Jump to content

Infected - iexplore.exe runs in background


Recommended Posts

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 18-01-2015 03
Ran by David (administrator) on INTEL975 on 18-01-2015 21:26:40
Running from G:\Documents and Settings\David\Desktop
Loaded Profiles: David (Available profiles: David & Administrator)
Platform: Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: English (United States)
Internet Explorer Version 8 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AVG Technologies CZ, s.r.o.) G:\PROGRA~1\AVG\AVG2015\avgrsx.exe
(AVG Technologies CZ, s.r.o.) G:\Program Files\AVG\AVG2015\avgcsrvx.exe
(ATI Technologies Inc.) G:\WINDOWS\system32\ati2evxx.exe
(ATI Technologies Inc.) G:\WINDOWS\system32\ati2evxx.exe
(IDT, Inc.) G:\Program Files\IDT\IntelXPV_v103\WDM\stacsv.exe
(Intel Corporation) G:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Hewlett-Packard) G:\Program Files\HP\HP Software Update\hpwuschd2.exe
(Microsoft Corporation) G:\WINDOWS\system32\netdde.exe
(Scansoft, Inc.) G:\Program Files\TextBridge Pro Millennium\Bin\InstantAccess.exe
(IDT, Inc.) G:\Program Files\IDT\WDM\sttray.exe
(ATI Technologies Inc.) G:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(AVG Technologies CZ, s.r.o.) G:\Program Files\AVG\AVG2015\avgui.exe
() G:\Program Files\DivX\DivX Update\DivXUpdate.exe
(Oracle Corporation) G:\Program Files\Common Files\Java\Java Update\jusched.exe
() G:\Program Files\Belkin Bulldog Plus\UPS-Status.exe
(Microsoft Corporation) G:\Program Files\Microsoft ActiveSync\wcescomm.exe
(Mobipocket.com) G:\Program Files\Common Files\Mobipocket Shared\webcomp.exe
(AVG Technologies CZ, s.r.o.) G:\Program Files\AVG\AVG2015\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) G:\Program Files\AVG\AVG2015\avgwdsvc.exe
(Coupons.com Inc.) G:\Program Files\Coupons\CouponPrinterService.exe
(Intel Corporation) G:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
(Oracle Corporation) G:\Program Files\Java\jre7\bin\jqs.exe
(Microsoft Corporation) G:\WINDOWS\system32\regsvr32.exe
(Microsoft Corporation) G:\WINDOWS\system32\regsvr32.exe
(Microsoft Corporation) G:\Program Files\Windows Media Player\wmpnscfg.exe
(Hewlett-Packard Development Company, L.P.) G:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
(Eastman Kodak Company) G:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
() G:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
(Nalpeiron Ltd.) G:\WINDOWS\system32\NLSSRV32.EXE
(Logitech, Inc.) G:\Program Files\Logitech\SetPoint\SetPoint.exe
(Microsoft Corporation) G:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
(AVG Technologies CZ, s.r.o.) G:\Program Files\AVG\AVG2015\avgnsx.exe
() G:\Program Files\CDBurnerXP\NMSAccessU.exe
(Hauppauge Computer Works) G:\Program Files\WinTV\Ir.exe
(AVG Technologies CZ, s.r.o.) G:\Program Files\AVG\AVG2015\avgemcx.exe
(OpenOffice.org) G:\Program Files\OpenOffice.org 3\program\soffice.exe
(ATI Technologies Inc.) G:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(OpenOffice.org) G:\Program Files\OpenOffice.org 3\program\soffice.bin
(Logitech, Inc.) G:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
(TeamViewer GmbH) G:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe
(Hewlett-Packard Development Company, L.P.) G:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
(Ulead Systems, Inc.) G:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
() G:\Program Files\Belkin Bulldog Plus\UPS-Service.exe
(RealVNC Ltd.) G:\Program Files\RealVNC\VNC4\winvnc4.exe
(Hewlett-Packard Development Company, L.P.) G:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe
(Malwarebytes Corporation) G:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) G:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) G:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) G:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) G:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) G:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) G:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) G:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) G:\Program Files\Internet Explorer\iexplore.exe

