This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Phishing Attack [Solved]

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, help required please.

 

I have been subject to an attempted fraud attack via my computer upon my bank account to extract money from my account, however the bank spotted this and prevented the transaction.

This started with a phone call perported to be from my internet provider TalkTalk saying that they had a serious attack on their networks which had caused my router to be compromised and allowed damage to my computer systems. They gave all my TalkTalk account details, account number, personal address, type of service etc and were convincing, but I questioned the validity of what they were telling me. They showed me how to see the damaged files on my system using Event Viewer and System Configuration Files, etc, which showed a large number of red dot, yellow triangle warning symbols as well as a large number of applications that were not running. They said this needed to be fixed immediately as it was spreading through my systems and would crash the computer, and also that they would have to disconnect my internet connection if I did not accept their help to stop this and clear up the applications/files damage. Their call was identical to other phone calls I had had with the providers technical team and was totally convincing.

They then directed me to a TalkTalk web page providing technical assistance where I authorised remote access to my computer to allow them to fix the issues. This resulted in a running graph page as the locked screen showing to me. This was kept running for a couple of hours whilst they talked to me on my phone, supposedly they were scanning my sytsems and correcting the damaged entries. They were also to make a physical service the next day to replace the router with a newer version with stronger security features. 

Eventually they said they would have to complete this the following day and asked me to close the computer and unplug the router.

 

A few hours later I had a phone call from my bank asking if I had authorised a payment transaction to another party, as they suspected it might be part of a widespread TalkTalk related scam, fortunately they had withheld the transaction. They said they could see no compromise of my accound details but I am to change my passwords, etc.

TalkTalk said tests showed no compromise to my account or router and all appeared to be running ok, they are aware of this widespread scam.

 

I have restarted my computer and all appears to be working normal, but I found team viewer icons on my desktop which I have now un-installed via control panel. I also ran MalwareBytes which found nothing. My conscern now is have the scammers installed anything on my computer which might continue to extract data or personal information.

If someone can help me to check or clean my computer for this problem I would be very grateful.

 

I have a Toshiba Satellite Pro L100 laptop (about 7 years old) running Windows XP Professional SP3, Office Pro 2003 SP3, Firefox browser, Avast antivirus, Windows Firewall, Wireless router, kept fully updated.

 

Many thanks

BarryA 

Hello BarryA and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Apologies for the delay but other members of the malware team are busy and I am away from home with limited Internet access at the moment.


With regard to your computer problem, if someone has had access to your computer, you should no longer consider it to be safe. Although we can check to see if it is free from malware, you can no longer fully trust it; therefore, my advice would be to backup all your files and reinstall your operating system.

That said, Microsoft stopped supporting Windows XP/SP3 on April 8, 2014.

This means that if you re-install Windows XP, your operating system will no longer have updates and patches to prevent infections.

Any XP machine that has accessed the Internet after that date can expect to become infected repeatedly and any information on is capable of being stolen and there is no real remedy. Criminals were reportedly making extra preparations for the date that XP support ended.

See this link from ESET


If you choose to re-install, see this link in our Windows Forum which leads you through formatting/re-installing.

If that is not an option and you still want me to check for malware, let me know and I’ll send further instructions.

Satchfan
 

Hello Satchfan

 

Thank you for your response.

I think I will plan to replace my computer as soon as I can as it is old now anyway. 

Re-installation is probably a retrograde step as it will then have no update patches at all since introduction.

 

In the meantime I would like to clean my computer as thoroughly as I can and carry out any checks possible to identify any system compromises.

Help with that will be appreciated. Besides malware, what else can we look for that may have been done to my machine? Might a Hyjackthis report show up any irregular scripts, etc. 

 

HSBC bank has recommended I then install IBM Trusteer Rapport to offer financial activity security, for keystroke protection, etc. Although I have never heard of this before, online comments appear to suggest it useful, although it might slow down my systems a little. Any comments you may have on this software is invited.

 

I look forward to your assistance Satchfan.

p.s. your link to ESET does not appear to work as it finds no pages.

 

BarryA  

I think I will plan to replace my computer as soon as I can as it is old now anyway.

I suggest you do it as soon as you can possibly afford it. Windows 10 is the most secure operating system ever introduced.
 

HSBC bank has recommended I then install IBM Trusteer Rapport

Trusteer Rapport is very well known and I would use it myself if I trusted/used Internet banking so it is worth installing but wait until your computer is "clean".
 

your link to ESET does not appear to work 

Sorry about that.
 

I would like to clean my computer as thoroughly as I can and carry out any checks possible to identify any system compromises..

OK
 

Might a Hyjackthis report show up any irregular scripts, etc.

HijackThis hasn't been used for some time but I'll get you to run some other scans to see what is on your computer.


Please read the following guidelines which will help to make cleaning your machine easier:

  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!

IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

===================================================

Run RogueKiller

IMPORTANT: Please remove any usb or external drives from the computer before you run this scan!

Close all running programs.


Download RogueKiller to your desktop

  • close all running programs
  • for Windows Vista/Seven, right click -> run as administrator, for XP simply double-click on RogueKiller.exe
  • when the pre-scan is finished, click on Scan
  • click on Report and copy/paste the content in your next post
  • NOTE: DO NOT attempt to remove anything that the scan detects –everything that is reported is not necessarily bad

If the program is blocked, continue to try it several times. If it still doesn’t work, (it could happen), rename it to winlogon.exe.

Please post the contents of the RKreport.txt in your next reply.

===================================================

Run Farbar Recovery Scan Tool

Please download Farbar Recovery Scan Tool and save it to your Desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

  • right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • press Scan button
  • it will produce a log called Frst.txt in the same directory the tool is run from
  • please copy and paste log back here.
  • the first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the Frst.txt into your reply.

Logs to include with next post:

RKreport.txt
Frst.txt
Addition.txt


Thanks

Satchfan

Hello

Sorry for delay, I was away from home yesterday but am back now. Here are the reports:

 

RogueKiller V11.0.9.0 [Jan 24 2016] (Free) by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/software/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User : GARETH [Administrator]
Started from : C:\Documents and Settings\GARETH\Desktop\RogueKiller.exe
Mode : Scan – Date : 01/31/2016 13:22:31

¤¤¤ Processes : 0 ¤¤¤

¤¤¤ Registry : 1 ¤¤¤
[PUM.StartMenu] HKEY_USERS\S-1-5-21-1528555759-1161534989-3529426194-1005\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowRecentDocs : 2  -> Found

¤¤¤ Tasks : 0 ¤¤¤

¤¤¤ Files : 0 ¤¤¤

¤¤¤ Hosts File : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: FUJITSU MHV2040BH +++++
— User —
[MBR] 0c151194efa3300619213c2034bb7af8
[BSP] e3890296318e99e943594b58f7994c9f : Windows XP|VT.Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 63 | Size: 38152 MB [Windows XP Bootstrap | Windows XP Bootloader]
User = LL1 … OK
User = LL2 … OK

+++++ PhysicalDrive1: Canon MP610 series USB Device +++++
Error reading User MBR! ([15] The device is not ready. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] The request is not supported. )
 

****************************************************************************************************************************

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:27-01-2016
Ran by [removed] (administrator) on ROBLAPTOP (31-01-2016 14:01:01)
Running from C:\Documents and Settings\[removed]\Desktop
[removed] Platform: Microsoft Windows XP Professional Service Pack 3 (X86) Language: English (United States)
Internet Explorer Version 8 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe
(AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
() C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(TOSHIBA CORPORATION) C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
(ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
() C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe
(TOSHIBA Corporation) C:\WINDOWS\system32\TPSMain.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\TOSHIBA Zooming Utility\SmoothView.exe
(TOSHIBA CORPORATION) C:\Program Files\Toshiba\ConfigFree\CFSServ.exe
(CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
(Nuance Communications, Inc.) C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe
(TOSHIBA Inc.) C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\Toshiba.exe
() C:\WINDOWS\system32\CmWatch.exe
(AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastUI.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(TOSHIBA) C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
(TOSHIBA Corporation) C:\WINDOWS\system32\TPSBattM.exe
(Microsoft Corporation) C:\WINDOWS\system32\wbem\unsecapp.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\…\Run: [TPSMain] => C:\WINDOWS\system32\TPSMain.exe [266240 2006-02-08] (TOSHIBA Corporation)
HKLM\…\Run: [SmoothView] => C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe [118784 2005-05-12] (TOSHIBA Corporation)
HKLM\…\Run: [CFSServ.exe] => CFSServ.exe -NoClient
HKLM\…\Run: [CanonSolutionMenu] => C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe [644696 2007-05-14] (CANON INC.)
HKLM\…\Run: [CanonMyPrinter] => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [1603152 2007-04-03] (CANON INC.)
HKLM\…\Run: [SSBkgdUpdate] => C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [210472 2006-10-25] (Nuance Communications, Inc.)
HKLM\…\Run: [OpwareSE4] => C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe [79400 2007-02-04] (Nuance Communications, Inc.)
HKLM\…\Run: [Toshiba Hotkey Utility] => C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe [1589248 2006-01-28] (TOSHIBA Inc.)
HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [761945 2005-12-16] (Synaptics, Inc.)
HKLM\…\Run: [BluetoothAuthenticationAgent] => rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
HKLM\…\Run: [NeroCheck] => C:\WINDOWS\system32\\NeroCheck.exe [155648 2001-07-09] (Ahead Software Gmbh)
HKLM\…\Run: [CmCardRun] => C:\WINDOWS\system32\CmWatch.exe [229376 2003-09-16] ()
HKLM\…\Run: [AvastUI.exe] => C:\Program Files\Alwil Software\Avast5\AvastUI.exe [7021880 2015-12-10] (AVAST Software)
HKLM\…\Run: [Nikon Message Center 2] => C:\Program Files\Nikon\Nikon Message Center 2\NkMC2.exe [571392 2011-10-30] (Nikon Corporation)
HKLM\…\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2014-05-08] (Adobe Systems Incorporated)
HKLM\…\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [597552 2015-08-04] (Oracle Corporation)
Winlogon\Notify\AtiExtEvent: C:\WINDOWS\system32\Ati2evxx.dll [2005-12-12] (ATI Technologies Inc.)
HKLM\…\Policies\Explorer: [NoCDBurning] 0
HKU\S-1-5-21-1528555759-1161534989-3529426194-1005\…\Run: [TOSCDSPD] => C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe [65536 2005-04-11] (TOSHIBA)
HKU\S-1-5-21-1528555759-1161534989-3529426194-1005\…\Run: [POP Peeper] => C:\Program Files\POP Peeper\POPPeeper.exe [1609728 2011-08-18] (Mortal Universe)
HKU\S-1-5-21-1528555759-1161534989-3529426194-1005\…\Policies\Explorer: [NoDriveAutoRun] 0xFFFFFFFF
HKU\S-1-5-21-1528555759-1161534989-3529426194-1005\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\ssstars.scr [14336 2008-04-14] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Alwil Software\Avast5\ashShell.dll [2015-12-10] (AVAST Software)
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Service Manager.lnk [2006-07-27]
ShortcutTarget: Service Manager.lnk -> C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe (Microsoft Corporation)
Startup: C:\Documents and Settings\GARETH\Start Menu\Programs\Startup\Microsoft Office OneNote 2003 Quick Launch.lnk [2008-10-06]
ShortcutTarget: Microsoft Office OneNote 2003 Quick Launch.lnk -> C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Documents and Settings\ROB\Start Menu\Programs\Startup\Microsoft Office OneNote 2003 Quick Launch.lnk [2006-07-31]
ShortcutTarget: Microsoft Office OneNote 2003 Quick Launch.lnk -> C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Winsock: Catalog5 05 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{7AB3E566-EB3E-4BDD-AF07-48A28BF0BD8F}: [DhcpNameServer] 192.168.1.1 192.168.1.1

Internet Explorer:
==================
HKU\S-1-5-21-1528555759-1161534989-3529426194-1005\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
HKU\S-1-5-21-1528555759-1161534989-3529426194-1005\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.co.uk/
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1528555759-1161534989-3529426194-1005 -> DefaultScope {406D5B00-B614-4825-A6B5-19BD5C004E33} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1528555759-1161534989-3529426194-1005 -> {406D5B00-B614-4825-A6B5-19BD5C004E33} URL = hxxp://www.google.com/search?q={searchTerms}
BHO: No Name -> {206E52E0-D52E-11D4-AD54-0000E86C26F6} -> C:\Program Files\FreshDevices\FreshDownload\fdcatch.dll [2007-04-25] (FreshDevices Corp.)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_60\bin\ssv.dll [2015-09-01] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll [2015-11-30] (AVAST Software)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_60\bin\jp2ssv.dll [2015-09-01] (Oracle Corporation)
Toolbar: HKLM - FreshDownload Bar - {ED0E8CA5-42FB-4B18-997B-769E0408E79D} - C:\Program Files\FreshDevices\FreshDownload\fdiebar.dll [2011-01-17] (FreshDevices Corp.)
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1395059582562
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL [2000-04-19] (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\WINDOWS\system32\Skype4COM.dll [2007-02-07] (Skype Technologies)

