Jump to content

IP Successfully blocked

Recommended Posts

Hey there, I'm new to this forum and would appreciate any help. Malwarebytes repeatedly brings up the message that it has blocked the following IP:


Malwarebytes report:

2013/11/19 21:50:22 GMT ROB-HP Rob IP-BLOCK (Type: outgoing, Port: 53046, Process: pmb.exe)
2013/11/19 21:50:50 GMT ROB-HP Rob MESSAGE Starting database refresh
2013/11/19 21:50:50 GMT ROB-HP Rob MESSAGE Stopping IP protection
2013/11/19 21:50:50 GMT ROB-HP Rob MESSAGE IP Protection stopped successfully
2013/11/19 21:50:58 GMT ROB-HP Rob MESSAGE Database refreshed successfully
2013/11/19 21:50:58 GMT ROB-HP Rob MESSAGE Starting IP protection
2013/11/19 21:50:59 GMT ROB-HP Rob MESSAGE IP Protection started successfully
2013/11/19 21:56:35 GMT ROB-HP Rob IP-BLOCK (Type: outgoing, Port: 53601, Process: pmb.exe)
2013/11/19 22:36:35 GMT ROB-HP Rob IP-BLOCK (Type: outgoing, Port: 56722, Process: pmb.exe)
2013/11/19 22:40:12 GMT ROB-HP Rob IP-BLOCK (Type: outgoing, Port: 56962, Process: pmb.exe)
2013/11/19 23:02:30 GMT ROB-HP Rob IP-BLOCK (Type: outgoing, Port: 59944, Process: pmb.exe)
DDS (Ver_2012-11-20.01) - NTFS_AMD64 
Internet Explorer: 9.0.8112.16421  BrowserJavaVersion: 10.45.2
Run by Rob at 23:13:29 on 2013-11-19
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.44.1033.18.6101.4344 [GMT 0:00]
AV: Kaspersky Internet Security *Disabled/Updated* {179979E8-273D-D14E-0543-2861940E4886}
SP: Kaspersky Internet Security *Disabled/Updated* {ACF8980C-0107-DEC0-3FF3-1313EF89023B}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Internet Security *Disabled* {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD}
============== Running Processes ===============
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\IDT\WDM\STacSV64.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\PDF Complete\pdfsvc.exe
C:\Program Files (x86)\Ralink\Common\RaRegistry.exe
C:\Program Files (x86)\Ralink\Common\RaRegistry64.exe
C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files\IDT\WDM\Beats64.exe
C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\klwtbws.exe
C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\GCalService.exe
C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\HPTouchSmartSyncCalReminderApp.exe
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\SeaPort.exe
C:\Windows\System32\svchost.exe -k swprv
============== Pseudo HJT Report ===============
mWinlogon: Userinit = userinit.exe
BHO: Content Blocker Plugin: {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll
BHO: Virtual Keyboard Plugin: {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
BHO: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Safe Money Plugin: {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll
BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BingExt.dll
BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO: URL Advisor Plugin: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - 
uRun: [skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
mRun: [uSB3MON] "C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
mRun: [startCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [HP Software Update] c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
mRun: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe
mRun: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ie_banner_deny.htm
IE: {0C4CC089-D306-440D-9772-464E226F6539} - {0BA14598-4178-4CE5-B1F1-B5C6408A3F2E} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll
TCP: NameServer =
TCP: Interfaces\{6114287C-5D63-48E1-BF1A-CA1116868F30} : DHCPNameServer =
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
mASetup: {438363A8-F486-4C37-834C-4955773CB3D3} - msiexec /fu {438363A8-F486-4C37-834C-4955773CB3D3} /qn
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: Content Blocker Plugin: {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll
x64-BHO: Virtual Keyboard Plugin: {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Safe Money Plugin: {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll
x64-BHO: Skype add-on for Internet Explorer: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
x64-BHO: URL Advisor Plugin: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll
x64-Run: [sysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe
x64-Run: [beatsOSDApp] C:\Program Files\IDT\WDM\beats64.exe
x64-Run: [HPSYSDRV] C:\Program Files (x86)\Hewlett-Packard\HP Odometer\HPSYSDRV.EXE
x64-IE: {0C4CC089-D306-440D-9772-464E226F6539} - {0BA14598-4178-4CE5-B1F1-B5C6408A3F2E} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
x64-IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
x64-IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll
x64-Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-SSODL: WebCheck - <orphaned>
============= SERVICES / DRIVERS ===============
R0 iusb3hcs;Intel® USB 3.0 Host Controller Switch Driver;C:\Windows\System32\drivers\iusb3hcs.sys [2011-12-5 16152]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\System32\drivers\klim6.sys [2013-10-9 29792]
R1 klpd;klpd;C:\Windows\System32\drivers\klpd.sys [2013-4-12 15456]
R1 kltdi;kltdi;C:\Windows\System32\drivers\kltdi.sys [2013-5-14 55904]
R1 kneps;kneps;C:\Windows\System32\drivers\kneps.sys [2013-6-6 178784]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2012-2-11 235520]
R2 AVP;Kaspersky Anti-Virus Service;C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [2013-10-9 214512]
R2 CalendarSynchService;CalendarSynchService;C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\GCalService.exe [2011-8-16 16384]
R2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe [2011-9-10 86072]
R2 HPAuto;HP Auto;C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe [2011-2-17 682040]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-3-29 94264]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-11-19 418376]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-11-19 701512]
R2 pdfcDispatcher;PDF Document Manager;C:\Program Files (x86)\PDF Complete\pdfsvc.exe [2013-1-7 1134584]
R2 RalinkRegistryWriter;RalinkRegistryWriter;C:\Program Files (x86)\Ralink\Common\RaRegistry.exe [2013-1-7 372736]
R2 RalinkRegistryWriter64;RalinkRegistryWriter64;C:\Program Files (x86)\Ralink\Common\RaRegistry64.exe [2013-1-7 447488]
R2 Skype C2C Service;Skype C2C Service;C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2013-10-9 3275136]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2011-12-6 95248]
R3 BBUpdate;BBUpdate;C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\SeaPort.EXE [2012-2-14 240408]
R3 iusb3hub;Intel® USB 3.0 Hub Driver;C:\Windows\System32\drivers\iusb3hub.sys [2011-12-5 355096]
R3 iusb3xhc;Intel® USB 3.0 eXtensible Host Controller Driver;C:\Windows\System32\drivers\iusb3xhc.sys [2011-12-5 785688]
R3 klkbdflt;Kaspersky Lab KLKBDFLT;C:\Windows\System32\drivers\klkbdflt.sys [2013-10-9 29280]
R3 klmouflt;Kaspersky Lab KLMOUFLT;C:\Windows\System32\drivers\klmouflt.sys [2013-10-9 29280]
R3 L1C;NDIS Miniport Driver for Atheros AR81xx PCI-E Ethernet Controller;C:\Windows\System32\drivers\L1C62x64.sys [2011-9-19 108656]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2013-11-19 25928]
R3 netr28x;Ralink 802.11n Extensible Wireless Driver;C:\Windows\System32\drivers\netr28x.sys [2013-1-7 1857600]
S2 BBSvc;BingBar Service;C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BBSvc.EXE [2012-2-14 193816]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 RaMediaServer;Ralink UPnP Media Server;C:\Program Files (x86)\Ralink\Common\RaMediaServer.exe [2013-1-7 625728]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-9-5 171680]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-21 31232]
S4 klflt;klflt;C:\Windows\System32\drivers\klflt.sys [2013-11-19 112224]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-23 57184]
=============== Created Last 30 ================
2013-11-20 03:42:15 -------- d-----w- C:\ProgramData\Recovery
2013-11-19 23:06:07 -------- d-----w- C:\ProgramData\Oracle
2013-11-19 23:05:53 96168 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2013-11-19 21:20:02 68616 ----a-w- C:\Windows\SysWow64\XAPOFX1_1.dll
2013-11-19 21:20:01 509448 ----a-w- C:\Windows\SysWow64\XAudio2_2.dll
2013-11-19 21:20:01 467984 ----a-w- C:\Windows\SysWow64\d3dx10_39.dll
2013-11-19 21:20:01 3851784 ----a-w- C:\Windows\SysWow64\D3DX9_39.dll
2013-11-19 21:20:01 1493528 ----a-w- C:\Windows\SysWow64\D3DCompiler_39.dll
2013-11-19 21:19:18 -------- d-sh--w- C:\Windows\SysWow64\AI_RecycleBin
2013-11-19 21:19:17 -------- d-----w- C:\Riot Games
2013-11-19 21:18:29 -------- d-----w- C:\Users\Rob\AppData\Local\PMB Files
2013-11-19 21:18:27 -------- d-----w- C:\ProgramData\PMB Files
2013-11-19 21:18:24 -------- d-----w- C:\Program Files (x86)\Pando Networks
2013-11-19 21:18:00 -------- d-----w- C:\Users\Rob\AppData\Roaming\Riot Games
2013-11-19 21:10:25 -------- d-----r- C:\Program Files (x86)\Skype
2013-11-19 21:06:39 -------- d-----w- C:\Users\Rob\AppData\Local\Google
2013-11-19 21:06:17 -------- d-----w- C:\Users\Rob\AppData\Local\Deployment
2013-11-19 21:06:17 -------- d-----w- C:\Users\Rob\AppData\Local\Apps
2013-11-19 20:32:28 -------- d-----w- C:\Users\Rob\AppData\Roaming\Malwarebytes
2013-11-19 20:32:19 -------- d-----w- C:\ProgramData\Malwarebytes
2013-11-19 20:32:18 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys
2013-11-19 20:32:18 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-11-19 20:32:06 -------- d-----w- C:\Users\Rob\AppData\Local\Programs
2013-11-19 20:22:04 826880 ----a-w- C:\Windows\SysWow64\rdpcore.dll
2013-11-19 20:22:04 23552 ----a-w- C:\Windows\System32\drivers\tdtcp.sys
2013-11-19 20:22:04 210944 ----a-w- C:\Windows\System32\drivers\rdpwd.sys
2013-11-19 20:22:04 1031680 ----a-w- C:\Windows\System32\rdpcore.dll
2013-11-19 20:20:35 110176 ----a-w- C:\Windows\System32\klfphc.dll
2013-11-19 20:20:11 -------- d-----w- C:\Windows\ELAMBKUP
2013-11-19 20:20:09 -------- d-----w- C:\ProgramData\Kaspersky Lab
2013-11-19 20:20:09 -------- d-----w- C:\Program Files (x86)\Kaspersky Lab
2013-11-19 20:19:59 112224 ----a-w- C:\Windows\System32\drivers\klflt.sys
2013-11-19 20:16:06 2622464 ----a-w- C:\Windows\System32\wucltux.dll
2013-11-19 20:16:02 99840 ----a-w- C:\Windows\System32\wudriver.dll
2013-11-19 20:15:57 36864 ----a-w- C:\Windows\System32\wuapp.exe
2013-11-19 20:15:57 186752 ----a-w- C:\Windows\System32\wuwebv.dll
2013-11-19 20:13:49 -------- d-----w- C:\Users\Rob\AppData\Local\ATI
2013-11-19 20:09:49 -------- d-----w- C:\Users\Rob\AppData\Local\PDFC
2013-11-19 20:09:26 -------- d-----w- C:\Users\Rob\AppData\Local\VirtualStore
2013-11-19 20:08:08 -------- d-----w- C:\Users\Rob\AppData\Local\TouchSmartData
==================== Find3M  ====================
2013-11-19 20:24:15 458336 ----a-w- C:\Windows\System32\drivers\kl1.sys
2013-10-09 11:46:16 29792 ----a-w- C:\Windows\System32\drivers\klim6.sys
2013-10-09 11:46:16 29280 ----a-w- C:\Windows\System32\drivers\klmouflt.sys
2013-10-09 11:46:16 29280 ----a-w- C:\Windows\System32\drivers\klkbdflt.sys
============= FINISH: 23:13:35.59 ===============


Link to post
Share on other sites

Sure, here it is:


DDS (Ver_2012-11-20.01)
Microsoft Windows 7 Home Premium 
Boot Device: \Device\HarddiskVolume1
Install Date: 19/11/2013 20:06:22
System Uptime: 19/11/2013 21:13:45 (2 hours ago)
Processor: Intel® Core i7-3770 CPU @ 3.40GHz |  | 3401/29285mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 921 GiB total, 886.972 GiB free.
D: is FIXED (NTFS) - 10 GiB total, 1.228 GiB free.
E: is CDROM ()
F: is Removable
G: is Removable
H: is Removable
I: is Removable
==== Disabled Device Manager Items =============
==== System Restore Points ===================
RP5: 19/11/2013 20:12:04 - Initial Restore Point
RP6: 19/11/2013 20:15:14 - Windows Update
RP7: 19/11/2013 20:22:07 - Windows Update
RP8: 19/11/2013 21:18:32 - Installed League of Legends
RP9: 19/11/2013 21:19:21 - Installed DirectX
RP10: 19/11/2013 23:04:58 - Installed Java 7 Update 45
==== Installed Programs ======================
Adobe Flash Player 11 ActiveX (x64)
AMD Catalyst Install Manager
Bing Bar
Bubble Wrap
Catalyst Control Center
Catalyst Control Center - Branding
Catalyst Control Center Graphics Previews Common
Catalyst Control Center InstallProxy
Catalyst Control Center Localization All
Catalyst Control Center Profiles Desktop
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help Czech
CCC Help Danish
CCC Help Dutch
CCC Help English
CCC Help Finnish
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Norwegian
CCC Help Polish
CCC Help Portuguese
CCC Help Russian
CCC Help Spanish
CCC Help Swedish
CCC Help Thai
CCC Help Turkish
DirectX for Managed Code Update (Summer 2004)
Google Chrome
Google Update Helper
Hewlett-Packard ACLM.NET v1.1.2.0
HP Auto
HP Calendar
HP Clock
HP Customer Experience Enhancements
HP LinkUp
HP Magic Canvas
HP Magic Canvas Tutorials
HP Notes
HP Odometer
HP Setup
HP Support Assistant
HP Support Information
HP TouchSmart Background - Beats
HP TouchSmart RecipeBox
HP Update
Intel® Management Engine Components
Intel® USB 3.0 eXtensible Host Controller Driver
Java 7 Update 45
Java Auto Updater
Junk Mail filter update
Kaspersky Internet Security
League of Legends
Malwarebytes Anti-Malware version
Mesh Runtime
Metric Converter
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Extended
Microsoft Application Error Reporting
Microsoft Mathematics
Microsoft Office 2010
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable (x64)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
Pando Media Booster
PDF Complete Corporate Edition
PlayReady PC Runtime amd64
Ralink 802.11n Wireless LAN Card
Recovery Manager
Remote Graphics Receiver
Skype Click to Call
Skype™ 6.10
Tap Tap Bear
Windows Live Communications Platform
Windows Live Essentials
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Language Selector
Windows Live Mail
Windows Live Mesh
Windows Live Mesh ActiveX Control for Remote Connections
Windows Live Messenger
Windows Live MIME IFilter
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live Remote Client
Windows Live Remote Client Resources
Windows Live Remote Service
Windows Live Remote Service Resources
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
WinZip 16.0
==== Event Viewer Messages From Past Week ========
19/11/2013 21:15:02, Error: Service Control Manager [7009]  - A timeout was reached (30000 milliseconds) while waiting for the Ralink UPnP Media Server service to connect.
19/11/2013 20:24:23, Error: Service Control Manager [7006]  - The ScRegSetValueExW call failed for FailureActions with the following error:  Access is denied.
==== End Of File ===========================
Link to post
Share on other sites

Uninstall this Pando Media Booster Re-boot when complete,




Download Farbar Recovery Scan Tool and save it to your desktop.


Note: You need to run the version compatible with your system (32 bit or 64 bit). If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.

Link to post
Share on other sites

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 18-11-2013

Ran by Rob (administrator) on ROB-HP on 20-11-2013 00:18:32

Running from C:\Users\Rob\Downloads

Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US)

Internet Explorer Version 9

Boot Mode: Normal


==================== Processes (Whitelisted) =================


(AMD) C:\Windows\system32\atiesrxx.exe

(IDT, Inc.) C:\Program Files\IDT\WDM\STacSV64.exe

(AMD) C:\Windows\system32\atieclxx.exe

(Microsoft Corporation) C:\Windows\system32\WLANExt.exe

(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe

(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe

(Hewlett-Packard ) C:\Program Files\IDT\WDM\Beats64.exe

(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe

(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe

(Intel Corporation) C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe

(Hewlett-Packard) C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe

(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

(Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BBSvc.exe

(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe

(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe

(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe

(PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe

(Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaRegistry.exe

(Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaRegistry64.exe

(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe

(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe

(Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe

(Skype Technologies) C:\Program Files (x86)\Skype\Updater\Updater.exe

(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe

(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\wmi64.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\klwtblfs.exe

(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe

(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe


==================== Registry (Whitelisted) ==================


HKLM\...\Run: [sysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [1425408 2012-03-30] (IDT, Inc.)

HKLM\...\Run: [beatsOSDApp] - C:\Program Files\IDT\WDM\Beats64.exe [37888 2012-03-30] (Hewlett-Packard )

HKLM\...\Run: [HPSYSDRV] - C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe [62768 2008-11-20] (Hewlett-Packard)

HKCU\...\Run: [skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20549280 2013-10-21] (Skype Technologies S.A.)

HKLM-x32\...\Run: [uSB3MON] - C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291096 2011-12-05] (Intel Corporation)

HKLM-x32\...\Run: [startCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [343168 2012-02-11] (Advanced Micro Devices, Inc.)

HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe [49208 2011-05-10] (Hewlett-Packard)

HKLM-x32\...\Run: [] - [x]

HKLM-x32\...\Run: [PDF Complete] - C:\Program Files (x86)\PDF Complete\pdfsty.exe [684024 2012-04-04] (PDF Complete Inc)

HKLM-x32\...\Run: [sunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)


==================== Internet (Whitelisted) ====================


HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.uk.msn.com/HPDSK/2

HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com/HPDSK/2

HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com/HPDSK/2

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.uk.msn.com/HPDSK/2

HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com/HPDSK/2

HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://g.uk.msn.com/HPDSK/2

StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe

SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox

SearchScopes: HKLM - {5B3938C2-BB61-44EA-9FBE-CB69BA36BD43} URL = http://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk3-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}

SearchScopes: HKLM - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = http://uk.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF

SearchScopes: HKLM - {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = http://en.wikipedia.org/wiki/Special:Search?search={searchTerms}

SearchScopes: HKLM-x32 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox

SearchScopes: HKLM-x32 - {5B3938C2-BB61-44EA-9FBE-CB69BA36BD43} URL = http://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk3-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}

SearchScopes: HKLM-x32 - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = http://uk.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF

SearchScopes: HKLM-x32 - {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = http://en.wikipedia.org/wiki/Special:Search?search={searchTerms}

SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox

SearchScopes: HKCU - {5B3938C2-BB61-44EA-9FBE-CB69BA36BD43} URL = http://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk3-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}

SearchScopes: HKCU - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = http://uk.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF

SearchScopes: HKCU - {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = http://en.wikipedia.org/wiki/Special:Search?search={searchTerms}

BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)

BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)

BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)

BHO: Skype add-on for Internet Explorer - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)

BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)

BHO-x32: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)

BHO-x32: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

BHO-x32: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)

BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)

BHO-x32: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)

BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)

BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BingExt.dll (Microsoft Corporation.)

BHO-x32: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)

BHO-x32: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)

Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BingExt.dll (Microsoft Corporation.)

Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File

Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)

Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)

Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)

Tcpip\Parameters: [DhcpNameServer]




CHR RestoreOnStartup: "https://www.google.com/"

CHR Extension: (Google Docs) - C:\Users\Rob\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0

CHR Extension: (Google Drive) - C:\Users\Rob\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0

CHR Extension: (YouTube) - C:\Users\Rob\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0

CHR Extension: (Google Search) - C:\Users\Rob\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\

CHR Extension: (Kaspersky URL Advisor) - C:\Users\Rob\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj\

CHR Extension: (AdBlock) - C:\Users\Rob\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.14_0

CHR Extension: (Dangerous Websites Blocker) - C:\Users\Rob\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail\

CHR Extension: (Google Wallet) - C:\Users\Rob\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\

CHR Extension: (Gmail) - C:\Users\Rob\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1

CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\urladvisor.crx

CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\online_banking_chrome.crx

CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\content_blocker_chrome.crx

CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\virtkbd.crx

CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx

CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\ab.crx


==================== Services (Whitelisted) =================


R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [214512 2013-10-09] (Kaspersky Lab ZAO)

R2 HPAuto; C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe [682040 2011-02-17] (Hewlett-Packard)

R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)

R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)

R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1134584 2012-04-04] (PDF Complete Inc)

S2 RaMediaServer; C:\Program Files (x86)\Ralink\Common\RaMediaServer.exe [625728 2011-08-19] ()


==================== Drivers (Whitelisted) ====================


R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2013-11-19] (Kaspersky Lab ZAO)

S4 klflt; C:\Windows\System32\DRIVERS\klflt.sys [112224 2013-06-08] (Kaspersky Lab ZAO)

R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [623200 2013-11-19] (Kaspersky Lab ZAO)

R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29792 2013-10-09] (Kaspersky Lab ZAO)

R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29280 2013-10-09] (Kaspersky Lab ZAO)

R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-10-09] (Kaspersky Lab ZAO)

R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO)

R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [55904 2013-05-14] (Kaspersky Lab ZAO)

R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178784 2013-06-06] (Kaspersky Lab ZAO)

R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)


==================== NetSvcs (Whitelisted) ===================



==================== One Month Created Files and Folders ========


2013-11-20 03:59 - 2013-11-19 20:06 - 00000000 __RSH C:\Windows\SysWOW64\Drivers\103C_HP_cPC_h9-1230ea_Y53316J_0U_QCZC2293K88_E12WE2RRW602_4A_I2AD5_SPEGATRON CORPORATION_V1.03_B7.14_T120522_W73-1_L409_M6102_J1000_7Intel_8506_93.40_#130107_N19691091;18145390_Z_G1002683D_Ohp CDDVDW SH-216ALN.MRK

2013-11-20 03:59 - 2013-11-19 20:06 - 00000000 __RSH C:\Windows\system32\Drivers\103C_HP_cPC_h9-1230ea_Y53316J_0U_QCZC2293K88_E12WE2RRW602_4A_I2AD5_SPEGATRON CORPORATION_V1.03_B7.14_T120522_W73-1_L409_M6102_J1000_7Intel_8506_93.40_#130107_N19691091;18145390_Z_G1002683D_Ohp CDDVDW SH-216ALN.MRK

2013-11-20 03:42 - 2013-11-20 03:48 - 00000000 ____D C:\ProgramData\Recovery

2013-11-20 00:18 - 2013-11-20 00:18 - 00015539 _____ C:\Users\Rob\Downloads\FRST.txt

2013-11-20 00:18 - 2013-11-20 00:18 - 00000000 ____D C:\FRST

2013-11-20 00:17 - 2013-11-20 00:17 - 01957964 _____ (Farbar) C:\Users\Rob\Downloads\FRST64.exe

2013-11-19 23:17 - 2013-11-19 23:17 - 00017457 _____ C:\Users\Rob\Desktop\DDSreport.txt

2013-11-19 23:17 - 2013-11-19 23:17 - 00004742 _____ C:\Users\Rob\Desktop\Attachreport.txt

2013-11-19 23:06 - 2013-11-19 23:06 - 00000000 ____D C:\ProgramData\Sun

2013-11-19 23:06 - 2013-11-19 23:06 - 00000000 ____D C:\ProgramData\Oracle

2013-11-19 23:05 - 2013-11-19 23:05 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe

2013-11-19 23:05 - 2013-11-19 23:05 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe

2013-11-19 23:05 - 2013-11-19 23:05 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe

2013-11-19 23:05 - 2013-11-19 23:05 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll

2013-11-19 23:05 - 2013-11-19 23:05 - 00000000 ____D C:\Program Files (x86)\Java

2013-11-19 23:04 - 2013-11-19 23:04 - 00915368 _____ (Oracle Corporation) C:\Users\Rob\Downloads\chromeinstall-7u45.exe

2013-11-19 23:04 - 2013-11-19 23:04 - 00000000 ____D C:\ProgramData\McAfee

2013-11-19 22:49 - 2013-11-19 22:49 - 00688992 ____R (Swearware) C:\Users\Rob\Downloads\dds.com

2013-11-19 21:20 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_1.dll

2013-11-19 21:20 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_2.dll

2013-11-19 21:20 - 2008-07-12 08:18 - 03851784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_39.dll

2013-11-19 21:20 - 2008-07-12 08:18 - 01493528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_39.dll

2013-11-19 21:20 - 2008-07-12 08:18 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_39.dll

2013-11-19 21:19 - 2013-11-19 21:19 - 00001613 _____ C:\Users\Public\Desktop\Play League of Legends.lnk

2013-11-19 21:19 - 2013-11-19 21:19 - 00000000 __SHD C:\Windows\SysWOW64\AI_RecycleBin

2013-11-19 21:19 - 2013-11-19 21:19 - 00000000 ____D C:\Riot Games

2013-11-19 21:18 - 2013-11-19 21:18 - 00000000 ____D C:\Users\Rob\AppData\Roaming\Riot Games

2013-11-19 21:18 - 2013-11-19 21:18 - 00000000 ____D C:\Program Files (x86)\Pando Networks

2013-11-19 21:17 - 2013-11-19 21:17 - 34888568 _____ (Riot Games) C:\Users\Rob\Downloads\LeagueofLegends_EUW_Installer_06_12_13.exe

2013-11-19 21:10 - 2013-11-20 00:16 - 00000000 ____D C:\Users\Rob\AppData\Roaming\Skype

2013-11-19 21:10 - 2013-11-20 00:03 - 00002697 _____ C:\Users\Public\Desktop\Skype.lnk

2013-11-19 21:10 - 2013-11-20 00:03 - 00000000 ____D C:\ProgramData\Skype

2013-11-19 21:10 - 2013-11-19 21:10 - 00000000 ___RD C:\Program Files (x86)\Skype

2013-11-19 21:09 - 2013-11-19 21:09 - 01550496 _____ (Skype Technologies S.A.) C:\Users\Rob\Downloads\SkypeSetup.exe

2013-11-19 21:07 - 2013-11-19 21:07 - 00002257 _____ C:\Users\Public\Desktop\Google Chrome.lnk

2013-11-19 21:06 - 2013-11-20 00:16 - 00000888 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job

2013-11-19 21:06 - 2013-11-19 23:16 - 00000892 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job

2013-11-19 21:06 - 2013-11-19 21:11 - 00003888 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA

2013-11-19 21:06 - 2013-11-19 21:11 - 00003636 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore

2013-11-19 21:06 - 2013-11-19 21:07 - 00000000 ____D C:\Users\Rob\AppData\Local\Google

2013-11-19 21:06 - 2013-11-19 21:07 - 00000000 ____D C:\Program Files (x86)\Google

2013-11-19 21:06 - 2013-11-19 21:06 - 00000000 ____D C:\Users\Rob\AppData\Local\Deployment

2013-11-19 21:06 - 2013-11-19 21:06 - 00000000 ____D C:\Users\Rob\AppData\Local\Apps\2.0

2013-11-19 20:32 - 2013-11-19 20:32 - 00001111 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk

2013-11-19 20:32 - 2013-11-19 20:32 - 00000000 ____D C:\Users\Rob\AppData\Roaming\Malwarebytes

2013-11-19 20:32 - 2013-11-19 20:32 - 00000000 ____D C:\ProgramData\Malwarebytes

2013-11-19 20:32 - 2013-11-19 20:32 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware

2013-11-19 20:32 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys

2013-11-19 20:22 - 2012-02-17 06:38 - 01031680 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll

2013-11-19 20:22 - 2012-02-17 05:34 - 00826880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll

2013-11-19 20:22 - 2012-02-17 04:58 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys

2013-11-19 20:22 - 2012-02-17 04:57 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys

2013-11-19 20:20 - 2013-11-20 00:16 - 00000000 ____D C:\ProgramData\Kaspersky Lab

2013-11-19 20:20 - 2013-11-19 20:20 - 00001126 _____ C:\Users\Public\Desktop\Kaspersky Internet Security.lnk

2013-11-19 20:20 - 2013-11-19 20:20 - 00000000 ____D C:\Windows\ELAMBKUP

2013-11-19 20:20 - 2013-11-19 20:20 - 00000000 ____D C:\Program Files (x86)\Kaspersky Lab

2013-11-19 20:20 - 2013-05-06 09:13 - 00110176 _____ (Kaspersky Lab ZAO) C:\Windows\system32\klfphc.dll

2013-11-19 20:19 - 2013-11-19 20:24 - 00623200 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys

2013-11-19 20:19 - 2013-06-08 20:18 - 00112224 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys

2013-11-19 20:16 - 2012-06-02 22:19 - 02428952 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll

2013-11-19 20:16 - 2012-06-02 22:19 - 00701976 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll

2013-11-19 20:16 - 2012-06-02 22:19 - 00057880 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe

2013-11-19 20:16 - 2012-06-02 22:19 - 00044056 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll

2013-11-19 20:16 - 2012-06-02 22:19 - 00038424 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll

2013-11-19 20:16 - 2012-06-02 22:15 - 02622464 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll

2013-11-19 20:16 - 2012-06-02 22:15 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll

2013-11-19 20:15 - 2012-06-02 15:19 - 00186752 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll

2013-11-19 20:15 - 2012-06-02 15:15 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe

2013-11-19 20:14 - 2013-11-19 20:14 - 00057560 _____ C:\Users\Rob\AppData\Local\GDIPFONTCACHEV1.DAT

2013-11-19 20:13 - 2013-11-19 20:13 - 00000000 ____D C:\Users\Rob\AppData\Roaming\Macromedia

2013-11-19 20:13 - 2013-11-19 20:13 - 00000000 ____D C:\Users\Rob\AppData\Roaming\ATI

2013-11-19 20:13 - 2013-11-19 20:13 - 00000000 ____D C:\Users\Rob\AppData\Roaming\Adobe

2013-11-19 20:13 - 2013-11-19 20:13 - 00000000 ____D C:\Users\Rob\AppData\Local\ATI

2013-11-19 20:09 - 2013-11-19 20:13 - 00003910 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{2E0AEB0B-3AE4-400F-8822-6BA43C7D59C0}

2013-11-19 20:09 - 2013-11-19 20:09 - 00001445 _____ C:\Users\Rob\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk

2013-11-19 20:09 - 2013-11-19 20:09 - 00001411 _____ C:\Users\Rob\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk

2013-11-19 20:09 - 2013-11-19 20:09 - 00000000 ___RD C:\Users\Rob\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup

2013-11-19 20:09 - 2013-11-19 20:09 - 00000000 ___RD C:\Users\Rob\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools

2013-11-19 20:09 - 2013-11-19 20:09 - 00000000 ____D C:\Users\Rob\AppData\Local\VirtualStore

2013-11-19 20:09 - 2013-11-19 20:09 - 00000000 ____D C:\Users\Rob\AppData\Local\PDFC

2013-11-19 20:08 - 2013-11-19 20:08 - 00000000 ____D C:\Users\Rob\AppData\Roaming\Hewlett-Packard

2013-11-19 20:08 - 2013-11-19 20:08 - 00000000 ____D C:\Users\Rob\AppData\Local\TouchSmartData

2013-11-19 20:06 - 2013-11-19 20:09 - 00003560 _____ C:\Windows\System32\Tasks\Registration

2013-11-19 20:06 - 2013-11-19 20:09 - 00000000 ____D C:\Users\Rob

2013-11-19 20:06 - 2013-11-19 20:08 - 00000000 ____D C:\Users\Rob\AppData\Local\Hewlett-Packard

2013-11-19 20:06 - 2013-11-19 20:06 - 00003290 _____ C:\Windows\System32\Tasks\RMCreator

2013-11-19 20:06 - 2013-11-19 20:06 - 00000020 ___SH C:\Users\Rob\ntuser.ini

2013-11-19 20:06 - 2013-11-19 20:06 - 00000000 ____D C:\Users\Rob\AppData\Local\RemEngine

2013-11-19 20:06 - 2013-11-19 20:06 - 00000000 ____D C:\Users\Rob\AppData\Local\Hewlett-Packard_Company

2013-11-19 20:06 - 2013-11-19 20:06 - 00000000 ____D C:\Program Files (x86)\Microsoft Mathematics

2013-11-19 20:06 - 2009-07-14 04:54 - 00000000 ___RD C:\Users\Rob\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories

2013-11-19 20:06 - 2009-07-14 04:49 - 00000000 ___RD C:\Users\Rob\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance

2013-11-19 20:03 - 2013-11-20 00:14 - 00303329 _____ C:\Windows\WindowsUpdate.log


==================== One Month Modified Files and Folders =======


2013-11-20 04:01 - 2013-01-07 02:57 - 00000000 ____D C:\ProgramData\Hewlett-Packard

2013-11-20 03:59 - 2009-07-14 04:46 - 00005075 _____ C:\Windows\DtcInstall.log

2013-11-20 03:59 - 2009-07-14 03:20 - 00000000 ____D C:\Windows\system32\sysprep

2013-11-20 03:55 - 2011-02-11 17:04 - 00005949 _____ C:\Windows\TSSysprep.log

2013-11-20 03:48 - 2013-11-20 03:42 - 00000000 ____D C:\ProgramData\Recovery

2013-11-20 03:43 - 2009-07-14 05:32 - 00028672 _____ C:\Windows\system32\config\BCD-Template

2013-11-20 03:42 - 2009-07-14 05:38 - 00025600 ___SH C:\Windows\system32\config\BCD-Template.LOG

2013-11-20 00:18 - 2013-11-20 00:18 - 00015539 _____ C:\Users\Rob\Downloads\FRST.txt

2013-11-20 00:18 - 2013-11-20 00:18 - 00000000 ____D C:\FRST

2013-11-20 00:17 - 2013-11-20 00:17 - 01957964 _____ (Farbar) C:\Users\Rob\Downloads\FRST64.exe

2013-11-20 00:16 - 2013-11-19 21:10 - 00000000 ____D C:\Users\Rob\AppData\Roaming\Skype

2013-11-20 00:16 - 2013-11-19 21:06 - 00000888 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job

2013-11-20 00:16 - 2013-11-19 20:20 - 00000000 ____D C:\ProgramData\Kaspersky Lab

2013-11-20 00:16 - 2013-01-07 03:05 - 00000000 ____D C:\ProgramData\PDFC

2013-11-20 00:16 - 2013-01-07 03:03 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job

2013-11-20 00:16 - 2009-07-14 05:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT

2013-11-20 00:16 - 2009-07-14 04:51 - 00041559 _____ C:\Windows\setupact.log

2013-11-20 00:14 - 2013-11-19 20:03 - 00303329 _____ C:\Windows\WindowsUpdate.log

2013-11-20 00:03 - 2013-11-19 21:10 - 00002697 _____ C:\Users\Public\Desktop\Skype.lnk

2013-11-20 00:03 - 2013-11-19 21:10 - 00000000 ____D C:\ProgramData\Skype

2013-11-19 23:35 - 2013-01-07 03:03 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater

2013-11-19 23:17 - 2013-11-19 23:17 - 00017457 _____ C:\Users\Rob\Desktop\DDSreport.txt

2013-11-19 23:17 - 2013-11-19 23:17 - 00004742 _____ C:\Users\Rob\Desktop\Attachreport.txt

2013-11-19 23:16 - 2013-11-19 21:06 - 00000892 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job

2013-11-19 23:06 - 2013-11-19 23:06 - 00000000 ____D C:\ProgramData\Sun

2013-11-19 23:06 - 2013-11-19 23:06 - 00000000 ____D C:\ProgramData\Oracle

2013-11-19 23:05 - 2013-11-19 23:05 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe

2013-11-19 23:05 - 2013-11-19 23:05 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe

2013-11-19 23:05 - 2013-11-19 23:05 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe

2013-11-19 23:05 - 2013-11-19 23:05 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll

2013-11-19 23:05 - 2013-11-19 23:05 - 00000000 ____D C:\Program Files (x86)\Java

2013-11-19 23:04 - 2013-11-19 23:04 - 00915368 _____ (Oracle Corporation) C:\Users\Rob\Downloads\chromeinstall-7u45.exe

2013-11-19 23:04 - 2013-11-19 23:04 - 00000000 ____D C:\ProgramData\McAfee

2013-11-19 22:49 - 2013-11-19 22:49 - 00688992 ____R (Swearware) C:\Users\Rob\Downloads\dds.com

2013-11-19 21:22 - 2009-07-14 04:45 - 00016752 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0

2013-11-19 21:22 - 2009-07-14 04:45 - 00016752 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0

2013-11-19 21:19 - 2013-11-19 21:19 - 00001613 _____ C:\Users\Public\Desktop\Play League of Legends.lnk

2013-11-19 21:19 - 2013-11-19 21:19 - 00000000 __SHD C:\Windows\SysWOW64\AI_RecycleBin

2013-11-19 21:19 - 2013-11-19 21:19 - 00000000 ____D C:\Riot Games

2013-11-19 21:19 - 2009-07-14 05:13 - 00775032 _____ C:\Windows\system32\PerfStringBackup.INI

2013-11-19 21:18 - 2013-11-19 21:18 - 00000000 ____D C:\Users\Rob\AppData\Roaming\Riot Games

2013-11-19 21:18 - 2013-11-19 21:18 - 00000000 ____D C:\Program Files (x86)\Pando Networks

2013-11-19 21:17 - 2013-11-19 21:17 - 34888568 _____ (Riot Games) C:\Users\Rob\Downloads\LeagueofLegends_EUW_Installer_06_12_13.exe

2013-11-19 21:13 - 2010-11-21 03:47 - 00556508 _____ C:\Windows\PFRO.log

2013-11-19 21:11 - 2013-11-19 21:06 - 00003888 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA

2013-11-19 21:11 - 2013-11-19 21:06 - 00003636 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore

2013-11-19 21:10 - 2013-11-19 21:10 - 00000000 ___RD C:\Program Files (x86)\Skype

2013-11-19 21:09 - 2013-11-19 21:09 - 01550496 _____ (Skype Technologies S.A.) C:\Users\Rob\Downloads\SkypeSetup.exe

2013-11-19 21:07 - 2013-11-19 21:07 - 00002257 _____ C:\Users\Public\Desktop\Google Chrome.lnk

2013-11-19 21:07 - 2013-11-19 21:06 - 00000000 ____D C:\Users\Rob\AppData\Local\Google

2013-11-19 21:07 - 2013-11-19 21:06 - 00000000 ____D C:\Program Files (x86)\Google

2013-11-19 21:06 - 2013-11-19 21:06 - 00000000 ____D C:\Users\Rob\AppData\Local\Deployment

2013-11-19 21:06 - 2013-11-19 21:06 - 00000000 ____D C:\Users\Rob\AppData\Local\Apps\2.0

2013-11-19 20:32 - 2013-11-19 20:32 - 00001111 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk

2013-11-19 20:32 - 2013-11-19 20:32 - 00000000 ____D C:\Users\Rob\AppData\Roaming\Malwarebytes

2013-11-19 20:32 - 2013-11-19 20:32 - 00000000 ____D C:\ProgramData\Malwarebytes

2013-11-19 20:32 - 2013-11-19 20:32 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware

2013-11-19 20:24 - 2013-11-19 20:19 - 00623200 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys

2013-11-19 20:24 - 2013-10-09 11:46 - 00458336 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kl1.sys

2013-11-19 20:20 - 2013-11-19 20:20 - 00001126 _____ C:\Users\Public\Desktop\Kaspersky Internet Security.lnk

2013-11-19 20:20 - 2013-11-19 20:20 - 00000000 ____D C:\Windows\ELAMBKUP

2013-11-19 20:20 - 2013-11-19 20:20 - 00000000 ____D C:\Program Files (x86)\Kaspersky Lab

2013-11-19 20:17 - 2013-01-07 03:07 - 00000000 ____D C:\ProgramData\Norton

2013-11-19 20:14 - 2013-11-19 20:14 - 00057560 _____ C:\Users\Rob\AppData\Local\GDIPFONTCACHEV1.DAT

2013-11-19 20:13 - 2013-11-19 20:13 - 00000000 ____D C:\Users\Rob\AppData\Roaming\Macromedia

2013-11-19 20:13 - 2013-11-19 20:13 - 00000000 ____D C:\Users\Rob\AppData\Roaming\ATI

2013-11-19 20:13 - 2013-11-19 20:13 - 00000000 ____D C:\Users\Rob\AppData\Roaming\Adobe

2013-11-19 20:13 - 2013-11-19 20:13 - 00000000 ____D C:\Users\Rob\AppData\Local\ATI

2013-11-19 20:13 - 2013-11-19 20:09 - 00003910 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{2E0AEB0B-3AE4-400F-8822-6BA43C7D59C0}

2013-11-19 20:12 - 2009-07-14 05:32 - 00000000 ____D C:\Windows\system32\restore

2013-11-19 20:11 - 2009-07-14 04:45 - 00274320 _____ C:\Windows\system32\FNTCACHE.DAT

2013-11-19 20:09 - 2013-11-19 20:09 - 00001445 _____ C:\Users\Rob\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk

2013-11-19 20:09 - 2013-11-19 20:09 - 00001411 _____ C:\Users\Rob\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk

2013-11-19 20:09 - 2013-11-19 20:09 - 00000000 ___RD C:\Users\Rob\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup

2013-11-19 20:09 - 2013-11-19 20:09 - 00000000 ___RD C:\Users\Rob\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools

2013-11-19 20:09 - 2013-11-19 20:09 - 00000000 ____D C:\Users\Rob\AppData\Local\VirtualStore

2013-11-19 20:09 - 2013-11-19 20:09 - 00000000 ____D C:\Users\Rob\AppData\Local\PDFC

2013-11-19 20:09 - 2013-11-19 20:06 - 00003560 _____ C:\Windows\System32\Tasks\Registration

2013-11-19 20:09 - 2013-11-19 20:06 - 00000000 ____D C:\Users\Rob

2013-11-19 20:09 - 2011-02-11 16:32 - 00000000 __RHD C:\SYSTEM.SAV

2013-11-19 20:09 - 2011-02-11 16:32 - 00000000 ____D C:\SWSETUP

2013-11-19 20:08 - 2013-11-19 20:08 - 00000000 ____D C:\Users\Rob\AppData\Roaming\Hewlett-Packard

2013-11-19 20:08 - 2013-11-19 20:08 - 00000000 ____D C:\Users\Rob\AppData\Local\TouchSmartData

2013-11-19 20:08 - 2013-11-19 20:06 - 00000000 ____D C:\Users\Rob\AppData\Local\Hewlett-Packard

2013-11-19 20:06 - 2013-11-20 03:59 - 00000000 __RSH C:\Windows\SysWOW64\Drivers\103C_HP_cPC_h9-1230ea_Y53316J_0U_QCZC2293K88_E12WE2RRW602_4A_I2AD5_SPEGATRON CORPORATION_V1.03_B7.14_T120522_W73-1_L409_M6102_J1000_7Intel_8506_93.40_#130107_N19691091;18145390_Z_G1002683D_Ohp CDDVDW SH-216ALN.MRK

2013-11-19 20:06 - 2013-11-20 03:59 - 00000000 __RSH C:\Windows\system32\Drivers\103C_HP_cPC_h9-1230ea_Y53316J_0U_QCZC2293K88_E12WE2RRW602_4A_I2AD5_SPEGATRON CORPORATION_V1.03_B7.14_T120522_W73-1_L409_M6102_J1000_7Intel_8506_93.40_#130107_N19691091;18145390_Z_G1002683D_Ohp CDDVDW SH-216ALN.MRK

2013-11-19 20:06 - 2013-11-19 20:06 - 00003290 _____ C:\Windows\System32\Tasks\RMCreator

2013-11-19 20:06 - 2013-11-19 20:06 - 00000020 ___SH C:\Users\Rob\ntuser.ini

2013-11-19 20:06 - 2013-11-19 20:06 - 00000000 ____D C:\Users\Rob\AppData\Local\RemEngine

2013-11-19 20:06 - 2013-11-19 20:06 - 00000000 ____D C:\Users\Rob\AppData\Local\Hewlett-Packard_Company

2013-11-19 20:06 - 2013-11-19 20:06 - 00000000 ____D C:\Program Files (x86)\Microsoft Mathematics

2013-11-19 20:06 - 2013-01-07 03:05 - 00000000 ___RD C:\Program Files (x86)\Online Services

2013-11-19 20:06 - 2011-02-11 17:00 - 00000000 ____D C:\Windows\Panther

2013-11-19 20:06 - 2009-07-14 05:32 - 00000000 ____D C:\Program Files\Windows Sidebar

2013-11-19 20:06 - 2009-07-14 05:32 - 00000000 ____D C:\Program Files (x86)\Windows Sidebar

2013-11-19 20:03 - 2009-07-14 03:20 - 00000000 ____D C:\Windows\rescache


Some content of TEMP:





==================== Bamital & volsnap Check =================


C:\Windows\System32\winlogon.exe => MD5 is legit

C:\Windows\System32\wininit.exe => MD5 is legit

C:\Windows\SysWOW64\wininit.exe => MD5 is legit

C:\Windows\explorer.exe => MD5 is legit

C:\Windows\SysWOW64\explorer.exe => MD5 is legit

C:\Windows\System32\svchost.exe => MD5 is legit

C:\Windows\SysWOW64\svchost.exe => MD5 is legit

C:\Windows\System32\services.exe => MD5 is legit

C:\Windows\System32\User32.dll => MD5 is legit

C:\Windows\SysWOW64\User32.dll => MD5 is legit

C:\Windows\System32\userinit.exe => MD5 is legit

C:\Windows\SysWOW64\userinit.exe => MD5 is legit

C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit



LastRegBack: 2011-02-11 19:22


==================== End Of Log ============================


Link to post
Share on other sites

Download attached fixlist.txt file and save it to the Desktop, or the folder you saved FRST into.

NOTE. It's important that both FRST and fixlist.txt are in the same location or the fix will not work.


Run FRST and press the Fix button just once and wait.

The tool will make a log on the Desktop (Fixlog.txt). Please post it to your reply.




Download AdwCleaner by Xplode from here: http://www.bleepingcomputer.com/download/adwcleaner/ and save to your Desktop.


  • Double click on AdwCleaner.exe to run the tool.
  • Vista/Windows 7/8 users right-click and select Run As Administrator
  • Click on the Scan button.
  • AdwCleaner will begin...be patient as the scan may take some time to complete.
  • When it's done you'll see: Pending: Uncheck any elements you don't want removed.
  • Now click on the Report button...a logfile (AdwCleaner[R0].txt) will open in Notepad for review.
  • Look over the log especially under Files/Folders for any program you want to save.
  • If there's a program you want to save, just uncheck it from AdwCleaner.
  • If you're not sure, post the log for review.
  • If you're ready to clean it all up.....click the Clean button.
  • After rebooting, a logfile report (AdwCleaner[s0].txt) will open automatically.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of that logfile will also be saved in the C:\AdwCleaner folder.
  • Items that are deleted are moved to the Quarantine Folder: C:\AdwCleaner\Quarantine
  • To restore an item that has been deleted (if necessary):
  • Go to Tools > Quarantine Manager > check what you want restored > now click on Restore.




Run Malwarebytes,  Open > Settings Tab > Scanner Settings > Under action for PUP > Select: Show in Results List and Check for removal.

Please Update and run a Quick Scan with Malwarebytes Anti-Malware,

Make sure that everything is checked, and click Remove Selected on any found items.

Post the produced log


Let me see those logs in next reply, also let me know if you have any remaining issues or concerns...








Link to post
Share on other sites


Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 18-11-2013
Ran by Rob at 2013-11-20 00:50:29 Run:1
Running from C:\Users\Rob\Downloads
Boot Mode: Normal
Content of fixlist:
C:\Program Files (x86)\Pando Networks
C:\Program Files (x86)\Pando Networks => Moved successfully.
C:\Users\Rob\AppData\Local\Temp\swt-win32-3349.dll => Moved successfully.
==== End of Fixlog ====
# AdwCleaner v3.012 - Report created 20/11/2013 at 00:57:01
# Updated 11/11/2013 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Rob - ROB-HP
# Running from : C:\Users\Rob\Downloads\AdwCleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
***** [ Browsers ] *****
-\\ Internet Explorer v9.0.8112.16421
-\\ Google Chrome v31.0.1650.57
[ File : C:\Users\Rob\AppData\Local\Google\Chrome\User Data\Default\preferences ]
AdwCleaner[R0].txt - [2291 octets] - [20/11/2013 00:52:31]
AdwCleaner[s0].txt - [1996 octets] - [20/11/2013 00:57:01]
########## EOF - C:\AdwCleaner\AdwCleaner[s0].txt - [2056 octets] ##########

Malwarebytes Log:

Malwarebytes Anti-Malware (Trial)
Database version: v2013.11.20.01
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Rob :: ROB-HP [administrator]
Protection: Enabled
20/11/2013 01:04:26
mbam-log-2013-11-20 (01-04-26).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 201641
Time elapsed: 1 minute(s), 56 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
Other than the initial problem, I think that's all I was worried about thanks.
Link to post
Share on other sites

Ok, do this to complete:


We need to remove FRST, first it is very important to deal with its Quarantine folder using FRST itself..

OK, we continue:

Delete any fixlist.txt file previously used, continue:


Download attached fixlist.txt file and save it to the Desktop, or the folder you saved FRST into.

NOTE. It's important that both FRST and fixlist.txt are in the same location or the fix will not work.


Run FRST and press the Fix button just once and wait.

The tool will make a log on the Desktop (Fixlog.txt). That will confirm the removal action, delete if successful. 



Delete FRST.exe from your Desktop or the folder it was saved to, navigate to and delete its folder C:\FRST




Uninstall adwcleaner.exe




  •   Please close all open programs and internet browsers.



  •   Double click on adwcleaner.exe to run the tool.



  •   Click on Uninstall



  • Click Yes at Would you like to Uninstall Adwcleaner





If all now ok with no remaining issues or concerns can we close out? Read the following link to fully understand PC security and best practices, you may find it useful....






Link to post
Share on other sites

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 18-11-2013

Ran by Rob at 2013-11-20 11:32:54 Run:2

Running from C:\Users\Rob\Downloads

Boot Mode: Normal



Content of fixlist:










C:\FRST\Quarantine => Removed successfully.


==== End of Fixlog ====


If that is fine, then I have no other issues with my computer. Thank you for all your help.

Link to post
Share on other sites

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.