Jump to content

please help suspect infection!


juan

Recommended Posts

.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Professional 
Boot Device: \Device\HarddiskVolume1
Install Date: 07/04/2013 15:13:41
System Uptime: 17/02/2014 20:46:12 (3 hours ago)
.
Motherboard: Hewlett-Packard  |  | 309B
Processor: AMD Turion 64 Mobile Technology ML-32 | U23 | 1800/mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 37 GiB total, 8,896 GiB free.
D: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Adaptador de minipuerto WiFi virtual de Microsoft
Device ID: {5D624F94-8850-40C3-A3FA-A4FD2080BAF3}\VWIFIMP\5&38348CA3&0&01
Manufacturer: Microsoft
Name: Microsoft Virtual WiFi Miniport Adapter #7
PNP Device ID: {5D624F94-8850-40C3-A3FA-A4FD2080BAF3}\VWIFIMP\5&38348CA3&0&01
Service: vwifimp
.
==== System Restore Points ===================
.
No restore point in system.
.
==== Image File Execution Options =============
.
IFEO: excel.exe - "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe"
IFEO: groove.exe - "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe"
IFEO: infopath.exe - "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe"
IFEO: msaccess.exe - "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe"
IFEO: msoxmled.exe - "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe"
IFEO: mspub.exe - "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe"
IFEO: mstore.exe - "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe"
IFEO: offdiag.exe - "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe"
IFEO: ois.exe - "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe"
IFEO: onenote.exe - "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe"
IFEO: outlook.exe - "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe"
IFEO: pmbbrowser.exe - "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe"
IFEO: pmblauncher.exe - "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe"
IFEO: pmbmapview.exe - "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe"
IFEO: powerpnt.exe - "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe"
IFEO: winword.exe - "C:\Program Files\TuneUp Utilities 2014\TUAutoReactivator32.exe"
.
==== Installed Programs ======================
.
Adobe Reader 9.1
Argente - Registry Cleaner 3.1.0.1
avast! Free Antivirus
CCleaner
Conexant AC-Link Audio
Defraggler
Equalify v2.2.1 (Stable)
FormatFactory 3.2.0.1
Glary Utilities 4.1
GOM Player
Google Chrome
Google Update Helper
HP Quick Launch Buttons
HP Support Solutions Framework
Malwarebytes Anti-Malware versión 1.75.0.1300
Microsoft .NET Framework 4 Client Profile
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
MSXML 4.0 SP3 Parser
Paquete de idioma de Microsoft .NET Framework 4 Client Profile ESN
PhotoScape
Revo Uninstaller 1.95
Spotify
Texas Instruments PCIxx21/x515/xx12 drivers.
TIPCI
TuneUp Utilities 2014 (es-MX)
Unity Web Player
Virtual DJ - Atomix Productions
.
==== End Of File ===========================
DDS (Ver_2012-11-20.01) - NTFS_x86 
Internet Explorer: 9.0.8112.16476
Run by user at 23:11:26 on 2014-02-17
Microsoft Windows 7 Professional   6.1.7601.1.1252.34.3082.18.766.231 [GMT -6:00]
.
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Hp\Common\HPSupportSolutionsFrameworkService.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\UI0Detect.exe
C:\Windows\system32\LogonUI.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
.
============== Pseudo HJT Report ===============
.
uSearch Bar = Preserve
uProxyServer = localhost:21320
uProxyOverride = 127.0.0.1;localhost;10.*;192.168.*;127.0.0.1:895;127.0.0.1:896;<local>
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\alwil software\avast5\aswWebRepIE.dll
TB: avast! Online Security: {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - c:\program files\alwil software\avast5\aswWebRepIE.dll
TB: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\alwil software\avast5\aswWebRepIE.dll
uRun: [GUDelayStartup] c:\program files\glary utilities 4\StartupManager.exe -delayrun
mRun: [QlbCtrl.exe] c:\program files\hewlett-packard\hp quick launch buttons\QlbCtrl.exe /Start                                                                                                                                                                                              
mRun: [AvastUI.exe] "c:\program files\alwil software\avast5\AvastUI.exe" /nogui
mRun: [20131121] c:\program files\alwil software\avast5\setup\emupdate\f216cba8-ca45-4fcc-b7c1-ae23a5854ba9.exe /check
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRunOnce: [Malwarebytes Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
dRunOnce: [sPReview] "c:\windows\system32\spreview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xport to Microsoft Excel - c:\progra~1\micros~1\office12\EXCEL.EXE/3000
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
   If you wish to scan all of them, select the 'Force scan all domains' option.
.
TCP: NameServer = 192.168.1.254
TCP: Interfaces\{48349739-7F5C-45FA-ADC0-298CFBE53BDF} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{7F93421A-EEF9-4885-AC8B-5551C91E810B} : DHCPNameServer = 192.168.1.254
TCP: Interfaces\{7F93421A-EEF9-4885-AC8B-5551C91E810B}\9525542455 : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{E9E4C4ED-69C0-4C47-A5EC-0726858F02A0} : DHCPNameServer = 192.168.1.254
TCP: Interfaces\{F37389C1-D19A-43E7-A674-6E6E9776675E} : DHCPNameServer = 192.168.1.1
SSODL: WebCheck - <orphaned>
SEH: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\32.0.1700.107\installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
IFEO: excel.exe - "c:\program files\tuneup utilities 2014\TUAutoReactivator32.exe"
IFEO: groove.exe - "c:\program files\tuneup utilities 2014\TUAutoReactivator32.exe"
IFEO: infopath.exe - "c:\program files\tuneup utilities 2014\TUAutoReactivator32.exe"
IFEO: msaccess.exe - "c:\program files\tuneup utilities 2014\TUAutoReactivator32.exe"
IFEO: msoxmled.exe - "c:\program files\tuneup utilities 2014\TUAutoReactivator32.exe"
.
Note: multiple IFEO entries found. Please refer to Attach.txt
Hosts: 127.0.0.1 www.spywareinfo.com
.
============= SERVICES / DRIVERS ===============
.
R0 aswRvrt;avast! Revert;c:\windows\system32\drivers\aswRvrt.sys [2013-4-11 49944]
R0 aswVmm;avast! VM Monitor;c:\windows\system32\drivers\aswVmm.sys [2013-4-11 180248]
R0 BootDefragDriver;BootDefragDriver;c:\windows\system32\drivers\BootDefragDriver.sys [2014-1-23 14528]
R0 SmartDefragDriver;SmartDefragDriver;c:\windows\system32\drivers\SmartDefragDriver.sys [2014-2-2 18624]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2013-4-11 775952]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswsp.sys [2013-4-11 410784]
R1 HssDRV6;Hotspot Shield Routing Driver 6;c:\windows\system32\drivers\hssdrv6.sys [2013-12-9 39624]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2013-4-11 67824]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2014-2-1 50344]
R2 HPSupportSolutionsFrameworkService;HP Support Solutions Framework Service;c:\program files\hp\common\HPSupportSolutionsFrameworkService.exe [2013-12-17 46904]
R3 mbamchameleon;mbamchameleon;c:\windows\system32\drivers\mbamchameleon.sys [2014-2-17 31560]
R3 taphss6;Anchorfree HSS VPN Adapter;c:\windows\system32\drivers\taphss6.sys [2013-10-15 37064]
R3 VST_DPV;VST_DPV;c:\windows\system32\drivers\VSTDPV3.SYS [2009-7-13 980992]
R3 VSTHWATI;VSTHWATI;c:\windows\system32\drivers\VSTATI3.SYS [2009-7-13 236032]
S?4 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2014-2-5 40776]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 LiveUpdateSvc;LiveUpdate;c:\program files\iobit\liveupdate\LiveUpdate.exe [2014-1-31 2151200]
S3 aswStm;aswStm;c:\windows\system32\drivers\aswstm.sys [2013-12-18 64168]
S3 aswTap;avast! SecureLine TAP Adapter v3;c:\windows\system32\drivers\aswTap.sys [2013-10-23 38472]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\ieetwcollector.exe [2014-2-3 108032]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2013-12-6 52224]
S4 Com4QLBEx;Com4QLBEx;c:\program files\hewlett-packard\hp quick launch buttons\Com4QLBEx.exe [2013-4-7 227896]
.
=============== Created Last 30 ================
.
2014-02-18 04:52:39 107224 ----a-w- c:\windows\system32\drivers\48230029.sys
2014-02-18 02:51:14 31560 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-02-18 02:49:18 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-02-18 02:49:18 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2014-02-13 14:15:53 255488 ----a-w- c:\windows\system32\pev.exe
2014-02-11 15:58:49 -------- d-----w- c:\program files\CCleaner
2014-02-07 18:46:15 -------- d-----w- c:\program files\Panda Security
2014-02-06 18:06:22 221184 ------w- c:\program files\common files\installshield\iscript\IScript.dll
2014-02-06 18:06:21 221184 ------w- c:\program files\common files\installshield\engine\6\intel 32\iuser.dll
2014-02-06 18:06:20 32768 ------w- c:\program files\common files\installshield\engine\6\intel 32\objectps.dll
2014-02-06 18:06:19 77824 ------w- c:\program files\common files\installshield\engine\6\intel 32\ctor.dll
2014-02-05 16:00:19 40776 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2014-02-05 03:26:25 -------- d-----w- C:\b2146195e30394a1b88f9c
2014-02-04 21:51:58 7760024 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{f9859fd0-517b-440f-be78-d8e67bfb8348}\mpengine.dll
2014-02-04 19:23:37 212992 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\ILog.dll
2014-02-04 17:21:30 -------- d-----w- c:\windows\CheckSur
2014-02-04 02:14:07 -------- d-----w- c:\program files\CONEXANT
2014-02-03 22:49:05 2724864 ----a-w- c:\windows\system32\mshtml.tlb
2014-02-03 22:49:05 235216 ----a-w- c:\program files\internet explorer\sqmapi.dll
2014-02-03 22:49:04 270848 ----a-w- c:\program files\internet explorer\ieproxy.dll
2014-02-03 22:49:04 251392 ----a-w- c:\program files\internet explorer\IEShims.dll
2014-02-03 22:49:03 7211008 ----a-w- c:\program files\internet explorer\F12Resources.dll
2014-02-03 22:49:01 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll
2014-02-03 22:49:01 1389056 ----a-w- c:\program files\internet explorer\MemoryAnalyzer.dll
2014-02-03 22:49:00 61952 ----a-w- c:\windows\system32\iesetup.dll
2014-02-03 22:40:47 12625408 ----a-w- c:\windows\system32\wmploc.DLL
2014-02-03 22:40:40 164864 ----a-w- c:\program files\windows media player\wmplayer.exe
2014-02-03 22:25:54 1077760 ----a-w- c:\windows\system32\DWrite.dll
2014-02-03 22:25:52 808448 ----a-w- c:\windows\system32\FntCache.dll
2014-02-03 15:54:30 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2014-02-03 15:54:19 15224 ----a-w- c:\windows\system32\sdnclean.exe
2014-02-03 03:08:07 103424 ----a-w- c:\windows\system32\IObitSmartDefragExtension.dll
2014-02-03 03:07:55 18624 ----a-w- c:\windows\system32\drivers\SmartDefragDriver.sys
2014-02-01 02:31:55 92464 ----a-w- c:\windows\system32\bcmwlcoi.dll
2014-02-01 02:31:53 3616768 ----a-w- c:\windows\system32\bcmihvui.dll
2014-02-01 02:31:52 3928064 ----a-w- c:\windows\system32\bcmihvsrv.dll
2014-02-01 02:31:52 -------- d-----w- C:\DrvInstall
2014-02-01 01:48:57 -------- d-----w- c:\programdata\ProductData
2014-02-01 01:48:21 -------- d-----w- c:\programdata\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D}
2014-02-01 01:47:56 -------- d-----w- c:\programdata\IObit
2014-02-01 01:45:03 -------- d-----w- c:\program files\IObit
2014-02-01 01:44:22 -------- d-----w- c:\users\user\appdata\roaming\IObit
2014-01-30 21:10:07 -------- d-----w- c:\users\user\appdata\local\Apple Computer
2014-01-30 20:59:54 -------- d-----w- c:\users\user\appdata\local\Apple
2014-01-23 16:31:14 14528 ----a-w- c:\windows\system32\drivers\BootDefragDriver.sys
2014-01-23 15:24:57 22304 ----a-w- c:\windows\system32\RegBootDefrag.exe
2014-01-21 03:12:55 -------- d-----w- c:\users\user\appdata\local\Facebook
2014-01-20 17:07:02 -------- d-----w- c:\program files\Spotify
.
==================== Find3M  ====================
.
2014-02-01 06:04:23 64168 ----a-w- c:\windows\system32\drivers\aswstm.sys
2014-02-01 06:04:22 775952 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2014-02-01 06:04:22 67824 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-02-01 06:04:21 43152 ----a-w- c:\windows\avastSS.scr
2014-01-27 22:10:03 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-01-27 22:10:02 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-01-16 15:59:46 231584 ------w- c:\windows\system32\MpSigStub.exe
2013-12-18 22:12:31 180248 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2013-12-17 18:04:17 646144 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2013-12-17 18:04:17 194048 ----a-w- c:\windows\system32\elshyph.dll
2013-12-17 18:04:13 645120 ----a-w- c:\windows\system32\jsIntl.dll
2013-12-17 18:04:13 34816 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll
2013-12-17 18:04:12 1051136 ----a-w- c:\windows\system32\mshtmlmedia.dll
2013-12-17 18:04:06 61952 ----a-w- c:\windows\system32\MshtmlDac.dll
2013-12-17 17:59:00 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-12-17 17:59:00 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-12-17 17:59:00 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-12-17 17:59:00 4096 ---ha-w- c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-12-17 17:59:00 3584 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-12-17 17:59:00 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-12-17 17:59:00 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-12-17 17:59:00 2560 ---ha-w- c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-12-17 17:59:00 10752 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-12-17 17:53:50 1505280 ----a-w- c:\windows\system32\d3d11.dll
2013-12-07 00:21:32 152576 ----a-w- c:\windows\system32\msclmd.dll
2013-12-04 02:15:00 101664 ----a-w- c:\windows\system32\BootDefrag.exe
2013-11-26 08:52:26 51200 ----a-w- c:\windows\system32\ieetwproxystub.dll
2013-11-26 08:29:55 112128 ----a-w- c:\windows\system32\ieUnatt.exe
2013-11-26 08:29:52 108032 ----a-w- c:\windows\system32\ieetwcollector.exe
2013-11-26 08:28:16 553472 ----a-w- c:\windows\system32\jscript9diag.dll
2013-11-26 07:32:06 1928192 ----a-w- c:\windows\system32\inetcpl.cpl
2013-11-26 06:33:33 1820160 ----a-w- c:\windows\system32\wininet.dll
.
============= FINISH: 23:13:13,75 ===============
 

 

Link to post
Share on other sites

Hi there,
my name is Marius and I will assist you with your malware related problems.

Before we move on, please read the following points carefully.

  • First, read my instructions completely. If there is anything that you do not understand kindly ask before proceeding.
  • Perform everything in the correct order. Sometimes one step requires the previous one.
  • If you have any problems while following my instructions, Stop there and tell me the exact nature of your problem.
  • Do not run any other scans without instruction or add/remove software unless I tell you to do so. This would change the output of our tools and could be confusing for me.
  • Post all logfiles as a reply rather than as an attachment unless I specifically ask you. If you can not post all logfiles in one reply, feel free to use more posts.
  • If I don't hear from you within 3 days from this initial or any subsequent post, then this thread will be closed.
  • Stay with me. I will give you some advice about prevention after the cleanup process. Absence of symptoms does not always mean the computer is clean.
  • My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.

 
 
 
 
Scan with Gmer rootkit scanner

Please download Gmer from here by clicking on the "Download EXE" Button.
  • Double click on the randomly named GMER.exe. If asked to allow gmer.sys driver to load, please consent.
  • If it gives you a warning about rootkit activity and asks if you want to run scan...click on NO.
  • In the right panel, you will see several boxes that have been checked. Uncheck the following ...
    • Sections
    • IAT/EAT
    • Show All ( should be unchecked by default )

    [*]Leave everything else as it is. [*]Close all other running programs as well as your Browser. [*]Click the Scan button & wait for it to finish. [*]Once done click on the Save.. button, and in the File name area, type in "ark.txt" or it will save as a .log file which cannot be uploaded to your post. [*]Save it where you can easily find it, such as your desktop. [*]Please post the content of the ark.txt here.


**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries

Link to post
Share on other sites

my language is Spanish I use google translator to use these services thanks for the help.    GMER 2.1.19357 - http://www.gmer.net

Rootkit scan 2014-02-18 09:34:37
Windows 6.1.7601 Service Pack 1 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 FUJITSU_MHT2040AH_PL rev.006C 37,26GB
Running: c3g8xmdo.exe; Driver: C:\Users\user\AppData\Local\Temp\kxldapob.sys
 
 
---- System - GMER 2.1 ----
 
SSDT   \??\C:\Windows\system32\drivers\aswSnx.sys                                                                                                                                               ZwAddBootEntry [0x8C031ACC]
SSDT   \??\C:\Windows\system32\drivers\aswSnx.sys                                                                                                                                               ZwAssignProcessToJobObject [0x8C0325AA]
SSDT   \??\C:\Windows\system32\drivers\aswSnx.sys                                                                                                                                               ZwCreateEvent [0x8C03E692]
SSDT   \??\C:\Windows\system32\drivers\aswSnx.sys                                                                                                                                               ZwCreateEventPair [0x8C03E6DE]
SSDT   \??\C:\Windows\system32\drivers\aswSnx.sys                                                                                                                                               ZwCreateIoCompletion [0x8C03E878]
SSDT   \??\C:\Windows\system32\drivers\aswSnx.sys                                                                                                                                               ZwCreateMutant [0x8C03E600]
SSDT   \??\C:\Windows\system32\drivers\aswSP.sys                                                                                                                                                ZwCreateSection [0x8C0E8426]
SSDT   \??\C:\Windows\system32\drivers\aswSnx.sys                                                                                                                                               ZwCreateSemaphore [0x8C03E648]
SSDT   \??\C:\Windows\system32\drivers\aswSnx.sys                                                                                                                                               ZwCreateThread [0x8C032AE0]
SSDT   \??\C:\Windows\system32\drivers\aswSnx.sys                                                                                                                                               ZwCreateThreadEx [0x8C032CFC]
SSDT   \??\C:\Windows\system32\drivers\aswSnx.sys                                                                                                                                               ZwCreateTimer [0x8C03E832]
SSDT   \??\C:\Windows\system32\drivers\aswSnx.sys                                                                                                                                               ZwDebugActiveProcess [0x8C033398]
SSDT   \??\C:\Windows\system32\drivers\aswSnx.sys                                                                                                                                               ZwDeleteBootEntry [0x8C031B32]
SSDT   \??\C:\Windows\system32\drivers\aswSnx.sys                                                                                                                                               ZwDuplicateObject [0x8C036BE4]
SSDT   \??\C:\Windows\system32\drivers\aswSnx.sys                                                                                                                                               ZwLoadDriver [0x8C03171E]
SSDT   \??\C:\Windows\system32\drivers\aswSP.sys                                                                                                                                                ZwMapViewOfSection [0x8C0E8506]
SSDT   \??\C:\Windows\system32\drivers\aswSnx.sys                                                                                                                                               ZwModifyBootEntry [0x8C031B98]
SSDT   \??\C:\Windows\system32\drivers\aswSnx.sys                                                                                                                                               ZwNotifyChangeKey [0x8C036FDA]
SSDT   \??\C:\Windows\system32\drivers\aswSnx.sys                                                                                                                                               ZwNotifyChangeMultipleKeys [0x8C033EDE]
SSDT   \??\C:\Windows\system32\drivers\aswSnx.sys                                                                                                                                               ZwOpenEvent [0x8C03E6BC]
SSDT   \??\C:\Windows\system32\drivers\aswSnx.sys                                                                                                                                               ZwOpenEventPair [0x8C03E700]
SSDT   \??\C:\Windows\system32\drivers\aswSnx.sys                                                                                                                                               ZwOpenIoCompletion [0x8C03E89C]
SSDT   \??\C:\Windows\system32\drivers\aswSnx.sys                                                                                                                                               ZwOpenMutant [0x8C03E626]
SSDT   \??\C:\Windows\system32\drivers\aswSnx.sys                                                                                                                                               ZwOpenProcess [0x8C0364DE]
SSDT   \??\C:\Windows\system32\drivers\aswSnx.sys                                                                                                                                               ZwOpenSection [0x8C03E7B0]
SSDT   \??\C:\Windows\system32\drivers\aswSnx.sys                                                                                                                                               ZwOpenSemaphore [0x8C03E670]
SSDT   \??\C:\Windows\system32\drivers\aswSnx.sys                                                                                                                                               ZwOpenThread [0x8C0368C6]
SSDT   \??\C:\Windows\system32\drivers\aswSnx.sys                                                                                                                                               ZwOpenTimer [0x8C03E856]
SSDT   \??\C:\Windows\system32\drivers\aswSP.sys                                                                                                                                                ZwProtectVirtualMemory [0x8C0E82AA]
SSDT   \??\C:\Windows\system32\drivers\aswSnx.sys                                                                                                                                               ZwQueryObject [0x8C033CF4]
SSDT   \??\C:\Windows\system32\drivers\aswSnx.sys                                                                                                                                               ZwQueueApcThreadEx [0x8C033A02]
SSDT   \??\C:\Windows\system32\drivers\aswSnx.sys                                                                                                                                               ZwSetBootEntryOrder [0x8C031BFE]
SSDT   \??\C:\Windows\system32\drivers\aswSnx.sys                                                                                                                                               ZwSetBootOptions [0x8C031C64]
SSDT   \??\C:\Windows\system32\drivers\aswSP.sys                                                                                                                                                ZwSetContextThread [0x8C0E8602]
SSDT   \??\C:\Windows\system32\drivers\aswSnx.sys                                                                                                                                               ZwSetSystemInformation [0x8C0317B8]
SSDT   \??\C:\Windows\system32\drivers\aswSnx.sys                                                                                                                                               ZwSetSystemPowerState [0x8C03198A]
SSDT   \??\C:\Windows\system32\drivers\aswSnx.sys                                                                                                                                               ZwShutdownSystem [0x8C031918]
SSDT   \??\C:\Windows\system32\drivers\aswSnx.sys                                                                                                                                               ZwSuspendProcess [0x8C033562]
SSDT   \??\C:\Windows\system32\drivers\aswSnx.sys                                                                                                                                               ZwSuspendThread [0x8C0336C4]
SSDT   \??\C:\Windows\system32\drivers\aswSnx.sys                                                                                                                                               ZwSystemDebugControl [0x8C031A12]
SSDT   \??\C:\Windows\system32\drivers\aswSP.sys                                                                                                                                                ZwTerminateProcess [0x8C0E8378]
SSDT   \??\C:\Windows\system32\drivers\aswSnx.sys                                                                                                                                               ZwTerminateThread [0x8C0331F2]
SSDT   \??\C:\Windows\system32\drivers\aswSnx.sys                                                                                                                                               ZwVdmControl [0x8C031CCA]
SSDT   \??\C:\Windows\system32\drivers\aswSnx.sys                                                                                                                                               ZwWriteVirtualMemory [0x8C032606]
 
---- Kernel code sections - GMER 2.1 ----
 
.text  ntkrnlpa.exe!ZwRollbackEnlistment + 140D                                                                                                                                                 8304DA09 1 Byte  [06]
.text  ntkrnlpa.exe!KiDispatchInterrupt + 5A2                                                                                                                                                   830871F2 19 Bytes  [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text  ntkrnlpa.exe!KeRemoveQueueEx + 10CB                                                                                                                                                      8308E220 4 Bytes  [CC, 1A, 03, 8C]
.text  ntkrnlpa.exe!KeRemoveQueueEx + 1153                                                                                                                                                      8308E2A8 4 Bytes  [AA, 25, 03, 8C]
.text  ntkrnlpa.exe!KeRemoveQueueEx + 11A7                                                                                                                                                      8308E2FC 8 Bytes  [92, E6, 03, 8C, DE, E6, 03, ...]
.text  ntkrnlpa.exe!KeRemoveQueueEx + 11B3                                                                                                                                                      8308E308 4 Bytes  CALL ADBA6F10 
.text  ntkrnlpa.exe!KeRemoveQueueEx + 11CF                                                                                                                                                      8308E324 4 Bytes  [00, E6, 03, 8C]
.text  ...                                                                                                                                                                                      
 
---- User code sections - GMER 2.1 ----
 
.text  C:\Windows\Explorer.EXE[332] kernel32.dll!GetBinaryTypeW + 70                                                                                                                            773869F4 1 Byte  [62]
.text  C:\Windows\system32\csrss.exe[340] kernel32.dll!GetBinaryTypeW + 70                                                                                                                      773869F4 1 Byte  [62]
.text  C:\Windows\system32\Dwm.exe[348] kernel32.dll!GetBinaryTypeW + 70                                                                                                                        773869F4 1 Byte  [62]
.text  C:\Windows\system32\wininit.exe[388] kernel32.dll!GetBinaryTypeW + 70                                                                                                                    773869F4 1 Byte  [62]
.text  C:\Windows\system32\csrss.exe[400] kernel32.dll!GetBinaryTypeW + 70                                                                                                                      773869F4 1 Byte  [62]
.text  ...                                                                                                                                                                                      
 
---- Registry - GMER 2.1 ----
 
Reg    HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{7F93421A-EEF9-4885-AC8B-5551C91E810B}@LeaseObtainedTime                                                              1392735763
Reg    HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{7F93421A-EEF9-4885-AC8B-5551C91E810B}@T1                                                                             1392735823
Reg    HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{7F93421A-EEF9-4885-AC8B-5551C91E810B}@T2                                                                             1392811363
Reg    HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{7F93421A-EEF9-4885-AC8B-5551C91E810B}@LeaseTerminatesTime                                                            1392822163
 
---- Files - GMER 2.1 ----
 
File   C:\avast! sandbox                                                                                                                                                                        0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000                                                                                                                         0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone                                                                                                                  0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C                                                                                                                0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\Program Files                                                                                                  0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\Program Files\Alwil Software                                                                                   0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\Program Files\Alwil Software\Avast5                                                                            0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\Program Files\Alwil Software\Avast5\sfzone                                                                     0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\Program Files\Google                                                                                           0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\Program Files\Google\CrashReports                                                                              0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile                                                                                                 0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Safe Browsing Bloom Prefix Set                                                                  1159246 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Certificate Revocation Lists                                                                    264731 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\chrome_shutdown_ms.txt                                                                          6 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default                                                                                         0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\History Index 2013-10                                                                   53248 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Archived History                                                                        57344 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Archived History-journal                                                                512 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Cache                                                                                   0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Cache\data_0                                                                            45056 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Cache\data_1                                                                            270336 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Cache\data_2                                                                            1056768 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Cache\data_3                                                                            4202496 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Cache\f_000001                                                                          20103 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Cache\f_000002                                                                          55264 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Cache\f_000003                                                                          62486 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Cache\f_000004                                                                          35572 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Cache\f_000005                                                                          41848 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Cache\f_000006                                                                          42660 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Cache\f_000007                                                                          34725 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Cache\f_000008                                                                          58423 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Cache\f_000009                                                                          51744 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Cache\f_00000a                                                                          101889 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Cache\f_00000b                                                                          36757 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Cache\f_00000c                                                                          29152 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Cache\f_00000d                                                                          177677 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Cache\f_00000e                                                                          100422 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Cache\f_00000f                                                                          42584 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Cache\f_000010                                                                          47276 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Cache\index                                                                             262512 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Cookies                                                                                 9216 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Cookies-journal                                                                         7736 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Current Session                                                                         771 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Current Tabs                                                                            8 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Favicons                                                                                20480 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Favicons-journal                                                                        14904 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\History                                                                                 94208 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Origin Bound Certs                                                                      7168 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Origin Bound Certs-journal                                                              3608 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Preferences                                                                             65319 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\README                                                                                  186 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Session Storage                                                                         0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Session Storage\000005.sst                                                              159 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Session Storage\000006.log                                                              0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Session Storage\CURRENT                                                                 16 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Session Storage\LOCK                                                                    0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Session Storage\LOG                                                                     259 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Session Storage\LOG.old                                                                 47 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Session Storage\MANIFEST-000004                                                         167 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Shortcuts                                                                               12288 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Shortcuts-journal                                                                       512 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Top Sites                                                                               20480 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Top Sites-journal                                                                       12824 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\User StyleSheets                                                                        0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\User StyleSheets\Custom.css                                                             0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Visited Links                                                                           131072 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Web Data                                                                                77824 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Web Data-journal                                                                        4624 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\History Provider Cache                                                                  2343 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\History-journal                                                                         16384 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\JumpListIcons                                                                           0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\JumpListIcons\3CBD.tmp                                                                  0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\JumpListIcons\3CBE.tmp                                                                  0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\JumpListIconsOld                                                                        0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\JumpListIconsOld\94F1.tmp                                                               0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\JumpListIconsOld\94F2.tmp                                                               0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Last Session                                                                            1080 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Last Tabs                                                                               8 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Local Storage                                                                           0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Local Storage\http_www.avast.com_0.localstorage                                         7168 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Local Storage\http_www.avast.com_0.localstorage-journal                                 3608 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Network Action Predictor                                                                16384 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Default\Network Action Predictor-journal                                                        3608 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\First Run                                                                                       0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Local State                                                                                     14187 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Safe Browsing Bloom                                                                             6642556 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Safe Browsing Cookies                                                                           6144 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Safe Browsing Cookies-journal                                                                   4640 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Safe Browsing Csd Whitelist                                                                     135288 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Safe Browsing Download                                                                          1555680 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Safe Browsing Download Whitelist                                                                19548 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\sfzone_profile\Safe Browsing Extension Blacklist                                                               6848 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\Users                                                                                                          0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\Users\user                                                                                                     0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\Users\user\AppData                                                                                             0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\Users\user\AppData\Local                                                                                       0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\Users\user\AppData\Local\Microsoft                                                                             0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\Users\user\AppData\Local\Microsoft\Windows                                                                     0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\Users\user\AppData\Local\Microsoft\Windows\History                                                             0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\Users\user\AppData\Local\Microsoft\Windows\History\History.IE5                                                 0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\Users\user\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat                                       16384 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files                                            0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5                                0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0WHYAI88                       0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0WHYAI88\desktop.ini           67 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HVBY8OMD                       0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HVBY8OMD\desktop.ini           67 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IID5224H                       0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IID5224H\desktop.ini           67 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat                      32768 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XOC4EWNE                       0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XOC4EWNE\desktop.ini           67 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\Users\user\AppData\Local\Temp                                                                                  0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\Users\user\AppData\Local\Temp\CRX_75DAF8CB7768                                                                 0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\Users\user\AppData\Local\Temp\CRX_75DAF8CB7768\crl-set                                                         264731 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\Users\user\AppData\Local\Temp\CRX_75DAF8CB7768\manifest.json                                                   34 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\Users\user\AppData\Local\Temp\CRX_DF399A9B283A                                                                 0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\Users\user\AppData\Local\Temp\CRX_DF399A9B283A\ChromeRecovery.exe                                              571272 bytes executable
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\Users\user\AppData\Local\Temp\CRX_DF399A9B283A\GoogleUpdateSetup.exe                                           774424 bytes executable
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\Users\user\AppData\Local\Temp\CRX_DF399A9B283A\manifest.json                                                   221 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\Users\user\AppData\Roaming                                                                                     0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\Users\user\AppData\Roaming\Microsoft                                                                           0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\Users\user\AppData\Roaming\Microsoft\Windows                                                                   0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\Users\user\AppData\Roaming\Microsoft\Windows\Cookies                                                           0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\index.dat                                                 16384 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\Users\user\AppData\Roaming\Microsoft\Windows\Recent                                                            0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations                                         0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d8b393b9387fc13c.customDestinations-ms  6340 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\Windows                                                                                                        0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\Windows\Prefetch                                                                                               0 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\Windows\Prefetch\CTFMON.EXE-9450846B.pf                                                                        16926 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\Windows\Prefetch\GOOGLEUPDATE.EXE-FE771DDA.pf                                                                  43988 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\C\Windows\Prefetch\SAFEZONEBROWSER.EXE-86BA6E22.pf                                                               18862 bytes
File   C:\avast! sandbox\S-1-5-21-2266009034-3112802113-2357346608-1000\sfzone\snx_fs.dat                                                                                                       21516 bytes
File   C:\avast! sandbox\snx_rhive                                                                                                                                                              262144 bytes
File   C:\avast! sandbox\snx_rhive.LOG1                                                                                                                                                         33792 bytes
File   C:\avast! sandbox\snx_rhive.LOG2                                                                                                                                                         0 bytes
File   C:\avast! sandbox\snx_rhive{758c9901-3d95-11e3-aa07-000fb0bd3373}.TM.blf                                                                                                                 65536 bytes
File   C:\avast! sandbox\snx_rhive{758c9901-3d95-11e3-aa07-000fb0bd3373}.TMContainer00000000000000000001.regtrans-ms                                                                            524288 bytes
File   C:\avast! sandbox\snx_rhive{758c9901-3d95-11e3-aa07-000fb0bd3373}.TMContainer00000000000000000002.regtrans-ms                                                                            524288 bytes
 
---- EOF - GMER 2.1 ----
Link to post
Share on other sites

Combofix

Combofix should only be run when adviced by a team member!

Link


Important - Save the file to your desktop!


  • Deactivate any and all of your antivirus programs /spyware scanners - they can prevent CF from doing its work.
  • Run Combofix.exe



When finished, Combofix creates a log file named C:\Combofix.txt. Please post its content in your next reply.

Note: When receiving an error message containing ""Illegal operation attempted on a registry key that has been marked for deletion" simply restart your computer to fix this.

Link to post
Share on other sites

ComboFix 14-02-16.01 - user 18/02/2014  10:56:06.1.1 - x86

Microsoft Windows 7 Professional   6.1.7601.1.1252.34.3082.18.766.271 [GMT -6:00]

Running from: c:\users\user\Downloads\ComboFix.exe

AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}

SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\windows\system32\oem19.inf

c:\windows\wininit.ini

.

.

(((((((((((((((((((((((((   Files Created from 2014-01-18 to 2014-02-18  )))))))))))))))))))))))))))))))

.

.

2014-02-18 17:26 . 2014-02-18 17:27 -------- d-----w- c:\users\user\AppData\Local\temp

2014-02-18 17:26 . 2014-02-18 17:26 -------- d-----w- c:\users\Invitado\AppData\Local\temp

2014-02-18 17:26 . 2014-02-18 17:26 -------- d-----w- c:\users\Default\AppData\Local\temp

2014-02-18 04:52 . 2014-02-18 05:01 107224 ----a-w- c:\windows\system32\drivers\48230029.sys

2014-02-18 02:51 . 2014-02-18 02:51 31560 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys

2014-02-18 02:49 . 2014-02-18 02:49 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2014-02-18 02:49 . 2013-04-04 20:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys

2014-02-13 14:15 . 2011-01-16 22:55 255488 ----a-w- c:\windows\system32\pev.exe

2014-02-11 15:58 . 2014-02-11 15:59 -------- d-----w- c:\program files\CCleaner

2014-02-07 18:46 . 2014-02-07 18:46 -------- d-----w- c:\program files\Panda Security

2014-02-05 16:00 . 2014-02-18 04:30 40776 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2014-02-05 03:26 . 2014-02-05 03:30 -------- d-----w- C:\b2146195e30394a1b88f9c

2014-02-04 21:51 . 2013-12-04 02:57 7760024 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F9859FD0-517B-440F-BE78-D8E67BFB8348}\mpengine.dll

2014-02-04 19:23 . 2014-02-04 19:23 -------- d-----w- c:\program files\Common Files\InstallShield

2014-02-04 17:21 . 2014-02-04 17:21 -------- d-----w- c:\windows\CheckSur

2014-02-04 02:14 . 2014-02-04 02:14 -------- d-----w- c:\program files\CONEXANT

2014-02-03 22:49 . 2013-11-27 00:20 235216 ----a-w- c:\program files\Internet Explorer\sqmapi.dll

2014-02-03 22:49 . 2013-11-26 09:23 2724864 ----a-w- c:\windows\system32\mshtml.tlb

2014-02-03 22:49 . 2013-11-26 06:41 251392 ----a-w- c:\program files\Internet Explorer\IEShims.dll

2014-02-03 22:49 . 2013-11-26 06:22 270848 ----a-w- c:\program files\Internet Explorer\ieproxy.dll

2014-02-03 22:49 . 2013-11-26 09:11 7211008 ----a-w- c:\program files\Internet Explorer\F12Resources.dll

2014-02-03 22:49 . 2013-11-26 09:22 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll

2014-02-03 22:49 . 2013-11-26 08:26 1389056 ----a-w- c:\program files\Internet Explorer\MemoryAnalyzer.dll

2014-02-03 22:49 . 2013-11-26 08:53 61952 ----a-w- c:\windows\system32\iesetup.dll

2014-02-03 22:40 . 2013-05-10 04:56 12625408 ----a-w- c:\windows\system32\wmploc.DLL

2014-02-03 22:40 . 2013-05-10 03:48 164864 ----a-w- c:\program files\Windows Media Player\wmplayer.exe

2014-02-03 22:25 . 2013-08-27 08:21 1077760 ----a-w- c:\windows\system32\DWrite.dll

2014-02-03 22:25 . 2013-08-27 08:21 808448 ----a-w- c:\windows\system32\FntCache.dll

2014-02-03 15:54 . 2014-02-03 19:48 -------- d-----w- c:\programdata\Spybot - Search & Destroy

2014-02-03 15:54 . 2009-01-25 19:14 15224 ----a-w- c:\windows\system32\sdnclean.exe

2014-02-03 03:08 . 2014-01-08 21:54 103424 ----a-w- c:\windows\system32\IObitSmartDefragExtension.dll

2014-02-03 03:07 . 2013-12-24 16:40 18624 ----a-w- c:\windows\system32\drivers\SmartDefragDriver.sys

2014-02-03 00:59 . 2014-02-03 00:59 -------- d-----w- c:\users\Invitado\AppData\Roaming\IObit

2014-02-01 02:31 . 2014-02-01 02:31 92464 ----a-w- c:\windows\system32\bcmwlcoi.dll

2014-02-01 02:31 . 2014-02-01 02:31 3616768 ----a-w- c:\windows\system32\bcmihvui.dll

2014-02-01 02:31 . 2014-02-01 02:38 -------- d-----w- C:\DrvInstall

2014-02-01 02:31 . 2014-02-01 02:31 3928064 ----a-w- c:\windows\system32\bcmihvsrv.dll

2014-02-01 01:48 . 2014-02-01 01:48 -------- d-----w- c:\programdata\ProductData

2014-02-01 01:48 . 2014-02-01 01:48 -------- d-----w- c:\programdata\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D}

2014-02-01 01:47 . 2014-02-01 02:46 -------- d-----w- c:\programdata\IObit

2014-02-01 01:45 . 2014-02-03 06:18 -------- d-----w- c:\program files\IObit

2014-02-01 01:44 . 2014-02-01 02:16 -------- d-----w- c:\users\user\AppData\Roaming\IObit

2014-01-30 21:10 . 2014-01-30 21:10 -------- d-----w- c:\users\user\AppData\Local\Apple Computer

2014-01-30 21:10 . 2014-02-01 01:49 -------- d-----w- c:\users\user\AppData\Roaming\Apple Computer

2014-01-30 21:08 . 2014-02-03 01:13 -------- dc----w- c:\windows\system32\DRVSTORE

2014-01-30 21:04 . 2014-01-30 21:04 -------- d-----w- c:\programdata\Apple Computer

2014-01-30 20:59 . 2014-01-30 20:59 -------- d-----w- c:\users\user\AppData\Local\Apple

2014-01-30 20:53 . 2014-02-03 01:25 -------- d-----w- c:\programdata\Apple

2014-01-23 16:31 . 2013-11-20 02:59 14528 ----a-w- c:\windows\system32\drivers\BootDefragDriver.sys

2014-01-23 15:24 . 2013-12-04 02:15 22304 ----a-w- c:\windows\system32\RegBootDefrag.exe

2014-01-21 03:12 . 2014-01-22 18:18 -------- d-----w- c:\users\user\AppData\Local\Facebook

2014-01-20 17:07 . 2014-01-20 17:21 -------- d-----w- c:\program files\Spotify

.

.

.

((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2014-02-01 06:04 . 2013-12-18 22:12 64168 ----a-w- c:\windows\system32\drivers\aswstm.sys

2014-02-01 06:04 . 2013-04-12 02:46 775952 ----a-w- c:\windows\system32\drivers\aswSnx.sys

2014-02-01 06:04 . 2013-04-12 02:32 410784 ----a-w- c:\windows\system32\drivers\aswsp.sys

2014-02-01 06:04 . 2013-04-12 02:32 67824 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys

2014-02-01 06:04 . 2013-04-12 02:46 43152 ----a-w- c:\windows\avastSS.scr

2014-02-01 06:04 . 2013-04-12 02:32 270240 ----a-w- c:\windows\system32\aswBoot.exe

2014-01-27 22:10 . 2014-01-05 20:01 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe

2014-01-27 22:10 . 2014-01-05 20:01 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2014-01-16 15:59 . 2013-04-07 20:31 231584 ------w- c:\windows\system32\MpSigStub.exe

2013-12-18 22:12 . 2013-04-12 02:46 180248 ----a-w- c:\windows\system32\drivers\aswVmm.sys

2013-12-17 18:04 . 2013-12-17 18:04 646144 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe

2013-12-17 18:04 . 2013-12-17 18:04 194048 ----a-w- c:\windows\system32\elshyph.dll

2013-12-17 18:04 . 2013-12-17 18:04 645120 ----a-w- c:\windows\system32\jsIntl.dll

2013-12-17 18:04 . 2013-12-17 18:04 34816 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll

2013-12-17 18:04 . 2013-12-17 18:04 1051136 ----a-w- c:\windows\system32\mshtmlmedia.dll

2013-12-17 18:04 . 2013-12-17 18:04 61952 ----a-w- c:\windows\system32\MshtmlDac.dll

2013-12-17 17:59 . 2013-12-17 17:59 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll

2013-12-17 17:59 . 2013-12-17 17:59 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll

2013-12-17 17:59 . 2013-12-17 17:59 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll

2013-12-17 17:59 . 2013-12-17 17:59 4096 ---ha-w- c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll

2013-12-17 17:59 . 2013-12-17 17:59 3584 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll

2013-12-17 17:59 . 2013-12-17 17:59 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll

2013-12-17 17:59 . 2013-12-17 17:59 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll

2013-12-17 17:59 . 2013-12-17 17:59 2560 ---ha-w- c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll

2013-12-17 17:59 . 2013-12-17 17:59 10752 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll

2013-12-17 17:53 . 2013-12-17 17:53 1505280 ----a-w- c:\windows\system32\d3d11.dll

2013-12-07 00:21 . 2009-07-14 02:05 152576 ----a-w- c:\windows\system32\msclmd.dll

2013-12-04 02:15 . 2013-12-16 19:35 101664 ----a-w- c:\windows\system32\BootDefrag.exe

.

.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown 

REGEDIT4

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]

@="{472083B0-C522-11CF-8763-00608CC02F24}"

[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]

2014-02-01 06:04 259464 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"GUDelayStartup"="c:\program files\Glary Utilities 4\StartupManager.exe" [2013-12-04 37152]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2009-11-24 323640]

"AvastUI.exe"="c:\program files\Alwil Software\Avast5\AvastUI.exe" [2014-02-01 3767096]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]

.

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]

"SPReview"="c:\windows\System32\SPReview\SPReview.exe" [2013-12-07 280576]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 5 (0x5)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]

BootExecute REG_MULTI_SZ   autocheck autochk * 

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GUDelayStartup]

2013-12-04 02:14 37152 ----a-w- c:\program files\Glary Utilities 4\StartupManager.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spotify]

2014-01-13 17:40 6118400 ----a-w- c:\users\user\AppData\Roaming\Spotify\spotify.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spotify Web Helper]

2014-01-13 17:40 1171968 ----a-w- c:\users\user\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

.

R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [x]

R2 LiveUpdateSvc;LiveUpdate;c:\program files\IObit\LiveUpdate\LiveUpdate.exe [2013-12-03 2151200]

R3 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys [2014-02-01 64168]

R3 aswTap;avast! SecureLine TAP Adapter v3;c:\windows\system32\DRIVERS\aswTap.sys [2013-10-24 38472]

R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2013-11-26 108032]

R3 mbamchameleon;mbamchameleon;c:\windows\system32\drivers\mbamchameleon.sys [2014-02-18 31560]

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]

R3 WatAdminSvc;Servicio de tecnologías de activación de Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2013-04-12 1343400]

R4 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2010-01-12 227896]

S0 aswRvrt;avast! Revert; [x]

S0 aswVmm;avast! VM Monitor; [x]

S0 BootDefragDriver;BootDefragDriver;c:\windows\System32\drivers\BootDefragDriver.sys [2013-11-20 14528]

S0 SmartDefragDriver;SmartDefragDriver;c:\windows\System32\Drivers\SmartDefragDriver.sys [2013-12-24 18624]

S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2014-02-01 775952]

S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2014-02-01 410784]

S1 HssDRV6;Hotspot Shield Routing Driver 6;c:\windows\system32\DRIVERS\hssdrv6.sys [2013-11-13 39624]

S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2014-02-01 67824]

S2 HPSupportSolutionsFrameworkService;HP Support Solutions Framework Service;c:\program files\Hp\Common\HPSupportSolutionsFrameworkService.exe [2013-12-17 46904]

S3 taphss6;Anchorfree HSS VPN Adapter;c:\windows\system32\DRIVERS\taphss6.sys [2013-10-16 37064]

S3 VST_DPV;VST_DPV;c:\windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-13 980992]

S3 VSTHWATI;VSTHWATI;c:\windows\system32\DRIVERS\VSTATI3.SYS [2009-07-13 236032]

.

.

--- Other Services/Drivers In Memory ---

.

*NewlyCreated* - KXLDAPOB

*Deregistered* - kxldapob

.

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]

2014-02-04 20:13 1211720 ----a-w- c:\program files\Google\Chrome\Application\32.0.1700.107\Installer\chrmstp.exe

.

Contents of the 'Scheduled Tasks' folder

.

2014-02-18 c:\windows\Tasks\GlaryInitialize 4.job

- c:\program files\Glary Utilities 4\Initialize.exe [2013-12-04 02:12]

.

2014-02-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2013-12-19 19:42]

.

2014-02-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2013-12-19 19:42]

.

.

------- Supplementary Scan -------

.

uInternet Settings,ProxyOverride = 127.0.0.1;localhost;10.*;192.168.*;127.0.0.1:895;127.0.0.1:896;<local>

uInternet Settings,ProxyServer = localhost:21320

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000

TCP: DhcpNameServer = 192.168.1.254

.

- - - - ORPHANS REMOVED - - - -

.

SafeBoot-Wdf01000.sys

SafeBoot-IMFservice

MSConfigStartUp-iTunesHelper - c:\program files\itunes\ituneshelper.exe

.

.

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_12_0_0_38_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_12_0_0_38_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\system\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

.

[HKEY_LOCAL_MACHINE\system\ControlSet002\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

Completion time: 2014-02-18  11:31:00

ComboFix-quarantined-files.txt  2014-02-18 17:30

.

Pre-Run: 9.527.320.576 bytes libres

Post-Run: 13.032.665.088 bytes libres

.

- - End Of File - - 4F31FDA2B57FEB5A48D0B7E570B5BED6

A36C5E4F47E84449FF07ED3517B43A31
Link to post
Share on other sites

IObit software products are installed on your system!

The company behind this product was found to be stealing our database. Personally I would not trust installing any software from a company that resorts to stealing someone's technology to sell their product.

Please see the following links and make up your own mind if you want to keep this on your system. If needed I can help you remove it.
 

 

 

 

 

Combofix scripting

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Download the attached CFScript.txt and save it to the location where Combofix is.


CFScriptB-4.gif


Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

 

 

 

Full System Scan with Malwarebytes Antimalware
 

  • If not existing, please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.

If the program is already installed:

  • Run Malwarebytes Antimalware
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform fullscan, place a checkmark on all hard drives, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location.
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Post that log back here.

 

 

CFScript.txt

Link to post
Share on other sites

ComboFix 14-02-19.01 - user 19/02/2014  11:03:27.2.1 - x86

Microsoft Windows 7 Professional   6.1.7601.1.1252.34.3082.18.766.303 [GMT -6:00]

Running from: c:\users\user\Desktop\ComboFix.exe

Command switches used :: c:\users\user\Desktop\CFScript.txt

AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}

SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

 * Created a new restore point

.

.

(((((((((((((((((((((((((   Files Created from 2014-01-19 to 2014-02-19  )))))))))))))))))))))))))))))))

.

.

2014-02-19 17:33 . 2014-02-19 17:33 -------- d-----w- c:\users\user\AppData\Local\temp

2014-02-19 17:33 . 2014-02-19 17:33 -------- d-----w- c:\users\Invitado\AppData\Local\temp

2014-02-19 17:33 . 2014-02-19 17:33 -------- d-----w- c:\users\Default\AppData\Local\temp

2014-02-18 04:52 . 2014-02-18 05:01 107224 ----a-w- c:\windows\system32\drivers\48230029.sys

2014-02-18 02:51 . 2014-02-18 02:51 31560 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys

2014-02-18 02:49 . 2014-02-18 02:49 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2014-02-18 02:49 . 2013-04-04 20:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys

2014-02-13 14:15 . 2011-01-16 22:55 255488 ----a-w- c:\windows\system32\pev.exe

2014-02-11 15:58 . 2014-02-11 15:59 -------- d-----w- c:\program files\CCleaner

2014-02-07 18:46 . 2014-02-07 18:46 -------- d-----w- c:\program files\Panda Security

2014-02-05 16:00 . 2014-02-18 04:30 40776 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2014-02-05 03:26 . 2014-02-05 03:30 -------- d-----w- C:\b2146195e30394a1b88f9c

2014-02-04 21:51 . 2013-12-04 02:57 7760024 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F9859FD0-517B-440F-BE78-D8E67BFB8348}\mpengine.dll

2014-02-04 19:23 . 2014-02-04 19:23 -------- d-----w- c:\program files\Common Files\InstallShield

2014-02-04 17:21 . 2014-02-04 17:21 -------- d-----w- c:\windows\CheckSur

2014-02-04 02:14 . 2014-02-04 02:14 -------- d-----w- c:\program files\CONEXANT

2014-02-03 22:49 . 2013-11-27 00:20 235216 ----a-w- c:\program files\Internet Explorer\sqmapi.dll

2014-02-03 22:49 . 2013-11-26 09:23 2724864 ----a-w- c:\windows\system32\mshtml.tlb

2014-02-03 22:49 . 2013-11-26 06:41 251392 ----a-w- c:\program files\Internet Explorer\IEShims.dll

2014-02-03 22:49 . 2013-11-26 06:22 270848 ----a-w- c:\program files\Internet Explorer\ieproxy.dll

2014-02-03 22:49 . 2013-11-26 09:11 7211008 ----a-w- c:\program files\Internet Explorer\F12Resources.dll

2014-02-03 22:49 . 2013-11-26 09:22 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll

2014-02-03 22:49 . 2013-11-26 08:26 1389056 ----a-w- c:\program files\Internet Explorer\MemoryAnalyzer.dll

2014-02-03 22:49 . 2013-11-26 08:53 61952 ----a-w- c:\windows\system32\iesetup.dll

2014-02-03 22:40 . 2013-05-10 04:56 12625408 ----a-w- c:\windows\system32\wmploc.DLL

2014-02-03 22:40 . 2013-05-10 03:48 164864 ----a-w- c:\program files\Windows Media Player\wmplayer.exe

2014-02-03 22:25 . 2013-08-27 08:21 1077760 ----a-w- c:\windows\system32\DWrite.dll

2014-02-03 22:25 . 2013-08-27 08:21 808448 ----a-w- c:\windows\system32\FntCache.dll

2014-02-03 15:54 . 2014-02-03 19:48 -------- d-----w- c:\programdata\Spybot - Search & Destroy

2014-02-03 15:54 . 2009-01-25 19:14 15224 ----a-w- c:\windows\system32\sdnclean.exe

2014-02-03 03:08 . 2014-01-08 21:54 103424 ----a-w- c:\windows\system32\IObitSmartDefragExtension.dll

2014-02-03 03:07 . 2013-12-24 16:40 18624 ----a-w- c:\windows\system32\drivers\SmartDefragDriver.sys

2014-02-03 00:59 . 2014-02-03 00:59 -------- d-----w- c:\users\Invitado\AppData\Roaming\IObit

2014-02-01 02:31 . 2014-02-01 02:31 92464 ----a-w- c:\windows\system32\bcmwlcoi.dll

2014-02-01 02:31 . 2014-02-01 02:31 3616768 ----a-w- c:\windows\system32\bcmihvui.dll

2014-02-01 02:31 . 2014-02-01 02:38 -------- d-----w- C:\DrvInstall

2014-02-01 02:31 . 2014-02-01 02:31 3928064 ----a-w- c:\windows\system32\bcmihvsrv.dll

2014-02-01 01:48 . 2014-02-01 01:48 -------- d-----w- c:\programdata\ProductData

2014-02-01 01:48 . 2014-02-01 01:48 -------- d-----w- c:\programdata\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D}

2014-02-01 01:47 . 2014-02-01 02:46 -------- d-----w- c:\programdata\IObit

2014-02-01 01:45 . 2014-02-03 06:18 -------- d-----w- c:\program files\IObit

2014-02-01 01:44 . 2014-02-01 02:16 -------- d-----w- c:\users\user\AppData\Roaming\IObit

2014-01-30 21:10 . 2014-01-30 21:10 -------- d-----w- c:\users\user\AppData\Local\Apple Computer

2014-01-30 21:10 . 2014-02-01 01:49 -------- d-----w- c:\users\user\AppData\Roaming\Apple Computer

2014-01-30 21:08 . 2014-02-03 01:13 -------- dc----w- c:\windows\system32\DRVSTORE

2014-01-30 21:04 . 2014-01-30 21:04 -------- d-----w- c:\programdata\Apple Computer

2014-01-30 20:59 . 2014-01-30 20:59 -------- d-----w- c:\users\user\AppData\Local\Apple

2014-01-30 20:53 . 2014-02-03 01:25 -------- d-----w- c:\programdata\Apple

2014-01-23 16:31 . 2013-11-20 02:59 14528 ----a-w- c:\windows\system32\drivers\BootDefragDriver.sys

2014-01-23 15:24 . 2013-12-04 02:15 22304 ----a-w- c:\windows\system32\RegBootDefrag.exe

2014-01-21 03:12 . 2014-01-22 18:18 -------- d-----w- c:\users\user\AppData\Local\Facebook

.

.

.

((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2014-02-01 06:04 . 2013-12-18 22:12 64168 ----a-w- c:\windows\system32\drivers\aswstm.sys

2014-02-01 06:04 . 2013-04-12 02:46 775952 ----a-w- c:\windows\system32\drivers\aswSnx.sys

2014-02-01 06:04 . 2013-04-12 02:32 410784 ----a-w- c:\windows\system32\drivers\aswsp.sys

2014-02-01 06:04 . 2013-04-12 02:32 67824 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys

2014-02-01 06:04 . 2013-04-12 02:46 43152 ----a-w- c:\windows\avastSS.scr

2014-02-01 06:04 . 2013-04-12 02:32 270240 ----a-w- c:\windows\system32\aswBoot.exe

2014-01-27 22:10 . 2014-01-05 20:01 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe

2014-01-27 22:10 . 2014-01-05 20:01 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2014-01-16 15:59 . 2013-04-07 20:31 231584 ------w- c:\windows\system32\MpSigStub.exe

2013-12-18 22:12 . 2013-04-12 02:46 180248 ----a-w- c:\windows\system32\drivers\aswVmm.sys

2013-12-17 18:04 . 2013-12-17 18:04 646144 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe

2013-12-17 18:04 . 2013-12-17 18:04 194048 ----a-w- c:\windows\system32\elshyph.dll

2013-12-17 18:04 . 2013-12-17 18:04 645120 ----a-w- c:\windows\system32\jsIntl.dll

2013-12-17 18:04 . 2013-12-17 18:04 34816 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll

2013-12-17 18:04 . 2013-12-17 18:04 1051136 ----a-w- c:\windows\system32\mshtmlmedia.dll

2013-12-17 18:04 . 2013-12-17 18:04 61952 ----a-w- c:\windows\system32\MshtmlDac.dll

2013-12-17 17:59 . 2013-12-17 17:59 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll

2013-12-17 17:59 . 2013-12-17 17:59 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll

2013-12-17 17:59 . 2013-12-17 17:59 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll

2013-12-17 17:59 . 2013-12-17 17:59 4096 ---ha-w- c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll

2013-12-17 17:59 . 2013-12-17 17:59 3584 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll

2013-12-17 17:59 . 2013-12-17 17:59 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll

2013-12-17 17:59 . 2013-12-17 17:59 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll

2013-12-17 17:59 . 2013-12-17 17:59 2560 ---ha-w- c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll

2013-12-17 17:59 . 2013-12-17 17:59 10752 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll

2013-12-17 17:53 . 2013-12-17 17:53 1505280 ----a-w- c:\windows\system32\d3d11.dll

2013-12-07 00:21 . 2009-07-14 02:05 152576 ----a-w- c:\windows\system32\msclmd.dll

2013-12-04 02:15 . 2013-12-16 19:35 101664 ----a-w- c:\windows\system32\BootDefrag.exe

.

.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown 

REGEDIT4

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]

@="{472083B0-C522-11CF-8763-00608CC02F24}"

[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]

2014-02-01 06:04 259464 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"GUDelayStartup"="c:\program files\Glary Utilities 4\StartupManager.exe" [2013-12-04 37152]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2009-11-24 323640]

"AvastUI.exe"="c:\program files\Alwil Software\Avast5\AvastUI.exe" [2014-02-01 3767096]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]

.

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]

"SPReview"="c:\windows\System32\SPReview\SPReview.exe" [2013-12-07 280576]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 5 (0x5)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]

BootExecute REG_MULTI_SZ   autocheck autochk * 

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GUDelayStartup]

2013-12-04 02:14 37152 ----a-w- c:\program files\Glary Utilities 4\StartupManager.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spotify]

2014-01-13 17:40 6118400 ----a-w- c:\users\user\AppData\Roaming\Spotify\spotify.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spotify Web Helper]

2014-01-13 17:40 1171968 ----a-w- c:\users\user\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

.

R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [x]

R2 LiveUpdateSvc;LiveUpdate;c:\program files\IObit\LiveUpdate\LiveUpdate.exe [2013-12-03 2151200]

R3 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys [2014-02-01 64168]

R3 aswTap;avast! SecureLine TAP Adapter v3;c:\windows\system32\DRIVERS\aswTap.sys [2013-10-24 38472]

R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2013-11-26 108032]

R3 mbamchameleon;mbamchameleon;c:\windows\system32\drivers\mbamchameleon.sys [2014-02-18 31560]

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]

R3 WatAdminSvc;Servicio de tecnologías de activación de Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2013-04-12 1343400]

R4 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2010-01-12 227896]

S0 aswRvrt;avast! Revert; [x]

S0 aswVmm;avast! VM Monitor; [x]

S0 BootDefragDriver;BootDefragDriver;c:\windows\System32\drivers\BootDefragDriver.sys [2013-11-20 14528]

S0 SmartDefragDriver;SmartDefragDriver;c:\windows\System32\Drivers\SmartDefragDriver.sys [2013-12-24 18624]

S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2014-02-01 775952]

S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2014-02-01 410784]

S1 HssDRV6;Hotspot Shield Routing Driver 6;c:\windows\system32\DRIVERS\hssdrv6.sys [2013-11-13 39624]

S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2014-02-01 67824]

S2 HPSupportSolutionsFrameworkService;HP Support Solutions Framework Service;c:\program files\Hp\Common\HPSupportSolutionsFrameworkService.exe [2013-12-17 46904]

S3 taphss6;Anchorfree HSS VPN Adapter;c:\windows\system32\DRIVERS\taphss6.sys [2013-10-16 37064]

S3 VST_DPV;VST_DPV;c:\windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-13 980992]

S3 VSTHWATI;VSTHWATI;c:\windows\system32\DRIVERS\VSTATI3.SYS [2009-07-13 236032]

.

.

--- Other Services/Drivers In Memory ---

.

*NewlyCreated* - WS2IFSL

.

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]

2014-02-04 20:13 1211720 ----a-w- c:\program files\Google\Chrome\Application\32.0.1700.107\Installer\chrmstp.exe

.

Contents of the 'Scheduled Tasks' folder

.

2014-02-19 c:\windows\Tasks\GlaryInitialize 4.job

- c:\program files\Glary Utilities 4\Initialize.exe [2013-12-04 02:12]

.

2014-02-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2013-12-19 19:42]

.

2014-02-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2013-12-19 19:42]

.

.

------- Supplementary Scan -------

.

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000

TCP: DhcpNameServer = 192.168.1.254

.

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_12_0_0_38_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_12_0_0_38_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\system\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

.

[HKEY_LOCAL_MACHINE\system\ControlSet002\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

Completion time: 2014-02-19  11:37:25

ComboFix-quarantined-files.txt  2014-02-19 17:37

ComboFix2.txt  2014-02-18 17:31

.

Pre-Run: 12.701.609.984 bytes libres

Post-Run: 12.625.616.896 bytes libres

.

- - End Of File - - 415A5C5F05FFA25E0A1DDC58017C24C0

A36C5E4F47E84449FF07ED3517B43A31
Link to post
Share on other sites

System File Check

For Windows XP:

  • Press the Windows- and the R-key simultanously.
  • Within the text box that jus opened, write cmd and hit Enter.


For Windows Vista/7:

  • Press the Windows key to open the start menu.
  • Don´t highlight anything, just write cmd.
  • The start menu will offer you an entry named cmd.
  • Right click it and select "run as administrator"




Within the opening window, write the following:

sfc /scannow
(See the blank within).


  • Hit enter. Your system will be checked for damaged system files.
  • Tell me the result of that scan in here (as the tool produces no log).

Link to post
Share on other sites

Microsoft Windows [Versión 6.1.7601]

Copyright © 2009 Microsoft Corporation. Reservados todos los derechos.

 

C:\Windows\system32>sfc /scannow

 

Iniciando examen en el sistema. Este proceso tardará algún tiempo.

 

Iniciando la fase de comprobación del examen del sistema.

Se completó la comprobación de 100%.

Protección de recursos de Windows encontró archivos dañados y no consiguió

reparar algunos de ellos. Para obtener más detalles, consulte CBS.Log

windir\Logs\CBS\CBS.log. Por ejemplo, C:\Windows\Logs\CBS\CBS.log.

Link to post
Share on other sites

Microsoft Windows [Version 6.1.7601] 

Copyright © 2009 Microsoft Corporation. All rights reserved. 

 

C: \ Windows \ system32> sfc / scannow 

 

Starting in the examination system. This process will take some time. 

 

Beginning verification phase of system scan. 

Verification 100% completed. 

Windows Resource Protection found corrupt files and failed 

repair some of them. For more details, see CBS.log 

windir \ Logs \ CBS \ CBS.log. For example, C: \ Windows \ Logs \ CBS \ CBS.log.

Link to post
Share on other sites

Filter SFC log file

For Windows XP:

  • Press the Windows- and the R-key simultanously.
  • Within the text box that jus opened, write cmd and hit Enter.


For Windows Vista/7:

  • Press the Windows key to open the start menu.
  • Don´t highlight anything, just write cmd.
  • The start menu will offer you an entry named cmd.
  • Right click it and select "run as administrator"




Within the opening window, write the following:

findstr /c:"[SR]" %windir%\logs\cbs\cbs.log >sfcdetails.txt


  • Hit enter. The tool will create a textfile named sfcdetails.txt within the folder where you ran the command, for example C:\windows\system32\.
    Attach this file to your next reply.

Link to post
Share on other sites

2014-02-20 08:47:06, Info                  CSI    00000009 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:47:06, Info                  CSI    0000000a [sR] Beginning Verify and Repair transaction

2014-02-20 08:47:13, Info                  CSI    0000000c [sR] Verify complete

2014-02-20 08:47:13, Info                  CSI    0000000d [sR] Verifying 100 (0x00000064) components

2014-02-20 08:47:13, Info                  CSI    0000000e [sR] Beginning Verify and Repair transaction

2014-02-20 08:47:19, Info                  CSI    00000010 [sR] Verify complete

2014-02-20 08:47:20, Info                  CSI    00000011 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:47:20, Info                  CSI    00000012 [sR] Beginning Verify and Repair transaction

2014-02-20 08:47:27, Info                  CSI    00000014 [sR] Verify complete

2014-02-20 08:47:28, Info                  CSI    00000015 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:47:28, Info                  CSI    00000016 [sR] Beginning Verify and Repair transaction

2014-02-20 08:47:33, Info                  CSI    00000018 [sR] Verify complete

2014-02-20 08:47:34, Info                  CSI    00000019 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:47:34, Info                  CSI    0000001a [sR] Beginning Verify and Repair transaction

2014-02-20 08:47:37, Info                  CSI    0000001c [sR] Verify complete

2014-02-20 08:47:37, Info                  CSI    0000001d [sR] Verifying 100 (0x00000064) components

2014-02-20 08:47:37, Info                  CSI    0000001e [sR] Beginning Verify and Repair transaction

2014-02-20 08:47:43, Info                  CSI    00000020 [sR] Verify complete

2014-02-20 08:47:44, Info                  CSI    00000021 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:47:44, Info                  CSI    00000022 [sR] Beginning Verify and Repair transaction

2014-02-20 08:47:49, Info                  CSI    00000024 [sR] Verify complete

2014-02-20 08:47:50, Info                  CSI    00000025 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:47:50, Info                  CSI    00000026 [sR] Beginning Verify and Repair transaction

2014-02-20 08:47:54, Info                  CSI    00000028 [sR] Verify complete

2014-02-20 08:47:55, Info                  CSI    00000029 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:47:55, Info                  CSI    0000002a [sR] Beginning Verify and Repair transaction

2014-02-20 08:48:01, Info                  CSI    0000002c [sR] Verify complete

2014-02-20 08:48:01, Info                  CSI    0000002d [sR] Verifying 100 (0x00000064) components

2014-02-20 08:48:01, Info                  CSI    0000002e [sR] Beginning Verify and Repair transaction

2014-02-20 08:48:06, Info                  CSI    00000030 [sR] Verify complete

2014-02-20 08:48:06, Info                  CSI    00000031 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:48:06, Info                  CSI    00000032 [sR] Beginning Verify and Repair transaction

2014-02-20 08:48:09, Info                  CSI    00000034 [sR] Verify complete

2014-02-20 08:48:10, Info                  CSI    00000035 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:48:10, Info                  CSI    00000036 [sR] Beginning Verify and Repair transaction

2014-02-20 08:48:16, Info                  CSI    00000038 [sR] Verify complete

2014-02-20 08:48:17, Info                  CSI    00000039 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:48:17, Info                  CSI    0000003a [sR] Beginning Verify and Repair transaction

2014-02-20 08:48:25, Info                  CSI    0000003c [sR] Verify complete

2014-02-20 08:48:26, Info                  CSI    0000003d [sR] Verifying 100 (0x00000064) components

2014-02-20 08:48:26, Info                  CSI    0000003e [sR] Beginning Verify and Repair transaction

2014-02-20 08:48:32, Info                  CSI    00000042 [sR] Verify complete

2014-02-20 08:48:33, Info                  CSI    00000043 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:48:33, Info                  CSI    00000044 [sR] Beginning Verify and Repair transaction

2014-02-20 08:48:39, Info                  CSI    00000048 [sR] Verify complete

2014-02-20 08:48:39, Info                  CSI    00000049 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:48:39, Info                  CSI    0000004a [sR] Beginning Verify and Repair transaction

2014-02-20 08:48:45, Info                  CSI    0000004c [sR] Verify complete

2014-02-20 08:48:46, Info                  CSI    0000004d [sR] Verifying 100 (0x00000064) components

2014-02-20 08:48:46, Info                  CSI    0000004e [sR] Beginning Verify and Repair transaction

2014-02-20 08:48:56, Info                  CSI    00000056 [sR] Verify complete

2014-02-20 08:48:56, Info                  CSI    00000057 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:48:56, Info                  CSI    00000058 [sR] Beginning Verify and Repair transaction

2014-02-20 08:49:06, Info                  CSI    0000005e [sR] Verify complete

2014-02-20 08:49:06, Info                  CSI    0000005f [sR] Verifying 100 (0x00000064) components

2014-02-20 08:49:06, Info                  CSI    00000060 [sR] Beginning Verify and Repair transaction

2014-02-20 08:49:14, Info                  CSI    00000062 [sR] Verify complete

2014-02-20 08:49:14, Info                  CSI    00000063 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:49:14, Info                  CSI    00000064 [sR] Beginning Verify and Repair transaction

2014-02-20 08:49:21, Info                  CSI    00000066 [sR] Verify complete

2014-02-20 08:49:22, Info                  CSI    00000067 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:49:22, Info                  CSI    00000068 [sR] Beginning Verify and Repair transaction

2014-02-20 08:49:29, Info                  CSI    0000006a [sR] Verify complete

2014-02-20 08:49:29, Info                  CSI    0000006b [sR] Verifying 100 (0x00000064) components

2014-02-20 08:49:29, Info                  CSI    0000006c [sR] Beginning Verify and Repair transaction

2014-02-20 08:49:37, Info                  CSI    0000006e [sR] Verify complete

2014-02-20 08:49:37, Info                  CSI    0000006f [sR] Verifying 100 (0x00000064) components

2014-02-20 08:49:37, Info                  CSI    00000070 [sR] Beginning Verify and Repair transaction

2014-02-20 08:49:42, Info                  CSI    00000072 [sR] Verify complete

2014-02-20 08:49:43, Info                  CSI    00000073 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:49:43, Info                  CSI    00000074 [sR] Beginning Verify and Repair transaction

2014-02-20 08:49:53, Info                  CSI    00000076 [sR] Verify complete

2014-02-20 08:49:54, Info                  CSI    00000077 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:49:54, Info                  CSI    00000078 [sR] Beginning Verify and Repair transaction

2014-02-20 08:50:10, Info                  CSI    0000007c [sR] Verify complete

2014-02-20 08:50:11, Info                  CSI    0000007d [sR] Verifying 100 (0x00000064) components

2014-02-20 08:50:11, Info                  CSI    0000007e [sR] Beginning Verify and Repair transaction

2014-02-20 08:50:22, Info                  CSI    00000080 [sR] Verify complete

2014-02-20 08:50:22, Info                  CSI    00000081 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:50:22, Info                  CSI    00000082 [sR] Beginning Verify and Repair transaction

2014-02-20 08:50:40, Info                  CSI    00000084 [sR] Verify complete

2014-02-20 08:50:41, Info                  CSI    00000085 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:50:41, Info                  CSI    00000086 [sR] Beginning Verify and Repair transaction

2014-02-20 08:50:51, Info                  CSI    00000088 [sR] Verify complete

2014-02-20 08:50:52, Info                  CSI    00000089 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:50:52, Info                  CSI    0000008a [sR] Beginning Verify and Repair transaction

2014-02-20 08:50:56, Info                  CSI    0000008c [sR] Verify complete

2014-02-20 08:50:56, Info                  CSI    0000008d [sR] Verifying 100 (0x00000064) components

2014-02-20 08:50:56, Info                  CSI    0000008e [sR] Beginning Verify and Repair transaction

2014-02-20 08:50:58, Info                  CSI    00000090 [sR] Verify complete

2014-02-20 08:50:59, Info                  CSI    00000091 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:50:59, Info                  CSI    00000092 [sR] Beginning Verify and Repair transaction

2014-02-20 08:51:03, Info                  CSI    00000094 [sR] Verify complete

2014-02-20 08:51:04, Info                  CSI    00000095 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:51:04, Info                  CSI    00000096 [sR] Beginning Verify and Repair transaction

2014-02-20 08:51:18, Info                  CSI    000000b4 [sR] Verify complete

2014-02-20 08:51:19, Info                  CSI    000000b5 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:51:19, Info                  CSI    000000b6 [sR] Beginning Verify and Repair transaction

2014-02-20 08:51:22, Info                  CSI    000000b8 [sR] Verify complete

2014-02-20 08:51:22, Info                  CSI    000000b9 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:51:22, Info                  CSI    000000ba [sR] Beginning Verify and Repair transaction

2014-02-20 08:51:26, Info                  CSI    000000bc [sR] Verify complete

2014-02-20 08:51:27, Info                  CSI    000000bd [sR] Verifying 100 (0x00000064) components

2014-02-20 08:51:27, Info                  CSI    000000be [sR] Beginning Verify and Repair transaction

2014-02-20 08:51:31, Info                  CSI    000000c0 [sR] Verify complete

2014-02-20 08:51:31, Info                  CSI    000000c1 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:51:31, Info                  CSI    000000c2 [sR] Beginning Verify and Repair transaction

2014-02-20 08:51:38, Info                  CSI    000000c4 [sR] Verify complete

2014-02-20 08:51:39, Info                  CSI    000000c5 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:51:39, Info                  CSI    000000c6 [sR] Beginning Verify and Repair transaction

2014-02-20 08:51:50, Info                  CSI    000000c8 [sR] Repairing corrupted file [ml:520{260},l:76{38}]"\??\C:\Program Files\Internet Explorer"\[l:14{7}]"pdm.dll" from store

2014-02-20 08:51:50, Info                  CSI    000000ca [sR] Repairing corrupted file [ml:520{260},l:76{38}]"\??\C:\Program Files\Internet Explorer"\[l:20{10}]"msdbg2.dll" from store

2014-02-20 08:51:51, Info                  CSI    000000ce [sR] Repairing corrupted file [ml:520{260},l:76{38}]"\??\C:\Program Files\Internet Explorer"\[l:14{7}]"pdm.dll" from store

2014-02-20 08:51:51, Info                  CSI    000000d0 [sR] Repairing corrupted file [ml:520{260},l:76{38}]"\??\C:\Program Files\Internet Explorer"\[l:20{10}]"msdbg2.dll" from store

2014-02-20 08:51:51, Info                  CSI    000000d4 [sR] Verify complete

2014-02-20 08:51:51, Info                  CSI    000000d5 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:51:51, Info                  CSI    000000d6 [sR] Beginning Verify and Repair transaction

2014-02-20 08:52:00, Info                  CSI    000000d9 [sR] Verify complete

2014-02-20 08:52:01, Info                  CSI    000000da [sR] Verifying 100 (0x00000064) components

2014-02-20 08:52:01, Info                  CSI    000000db [sR] Beginning Verify and Repair transaction

2014-02-20 08:52:04, Info                  CSI    000000dd [sR] Verify complete

2014-02-20 08:52:05, Info                  CSI    000000de [sR] Verifying 100 (0x00000064) components

2014-02-20 08:52:05, Info                  CSI    000000df [sR] Beginning Verify and Repair transaction

2014-02-20 08:52:08, Info                  CSI    000000e1 [sR] Verify complete

2014-02-20 08:52:09, Info                  CSI    000000e2 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:52:09, Info                  CSI    000000e3 [sR] Beginning Verify and Repair transaction

2014-02-20 08:52:18, Info                  CSI    000000e5 [sR] Verify complete

2014-02-20 08:52:18, Info                  CSI    000000e6 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:52:18, Info                  CSI    000000e7 [sR] Beginning Verify and Repair transaction

2014-02-20 08:52:25, Info                  CSI    000000e9 [sR] Verify complete

2014-02-20 08:52:26, Info                  CSI    000000ea [sR] Verifying 100 (0x00000064) components

2014-02-20 08:52:26, Info                  CSI    000000eb [sR] Beginning Verify and Repair transaction

2014-02-20 08:52:33, Info                  CSI    000000ed [sR] Verify complete

2014-02-20 08:52:34, Info                  CSI    000000ee [sR] Verifying 100 (0x00000064) components

2014-02-20 08:52:34, Info                  CSI    000000ef [sR] Beginning Verify and Repair transaction

2014-02-20 08:52:48, Info                  CSI    000000f2 [sR] Verify complete

2014-02-20 08:52:48, Info                  CSI    000000f3 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:52:48, Info                  CSI    000000f4 [sR] Beginning Verify and Repair transaction

2014-02-20 08:53:01, Info                  CSI    00000119 [sR] Verify complete

2014-02-20 08:53:02, Info                  CSI    0000011a [sR] Verifying 100 (0x00000064) components

2014-02-20 08:53:02, Info                  CSI    0000011b [sR] Beginning Verify and Repair transaction

2014-02-20 08:53:13, Info                  CSI    0000011d [sR] Verify complete

2014-02-20 08:53:14, Info                  CSI    0000011e [sR] Verifying 100 (0x00000064) components

2014-02-20 08:53:14, Info                  CSI    0000011f [sR] Beginning Verify and Repair transaction

2014-02-20 08:53:48, Info                  CSI    00000121 [sR] Verify complete

2014-02-20 08:53:49, Info                  CSI    00000122 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:53:49, Info                  CSI    00000123 [sR] Beginning Verify and Repair transaction

2014-02-20 08:54:07, Info                  CSI    00000125 [sR] Verify complete

2014-02-20 08:54:08, Info                  CSI    00000126 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:54:08, Info                  CSI    00000127 [sR] Beginning Verify and Repair transaction

2014-02-20 08:54:17, Info                  CSI    00000129 [sR] Verify complete

2014-02-20 08:54:18, Info                  CSI    0000012a [sR] Verifying 100 (0x00000064) components

2014-02-20 08:54:18, Info                  CSI    0000012b [sR] Beginning Verify and Repair transaction

2014-02-20 08:54:27, Info                  CSI    0000012d [sR] Verify complete

2014-02-20 08:54:27, Info                  CSI    0000012e [sR] Verifying 100 (0x00000064) components

2014-02-20 08:54:27, Info                  CSI    0000012f [sR] Beginning Verify and Repair transaction

2014-02-20 08:54:34, Info                  CSI    00000131 [sR] Verify complete

2014-02-20 08:54:35, Info                  CSI    00000132 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:54:35, Info                  CSI    00000133 [sR] Beginning Verify and Repair transaction

2014-02-20 08:54:41, Info                  CSI    00000135 [sR] Verify complete

2014-02-20 08:54:42, Info                  CSI    00000136 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:54:42, Info                  CSI    00000137 [sR] Beginning Verify and Repair transaction

2014-02-20 08:54:49, Info                  CSI    0000013a [sR] Verify complete

2014-02-20 08:54:50, Info                  CSI    0000013b [sR] Verifying 100 (0x00000064) components

2014-02-20 08:54:50, Info                  CSI    0000013c [sR] Beginning Verify and Repair transaction

2014-02-20 08:55:00, Info                  CSI    0000013e [sR] Repairing corrupted file [ml:520{260},l:58{29}]"\??\C:\Windows\System32\en-US"\[l:32{16}]"jscript9.dll.mui" from store

2014-02-20 08:55:03, Info                  CSI    00000141 [sR] Repairing corrupted file [ml:520{260},l:58{29}]"\??\C:\Windows\System32\es-ES"\[l:32{16}]"jscript9.dll.mui" from store

2014-02-20 08:55:04, Info                  CSI    00000144 [sR] Verify complete

2014-02-20 08:55:04, Info                  CSI    00000145 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:55:04, Info                  CSI    00000146 [sR] Beginning Verify and Repair transaction

2014-02-20 08:55:12, Info                  CSI    00000149 [sR] Verify complete

2014-02-20 08:55:13, Info                  CSI    0000014a [sR] Verifying 100 (0x00000064) components

2014-02-20 08:55:13, Info                  CSI    0000014b [sR] Beginning Verify and Repair transaction

2014-02-20 08:55:21, Info                  CSI    0000014d [sR] Verify complete

2014-02-20 08:55:22, Info                  CSI    0000014e [sR] Verifying 100 (0x00000064) components

2014-02-20 08:55:22, Info                  CSI    0000014f [sR] Beginning Verify and Repair transaction

2014-02-20 08:55:29, Info                  CSI    00000151 [sR] Repairing corrupted file [ml:520{260},l:46{23}]"\??\C:\Windows\System32"\[l:24{12}]"jscript9.dll" from store

2014-02-20 08:55:30, Info                  CSI    00000154 [sR] Verify complete

2014-02-20 08:55:31, Info                  CSI    00000155 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:55:31, Info                  CSI    00000156 [sR] Beginning Verify and Repair transaction

2014-02-20 08:55:43, Info                  CSI    00000159 [sR] Verify complete

2014-02-20 08:55:43, Info                  CSI    0000015a [sR] Verifying 100 (0x00000064) components

2014-02-20 08:55:43, Info                  CSI    0000015b [sR] Beginning Verify and Repair transaction

2014-02-20 08:55:53, Info                  CSI    0000015d [sR] Verify complete

2014-02-20 08:55:53, Info                  CSI    0000015e [sR] Verifying 100 (0x00000064) components

2014-02-20 08:55:53, Info                  CSI    0000015f [sR] Beginning Verify and Repair transaction

2014-02-20 08:56:00, Info                  CSI    00000161 [sR] Verify complete

2014-02-20 08:56:01, Info                  CSI    00000162 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:56:01, Info                  CSI    00000163 [sR] Beginning Verify and Repair transaction

2014-02-20 08:56:10, Info                  CSI    00000165 [sR] Verify complete

2014-02-20 08:56:10, Info                  CSI    00000166 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:56:10, Info                  CSI    00000167 [sR] Beginning Verify and Repair transaction

2014-02-20 08:56:17, Info                  CSI    0000016a [sR] Verify complete

2014-02-20 08:56:18, Info                  CSI    0000016b [sR] Verifying 100 (0x00000064) components

2014-02-20 08:56:18, Info                  CSI    0000016c [sR] Beginning Verify and Repair transaction

2014-02-20 08:56:27, Info                  CSI    0000016e [sR] Verify complete

2014-02-20 08:56:27, Info                  CSI    0000016f [sR] Verifying 100 (0x00000064) components

2014-02-20 08:56:27, Info                  CSI    00000170 [sR] Beginning Verify and Repair transaction

2014-02-20 08:56:31, Info                  CSI    00000172 [sR] Verify complete

2014-02-20 08:56:32, Info                  CSI    00000173 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:56:32, Info                  CSI    00000174 [sR] Beginning Verify and Repair transaction

2014-02-20 08:56:39, Info                  CSI    00000176 [sR] Verify complete

2014-02-20 08:56:39, Info                  CSI    00000177 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:56:39, Info                  CSI    00000178 [sR] Beginning Verify and Repair transaction

2014-02-20 08:56:49, Info                  CSI    0000017a [sR] Verify complete

2014-02-20 08:56:49, Info                  CSI    0000017b [sR] Verifying 100 (0x00000064) components

2014-02-20 08:56:49, Info                  CSI    0000017c [sR] Beginning Verify and Repair transaction

2014-02-20 08:56:56, Info                  CSI    0000017f [sR] Verify complete

2014-02-20 08:56:57, Info                  CSI    00000180 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:56:57, Info                  CSI    00000181 [sR] Beginning Verify and Repair transaction

2014-02-20 08:57:07, Info                  CSI    00000183 [sR] Verify complete

2014-02-20 08:57:08, Info                  CSI    00000184 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:57:08, Info                  CSI    00000185 [sR] Beginning Verify and Repair transaction

2014-02-20 08:57:16, Info                  CSI    00000187 [sR] Verify complete

2014-02-20 08:57:17, Info                  CSI    00000188 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:57:17, Info                  CSI    00000189 [sR] Beginning Verify and Repair transaction

2014-02-20 08:57:25, Info                  CSI    0000018b [sR] Verify complete

2014-02-20 08:57:26, Info                  CSI    0000018c [sR] Verifying 100 (0x00000064) components

2014-02-20 08:57:26, Info                  CSI    0000018d [sR] Beginning Verify and Repair transaction

2014-02-20 08:57:30, Info                  CSI    0000018f [sR] Verify complete

2014-02-20 08:57:31, Info                  CSI    00000190 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:57:31, Info                  CSI    00000191 [sR] Beginning Verify and Repair transaction

2014-02-20 08:57:36, Info                  CSI    00000193 [sR] Verify complete

2014-02-20 08:57:36, Info                  CSI    00000194 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:57:36, Info                  CSI    00000195 [sR] Beginning Verify and Repair transaction

2014-02-20 08:57:41, Info                  CSI    00000197 [sR] Verify complete

2014-02-20 08:57:42, Info                  CSI    00000198 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:57:42, Info                  CSI    00000199 [sR] Beginning Verify and Repair transaction

2014-02-20 08:57:48, Info                  CSI    0000019b [sR] Verify complete

2014-02-20 08:57:49, Info                  CSI    0000019c [sR] Verifying 100 (0x00000064) components

2014-02-20 08:57:49, Info                  CSI    0000019d [sR] Beginning Verify and Repair transaction

2014-02-20 08:57:54, Info                  CSI    0000019f [sR] Verify complete

2014-02-20 08:57:55, Info                  CSI    000001a0 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:57:55, Info                  CSI    000001a1 [sR] Beginning Verify and Repair transaction

2014-02-20 08:57:59, Info                  CSI    000001a3 [sR] Verify complete

2014-02-20 08:58:00, Info                  CSI    000001a4 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:58:00, Info                  CSI    000001a5 [sR] Beginning Verify and Repair transaction

2014-02-20 08:58:11, Info                  CSI    000001a7 [sR] Verify complete

2014-02-20 08:58:11, Info                  CSI    000001a8 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:58:11, Info                  CSI    000001a9 [sR] Beginning Verify and Repair transaction

2014-02-20 08:58:48, Info                  CSI    000001ab [sR] Verify complete

2014-02-20 08:58:48, Info                  CSI    000001ac [sR] Verifying 100 (0x00000064) components

2014-02-20 08:58:48, Info                  CSI    000001ad [sR] Beginning Verify and Repair transaction

2014-02-20 08:59:01, Info                  CSI    000001af [sR] Verify complete

2014-02-20 08:59:02, Info                  CSI    000001b0 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:59:02, Info                  CSI    000001b1 [sR] Beginning Verify and Repair transaction

2014-02-20 08:59:14, Info                  CSI    000001b3 [sR] Verify complete

2014-02-20 08:59:15, Info                  CSI    000001b4 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:59:15, Info                  CSI    000001b5 [sR] Beginning Verify and Repair transaction

2014-02-20 08:59:18, Info                  CSI    000001b7 [sR] Verify complete

2014-02-20 08:59:18, Info                  CSI    000001b8 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:59:18, Info                  CSI    000001b9 [sR] Beginning Verify and Repair transaction

2014-02-20 08:59:24, Info                  CSI    000001bb [sR] Verify complete

2014-02-20 08:59:25, Info                  CSI    000001bc [sR] Verifying 100 (0x00000064) components

2014-02-20 08:59:25, Info                  CSI    000001bd [sR] Beginning Verify and Repair transaction

2014-02-20 08:59:30, Info                  CSI    000001bf [sR] Verify complete

2014-02-20 08:59:31, Info                  CSI    000001c0 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:59:31, Info                  CSI    000001c1 [sR] Beginning Verify and Repair transaction

2014-02-20 08:59:37, Info                  CSI    000001c3 [sR] Verify complete

2014-02-20 08:59:37, Info                  CSI    000001c4 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:59:37, Info                  CSI    000001c5 [sR] Beginning Verify and Repair transaction

2014-02-20 08:59:39, Info                  CSI    000001c7 [sR] Verify complete

2014-02-20 08:59:39, Info                  CSI    000001c8 [sR] Verifying 100 (0x00000064) components

2014-02-20 08:59:39, Info                  CSI    000001c9 [sR] Beginning Verify and Repair transaction

2014-02-20 08:59:45, Info                  CSI    000001cb [sR] Verify complete

2014-02-20 08:59:45, Info                  CSI    000001cc [sR] Verifying 85 (0x00000055) components

2014-02-20 08:59:45, Info                  CSI    000001cd [sR] Beginning Verify and Repair transaction

2014-02-20 08:59:51, Info                  CSI    000001cf [sR] Verify complete

2014-02-20 08:59:51, Info                  CSI    000001d0 [sR] Repairing 5 components

2014-02-20 08:59:51, Info                  CSI    000001d1 [sR] Beginning Verify and Repair transaction

2014-02-20 08:59:51, Info                  CSI    000001d3 [sR] Repairing corrupted file [ml:520{260},l:58{29}]"\??\C:\Windows\System32\es-ES"\[l:32{16}]"jscript9.dll.mui" from store

2014-02-20 08:59:52, Info                  CSI    000001d6 [sR] Repairing corrupted file [ml:520{260},l:46{23}]"\??\C:\Windows\System32"\[l:24{12}]"jscript9.dll" from store

2014-02-20 08:59:52, Info                  CSI    000001d9 [sR] Repairing corrupted file [ml:520{260},l:76{38}]"\??\C:\Program Files\Internet Explorer"\[l:14{7}]"pdm.dll" from store

2014-02-20 08:59:52, Info                  CSI    000001db [sR] Repairing corrupted file [ml:520{260},l:76{38}]"\??\C:\Program Files\Internet Explorer"\[l:20{10}]"msdbg2.dll" from store

2014-02-20 08:59:52, Info                  CSI    000001df [sR] Repairing corrupted file [ml:520{260},l:58{29}]"\??\C:\Windows\System32\en-US"\[l:32{16}]"jscript9.dll.mui" from store

2014-02-20 08:59:53, Info                  CSI    000001e2 [sR] Repair complete

2014-02-20 08:59:53, Info                  CSI    000001e3 [sR] Committing transaction

2014-02-20 08:59:53, Info                  CSI    000001e7 [sR] Verify and Repair Transaction completed. All files and registry keys listed in this transaction  have been successfully repaired

2014-02-20 13:26:15, Info                  CSI    00000009 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:26:15, Info                  CSI    0000000a [sR] Beginning Verify and Repair transaction

2014-02-20 13:26:23, Info                  CSI    0000000c [sR] Verify complete

2014-02-20 13:26:24, Info                  CSI    0000000d [sR] Verifying 100 (0x00000064) components

2014-02-20 13:26:24, Info                  CSI    0000000e [sR] Beginning Verify and Repair transaction

2014-02-20 13:26:32, Info                  CSI    00000010 [sR] Verify complete

2014-02-20 13:26:32, Info                  CSI    00000011 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:26:32, Info                  CSI    00000012 [sR] Beginning Verify and Repair transaction

2014-02-20 13:26:43, Info                  CSI    00000014 [sR] Verify complete

2014-02-20 13:26:43, Info                  CSI    00000015 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:26:43, Info                  CSI    00000016 [sR] Beginning Verify and Repair transaction

2014-02-20 13:26:49, Info                  CSI    00000018 [sR] Verify complete

2014-02-20 13:26:50, Info                  CSI    00000019 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:26:50, Info                  CSI    0000001a [sR] Beginning Verify and Repair transaction

2014-02-20 13:26:54, Info                  CSI    0000001c [sR] Verify complete

2014-02-20 13:26:54, Info                  CSI    0000001d [sR] Verifying 100 (0x00000064) components

2014-02-20 13:26:54, Info                  CSI    0000001e [sR] Beginning Verify and Repair transaction

2014-02-20 13:27:01, Info                  CSI    00000020 [sR] Verify complete

2014-02-20 13:27:02, Info                  CSI    00000021 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:27:02, Info                  CSI    00000022 [sR] Beginning Verify and Repair transaction

2014-02-20 13:27:09, Info                  CSI    00000024 [sR] Verify complete

2014-02-20 13:27:10, Info                  CSI    00000025 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:27:10, Info                  CSI    00000026 [sR] Beginning Verify and Repair transaction

2014-02-20 13:27:17, Info                  CSI    00000028 [sR] Verify complete

2014-02-20 13:27:18, Info                  CSI    00000029 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:27:18, Info                  CSI    0000002a [sR] Beginning Verify and Repair transaction

2014-02-20 13:27:25, Info                  CSI    0000002c [sR] Verify complete

2014-02-20 13:27:26, Info                  CSI    0000002d [sR] Verifying 100 (0x00000064) components

2014-02-20 13:27:26, Info                  CSI    0000002e [sR] Beginning Verify and Repair transaction

2014-02-20 13:27:34, Info                  CSI    00000030 [sR] Verify complete

2014-02-20 13:27:34, Info                  CSI    00000031 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:27:34, Info                  CSI    00000032 [sR] Beginning Verify and Repair transaction

2014-02-20 13:27:38, Info                  CSI    00000034 [sR] Verify complete

2014-02-20 13:27:38, Info                  CSI    00000035 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:27:38, Info                  CSI    00000036 [sR] Beginning Verify and Repair transaction

2014-02-20 13:27:46, Info                  CSI    00000038 [sR] Verify complete

2014-02-20 13:27:46, Info                  CSI    00000039 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:27:46, Info                  CSI    0000003a [sR] Beginning Verify and Repair transaction

2014-02-20 13:28:01, Info                  CSI    0000003c [sR] Verify complete

2014-02-20 13:28:01, Info                  CSI    0000003d [sR] Verifying 100 (0x00000064) components

2014-02-20 13:28:01, Info                  CSI    0000003e [sR] Beginning Verify and Repair transaction

2014-02-20 13:28:11, Info                  CSI    00000042 [sR] Verify complete

2014-02-20 13:28:12, Info                  CSI    00000043 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:28:12, Info                  CSI    00000044 [sR] Beginning Verify and Repair transaction

2014-02-20 13:28:19, Info                  CSI    00000048 [sR] Verify complete

2014-02-20 13:28:20, Info                  CSI    00000049 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:28:20, Info                  CSI    0000004a [sR] Beginning Verify and Repair transaction

2014-02-20 13:28:27, Info                  CSI    0000004c [sR] Verify complete

2014-02-20 13:28:27, Info                  CSI    0000004d [sR] Verifying 100 (0x00000064) components

2014-02-20 13:28:27, Info                  CSI    0000004e [sR] Beginning Verify and Repair transaction

2014-02-20 13:28:44, Info                  CSI    00000056 [sR] Verify complete

2014-02-20 13:28:45, Info                  CSI    00000057 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:28:45, Info                  CSI    00000058 [sR] Beginning Verify and Repair transaction

2014-02-20 13:29:03, Info                  CSI    0000005e [sR] Verify complete

2014-02-20 13:29:04, Info                  CSI    0000005f [sR] Verifying 100 (0x00000064) components

2014-02-20 13:29:04, Info                  CSI    00000060 [sR] Beginning Verify and Repair transaction

2014-02-20 13:29:14, Info                  CSI    00000062 [sR] Verify complete

2014-02-20 13:29:15, Info                  CSI    00000063 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:29:15, Info                  CSI    00000064 [sR] Beginning Verify and Repair transaction

2014-02-20 13:29:23, Info                  CSI    00000066 [sR] Verify complete

2014-02-20 13:29:25, Info                  CSI    00000067 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:29:25, Info                  CSI    00000068 [sR] Beginning Verify and Repair transaction

2014-02-20 13:29:33, Info                  CSI    0000006a [sR] Verify complete

2014-02-20 13:29:33, Info                  CSI    0000006b [sR] Verifying 100 (0x00000064) components

2014-02-20 13:29:33, Info                  CSI    0000006c [sR] Beginning Verify and Repair transaction

2014-02-20 13:29:47, Info                  CSI    0000006e [sR] Verify complete

2014-02-20 13:29:48, Info                  CSI    0000006f [sR] Verifying 100 (0x00000064) components

2014-02-20 13:29:48, Info                  CSI    00000070 [sR] Beginning Verify and Repair transaction

2014-02-20 13:29:54, Info                  CSI    00000072 [sR] Verify complete

2014-02-20 13:29:55, Info                  CSI    00000073 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:29:55, Info                  CSI    00000074 [sR] Beginning Verify and Repair transaction

2014-02-20 13:30:09, Info                  CSI    00000076 [sR] Verify complete

2014-02-20 13:30:10, Info                  CSI    00000077 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:30:10, Info                  CSI    00000078 [sR] Beginning Verify and Repair transaction

2014-02-20 13:30:42, Info                  CSI    0000007c [sR] Verify complete

2014-02-20 13:30:42, Info                  CSI    0000007d [sR] Verifying 100 (0x00000064) components

2014-02-20 13:30:42, Info                  CSI    0000007e [sR] Beginning Verify and Repair transaction

2014-02-20 13:30:58, Info                  CSI    00000080 [sR] Verify complete

2014-02-20 13:30:58, Info                  CSI    00000081 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:30:58, Info                  CSI    00000082 [sR] Beginning Verify and Repair transaction

2014-02-20 13:31:46, Info                  CSI    00000084 [sR] Verify complete

2014-02-20 13:31:47, Info                  CSI    00000085 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:31:47, Info                  CSI    00000086 [sR] Beginning Verify and Repair transaction

2014-02-20 13:32:28, Info                  CSI    00000088 [sR] Verify complete

2014-02-20 13:32:29, Info                  CSI    00000089 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:32:29, Info                  CSI    0000008a [sR] Beginning Verify and Repair transaction

2014-02-20 13:32:36, Info                  CSI    0000008c [sR] Verify complete

2014-02-20 13:32:36, Info                  CSI    0000008d [sR] Verifying 100 (0x00000064) components

2014-02-20 13:32:36, Info                  CSI    0000008e [sR] Beginning Verify and Repair transaction

2014-02-20 13:32:39, Info                  CSI    00000090 [sR] Verify complete

2014-02-20 13:32:40, Info                  CSI    00000091 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:32:40, Info                  CSI    00000092 [sR] Beginning Verify and Repair transaction

2014-02-20 13:32:46, Info                  CSI    00000094 [sR] Verify complete

2014-02-20 13:32:46, Info                  CSI    00000095 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:32:46, Info                  CSI    00000096 [sR] Beginning Verify and Repair transaction

2014-02-20 13:33:11, Info                  CSI    000000b4 [sR] Verify complete

2014-02-20 13:33:12, Info                  CSI    000000b5 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:33:12, Info                  CSI    000000b6 [sR] Beginning Verify and Repair transaction

2014-02-20 13:33:16, Info                  CSI    000000b8 [sR] Verify complete

2014-02-20 13:33:17, Info                  CSI    000000b9 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:33:17, Info                  CSI    000000ba [sR] Beginning Verify and Repair transaction

2014-02-20 13:33:28, Info                  CSI    000000bc [sR] Verify complete

2014-02-20 13:33:29, Info                  CSI    000000bd [sR] Verifying 100 (0x00000064) components

2014-02-20 13:33:29, Info                  CSI    000000be [sR] Beginning Verify and Repair transaction

2014-02-20 13:33:37, Info                  CSI    000000c0 [sR] Verify complete

2014-02-20 13:33:38, Info                  CSI    000000c1 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:33:38, Info                  CSI    000000c2 [sR] Beginning Verify and Repair transaction

2014-02-20 13:33:46, Info                  CSI    000000c4 [sR] Verify complete

2014-02-20 13:33:47, Info                  CSI    000000c5 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:33:47, Info                  CSI    000000c6 [sR] Beginning Verify and Repair transaction

2014-02-20 13:34:06, Info                  CSI    000000c8 [sR] Repairing corrupted file [ml:520{260},l:76{38}]"\??\C:\Program Files\Internet Explorer"\[l:14{7}]"pdm.dll" from store

2014-02-20 13:34:06, Info                  CSI    000000ca [sR] Repairing corrupted file [ml:520{260},l:76{38}]"\??\C:\Program Files\Internet Explorer"\[l:20{10}]"msdbg2.dll" from store

2014-02-20 13:34:07, Info                  CSI    000000ce [sR] Verify complete

2014-02-20 13:34:08, Info                  CSI    000000cf [sR] Verifying 100 (0x00000064) components

2014-02-20 13:34:08, Info                  CSI    000000d0 [sR] Beginning Verify and Repair transaction

2014-02-20 13:34:20, Info                  CSI    000000d3 [sR] Verify complete

2014-02-20 13:34:20, Info                  CSI    000000d4 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:34:20, Info                  CSI    000000d5 [sR] Beginning Verify and Repair transaction

2014-02-20 13:34:24, Info                  CSI    000000d7 [sR] Verify complete

2014-02-20 13:34:25, Info                  CSI    000000d8 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:34:25, Info                  CSI    000000d9 [sR] Beginning Verify and Repair transaction

2014-02-20 13:34:29, Info                  CSI    000000db [sR] Verify complete

2014-02-20 13:34:30, Info                  CSI    000000dc [sR] Verifying 100 (0x00000064) components

2014-02-20 13:34:30, Info                  CSI    000000dd [sR] Beginning Verify and Repair transaction

2014-02-20 13:34:47, Info                  CSI    000000df [sR] Verify complete

2014-02-20 13:34:48, Info                  CSI    000000e0 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:34:48, Info                  CSI    000000e1 [sR] Beginning Verify and Repair transaction

2014-02-20 13:35:22, Info                  CSI    000000e3 [sR] Verify complete

2014-02-20 13:35:23, Info                  CSI    000000e4 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:35:23, Info                  CSI    000000e5 [sR] Beginning Verify and Repair transaction

2014-02-20 13:35:36, Info                  CSI    000000e7 [sR] Verify complete

2014-02-20 13:35:38, Info                  CSI    000000e8 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:35:38, Info                  CSI    000000e9 [sR] Beginning Verify and Repair transaction

2014-02-20 13:36:03, Info                  CSI    000000ec [sR] Verify complete

2014-02-20 13:36:03, Info                  CSI    000000ed [sR] Verifying 100 (0x00000064) components

2014-02-20 13:36:03, Info                  CSI    000000ee [sR] Beginning Verify and Repair transaction

2014-02-20 13:36:29, Info                  CSI    00000113 [sR] Verify complete

2014-02-20 13:36:30, Info                  CSI    00000114 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:36:30, Info                  CSI    00000115 [sR] Beginning Verify and Repair transaction

2014-02-20 13:36:42, Info                  CSI    00000117 [sR] Verify complete

2014-02-20 13:36:43, Info                  CSI    00000118 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:36:43, Info                  CSI    00000119 [sR] Beginning Verify and Repair transaction

2014-02-20 13:37:28, Info                  CSI    0000011b [sR] Verify complete

2014-02-20 13:37:29, Info                  CSI    0000011c [sR] Verifying 100 (0x00000064) components

2014-02-20 13:37:29, Info                  CSI    0000011d [sR] Beginning Verify and Repair transaction

2014-02-20 13:37:51, Info                  CSI    0000011f [sR] Verify complete

2014-02-20 13:37:52, Info                  CSI    00000120 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:37:52, Info                  CSI    00000121 [sR] Beginning Verify and Repair transaction

2014-02-20 13:38:03, Info                  CSI    00000123 [sR] Verify complete

2014-02-20 13:38:04, Info                  CSI    00000124 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:38:04, Info                  CSI    00000125 [sR] Beginning Verify and Repair transaction

2014-02-20 13:38:13, Info                  CSI    00000127 [sR] Verify complete

2014-02-20 13:38:14, Info                  CSI    00000128 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:38:14, Info                  CSI    00000129 [sR] Beginning Verify and Repair transaction

2014-02-20 13:38:23, Info                  CSI    0000012b [sR] Verify complete

2014-02-20 13:38:24, Info                  CSI    0000012c [sR] Verifying 100 (0x00000064) components

2014-02-20 13:38:24, Info                  CSI    0000012d [sR] Beginning Verify and Repair transaction

2014-02-20 13:38:31, Info                  CSI    0000012f [sR] Verify complete

2014-02-20 13:38:32, Info                  CSI    00000130 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:38:32, Info                  CSI    00000131 [sR] Beginning Verify and Repair transaction

2014-02-20 13:38:41, Info                  CSI    00000134 [sR] Verify complete

2014-02-20 13:38:41, Info                  CSI    00000135 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:38:41, Info                  CSI    00000136 [sR] Beginning Verify and Repair transaction

2014-02-20 13:38:54, Info                  CSI    00000138 [sR] Verify complete

2014-02-20 13:38:54, Info                  CSI    00000139 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:38:54, Info                  CSI    0000013a [sR] Beginning Verify and Repair transaction

2014-02-20 13:39:01, Info                  CSI    0000013c [sR] Repairing corrupted file [ml:520{260},l:58{29}]"\??\C:\Windows\System32\es-ES"\[l:32{16}]"jscript9.dll.mui" from store

2014-02-20 13:39:02, Info                  CSI    00000140 [sR] Repairing corrupted file [ml:520{260},l:58{29}]"\??\C:\Windows\System32\en-US"\[l:32{16}]"jscript9.dll.mui" from store

2014-02-20 13:39:03, Info                  CSI    00000143 [sR] Verify complete

2014-02-20 13:39:03, Info                  CSI    00000144 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:39:03, Info                  CSI    00000145 [sR] Beginning Verify and Repair transaction

2014-02-20 13:39:13, Info                  CSI    00000147 [sR] Verify complete

2014-02-20 13:39:14, Info                  CSI    00000148 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:39:14, Info                  CSI    00000149 [sR] Beginning Verify and Repair transaction

2014-02-20 13:39:21, Info                  CSI    0000014b [sR] Repairing corrupted file [ml:520{260},l:46{23}]"\??\C:\Windows\System32"\[l:24{12}]"jscript9.dll" from store

2014-02-20 13:39:21, Info                  CSI    0000014e [sR] Repairing corrupted file [ml:520{260},l:46{23}]"\??\C:\Windows\System32"\[l:24{12}]"jscript9.dll" from store

2014-02-20 13:39:22, Info                  CSI    00000151 [sR] Verify complete

2014-02-20 13:39:23, Info                  CSI    00000152 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:39:23, Info                  CSI    00000153 [sR] Beginning Verify and Repair transaction

2014-02-20 13:39:36, Info                  CSI    00000156 [sR] Verify complete

2014-02-20 13:39:37, Info                  CSI    00000157 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:39:37, Info                  CSI    00000158 [sR] Beginning Verify and Repair transaction

2014-02-20 13:39:47, Info                  CSI    0000015a [sR] Verify complete

2014-02-20 13:39:47, Info                  CSI    0000015b [sR] Verifying 100 (0x00000064) components

2014-02-20 13:39:47, Info                  CSI    0000015c [sR] Beginning Verify and Repair transaction

2014-02-20 13:39:56, Info                  CSI    0000015e [sR] Verify complete

2014-02-20 13:39:56, Info                  CSI    0000015f [sR] Verifying 100 (0x00000064) components

2014-02-20 13:39:56, Info                  CSI    00000160 [sR] Beginning Verify and Repair transaction

2014-02-20 13:40:06, Info                  CSI    00000162 [sR] Verify complete

2014-02-20 13:40:07, Info                  CSI    00000163 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:40:07, Info                  CSI    00000164 [sR] Beginning Verify and Repair transaction

2014-02-20 13:40:14, Info                  CSI    00000167 [sR] Verify complete

2014-02-20 13:40:15, Info                  CSI    00000168 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:40:15, Info                  CSI    00000169 [sR] Beginning Verify and Repair transaction

2014-02-20 13:40:25, Info                  CSI    0000016b [sR] Verify complete

2014-02-20 13:40:26, Info                  CSI    0000016c [sR] Verifying 100 (0x00000064) components

2014-02-20 13:40:26, Info                  CSI    0000016d [sR] Beginning Verify and Repair transaction

2014-02-20 13:40:31, Info                  CSI    0000016f [sR] Verify complete

2014-02-20 13:40:32, Info                  CSI    00000170 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:40:32, Info                  CSI    00000171 [sR] Beginning Verify and Repair transaction

2014-02-20 13:40:40, Info                  CSI    00000173 [sR] Verify complete

2014-02-20 13:40:41, Info                  CSI    00000174 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:40:41, Info                  CSI    00000175 [sR] Beginning Verify and Repair transaction

2014-02-20 13:40:51, Info                  CSI    00000177 [sR] Verify complete

2014-02-20 13:40:51, Info                  CSI    00000178 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:40:51, Info                  CSI    00000179 [sR] Beginning Verify and Repair transaction

2014-02-20 13:40:59, Info                  CSI    0000017c [sR] Verify complete

2014-02-20 13:40:59, Info                  CSI    0000017d [sR] Verifying 100 (0x00000064) components

2014-02-20 13:40:59, Info                  CSI    0000017e [sR] Beginning Verify and Repair transaction

2014-02-20 13:41:14, Info                  CSI    00000180 [sR] Verify complete

2014-02-20 13:41:15, Info                  CSI    00000181 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:41:15, Info                  CSI    00000182 [sR] Beginning Verify and Repair transaction

2014-02-20 13:41:29, Info                  CSI    00000184 [sR] Verify complete

2014-02-20 13:41:31, Info                  CSI    00000185 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:41:31, Info                  CSI    00000186 [sR] Beginning Verify and Repair transaction

2014-02-20 13:41:50, Info                  CSI    00000188 [sR] Verify complete

2014-02-20 13:41:51, Info                  CSI    00000189 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:41:51, Info                  CSI    0000018a [sR] Beginning Verify and Repair transaction

2014-02-20 13:42:02, Info                  CSI    0000018c [sR] Verify complete

2014-02-20 13:42:03, Info                  CSI    0000018d [sR] Verifying 100 (0x00000064) components

2014-02-20 13:42:03, Info                  CSI    0000018e [sR] Beginning Verify and Repair transaction

2014-02-20 13:42:09, Info                  CSI    00000190 [sR] Verify complete

2014-02-20 13:42:10, Info                  CSI    00000191 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:42:10, Info                  CSI    00000192 [sR] Beginning Verify and Repair transaction

2014-02-20 13:42:17, Info                  CSI    00000194 [sR] Verify complete

2014-02-20 13:42:17, Info                  CSI    00000195 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:42:17, Info                  CSI    00000196 [sR] Beginning Verify and Repair transaction

2014-02-20 13:42:25, Info                  CSI    00000198 [sR] Verify complete

2014-02-20 13:42:25, Info                  CSI    00000199 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:42:25, Info                  CSI    0000019a [sR] Beginning Verify and Repair transaction

2014-02-20 13:42:31, Info                  CSI    0000019c [sR] Verify complete

2014-02-20 13:42:32, Info                  CSI    0000019d [sR] Verifying 100 (0x00000064) components

2014-02-20 13:42:32, Info                  CSI    0000019e [sR] Beginning Verify and Repair transaction

2014-02-20 13:42:36, Info                  CSI    000001a0 [sR] Verify complete

2014-02-20 13:42:37, Info                  CSI    000001a1 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:42:37, Info                  CSI    000001a2 [sR] Beginning Verify and Repair transaction

2014-02-20 13:42:54, Info                  CSI    000001a4 [sR] Verify complete

2014-02-20 13:42:54, Info                  CSI    000001a5 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:42:54, Info                  CSI    000001a6 [sR] Beginning Verify and Repair transaction

2014-02-20 13:43:30, Info                  CSI    000001a8 [sR] Verify complete

2014-02-20 13:43:31, Info                  CSI    000001a9 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:43:31, Info                  CSI    000001aa [sR] Beginning Verify and Repair transaction

2014-02-20 13:43:45, Info                  CSI    000001ac [sR] Verify complete

2014-02-20 13:43:46, Info                  CSI    000001ad [sR] Verifying 100 (0x00000064) components

2014-02-20 13:43:46, Info                  CSI    000001ae [sR] Beginning Verify and Repair transaction

2014-02-20 13:43:59, Info                  CSI    000001b0 [sR] Verify complete

2014-02-20 13:44:00, Info                  CSI    000001b1 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:44:00, Info                  CSI    000001b2 [sR] Beginning Verify and Repair transaction

2014-02-20 13:44:03, Info                  CSI    000001b4 [sR] Verify complete

2014-02-20 13:44:03, Info                  CSI    000001b5 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:44:03, Info                  CSI    000001b6 [sR] Beginning Verify and Repair transaction

2014-02-20 13:44:15, Info                  CSI    000001b8 [sR] Verify complete

2014-02-20 13:44:16, Info                  CSI    000001b9 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:44:16, Info                  CSI    000001ba [sR] Beginning Verify and Repair transaction

2014-02-20 13:44:22, Info                  CSI    000001bc [sR] Verify complete

2014-02-20 13:44:22, Info                  CSI    000001bd [sR] Verifying 100 (0x00000064) components

2014-02-20 13:44:22, Info                  CSI    000001be [sR] Beginning Verify and Repair transaction

2014-02-20 13:44:29, Info                  CSI    000001c0 [sR] Verify complete

2014-02-20 13:44:30, Info                  CSI    000001c1 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:44:30, Info                  CSI    000001c2 [sR] Beginning Verify and Repair transaction

2014-02-20 13:44:31, Info                  CSI    000001c4 [sR] Verify complete

2014-02-20 13:44:32, Info                  CSI    000001c5 [sR] Verifying 100 (0x00000064) components

2014-02-20 13:44:32, Info                  CSI    000001c6 [sR] Beginning Verify and Repair transaction

2014-02-20 13:44:38, Info                  CSI    000001c8 [sR] Verify complete

2014-02-20 13:44:38, Info                  CSI    000001c9 [sR] Verifying 85 (0x00000055) components

2014-02-20 13:44:38, Info                  CSI    000001ca [sR] Beginning Verify and Repair transaction

2014-02-20 13:44:45, Info                  CSI    000001cc [sR] Verify complete

2014-02-20 13:44:45, Info                  CSI    000001cd [sR] Repairing 5 components

2014-02-20 13:44:45, Info                  CSI    000001ce [sR] Beginning Verify and Repair transaction

2014-02-20 13:44:46, Info                  CSI    000001d0 [sR] Repairing corrupted file [ml:520{260},l:76{38}]"\??\C:\Program Files\Internet Explorer"\[l:14{7}]"pdm.dll" from store

2014-02-20 13:44:46, Info                  CSI    000001d2 [sR] Repairing corrupted file [ml:520{260},l:76{38}]"\??\C:\Program Files\Internet Explorer"\[l:20{10}]"msdbg2.dll" from store

2014-02-20 13:44:46, Info                  CSI    000001d6 [sR] Repairing corrupted file [ml:520{260},l:58{29}]"\??\C:\Windows\System32\en-US"\[l:32{16}]"jscript9.dll.mui" from store

2014-02-20 13:44:46, Info                  CSI    000001d9 [sR] Repairing corrupted file [ml:520{260},l:58{29}]"\??\C:\Windows\System32\es-ES"\[l:32{16}]"jscript9.dll.mui" from store

2014-02-20 13:44:47, Info                  CSI    000001dc [sR] Repairing corrupted file [ml:520{260},l:46{23}]"\??\C:\Windows\System32"\[l:24{12}]"jscript9.dll" from store

2014-02-20 13:44:47, Info                  CSI    000001df [sR] Repair complete

2014-02-20 13:44:47, Info                  CSI    000001e0 [sR] Committing transaction

2014-02-20 13:44:48, Info                  CSI    000001e4 [sR] Verify and Repair Transaction completed. All files and registry keys listed in this transaction  have been successfully repaired
Link to post
Share on other sites

2014-02-20 13:33:47, Info                  CSI    000000c5 [sR] Verifying 100 (0

x00000064) components
2014-02-20 13:33:47, Info                  CSI    000000c6 [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:34:06, Info                  CSI    000000c8 [sR] Repairing corrup
ted file [ml:520{260},l:76{38}]"\??\C:\Program Files\Internet Explorer"\[l:14{7}
]"pdm.dll" from store
2014-02-20 13:34:06, Info                  CSI    000000ca [sR] Repairing corrup
ted file [ml:520{260},l:76{38}]"\??\C:\Program Files\Internet Explorer"\[l:20{10
}]"msdbg2.dll" from store
2014-02-20 13:34:07, Info                  CSI    000000ce [sR] Verify complete
2014-02-20 13:34:08, Info                  CSI    000000cf [sR] Verifying 100 (0
x00000064) components
2014-02-20 13:34:08, Info                  CSI    000000d0 [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:34:20, Info                  CSI    000000d3 [sR] Verify complete
2014-02-20 13:34:20, Info                  CSI    000000d4 [sR] Verifying 100 (0
x00000064) components
2014-02-20 13:34:20, Info                  CSI    000000d5 [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:34:24, Info                  CSI    000000d7 [sR] Verify complete
2014-02-20 13:34:25, Info                  CSI    000000d8 [sR] Verifying 100 (0
x00000064) components
2014-02-20 13:34:25, Info                  CSI    000000d9 [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:34:29, Info                  CSI    000000db [sR] Verify complete
2014-02-20 13:34:30, Info                  CSI    000000dc [sR] Verifying 100 (0
x00000064) components
2014-02-20 13:34:30, Info                  CSI    000000dd [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:34:47, Info                  CSI    000000df [sR] Verify complete
2014-02-20 13:34:48, Info                  CSI    000000e0 [sR] Verifying 100 (0
x00000064) components
2014-02-20 13:34:48, Info                  CSI    000000e1 [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:35:22, Info                  CSI    000000e3 [sR] Verify complete
2014-02-20 13:35:23, Info                  CSI    000000e4 [sR] Verifying 100 (0
x00000064) components
2014-02-20 13:35:23, Info                  CSI    000000e5 [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:35:36, Info                  CSI    000000e7 [sR] Verify complete
2014-02-20 13:35:38, Info                  CSI    000000e8 [sR] Verifying 100 (0
x00000064) components
2014-02-20 13:35:38, Info                  CSI    000000e9 [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:36:03, Info                  CSI    000000ec [sR] Verify complete
2014-02-20 13:36:03, Info                  CSI    000000ed [sR] Verifying 100 (0
x00000064) components
2014-02-20 13:36:03, Info                  CSI    000000ee [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:36:29, Info                  CSI    00000113 [sR] Verify complete
2014-02-20 13:36:30, Info                  CSI    00000114 [sR] Verifying 100 (0
x00000064) components
2014-02-20 13:36:30, Info                  CSI    00000115 [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:36:42, Info                  CSI    00000117 [sR] Verify complete
2014-02-20 13:36:43, Info                  CSI    00000118 [sR] Verifying 100 (0
x00000064) components
2014-02-20 13:36:43, Info                  CSI    00000119 [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:37:28, Info                  CSI    0000011b [sR] Verify complete
2014-02-20 13:37:29, Info                  CSI    0000011c [sR] Verifying 100 (0
x00000064) components
2014-02-20 13:37:29, Info                  CSI    0000011d [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:37:51, Info                  CSI    0000011f [sR] Verify complete
2014-02-20 13:37:52, Info                  CSI    00000120 [sR] Verifying 100 (0
x00000064) components
2014-02-20 13:37:52, Info                  CSI    00000121 [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:38:03, Info                  CSI    00000123 [sR] Verify complete
2014-02-20 13:38:04, Info                  CSI    00000124 [sR] Verifying 100 (0
x00000064) components
2014-02-20 13:38:04, Info                  CSI    00000125 [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:38:13, Info                  CSI    00000127 [sR] Verify complete
2014-02-20 13:38:14, Info                  CSI    00000128 [sR] Verifying 100 (0
x00000064) components
2014-02-20 13:38:14, Info                  CSI    00000129 [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:38:23, Info                  CSI    0000012b [sR] Verify complete
2014-02-20 13:38:24, Info                  CSI    0000012c [sR] Verifying 100 (0
x00000064) components
2014-02-20 13:38:24, Info                  CSI    0000012d [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:38:31, Info                  CSI    0000012f [sR] Verify complete
2014-02-20 13:38:32, Info                  CSI    00000130 [sR] Verifying 100 (0
x00000064) components
2014-02-20 13:38:32, Info                  CSI    00000131 [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:38:41, Info                  CSI    00000134 [sR] Verify complete
2014-02-20 13:38:41, Info                  CSI    00000135 [sR] Verifying 100 (0
x00000064) components
2014-02-20 13:38:41, Info                  CSI    00000136 [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:38:54, Info                  CSI    00000138 [sR] Verify complete
2014-02-20 13:38:54, Info                  CSI    00000139 [sR] Verifying 100 (0
x00000064) components
2014-02-20 13:38:54, Info                  CSI    0000013a [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:39:01, Info                  CSI    0000013c [sR] Repairing corrup
ted file [ml:520{260},l:58{29}]"\??\C:\Windows\System32\es-ES"\[l:32{16}]"jscrip
t9.dll.mui" from store
2014-02-20 13:39:02, Info                  CSI    00000140 [sR] Repairing corrup
ted file [ml:520{260},l:58{29}]"\??\C:\Windows\System32\en-US"\[l:32{16}]"jscrip
t9.dll.mui" from store
2014-02-20 13:39:03, Info                  CSI    00000143 [sR] Verify complete
2014-02-20 13:39:03, Info                  CSI    00000144 [sR] Verifying 100 (0
x00000064) components
2014-02-20 13:39:03, Info                  CSI    00000145 [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:39:13, Info                  CSI    00000147 [sR] Verify complete
2014-02-20 13:39:14, Info                  CSI    00000148 [sR] Verifying 100 (0
x00000064) components
2014-02-20 13:39:14, Info                  CSI    00000149 [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:39:21, Info                  CSI    0000014b [sR] Repairing corrup
ted file [ml:520{260},l:46{23}]"\??\C:\Windows\System32"\[l:24{12}]"jscript9.dll
" from store
2014-02-20 13:39:21, Info                  CSI    0000014e [sR] Repairing corrup
ted file [ml:520{260},l:46{23}]"\??\C:\Windows\System32"\[l:24{12}]"jscript9.dll
" from store
2014-02-20 13:39:22, Info                  CSI    00000151 [sR] Verify complete
2014-02-20 13:39:23, Info                  CSI    00000152 [sR] Verifying 100 (0
x00000064) components
2014-02-20 13:39:23, Info                  CSI    00000153 [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:39:36, Info                  CSI    00000156 [sR] Verify complete
2014-02-20 13:39:37, Info                  CSI    00000157 [sR] Verifying 100 (0
x00000064) components
2014-02-20 13:39:37, Info                  CSI    00000158 [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:39:47, Info                  CSI    0000015a [sR] Verify complete
2014-02-20 13:39:47, Info                  CSI    0000015b [sR] Verifying 100 (0
x00000064) components
2014-02-20 13:39:47, Info                  CSI    0000015c [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:39:56, Info                  CSI    0000015e [sR] Verify complete
2014-02-20 13:39:56, Info                  CSI    0000015f [sR] Verifying 100 (0
x00000064) components
2014-02-20 13:39:56, Info                  CSI    00000160 [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:40:06, Info                  CSI    00000162 [sR] Verify complete
2014-02-20 13:40:07, Info                  CSI    00000163 [sR] Verifying 100 (0
x00000064) components
2014-02-20 13:40:07, Info                  CSI    00000164 [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:40:14, Info                  CSI    00000167 [sR] Verify complete
2014-02-20 13:40:15, Info                  CSI    00000168 [sR] Verifying 100 (0
x00000064) components
2014-02-20 13:40:15, Info                  CSI    00000169 [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:40:25, Info                  CSI    0000016b [sR] Verify complete
2014-02-20 13:40:26, Info                  CSI    0000016c [sR] Verifying 100 (0
x00000064) components
2014-02-20 13:40:26, Info                  CSI    0000016d [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:40:31, Info                  CSI    0000016f [sR] Verify complete
2014-02-20 13:40:32, Info                  CSI    00000170 [sR] Verifying 100 (0
x00000064) components
2014-02-20 13:40:32, Info                  CSI    00000171 [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:40:40, Info                  CSI    00000173 [sR] Verify complete
2014-02-20 13:40:41, Info                  CSI    00000174 [sR] Verifying 100 (0
x00000064) components
2014-02-20 13:40:41, Info                  CSI    00000175 [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:40:51, Info                  CSI    00000177 [sR] Verify complete
2014-02-20 13:40:51, Info                  CSI    00000178 [sR] Verifying 100 (0
x00000064) components
2014-02-20 13:40:51, Info                  CSI    00000179 [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:40:59, Info                  CSI    0000017c [sR] Verify complete
2014-02-20 13:40:59, Info                  CSI    0000017d [sR] Verifying 100 (0
x00000064) components
2014-02-20 13:40:59, Info                  CSI    0000017e [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:41:14, Info                  CSI    00000180 [sR] Verify complete
2014-02-20 13:41:15, Info                  CSI    00000181 [sR] Verifying 100 (0
x00000064) components
2014-02-20 13:41:15, Info                  CSI    00000182 [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:41:29, Info                  CSI    00000184 [sR] Verify complete
2014-02-20 13:41:31, Info                  CSI    00000185 [sR] Verifying 100 (0
x00000064) components
2014-02-20 13:41:31, Info                  CSI    00000186 [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:41:50, Info                  CSI    00000188 [sR] Verify complete
2014-02-20 13:41:51, Info                  CSI    00000189 [sR] Verifying 100 (0
x00000064) components
2014-02-20 13:41:51, Info                  CSI    0000018a [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:42:02, Info                  CSI    0000018c [sR] Verify complete
2014-02-20 13:42:03, Info                  CSI    0000018d [sR] Verifying 100 (0
x00000064) components
2014-02-20 13:42:03, Info                  CSI    0000018e [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:42:09, Info                  CSI    00000190 [sR] Verify complete
2014-02-20 13:42:10, Info                  CSI    00000191 [sR] Verifying 100 (0
x00000064) components
2014-02-20 13:42:10, Info                  CSI    00000192 [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:42:17, Info                  CSI    00000194 [sR] Verify complete
2014-02-20 13:42:17, Info                  CSI    00000195 [sR] Verifying 100 (0
x00000064) components
2014-02-20 13:42:17, Info                  CSI    00000196 [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:42:25, Info                  CSI    00000198 [sR] Verify complete
2014-02-20 13:42:25, Info                  CSI    00000199 [sR] Verifying 100 (0
x00000064) components
2014-02-20 13:42:25, Info                  CSI    0000019a [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:42:31, Info                  CSI    0000019c [sR] Verify complete
2014-02-20 13:42:32, Info                  CSI    0000019d [sR] Verifying 100 (0
x00000064) components
2014-02-20 13:42:32, Info                  CSI    0000019e [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:42:36, Info                  CSI    000001a0 [sR] Verify complete
2014-02-20 13:42:37, Info                  CSI    000001a1 [sR] Verifying 100 (0
x00000064) components
2014-02-20 13:42:37, Info                  CSI    000001a2 [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:42:54, Info                  CSI    000001a4 [sR] Verify complete
2014-02-20 13:42:54, Info                  CSI    000001a5 [sR] Verifying 100 (0
x00000064) components
2014-02-20 13:42:54, Info                  CSI    000001a6 [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:43:30, Info                  CSI    000001a8 [sR] Verify complete
2014-02-20 13:43:31, Info                  CSI    000001a9 [sR] Verifying 100 (0
x00000064) components
2014-02-20 13:43:31, Info                  CSI    000001aa [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:43:45, Info                  CSI    000001ac [sR] Verify complete
2014-02-20 13:43:46, Info                  CSI    000001ad [sR] Verifying 100 (0
x00000064) components
2014-02-20 13:43:46, Info                  CSI    000001ae [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:43:59, Info                  CSI    000001b0 [sR] Verify complete
2014-02-20 13:44:00, Info                  CSI    000001b1 [sR] Verifying 100 (0
x00000064) components
2014-02-20 13:44:00, Info                  CSI    000001b2 [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:44:03, Info                  CSI    000001b4 [sR] Verify complete
2014-02-20 13:44:03, Info                  CSI    000001b5 [sR] Verifying 100 (0
x00000064) components
2014-02-20 13:44:03, Info                  CSI    000001b6 [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:44:15, Info                  CSI    000001b8 [sR] Verify complete
2014-02-20 13:44:16, Info                  CSI    000001b9 [sR] Verifying 100 (0
x00000064) components
2014-02-20 13:44:16, Info                  CSI    000001ba [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:44:22, Info                  CSI    000001bc [sR] Verify complete
2014-02-20 13:44:22, Info                  CSI    000001bd [sR] Verifying 100 (0
x00000064) components
2014-02-20 13:44:22, Info                  CSI    000001be [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:44:29, Info                  CSI    000001c0 [sR] Verify complete
2014-02-20 13:44:30, Info                  CSI    000001c1 [sR] Verifying 100 (0
x00000064) components
2014-02-20 13:44:30, Info                  CSI    000001c2 [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:44:31, Info                  CSI    000001c4 [sR] Verify complete
2014-02-20 13:44:32, Info                  CSI    000001c5 [sR] Verifying 100 (0
x00000064) components
2014-02-20 13:44:32, Info                  CSI    000001c6 [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:44:38, Info                  CSI    000001c8 [sR] Verify complete
2014-02-20 13:44:38, Info                  CSI    000001c9 [sR] Verifying 85 (0x
00000055) components
2014-02-20 13:44:38, Info                  CSI    000001ca [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:44:45, Info                  CSI    000001cc [sR] Verify complete
2014-02-20 13:44:45, Info                  CSI    000001cd [sR] Repairing 5 comp
onents
2014-02-20 13:44:45, Info                  CSI    000001ce [sR] Beginning Verify
 and Repair transaction
2014-02-20 13:44:46, Info                  CSI    000001d0 [sR] Repairing corrup
ted file [ml:520{260},l:76{38}]"\??\C:\Program Files\Internet Explorer"\[l:14{7}
]"pdm.dll" from store
2014-02-20 13:44:46, Info                  CSI    000001d2 [sR] Repairing corrup
ted file [ml:520{260},l:76{38}]"\??\C:\Program Files\Internet Explorer"\[l:20{10
}]"msdbg2.dll" from store
2014-02-20 13:44:46, Info                  CSI    000001d6 [sR] Repairing corrup
ted file [ml:520{260},l:58{29}]"\??\C:\Windows\System32\en-US"\[l:32{16}]"jscrip
t9.dll.mui" from store
2014-02-20 13:44:46, Info                  CSI    000001d9 [sR] Repairing corrup
ted file [ml:520{260},l:58{29}]"\??\C:\Windows\System32\es-ES"\[l:32{16}]"jscrip
t9.dll.mui" from store
2014-02-20 13:44:47, Info                  CSI    000001dc [sR] Repairing corrup
ted file [ml:520{260},l:46{23}]"\??\C:\Windows\System32"\[l:24{12}]"jscript9.dll
" from store
2014-02-20 13:44:47, Info                  CSI    000001df [sR] Repair complete
2014-02-20 13:44:47, Info                  CSI    000001e0 [sR] Committing trans
action
2014-02-20 13:44:48, Info                  CSI    000001e4 [sR] Verify and Repai
r Transaction completed. All files and registry keys listed in this transaction
 have been successfully repaired
 
C:\Windows\system32>
Link to post
Share on other sites

Scan with ESET Online Scan

Please go to here to run the online scannner from ESET.

  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked
  • Click on Advanced Settings and ensure these options are ticked:
    • Scan for potentially unwanted applications
  • Scan for potentially unsafe applications
  • Enable Anti-Stealth Technology

[*]Click Scan[*]Wait for the scan to finish[*]If any threats were found, click the 'List of found threats' , then click Export to text file.... [*]Save it to your desktop, then please copy and paste that log as a reply to this topic.

Link to post
Share on other sites

Windows Repair (all-in-one)

Please download Windows Repair (all in one) from here.

Install the program then run it.

Go to step 2 and allow it to run Disk check.

Capture3.gif

Once that is done then go to step 3 and allow it to run SFC by clicking Do it

Capture.gif


On the Start Repairs tab, click Start.
Within the opening window, hit unselect all.
Check only the following:



  • Reset Registry Permissions
  • Reset File Permissions
  • Register System Files
  • Repair Windows Firewall
  • Repair Windows Updates



then click on Start

DON'T use the computer while each scan is in progress.

Restart may be needed to finish the repair procedure.

Let me know how that worked out for you.

Link to post
Share on other sites

Well, then we have to send you to the MBAM forum...

 

 

Then we can do the cleanup - if you are facing any issues, report that immediately.

Delete junk with adwCleaner


Please download AdwCleaner to your desktop.


  • Run adwcleaner.exe
  • Hit Scan and wait for the scan to finish.
  • Confirm the message but don´t uncheck anything.
  • Hit Clean
  • When the run is finished, it will open up a text file
  • Please post its contents within your next reply
  • You´ll find the log file at C:\AdwCleaner[s1].txt also


SecurityCheck

Please download SecurityCheck: LINK1 LINK2

  • Save it to your desktop, start it and follow the instructions in the window.
  • After the scan finished the (checkup.txt) will open. Copy its content to your thread.

Link to post
Share on other sites

 Results of screen317's Security Check version 0.99.79  

 Windows 7 Service Pack 1 x86 (UAC is enabled)  

 Internet Explorer 11  

``````````````Antivirus/Firewall Check:`````````````` 

avast! Antivirus   

 Antivirus out of date!  

`````````Anti-malware/Other Utilities Check:````````` 

 TuneUp Utilities 2014 (es-MX)  

 Argente - Registry Cleaner 3.1.0.1 

 CCleaner     

 Adobe Reader 9 Adobe Reader out of Date! 

 Google Chrome 32.0.1700.107  

 Google Chrome 33.0.1750.117  

````````Process Check: objlist.exe by Laurent````````  

 Malwarebytes Anti-Malware mbamservice.exe  

 Malwarebytes Anti-Malware mbamgui.exe  

 Alwil Software Avast5 AvastSvc.exe  

 Alwil Software Avast5 AvastUI.exe  

`````````````````System Health check````````````````` 

 Total Fragmentation on Drive C:  

````````````````````End of Log`````````````````````` 


# AdwCleaner v3.020 - Reporte Creado 27/02/2014 en 11:53:49

# Actualizado 27/02/2014 por Xplode

# Sistema Operativo : Windows 7 Professional Service Pack 1 (32 bits)

# Nombre de usuario : user - USER-PC

# Ejecutado desde : C:\Users\user\Downloads\adwcleaner.exe

# Opción : Limpiar

 

***** [ Servicios ] *****

 

 

***** [ Archivos / Carpetas ] *****

 

 

***** [ Accesos directos ] *****

 

 

***** [ Registro ] *****

 

 

***** [ Navegadores ] *****

 

-\\ Internet Explorer v11.0.9600.16518

 

 

-\\ Google Chrome v33.0.1750.117

 

[ Archivo : C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\preferences ]

 

 

[ Archivo : C:\Users\Invitado\AppData\Local\Google\Chrome\User Data\Default\preferences ]

 

 

*************************

 

AdwCleaner[R0].txt - [894 octets] - [27/02/2014 11:51:57]

AdwCleaner[s0].txt - [814 octets] - [27/02/2014 11:53:49]

 

########## EOF - C:\AdwCleaner\AdwCleaner[s0].txt - [873 octets] ##########

 

Link to post
Share on other sites

Please start a new topic here: https://forums.malwarebytes.org/index.php?showforum=41

Tell the helper that you came from here and finished the malware removal process.

 

 

 

Adobe Reader out of date

Your Adobe Reader is outdated. We will fix this.


  • Get the actual software from here. Important: Uncheck any optional software (for example Google Chrome, etc.) offered.
  • Run setup and follow the instructions.
  • Click upon Start-->control panel-->add/remove programs.
  • Search for and remove any older reader versions.

 

 

Also, update you Avast! definitions!!

 

 

Uninstall our tools using delfix

Please follow these steps in order:

  1. In the case we used Defogger to turn off your CD emulation software. You can start it again and use the Enable button.
  2. In the case we used Combofix. Deactivate your antivirus software once more, then rename the combofix.exe to uninstall.exe and run it one last time. You shall be noted that Combofix has been removed.
  3. In any case please download delfix to your desktop.
    • Close all other programms and start delfix.
    • Please check all the boxes and run the tool.
    • delfix will now delete all found traces of our removal process

[*] If there is still something left please delete it manualy.

 

 

 

Recommendations: How to protect yourself

  • System Updates
    Please ensure to have automatic updates activated in your control panel.
    For further information and a tutorial, see this Microsoft Support article.
  • Protection
    What you need is one (not more) virus scanner with background protection. Additionally I recommend a special malware scanner to run on demand weekly.
    Personally I am using avast! Antivirus Free Edition and Malwarebytes Anti-Malware. They offer good protection for free.
    • To keep your browser free of advertising, you may install the Adblock Plus browser extension.
      It will filter unwanted advertising out of the website´s content.
    • To protect yourself from accidentally visiting malicious web sites, install the Web of Trust (WOT) browser extension.
      It will display a green (safe), yellow (unknown) or red (potentially dangerous) icon for a visited website within your browser.
      In addition, before accessing a dangerous classified web site, a warning screen is displayed.


    [*]Up to date Software
    Keep your Windows and your third party software up to date. The easiest way to get infected is an outdated windows, followed by: browser(s) (including add-ons and plug-ins), Adobe Flash Player and Adobe Reader, Java Runtime Environment, your antivirus program and so on. These links may help you to check:

    [*]Backup
    Hardware issues, malware, fire, lightning strike: There is a long list of different ways to loose all your data. Back up your files regularly. Use the windows internal backup function or a third party tool and save your data onto an external hard drive, cloud storage, optical media like CDs or DVDs or (if available) a professional network backup system. [*]Behaviour
    The commonest error when using a computer is "error 80" - what means that the error is located about 80cm in front of the monitor. This is a common joke between IT support technicians but it shows that all the safety mechanisms won´t help you if aren´t careful enough.

    • While surfing the internet, don´t click on anything you don´t know. In the worst case, it infects your system with malware.
    • Watch your step in social networks! Many cyber criminals use them to spread malware, mine personal pata (to be sold to advertising companies, for example) or simply do damage to other users. Even if a received hyperlink within a message seems to be coming from one of your friends, have a closer look. In addition, don´t click everything.
    • When installing software, have a look to each of the setup windows and uncheck any additional toolbars or free programs that may be offered additionally. Most of today´s setup procedures contain potentially unwanted programs so keep them off your system.
    • Avoid gaming sites, pirated software, cracking tools, keygens, and peer-to-peer (P2P) file sharing programs.
      They are a security risk which can make your computer susceptible to a wide variety of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites.



Link to post
Share on other sites

  • Root Admin

Glad we could help. :)

If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.