FireFox:
========
FF ProfilePath: C:\Documents and Settings\GARETH\Application Data\Mozilla\Firefox\Profiles\8pnurqgc.default
FF DefaultSearchEngine: Google (avast)
FF DefaultSearchUrl: hxxps://www.google.com/search/?trackid=sp-006
FF SearchEngineOrder.1: Google (avast)
FF SelectedSearchEngine: Google (avast)
FF Homepage: hxxps://www.google.co.uk/
FF Session Restore: -> is enabled.
FF Keyword.URL: hxxps://www.google.com/search/?trackid=sp-006
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_20_0_0_286.dll [2016-01-20] ()
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\PROGRAM FILES\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [2015-02-11] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\PROGRAM FILES\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [2015-02-11] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\PROGRAM FILES\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [2015-02-11] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\PROGRAM FILES\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [2015-02-11] (Foxit Corporation)
FF Plugin: @java.com/DTPlugin,version=11.60.2 -> C:\Program Files\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll [2015-09-01] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.60.2 -> C:\Program Files\Java\jre1.8.0_60\bin\plugin2\npjp2.dll [2015-09-01] (Oracle Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npfd.dll [2010-09-29] (FreshDevices Corp.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFFICE.DLL [2007-03-22] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF SearchPlugin: C:\Documents and Settings\GARETH\Application Data\Mozilla\Firefox\Profiles\8pnurqgc.default\searchplugins\google-avast.xml [2015-01-20]
FF Extension: NoScript - C:\Documents and Settings\GARETH\Application Data\Mozilla\Firefox\Profiles\8pnurqgc.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2016-01-14]
FF Extension: Microsoft .NET Framework Assistant - C:\Documents and Settings\GARETH\Application Data\Mozilla\Firefox\Profiles\8pnurqgc.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi [2015-01-27] [not signed]
FF Extension: Google Toolbar for Firefox - C:\Documents and Settings\GARETH\Application Data\Mozilla\Firefox\Profiles\8pnurqgc.default\Extensions\{3112ca9c-de6d-4884-a869-9855de68056c} [2010-07-05] [not signed]
FF Extension: Adblock Plus - C:\Documents and Settings\GARETH\Application Data\Mozilla\Firefox\Profiles\8pnurqgc.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-01-19]
FF Extension: Google Toolbar for Firefox - C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c} [2016-01-27] [not signed]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2016-01-27] [not signed]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2016-01-27] [not signed]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\Alwil Software\Avast5\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\Alwil Software\Avast5\WebRep\FF [2015-12-10]
FF HKLM\…\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2013-01-28] [not signed]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\Alwil Software\Avast5\SafePrice\FF
FF Extension: Avast SafePrice - C:\Program Files\Alwil Software\Avast5\SafePrice\FF [2015-12-10]

Chrome:
=======
CHR Profile: C:\Documents and Settings\GARETH\Local Settings\Application Data\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Documents and Settings\GARETH\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-01-31]
CHR Extension: (Google Drive) - C:\Documents and Settings\GARETH\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-01-31]
CHR Extension: (YouTube) - C:\Documents and Settings\GARETH\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-01-31]
CHR Extension: (Google Search) - C:\Documents and Settings\GARETH\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-01-31]
CHR Extension: (Store) - C:\Documents and Settings\GARETH\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-02-03]
CHR Extension: (Google Wallet) - C:\Documents and Settings\GARETH\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-31]
CHR Extension: (Gmail) - C:\Documents and Settings\GARETH\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-01-31]
CHR HKLM\…\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\Alwil Software\Avast5\WebRep\Chrome\aswWebRepChrome.crx [2015-11-30]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [226440 2015-12-10] (AVAST Software)
R2 BlueSoleil Hid Service; C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe [166520 2008-03-19] ()
R2 CFSvcs; C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe [40960 2005-01-17] (TOSHIBA CORPORATION) [File not signed]
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
R2 MSSQL$MICROSOFTSMLBIZ; C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe [9150464 2005-05-03] (Microsoft Corporation) [File not signed]
S3 MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe [73728 2005-05-03] (Microsoft Corporation) [File not signed]
S3 SQLAgent$MICROSOFTSMLBIZ; C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlagent.EXE [323584 2005-05-03] (Microsoft Corporation) [File not signed]
R2 Start BT in service; C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe [51816 2008-03-19] ()

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AegisP; C:\WINDOWS\System32\DRIVERS\AegisP.sys [17801 2006-07-27] (Meetinghouse Data Communications) [File not signed]
R3 AR5211; C:\WINDOWS\System32\DRIVERS\ar5211.sys [468736 2005-09-13] (Atheros Communications, Inc.)
R2 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [24016 2015-12-10] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [81168 2016-01-07] (AVAST Software)
R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [55200 2015-12-10] (AVAST Software)
R0 aswRvrt; C:\WINDOWS\system32\Drivers\aswRvrt.sys [49776 2015-12-10] (AVAST Software)
R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [812208 2016-01-20] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [449384 2016-01-20] (AVAST Software)
R3 aswStmXP; C:\WINDOWS\system32\drivers\aswStmXP.sys [165104 2015-12-10] (AVAST Software)
S3 aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [58016 2015-12-10] (AVAST Software)
R0 aswVmm; C:\WINDOWS\system32\Drivers\aswVmm.sys [209432 2015-12-10] (AVAST Software)
R3 BlueletAudio; C:\WINDOWS\System32\DRIVERS\blueletaudio.sys [34312 2007-06-24] (IVT Corporation.)
R3 BlueletSCOAudio; C:\WINDOWS\System32\DRIVERS\BlueletSCOAudio.sys [27656 2007-06-24] (IVT Corporation.)
R3 BoiHwsetup; C:\WINDOWS\System32\drivers\BoiHwSetup.sys [5504 2005-06-11] (Quanta Computer Corp)
S3 BT; C:\WINDOWS\System32\DRIVERS\btnetdrv.sys [18320 2007-03-05] (IVT Corporation.)
S3 Btcsrusb; C:\WINDOWS\System32\Drivers\btcusb.sys [38920 2007-06-24] (IVT Corporation.)
R0 BTHidEnum; C:\WINDOWS\System32\Drivers\vbtenum.sys [20880 2007-03-05] (IVT Corporation.)
R0 BTHidMgr; C:\WINDOWS\System32\Drivers\BTHidMgr.sys [35600 2007-03-05] (IVT Corporation.)
R3 HSFHWATI; C:\WINDOWS\System32\DRIVERS\HSFHWATI.sys [225792 2005-11-29] (Conexant Systems, Inc.)
R3 HSF_DPV; C:\WINDOWS\System32\DRIVERS\HSF_DPV.sys [936960 2005-11-29] (Conexant Systems, Inc.)
R3 Iviaspi; C:\WINDOWS\System32\drivers\iviaspi.sys [21060 2003-09-10] (InterVideo, Inc.) [File not signed]
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [23256 2015-10-05] (Malwarebytes)
S3 MonitorFunction; C:\WINDOWS\System32\DRIVERS\TVMonitor.sys [13304 2015-11-16] (TeamViewer GmbH)
R2 Netdevio; C:\WINDOWS\System32\DRIVERS\netdevio.sys [12032 2003-01-29] (TOSHIBA Corporation.) [File not signed]
R3 Pfc; C:\WINDOWS\System32\drivers\pfc.sys [10368 2003-09-19] (Padus, Inc.) [File not signed]
R0 PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [20640 2005-04-25] (Sonic Solutions) [File not signed]
R3 qkbfiltr; C:\WINDOWS\System32\drivers\qkbfiltr.sys [31872 2006-01-12] (Quanta Computer, Inc.) [File not signed]
R3 qmofiltr; C:\WINDOWS\System32\drivers\qmofiltr.sys [7936 2005-05-05] (Quanta Computer, Inc.) [File not signed]
S3 RTL8023xp; C:\WINDOWS\System32\DRIVERS\Rtlnicxp.sys [74496 2005-03-04] (Realtek Semiconductor Corporation                           )
S3 rtl8139; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [20992 2004-08-03] (Realtek Semiconductor Corporation)
S3 UMSSSTOR; C:\WINDOWS\System32\DRIVERS\UMSS.SYS [48384 2003-09-16] (C-Media Corporation)
R3 VComm; C:\WINDOWS\System32\DRIVERS\VComm.sys [34448 2007-03-05] (IVT Corporation.)
R3 VcommMgr; C:\WINDOWS\System32\Drivers\VcommMgr.sys [44304 2007-03-05] (IVT Corporation.)
S4 IntelIde; no ImagePath
S3 Lavasoft Kernexplorer; \??\C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys [X]
S0 Lbd; system32\DRIVERS\Lbd.sys [X]
S1 SBRE; \??\C:\WINDOWS\system32\drivers\SBREdrv.sys [X]
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
U1 WS2IFSL; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-01-31 14:01 - 2016-01-31 14:01 - 00020505 _____ C:\Documents and Settings\GARETH\Desktop\FRST.txt
2016-01-31 14:00 - 2016-01-31 14:01 - 00000000 ____D C:\FRST
2016-01-31 13:58 - 2016-01-31 13:58 - 01721856 _____ (Farbar) C:\Documents and Settings\GARETH\Desktop\FRST.exe
2016-01-31 13:45 - 2016-01-31 13:45 - 00002846 _____ C:\Documents and Settings\GARETH\Desktop\Rogue Killer Report.txt
2016-01-31 13:01 - 2016-01-31 13:46 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\RogueKiller
2016-01-31 13:01 - 2016-01-31 13:01 - 00024688 _____ C:\WINDOWS\system32\Drivers\TrueSight.sys
2016-01-31 12:57 - 2016-01-31 12:57 - 00000000 ___HD C:\WINDOWS\PIF
2016-01-31 12:50 - 2016-01-31 12:53 - 20940872 _____ C:\Documents and Settings\GARETH\Desktop\RogueKiller.exe
2016-01-27 11:37 - 2016-01-28 11:17 - 00000000 ____D C:\Program Files\Mozilla Firefox
2016-01-27 11:34 - 2015-11-16 15:18 - 00013304 _____ (TeamViewer GmbH) C:\WINDOWS\system32\Drivers\TVMonitor.sys
2016-01-27 10:57 - 2016-01-27 10:57 - 00000000 ____D C:\Documents and Settings\GARETH\Application Data\TeamViewer
2016-01-23 10:24 - 2016-01-23 10:24 - 00000000 ____D C:\Documents and Settings\LocalService\Local Settings\Application Data\Temp
2016-01-20 07:39 - 2016-01-20 08:39 - 04499648 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerInstaller.exe
2016-01-15 15:01 - 2016-01-15 15:01 - 00731997 _____ C:\Documents and Settings\GARETH\Desktop\Jan IVC 2016 Bulletin. pdf
2016-01-10 19:42 - 2016-01-10 19:42 - 00000000 ____D C:\Documents and Settings\All Users\Foxit Software
2016-01-10 19:41 - 2016-01-10 19:41 - 00001786 _____ C:\Documents and Settings\All Users\Desktop\Foxit Reader.lnk
2016-01-10 19:41 - 2016-01-10 19:41 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Foxit Reader

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-01-31 14:01 - 2006-07-27 08:18 - 00000000 ____D C:\Documents and Settings\GARETH\Local Settings\Temp
2016-01-31 13:59 - 2015-10-26 11:34 - 461063168 _____ C:\Documents and Settings\GARETH\Desktop\Outlook backup.pst
2016-01-31 13:39 - 2015-08-16 21:30 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-01-31 12:44 - 2012-05-25 11:50 - 03794802 _____ C:\WINDOWS\system32\English
2016-01-31 12:43 - 2012-08-05 19:08 - 00000366 ____H C:\WINDOWS\Tasks\avast! Emergency Update.job
2016-01-31 12:37 - 2008-10-06 23:11 - 00083672 _____ C:\Documents and Settings\GARETH\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2016-01-31 12:36 - 2006-02-15 14:29 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-01-31 12:35 - 2006-02-15 14:29 - 00032542 _____ C:\WINDOWS\SchedLgU.Txt
2016-01-31 12:34 - 2006-07-27 08:18 - 00000278 ___SH C:\Documents and Settings\GARETH\ntuser.ini
2016-01-31 03:20 - 2013-10-14 15:17 - 00000424 ____H C:\WINDOWS\Tasks\User_Feed_Synchronization-{E3CB84DD-4309-468E-B967-A2F4E33CA2E1}.job
2016-01-28 12:42 - 2015-10-29 17:20 - 00170200 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-01-28 12:37 - 2015-01-14 19:47 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2016-01-28 12:37 - 2006-02-15 14:16 - 00326704 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-01-28 12:29 - 2006-02-15 14:11 - 00000000 ___HD C:\WINDOWS\inf
2016-01-28 11:32 - 2006-02-15 13:10 - 00000211 __RSH C:\boot.ini
2016-01-28 11:32 - 2006-02-15 13:09 - 00000603 _____ C:\WINDOWS\win.ini
2016-01-28 11:32 - 2006-02-15 13:09 - 00000227 _____ C:\WINDOWS\system.ini
2016-01-28 00:01 - 2006-07-27 08:18 - 00000000 ____D C:\Documents and Settings\GARETH
2016-01-27 11:35 - 2006-02-15 14:12 - 00000000 ____D C:\WINDOWS\system32\ReinstallBackups
2016-01-21 17:47 - 2012-10-04 17:02 - 00500736 ___SH C:\Documents and Settings\GARETH\Desktop\Thumbs.db
2016-01-20 19:23 - 2011-05-20 17:23 - 00812208 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsnx.sys
2016-01-20 19:23 - 2010-07-02 14:39 - 00449384 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsp.sys
2016-01-20 08:40 - 2012-04-16 10:31 - 00796864 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2016-01-20 08:40 - 2011-05-13 23:23 - 00142528 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2016-01-10 19:42 - 2006-02-15 14:16 - 00000000 ____D C:\Documents and Settings\All Users
2016-01-07 19:23 - 2013-03-05 11:00 - 00081168 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswmonflt.sys
2016-01-07 17:53 - 2012-10-05 10:46 - 00015949 _____ C:\Documents and Settings\GARETH\English
2016-01-07 15:13 - 2006-02-15 14:11 - 00000000 ____D C:\WINDOWS\security
2016-01-07 14:37 - 2006-02-15 13:09 - 00001158 _____ C:\WINDOWS\system32\wpa.dbl

