This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

NASTY Trojan:Ransomware !.. [Solved]

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Dear Person;…

This IS one HELLUVA LONG post…
I'd  suggest you grab a six-pack & settle in for a long haul !!!


My computer started acting strange & I went to System Restore to reset it…
The restore seemed to work but it actually did not restore correctly…
It took me awhile to get the message that something was going on that shouldn't have…
Glitches started with IE11 , some files were misbehaving , etc..
I tried to use the "repair" feature of the new Win8…
I used the ISO image & started a repair..

All went well till I got to the execute function of the repair process…
I got the following message;=>
""The Drive Where Windows is Located is LOCKED..
Unlock the Drive & Try Again""…

I went to Safe Mode & scanned with Avast , nothing found…
I scanned with MBAM & it found some PUP infections that I promptly eliminated…
I then downloaded Sophos Virus Removal Tool..(128MBs)…
I ran a scan…(TWO HOURS !!)..
Lo & behold , it found the problem !!!..
I have a "Trojan:Ransomware" infection !!!..
I tried to find some "Trojan:Ransomware" Removal programs & was unable to get any results…
Hence my being here….
Here is some further information on the Trojan that Sophos found;=>…

Detailed Analysis - Troj/Ransom-BDZ - Viruses and Spyware - Web Threat, Virus and Spyware Detection and Removal | Sophos - Threat …
More info can be found here;=>..
https://www.sophos.com/en-us/search-results.aspx?search=Troj~Ransom-BDZ&refine;=7edf01e4de3c4c8791a56ba6ce685d09

Farbar Recovery Scan Tool (FRST) Goes to:=>..
http://www.geekstogo.com/forum/files/getdownload/692-frst-farbars-recovery-scan-tool/
This is the message there;=>..
""Sorry, we couldn't find that!""
I found one at;=>..
http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Downloaded it & ran scans….


aswMBR results;=>..
 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2015-10-02 14:40:39
—————————–
14:40:39.233    OS Version: Windows 6.2.9200
14:40:39.234    Number of processors: 1 586 0x401
14:40:39.237    ComputerName: HOME  UserName:
14:42:13.596    Initialize success
14:42:14.473    VM: initialized successfully
14:42:14.476    VM: Intel CPU virtualization not supported
15:03:22.787    AVAST engine defs: 15100202
15:21:32.884    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-1
15:21:32.888    Disk 0 Vendor: ST3500820AS SD81 Size: 476940MB BusType: 3
15:21:33.037    Disk 0 MBR read successfully
15:21:33.041    Disk 0 MBR scan
15:21:33.273    Disk 0 Windows 7 default MBR code
15:21:33.293    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS       476588 MB offset 718848
15:21:33.327    Disk 0 scanning sectors +976771072
15:21:33.592    Disk 0 scanning C:\WINDOWS\system32\drivers
15:21:57.474    Service scanning
15:22:01.467    Service bdfwfpf C:\Program Files\Bitdefender\Antivirus Free Edition\bdfwfpf.sys **LOCKED** 5
15:22:02.202    Service bdselfpr C:\Program Files\Bitdefender\Antivirus Free Edition\bdselfpr.sys **LOCKED** 5
15:22:40.920    Modules scanning
15:22:40.970    Disk 0 trace - called modules:
15:22:40.993    ntoskrnl.exe CLASSPNP.SYS disk.sys ataport.SYS halmacpi.dll intelide.sys PCIIDEX.SYS atapi.sys
15:22:41.003    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x88795910]
15:22:41.053    3 CLASSPNP.SYS[8619863c] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-1[0x8877c030]
15:22:43.694    AVAST engine scan C:\WINDOWS
15:22:49.874    AVAST engine scan C:\WINDOWS\system32
15:31:06.699    AVAST engine scan C:\WINDOWS\system32\drivers
15:31:51.927    AVAST engine scan C:\Users\Ron.M
15:36:48.682    Disk 0 MBR has been saved successfully to "C:\Users\Ron.M\Desktop\MBR.dat"
15:36:48.765    The log file has been saved successfully to "C:\Users\Ron.M\Desktop\aswMBR.txt"

 

 

Farbar Recovery Scan Tool (FRST) Results;=>..
FRST.txt

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:30-09-2015
Ran by [removed] (administrator) on HOME (02-10-2015 16:06:53)
Running from C:\Users\[removed]\Desktop

FRST.txt

[removed] Platform: Microsoft Windows 8.1 Pro (X86) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Bitdefender) C:\Program Files\Bitdefender\Antivirus Free Edition\gzserv.exe
(LSI Corporation) C:\Program Files\LSI SoftModem\agrsmsvc.exe
(iolo technologies, LLC) C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe
( ) C:\Windows\System32\lxdpcoms.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Exploit\mbae-svc.exe
(Bitdefender) C:\Program Files\Bitdefender\Antivirus Free Edition\gziface.exe
(iolo technologies, LLC) C:\Program Files\iolo\System Mechanic\ioloGovernor.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(Paramount Software UK Ltd) C:\Program Files\Macrium\Reflect\ReflectService.exe
( ) C:\Windows\System32\slserv.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Google Inc.) C:\Program Files\Google\Gmail Notifier\gnotify.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Exploit\mbae.exe
(Siber Systems) C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe
(Microsoft Corporation) C:\Windows\System32\perfmon.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(AVAST Software) C:\Users\Ron.M\Desktop\aswMBR.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\…\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] => C:\Program Files\Google\Gmail Notifier\gnotify.exe [479232 2005-07-15] (Google Inc.)
HKLM\…\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [150208 2014-01-18] (IvoSoft)
HKLM\…\Run: [iolo Startup] => C:\Program Files\iolo\Common\Lib\ioloLManager.exe [4536120 2015-07-24] (iolo technologies, LLC)
HKLM\…\Run: [Greenshot] => C:\Program Files\Greenshot\Greenshot.exe [540672 2015-04-19] (Greenshot)
HKLM\…\Run: [Malwarebytes Anti-Exploit] => C:\Program Files\Malwarebytes Anti-Exploit\mbae.exe [2620728 2015-07-22] (Malwarebytes Corporation)
HKU\S-1-5-21-2697119639-1211797034-894152058-1001\…\Run: [NetZero_uoltray] => C:\Program Files\NetZero\exec.exe [1776640 2010-06-29] (NetZero, Inc.)
HKU\S-1-5-21-2697119639-1211797034-894152058-1001\…\Run: [RoboForm] => C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [111320 2015-07-02] (Siber Systems)
HKU\S-1-5-21-2697119639-1211797034-894152058-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Ribbons.scr [120832 2014-11-21] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  No File
ShellIconOverlayIdentifiers: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer32.dll [2014-01-18] (IvoSoft)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ImageBrowser EX Agent.lnk [2015-08-01]
ShortcutTarget: ImageBrowser EX Agent.lnk -> C:\Program Files\Canon\ImageBrowser EX\MFManager.exe ()

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 [removed]
Tcpip\..\Interfaces\{A983AEA1-09B4-44F5-8D1C-7FB64360C76A}: [DhcpNameServer] 192.168.0.1 [removed]

Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-2697119639-1211797034-894152058-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://my.netzero.net/s/search?r=minisearch
HKU\S-1-5-21-2697119639-1211797034-894152058-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://centurylink.net/?dc=O&s;=e77e1ca0-581a-3472-1d5b-39d1f285b39a&p;=2036&k;=f69bda69-22e4-40ac-9305-c0b7019b67a8&d;=lctl-res&pct;=100
HKU\S-1-5-21-2697119639-1211797034-894152058-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://my.netzero.net/s/search?r=minisearch
HKU\S-1-5-21-2697119639-1211797034-894152058-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
URLSearchHook: [S-1-5-21-2697119639-1211797034-894152058-1001] ATTENTION => Default URLSearchHook is missing
URLSearchHook: HKU\S-1-5-21-2697119639-1211797034-894152058-1001 - (No Name) - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} -  No File
SearchScopes: HKU\S-1-5-21-2697119639-1211797034-894152058-1001 -> {88BA080D-DF1A-45D2-8CE2-8461E30FBFFE} URL = hxxp://search.netzero.net/search?action=search&source;=browserboxapp_isp&query;={searchTerms}
BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer32.dll [2014-01-18] (IvoSoft)
BHO: RoboForm Toolbar Helper -> {724d43a9-0d85-11d4-9908-00400523e39a} -> C:\Program Files\Siber Systems\AI RoboForm\roboform.dll [2015-07-02] (Siber Systems Inc.)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_51\bin\ssv.dll [2015-08-02] (Oracle Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_51\bin\jp2ssv.dll [2015-08-02] (Oracle Corporation)
BHO: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_32.dll [2014-01-18] (IvoSoft)
BHO: NetZero Toolbar Helper -> {FE3098B0-04A3-41fd-8CA9-BEA39CB14C87} -> C:\Program Files\NetZero\ucreg.dll [2010-06-30] (NetZero, Inc.)
Toolbar: HKLM - &RoboForm; Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll [2015-07-02] (Siber Systems Inc.)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2014-01-18] (IvoSoft)
Toolbar: HKU\S-1-5-21-2697119639-1211797034-894152058-1001 -> &RoboForm; Toolbar - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll [2015-07-02] (Siber Systems Inc.)
Toolbar: HKU\S-1-5-21-2697119639-1211797034-894152058-1001 -> No Name - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} -  No File

FireFox:
========
FF Plugin: @canon.com/MycameraPlugin -> C:\Program Files\Canon\MyCamera Download Plugin\NPCIG.dll [2008-10-15] (CANON INC.)
FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll [2015-07-10] (Google, Inc.)
FF Plugin: @java.com/DTPlugin,version=11.51.2 -> C:\Program Files\Java\jre1.8.0_51\bin\dtplugin\npDeployJava1.dll [2015-08-02] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.51.2 -> C:\Program Files\Java\jre1.8.0_51\bin\plugin2\npjp2.dll [2015-08-02] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AgereModemAudio; C:\Program Files\LSI SoftModem\agrsmsvc.exe [14336 2009-03-27] (LSI Corporation)
R2 BFE; C:\WINDOWS\System32\bfe.dll [570368 2015-08-10] (Microsoft Corporation) [File not signed]
R2 gzserv; C:\Program Files\Bitdefender\Antivirus Free Edition\gzserv.exe [57520 2013-10-23] (Bitdefender)
R2 ioloSystemService; C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe [4682040 2015-07-24] (iolo technologies, LLC)
S3 lxcf_device; C:\WINDOWS\system32\lxcfcoms.exe [491520 2005-07-25] ( )
R2 lxdp_device; C:\WINDOWS\system32\lxdpcoms.exe [589824 2007-11-19] ( )
R2 MbaeSvc; C:\Program Files\Malwarebytes Anti-Exploit\mbae-svc.exe [713016 2015-07-22] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 ReflectService.exe; C:\Program Files\Macrium\Reflect\ReflectService.exe [2589136 2015-02-23] (Paramount Software UK Ltd)
R2 SLService; C:\WINDOWS\system32\slserv.exe [45056 2004-05-12] ( ) [File not signed]
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [284520 2015-07-07] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [22224 2015-07-07] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R0 avc3; C:\WINDOWS\System32\DRIVERS\avc3.sys [633344 2013-04-17] (BitDefender)
S3 avckf; C:\WINDOWS\System32\DRIVERS\avckf.sys [486536 2013-04-17] (BitDefender)
R1 bdfwfpf; C:\Program Files\Bitdefender\Antivirus Free Edition\bdfwfpf.sys [108008 2013-07-02] (Bitdefender SRL)
R1 bdselfpr; C:\Program Files\Bitdefender\Antivirus Free Edition\bdselfpr.sys [135472 2013-07-16] (BitDefender LLC)
R1 ElRawDisk; C:\Windows\system32\drivers\ElRawDsk.sys [26248 2012-12-06] (EldoS Corporation)
S3 EsgScanner; C:\WINDOWS\System32\DRIVERS\EsgScanner.sys [19984 2015-10-01] ()
R1 ESProtectionDriver; C:\Program Files\Malwarebytes Anti-Exploit\mbae.sys [47928 2015-07-22] ()
R3 gzflt; C:\WINDOWS\System32\DRIVERS\gzflt.sys [164952 2013-04-22] (BitDefender LLC)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [23256 2015-06-18] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [51928 2015-06-18] (Malwarebytes Corporation)
S3 Mtlstrm; C:\WINDOWS\system32\DRIVERS\Mtlstrm.sys [1395296 2004-05-12] ( ) [File not signed]
R2 PDFsFilter; C:\WINDOWS\System32\DRIVERS\PDFsFilter.sys [69016 2015-07-24] (Raxco Software, Inc.)
R1 RawDisk3; C:\WINDOWS\system32\drivers\rawdsk3.sys [28088 2015-07-24] (EldoS Corporation)
R0 RecAgent; C:\WINDOWS\System32\DRIVERS\RecAgent.sys [14408 2004-05-12] ( ) [File not signed]
S3 SlNtHal; C:\WINDOWS\system32\DRIVERS\Slnthal.sys [100384 2004-05-12] ( ) [File not signed]
S3 SlWdmSup; C:\WINDOWS\system32\DRIVERS\SlWdmSup.sys [13232 2004-05-12] ( ) [File not signed]
R0 trufos; C:\WINDOWS\System32\DRIVERS\trufos.sys [355744 2013-05-28] (BitDefender S.R.L.)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [38928 2015-07-07] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [233304 2015-07-07] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [84824 2015-07-07] (Microsoft Corporation)
S3 WUDFWpdMtp; C:\WINDOWS\system32\DRIVERS\WUDFRd.sys [190976 2014-11-21] (Microsoft Corporation)
S1 BAPIDRV; system32\DRIVERS\BAPIDRV.sys [X]
U3 aswMBR; \??\C:\Users\RONALD~1\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\RONALD~1\AppData\Local\Temp\aswVmm.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-10-02 16:06 - 2015-10-02 16:07 - 00011894 _____ C:\Users\Ron.M\Desktop\FRST.txt
2015-10-02 16:06 - 2015-10-02 16:06 - 00000000 ____D C:\FRST
2015-10-02 15:59 - 2015-10-02 15:56 - 01696256 _____ (Farbar) C:\Users\Ron.M\Desktop\FRST.exe
2015-10-02 15:56 - 2015-10-02 15:56 - 01696256 _____ (Farbar) C:\Users\Ron.M\Downloads\FRST.exe
2015-10-02 15:36 - 2015-10-02 15:38 - 00001991 _____ C:\Users\Ron.M\Desktop\aswMBR.txt
2015-10-02 15:36 - 2015-10-02 15:36 - 00000512 _____ C:\Users\Ron.M\Desktop\MBR.dat
2015-10-02 15:10 - 2015-10-02 15:10 - 00001119 _____ C:\Users\Ron.M\Desktop\Naturpic Video Converter.lnk
2015-10-02 15:10 - 2015-10-02 15:10 - 00000000 ____D C:\Users\Ron.M\AppData\Local\Spoon
2015-10-02 15:10 - 2015-10-02 15:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Naturpic Video Converter
2015-10-02 15:10 - 2011-12-09 08:56 - 01931256 _____ (Codejock Software) C:\WINDOWS\system32\Codejock.Controls.Unicode.v15.2.1.ocx
2015-10-02 15:10 - 2011-12-09 08:56 - 01140728 _____ (Codejock Software) C:\WINDOWS\system32\Codejock.PropertyGrid.Unicode.v15.2.1.ocx
2015-10-02 15:10 - 2011-12-09 08:56 - 00587768 _____ (Codejock Software) C:\WINDOWS\system32\Codejock.SkinFramework.Unicode.v15.2.1.ocx
2015-10-02 15:10 - 2011-12-09 08:55 - 02775032 _____ (Codejock Software) C:\WINDOWS\system32\Codejock.CommandBars.Unicode.v15.2.1.ocx
2015-10-02 15:09 - 2015-10-02 15:10 - 00000000 ____D C:\Program Files\Naturpic Video Converter
2015-10-02 15:07 - 2013-11-27 13:37 - 00923784 _____ (CNET Download.com) C:\Users\Ron.Mn\Desktop\cbsidlm-cbsi145-Naturpic_Video_Converter-BP-10610649.exe
2015-10-02 13:53 - 2015-10-02 13:52 - 05198336 _____ (AVAST Software) C:\Users\Ron.M\Desktop\aswMBR.exe
2015-10-02 13:52 - 2015-10-02 13:52 - 05198336 _____ (AVAST Software) C:\Users\Ron.M\Downloads\aswMBR.exe
2015-10-02 13:29 - 2015-10-02 13:29 - 00242504 _____ (BitDefender) C:\WINDOWS\system32\Drivers\avchv.sys
2015-10-02 11:45 - 2015-10-02 11:45 - 00179004 _____ C:\ProgramData\1443811523.bdinstall.bin
2015-10-02 11:45 - 2015-10-02 11:45 - 00038194 _____ C:\ProgramData\1443811515.bdinstall.bin
2015-10-02 11:45 - 2015-10-02 11:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Antivirus Free Edition
2015-10-02 11:42 - 2015-10-02 11:42 - 00181009 _____ C:\ProgramData\1443811290.bdinstall.bin
2015-10-02 11:41 - 2015-10-02 11:41 - 00036113 _____ C:\ProgramData\1443811282.bdinstall.bin
2015-10-02 11:41 - 2015-10-02 11:41 - 00000088 _____ C:\ProgramData\1443811282.1736.bin
2015-10-02 11:40 - 2015-10-02 11:40 - 00251880 _____ C:\ProgramData\1443810981.bdinstall.bin
2015-10-02 11:39 - 2015-10-02 11:39 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2015-10-02 11:39 - 2013-04-17 14:59 - 00633344 _____ (BitDefender) C:\WINDOWS\system32\Drivers\avc3.sys
2015-10-02 11:39 - 2013-04-17 14:59 - 00486536 _____ (BitDefender) C:\WINDOWS\system32\Drivers\avckf.sys
2015-10-02 11:39 - 2012-11-02 14:17 - 00242504 _____ (BitDefender) C:\WINDOWS\system32\Drivers\SET4C72.tmp
2015-10-02 11:39 - 2009-07-14 23:27 - 01461992 _____ (Microsoft Corporation) C:\WINDOWS\system32\WdfCoInstaller01009.dll
2015-10-02 11:36 - 2015-10-02 11:39 - 00000000 ____D C:\Program Files\Bitdefender
2015-10-02 11:36 - 2013-05-28 12:11 - 00355744 _____ (BitDefender S.R.L.) C:\WINDOWS\system32\Drivers\trufos.sys
2015-10-02 11:36 - 2013-04-22 13:20 - 00164952 _____ (BitDefender LLC) C:\WINDOWS\system32\Drivers\gzflt.sys
2015-10-02 11:34 - 2015-10-02 13:04 - 00332710 _____ C:\WINDOWS\PFRO.log
2015-10-02 11:29 - 2015-10-02 11:37 - 00000000 ____D C:\Users\Ron.M\AppData\Roaming\QuickScan
2015-10-02 11:29 - 2015-10-02 11:29 - 00045195 _____ C:\ProgramData\1443810550.bdinstall.bin
2015-10-02 11:28 - 2015-10-02 11:29 - 09927424 _____ C:\Users\Ron.M\Desktop\Antivirus_Free_Edition_x86.exe
2015-10-02 11:28 - 2015-10-02 11:26 - 00162208 _____ C:\Users\Ron.M\Desktop\Bitdefender Antivirus Free Edition.exe
2015-10-02 11:26 - 2015-10-02 11:26 - 00162208 _____ C:\Users\Ron.M\Downloads\Bitdefender Antivirus Free Edition.exe
2015-10-02 10:42 - 2015-10-02 13:19 - 00001080 _____ C:\WINDOWS\setupact.log
2015-10-02 10:42 - 2015-10-02 10:42 - 00000000 _____ C:\WINDOWS\setuperr.log
2015-10-02 08:26 - 2015-10-02 08:27 - 00361912 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-10-01 17:28 - 2015-10-01 17:29 - 16783752 _____ (Bitdefender LLC) C:\Users\Ron.M\Downloads\BDRemoval_Trojan_Ransom_IcePol.exe
2015-10-01 16:18 - 2015-10-01 16:18 - 00000000 ____D C:\KVRT_Data
2015-10-01 15:10 - 2015-10-01 15:11 - 00000000 ____D C:\sh4ldr
2015-10-01 15:06 - 2015-10-01 15:06 - 00019984 _____ C:\WINDOWS\system32\Drivers\EsgScanner.sys
2015-10-01 15:06 - 2015-10-01 15:06 - 00000000 ____D C:\Program Files\Enigma Software Group
2015-09-30 18:47 - 2015-09-30 18:47 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Exploit
2015-09-30 18:44 - 2015-09-30 18:53 - 00098520 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-09-30 18:44 - 2015-09-30 18:44 - 00001072 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-09-30 18:44 - 2015-09-30 18:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-09-30 18:44 - 2015-06-18 08:41 - 00094936 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-09-30 18:44 - 2015-06-18 08:41 - 00051928 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-09-30 18:44 - 2015-06-18 08:41 - 00023256 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-09-30 17:26 - 2015-09-30 17:27 - 00000000 ____D C:\ProgramData\Sophos
2015-09-30 17:26 - 2015-09-30 17:26 - 00002763 _____ C:\Users\Public\Desktop\Sophos Virus Removal Tool.lnk
2015-09-30 17:26 - 2015-09-30 17:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos
2015-09-30 17:26 - 2015-09-30 17:26 - 00000000 ____D C:\Program Files\Sophos
2015-09-30 17:11 - 2015-09-30 17:23 - 134793624 _____ (Sophos Limited) C:\Users\Ron.M\Downloads\Sophos Virus Removal Tool.exe
2015-09-30 11:02 - 2015-06-19 15:27 - 2632460288 _____ C:\Users\Ron.M\Desktop\HRM_CCSA_X86FRE_EN-US_DV5.ISO
2015-09-29 18:34 - 2015-10-02 13:35 - 00721042 _____ C:\WINDOWS\WindowsUpdate.log
2015-09-28 10:19 - 2015-09-30 10:49 - 00000000 ____D C:\Program Files\AviSynth 2.5
2015-09-28 10:19 - 2015-09-30 10:48 - 00000000 ____D C:\Program Files\Sothink Video Converter
2015-09-28 10:19 - 2015-09-30 10:48 - 00000000 ____D C:\Program Files\ffdshow
2015-09-28 10:19 - 2015-09-28 10:19 - 00000000 ____D C:\Program Files\Common Files\SourceTec
2015-09-28 10:13 - 2015-09-28 10:13 - 00000000 ____D C:\Users\Ron.M\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\illiminable
2015-09-27 10:04 - 2015-09-27 10:14 - 00000319 _____ C:\Users\Ron.M\Desktop\How to Get Into Safe Mode With Win 8.txt-
2015-09-24 09:28 - 2015-09-24 09:28 - 00000383 _____ C:\Users\Ron.M\Desktop\Windows 10.website
2015-09-23 16:23 - 2015-09-23 16:23 - 00000000 ___HD C:\ProgramData\CanonIJQuickMenu
2015-09-23 16:20 - 2015-09-24 08:52 - 00000000 ____D C:\ProgramData\CanonIJPLM
2015-09-23 15:57 - 2015-09-30 10:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MG2500 series User Registration
2015-09-23 15:55 - 2015-09-23 15:55 - 00000000 ____D C:\ProgramData\CanonIJWSpt
2015-09-23 15:48 - 2015-09-23 15:48 - 00000000 ___HD C:\ProgramData\CanonBJ
2015-09-23 15:45 - 2015-09-30 10:48 - 00000000 ____D C:\Program Files\CanonBJ
2015-09-23 14:59 - 2015-09-23 14:59 - 00000361 _____ C:\Users\Ron.M\Desktop\Phone Battery eBay…txt
2015-09-23 14:45 - 2015-09-23 14:58 - 00000655 _____ C:\Users\Ron.M\Desktop\2000mAh Cordless Phone Battery for Uniden BT 905 BP 800 BT 800 BP 905 DXI9862 US  eBay.website
2015-09-23 14:00 - 2015-09-23 14:02 - 00000474 _____ C:\Users\Ron.M\Desktop\Power Window Message.txt
2015-09-23 09:49 - 2015-09-23 09:49 - 00001079 _____ C:\Users\Ron.M\Desktop\Backup USB.txt
2015-09-22 17:25 - 2015-08-22 09:50 - 02279424 ____N (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-09-22 17:25 - 2015-08-22 09:00 - 01951232 ____N (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-09-22 17:25 - 2015-08-22 08:56 - 01310720 ____N (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-09-22 17:09 - 2015-07-22 07:25 - 02461184 ____N (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2015-09-22 17:08 - 2015-09-02 19:17 - 01903848 ____N (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2015-09-22 17:08 - 2015-09-02 10:09 - 01556992 ____N (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2015-09-22 17:08 - 2015-08-26 11:00 - 00721920 ____N (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2015-09-22 16:54 - 2015-08-07 14:46 - 01469456 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2015-09-22 16:54 - 2015-08-07 14:46 - 00888896 ____N (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2015-09-22 16:54 - 2015-08-07 14:40 - 00507176 ____N (Microsoft Corporation) C:\WINDOWS\system32\advapi32.dll
2015-09-22 16:54 - 2015-08-06 09:18 - 04068352 ____N (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
2015-09-22 16:53 - 2015-08-10 10:01 - 00570368 ____N (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL
2015-09-22 16:53 - 2015-08-10 09:56 - 00272384 ____N (Microsoft Corporation) C:\WINDOWS\system32\FWPUCLNT.DLL
2015-09-22 16:48 - 2015-09-30 18:44 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2015-09-22 16:21 - 2015-09-22 16:21 - 00000093 _____ C:\rescuepe.log
2015-09-22 16:06 - 2015-09-30 11:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Macrium
2015-09-22 16:06 - 2015-09-22 16:06 - 00001949 _____ C:\Users\Public\Desktop\Reflect.lnk
2015-09-22 16:06 - 2015-09-22 16:06 - 00000000 ____D C:\Program Files\Macrium
2015-09-22 16:04 - 2015-09-22 16:04 - 00000035 _____ C:\Users\Ron.M\Desktop\Macrium  License Key.txt
2015-09-22 15:58 - 2015-09-22 16:06 - 00266400 _____ C:\Reflect_Install.log
2015-09-22 15:13 - 2015-09-22 15:56 - 00000000 ____D C:\Users\Ron.M\Downloads\Macrium
2015-09-21 11:32 - 2015-08-07 14:46 - 01469456 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll(125).dll
2015-09-21 11:32 - 2015-08-07 14:46 - 00888896 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase(120).dll
2015-09-21 11:32 - 2015-08-07 14:40 - 00507176 _____ (Microsoft Corporation) C:\WINDOWS\system32\advapi32(112).dll
2015-09-21 11:32 - 2015-08-06 09:18 - 04068352 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1(117).dll
2015-09-21 11:12 - 2015-07-22 07:25 - 02461184 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui(114).dll
2015-09-21 10:39 - 2015-09-21 10:39 - 00000000 ____D C:\Users\Ron.M\AppData\Local\Downloaded Installations
2015-09-20 15:40 - 2015-09-20 15:42 - 00000000 ____D C:\Users\Ron.M\Desktop\RoboForm
2015-09-14 08:54 - 2015-09-28 11:07 - 00000782 _____ C:\Users\Ron.M\Desktop\Canon PIXMA MG2520 All-in-One Printer - Print, Copy, Scan, up to 8 ipm Black, 4 ipm Color, Up 4800 x 600 dpi Print Resolution a.website
2015-09-13 11:02 - 2015-09-13 11:03 - 00000000 ___HD C:\$Windows.~BT
2015-09-13 10:22 - 2015-09-21 08:42 - 00000000 ____D C:\fafd8dd900cbeeaa90a92b
2015-09-12 15:32 - 2015-09-21 08:42 - 00000000 ____D C:\Users\Rona.M\AppData\Roaming\vlc
2015-09-12 15:31 - 2015-09-20 18:27 - 00000000 ____D C:\Program Files\VideoLAN

 

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-10-02 16:00 - 2013-08-22 01:17 - 00000000 ____D C:\WINDOWS\system32\sru
2015-10-02 14:40 - 2015-07-27 14:00 - 00003568 _____ C:\Users\Ron.M\Desktop\Tracking numbers.txt
2015-10-02 13:31 - 2015-06-23 15:29 - 00000000 ____D C:\Users\Ron.M\AppData\Roaming\ClassicShell
2015-10-02 13:21 - 2015-07-06 17:59 - 00007594 _____ C:\Users\Ron.M\AppData\Local\Resmon.ResmonCfg
2015-10-02 13:19 - 2013-08-22 00:23 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-10-02 11:34 - 2015-06-23 16:51 - 00000000 ____D C:\ProgramData\AVAST Software
2015-10-02 08:23 - 2015-07-31 12:19 - 00711168 ___SH C:\Users\Ron.M\Desktop\Thumbs.db
2015-10-01 12:44 - 2015-07-16 11:54 - 00000000 ___RD C:\Users\Ron.M\Documents\PI
2015-10-01 09:52 - 2015-08-23 11:36 - 00000000 ____D C:\ProgramData\Malwarebytes Anti-Exploit
2015-09-30 16:56 - 2013-08-22 01:17 - 00000000 ____D C:\WINDOWS\system32\LogFiles
2015-09-30 15:47 - 2015-08-06 12:28 - 00000966 __RSH C:\ProgramData\ntuser.pol
2015-09-30 15:24 - 2014-11-21 18:00 - 00863592 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-09-30 11:31 - 2015-07-31 10:21 - 00000000 ___SD C:\WINDOWS\system32\GWX
2015-09-30 11:31 - 2015-07-24 11:24 - 00000000 ___RD C:\Users\Ron.M\Desktop\EXE's
2015-09-30 11:31 - 2015-07-18 15:24 - 00000000 ____D C:\Users\Ron.M\AppData\Roaming\GRETECH
2015-09-30 11:31 - 2015-07-16 11:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\illiminable
2015-09-30 11:31 - 2015-07-02 13:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RoboForm
2015-09-30 11:31 - 2014-11-21 17:45 - 00000000 ____D C:\WINDOWS\ShellNew
2015-09-30 11:31 - 2014-11-21 17:45 - 00000000 ____D C:\Program Files\Windows Journal
2015-09-30 11:31 - 2013-08-22 01:17 - 00000000 __RSD C:\WINDOWS\Media
2015-09-30 11:31 - 2013-08-22 01:17 - 00000000 ____D C:\WINDOWS\system32\WinMetadata
2015-09-30 11:31 - 2013-08-22 01:17 - 00000000 ____D C:\WINDOWS\system32\Macromed
2015-09-30 11:31 - 2013-08-22 01:17 - 00000000 ____D C:\WINDOWS\AppCompat
2015-09-30 11:28 - 2013-08-22 01:17 - 00000000 ____D C:\WINDOWS\registration
2015-09-30 11:06 - 2013-08-21 23:13 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2015-09-30 10:51 - 2015-07-30 21:37 - 00000000 ____D C:\Users\Ron.M
2015-09-30 10:43 - 2013-08-22 01:17 - 00000000 ____D C:\WINDOWS\Microsoft.NET
2015-09-30 10:42 - 2015-06-23 17:03 - 00000000 ____D C:\Users\Ron.M\AppData\Roaming\iolo
2015-09-30 10:41 - 2015-07-16 11:49 - 00000000 ____D C:\Program Files\illiminable
2015-09-24 08:43 - 2015-07-31 13:17 - 00000000 ____D C:\Users\Ron.M\AppData\Roaming\canon
2015-09-23 16:31 - 2015-09-01 14:14 - 00014920 _____ C:\Users\Ron.M\Desktop\Rent Payment Form  #2.odt
2015-09-23 15:10 - 2012-07-25 23:43 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-09-23 11:37 - 2013-08-22 01:17 - 00000000 ____D C:\WINDOWS\system32\NDF
2015-09-22 17:30 - 2015-07-07 05:03 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-09-22 16:23 - 2013-08-22 01:17 - 00262144 _____ C:\WINDOWS\system32\config\BCD-Template
2015-09-22 14:53 - 2013-08-22 01:17 - 00000000 ____D C:\WINDOWS\System
2015-09-22 14:49 - 2015-08-22 11:22 - 00000000 ____D C:\Program Files\Reference Assemblies
2015-09-22 14:49 - 2015-08-22 11:22 - 00000000 ____D C:\Program Files\MSBuild
2015-09-22 14:49 - 2015-07-02 13:01 - 00000000 ____D C:\Program Files\Siber Systems
2015-09-22 14:49 - 2013-08-22 01:17 - 00000000 ____D C:\WINDOWS\rescache
2015-09-22 14:49 - 2013-08-22 01:17 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2015-09-22 13:34 - 2013-08-21 23:21 - 00000000 ___RD C:\Users\Public
2015-09-21 08:57 - 2013-08-21 23:13 - 00262144 ___SH C:\WINDOWS\system32\config\BBI(28)
2015-09-21 08:57 - 2013-08-21 23:13 - 00262144 ___SH C:\WINDOWS\system32\config\BBI(116)
2015-09-21 08:57 - 2013-08-21 23:13 - 00262144 ___SH C:\WINDOWS\system32\config\BBI(11)
2015-09-20 15:47 - 2015-06-23 16:00 - 00000000 ____D C:\ProgramData\RoboForm
2015-09-15 11:50 - 2015-07-16 11:56 - 00000000 ____D C:\Users\Ron.M\Documents\Mas
2015-09-13 11:02 - 2015-07-30 22:14 - 00000000 ___DC C:\WINDOWS\Panther
2015-09-13 11:02 - 2013-08-22 01:17 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-09-13 10:51 - 2013-08-21 23:13 - 00262144 ___SH C:\WINDOWS\system32\config\BBI(61)
2015-09-13 10:51 - 2013-08-21 23:13 - 00262144 ___SH C:\WINDOWS\system32\config\BBI(43)
2015-09-13 10:51 - 2013-08-21 23:13 - 00262144 ___SH C:\WINDOWS\system32\config\BBI(38)
2015-09-09 11:18 - 2015-08-22 16:17 - 00000737 _____ C:\Users\Ron.M\Desktop\3.6 volt phone battery  eBay.website
2015-09-07 15:46 - 2015-08-14 15:26 - 00000499 _____ C:\Users\Ron.M\Desktop\2 Bedroom ONLY $525.website
2015-09-04 13:16 - 2015-07-22 21:54 - 00000654 _____ C:\Users\Ron.M\Desktop\Shaver List eBay.website

==================== Files in the root of some directories =======

2015-07-06 17:59 - 2015-10-02 13:21 - 0007594 _____ () C:\Users\Ron.M\AppData\Local\Resmon.ResmonCfg
2015-10-02 11:29 - 2015-10-02 11:29 - 0045195 _____ () C:\ProgramData\1443810550.bdinstall.bin
2015-10-02 11:40 - 2015-10-02 11:40 - 0251880 _____ () C:\ProgramData\1443810981.bdinstall.bin
2015-10-02 11:41 - 2015-10-02 11:41 - 0000088 _____ () C:\ProgramData\1443811282.1736.bin
2015-10-02 11:41 - 2015-10-02 11:41 - 0036113 _____ () C:\ProgramData\1443811282.bdinstall.bin
2015-10-02 11:42 - 2015-10-02 11:42 - 0181009 _____ () C:\ProgramData\1443811290.bdinstall.bin
2015-10-02 11:45 - 2015-10-02 11:45 - 0038194 _____ () C:\ProgramData\1443811515.bdinstall.bin
2015-10-02 11:45 - 2015-10-02 11:45 - 0179004 _____ () C:\ProgramData\1443811523.bdinstall.bin

==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2015-09-20 10:03

==================== End of FRST.txt ============================

 

Addition.txt;=>..
 

Addition.txt

Additional scan result of Farbar Recovery Scan Tool (x86) Version:30-09-2015
Ran by [removed] (2015-10-02 16:08:35)
Running from C:\Users\[removed]\Desktop
Microsoft Windows 8.1 Pro (X86) (2015-07-31 04:54:16)
Boot Mode: Normal
==========================================================

==================== Accounts: =============================

Administrator (S-1-5-21-2697119639-1211797034-894152058-500 - Administrator - Disabled)
Guest (S-1-5-21-2697119639-1211797034-894152058-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2697119639-1211797034-894152058-1003 - Limited - Enabled)
Ron.M (S-1-5-21-2697119639-1211797034-894152058-1001 - Administrator - Enabled) => C:\Users\Ron.M

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Bitdefender Antivirus Free Edition (Enabled - Up to date) {9B5F5313-CAF9-DD97-C460-E778420237B4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Bitdefender Antivirus Free Edition (Enabled - Up to date) {203EB2F7-ECC3-D219-FED0-DC0A39857D09}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 4.65 (HKLM\…\7-Zip) (Version:  - )
Bitdefender Antivirus Free Edition (HKLM\…\BitDefender Gonzales) (Version: 1.0.21.1099 - Bitdefender)
Canon Utilities CameraWindow DC 8 (HKLM\…\CameraWindowDC) (Version: 8.8.0.17 - Canon Inc.)
Canon Utilities ImageBrowser EX (HKLM\…\ImageBrowser EX) (Version: 1.5.2.8 - Canon Inc.)
CCleaner (HKLM\…\CCleaner) (Version: 3.14 - Piriform)
Classic Shell (HKLM\…\{13793E6A-6DBC-4112-81B7-7554DFC5D959}) (Version: 4.0.4 - IvoSoft)
Customer Support (HKLM\…\{B33D89E4-FB43-6749-447E-2E469AC9EB5B}) (Version: 0.0.0.1 - Lexmark International, Inc.)
Foxit Reader (HKLM\…\Foxit Reader) (Version: 4.3.0.1110 - Foxit Corporation)
GOM Player (HKLM\…\GOM Player) (Version: 2.2.69.5227 - Gretech Corporation)
Google Gmail Notifier (HKLM\…\{0228e555-4f9c-4e35-a3ec-b109a192b4c2}) (Version:  - Google Inc.)
Greenshot 1.2.6.7 (HKLM\…\Greenshot_is1) (Version: 1.2.6.7 - Greenshot)
Intel® Driver Update Utility (HKLM\…\{8409c4f7-2340-4933-a304-5d37db4fb48b}) (Version: 2.0.0.29 - Intel)
iolo technologies' System Mechanic (HKLM\…\{55FD1D5A-7AEF-4DA3-8FAF-A71B2A52FFC7}_is1) (Version: 14.6.0 - iolo technologies, LLC)
Java 8 Update 51 (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F83218051F0}) (Version: 8.0.510 - Oracle Corporation)
LSI PCI-SV92PP Soft Modem (HKLM\…\LSI Soft Modem) (Version: 2.2.98 - LSI Corporation)
Macrium Reflect Free Edition (HKLM\…\MacriumReflect) (Version: 6.0 - Paramount Software (UK) Ltd.)
Macrium Reflect Free Edition (Version: 6.0.753 - Paramount Software (UK) Ltd.) Hidden
Malwarebytes Anti-Exploit version 1.07.1.1015 (HKLM\…\Malwarebytes Anti-Exploit_is1) (Version: 1.07.1.1015 - Malwarebytes)
Malwarebytes Anti-Malware version 2.1.8.1057 (HKLM\…\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Naturpic Video Converter 6.0 (HKLM\…\Naturpic Video Converter_is1) (Version:  - Naturpic Software)
NetZero Internet (HKLM\…\{6c651250-2eb2-11d5-8e33-0050dad72ac2}) (Version: 8.9.3.0 - NetZero, Inc.)
oggcodecs 0.71.0946 (HKLM\…\oggcodecs) (Version: 0.71.0946 - illiminable)
OpenOffice 4.1.1 (HKLM\…\{9395F41D-0F80-432E-9A59-B8E477E7E163}) (Version: 4.11.9775 - Apache Software Foundation)
Picasa 3 (HKLM\…\Picasa 3) (Version: 3.9.140.239 - Google, Inc.)
Privacy Guardian 4.5 (HKLM\…\Privacy Guardian_is1) (Version: 4.5 - PC Tools)
Revo Uninstaller 1.90 (HKLM\…\Revo Uninstaller) (Version: 1.90 - VS Revo Group)
RoboForm 7-9-10-1 (All Users) (HKLM\…\AI RoboForm) (Version: 7-9-10-1 - Siber Systems)
Sophos Virus Removal Tool (HKLM\…\{B829E117-D072-41EA-9606-9826A38D34C1}) (Version: 2.5.4 - Sophos Limited)
SoundMAX (HKLM\…\{F0A37341-D692-11D4-A984-009027EC0A9C}) (Version: 5.12.1.7010 - Analog Devices)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

==================== Restore Points =========================

22-09-2015 16:30:40 avast! antivirus system restore point
24-09-2015 08:45:06 Revo Uninstaller's restore point - Canon My Image Garden
27-09-2015 11:07:51 Windows Update
30-09-2015 10:36:02 Restore Operation
01-10-2015 15:58:03 Revo Uninstaller's restore point - SpyHunter 4

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-08-21 23:13 - 2013-08-21 23:13 - 00000824 ____N C:\WINDOWS\system32\Drivers\etc\hosts

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {07C81133-C612-4F6F-97A1-23C3BCE75144} - System32\Tasks\Open URL by RoboForm => Rundll32.exe url.dll,FileProtocolHandler "http://www.roboform.com/test-pass.html?aaa=KICMLJMJMMPMOJIMOJJMCNMMNJMJMJCNLMLJPMGMCNNJKJIMNMCNHMNMJJNMKJJMIMMMPMKMMMJMJNJICMIMCNGMCNOMPMFMOMPMCNPMCNGMNMPMPMFMJMCNNMCNGMNMPMPMCNNMJNPICMPMFMMJBJKJLIMJFMHMJNHICMMJBJKJLIMJJNBJCMNKAJBJOJDJLJPNCLOJIJBJOJBJJNKJCMJNNICMJNDJCMKJBJJNMJCMPMFMOMFMPMJNFICMGJLJKJBJLIGJLIGJKJMIBNKJHIKJ"
Task: {1DCB230B-0545-48E3-A0DB-A920AE584A9B} - System32\Tasks\{BB6188E0-1E61-4FDE-8005-585003C081E5} => pcalua.exe -a "D:\My Documents\EXE's\R96000 #4.EXE" -d "D:\My Documents\EXE's"
Task: {3CFB71B0-C012-4AA6-99F0-04AD026A2A67} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => Rundll32.exe invagent.dll,RunUpdate -noappraiser
Task: {46A43753-EBE3-4138-8FCF-AE14631C863F} - System32\Tasks\{31E034A6-F0E0-4481-BC2C-B4F57CFDEAAB} => pcalua.exe -a "D:\My Documents\EXE's\R79695 #2.EXE" -d "D:\My Documents\EXE's"
Task: {5CF12292-B5B8-4E1C-AC2B-7C774A1437D4} - System32\Tasks\SpyHunter4Startup => C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe
Task: {732987B3-3ED0-4E59-95EF-61D38CF0A472} - \ProPCCleaner_Start -> No File <==== ATTENTION
Task: {9BDE793B-D1BF-4763-AE01-0B5FDF836233} - \ProPCCleaner_Popup -> No File <==== ATTENTION
Task: {9F16C1E8-2A29-4AD2-A7B7-B48B57F50E34} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2015-07-30] (AVAST Software)
Task: {B137BFB3-89B0-490A-B0B2-CB80774C541E} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-07-28] (Microsoft Corporation)
Task: {CDC720FA-5F05-4827-AE3D-2BE06D1C3342} - System32\Tasks\{EEF87537-F6FC-4B1A-A5B6-1D8AF02F8CEA} => pcalua.exe -a "D:\My Documents\EXE's\R121089 #1.EXE" -d "D:\My Documents\EXE's"
Task: {DBE78EB1-2E54-4A23-AB55-E2F4CF03FD88} - System32\Tasks\{00257BAD-FED6-4477-8719-9E01FC709F1D} => pcalua.exe -a "C:\Users\Ron.M\Desktop\EXE's\dotnetfx  Net (IE).exe"
Task: {E72E2732-B9D5-4DE1-9974-85069A0B2C74} - System32\Tasks\Run RoboForm TaskBar Icon => C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [2015-07-02] (Siber Systems)
Task: {EBB242FC-3B39-4895-ADDB-D8E52DDFEAAD} - System32\Tasks\iolo Process Governor => C:\Program Files\iolo\System Mechanic\iologovernor.exe [2015-07-25] (iolo technologies, LLC)
Task: {EBFBEBB4-9030-4B15-9518-D0BA3EA1A3FB} - System32\Tasks\{ED55B930-C6AC-47DE-ADCE-7217DC24BA02} => pcalua.exe -a "C:\Program Files\ERUNT\AUTOBACK.EXE" -d "C:\Users\Ron.M\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup" -c C:\WINDOWS\ERDNT\AutoBackup\#Date# /noconfirmdelete /noprogresswindow

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

==================== Loaded Modules (Whitelisted) ==============

2015-10-02 11:39 - 2013-03-19 12:07 - 00508136 _____ () C:\Program Files\Bitdefender\Antivirus Free Edition\sqlite3.dll
2015-10-02 11:39 - 2013-09-03 14:29 - 00095088 _____ () C:\Program Files\Bitdefender\Antivirus Free Edition\BDMetrics.dll
2015-08-28 10:41 - 2009-08-13 12:02 - 00147968 _____ () C:\WINDOWS\system32\spool\PRTPROCS\W32X86\lxdpdrpp.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData\TEMP:42D9E231

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ioloSystemService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ioloSystemService => ""="Service"

==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\S-1-5-21-2697119639-1211797034-894152058-1001\…\dell.com -> dell.com

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2697119639-1211797034-894152058-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Theme2\img7.jpg
DNS Servers: 192.168.0.1 - [removed]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

HKLM\…\StartupApproved\StartupFolder: => "ImageBrowser EX Agent.lnk"
HKLM\…\StartupApproved\Run: => "Greenshot"
HKLM\…\StartupApproved\Run: => "iolo Startup"
HKU\S-1-5-21-2697119639-1211797034-894152058-1001\…\StartupApproved\Run: => "NetZero_uoltray"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{0D637031-70D7-4173-8474-F7E317A2E18D}] => (Allow) C:\Windows\System32\lxdpcoms.exe
FirewallRules: [{883D49B1-A924-44BE-B3E5-AB2377A7425D}] => (Allow) C:\Windows\System32\lxdpcoms.exe

==================== Faulty Device Manager Devices =============

Name: Video Controller
Description: Video Controller
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

==================== Event log errors: =========================

Application errors:
==================
Error: (10/02/2015 03:02:29 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: GOM.EXE, version: 2.2.69.5227, time stamp: 0x5513bb04
Faulting module name: grfu.ax, version: 1.1.8.35, time stamp: 0x54f913ec
Exception code: 0xc0000005
Fault offset: 0x0000c891
Faulting process id: 0x1344
Faulting application start time: 0xGOM.EXE0
Faulting application path: GOM.EXE1
Faulting module path: GOM.EXE2
Report Id: GOM.EXE3
Faulting package full name: GOM.EXE4
Faulting package-relative application ID: GOM.EXE5

Error: (10/02/2015 03:02:14 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: GOM.EXE, version: 2.2.69.5227, time stamp: 0x5513bb04
Faulting module name: grfu.ax, version: 1.1.8.35, time stamp: 0x54f913ec
Exception code: 0xc0000005
Fault offset: 0x0000c891
Faulting process id: 0x1290
Faulting application start time: 0xGOM.EXE0
Faulting application path: GOM.EXE1
Faulting module path: GOM.EXE2
Report Id: GOM.EXE3
Faulting package full name: GOM.EXE4
Faulting package-relative application ID: GOM.EXE5

Error: (10/02/2015 03:01:46 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: GOM.EXE, version: 2.2.69.5227, time stamp: 0x5513bb04
Faulting module name: grfu.ax, version: 1.1.8.35, time stamp: 0x54f913ec
Exception code: 0xc0000005
Fault offset: 0x0000c891
Faulting process id: 0x1150
Faulting application start time: 0xGOM.EXE0
Faulting application path: GOM.EXE1
Faulting module path: GOM.EXE2
Report Id: GOM.EXE3
Faulting package full name: GOM.EXE4
Faulting package-relative application ID: GOM.EXE5

Error: (10/02/2015 10:46:44 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program iexplore.exe version 11.0.9600.17840 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 54c

Start Time: 01d0fd3a25bcc503

Termination Time: 343

Application Path: C:\Program Files\Internet Explorer\iexplore.exe

Report Id: 87028166-692d-11e5-b009-001143c8f08b

Faulting package full name:

Faulting package-relative application ID:

Error: (10/01/2015 05:17:27 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program iexplore.exe version 11.0.9600.17840 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: e0

Start Time: 01d0fca5d7371904

Termination Time: 236

Application Path: C:\Program Files\Internet Explorer\iexplore.exe

Report Id: f5981aa8-689a-11e5-b007-001143c8f08b

Faulting package full name:

Faulting package-relative application ID:

Error: (10/01/2015 05:04:00 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program iexplore.exe version 11.0.9600.17840 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 708

Start Time: 01d0fca5859b6b69

Termination Time: 8234

Application Path: C:\Program Files\Internet Explorer\iexplore.exe

Report Id: 0ef9ae61-6899-11e5-b007-001143c8f08b

Faulting package full name:

Faulting package-relative application ID:

Error: (10/01/2015 05:01:42 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program iexplore.exe version 11.0.9600.17840 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 930

Start Time: 01d0fca45c53379f

Termination Time: 5812

Application Path: C:\Program Files\Internet Explorer\iexplore.exe

Report Id: bdd798d3-6898-11e5-b007-001143c8f08b

Faulting package full name:

Faulting package-relative application ID:

Error: (10/01/2015 03:58:21 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.

System Error:
Access is denied.
.

Error: (10/01/2015 03:58:02 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface.  hr = 0x80070005, Access is denied.
.
This is often caused by incorrect security settings in either the writer or requestor process.

Operation:
   Gathering Writer Data

Context:
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {1f4e6ade-2f72-4015-9565-f4a4628752b0}

Error: (10/01/2015 11:29:54 AM) (Source: System Restore) (EventID: 8193) (User: )
Description: Failed to create restore point (Process = C:\Program Files\VS Revo Group\Revo Uninstaller\Revouninstaller.exe Files\VS Revo Group\Revo Uninstaller\Revouninstaller.exe" ; Description = Revo Uninstaller's restore point - E.M. Total Video Player 1.31; Error = 0x8007043c).

System errors:
=============
Error: (10/02/2015 01:09:59 PM) (Source: DCOM) (EventID: 10005) (User: HOME)
Description: 1084WSearchUnavailable{9E175B68-F52A-11D8-B9A5-505054503030}

Error: (10/02/2015 01:09:59 PM) (Source: DCOM) (EventID: 10005) (User: HOME)
Description: 1084ShellHWDetectionUnavailable{DD522ACC-F821-461A-A407-50B198B896DC}

Error: (10/02/2015 01:09:51 PM) (Source: DCOM) (EventID: 10005) (User: HOME)
Description: 1084wuauservUnavailable{9B1F122C-2982-4E91-AA8B-E071D54F2A4D}

Error: (10/02/2015 01:09:51 PM) (Source: DCOM) (EventID: 10005) (User: HOME)
Description: 1084wuauservUnavailable{9B1F122C-2982-4E91-AA8B-E071D54F2A4D}

Error: (10/02/2015 01:09:51 PM) (Source: DCOM) (EventID: 10005) (User: HOME)
Description: 1084wuauservUnavailable{9B1F122C-2982-4E91-AA8B-E071D54F2A4D}

Error: (10/02/2015 01:09:51 PM) (Source: DCOM) (EventID: 10005) (User: HOME)
Description: 1084wuauservUnavailable{9B1F122C-2982-4E91-AA8B-E071D54F2A4D}

Error: (10/02/2015 01:09:51 PM) (Source: DCOM) (EventID: 10005) (User: HOME)
Description: 1084wuauservUnavailable{9B1F122C-2982-4E91-AA8B-E071D54F2A4D}

Error: (10/02/2015 01:09:51 PM) (Source: DCOM) (EventID: 10005) (User: HOME)
Description: 1084wuauservUnavailable{9B1F122C-2982-4E91-AA8B-E071D54F2A4D}

Error: (10/02/2015 01:09:51 PM) (Source: DCOM) (EventID: 10005) (User: HOME)
Description: 1084wuauservUnavailable{9B1F122C-2982-4E91-AA8B-E071D54F2A4D}

Error: (10/02/2015 01:09:51 PM) (Source: DCOM) (EventID: 10005) (User: HOME)
Description: 1084wuauservUnavailable{9B1F122C-2982-4E91-AA8B-E071D54F2A4D}

==================== Memory info ===========================

Processor: Intel(R) Pentium(R) 4 CPU 2.80GHz
Percentage of memory in use: 60%
Total physical RAM: 2038.14 MB
Available physical RAM: 803.71 MB
Total Virtual: 2806.14 MB
Available Virtual: 850.98 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:465.42 GB) (Free:425.03 GB) NTFS ==>[drive with boot components (obtained from BCD)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 00021F46)
Partition 1: (Active) - (Size=465.4 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================

 

Your help IS GREATLY APPRECIATED !!!
THANK YOU VERRRRY MUCH ….



I hope you can sort all this data….
Have fun…
Have a GREAT day & weekend…

Later…Ron.M….   :-) 








 

Hello Ron.M and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:

  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!

IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

===================================================

System Mechanic

It's not a good idea to use registry cleaners/boosters besides which, IOLO has a pretty bad reputation and some versions have been known to disable virus scanners.

Apart from that, the usefulness of cleaning the registry is highly overrated and can be dangerous. In most cases, using a cleaner to remove obsolete, invalid and erroneous entries does not affect system performance but it can result in "unpredictable results". Unless you have a particular problem that requires a registry edit to correct it, (and you are expert in the registry), I would suggest you leave the registry alone.

I strongly advise you to get rid of System Mechanic and any other cleaner/optimizer/booster/tuneup/tweak type utilities that you have on this or any other computer.

One of the malware experts, miekiemoes, has an excellent write-up here
Another excellent article by Bill Castner is located here

===================================================

Note: Please run these in the order given in the instructions.

===================================================

Download and run AdwCleaner

Download AdwCleaner from here and save it to your desktop.


  • run AdwCleaner
  • when it has finished, select Clean
  • if it asks to reboot, allow the reboot
  • on reboot a log will be produced; please attach the content of the log to your next reply.

===================================================

Download and run Junkware Removal Tool

[external image: thisisujrt.gif] Please download Junkware Removal Tool to your desktop.

  • shut down your protection software now to avoid potential conflicts.
  • run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator"
  • the tool will open and start scanning your system
  • please be patient as this can take a while to complete depending on your system's specifications
  • on completion, a log (JRT.txt) is saved to your desktop and will automatically open
  • post the contents of JRT.txt into your next message.

===================================================

Run RogueKiller

IMPORTANT: Please remove any usb or external drives from the computer before you run this scan!

Close all running programs.


Download RogueKiller to your desktop

  • close all running programs
  • for Windows Vista/Seven, right click -> run as administrator, for XP simply double-click on RogueKiller.exe
  • when the pre-scan is finished, click on Scan
  • click on Report and copy/paste the content in your next post
  • NOTE: DO NOT attempt to remove anything that the scan detects –everything that is reported is not necessarily bad

If the program is blocked, continue to try it several times. If it still doesn’t work, (it could happen), rename it to winlogon.exe.

Please post the contents of the RKreport.txt in your next reply.

Logs to include with next post:

AdwCleaner log
JRT.txt
RKreport.txt


Thanks

Satchfan

 

Satchfan;….