==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [iAAnotif] => G:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [139264 2005-10-12] (Intel Corporation)
HKLM\...\Run: [Logitech Hardware Abstraction Layer] => G:\WINDOWS\KHALMNPR.EXE [76304 2008-02-29] (Logitech, Inc.)
HKLM\...\Run: [startCCC] => g:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [90112 2006-11-10] ()
HKLM\...\Run: [NeroCheck] => G:\WINDOWS\system32\\NeroCheck.exe [155648 2001-07-09] (Ahead Software Gmbh)
HKLM\...\Run: [intelAudioStudio] => G:\Program Files\Intel Audio Studio\IntelAudioStudio.exe [9142272 2008-03-27] (Intel Corporation)
HKLM\...\Run: [Kernel and Hardware Abstraction Layer] => G:\WINDOWS\KHALMNPR.EXE [76304 2008-02-29] (Logitech, Inc.)
HKLM\...\Run: [HP Software Update] => G:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49208 2010-03-12] (Hewlett-Packard)
HKLM\...\Run: [] => [X]
HKLM\...\Run: [instantAccess] => G:\Program Files\TextBridge Pro Millennium\Bin\InstantAccess.exe [49152 2000-01-19] (Scansoft, Inc.)
HKLM\...\Run: [Adobe Reader Speed Launcher] => G:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [35760 2009-12-22] (Adobe Systems Incorporated)
HKLM\...\Run: [sysTrayApp] => G:\Program Files\IDT\WDM\sttray.exe [483422 2009-03-12] (IDT, Inc.)
HKLM\...\Run: [APSDaemon] => G:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM\...\Run: [AVG_UI] => G:\Program Files\AVG\AVG2015\avgui.exe [3667472 2014-12-18] (AVG Technologies CZ, s.r.o.)
HKLM\...\Run: [DivXMediaServer] => G:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [448856 2014-11-17] (DivX, LLC)
HKLM\...\Run: [DivXUpdate] => G:\Program Files\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] ()
HKLM\...\Run: [KernelFaultCheck] => %systemroot%\system32\dumprep 0 -k
HKLM\...\Run: [sunJavaUpdateSched] => G:\Program Files\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation)
HKLM\...\Run: [uPS-Status] => G:\Program Files\Belkin Bulldog Plus\UPS-Status.exe [69632 2006-11-15] ()
HKLM\...\Run: [QuickTime Task] => G:\Program Files\QuickTime\qttask.exe [421888 2014-10-02] (Apple Inc.)
HKLM\...\RunOnce: [b Register G:\Program Files\DivX\DivX Transcode Engine\plugins\mc_demux_mp2_ds.ax] => "G:\WINDOWS\system32\rundll32.exe" "G:\Program Files\DivX\DivX Transcode Engine\plugins\mc_demux_mp2_ds.ax",DllRegisterServer
HKLM\...\runonceex: [] => [X]
Winlogon\Notify\AtiExtEvent: G:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
Winlogon\Notify\LBTWlgn: g:\program files\common files\logitech\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-1606980848-706699826-682003330-1003\...\Run: [H/PC Connection Agent] => G:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE [401491 2004-02-03] (Microsoft Corporation)
HKU\S-1-5-21-1606980848-706699826-682003330-1003\...\Run: [Mobipocket Web Companion] => G:\Program Files\Common Files\Mobipocket Shared\webcomp.exe [1617920 2004-02-12] (Mobipocket.com)
HKU\S-1-5-21-1606980848-706699826-682003330-1003\...\Run: [AVG-Secure-Search-Update_0913a] => G:\Documents and Settings\David\Application Data\AVG 0913a Campaign\AVG-Secure-Search-Update-0913a.exe /PROMPT --mid 842c4660c97b47d19f9ad15097debd06-7ce3e79853d9ee8cf88dd64f4d1c6ffc99a244b7 --CMPID 0 (the data entry has 4 more characters).
HKU\S-1-5-21-1606980848-706699826-682003330-1003\...\Run: [YSWPack] => regsvr32.exe "G:\Documents and Settings\David\Local Settings\Application Data\YSWPack\rfvelocityshader.dll"
HKU\S-1-5-21-1606980848-706699826-682003330-1003\...\Run: [AQJworks] => G:\WINDOWS\system32\regsvr32.exe "G:\Documents and Settings\David\Local Settings\Application Data\Ucmedia\TFFONTMGR.dll"
HKU\S-1-5-21-1606980848-706699826-682003330-1003\...\Run: [WMPNSCFG] => G:\Program Files\Windows Media Player\WMPNSCFG.exe [204288 2006-10-18] (Microsoft Corporation)
HKU\S-1-5-21-1606980848-706699826-682003330-1003\...\Policies\Explorer: [NoDrives] 0x02000000
Startup: G:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutoStart IR.lnk
ShortcutTarget: AutoStart IR.lnk -> G:\Program Files\WinTV\Ir.exe (Hauppauge Computer Works)
Startup: G:\Documents and Settings\All Users\Start Menu\Programs\Startup\Forget Me Not.lnk
ShortcutTarget: Forget Me Not.lnk -> G:\Program Files\Broderbund\AG CreataCard\AGremind.exe (Broderbund Properties LLC)
Startup: G:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> G:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Development Company, L.P.)
Startup: G:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk
ShortcutTarget: HP Photosmart Premier Fast Start.lnk -> G:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Development Company, L.P.)
Startup: G:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
ShortcutTarget: Kodak EasyShare software.lnk -> G:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe (Eastman Kodak Company)
Startup: G:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak software updater.lnk
ShortcutTarget: Kodak software updater.lnk -> G:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe ()
Startup: G:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk
ShortcutTarget: Logitech SetPoint.lnk -> G:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
Startup: G:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
ShortcutTarget: Microsoft Office.lnk -> G:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
Startup: G:\Documents and Settings\All Users\Start Menu\Programs\Startup\Symantec Fax Starter Edition Port.lnk
ShortcutTarget: Symantec Fax Starter Edition Port.lnk -> G:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE (Microsoft Corporation)
Startup: G:\Documents and Settings\David\Start Menu\Programs\Startup\AutoStart IR.lnk
ShortcutTarget: AutoStart IR.lnk -> G:\Program Files\WinTV\Ir.exe (Hauppauge Computer Works)
Startup: G:\Documents and Settings\David\Start Menu\Programs\Startup\Forget Me Not.lnk
ShortcutTarget: Forget Me Not.lnk -> G:\Program Files\Broderbund\AG CreataCard\AGremind.exe (Broderbund Properties LLC)
Startup: G:\Documents and Settings\David\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> G:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Development Company, L.P.)
Startup: G:\Documents and Settings\David\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk
ShortcutTarget: HP Photosmart Premier Fast Start.lnk -> G:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Development Company, L.P.)
Startup: G:\Documents and Settings\David\Start Menu\Programs\Startup\Logitech SetPoint.lnk
ShortcutTarget: Logitech SetPoint.lnk -> G:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
Startup: G:\Documents and Settings\David\Start Menu\Programs\Startup\Microsoft Office.lnk
ShortcutTarget: Microsoft Office.lnk -> G:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
Startup: G:\Documents and Settings\David\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
ShortcutTarget: OpenOffice.org 3.3.lnk -> G:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
Startup: G:\Documents and Settings\David\Start Menu\Programs\Startup\Symantec Fax Starter Edition Port.lnk
ShortcutTarget: Symantec Fax Starter Edition Port.lnk -> G:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE (Microsoft Corporation)
BootExecute: autocheck autochk * G:\PROGRA~1\AVG\AVG2015\avgrsx.exe /sync /restart

