This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Virus Help [Solved]

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I had a message come up the other day saying My computer was infected with a virus and It wouldn't allow me to close the message.  A co-worker sent me a portion of a clip from a movie which must have been infected as they usually are. 

 

I didn't have symptoms right away, but then when I went to shut down I noticed my computer installed 21 windows updates which was odd.  Upon powering on my computer, it wouldn't boot up.  I tried to start it in safe mode and it eventually mentioned reverting windows updates and started up in the regular mode.

 

 

I ran combofix, the results are posted below.

 

What else can I run?

 

ComboFix 15-02-09.01 - stevej89 02/11/2015  18:41:28.6.2 - x64
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.1.1033.18.2811.680 [GMT -5:00]
Running from: c:\users\[removed]\Documents\ComboFix.exe
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\stevej89\AppData\Local\Microsoft\Windows\Temporary Internet Files\WebConnect_iels
.
.
(((((((((((((((((((((((((   Files Created from 2015-01-11 to 2015-02-11  )))))))))))))))))))))))))))))))
.
.
2015-02-11 23:58 . 2015-02-11 23:58 ——– d—–w- c:\users\Public\AppData\Local\temp
2015-02-11 23:58 . 2015-02-11 23:58 ——– d—–w- c:\users\Default\AppData\Local\temp
2015-02-11 23:58 . 2015-02-11 23:58 ——– d—–w- c:\users\Administrator\AppData\Local\temp
2015-02-11 05:07 . 2015-02-11 05:07 75888 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F5A3E96A-768D-4EC2-BBB5-207B839655D7}\offreg.dll
2015-02-11 03:45 . 2014-12-02 10:26 11870360 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F5A3E96A-768D-4EC2-BBB5-207B839655D7}\mpengine.dll
2015-01-16 22:23 . 2014-12-06 04:17 303616 —-a-w- c:\windows\system32\nlasvc.dll
2015-01-16 22:23 . 2014-12-06 03:50 52224 —-a-w- c:\windows\SysWow64\nlaapi.dll
2015-01-16 22:23 . 2014-12-06 03:50 156672 —-a-w- c:\windows\SysWow64\ncsi.dll
2015-01-16 22:23 . 2014-12-12 05:35 5553592 —-a-w- c:\windows\system32\ntoskrnl.exe
2015-01-16 22:23 . 2014-12-12 05:11 3971512 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe
2015-01-16 22:23 . 2014-12-12 05:31 503808 —-a-w- c:\windows\system32\srcore.dll
2015-01-16 22:23 . 2014-12-12 05:11 3916728 —-a-w- c:\windows\SysWow64\ntoskrnl.exe
2015-01-16 22:23 . 2014-12-12 05:31 50176 —-a-w- c:\windows\system32\srclient.dll
2015-01-16 22:23 . 2014-12-12 05:31 296960 —-a-w- c:\windows\system32\rstrui.exe
2015-01-16 22:23 . 2014-12-12 05:07 43008 —-a-w- c:\windows\SysWow64\srclient.dll
2015-01-15 02:08 . 2014-12-11 17:47 52736 —-a-w- c:\windows\system32\TSWbPrxy.exe
2015-01-15 02:08 . 2014-12-19 03:06 210432 —-a-w- c:\windows\system32\profsvc.dll
2015-01-15 02:08 . 2014-12-19 01:46 141312 —-a-w- c:\windows\system32\drivers\mrxdav.sys
2015-01-14 00:17 . 2015-01-14 00:17 18479800 —-a-w- c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\MSO.DLL
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-01-06 09:36 . 2010-12-28 18:35 298120 ——w- c:\windows\system32\MpSigStub.exe
2014-12-13 05:09 . 2014-12-19 04:45 144384 —-a-w- c:\windows\system32\ieUnatt.exe
2014-12-13 03:33 . 2014-12-19 04:45 115712 —-a-w- c:\windows\SysWow64\ieUnatt.exe
2014-12-04 02:50 . 2014-12-11 03:09 413184 —-a-w- c:\windows\system32\generaltel.dll
2014-12-04 02:50 . 2014-12-11 03:09 741376 —-a-w- c:\windows\system32\invagent.dll
2014-12-04 02:50 . 2014-12-11 03:09 396800 —-a-w- c:\windows\system32\devinv.dll
2014-12-04 02:50 . 2014-12-11 03:09 830976 —-a-w- c:\windows\system32\appraiser.dll
2014-12-04 02:50 . 2014-12-11 03:09 192000 —-a-w- c:\windows\system32\aepic.dll
2014-12-04 02:50 . 2014-12-11 03:09 227328 —-a-w- c:\windows\system32\aepdu.dll
2014-12-04 02:44 . 2014-12-11 03:09 1083392 —-a-w- c:\windows\system32\aeinv.dll
2014-12-01 23:28 . 2014-12-11 03:09 1232040 —-a-w- c:\windows\system32\aitstatic.exe
2014-11-27 01:43 . 2014-12-11 03:09 389296 —-a-w- c:\windows\system32\iedkcs32.dll
2014-11-22 03:13 . 2014-12-11 03:08 25059840 —-a-w- c:\windows\system32\mshtml.dll
2014-11-22 03:06 . 2014-12-11 03:09 2724864 —-a-w- c:\windows\system32\mshtml.tlb
2014-11-22 03:06 . 2014-12-11 03:09 4096 —-a-w- c:\windows\system32\ieetwcollectorres.dll
2014-11-22 02:50 . 2014-12-11 03:09 66560 —-a-w- c:\windows\system32\iesetup.dll
2014-11-22 02:50 . 2014-12-11 03:08 580096 —-a-w- c:\windows\system32\vbscript.dll
2014-11-22 02:49 . 2014-12-11 03:09 48640 —-a-w- c:\windows\system32\ieetwproxystub.dll
2014-11-22 02:49 . 2014-12-11 03:09 2885120 —-a-w- c:\windows\system32\iertutil.dll
2014-11-22 02:48 . 2014-12-11 03:08 88064 —-a-w- c:\windows\system32\MshtmlDac.dll
2014-11-22 02:41 . 2014-12-11 03:08 54784 —-a-w- c:\windows\system32\jsproxy.dll
2014-11-22 02:40 . 2014-12-11 03:09 34304 —-a-w- c:\windows\system32\iernonce.dll
2014-11-22 02:37 . 2014-12-11 03:08 633856 —-a-w- c:\windows\system32\ieui.dll
2014-11-22 02:35 . 2014-12-11 03:09 114688 —-a-w- c:\windows\system32\ieetwcollector.exe
2014-11-22 02:34 . 2014-12-11 03:08 814080 —-a-w- c:\windows\system32\jscript9diag.dll
2014-11-22 02:34 . 2014-12-11 03:08 6039552 —-a-w- c:\windows\system32\jscript9.dll
2014-11-22 02:26 . 2014-12-11 03:09 968704 —-a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2014-11-22 02:22 . 2014-12-11 03:08 490496 —-a-w- c:\windows\system32\dxtmsft.dll
2014-11-22 02:20 . 2014-12-11 03:09 2724864 —-a-w- c:\windows\SysWow64\mshtml.tlb
2014-11-22 02:14 . 2014-12-11 03:09 77824 —-a-w- c:\windows\system32\JavaScriptCollectionAgent.dll
2014-11-22 02:09 . 2014-12-11 03:08 199680 —-a-w- c:\windows\system32\msrating.dll
2014-11-22 02:08 . 2014-12-11 03:08 92160 —-a-w- c:\windows\system32\mshtmled.dll
2014-11-22 02:07 . 2014-12-11 03:09 501248 —-a-w- c:\windows\SysWow64\vbscript.dll
2014-11-22 02:07 . 2014-12-11 03:09 62464 —-a-w- c:\windows\SysWow64\iesetup.dll
2014-11-22 02:06 . 2014-12-11 03:09 47616 —-a-w- c:\windows\SysWow64\ieetwproxystub.dll
2014-11-22 02:05 . 2014-12-11 03:08 64000 —-a-w- c:\windows\SysWow64\MshtmlDac.dll
2014-11-22 02:05 . 2014-12-11 03:09 316928 —-a-w- c:\windows\system32\dxtrans.dll
2014-11-22 01:54 . 2014-12-11 03:09 620032 —-a-w- c:\windows\SysWow64\jscript9diag.dll
2014-11-22 01:49 . 2014-12-11 03:09 718848 —-a-w- c:\windows\system32\ie4uinit.exe
2014-11-22 01:49 . 2014-12-11 03:09 800768 —-a-w- c:\windows\system32\msfeeds.dll
2014-11-22 01:47 . 2014-12-11 03:08 1359360 —-a-w- c:\windows\system32\mshtmlmedia.dll
2014-11-22 01:46 . 2014-12-11 03:09 2125312 —-a-w- c:\windows\system32\inetcpl.cpl
2014-11-22 01:43 . 2014-12-11 03:08 14412800 —-a-w- c:\windows\system32\ieframe.dll
2014-11-22 01:40 . 2014-12-11 03:09 60416 —-a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll
2014-11-22 01:29 . 2014-12-11 03:09 4299264 —-a-w- c:\windows\SysWow64\jscript9.dll
2014-11-22 01:28 . 2014-12-11 03:08 2358272 —-a-w- c:\windows\system32\wininet.dll
2014-11-22 01:22 . 2014-12-11 03:09 2052096 —-a-w- c:\windows\SysWow64\inetcpl.cpl
2014-11-22 01:21 . 2014-12-11 03:09 1155072 —-a-w- c:\windows\SysWow64\mshtmlmedia.dll
2014-11-22 01:15 . 2014-12-11 03:09 1548288 —-a-w- c:\windows\system32\urlmon.dll
2014-11-22 01:03 . 2014-12-11 03:09 800768 —-a-w- c:\windows\system32\ieapfltr.dll
2014-11-22 01:00 . 2014-12-11 03:08 1888256 —-a-w- c:\windows\SysWow64\wininet.dll
2014-11-18 19:56 . 2014-11-18 19:56 1202848 —-a-w- c:\windows\SysWow64\FM20.DLL
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim"="c:\program files (x86)\AIM\aim.exe" [2011-01-05 4321112]
"Nike+ Connect"="c:\users\stevej89\AppData\Local\Nike\Nike+ Connect\Nike+ Connect daemon.exe" [2013-11-01 70656]
"AOL Fast Start"="c:\program files (x86)\AOL Desktop 9.6\AOL.EXE" [2010-11-24 42320]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-06-17 98304]
"Microsoft Default Manager"="c:\program files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2010-05-10 439568]
"HP Quick Launch"="c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe" [2010-06-30 602168]
"Norton Online Backup"="c:\program files (x86)\Symantec\Norton Online Backup\NOBuClient.exe" [2010-06-01 1155928]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"HostManager"="c:\program files (x86)\Common Files\AOL\1293562345\ee\AOLSoftware.exe" [2010-03-08 41800]
"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"hpqSRMon"="c:\program files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-07-22 150528]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-04-14 421160]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"Nike+ Connect"="c:\program files (x86)\Nike\Nike+ Connect\Nike+ Connect daemon.exe" [2014-04-09 71680]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-9-20 270336]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableVirtualization"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys;c:\windows\SYSNATIVE\DRIVERS\netw5v64.sys [x]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x]
R3 S3XXx64;SCR3xx USB SmartCardReader64;c:\windows\system32\DRIVERS\S3XXx64.sys;c:\windows\SYSNATIVE\DRIVERS\S3XXx64.sys [x]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTAZL6.SYS [x]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTDPV6.SYS [x]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTCNXT6.SYS [x]
R3 SwitchBoard;Adobe SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys;c:\windows\SYSNATIVE\DRIVERS\yk62x64.sys [x]
S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 BitGuard;BitGuard;c:\programdata\BitGuard\2.7.1832.68\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe;c:\programdata\BitGuard\2.7.1832.68\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe [x]
S2 CinemaNow Service;CinemaNow Service;c:\program files (x86)\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe;c:\program files (x86)\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe [x]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x]
S2 HP Wireless Assistant Service;HP Wireless Assistant Service;c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe;c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [x]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [x]
S2 HPWMISVC;HPWMISVC;c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe;c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [x]
S2 NOBU;Norton Online Backup;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE [x]
S2 RtVOsdService;RtVOsdService Installer;c:\program files\Realtek\RtVOsd\RtVOsdService.exe;c:\program files\Realtek\RtVOsd\RtVOsdService.exe [x]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ    hpqcxs08 hpqddsvc
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{2D46B6DC-2207-486B-B523-A557E6D54B47}]
start [BU]
.
Contents of the 'Scheduled Tasks' folder
.
2015-02-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3891086701-1241933595-968087049-1001Core.job
- c:\users\stevej89\AppData\Local\Google\Update\GoogleUpdate.exe [2012-08-30 17:27]
.
2015-02-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3891086701-1241933595-968087049-1001UA.job
- c:\users\stevej89\AppData\Local\Google\Update\GoogleUpdate.exe [2012-08-30 17:27]
.
2015-02-09 c:\windows\Tasks\HPCeeScheduleForstevej89.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-01-05 10:53]
.
.
——— X64 Entries ———–
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2010-05-26 6245408]
"HPWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe" [2010-06-18 8192]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"NCPluginUpdater"="c:\program files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" [2015-01-28 21720]
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~3\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-10 - (no file)
AddRemove-SoftwareUpdUtility - c:\program files (x86)\Common Files\Software Update Utility\uninstall.exe
.
.
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_12_0_0_70_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_12_0_0_70_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_12_0_0_70_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_12_0_0_70_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_70.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.12"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_70.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_70.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_70.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2015-02-11  19:03:02
ComboFix-quarantined-files.txt  2015-02-12 00:03
ComboFix2.txt  2013-10-19 15:50
ComboFix3.txt  2013-10-02 00:18
ComboFix4.txt  2013-10-01 01:54
ComboFix5.txt  2014-02-13 02:42
.
Pre-Run: 174,339,735,552 bytes free
Post-Run: 175,012,524,032 bytes free
.
- - End Of File - - 12CD28A45A84A2553AF8745C81787EAD
 

 

Hi phillysportz,

My name is OCD. I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • Copy and Paste logs directly into the reply window. DO NOT attach the logs unless specifically instructed to do so.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.

DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

Please stay with this topic until I let you know that your system appears to be "All Clear"

Important: All tools MUST be run from the Desktop.

=========================

[external image: bullseye_zpse9eaf36e.gif] Security Check

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
=========================

[external image: bullseye_zpse9eaf36e.gif] aswMBR

Download aswMBR.exe and save it to your desktop.
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click Scan
  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.
=========================

[external image: bullseye_zpse9eaf36e.gif] Download Farbar Recovery Scan Tool and save to your desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
  • Right click and select "Run as Administrator" to run it. When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply
=========================

In your next post please provide the following:
  • checkup.txt
  • aswMBR.txt
  • attach MBR.zip
  • FRST.txt
  • Addition.txt
Results of screen317's Security Check version 0.99.79 Windows 7 Service Pack 1 x64 (UAC is disabled!) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Windows Firewall Enabled! WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:````````` Java(TM) 6 Update 30 Java version out of Date! Adobe Reader 9 Adobe Reader out of Date! Google Chrome 40.0.2214.111 Google Chrome 40.0.2214.94 ````````Process Check: objlist.exe by Laurent```````` Symantec Norton Online Backup NOBuAgent.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log``````````````````````
aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-12-18 20:43:14 —————————– 20:43:14.257 OS Version: Windows x64 6.1.7601 Service Pack 1 20:43:14.257 Number of processors: 2 586 0x603 20:43:14.258 ComputerName: STEVEJ89-HP UserName: stevej89 20:43:20.594 Initialize success 20:43:38.248 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000064 20:43:38.250 Disk 0 Vendor: TOSHIBA_ GJ00 Size: 305245MB BusType: 11 20:43:40.305 Disk 0 MBR read successfully 20:43:40.308 Disk 0 MBR scan 20:43:40.310 Disk 0 unknown MBR code 20:43:40.315 Service scanning 20:43:44.330 Modules scanning 20:43:44.333 Disk 0 trace - called modules: 20:43:44.372 ntoskrnl.exe CLASSPNP.SYS disk.sys amdxata.sys storport.sys hal.dll amdsata.sys 20:43:44.375 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80031e6060] 20:43:44.379 3 CLASSPNP.SYS[fffff88001b4943f] -> nt!IofCallDriver -> [0xfffffa80021dab80] 20:43:44.383 5 amdxata.sys[fffff8800111e7a8] -> nt!IofCallDriver -> \Device\00000064[0xfffffa8003186060] 20:43:44.387 Scan finished successfully 20:44:52.268 Disk 0 MBR has been saved successfully to "C:\Users\stevej89\Documents\MBR.dat" 20:44:52.275 The log file has been saved successfully to "C:\Users\stevej89\Documents\aswMBR.txt" aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software Run date: 2013-09-23 22:55:11 —————————– 22:55:11.892 OS Version: Windows x64 6.1.7601 Service Pack 1 22:55:11.892 Number of processors: 2 586 0x603 22:55:11.892 ComputerName: STEVEJ89-HP UserName: stevej89 22:55:15.558 Initialize success 22:58:26.868 AVAST engine defs: 13092301 22:58:45.425 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000064 22:58:45.431 Disk 0 Vendor: TOSHIBA_ GJ00 Size: 305245MB BusType: 11 22:58:46.212 Disk 0 MBR read successfully 22:58:46.218 Disk 0 MBR scan 22:58:46.230 Disk 0 unknown MBR code 22:58:46.365 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 199 MB offset 2048 22:58:46.429 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 287356 MB offset 409600 22:58:46.476 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 17585 MB offset 588914688 22:58:46.539 Disk 0 Partition 4 00 0C FAT32 LBA MSDOS5.0 103 MB offset 624928768 22:58:47.270 Disk 0 scanning C:\Windows\system32\drivers 22:59:40.285 Service scanning 23:01:05.337 Modules scanning 23:01:05.357 Disk 0 trace - called modules: 23:01:05.382 ntoskrnl.exe CLASSPNP.SYS disk.sys amdxata.sys storport.sys hal.dll amdsata.sys 23:01:05.395 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80031ec060] 23:01:05.408 3 CLASSPNP.SYS[fffff8800145143f] -> nt!IofCallDriver -> [0xfffffa8003191450] 23:01:05.421 5 amdxata.sys[fffff880010707a8] -> nt!IofCallDriver -> \Device\00000064[0xfffffa8003074420] 23:01:07.194 AVAST engine scan C:\Windows 23:01:11.861 AVAST engine scan C:\Windows\system32 23:07:33.311 AVAST engine scan C:\Windows\system32\drivers 23:07:56.438 AVAST engine scan C:\Users\stevej89 23:36:49.085 File: C:\Users\stevej89\Downloads\dds.scr **INFECTED** Win32:Malware-gen 23:44:38.755 AVAST engine scan C:\ProgramData 23:58:04.933 Scan finished successfully 00:02:03.118 Disk 0 MBR has been saved successfully to "C:\Users\stevej89\Documents\MBR.dat" 00:02:03.164 The log file has been saved successfully to "C:\Users\stevej89\Documents\aswMBR.txt" aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software Run date: 2015-02-12 21:30:56 —————————– 21:30:56.301 OS Version: Windows x64 6.1.7601 Service Pack 1 21:30:56.301 Number of processors: 2 586 0x603 21:30:56.301 ComputerName: STEVEJ89-HP UserName: stevej89 21:30:57.341 Initialize success 21:30:57.551 VM: initialized successfully 21:30:57.551 VM: Amd CPU supported 21:34:45.176 AVAST engine defs: 15021201 21:38:50.566 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000005c 21:38:50.576 Disk 0 Vendor: TOSHIBA_ GJ00 Size: 305245MB BusType: 11 21:38:50.706 Disk 0 MBR read successfully 21:38:50.716 Disk 0 MBR scan 21:38:50.726 Disk 0 unknown MBR code 21:38:50.736 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 199 MB offset 2048 21:38:50.746 Disk 0 default boot code 21:38:50.766 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 287356 MB offset 409600 21:38:50.806 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 17585 MB offset 588914688 21:38:50.836 Disk 0 Partition 4 00 0C FAT32 LBA MSDOS5.0 103 MB offset 624928768 21:38:51.004 Disk 0 scanning C:\Windows\system32\drivers 21:39:09.785 Service scanning 21:40:17.174 Modules scanning 21:40:17.184 Disk 0 trace - called modules: 21:40:17.234 ntoskrnl.exe CLASSPNP.SYS disk.sys amdxata.sys storport.sys hal.dll amdsata.sys 21:40:17.244 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80031dc6e0] 21:40:17.254 3 CLASSPNP.SYS[fffff8800195543f] -> nt!IofCallDriver -> [0xfffffa8003182b80] 21:40:17.264 5 amdxata.sys[fffff8800113d7a8] -> nt!IofCallDriver -> \Device\0000005c[0xfffffa8003061700] 21:40:18.384 AVAST engine scan C:\Windows 21:40:23.541 AVAST engine scan C:\Windows\system32 21:46:40.691 AVAST engine scan C:\Windows\system32\drivers 21:47:01.864 AVAST engine scan C:\Users\stevej89 22:08:58.634 File: C:\Users\stevej89\Documents\iLividSetupV1.exe **INFECTED** Win32:Adware-gen [Adw] 22:09:11.737 File: C:\Users\stevej89\Downloads\dds.scr **INFECTED** Win32:Malware-gen 22:09:12.547 File: C:\Users\stevej89\Downloads\iLividSetupV1.exe **INFECTED** Win32:Adware-gen [Adw] 22:22:05.974 File: C:\Users\stevej89\Pictures\iLividSetupV1.exe **INFECTED** Win32:Adware-gen [Adw] 22:22:57.645 AVAST engine scan C:\ProgramData 22:24:20.897 File: C:\ProgramData\BitGuard\2.7.1832.68\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\x64injector.exe **INFECTED** Win64:Adware-B [Adw] 22:28:40.289 Disk 0 statistics 4492610/0/0 @ 0.92 MB/s 22:28:40.309 Scan finished successfully 22:29:22.807 Disk 0 MBR has been saved successfully to "C:\Users\stevej89\Documents\MBR.dat" 22:29:22.967 The log file has been saved successfully to "C:\Users\stevej89\Documents\aswMBR.txt" aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software Run date: 2015-02-12 21:30:56 —————————– 21:30:56.301 OS Version: Windows x64 6.1.7601 Service Pack 1 21:30:56.301 Number of processors: 2 586 0x603 21:30:56.301 ComputerName: STEVEJ89-HP UserName: stevej89 21:30:57.341 Initialize success 21:30:57.551 VM: initialized successfully 21:30:57.551 VM: Amd CPU supported 21:34:45.176 AVAST engine defs: 15021201 21:38:50.566 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000005c 21:38:50.576 Disk 0 Vendor: TOSHIBA_ GJ00 Size: 305245MB BusType: 11 21:38:50.706 Disk 0 MBR read successfully 21:38:50.716 Disk 0 MBR scan 21:38:50.726 Disk 0 unknown MBR code 21:38:50.736 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 199 MB offset 2048 21:38:50.746 Disk 0 default boot code 21:38:50.766 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 287356 MB offset 409600 21:38:50.806 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 17585 MB offset 588914688 21:38:50.836 Disk 0 Partition 4 00 0C FAT32 LBA MSDOS5.0 103 MB offset 624928768 21:38:51.004 Disk 0 scanning C:\Windows\system32\drivers 21:39:09.785 Service scanning 21:40:17.174 Modules scanning 21:40:17.184 Disk 0 trace - called modules: 21:40:17.234 ntoskrnl.exe CLASSPNP.SYS disk.sys amdxata.sys storport.sys hal.dll amdsata.sys 21:40:17.244 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80031dc6e0] 21:40:17.254 3 CLASSPNP.SYS[fffff8800195543f] -> nt!IofCallDriver -> [0xfffffa8003182b80] 21:40:17.264 5 amdxata.sys[fffff8800113d7a8] -> nt!IofCallDriver -> \Device\0000005c[0xfffffa8003061700] 21:40:18.384 AVAST engine scan C:\Windows 21:40:23.541 AVAST engine scan C:\Windows\system32 21:46:40.691 AVAST engine scan C:\Windows\system32\drivers 21:47:01.864 AVAST engine scan C:\Users\stevej89 22:08:58.634 File: C:\Users\stevej89\Documents\iLividSetupV1.exe **INFECTED** Win32:Adware-gen [Adw] 22:09:11.737 File: C:\Users\stevej89\Downloads\dds.scr **INFECTED** Win32:Malware-gen 22:09:12.547 File: C:\Users\stevej89\Downloads\iLividSetupV1.exe **INFECTED** Win32:Adware-gen [Adw] 22:22:05.974 File: C:\Users\stevej89\Pictures\iLividSetupV1.exe **INFECTED** Win32:Adware-gen [Adw] 22:22:57.645 AVAST engine scan C:\ProgramData 22:24:20.897 File: C:\ProgramData\BitGuard\2.7.1832.68\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\x64injector.exe **INFECTED** Win64:Adware-B [Adw] 22:28:40.289 Disk 0 statistics 4492610/0/0 @ 0.92 MB/s 22:28:40.309 Scan finished successfully 22:29:22.807 Disk 0 MBR has been saved successfully to "C:\Users\stevej89\Documents\MBR.dat" 22:29:22.967 The log file has been saved successfully to "C:\Users\stevej89\Documents\aswMBR.txt" 22:30:38.167 Disk 0 MBR has been saved successfully to "C:\Users\stevej89\Documents\MBR.dat" 22:30:38.183 The log file has been saved successfully to "C:\Users\stevej89\Documents\aswMBR.txt"
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 12-02-2015 Ran by [removed] at 2015-02-12 22:41:09 Running from C:\Users\[removed]\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\O7F5SGM1 Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 64 Bit HP CIO Components Installer (Version: 6.2.1 - Hewlett-Packard) Hidden Acrobat.com (HKLM-x32\…\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated) ActiveCheck component for HP Active Support Library (x32 Version: 3.0.0.3 - Hewlett-Packard) Hidden Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 2.7.1.19610 - Adobe Systems Incorporated) Adobe Community Help (HKLM-x32\…\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.0.0.400 - Adobe Systems Incorporated) Adobe Flash Player 12 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 12.0.0.70 - Adobe Systems Incorporated) Adobe Photoshop CS5 (HKLM-x32\…\{15FEDA5F-141C-4127-8D7E-B962D1742728}) (Version: 12.0 - Adobe Systems Incorporated) Adobe Reader 9.4.1 MUI (HKLM-x32\…\{AC76BA86-7AD7-FFFF-7B44-A91000000001}) (Version: 9.4.1 - Adobe Systems Incorporated) Adobe Shockwave Player 11.5 (HKLM-x32\…\{9ECF7817-DB11-4FBA-9DF1-296A578D513A}) (Version: 11.5.7.609 - Adobe Systems, Inc) AIM 7 (HKLM-x32\…\AIM_7) (Version: - ) AOL Uninstaller (Choose which Products to Remove) (HKLM-x32\…\AOL Uninstaller) (Version: - AOL Inc.) Apple Application Support (HKLM-x32\…\{853A4763-6643-4604-8D64-28BDD8925F4C}) (Version: 1.5.1 - Apple Inc.) Apple Mobile Device Support (HKLM\…\{8F473675-D702-45F9-8EBC-342B40C17BF5}) (Version: 3.4.0.25 - Apple Inc.) Apple Software Update (HKLM-x32\…\{C41300B9-185D-475E-BFEC-39EF732F19B1}) (Version: 2.1.2.120 - Apple Inc.) ATI Catalyst Install Manager (HKLM\…\{ECD0D4B5-FFA9-6E1B-A08D-58E82EA5EEB9}) (Version: 3.0.765.0 - ATI Technologies, Inc.) Audacity 2.0 (HKLM-x32\…\Audacity_is1) (Version: - Audacity Team) Bejeweled 2 Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden Bing Bar (HKLM-x32\…\{77F8A71E-3515-4832-B8B2-2F1EDBD2E0F1}) (Version: 7.0.609.0 - Microsoft Corporation) Bing Rewards Client Installer (x32 Version: 16.0.345.0 - Microsoft Corporation) Hidden BitGuard (HKLM-x32\…\{15D2D75C-9CB2-4efd-BAD7-B9B4CB4BC693}) (Version: - MediaTechSoft Inc.) <==== ATTENTION BitPim 1.0.7 (HKLM-x32\…\{FA61D601-A0FC-48BD-AE7A-54946BCD7FB6}_is1) (Version: 1.0.7 - Joe Pham ) Blackhawk Striker 2 (x32 Version: 2.2.0.95 - WildTangent) Hidden Bonjour (HKLM\…\{0E543634-7E25-4B8F-8D5B-97880E5E5088}) (Version: 2.0.5.0 - Apple Inc.) Broadcom 802.11 Wireless LAN Adapter (HKLM\…\Broadcom 802.11 Wireless LAN Adapter) (Version: 5.60.350.6 - Broadcom Corporation) BufferChm (x32 Version: 130.0.331.000 - Hewlett-Packard) Hidden Build-a-lot 2 (x32 Version: 2.2.0.95 - WildTangent) Hidden C4400 (x32 Version: 130.0.365.000 - Hewlett-Packard) Hidden ccc-core-static (x32 Version: 2010.0617.855.14122 - ATI) Hidden Chuzzle Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden CinemaNow Media Manager (HKLM-x32\…\{6C122441-1861-4CD7-B1C5-A163A6984E12}) (Version: 1.9.1.105 - CinemaNow, Inc.) Copy (x32 Version: 130.0.428.000 - Hewlett-Packard) Hidden CyberLink DVD Suite (HKLM-x32\…\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 7.0.3003 - CyberLink Corp.) CyberLink MediaShow (HKLM-x32\…\InstallShield_{80E158EA-7181-40FE-A701-301CE6BE64AB}) (Version: 5.0.1616 - CyberLink Corp.) CyberLink PowerDVD 9 (HKLM-x32\…\InstallShield_{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}) (Version: 9.0.1.4217 - CyberLink Corp.) CyberLink YouCam (HKLM-x32\…\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.0.2511 - CyberLink Corp.) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Destinations (x32 Version: 130.0.0.0 - Hewlett-Packard) Hidden DeviceDiscovery (x32 Version: 130.0.465.000 - Hewlett-Packard) Hidden Diner Dash 2 Restaurant Rescue (x32 Version: 2.2.0.95 - WildTangent) Hidden DocProc (x32 Version: 13.0.0.0 - Hewlett-Packard) Hidden Dora's Carnival Adventure (x32 Version: 2.2.0.95 - WildTangent) Hidden Download Updater (AOL LLC) (HKLM-x32\…\SoftwareUpdUtility) (Version: - ) <==== ATTENTION Energy Star Digital Logo (HKLM-x32\…\{BD1A34C9-4764-4F79-AE1F-112F8C89D3D4}) (Version: 1.0.1 - Hewlett-Packard) Escape Rosecliff Island (x32 Version: 2.2.0.95 - WildTangent) Hidden ESU for Microsoft Windows 7 (HKLM-x32\…\{3877C901-7B90-4727-A639-B6ED2DD59D43}) (Version: 1.0.0 - Hewlett-Packard) FATE (x32 Version: 2.2.0.95 - WildTangent) Hidden Final Drive Nitro (x32 Version: 2.2.0.95 - WildTangent) Hidden Google Chrome (HKU\S-1-5-21-3891086701-1241933595-968087049-1001\…\Google Chrome) (Version: 40.0.2214.111 - Google Inc.) GPBaseService2 (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden Heroes of Hellas 2 - Olympia (x32 Version: 2.2.0.95 - WildTangent) Hidden HP Advisor (HKLM-x32\…\{40FB8D7C-6FF8-4AF2-BC8B-0B1DB32AF04B}) (Version: 3.4.10262.3295 - Hewlett-Packard) HP Customer Participation Program 13.0 (HKLM\…\HPExtendedCapabilities) (Version: 13.0 - HP) HP Documentation (HKLM-x32\…\{8602BE60-3908-4637-ADAE-6228F4D582AD}) (Version: 1.1.1.0 - Hewlett-Packard) HP Games (HKLM-x32\…\WildTangent hp Master Uninstall) (Version: 1.0.1.3 - WildTangent) HP Imaging Device Functions 13.0 (HKLM\…\HP Imaging Device Functions) (Version: 13.0 - HP) HP MediaSmart CinemaNow 2.0 (HKLM-x32\…\{9008D736-35CA-40DB-A2BE-5F32D954E5AA}) (Version: 2.0 - Hewlett-Packard) HP Photo Creations (HKLM-x32\…\HP Photo Creations) (Version: 1.0.0.3611 - HP Photo Creations Powered by RocketLife) HP Photosmart C4400 All-In-One Driver Software 13.0 Rel. 3 (HKLM\…\{8181C5B7-2FF5-4677-BA6A-8E2C3F5A7601}) (Version: 13.0 - HP) HP Photosmart Essential 3.5 (HKLM\…\HP Photosmart Essential) (Version: 3.5 - HP) HP Power Manager (HKLM-x32\…\{4B156358-CE9C-4E9F-8CAD-79AE86A68C60}) (Version: 1.0.3 - Hewlett-Packard Company) HP Quick Launch (HKLM-x32\…\{E342D296-DB9D-4FC7-ACB0-39926C0BFA16}) (Version: 2.1.5 - Hewlett-Packard Company) HP Setup (HKLM-x32\…\{72D90DB3-A16A-4545-B555-868471101833}) (Version: 8.1.4186.3400 - Hewlett-Packard) HP Smart Web Printing 4.51 (HKLM\…\HP Smart Web Printing) (Version: 4.51 - HP) HP Software Framework (HKLM-x32\…\{E05DB9F9-C8E7-45F2-BE9E-76D4C447CE9B}) (Version: 4.0.39.1 - Hewlett-Packard Company) HP Solution Center 13.0 (HKLM\…\HP Solution Center & Imaging Support Tools) (Version: 13.0 - HP) HP Support Assistant (HKLM-x32\…\{08DB3902-2CE0-474D-BCE3-0177766CE9F1}) (Version: 5.1.10.7 - Hewlett-Packard Company) HP Update (HKLM-x32\…\{7059BDA7-E1DB-442C-B7A1-6144596720A4}) (Version: 4.000.011.006 - Hewlett-Packard) HP Wireless Assistant (HKLM\…\{B5FC1E1B-E70D-45F1-8E40-A3C30698B323}) (Version: 4.0.9.0 - Hewlett-Packard Company) HPAsset component for HP Active Support Library (x32 Version: 3.0.2.2 - Hewlett-Packard) Hidden HPPhotoGadget (x32 Version: 130.0.282.000 - Hewlett-Packard) Hidden HPPhotoSmartDiscLabelContent1 (x32 Version: 2.04.0000 - Hewlett-Packard) Hidden HPPhotosmartEssential (x32 Version: 2.04.0000 - Hewlett-Packard) Hidden HPProductAssistant (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden HPSSupply (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden InstallIQ Updater (HKLM-x32\…\{8E1CB0F1-67BF-4052-AA23-FA22E94804C1}) (Version: 1.4.3.0 - W3i, LLC) iTunes (HKLM\…\{16DDB3D1-5C27-4599-9C63-E583287191CC}) (Version: 10.2.2.12 - Apple Inc.) Java(TM) 6 Update 20 (64-bit) (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F86416020FF}) (Version: 6.0.200 - Sun Microsystems, Inc.) Java(TM) 6 Update 30 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83216020FF}) (Version: 6.0.300 - Sun Microsystems, Inc.) Java(TM) 7 Update 2 (64-bit) (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F86417002FF}) (Version: 7.0.20 - Oracle) Jewel Quest 3 (x32 Version: 2.2.0.95 - WildTangent) Hidden Jewel Quest Solitaire 2 (x32 Version: 2.2.0.95 - WildTangent) Hidden Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden jZip (HKLM-x32\…\jZip) (Version: - Bandoo Media Inc.) <==== ATTENTION LabelPrint (HKLM-x32\…\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.2907 - CyberLink Corp.) LabelPrint (x32 Version: 2.5.2907 - CyberLink Corp.) Hidden MarketResearch (x32 Version: 130.0.374.000 - Hewlett-Packard) Hidden Microsoft .NET Framework 4.5.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\…\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office 2010 (HKLM-x32\…\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Click-to-Run 2010 (HKLM-x32\…\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Enterprise 2007 (HKLM-x32\…\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office File Validation Add-In (HKLM-x32\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Starter 2010 - English (HKLM-x32\…\{90140011-0066-0409-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft PowerPoint Viewer (HKLM-x32\…\{95140000-00AF-0409-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\…\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (HKLM\…\{8338783A-0968-3B85-AFC7-BAAE0A63DC50}) (Version: 9.0.30729.5570 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM-x32\…\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\…\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation) Mplayer 0.6.9 (HKLM-x32\…\Mplayer) (Version: 0.6.9 - ) MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) Navionics Chart Installer (HKLM-x32\…\navionicsChartInstaller.Air.A3B2DB703D5E0A7ECA24FBD4B07176191EDD3C63.1) (Version: 1.0.13.37 - Navionics) Navionics Chart Installer (x32 Version: 1.0.13 - Navionics) Hidden Navionics PC App-1.4 (HKLM-x32\…\Navionics PC App 1.4) (Version: 1.4 - Navionics PC App) Nike+ Connect (HKLM-x32\…\Nike+ Connect) (Version: 6.6.21 - Nike) Nike+ Connect (HKU\S-1-5-21-3891086701-1241933595-968087049-1001\…\Nike+ Connect) (Version: 6.1.10 - Nike) Norton Online Backup (HKLM-x32\…\{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}) (Version: 2.1.17869 - Symantec Corporation) OCR Software by I.R.I.S. 13.0 (HKLM\…\HPOCR) (Version: 13.0 - HP) PDF Settings CS5 (x32 Version: 10.0 - Adobe Systems Incorporated) Hidden Penguins! (x32 Version: 2.2.0.95 - WildTangent) Hidden PhotoNow! (HKLM-x32\…\InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}) (Version: 1.1.6904 - CyberLink Corp.) PhotoNow! (x32 Version: 1.1.6904 - CyberLink Corp.) Hidden Plants vs. Zombies (x32 Version: 2.2.0.95 - WildTangent) Hidden Poker Superstars III (x32 Version: 2.2.0.95 - WildTangent) Hidden Polar Bowler (x32 Version: 2.2.0.95 - WildTangent) Hidden Polar Golfer (x32 Version: 2.2.0.95 - WildTangent) Hidden Power2Go (HKLM-x32\…\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.4204 - CyberLink Corp.) Power2Go (x32 Version: 6.1.4204 - CyberLink Corp.) Hidden PowerDirector (HKLM-x32\…\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 8.0.3003 - CyberLink Corp.) PowerDirector (x32 Version: 8.0.3003 - CyberLink Corp.) Hidden PS_AIO_03_C4400_Software_Min (x32 Version: 130.0.365.000 - Hewlett-Packard) Hidden QuickTime (HKLM-x32\…\{57752979-A1C9-4C02-856B-FBB27AC4E02C}) (Version: 7.69.80.9 - Apple Inc.) Realtek Ethernet Controller Driver For Windows 7 (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.18.322.2010 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6122 - Realtek Semiconductor Corp.) Realtek USB 2.0 Card Reader (HKLM-x32\…\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30120 - Realtek Semiconductor Corp.) Recovery Manager (x32 Version: 5.5.3023 - CyberLink Corp.) Hidden RtVOsd (HKLM\…\{F3D7AC17-1FF4-41A8-BB18-3FC39C65AEB9}) (Version: 1.0.3 - Realtek Semiconductor Corp.) SAMSUNG USB Driver for Mobile Phones V5.16.0.0 (HKLM-x32\…\{C0C1D2BC-72FE-4F77-A2F9-CD10D5AA8F93}) (Version: 1.2.2200.0 - SAMSUNG Electronics CO., LTD.) Scan (x32 Version: 13.0.0.0 - Hewlett-Packard) Hidden Shop for HP Supplies (HKLM\…\Shop for HP Supplies) (Version: 13.0 - HP) Skype 6.11 (HKLM-x32\…\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.) SmartWebPrinting (x32 Version: 130.0.457.000 - Hewlett-Packard) Hidden SolutionCenter (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden Status (x32 Version: 130.0.469.000 - Hewlett-Packard) Hidden Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 15.0.18.0 - Synaptics Incorporated) Toolbox (x32 Version: 130.0.648.000 - Hewlett-Packard) Hidden TrayApp (x32 Version: 130.0.422.000 - Hewlett-Packard) Hidden UnloadSupport (x32 Version: 11.0.0 - Hewlett-Packard) Hidden Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\…\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Virtual Families (x32 Version: 2.2.0.95 - WildTangent) Hidden Virtual Villagers - The Secret City (x32 Version: 2.2.0.95 - WildTangent) Hidden VZAccess Manager (HKLM-x32\…\{1FFA1C07-525F-4691-B986-E570C4B659E9}) (Version: 7.3.2.2 - Smith Micro Software Inc.) WebConnect 3.0.0 (HKLM\…\WebConnect) (Version: 3.0.0 - Web Connect) <==== ATTENTION WebReg (x32 Version: 130.0.132.017 - Hewlett-Packard) Hidden Wheel of Fortune 2 (x32 Version: 2.2.0.95 - WildTangent) Hidden Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live Sync (HKLM-x32\…\{B10914FD-8812-47A4-85A1-50FCDE7F1F33}) (Version: 14.0.8117.416 - Microsoft Corporation) WinRAR archiver (HKLM-x32\…\WinRAR archiver) (Version: - ) WModem Driver Installer (HKLM-x32\…\HTC_WModemDriver) (Version: 2.0.6.9 - HTC) Yahoo! Toolbar (HKLM-x32\…\Yahoo! Companion) (Version: - ) Zip Extractor Packages (HKU\S-1-5-21-3891086701-1241933595-968087049-1001\…\Zip Extractor Packages) (Version: - ) <==== ATTENTION Zuma Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-3891086701-1241933595-968087049-1001_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\stevej89\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll No File CustomCLSID: HKU\S-1-5-21-3891086701-1241933595-968087049-1001_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\stevej89\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll No File CustomCLSID: HKU\S-1-5-21-3891086701-1241933595-968087049-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\stevej89\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll No File CustomCLSID: HKU\S-1-5-21-3891086701-1241933595-968087049-1001_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\stevej89\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-3891086701-1241933595-968087049-1001_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\stevej89\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll No File CustomCLSID: HKU\S-1-5-21-3891086701-1241933595-968087049-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\stevej89\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-3891086701-1241933595-968087049-1001_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\stevej89\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll No File ==================== Restore Points ========================= ATTENTION: System Restore is disabled. ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-13 21:34 - 2015-02-11 18:58 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {0D4330C1-090E-443F-A53C-9637816C9DA3} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc Task: {387E2672-EB9D-41A7-AA6B-0735CB030914} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Total Care Tune-Up => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPTuneUp.exe [2010-11-15] (Hewlett-Packard Company) Task: {457B5768-4755-45DA-B676-5B46CD6FBDD9} - System32\Tasks\ServicePlan => C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe [2010-05-25] () Task: {5183B3B9-EB96-4659-AD37-492B693A43B7} - System32\Tasks\Hewlett-Packard\HP Support Assistant\GetAssistance Maintenance Events => C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\HPSAObjUtil.exe [2015-01-28] (Hewlett-Packard) Task: {64139B91-8DE1-4DDC-B346-016E00E0D13D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HPSAObjUtilTask => C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\UtilTask.exe [2015-01-28] (Microsoft) Task: {7F928820-7803-47D8-A369-816328C7BF21} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3891086701-1241933595-968087049-1001Core => C:\Users\stevej89\AppData\Local\Google\Update\GoogleUpdate.exe [2012-08-30] (Google Inc.) Task: {86847E8C-C62A-44DE-868F-D75F3FA66B5B} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2010-11-15] (Hewlett-Packard Company) Task: {8DA4AFB6-9D44-40F7-9EAC-3C4BA145FE8B} - System32\Tasks\EPUpdater => C:\Users\stevej89\AppData\Roaming\BABSOL~1\Shared\BabMaint.exe <==== ATTENTION Task: {977C879B-BBBF-4E6C-A684-20962AE64748} - System32\Tasks\{AB6ACCF3-83EB-430C-AA9F-97B987BAF895} => pcalua.exe -a E:\setup.exe -d E:\ Task: {99668A72-29CD-4A5D-B9DD-FB806F6082A6} - System32\Tasks\AdobeAAMUpdater-1.0-stevej89-HP-stevej89 => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06] (Adobe Systems Incorporated) Task: {BD626873-375E-4568-8562-152716777745} - System32\Tasks\{CDF84EA3-FF33-41B9-9684-3D843C9239EB} => pcalua.exe -a C:\Users\stevej89\Downloads\InstallRoot_v3_15A.exe -d C:\Users\stevej89\Downloads Task: {BDBAB1FB-A872-4C43-86EF-D3266EB443FC} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Ghost Resign Task => c:\program files (x86)\hewlett-packard\hp health check\activecheck\product_line\HPResignFileLoader.exe [2015-01-28] (Microsoft) Task: {C466E28B-D228-468B-88AF-A5F71DD917AA} - System32\Tasks\HPCeeScheduleForstevej89 => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-01-05] (Hewlett-Packard) Task: {FBC10CCA-41C0-4CEF-B09F-C2FC78053CB3} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3891086701-1241933595-968087049-1001UA => C:\Users\stevej89\AppData\Local\Google\Update\GoogleUpdate.exe [2012-08-30] (Google Inc.) Task: {FE5B8BDB-E16E-4A9D-A16E-C1EC81912964} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Tuneup => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2010-11-15] (Hewlett-Packard Company) Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3891086701-1241933595-968087049-1001Core.job => C:\Users\stevej89\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3891086701-1241933595-968087049-1001UA.job => C:\Users\stevej89\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\HPCeeScheduleForstevej89.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe ==================== Loaded Modules (whitelisted) ============== 2013-11-21 22:37 - 2013-11-18 09:32 - 03780064 _____ () C:\ProgramData\BitGuard\2.7.1832.68\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe 2010-06-29 21:00 - 2010-06-29 21:00 - 00027192 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe 2010-06-18 18:26 - 2010-06-18 18:26 - 00267832 _____ () C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPCommon.XmlSerializers.dll 2010-06-10 19:42 - 2010-06-10 19:42 - 00016384 ____R () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll 2010-11-20 03:41 - 2010-11-20 03:41 - 00270336 _____ () C:\Windows\assembly\GAC_MSIL\CLI.Aspect.CrossDisplay.Graphics.Dashboard\1.0.0.0__90ba9c70f846762e\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll 2010-06-18 18:26 - 2010-06-18 18:26 - 00030264 _____ () C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_LogicLayer.dll 2010-06-18 18:26 - 2010-06-18 18:26 - 00052280 _____ () C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HardwareAccess.dll 2013-11-21 22:37 - 2013-11-18 09:31 - 03618304 _____ () C:\ProgramData\BitGuard\2.7.1832.68\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll 2010-11-24 14:40 - 2010-11-24 14:40 - 00048640 _____ () C:\Program Files (x86)\AOL Desktop 9.6\zlib.dll 2010-11-24 14:40 - 2010-11-24 14:40 - 00094208 _____ () C:\Program Files (x86)\AOL Desktop 9.6\Components\Tier2Svc.dll 2010-11-24 14:40 - 2010-11-24 14:40 - 00060928 _____ () C:\Program Files (x86)\AOL Desktop 9.6\Components\DataSvcs.dll 2011-03-21 16:30 - 2011-03-21 16:30 - 00067872 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) =============== (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3891086701-1241933595-968087049-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\stevej89\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.1.1 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) ==================== Accounts: ============================= Administrator (S-1-5-21-3891086701-1241933595-968087049-500 - Administrator - Disabled) Guest (S-1-5-21-3891086701-1241933595-968087049-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-3891086701-1241933595-968087049-1002 - Limited - Enabled) stevej89 (S-1-5-21-3891086701-1241933595-968087049-1001 - Administrator - Enabled) => C:\Users\stevej89 ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (02/11/2015 08:30:20 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: GetLargeResourceRecord: opt 65002 optlen 8 wrong Error: (02/11/2015 08:30:20 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: GetLargeResourceRecord: opt 65002 optlen 8 wrong Error: (02/11/2015 08:30:20 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: GetLargeResourceRecord: opt 65002 optlen 8 wrong Error: (02/11/2015 08:30:20 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: GetLargeResourceRecord: opt 65002 optlen 8 wrong Error: (02/11/2015 08:30:11 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: GetLargeResourceRecord: opt 65002 optlen 8 wrong Error: (02/11/2015 08:30:11 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: GetLargeResourceRecord: opt 65002 optlen 8 wrong Error: (02/11/2015 08:30:11 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: GetLargeResourceRecord: opt 65002 optlen 8 wrong Error: (02/11/2015 08:30:11 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: GetLargeResourceRecord: opt 65002 optlen 8 wrong Error: (02/11/2015 08:30:08 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: GetLargeResourceRecord: opt 65002 optlen 8 wrong Error: (02/11/2015 08:30:08 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: GetLargeResourceRecord: opt 65002 optlen 8 wrong System errors: ============= Error: (02/11/2015 07:36:04 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The Windows Presentation Foundation Font Cache 3.0.0.0 service failed to start due to the following error: %%31 Error: (02/11/2015 06:58:31 PM) (Source: Service Control Manager) (EventID: 7030) (User: ) Description: The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly. Error: (02/11/2015 06:57:34 PM) (Source: Application Popup) (EventID: 1060) (User: ) Description: \??\C:\ComboFix\catchme.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver. Error: (02/11/2015 06:57:30 PM) (Source: Application Popup) (EventID: 1060) (User: ) Description: \??\C:\ComboFix\catchme.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver. Error: (02/11/2015 06:52:00 PM) (Source: Service Control Manager) (EventID: 7030) (User: ) Description: The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly. Error: (02/11/2015 06:37:30 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The hpqcxs08 service terminated unexpectedly. It has done this 2 time(s). Error: (02/11/2015 06:37:30 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The BitGuard service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service. Error: (02/11/2015 06:36:31 PM) (Source: Service Control Manager) (EventID: 7032) (User: ) Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the BitGuard service, but this action failed with the following error: %%1056 Error: (02/11/2015 06:36:01 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The BitGuard service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service. Error: (02/11/2015 06:36:01 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The HP CUE DeviceDiscovery Service service terminated unexpectedly. It has done this 1 time(s). Microsoft Office Sessions: ========================= CodeIntegrity Errors: =================================== Date: 2015-02-11 18:57:34.150 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-02-11 18:57:32.044 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-02-11 18:57:30.000 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-02-11 18:57:28.409 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2013-10-19 02:29:27.233 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2013-10-19 02:29:26.733 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2013-10-19 02:29:26.234 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2013-10-19 02:29:25.704 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2013-09-30 21:43:42.401 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2013-09-30 21:43:41.886 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. ==================== Memory info =========================== Processor: AMD Athlon™ II P340 Dual-Core Processor Percentage of memory in use: 51% Total physical RAM: 2810.9 MB Available physical RAM: 1368.21 MB Total Pagefile: 5619.99 MB Available Pagefile: 3457.92 MB Total Virtual: 8192 MB Available Virtual: 8191.84 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:280.62 GB) (Free:162.42 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: (RECOVERY) (Fixed) (Total:17.17 GB) (Free:2.48 GB) NTFS ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 298.1 GB) (Disk ID: D2ED6EA8) Partition 1: (Active) - (Size=199 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=280.6 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=17.2 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=103 MB) - (Type=0C) ==================== End Of Log ============================
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-02-2015 Ran by [removed] (administrator) on STEVEJ89-HP on 12-02-2015 22:40:12 Running from C:\Users\[removed]\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\O7F5SGM1 [removed] Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States) Internet Explorer Version 11 (Default browser: IE) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AMD) C:\Windows\System32\atiesrxx.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe () C:\ProgramData\BitGuard\2.7.1832.68\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe (Apple Inc.) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Microsoft Corporation) C:\Windows\SysWOW64\schtasks.exe (CinemaNow, Inc.) C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemaNowSvc.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe () C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE (AMD) C:\Windows\System32\atieclxx.exe () C:\ProgramData\BitGuard\2.7.1832.68\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Service.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Nike) C:\Users\stevej89\AppData\Local\Nike\Nike+ Connect\Nike+ Connect daemon.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (AOL Inc.) C:\Program Files (x86)\AOL Desktop 9.6\waol.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (AOL Inc.) C:\Program Files (x86)\Common Files\AOL\1293562345\ee\aolsoftware.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Nike) C:\Program Files (x86)\Nike\Nike+ Connect\Nike+ Connect daemon.exe (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe (Realtek Semiconductor Corp.) C:\Program Files\Realtek\RtVOsd\RtVOsdService.exe (Realtek Semiconductor Corp.) C:\Program Files\Realtek\RtVOsd\RtVOsd.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (AOL LLC) C:\Program Files (x86)\Common Files\AOL\acs\AOLacsd.exe (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe (Hewlett-Packard) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe (AOL Inc.) C:\Program Files (x86)\AOL Desktop 9.6\shellmon.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe (Hewlett-Packard Development Company L.P.) C:\Program Files (x86)\Hewlett-Packard\Shared\hpCaslNotification.exe (Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe (AOL Inc.) C:\Program Files (x86)\Common Files\AOL\1293562345\ee\aolupdates.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (AOL Inc.) C:\Program Files (x86)\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe (AOL Inc.) C:\Program Files (x86)\AOL Desktop 9.6\AOLBrowser\aolbrowser.exe (Farbar) C:\Users\stevej89\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\O7F5SGM1\FRST64[1].exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2097960 2010-04-22] (Synaptics Incorporated) HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6245408 2010-05-25] (Realtek Semiconductor) HKLM\…\Run: [HPWirelessAssistant] => C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe [363064 2010-06-18] (Hewlett-Packard Company) HKLM\…\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500208 2010-03-06] (Adobe Systems Incorporated) HKLM-x32\…\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-06-17] (Advanced Micro Devices, Inc.) HKLM-x32\…\Run: [Microsoft Default Manager] => C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [439568 2010-05-10] (Microsoft Corporation) HKLM-x32\…\Run: [HP Quick Launch] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [602168 2010-06-29] (Hewlett-Packard Company) HKLM-x32\…\Run: [Norton Online Backup] => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-01] (Symantec Corporation) HKLM-x32\…\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\…\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35760 2010-09-23] (Adobe Systems Incorporated) HKLM-x32\…\Run: [HostManager] => C:\Program Files (x86)\Common Files\AOL\1293562345\ee\AOLSoftware.exe [41800 2010-03-08] (AOL Inc.) HKLM-x32\…\Run: [HP Software Update] => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [54840 2007-05-08] (Hewlett-Packard) HKLM-x32\…\Run: [hpqSRMon] => C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [150528 2008-07-22] (Hewlett-Packard) HKLM-x32\…\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM-x32\…\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\…\Run: [AdobeCS5ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [406992 2010-02-22] (Adobe Systems Incorporated) HKLM-x32\…\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2010-11-29] (Apple Inc.) HKLM-x32\…\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [421160 2011-04-14] (Apple Inc.) HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254696 2011-06-09] (Sun Microsystems, Inc.) HKLM-x32\…\Run: [Nike+ Connect] => C:\Program Files (x86)\Nike\Nike+ Connect\Nike+ Connect daemon.exe [71680 2014-04-09] (Nike) HKLM\…\RunOnce: [NCPluginUpdater] => C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe [21720 2015-01-28] (Hewlett-Packard) Winlogon\Notify\ScCertProp: wlnotify.dll [X] HKU\S-1-5-21-3891086701-1241933595-968087049-1001\…\Run: [Aim] => C:\Program Files (x86)\AIM\aim.exe [4321112 2011-01-05] (AOL Inc.) HKU\S-1-5-21-3891086701-1241933595-968087049-1001\…\Run: [Nike+ Connect] => C:\Users\stevej89\AppData\Local\Nike\Nike+ Connect\Nike+ Connect daemon.exe [70656 2013-11-01] (Nike) HKU\S-1-5-21-3891086701-1241933595-968087049-1001\…\Run: [AOL Fast Start] => C:\Program Files (x86)\AOL Desktop 9.6\AOL.EXE [42320 2010-11-24] (AOL Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-3891086701-1241933595-968087049-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-3891086701-1241933595-968087049-1001\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch URLSearchHook: HKU\S-1-5-21-3891086701-1241933595-968087049-1001 - (No Name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File SearchScopes: HKLM -> DefaultScope value is missing. SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM -> {2473B431-C46D-4A3F-AC39-96ACD267EFBD} URL = http://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox SearchScopes: HKLM -> {42DAFC06-8624-428E-AEEB-5AB666A15406} URL = http://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF SearchScopes: HKLM -> {64CA8089-F823-4FA5-BAF1-64B36201DD96} URL = http://en.wikipedia.org/wiki/Special:Search?search={searchTerms} SearchScopes: HKLM-x32 -> DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2102} URL = SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> {2473B431-C46D-4A3F-AC39-96ACD267EFBD} URL = http://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox SearchScopes: HKLM-x32 -> {42DAFC06-8624-428E-AEEB-5AB666A15406} URL = http://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF SearchScopes: HKU\S-1-5-21-3891086701-1241933595-968087049-1001 -> DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2102} URL = http://www.bing.com/search?FORM=UP97DF&PC=UP97&dt=071613&q={searchTerms}&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-3891086701-1241933595-968087049-1001 -> F7BCF00E166B4980885A622C3B81A7D8 URL = http://dts.search-results.com/sr?src=ieb&appid=0&systemid=102&sr=0&q={searchTerms} SearchScopes: HKU\S-1-5-21-3891086701-1241933595-968087049-1001 -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = SearchScopes: HKU\S-1-5-21-3891086701-1241933595-968087049-1001 -> {2473B431-C46D-4A3F-AC39-96ACD267EFBD} URL = SearchScopes: HKU\S-1-5-21-3891086701-1241933595-968087049-1001 -> {42DAFC06-8624-428E-AEEB-5AB666A15406} URL = http://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF SearchScopes: HKU\S-1-5-21-3891086701-1241933595-968087049-1001 -> {64CA8089-F823-4FA5-BAF1-64B36201DD96} URL = SearchScopes: HKU\S-1-5-21-3891086701-1241933595-968087049-1001 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2102} URL = http://www.bing.com/search?FORM=UP97DF&PC=UP97&dt=071613&q={searchTerms}&src=IE-SearchBox BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.) BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO-x32: SingleInstance Class -> {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} -> C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc) BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) Toolbar: HKLM-x32 - No Name - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.) DPF: HKLM-x32 {2FF8D282-F78A-4A33-ABC2-49E72A341482} http://riteaid.storefront.com/images/global/activex/SFImageUpload1_10.CAB DPF: HKLM-x32 {BEA7310D-06C4-4339-A784-DC3804819809} http://images3.pnimedia.com/ProductAssets/costcous/activex/v3_0_0_7/PhotoCenter_ActiveX_Control.cab Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @viewpoint.com/VMP -> C:\Program Files (x86)\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll No File FF Plugin HKU\S-1-5-21-3891086701-1241933595-968087049-1001: @tools.google.com/Google Update;version=3 -> C:\Users\stevej89\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKU\S-1-5-21-3891086701-1241933595-968087049-1001: @tools.google.com/Google Update;version=9 -> C:\Users\stevej89\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.) FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011-01-05] FF HKLM-x32\…\Firefox\Extensions: [{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}] - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension FF Extension: Default Manager - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension [2011-01-16] FF HKU\S-1-5-21-3891086701-1241933595-968087049-1001\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 Chrome: ======= CHR HomePage: Default -> hxxp://www.searchgol.com/?babsrc=HP_ss&mntrId=A601AC811228EE3A&affID=119351&tt=240913_246&tsp=5016 CHR StartupUrls: Default -> "hxxp://www.searchgol.com/?babsrc=HP_ss&mntrId=A601AC811228EE3A&affID=119351&tt=240913_246&tsp=5016" CHR DefaultSearchKeyword: Default -> searchgol.com CHR DefaultSearchURL: Default -> http://www.searchgol.com/?q={searchTerms}&babsrc=SP_ss&mntrId=A601AC811228EE3A&affID=119351&tt=240913_246&tsp=5016 CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Users\stevej89\AppData\Local\Google\Chrome\Application\21.0.1180.83\PepperFlash\pepflashplayer.dll No File CHR Plugin: (Shockwave Flash) - C:\Users\stevej89\AppData\Local\Google\Chrome\Application\40.0.2214.111\gcswf32.dll No File CHR Plugin: (Remoting Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\stevej89\AppData\Local\Google\Chrome\Application\40.0.2214.111\ppGoogleNaClPluginChrome.dll No File CHR Plugin: (Chrome PDF Viewer) - C:\Users\stevej89\AppData\Local\Google\Chrome\Application\40.0.2214.111\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Java Deployment Toolkit 6.0.300.12) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll (Sun Microsystems, Inc.) CHR Plugin: (Java(TM) Platform SE 6 U30) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll (Apple Inc.) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (MetaStream 3 Plugin) - C:\Program Files (x86)\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll No File CHR Plugin: (Windows Live0099 Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () CHR Plugin: (Google Update) - C:\Users\stevej89\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File CHR Plugin: (Shockwave for Director) - C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File CHR Profile: C:\Users\stevej89\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\stevej89\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-05-27] CHR Extension: (Google Wallet) - C:\Users\stevej89\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-27] CHR HKLM-x32\…\Chrome\Extension: [ieakfmpjhljbpbfpldjkddkjmmgjmgon] - C:\Program Files (x86)\WebConnect\ieakfmpjhljbpbfpldjkddkjmmgjmgon.crx [Not Found] CHR HKLM-x32\…\Chrome\Extension: [pacgpkgadgmibnhpdidcnfafllnmeomc] - C:\Users\stevej89\AppData\Local\Temp\ccex.crx [Not Found] StartMenuInternet: Google Chrome - C:\Users\stevej89\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 BitGuard; C:\ProgramData\BitGuard\2.7.1832.68\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe [3780064 2013-11-18] () R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [248832 2009-05-21] (Hewlett-Packard Co.) [File not signed] R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-09-20] (Hewlett-Packard Co.) [File not signed] R2 HPWMISVC; C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [27192 2010-06-29] () R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2008-12-03] (Hewlett-Packard) [File not signed] R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-01] (Symantec Corporation) R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2008-12-03] (Hewlett-Packard) [File not signed] R2 RtVOsdService; C:\Program Files\Realtek\RtVOsd\RtVOsdService.exe [315392 2010-04-19] (Realtek Semiconductor Corp.) [File not signed] S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed] R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-13] (Microsoft Corporation) S3 S3XXx64; C:\Windows\System32\DRIVERS\S3XXx64.sys [73984 2013-06-05] (Identive) S3 catchme; \??\C:\ComboFix\catchme.sys [X] U3 aswMBR; \??\C:\Users\stevej89\AppData\Local\Temp\aswMBR.sys [X] U3 aswVmm; \??\C:\Users\stevej89\AppData\Local\Temp\aswVmm.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-02-12 22:33 - 2015-02-12 22:40 - 00000000 ____D () C:\FRST 2015-02-12 21:27 - 2015-02-12 21:27 - 00000924 _____ () C:\Users\stevej89\Documents\checkup.txt 2015-02-11 19:03 - 2015-02-11 19:03 - 00022259 _____ () C:\ComboFix.txt 2015-02-10 23:09 - 2015-02-03 22:16 - 00894976 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2015-02-10 23:09 - 2015-02-03 22:16 - 00762368 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2015-02-10 23:09 - 2015-02-03 22:16 - 00609280 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2015-02-10 23:09 - 2015-02-03 22:16 - 00414720 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2015-02-10 23:09 - 2015-02-03 22:16 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2015-02-10 23:09 - 2015-02-03 22:16 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2015-02-10 23:09 - 2015-02-03 22:13 - 01098752 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2015-02-10 23:09 - 2015-01-27 18:36 - 01239720 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe 2015-02-10 23:09 - 2015-01-14 00:47 - 00389808 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2015-02-10 23:09 - 2015-01-14 00:09 - 00342712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2015-02-10 23:09 - 2015-01-11 22:09 - 25056256 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-02-10 23:09 - 2015-01-11 22:05 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2015-02-10 23:09 - 2015-01-11 22:05 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2015-02-10 23:09 - 2015-01-11 21:49 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2015-02-10 23:09 - 2015-01-11 21:48 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-02-10 23:09 - 2015-01-11 21:48 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-02-10 23:09 - 2015-01-11 21:48 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2015-02-10 23:09 - 2015-01-11 21:47 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2015-02-10 23:09 - 2015-01-11 21:40 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2015-02-10 23:09 - 2015-01-11 21:39 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2015-02-10 23:09 - 2015-01-11 21:36 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2015-02-10 23:09 - 2015-01-11 21:34 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2015-02-10 23:09 - 2015-01-11 21:34 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2015-02-10 23:09 - 2015-01-11 21:33 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2015-02-10 23:09 - 2015-01-11 21:32 - 06041088 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-02-10 23:09 - 2015-01-11 21:25 - 19740160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2015-02-10 23:09 - 2015-01-11 21:25 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2015-02-10 23:09 - 2015-01-11 21:21 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2015-02-10 23:09 - 2015-01-11 21:21 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2015-02-10 23:09 - 2015-01-11 21:13 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2015-02-10 23:09 - 2015-01-11 21:08 - 00503296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2015-02-10 23:09 - 2015-01-11 21:08 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2015-02-10 23:09 - 2015-01-11 21:07 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2015-02-10 23:09 - 2015-01-11 21:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2015-02-10 23:09 - 2015-01-11 21:07 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2015-02-10 23:09 - 2015-01-11 21:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2015-02-10 23:09 - 2015-01-11 21:04 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2015-02-10 23:09 - 2015-01-11 21:02 - 02277888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2015-02-10 23:09 - 2015-01-11 21:00 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2015-02-10 23:09 - 2015-01-11 20:59 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2015-02-10 23:09 - 2015-01-11 20:57 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2015-02-10 23:09 - 2015-01-11 20:55 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2015-02-10 23:09 - 2015-01-11 20:55 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2015-02-10 23:09 - 2015-01-11 20:48 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-02-10 23:09 - 2015-01-11 20:48 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2015-02-10 23:09 - 2015-01-11 20:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-02-10 23:09 - 2015-01-11 20:46 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2015-02-10 23:09 - 2015-01-11 20:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2015-02-10 23:09 - 2015-01-11 20:43 - 14401024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-02-10 23:09 - 2015-01-11 20:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2015-02-10 23:09 - 2015-01-11 20:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2015-02-10 23:09 - 2015-01-11 20:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2015-02-10 23:09 - 2015-01-11 20:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2015-02-10 23:09 - 2015-01-11 20:29 - 04300800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2015-02-10 23:09 - 2015-01-11 20:27 - 02358272 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-02-10 23:09 - 2015-01-11 20:23 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2015-02-10 23:09 - 2015-01-11 20:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2015-02-10 23:09 - 2015-01-11 20:22 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2015-02-10 23:09 - 2015-01-11 20:14 - 12829184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2015-02-10 23:09 - 2015-01-11 20:14 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-02-10 23:09 - 2015-01-11 20:02 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2015-02-10 23:09 - 2015-01-11 20:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2015-02-10 23:09 - 2015-01-11 19:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2015-02-10 23:09 - 2015-01-11 19:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2015-02-10 23:09 - 2015-01-10 01:48 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2015-02-10 23:09 - 2015-01-10 01:48 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2015-02-10 23:09 - 2015-01-10 01:48 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2015-02-10 23:09 - 2015-01-10 01:48 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2015-02-10 23:09 - 2015-01-10 01:48 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2015-02-10 23:09 - 2015-01-10 01:48 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2015-02-10 23:09 - 2015-01-10 01:48 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2015-02-10 23:09 - 2015-01-10 01:27 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2015-02-10 23:09 - 2015-01-10 01:27 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2015-02-10 23:09 - 2015-01-10 01:27 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2015-02-10 23:09 - 2015-01-10 01:27 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2015-02-10 23:09 - 2015-01-10 01:27 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2015-02-10 23:09 - 2015-01-10 01:27 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2015-02-10 23:09 - 2015-01-10 01:27 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2015-02-10 23:09 - 2015-01-08 22:14 - 00950272 _____ (Microsoft Corporation) C:\Windows\system32\perftrack.dll 2015-02-10 23:09 - 2015-01-08 22:14 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\wdi.dll 2015-02-10 23:09 - 2015-01-08 22:14 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\powertracker.dll 2015-02-10 23:09 - 2015-01-08 21:48 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdi.dll 2015-02-10 23:05 - 2015-01-15 03:14 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2015-02-10 23:05 - 2015-01-15 03:09 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2015-02-10 23:05 - 2015-01-15 03:04 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2015-02-10 23:05 - 2015-01-15 02:37 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2015-02-10 23:05 - 2015-01-14 23:22 - 00458824 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2015-02-10 23:05 - 2015-01-12 22:10 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2015-02-10 23:05 - 2015-01-12 21:49 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2015-02-10 23:04 - 2015-01-15 03:14 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2015-02-10 23:04 - 2015-01-15 03:09 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2015-02-10 23:04 - 2015-01-15 03:09 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2015-02-10 23:04 - 2015-01-15 03:09 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2015-02-10 23:04 - 2015-01-15 03:09 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2015-02-10 23:04 - 2015-01-15 03:08 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2015-02-10 23:04 - 2015-01-15 03:06 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2015-02-10 23:04 - 2015-01-15 03:06 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2015-02-10 23:04 - 2015-01-15 02:42 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2015-02-10 23:04 - 2015-01-15 02:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2015-02-10 23:04 - 2015-01-15 02:41 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2015-02-10 23:04 - 2015-01-15 02:39 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2015-02-10 23:04 - 2015-01-15 02:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2015-02-10 23:04 - 2014-12-12 00:31 - 01480192 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2015-02-10 23:04 - 2014-12-12 00:07 - 01174528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2015-02-10 23:04 - 2014-11-25 22:53 - 00861696 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2015-02-10 23:04 - 2014-11-25 22:32 - 00571904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll 2015-02-10 23:04 - 2014-10-03 21:10 - 03722752 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2015-02-10 23:04 - 2014-10-03 20:42 - 03221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2015-02-10 23:04 - 2014-10-03 20:42 - 00131584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll 2015-02-10 23:04 - 2014-07-06 21:07 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2015-02-10 23:04 - 2014-07-06 21:06 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2015-02-10 23:04 - 2014-07-06 20:40 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2015-02-10 23:04 - 2014-07-06 20:40 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2015-02-10 23:03 - 2015-01-14 01:09 - 05554112 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-02-10 23:03 - 2015-01-14 01:05 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2015-02-10 23:03 - 2015-01-14 01:05 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2015-02-10 23:03 - 2015-01-14 01:04 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2015-02-10 23:03 - 2015-01-14 00:44 - 03972544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2015-02-10 23:03 - 2015-01-14 00:44 - 03917760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2015-02-10 23:03 - 2015-01-14 00:41 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2015-02-10 23:02 - 2015-01-08 21:03 - 03201536 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2015-02-10 23:02 - 2014-12-07 22:09 - 00406528 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll 2015-02-10 23:02 - 2014-12-07 21:46 - 00308224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scesrv.dll 2015-02-09 21:53 - 2015-02-11 23:06 - 00000000 ____D () C:\Users\stevej89\Documents\OL 500 2015-02-09 20:45 - 2015-02-09 20:45 - 00118272 _____ () C:\Users\stevej89\Downloads\sample.ppt 2015-02-04 23:09 - 2015-02-04 23:09 - 30431144 _____ (Oracle Corporation) C:\Users\stevej89\Downloads\jre-8u31-windows-i586.com 2015-01-22 22:59 - 2015-01-22 22:59 - 00010215 _____ () C:\Users\stevej89\Documents\Flyers2014.xlsx 2015-01-16 17:23 - 2014-12-05 23:17 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll 2015-01-16 17:23 - 2014-12-05 22:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll 2015-01-16 17:23 - 2014-12-05 22:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll 2015-01-14 21:08 - 2014-12-18 22:06 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll 2015-01-14 21:08 - 2014-12-18 20:46 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2015-01-14 21:08 - 2014-12-11 12:47 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-02-12 22:30 - 2011-12-18 20:44 - 00009424 _____ () C:\Users\stevej89\Documents\aswMBR.txt 2015-02-12 22:30 - 2011-12-18 20:44 - 00000512 _____ () C:\Users\stevej89\Documents\MBR.dat 2015-02-12 22:19 - 2013-07-16 17:26 - 00000000 ____D () C:\Users\stevej89\AppData\Roaming\Skype 2015-02-12 22:05 - 2010-11-20 03:42 - 01484186 _____ () C:\Windows\WindowsUpdate.log 2015-02-12 21:49 - 2012-08-30 12:28 - 00000920 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3891086701-1241933595-968087049-1001UA.job 2015-02-12 21:36 - 2014-05-27 21:27 - 00019279 _____ () C:\Users\stevej89\Documents\Ebay.xlsx 2015-02-12 21:28 - 2013-09-23 21:54 - 05198336 _____ (AVAST Software) C:\Users\stevej89\Documents\aswMBR.exe 2015-02-12 21:26 - 2013-09-23 21:44 - 00852594 _____ () C:\Users\stevej89\Documents\SecurityCheck.exe 2015-02-12 21:12 - 2009-07-13 23:45 - 00026192 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-02-12 21:12 - 2009-07-13 23:45 - 00026192 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-02-12 21:09 - 2013-11-03 21:14 - 00080360 _____ () C:\VETlog.dmp 2015-02-12 21:06 - 2009-07-13 23:45 - 04979792 _____ () C:\Windows\system32\FNTCACHE.DAT 2015-02-12 21:05 - 2009-07-14 00:08 - 00032646 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2015-02-12 21:05 - 2009-07-14 00:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-02-12 21:05 - 2009-07-13 23:51 - 00072943 _____ () C:\Windows\setupact.log 2015-02-12 21:03 - 2014-12-21 12:31 - 00000000 ____D () C:\Windows\system32\appraiser 2015-02-12 21:03 - 2014-05-08 03:01 - 00000000 ___SD () C:\Windows\system32\CompatTel 2015-02-12 21:03 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\tracing 2015-02-12 21:02 - 2010-12-29 05:14 - 01030950 _____ () C:\Windows\PFRO.log 2015-02-11 20:31 - 2009-07-14 00:13 - 00783400 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-02-11 19:48 - 2012-08-30 12:28 - 00000868 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3891086701-1241933595-968087049-1001Core.job 2015-02-11 19:03 - 2011-12-19 00:49 - 00000000 ____D () C:\Qoobox 2015-02-11 18:58 - 2009-07-13 21:34 - 00000215 _____ () C:\Windows\system.ini 2015-02-11 18:34 - 2013-09-30 20:20 - 05611930 ____R (Swearware) C:\Users\stevej89\Documents\ComboFix.exe 2015-02-11 00:14 - 2011-02-15 16:34 - 00000000 ____D () C:\ProgramData\Microsoft Help 2015-02-08 20:36 - 2013-09-19 16:46 - 00003204 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForstevej89 2015-02-08 20:36 - 2013-09-19 16:46 - 00000344 _____ () C:\Windows\Tasks\HPCeeScheduleForstevej89.job 2015-02-08 19:50 - 2012-08-30 12:28 - 00002382 _____ () C:\Users\stevej89\Desktop\Google Chrome.lnk 2015-02-08 19:47 - 2010-12-29 21:50 - 00000052 _____ () C:\Windows\SysWOW64\DOErrors.log 2015-02-08 19:43 - 2012-08-30 12:28 - 00003900 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3891086701-1241933595-968087049-1001UA 2015-02-08 19:43 - 2012-08-30 12:28 - 00003504 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3891086701-1241933595-968087049-1001Core 2015-02-04 22:53 - 2011-02-17 16:02 - 00000000 ____D () C:\Users\stevej89\AppData\Local\CrashDumps ==================== Files in the root of some directories ======= 2012-08-22 19:26 - 2014-05-18 09:55 - 0001854 _____ () C:\Users\stevej89\AppData\Roaming\GhostObjGAFix.xml 2013-09-24 20:58 - 2013-09-26 03:03 - 0000095 _____ () C:\Users\stevej89\AppData\Roaming\WB.CFG 2013-09-24 20:58 - 2013-09-26 03:03 - 0000005 _____ () C:\Users\stevej89\AppData\Roaming\WBPU-TTL.DAT 2011-05-19 19:25 - 2013-07-01 19:25 - 0001940 _____ () C:\Users\stevej89\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini 2011-01-05 12:20 - 2011-01-05 23:03 - 0001627 _____ () C:\ProgramData\hpzinstall.log 2010-11-20 03:52 - 2010-11-20 03:52 - 0000032 _____ () C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log 2010-07-14 11:19 - 2010-07-14 11:20 - 0000109 _____ () C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log 2010-11-20 03:51 - 2010-11-20 03:51 - 0000032 _____ () C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log 2010-07-14 11:11 - 2010-07-14 11:13 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log 2010-11-20 03:51 - 2010-11-20 03:51 - 0000032 _____ () C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log 2010-11-20 03:52 - 2010-11-20 03:52 - 0000032 _____ () C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log 2010-07-14 11:11 - 2010-07-14 11:11 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log 2010-07-14 11:13 - 2010-07-14 11:19 - 0000110 _____ () C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log 2010-11-20 03:52 - 2010-11-20 03:52 - 0000105 _____ () C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-11-03 20:37 ==================== End Of Log ============================
Hi phillysportz ,