First off;…
THANK you VERRRY , VERRRY MUCH for your reply….
It IS MUCH APPRECIATED !!!

I uninstalled System Mechanic using Revo Uninstaller…
I uninstalled CCleaner using Revo Uninstaller…
I got those to remove junk & temporary files…


 

Here are the results you asked for
 

The Junkware Removal Tool & RogueKiller results are pasted below as you asked for…



Junkware Removal Tool Results;=>..



 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.6.4 (09.28.2015:1)
OS: Windows 8.1 Pro x86
Ran by [removed] on Sat 10/03/2015 at 10:15:42.34
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 

~~~ Services

 

~~~ Tasks

 

~~~ Registry Values

 

~~~ Registry Keys

 

~~~ Files

Successfully deleted: [File] C:\ProgramData\1443810550.bdinstall.bin
Successfully deleted: [File] C:\ProgramData\1443810981.bdinstall.bin
Successfully deleted: [File] C:\ProgramData\1443811282.1736.bin
Successfully deleted: [File] C:\ProgramData\1443811282.bdinstall.bin
Successfully deleted: [File] C:\ProgramData\1443811290.bdinstall.bin
Successfully deleted: [File] C:\ProgramData\1443811515.bdinstall.bin
Successfully deleted: [File] C:\ProgramData\1443811523.bdinstall.bin
Successfully deleted: [File] C:\ProgramData\1443891546.bdinstall.bin
Successfully deleted: [File] C:\ProgramData\1443891548.bdinstall.bin

 

~~~ Folders

 

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Sat 10/03/2015 at 10:17:44.38
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

RogueKiller Results;=>…

 

RogueKiller V10.10.7.0 [Sep 28 2015] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/software/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows 8.1 (6.3.9600) 32 bits version
Started in : Normal mode
User : Ron.M [Administrator]
Started from : C:\Users\Ron.M\Desktop\RogueKiller.exe
Mode : Scan – Date : 10/03/2015 10:37:45

¤¤¤ Processes : 0 ¤¤¤

¤¤¤ Registry : 1 ¤¤¤
[PUM.HomePage] HKEY_USERS\S-1-5-21-2697119639-1211797034-894152058-1001\Software\Microsoft\Internet Explorer\Main | Start Page : http://centurylink.net/?dc=O&s;=e77e1ca0-581a-3472-1d5b-39d1f285b39a&p;=2036&k;=f69bda69-22e4-40ac-9305-c0b7019b67a8&d;=lctl-res&pct;=100  -> Found

¤¤¤ Tasks : 0 ¤¤¤

¤¤¤ Files : 0 ¤¤¤

¤¤¤ Hosts File : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: ST3500820AS ATA Device +++++
— User —
[MBR] 032588a49d52816d49ab1453651dfdff
[BSP] 368ba19f6c1e5717ada0033d4e6193d2 : Windows Vista/7/8|VT.Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 718848 | Size: 476588 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 … OK
User = LL2 … OK

 

Hope all this helps….




Have a GREAT day & weekend…..
Later..Ron.M…. B) …..







 

 

Have a GREAT day & weekend

 

 

Thanks Ron. You too and excuse me if some answers are a bit delayed because of it being the weekend.

 

Please run FRST again, post the new log and let me know if here is any change or if things remain the same.

 

Satchfan

Satchfan;…


Here are the reruns you asked for…
Farbar Recovery Scan Tool (FRST) Results;=>..

 

 

 

FRST.txt;..
 

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:30-10-2015
Ran by [removed] (administrator) on HOME (04-10-2015 09:02:17)
Running from C:\Users\[removed]\Desktop
[removed] Platform: Microsoft Windows 8.1 Pro (X86) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(LSI Corporation) C:\Program Files\LSI SoftModem\agrsmsvc.exe
( ) C:\Windows\System32\lxdpcoms.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Exploit\mbae-svc.exe
(Paramount Software UK Ltd) C:\Program Files\Macrium\Reflect\ReflectService.exe
( ) C:\Windows\System32\slserv.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
( ) C:\Windows\System32\lxcfcoms.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Google Inc.) C:\Program Files\Google\Gmail Notifier\gnotify.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Exploit\mbae.exe
(Siber Systems) C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe
(Microsoft Corporation) C:\Windows\System32\perfmon.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\…\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] => C:\Program Files\Google\Gmail Notifier\gnotify.exe [479232 2005-07-15] (Google Inc.)
HKLM\…\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [150208 2014-01-18] (IvoSoft)
HKLM\…\Run: [Greenshot] => C:\Program Files\Greenshot\Greenshot.exe [540672 2015-04-19] (Greenshot)
HKLM\…\Run: [Malwarebytes Anti-Exploit] => C:\Program Files\Malwarebytes Anti-Exploit\mbae.exe [2620728 2015-07-22] (Malwarebytes Corporation)
HKU\S-1-5-21-2697119639-1211797034-894152058-1001\…\Run: [NetZero_uoltray] => C:\Program Files\NetZero\exec.exe [1776640 2010-06-29] (NetZero, Inc.)
HKU\S-1-5-21-2697119639-1211797034-894152058-1001\…\Run: [RoboForm] => C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [111320 2015-07-02] (Siber Systems)
HKU\S-1-5-21-2697119639-1211797034-894152058-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Ribbons.scr [120832 2014-11-21] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  No File
ShellIconOverlayIdentifiers: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer32.dll [2014-01-18] (IvoSoft)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ImageBrowser EX Agent.lnk [2015-08-01]
ShortcutTarget: ImageBrowser EX Agent.lnk -> C:\Program Files\Canon\ImageBrowser EX\MFManager.exe ()

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{A983AEA1-09B4-44F5-8D1C-7FB64360C76A}: [DhcpNameServer] 192.168.0.1

Internet Explorer:
==================
HKU\S-1-5-21-2697119639-1211797034-894152058-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://centurylink.net/?dc=O&s;=e77e1ca0-581a-3472-1d5b-39d1f285b39a&p;=2036&k;=f69bda69-22e4-40ac-9305-c0b7019b67a8&d;=lctl-res&pct;=100
HKU\S-1-5-21-2697119639-1211797034-894152058-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
URLSearchHook: [S-1-5-21-2697119639-1211797034-894152058-1001] ATTENTION => Default URLSearchHook is missing
URLSearchHook: HKU\S-1-5-21-2697119639-1211797034-894152058-1001 - (No Name) - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} -  No File
BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer32.dll [2014-01-18] (IvoSoft)
BHO: RoboForm Toolbar Helper -> {724d43a9-0d85-11d4-9908-00400523e39a} -> C:\Program Files\Siber Systems\AI RoboForm\roboform.dll [2015-07-02] (Siber Systems Inc.)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_51\bin\ssv.dll [2015-08-02] (Oracle Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_51\bin\jp2ssv.dll [2015-08-02] (Oracle Corporation)
BHO: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_32.dll [2014-01-18] (IvoSoft)
BHO: NetZero Toolbar Helper -> {FE3098B0-04A3-41fd-8CA9-BEA39CB14C87} -> C:\Program Files\NetZero\ucreg.dll [2010-06-30] (NetZero, Inc.)
Toolbar: HKLM - &RoboForm; Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll [2015-07-02] (Siber Systems Inc.)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2014-01-18] (IvoSoft)
Toolbar: HKU\S-1-5-21-2697119639-1211797034-894152058-1001 -> &RoboForm; Toolbar - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll [2015-07-02] (Siber Systems Inc.)
Toolbar: HKU\S-1-5-21-2697119639-1211797034-894152058-1001 -> No Name - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} -  No File

FireFox:
========
FF Plugin: @canon.com/MycameraPlugin -> C:\Program Files\Canon\MyCamera Download Plugin\NPCIG.dll [2008-10-15] (CANON INC.)
FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll [2015-07-10] (Google, Inc.)
FF Plugin: @java.com/DTPlugin,version=11.51.2 -> C:\Program Files\Java\jre1.8.0_51\bin\dtplugin\npDeployJava1.dll [2015-08-02] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.51.2 -> C:\Program Files\Java\jre1.8.0_51\bin\plugin2\npjp2.dll [2015-08-02] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AgereModemAudio; C:\Program Files\LSI SoftModem\agrsmsvc.exe [14336 2009-03-27] (LSI Corporation)
R2 BFE; C:\WINDOWS\System32\bfe.dll [570368 2015-08-10] (Microsoft Corporation) [File not signed]
R3 lxcf_device; C:\WINDOWS\system32\lxcfcoms.exe [491520 2005-07-25] ( )
R2 lxdp_device; C:\WINDOWS\system32\lxdpcoms.exe [589824 2007-11-19] ( )
R2 MbaeSvc; C:\Program Files\Malwarebytes Anti-Exploit\mbae-svc.exe [713016 2015-07-22] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 ReflectService.exe; C:\Program Files\Macrium\Reflect\ReflectService.exe [2589136 2015-02-23] (Paramount Software UK Ltd)
R2 SLService; C:\WINDOWS\system32\slserv.exe [45056 2004-05-12] ( ) [File not signed]
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [284520 2015-07-07] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [22224 2015-07-07] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 ElRawDisk; C:\Windows\system32\drivers\ElRawDsk.sys [26248 2012-12-06] (EldoS Corporation)
S3 EsgScanner; C:\WINDOWS\System32\DRIVERS\EsgScanner.sys [19984 2015-10-01] ()
R1 ESProtectionDriver; C:\Program Files\Malwarebytes Anti-Exploit\mbae.sys [47928 2015-07-22] ()
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [23256 2015-06-18] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [51928 2015-06-18] (Malwarebytes Corporation)
S3 Mtlstrm; C:\WINDOWS\system32\DRIVERS\Mtlstrm.sys [1395296 2004-05-12] ( ) [File not signed]
R1 RawDisk3; C:\WINDOWS\system32\drivers\rawdsk3.sys [28088 2015-07-24] (EldoS Corporation)
R0 RecAgent; C:\WINDOWS\System32\DRIVERS\RecAgent.sys [14408 2004-05-12] ( ) [File not signed]
S3 SlNtHal; C:\WINDOWS\system32\DRIVERS\Slnthal.sys [100384 2004-05-12] ( ) [File not signed]
S3 SlWdmSup; C:\WINDOWS\system32\DRIVERS\SlWdmSup.sys [13232 2004-05-12] ( ) [File not signed]
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [38928 2015-07-07] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [233304 2015-07-07] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [84824 2015-07-07] (Microsoft Corporation)
S3 WUDFWpdMtp; C:\WINDOWS\system32\DRIVERS\WUDFRd.sys [190976 2014-11-21] (Microsoft Corporation)
S1 BAPIDRV; system32\DRIVERS\BAPIDRV.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-10-04 09:02 - 2015-10-04 09:02 - 00009903 _____ C:\Users\Ron.M\Desktop\FRST.txt
2015-10-04 08:59 - 2015-10-04 08:59 - 00000000 ____D C:\Users\Ron.M\Desktop\FRST-OlderVersion
2015-10-04 08:58 - 2015-10-04 08:59 - 01697280 _____ (Farbar) C:\Users\Ron.M\Desktop\FRST.exe
2015-10-03 10:23 - 2015-10-03 10:40 - 00000000 ____D C:\ProgramData\RogueKiller
2015-10-03 10:23 - 2015-10-03 10:23 - 00035064 _____ C:\WINDOWS\system32\Drivers\TrueSight.sys
2015-10-03 10:06 - 2015-10-03 10:10 - 00000000 ____D C:\AdwCleaner
2015-10-03 09:53 - 2015-10-03 10:05 - 00001826 _____ C:\Users\Ron.M\Desktop\WTT  Satchfan Reply.txt
2015-10-03 09:48 - 2015-10-03 09:47 - 18801736 _____ C:\Users\Ron.M\Desktop\RogueKiller.exe
2015-10-03 09:45 - 2015-10-03 09:47 - 18801736 _____ C:\Users\Ron.M\Downloads\RogueKiller.exe
2015-10-03 09:43 - 2015-10-03 09:42 - 01801288 _____ (Malwarebytes) C:\Users\Ron.M\Desktop\Junkware Removal Tool .exe
2015-10-03 09:42 - 2015-10-03 09:42 - 01801288 _____ (Malwarebytes) C:\Users\Ron.M\Downloads\Junkware Removal Tool .exe
2015-10-03 09:39 - 2015-10-03 09:34 - 01670656 _____ C:\Users\Ron.M\Desktop\adwcleaner_5.009.exe
2015-10-03 09:34 - 2015-10-03 09:34 - 01670656 _____ C:\Users\Ron.M\Downloads\adwcleaner_5.009.exe
2015-10-03 09:25 - 2015-10-03 09:53 - 00000150 _____ C:\Users\Ron.M\Desktop\WTT Ransomeware reply.txt
2015-10-03 08:45 - 2015-10-03 08:45 - 00000552 _____ C:\Users\Ron.M\Desktop\ .website
2015-10-02 16:06 - 2015-10-04 09:02 - 00000000 ____D C:\FRST
2015-10-02 15:56 - 2015-10-02 15:56 - 01696256 _____ (Farbar) C:\Users\Ron.M\Downloads\FRST.exe
2015-10-02 15:10 - 2015-10-02 15:10 - 00001119 _____ C:\Users\Ron.M\Desktop\Naturpic Video Converter.lnk
2015-10-02 15:10 - 2015-10-02 15:10 - 00000000 ____D C:\Users\Ron.M\AppData\Local\Spoon
2015-10-02 15:10 - 2015-10-02 15:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Naturpic Video Converter
2015-10-02 15:10 - 2011-12-09 08:56 - 01931256 _____ (Codejock Software) C:\WINDOWS\system32\Codejock.Controls.Unicode.v15.2.1.ocx
2015-10-02 15:10 - 2011-12-09 08:56 - 01140728 _____ (Codejock Software) C:\WINDOWS\system32\Codejock.PropertyGrid.Unicode.v15.2.1.ocx
2015-10-02 15:10 - 2011-12-09 08:56 - 00587768 _____ (Codejock Software) C:\WINDOWS\system32\Codejock.SkinFramework.Unicode.v15.2.1.ocx
2015-10-02 15:10 - 2011-12-09 08:55 - 02775032 _____ (Codejock Software) C:\WINDOWS\system32\Codejock.CommandBars.Unicode.v15.2.1.ocx
2015-10-02 15:09 - 2015-10-02 15:10 - 00000000 ____D C:\Program Files\Naturpic Video Converter
2015-10-02 14:05 - 2015-10-02 14:05 - 00000000 ____D C:\Users\Ron.M\AppData\LocalLow\Temp
2015-10-02 13:52 - 2015-10-02 13:52 - 05198336 _____ (AVAST Software) C:\Users\Ron.M\Downloads\aswMBR.exe
2015-10-02 11:39 - 2015-10-02 11:39 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2015-10-02 11:39 - 2012-11-02 14:17 - 00242504 _____ (BitDefender) C:\WINDOWS\system32\Drivers\SET4C72.tmp
2015-10-02 11:39 - 2009-07-14 23:27 - 01461992 _____ (Microsoft Corporation) C:\WINDOWS\system32\WdfCoInstaller01009.dll
2015-10-02 11:34 - 2015-10-03 10:02 - 00590952 _____ C:\WINDOWS\PFRO.log
2015-10-02 11:29 - 2015-10-02 11:37 - 00000000 ____D C:\Users\Ron.M\AppData\Roaming\QuickScan
2015-10-02 11:28 - 2015-10-02 11:29 - 09927424 _____ C:\Users\Ron.M\Desktop\Antivirus_Free_Edition_x86.exe
2015-10-02 10:42 - 2015-10-03 10:40 - 00001388 _____ C:\WINDOWS\setupact.log
2015-10-02 10:42 - 2015-10-02 10:42 - 00000000 _____ C:\WINDOWS\setuperr.log
2015-10-02 08:26 - 2015-10-02 08:27 - 00361912 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-10-01 16:18 - 2015-10-01 16:18 - 00000000 ____D C:\KVRT_Data
2015-10-01 15:10 - 2015-10-01 15:11 - 00000000 ____D C:\sh4ldr
2015-10-01 15:06 - 2015-10-01 15:06 - 00019984 _____ C:\WINDOWS\system32\Drivers\EsgScanner.sys
2015-10-01 15:06 - 2015-10-01 15:06 - 00000000 ____D C:\Program Files\Enigma Software Group
2015-09-30 18:47 - 2015-09-30 18:47 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Exploit
2015-09-30 18:44 - 2015-09-30 18:53 - 00098520 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-09-30 18:44 - 2015-09-30 18:44 - 00001072 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-09-30 18:44 - 2015-09-30 18:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-09-30 18:44 - 2015-06-18 08:41 - 00094936 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-09-30 18:44 - 2015-06-18 08:41 - 00051928 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-09-30 18:44 - 2015-06-18 08:41 - 00023256 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-09-30 17:26 - 2015-09-30 17:27 - 00000000 ____D C:\ProgramData\Sophos
2015-09-30 17:26 - 2015-09-30 17:26 - 00002763 _____ C:\Users\Public\Desktop\Sophos Virus Removal Tool.lnk
2015-09-30 17:26 - 2015-09-30 17:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos
2015-09-30 17:26 - 2015-09-30 17:26 - 00000000 ____D C:\Program Files\Sophos
2015-09-30 17:11 - 2015-09-30 17:23 - 134793624 _____ (Sophos Limited) C:\Users\Ron.M\Downloads\Sophos Virus Removal Tool.exe
2015-09-30 11:02 - 2015-06-19 15:27 - 2632460288 _____ C:\Users\Ron.M\Desktop\HRM_CCSA_X86FRE_EN-US_DV5.ISO
2015-09-29 18:34 - 2015-10-04 08:51 - 00926277 _____ C:\WINDOWS\WindowsUpdate.log
2015-09-28 10:19 - 2015-09-30 10:49 - 00000000 ____D C:\Program Files\AviSynth 2.5
2015-09-28 10:19 - 2015-09-30 10:48 - 00000000 ____D C:\Program Files\Sothink Video Converter
2015-09-28 10:19 - 2015-09-30 10:48 - 00000000 ____D C:\Program Files\ffdshow
2015-09-28 10:19 - 2015-09-28 10:19 - 00000000 ____D C:\Program Files\Common Files\SourceTec
2015-09-28 10:13 - 2015-09-28 10:13 - 00000000 ____D C:\Users\Ron.M\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\illiminable
2015-09-27 10:04 - 2015-09-27 10:14 - 00000319 _____ C:\Users\Ron.M\Desktop\How to Get Into Safe Mode With Win 8.txt
2015-09-24 09:28 - 2015-09-24 09:28 - 00000383 _____ C:\Users\Ron.M\Desktop\Windows 10.website
2015-09-23 16:23 - 2015-09-23 16:23 - 00000000 ___HD C:\ProgramData\CanonIJQuickMenu
2015-09-23 16:20 - 2015-09-24 08:52 - 00000000 ____D C:\ProgramData\CanonIJPLM
2015-09-23 15:57 - 2015-09-30 10:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MG2500 series User Registration
2015-09-23 15:57 - 2015-09-23 15:57 - 00000000 ____D C:\Users\Ron.M\AppData\LocalLow\Canon Easy-WebPrint EX2
2015-09-23 15:57 - 2015-09-23 15:57 - 00000000 ____D C:\Users\Ron.M\AppData\LocalLow\Canon Easy-WebPrint EX
2015-09-23 15:55 - 2015-09-23 15:55 - 00000000 ____D C:\ProgramData\CanonIJWSpt
2015-09-23 15:48 - 2015-09-23 15:48 - 00000000 ___HD C:\ProgramData\CanonBJ
2015-09-23 15:45 - 2015-09-30 10:48 - 00000000 ____D C:\Program Files\CanonBJ
2015-09-23 14:59 - 2015-09-23 14:59 - 00000361 _____ C:\Users\Ron.M\Desktop\Phone Battery eBay…txt
2015-09-23 14:45 - 2015-09-23 14:58 - 00000655 _____ C:\Users\Ron.M\Desktop\2000mAh Cordless Phone Battery for Uniden BT 905 BP 800 BT 800 BP 905 DXI9862 US  eBay.website
2015-09-23 09:49 - 2015-09-23 09:49 - 00001079 _____ C:\Users\Ron.M\Desktop\Backup USB.txt
2015-09-22 17:25 - 2015-08-22 09:50 - 02279424 ____N (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-09-22 17:25 - 2015-08-22 09:00 - 01951232 ____N (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-09-22 17:25 - 2015-08-22 08:56 - 01310720 ____N (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-09-22 17:09 - 2015-07-22 07:25 - 02461184 ____N (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2015-09-22 17:08 - 2015-09-02 19:17 - 01903848 ____N (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2015-09-22 17:08 - 2015-09-02 10:09 - 01556992 ____N (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2015-09-22 17:08 - 2015-08-26 11:00 - 00721920 ____N (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2015-09-22 16:54 - 2015-08-07 14:46 - 01469456 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2015-09-22 16:54 - 2015-08-07 14:46 - 00888896 ____N (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2015-09-22 16:54 - 2015-08-07 14:40 - 00507176 ____N (Microsoft Corporation) C:\WINDOWS\system32\advapi32.dll
2015-09-22 16:54 - 2015-08-06 09:18 - 04068352 ____N (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
2015-09-22 16:53 - 2015-08-10 10:01 - 00570368 ____N (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL
2015-09-22 16:53 - 2015-08-10 09:56 - 00272384 ____N (Microsoft Corporation) C:\WINDOWS\system32\FWPUCLNT.DLL
2015-09-22 16:48 - 2015-09-30 18:44 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2015-09-22 16:21 - 2015-09-22 16:21 - 00000093 _____ C:\rescuepe.log
2015-09-22 16:06 - 2015-09-30 11:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Macrium
2015-09-22 16:06 - 2015-09-22 16:06 - 00001949 _____ C:\Users\Public\Desktop\Reflect.lnk
2015-09-22 16:06 - 2015-09-22 16:06 - 00000000 ____D C:\Program Files\Macrium
2015-09-22 16:04 - 2015-09-22 16:04 - 00000035 _____ C:\Users\Ron.M\Desktop\Macrium  License Key.txt
2015-09-22 15:58 - 2015-09-22 16:06 - 00266400 _____ C:\Reflect_Install.log
2015-09-22 15:13 - 2015-09-22 15:56 - 00000000 ____D C:\Users\Ron.M\Downloads\Macrium
2015-09-22 14:58 - 2015-09-22 16:07 - 00000000 ____D C:\ProgramData\Macrium
2015-09-21 11:32 - 2015-08-07 14:46 - 01469456 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll(125).dll
2015-09-21 11:32 - 2015-08-07 14:46 - 00888896 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase(120).dll
2015-09-21 11:32 - 2015-08-07 14:40 - 00507176 _____ (Microsoft Corporation) C:\WINDOWS\system32\advapi32(112).dll
2015-09-21 11:32 - 2015-08-06 09:18 - 04068352 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1(117).dll
2015-09-21 11:12 - 2015-07-22 07:25 - 02461184 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui(114).dll
2015-09-21 10:39 - 2015-09-21 10:39 - 00000000 ____D C:\Users\Ron.M\AppData\Local\Downloaded Installations
2015-09-20 15:40 - 2015-09-20 15:42 - 00000000 ____D C:\Users\Ron.M\Desktop\RoboForm
2015-09-17 15:09 - 2015-09-17 15:09 - 00002846 _____ C:\Users\Ron.M\Desktop\P.ED.txt
2015-09-14 08:54 - 2015-09-28 11:07 - 00000782 _____ C:\Users\Ron.M\Desktop\Canon PIXMA MG2520 All-in-One Printer - Print, Copy, Scan, up to 8 ipm Black, 4 ipm Color, Up 4800 x 600 dpi Print Resolution a.website
2015-09-13 11:02 - 2015-09-13 11:03 - 00000000 ___HD C:\$Windows.~BT
2015-09-13 10:22 - 2015-09-21 08:42 - 00000000 ____D C:\fafd8dd900cbeeaa90a92b
2015-09-12 15:32 - 2015-09-21 08:42 - 00000000 ____D C:\Users\Ron.M\AppData\Roaming\vlc
2015-09-12 15:31 - 2015-09-20 18:27 - 00000000 ____D C:\Program Files\VideoLAN
2015-09-12 12:50 - 2015-09-12 13:40 - 00000439 _____ C:\Users\Ron.M\Desktop\Yohimbe.txt

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-10-04 09:00 - 2013-08-22 01:17 - 00000000 ____D C:\WINDOWS\system32\sru
2015-10-03 11:28 - 2015-07-06 17:59 - 00007594 _____ C:\Users\Ron.M\AppData\Local\Resmon.ResmonCfg
2015-10-03 11:28 - 2015-06-23 15:29 - 00000000 ____D C:\Users\Ron.M\AppData\Roaming\ClassicShell
2015-10-03 11:15 - 2013-08-21 23:13 - 00262144 ___SH C:\WINDOWS\system32\config\ELAM
2015-10-03 10:40 - 2013-08-22 00:23 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-10-03 09:39 - 2015-07-24 11:24 - 00000000 ___RD C:\Users\Ron.M\Desktop\EXE's
2015-10-03 09:22 - 2013-08-22 01:17 - 00000000 __RSD C:\WINDOWS\Media
2015-10-03 08:56 - 2015-07-31 12:19 - 00719872 ___SH C:\Users\Ron.M\Desktop\Thumbs.db
2015-10-02 17:37 - 2015-08-23 11:36 - 00000000 ____D C:\ProgramData\Malwarebytes Anti-Exploit
2015-10-02 14:40 - 2015-07-27 14:00 - 00003568 _____ C:\Users\Ron.M\Desktop\Tracking numbers.txt
2015-10-02 11:34 - 2015-06-23 16:51 - 00000000 ____D C:\ProgramData\AVAST Software
2015-10-01 12:44 - 2015-07-16 11:54 - 00000000 ___RD C:\Users\Ron.M\Documents\PI
2015-09-30 16:56 - 2013-08-22 01:17 - 00000000 ____D C:\WINDOWS\system32\LogFiles
2015-09-30 15:24 - 2014-11-21 18:00 - 00863592 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-09-30 11:31 - 2015-07-31 10:21 - 00000000 ___SD C:\WINDOWS\system32\GWX
2015-09-30 11:31 - 2015-07-18 15:24 - 00000000 ____D C:\Users\Ron.M\AppData\Roaming\GRETECH
2015-09-30 11:31 - 2015-07-16 11:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\illiminable
2015-09-30 11:31 - 2015-07-02 13:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RoboForm
2015-09-30 11:31 - 2014-11-21 17:45 - 00000000 ____D C:\WINDOWS\ShellNew
2015-09-30 11:31 - 2014-11-21 17:45 - 00000000 ____D C:\Program Files\Windows Journal
2015-09-30 11:31 - 2013-08-22 01:17 - 00000000 ____D C:\WINDOWS\system32\WinMetadata
2015-09-30 11:31 - 2013-08-22 01:17 - 00000000 ____D C:\WINDOWS\system32\Macromed
2015-09-30 11:31 - 2013-08-22 01:17 - 00000000 ____D C:\WINDOWS\AppCompat
2015-09-30 11:28 - 2013-08-22 01:17 - 00000000 ____D C:\WINDOWS\registration
2015-09-30 11:06 - 2013-08-21 23:13 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2015-09-30 10:51 - 2015-07-30 21:37 - 00000000 ____D C:\Users\Ron.M
2015-09-30 10:43 - 2013-08-22 01:17 - 00000000 ____D C:\WINDOWS\Microsoft.NET
2015-09-30 10:41 - 2015-07-16 11:49 - 00000000 ____D C:\Program Files\illiminable
2015-09-24 08:43 - 2015-07-31 13:17 - 00000000 ____D C:\Users\Ron.M\AppData\Roaming\canon
2015-09-23 16:31 - 2015-09-01 14:14 - 00014920 _____ C:\Users\Ron.M\Desktop\Rent Payment Form  #2.odt
2015-09-23 15:10 - 2012-07-25 23:43 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-09-23 11:37 - 2013-08-22 01:17 - 00000000 ____D C:\WINDOWS\system32\NDF
2015-09-22 17:30 - 2015-07-07 05:03 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-09-22 16:23 - 2013-08-22 01:17 - 00262144 _____ C:\WINDOWS\system32\config\BCD-Template
2015-09-22 14:53 - 2013-08-22 01:17 - 00000000 ____D C:\WINDOWS\System
2015-09-22 14:49 - 2015-08-22 11:22 - 00000000 ____D C:\Program Files\Reference Assemblies
2015-09-22 14:49 - 2015-08-22 11:22 - 00000000 ____D C:\Program Files\MSBuild
2015-09-22 14:49 - 2015-07-02 13:01 - 00000000 ____D C:\Program Files\Siber Systems
2015-09-22 14:49 - 2013-08-22 01:17 - 00000000 ____D C:\WINDOWS\rescache
2015-09-22 14:49 - 2013-08-22 01:17 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2015-09-22 13:34 - 2013-08-21 23:21 - 00000000 ___RD C:\Users\Public
2015-09-21 08:57 - 2013-08-21 23:13 - 00262144 ___SH C:\WINDOWS\system32\config\BBI(28)
2015-09-21 08:57 - 2013-08-21 23:13 - 00262144 ___SH C:\WINDOWS\system32\config\BBI(116)
2015-09-21 08:57 - 2013-08-21 23:13 - 00262144 ___SH C:\WINDOWS\system32\config\BBI(11)
2015-09-20 15:47 - 2015-06-23 16:00 - 00000000 ____D C:\ProgramData\RoboForm
2015-09-15 11:50 - 2015-07-16 11:56 - 00000000 ____D C:\Users\Ron.M\Documents\Mas
2015-09-13 11:02 - 2015-07-30 22:14 - 00000000 ___DC C:\WINDOWS\Panther
2015-09-13 11:02 - 2013-08-22 01:17 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-09-13 10:51 - 2013-08-21 23:13 - 00262144 ___SH C:\WINDOWS\system32\config\BBI(61)
2015-09-13 10:51 - 2013-08-21 23:13 - 00262144 ___SH C:\WINDOWS\system32\config\BBI(43)
2015-09-13 10:51 - 2013-08-21 23:13 - 00262144 ___SH C:\WINDOWS\system32\config\BBI(38)
2015-09-09 11:18 - 2015-08-22 16:17 - 00000737 _____ C:\Users\Ron.M\Desktop\3.6 volt phone battery  eBay.website
2015-09-07 15:46 - 2015-08-14 15:26 - 00000499 _____ C:\Users\Ron.M\Desktop\2 Bedroom ONLY $525.website
2015-09-04 13:16 - 2015-07-22 21:54 - 00000654 _____ C:\Users\Ron.M\Desktop\Shaver List eBay.website

==================== Files in the root of some directories =======

2015-07-06 17:59 - 2015-10-03 11:28 - 0007594 _____ () C:\Users\Ron.M\AppData\Local\Resmon.ResmonCfg

Some files in TEMP:
====================
C:\Users\Ron.M\AppData\Local\Temp\dllnt_dump.dll
C:\Users\Ron.M\AppData\Local\Temp\sqlite3.dll

==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2015-09-20 10:03

==================== End of FRST.txt ============================



Additional scan results;=>..
 

Additional scan result of Farbar Recovery Scan Tool (x86) Version:30-10-2015
Ran by [removed](2015-10-04 09:03:00)
Running from C:\Users\[removed]\Desktop
Microsoft Windows 8.1 Pro (X86) (2015-07-31 04:54:16)
Boot Mode: Normal
==========================================================

==================== Accounts: =============================

Administrator (S-1-5-21-2697119639-1211797034-894152058-500 - Administrator - Disabled)
Guest (S-1-5-21-2697119639-1211797034-894152058-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2697119639-1211797034-894152058-1003 - Limited - Enabled)
Ron.M (S-1-5-21-2697119639-1211797034-894152058-1001 - Administrator - Enabled) => C:\Users\Ron.M

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 4.65 (HKLM\…\7-Zip) (Version:  - )
Canon Utilities CameraWindow DC 8 (HKLM\…\CameraWindowDC) (Version: 8.8.0.17 - Canon Inc.)
Canon Utilities ImageBrowser EX (HKLM\…\ImageBrowser EX) (Version: 1.5.2.8 - Canon Inc.)
Classic Shell (HKLM\…\{13793E6A-6DBC-4112-81B7-7554DFC5D959}) (Version: 4.0.4 - IvoSoft)
Customer Support (HKLM\…\{B33D89E4-FB43-6749-447E-2E469AC9EB5B}) (Version: 0.0.0.1 - Lexmark International, Inc.)
Foxit Reader (HKLM\…\Foxit Reader) (Version: 4.3.0.1110 - Foxit Corporation)
GOM Player (HKLM\…\GOM Player) (Version: 2.2.69.5227 - Gretech Corporation)
Google Gmail Notifier (HKLM\…\{0228e555-4f9c-4e35-a3ec-b109a192b4c2}) (Version:  - Google Inc.)
Greenshot 1.2.6.7 (HKLM\…\Greenshot_is1) (Version: 1.2.6.7 - Greenshot)
Intel® Driver Update Utility (HKLM\…\{8409c4f7-2340-4933-a304-5d37db4fb48b}) (Version: 2.0.0.29 - Intel)
Java 8 Update 51 (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F83218051F0}) (Version: 8.0.510 - Oracle Corporation)
LSI PCI-SV92PP Soft Modem (HKLM\…\LSI Soft Modem) (Version: 2.2.98 - LSI Corporation)
Macrium Reflect Free Edition (HKLM\…\MacriumReflect) (Version: 6.0 - Paramount Software (UK) Ltd.)
Macrium Reflect Free Edition (Version: 6.0.753 - Paramount Software (UK) Ltd.) Hidden
Malwarebytes Anti-Exploit version 1.07.1.1015 (HKLM\…\Malwarebytes Anti-Exploit_is1) (Version: 1.07.1.1015 - Malwarebytes)
Malwarebytes Anti-Malware version 2.1.8.1057 (HKLM\…\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Naturpic Video Converter 6.0 (HKLM\…\Naturpic Video Converter_is1) (Version:  - Naturpic Software)
NetZero Internet (HKLM\…\{6c651250-2eb2-11d5-8e33-0050dad72ac2}) (Version: 8.9.3.0 - NetZero, Inc.)
oggcodecs 0.71.0946 (HKLM\…\oggcodecs) (Version: 0.71.0946 - illiminable)
OpenOffice 4.1.1 (HKLM\…\{9395F41D-0F80-432E-9A59-B8E477E7E163}) (Version: 4.11.9775 - Apache Software Foundation)
Picasa 3 (HKLM\…\Picasa 3) (Version: 3.9.140.239 - Google, Inc.)
Privacy Guardian 4.5 (HKLM\…\Privacy Guardian_is1) (Version: 4.5 - PC Tools)
Revo Uninstaller 1.90 (HKLM\…\Revo Uninstaller) (Version: 1.90 - VS Revo Group)
RoboForm 7-9-10-1 (All Users) (HKLM\…\AI RoboForm) (Version: 7-9-10-1 - Siber Systems)
Sophos Virus Removal Tool (HKLM\…\{B829E117-D072-41EA-9606-9826A38D34C1}) (Version: 2.5.4 - Sophos Limited)
SoundMAX (HKLM\…\{F0A37341-D692-11D4-A984-009027EC0A9C}) (Version: 5.12.1.7010 - Analog Devices)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

==================== Restore Points =========================

22-09-2015 16:30:40 avast! antivirus system restore point
24-09-2015 08:45:06 Revo Uninstaller's restore point - Canon My Image Garden
27-09-2015 11:07:51 Windows Update
30-09-2015 10:36:02 Restore Operation
01-10-2015 15:58:03 Revo Uninstaller's restore point - SpyHunter 4
03-10-2015 09:20:45 Revo Uninstaller's restore point - iolo technologies' System Mechanic

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-08-21 23:13 - 2013-08-21 23:13 - 00000824 ____N C:\WINDOWS\system32\Drivers\etc\hosts

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {07C81133-C612-4F6F-97A1-23C3BCE75144} - System32\Tasks\Open URL by RoboForm => Rundll32.exe url.dll,FileProtocolHandler "http://www.roboform.com/test-pass.html?aaa=KICMLJMJMMPMOJIMOJJMCNMMNJMJMJCNLMLJPMGMCNNJKJIMNMCNHMNMJJNMKJJMIMMMPMKMMMJMJNJICMIMCNGMCNOMPMFMOMPMCNPMCNGMNMPMPMFMJMCNNMCNGMNMPMPMCNNMJNPICMPMFMMJBJKJLIMJFMHMJNHICMMJBJKJLIMJJNBJCMNKAJBJOJDJLJPNCLOJIJBJOJBJJNKJCMJNNICMJNDJCMKJBJJNMJCMPMFMOMFMPMJNFICMGJLJKJBJLIGJLIGJKJMIBNKJHIKJ"
Task: {1DCB230B-0545-48E3-A0DB-A920AE584A9B} - System32\Tasks\{BB6188E0-1E61-4FDE-8005-585003C081E5} => pcalua.exe -a "D:\My Documents\EXE's\R96000 #4.EXE" -d "D:\My Documents\EXE's"
Task: {3CFB71B0-C012-4AA6-99F0-04AD026A2A67} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => Rundll32.exe invagent.dll,RunUpdate -noappraiser
Task: {46A43753-EBE3-4138-8FCF-AE14631C863F} - System32\Tasks\{31E034A6-F0E0-4481-BC2C-B4F57CFDEAAB} => pcalua.exe -a "D:\My Documents\EXE's\R79695 #2.EXE" -d "D:\My Documents\EXE's"
Task: {5CF12292-B5B8-4E1C-AC2B-7C774A1437D4} - System32\Tasks\SpyHunter4Startup => C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe
Task: {732987B3-3ED0-4E59-95EF-61D38CF0A472} - \ProPCCleaner_Start -> No File <==== ATTENTION
Task: {9BDE793B-D1BF-4763-AE01-0B5FDF836233} - \ProPCCleaner_Popup -> No File <==== ATTENTION
Task: {9F16C1E8-2A29-4AD2-A7B7-B48B57F50E34} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2015-07-30] (AVAST Software)
Task: {B137BFB3-89B0-490A-B0B2-CB80774C541E} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-07-28] (Microsoft Corporation)
Task: {CDC720FA-5F05-4827-AE3D-2BE06D1C3342} - System32\Tasks\{EEF87537-F6FC-4B1A-A5B6-1D8AF02F8CEA} => pcalua.exe -a "D:\My Documents\EXE's\R121089 #1.EXE" -d "D:\My Documents\EXE's"
Task: {DBE78EB1-2E54-4A23-AB55-E2F4CF03FD88} - System32\Tasks\{00257BAD-FED6-4477-8719-9E01FC709F1D} => pcalua.exe -a "C:\Users\Ron.M\Desktop\EXE's\dotnetfx  Net (IE).exe"
Task: {E72E2732-B9D5-4DE1-9974-85069A0B2C74} - System32\Tasks\Run RoboForm TaskBar Icon => C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [2015-07-02] (Siber Systems)
Task: {EBFBEBB4-9030-4B15-9518-D0BA3EA1A3FB} - System32\Tasks\{ED55B930-C6AC-47DE-ADCE-7217DC24BA02} => pcalua.exe -a "C:\Program Files\ERUNT\AUTOBACK.EXE" -d "C:\Users\Ron.M\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup" -c C:\WINDOWS\ERDNT\AutoBackup\#Date# /noconfirmdelete /noprogresswindow

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

==================== Loaded Modules (Whitelisted) ==============

2015-08-28 10:41 - 2009-08-13 12:02 - 00147968 _____ () C:\WINDOWS\system32\spool\PRTPROCS\W32X86\lxdpdrpp.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData\TEMP:42D9E231

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)

==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\S-1-5-21-2697119639-1211797034-894152058-1001\…\dell.com -> dell.com

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2697119639-1211797034-894152058-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Theme2\img7.jpg
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

HKLM\…\StartupApproved\StartupFolder: => "ImageBrowser EX Agent.lnk"
HKLM\…\StartupApproved\Run: => "Greenshot"
HKLM\…\StartupApproved\Run: => "iolo Startup"
HKU\S-1-5-21-2697119639-1211797034-894152058-1001\…\StartupApproved\Run: => "NetZero_uoltray"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{0D637031-70D7-4173-8474-F7E317A2E18D}] => (Allow) C:\Windows\System32\lxdpcoms.exe
FirewallRules: [{883D49B1-A924-44BE-B3E5-AB2377A7425D}] => (Allow) C:\Windows\System32\lxdpcoms.exe

==================== Faulty Device Manager Devices =============

Name: Video Controller
Description: Video Controller
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

==================== Event log errors: =========================

Application errors:
==================
Error: (10/03/2015 09:20:57 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.

System Error:
Access is denied.
.

Error: (10/03/2015 09:20:44 AM) (Source: VSS) (EventID: 8194) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface.  hr = 0x80070005, Access is denied.
.
This is often caused by incorrect security settings in either the writer or requestor process.

Operation:
   Gathering Writer Data

Context:
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {3b37a68e-e213-4dcc-af5f-e278269be3e1}

Error: (10/02/2015 03:02:29 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: GOM.EXE, version: 2.2.69.5227, time stamp: 0x5513bb04
Faulting module name: grfu.ax, version: 1.1.8.35, time stamp: 0x54f913ec
Exception code: 0xc0000005
Fault offset: 0x0000c891
Faulting process id: 0x1344
Faulting application start time: 0xGOM.EXE0
Faulting application path: GOM.EXE1
Faulting module path: GOM.EXE2
Report Id: GOM.EXE3
Faulting package full name: GOM.EXE4
Faulting package-relative application ID: GOM.EXE5

Error: (10/02/2015 03:02:14 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: GOM.EXE, version: 2.2.69.5227, time stamp: 0x5513bb04
Faulting module name: grfu.ax, version: 1.1.8.35, time stamp: 0x54f913ec
Exception code: 0xc0000005
Fault offset: 0x0000c891
Faulting process id: 0x1290
Faulting application start time: 0xGOM.EXE0
Faulting application path: GOM.EXE1
Faulting module path: GOM.EXE2
Report Id: GOM.EXE3
Faulting package full name: GOM.EXE4
Faulting package-relative application ID: GOM.EXE5

Error: (10/02/2015 03:01:46 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: GOM.EXE, version: 2.2.69.5227, time stamp: 0x5513bb04
Faulting module name: grfu.ax, version: 1.1.8.35, time stamp: 0x54f913ec
Exception code: 0xc0000005
Fault offset: 0x0000c891
Faulting process id: 0x1150
Faulting application start time: 0xGOM.EXE0
Faulting application path: GOM.EXE1
Faulting module path: GOM.EXE2
Report Id: GOM.EXE3
Faulting package full name: GOM.EXE4
Faulting package-relative application ID: GOM.EXE5

Error: (10/02/2015 10:46:44 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program iexplore.exe version 11.0.9600.17840 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 54c

Start Time: 01d0fd3a25bcc503

Termination Time: 343

Application Path: C:\Program Files\Internet Explorer\iexplore.exe

Report Id: 87028166-692d-11e5-b009-001143c8f08b

Faulting package full name:

Faulting package-relative application ID:

Error: (10/01/2015 05:17:27 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program iexplore.exe version 11.0.9600.17840 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: e0

Start Time: 01d0fca5d7371904

Termination Time: 236

Application Path: C:\Program Files\Internet Explorer\iexplore.exe

Report Id: f5981aa8-689a-11e5-b007-001143c8f08b

Faulting package full name:

Faulting package-relative application ID:

Error: (10/01/2015 05:04:00 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program iexplore.exe version 11.0.9600.17840 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 708

Start Time: 01d0fca5859b6b69

Termination Time: 8234

Application Path: C:\Program Files\Internet Explorer\iexplore.exe

Report Id: 0ef9ae61-6899-11e5-b007-001143c8f08b

Faulting package full name:

Faulting package-relative application ID:

Error: (10/01/2015 05:01:42 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program iexplore.exe version 11.0.9600.17840 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 930

Start Time: 01d0fca45c53379f

Termination Time: 5812

Application Path: C:\Program Files\Internet Explorer\iexplore.exe

Report Id: bdd798d3-6898-11e5-b007-001143c8f08b

Faulting package full name:

Faulting package-relative application ID:

Error: (10/01/2015 03:58:21 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.

System Error:
Access is denied.
.

System errors:
=============
Error: (10/03/2015 10:16:02 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Media Player Network Sharing Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.

Error: (10/03/2015 10:16:01 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The SmartLinkService service terminated unexpectedly.  It has done this 1 time(s).

Error: (10/03/2015 10:16:01 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Macrium Reflect Image Mounting Service service terminated unexpectedly.  It has done this 1 time(s).

Error: (10/03/2015 10:16:01 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Malwarebytes Anti-Exploit Service service terminated unexpectedly.  It has done this 1 time(s).

Error: (10/03/2015 10:16:01 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The lxdp_device service terminated unexpectedly.  It has done this 1 time(s).

Error: (10/03/2015 10:16:01 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Agere Modem Call Progress Audio service terminated unexpectedly.  It has done this 1 time(s).

Error: (10/03/2015 10:10:33 AM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Search service, but this action failed with the following error:
%%1056

Error: (10/03/2015 10:10:03 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Media Player Network Sharing Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.

Error: (10/03/2015 10:10:03 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Search service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.

Error: (10/03/2015 10:10:03 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The SmartLinkService service terminated unexpectedly.  It has done this 1 time(s).

CodeIntegrity:
===================================
  Date: 2015-10-03 11:24:42.939
  Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-10-03 11:24:42.924
  Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-10-03 11:24:42.908
  Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-10-03 11:24:42.877
  Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-10-03 11:15:28.664
  Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-10-03 11:15:28.648
  Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-10-03 11:15:28.633
  Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-10-03 11:15:27.976
  Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

==================== Memory info ===========================

Processor: Intel(R) Pentium(R) 4 CPU 2.80GHz
Percentage of memory in use: 45%
Total physical RAM: 2038.14 MB
Available physical RAM: 1109.4 MB
Total Virtual: 2678.14 MB
Available Virtual: 1590.79 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:465.42 GB) (Free:427.85 GB) NTFS ==>[drive with boot components (obtained from BCD)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 00021F46)
Partition 1: (Active) - (Size=465.4 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================



 

 


Satchfan;…

The ONLY things that are different in BOTH posts that I altered is my REAL name…
Wherever you see Ron.M in those logs had my real name that I chose to not have seen here…
There were tons of my name plastered in the 1st log…
As far as being hit & miss with replying , I have the same reason as you regarding the weekend , so no problem there…
I have NO way to tell IF there are any differences between the 2 logs !!!
I do not have any expertise along those lines..
Sorry , but , I'm not an analyst…
I will leave that up to you &/or anyone else who choses to do so…
Sorry about that…

 

Anything else you need or want me to do , just ask…..


Have a GREAT day….


Later…Ron.M… B) ….

 

 

 

 

let me know if here is any change or if things remain the same.

 

I meant has there been any change or improvement in your computer.

 

Satchfan

There is no sign of malware in your logs just a lot of tidying up and clearing out of the various scanners/tweakers that you’ve thrown at your machine but when we’ve done that we’ll try a different online scan and see what that comes up with.
 

Wherever you see Ron.M in those logs had my real name that I chose to not have seen here…
There were tons of my name plastered in the 1st log


The logs we ask for do not contain any information that can be used to harm your computer, (unless your password is same as your username).

All the accounts currently in your PC are shown in the log and are necessary if you wish to fix any problems. I would advise you to refrain from changing anything shown in the logs otherwise the fix(es) won't work.

===================================================

Uninstall programs

Uninstall this program:

Sophos Virus Removal Tool
 

  • hold down the Windows logo key and press X to open a menu at the lower-left area of the screen
  • select Programs and Features from the menu
  • search and select the above programs one by one and click on Uninstall
  • reboot your computer.

===================================================

Run Farbar Recovery Scan Tool

Download attached fixlist.txt file and save it to the Desktop.

NOTE. It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.

NOTE: this script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

Run FRST/FRST64 and press the Fix button just once and wait.

If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.

When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

 

📎Fixlist.txt

================================================

Run ESET Online Scan

Note: This may take a long time so please be patient.

IMPORTANT Please make sure you uncheck the box next to Remove found threats. Eset will detect anything that looks even slightly suspicious, which could include legitimate program files. If you do not uncheck the box, Eset will automatically remove all suspicious files which could leave some of your software inoperable.

Note: You can use Internet Explorer, FireFox or  Chrome for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Hold down Control and click on the following link to open ESET OnlineScan in a new window.

ESET OnlineScan

  • click the Eset online Scanner button
  • for alternate browsers only: (Microsoft Internet Explorer users can skip these steps)


    o    click on esetinstaller.exe to download the ESET Smart Installer. Save it to your desktop.
    o    double click on the Eset installer icon on your desktop.
     

  • check Yes, I accept the Terms of Use
  • click the Start button
  • accept any security warnings from your browser
  • check Enable detection of potentially unwanted applications
  • click Advanced settings and select the following:


    o    scan archives
    o    scan for potentially unsafe applications
    o    enable Anti-Stealth technology


    Note: Do not check Remove found threats
     

  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • when the scan completes, push List of found threats
  • push Export to Text file and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.


    Note - if ESET doesn't find any threats, no report will be created.
     

  • push the back button.
  • push Finish

When the scan is complete:

If no threats were found:


o    put a checkmark in "Uninstall application on close"
o    close program
o    report to me that nothing was found.
 

If threats were found:


o    click on "list of threats found"
o    click on "export to text file" and save it as ESET results and save to the desktop
o    Click on back
o    put a checkmark in "Uninstall application on close"
o    click on finish
o    close program
o    copy and paste the report here.
 

Please also remember to include Fixlog.txt

Thanks

Satchfan
 

 

Satchfan;….

Having a problem with your instructions…

I will uninstall Sophos later…
What is it that you don't like about that program ??
I ran it yesterday & lo & behold the "Trojan;Ransomeware" is GONE ???
That's the good news…


Now the bad news;=>..
There hasn't been any great changes to the way my computer is working..
The System Recovery still says the restore was not successfully completed & I still can not Repair the OS using the Install USB ISO…





Concerning 
Having problems with this one !!!  
Clicked on this
ESET OnlineScan 
and could not find "esetinstaller.exe" to download …

Concerning Farbar Recovery Scan Tool 
;=>…
I ran the one I got before >> ""FRST.exe""…
I got 2 texts..
One is "FRST.txt" & the other is "Addition.txt"…
I downloaded "Fixlist (1).txt" & installed it on my desktop…
When I ran the tool & clicked on Fix one time I get this message;=>.."No fixlist.txt" found …
The fixlist.txt should be in the same folder/directory the tool is located in…"""
Do you think that the text you want me to use is mislabeled ???
Should "Fixlist (1).txt" be "Fixlist.txt" without the (1) ???


I could not find this;=>.. ""Run >>> FRST/FRST64 <<< and press the Fix button just once and wait.""


Later…Ron.M… B) …

Clicked on this ESET OnlineScan 
and could not find "esetinstaller.exe" to download

 

  • click on the Run Eset online Scanner button and another window should open
  • in this window, click on esetsmartinstaller_enu.exe
  • a popup will appear, click on Save.

You should then be able to locate it in your default download location.

 

If you are having problems and the Esetsmartinstaller window doesn't appear, please try it using a different browser.

 

======================================

 

The Farbar "fix" may not be working for one of two reasons:

 

  1. You have changed the entries in your log and they don't match the entries in the fix
  2. You haven't saved the fixlist.txt file to your desktop, (the same location as FRST

Please check and try again.

 

BTW, Windows Defender will be temporarily disabled in case it hinders the registry removal

 

If it doesn't work, let me know. You may need to run FRST again and post the log "as is", ie, not a tampered-with version. :)

 

Let me know how it goes.

 

Satchfan

Satchfan;…..

OK . Thanks , I now have  esetsmartinstaller_enu.exe downloaded & on my desktop…

 

 

You haven't saved the fixlist.txt file to your desktop, (the same location as FRST

IF you mean the text file from the first scan , then that's what happened…
My desktop is quite filled with stuff & after we moved on to the next steps , I shredded the text files to make some room thinking that we were done with them…
Had I known that they would be needed for future use , I WOULD have saved them & left them as-is…

 

 

You have changed the entries in your log and they don't match the entries in the fix

The ONLY things that were changed in the original "FRST.txt" was my real name to Ron.M…
IF I screwed this up , I'm terribly sorry…
How do I fix this ???

Do you want me to proceed with the ESET online scan ??


Later…Ron.M… B) ….

Satchfan;….

In an attempt to correct this;….
I tried to restore the OS back to when those files were on my desktop….
The restore was SUCCESSFUL !!!
However some files were not there…
Including some of the ones we downloaded for this endeavor…
Other stuff appears missing also…
So while there I downloaded the missing files & ran them again..
I re-installed "adwcleaner_5.010.exe" & ran the  file…
I re-installed "Farbar Recovery Scan Tool.exe" & ran the file & have "FRST.txt" & "Addition.txt" texts on my desktop…
I also had "Fixlist (1).txt" in my downloads list…
I carefully removed "(1)" from the name…
I then clicked on "Fix" one time & ta-da , it appears to have WORKED !!!
I re-installed "RogueKiller.exe" & ran the file…
I then restored to the original date (today's date)..
That one did not successfully restore …
So I downloaded the missing files & ran them again..
I have "FRST.txt" & "Addition.txt" texts on my desktop…
Plus , "Fixlog.txt" & "Etscan Online.txt" & will keep them there till no longer needed & have clearance from you…



HOLY MOLDY , Batman , I have 39 infected files !!!… :smack: ..


Screwed up again !!!!
Did not see this part in time;=>..

 

If threats were found:


o    click on "list of threats found"
o    click on "export to text file" and save it as ESET results and save to the desktop
o    Click on back
o    put a checkmark in "Uninstall application on close"
o    click on finish
o    close program
o    copy and paste the report here.
 

I will re-scan later tonite & follow thru with the rest of this procedure..


Later…Ron.M…. B) ….

Satchfan;……

Turns out that the 2 texts I posted earlier are the CORRECT ones you asked for…
I compared each to the earlier versions & they are carbon copies of each other…

Have a GREAT evening…


Let me know what's next…

BTW: ..
That Etscan IS a GREAT tool….
I intend on keeping it for future scans…
THANKS…


Later…Ron.M…. B) ….




 

It would appear that you “old computer” was infected with a variant of CryptoWall as “HELP_DECRYPT.TXT” is an indication of that so we’ll get rid of those. The rest of the Online scan is only reporting items located in System Restore's cache C:\System Volume Information\.


Let’s tidy up what Eset found.

Please copy all text in the code box below and paste it into Notepad:
 


  • save the Notepad file to your desktop and name it delfiles.bat
  • save type as "All Files"
  • on your desktop, double-click on delfiles.bat to run it, (a black CMD window will flash, then disappear - this is normal).

The files/folders, if found, will have been deleted and the "delfile.bat" file will also be deleted.

Can you tell me the current situation and what the remaining problems are.

Thanks

Satchfan

Satchfan;….

I ran "delfiles.bat" as you requested..
It performed as you said..
Bad news is;..
NO noticeable changes , bad or good !!!!…
Still recovery/restore problem & NO Installation Repair due to blocked file(?) …
I re-scanned with "ESET OnlineScan:" & I STILL have 39 infected files…



Can you edit out the Notepad text you have in your last post ???..
I AM PARANOID about having my real name on ANY forum…
As you well know there are scammers & crooks galore online…
All they need to steal your ID is your name , S.S. number , credit card number , phone number &/or lesser info about you to have "fun" with your ID…
THANKS…


What's next ???…



Later…Ron.M… B) ….

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI