Jump to content

Malware infection. Safe mode prevented. Help with 'Farbar Recovery Scan Tool'


Recommended Posts


Hi there,


 


My computer was infected with some sort of malware just yesterday. It's not something I have any experience with, so started to Google. I've tried to start in all three safe modes but the malware performs an auto restart.


 


I came across another thread on this forum that uses 'Farbar Recovery Scan Tool'


I've followed the steps and have the resulting text file. I was just hoping somebody would be able to help me out with where to go from here!


 


Any help would be greatly appreciated.


 


Gregg


 


From 'FRST.txt':


 


 


Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 29-12-2013 01

Ran by SYSTEM on MININT-JSEPN98 on 30-12-2013 19:02:26

Running from G:\

Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US)

Internet Explorer Version 11

Boot Mode: Recovery

 

The current controlset is ControlSet001

ATTENTION!:=====> If the system is bootable FRST could be run from normal or Safe mode to create a complete log.

 

==================== Registry (Whitelisted) ==================

 

HKLM\...\Run: [synTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2741544 2011-04-07] (Synaptics Incorporated)

HKLM\...\Run: [Lenovo EE Boot Optimizer] - C:\Program Files (x86)\Lenovo\Boot Optimizer\PopWnd.exe [114688 2011-12-23] (Lenovo)

HKLM\...\Run: [Energy Management] - C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [9753024 2011-12-23] (Lenovo (Beijing) Limited)

HKLM\...\Run: [EnergyUtility] - C:\Program Files (x86)\Lenovo\Energy Management\utility.exe [5908928 2011-12-23] (Lenovo(beijing) Limited)

HKLM\...\Run: [HotKeysCmds] - C:\windows\system32\hkcmd.exe [ ] ()

HKLM\...\Run: [installerLauncher] - C:\Users\Gregg\AppData\Local\Temp\GZ_INSTALL_0\setuplauncher.exe [815600 2013-03-25] (BitDefender S.R.L.) <===== ATTENTION

HKLM-x32\...\Run: [iAStorIcon] - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [283160 2011-02-18] (Intel Corporation)

HKLM-x32\...\Run: [331BigDog] - C:\Program Files (x86)\USB Camera\VM331_STI.EXE [548864 2011-06-15] (Vimicro)

HKLM-x32\...\Run: [updateP2GShortCut] - C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2010-07-26] (CyberLink Corp.)

HKLM-x32\...\Run: [YouCam Mirage] - C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [136488 2011-01-28] (CyberLink)

HKLM-x32\...\Run: [YouCam Tray] - C:\Program Files (x86)\Lenovo\YouCam\YouCam.exe [228448 2011-01-28] (CyberLink Corp.)

HKLM-x32\...\Run: [VeriFaceManager] - C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe [329056 2011-12-23] (Lenovo)

HKLM-x32\...\Run: [updatePRCShortCut] - C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-13] (CyberLink Corp.)

HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\qttask.exe [282624 2006-09-01] (Apple Computer, Inc.)

HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)

HKLM-x32\...\Run: [iJNetworkScannerSelectorEX] - C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [452016 2011-01-15] (CANON INC.)

HKLM-x32\...\Run: [sDTray] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [3825176 2012-11-13] (Safer-Networking Ltd.)

HKLM-x32\...\Run: [sunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)

HKLM-x32\...\Run: [mobilegeni daemon] - C:\Program Files (x86)\Mobogenie\DaemonProcess.exe

HKLM\...\RunOnce: [*Restore] - C:\windows\system32\rstrui.exe /RUNONCE [296960 2010-11-20] (Microsoft Corporation)

Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)

HKU\Gregg\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3481408 2012-02-13] (DT Soft Ltd)

HKU\Gregg\...\Run: [spotify] - C:\Users\Gregg\AppData\Roaming\Spotify\spotify.exe [5951488 2013-12-06] (Spotify Ltd)

HKU\Gregg\...\Run: [spotify Web Helper] - C:\Users\Gregg\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1168896 2013-12-06] (Spotify Ltd)

HKU\Gregg\...\Run: [spybot-S&D Cleaning] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [3713032 2012-11-13] (Safer-Networking Ltd.)

HKU\Gregg\...\Run: [AVG-Secure-Search-Update_0913b] - C:\Users\Gregg\AppData\Roaming\AVG 0913b Campaign\AVG-Secure-Search-Update-0913b.exe /PROMPT --mid 45a45455a29747d09f070d47e79695c6-c667900443f428256cb6426b89cc29aed3ea26a7 --CMPID 0913b

Startup: C:\Users\Gregg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\vrjrtll.lnk

ShortcutTarget: vrjrtll.lnk -> C:\ProgramData\lltrjrv.jss ()

BootExecute: autocheck autochk * sdnclean64.exe

 

==================== Services (Whitelisted) =================

 

S2 MSSQL$SQLEXPRESS; c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [57617752 2009-03-29] (Microsoft Corporation)

S2 OfficeSvc; C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [1907896 2013-11-01] (Microsoft Corporation)

S2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1103392 2012-11-13] (Safer-Networking Ltd.)

S2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1369624 2012-11-13] (Safer-Networking Ltd.)

S2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [168384 2012-11-13] (Safer-Networking Ltd.)

S4 SQLAgent$SQLEXPRESS; c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [427880 2009-03-29] (Microsoft Corporation)

S2 Winmgmt; C:\ProgramData\vrjrtll.zvv [61532 2013-12-29] (Microsoft Corporation)

 

==================== Drivers (Whitelisted) ====================

 

S3 Apowersoft_AudioDevice; C:\Windows\System32\drivers\Apowersoft_AudioDevice.sys [29288 2010-12-24] (Wondershare)

S1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-04-15] (DT Soft Ltd)

S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [27520 2007-05-14] (Research In Motion Limited)

S3 vm331avs; C:\Windows\System32\Drivers\vm331avs.sys [250752 2011-06-14] (Vimicro Corporation)

S3 vmuvcflt; C:\Windows\System32\Drivers\vmuvcflt.sys [8320 2010-08-16] (Vimicro Corporation)

S3 BcmSqlStartupSvc; 

S2 CLKMSVC10_3A60B698; 

S2 CLKMSVC10_C3B3B687; 