I cannot read the logs in their current format. Please re-post them after removing the word wrap setting in notepad.

[external image: bullseye_zpse9eaf36e.gif] Remove Word Wrap in Notepad
  • Click the Windows Start button.
  • Enter Notepad into the search box and double-click the application from the list of search results that appears. The Notepad application opens.
  • Click Format from the main menu in Notepad to display the formatting drop-down menu. You will see a check mark next to the words Word Wrap, which indicates that the Word Wrap feature is currently inserting line endings into your Notepad files.
  • Click Word Wrap to remove line endings. The check mark that used to appear next to Word Wrap disappears, indicating that you have successfully disabled this feature and removed all line endings from your document.
=========================

Re-post the new logs.
Word wrap is unchecked. Results of screen317's Security Check version 0.99.79 Windows 7 Service Pack 1 x64 (UAC is disabled!) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Windows Firewall Enabled! WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:````````` Java(TM) 6 Update 30 Java version out of Date! Adobe Reader 9 Adobe Reader out of Date! Google Chrome 40.0.2214.111 Google Chrome 40.0.2214.94 ````````Process Check: objlist.exe by Laurent```````` Symantec Norton Online Backup NOBuAgent.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log``````````````````````
aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-12-18 20:43:14 —————————– 20:43:14.257 OS Version: Windows x64 6.1.7601 Service Pack 1 20:43:14.257 Number of processors: 2 586 0x603 20:43:14.258 ComputerName: STEVEJ89-HP UserName: stevej89 20:43:20.594 Initialize success 20:43:38.248 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000064 20:43:38.250 Disk 0 Vendor: TOSHIBA_ GJ00 Size: 305245MB BusType: 11 20:43:40.305 Disk 0 MBR read successfully 20:43:40.308 Disk 0 MBR scan 20:43:40.310 Disk 0 unknown MBR code 20:43:40.315 Service scanning 20:43:44.330 Modules scanning 20:43:44.333 Disk 0 trace - called modules: 20:43:44.372 ntoskrnl.exe CLASSPNP.SYS disk.sys amdxata.sys storport.sys hal.dll amdsata.sys 20:43:44.375 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80031e6060] 20:43:44.379 3 CLASSPNP.SYS[fffff88001b4943f] -> nt!IofCallDriver -> [0xfffffa80021dab80] 20:43:44.383 5 amdxata.sys[fffff8800111e7a8] -> nt!IofCallDriver -> \Device\00000064[0xfffffa8003186060] 20:43:44.387 Scan finished successfully 20:44:52.268 Disk 0 MBR has been saved successfully to "C:\Users\stevej89\Documents\MBR.dat" 20:44:52.275 The log file has been saved successfully to "C:\Users\stevej89\Documents\aswMBR.txt" aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software Run date: 2013-09-23 22:55:11 —————————– 22:55:11.892 OS Version: Windows x64 6.1.7601 Service Pack 1 22:55:11.892 Number of processors: 2 586 0x603 22:55:11.892 ComputerName: STEVEJ89-HP UserName: stevej89 22:55:15.558 Initialize success 22:58:26.868 AVAST engine defs: 13092301 22:58:45.425 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000064 22:58:45.431 Disk 0 Vendor: TOSHIBA_ GJ00 Size: 305245MB BusType: 11 22:58:46.212 Disk 0 MBR read successfully 22:58:46.218 Disk 0 MBR scan 22:58:46.230 Disk 0 unknown MBR code 22:58:46.365 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 199 MB offset 2048 22:58:46.429 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 287356 MB offset 409600 22:58:46.476 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 17585 MB offset 588914688 22:58:46.539 Disk 0 Partition 4 00 0C FAT32 LBA MSDOS5.0 103 MB offset 624928768 22:58:47.270 Disk 0 scanning C:\Windows\system32\drivers 22:59:40.285 Service scanning 23:01:05.337 Modules scanning 23:01:05.357 Disk 0 trace - called modules: 23:01:05.382 ntoskrnl.exe CLASSPNP.SYS disk.sys amdxata.sys storport.sys hal.dll amdsata.sys 23:01:05.395 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80031ec060] 23:01:05.408 3 CLASSPNP.SYS[fffff8800145143f] -> nt!IofCallDriver -> [0xfffffa8003191450] 23:01:05.421 5 amdxata.sys[fffff880010707a8] -> nt!IofCallDriver -> \Device\00000064[0xfffffa8003074420] 23:01:07.194 AVAST engine scan C:\Windows 23:01:11.861 AVAST engine scan C:\Windows\system32 23:07:33.311 AVAST engine scan C:\Windows\system32\drivers 23:07:56.438 AVAST engine scan C:\Users\stevej89 23:36:49.085 File: C:\Users\stevej89\Downloads\dds.scr **INFECTED** Win32:Malware-gen 23:44:38.755 AVAST engine scan C:\ProgramData 23:58:04.933 Scan finished successfully 00:02:03.118 Disk 0 MBR has been saved successfully to "C:\Users\stevej89\Documents\MBR.dat" 00:02:03.164 The log file has been saved successfully to "C:\Users\stevej89\Documents\aswMBR.txt" aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software Run date: 2015-02-12 21:30:56 —————————– 21:30:56.301 OS Version: Windows x64 6.1.7601 Service Pack 1 21:30:56.301 Number of processors: 2 586 0x603 21:30:56.301 ComputerName: STEVEJ89-HP UserName: stevej89 21:30:57.341 Initialize success 21:30:57.551 VM: initialized successfully 21:30:57.551 VM: Amd CPU supported 21:34:45.176 AVAST engine defs: 15021201 21:38:50.566 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000005c 21:38:50.576 Disk 0 Vendor: TOSHIBA_ GJ00 Size: 305245MB BusType: 11 21:38:50.706 Disk 0 MBR read successfully 21:38:50.716 Disk 0 MBR scan 21:38:50.726 Disk 0 unknown MBR code 21:38:50.736 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 199 MB offset 2048 21:38:50.746 Disk 0 default boot code 21:38:50.766 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 287356 MB offset 409600 21:38:50.806 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 17585 MB offset 588914688 21:38:50.836 Disk 0 Partition 4 00 0C FAT32 LBA MSDOS5.0 103 MB offset 624928768 21:38:51.004 Disk 0 scanning C:\Windows\system32\drivers 21:39:09.785 Service scanning 21:40:17.174 Modules scanning 21:40:17.184 Disk 0 trace - called modules: 21:40:17.234 ntoskrnl.exe CLASSPNP.SYS disk.sys amdxata.sys storport.sys hal.dll amdsata.sys 21:40:17.244 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80031dc6e0] 21:40:17.254 3 CLASSPNP.SYS[fffff8800195543f] -> nt!IofCallDriver -> [0xfffffa8003182b80] 21:40:17.264 5 amdxata.sys[fffff8800113d7a8] -> nt!IofCallDriver -> \Device\0000005c[0xfffffa8003061700] 21:40:18.384 AVAST engine scan C:\Windows 21:40:23.541 AVAST engine scan C:\Windows\system32 21:46:40.691 AVAST engine scan C:\Windows\system32\drivers 21:47:01.864 AVAST engine scan C:\Users\stevej89 22:08:58.634 File: C:\Users\stevej89\Documents\iLividSetupV1.exe **INFECTED** Win32:Adware-gen [Adw] 22:09:11.737 File: C:\Users\stevej89\Downloads\dds.scr **INFECTED** Win32:Malware-gen 22:09:12.547 File: C:\Users\stevej89\Downloads\iLividSetupV1.exe **INFECTED** Win32:Adware-gen [Adw] 22:22:05.974 File: C:\Users\stevej89\Pictures\iLividSetupV1.exe **INFECTED** Win32:Adware-gen [Adw] 22:22:57.645 AVAST engine scan C:\ProgramData 22:24:20.897 File: C:\ProgramData\BitGuard\2.7.1832.68\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\x64injector.exe **INFECTED** Win64:Adware-B [Adw] 22:28:40.289 Disk 0 statistics 4492610/0/0 @ 0.92 MB/s 22:28:40.309 Scan finished successfully 22:29:22.807 Disk 0 MBR has been saved successfully to "C:\Users\stevej89\Documents\MBR.dat" 22:29:22.967 The log file has been saved successfully to "C:\Users\stevej89\Documents\aswMBR.txt" aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software Run date: 2015-02-12 21:30:56 —————————– 21:30:56.301 OS Version: Windows x64 6.1.7601 Service Pack 1 21:30:56.301 Number of processors: 2 586 0x603 21:30:56.301 ComputerName: STEVEJ89-HP UserName: stevej89 21:30:57.341 Initialize success 21:30:57.551 VM: initialized successfully 21:30:57.551 VM: Amd CPU supported 21:34:45.176 AVAST engine defs: 15021201 21:38:50.566 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000005c 21:38:50.576 Disk 0 Vendor: TOSHIBA_ GJ00 Size: 305245MB BusType: 11 21:38:50.706 Disk 0 MBR read successfully 21:38:50.716 Disk 0 MBR scan 21:38:50.726 Disk 0 unknown MBR code 21:38:50.736 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 199 MB offset 2048 21:38:50.746 Disk 0 default boot code 21:38:50.766 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 287356 MB offset 409600 21:38:50.806 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 17585 MB offset 588914688 21:38:50.836 Disk 0 Partition 4 00 0C FAT32 LBA MSDOS5.0 103 MB offset 624928768 21:38:51.004 Disk 0 scanning C:\Windows\system32\drivers 21:39:09.785 Service scanning 21:40:17.174 Modules scanning 21:40:17.184 Disk 0 trace - called modules: 21:40:17.234 ntoskrnl.exe CLASSPNP.SYS disk.sys amdxata.sys storport.sys hal.dll amdsata.sys 21:40:17.244 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80031dc6e0] 21:40:17.254 3 CLASSPNP.SYS[fffff8800195543f] -> nt!IofCallDriver -> [0xfffffa8003182b80] 21:40:17.264 5 amdxata.sys[fffff8800113d7a8] -> nt!IofCallDriver -> \Device\0000005c[0xfffffa8003061700] 21:40:18.384 AVAST engine scan C:\Windows 21:40:23.541 AVAST engine scan C:\Windows\system32 21:46:40.691 AVAST engine scan C:\Windows\system32\drivers 21:47:01.864 AVAST engine scan C:\Users\stevej89 22:08:58.634 File: C:\Users\stevej89\Documents\iLividSetupV1.exe **INFECTED** Win32:Adware-gen [Adw] 22:09:11.737 File: C:\Users\stevej89\Downloads\dds.scr **INFECTED** Win32:Malware-gen 22:09:12.547 File: C:\Users\stevej89\Downloads\iLividSetupV1.exe **INFECTED** Win32:Adware-gen [Adw] 22:22:05.974 File: C:\Users\stevej89\Pictures\iLividSetupV1.exe **INFECTED** Win32:Adware-gen [Adw] 22:22:57.645 AVAST engine scan C:\ProgramData 22:24:20.897 File: C:\ProgramData\BitGuard\2.7.1832.68\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\x64injector.exe **INFECTED** Win64:Adware-B [Adw] 22:28:40.289 Disk 0 statistics 4492610/0/0 @ 0.92 MB/s 22:28:40.309 Scan finished successfully 22:29:22.807 Disk 0 MBR has been saved successfully to "C:\Users\stevej89\Documents\MBR.dat" 22:29:22.967 The log file has been saved successfully to "C:\Users\stevej89\Documents\aswMBR.txt" 22:30:38.167 Disk 0 MBR has been saved successfully to "C:\Users\stevej89\Documents\MBR.dat" 22:30:38.183 The log file has been saved successfully to "C:\Users\stevej89\Documents\aswMBR.txt"
aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-12-18 20:43:14 —————————– 20:43:14.257 OS Version: Windows x64 6.1.7601 Service Pack 1 20:43:14.257 Number of processors: 2 586 0x603 20:43:14.258 ComputerName: STEVEJ89-HP UserName: stevej89 20:43:20.594 Initialize success 20:43:38.248 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000064 20:43:38.250 Disk 0 Vendor: TOSHIBA_ GJ00 Size: 305245MB BusType: 11 20:43:40.305 Disk 0 MBR read successfully 20:43:40.308 Disk 0 MBR scan 20:43:40.310 Disk 0 unknown MBR code 20:43:40.315 Service scanning 20:43:44.330 Modules scanning 20:43:44.333 Disk 0 trace - called modules: 20:43:44.372 ntoskrnl.exe CLASSPNP.SYS disk.sys amdxata.sys storport.sys hal.dll amdsata.sys 20:43:44.375 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80031e6060] 20:43:44.379 3 CLASSPNP.SYS[fffff88001b4943f] -> nt!IofCallDriver -> [0xfffffa80021dab80] 20:43:44.383 5 amdxata.sys[fffff8800111e7a8] -> nt!IofCallDriver -> \Device\00000064[0xfffffa8003186060] 20:43:44.387 Scan finished successfully 20:44:52.268 Disk 0 MBR has been saved successfully to "C:\Users\stevej89\Documents\MBR.dat" 20:44:52.275 The log file has been saved successfully to "C:\Users\stevej89\Documents\aswMBR.txt" aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software Run date: 2013-09-23 22:55:11 —————————– 22:55:11.892 OS Version: Windows x64 6.1.7601 Service Pack 1 22:55:11.892 Number of processors: 2 586 0x603 22:55:11.892 ComputerName: STEVEJ89-HP UserName: stevej89 22:55:15.558 Initialize success 22:58:26.868 AVAST engine defs: 13092301 22:58:45.425 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000064 22:58:45.431 Disk 0 Vendor: TOSHIBA_ GJ00 Size: 305245MB BusType: 11 22:58:46.212 Disk 0 MBR read successfully 22:58:46.218 Disk 0 MBR scan 22:58:46.230 Disk 0 unknown MBR code 22:58:46.365 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 199 MB offset 2048 22:58:46.429 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 287356 MB offset 409600 22:58:46.476 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 17585 MB offset 588914688 22:58:46.539 Disk 0 Partition 4 00 0C FAT32 LBA MSDOS5.0 103 MB offset 624928768 22:58:47.270 Disk 0 scanning C:\Windows\system32\drivers 22:59:40.285 Service scanning 23:01:05.337 Modules scanning 23:01:05.357 Disk 0 trace - called modules: 23:01:05.382 ntoskrnl.exe CLASSPNP.SYS disk.sys amdxata.sys storport.sys hal.dll amdsata.sys 23:01:05.395 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80031ec060] 23:01:05.408 3 CLASSPNP.SYS[fffff8800145143f] -> nt!IofCallDriver -> [0xfffffa8003191450] 23:01:05.421 5 amdxata.sys[fffff880010707a8] -> nt!IofCallDriver -> \Device\00000064[0xfffffa8003074420] 23:01:07.194 AVAST engine scan C:\Windows 23:01:11.861 AVAST engine scan C:\Windows\system32 23:07:33.311 AVAST engine scan C:\Windows\system32\drivers 23:07:56.438 AVAST engine scan C:\Users\stevej89 23:36:49.085 File: C:\Users\stevej89\Downloads\dds.scr **INFECTED** Win32:Malware-gen 23:44:38.755 AVAST engine scan C:\ProgramData 23:58:04.933 Scan finished successfully 00:02:03.118 Disk 0 MBR has been saved successfully to "C:\Users\stevej89\Documents\MBR.dat" 00:02:03.164 The log file has been saved successfully to "C:\Users\stevej89\Documents\aswMBR.txt" aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software Run date: 2015-02-12 21:30:56 —————————– 21:30:56.301 OS Version: Windows x64 6.1.7601 Service Pack 1 21:30:56.301 Number of processors: 2 586 0x603 21:30:56.301 ComputerName: STEVEJ89-HP UserName: stevej89 21:30:57.341 Initialize success 21:30:57.551 VM: initialized successfully 21:30:57.551 VM: Amd CPU supported 21:34:45.176 AVAST engine defs: 15021201 21:38:50.566 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000005c 21:38:50.576 Disk 0 Vendor: TOSHIBA_ GJ00 Size: 305245MB BusType: 11 21:38:50.706 Disk 0 MBR read successfully 21:38:50.716 Disk 0 MBR scan 21:38:50.726 Disk 0 unknown MBR code 21:38:50.736 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 199 MB offset 2048 21:38:50.746 Disk 0 default boot code 21:38:50.766 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 287356 MB offset 409600 21:38:50.806 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 17585 MB offset 588914688 21:38:50.836 Disk 0 Partition 4 00 0C FAT32 LBA MSDOS5.0 103 MB offset 624928768 21:38:51.004 Disk 0 scanning C:\Windows\system32\drivers 21:39:09.785 Service scanning 21:40:17.174 Modules scanning 21:40:17.184 Disk 0 trace - called modules: 21:40:17.234 ntoskrnl.exe CLASSPNP.SYS disk.sys amdxata.sys storport.sys hal.dll amdsata.sys 21:40:17.244 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80031dc6e0] 21:40:17.254 3 CLASSPNP.SYS[fffff8800195543f] -> nt!IofCallDriver -> [0xfffffa8003182b80] 21:40:17.264 5 amdxata.sys[fffff8800113d7a8] -> nt!IofCallDriver -> \Device\0000005c[0xfffffa8003061700] 21:40:18.384 AVAST engine scan C:\Windows 21:40:23.541 AVAST engine scan C:\Windows\system32 21:46:40.691 AVAST engine scan C:\Windows\system32\drivers 21:47:01.864 AVAST engine scan C:\Users\stevej89 22:08:58.634 File: C:\Users\stevej89\Documents\iLividSetupV1.exe **INFECTED** Win32:Adware-gen [Adw] 22:09:11.737 File: C:\Users\stevej89\Downloads\dds.scr **INFECTED** Win32:Malware-gen 22:09:12.547 File: C:\Users\stevej89\Downloads\iLividSetupV1.exe **INFECTED** Win32:Adware-gen [Adw] 22:22:05.974 File: C:\Users\stevej89\Pictures\iLividSetupV1.exe **INFECTED** Win32:Adware-gen [Adw] 22:22:57.645 AVAST engine scan C:\ProgramData 22:24:20.897 File: C:\ProgramData\BitGuard\2.7.1832.68\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\x64injector.exe **INFECTED** Win64:Adware-B [Adw] 22:28:40.289 Disk 0 statistics 4492610/0/0 @ 0.92 MB/s 22:28:40.309 Scan finished successfully 22:29:22.807 Disk 0 MBR has been saved successfully to "C:\Users\stevej89\Documents\MBR.dat" 22:29:22.967 The log file has been saved successfully to "C:\Users\stevej89\Documents\aswMBR.txt" aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software Run date: 2015-02-12 21:30:56 —————————– 21:30:56.301 OS Version: Windows x64 6.1.7601 Service Pack 1 21:30:56.301 Number of processors: 2 586 0x603 21:30:56.301 ComputerName: STEVEJ89-HP UserName: stevej89 21:30:57.341 Initialize success 21:30:57.551 VM: initialized successfully 21:30:57.551 VM: Amd CPU supported 21:34:45.176 AVAST engine defs: 15021201 21:38:50.566 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000005c 21:38:50.576 Disk 0 Vendor: TOSHIBA_ GJ00 Size: 305245MB BusType: 11 21:38:50.706 Disk 0 MBR read successfully 21:38:50.716 Disk 0 MBR scan 21:38:50.726 Disk 0 unknown MBR code 21:38:50.736 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 199 MB offset 2048 21:38:50.746 Disk 0 default boot code 21:38:50.766 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 287356 MB offset 409600 21:38:50.806 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 17585 MB offset 588914688 21:38:50.836 Disk 0 Partition 4 00 0C FAT32 LBA MSDOS5.0 103 MB offset 624928768 21:38:51.004 Disk 0 scanning C:\Windows\system32\drivers 21:39:09.785 Service scanning 21:40:17.174 Modules scanning 21:40:17.184 Disk 0 trace - called modules: 21:40:17.234 ntoskrnl.exe CLASSPNP.SYS disk.sys amdxata.sys storport.sys hal.dll amdsata.sys 21:40:17.244 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80031dc6e0] 21:40:17.254 3 CLASSPNP.SYS[fffff8800195543f] -> nt!IofCallDriver -> [0xfffffa8003182b80] 21:40:17.264 5 amdxata.sys[fffff8800113d7a8] -> nt!IofCallDriver -> \Device\0000005c[0xfffffa8003061700] 21:40:18.384 AVAST engine scan C:\Windows 21:40:23.541 AVAST engine scan C:\Windows\system32 21:46:40.691 AVAST engine scan C:\Windows\system32\drivers 21:47:01.864 AVAST engine scan C:\Users\stevej89 22:08:58.634 File: C:\Users\stevej89\Documents\iLividSetupV1.exe **INFECTED** Win32:Adware-gen [Adw] 22:09:11.737 File: C:\Users\stevej89\Downloads\dds.scr **INFECTED** Win32:Malware-gen 22:09:12.547 File: C:\Users\stevej89\Downloads\iLividSetupV1.exe **INFECTED** Win32:Adware-gen [Adw] 22:22:05.974 File: C:\Users\stevej89\Pictures\iLividSetupV1.exe **INFECTED** Win32:Adware-gen [Adw] 22:22:57.645 AVAST engine scan C:\ProgramData 22:24:20.897 File: C:\ProgramData\BitGuard\2.7.1832.68\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\x64injector.exe **INFECTED** Win64:Adware-B [Adw] 22:28:40.289 Disk 0 statistics 4492610/0/0 @ 0.92 MB/s 22:28:40.309 Scan finished successfully 22:29:22.807 Disk 0 MBR has been saved successfully to "C:\Users\stevej89\Documents\MBR.dat" 22:29:22.967 The log file has been saved successfully to "C:\Users\stevej89\Documents\aswMBR.txt" 22:30:38.167 Disk 0 MBR has been saved successfully to "C:\Users\stevej89\Documents\MBR.dat" 22:30:38.183 The log file has been saved successfully to "C:\Users\stevej89\Documents\aswMBR.txt"
I'm sorry they are posting that way regardless. I do see a few malware programs in the log. Please let me know what scans to run to remove them.

Go back into notepad and select word wrap and see if it changes the formatting. Because as the aswMBR,  FRST and Addition logs are right now I can't read them to formulate a fix

Hi phillysportz ,

Please post all logs in one (1) reply window. (if they will fit).

=========================

Open Notepad and verify that Word Wrap is unchecked, then close Notepad.

=========================

Re-run the following scans:

[external image: bullseye_zpse9eaf36e.gif] aswMBR

Download aswMBR.exe and save it to your desktop.

    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click Scan
  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.

=========================

[external image: bullseye_zpse9eaf36e.gif] Re-run Farbar Recovery Scan Tool it should be on your desktop.

    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • When the tool opens click Yes to disclaimer.
  • Select the Addition box
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • It will also make (Addition.txt). Please attach it to your reply

=========================

In your next post please provide the following:

  • aswMBR.txt
  • attach MBR.zip
  • FRST.txt
  • Addition.txt

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI