Jump to content

Recommended Posts

When I open chrome, it goes to a yahoo search page that has the term spigot in it.

My lastpass browser extension also fails to load.

 

dds.txt

DDS (Ver_2012-11-20.01) - NTFS_AMD64 
Internet Explorer: 10.0.9200.16660  BrowserJavaVersion: 10.25.2
Run by Travis at 19:37:32 on 2013-08-27
Microsoft Windows 7 Professional   6.1.7601.1.1252.1.1033.18.8079.6335 [GMT -5:00]
.
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\WUDFHost.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\TortoiseHg\TortoiseHgOverlayServer.exe
C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Windows\system32\svchost.exe -k HPService
C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\taskeng.exe
C:\Windows\system32\msiexec.exe
C:\Windows\system32\vssvc.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
mWinlogon: Userinit = userinit.exe
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
BHO: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO: LastPass Vault: {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files (x86)\LastPass\LPToolbar.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL
BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
TB: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
TB: LastPass Toolbar: {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar.dll
uRun: [sUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
mRun: [iAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
mRun: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [bCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
mRun: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
mRun: [googletalk] C:\Program Files (x86)\Google\Google Talk\googletalk.exe /autostart
StartupFolder: C:\Users\Travis\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\Travis\AppData\Roaming\Dropbox\bin\Dropbox.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\INSTAL~1.LNK - C:\Program Files (x86)\Common Files\lpuninstall.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: LastPass - C:\Users\Travis\AppData\LocalLow\LastPass\context.html?cmd=lastpass
IE: LastPass Fill Forms - C:\Users\Travis\AppData\LocalLow\LastPass\context.html?cmd=fillforms
IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {43699cd0-e34f-11de-8a39-0800200c9a66} - {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files (x86)\LastPass\LPToolbar.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
TCP: NameServer = 75.75.76.76 75.75.75.75
TCP: Interfaces\{EB36D9E6-96A6-484C-8184-EDA6F235B346} : DHCPNameServer = 75.75.76.76 75.75.75.75
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.57\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: avast! Online Security: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL
x64-BHO: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
x64-BHO: LastPass Vault: {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files (x86)\LastPass\LPToolbar_x64.dll
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL
x64-BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
x64-TB: avast! Online Security: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-TB: LastPass Toolbar: {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar_x64.dll
x64-Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-Run: [igfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [TortoiseHgOverlayIconServer] C:\Program Files\TortoiseHg\TortoiseHgOverlayServer.exe
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
x64-IE: {43699cd0-e34f-11de-8a39-0800200c9a66} - {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files (x86)\LastPass\LPToolbar_x64.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
x64-SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL
.
============= SERVICES / DRIVERS ===============
.
R0 aswRvrt;aswRvrt;C:\Windows\System32\drivers\aswRvrt.sys [2013-8-20 65336]
R0 aswVmm;aswVmm;C:\Windows\System32\drivers\aswVmm.sys [2013-8-20 189936]
R1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2013-8-20 1030952]
R1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2013-8-20 378944]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2013-5-23 143120]
R2 aswFsBlk;aswFsBlk;C:\Windows\System32\drivers\aswFsBlk.sys [2013-8-20 33400]
R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2013-8-20 80816]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-8-20 46808]
R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2013-8-14 13592]
R3 asmthub3;ASMedia USB3 Hub Service;C:\Windows\System32\drivers\asmthub3.sys [2012-2-21 130536]
R3 asmtxhci;ASMEDIA XHCI Service;C:\Windows\System32\drivers\asmtxhci.sys [2012-2-21 396776]
R3 IntcDAud;Intel® Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2013-8-14 331264]
R3 siigPCIeMf;siigPCIeMf;C:\Windows\System32\drivers\siigPCIeMf.sys [2010-4-1 55808]
R3 siigPCIeSer;siigPCIeSer;C:\Windows\System32\drivers\siigPCIeSer.sys [2010-4-1 98304]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 dmvsc;dmvsc;C:\Windows\System32\drivers\dmvsc.sys [2010-11-21 71168]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2013-8-20 19456]
S3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2013-8-14 428136]
S3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver;C:\Windows\System32\drivers\rtl8192Ce.sys [2013-8-14 878696]
S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2013-8-20 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2013-8-20 30208]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2013-8-20 1255736]
.
=============== Created Last 30 ================
.
2013-08-27 22:43:15 -------- d-----w- C:\Windows\System32\appmgmt
2013-08-27 22:38:31 -------- d-----w- C:\Users\Travis\AppData\Roaming\Malwarebytes
2013-08-27 22:33:47 -------- d-----w- C:\Program Files\CCleaner
2013-08-27 22:33:03 -------- d-----w- C:\ProgramData\Malwarebytes
2013-08-27 22:33:02 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys
2013-08-27 22:33:01 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-08-27 21:56:42 9515512 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{1E3CAB20-4C27-4657-AC6D-9561333BE83C}\mpengine.dll
2013-08-27 03:22:22 -------- d-----w- C:\Users\Travis\AppData\Local\Diagnostics
2013-08-27 02:29:07 -------- d-----w- C:\Users\Travis\AppData\Roaming\uTorrent
2013-08-24 14:44:16 -------- d-----w- C:\ProgramData\Reprise
2013-08-24 14:38:11 -------- d-----w- C:\Users\Travis\AppData\Roaming\Sublime Text 2
2013-08-24 14:38:05 -------- d-----w- C:\Program Files\Sublime Text 2
2013-08-24 14:34:38 -------- d-----w- C:\Users\Travis\.mplabcomm
2013-08-24 14:28:51 -------- d-----w- C:\Users\Travis\MPLABXProjects
2013-08-24 14:28:51 -------- d-----w- C:\Users\Travis\.netbeans
2013-08-24 14:28:42 -------- d-----w- C:\Users\Travis\AppData\Roaming\.mplab_ide
2013-08-24 14:27:42 -------- d-----w- C:\gnuwin32
2013-08-24 14:09:40 -------- d-----w- C:\Users\Travis\.ssh
2013-08-24 14:03:43 -------- d-----w- C:\Users\Travis\AppData\Roaming\TortoiseHg
2013-08-24 14:03:27 -------- d-----w- C:\Program Files\Common Files\TortoiseOverlays
2013-08-24 14:03:26 -------- d-----w- C:\Program Files\TortoiseHg
2013-08-24 13:59:19 -------- d-----w- C:\Projects
2013-08-24 13:42:52 -------- d-----w- C:\Users\Travis\AppData\Roaming\HpUpdate
2013-08-24 13:42:50 741480 ------w- C:\Windows\System32\HPDiscoPM5412.dll
2013-08-24 13:42:43 -------- d-----w- C:\Program Files (x86)\HP
2013-08-24 13:42:42 -------- d-----w- C:\Program Files\HP
2013-08-24 13:41:50 -------- d-----w- C:\Users\Travis\AppData\Local\HP
2013-08-23 02:41:34 -------- d-----w- C:\Program Files\Microsoft Mouse and Keyboard Center
2013-08-21 02:49:31 -------- d-----w- C:\ProgramData\Microchip
2013-08-21 02:46:45 98304 ----a-w- C:\Windows\SysWow64\mchpwinusbdevice.exe
2013-08-21 02:46:45 83456 ----a-w- C:\Windows\System32\SerialAccessLink.dll
2013-08-21 02:46:45 708168 ----a-w- C:\Windows\System32\WinUSBCoInstaller.dll
2013-08-21 02:46:45 4389441 ----a-w- C:\Windows\SysWow64\USBAccessLink.dll
2013-08-21 02:46:45 161792 ----a-w- C:\Windows\System32\USBAccessLink.dll
2013-08-21 02:46:45 1533512 ----a-w- C:\Windows\System32\WUDFUpdate_01007.dll
2013-08-21 02:46:45 151552 ----a-w- C:\Windows\SysWow64\SerialAccessLink.dll
2013-08-21 02:46:45 1490656 ----a-w- C:\Windows\System32\WdfCoInstaller01007.dll
2013-08-21 02:46:45 105472 ----a-w- C:\Windows\System32\mchpwinusbdevice64.exe
2013-08-21 02:46:06 -------- d-----w- C:\Program Files (x86)\Microchip
2013-08-21 02:32:34 1424384 ----a-w- C:\Windows\System32\WindowsCodecs.dll
2013-08-21 02:32:34 1230336 ----a-w- C:\Windows\SysWow64\WindowsCodecs.dll
2013-08-21 02:15:16 -------- d-----w- C:\ProgramData\regid.1991-06.com.microsoft
2013-08-21 02:14:49 -------- d-----w- C:\Program Files (x86)\MSECache
2013-08-21 02:10:39 -------- d-----r- C:\Users\Travis\Dropbox
2013-08-21 02:06:33 -------- d-----w- C:\Program Files (x86)\Microsoft Synchronization Services
2013-08-21 02:06:22 -------- d-----w- C:\Windows\PCHEALTH
2013-08-21 02:06:22 -------- d-----w- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2013-08-21 02:04:13 -------- d-----w- C:\Program Files (x86)\Microsoft Visual Studio 8
2013-08-21 02:03:20 -------- d-----w- C:\Program Files (x86)\Microsoft Analysis Services
2013-08-21 02:03:05 -------- d-----w- C:\Users\Travis\AppData\Local\Microsoft Help
2013-08-21 01:57:17 157000 ----a-w- C:\Windows\SysWow64\COMDLG32.OCX
2013-08-21 01:57:17 128840 ----a-w- C:\Windows\SysWow64\MSWINSCK.OCX
2013-08-21 01:57:16 259912 ----a-w- C:\Windows\SysWow64\MSFLXGRD.OCX
2013-08-21 01:57:16 219464 ----a-w- C:\Windows\SysWow64\RICHTX32.OCX
2013-08-21 01:57:16 130888 ----a-w- C:\Windows\SysWow64\MSSTDFMT.DLL
2013-08-21 01:57:16 -------- d-----w- C:\Program Files (x86)\FuH
2013-08-21 01:57:05 -------- d-----w- C:\Users\Travis\AppData\Local\Programs
2013-08-21 01:47:08 -------- d-----w- C:\Users\Travis\AppData\Roaming\SUPERAntiSpyware.com
2013-08-21 01:47:05 -------- d-----w- C:\ProgramData\SUPERAntiSpyware.com
2013-08-21 01:47:05 -------- d-----w- C:\Program Files\SUPERAntiSpyware
2013-08-21 01:46:52 159744 ----a-w- C:\Program Files\Internet Explorer\Plugins\npqtplugin5.dll
2013-08-21 01:46:52 159744 ----a-w- C:\Program Files\Internet Explorer\Plugins\npqtplugin4.dll
2013-08-21 01:46:52 159744 ----a-w- C:\Program Files\Internet Explorer\Plugins\npqtplugin3.dll
2013-08-21 01:46:52 159744 ----a-w- C:\Program Files\Internet Explorer\Plugins\npqtplugin2.dll
2013-08-21 01:46:52 159744 ----a-w- C:\Program Files\Internet Explorer\Plugins\npqtplugin.dll
2013-08-21 01:46:42 -------- d-----w- C:\Users\Travis\AppData\Local\Apple
2013-08-21 01:46:12 -------- d-----w- C:\Users\Travis\AppData\Roaming\Dropbox
2013-08-21 01:45:49 216064 ----a-w- C:\Windows\SysWow64\gcapi_dll.dll
2013-08-21 01:45:44 -------- d-----w- C:\Users\Travis\AppData\Roaming\Foxit Software
2013-08-21 01:45:43 -------- d-----w- C:\Program Files (x86)\Foxit Software
2013-08-21 01:45:03 -------- d-----w- C:\Program Files (x86)\VideoLAN
2013-08-21 01:43:21 -------- d-----w- C:\Windows\SysWow64\Adobe
2013-08-21 01:43:04 -------- d-----w- C:\Python27
2013-08-21 01:40:13 -------- d-----w- C:\Users\Travis\AppData\Roaming\Scooter Software
2013-08-21 01:40:10 -------- d-----w- C:\Program Files (x86)\Beyond Compare 3
2013-08-21 01:31:10 3913664 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2013-08-21 01:31:09 5550528 ----a-w- C:\Windows\System32\ntoskrnl.exe
2013-08-21 01:31:09 3968960 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2013-08-21 01:31:09 243712 ----a-w- C:\Windows\System32\wow64.dll
2013-08-21 01:31:09 1732032 ----a-w- C:\Windows\System32\ntdll.dll
2013-08-21 01:31:09 1292192 ----a-w- C:\Windows\SysWow64\ntdll.dll
2013-08-21 01:31:08 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2013-08-21 01:31:08 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2013-08-21 01:31:08 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2013-08-21 01:31:08 2048 ----a-w- C:\Windows\SysWow64\user.exe
2013-08-21 01:31:08 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2013-08-21 01:29:24 -------- d-----w- C:\Users\Travis\AppData\Local\Adobe
2013-08-21 01:15:22 1643520 ----a-w- C:\Windows\System32\DWrite.dll
2013-08-21 01:15:22 1247744 ----a-w- C:\Windows\SysWow64\DWrite.dll
2013-08-21 01:07:57 -------- d-----w- C:\Windows\SysWow64\Wat
2013-08-21 01:07:57 -------- d-----w- C:\Windows\System32\Wat
2013-08-21 00:58:38 9728 ----a-w- C:\Windows\System32\Wdfres.dll
2013-08-21 00:58:38 785512 ----a-w- C:\Windows\System32\drivers\Wdf01000.sys
2013-08-21 00:58:38 54376 ----a-w- C:\Windows\System32\drivers\WdfLdr.sys
2013-08-21 00:58:38 2560 ----a-w- C:\Windows\System32\drivers\en-US\wdf01000.sys.mui
2013-08-21 00:57:43 9515512 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2013-08-21 00:54:14 -------- d-----w- C:\Windows\System32\MRT
2013-08-21 00:50:39 46080 ----a-w- C:\Windows\System32\atmlib.dll
2013-08-21 00:50:39 367616 ----a-w- C:\Windows\System32\atmfd.dll
2013-08-21 00:50:39 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll
2013-08-21 00:50:39 295424 ----a-w- C:\Windows\SysWow64\atmfd.dll
2013-08-21 00:50:08 87040 ----a-w- C:\Windows\System32\drivers\WUDFPf.sys
2013-08-21 00:50:08 84992 ----a-w- C:\Windows\System32\WUDFSvc.dll
2013-08-21 00:50:08 198656 ----a-w- C:\Windows\System32\drivers\WUDFRd.sys
2013-08-21 00:50:08 194048 ----a-w- C:\Windows\System32\WUDFPlatform.dll
2013-08-21 00:50:07 744448 ----a-w- C:\Windows\System32\WUDFx.dll
2013-08-21 00:50:07 45056 ----a-w- C:\Windows\System32\WUDFCoinstaller.dll
2013-08-21 00:50:07 229888 ----a-w- C:\Windows\System32\WUDFHost.exe
2013-08-21 00:40:56 1192448 ----a-w- C:\Windows\System32\certutil.exe
2013-08-21 00:37:14 1887232 ----a-w- C:\Windows\System32\d3d11.dll
2013-08-21 00:37:14 1505280 ----a-w- C:\Windows\SysWow64\d3d11.dll
2013-08-21 00:31:13 72016 ----a-w- C:\Windows\System32\drivers\aswRdr2.sys
2013-08-21 00:31:13 65336 ----a-w- C:\Windows\System32\drivers\aswRvrt.sys
2013-08-21 00:31:13 189936 ----a-w- C:\Windows\System32\drivers\aswVmm.sys
2013-08-21 00:31:13 1030952 ----a-w- C:\Windows\System32\drivers\aswSnx.sys