==================== Files in the root of some directories =======

2013-12-03 13:44 - 2013-12-03 13:44 - 0000268 ___RH () C:\Documents and Settings\GARETH\Application Data\Grapher
2013-12-03 13:46 - 2013-12-03 13:46 - 0000268 ___RH () C:\Documents and Settings\GARETH\Application Data\Graphics
2013-12-03 13:44 - 2013-12-03 13:44 - 0000268 ___RH () C:\Documents and Settings\GARETH\Application Data\Guides
2013-12-03 13:31 - 2013-12-03 13:31 - 0000268 ___RH () C:\Documents and Settings\GARETH\Application Data\Horns
2014-01-16 09:40 - 2014-01-16 09:40 - 0000105 _____ () C:\Documents and Settings\GARETH\Application Data\WB.CFG
2011-04-13 11:38 - 2015-10-26 11:31 - 0023552 _____ () C:\Documents and Settings\GARETH\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2006-07-27 09:46 - 2006-07-27 09:46 - 0000129 _____ () C:\Documents and Settings\GARETH\Local Settings\Application Data\fusioncache.dat
2013-12-03 13:44 - 2013-12-03 13:44 - 0000268 ___RH () C:\Documents and Settings\All Users\Application Data\Guitars
2013-12-03 13:46 - 2013-12-03 13:46 - 0000268 ___RH () C:\Documents and Settings\All Users\Application Data\HAL
2013-12-03 13:44 - 2013-12-03 13:44 - 0000268 ___RH () C:\Documents and Settings\All Users\Application Data\Halftone
2013-12-03 13:31 - 2013-12-03 13:31 - 0000268 ___RH () C:\Documents and Settings\All Users\Application Data\Hybrid Synthesizers
2013-12-03 13:31 - 2013-12-03 13:44 - 0000020 ____H () C:\Documents and Settings\All Users\Application Data\PKP_DLeo.DAT
2013-12-03 13:46 - 2013-12-03 13:46 - 0000020 ____H () C:\Documents and Settings\All Users\Application Data\PKP_DLes.DAT
2013-12-03 13:44 - 2014-07-27 14:49 - 0000020 ____H () C:\Documents and Settings\All Users\Application Data\PKP_DLet.DAT
2013-12-03 13:44 - 2013-12-03 13:44 - 0000020 ____H () C:\Documents and Settings\All Users\Application Data\PKP_DLev.DAT

Some files in TEMP:
====================
C:\Documents and Settings\GARETH\Local Settings\Temp\dllnt_dump.dll


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

==================== End of FRST.txt ============================

 

Additional scan result of Farbar Recovery Scan Tool (x86) Version:27-01-2016
Ran by [removed] (2016-01-31 14:02:16)
Running from C:\Documents and Settings\[removed]\Desktop
Microsoft Windows XP Professional Service Pack 3 (X86) (2006-07-27 08:16:31)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-1528555759-1161534989-3529426194-500 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Administrator
ASPNET (S-1-5-21-1528555759-1161534989-3529426194-1003 - Limited - Enabled)
GARETH (S-1-5-21-1528555759-1161534989-3529426194-1005 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\GARETH
Guest (S-1-5-21-1528555759-1161534989-3529426194-501 - Limited - Enabled)
HelpAssistant (S-1-5-21-1528555759-1161534989-3529426194-1004 - Limited - Disabled)
ROB (S-1-5-21-1528555759-1161534989-3529426194-1006 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\ROB
SUPPORT_388945a0 (S-1-5-21-1528555759-1161534989-3529426194-1002 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: avast! Antivirus (Disabled - Up to date) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: Norton Internet Worm Protection (Disabled) {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

AC97 Data Fax SoftModem with SmartCP (HKLM\…\CNXT_MODEM_PCI_VEN_1002&DEV;_4378&SUBSYS;_FF311179) (Version:  - )
Adobe Flash Player 20 ActiveX (HKLM\…\Adobe Flash Player ActiveX) (Version: 20.0.0.286 - Adobe Systems Incorporated)
Adobe Flash Player 20 NPAPI (HKLM\…\Adobe Flash Player NPAPI) (Version: 20.0.0.286 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.08) (HKLM\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.08 - Adobe Systems Incorporated)
ArcSoft Panorama Maker 6 (HKLM\…\{DABFD34E-BE68-4BC6-9254-5D7A7FF76B99}) (Version: 6.0.8.85 - ArcSoft)
Atheros Client Utility (HKLM\…\{71D658CF-4E0D-4DA8-AA67-8C0B6F1C01FE}) (Version: 1.41.000 - )
Atheros Wireless LAN MiniPCI card Driver (HKLM\…\{05832D65-6EDB-4D32-BA78-BCD0E2B91C02}) (Version: 1.26.000 - )
ATI - Software Uninstall Utility (HKLM\…\All ATI Software) (Version: 6.14.10.1014 - )
ATI Control Panel (HKLM\…\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}) (Version: 6.14.10.5173 - )
ATI Display Driver (HKLM\…\ATI Display Driver) (Version: 8.203-051211a-030226C-Toshiba - )
Avast Free Antivirus (HKLM\…\avast) (Version: 11.1.2245 - AVAST Software)
BFPA '99 (HKLM\…\ST5UNST #1) (Version:  - )
Bluesoleil2.7.0.35 VoIP Release 080317 (HKLM\…\{B9A17C96-1348-45CB-BB0A-1BCB3A0F854E}) (Version: 2.7.0.35 VoIP Release 080317 - IVT Corporation)
Bonjour (HKLM\…\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
Canon MP Navigator EX 1.0 (HKLM\…\MP Navigator EX 1.0) (Version:  - )
Canon MP610 series (HKLM\…\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP610_series) (Version:  - )
Canon MP610 series User Registration (HKLM\…\Canon MP610 series User Registration) (Version:  - )
Canon My Printer (HKLM\…\CanonMyPrinter) (Version:  - )
Canon Utilities Easy-PhotoPrint EX (HKLM\…\Easy-PhotoPrint EX) (Version:  - )
Canon Utilities Solution Menu (HKLM\…\CanonSolutionMenu) (Version:  - )
CD/DVD Drive Acoustic Silencer (HKLM\…\{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}) (Version: 1.00.008 - TOSHIBA)
CD-LabelPrint (HKLM\…\MediaNavigation.CDLabelPrint) (Version:  - )
CleanUp! (HKLM\…\CleanUp!) (Version:  - )
C-Media USB Mass Storage Driver (HKLM\…\C-Media Card Reader Driver) (Version:  - )
Compatibility Pack for the 2007 Office system (HKLM\…\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Conexant AC-Link Audio (HKLM\…\CNXT_AUDIO) (Version:  - )
Foxit Reader (HKLM\…\Foxit Reader_is1) (Version: 7.2.8.1124 - Foxit Software Inc.)
FreshDownload (HKLM\…\FreshDevices - FreshDownload_is1) (Version:  - )
ImgBurn (HKLM\…\ImgBurn) (Version: 2.5.7.0 - LIGHTNING UK!)
InterVideo WinDVD Creator 2 (HKLM\…\{2FCE4FC5-6930-40E7-A4F1-F862207424EF}) (Version: 2.0.14.376 - InterVideo Inc.)
InterVideo WinDVD for TOSHIBA (HKLM\…\{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}) (Version: 5.0-B11.535 - InterVideo Inc.)
Java 7 Update 80 (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F03217080FF}) (Version: 7.0.800 - Oracle)
Java 8 Update 40 (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F83218040F0}) (Version: 8.0.400 - Oracle Corporation)
Java 8 Update 45 (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F83218045F0}) (Version: 8.0.450 - Oracle Corporation)
Java 8 Update 60 (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F83218060F0}) (Version: 8.0.600.27 - Oracle Corporation)
Macromedia Flash Player (HKLM\…\{0456ebd7-5f67-4ab6-852e-63781e3f389c}) (Version: 7.0.19.0 - Macromedia, Inc.)
Mail Merge Toolkit (HKLM\…\{B008D66F-B796-4C06-B707-932F0B225531}) (Version: 2.6.1 - MAPILab Ltd.)
Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Microsoft .NET Framework 1.1 (HKLM\…\Microsoft .NET Framework 1.1  (1033)) (Version:  - )
Microsoft .NET Framework 1.1 Security Update (KB2833941) (HKLM\…\M2833941) (Version:  - )
Microsoft .NET Framework 1.1 Security Update (KB979906) (HKLM\…\M979906) (Version:  - )
Microsoft .NET Framework 2.0 Service Pack 2 (HKLM\…\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}) (Version: 2.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.0 Service Pack 2 (HKLM\…\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}) (Version: 3.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (HKLM\…\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
Microsoft Access 2002 Runtime (HKLM\…\{901C0409-6000-11D3-8CFE-0050048383C9}) (Version: 10.0.4302.00 - Microsoft Corporation)
Microsoft Compression Client Pack 1.0 for Windows XP (HKLM\…\MSCompPackV1) (Version: 1 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office OneNote 2003 (HKLM\…\{91A10409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.7969.0 - Microsoft Corporation)
Microsoft Office Outlook 2003 with Business Contact Manager Update (HKLM\…\{BA68600E-96D9-4E92-80F2-26B9681B5A63}) (Version: 2.0.5324.0 - Microsoft Corporation)
Microsoft Office Small Business Edition 2003 (HKLM\…\{91CA0409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft Outlook Personal Folders Backup (HKLM\…\{C63E7C60-25EB-11D3-8EDA-00A0C911E8E5}) (Version: 1.10.0.0 - Microsoft Corporation)
Microsoft SQL Server Desktop Engine (MICROSOFTSMLBIZ) (HKLM\…\{E09B48B5-E141-427A-AB0C-D3605127224A}) (Version: 8.00.2039 - Microsoft Corporation)
Microsoft User-Mode Driver Framework Feature Pack 1.0 (HKLM\…\Wudf01000) (Version:  - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Mozilla Firefox 44.0 (x86 en-GB) (HKLM\…\Mozilla Firefox 44.0 (x86 en-GB)) (Version: 44.0 - Mozilla)
Mozilla Maintenance Service (HKLM\…\MozillaMaintenanceService) (Version: 44.0.0.5866 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 6.0 Parser (HKLM\…\{A43BF6A5-D5F0-4AAA-BF41-65995063EC44}) (Version: 6.10.1129.0 - Microsoft Corporation)
Nero - Burning Rom (HKLM\…\{A4D7B764-4140-11D4-88EB-0050DA3579C0}) (Version: 5.5.9 - ahead software gmbh)
Nikon Message Center 2 (HKLM\…\{B014EE44-9197-4513-9613-71E6EB1B514E}) (Version: 2.1.0 - Nikon)
Nikon Movie Editor (HKLM\…\{5CAD3393-EEC0-44CE-9F93-BCAA365B77FB}) (Version: 2.8.0 - Nikon)
Paint.NET v3.5.10 (HKLM\…\{529125EF-E3AC-4B74-97E6-F688A7C0F1BF}) (Version: 3.60.0 - dotPDN LLC)
Particle DDE Server (HKLM\…\ST6UNST #1) (Version:  - )
PeaZip 5.5.2 (HKLM\…\{5A2BC38A-406C-4A5B-BF45-6991F9A05325}_is1) (Version:  - Giorgio Tani)
Picture Control Utility (HKLM\…\{87441A59-5E64-4096-A170-14EFE67200C3}) (Version: 1.4.15 - Nikon)
POP Peeper (HKLM\…\POP Peeper) (Version:  - Mortal Universe)
REALTEK Gigabit and Fast Ethernet NIC Driver (HKLM\…\{94FB906A-CF42-4128-A509-D353026A607E}) (Version: 1.70 - REALTEK Semiconductor Corp.)
ScanSoft OmniPage SE 4 (HKLM\…\{DEE88727-779B-47A9-ACEF-F87CA5F92A65}) (Version: 15.2.0020 - Nuance Communications, Inc.)
Sonic RecordNow! (HKLM\…\{9541FED0-327F-4DF0-8B96-EF57EF622F19}) (Version: 7.31 - Sonic Solutions)
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 8.2.9.0 - Synaptics)
SYSPRO 6.0 (HKLM\…\SYSPRO 6.0) (Version:  - )
TOSHIBA Assist (HKLM\…\{12B3A009-A080-4619-9A2A-C6DB151D8D67}) (Version:  - )
TOSHIBA ConfigFree (HKLM\…\{BDD83DC9-BEE9-4654-A5DA-CC46C250088D}) (Version: 5.90.05 - )
Toshiba Hotkey Utility (HKLM\…\InstallShield_{7B1F9CB1-349A-43F5-A742-6215C2E2DB6F}) (Version: 1.07.09.02 - TOSHIBA)
TOSHIBA Manuals (HKLM\…\{3EB6332B-AF02-457C-A31C-835458C5B48B}) (Version: 7.05 - TOSHIBA)
TOSHIBA PC Diagnostic Tool (HKLM\…\PC Diagnostic Tool) (Version:  - )
TOSHIBA Power Saver (HKLM\…\Power Saver) (Version: 7.03.07.Q - )
Toshiba Touchpad Utility (HKLM\…\InstallShield_{F77890F3-774A-4CBE-A2E3-7BB0DC71D1FA}) (Version: 1.07.09.02 - TOSHIBA)
Toshiba Utility (HKLM\…\InstallShield_{099D12EC-0321-4CAC-A0CC-33D020156FCD}) (Version: 1.07.09.02 - TOSHIBA)
TOSHIBA Zooming Utility (HKLM\…\{64212898-097F-4F3F-AECA-6D34A7EF82DF}) (Version:  - )
Touch and Launch (HKLM\…\{5D96E2B1-D9AC-46E0-9073-425C5F63E338}) (Version:  - )
ViewNX 2 (HKLM\…\{E64C137C-D0B7-467A-B47F-460AAB30F0A3}) (Version: 2.8.2 - Nikon)
Visual C++ 2008 x86 Runtime - v9.0.30729.01 (HKLM\…\{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01) (Version: 9.0.30729.01 - Microsoft Corporation)
WebFldrs XP (Version: 9.50.7523 - Microsoft Corporation) Hidden
Windows Genuine Advantage Validation Tool (KB892130) (HKLM\…\KB892130) (Version:  - Microsoft Corporation)
Windows Genuine Advantage Validation Tool (KB892130) (HKLM\…\WGA) (Version: 1.7.0069.2 - Microsoft Corporation)
Windows Internet Explorer 8 (HKLM\…\ie8) (Version: 20090308.140743 - Microsoft Corporation)
Windows Media Format 11 runtime (HKLM\…\Windows Media Format Runtime) (Version:  - )
Windows Media Player 11 (HKLM\…\Windows Media Player) (Version:  - )
Windows XP Service Pack 3 (HKLM\…\Windows XP Service Pack) (Version: 20080414.031525 - Microsoft Corporation)
xHamster Video Downloader 3.22 (HKLM\…\xHamster Video Downloader_is1) (Version:  - DownloadToolz, Inc.)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-1528555759-1161534989-3529426194-1005_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Documents and Settings\GARETH\Application Data\Dropbox\bin\Dropbox.exe /autoplay => No File
CustomCLSID: HKU\S-1-5-21-1528555759-1161534989-3529426194-1005_Classes\CLSID\{00F02382-34F1-4E11-9CBD-9BC7D68E0383}\InprocServer32 -> C:\Program Files\MAPILab Ltd\Mail Merge Toolkit\OutlookSenderAddin.dll (MAPILab Ltd.)
CustomCLSID: HKU\S-1-5-21-1528555759-1161534989-3529426194-1005_Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}\InprocServer32 -> C:\Program Files\Common Files\Outlook Security Manager\secman.dll (MAPILab Ltd. & Add-in Express Ltd.)
CustomCLSID: HKU\S-1-5-21-1528555759-1161534989-3529426194-1005_Classes\CLSID\{CB32F11A-81B4-4455-91EF-6219447739C0}\InprocServer32 -> C:\Program Files\Common Files\MAPILab Ltd\MLTrial21.dll (MAPILab Ltd.)
CustomCLSID: HKU\S-1-5-21-1528555759-1161534989-3529426194-1005_Classes\CLSID\{E69341A3-E6D2-4175-B60C-C9D3D6FA40F6}\localserver32 -> C:\Documents and Settings\GARETH\Application Data\Dropbox\bin\Dropbox.exe /wiacallback => No File
CustomCLSID: HKU\S-1-5-21-1528555759-1161534989-3529426194-1005_Classes\CLSID\{FA075D03-1BAF-4AE1-9ADD-56C740247836}\InprocServer32 -> C:\Program Files\MAPILab Ltd\Mail Merge Toolkit\MMTProg.dll (MAPILab Ltd.)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job =>
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\avast! Emergency Update.job => C:\Program Files\Alwil Software\Avast5\AvastEmUpdate.exe
Task: C:\WINDOWS\Tasks\User_Feed_Synchronization-{E3CB84DD-4309-468E-B967-A2F4E33CA2E1}.job => C:\WINDOWS\system32\msfeedssync.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\FreshDevices\FreshDownload\Get Free Registration Code!!.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> "hxxp://www.freshdevices.com/register.html"

==================== Loaded Modules (Whitelisted) ==============

2015-03-19 10:47 - 2015-12-10 07:22 - 00103888 _____ () C:\Program Files\Alwil Software\Avast5\log.dll
2015-03-19 10:47 - 2015-12-10 07:22 - 00125512 _____ () C:\Program Files\Alwil Software\Avast5\JsonRpcServer.dll
2016-01-30 17:30 - 2016-01-30 17:30 - 02819072 _____ () C:\Program Files\Alwil Software\Avast5\defs\16013001\algo.dll
2015-11-30 19:55 - 2015-12-10 07:22 - 00469008 _____ () C:\Program Files\Alwil Software\Avast5\ffl2.dll
2016-01-31 13:55 - 2016-01-31 13:55 - 02819072 _____ () C:\Program Files\Alwil Software\Avast5\defs\16013100\algo.dll
2014-01-14 09:48 - 2012-09-18 15:26 - 00169472 _____ () C:\WINDOWS\system32\zlhp1020.dll
2014-01-14 09:48 - 2012-09-18 15:26 - 00059904 _____ () C:\WINDOWS\System32\spool\PRTPROCS\W32X86\pphp1020.dll
2008-03-19 16:52 - 2008-03-19 16:52 - 00166520 _____ () C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
2008-03-19 16:52 - 2008-03-19 16:52 - 00051816 _____ () C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe
2006-01-26 17:03 - 2006-01-26 17:03 - 00122880 _____ () C:\WINDOWS\system32\TPeculiarity.dll
2005-12-08 18:56 - 2005-12-08 18:56 - 00151552 _____ () C:\WINDOWS\system32\TSBWLS.dll
2003-09-16 17:50 - 2003-09-16 09:50 - 00229376 _____ () C:\WINDOWS\system32\CmWatch.exe
2013-10-21 13:56 - 2015-12-10 07:22 - 40539648 _____ () C:\Program Files\Alwil Software\Avast5\libcef.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Documents and Settings\GARETH\Desktop:;䯡
AlternateDataStreams: C:\Documents and Settings\GARETH\Desktop:ّ㑈
AlternateDataStreams: C:\Documents and Settings\GARETH\Desktop\FileFormatConverters.exe:SummaryInformation
AlternateDataStreams: C:\Documents and Settings\GARETH\Desktop\FileFormatConverters.exe:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"

==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2006-02-15 13:09 - 2004-08-04 13:00 - 00000734 ____A C:\WINDOWS\system32\Drivers\etc\hosts

127.0.0.1       localhost

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1528555759-1161534989-3529426194-1005\Control Panel\Desktop\\Wallpaper ->
DNS Servers: 192.168.1.1
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\startupreg: ATIPTA => "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
MSCONFIG\startupreg: BIBLauncher => C:\Program Files\Business-in-a-Box 2015\BIBLauncher.exe
MSCONFIG\startupreg: MSMSGS => "C:\Program Files\Messenger\msmsgs.exe" /background
MSCONFIG\startupreg: PadTouch => C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

StandardProfile\AuthorizedApplications: [C:\Program Files\FreshDevices\FreshDownload\fd.exe] => Enabled:FreshDownload
StandardProfile\AuthorizedApplications: [C:\Program Files\Internet Explorer\iexplore.exe] => Enabled:Internet Explorer
StandardProfile\AuthorizedApplications: [C:\Program Files\Atheros\ACU.exe] => Enabled:Atheros Client Utility
StandardProfile\AuthorizedApplications: [C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe] => Disabled:BlueSoleil
StandardProfile\AuthorizedApplications: [C:\WINDOWS\Network Diagnostic\xpnetdiag.exe] => Disabled:@xpsp3res.dll,-20000
StandardProfile\AuthorizedApplications: [C:\WINDOWS\system32\sessmgr.exe] => Disabled:@xpsp2res.dll,-22019
StandardProfile\AuthorizedApplications: [C:\Program Files\Bonjour\mDNSResponder.exe] => Enabled:Bonjour Service
StandardProfile\AuthorizedApplications: [C:\Program Files\Mozilla Firefox\firefox.exe] => Enabled:Firefox (C:\Program Files\Mozilla Firefox)
DomainProfile\GloballyOpenPorts: [139:TCP] => Enabled:@xpsp2res.dll,-22004
DomainProfile\GloballyOpenPorts: [445:TCP] => Enabled:@xpsp2res.dll,-22005
DomainProfile\GloballyOpenPorts: [137:UDP] => Enabled:@xpsp2res.dll,-22001
DomainProfile\GloballyOpenPorts: [138:UDP] => Enabled:@xpsp2res.dll,-22002
StandardProfile\GloballyOpenPorts: [1900:UDP] => :LocalSubNet:Disabled:@xpsp2res.dll,-22007
StandardProfile\GloballyOpenPorts: [2869:TCP] => :LocalSubNet:Disabled:@xpsp2res.dll,-22008
StandardProfile\GloballyOpenPorts: [139:TCP] => :LocalSubNet:Disabled:@xpsp2res.dll,-22004
StandardProfile\GloballyOpenPorts: [445:TCP] => :LocalSubNet:Disabled:@xpsp2res.dll,-22005
StandardProfile\GloballyOpenPorts: [137:UDP] => :LocalSubNet:Disabled:@xpsp2res.dll,-22001
StandardProfile\GloballyOpenPorts: [138:UDP] => :LocalSubNet:Disabled:@xpsp2res.dll,-22002

==================== Restore Points =========================

10-01-2016 19:42:56 Printer Driver Foxit Reader PDF Printer Driver Installed
11-01-2016 20:45:29 System Checkpoint
12-01-2016 20:57:42 System Checkpoint
13-01-2016 19:17:34 Software Distribution Service 3.0
13-01-2016 19:41:39 Software Distribution Service 3.0
14-01-2016 19:48:45 System Checkpoint
15-01-2016 21:32:35 System Checkpoint
16-01-2016 21:46:05 System Checkpoint
17-01-2016 21:48:43 System Checkpoint
18-01-2016 22:48:58 System Checkpoint
19-01-2016 23:49:54 System Checkpoint
21-01-2016 00:48:54 System Checkpoint
22-01-2016 01:48:59 System Checkpoint
23-01-2016 01:54:44 System Checkpoint
24-01-2016 02:54:43 System Checkpoint
25-01-2016 03:54:48 System Checkpoint
26-01-2016 04:54:52 System Checkpoint
27-01-2016 05:54:52 System Checkpoint
28-01-2016 14:34:53 System Checkpoint
29-01-2016 15:25:53 System Checkpoint
30-01-2016 15:46:26 System Checkpoint

==================== Faulty Device Manager Devices =============

Name: Realtek RTL8139/810x Family Fast Ethernet NIC
Description: Realtek RTL8139/810x Family Fast Ethernet NIC
Class Guid: {4D36E972-E325-11CE-BFC1-08002BE10318}
Manufacturer: Realtek Semiconductor Corp.
Service: RTL8023xp
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

Name: Bluetooth PAN Network Adapter
Description: Bluetooth PAN Network Adapter
Class Guid: {4D36E972-E325-11CE-BFC1-08002BE10318}
Manufacturer: IVT Corporation
Service: BT
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: =========================

Application errors:
==================
Error: (01/31/2016 01:55:32 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Hanging application AvastUI.exe, version 11.1.2245.1540, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

Error: (01/28/2016 11:08:34 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Hanging application WINWORD.EXE, version 11.0.8411.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

Error: (01/13/2016 07:18:27 PM) (Source: crypt32) (EventID: 5) (User: )
Description: Failed auto update retrieval of third-party root certificate from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/D69B561148F01C77C54578C10926DF5B856976AD.crt>with error: This operation returned because the timeout period expired.

Error: (01/13/2016 07:16:11 PM) (Source: crypt32) (EventID: 5) (User: )
Description: Failed auto update retrieval of third-party root certificate from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/D69B561148F01C77C54578C10926DF5B856976AD.crt>with error: This operation returned because the timeout period expired.

Error: (01/13/2016 07:14:05 PM) (Source: crypt32) (EventID: 5) (User: )
Description: Failed auto update retrieval of third-party root certificate from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/D69B561148F01C77C54578C10926DF5B856976AD.crt>with error: This operation returned because the timeout period expired.

Error: (01/13/2016 07:11:53 PM) (Source: crypt32) (EventID: 5) (User: )
Description: Failed auto update retrieval of third-party root certificate from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/D69B561148F01C77C54578C10926DF5B856976AD.crt>with error: This operation returned because the timeout period expired.

Error: (01/13/2016 07:09:48 PM) (Source: crypt32) (EventID: 5) (User: )
Description: Failed auto update retrieval of third-party root certificate from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/D69B561148F01C77C54578C10926DF5B856976AD.crt>with error: This operation returned because the timeout period expired.

Error: (01/13/2016 07:07:42 PM) (Source: crypt32) (EventID: 5) (User: )
Description: Failed auto update retrieval of third-party root certificate from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/D69B561148F01C77C54578C10926DF5B856976AD.crt>with error: This operation returned because the timeout period expired.

Error: (01/13/2016 07:05:35 PM) (Source: crypt32) (EventID: 5) (User: )
Description: Failed auto update retrieval of third-party root certificate from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/D69B561148F01C77C54578C10926DF5B856976AD.crt>with error: This operation returned because the timeout period expired.

Error: (01/13/2016 07:04:15 PM) (Source: crypt32) (EventID: 5) (User: )
Description: Failed auto update retrieval of third-party root certificate from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/D69B561148F01C77C54578C10926DF5B856976AD.crt>with error: This operation returned because the timeout period expired.


System errors:
=============
Error: (01/31/2016 12:37:31 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
Lbd
SBRE

Error: (01/28/2016 12:38:23 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
Lbd
SBRE

Error: (01/28/2016 11:06:21 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
Lbd
SBRE

Error: (01/28/2016 11:05:48 AM) (Source: 0) (EventID: 1) (User: )
Description: 0xC0000001HarddiskVolume1

Error: (01/27/2016 10:52:06 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
Lbd
SBRE

Error: (01/22/2016 07:51:07 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
Lbd
SBRE

Error: (01/22/2016 07:50:59 PM) (Source: 0) (EventID: 1) (User: )
Description: 0xC0000001HarddiskVolume1

Error: (01/13/2016 07:45:00 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
Lbd
SBRE

Error: (01/13/2016 07:25:56 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
Lbd
SBRE

Error: (01/13/2016 07:25:41 PM) (Source: 0) (EventID: 1) (User: )
Description: 0xC0000001HarddiskVolume1


==================== Memory info ===========================

Processor: Intel(R) Celeron(R) M processor 1.40GHz
Percentage of memory in use: 52%
Total physical RAM: 1406.23 MB
Available physical RAM: 674.46 MB
Total Virtual: 2760.23 MB
Available Virtual: 2285.93 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:37.26 GB) (Free:2.94 GB) NTFS ==>[drive with boot components (Windows XP)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows XP) (Size: 37.3 GB) (Disk ID: 250C2096)
Partition 1: (Active) - (Size=37.3 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================

 

Regards

BarryA

Thanks for your patience.


Run Farbar Recovery Scan Tool

Open notepad (Start >All Programs > Accessories > Notepad). Please copy the entire contents of the code box below and paste it into Notepad.

HKU\S-1-5-21-1528555759-1161534989-3529426194-1005\…\Policies\Explorer: [NoDriveAutoRun] 0xFFFFFFFF
SearchScopes: HKU\S-1-5-21-1528555759-1161534989-3529426194-1005 -> DefaultScope {406D5B00-B614-4825-A6B5-19BD5C004E33} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1528555759-1161534989-3529426194-1005 -> {406D5B00-B614-4825-A6B5-19BD5C004E33} URL = hxxp://www.google.com/search?q={searchTerms}
FF DefaultSearchUrl: hxxps://www.google.com/search/?trackid=sp-006
FF Keyword.URL: hxxps://www.google.com/search/?trackid=sp-006
S4 IntelIde; no ImagePath
S3 Lavasoft Kernexplorer; \??\C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys [X]
S0 Lbd; system32\DRIVERS\Lbd.sys [X]
S1 SBRE; \??\C:\WINDOWS\system32\drivers\SBREdrv.sys [X]
U1 WS2IFSL; no ImagePath
2016-01-31 12:37 - 2008-10-06 23:11 - 00083672 _____ C:\Documents and Settings\GARETH\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
C:\Documents and Settings\All Users\Application Data\PKP_DLeo.DAT
C:\Documents and Settings\All Users\Application Data\PKP_DLes.DAT
C:\Documents and Settings\All Users\Application Data\PKP_DLet.DAT
C:\Documents and Settings\All Users\Application Data\PKP_DLev.DAT
C:\Documents and Settings\GARETH\Local Settings\Temp\dllnt_dump.dll
Task: C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job =>
AlternateDataStreams: C:\Documents and Settings\GARETH\Desktop:;䯡
AlternateDataStreams: C:\Documents and Settings\GARETH\Desktop:ّ㑈
DomainProfile\GloballyOpenPorts: [139:TCP] => Enabled:@xpsp2res.dll,-22004
DomainProfile\GloballyOpenPorts: [445:TCP] => Enabled:@xpsp2res.dll,-22005
DomainProfile\GloballyOpenPorts: [137:UDP] => Enabled:@xpsp2res.dll,-22001
DomainProfile\GloballyOpenPorts: [138:UDP] => Enabled:@xpsp2res.dll,-22002
StandardProfile\GloballyOpenPorts: [1900:UDP] => :LocalSubNet:Disabled:@xpsp2res.dll,-22007
StandardProfile\GloballyOpenPorts: [2869:TCP] => :LocalSubNet:Disabled:@xpsp2res.dll,-22008
StandardProfile\GloballyOpenPorts: [139:TCP] => :LocalSubNet:Disabled:@xpsp2res.dll,-22004
StandardProfile\GloballyOpenPorts: [445:TCP] => :LocalSubNet:Disabled:@xpsp2res.dll,-22005
StandardProfile\GloballyOpenPorts: [137:UDP] => :LocalSubNet:Disabled:@xpsp2res.dll,-22001
StandardProfile\GloballyOpenPorts: [138:UDP] => :LocalSubNet:Disabled:@xpsp2res.dll,-22002
C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
CMD: ipconfig /flushdns
Hosts:
EmptyTemp:

NOTE: this script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system


  • save the files as fixlist.txt in the same folder as FRST – NOTE: It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work
  • run FRST then click Fix just once and wait
  • it will create a log (Fixlog.txt); please post it to your reply.

================================================

Download and run AdwCleaner

Download AdwCleaner from here and save it to your desktop.

  • run AdwCleaner
  • when it has finished, select Clean
  • if it asks to reboot, allow the reboot
  • on reboot a log will be produced; please attach the content of the log to your next reply.

===================================================

Download and run Junkware Removal Tool

[external image: thisisujrt.gif] Please download Junkware Removal Tool to your desktop.

  • shut down your protection software now to avoid potential conflicts.
  • run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator"
  • the tool will open and start scanning your system
  • please be patient as this can take a while to complete depending on your system's specifications
  • on completion, a log (JRT.txt) is saved to your desktop and will automatically open
  • post the contents of JRT.txt into your next message.

===================================================

Run Farbar Recovery Scan Tool

Please run FRST again and post the new log.

Logs to include with next post:

Fixlog.txt
AdwCleaner log
JRT.txt
Frst.txt


Thanks

Satchfan

 

Hello Satchfan,   reports herewith:

 

Fix result of Farbar Recovery Scan Tool (x86) Version:27-01-2016
Ran by [removed] (2016-02-01 19:36:17) Run:1
Running from C:\Documents and Settings\[removed]\Desktop
[removed] Boot Mode: Normal

==============================================

fixlist content:
*****************
HKU\S-1-5-21-1528555759-1161534989-3529426194-1005\…\Policies\Explorer: [NoDriveAutoRun] 0xFFFFFFFF
SearchScopes:
HKU\S-1-5-21-1528555759-1161534989-3529426194-1005 -> DefaultScope {406D5B00-B614-4825-A6B5-19BD5C004E33} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1528555759-1161534989-3529426194-1005 -> {406D5B00-B614-4825-A6B5-19BD5C004E33} URL = hxxp://www.google.com/search?q={searchTerms}
FF DefaultSearchUrl: hxxps://www.google.com/search/?trackid=sp-006
FF Keyword.URL: hxxps://www.google.com/search/?trackid=sp-006
S4 IntelIde; no ImagePath
S3 Lavasoft Kernexplorer; \??\C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys [X]
S0 Lbd; system32\DRIVERS\Lbd.sys [X]
S1 SBRE; \??\C:\WINDOWS\system32\drivers\SBREdrv.sys [X]
U1 WS2IFSL; no ImagePath
2016-01-31 12:37 - 2008-10-06 23:11 - 00083672 _____ C:\Documents and Settings\GARETH\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
C:\Documents and Settings\All Users\Application Data\PKP_DLeo.DAT
C:\Documents and Settings\All Users\Application Data\PKP_DLes.DAT
C:\Documents and Settings\All
Users\Application Data\PKP_DLet.DAT
C:\Documents and Settings\All Users\Application Data\PKP_DLev.DAT
C:\Documents and Settings\GARETH\Local Settings\Temp\dllnt_dump.dll
Task: C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job =>
AlternateDataStreams: C:\Documents and Settings\GARETH\Desktop:;䯡
AlternateDataStreams: C:\Documents and Settings\GARETH\Desktop:ّ㑈
DomainProfile\GloballyOpenPorts: [139:TCP] => Enabled:@xpsp2res.dll,-22004
DomainProfile\GloballyOpenPorts: [445:TCP] => Enabled:@xpsp2res.dll,-22005
DomainProfile\GloballyOpenPorts: [137:UDP] => Enabled:@xpsp2res.dll,-22001
DomainProfile\GloballyOpenPorts: [138:UDP] => Enabled:@xpsp2res.dll,-22002
StandardProfile\GloballyOpenPorts: [1900:UDP] => :LocalSubNet:Disabled:@xpsp2res.dll,-22007
StandardProfile\GloballyOpenPorts: [2869:TCP] => :LocalSubNet:Disabled:@xpsp2res.dll,-22008
StandardProfile\GloballyOpenPorts: [139:TCP] =>
:LocalSubNet:Disabled:@xpsp2res.dll,-22004
StandardProfile\GloballyOpenPorts: [445:TCP] => :LocalSubNet:Disabled:@xpsp2res.dll,-22005
StandardProfile\GloballyOpenPorts: [137:UDP] => :LocalSubNet:Disabled:@xpsp2res.dll,-22001
StandardProfile\GloballyOpenPorts: [138:UDP] => :LocalSubNet:Disabled:@xpsp2res.dll,-22002
C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
CMD: ipconfig /flushdns
Hosts:
EmptyTemp:

*****************

HKU\S-1-5-21-1528555759-1161534989-3529426194-1005\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDriveAutoRun => value removed successfully.
SearchScopes: => Error: No automatic fix found for this entry.
HKU\S-1-5-21-1528555759-1161534989-3529426194-1005 -> DefaultScope {406D5B00-B614-4825-A6B5-19BD5C004E33} URL = hxxp://www.google.com/search?q={searchTerms} => Error: No automatic fix found for this entry.
"HKU\S-1-5-21-1528555759-1161534989-3529426194-1005\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{406D5B00-B614-4825-A6B5-19BD5C004E33}" => key removed successfully.
HKCR\CLSID\{406D5B00-B614-4825-A6B5-19BD5C004E33} => key not found.
Firefox DefaultSearchUrl removed successfully.
Firefox "Keyword.URL" removed successfully.
IntelIde => service removed successfully.
Lavasoft Kernexplorer => service removed successfully.
Lbd => service removed successfully.
SBRE => service removed successfully.
WS2IFSL => service removed successfully.
C:\Documents and Settings\GARETH\Local Settings\Application Data\GDIPFONTCACHEV1.DAT => moved successfully
C:\Documents and Settings\All Users\Application Data\PKP_DLeo.DAT => moved successfully
C:\Documents and Settings\All Users\Application Data\PKP_DLes.DAT => moved successfully
"C:\Documents and Settings\All" => not found.
Users\Application Data\PKP_DLet.DAT => Error: No automatic fix found for this entry.
C:\Documents and Settings\All Users\Application Data\PKP_DLev.DAT => moved successfully
C:\Documents and Settings\GARETH\Local Settings\Temp\dllnt_dump.dll => moved successfully
Task: C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job => => not found.
C:\Documents and Settings\GARETH\Desktop => ":;䯡" ADS removed successfully..
C:\Documents and Settings\GARETH\Desktop => ":ّ㑈" ADS removed successfully..
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List\\139:TCP => value removed successfully.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List\\445:TCP => value removed successfully.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List\\137:UDP => value removed successfully.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List\\138:UDP => value removed successfully.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\1900:UDP => value removed successfully.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\2869:TCP => value removed successfully.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\139:TCP => value removed successfully.
:LocalSubNet:Disabled:@xpsp2res.dll,-22004 => Error: No automatic fix found for this entry.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\445:TCP => value removed successfully.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\137:UDP => value removed successfully.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\138:UDP => value removed successfully.
C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job => moved successfully

=========  ipconfig /flushdns =========



Windows IP Configuration



Successfully flushed the DNS Resolver Cache.


========= End of CMD: =========

C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
EmptyTemp: => 350.7 MB temporary data Removed.


The system needed a reboot.

==== End of Fixlog 19:39:04 ====

 

************************************************************************************************

 

# AdwCleaner v5.032 - Logfile created 01/02/2016 at 19:52:55
# Updated 31/01/2016 by Xplode
# Database : 2016-01-31.1 [Server]
# Operating system : Microsoft Windows XP Service Pack 3 (x86)
# Username : GARETH - ROBLAPTOP
# Running from : C:\Documents and Settings\GARETH\Desktop\adwcleaner_5.032.exe
# Option : Cleaning
# Support : http://toolslib.net/forum

***** [ Services ] *****


***** [ Folders ] *****

[-] Folder Deleted : C:\Documents and Settings\GARETH\Application Data\Mozilla\Firefox\Profiles\8pnurqgc.default\adawaretb
[-] Folder Deleted : C:\Documents and Settings\GARETH\Local Settings\Application Data\FileViewPro
[-] Folder Deleted : C:\Documents and Settings\ROB\Application Data\Mozilla\Firefox\Profiles\pjrd4kmj.default\adawaretb

***** [ Files ] *****


***** [ DLLs ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****


***** [ Registry ] *****

[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}

***** [ Web browsers ] *****


*************************

:: "Tracing" keys removed
:: Winsock settings cleared

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [1128 bytes] ##########
 

****************************************************************************************************************************

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.2 (01.06.2016)
Operating System: Microsoft Windows XP x86
Ran by [removed] (Administrator) on 01/02/2016 at 20:02:19.87
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 1

Successfully deleted: C:\Documents and Settings\GARETH\Application Data\Mozilla\Firefox\Profiles\8pnurqgc.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\defaults\custombuttons\google.com_blog_search.xml (File)



Registry: 1

Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\Search\\SearchAssistant (Registry Value)




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 01/02/2016 at 20:06:19.71
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 

*************************************************************************************************************************************

 

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:27-01-2016
Ran by [removed] (administrator) on ROBLAPTOP (01-02-2016 20:08:59)
Running from C:\Documents and Settings\[removed]\Desktop
[removed] Platform: Microsoft Windows XP Professional Service Pack 3 (X86) Language: English (United States)
Internet Explorer Version 8 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
(AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastUI.exe
(Microsoft Corporation) C:\WINDOWS\system32\wbem\unsecapp.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\…\Run: [TPSMain] => C:\WINDOWS\system32\TPSMain.exe [266240 2006-02-08] (TOSHIBA Corporation)
HKLM\…\Run: [SmoothView] => C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe [118784 2005-05-12] (TOSHIBA Corporation)
HKLM\…\Run: [CFSServ.exe] => CFSServ.exe -NoClient
HKLM\…\Run: [CanonSolutionMenu] => C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe [644696 2007-05-14] (CANON INC.)
HKLM\…\Run: [CanonMyPrinter] => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [1603152 2007-04-03] (CANON INC.)
HKLM\…\Run: [SSBkgdUpdate] => C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [210472 2006-10-25] (Nuance Communications, Inc.)
HKLM\…\Run: [OpwareSE4] => C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe [79400 2007-02-04] (Nuance Communications, Inc.)
HKLM\…\Run: [Toshiba Hotkey Utility] => C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe [1589248 2006-01-28] (TOSHIBA Inc.)
HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [761945 2005-12-16] (Synaptics, Inc.)
HKLM\…\Run: [BluetoothAuthenticationAgent] => rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
HKLM\…\Run: [NeroCheck] => C:\WINDOWS\system32\\NeroCheck.exe [155648 2001-07-09] (Ahead Software Gmbh)
HKLM\…\Run: [CmCardRun] => C:\WINDOWS\system32\CmWatch.exe [229376 2003-09-16] ()
HKLM\…\Run: [AvastUI.exe] => C:\Program Files\Alwil Software\Avast5\AvastUI.exe [7021880 2015-12-10] (AVAST Software)
HKLM\…\Run: [Nikon Message Center 2] => C:\Program Files\Nikon\Nikon Message Center 2\NkMC2.exe [571392 2011-10-30] (Nikon Corporation)
HKLM\…\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2014-05-08] (Adobe Systems Incorporated)
HKLM\…\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [597552 2015-08-04] (Oracle Corporation)
Winlogon\Notify\AtiExtEvent: C:\WINDOWS\system32\Ati2evxx.dll [2005-12-12] (ATI Technologies Inc.)
HKLM\…\Policies\Explorer: [NoCDBurning] 0
HKU\S-1-5-21-1528555759-1161534989-3529426194-1005\…\Run: [TOSCDSPD] => C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe [65536 2005-04-11] (TOSHIBA)
HKU\S-1-5-21-1528555759-1161534989-3529426194-1005\…\Run: [POP Peeper] => C:\Program Files\POP Peeper\POPPeeper.exe [1609728 2011-08-18] (Mortal Universe)
HKU\S-1-5-21-1528555759-1161534989-3529426194-1005\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\ssstars.scr [14336 2008-04-14] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Alwil Software\Avast5\ashShell.dll [2015-12-10] (AVAST Software)
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Service Manager.lnk [2006-07-27]
ShortcutTarget: Service Manager.lnk -> C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe (Microsoft Corporation)
Startup: C:\Documents and Settings\GARETH\Start Menu\Programs\Startup\Microsoft Office OneNote 2003 Quick Launch.lnk [2008-10-06]
ShortcutTarget: Microsoft Office OneNote 2003 Quick Launch.lnk -> C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Documents and Settings\ROB\Start Menu\Programs\Startup\Microsoft Office OneNote 2003 Quick Launch.lnk [2006-07-31]
ShortcutTarget: Microsoft Office OneNote 2003 Quick Launch.lnk -> C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Winsock: Catalog5 05 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{7AB3E566-EB3E-4BDD-AF07-48A28BF0BD8F}: [DhcpNameServer] 192.168.1.1 192.168.1.1

Internet Explorer:
==================
HKU\S-1-5-21-1528555759-1161534989-3529426194-1005\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
HKU\S-1-5-21-1528555759-1161534989-3529426194-1005\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.co.uk/
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1528555759-1161534989-3529426194-1005 -> DefaultScope {406D5B00-B614-4825-A6B5-19BD5C004E33} URL =
BHO: No Name -> {206E52E0-D52E-11D4-AD54-0000E86C26F6} -> C:\Program Files\FreshDevices\FreshDownload\fdcatch.dll [2007-04-25] (FreshDevices Corp.)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_60\bin\ssv.dll [2015-09-01] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll [2015-11-30] (AVAST Software)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_60\bin\jp2ssv.dll [2015-09-01] (Oracle Corporation)
Toolbar: HKLM - FreshDownload Bar - {ED0E8CA5-42FB-4B18-997B-769E0408E79D} - C:\Program Files\FreshDevices\FreshDownload\fdiebar.dll [2011-01-17] (FreshDevices Corp.)
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1395059582562
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL [2000-04-19] (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\WINDOWS\system32\Skype4COM.dll [2007-02-07] (Skype Technologies)

FireFox:
========
FF ProfilePath: C:\Documents and Settings\GARETH\Application Data\Mozilla\Firefox\Profiles\8pnurqgc.default
FF DefaultSearchEngine: Google (avast)
FF SearchEngineOrder.1: Google (avast)
FF SelectedSearchEngine: Google (avast)
FF Homepage: hxxps://www.google.co.uk/
FF Session Restore: -> is enabled.
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_20_0_0_286.dll [2016-01-20] ()
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\PROGRAM FILES\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [2015-02-11] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\PROGRAM FILES\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [2015-02-11] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\PROGRAM FILES\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [2015-02-11] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\PROGRAM FILES\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [2015-02-11] (Foxit Corporation)
FF Plugin: @java.com/DTPlugin,version=11.60.2 -> C:\Program Files\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll [2015-09-01] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.60.2 -> C:\Program Files\Java\jre1.8.0_60\bin\plugin2\npjp2.dll [2015-09-01] (Oracle Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npfd.dll [2010-09-29] (FreshDevices Corp.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFFICE.DLL [2007-03-22] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF SearchPlugin: C:\Documents and Settings\GARETH\Application Data\Mozilla\Firefox\Profiles\8pnurqgc.default\searchplugins\google-avast.xml [2015-01-20]
FF Extension: NoScript - C:\Documents and Settings\GARETH\Application Data\Mozilla\Firefox\Profiles\8pnurqgc.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2016-01-14]
FF Extension: Microsoft .NET Framework Assistant - C:\Documents and Settings\GARETH\Application Data\Mozilla\Firefox\Profiles\8pnurqgc.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi [2015-01-27] [not signed]
FF Extension: Google Toolbar for Firefox - C:\Documents and Settings\GARETH\Application Data\Mozilla\Firefox\Profiles\8pnurqgc.default\Extensions\{3112ca9c-de6d-4884-a869-9855de68056c} [2010-07-05] [not signed]
FF Extension: Adblock Plus - C:\Documents and Settings\GARETH\Application Data\Mozilla\Firefox\Profiles\8pnurqgc.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-01-19]
FF Extension: Google Toolbar for Firefox - C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c} [2016-01-27] [not signed]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2016-01-27] [not signed]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2016-01-27] [not signed]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\Alwil Software\Avast5\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\Alwil Software\Avast5\WebRep\FF [2015-12-10]
FF HKLM\…\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2013-01-28] [not signed]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\Alwil Software\Avast5\SafePrice\FF
FF Extension: Avast SafePrice - C:\Program Files\Alwil Software\Avast5\SafePrice\FF [2015-12-10]

Chrome:
=======
CHR Profile: C:\Documents and Settings\GARETH\Local Settings\Application Data\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Documents and Settings\GARETH\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-01-31]
CHR Extension: (Google Drive) - C:\Documents and Settings\GARETH\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-01-31]
CHR Extension: (YouTube) - C:\Documents and Settings\GARETH\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-01-31]
CHR Extension: (Google Search) - C:\Documents and Settings\GARETH\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-01-31]
CHR Extension: (Store) - C:\Documents and Settings\GARETH\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-02-03]
CHR Extension: (Google Wallet) - C:\Documents and Settings\GARETH\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-31]
CHR Extension: (Gmail) - C:\Documents and Settings\GARETH\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-01-31]
CHR HKLM\…\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\Alwil Software\Avast5\WebRep\Chrome\aswWebRepChrome.crx [2015-11-30]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [226440 2015-12-10] (AVAST Software)
S2 BlueSoleil Hid Service; C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe [166520 2008-03-19] ()
S2 CFSvcs; C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe [40960 2005-01-17] (TOSHIBA CORPORATION) [File not signed]
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
S2 MSSQL$MICROSOFTSMLBIZ; C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe [9150464 2005-05-03] (Microsoft Corporation) [File not signed]
S3 MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe [73728 2005-05-03] (Microsoft Corporation) [File not signed]
S3 SQLAgent$MICROSOFTSMLBIZ; C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlagent.EXE [323584 2005-05-03] (Microsoft Corporation) [File not signed]
S2 Start BT in service; C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe [51816 2008-03-19] ()

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AegisP; C:\WINDOWS\System32\DRIVERS\AegisP.sys [17801 2006-07-27] (Meetinghouse Data Communications) [File not signed]
R3 AR5211; C:\WINDOWS\System32\DRIVERS\ar5211.sys [468736 2005-09-13] (Atheros Communications, Inc.)
R2 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [24016 2015-12-10] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [81168 2016-01-07] (AVAST Software)
R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [55200 2015-12-10] (AVAST Software)
R0 aswRvrt; C:\WINDOWS\system32\Drivers\aswRvrt.sys [49776 2015-12-10] (AVAST Software)
R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [812208 2016-01-20] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [449384 2016-01-20] (AVAST Software)
R3 aswStmXP; C:\WINDOWS\system32\drivers\aswStmXP.sys [165104 2015-12-10] (AVAST Software)
S3 aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [58016 2015-12-10] (AVAST Software)
R0 aswVmm; C:\WINDOWS\system32\Drivers\aswVmm.sys [209432 2015-12-10] (AVAST Software)
R3 BlueletAudio; C:\WINDOWS\System32\DRIVERS\blueletaudio.sys [34312 2007-06-24] (IVT Corporation.)
R3 BlueletSCOAudio; C:\WINDOWS\System32\DRIVERS\BlueletSCOAudio.sys [27656 2007-06-24] (IVT Corporation.)
R3 BoiHwsetup; C:\WINDOWS\System32\drivers\BoiHwSetup.sys [5504 2005-06-11] (Quanta Computer Corp)
S3 BT; C:\WINDOWS\System32\DRIVERS\btnetdrv.sys [18320 2007-03-05] (IVT Corporation.)
S3 Btcsrusb; C:\WINDOWS\System32\Drivers\btcusb.sys [38920 2007-06-24] (IVT Corporation.)
R0 BTHidEnum; C:\WINDOWS\System32\Drivers\vbtenum.sys [20880 2007-03-05] (IVT Corporation.)
R0 BTHidMgr; C:\WINDOWS\System32\Drivers\BTHidMgr.sys [35600 2007-03-05] (IVT Corporation.)
R3 HSFHWATI; C:\WINDOWS\System32\DRIVERS\HSFHWATI.sys [225792 2005-11-29] (Conexant Systems, Inc.)
R3 HSF_DPV; C:\WINDOWS\System32\DRIVERS\HSF_DPV.sys [936960 2005-11-29] (Conexant Systems, Inc.)
R3 Iviaspi; C:\WINDOWS\System32\drivers\iviaspi.sys [21060 2003-09-10] (InterVideo, Inc.) [File not signed]
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [23256 2015-10-05] (Malwarebytes)
S3 MonitorFunction; C:\WINDOWS\System32\DRIVERS\TVMonitor.sys [13304 2015-11-16] (TeamViewer GmbH)
R2 Netdevio; C:\WINDOWS\System32\DRIVERS\netdevio.sys [12032 2003-01-29] (TOSHIBA Corporation.) [File not signed]
R3 Pfc; C:\WINDOWS\System32\drivers\pfc.sys [10368 2003-09-19] (Padus, Inc.) [File not signed]
R0 PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [20640 2005-04-25] (Sonic Solutions) [File not signed]
R3 qkbfiltr; C:\WINDOWS\System32\drivers\qkbfiltr.sys [31872 2006-01-12] (Quanta Computer, Inc.) [File not signed]
R3 qmofiltr; C:\WINDOWS\System32\drivers\qmofiltr.sys [7936 2005-05-05] (Quanta Computer, Inc.) [File not signed]
S3 RTL8023xp; C:\WINDOWS\System32\DRIVERS\Rtlnicxp.sys [74496 2005-03-04] (Realtek Semiconductor Corporation                           )
S3 rtl8139; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [20992 2004-08-03] (Realtek Semiconductor Corporation)
S3 UMSSSTOR; C:\WINDOWS\System32\DRIVERS\UMSS.SYS [48384 2003-09-16] (C-Media Corporation)
R3 VComm; C:\WINDOWS\System32\DRIVERS\VComm.sys [34448 2007-03-05] (IVT Corporation.)
R3 VcommMgr; C:\WINDOWS\System32\Drivers\VcommMgr.sys [44304 2007-03-05] (IVT Corporation.)
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-02-01 20:06 - 2016-02-01 20:06 - 00000883 _____ C:\Documents and Settings\GARETH\Desktop\JRT.txt
2016-02-01 19:58 - 2016-02-01 19:58 - 00001207 _____ C:\Documents and Settings\GARETH\Desktop\AdwCleaner[C1] Report.txt
2016-02-01 19:44 - 2016-02-01 19:52 - 00000000 ____D C:\AdwCleaner
2016-02-01 19:36 - 2016-02-01 19:39 - 00006716 _____ C:\Documents and Settings\GARETH\Desktop\Fixlog.txt
2016-02-01 19:28 - 2016-02-01 19:28 - 01721856 _____ (Farbar) C:\Documents and Settings\GARETH\Desktop\FRST.exe
2016-02-01 19:22 - 2016-02-01 19:22 - 01609032 _____ (Malwarebytes) C:\Documents and Settings\GARETH\Desktop\JRT.exe
2016-02-01 19:21 - 2016-02-01 19:20 - 01508352 _____ C:\Documents and Settings\GARETH\Desktop\adwcleaner_5.032.exe
2016-01-31 14:02 - 2016-01-31 14:03 - 00027343 _____ C:\Documents and Settings\GARETH\Desktop\Addition.txt
2016-01-31 14:01 - 2016-02-01 20:08 - 00018391 _____ C:\Documents and Settings\GARETH\Desktop\FRST.txt
2016-01-31 14:00 - 2016-02-01 20:08 - 00000000 ____D C:\FRST
2016-01-31 13:45 - 2016-01-31 13:45 - 00002846 _____ C:\Documents and Settings\GARETH\Desktop\Rogue Killer Report.txt
2016-01-31 13:01 - 2016-01-31 13:46 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\RogueKiller
2016-01-31 13:01 - 2016-01-31 13:01 - 00024688 _____ C:\WINDOWS\system32\Drivers\TrueSight.sys
2016-01-31 12:57 - 2016-01-31 12:57 - 00000000 ___HD C:\WINDOWS\PIF
2016-01-31 12:50 - 2016-01-31 12:53 - 20940872 _____ C:\Documents and Settings\GARETH\Desktop\RogueKiller.exe
2016-01-27 11:37 - 2016-01-28 11:17 - 00000000 ____D C:\Program Files\Mozilla Firefox
2016-01-27 11:34 - 2015-11-16 15:18 - 00013304 _____ (TeamViewer GmbH) C:\WINDOWS\system32\Drivers\TVMonitor.sys
2016-01-27 10:57 - 2016-01-27 10:57 - 00000000 ____D C:\Documents and Settings\GARETH\Application Data\TeamViewer
2016-01-23 10:24 - 2016-01-23 10:24 - 00000000 ____D C:\Documents and Settings\LocalService\Local Settings\Application Data\Temp
2016-01-20 07:39 - 2016-01-20 08:39 - 04499648 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerInstaller.exe
2016-01-15 15:01 - 2016-01-15 15:01 - 00731997 _____ C:\Documents and Settings\GARETH\Desktop\Jan IVC 2016 Bulletin. pdf
2016-01-10 19:42 - 2016-01-10 19:42 - 00000000 ____D C:\Documents and Settings\All Users\Foxit Software
2016-01-10 19:41 - 2016-01-10 19:41 - 00001786 _____ C:\Documents and Settings\All Users\Desktop\Foxit Reader.lnk
2016-01-10 19:41 - 2016-01-10 19:41 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Foxit Reader

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-02-01 20:09 - 2006-07-27 08:18 - 00000000 ____D C:\Documents and Settings\GARETH\Local Settings\Temp
2016-02-01 19:56 - 2012-08-05 19:08 - 00000366 ____H C:\WINDOWS\Tasks\avast! Emergency Update.job
2016-02-01 19:55 - 2006-02-15 14:29 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-02-01 19:54 - 2006-07-27 08:18 - 00000278 ___SH C:\Documents and Settings\GARETH\ntuser.ini
2016-02-01 19:54 - 2006-07-27 08:18 - 00000000 ____D C:\Documents and Settings\GARETH
2016-02-01 19:54 - 2006-02-15 14:29 - 00032570 _____ C:\WINDOWS\SchedLgU.Txt
2016-02-01 19:39 - 2015-08-16 21:30 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-02-01 19:36 - 2015-10-26 11:34 - 461063168 _____ C:\Documents and Settings\GARETH\Desktop\Outlook backup.pst
2016-02-01 19:24 - 2012-05-25 11:50 - 03795520 _____ C:\WINDOWS\system32\English
2016-02-01 15:06 - 2013-10-14 15:17 - 00000424 ____H C:\WINDOWS\Tasks\User_Feed_Synchronization-{E3CB84DD-4309-468E-B967-A2F4E33CA2E1}.job
2016-01-28 12:42 - 2015-10-29 17:20 - 00170200 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-01-28 12:37 - 2015-01-14 19:47 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2016-01-28 12:37 - 2006-02-15 14:16 - 00326704 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-01-28 12:29 - 2006-02-15 14:11 - 00000000 ___HD C:\WINDOWS\inf
2016-01-28 11:32 - 2006-02-15 13:10 - 00000211 __RSH C:\boot.ini
2016-01-28 11:32 - 2006-02-15 13:09 - 00000603 _____ C:\WINDOWS\win.ini
2016-01-28 11:32 - 2006-02-15 13:09 - 00000227 _____ C:\WINDOWS\system.ini
2016-01-27 11:35 - 2006-02-15 14:12 - 00000000 ____D C:\WINDOWS\system32\ReinstallBackups
2016-01-21 17:47 - 2012-10-04 17:02 - 00500736 ___SH C:\Documents and Settings\GARETH\Desktop\Thumbs.db
2016-01-20 19:23 - 2011-05-20 17:23 - 00812208 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsnx.sys
2016-01-20 19:23 - 2010-07-02 14:39 - 00449384 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsp.sys
2016-01-20 08:40 - 2012-04-16 10:31 - 00796864 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2016-01-20 08:40 - 2011-05-13 23:23 - 00142528 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2016-01-10 19:42 - 2006-02-15 14:16 - 00000000 ____D C:\Documents and Settings\All Users
2016-01-07 19:23 - 2013-03-05 11:00 - 00081168 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswmonflt.sys
2016-01-07 17:53 - 2012-10-05 10:46 - 00015949 _____ C:\Documents and Settings\GARETH\English
2016-01-07 15:13 - 2006-02-15 14:11 - 00000000 ____D C:\WINDOWS\security
2016-01-07 14:37 - 2006-02-15 13:09 - 00001158 _____ C:\WINDOWS\system32\wpa.dbl

==================== Files in the root of some directories =======

2013-12-03 13:44 - 2013-12-03 13:44 - 0000268 ___RH () C:\Documents and Settings\GARETH\Application Data\Grapher
2013-12-03 13:46 - 2013-12-03 13:46 - 0000268 ___RH () C:\Documents and Settings\GARETH\Application Data\Graphics
2013-12-03 13:44 - 2013-12-03 13:44 - 0000268 ___RH () C:\Documents and Settings\GARETH\Application Data\Guides
2013-12-03 13:31 - 2013-12-03 13:31 - 0000268 ___RH () C:\Documents and Settings\GARETH\Application Data\Horns
2014-01-16 09:40 - 2014-01-16 09:40 - 0000105 _____ () C:\Documents and Settings\GARETH\Application Data\WB.CFG
2011-04-13 11:38 - 2015-10-26 11:31 - 0023552 _____ () C:\Documents and Settings\GARETH\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2006-07-27 09:46 - 2006-07-27 09:46 - 0000129 _____ () C:\Documents and Settings\GARETH\Local Settings\Application Data\fusioncache.dat
2013-12-03 13:44 - 2013-12-03 13:44 - 0000268 ___RH () C:\Documents and Settings\All Users\Application Data\Guitars
2013-12-03 13:46 - 2013-12-03 13:46 - 0000268 ___RH () C:\Documents and Settings\All Users\Application Data\HAL
2013-12-03 13:44 - 2013-12-03 13:44 - 0000268 ___RH () C:\Documents and Settings\All Users\Application Data\Halftone
2013-12-03 13:31 - 2013-12-03 13:31 - 0000268 ___RH () C:\Documents and Settings\All Users\Application Data\Hybrid Synthesizers
2013-12-03 13:44 - 2014-07-27 14:49 - 0000020 ____H () C:\Documents and Settings\All Users\Application Data\PKP_DLet.DAT

Some files in TEMP:
====================
C:\Documents and Settings\GARETH\Local Settings\Temp\sqlite3.dll


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

==================== End of FRST.txt ============================

 

 

thanks & regards

BarryA

There's a suspicious file that has reappeared so I’d like a different look.


Run TDSSKiller

Please download TDSSKiller.zip

  • extract it to your desktop
  • double click TDSSKiller.exe
  • press Start Scan
    • only if Malicious objects are found then ensure Cure is selected. Do not change it to Delete or Quarantine as it may delete infected files that are required for Windows to operate properly.
    • then click Continue > Reboot now
  • copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\) called TDSSKiller_*** (*** denotes version & date)

======================================================

Download and run ComboFix

Download ComboFix from the following location:

Link

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • see this Link  for programs that need to be disabled and instruction on how to disable them.
  • remember to re-enable them when we're done.
  • double click on ComboFix.exe & follow the prompts.
  • as part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal.  It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue its malware removal procedures.

    [external image: RcAuto1.gif]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    [external image: whatnext.jpg]

    Click on Yes, to continue scanning for malware.

Note: Do not mouse-click combofix's window while it is running. That may cause it to stall.

When finished, it will produce a log.   Please include the ComboFix.txt in your next reply. It can be found at C:\ComboFix.txt

Please also remember to include the TDSSKiller log

Thanks

Satchfan

 

Hi Satchfan

 

TDSSKiller found nothing so there was no report produced.

 

Combofix ran, said there was no Recovery Console, I clicked to download it, an error message then said "failed to download files", but then some seconds afterwards continued to scan for malware. In the report it says that the Recovery Console is not present on this machine.

For some reason it could not download it, so can I obtain it from another source as it seems advisable to have it?

 

Combofix report below:

 

