Jump to content

Cannot run Malwarebytes, Excel will not work, Explorer errors

Recommended Posts

I removed the extra drive but it didn't make a difference

there appears to be 3 partitions on the C drive, I didn't set it up this way is this normal for a windows 7 64 bit standard install?

but I got the report

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 03-06-2013 02

Ran by SYSTEM on 08-06-2013 18:56:15

Running from F:\

Windows 7 Professional (X64) OS Language: English(US)

Internet Explorer Version 9

Boot Mode: Recovery

The current controlset is ControlSet001

ATTENTION!:=====> FRST is updated to run from normal or Safe mode to produce a full FRST.txt log and an extra Addition.txt log.

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [Launch LCore] "C:\Program Files\Logitech Gaming Software\LCore.exe" /minimized [104008 2010-11-16] (Logitech Inc.)

HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1281512 2013-01-27] (Microsoft Corporation)

HKLM-x32\...\Run: [FUFAXSTM] "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe" [847872 2009-12-02] (SEIKO EPSON CORPORATION)

HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [946352 2012-12-18] (Adobe Systems Incorporated)

HKLM-x32\...\Run: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [253816 2013-03-12] (Oracle Corporation)

HKLM-x32\...\Run: [seagate Dashboard] C:\Program Files (x86)\Seagate\Seagate Dashboard\MemeoLauncher.exe --silent --no_ui [79112 2011-06-01] ()

HKLM-x32\...\Run: [Memeo Instant Backup] C:\Program Files (x86)\Memeo\AutoBackup\MemeoLauncher2.exe --silent --no_ui [136416 2011-01-24] (Memeo Inc.)

HKLM-x32\...\Run: [DNS7reminder] "C:\Program Files (x86)\Nuance\NaturallySpeaking11\Ereg\Ereg.exe" -r "C:\ProgramData\Nuance\NaturallySpeaking11\Ereg.ini [259624 2007-04-16] (Nuance Communications, Inc.)

Startup: C:\ProgramData\Start Menu\Programs\Startup\Lotus Organizer EasyClip.lnk

ShortcutTarget: Lotus Organizer EasyClip.lnk -> E:\lotus\organize\easyclip.exe (No File)

Startup: C:\ProgramData\Start Menu\Programs\Startup\Lotus QuickStart.lnk

ShortcutTarget: Lotus QuickStart.lnk -> E:\lotus\wordpro\ltsstart.exe (No File)

Startup: C:\ProgramData\Start Menu\Programs\Startup\Lotus SmartCenter.lnk

ShortcutTarget: Lotus SmartCenter.lnk -> E:\lotus\smartctr\smartctr.exe (No File)

Startup: C:\ProgramData\Start Menu\Programs\Startup\Lotus SuiteStart.lnk

ShortcutTarget: Lotus SuiteStart.lnk -> E:\lotus\smartctr\suitest.exe (No File)

Startup: C:\Users\Mitch Tiffin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk

ShortcutTarget: ERUNT AutoBackup.lnk -> C:\Program Files (x86)\ERUNT\AUTOBACK.EXE ()

Startup: C:\Users\Mitch Tiffin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk

ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()

==================== Services (Whitelisted) =================

S4 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [140672 2011-08-11] (SUPERAntiSpyware.com)

S4 ABBYY.Licensing.FineReader.Sprint.9.0; C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [759048 2009-05-14] (ABBYY)

S4 DraftSight API Service; C:\Program Files (x86)\Dassault Systemes\DraftSight\bin\dsHttpApiService.exe [78336 2012-07-07] (Dassault Systèmes)

S4 FlipShare Service; C:\Program Files (x86)\Flip Video\FlipShare\FlipShareService.exe [460144 2011-05-06] ()

S4 FlipShareServer; C:\Program Files (x86)\Flip Video\FlipShareServer\FlipShareServer.exe [1085440 2011-05-06] ()

S2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22056 2013-01-27] (Microsoft Corporation)

S3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [379360 2013-01-27] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

S0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [230320 2013-01-20] (Microsoft Corporation)

S3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2005-03-28] ()

S2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [130008 2013-01-20] (Microsoft Corporation)

S3 PaeFireStudio; C:\Windows\System32\Drivers\PaeFireStudio.sys [214776 2010-10-14] (PreSonus Audio Electronics)

S3 PaeFireStudioAudio; C:\Windows\System32\drivers\PaeFireStudioAudio.sys [39032 2010-10-14] (PreSonus Audio Electronics)

S3 PaeFireStudioMidi; C:\Windows\System32\drivers\PaeFireStudioMidi.sys [42616 2010-10-14] (PreSonus Audio Electronics)

S2 PMEM; C:\Windows\SysWOW64\drivers\pmemnt.sys [7168 1999-03-08] (Microsoft Corporation)

S1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)

S1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)

S0 speedfan; C:\Windows\SysWow64\speedfan.sys [14104 2007-02-07] (Windows ® Server 2003 DDK provider)

S3 catchme; \??\C:\ComboFix\catchme.sys [x]

==================== NetSvcs (Whitelisted) ===================

==================== One Month Created Files and Folders ========

2013-06-08 18:55 - 2013-06-08 18:55 - 00000000 ____D C:\FRST

2013-06-08 11:47 - 2013-06-08 11:47 - 00001593 ____A C:\Users\Mitch Tiffin\Desktop\Live Like You Were Dying - Shortcut.lnk

2013-06-08 11:14 - 2013-06-08 11:14 - 00001332 ____A C:\AdwCleaner[R8].txt

2013-06-04 03:27 - 2013-06-04 03:28 - 00001271 ____A C:\AdwCleaner[R7].txt

2013-06-02 13:19 - 2013-06-02 13:19 - 00002834 ____A C:\Users\Mitch Tiffin\Desktop\RKreport[1]_S_06022013_02d1619.txt

2013-06-02 12:17 - 2013-06-02 12:17 - 00016020 ____A C:\ComboFix.txt

2013-06-02 08:34 - 2013-06-02 08:34 - 00001211 ____A C:\AdwCleaner[R6].txt

2013-06-01 10:37 - 2013-06-01 10:38 - 00001348 ____A C:\Users\Mitch Tiffin\Desktop\SystemLook.txt

2013-06-01 10:36 - 2013-06-01 10:36 - 00139264 ____A C:\Users\Mitch Tiffin\Desktop\SystemLook.exe

2013-05-30 03:15 - 2013-06-02 12:17 - 00000000 ___AD C:\Qoobox

2013-05-30 03:15 - 2011-06-25 22:45 - 00256000 ____A C:\Windows\PEV.exe

2013-05-30 03:15 - 2010-11-07 09:20 - 00208896 ____A C:\Windows\MBR.exe

2013-05-30 03:15 - 2009-04-19 20:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe

2013-05-30 03:15 - 2000-08-30 16:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe

2013-05-30 03:15 - 2000-08-30 16:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe

2013-05-30 03:15 - 2000-08-30 16:00 - 00098816 ____A C:\Windows\sed.exe

2013-05-30 03:15 - 2000-08-30 16:00 - 00080412 ____A C:\Windows\grep.exe

2013-05-30 03:15 - 2000-08-30 16:00 - 00068096 ____A C:\Windows\zip.exe

2013-05-30 02:59 - 2013-06-02 12:09 - 05076415 ____R (Swearware) C:\Users\Mitch Tiffin\Desktop\ComboFix.exe

2013-05-29 17:39 - 2013-06-02 13:19 - 00000000 ____D C:\Users\Mitch Tiffin\Desktop\RK_Quarantine

2013-05-29 17:37 - 2013-05-29 17:37 - 00816128 ____A C:\Users\Mitch Tiffin\Desktop\RogueKiller.exe

2013-05-29 17:29 - 2013-05-29 17:29 - 00000000 ____D C:\TDSSKiller_Quarantine

2013-05-29 17:25 - 2013-05-29 17:26 - 02237968 ____A (Kaspersky Lab ZAO) C:\Users\Mitch Tiffin\Desktop\tdsskiller.exe

2013-05-29 17:22 - 2013-05-29 17:22 - 00001150 ____A C:\AdwCleaner[R5].txt

2013-05-29 16:33 - 2013-05-29 16:33 - 00002770 ____A C:\AdwCleaner[s1].txt

2013-05-29 16:33 - 2013-05-29 16:33 - 00002563 ____A C:\AdwCleaner[R3].txt

2013-05-29 16:14 - 2013-05-29 16:14 - 00000000 ____D C:\ERDNT

2013-05-29 03:46 - 2013-05-29 03:46 - 00002136 ____A C:\AdwCleaner[R2].txt

2013-05-29 03:37 - 2013-05-29 03:37 - 00632031 ____A C:\Users\Mitch Tiffin\Desktop\adwcleaner.exe

2013-05-29 03:04 - 2013-06-02 13:42 - 00000000 ____D C:\Windows\ERDNT

2013-05-28 17:57 - 2013-05-28 17:58 - 00000928 ____A C:\Users\UpdatusUser\Desktop\NTREGOPT.lnk

2013-05-28 17:57 - 2013-05-28 17:58 - 00000928 ____A C:\Users\Music\Desktop\NTREGOPT.lnk

2013-05-28 17:57 - 2013-05-28 17:58 - 00000928 ____A C:\Users\Mitch Tiffin\Desktop\NTREGOPT.lnk

2013-05-28 17:57 - 2013-05-28 17:58 - 00000909 ____A C:\Users\UpdatusUser\Desktop\ERUNT.lnk

2013-05-28 17:57 - 2013-05-28 17:58 - 00000909 ____A C:\Users\Music\Desktop\ERUNT.lnk

2013-05-28 17:57 - 2013-05-28 17:58 - 00000909 ____A C:\Users\Mitch Tiffin\Desktop\ERUNT.lnk

2013-05-28 17:57 - 2013-05-28 17:58 - 00000000 ____D C:\Program Files (x86)\ERUNT

2013-05-28 17:56 - 2013-05-28 17:56 - 00791393 ____A (Lars Hederer ) C:\Users\Mitch Tiffin\Downloads\erunt-setup(1).exe

2013-05-28 17:55 - 2013-05-28 17:55 - 00791393 ____A (Lars Hederer ) C:\Users\Mitch Tiffin\Downloads\erunt-setup (3).exe

2013-05-28 17:54 - 2013-05-28 17:54 - 00791393 ____A (Lars Hederer ) C:\Users\Mitch Tiffin\Downloads\erunt-setup (2).exe

2013-05-28 17:53 - 2013-05-28 17:53 - 00791393 ____A (Lars Hederer ) C:\Users\Mitch Tiffin\Downloads\erunt-setup.exe

2013-05-28 17:53 - 2013-05-28 17:53 - 00791393 ____A (Lars Hederer ) C:\Users\Mitch Tiffin\Downloads\erunt-setup (1).exe

2013-05-28 14:36 - 2013-05-28 14:36 - 00013355 ____A C:\Users\Mitch Tiffin\Desktop\attach.txt