2013-08-21 00:31:12 80816 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2013-08-21 00:30:57 41664 ----a-w- C:\Windows\avastSS.scr
2013-08-21 00:30:22 -------- d-----w- C:\Program Files\AVAST Software
2013-08-21 00:29:49 -------- d-----w- C:\ProgramData\AVAST Software
2013-08-21 00:29:25 -------- d-----w- C:\Users\Travis\AppData\Local\Google
2013-08-21 00:28:55 -------- d-----w- C:\Users\Travis\AppData\Local\Deployment
2013-08-21 00:28:55 -------- d-----w- C:\Users\Travis\AppData\Local\Apps
2013-08-15 04:23:11 -------- d-----w- C:\Program Files (x86)\Common Files\Intel Corporation
2013-08-15 04:14:15 829264 ----a-r- C:\Windows\System32\msvcr100.dll
2013-08-15 04:14:15 -------- d-----w- C:\Windows\System32\OEM
2013-08-15 04:14:15 -------- d-----w- C:\Windows\Panther
2013-08-15 04:11:52 514560 ----a-w- C:\Windows\SysWow64\qdvd.dll
2013-08-15 04:11:52 366592 ----a-w- C:\Windows\System32\qdvd.dll
2013-08-15 04:11:26 209920 ----a-w- C:\Windows\System32\profsvc.dll
2013-08-15 04:10:56 2342400 ----a-w- C:\Windows\SysWow64\msi.dll
2013-08-15 04:10:55 3216384 ----a-w- C:\Windows\System32\msi.dll
2013-08-15 04:10:29 210944 ----a-w- C:\Windows\System32\drivers\rdpwd.sys
2013-08-15 04:09:57 9216 ----a-w- C:\Windows\System32\rdrmemptylst.exe
2013-08-15 04:09:57 77312 ----a-w- C:\Windows\System32\rdpwsx.dll
2013-08-15 04:09:57 149504 ----a-w- C:\Windows\System32\rdpcorekmts.dll
2013-08-15 04:09:05 331264 ----a-w- C:\Windows\System32\drivers\IntcDAud.sys
2013-08-15 04:09:05 14848 ----a-w- C:\Windows\System32\IntcDAuC.dll
2013-08-15 04:07:32 557848 ----a-w- C:\Windows\System32\drivers\iaStor.sys
2013-08-15 04:07:05 -------- d-----w- C:\Program Files (x86)\ASM104xUSB3
2013-08-15 04:05:37 53248 ----a-w- C:\Windows\SysWow64\CSVer.dll
2013-08-15 04:05:35 -------- d-----w- C:\Intel
2013-08-15 04:05:15 878696 ----a-w- C:\Windows\System32\drivers\rtl8192Ce.sys
2013-08-15 04:05:02 -------- d-----w- C:\Program Files (x86)\Microsoft
2013-08-15 04:05:02 -------- d-----w- C:\Program Files (x86)\Common Files\Windows Live
2013-08-15 03:50:05 -------- d-----w- C:\Program Files (x86)\ESET Activation Helper (Noderator)
2013-08-15 03:48:39 -------- d-sh--w- C:\Windows\Installer
.
==================== Find3M  ====================
.
2013-08-21 01:42:51 108968 ----a-w- C:\Windows\System32\WindowsAccessBridge-64.dll
2013-08-21 01:42:50 972712 ----a-w- C:\Windows\System32\deployJava1.dll
2013-08-21 01:42:50 1093032 ----a-w- C:\Windows\System32\npDeployJava1.dll
2013-08-21 01:42:32 96168 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2013-08-21 01:42:31 867240 ----a-w- C:\Windows\SysWow64\npDeployJava1.dll
2013-08-21 01:42:31 789416 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2013-08-21 00:40:59 15604224 ----a-w- C:\Program Files (x86)\Common Files\lpuninstall.exe
2013-08-21 00:40:54 916992 ----a-w- C:\Program Files (x86)\LPToolbar_x64.dll
2013-08-21 00:40:54 6484992 ----a-w- C:\Program Files (x86)\LPPlugin.dll
2013-08-21 00:40:54 612864 ----a-w- C:\Program Files (x86)\LPToolbar.dll
2013-08-21 00:40:54 180736 ----a-w- C:\Program Files (x86)\WinBioStandalone.exe
2013-08-21 00:40:54 1425408 ----a-w- C:\Program Files (x86)\LPIEHome64.ocx
2013-08-21 00:40:54 11877888 ----a-w- C:\Program Files (x86)\LPPlugin_x64.dll
2013-08-21 00:40:54 1068544 ----a-w- C:\Program Files (x86)\LPIEHome.ocx
2013-07-25 09:25:54 1888768 ----a-w- C:\Windows\System32\WMVDECOD.DLL
2013-07-25 08:57:27 1620992 ----a-w- C:\Windows\SysWow64\WMVDECOD.DLL
2013-07-19 01:58:42 2048 ----a-w- C:\Windows\System32\tzres.dll
2013-07-19 01:41:01 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2013-07-09 05:52:52 224256 ----a-w- C:\Windows\System32\wintrust.dll
2013-07-09 05:51:16 1217024 ----a-w- C:\Windows\System32\rpcrt4.dll
2013-07-09 05:46:20 184320 ----a-w- C:\Windows\System32\cryptsvc.dll
2013-07-09 05:46:20 1472512 ----a-w- C:\Windows\System32\crypt32.dll
2013-07-09 05:46:20 139776 ----a-w- C:\Windows\System32\cryptnet.dll
2013-07-09 04:52:33 663552 ----a-w- C:\Windows\SysWow64\rpcrt4.dll
2013-07-09 04:52:10 175104 ----a-w- C:\Windows\SysWow64\wintrust.dll
2013-07-09 04:46:31 140288 ----a-w- C:\Windows\SysWow64\cryptsvc.dll
2013-07-09 04:46:31 1166848 ----a-w- C:\Windows\SysWow64\crypt32.dll
2013-07-09 04:46:31 103936 ----a-w- C:\Windows\SysWow64\cryptnet.dll
2013-07-09 04:45:07 44032 ----a-w- C:\Windows\apppatch\acwow64.dll
2013-07-06 06:03:53 1910208 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2013-06-15 04:32:16 39936 ----a-w- C:\Windows\System32\drivers\tssecsrv.sys
2013-06-05 03:34:27 3153920 ----a-w- C:\Windows\System32\win32k.sys
2013-06-04 06:00:13 624128 ----a-w- C:\Windows\System32\qedit.dll
2013-06-04 04:53:07 509440 ----a-w- C:\Windows\SysWow64\qedit.dll
.
============= FINISH: 19:37:40.92 ===============
 
 
attach.txt
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Professional 
Boot Device: \Device\HarddiskVolume1
Install Date: 8/20/2013 7:26:06 PM
System Uptime: 8/27/2013 7:20:03 PM (0 hours ago)
.
Motherboard: ECS |  | H61H2-WM
Processor: Intel® Core i5-3470 CPU @ 3.20GHz | SOCKET 0 | 3201/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 1863 GiB total, 1810.226 GiB free.
D: is CDROM ()
E: is Removable
F: is Removable
G: is Removable
H: is Removable
.
==== Disabled Device Manager Items =============
.
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Realtek PCIe GBE Family Controller
Device ID: PCI\VEN_10EC&DEV_8168&SUBSYS_31941019&REV_06\4&1AA791EF&0&00E4
Manufacturer: Realtek
Name: Realtek PCIe GBE Family Controller
PNP Device ID: PCI\VEN_10EC&DEV_8168&SUBSYS_31941019&REV_06\4&1AA791EF&0&00E4
Service: RTL8167
.
Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
Description: Officejet 6500 E710n-z
Device ID: ROOT\MULTIFUNCTION\0000
Manufacturer: HP
Name: Officejet 6500 E710n-z
PNP Device ID: ROOT\MULTIFUNCTION\0000
Service: 
.
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Realtek RTL8188CE Wireless LAN 802.11n PCI-E NIC
Device ID: PCI\VEN_10EC&DEV_8176&SUBSYS_11391A3B&REV_01\4&5BF6660&0&00E0
Manufacturer: Realtek Semiconductor Corp.
Name: Realtek RTL8188CE Wireless LAN 802.11n PCI-E NIC
PNP Device ID: PCI\VEN_10EC&DEV_8176&SUBSYS_11391A3B&REV_01\4&5BF6660&0&00E0
Service: RTL8192Ce
.
==== System Restore Points ===================
.
RP18: 8/22/2013 9:57:55 PM - Windows Update
RP19: 8/22/2013 9:58:25 PM - Windows Update
RP20: 8/24/2013 8:45:57 AM - Windows Update
RP21: 8/24/2013 9:03:16 AM - Installed TortoiseHg 2.9.0 (x64)
RP22: 8/26/2013 10:23:28 PM - Restore Operation
RP23: 8/27/2013 4:56:16 PM - Windows Update
RP24: 8/27/2013 5:03:54 PM - Installed TortoiseHg 2.9.0 (x64)
RP25: 8/27/2013 5:21:45 PM - Windows Update
RP26: 8/27/2013 5:42:18 PM - Removed Adobe Reader X (10.1.7).
RP27: 8/27/2013 7:35:24 PM - Removed HP Officejet 6500 E710n-z Product Improvement Study
.
==== Installed Programs ======================
.
7-Zip 9.20 (x64 edition)
Adobe AIR
Adobe Shockwave Player 12.0
Apple Application Support
Apple Software Update
Asmedia ASM104x USB 3.0 Host Controller Driver
avast! Free Antivirus
Beyond Compare 3.3.8
CCleaner
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition
Docklight Scripting V2.0
Dropbox
FileZilla Client 3.7.3
Foxit Reader
Google Chrome
Google Drive
Google Earth
Google Talk (remove only)
Google Update Helper
HP Officejet 6500 E710n-z Basic Device Software
HP Officejet 6500 E710n-z Help
HP Update
I.R.I.S. OCR
Intel® Control Center
Intel® Processor Graphics
Intel® Rapid Storage Technology
Java 7 Update 25
Java 7 Update 25 (64-bit)
Java Auto Updater
LastPass (uninstall only)
Malwarebytes Anti-Malware version 1.75.0.1300
Microsoft .NET Framework 4 Client Profile
Microsoft Mouse and Keyboard Center
Microsoft Office Access MUI (English) 2010
Microsoft Office Access Setup Metadata MUI (English) 2010
Microsoft Office Excel MUI (English) 2010
Microsoft Office Groove MUI (English) 2010
Microsoft Office InfoPath MUI (English) 2010
Microsoft Office Office 64-bit Components 2010
Microsoft Office OneNote MUI (English) 2010
Microsoft Office Outlook MUI (English) 2010
Microsoft Office PowerPoint MUI (English) 2010
Microsoft Office Professional Plus 2010
Microsoft Office Proof (English) 2010
Microsoft Office Proof (French) 2010
Microsoft Office Proof (Spanish) 2010
Microsoft Office Proofing (English) 2010
Microsoft Office Publisher MUI (English) 2010
Microsoft Office Shared 64-bit MUI (English) 2010
Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
Microsoft Office Shared MUI (English) 2010
Microsoft Office Shared Setup Metadata MUI (English) 2010
Microsoft Office Word MUI (English) 2010
Microsoft Silverlight
Microsoft Visio Viewer 2013
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
MPLAB X IDE v1.85
MPLAB XC16 C Compiler
PuTTY version 0.63
Python 2.7.5
QuickTime
Realtek High Definition Audio Driver
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2835393)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628v2)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition
SUPERAntiSpyware
swMSM
TortoiseHg 2.9.0 (x64)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939)
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition
Update for Microsoft Office 2010 (KB2825640) 32-Bit Edition
VLC media player 2.0.8
.
==== Event Viewer Messages From Past Week ========
.
8/27/2013 7:20:18 PM, Error: Microsoft-Windows-WLAN-AutoConfig [10000]  - WLAN Extensibility Module has failed to start. Module Path: C:\Windows\system32\Rtlihvs.dll Error Code: 126
8/22/2013 9:58:53 PM, Error: Microsoft-Windows-WindowsUpdateClient [20]  - Installation Failure: Windows failed to install the following update with error 0x80070103: SIIG, Inc. - Bus Controllers and Ports, Other hardware - CyberSerial 16C950.
8/20/2013 8:10:24 PM, Error: Service Control Manager [7023]  - 
8/20/2013 7:57:44 PM, Error: Microsoft-Windows-WindowsUpdateClient [20]  - Installation Failure: Windows failed to install the following update with error 0x80070643: Internet Explorer 10 for Windows 7 for x64-based Systems.
.
==== End Of File ===========================
 

 

Link to post
Share on other sites

Welcome to the forum.

Please download and run RogueKiller 32 Bit to your desktop.

RogueKiller 64 Bit <---use this one for 64 bit systems

Quit all running programs.

For Windows XP, double-click to start.

For Vista or Windows 7-8, do a right-click on the program, select Run as Administrator to start, & when prompted Allow to run.

Click Scan to scan the system.

When the scan completes > Close out the program > Don't Fix anything!

Don't run any other options, they're not all bad!!!!!!!

Post back the report which should be located on your desktop.

(please don't put logs in code or quotes)

P2P/Piracy Warning:

1. If you're using Peer 2 Peer software such as uTorrent, BitTorrent or similar you must either fully uninstall it or completely disable it from running while being assisted here.

Failure to remove or disable such software will result in your topic being closed and no further assistance being provided.

2. If you have illegal/cracked software, cracks, keygens, Adobe host file, etc. on the system, please remove or uninstall them now and read the policy on Piracy.

Failure to remove such software will result in your topic being closed and no further assistance being provided.

MrC

Note:

Please read all of my instructions completely including these.

Make sure you're subscribed to this topic: Click on the Follow This Topic Button (at the top right of this page), make sure that the Receive notification box is checked and that it is set to Instantly

Removing malware can be unpredictable...unlikely but things can go very wrong! Backup any files that cannot be replaced. You can copy them to a CD/DVD, external drive or a pen drive

<+>Please don't run any other scans, download, install or uninstall any programs while I'm working with you.

<+>The removal of malware isn't instantaneous, please be patient.

<+>When we are done, I'll give to instructions on how to cleanup all the tools and logs

<+>Please stick with me until I give you the "all clear" and Please don't waste my time by leaving before that.

------->Your topic will be closed if you haven't replied within 3 days!<--------

(If I don't respond within 24 hours, please send me a PM)

Link to post
Share on other sites
RogueKiller V8.6.7 _x64_ [Aug 28 2013] by Tigzy

mail : tigzyRK<at>gmail<dot>com




 

Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version

Started in : Normal mode

User : Travis [Admin rights]

Mode : Scan -- Date : 08/28/2013 16:37:11

| ARK || FAK || MBR |

 

¤¤¤ Bad processes : 0 ¤¤¤

 

¤¤¤ Registry Entries : 4 ¤¤¤

[HJ DESK] HKCU\[...]\ClassicStartMenu : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND

[HJ DESK] HKCU\[...]\ClassicStartMenu : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

[HJ DESK] HKCU\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND

[HJ DESK] HKCU\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

 

¤¤¤ Scheduled tasks : 0 ¤¤¤

 

¤¤¤ Startup Entries : 0 ¤¤¤

 

¤¤¤ Web browsers : 0 ¤¤¤

 

¤¤¤ Particular Files / Folders: ¤¤¤

 

¤¤¤ Driver : [NOT LOADED 0x0] ¤¤¤

 

¤¤¤ External Hives: ¤¤¤

 

¤¤¤ Infection :  ¤¤¤

 

¤¤¤ HOSTS File: ¤¤¤

--> %SystemRoot%\System32\drivers\etc\hosts

 

 

 

 

¤¤¤ MBR Check: ¤¤¤

 

+++++ PhysicalDrive0: TOSHIBA DT01ACA200 +++++

--- User ---

[MBR] 48d5aa151d774c82563fadc74d7772bd

[bSP] d63f79e05af06798299a561ef50e6cfa : Empty MBR Code

Partition table:

0 - [XXXXXX] UNKNOWN (0x00) [VISIBLE] Offset (sectors): 1 | Size: 2097152 Mo

User = LL1 ... OK!

User = LL2 ... OK!

 

Finished : << RKreport[0]_S_08282013_163711.txt >>
Link to post
Share on other sites

Give this a try:

Please download AdwCleaner by Xplode and save to your Desktop.

  • Double click on AdwCleaner.exe to run the tool.

    Vista/Windows 7/8 users right-click and select Run As Administrator

  • Click on the Scan button.
  • AdwCleaner will begin...be patient as the scan may take some time to complete.
  • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R0].txt) will open in Notepad for review.
  • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.
If you agree with everything listed to be removed in the folders section...........

Double click on AdwCleaner.exe to run the tool again.

  • Click on the Scan button.
  • AdwCleaner will begin to scan your computer like it did before.
  • After the scan has finished...
  • This time click on the Clean button.
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
  • After rebooting, a logfile report (AdwCleaner[s0].txt) will open automatically.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of that logfile will also be saved in the C:\AdwCleaner folder.
Then..................

thisisujrt.gif Please download Junkware Removal Tool to your desktop.

  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
Last.......

Open up Malwarebytes > Settings Tab > Scanner Settings > Under action for PUP > Select Show in Results List and Check for removal.

Please Update and run a Quick Scan with Malwarebytes Anti-Malware, post the report.

Make sure that everything is checked, and click Remove Selected.

Please let me know how computer is running now, MrC

Link to post
Share on other sites



# AdwCleaner v3.001 - Report created 28/08/2013 at 16:50:58

# Updated 24/08/2013 by Xplode

# Operating System : Windows 7 Professional Service Pack 1 (64 bits)

# Username : Travis - TLH-ENG-PC

# Running from : C:\Users\Travis\Desktop\AdwCleaner.exe

# Option : Scan

 

***** [ Services ] *****

 

 

***** [ Files / Folders ] *****

 

 

***** [ Shortcuts ] *****

 

 

***** [ Registry ] *****

 

 

***** [ Browsers ] *****

 

-\\ Internet Explorer v10.0.9200.16660

 

 

-\\ Google Chrome v29.0.1547.57

 

[ File : C:\Users\Travis\AppData\Local\Google\Chrome\User Data\Default\preferences ]

 

 

*************************

 

AdwCleaner[R0].txt - [627 octets] - [28/08/2013 16:50:58]

 

########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [686 octets] ##########


 

# AdwCleaner v3.001 - Report created 28/08/2013 at 16:53:10

# Updated 24/08/2013 by Xplode

# Operating System : Windows 7 Professional Service Pack 1 (64 bits)

# Username : Travis - TLH-ENG-PC

# Running from : C:\Users\Travis\Desktop\AdwCleaner.exe

# Option : Clean

 

***** [ Services ] *****

 

 

***** [ Files / Folders ] *****

 

 

***** [ Shortcuts ] *****

 

 

***** [ Registry ] *****

 

 

***** [ Browsers ] *****

 

-\\ Internet Explorer v10.0.9200.16660

 

 

-\\ Google Chrome v29.0.1547.57

 

[ File : C:\Users\Travis\AppData\Local\Google\Chrome\User Data\Default\preferences ]

 

 

*************************

 

AdwCleaner[R0].txt - [765 octets] - [28/08/2013 16:50:58]

AdwCleaner[s0].txt - [687 octets] - [28/08/2013 16:53:10]

 

########## EOF - C:\AdwCleaner\AdwCleaner[s0].txt - [746 octets] ##########


 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Junkware Removal Tool (JRT) by Thisisu

Version: 5.5.4 (08.22.2013:1)

OS: Windows 7 Professional x64

Ran by Travis on Wed 08/28/2013 at 16:57:37.32

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 

 

 

 

~~~ Services

 

 

 

~~~ Registry Values

 

 

 

~~~ Registry Keys

 

 

 

~~~ Files

 

 

 

~~~ Folders

 

 

 

~~~ Event Viewer Logs were cleared

 

 

 

 

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Scan was completed on Wed 08/28/2013 at 17:01:03.47

End of JRT log

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 


 

Malwarebytes Anti-Malware 1.75.0.1300

www.malwarebytes.org

 

Database version: v2013.08.28.08

 

Windows 7 Service Pack 1 x64 NTFS

Internet Explorer 10.0.9200.16660

Travis :: TLH-ENG-PC [administrator]

 

8/28/2013 5:03:26 PM

mbam-log-2013-08-28 (17-03-26).txt

 

Scan type: Quick scan

Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM

Scan options disabled: P2P

Objects scanned: 215754

Time elapsed: 1 minute(s), 20 second(s)

 

Memory Processes Detected: 0

(No malicious items detected)

 

Memory Modules Detected: 0

(No malicious items detected)

 

Registry Keys Detected: 0

(No malicious items detected)

 

Registry Values Detected: 0

(No malicious items detected)

 

Registry Data Items Detected: 0

(No malicious items detected)

 

Folders Detected: 0

(No malicious items detected)

 

Files Detected: 0

(No malicious items detected)

 

(end)
Link to post
Share on other sites

After all these steps, there is no change in behavior.

 

Spigot still has the browser hijacked and lastpass still doesn't work.

Lastpass not working may be because I did a system restore.

I noticed some other programs after the system restore which do not work.

I think an uninstall/reinstall cycle on those programs will probably fix them up.

 

At this point I'm afraid to use lastpass because I fear a keylogger or spyware may be still infecting the PC.

At least until we can get the browser hijack cleaned up.

 

Thanks,

Travis

Link to post
Share on other sites

Why did you use system restore? You can un-do it if needed.

------------------------------

At this point I'm afraid to use lastpass because I fear a keylogger or spyware may be still infecting the PC.

You never mentioned anything about "fear a keylogger or spyware may be still infecting the PC" until now.
 

There's no indication of such on the system.

 

When I open chrome, it goes to a yahoo search page that has the term spigot in it.
My lastpass browser extension also fails to load.

 

 

At least until we can get the browser hijack cleaned up.

Yes we can, as I say in my opening statement:

<+>The removal of malware isn't instantaneous, please be patient.

----------------------------------------------

Chrome sometimes has to be manually fixed, the new version also has a Reset Button.
Go to Settings > Advanced Settings > It's at the bottom of the page.

For Chrome...........

First make sure you have the latest version of Chrome:
Open up Chrome > Click on the 3 bars in the upper right hand corner
Click on About Google Chrome
If there's an update available it will automatically update


Next:
Go to Tools > Clear Browser Data
Put a check next to all of these:

  • Clear browsing history
  • Clear download history
  • Empty the cache

Click "Clear Browsing Data"

-------------------------------

Next:
Click the Chrome menu on the browser toolbar.
Select Settings.
In the "Search" section, click Manage search engines.
Check if (Default) is displayed next to your preferred search engine. If not, mouse over it and click Make default.
Mouse over any other suspicious search engine entries that are not familiar and click X to remove them.

-------------------------------------

Click the Chrome menu .
Select Settings.
In the "On startup" section, select Open a specific page or set of pages.
Click Set pages. (in blue to the right)
Remove any unfamiliar pages.

-----------------------

Click the Chrome menu .
Select Settings.
In the "Appearance" section, if the "Show Home button" checkbox is selected, see if the page listed below is the home page you’d like to use.
If the page isn't the home page you'd like to use, click Change and select your preferred page.

-------------------------


Carefully check for any odd extensions or plugins: (it's a good idea to disable them all and see if you're still redirected and then add each one back until you find the culprit)

Type the following into the address box and hit Enter:

chrome:plugins

Do the same for:

chrome:extensions

Let me know.....MrC

Link to post
Share on other sites

I used system restore yesterday when I first found out about the browser hijack, thinking it would be the easiest way to clean the problem.

I have no evidence of a keylogger but was extra paranoid because of the browser hijack.

 

I appreciate the quick response! Much appreciated and I will be donating.

 

I followed all the steps, and the update to chrome is the step that fixed the problem.

 

The browser hijack is now gone.

 

Thanks so much!!!

Link to post
Share on other sites

Good......

Lets check your computers security before you go and we have a little cleanup to do also:

Download Security Check by screen317 from HERE or HERE.

  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • If you get Unsupported operating system. Aborting now, just reboot and try again.
  • A Notepad document should open automatically called checkup.txt.
  • Please Post the contents of that document.
  • Do Not Attach It!!!
MrC
Link to post
Share on other sites
 Results of screen317's Security Check version 0.99.73  

 Windows 7 Service Pack 1 x64 (UAC is enabled)  

 Internet Explorer 10  

``````````````Antivirus/Firewall Check:`````````````` 

 Windows Security Center service is not running! This report may not be accurate! 

 Windows Firewall Enabled!  

avast! Antivirus   

 Antivirus up to date!   

`````````Anti-malware/Other Utilities Check:````````` 

 Malwarebytes Anti-Malware version 1.75.0.1300  

 Java 7 Update 25  

 Google Chrome 29.0.1547.57  

 Google Chrome 29.0.1547.62  

````````Process Check: objlist.exe by Laurent````````  

 AVAST Software Avast AvastSvc.exe  

 AVAST Software Avast AvastUI.exe  

`````````````````System Health check````````````````` 

 Total Fragmentation on Drive C: 0% 

````````````````````End of Log`````````````````````` 
Link to post
Share on other sites

Looks OK.......

A little clean up to do....

Please Uninstall ComboFix: (if you used it)

Press the Windows logo key + R to bring up the "run box"

Copy and paste next command in the field:

ComboFix /uninstall

Make sure there's a space between Combofix and /

cf2.jpg

Then hit enter.

This will uninstall Combofix, delete its related folders and files, hide file extensions, hide the system/hidden files and clears System Restore cache and create new Restore point

(If that doesn't work.....you can simply rename ComboFix.exe to Uninstall.exe and double click it to complete the uninstall or download and run the uninstaller)

---------------------------------

If you used FRST:

Download the fixlist.txt to the same folder as FRST.

Run FRST and click Fix only once and wait

That will delete the quarantine folder created by FRST.

-----------------------------

If you used DeFogger to disable your CD Emulation drivers, please re-enable them.

-------------------------------

Please download OTC to your desktop.

http://oldtimer.geekstogo.com/OTC.exe

Double-click OTC to run it. (Vista and up users, please right click on OTC and select "Run as an Administrator")

Click on the CleanUp! button and follow the prompts.

(If you get a warning from your firewall or other security programs regarding OTC attempting to contact the Internet, please allow the connection.)

You will be asked to reboot the machine to finish the Cleanup process, choose Yes.

After the reboot all the tools we used should be gone.

Note: Some more recently created tools may not yet be removed by OTC. Feel free to manually delete any tools it leaves behind.

Any other programs or logs you can manually delete.

IE: RogueKiller.exe, RKreport.txt, RK_Quarantine folder, C:\FRST, MBAR, etc....AdwCleaner > just run the program and click uninstall.

-------------------------------

Any questions...please post back.

If you think I've helped you, please leave a comment > click on my avatar picture > click Profile Feed.

Take a look at My Preventive Maintenance to avoid being infected again.

Good Luck and Thanks for using the forum, MrC

Link to post
Share on other sites
Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    No registered users viewing this page.

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.