ComboFix 16-01-31.01 - GARETH 02/02/2016  13:48:13.1.1 - x86
Microsoft Windows XP Professional  5.1.2600.3.1252.44.1033.18.1406.950 [GMT 0:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: Norton Internet Worm Protection *Disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
.
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Administrator\WINDOWS
c:\documents and settings\Default User\WINDOWS
c:\documents and settings\GARETH\WINDOWS
c:\documents and settings\ROB\WINDOWS
c:\windows\$msi31uninstall_kb893803v2$
c:\windows\$msi31uninstall_kb893803v2$\msi.dll
c:\windows\$msi31uninstall_kb893803v2$\msiexec.exe
c:\windows\$msi31uninstall_kb893803v2$\msihnd.dll
c:\windows\$msi31uninstall_kb893803v2$\msimsg.dll
c:\windows\$msi31uninstall_kb893803v2$\msisip.dll
c:\windows\$msi31uninstall_kb893803v2$\reg00013
c:\windows\$msi31uninstall_kb893803v2$\reg00014
c:\windows\$msi31uninstall_kb893803v2$\reg00015
c:\windows\$msi31uninstall_kb893803v2$\reg00016
c:\windows\$msi31uninstall_kb893803v2$\reg00017
c:\windows\$msi31uninstall_kb893803v2$\reg00018
c:\windows\$msi31uninstall_kb893803v2$\reg00019
c:\windows\$msi31uninstall_kb893803v2$\reg00020
c:\windows\$msi31uninstall_kb893803v2$\reg00021
c:\windows\$msi31uninstall_kb893803v2$\reg00022
c:\windows\$msi31uninstall_kb893803v2$\reg00023
c:\windows\$msi31uninstall_kb893803v2$\reg00024
c:\windows\$msi31uninstall_kb893803v2$\reg00025
c:\windows\$msi31uninstall_kb893803v2$\reg00026
c:\windows\$msi31uninstall_kb893803v2$\reg00027
c:\windows\$msi31uninstall_kb893803v2$\reg00028
c:\windows\$msi31uninstall_kb893803v2$\reg00029
c:\windows\$msi31uninstall_kb893803v2$\reg00030
c:\windows\$msi31uninstall_kb893803v2$\reg00031
c:\windows\$msi31uninstall_kb893803v2$\reg00032
c:\windows\$msi31uninstall_kb893803v2$\reg00033
c:\windows\$msi31uninstall_kb893803v2$\reg00034
c:\windows\$msi31uninstall_kb893803v2$\reg00035
c:\windows\$msi31uninstall_kb893803v2$\reg00036
c:\windows\$msi31uninstall_kb893803v2$\reg00037
c:\windows\$msi31uninstall_kb893803v2$\reg00038
c:\windows\$msi31uninstall_kb893803v2$\reg00039
c:\windows\$msi31uninstall_kb893803v2$\reg00040
c:\windows\$msi31uninstall_kb893803v2$\reg00041
c:\windows\$msi31uninstall_kb893803v2$\reg00042
c:\windows\$msi31uninstall_kb893803v2$\reg00043
c:\windows\$msi31uninstall_kb893803v2$\reg00044
c:\windows\$msi31uninstall_kb893803v2$\reg00045
c:\windows\$msi31uninstall_kb893803v2$\reg00046
c:\windows\$msi31uninstall_kb893803v2$\reg00047
c:\windows\$msi31uninstall_kb893803v2$\reg00048
c:\windows\$msi31uninstall_kb893803v2$\reg00051
c:\windows\$msi31uninstall_kb893803v2$\reg00052
c:\windows\$msi31uninstall_kb893803v2$\reg00053
c:\windows\$msi31uninstall_kb893803v2$\reg00054
c:\windows\$msi31uninstall_kb893803v2$\reg00055
c:\windows\$msi31uninstall_kb893803v2$\reg00056
c:\windows\$msi31uninstall_kb893803v2$\reg00057
c:\windows\$msi31uninstall_kb893803v2$\reg00058
c:\windows\$msi31uninstall_kb893803v2$\reg00059
c:\windows\$msi31uninstall_kb893803v2$\reg00060
c:\windows\$msi31uninstall_kb893803v2$\reg00061
c:\windows\$msi31uninstall_kb893803v2$\reg00062
c:\windows\$msi31uninstall_kb893803v2$\reg00063
c:\windows\$msi31uninstall_kb893803v2$\reg00064
c:\windows\$msi31uninstall_kb893803v2$\reg00065
c:\windows\$msi31uninstall_kb893803v2$\reg00066
c:\windows\$msi31uninstall_kb893803v2$\reg00067
c:\windows\$msi31uninstall_kb893803v2$\reg00068
c:\windows\$msi31uninstall_kb893803v2$\reg00069
c:\windows\$msi31uninstall_kb893803v2$\reg00070
c:\windows\$msi31uninstall_kb893803v2$\reg00071
c:\windows\$msi31uninstall_kb893803v2$\reg00072
c:\windows\$msi31uninstall_kb893803v2$\reg00073
c:\windows\$msi31uninstall_kb893803v2$\reg00074
c:\windows\$msi31uninstall_kb893803v2$\reg00075
c:\windows\$msi31uninstall_kb893803v2$\reg00076
c:\windows\$msi31uninstall_kb893803v2$\reg00077
c:\windows\$msi31uninstall_kb893803v2$\reg00078
c:\windows\$msi31uninstall_kb893803v2$\reg00079
c:\windows\$msi31uninstall_kb893803v2$\reg00080
c:\windows\$msi31uninstall_kb893803v2$\reg00081
c:\windows\$msi31uninstall_kb893803v2$\reg00082
c:\windows\$msi31uninstall_kb893803v2$\reg00083
c:\windows\$msi31uninstall_kb893803v2$\reg00084
c:\windows\$msi31uninstall_kb893803v2$\reg00085
c:\windows\$msi31uninstall_kb893803v2$\reg00086
c:\windows\$msi31uninstall_kb893803v2$\reg00087
c:\windows\$msi31uninstall_kb893803v2$\reg00088
c:\windows\$msi31uninstall_kb893803v2$\reg00089
c:\windows\$msi31uninstall_kb893803v2$\reg00090
c:\windows\$msi31uninstall_kb893803v2$\reg00091
c:\windows\$msi31uninstall_kb893803v2$\reg00092
c:\windows\$msi31uninstall_kb893803v2$\reg00093
c:\windows\$msi31uninstall_kb893803v2$\reg00094
c:\windows\$msi31uninstall_kb893803v2$\reg00095
c:\windows\$msi31uninstall_kb893803v2$\reg00096
c:\windows\$msi31uninstall_kb893803v2$\reg00097
c:\windows\$msi31uninstall_kb893803v2$\reg00098
c:\windows\$msi31uninstall_kb893803v2$\reg00099
c:\windows\$msi31uninstall_kb893803v2$\reg00100
c:\windows\$msi31uninstall_kb893803v2$\reg00101
c:\windows\$msi31uninstall_kb893803v2$\reg00102
c:\windows\$msi31uninstall_kb893803v2$\reg00103
c:\windows\$msi31uninstall_kb893803v2$\reg00104
c:\windows\$msi31uninstall_kb893803v2$\reg00105
c:\windows\$msi31uninstall_kb893803v2$\reg00106
c:\windows\$msi31uninstall_kb893803v2$\reg00107
c:\windows\$msi31uninstall_kb893803v2$\reg00108
c:\windows\$msi31uninstall_kb893803v2$\reg00109
c:\windows\$msi31uninstall_kb893803v2$\reg00110
c:\windows\$msi31uninstall_kb893803v2$\reg00111
c:\windows\$msi31uninstall_kb893803v2$\reg00112
c:\windows\$msi31uninstall_kb893803v2$\reg00113
c:\windows\$msi31uninstall_kb893803v2$\reg00114
c:\windows\$msi31uninstall_kb893803v2$\reg00115
c:\windows\$msi31uninstall_kb893803v2$\reg00116
c:\windows\$msi31uninstall_kb893803v2$\spuninst\spuninst.exe
c:\windows\$msi31uninstall_kb893803v2$\spuninst\spuninst.inf
c:\windows\$msi31uninstall_kb893803v2$\spuninst\spuninst.txt
c:\windows\$msi31uninstall_kb893803v2$\spuninst\updspapi.dll
c:\windows\EventSystem.log
c:\windows\system32\config\systemprofile\WINDOWS
.
.
(((((((((((((((((((((((((   Files Created from 2016-01-02 to 2016-02-02  )))))))))))))))))))))))))))))))
.
.
2016-02-01 19:44 . 2016-02-01 19:52 ——– d—–w- C:\AdwCleaner
2016-01-31 14:00 . 2016-02-01 20:09 ——– d—–w- C:\FRST
2016-01-31 13:01 . 2016-01-31 13:01 24688 —-a-w- c:\windows\system32\drivers\TrueSight.sys
2016-01-31 13:01 . 2016-01-31 13:46 ——– d—–w- c:\documents and settings\All Users\Application Data\RogueKiller
2016-01-31 12:57 . 2016-01-31 12:57 ——– d–h–w- c:\windows\PIF
2016-01-27 11:34 . 2015-11-16 15:18 13304 —-a-w- c:\windows\system32\drivers\TVMonitor.sys
2016-01-27 10:57 . 2016-01-27 10:57 ——– d—–w- c:\documents and settings\GARETH\Application Data\TeamViewer
2016-01-23 10:24 . 2016-01-23 10:24 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Temp
2016-01-20 07:39 . 2016-01-20 08:39 4499648 —-a-w- c:\windows\system32\FlashPlayerInstaller.exe
2016-01-10 19:42 . 2016-01-10 19:42 ——– d—–w- c:\documents and settings\All Users\Foxit Software
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2016-01-28 12:42 . 2015-10-29 17:20 170200 —-a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2016-01-20 19:23 . 2010-07-02 14:39 449384 —-a-w- c:\windows\system32\drivers\aswsp.sys
2016-01-20 19:23 . 2011-05-20 17:23 812208 —-a-w- c:\windows\system32\drivers\aswsnx.sys
2016-01-20 08:40 . 2012-04-16 10:31 796864 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2016-01-20 08:40 . 2011-05-13 23:23 142528 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2016-01-07 19:23 . 2013-03-05 11:00 81168 —-a-w- c:\windows\system32\drivers\aswmonflt.sys
2015-12-10 07:22 . 2015-09-01 14:09 165104 —-a-w- c:\windows\system32\drivers\aswStmXP.sys
2015-12-10 07:22 . 2014-04-22 14:26 24016 —-a-w- c:\windows\system32\drivers\aswHwid.sys
2015-12-10 07:22 . 2013-03-05 11:00 209432 —-a-w- c:\windows\system32\drivers\aswVmm.sys
2015-12-10 07:22 . 2013-03-05 11:00 49776 —-a-w- c:\windows\system32\drivers\aswRvrt.sys
2015-12-10 07:22 . 2010-07-02 14:39 58016 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2015-12-10 07:22 . 2010-07-02 14:39 55200 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2015-12-10 07:22 . 2015-12-10 07:22 322760 —-a-w- c:\windows\system32\aswBoot.exe
2015-12-10 07:22 . 2015-12-10 07:22 43112 —-a-w- c:\windows\avastSS.scr
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2015-12-10 07:22 750216 —-a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2005-04-11 65536]
"POP Peeper"="c:\program files\POP Peeper\POPPeeper.exe" [2011-08-18 1609728]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CFSServ.exe"="CFSServ.exe -NoClient" [X]
"TPSMain"="TPSMain.exe" [2006-02-08 266240]
"SmoothView"="c:\program files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2005-05-12 118784]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-14 644696]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-03 1603152]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400]
"Toshiba Hotkey Utility"="c:\program files\Toshiba\Windows Utilities\Hotkey.exe" [2006-01-28 1589248]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-12-16 761945]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"NeroCheck"="c:\windows\system32\\NeroCheck.exe" [2001-07-09 155648]
"CmCardRun"="c:\windows\system32\CmWatch.exe" [2003-09-16 229376]
"AvastUI.exe"="c:\program files\Alwil Software\Avast5\AvastUI.exe" [2015-12-10 7021880]
"Nikon Message Center 2"="c:\program files\Nikon\Nikon Message Center 2\NkMC2.exe" [2011-10-30 571392]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2014-05-08 959904]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2015-08-04 597552]
.
c:\documents and settings\ROB\Start Menu\Programs\Startup\
Microsoft Office OneNote 2003 Quick Launch.lnk - c:\program files\Microsoft Office\OFFICE11\ONENOTEM.EXE /tsr [2005-3-17 59080]
.
c:\documents and settings\GARETH\Start Menu\Programs\Startup\
Microsoft Office OneNote 2003 Quick Launch.lnk - c:\program files\Microsoft Office\OFFICE11\ONENOTEM.EXE /tsr [2005-3-17 59080]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Service Manager.lnk - c:\program files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe /n [2005-5-3 81920]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SoftwareSASGeneration"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
2005-12-11 21:05 344064 —-a-w- c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 —-a-w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PadTouch]
2005-12-21 13:52 1077330 —-a-w- c:\program files\Toshiba\Touch and Launch\PadExe.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\FreshDevices\\FreshDownload\\fd.exe"=
"c:\\Program Files\\Atheros\\ACU.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
.
R0 aswRvrt;avast! Revert;c:\windows\system32\drivers\aswRvrt.sys [05/03/2013 11:00 49776]
R0 aswVmm;avast! VM Monitor;c:\windows\system32\drivers\aswVmm.sys [05/03/2013 11:00 209432]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswsnx.sys [20/05/2011 17:23 812208]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswsp.sys [02/07/2010 14:39 449384]
R2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys [22/04/2014 14:26 24016]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswmonflt.sys [05/03/2013 11:00 81168]
R2 Start BT in service;Start BT in service;c:\program files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe [19/03/2008 16:52 51816]
R3 aswStmXP;Avast StreamFilter Driver;c:\windows\system32\drivers\aswStmXP.sys [01/09/2015 14:09 165104]
R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [15/02/2006 20:53 225792]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [29/10/2015 17:19 23256]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes Anti-Malware\mbamservice.exe [29/10/2015 17:19 1135416]
S3 MonitorFunction;Driver for Monitor;c:\windows\system32\drivers\TVMonitor.sys [27/01/2016 11:34 13304]
S3 UMSSSTOR;C-Media Storage;c:\windows\system32\drivers\Umss.SYS [13/07/2004 12:40 48384]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - 34443983
*Deregistered* - 34443983
.
Contents of the 'Scheduled Tasks' folder
.
2016-02-02 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-16 08:40]
.
2016-02-02 c:\windows\Tasks\avast! Emergency Update.job
- c:\program files\Alwil Software\Avast5\AvastEmUpdate.exe [2015-12-10 07:22]
.
2016-02-02 c:\windows\Tasks\User_Feed_Synchronization-{E3CB84DD-4309-468E-B967-A2F4E33CA2E1}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 03:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.co.uk/
uInternet Settings,ProxyOverride = *.local
IE: {{68FA54C1-9EA9-4887-B031-8F56C744AA32} - c:\program files\FreshDevices\FreshDownload\fd.exe
TCP: DhcpNameServer = 192.168.1.1 192.168.1.1
FF - ProfilePath - c:\documents and settings\GARETH\Application Data\Mozilla\Firefox\Profiles\8pnurqgc.default\
FF - prefs.js: browser.search.selectedEngine - Google (avast)
FF - prefs.js: browser.startup.homepage - hxxps://www.google.co.uk/
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
MSConfigStartUp-BIBLauncher - c:\program files\Business-in-a-Box 2015\BIBLauncher.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2016-02-02 13:59
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes … 
.
scanning hidden autostart entries …
.
scanning hidden files … 
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
   d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,bd,ec,b6,7d,36,4f,56,40,b8,c4,7e,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
   d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,bd,ec,b6,7d,36,4f,56,40,b8,c4,7e,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_20_0_0_286_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_20_0_0_286_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Micro Focus]
@Denied: (C D) (Everyone)
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(584)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2016-02-02  14:03:22
ComboFix-quarantined-files.txt  2016-02-02 14:03
.
Pre-Run: 3,140,747,264 bytes free
Post-Run: 3,138,719,744 bytes free
.
- - End Of File - - CB30ED9E1C333B5E669944E544CA2FDC
8F558EB6672622401DA993E1E865C861
 

*****************************************************************************************************

 

regards

Barry A  

Looking better.

Run Malwarebytes’ Anti-Malware

I noticed that you had MBAM on your system: if you no longer have it, you can download it from here:

  • start Malwarebytes-Anti-Malware and update it, (“Update” tab}
  • once it is updated, click on “Scan” tab, select Threat Scan, then click Scan.
  • when the scan is complete, if no malicious items are found you can close the program
  • if malicious items are found be sure that everything is checked and click Quarantine
  • when removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • the log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • copy and paste the contents of that report in your next reply and exit MBAM.

NOTE: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

Can you tell me if there are any outstanding problems.

Satchfan

 

Hi BarryA

It has been several days since I sent my last set of instructions to help with your computer problem.

Please let me know if you still need help. If I don't get a reply within 24 hours I'll assume you no longer need help and close this topic.

Satchfan

Hello Satchfan

 

I am sorry but I did not get a notification that you had posted a reply so was waiting for you to review my previous logs, thinking that you may have been away. I got your reminder today so have now run the MalwareBytes and it found nothing so no log.

 

I have not noticed any problems with the running of my computer, but then did not after the phishing attack either.

As we have not at this point detected anything planted in my system files, I am hoping that the scammers did not do so.

 

regards

BarryA

I am sorry but I did not get a notification that you had posted a reply

Don't know why that happens but it has happened to me on this and other forums but at least you got the reminder so no problem.

 

There is  no indication of anything untoward in your logs but we did get rid of some suspect entries so let’s run an online scan to be sure nothing is left and if that’s clear I’ll send instructions to tidy up.


Run ESET Online Scan

Note: This may take a long time so please be patient.

IMPORTANT Please make sure you uncheck the box next to Remove found threats. Eset will detect anything that looks even slightly suspicious, which could include legitimate program files. If you do not uncheck the box, Eset will automatically remove all suspicious files which could leave some of your software inoperable.

Note: You can use Internet Explorer, FireFox or  Chrome for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Hold down Control and click on the following link to open ESET OnlineScan in a new window.

ESET OnlineScan

  • click the Run Eset online Scanner button
  • for alternate browsers only: (Microsoft Internet Explorer users can skip these steps)


    o    click on esetinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop.
    o    double click on the Eset installer icon on your desktop.
     

  • check Yes, I accept the Terms of Use
  • click the Start button
  • accept any security warnings from your browser
  • check Enable detection of potentially unwanted applications
  • click Advanced settings and select the following:


    o    scan archives
    o    scan for potentially unsafe applications
    o    enable Anti-Stealth technology


    Note: Do not check Remove found threats
     

  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • when the scan completes, push List of found threats
  • push Export to Text file and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.


    Note - if ESET doesn't find any threats, no report will be created.
     

  • push the back button.
  • push Finish

When the scan is complete:

If no threats were found:


o    put a checkmark in "Uninstall application on close"
o    close program
o    report to me that nothing was found.
 

If threats were found:


o    click on "list of threats found"
o    click on "export to text file" and save it as ESET results and save to the desktop
o    click on back
o    put a checkmark in "Uninstall application on close"
o    click on finish
o    close program
o    copy and paste the report here.
 

Thanks

Satchfan

Hi Satchfan

 

ESET run and report below showing 4 items needing removal. Somehow I missed getting back to check uninstall on exit, so the scn program is still installed.

 

C:\Documents and Settings\GARETH\Application Data\Sun\Java\jre1.7.0_45\java_sp.dll    a variant of Win32/Bundled.Toolbar.Ask.F potentially unsafe application
C:\Documents and Settings\GARETH\My Documents\Downloads\FoxitReader545.0124_enu_Setup.exe    a variant of Win32/Bundled.Toolbar.Ask.C potentially unsafe application
C:\Documents and Settings\GARETH\My Documents\Downloads\FoxitReader603.0524_enu_Setup.exe    a variant of Win32/Bundled.Toolbar.Ask.C potentially unsafe application
C:\Documents and Settings\GARETH\My Documents\Downloads\SetupImgBurn_2.5.7.0.exe    a variant of Win32/Bundled.Toolbar.Ask.G potentially unsafe application

 

regards

BarryA
 

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI