Jump to content

Infected with nearly 7000 items, all Trojan.FakeMS.ED


Recommended Posts

Hello,

 

So I did a full scan today and the results showed that I'm infected with nearly 7000 items of Trojan.FakeMS.ED. Normally I would just quarantine it but the number of items has me quite worried so I wanted to ask the advice of some experts. Appreciate the help, thank you.

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 26-07-2014
Ran by Megan (administrator) on MEGAN-PC on 26-07-2014 18:39:46
Running from C:\Users\Megan\Desktop
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal
 
The only official download link for FRST:
Download link from any site other than Bleeping Computer is unpermitted or outdated.
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe
(Alipay Inc. ) C:\Program Files (x86)\alipay\alieditplus\AlipaySecSvc.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
() C:\Program Files (x86)\Microsoft Device Health\DhMachineSvc.exe
(阿里巴巴(中国)有限公司) C:\Program Files (x86)\alipay\SafeTransaction\TaobaoProtect.exe
(Alipay Inc. ) C:\Program Files (x86)\alipay\SafeTransaction\Alipaybsm.exe
(Juniper Networks) C:\Program Files (x86)\Juniper Networks\Common Files\dsNcService.exe
(Interactive Intelligence, Inc.) C:\Program Files (x86)\Interactive Intelligence\ININ Trace Initialization\i3trace_initializer-w32r-1-1.exe
(Box, Inc.) C:\Program Files\Box\Box Sync\BoxSync.exe
(SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_IATIHAA.EXE
(Plex, Inc.) C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe
(Dropbox, Inc.) C:\Users\Megan\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
(Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Box, Inc.) C:\Program Files\Box\Box Sync\BoxSync.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Python Software Foundation) C:\Program Files (x86)\Plex\Plex Media Server\PlexScriptHost.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation) C:\Windows\System32\igfxTray.exe
(Plex, Inc.) C:\Program Files (x86)\Plex\Plex Media Server\PlexDlnaServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\Program Files\Box\Box Sync\BoxSyncMonitor.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [boxSync] => c:\Program Files\Box\Box Sync\BoxSync.exe [13606960 2014-07-17] (Box, Inc.)
HKLM-x32\...\Run: [iMSS] => C:\Program Files (x86)\Intel\Intel® Management Engine Components\IMSS\PIconStartup.exe [133400 2011-12-16] (Intel Corporation)
HKLM-x32\...\Run: [uSB3MON] => C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-27] (Intel Corporation)
HKLM-x32\...\Run: [iAStorIcon] => C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [284440 2012-02-01] (Intel Corporation)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [40312 2014-05-08] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AVP] => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356128 2013-10-09] (Kaspersky Lab ZAO)
HKLM-x32\...\Run: [sunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-11] (Oracle Corporation)
Winlogon\Notify\igfxcui: igfxdev.dll [X]
HKU\S-1-5-19\...\RunOnce: [mctadmin] => C:\Windows\System32\mctadmin.exe [97280 2009-07-13] (Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [mctadmin] => C:\Windows\System32\mctadmin.exe [97280 2009-07-13] (Microsoft Corporation)
HKU\S-1-5-21-4175754119-1806728938-4148705958-1000\...\Run: [EPSON0B67E1 (Epson Stylus NX330)] => C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIHAA.EXE [232448 2011-01-20] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-4175754119-1806728938-4148705958-1000\...\Run: [OutfoxTV] => C:\Program Files\OutfoxTV\OutfoxTV\DesktopContainer.exe 
HKU\S-1-5-21-4175754119-1806728938-4148705958-1000\...\Run: [Plex Media Server] => C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe [4419720 2014-04-09] (Plex, Inc.)
HKU\S-1-5-21-4175754119-1806728938-4148705958-1000\...\MountPoints2: {ad16054c-c3b3-11e2-a5eb-806e6f6e6963} - E:\SISetup.exe
Startup: C:\Users\Megan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Megan\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
ShellIconOverlayIdentifiers:  SkyDrivePro1 (ErrorConflict) -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers:  SkyDrivePro2 (SyncInProgress) -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers:  SkyDrivePro3 (InSync) -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers: 0000BoxSyncFileLocked -> {1b9c95e1-ce36-3737-81c8-1ec9807f03c1} => C:\Windows\system32\mscoree.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers: 0000BoxSyncNotSynced -> {e22ccf16-2db6-3de8-9a2c-acb66b571b69} => C:\Windows\system32\mscoree.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers: 0000BoxSyncProblem -> {84878798-e5c4-3e6b-b7c4-b51c4ac4e7dc} => C:\Windows\system32\mscoree.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers: 0000BoxSyncSynced -> {01fcd170-7f0a-3b6a-b992-66a7a20289b5} => C:\Windows\system32\mscoree.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers: 115ErrorOverlayIcon -> {361F6990-0582-4B1B-88D1-294640A2AB65} => C:\Program Files (x86)\115\115com\Shell_x64.dll (广东一一五科技有限公司)
ShellIconOverlayIdentifiers: 115ProcessOverlayIcon -> {52F2EEDF-65F7-4685-8C30-10F56E1080E6} => C:\Program Files (x86)\115\115com\Shell_x64.dll (广东一一五科技有限公司)
ShellIconOverlayIdentifiers: 115SucceedOverlayIcon -> {E6DDA755-8C6C-4D06-8765-FEA0DC7F2660} => C:\Program Files (x86)\115\115com\Shell_x64.dll (广东一一五科技有限公司)
ShellIconOverlayIdentifiers: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Megan\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Megan\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Megan\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: DropboxExt4 -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Megan\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: GDriveBlacklistedOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
ShellIconOverlayIdentifiers: GDriveSharedEditOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
ShellIconOverlayIdentifiers: GDriveSharedOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
ShellIconOverlayIdentifiers: GDriveSharedViewOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
ShellIconOverlayIdentifiers: GDriveSyncedOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
ShellIconOverlayIdentifiers: GDriveSyncingOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
ShellIconOverlayIdentifiers-x32: AAADesktopTips -> {4562B511-62E9-4533-B7B2-56A8BB10B482} => C:\Users\Public\Thunder Network\KanKan\reghelper\xappex.1.1.1.73.(966).dll (深圳市迅雷网络技术有限公司)
ShellIconOverlayIdentifiers-x32: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Megan\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Megan\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Megan\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll (Dropbox, Inc.)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.le123.com/hao123.html
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = 
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.le123.com/hao123.html
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.le123.com/hao123.html
SearchScopes: HKLM - DefaultScope {11D3EB5F-D814-48A3-8785-7A4433455F45} URL = http://www.bing.com/search?q={searchTerms}&form=IE9TR&src=IE9TR&pc=MDDSJS
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM - {11D3EB5F-D814-48A3-8785-7A4433455F45} URL = http://www.bing.com/search?q={searchTerms}&form=IE9TR&src=IE9TR&pc=MDDSJS
SearchScopes: HKLM-x32 - DefaultScope {11D3EB5F-D814-48A3-8785-7A4433455F45} URL = http://www.bing.com/search?q={searchTerms}&form=IE9TR&src=IE9TR&pc=MDDSJS
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 - {11D3EB5F-D814-48A3-8785-7A4433455F45} URL = http://www.bing.com/search?q={searchTerms}&form=IE9TR&src=IE9TR&pc=MDDSJS
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKCU - {11D3EB5F-D814-48A3-8785-7A4433455F45} URL = 
BHO: 迅雷下载支持 -> {004B0726-A010-4ABF-8556-FCDB7F1FCA1E} -> C:\Program Files (x86)\Thunder Network\Thunder\BHO\XunleiBHO647.9.8.4550.dll (深圳市迅雷网络技术有限公司)
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
BHO-x32: FGCatchUrl -> {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} -> C:\Program Files (x86)\FlashGet\jccatch.dll (www.flashget.com)
BHO-x32: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: 迅雷下载支持 -> {889D2FEB-5411-4565-8998-1DD2C5261283} -> C:\Program Files (x86)\Thunder Network\Thunder\BHO\XunleiBHO7.9.8.4550.dll (深圳市迅雷网络技术有限公司)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
BHO-x32: FlashGet GetFlash Class -> {F156768E-81EF-470C-9057-481BA8380DBA} -> C:\Program Files (x86)\FlashGet\getflash.dll (www.flashget.com)
Toolbar: HKLM-x32 - No Name - {E0E899AB-F487-11D5-8D29-0050BA6940E3} -  No File
DPF: HKLM-x32 {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://vpn.pizzapizza.ca/dana-cached/sc/JuniperSetupClient.cab
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\..\Interfaces\{ED01D376-507A-4096-94D5-8993B8ABD777}: [NameServer]198.27.106.150,208.110.81.51
 
FireFox:
========
FF ProfilePath: C:\Users\Megan\AppData\Roaming\Mozilla\Firefox\Profiles\n2xg92nq.default-1395432669716
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll ()
FF Plugin: @alipay.com/npAliSecCtrl - C:\Windows\SysWOW64\aliedit\3.8.0.0\npAliSecCtrl64.dll (Alipay.com Inc. )
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @115.com/CheckPluginEx - C:\Program Files (x86)\115\115com\np_115download_plugin.dll (115.COM Inc.)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin-x32: @alipay.com/npalidcp - C:\Windows\system32\aliedit\3.8.0.0\npalidcp.dll No File
FF Plugin-x32: @alipay.com/npaliedit - C:\Windows\system32\aliedit\3.8.0.0\npaliedit.dll No File
FF Plugin-x32: @alipay.com/npAliSecCtrl - C:\Windows\system32\aliedit\3.8.0.0\npAliSecCtrl.dll No File
FF Plugin-x32: @baidu.com/YunWebDetectPlugin - C:\Users\Megan\AppData\Roaming\baidu\BaiduYunGuanjia\npYunWebDetect.dll (Baidu.com, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.65.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.65.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @qq.com/QQPhotoDrawEx - C:\Program Files (x86)\Tencent\Qzone\Ver_247.312\npQQPhotoDrawEx.dll ()
FF Plugin-x32: @qq.com/QzoneMusic - C:\Program Files (x86)\Tencent\QQMusic\QzoneMusic\npQzoneMusic.dll (Tencent)
FF Plugin-x32: @qq.com/TXSSO - C:\Program Files (x86)\Common Files\Tencent\TXSSO\1.2.2.23\Bin\npSSOAxCtrlForPTLogin.dll (Tencent)
FF Plugin-x32: @tencent.com/npQQMailWebKit,version=1.0.0.1 - C:\Program Files (x86)\QQMailPlugin\npQQMailWebKit.dll (Tencent)
FF Plugin-x32: @tencent.com/nptxftnWebKit,version=1.0.0.1 - C:\Program Files (x86)\QQMailPlugin\nptxftnWebKit.dll (Tencent Technology (Shenzhen) Company Limited)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll No File
FF Plugin-x32: @videolan.org/vlc,version=2.1.1 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll No File
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll No File
FF Plugin-x32: @xunlei.com/npaplayer - C:\Users\Public\Thunder Network\APlayer\codecs\npaplayer.dll No File
FF Plugin-x32: @xunlei.com/npxluser - C:\Program Files (x86)\Common Files\Thunder Network\UserAgent\npxluser1.0.2.2.dll (Thunder Networking Technologies,LTD)
FF Plugin-x32: @xunlei.com/npxunlei;version=1.0.0.2 - C:\Program Files (x86)\Thunder Network\Thunder\Data\npxunlei1.0.0.2.dll ( )
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @alipay.com/npalicert - C:\Users\Megan\AppData\Roaming\alipay\cf\npalicdo.dll (alipay.com)
FF Plugin HKCU: @xunlei.com/npxluser - C:\Program Files (x86)\Common Files\Thunder Network\UserAgent\npxluser1.0.2.2.dll (Thunder Networking Technologies,LTD)
FF Plugin HKCU: @xunlei.com/npxunlei;version=1.0.0.2 - C:\Program Files (x86)\Thunder Network\Thunder\Data\npxunlei1.0.0.2.dll ( )
FF Plugin HKCU: wacom.com/WacomTabletPlugin - C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll No File
FF HKLM-x32\...\Firefox\Extensions: [url_advisor@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com
FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com [2013-05-23]
FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com
FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com [2013-05-23]
FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com
FF Extension: Dangerous Websites Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com [2013-05-23]
FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com
FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com [2013-05-23]
FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com
FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com [2013-05-23]
FF HKCU\...\Firefox\Extensions: [{1B33E42F-EF14-4cd3-B6DC-174571C4349C}] - C:\Program Files (x86)\Thunder Network\Thunder\BHO\Firefox
FF Extension: Thunder Extension - C:\Program Files (x86)\Thunder Network\Thunder\BHO\Firefox [2013-11-19]
 
Chrome: 
=======
CHR HomePage: hxxp://google.ca/
CHR StartupUrls: "hxxp://search.swagbucks.com/"
CHR DefaultSearchKeyword: google.com__
CHR DefaultNewTabURL: 
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll No File
CHR Plugin: (Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Extension: (Google Docs) - C:\Users\Megan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-05-22]
CHR Extension: (Google Drive) - C:\Users\Megan\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-05-22]
CHR Extension: (YouTube) - C:\Users\Megan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-05-22]
CHR Extension: (Google Search) - C:\Users\Megan\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-05-22]
CHR Extension: (Kaspersky URL Advisor) - C:\Users\Megan\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj [2013-05-23]
CHR Extension: (AdBlock) - C:\Users\Megan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2013-05-23]
CHR Extension: (Swagbucks Extension) - C:\Users\Megan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gngocbkfmikdgphklgmmehbjjlfgdemm [2014-02-21]
CHR Extension: (avast! Online Security) - C:\Users\Megan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-02-27]
CHR Extension: (Safe Money) - C:\Users\Megan\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh [2013-05-23]
CHR Extension: (Virtual Keyboard) - C:\Users\Megan\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh [2013-05-23]
CHR Extension: (Kaspersky Protection) - C:\Users\Megan\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpoimibckejjdjcfbdnajaicnklhfplh [2014-05-19]
CHR Extension: (Google Wallet) - C:\Users\Megan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-21]
CHR Extension: (Unblock Youku) - C:\Users\Megan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdnfnkhpgegpcingjbfihlkjeighnddk [2013-12-26]
CHR Extension: (Gmail) - C:\Users\Megan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-05-22]
CHR Extension: (Anti-Banner) - C:\Users\Megan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman [2013-05-23]
CHR HKCU\...\Chrome\Extension: [apjkpjchfbckhjhokinlgdbmibpbbjak] - C:\Users\Megan\AppData\Local\CRE\apjkpjchfbckhjhokinlgdbmibpbbjak.crx [2013-05-23]
CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\urladvisor.crx [2012-10-25]
CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\online_banking_chrome.crx [2012-10-25]
CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\content_blocker_chrome.crx [2012-10-25]
CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\virtkbd.crx [2012-10-25]
CHR HKLM-x32\...\Chrome\Extension: [lpoimibckejjdjcfbdnajaicnklhfplh] - https://chrome.google.com/webstore/detail/lpoimibckejjdjcfbdnajaicnklhfplh [2012-10-25]
CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\ab.crx [2012-10-25]
 
==================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AlipaySecSvc; C:\Program Files (x86)\alipay\alieditplus\AlipaySecSvc.exe [540032 2014-06-04] (Alipay Inc. )
R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356128 2013-10-09] (Kaspersky Lab ZAO)
S3 BoxSyncUpdateService; C:\Program Files\Box\Box Sync\SyncUpdaterService.exe [22016 2014-01-13] (Box Inc.) [File not signed]
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2356408 2014-06-19] (Microsoft Corporation)
R2 DeviceHealth; C:\Program Files (x86)\Microsoft Device Health\DhMachineSvc.exe [85664 2014-06-06] ()
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [314696 2014-05-21] (Intel Corporation)
R2 ININ Tracing; C:\Program Files (x86)\Interactive Intelligence\ININ Trace Initialization\i3trace_initializer-w32r-1-1.exe [36352 2010-10-26] (Interactive Intelligence, Inc.) [File not signed]
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 XLServicePlatform; C:\Program Files (x86)\Common Files\Thunder Network\ServicePlatform\XLSP.dll [174024 2013-11-19] (ShenZhen Xunlei Networking Technologies,LTD)
S3 AeLookupSvc; %SystemRoot%\System32\aelupsvc.dll [X]
S2 OutfoxTvService; C:\Program Files\OutfoxTV\OutfoxTvService.exe [X]
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2013-12-10] (Kaspersky Lab ZAO)
U5 klflt; C:\Windows\System32\Drivers\klflt.sys [91008 2014-05-19] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [628320 2014-05-19] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29792 2013-12-10] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29280 2013-10-09] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-10-09] (Kaspersky Lab ZAO)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [54368 2013-06-20] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178448 2013-05-23] (Kaspersky Lab ZAO)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-07-26] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation)
S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-13] (Brother Industries Ltd.)
S3 athr; system32\DRIVERS\athrx.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
==================== One Month Created Files and Folders ========
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2014-07-26 18:39 - 2014-07-26 18:40 - 00030944 _____ () C:\Users\Megan\Desktop\FRST.txt
2014-07-26 18:39 - 2014-07-26 18:39 - 00000000 ____D () C:\FRST
2014-07-26 18:38 - 2014-07-26 18:38 - 02093568 _____ (Farbar) C:\Users\Megan\Desktop\FRST64.exe
2014-07-26 18:37 - 2014-07-26 18:37 - 00839506 _____ () C:\Users\Megan\Desktop\Scan0726.txt
2014-07-26 17:09 - 2014-07-26 17:26 - 367229820 _____ () C:\Users\Megan\Desktop\[bbs.xskwhd.com]真爱遇到他23.540P-新时空家园.mkv
2014-07-26 17:09 - 2014-07-26 17:14 - 00000000 ____D () C:\Users\Megan\Desktop\真爱遇到他
2014-07-26 17:07 - 2014-07-26 17:21 - 366901440 _____ () C:\Users\Megan\Desktop\[bbs.xskwhd.com]真爱遇到他22.540P-新时空家园.mkv
2014-07-26 17:06 - 2014-07-26 17:32 - 367112086 _____ () C:\Users\Megan\Desktop\[bbs.xskwhd.com]真爱遇到他24.540P-新时空家园.mkv
2014-07-26 17:05 - 2014-07-26 17:25 - 367181853 _____ () C:\Users\Megan\Desktop\[bbs.xskwhd.com]真爱遇到他03.540P-新时空家园.mkv
2014-07-22 18:59 - 2014-07-22 18:59 - 00000000 ____D () C:\Users\Megan\Desktop\Split Second
2014-07-22 13:25 - 2014-07-22 13:25 - 00004460 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_65-b20.log
2014-07-22 13:25 - 2014-07-22 13:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-07-22 13:25 - 2014-07-11 03:02 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-07-22 13:25 - 2014-07-11 02:56 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-07-22 13:25 - 2014-07-11 02:56 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-07-22 13:25 - 2014-07-11 02:55 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-07-15 09:12 - 2014-07-15 09:12 - 00000000 ____D () C:\Program Files (x86)\Box
2014-07-14 12:33 - 2014-07-25 18:19 - 00000000 ____D () C:\Users\Megan\Desktop\MDWAV
2014-07-14 09:05 - 2014-07-15 08:59 - 00000000 ____D () C:\Users\Megan\AppData\Local\LogMeIn Rescue Applet
2014-07-10 07:15 - 2014-06-29 22:09 - 00519168 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-07-10 07:15 - 2014-06-29 22:04 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-07-10 07:15 - 2014-06-20 16:14 - 00266424 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-07-10 07:15 - 2014-06-20 15:39 - 00240824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-07-10 07:15 - 2014-06-18 21:39 - 23464448 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-07-10 07:15 - 2014-06-18 21:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-07-10 07:15 - 2014-06-18 21:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-07-10 07:15 - 2014-06-18 20:48 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-07-10 07:15 - 2014-06-18 20:42 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-07-10 07:15 - 2014-06-18 20:42 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-07-10 07:15 - 2014-06-18 20:41 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-07-10 07:15 - 2014-06-18 20:41 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-07-10 07:15 - 2014-06-18 20:32 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-07-10 07:15 - 2014-06-18 20:31 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-07-10 07:15 - 2014-06-18 20:26 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-07-10 07:15 - 2014-06-18 20:24 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-07-10 07:15 - 2014-06-18 20:24 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-07-10 07:15 - 2014-06-18 20:23 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-07-10 07:15 - 2014-06-18 20:16 - 17276416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-07-10 07:15 - 2014-06-18 20:14 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-07-10 07:15 - 2014-06-18 20:09 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-07-10 07:15 - 2014-06-18 19:59 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-07-10 07:15 - 2014-06-18 19:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-07-10 07:15 - 2014-06-18 19:53 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-07-10 07:15 - 2014-06-18 19:51 - 05721088 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-07-10 07:15 - 2014-06-18 19:50 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-07-10 07:15 - 2014-06-18 19:48 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-07-10 07:15 - 2014-06-18 19:39 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-07-10 07:15 - 2014-06-18 19:38 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-07-10 07:15 - 2014-06-18 19:37 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-07-10 07:15 - 2014-06-18 19:36 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-07-10 07:15 - 2014-06-18 19:35 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-07-10 07:15 - 2014-06-18 19:33 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-07-10 07:15 - 2014-06-18 19:32 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-07-10 07:15 - 2014-06-18 19:28 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-07-10 07:15 - 2014-06-18 19:28 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-07-10 07:15 - 2014-06-18 19:27 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-07-10 07:15 - 2014-06-18 19:27 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-07-10 07:15 - 2014-06-18 19:25 - 00442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-07-10 07:15 - 2014-06-18 19:23 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-07-10 07:15 - 2014-06-18 19:22 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-07-10 07:15 - 2014-06-18 19:12 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-07-10 07:15 - 2014-06-18 19:06 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-07-10 07:15 - 2014-06-18 19:01 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-07-10 07:15 - 2014-06-18 18:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-07-10 07:15 - 2014-06-18 18:58 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-07-10 07:15 - 2014-06-18 18:58 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-07-10 07:15 - 2014-06-18 18:52 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-07-10 07:15 - 2014-06-18 18:51 - 13527040 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-07-10 07:15 - 2014-06-18 18:49 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-07-10 07:15 - 2014-06-18 18:46 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-07-10 07:15 - 2014-06-18 18:45 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-07-10 07:15 - 2014-06-18 18:35 - 11742208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-07-10 07:15 - 2014-06-18 18:34 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-07-10 07:15 - 2014-06-18 18:15 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-07-10 07:15 - 2014-06-18 18:13 - 01791488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-07-10 07:15 - 2014-06-18 18:09 - 01139200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-07-10 07:15 - 2014-06-18 18:07 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-07-10 07:15 - 2014-06-17 22:18 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-07-10 07:15 - 2014-06-17 21:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe
2014-07-10 07:15 - 2014-06-17 21:10 - 03157504 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-07-10 07:15 - 2014-06-06 06:10 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-07-10 07:15 - 2014-06-06 05:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-07-10 07:15 - 2014-06-05 10:45 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-07-10 07:15 - 2014-06-05 10:26 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-07-10 07:15 - 2014-06-05 10:25 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-07-10 07:15 - 2014-05-30 04:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-07-10 07:15 - 2014-05-30 04:08 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-07-10 07:15 - 2014-05-30 04:08 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-07-10 07:15 - 2014-05-30 04:08 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-07-10 07:15 - 2014-05-30 04:08 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-07-10 07:15 - 2014-05-30 04:08 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-07-10 07:15 - 2014-05-30 04:08 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-07-10 07:15 - 2014-05-30 03:52 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-07-10 07:15 - 2014-05-30 03:52 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-07-10 07:15 - 2014-05-30 03:52 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-07-10 07:15 - 2014-05-30 03:52 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2014-07-10 07:15 - 2014-05-30 03:52 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-07-10 07:15 - 2014-05-30 03:52 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-07-10 07:15 - 2014-05-30 03:52 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-07-10 07:15 - 2014-05-30 02:45 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-07-09 08:39 - 2014-07-09 08:39 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\615E4A12.sys
2014-07-08 10:18 - 2014-07-10 18:45 - 00000000 ____D () C:\Users\Megan\Desktop\恋恋不忘
2014-07-07 12:32 - 2014-07-07 12:32 - 00000000 ____D () C:\Users\Megan\AppData\Local\Adobe
2014-07-06 17:40 - 2014-07-06 17:40 - 2016985909 _____ () C:\Users\Megan\Desktop\title00.mkv
2014-07-06 08:57 - 2014-07-06 08:58 - 2828652577 _____ () C:\Users\Megan\Desktop\D92.mkv
2014-07-06 08:56 - 2014-07-06 09:00 - 14407386 _____ () C:\Users\Megan\Desktop\D1.mkv
2014-07-06 08:56 - 2014-07-06 08:57 - 1703187375 _____ () C:\Users\Megan\Desktop\D9.mkv
2014-07-06 08:53 - 2014-07-06 08:56 - 215376906 _____ () C:\Users\Megan\Desktop\D8.mkv
2014-07-06 08:50 - 2014-07-06 08:53 - 4193130039 _____ () C:\Users\Megan\Desktop\D7.mkv
2014-07-05 21:38 - 2014-07-05 21:39 - 4065605302 _____ () C:\Users\Megan\Desktop\D6.mkv
2014-07-05 20:38 - 2014-07-05 20:40 - 4278199714 _____ () C:\Users\Megan\Desktop\D5.mkv
2014-07-05 19:54 - 2014-07-05 19:55 - 4272433246 _____ () C:\Users\Megan\Desktop\D4.mkv
2014-07-05 19:51 - 2014-07-05 19:53 - 4143195186 _____ () C:\Users\Megan\Desktop\D2.mkv
2014-07-05 19:45 - 2014-07-05 19:51 - 161131043 _____ () C:\Users\Megan\Desktop\D3.mkv
2014-07-05 19:45 - 2014-07-05 19:47 - 105358587 _____ () C:\Users\Megan\Desktop\D10.mkv
2014-07-05 19:43 - 2014-07-05 19:52 - 1199253811 _____ () C:\Users\Megan\Desktop\02.mkv
2014-07-05 19:32 - 2014-07-05 19:41 - 1290297654 _____ () C:\Users\Megan\Desktop\01.mkv
2014-07-05 14:46 - 2014-07-06 02:14 - 00000000 ____D () C:\Users\Megan\Desktop\[115][国产剧集][命中注定我爱你]陈乔恩-阮经天国语中字[10碟全DVD5原盘ISO]
2014-07-05 09:37 - 2014-07-05 09:37 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\1DB14667.sys
2014-07-03 15:56 - 2014-07-03 15:57 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-07-03 14:30 - 2014-07-14 10:15 - 00000000 ____D () C:\Users\Megan\Desktop\缘份无边界(雾中楼星河-新)
2014-06-30 08:08 - 2014-07-26 11:16 - 00000000 ____D () C:\Users\Megan\AppData\Roaming\TaobaoProtect
2014-06-30 08:07 - 2014-07-26 18:34 - 00000340 _____ () C:\Windows\Tasks\微软设备健康助手自动更新.job
2014-06-30 08:07 - 2014-06-30 08:07 - 00003286 _____ () C:\Windows\System32\Tasks\微软设备健康助手自动更新
2014-06-30 08:07 - 2014-06-30 08:07 - 00000000 ____D () C:\Program Files (x86)\Microsoft Device Health
2014-06-30 07:56 - 2014-06-30 07:56 - 00000000 ____D () C:\Users\Megan\AppData\Roaming\alipay
2014-06-26 19:54 - 2014-06-26 19:54 - 00000000 ___HD () C:\Users\Megan\.boxsync
2014-06-26 18:35 - 2014-06-26 19:44 - 00000000 ____D () C:\Users\Megan\Desktop\New folder (2)
 
==================== One Month Modified Files and Folders =======
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2014-07-26 18:40 - 2014-07-26 18:39 - 00030944 _____ () C:\Users\Megan\Desktop\FRST.txt
2014-07-26 18:39 - 2014-07-26 18:39 - 00000000 ____D () C:\FRST
2014-07-26 18:38 - 2014-07-26 18:38 - 02093568 _____ (Farbar) C:\Users\Megan\Desktop\FRST64.exe
2014-07-26 18:37 - 2014-07-26 18:37 - 00839506 _____ () C:\Users\Megan\Desktop\Scan0726.txt
2014-07-26 18:37 - 2014-01-17 13:16 - 00000000 ____D () C:\Users\Megan\AppData\Local\Box Sync
2014-07-26 18:34 - 2014-06-30 08:07 - 00000340 _____ () C:\Windows\Tasks\微软设备健康助手自动更新.job
2014-07-26 18:15 - 2013-05-14 17:41 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-07-26 18:08 - 2014-04-13 20:06 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-26 17:57 - 2013-05-22 13:06 - 00000896 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-07-26 17:32 - 2014-07-26 17:06 - 367112086 _____ () C:\Users\Megan\Desktop\[bbs.xskwhd.com]真爱遇到他24.540P-新时空家园.mkv
2014-07-26 17:26 - 2014-07-26 17:09 - 367229820 _____ () C:\Users\Megan\Desktop\[bbs.xskwhd.com]真爱遇到他23.540P-新时空家园.mkv
2014-07-26 17:25 - 2014-07-26 17:05 - 367181853 _____ () C:\Users\Megan\Desktop\[bbs.xskwhd.com]真爱遇到他03.540P-新时空家园.mkv
2014-07-26 17:21 - 2014-07-26 17:07 - 366901440 _____ () C:\Users\Megan\Desktop\[bbs.xskwhd.com]真爱遇到他22.540P-新时空家园.mkv
2014-07-26 17:14 - 2014-07-26 17:09 - 00000000 ____D () C:\Users\Megan\Desktop\真爱遇到他
2014-07-26 17:03 - 2013-05-23 13:48 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-07-26 15:46 - 2013-05-14 17:40 - 02036771 _____ () C:\Windows\WindowsUpdate.log
2014-07-26 11:16 - 2014-06-30 08:08 - 00000000 ____D () C:\Users\Megan\AppData\Roaming\TaobaoProtect
2014-07-26 10:24 - 2013-05-23 15:36 - 00000000 ___RD () C:\Users\Megan\Dropbox
2014-07-26 10:24 - 2013-05-23 15:35 - 00000000 ____D () C:\Users\Megan\AppData\Roaming\Dropbox
2014-07-26 10:22 - 2009-07-14 00:45 - 00021312 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-26 10:22 - 2009-07-14 00:45 - 00021312 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-26 10:21 - 2013-11-07 12:31 - 00000000 ____D () C:\Users\Megan\AppData\Roaming\uTorrent
2014-07-26 10:14 - 2014-02-12 11:10 - 00000000 ____D () C:\ProgramData\boost_interprocess
2014-07-26 10:14 - 2013-05-23 21:17 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-07-26 10:14 - 2013-05-23 21:17 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-07-26 10:14 - 2013-05-22 13:06 - 00000892 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-07-26 10:14 - 2009-07-14 01:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-26 10:14 - 2009-07-14 00:51 - 00082366 _____ () C:\Windows\setupact.log
2014-07-25 18:19 - 2014-07-14 12:33 - 00000000 ____D () C:\Users\Megan\Desktop\MDWAV
2014-07-25 15:41 - 2014-02-24 11:49 - 00000000 ____D () C:\Users\Megan\AppData\Local\alipay
2014-07-24 22:19 - 2013-05-23 10:44 - 00000000 ____D () C:\Users\Megan\AppData\Local\Deployment
2014-07-24 14:20 - 2013-05-23 21:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-07-24 07:31 - 2013-05-23 15:36 - 00001021 _____ () C:\Users\Megan\Desktop\Dropbox.lnk
2014-07-24 07:31 - 2013-05-23 15:35 - 00000000 ____D () C:\Users\Megan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-07-23 11:47 - 2013-11-07 12:31 - 00000855 _____ () C:\Users\Megan\Desktop\µTorrent.lnk
2014-07-23 11:47 - 2013-11-07 12:31 - 00000835 _____ () C:\Users\Megan\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2014-07-22 18:59 - 2014-07-22 18:59 - 00000000 ____D () C:\Users\Megan\Desktop\Split Second
2014-07-22 15:45 - 2014-01-17 13:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Box Sync
2014-07-22 14:00 - 2013-05-22 13:06 - 00002185 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-07-22 13:25 - 2014-07-22 13:25 - 00004460 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_65-b20.log
2014-07-22 13:25 - 2014-07-22 13:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-07-22 13:25 - 2014-01-10 22:25 - 00000000 ____D () C:\ProgramData\Oracle
2014-07-22 13:25 - 2014-01-10 22:24 - 00000000 ____D () C:\Program Files (x86)\Java
2014-07-15 09:13 - 2014-01-17 13:16 - 00000000 ____D () C:\Users\Megan\Box Sync
2014-07-15 09:12 - 2014-07-15 09:12 - 00000000 ____D () C:\Program Files (x86)\Box
2014-07-15 09:12 - 2014-01-17 13:24 - 00000000 ____D () C:\Users\Megan\AppData\Roaming\Box
2014-07-15 08:59 - 2014-07-14 09:05 - 00000000 ____D () C:\Users\Megan\AppData\Local\LogMeIn Rescue Applet
2014-07-15 08:59 - 2010-11-20 23:47 - 00400468 _____ () C:\Windows\PFRO.log
2014-07-14 13:39 - 2009-07-14 01:13 - 00798066 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-07-14 13:32 - 2013-10-04 11:54 - 00000000 ____D () C:\Users\Megan\Desktop\115 DiscRobot
2014-07-14 10:30 - 2014-06-01 09:39 - 00000000 ____D () C:\Users\Megan\Desktop\Colorful Life - 錦繡良緣
2014-07-14 10:15 - 2014-07-03 14:30 - 00000000 ____D () C:\Users\Megan\Desktop\缘份无边界(雾中楼星河-新)
2014-07-11 16:40 - 2014-05-11 19:21 - 00000000 ____D () C:\Users\Megan\AppData\Roaming\HandBrake
2014-07-11 14:17 - 2014-04-18 12:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC-HC x64
2014-07-11 14:17 - 2014-04-18 12:19 - 00000000 ____D () C:\Program Files\MPC-HC
2014-07-11 11:12 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\rescache
2014-07-11 03:02 - 2014-07-22 13:25 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-07-11 02:56 - 2014-07-22 13:25 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-07-11 02:56 - 2014-07-22 13:25 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-07-11 02:55 - 2014-07-22 13:25 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-07-10 19:27 - 2009-07-14 00:45 - 00445416 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-07-10 19:25 - 2014-05-06 11:27 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-07-10 19:25 - 2010-11-21 03:17 - 00000000 ____D () C:\Program Files\Windows Journal
2014-07-10 19:25 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2014-07-10 19:25 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\system32\Dism
2014-07-10 19:20 - 2013-07-12 17:06 - 00000000 ____D () C:\Windows\system32\MRT
2014-07-10 19:19 - 2013-05-23 17:19 - 96441528 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-07-10 18:45 - 2014-07-08 10:18 - 00000000 ____D () C:\Users\Megan\Desktop\恋恋不忘
2014-07-10 07:25 - 2013-08-19 19:47 - 00000000 ____D () C:\Program Files\Microsoft Office 15
2014-07-09 08:39 - 2014-07-09 08:39 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\615E4A12.sys
2014-07-08 17:58 - 2013-05-23 15:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2014-07-08 14:13 - 2013-05-14 17:41 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-07-08 14:13 - 2013-05-14 17:41 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-07-08 14:13 - 2013-05-14 17:41 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-07-08 10:16 - 2013-11-19 21:50 - 00000000 ___SD () C:\kankan
2014-07-07 12:32 - 2014-07-07 12:32 - 00000000 ____D () C:\Users\Megan\AppData\Local\Adobe
2014-07-06 17:40 - 2014-07-06 17:40 - 2016985909 _____ () C:\Users\Megan\Desktop\title00.mkv
2014-07-06 09:00 - 2014-07-06 08:56 - 14407386 _____ () C:\Users\Megan\Desktop\D1.mkv
2014-07-06 08:58 - 2014-07-06 08:57 - 2828652577 _____ () C:\Users\Megan\Desktop\D92.mkv
2014-07-06 08:57 - 2014-07-06 08:56 - 1703187375 _____ () C:\Users\Megan\Desktop\D9.mkv
2014-07-06 08:56 - 2014-07-06 08:53 - 215376906 _____ () C:\Users\Megan\Desktop\D8.mkv
2014-07-06 08:53 - 2014-07-06 08:50 - 4193130039 _____ () C:\Users\Megan\Desktop\D7.mkv
2014-07-06 02:14 - 2014-07-05 14:46 - 00000000 ____D () C:\Users\Megan\Desktop\[115][国产剧集][命中注定我爱你]陈乔恩-阮经天国语中字[10碟全DVD5原盘ISO]
2014-07-05 21:39 - 2014-07-05 21:38 - 4065605302 _____ () C:\Users\Megan\Desktop\D6.mkv
2014-07-05 20:40 - 2014-07-05 20:38 - 4278199714 _____ () C:\Users\Megan\Desktop\D5.mkv
2014-07-05 19:55 - 2014-07-05 19:54 - 4272433246 _____ () C:\Users\Megan\Desktop\D4.mkv
2014-07-05 19:53 - 2014-07-05 19:51 - 4143195186 _____ () C:\Users\Megan\Desktop\D2.mkv
2014-07-05 19:52 - 2014-07-05 19:43 - 1199253811 _____ () C:\Users\Megan\Desktop\02.mkv
2014-07-05 19:51 - 2014-07-05 19:45 - 161131043 _____ () C:\Users\Megan\Desktop\D3.mkv
2014-07-05 19:47 - 2014-07-05 19:45 - 105358587 _____ () C:\Users\Megan\Desktop\D10.mkv
2014-07-05 19:41 - 2014-07-05 19:32 - 1290297654 _____ () C:\Users\Megan\Desktop\01.mkv
2014-07-05 09:37 - 2014-07-05 09:37 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\1DB14667.sys
2014-07-04 12:04 - 2013-05-23 10:45 - 01419388 _____ () C:\Users\Megan\AppData\PizCICNet.log
2014-07-04 08:06 - 2013-05-22 12:54 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-07-03 15:57 - 2014-07-03 15:56 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-30 08:07 - 2014-06-30 08:07 - 00003286 _____ () C:\Windows\System32\Tasks\微软设备健康助手自动更新
2014-06-30 08:07 - 2014-06-30 08:07 - 00000000 ____D () C:\Program Files (x86)\Microsoft Device Health
2014-06-30 07:56 - 2014-06-30 07:56 - 00000000 ____D () C:\Users\Megan\AppData\Roaming\alipay
2014-06-29 22:09 - 2014-07-10 07:15 - 00519168 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-29 22:04 - 2014-07-10 07:15 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-06-28 11:08 - 2014-01-02 13:14 - 00000000 ____D () C:\Users\Megan\Desktop\A Kindred Spirit - 真情
2014-06-27 10:25 - 2013-05-27 10:23 - 00001078 _____ () C:\Users\Megan\AppData\Roaming\base64.cer
2014-06-27 10:25 - 2013-05-27 10:23 - 00000000 ____D () C:\Windows\SysWOW64\aliedit
2014-06-26 19:54 - 2014-06-26 19:54 - 00000000 ___HD () C:\Users\Megan\.boxsync
2014-06-26 19:54 - 2013-05-22 12:48 - 00000000 ____D () C:\Users\Megan
2014-06-26 19:44 - 2014-06-26 18:35 - 00000000 ____D () C:\Users\Megan\Desktop\New folder (2)
 
Files to move or delete:
====================
C:\Users\Megan\IP_Log_Data.js
 
 
Some content of TEMP:
====================
C:\Users\Megan\AppData\Local\Temp\BoxForOffice.exe
C:\Users\Megan\AppData\Local\Temp\dl_peer_id.dll
C:\Users\Megan\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmps91kdb.dll
C:\Users\Megan\AppData\Local\Temp\dsHostCheckerSetup.exe
C:\Users\Megan\AppData\Local\Temp\ExPromo.exe
C:\Users\Megan\AppData\Local\Temp\fp_pl_pfs_installer-1.exe
C:\Users\Megan\AppData\Local\Temp\fp_pl_pfs_installer.exe
C:\Users\Megan\AppData\Local\Temp\gtapi.dll
C:\Users\Megan\AppData\Local\Temp\Helper.exe
C:\Users\Megan\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe
C:\Users\Megan\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe
C:\Users\Megan\AppData\Local\Temp\jre-7u55-windows-i586-iftw.exe
C:\Users\Megan\AppData\Local\Temp\jre-7u65-windows-i586-iftw.exe
C:\Users\Megan\AppData\Local\Temp\log4net.dll
C:\Users\Megan\AppData\Local\Temp\neoNCSetup64.exe
C:\Users\Megan\AppData\Local\Temp\nsdCCCF.tmp.exe
C:\Users\Megan\AppData\Local\Temp\nsisdt.dll
C:\Users\Megan\AppData\Local\Temp\OfficeSetup.exe
C:\Users\Megan\AppData\Local\Temp\ose00000.exe
C:\Users\Megan\AppData\Local\Temp\Quarantine.exe
C:\Users\Megan\AppData\Local\Temp\QzoneMusic.exe
C:\Users\Megan\AppData\Local\Temp\safeguard.exe
C:\Users\Megan\AppData\Local\Temp\Setup.X86.en-US_O365HomePremRetail_86979110-9632-4e8a-810c-ec99599335e0_TX_PR_.exe
C:\Users\Megan\AppData\Local\Temp\SyncRestarter.exe
C:\Users\Megan\AppData\Local\Temp\sync_upgrader.exe
C:\Users\Megan\AppData\Local\Temp\vlc-2.0.7-win32.exe
C:\Users\Megan\AppData\Local\Temp\vlc-2.0.8-win32.exe
C:\Users\Megan\AppData\Local\Temp\vlc-2.1.1-win32.exe
C:\Users\Megan\AppData\Local\Temp\vlc-2.1.2-win32.exe
C:\Users\Megan\AppData\Local\Temp\vlc-2.1.3-win32.exe
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2014-07-22 19:35
 
==================== End Of Log ============================
 
I tried pasting the Addition log but the post is too long so I've attached it.
Link to post
Share on other sites

I am using the free version.  Last scan was taken 20 days ago.  Today I started Malwarebyte then ran 'update'. Then started a full scan. And there are over 10,000 malware items detected!!!!  Seems all are Ttojan.FakeMS.ED.

 

I have installed AVAST! antivirus software also and the signature is up-to-date.

 

The astonishing number of items reports leave me a bit doubtful if it is false alerts.  And I check the log files and found some items are repeated.  I am pasting some lines here (but not the entire log file yet) hoping that someone could kindly help me with my concerns.

 

Thanks.

 

*** start paste **

Scan Time: 7:08:17
Logfile: Malwarebytes Log 20140727.txt
Administrator: Yes

Version: 2.00.2.1012
Malware Database: v2014.07.26.09
Rootkit Database: v2014.07.17.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Kwan

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 289361
Time Elapsed: 41 min, 27 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 7
Trojan.FakeMS.ED, C:\Windows\System32\lsm.exe, 720, , [336e534d4d2e0630767cfba6728f8878]
Trojan.FakeMS.ED, C:\Windows\System32\conhost.exe, 1448, , [41603a66b1ca59dd49a9940dda276898]
Trojan.FakeMS.ED, C:\Windows\System32\wbem\WmiPrvSE.exe, 3256, , [a100722e85f6231314de3f62cb36b64a]
Trojan.FakeMS.ED, C:\Windows\System32\wbem\WmiPrvSE.exe, 4792, , [a100722e85f6231314de3f62cb36b64a]
Trojan.FakeMS.ED, C:\Windows\System32\taskhost.exe, 3944, , [8e137c24067549edbe34930eba475ba5]
Trojan.FakeMS.ED, C:\Windows\System32\dwm.exe, 3348, , [841db3ed5f1c75c130c2f8a908f9847c]
Trojan.FakeMS.ED, C:\Windows\System32\SEARCHINDEXER.EXE, 4208, , [bfe2901026550036e111a001649dc739]

Modules: 366
Trojan.FakeMS.ED, C:\Windows\System32\userenv.dll, , [9011336d8af17db9b53d277acc35ff01],
Trojan.FakeMS.ED, C:\Windows\System32\userenv.dll, , [9011336d8af17db9b53d277acc35ff01],
Trojan.FakeMS.ED, C:\Windows\System32\userenv.dll, , [9011336d8af17db9b53d277acc35ff01],
Trojan.FakeMS.ED, C:\Windows\System32\userenv.dll, , [9011336d8af17db9b53d277acc35ff01],
Trojan.FakeMS.ED, C:\Windows\System32\userenv.dll, , [9011336d8af17db9b53d277acc35ff01],
Trojan.FakeMS.ED, C:\Windows\System32\userenv.dll, , [9011336d8af17db9b53d277acc35ff01],
Trojan.FakeMS.ED, C:\Windows\System32\userenv.dll, , [9011336d8af17db9b53d277acc35ff01],
Trojan.FakeMS.ED, C:\Windows\System32\userenv.dll, , [9011336d8af17db9b53d277acc35ff01],
Trojan.FakeMS.ED, C:\Windows\System32\userenv.dll, , [9011336d8af17db9b53d277acc35ff01],
Trojan.FakeMS.ED, C:\Windows\System32\userenv.dll, , [9011336d8af17db9b53d277acc35ff01],
Trojan.FakeMS.ED, C:\Windows\System32\userenv.dll, , [9011336d8af17db9b53d277acc35ff01],
Trojan.FakeMS.ED, C:\Windows\System32\userenv.dll, , [9011336d8af17db9b53d277acc35ff01],

(truncated)

 

*** end paste ***

Link to post
Share on other sites

Just got similar warning. Ran Malwarebytes and scanning results show 3000+ items as infected with Trojan.FakeMS.ED. Wondered whether they might be false positives. Saw this thread here, so have not quarantined the supposedly infected files just yet. Currently running Norton IS and so far scanning results clean/nothing showing up as infected. What's going on?

Link to post
Share on other sites

Yep.

 

What the mod said to do:

 

"If anyone is currently running a scan STOP the scan immediately.

 

Do not allow anyting to be quarantined or removed.

 

Update the database and then run another scan."

Thanks.  The problem is I cannot do any further update as the 'update' icon is dim (meaning it thinks I have the latest update).  And now I cannot even start up MB again  :<

Link to post
Share on other sites

Thanks.  The problem is I cannot do any further update as the 'update' icon is dim (meaning it thinks I have the latest update).  And now I cannot even start up MB again  :<

Oh after trying for 5-6 times now I can start MB and now downloaded v2014.07.27.02.  Let me try scan.

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.