2013-05-28 14:36 - 2013-05-28 14:36 - 00013236 ____A C:\Users\Mitch Tiffin\Desktop\dds.txt

2013-05-28 14:33 - 2013-05-28 14:33 - 00688992 ____R (Swearware) C:\Users\Mitch Tiffin\Desktop\dds.com

2013-05-28 14:33 - 2013-05-28 14:33 - 00001554 ____A C:\Users\Mitch Tiffin\Desktop\nptcxvyf9p - Shortcut.lnk

2013-05-28 14:28 - 2013-05-28 14:28 - 10285040 ____A (Malwarebytes Corporation ) C:\Users\Mitch Tiffin\Downloads\nptcxvyf9p.exe

2013-05-28 14:10 - 2013-05-28 14:11 - 18778291 ____A C:\Users\Mitch Tiffin\Downloads\Vince Gill - Tryin' To Get Over You(1).mp4

2013-05-28 14:07 - 2013-05-28 14:08 - 10285040 ____A (Malwarebytes Corporation ) C:\Users\Mitch Tiffin\Downloads\u1lvyfhl1e.exe.part

2013-05-27 18:13 - 2013-06-06 01:27 - 00002183 ____A C:\Users\Public\Desktop\Google Chrome.lnk

2013-05-27 18:11 - 2013-06-08 12:25 - 00000910 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job

2013-05-27 18:11 - 2013-06-07 19:25 - 00000906 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job

2013-05-27 18:11 - 2013-05-27 18:11 - 00000000 ____A C:\Windows\SysWOW64\config.nt

2013-05-27 18:11 - 2013-05-09 00:58 - 00287840 ____A (AVAST Software) C:\Windows\System32\aswBoot.exe

2013-05-27 18:10 - 2013-05-27 18:10 - 00000000 ____D C:\Program Files\AVAST Software

2013-05-27 18:09 - 2013-05-27 18:10 - 00000000 ____D C:\ProgramData\AVAST Software

2013-05-27 18:00 - 2013-05-27 18:00 - 00000000 ____D C:\Users\Mitch Tiffin\AppData\Roaming\OpenOffice.org

2013-05-27 17:59 - 2013-05-27 17:59 - 00001168 ____A C:\Users\Public\Desktop\OpenOffice.org 3.4.1.lnk

2013-05-27 17:58 - 2013-05-27 17:58 - 00000000 ____D C:\Program Files (x86)\OpenOffice.org 3

2013-05-27 17:55 - 2013-05-27 17:55 - 00000000 ____D C:\Users\Mitch Tiffin\Desktop\OpenOffice.org 3.4.1 (en-US) Installation Files

2013-05-27 17:30 - 2013-05-27 17:34 - 135933721 ____A C:\Users\Mitch Tiffin\Downloads\Apache_OpenOffice_incubating_3.4.1_Win_x86_install_en-US.exe

2013-05-27 17:27 - 2013-05-27 17:30 - 117478104 ____A C:\Users\Mitch Tiffin\Downloads\avast_free_antivirus_setup.exe

2013-05-27 14:42 - 2013-05-27 14:42 - 10285040 ____A (Malwarebytes Corporation ) C:\Users\Mitch Tiffin\Downloads\mbam-setup-

2013-05-26 10:33 - 2013-05-26 10:34 - 15396940 ____A C:\Users\Mitch Tiffin\Downloads\Jake Owen - Somewhere In The Middle.mp4

2013-05-26 10:32 - 2013-05-26 10:34 - 22531300 ____A C:\Users\Mitch Tiffin\Downloads\Jake Owen - The Journey Of Your Life.mp4

2013-05-26 10:32 - 2013-05-26 10:33 - 16998045 ____A C:\Users\Mitch Tiffin\Downloads\Jake Owen - Alone With You.mp4

2013-05-26 10:30 - 2013-05-26 10:32 - 19752103 ____A C:\Users\Mitch Tiffin\Downloads\Jake Owen - Eight Second Ride.mp4

2013-05-26 10:20 - 2013-05-26 10:22 - 11465574 ____A C:\Users\Mitch Tiffin\Downloads\CMA Songwriters Series _ How Forever Feels.mp4

2013-05-26 10:19 - 2013-05-26 10:20 - 12588214 ____A C:\Users\Mitch Tiffin\Downloads\CMA Songwriters Series _ I Can't Go There.mp4

2013-05-26 10:17 - 2013-05-26 10:18 - 16349649 ____A C:\Users\Mitch Tiffin\Downloads\CMA Songwriters Series _ Out Last Night.mp4

2013-05-26 10:16 - 2013-05-26 10:18 - 19805330 ____A C:\Users\Mitch Tiffin\Downloads\CMA Songwriters Series _ You Save Me.mp4

2013-05-19 07:21 - 2013-05-19 07:21 - 12615468 ____A C:\Users\Mitch Tiffin\Downloads\Kenny Chesney & Grace Potter You & Tequila on 2011 CMA's.mp4

2013-05-19 07:18 - 2013-05-19 07:19 - 21880505 ____A C:\Users\Mitch Tiffin\Downloads\Eric Church - Creepin' Live at the Grand Ole Opry.mp4

2013-05-19 07:15 - 2013-05-19 07:17 - 17440676 ____A C:\Users\Mitch Tiffin\Downloads\Eric Church - Springsteen (AOL Sessions).mp4

2013-05-19 07:14 - 2013-05-19 07:16 - 15806482 ____A C:\Users\Mitch Tiffin\Downloads\Eric Church - Drink in My Hand (AOL Sessions).mp4

2013-05-19 07:13 - 2013-05-19 07:14 - 14809034 ____A C:\Users\Mitch Tiffin\Downloads\Eric Church - Smoke a Little Smoke (AOL Sessions).mp4

2013-05-19 07:10 - 2013-05-19 07:11 - 09204660 ____A C:\Users\Mitch Tiffin\Downloads\Eric Church - Like Jesus Does ((ACM Awards 2013)).mp4

2013-05-19 07:08 - 2013-05-19 07:09 - 14890732 ____A C:\Users\Mitch Tiffin\Downloads\Chris Young - Drinkin' Me Lonely on Opry Live.mp4

2013-05-19 06:51 - 2013-05-19 06:55 - 95342853 ____A C:\Users\Mitch Tiffin\Downloads\Chris Young - Don't Close Your Eyes at the Grand Ole Opry on Opry Live.mp4

2013-05-19 06:48 - 2013-05-19 06:50 - 21854277 ____A C:\Users\Mitch Tiffin\Downloads\Chris Young You London 2013.mp4

2013-05-19 06:48 - 2013-05-19 06:50 - 18245645 ____A C:\Users\Mitch Tiffin\Downloads\Chris Young Man I Want To Be London 2013.mp4

2013-05-19 06:46 - 2013-05-19 06:47 - 24237132 ____A C:\Users\Mitch Tiffin\Downloads\Chris Young I Can Take It From There.mp4

2013-05-19 06:45 - 2013-05-19 06:46 - 20099493 ____A C:\Users\Mitch Tiffin\Downloads\Chris Young Tomorrow.mp4

2013-05-19 06:44 - 2013-05-19 06:45 - 20780608 ____A C:\Users\Mitch Tiffin\Downloads\Chris Young Getting You Home London 2013.mp4

2013-05-19 06:39 - 2013-05-19 07:13 - 385244388 ____A C:\Users\Mitch Tiffin\Downloads\CMA Songwriters Series(1).mp4

2013-05-18 00:57 - 2013-05-18 00:58 - 27638023 ____A C:\Users\Mitch Tiffin\Downloads\CMA Songwriters Series _ Young.mp4

2013-05-18 00:52 - 2013-05-18 00:53 - 14546682 ____A C:\Users\Mitch Tiffin\Downloads\CMA Songwriters Series _ Soul of a Sailor.mp4

2013-05-11 14:24 - 2013-05-11 14:28 - 27736754 ____A C:\Users\Mitch Tiffin\Downloads\Bass-Amp.zip

2013-05-11 14:24 - 2013-05-11 14:28 - 27536208 ____A C:\Users\Mitch Tiffin\Downloads\Snare.zip

2013-05-11 14:24 - 2013-05-11 14:27 - 28353546 ____A C:\Users\Mitch Tiffin\Downloads\Bass-DI.zip

2013-05-11 14:23 - 2013-05-11 14:29 - 52688338 ____A C:\Users\Mitch Tiffin\Downloads\Overheads.zip

2013-05-11 14:23 - 2013-05-11 14:28 - 28821471 ____A C:\Users\Mitch Tiffin\Downloads\Vox.zip

2013-05-11 14:23 - 2013-05-11 14:27 - 29960754 ____A C:\Users\Mitch Tiffin\Downloads\Guitar-Amp.zip

2013-05-11 14:23 - 2013-05-11 14:24 - 27251849 ____A C:\Users\Mitch Tiffin\Downloads\Kick-Drum.zip

2013-05-11 10:42 - 2013-05-11 10:42 - 00002202 ____A C:\Windows\DPINST.LOG

==================== One Month Modified Files and Folders =======

2013-06-08 18:55 - 2013-06-08 18:55 - 00000000 ____D C:\FRST

2013-06-08 15:47 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT

2013-06-08 15:46 - 2009-07-13 20:51 - 00110660 ____A C:\Windows\setupact.log

2013-06-08 12:48 - 2011-01-22 07:37 - 01139548 ____A C:\Windows\WindowsUpdate.log

2013-06-08 12:25 - 2013-05-27 18:11 - 00000910 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job

2013-06-08 11:47 - 2013-06-08 11:47 - 00001593 ____A C:\Users\Mitch Tiffin\Desktop\Live Like You Were Dying - Shortcut.lnk

2013-06-08 11:16 - 2011-12-23 14:56 - 00000000 ____D C:\Users\Mitch Tiffin\AppData\Roaming\Celemony Software GmbH

2013-06-08 11:14 - 2013-06-08 11:14 - 00001332 ____A C:\AdwCleaner[R8].txt

2013-06-07 19:25 - 2013-05-27 18:11 - 00000906 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job

2013-06-07 13:26 - 2009-07-13 20:45 - 00015376 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0

2013-06-07 13:26 - 2009-07-13 20:45 - 00015376 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0

2013-06-06 01:27 - 2013-05-27 18:13 - 00002183 ____A C:\Users\Public\Desktop\Google Chrome.lnk

2013-06-05 13:07 - 2012-11-03 12:35 - 00000000 ____D C:\Scans

2013-06-05 12:55 - 2011-01-22 07:38 - 00000000 ____D C:\users\Mitch Tiffin

2013-06-04 03:33 - 2009-07-13 21:13 - 00730512 ____A C:\Windows\System32\PerfStringBackup.INI

2013-06-04 03:28 - 2013-06-04 03:27 - 00001271 ____A C:\AdwCleaner[R7].txt

2013-06-02 13:42 - 2013-05-29 03:04 - 00000000 ____D C:\Windows\ERDNT

2013-06-02 13:19 - 2013-06-02 13:19 - 00002834 ____A C:\Users\Mitch Tiffin\Desktop\RKreport[1]_S_06022013_02d1619.txt

2013-06-02 13:19 - 2013-05-29 17:39 - 00000000 ____D C:\Users\Mitch Tiffin\Desktop\RK_Quarantine

2013-06-02 12:22 - 2011-01-25 05:56 - 00020860 ____A C:\Windows\PFRO.log

2013-06-02 12:19 - 2011-04-24 06:55 - 00000000 ____D C:\Users\Mitch Tiffin\AppData\Local\Apps\2.0

2013-06-02 12:17 - 2013-06-02 12:17 - 00016020 ____A C:\ComboFix.txt

2013-06-02 12:17 - 2013-05-30 03:15 - 00000000 ___AD C:\Qoobox

2013-06-02 12:16 - 2009-07-13 18:34 - 00000215 ____A C:\Windows\system.ini

2013-06-02 12:09 - 2013-05-30 02:59 - 05076415 ____R (Swearware) C:\Users\Mitch Tiffin\Desktop\ComboFix.exe

2013-06-02 08:34 - 2013-06-02 08:34 - 00001211 ____A C:\AdwCleaner[R6].txt

2013-06-01 11:05 - 2013-03-09 08:15 - 00000000 ____D C:\Sawdust Road

2013-06-01 10:38 - 2013-06-01 10:37 - 00001348 ____A C:\Users\Mitch Tiffin\Desktop\SystemLook.txt

2013-06-01 10:36 - 2013-06-01 10:36 - 00139264 ____A C:\Users\Mitch Tiffin\Desktop\SystemLook.exe

2013-05-31 03:40 - 2011-03-28 20:58 - 00000000 ____D C:\Users\Mitch Tiffin\AppData\Roaming\vlc

2013-05-29 17:37 - 2013-05-29 17:37 - 00816128 ____A C:\Users\Mitch Tiffin\Desktop\RogueKiller.exe

2013-05-29 17:29 - 2013-05-29 17:29 - 00000000 ____D C:\TDSSKiller_Quarantine

2013-05-29 17:26 - 2013-05-29 17:25 - 02237968 ____A (Kaspersky Lab ZAO) C:\Users\Mitch Tiffin\Desktop\tdsskiller.exe

2013-05-29 17:22 - 2013-05-29 17:22 - 00001150 ____A C:\AdwCleaner[R5].txt

2013-05-29 16:33 - 2013-05-29 16:33 - 00002770 ____A C:\AdwCleaner[s1].txt

2013-05-29 16:33 - 2013-05-29 16:33 - 00002563 ____A C:\AdwCleaner[R3].txt

2013-05-29 16:14 - 2013-05-29 16:14 - 00000000 ____D C:\ERDNT

2013-05-29 03:46 - 2013-05-29 03:46 - 00002136 ____A C:\AdwCleaner[R2].txt

2013-05-29 03:37 - 2013-05-29 03:37 - 00632031 ____A C:\Users\Mitch Tiffin\Desktop\adwcleaner.exe

2013-05-28 17:58 - 2013-05-28 17:57 - 00000928 ____A C:\Users\UpdatusUser\Desktop\NTREGOPT.lnk

2013-05-28 17:58 - 2013-05-28 17:57 - 00000928 ____A C:\Users\Music\Desktop\NTREGOPT.lnk

2013-05-28 17:58 - 2013-05-28 17:57 - 00000928 ____A C:\Users\Mitch Tiffin\Desktop\NTREGOPT.lnk

2013-05-28 17:58 - 2013-05-28 17:57 - 00000909 ____A C:\Users\UpdatusUser\Desktop\ERUNT.lnk

2013-05-28 17:58 - 2013-05-28 17:57 - 00000909 ____A C:\Users\Music\Desktop\ERUNT.lnk

2013-05-28 17:58 - 2013-05-28 17:57 - 00000909 ____A C:\Users\Mitch Tiffin\Desktop\ERUNT.lnk

2013-05-28 17:58 - 2013-05-28 17:57 - 00000000 ____D C:\Program Files (x86)\ERUNT

2013-05-28 17:56 - 2013-05-28 17:56 - 00791393 ____A (Lars Hederer ) C:\Users\Mitch Tiffin\Downloads\erunt-setup(1).exe

2013-05-28 17:55 - 2013-05-28 17:55 - 00791393 ____A (Lars Hederer ) C:\Users\Mitch Tiffin\Downloads\erunt-setup (3).exe

2013-05-28 17:54 - 2013-05-28 17:54 - 00791393 ____A (Lars Hederer ) C:\Users\Mitch Tiffin\Downloads\erunt-setup (2).exe

2013-05-28 17:53 - 2013-05-28 17:53 - 00791393 ____A (Lars Hederer ) C:\Users\Mitch Tiffin\Downloads\erunt-setup.exe

2013-05-28 17:53 - 2013-05-28 17:53 - 00791393 ____A (Lars Hederer ) C:\Users\Mitch Tiffin\Downloads\erunt-setup (1).exe

2013-05-28 14:36 - 2013-05-28 14:36 - 00013355 ____A C:\Users\Mitch Tiffin\Desktop\attach.txt

2013-05-28 14:36 - 2013-05-28 14:36 - 00013236 ____A C:\Users\Mitch Tiffin\Desktop\dds.txt

2013-05-28 14:33 - 2013-05-28 14:33 - 00688992 ____R (Swearware) C:\Users\Mitch Tiffin\Desktop\dds.com

2013-05-28 14:33 - 2013-05-28 14:33 - 00001554 ____A C:\Users\Mitch Tiffin\Desktop\nptcxvyf9p - Shortcut.lnk

2013-05-28 14:30 - 2012-01-10 06:08 - 00001113 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk

2013-05-28 14:30 - 2011-09-03 12:54 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware

2013-05-28 14:28 - 2013-05-28 14:28 - 10285040 ____A (Malwarebytes Corporation ) C:\Users\Mitch Tiffin\Downloads\nptcxvyf9p.exe

2013-05-28 14:11 - 2013-05-28 14:10 - 18778291 ____A C:\Users\Mitch Tiffin\Downloads\Vince Gill - Tryin' To Get Over You(1).mp4

2013-05-28 14:08 - 2013-05-28 14:07 - 10285040 ____A (Malwarebytes Corporation ) C:\Users\Mitch Tiffin\Downloads\u1lvyfhl1e.exe.part

2013-05-27 18:27 - 2011-01-22 07:58 - 00158952 ____A C:\Users\Mitch Tiffin\AppData\Local\GDIPFONTCACHEV1.DAT

2013-05-27 18:24 - 2009-07-13 20:45 - 00543504 ____A C:\Windows\System32\FNTCACHE.DAT

2013-05-27 18:14 - 2012-09-14 14:20 - 00000000 ____D C:\Users\Mitch Tiffin\AppData\Local\Google

2013-05-27 18:13 - 2012-09-14 14:20 - 00000000 ____D C:\Program Files (x86)\Google

2013-05-27 18:11 - 2013-05-27 18:11 - 00000000 ____A C:\Windows\SysWOW64\config.nt

2013-05-27 18:10 - 2013-05-27 18:10 - 00000000 ____D C:\Program Files\AVAST Software

2013-05-27 18:10 - 2013-05-27 18:09 - 00000000 ____D C:\ProgramData\AVAST Software

2013-05-27 18:00 - 2013-05-27 18:00 - 00000000 ____D C:\Users\Mitch Tiffin\AppData\Roaming\OpenOffice.org

2013-05-27 17:59 - 2013-05-27 17:59 - 00001168 ____A C:\Users\Public\Desktop\OpenOffice.org 3.4.1.lnk

2013-05-27 17:58 - 2013-05-27 17:58 - 00000000 ____D C:\Program Files (x86)\OpenOffice.org 3

2013-05-27 17:56 - 2009-07-13 19:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared

2013-05-27 17:55 - 2013-05-27 17:55 - 00000000 ____D C:\Users\Mitch Tiffin\Desktop\OpenOffice.org 3.4.1 (en-US) Installation Files

2013-05-27 17:34 - 2013-05-27 17:30 - 135933721 ____A C:\Users\Mitch Tiffin\Downloads\Apache_OpenOffice_incubating_3.4.1_Win_x86_install_en-US.exe

2013-05-27 17:30 - 2013-05-27 17:27 - 117478104 ____A C:\Users\Mitch Tiffin\Downloads\avast_free_antivirus_setup.exe

2013-05-27 14:42 - 2013-05-27 14:42 - 10285040 ____A (Malwarebytes Corporation ) C:\Users\Mitch Tiffin\Downloads\mbam-setup-

2013-05-27 12:31 - 2012-04-26 03:56 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service

2013-05-26 10:34 - 2013-05-26 10:33 - 15396940 ____A C:\Users\Mitch Tiffin\Downloads\Jake Owen - Somewhere In The Middle.mp4

2013-05-26 10:34 - 2013-05-26 10:32 - 22531300 ____A C:\Users\Mitch Tiffin\Downloads\Jake Owen - The Journey Of Your Life.mp4

2013-05-26 10:33 - 2013-05-26 10:32 - 16998045 ____A C:\Users\Mitch Tiffin\Downloads\Jake Owen - Alone With You.mp4

2013-05-26 10:32 - 2013-05-26 10:30 - 19752103 ____A C:\Users\Mitch Tiffin\Downloads\Jake Owen - Eight Second Ride.mp4

2013-05-26 10:22 - 2013-05-26 10:20 - 11465574 ____A C:\Users\Mitch Tiffin\Downloads\CMA Songwriters Series _ How Forever Feels.mp4

2013-05-26 10:20 - 2013-05-26 10:19 - 12588214 ____A C:\Users\Mitch Tiffin\Downloads\CMA Songwriters Series _ I Can't Go There.mp4

2013-05-26 10:18 - 2013-05-26 10:17 - 16349649 ____A C:\Users\Mitch Tiffin\Downloads\CMA Songwriters Series _ Out Last Night.mp4

2013-05-26 10:18 - 2013-05-26 10:16 - 19805330 ____A C:\Users\Mitch Tiffin\Downloads\CMA Songwriters Series _ You Save Me.mp4

2013-05-26 07:56 - 2011-09-26 17:53 - 00000000 ____D C:\Program Files (x86)\MasterWriter 2.0

2013-05-25 05:38 - 2011-02-04 16:20 - 00000000 ____D C:\Users\Mitch Tiffin\Documents\NSAI

2013-05-24 17:23 - 2012-12-11 09:08 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox

2013-05-19 15:40 - 2012-04-05 06:38 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe

2013-05-19 15:40 - 2011-05-17 13:39 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl

2013-05-19 15:40 - 2011-01-31 12:57 - 00000663 ____A C:\Users\Mitch Tiffin\Desktop\Lotus 1-2-3.lnk

2013-05-19 07:21 - 2013-05-19 07:21 - 12615468 ____A C:\Users\Mitch Tiffin\Downloads\Kenny Chesney & Grace Potter You & Tequila on 2011 CMA's.mp4

2013-05-19 07:19 - 2013-05-19 07:18 - 21880505 ____A C:\Users\Mitch Tiffin\Downloads\Eric Church - Creepin' Live at the Grand Ole Opry.mp4

2013-05-19 07:17 - 2013-05-19 07:15 - 17440676 ____A C:\Users\Mitch Tiffin\Downloads\Eric Church - Springsteen (AOL Sessions).mp4

2013-05-19 07:16 - 2013-05-19 07:14 - 15806482 ____A C:\Users\Mitch Tiffin\Downloads\Eric Church - Drink in My Hand (AOL Sessions).mp4

2013-05-19 07:14 - 2013-05-19 07:13 - 14809034 ____A C:\Users\Mitch Tiffin\Downloads\Eric Church - Smoke a Little Smoke (AOL Sessions).mp4

2013-05-19 07:13 - 2013-05-19 06:39 - 385244388 ____A C:\Users\Mitch Tiffin\Downloads\CMA Songwriters Series(1).mp4

2013-05-19 07:11 - 2013-05-19 07:10 - 09204660 ____A C:\Users\Mitch Tiffin\Downloads\Eric Church - Like Jesus Does ((ACM Awards 2013)).mp4

2013-05-19 07:09 - 2013-05-19 07:08 - 14890732 ____A C:\Users\Mitch Tiffin\Downloads\Chris Young - Drinkin' Me Lonely on Opry Live.mp4

2013-05-19 06:55 - 2013-05-19 06:51 - 95342853 ____A C:\Users\Mitch Tiffin\Downloads\Chris Young - Don't Close Your Eyes at the Grand Ole Opry on Opry Live.mp4

2013-05-19 06:50 - 2013-05-19 06:48 - 21854277 ____A C:\Users\Mitch Tiffin\Downloads\Chris Young You London 2013.mp4

2013-05-19 06:50 - 2013-05-19 06:48 - 18245645 ____A C:\Users\Mitch Tiffin\Downloads\Chris Young Man I Want To Be London 2013.mp4

2013-05-19 06:47 - 2013-05-19 06:46 - 24237132 ____A C:\Users\Mitch Tiffin\Downloads\Chris Young I Can Take It From There.mp4

2013-05-19 06:46 - 2013-05-19 06:45 - 20099493 ____A C:\Users\Mitch Tiffin\Downloads\Chris Young Tomorrow.mp4

2013-05-19 06:45 - 2013-05-19 06:44 - 20780608 ____A C:\Users\Mitch Tiffin\Downloads\Chris Young Getting You Home London 2013.mp4

2013-05-18 00:58 - 2013-05-18 00:57 - 27638023 ____A C:\Users\Mitch Tiffin\Downloads\CMA Songwriters Series _ Young.mp4

2013-05-18 00:53 - 2013-05-18 00:52 - 14546682 ____A C:\Users\Mitch Tiffin\Downloads\CMA Songwriters Series _ Soul of a Sailor.mp4

2013-05-17 16:47 - 2011-01-31 17:08 - 00000000 ____D C:\Windows\pss

2013-05-17 16:45 - 2011-01-31 12:57 - 00000698 ____A C:\Users\Mitch Tiffin\Desktop\Lotus Word Pro.lnk

2013-05-11 14:29 - 2013-05-11 14:23 - 52688338 ____A C:\Users\Mitch Tiffin\Downloads\Overheads.zip

2013-05-11 14:28 - 2013-05-11 14:24 - 27736754 ____A C:\Users\Mitch Tiffin\Downloads\Bass-Amp.zip

2013-05-11 14:28 - 2013-05-11 14:24 - 27536208 ____A C:\Users\Mitch Tiffin\Downloads\Snare.zip

2013-05-11 14:28 - 2013-05-11 14:23 - 28821471 ____A C:\Users\Mitch Tiffin\Downloads\Vox.zip

2013-05-11 14:27 - 2013-05-11 14:24 - 28353546 ____A C:\Users\Mitch Tiffin\Downloads\Bass-DI.zip

2013-05-11 14:27 - 2013-05-11 14:23 - 29960754 ____A C:\Users\Mitch Tiffin\Downloads\Guitar-Amp.zip

2013-05-11 14:24 - 2013-05-11 14:23 - 27251849 ____A C:\Users\Mitch Tiffin\Downloads\Kick-Drum.zip

2013-05-11 10:42 - 2013-05-11 10:42 - 00002202 ____A C:\Windows\DPINST.LOG

2013-05-11 10:39 - 2013-03-17 19:44 - 00000000 ____D C:\Users\Mitch Tiffin\AppData\Roaming\dvdcss

2013-05-09 00:58 - 2013-05-27 18:11 - 00287840 ____A (AVAST Software) C:\Windows\System32\aswBoot.exe

==================== Known DLLs (Whitelisted) ================

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit

C:\Windows\System32\wininit.exe => MD5 is legit

C:\Windows\SysWOW64\wininit.exe => MD5 is legit

C:\Windows\explorer.exe => MD5 is legit

C:\Windows\SysWOW64\explorer.exe => MD5 is legit

C:\Windows\System32\svchost.exe => MD5 is legit

C:\Windows\SysWOW64\svchost.exe => MD5 is legit

C:\Windows\System32\services.exe => MD5 is legit

C:\Windows\System32\User32.dll => MD5 is legit

C:\Windows\SysWOW64\User32.dll => MD5 is legit

C:\Windows\System32\userinit.exe => MD5 is legit

C:\Windows\SysWOW64\userinit.exe => MD5 is legit

C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== EXE ASSOCIATION =====================

HKLM\...\.exe: exefile => OK

HKLM\...\exefile\DefaultIcon: %1 => OK

HKLM\...\exefile\open\command: "%1" %* => OK

==================== Restore Points =========================

Restore point made on: 2013-05-22 13:59:02

Restore point made on: 2013-05-25 14:51:38

Restore point made on: 2013-05-27 16:24:05

Restore point made on: 2013-05-27 17:56:22

Restore point made on: 2013-05-27 17:58:22

Restore point made on: 2013-05-27 18:10:23

Restore point made on: 2013-05-28 17:33:37

Restore point made on: 2013-05-28 17:56:53

Restore point made on: 2013-06-01 23:27:21

Restore point made on: 2013-06-05 13:05:14

==================== Memory info ===========================

Percentage of memory in use: 7%

Total physical RAM: 16382.18 MB

Available physical RAM: 15192.79 MB

Total Pagefile: 16380.33 MB

Available Pagefile: 15200.83 MB

Total Virtual: 8192 MB

Available Virtual: 8191.85 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:931.41 GB) (Free:432.09 GB) NTFS (Disk=0 Partition=2)

Drive f: (CENTON USB) (Removable) (Total:7.82 GB) (Free:4.65 GB) FAT32 (Disk=1 Partition=1)

Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS

Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS (Disk=0 Partition=1) ==>[system with boot components (obtained from reading drive)]

==================== MBR & Partition Table ==================


Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: D4F15274)

Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)

Partition 2: (Not Active) - (Size=931 GB) - (Type=07 NTFS)


Disk: 1 (Size: 8 GB) (Disk ID: 014FCB3D)

Partition 1: (Not Active) - (Size=8 GB) - (Type=0B)

Last Boot: 2013-06-04 04:37

==================== End Of Log ============================

Link to post
Share on other sites

I did not notice an infection from this log-report.

1. Download Malwarebytes Anti-Rootkit from http://www.malwarebytes.org/products/mbar/

2. Unzip the contents to a folder in a convenient location.

3. Open the folder where the contents were unzipped and run mbar.exe

IF your Windows is Windows 8 or 7 or Vista, do a RIGHT-Click on mbar.exe and select Run As Administrator and allow to run.

If your Windows is XP, double-click to start.

4. Follow the instructions in the wizard to update and allow the program to scan your computer for threats.

5. Click on the Cleanup button to remove any threats and reboot if prompted to do so.

6. Wait while the system shuts down and the cleanup process is performed.

7. Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.

Link to post
Share on other sites

Mbar didn't find anything


Excel is broken

I've went through and killed any process that are not essential

Also removed a few programs that i don't use

During that process i found that Dragon Natural speak was not installed properly. i tried to uninstall and got an error 1305 that it could not find a file. I looked in the folder and the file was there (dd105hrd.dll) when to their website and got their tools they also failed

tried to fix it with their installer and that failed it is always an error reading a file that is in the folder that it says it can find

Boot issues 8 to nine min from cold boot to being able to use the computer

every two or three times I boot it hangs on a blank screen

if I restart without a shutdown It hangs and just changes the screen color from red to black to grey to green and blue

Is there a program that will track each step of the windows loading process and tell us what slowing everything down?

Link to post
Share on other sites

We need to wrap this up now. There is no malware onboard. We have run MBAM & MBAR and those found nothing.

We have as well run Combofix tool.

You may well need to re-install Excel. And as to your Windows instability issues, 2 suggestions.

a) Seriously consider doing a wipe/ erase / and new install of Windows plus all your apps.

An unsteady system is tough to fix.

b) Seek help in other venues, such as the general PC Help forum http://forums.malwar...php?showforum=6

If you have a problem with these steps, or something does not quite work here, do let me know.

The following few steps will remove tools we used.

We have to remove Combofix and all its associated folders. By whichever name you named it, ( you had named it ComboFix

put that name in the RUN box stated just below.

The "/uninstall" in the Run line below is to start Combofix for it's cleanup & removal function.

Note the space before the slash mark.

The utility must be removed to prevent any un-intentional or accidental usage, PLUS, to free up much space on your hard disk.

  • Highlight the line in this CODEBOX.
    Select & Copy the entire line within this codebox (so that it is in Windows clipboard memory)
    c:\users\Mitch Tiffin\Desktop\ComboFix.exe /uninstall

  • Start >> type in cmd >> press the Ctrl+Shift+Enter keyboard combination and cmd.exe will be launched as if you selected Run as Administrator. You will then see a User Account Control prompt asking if you would like to allow the Command Prompt to be able to make changes on your computer. Click on the Yes button and you will now be at the Elevated Command Prompt.
    Do a Right click within the command prompt window and select Paste. This must show the line from Codebox above.
    Then tap Enter

IF in the case Combofix un-install has an issue, skip that step.


  • Download OTC to your desktop and run it
  • Click Yes to beginning the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. Choose Yes.

ERUNT you should keep and use periodically to backup Windows registry.

Delete the following if still present:






Safer practices & malware prevention

We are finished here. Best regards. cool.gif

Link to post
Share on other sites

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.