S2 DriverService; 

S2 iATAgentService; 

S2 idealife Update Service; 

S3 IGRS; 

S2 IviRegMgr; 

S2 McAfee SiteAdvisor Service; 

S2 McMPFSvc; 

S2 McProxy; 

S2 nvUpdatusService; 

S2 Oasis2Service; 

S2 PCCarerService; 

S2 ReadyComm.DirectRouter; 

S2 RichVideo; 

S2 RtLedService; 

S2 SeaPort; 

S2 SoftwareService; 

S2 Stereo Service; 

 

==================== NetSvcs (Whitelisted) ===================

 

 

==================== One Month Created Files and Folders ========

 

2013-12-30 19:02 - 2013-12-30 19:02 - 00000000 ___DC C:\FRST

2013-12-30 10:25 - 2013-12-30 10:25 - 00003288 ____N C:\bootsqm.dat

2013-12-30 09:33 - 2013-12-30 09:39 - 57196026 ____C C:\Users\Gregg\Downloads\Unconfirmed 727329.crdownload

2013-12-30 09:32 - 2013-12-30 09:32 - 00045508 ____C C:\ProgramData\1388424726.bdinstall.bin

2013-12-30 09:32 - 2013-12-30 09:32 - 00000000 ___DC C:\Users\Gregg\AppData\Roaming\QuickScan

2013-12-30 09:31 - 2013-12-30 09:32 - 10447328 ____C C:\Users\Gregg\Downloads\Antivirus_Free_Edition_x64.exe

2013-12-30 09:31 - 2013-12-30 09:31 - 00162208 ____C C:\Users\Gregg\Downloads\Antivirus_Free_Edition.exe

2013-12-30 09:30 - 2013-12-30 09:30 - 00001109 ____C C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk

2013-12-30 09:30 - 2013-12-30 09:30 - 00000000 ___DC C:\Users\Gregg\AppData\Roaming\Malwarebytes

2013-12-30 09:30 - 2013-12-30 09:30 - 00000000 ___DC C:\ProgramData\Malwarebytes

2013-12-30 09:30 - 2013-12-30 09:30 - 00000000 ___DC C:\Program Files (x86)\Malwarebytes' Anti-Malware

2013-12-30 09:30 - 2013-04-04 06:50 - 00025928 ____C (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys

2013-12-30 09:29 - 2013-12-30 09:29 - 10285040 ____C (Malwarebytes Corporation                                    ) C:\Users\Gregg\Downloads\mbam-setup-1.75.0.1300 (1).exe

2013-12-30 09:28 - 2013-12-30 09:28 - 10285040 ____C (Malwarebytes Corporation                                    ) C:\Users\Gregg\Downloads\mbam-setup-1.75.0.1300.exe

2013-12-30 09:15 - 2013-12-30 10:50 - 00000784 ____C C:\Windows\setupact.log

2013-12-29 15:00 - 2013-12-29 15:00 - 00000894 ____C C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cf04e9ce9f5e09.job

2013-12-29 14:51 - 2013-12-29 14:51 - 23212032 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 12995584 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 05765120 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 02764288 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb

2013-12-29 14:51 - 2013-12-29 14:51 - 02724864 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb

2013-12-29 14:51 - 2013-12-29 14:51 - 02332160 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 01993728 _____ (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl

2013-12-29 14:51 - 2013-12-29 14:51 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl

2013-12-29 14:51 - 2013-12-29 14:51 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 01394176 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 01228800 _____ (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00942592 _____ (Microsoft Corporation) C:\Windows\System32\jsIntl.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00940032 _____ (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe

2013-12-29 14:51 - 2013-12-29 14:51 - 00817664 _____ (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00774144 _____ (Microsoft Corporation) C:\Windows\System32\jscript.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00708608 _____ (Microsoft Corporation) C:\Windows\System32\jscript9diag.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00626176 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat

2013-12-29 14:51 - 2013-12-29 14:51 - 00616104 _____ (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat

2013-12-29 14:51 - 2013-12-29 14:51 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00574976 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00548352 _____ (Microsoft Corporation) C:\Windows\System32\vbscript.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00453120 _____ (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00413696 _____ (Microsoft Corporation) C:\Windows\System32\html.iec

2013-12-29 14:51 - 2013-12-29 14:51 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec

2013-12-29 14:51 - 2013-12-29 14:51 - 00296960 _____ (Microsoft Corporation) C:\Windows\System32\dxtrans.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00263376 _____ (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00247808 _____ (Microsoft Corporation) C:\Windows\System32\msls31.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00243200 _____ (Microsoft Corporation) C:\Windows\System32\webcheck.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00235520 _____ (Microsoft Corporation) C:\Windows\System32\url.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00235008 _____ (Microsoft Corporation) C:\Windows\System32\elshyph.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00218624 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe

2013-12-29 14:51 - 2013-12-29 14:51 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00195584 _____ (Microsoft Corporation) C:\Windows\System32\msrating.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00167424 _____ (Microsoft Corporation) C:\Windows\System32\iexpress.exe

2013-12-29 14:51 - 2013-12-29 14:51 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe

2013-12-29 14:51 - 2013-12-29 14:51 - 00147968 _____ (Microsoft Corporation) C:\Windows\System32\occache.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00143872 _____ (Microsoft Corporation) C:\Windows\System32\wextract.exe

2013-12-29 14:51 - 2013-12-29 14:51 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe

2013-12-29 14:51 - 2013-12-29 14:51 - 00139264 _____ (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe

2013-12-29 14:51 - 2013-12-29 14:51 - 00135680 _____ (Microsoft Corporation) C:\Windows\System32\iepeers.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00131072 _____ (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe

2013-12-29 14:51 - 2013-12-29 14:51 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00111616 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollector.exe

2013-12-29 14:51 - 2013-12-29 14:51 - 00105984 _____ (Microsoft Corporation) C:\Windows\System32\iesysprep.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00101376 _____ (Microsoft Corporation) C:\Windows\System32\inseng.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00090112 _____ (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe

2013-12-29 14:51 - 2013-12-29 14:51 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00086016 _____ (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe

2013-12-29 14:51 - 2013-12-29 14:51 - 00084992 _____ (Microsoft Corporation) C:\Windows\System32\mshtmled.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00083968 _____ (Microsoft Corporation) C:\Windows\System32\MshtmlDac.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00081408 _____ (Microsoft Corporation) C:\Windows\System32\icardie.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00077312 _____ (Microsoft Corporation) C:\Windows\System32\tdc.ocx

2013-12-29 14:51 - 2013-12-29 14:51 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe

2013-12-29 14:51 - 2013-12-29 14:51 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe

2013-12-29 14:51 - 2013-12-29 14:51 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00066048 _____ (Microsoft Corporation) C:\Windows\System32\iesetup.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx

2013-12-29 14:51 - 2013-12-29 14:51 - 00062464 _____ (Microsoft Corporation) C:\Windows\System32\pngfilt.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00053760 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00052224 _____ (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\System32\mshtmler.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\System32\ieetwproxystub.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00048128 _____ (Microsoft Corporation) C:\Windows\System32\imgutil.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00040448 _____ (Microsoft Corporation) C:\Windows\System32\JavaScriptCollectionAgent.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00033792 _____ (Microsoft Corporation) C:\Windows\System32\iernonce.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00030208 _____ (Microsoft Corporation) C:\Windows\System32\licmgr10.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00013824 _____ (Microsoft Corporation) C:\Windows\System32\mshta.exe

2013-12-29 14:51 - 2013-12-29 14:51 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe

2013-12-29 14:51 - 2013-12-29 14:51 - 00013312 _____ (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe

2013-12-29 14:51 - 2013-12-29 14:51 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe

2013-12-29 14:51 - 2013-12-29 14:51 - 00004096 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollectorres.dll

2013-12-29 14:45 - 2013-12-29 14:45 - 00002255 ____C C:\Users\Public\Desktop\Google Chrome.lnk

2013-12-29 14:40 - 2013-12-29 14:40 - 00000000 ___HC C:\Users\Gregg\AppData\Local\BITE1F5.tmp

2013-12-29 14:39 - 2013-12-29 14:53 - 00008011 ____C C:\Windows\IE11_main.log

2013-12-29 14:39 - 2013-12-29 14:39 - 02077392 ____C (Microsoft Corporation) C:\Users\Gregg\Downloads\IE11-Windows6.1.exe

2013-12-29 06:32 - 2013-12-29 06:33 - 00000000 ___DC C:\Spotify

2013-12-29 06:32 - 2013-12-29 06:32 - 00000000 ___DC C:\DAEMON Tools Lite

2013-12-29 06:28 - 2013-12-29 06:28 - 00000279 ____C C:\ProgramData\vrjrtll.reg

2013-12-29 06:27 - 2013-12-29 06:28 - 95025368 ___CT C:\ProgramData\vrjrtll.fee

2013-12-29 06:27 - 2013-12-29 06:27 - 00150016 ____C C:\ProgramData\lltrjrv.jss

2013-12-29 06:27 - 2013-12-29 06:27 - 00061532 ___CT (Microsoft Corporation) C:\ProgramData\vrjrtll.zvv

2013-12-29 06:27 - 2013-12-29 06:27 - 00000000 ____C C:\ProgramData\vrjrtll.odd

2013-12-22 12:17 - 2013-12-30 09:08 - 00092672 __SHC C:\Users\Gregg\Desktop\Thumbs.db

2013-12-15 04:35 - 2013-12-15 04:39 - 03155968 _____ (Microsoft Corporation) C:\Windows\System32\win32k.sys

2013-12-15 04:35 - 2013-12-15 04:37 - 00497152 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\afd.sys

2013-12-15 04:34 - 2013-12-15 04:37 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll

2013-12-15 04:34 - 2013-12-15 04:37 - 00081408 _____ (Microsoft Corporation) C:\Windows\System32\imagehlp.dll

2013-12-15 04:34 - 2013-12-15 04:37 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll

2013-12-15 04:34 - 2013-12-15 04:37 - 00002048 _____ (Microsoft Corporation) C:\Windows\System32\tzres.dll

2013-12-15 04:34 - 2013-12-15 04:36 - 00404480 _____ (Microsoft Corporation) C:\Windows\System32\gdi32.dll

2013-12-15 04:34 - 2013-12-15 04:36 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll

2013-12-15 04:34 - 2013-12-15 04:36 - 00202752 _____ (Microsoft Corporation) C:\Windows\System32\scrrun.dll

2013-12-15 04:34 - 2013-12-15 04:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\System32\wscript.exe

2013-12-15 04:34 - 2013-12-15 04:36 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll

2013-12-15 04:34 - 2013-12-15 04:36 - 00156160 _____ (Microsoft Corporation) C:\Windows\System32\cscript.exe

2013-12-15 04:34 - 2013-12-15 04:36 - 00150016 _____ (Microsoft Corporation) C:\Windows\System32\wshom.ocx

2013-12-15 04:34 - 2013-12-15 04:36 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe

2013-12-15 04:34 - 2013-12-15 04:36 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe

2013-12-15 04:34 - 2013-12-15 04:36 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx

2013-12-15 04:34 - 2013-10-03 18:16 - 00116736 ____C (Microsoft Corporation) C:\Windows\System32\Drivers\drmk.sys

2013-12-15 04:34 - 2013-10-03 17:36 - 00230400 ____C (Microsoft Corporation) C:\Windows\System32\Drivers\portcls.sys

2013-12-01 14:11 - 2013-12-01 14:11 - 00000000 ___DC C:\Program Files\Common Files\Propellerhead Software

2013-12-01 13:30 - 2013-12-01 13:30 - 00028458 ____C C:\Users\Gregg\Downloads\Ableton.Live.9.Suite.9.1.0.(Win.64.bit).(patch.IO).torrent

2013-12-01 12:43 - 2013-12-01 12:43 - 00021349 ____C C:\Users\Gregg\Downloads\Ableton.Live.9.Suite.9.0.1.(64.bit-R2R).torrent

2013-12-01 12:40 - 2013-12-01 12:41 - 00000000 ___DC C:\Users\Gregg\AppData\Local\Mobogenie

2013-12-01 12:40 - 2013-12-01 12:40 - 00000000 ___DC C:\Users\Gregg\Documents\Mobogenie

2013-12-01 12:40 - 2013-12-01 12:40 - 00000000 ___DC C:\Users\Gregg\.android

2013-12-01 12:40 - 2013-12-01 12:40 - 00000000 ____C C:\Users\Gregg\daemonprocess.txt

2013-12-01 12:38 - 2013-12-01 12:39 - 00000000 ___DC C:\Program Files (x86)\IminentToolbar

2013-12-01 12:35 - 2013-12-01 12:40 - 00000000 ___DC C:\Program Files (x86)\TornTV.com

2013-12-01 12:35 - 2013-12-01 12:35 - 00321920 ____C C:\Users\Gregg\Downloads\Ableton_Live_9_Suite_9.0.exe

2013-12-01 12:31 - 2013-12-01 12:31 - 02308232 ____C C:\Users\Gregg\Downloads\Ableton_Live_Suite_9.1_32-bit.exe

2013-12-01 12:04 - 2013-12-01 12:05 - 00000496 ____C C:\Users\Gregg\.lmmsrc.xml

2013-12-01 11:55 - 2013-12-01 11:55 - 00000000 ___DC C:\Users\Gregg\lmms

2013-12-01 11:52 - 2013-12-01 11:52 - 00401720 ____C (Softonic                                        ) C:\Users\Gregg\Downloads\SoftonicDownloader_for_lmms.exe

2013-12-01 11:49 - 2013-12-01 11:49 - 00401728 ____C (Softonic                                        ) C:\Users\Gregg\Downloads\SoftonicDownloader_for_midipiano.exe

 

==================== One Month Modified Files and Folders =======

 

2013-12-30 19:02 - 2013-12-30 19:02 - 00000000 ___DC C:\FRST

2013-12-30 10:53 - 2011-12-23 02:23 - 02058637 ____C C:\Windows\WindowsUpdate.log

2013-12-30 10:52 - 2012-03-12 12:49 - 02304624 ____C C:\FaceProv.log

2013-12-30 10:51 - 2011-12-23 03:04 - 00155629 ____C C:\Windows\System32\fastboot.set

2013-12-30 10:51 - 2009-07-13 21:08 - 00032576 _____ C:\Windows\Tasks\SCHEDLGU.TXT

2013-12-30 10:51 - 2009-07-13 21:08 - 00000006 ___HC C:\Windows\Tasks\SA.DAT

2013-12-30 10:50 - 2013-12-30 09:15 - 00000784 ____C C:\Windows\setupact.log

2013-12-30 10:45 - 2009-07-13 20:45 - 00021280 ___HC C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0

2013-12-30 10:45 - 2009-07-13 20:45 - 00021280 ___HC C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0

2013-12-30 10:25 - 2013-12-30 10:25 - 00003288 ____N C:\bootsqm.dat

2013-12-30 09:46 - 2013-05-07 13:57 - 00000000 ___DC C:\Users\Gregg\AppData\Roaming\Spotify

2013-12-30 09:45 - 2011-12-23 02:56 - 00000000 ___DC C:\ProgramData\VeriFace

2013-12-30 09:44 - 2012-03-12 12:50 - 00000000 ___DC C:\users\Gregg

2013-12-30 09:40 - 2013-04-26 07:45 - 00200882 ____C C:\Windows\PFRO.log

2013-12-30 09:39 - 2013-12-30 09:33 - 57196026 ____C C:\Users\Gregg\Downloads\Unconfirmed 727329.crdownload

2013-12-30 09:38 - 2013-04-25 10:06 - 00000000 ___DC C:\ProgramData\AVG2013

2013-12-30 09:38 - 2012-03-12 13:47 - 00000000 ___DC C:\ProgramData\MFAData

2013-12-30 09:35 - 2013-04-25 10:06 - 00000000 __HDC C:\$AVG

2013-12-30 09:32 - 2013-12-30 09:32 - 00045508 ____C C:\ProgramData\1388424726.bdinstall.bin

2013-12-30 09:32 - 2013-12-30 09:32 - 00000000 ___DC C:\Users\Gregg\AppData\Roaming\QuickScan

2013-12-30 09:32 - 2013-12-30 09:31 - 10447328 ____C C:\Users\Gregg\Downloads\Antivirus_Free_Edition_x64.exe

2013-12-30 09:31 - 2013-12-30 09:31 - 00162208 ____C C:\Users\Gregg\Downloads\Antivirus_Free_Edition.exe

2013-12-30 09:30 - 2013-12-30 09:30 - 00001109 ____C C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk

2013-12-30 09:30 - 2013-12-30 09:30 - 00000000 ___DC C:\Users\Gregg\AppData\Roaming\Malwarebytes

2013-12-30 09:30 - 2013-12-30 09:30 - 00000000 ___DC C:\ProgramData\Malwarebytes

2013-12-30 09:30 - 2013-12-30 09:30 - 00000000 ___DC C:\Program Files (x86)\Malwarebytes' Anti-Malware

2013-12-30 09:29 - 2013-12-30 09:29 - 10285040 ____C (Malwarebytes Corporation                                    ) C:\Users\Gregg\Downloads\mbam-setup-1.75.0.1300 (1).exe

2013-12-30 09:28 - 2013-12-30 09:28 - 10285040 ____C (Malwarebytes Corporation                                    ) C:\Users\Gregg\Downloads\mbam-setup-1.75.0.1300.exe

2013-12-30 09:08 - 2013-12-22 12:17 - 00092672 __SHC C:\Users\Gregg\Desktop\Thumbs.db

2013-12-29 15:19 - 2009-07-13 19:20 - 00000000 ___DC C:\Windows\PolicyDefinitions

2013-12-29 15:00 - 2013-12-29 15:00 - 00000894 ____C C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cf04e9ce9f5e09.job

2013-12-29 14:53 - 2013-12-29 14:39 - 00008011 ____C C:\Windows\IE11_main.log

2013-12-29 14:51 - 2013-12-29 14:51 - 23212032 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 12995584 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 05765120 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 02764288 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb

2013-12-29 14:51 - 2013-12-29 14:51 - 02724864 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb

2013-12-29 14:51 - 2013-12-29 14:51 - 02332160 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 01993728 _____ (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl

2013-12-29 14:51 - 2013-12-29 14:51 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl

2013-12-29 14:51 - 2013-12-29 14:51 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 01394176 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 01228800 _____ (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00942592 _____ (Microsoft Corporation) C:\Windows\System32\jsIntl.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00940032 _____ (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe

2013-12-29 14:51 - 2013-12-29 14:51 - 00817664 _____ (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00774144 _____ (Microsoft Corporation) C:\Windows\System32\jscript.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00708608 _____ (Microsoft Corporation) C:\Windows\System32\jscript9diag.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00626176 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat

2013-12-29 14:51 - 2013-12-29 14:51 - 00616104 _____ (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat

2013-12-29 14:51 - 2013-12-29 14:51 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00574976 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00548352 _____ (Microsoft Corporation) C:\Windows\System32\vbscript.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00453120 _____ (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00413696 _____ (Microsoft Corporation) C:\Windows\System32\html.iec

2013-12-29 14:51 - 2013-12-29 14:51 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec

2013-12-29 14:51 - 2013-12-29 14:51 - 00296960 _____ (Microsoft Corporation) C:\Windows\System32\dxtrans.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00263376 _____ (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00247808 _____ (Microsoft Corporation) C:\Windows\System32\msls31.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00243200 _____ (Microsoft Corporation) C:\Windows\System32\webcheck.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00235520 _____ (Microsoft Corporation) C:\Windows\System32\url.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00235008 _____ (Microsoft Corporation) C:\Windows\System32\elshyph.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00218624 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe

2013-12-29 14:51 - 2013-12-29 14:51 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00195584 _____ (Microsoft Corporation) C:\Windows\System32\msrating.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00167424 _____ (Microsoft Corporation) C:\Windows\System32\iexpress.exe

2013-12-29 14:51 - 2013-12-29 14:51 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe

2013-12-29 14:51 - 2013-12-29 14:51 - 00147968 _____ (Microsoft Corporation) C:\Windows\System32\occache.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00143872 _____ (Microsoft Corporation) C:\Windows\System32\wextract.exe

2013-12-29 14:51 - 2013-12-29 14:51 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe

2013-12-29 14:51 - 2013-12-29 14:51 - 00139264 _____ (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe

2013-12-29 14:51 - 2013-12-29 14:51 - 00135680 _____ (Microsoft Corporation) C:\Windows\System32\iepeers.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00131072 _____ (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe

2013-12-29 14:51 - 2013-12-29 14:51 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00111616 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollector.exe

2013-12-29 14:51 - 2013-12-29 14:51 - 00105984 _____ (Microsoft Corporation) C:\Windows\System32\iesysprep.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00101376 _____ (Microsoft Corporation) C:\Windows\System32\inseng.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00090112 _____ (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe

2013-12-29 14:51 - 2013-12-29 14:51 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00086016 _____ (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe

2013-12-29 14:51 - 2013-12-29 14:51 - 00084992 _____ (Microsoft Corporation) C:\Windows\System32\mshtmled.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00083968 _____ (Microsoft Corporation) C:\Windows\System32\MshtmlDac.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00081408 _____ (Microsoft Corporation) C:\Windows\System32\icardie.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00077312 _____ (Microsoft Corporation) C:\Windows\System32\tdc.ocx

2013-12-29 14:51 - 2013-12-29 14:51 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe

2013-12-29 14:51 - 2013-12-29 14:51 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe

2013-12-29 14:51 - 2013-12-29 14:51 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00066048 _____ (Microsoft Corporation) C:\Windows\System32\iesetup.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx

2013-12-29 14:51 - 2013-12-29 14:51 - 00062464 _____ (Microsoft Corporation) C:\Windows\System32\pngfilt.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00053760 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00052224 _____ (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\System32\mshtmler.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\System32\ieetwproxystub.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00048128 _____ (Microsoft Corporation) C:\Windows\System32\imgutil.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00040448 _____ (Microsoft Corporation) C:\Windows\System32\JavaScriptCollectionAgent.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00033792 _____ (Microsoft Corporation) C:\Windows\System32\iernonce.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00030208 _____ (Microsoft Corporation) C:\Windows\System32\licmgr10.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll

2013-12-29 14:51 - 2013-12-29 14:51 - 00013824 _____ (Microsoft Corporation) C:\Windows\System32\mshta.exe

2013-12-29 14:51 - 2013-12-29 14:51 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe

2013-12-29 14:51 - 2013-12-29 14:51 - 00013312 _____ (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe

2013-12-29 14:51 - 2013-12-29 14:51 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe

2013-12-29 14:51 - 2013-12-29 14:51 - 00004096 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollectorres.dll

2013-12-29 14:45 - 2013-12-29 14:45 - 00002255 ____C C:\Users\Public\Desktop\Google Chrome.lnk

2013-12-29 14:45 - 2012-03-12 12:55 - 00000000 ___DC C:\Users\Gregg\AppData\Local\Google

2013-12-29 14:44 - 2011-12-23 03:02 - 00000000 ___DC C:\Program Files (x86)\Google

2013-12-29 14:40 - 2013-12-29 14:40 - 00000000 ___HC C:\Users\Gregg\AppData\Local\BITE1F5.tmp

2013-12-29 14:40 - 2012-03-13 16:19 - 00000000 ___DC C:\Users\Gregg\AppData\Local\Deployment

2013-12-29 14:39 - 2013-12-29 14:39 - 02077392 ____C (Microsoft Corporation) C:\Users\Gregg\Downloads\IE11-Windows6.1.exe

2013-12-29 14:28 - 2013-05-07 13:58 - 00000000 ___DC C:\Users\Gregg\AppData\Local\Spotify

2013-12-29 06:38 - 2012-05-28 12:24 - 00000000 ___DC C:\Users\Gregg\Documents\Finance

2013-12-29 06:33 - 2013-12-29 06:32 - 00000000 ___DC C:\Spotify

2013-12-29 06:32 - 2013-12-29 06:32 - 00000000 ___DC C:\DAEMON Tools Lite

2013-12-29 06:28 - 2013-12-29 06:28 - 00000279 ____C C:\ProgramData\vrjrtll.reg

2013-12-29 06:28 - 2013-12-29 06:27 - 95025368 ___CT C:\ProgramData\vrjrtll.fee

2013-12-29 06:27 - 2013-12-29 06:27 - 00150016 ____C C:\ProgramData\lltrjrv.jss

2013-12-29 06:27 - 2013-12-29 06:27 - 00061532 ___CT (Microsoft Corporation) C:\ProgramData\vrjrtll.zvv

2013-12-29 06:27 - 2013-12-29 06:27 - 00000000 ____C C:\ProgramData\vrjrtll.odd

2013-12-29 06:22 - 2009-07-13 21:13 - 00875230 ____C C:\Windows\System32\PerfStringBackup.INI

2013-12-29 06:21 - 2012-04-01 13:42 - 00000830 ____C C:\Windows\Tasks\Adobe Flash Player Updater.job

2013-12-20 15:58 - 2013-08-16 12:34 - 00000000 ___DC C:\Users\Gregg\AppData\Local\PokerStars

2013-12-15 13:34 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\rescache

2013-12-15 04:43 - 2009-07-13 20:45 - 00579952 ____C C:\Windows\System32\FNTCACHE.DAT

2013-12-15 04:39 - 2013-12-15 04:35 - 03155968 _____ (Microsoft Corporation) C:\Windows\System32\win32k.sys

2013-12-15 04:37 - 2013-12-15 04:35 - 00497152 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\afd.sys

2013-12-15 04:37 - 2013-12-15 04:34 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll

2013-12-15 04:37 - 2013-12-15 04:34 - 00081408 _____ (Microsoft Corporation) C:\Windows\System32\imagehlp.dll

2013-12-15 04:37 - 2013-12-15 04:34 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll

2013-12-15 04:37 - 2013-12-15 04:34 - 00002048 _____ (Microsoft Corporation) C:\Windows\System32\tzres.dll

2013-12-15 04:36 - 2013-12-15 04:34 - 00404480 _____ (Microsoft Corporation) C:\Windows\System32\gdi32.dll

2013-12-15 04:36 - 2013-12-15 04:34 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll

2013-12-15 04:36 - 2013-12-15 04:34 - 00202752 _____ (Microsoft Corporation) C:\Windows\System32\scrrun.dll

2013-12-15 04:36 - 2013-12-15 04:34 - 00168960 _____ (Microsoft Corporation) C:\Windows\System32\wscript.exe

2013-12-15 04:36 - 2013-12-15 04:34 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll

2013-12-15 04:36 - 2013-12-15 04:34 - 00156160 _____ (Microsoft Corporation) C:\Windows\System32\cscript.exe

2013-12-15 04:36 - 2013-12-15 04:34 - 00150016 _____ (Microsoft Corporation) C:\Windows\System32\wshom.ocx

2013-12-15 04:36 - 2013-12-15 04:34 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe

2013-12-15 04:36 - 2013-12-15 04:34 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe

2013-12-15 04:36 - 2013-12-15 04:34 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx

2013-12-15 04:29 - 2012-05-03 08:43 - 00000000 ___DC C:\Windows\Minidump

2013-12-14 15:13 - 2009-07-13 19:20 - 00000000 ___DC C:\Windows\System32\NDF

2013-12-13 12:19 - 2013-02-05 13:44 - 00000000 ___DC C:\Program Files\Microsoft Office 15

2013-12-10 13:58 - 2012-04-01 13:42 - 00692616 ____C (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe

2013-12-10 13:58 - 2012-04-01 13:42 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater

2013-12-10 13:58 - 2012-03-13 15:27 - 00071048 ____C (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl

2013-12-04 13:44 - 2013-08-16 12:33 - 00000000 ___DC C:\Program Files (x86)\PokerStars

2013-12-01 14:20 - 2012-03-13 15:26 - 00000000 ___DC C:\Users\Gregg\AppData\Roaming\Azureus

2013-12-01 14:11 - 2013-12-01 14:11 - 00000000 ___DC C:\Program Files\Common Files\Propellerhead Software

2013-12-01 14:11 - 2012-03-14 09:53 - 00000000 ___DC C:\Users\Gregg\AppData\Roaming\Ableton

2013-12-01 13:30 - 2013-12-01 13:30 - 00028458 ____C C:\Users\Gregg\Downloads\Ableton.Live.9.Suite.9.1.0.(Win.64.bit).(patch.IO).torrent

2013-12-01 12:43 - 2013-12-01 12:43 - 00021349 ____C C:\Users\Gregg\Downloads\Ableton.Live.9.Suite.9.0.1.(64.bit-R2R).torrent

2013-12-01 12:41 - 2013-12-01 12:40 - 00000000 ___DC C:\Users\Gregg\AppData\Local\Mobogenie

2013-12-01 12:40 - 2013-12-01 12:40 - 00000000 ___DC C:\Users\Gregg\Documents\Mobogenie

2013-12-01 12:40 - 2013-12-01 12:40 - 00000000 ___DC C:\Users\Gregg\.android

2013-12-01 12:40 - 2013-12-01 12:40 - 00000000 ____C C:\Users\Gregg\daemonprocess.txt

2013-12-01 12:40 - 2013-12-01 12:35 - 00000000 ___DC C:\Program Files (x86)\TornTV.com

2013-12-01 12:40 - 2012-11-06 05:47 - 00000000 ___DC C:\Users\Gregg\AppData\Local\cache

2013-12-01 12:39 - 2013-12-01 12:38 - 00000000 ___DC C:\Program Files (x86)\IminentToolbar

2013-12-01 12:39 - 2012-03-13 15:27 - 00001729 ____C C:\Windows\SysWOW64\InstallUtil.InstallLog

2013-12-01 12:35 - 2013-12-01 12:35 - 00321920 ____C C:\Users\Gregg\Downloads\Ableton_Live_9_Suite_9.0.exe

2013-12-01 12:31 - 2013-12-01 12:31 - 02308232 ____C C:\Users\Gregg\Downloads\Ableton_Live_Suite_9.1_32-bit.exe

2013-12-01 12:05 - 2013-12-01 12:04 - 00000496 ____C C:\Users\Gregg\.lmmsrc.xml

2013-12-01 11:55 - 2013-12-01 11:55 - 00000000 ___DC C:\Users\Gregg\lmms

2013-12-01 11:52 - 2013-12-01 11:52 - 00401720 ____C (Softonic                                        ) C:\Users\Gregg\Downloads\SoftonicDownloader_for_lmms.exe

2013-12-01 11:49 - 2013-12-01 11:49 - 00401728 ____C (Softonic                                        ) C:\Users\Gregg\Downloads\SoftonicDownloader_for_midipiano.exe

 

Files to move or delete:

====================

C:\Users\Gregg\AppData\Local\Temp\GZ_INSTALL_0\setuplauncher.exe

C:\ProgramData\vrjrtll.reg

 

 

==================== Known DLLs (Whitelisted) ================

 

 

==================== Bamital & volsnap Check =================

 

C:\Windows\System32\winlogon.exe => MD5 is legit

C:\Windows\System32\wininit.exe => MD5 is legit

C:\Windows\SysWOW64\wininit.exe => MD5 is legit

C:\Windows\explorer.exe => MD5 is legit

C:\Windows\SysWOW64\explorer.exe => MD5 is legit

C:\Windows\System32\svchost.exe => MD5 is legit

C:\Windows\SysWOW64\svchost.exe => MD5 is legit

C:\Windows\System32\services.exe => MD5 is legit

C:\Windows\System32\User32.dll => MD5 is legit

C:\Windows\SysWOW64\User32.dll => MD5 is legit

C:\Windows\System32\userinit.exe => MD5 is legit

C:\Windows\SysWOW64\userinit.exe => MD5 is legit

C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

 

==================== EXE ASSOCIATION =====================

 

HKLM\...\.exe: exefile => OK

HKLM\...\exefile\DefaultIcon: %1 => OK

HKLM\...\exefile\open\command: "%1" %* => OK

 

==================== Restore Points  =========================

 

Restore point made on: 2013-12-01 13:25:18

Restore point made on: 2013-12-01 14:06:04

Restore point made on: 2013-12-09 11:41:05

Restore point made on: 2013-12-15 04:35:43

Restore point made on: 2013-12-24 06:33:46

Restore point made on: 2013-12-29 14:41:35

Restore point made on: 2013-12-29 14:50:03

Restore point made on: 2013-12-30 09:33:42

Restore point made on: 2013-12-30 09:39:51

 

==================== Memory info =========================== 

 

Percentage of memory in use: 16%

Total physical RAM: 4039.86 MB

Available physical RAM: 3372.86 MB

Total Pagefile: 4038.06 MB

Available Pagefile: 3361.96 MB

Total Virtual: 8192 MB

Available Virtual: 8191.87 MB

 

==================== Drives ================================

 

Drive c: () (Fixed) (Total:421.81 GB) (Free:103.47 GB) NTFS

Drive d: (LENOVO) (Fixed) (Total:29 GB) (Free:27.45 GB) NTFS

Drive g: () (Removable) (Total:3.86 GB) (Free:0.53 GB) FAT32

Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS

Drive y: () (Fixed) (Total:0.2 GB) (Free:0.15 GB) NTFS ==>[system with boot components (obtained from reading drive)]

 

==================== MBR & Partition Table ==================

 

========================================================

Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 510ACB4C)

Partition 1: (Active) - (Size=200 MB) - (Type=07 NTFS)

Partition 2: (Not Active) - (Size=422 GB) - (Type=07 NTFS)

Partition 3: (Not Active) - (Size=29 GB) - (Type=OF Extended)

Partition 4: (Not Active) - (Size=15 GB) - (Type=12)

 

========================================================

Disk: 1 (Size: 4 GB) (Disk ID: 003FB7F3)

Partition 1: (Active) - (Size=4 GB) - (Type=0B)

 

 

LastRegBack: 2013-12-20 09:23

 

==================== End Of Log ============================

Link to post
Share on other sites

Please download the attached fixlist.txt and copy it to your flashdrive.

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

On Vista or Windows 7: Now please enter System Recovery Options. (as you did before)

Run FRST64 or FRST (which ever one you're using) and press the Fix button just once and wait.

The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.

See if the computer boots normally now and if so..........run MBAR

If not...rescan with FRST and post the new log

Download Malwarebytes Anti-Rootkit from HERE

  • Unzip the contents to a folder in a convenient location.
  • Open the folder where the contents were unzipped and run mbar.exe
  • Follow the instructions in the wizard to update and allow the program to scan your computer for threats.
  • Click on the Cleanup button to remove any threats and reboot if prompted to do so.
  • Wait while the system shuts down and the cleanup process is performed.
  • Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
  • When done, please post the two logs produced they will be in the MBAR folder..... mbar-log.txt and system-log.txt
To attach a log if needed:

Bottom right corner of this page.

reply1.jpg

New window that comes up.

replyer1.jpg

~~~~~~~~~~~~~~~~~~~~~~~

Note:

If no additional threats were found, verify that your system is now running normally, making sure that the following items are functional:

Internet access

Windows Update

Windows Firewall

If there are additional problems with your system, such as any of those listed above or other system issues, then run the fixdamage tool included with Malwarebytes Anti-Rootkit and reboot. It's located in the Plugins folder which is in the MBAR folder.

Just run fixdamage.exe.

Verify that they are now functioning normally.

MrC

Link to post
Share on other sites

Please download and run ComboFix.

The most important things to remember when running it is to disable all your malware programs and run Combofix from your desktop.

Please visit this webpage for download links, and instructions for running ComboFix

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Please make sure you click download buttons that look similar to this, not "sponsored ad links":

bleep-crop.jpg

Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Information on disabling your malware programs can be found Here.

Make sure you run ComboFix from your desktop.

Give it at least 30-45 minutes to finish if needed.

Please include the C:\ComboFix.txt in your next reply for further review.

---------->NOTE<----------

If you get the message Illegal operation attempted on registry key that has been marked for deletion after you run ComboFix....please reboot the computer, this should resolve the problem. You may have to do this several times if needed.

MrC

Link to post
Share on other sites

Looks Good.....

Lets clean out any adware/spyware now: (this will require a reboot so save all your work)

Please download AdwCleaner by Xplode and save to your Desktop.

Make sure you click on download buttons that look similar to this, not "sponsored ad links":

bleep-crop.jpg

  • Double click on AdwCleaner.exe to run the tool.

    Vista/Windows 7/8 users right-click and select Run As Administrator

  • Click on the Scan button.
  • AdwCleaner will begin...be patient as the scan may take some time to complete.
  • When it's done you'll see: Pending: Please uncheck elements you don't want removed.
  • Now click on the Report button...a logfile (AdwCleaner[R0].txt) will open in Notepad for review.
  • Look over the log especially under Files/Folders for any program you want to save.
  • If there's a program you may want to save, just uncheck it from AdwCleaner.
  • If you're not sure, post the log for review. (all items found are adware/spyware/foistware)
  • If you're ready to clean it all up.....click the Clean button.
  • After rebooting, a logfile report (AdwCleaner[s0].txt) will open automatically.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of that logfile will also be saved in the C:\AdwCleaner folder.
  • Items that are deleted are moved to the Quarantine Folder: C:\AdwCleaner\Quarantine
  • To restore an item that has been deleted:
  • Go to Tools > Quarantine Manager > check what you want restored > now click on Restore.
Then..................

Open up Malwarebytes > Settings Tab > Scanner Settings > Under action for PUP > Select: Show in Results List and Check for removal.

Please Update and run a FULL Scan with Malwarebytes Anti-Malware, post the report.

Make sure that everything is checked, and click Remove Selected.

Please let me know how computer is running now, MrC

Link to post
Share on other sites

There does seem to be one odd thing though... although my computer seems fine now, and is starting up quickly etc - I do seem to be having a bit of trouble with IE Browser. When I click a link or go to open a new tab, most of the time it's just staying blank, the web page doesn't even seem to begin to load.

 

Do you have any idea what the cause might be?

 

Much appreciated.

Gregg

Link to post
Share on other sites

Lets take a look:

Please download Farbar Recovery Scan Tool and save it to a folder. (use correct version for your system.....Which system am I using?)

Please make sure you click download buttons that look similar to this, not "sponsored ad links":

bleep-crop.jpg

  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
If the logs are large, you can attach them:

To attach a log:

Bottom right corner of this page.

reply1.jpg

New window that comes up.

replyer1.jpg

MrC

Link to post
Share on other sites

Not much showing.

Download the attached fixlist.txt to the same folder as FRST.

Run FRST.exe and click Fix only once and wait

The tool will create a log (Fixlog.txt) in the folder, please post it to your reply.

Then......if no improvement, you can always reset IE:

http://malwaretips.com/blogs/reset-internet-explorer-settings/

Let me know....MrC

Link to post
Share on other sites

Good....

Lets check your computers security before you go and we have a little cleanup to do also:

Download Security Check by screen317 from HERE or HERE.

  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • If you get Unsupported operating system. Aborting now, just reboot and try again.
  • A Notepad document should open automatically called checkup.txt.
  • Please Post the contents of that document.
  • Do Not Attach It!!!
MrC
Link to post
Share on other sites

Results of screen317's Security Check version 0.99.78

Windows 7 Service Pack 1 x64 (UAC is enabled)

Internet Explorer 11

``````````````Antivirus/Firewall Check:``````````````

Windows Firewall Enabled!

Microsoft Security Essentials

Antivirus up to date!

`````````Anti-malware/Other Utilities Check:`````````

Malwarebytes Anti-Malware version 1.75.0.1300

JavaFX 2.1.1

Java 7 Update 45

Adobe Reader 10.1.8 Adobe Reader out of Date!

Google Chrome 31.0.1650.63

````````Process Check: objlist.exe by Laurent````````

Microsoft Security Essentials MSMpEng.exe

Microsoft Security Essentials msseces.exe

`````````````````System Health check`````````````````

Total Fragmentation on Drive C: 3%

````````````````````End of Log``````````````````````

Link to post
Share on other sites

Out dated programs on the system are vulnerable to malware.
Please update or uninstall them:


--------------------------------

Adobe Reader 10.1.8 Adobe Reader out of Date! <---please check for an update if available or uninstall and download and install Foxit Reader which is less vulnerable to malware and much better than Adobe. Don't install any toolbars that may come with it (ASK Toolbar).

~~~~~~~~~~~~~~~~~~~~~~

A little clean up to do....

Please Uninstall ComboFix: (if you used it)

Press the Windows logo key + R to bring up the "run box"

Copy and paste next command in the field:

ComboFix /uninstall

Make sure there's a space between Combofix and /

cf2.jpg

Then hit enter.
This will uninstall Combofix, delete its related folders and files, hide file extensions, hide the system/hidden files and clears System Restore cache and create new Restore point

(If that doesn't work.....you can simply rename ComboFix.exe to Uninstall.exe and double click it to complete the uninstall or download and run the uninstaller)

---------------------------------

Please download OTC to your desktop. (This will clean up most of the tools and logs)
http://oldtimer.geekstogo.com/OTC.exe

Double-click OTC to run it. (Vista and up users, please right click on OTC and select "Run as an Administrator")
Click on the CleanUp! button and follow the prompts.
(If you get a warning from your firewall or other security programs regarding OTC attempting to contact the Internet, please allow the connection.)
You will be asked to reboot the machine to finish the Cleanup process, choose Yes.
After the reboot all the tools we used should be gone.
Note: Some more recently created tools may not yet be removed by OTC. Feel free to manually delete any tools it leaves behind.

Any other programs or logs you can manually delete. (right click.....Delete)
IE: RogueKiller.exe, RKreport.txt, RK_Quarantine folder, C:\FRST folder, FRST-OlderVersion folder, MBAR folder, etc....AdwCleaner > just run the program and click uninstall.

Note:
If you used FRST and can't delete the quarantine folder:
Download the fixlist.txt to the same folder as FRST.exe.
Run FRST.exe and click Fix only once and wait
That will delete the quarantine folder created by FRST.
The rest you can manually delete.

-------------------------------

Any questions...please post back.
If you think I've helped you, please leave a comment > click on my avatar picture > click Profile Feed.

Take a look at My Preventive Maintenance to avoid being infected again.

Good Luck and Thanks for using the forum, MrC

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.