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-1606980848-706699826-682003330-1003\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-1606980848-706699826-682003330-1003\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
SearchScopes: HKU\.DEFAULT -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
SearchScopes: HKU\S-1-5-21-1606980848-706699826-682003330-1003 -> {DC4ED5D9-DB1B-4959-8AAA-D0CE8125D189} URL = http://www.mysearchresults.com/search?c=4200&t=01&q={searchTerms}
BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> G:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: AVG Safe Search -> {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -> G:\Program Files\AVG\AVG2012\avgssie.dll No File
BHO: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> G:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Google Toolbar Notifier BHO -> {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -> G:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.)
BHO: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> G:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKU\S-1-5-21-1606980848-706699826-682003330-1003 -> No Name - {41565256-3700-A76A-76A7-7A786E7484D7} -  No File
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_25-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0025-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_25-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_25-windows-i586.cab
DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} http://content.systemrequirementslab.com/bin/srldetect_intel_4.5.24.0.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - G:\Program Files\AVG\AVG2012\avgpp.dll No File
Handler: mctp - {d7b95390-b1c5-11d0-b111-0080c712fe82} - G:\Program Files\Microsoft ActiveSync\aatp.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1

FireFox:
========
FF ProfilePath: G:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\xm8wwrtg.default
FF Homepage: hxxp://www.yahoo.com/|hxxp://www.google.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official
FF Plugin: @adobe.com/ShockwavePlayer -> G:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin: @divx.com/DivX Content Upload Plugin,version=1.0.0 -> G:\Program Files\DivX\DivX Content Uploader\npUpload.dll No File
FF Plugin: @divx.com/DivX Player Plugin,version=1.0.0 -> G:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll No File
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> G:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> G:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
FF Plugin: @Google.com/GoogleEarthPlugin -> G:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/DTPlugin,version=10.71.2 -> G:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.71.2 -> G:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> g:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> g:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @pack.google.com/Google Updater;version=14 -> G:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF Plugin: @tools.google.com/Google Update;version=3 -> G:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> G:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF user.js: detected! => G:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\xm8wwrtg.default\user.js
FF Plugin ProgramFiles/Appdata: G:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll (Coupons, Inc.)
FF Plugin ProgramFiles/Appdata: G:\Program Files\mozilla firefox\plugins\npDivxPlayerPlugin.dll (DivX, Inc)
FF Plugin ProgramFiles/Appdata: G:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll (Coupons, Inc.)
FF Plugin ProgramFiles/Appdata: G:\Program Files\mozilla firefox\plugins\npnul32.dll (mozilla.org)
FF Plugin ProgramFiles/Appdata: G:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: G:\Program Files\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: G:\Program Files\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: G:\Program Files\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: G:\Program Files\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: G:\Program Files\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF SearchPlugin: G:\Program Files\mozilla firefox\searchplugins\answers.xml
FF SearchPlugin: G:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
FF Extension: DOM Inspector - G:\Program Files\Mozilla Firefox\extensions\inspector@mozilla.org [2008-03-09]
FF Extension: Talkback - G:\Program Files\Mozilla Firefox\extensions\talkback@mozilla.org [2008-03-09]
FF Extension: Java Console - G:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} [2009-10-09]
FF Extension: Java Console - G:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} [2009-11-03]
FF Extension: Java Console - G:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} [2010-04-07]
FF Extension: Java Console - G:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} [2010-05-13]
FF Extension: Java Console - G:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} [2010-08-19]
FF Extension: Java Console - G:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} [2011-01-15]
FF Extension: Java Console - G:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} [2011-02-26]
FF Extension: Java Console - G:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} [2011-06-22]
FF Extension: Java Console - G:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} [2011-10-03]
FF Extension: Java Console - G:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2012-06-15]
FF Extension: Java Console - G:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2012-09-03]
FF Extension: Java Console - G:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2012-11-06]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - g:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - g:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-07-08]
FF HKLM\...\Firefox\Extensions: [{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}] - G:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF HKU\S-1-5-21-1606980848-706699826-682003330-1003\...\Firefox\Extensions: [addon@smartinline.com] - G:\Program Files\SmartInline\addon@smartinline.com
FF Extension: SmartInline - G:\Program Files\SmartInline\addon@smartinline.com [2012-12-14]

Chrome:
=======
CHR HKLM\...\Chrome\Extension: [mljlkfaflemgicpnbejggbnmjgkhbfdo] - G:\Program Files\SmartInline\smartinline.crx [2012-11-16]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S2 ATI Smart; G:\WINDOWS\system32\ati2sgag.exe [520192 2007-06-13] () [File not signed]
R2 AVGIDSAgent; G:\Program Files\AVG\AVG2015\avgidsagent.exe [3432976 2014-12-18] (AVG Technologies CZ, s.r.o.)
R2 avgwd; G:\Program Files\AVG\AVG2015\avgwdsvc.exe [298080 2014-12-18] (AVG Technologies CZ, s.r.o.)
R2 CouponPrinterService; G:\Program Files\Coupons\CouponPrinterService.exe [154096 2014-10-15] (Coupons.com Inc.)
S2 gupdate1ca0fedc6bc4b18; G:\Program Files\Google\Update\GoogleUpdate.exe [107912 2014-10-18] (Google Inc.)
R2 IAANTMon; G:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe [86140 2005-10-12] (Intel Corporation) [File not signed]
S3 IDriverT; G:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [File not signed]
R2 JavaQuickStarterService; G:\Program Files\Java\jre7\bin\jqs.exe [182696 2014-10-14] (Oracle Corporation)
S3 LBTServ; G:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe [121360 2008-05-02] (Logitech, Inc.)
S2 MSMQ; G:\WINDOWS\system32\mqsvc.exe [4608 2008-04-13] (Microsoft Corporation)
R2 NMSAccess; G:\Program Files\CDBurnerXP\NMSAccessU.exe [71096 2010-03-04] ()
S2 Pml Driver HPZ12; G:\WINDOWS\system32\HPZipm12.exe [73728 2007-08-09] (HP) [File not signed]
R2 STacSV; g:\program files\idt\intelxpv_v103\wdm\STacSV.exe [254036 2009-03-12] (IDT, Inc.)
R2 UleadBurningHelper; G:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [49152 2004-03-13] (Ulead Systems, Inc.) [File not signed]
R2 UPSentry_Smart; G:\Program Files\Belkin Bulldog Plus\UPS-Service.exe [290816 2006-12-19] () [File not signed]
R2 WinVNC4; G:\Program Files\RealVNC\VNC4\WinVNC4.exe [439632 2008-10-15] (RealVNC Ltd.)
S3 rpcapd; "%ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini" [X]
S3 SwPrv; G:\WINDOWS\System32\dllhost.exe /Processid:{FD7E7858-27C9-49DC-A3A0-ADC75B2E2AFC}
S2 USBMate; G:\Program Files\Belkin\Belkin Power Management Software\usbmate.exe [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 ASPI32; G:\WINDOWS\system32\Drivers\ASPI32.sys [16877 2002-07-17] (Adaptec)
R1 Avgdiskx; G:\WINDOWS\System32\DRIVERS\avgdiskx.sys [121624 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriverl; G:\WINDOWS\System32\DRIVERS\avgidsdriverlx.sys [192792 2014-12-08] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHX; G:\WINDOWS\System32\DRIVERS\avgidshx.sys [154904 2014-11-18] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSShim; G:\WINDOWS\System32\DRIVERS\avgidsshimx.sys [21272 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 Avgldx86; G:\WINDOWS\System32\DRIVERS\avgldx86.sys [192792 2014-08-28] (AVG Technologies CZ, s.r.o.)
R0 Avglogx; G:\WINDOWS\System32\DRIVERS\avglogx.sys [230680 2014-07-18] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx86; G:\WINDOWS\System32\DRIVERS\avgmfx86.sys [98584 2014-10-05] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx86; G:\WINDOWS\System32\DRIVERS\avgrkx86.sys [27416 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 Avgtdix; G:\WINDOWS\System32\DRIVERS\avgtdix.sys [200984 2014-10-10] (AVG Technologies CZ, s.r.o.)
S3 CCDECODE; G:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation)
R1 CDRPDACC; G:\Program Files\InfinaDyne\Shared\CDRPDACC.sys [4633 2002-07-10] (Arrowkey) [File not signed]
S3 cpudrv; G:\Program Files\SystemRequirementsLab\cpudrv.sys [11336 2011-06-02] ()
R3 hcwPVRP2; G:\WINDOWS\System32\DRIVERS\hcwPVRP2.sys [824512 2007-06-17] (Hauppauge Computer Works, Inc.)
R0 hotcore3; G:\WINDOWS\System32\drivers\hotcore3.sys [38432 2007-04-27] (Paragon Software Group)
R3 MQAC; G:\WINDOWS\system32\drivers\mqac.sys [92544 2008-04-13] (Microsoft Corporation)
R0 mv61xx; G:\WINDOWS\System32\DRIVERS\mv61xx.sys [91520 2007-02-09] (Marvell Semiconductor, Inc.)
S3 NAL; G:\WINDOWS\System32\Drivers\iqvw32.sys [24064 2006-07-05] (Intel Corporation ) [File not signed]
S3 NdisIP; G:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation)
R2 NPF; G:\WINDOWS\System32\drivers\npf.sys [35088 2010-06-25] (CACE Technologies, Inc.)
R1 PQNTDrv; G:\WINDOWS\system32\Drivers\PQNTDrv.sys [4228 2004-05-05] (PowerQuest Corporation) [File not signed]
R2 SBKUPNT; G:\WINDOWS\system32\Drivers\SBKUPNT.SYS [14976 2001-07-13] () [File not signed]
S3 SER120; G:\WINDOWS\System32\DRIVERS\SER120.sys [32814 2005-03-16] (USB Com port.) [File not signed]
S3 slabbus; G:\WINDOWS\System32\DRIVERS\slabbus.sys [55312 2005-04-11] (MCCI) [File not signed]
S3 slabser; G:\WINDOWS\System32\DRIVERS\slabser.sys [89808 2005-04-11] (MCCI) [File not signed]
R3 SMBios; G:\WINDOWS\System32\DRIVERS\SMBios.sys [36484 2003-09-17] (Intel Corporation) [File not signed]
R3 smbusp; G:\WINDOWS\System32\DRIVERS\intelsmb.sys [21248 2007-10-12] (Intel Corporation) [File not signed]
R2 StarOpen; G:\WINDOWS\system32\Drivers\StarOpen.sys [5504 2012-06-03] () [File not signed]
R3 STHDA; G:\WINDOWS\System32\drivers\sthda.sys [1550613 2009-03-12] (IDT, Inc.)
S3 SUSTUCAM; G:\WINDOWS\System32\DRIVERS\sustucam.sys [38272 2007-04-04] (Susteen, Inc.) [File not signed]
S3 SUSTUCAP; G:\WINDOWS\System32\DRIVERS\sustucap.sys [38272 2007-04-04] (Susteen, Inc.) [File not signed]
S3 SUSTUCAU; G:\WINDOWS\System32\DRIVERS\sustucau.sys [21376 2007-04-04] (Susteen, Inc.) [File not signed]
R3 USR1806V; G:\WINDOWS\System32\DRIVERS\USR1806V.SYS [794399 2001-08-17] (U.S. Robotics, Inc.)
S3 vncmirror; G:\WINDOWS\System32\DRIVERS\vncmirror.sys [4608 2011-08-18] (RealVNC Ltd.)
S3 wceusbsh; G:\WINDOWS\System32\DRIVERS\wceusbsh.sys [104576 2010-06-23] (Microsoft Corporation)
S4 IntelIde; No ImagePath
U5 ScsiPort; G:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
S3 sfng32; system32\drivers\sfng32.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)

==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-01-18 21:26 - 2015-01-18 21:27 - 00027306 _____ () G:\Documents and Settings\David\Desktop\FRST.txt
2015-01-18 21:23 - 2015-01-18 21:26 - 00000000 ____D () G:\FRST
2015-01-18 21:14 - 2015-01-18 21:14 - 01118208 _____ (Farbar) G:\Documents and Settings\David\Desktop\FRST.exe
2015-01-18 21:03 - 2015-01-18 21:03 - 00001698 _____ () G:\Documents and Settings\David\Desktop\I'm infected - What do I do now - Malware Removal Help - Malwarebytes Forum.url
2015-01-18 16:21 - 2015-01-18 17:24 - 00114904 _____ (Malwarebytes Corporation) G:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-01-18 16:08 - 2015-01-18 16:17 - 00000000 ____D () G:\Program Files\Malwarebytes Anti-Malware
2015-01-18 16:08 - 2015-01-18 16:13 - 00000777 _____ () G:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2015-01-18 16:08 - 2015-01-18 16:13 - 00000000 ____D () G:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware
2015-01-18 16:08 - 2015-01-18 16:08 - 00000000 ____D () G:\Documents and Settings\All Users\Application Data\Malwarebytes
2015-01-18 16:08 - 2014-11-21 06:14 - 00054360 _____ (Malwarebytes Corporation) G:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-01-18 16:08 - 2014-11-21 06:14 - 00023256 _____ (Malwarebytes Corporation) G:\WINDOWS\system32\Drivers\mbam.sys
2015-01-18 13:09 - 2015-01-18 15:05 - 00004189 _____ () G:\Documents and Settings\Administrator\avgrep.txt
2015-01-18 13:08 - 2015-01-18 13:09 - 00000000 ____D () G:\Documents and Settings\Administrator\Local Settings\Application Data\Avg2015
2015-01-18 13:08 - 2015-01-18 13:08 - 00000000 ____D () G:\Documents and Settings\Administrator\Application Data\AVG2015
2015-01-14 18:54 - 2015-01-14 18:55 - 00003785 _____ () G:\Documents and Settings\All Users\Application Data\lpm.dat
2015-01-07 20:56 - 2015-01-07 23:31 - 00000000 ____D () G:\Documents and Settings\David\Local Settings\Application Data\Ucmedia
2015-01-07 20:56 - 2015-01-07 20:56 - 00000000 ____D () G:\Documents and Settings\David\Local Settings\Application Data\YSWPack
2014-12-24 09:02 - 2014-12-24 09:02 - 00000000 ____D () G:\Documents and Settings\Administrator\Local Settings\Application Data\Apple
2014-12-22 11:21 - 2014-12-22 11:22 - 00000000 ____D () G:\Documents and Settings\Administrator\Local Settings\Application Data\Adobe

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-01-18 21:27 - 2007-05-13 19:58 - 00000000 ____D () G:\Documents and Settings\David\Local Settings\Temp
2015-01-18 20:52 - 2009-07-28 20:53 - 00000886 _____ () G:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-01-18 20:48 - 2012-11-07 10:45 - 00000830 _____ () G:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-01-18 19:16 - 2007-05-13 21:33 - 01166585 _____ () G:\WINDOWS\WindowsUpdate.log
2015-01-18 19:16 - 2003-03-31 07:00 - 00001182 _____ () G:\WINDOWS\win.ini
2015-01-18 19:13 - 2003-03-31 07:00 - 00013708 _____ () G:\WINDOWS\system32\wpa.dbl
2015-01-18 19:12 - 2007-05-13 03:44 - 00000159 _____ () G:\WINDOWS\wiadebug.log
2015-01-18 19:12 - 2007-05-13 03:44 - 00000049 _____ () G:\WINDOWS\wiaservc.log
2015-01-18 19:11 - 2014-09-24 15:01 - 00000278 _____ () G:\WINDOWS\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1606980848-706699826-682003330-1003.job
2015-01-18 19:11 - 2012-10-15 14:02 - 00000278 _____ () G:\WINDOWS\Tasks\RealUpgradeLogonTaskS-1-5-21-1606980848-706699826-682003330-1003.job
2015-01-18 19:11 - 2011-05-19 19:45 - 00000294 _____ () G:\WINDOWS\Tasks\RealUpgradeLogonTaskS-1-5-21-1606980848-706699826-682003330-500.job
2015-01-18 19:11 - 2009-07-28 20:53 - 00000882 _____ () G:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-01-18 19:11 - 2007-05-13 19:54 - 00000006 ____H () G:\WINDOWS\Tasks\SA.DAT
2015-01-18 19:10 - 2007-07-03 08:31 - 00000178 ___SH () G:\Documents and Settings\Administrator\ntuser.ini
2015-01-18 17:18 - 2007-05-13 20:16 - 00524288 _____ () G:\WINDOWS\system32\config\ACEEvent.evt
2015-01-18 17:18 - 2007-05-13 19:58 - 00000278 ___SH () G:\Documents and Settings\David\ntuser.ini
2015-01-18 17:18 - 2007-05-13 19:57 - 00031946 _____ () G:\WINDOWS\SchedLgU.Txt
2015-01-18 17:14 - 2007-05-13 19:53 - 00000000 ___RD () G:\WINDOWS\Offline Web Pages
2015-01-18 13:09 - 2007-07-03 08:31 - 00000000 ____D () G:\Documents and Settings\Administrator
2015-01-18 12:32 - 2009-07-28 20:41 - 00000868 _____ () G:\WINDOWS\Tasks\Google Software Updater.job
2015-01-18 10:55 - 2011-09-04 21:34 - 00000000 ____D () G:\Documents and Settings\All Users\Application Data\MFAData
2015-01-17 14:26 - 2012-04-15 19:13 - 00701616 _____ (Adobe Systems Incorporated) G:\WINDOWS\system32\FlashPlayerApp.exe
2015-01-17 14:26 - 2011-05-13 13:07 - 00071344 _____ (Adobe Systems Incorporated) G:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2015-01-15 20:45 - 2011-05-19 19:45 - 00000302 _____ () G:\WINDOWS\Tasks\RealUpgradeScheduledTaskS-1-5-21-1606980848-706699826-682003330-500.job
2015-01-15 20:35 - 2007-05-13 22:11 - 00210204 _____ () G:\WINDOWS\wmsetup.log
2015-01-14 20:48 - 2013-08-14 15:45 - 00000000 ____D () G:\WINDOWS\system32\MRT
2015-01-14 20:36 - 2007-05-13 21:54 - 110348472 _____ (Microsoft Corporation) G:\WINDOWS\system32\MRT.exe
2015-01-14 11:15 - 2014-09-24 15:01 - 00000286 _____ () G:\WINDOWS\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1606980848-706699826-682003330-1003.job
2015-01-14 11:15 - 2010-05-04 00:37 - 00000286 _____ () G:\WINDOWS\Tasks\RealUpgradeScheduledTaskS-1-5-21-1606980848-706699826-682003330-1003.job
2015-01-14 09:02 - 2009-09-25 14:30 - 00000284 _____ () G:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2015-01-10 09:05 - 2014-04-25 08:18 - 00000000 ____D () G:\Documents and Settings\All Users\Start Menu\Programs\AVG
2015-01-10 09:05 - 2007-05-13 03:42 - 01084539 _____ () G:\WINDOWS\setupapi.log
2014-12-31 23:47 - 2007-07-03 09:52 - 00129536 _____ () G:\Documents and Settings\David\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-12-22 11:22 - 2007-07-03 08:31 - 00000000 ____D () G:\Documents and Settings\Administrator\Local Settings\Temp

==================== Files in the root of some directories =======
2008-04-20 18:38 - 2008-04-20 18:38 - 0000568 _____ () G:\Program Files\fpsectbl
2008-01-20 23:16 - 1999-12-07 12:00 - 0995383 ____N (Microsoft Corporation) G:\Program Files\MFC42.DLL
2008-01-20 23:16 - 1998-04-08 12:12 - 0082432 _____ (Code Jockey - Dedicated to MFC Professionals) G:\Program Files\ONSCOOLR.DLL
2008-01-20 23:16 - 1998-04-08 12:31 - 0050176 ____N () G:\Program Files\ONSDOCKR.DLL
2008-01-20 23:16 - 2005-12-01 15:45 - 0282624 ____N (CompuApps Inc.,) G:\Program Files\PARTUTIL.DLL
2008-01-20 23:16 - 2005-11-22 23:37 - 0002108 _____ () G:\Program Files\README.TXT
2008-04-20 18:38 - 2008-04-20 18:38 - 0214560 _____ (RealNetworks, Inc.) G:\Program Files\realplay.exe
2008-04-20 18:38 - 2008-04-20 18:38 - 0000682 _____ () G:\Program Files\realplay.exe.manifest
2008-01-20 23:16 - 2002-08-06 00:36 - 0024576 ____N () G:\Program Files\SKUNINST.DLL
2008-01-20 23:16 - 2008-01-20 23:16 - 0031237 _____ () G:\Program Files\SKUninst.ISU
2008-01-20 23:16 - 2005-12-04 07:18 - 1796476 _____ () G:\Program Files\StepByStep Guide.pdf
2008-01-20 23:16 - 2005-04-21 13:13 - 0102870 ____N () G:\Program Files\Swishd.dat
2008-01-20 23:16 - 2005-12-04 06:20 - 0475284 ____N () G:\Program Files\SWISMAN.PDF
2008-01-20 23:16 - 2005-11-24 04:55 - 0000922 ____N () G:\Program Files\SWISNIFE.CNT
2008-01-20 23:16 - 2005-12-01 15:59 - 1077248 _____ (CompuApps, Inc.) G:\Program Files\SWISNIFE.EXE
2008-01-20 23:16 - 2005-12-04 06:14 - 0421023 ____N () G:\Program Files\SWISNIFE.HLP
2008-01-20 23:16 - 2005-04-21 13:13 - 0086358 _____ () G:\Program Files\Warning.dat
2008-01-20 23:16 - 1998-09-23 04:57 - 0048128 ____R (Adaptec) G:\Program Files\WNASPI32.DLL
1998-12-08 21:53 - 1998-12-08 21:53 - 0099840 _____ (Symantec Corp.) G:\Program Files\Common Files\IRAABOUT.DLL
1998-12-08 21:53 - 1998-12-08 21:53 - 0048640 _____ (Symantec Corp., Peter Norton Computing Group) G:\Program Files\Common Files\IRALPTTR.DLL
1998-12-08 21:53 - 1998-12-08 21:53 - 0070144 _____ (Symantec Corp., Peter Norton Computing Group) G:\Program Files\Common Files\IRAMDMTR.DLL
1998-12-08 21:53 - 1998-12-08 21:53 - 0186368 _____ (Symantec Corp., Peter Norton Computing Group) G:\Program Files\Common Files\IRAREG.DLL
1998-12-08 21:53 - 1998-12-08 21:53 - 0017920 _____ (Symantec Corp.) G:\Program Files\Common Files\IRASRIAL.DLL
1998-12-08 21:53 - 1998-12-08 21:53 - 0031744 _____ (Symantec Corp., Peter Norton Computing Group) G:\Program Files\Common Files\IRAWEBTR.DLL
2007-07-24 14:12 - 2007-07-24 14:12 - 0002508 _____ () G:\Documents and Settings\David\Application Data\$_hpcst$.hpc
2013-06-18 13:20 - 2013-06-18 13:53 - 0022937 _____ () G:\Documents and Settings\David\Application Data\Comma Separated Values (DOS).ADR
2013-06-18 13:58 - 2013-06-19 00:18 - 0037761 _____ () G:\Documents and Settings\David\Application Data\Comma Separated Values (Windows).ADR
2010-01-07 15:42 - 2010-01-07 15:42 - 0000760 _____ () G:\Documents and Settings\David\Application Data\setup_ldm.iss
2009-03-31 21:38 - 2009-03-31 21:38 - 0000036 ____H () G:\Documents and Settings\David\Application Data\swk.ini
2007-07-03 09:52 - 2014-12-31 23:47 - 0129536 _____ () G:\Documents and Settings\David\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-11-30 22:25 - 2012-11-30 22:25 - 0027520 _____ () G:\Documents and Settings\David\Local Settings\Application Data\dt.dat
2007-05-13 20:16 - 2007-05-13 20:16 - 0000128 _____ () G:\Documents and Settings\David\Local Settings\Application Data\fusioncache.dat

Some content of TEMP:
====================
G:\Documents and Settings\David\Local Settings\Temp\axi7C.tmp.exe
G:\Documents and Settings\David\Local Settings\Temp\DivXSetup.exe
G:\Documents and Settings\David\Local Settings\Temp\IadHide5.dll
G:\Documents and Settings\David\Local Settings\Temp\jre-6u39-windows-i586-iftw.exe
G:\Documents and Settings\David\Local Settings\Temp\jre-7u15-windows-i586-iftw.exe
G:\Documents and Settings\David\Local Settings\Temp\jre-7u17-windows-i586-iftw.exe
G:\Documents and Settings\David\Local Settings\Temp\jre-7u21-windows-i586-iftw.exe
G:\Documents and Settings\David\Local Settings\Temp\jre-7u25-windows-i586-iftw.exe
G:\Documents and Settings\David\Local Settings\Temp\jre-7u51-windows-i586-iftw.exe
G:\Documents and Settings\David\Local Settings\Temp\jre-7u55-windows-i586-iftw.exe
G:\Documents and Settings\David\Local Settings\Temp\jre-7u65-windows-i586-iftw.exe
G:\Documents and Settings\David\Local Settings\Temp\jre-7u67-windows-i586-iftw.exe
G:\Documents and Settings\David\Local Settings\Temp\lowproc.exe
G:\Documents and Settings\David\Local Settings\Temp\OutSec.exe
G:\Documents and Settings\David\Local Settings\Temp\stubhelper.dll

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

G:\WINDOWS\explorer.exe => File is digitally signed
G:\WINDOWS\system32\winlogon.exe => File is digitally signed
G:\WINDOWS\system32\svchost.exe => File is digitally signed
G:\WINDOWS\system32\services.exe => File is digitally signed
G:\WINDOWS\system32\User32.dll => File is digitally signed
G:\WINDOWS\system32\userinit.exe => File is digitally signed
G:\WINDOWS\system32\rpcss.dll => File is digitally signed
G:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

==================== End Of Log ============================

Addition.txt

Link to post
Share on other sites

Hello,
    
 
They call me TwinHeadedEagle around here, and I'll be working with you.
 
     
    
Before we start please read and note the following:

  • Limit your internet access to posting here, some infections just wait to steal typed-in passwords.
  • Please be patient. I know it is frustrating when your PC isn't working properly, but malware removal takes time.
  • Don't run any scripts or tools on your own, unsupervised usage may cause more harm than good.
  • Do not paste the logs in your posts, attachments make my work easier. There is a More reply options button, that gives you Upload Files option below which you can use to attach your reports. Always attach reports from all tools.
  • Always execute my instructions in given order. If for some reason you cannot completely follow one instruction, inform me about that.
  • Stay with me to the end, the absence of symptoms doesn't mean that your machine is fully operational.
  • Note that we may live in totally different time zones, what may cause some delays between answers.
  • Do not ask for help for your business PC. Companies are making revenue via computers, so it is good thing to pay someone to repair it.
  • If I don't hear from you within 3 days from this initial or any subsequent post, then this thread will be closed.

:excl: I can't foresee everything, so if anything unexpected happens, please stop and inform me!
:excl: There are no silly questions. Never be afraid to ask if in doubt!
 
 
 
  warning.gif Rules and policies
 
We won't support any piracy.
That being told, if any evidence of illegal OS, software, cracks/keygens or any other will be revealed, any further assistance will be suspended. If you are aware that there is this kind of stuff on your machine, remove it before proceeding!
The same applies to any use of P2P software: uTorrent, BitTorrent, Vuze, Kazaa, Ares... We don't provide any help for P2P, except for their removal. All P2P software has to be uninstalled or at least fully disabled before proceeding!
 
Failure to follow these guidelines will result with closing your topic and withdrawning any assistance.
 
 
 
 

51a5bf3d99e8a-ComboFixlogo16.png Scan with ComboFix
 
This is a very powerful tool that should be used only if advised by Malware Analyst.
Do not run ComboFix on your own!

 
Referring to this instruction, please download ComboFix by sUBs and save it to your desktop.
Temporary disable your AntiVirus and AntiSpyware protection - instructions here.

  • Right-click on 51a5bf3d99e8a-ComboFixlogo16.png icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
  • Accept the disclaimer and agree if prompted to install Recovery Console.
  • Do not take any actions while ComboFix goes through your System - it may cause it to stall!
  • This scan may take some time!
  • When finished - it will display a logfile (located also on your main drive, usually C:\ComboFix.txt).

Include that log in your next reply.
icon_idea.gif If you'll encounter any issues with internet connection after running ComboFix, please visit this link.
icon_idea.gif If an error about operation on the key marked for deletion will appear after running the tool, please reboot your machine.

Link to post
Share on other sites

I ran ComboFix and it said it takes 10 minutes or longer for very infected systems.

I let it run over night and there was no progress in the morning.

I rebooted the computer and re-ran ComboFix but it stays at the same stage as

before -see below.

 

http://i1251.photobucket.com/albums/hh556/condor655/combofix_status.jpg

 

Not sure what to do next?

 

combofix_status.jpg

Link to post
Share on other sites

If it doesn't move, proceed with this step:
 
 
 
FRST.gif Scan with Farbar Recovery Scan Tool
 
Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.

  • Right-click on FRST.gif icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Make sure that Addition option is checked.
  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.

Please upload them into your next reply.

Link to post
Share on other sites

remove%20outdated.jpg Uninstall some programs
 
We need to uninstall some unwanted/unneeded programs.

  • Press the WindowsKey.png + R on your keyboard at the same time. Type appwiz.cpl and click OK.
  • Search there for each entry mentioned below, right-click the entry and click Uninstall one at a time

The list of programs to uninstall:

  • Download Updater
  • Easy Mobile Soft
  • FoxTab PDF Converter
  • ID3 Lyrics Editor
  • SmartInline

After completing uninstalls, please manually reboot your machine!
 
Note: If you get the message like: An error occurred while trying to uninstall, just press Yes.
 
 
 
 
 
FRST.gif Fix with Farbar Recovery Scan Tool
 

icon_exclaim.gif This fix was created for this user for use on that particular machine. icon_exclaim.gif
icon_exclaim.gif Running it on another one may cause damage and render the system unstable. icon_exclaim.gif

 
Download attached fixlist.txt file and save it to the Desktop:
 
Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

  • Right-click on FRST.gif icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.

Please post it to your reply.
 
 
 
 
Download 51a5f31352b88-icon_MBAR.pngMalwarebytes Anti-Rootkit to your desktop.

  • Double-click the icon to start the tool.
  • It will ask you where to extract it, then it will start.
  • Warning! Malwarebytes Anti-Rootkit needs to be run from an account with administrator rights.
  • Click in the introduction screen "next" to continue.
  • Click in the following screen "Update" to obtain the latest malware definitions.
  • Once the update is complete select "Next" and click "Scan".
  • When the scan is finished and no malware has been found select "Exit".
  • If malware was detected, make sure to check all the items and click "Cleanup". Reboot your computer.
  • Open the MBAR folder and attach the content of the following files in your next reply:
    • "mbar-log-{date} (xx-xx-xx).txt"
    • "system-log.txt"

fixlist.txt

Link to post
Share on other sites

Was able to remove all programs EXCEPT "FoxTab PDF Converter"

It does not respond in the add/remove programs.

When I access it - it just blinks, but nothing happens.

Went into the Program File folder and there is no "uninstall" file there.

Re-booted into safe mode to try and remove it, but the same thing happened.

So I did not proceed further until you let me know what to do. Thanks.

Link to post
Share on other sites

Ran Farbar Recovery Scan Tool - ran OK - Fixlog.txt attached.

 

Malwarebytes Anti-Rootkit when run causes blue screen with writing for only split second - cant make out what it says - then reboots immediately! Upon re-boot, there was a windows error screen with sub-screens which I attached as well.

Stopped at that point.

 

 

Fixlog.txt

post-181936-0-47571800-1421800536_thumb.

post-181936-0-13901000-1421800537_thumb.

post-181936-0-28584700-1421800538_thumb.

Link to post
Share on other sites

FRST.gif Scan with Farbar Recovery Scan Tool
 
Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.

  • Right-click on FRST.gif icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Make sure that Addition option is checked.
  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.

Please include their content into your next reply.

Link to post
Share on other sites

FRST.gif Fix with Farbar Recovery Scan Tool
 


icon_exclaim.gif This fix was created for this user for use on that particular machine. icon_exclaim.gif
icon_exclaim.gif Running it on another one may cause damage and render the system unstable. icon_exclaim.gif

 
Download attached fixlist.txt file and save it to the Desktop:
 
Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

  • Right-click on FRST.gif icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.

Please post it to your reply.

fixlist.txt

Link to post
Share on other sites

Ran Farbar Recovery Scan Tool with fixlist.txt.

Application ran and generated Fixlog.txt (attached) but bombed out - error shown below.

Re-booted and AVG Virus Program no longer recognized  - so I uninstalled and reinstalled.

Also had error (see below) re: Intel HD Audio Drivers - looks like they no longer install automatically.

Guess I'll have to reinstall at some point.

Good news is that iexplore.exe not running in background on it's own!

But when I do open Internet Explorer Window - one window - one tab -

It is showing two processes (iexplore.exe) running.

Not sure if this is normal or not?

Also, I have (8) svchost.exe running - dont remember having this many,

but not sure - normal?

thanks!

post-181936-0-11294700-1421875513_thumb.

post-181936-0-81632400-1421875519_thumb.

Fixlog.txt

Link to post
Share on other sites

I have other problems now.  My AVG anti-virus will not install. Bombs out. Error below.

Also, my desktop shortcuts do not work. Double click - no response.

My Internet Explorer isnt working right either. 

Can not drop down the address box - does not respond.

These are things I noticed immediately.

post-181936-0-44544700-1421879397_thumb.

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.