Marina22

Hi Adam,
Just to be clear, it IS safe to save files from My Docs, right? What my husband is afraid of is that he is thinking the virus is in the files somewhere. I told him it was on the hard drive. Correct?
Hi again Adam. I read & printed the instructions above for myself. One question… In the instructions it says after you are done clean installing Win 7 you need to reinstall all drivers. How do I do this? I don' t have a driver disc. Can I download them from a website & burn it to a disc for myself? Where do I get them from?

TYIA,
Marina22
Ok, I reinstalled windows & also found my drivers folder. I will have to continue tomorrow as I am taking a break after being on the computer since 7:30 this morning. I spent most of the time trying to find another place to save my files.

Goodnight :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI