1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved Windows 7 Explorer fails on startup & wow.dll error message

Discussion in 'Malware and Virus Removal Archive' started by Woodstock1780, 2013/06/12.

  1. 2013/06/12
    Woodstock1780

    Woodstock1780 Inactive Thread Starter

    Joined:
    2013/06/12
    Messages:
    57
    Likes Received:
    0
    [Resolved] Windows 7 Explorer fails on startup & wow.dll error message

    This is my first post to get help. I have a similar problem to the post regarding wow.dll errors. When my system boots everything loads, but Windows Explorer will not load. I get the pop-up asking if I want to restart explorer and I click on that and explorer then starts but I get the error pop-up stating:

    There was a problem starting c:\users\DAVIDL~1\appdata\local\temp\spqvjee\sfrxqq\wow.dll
    Plus: A dynamic link library initialization routine failed.

    The message disappears after clicking "OKâ€, but if I right click on any icon or file it will reappear.

    I have run a complete Norton AV scan…clean. I have run a complete MBAR scan, no flags. I ran sfc \scannow and it came up clean.

    Per posting instructions I have run a dds and MBAM and saved the log files. dds is below.


    DDS (Ver_2012-11-20.01) - NTFS_AMD64
    Internet Explorer: 9.0.8112.16490
    Run by David Lee Volz at 16:29:28 on 2013-06-12
    Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.8151.6218 [GMT -4:00]
    .
    AV: Norton Internet Security *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
    SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    SP: Norton Internet Security *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
    FW: Norton Internet Security *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
    .
    ============== Running Processes ===============
    .
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\svchost.exe -k RPCSS
    C:\Windows\system32\atiesrxx.exe
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
    C:\Windows\system32\svchost.exe -k GPSvcGroup
    C:\Windows\system32\atieclxx.exe
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Windows\system32\svchost.exe -k apphost
    C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Windows\system32\taskhost.exe
    C:\Windows\system32\Dwm.exe
    C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe
    C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE
    C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE
    c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
    C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleCrashHandler.exe
    C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleCrashHandler64.exe
    C:\Windows\System32\spool\drivers\x64\3\WrtMon.exe
    C:\Program Files\Microsoft IntelliPoint\ipoint.exe
    C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
    C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe
    C:\Windows\System32\spool\drivers\x64\3\WrtProc.exe
    C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files (x86)\Microsoft Location Finder\LocationFinder.exe
    C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Windows\system32\vssvc.exe
    C:\Windows\system32\svchost.exe -k iissvcs
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    C:\Program Files (x86)\Audible\Bin\AudibleDownloadHelper.exe
    C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
    C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
    C:\Windows\SysWOW64\CTXFISPI.EXE
    C:\Program Files (x86)\iTunes\iTunesHelper.exe
    C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
    C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe
    C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
    C:\Windows\SysWOW64\Ctxfihlp.exe
    C:\ProgramData\Anti-phishing Domain Advisor\visicom_antiphishing.exe
    C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe
    C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
    C:\Windows\system32\SearchIndexer.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Windows\syswow64\rundll32.exe
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Windows\syswow64\svchost.exe -k netsvcs
    C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Windows\system32\svchost.exe -k SDRSVC
    C:\Windows\explorer.exe
    C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\cvh.exe
    C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe
    C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
    Q:\140066.enu\Office14\WINWORDC.EXE
    Q:\140066.enu\Office14\OffSpon.EXE
    C:\Windows\splwow64.exe
    C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_7_700_224_ActiveX.exe
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Windows\System32\cscript.exe
    .
    ============== Pseudo HJT Report ===============
    .
    uStart Page = hxxp://www.foxnews.com/index.html
    uSearch Bar = Preserve
    mWinlogon: Userinit = userinit.exe,
    BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    BHO: Norton Identity Protection: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\coieplg.dll
    BHO: Norton Vulnerability Protection: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ips\ipsbho.dll
    BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
    BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - <orphaned>
    BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\coieplg.dll
    uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    uRun: [Microsoft Location Finder] "C:\Program Files (x86)\Microsoft Location Finder\LocationFinder.exe "
    uRun: [EPSON Artisan 810 Series] C:\Windows\System32\spool\DRIVERS\x64\3\E_IATIFRA.EXE /FU "C:\Windows\TEMP\E_SFC1.tmp" /EF "HKCU "
    mRun: [EfficientCalendarFree] <no file>
    StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\AUDIBL~1.LNK - C:\Program Files (x86)\Audible\Bin\AudibleDownloadHelper.exe
    mPolicies-Explorer: NoActiveDesktop = dword:1
    mPolicies-Explorer: NoActiveDesktopChanges = dword:1
    mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
    mPolicies-System: ConsentPromptBehaviorUser = dword:3
    mPolicies-System: EnableUIADesktopToggle = dword:0
    IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
    DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/4.0.4.0/GarminAxControl_32.CAB
    DPF: {7A0D1738-10EA-47FF-92BE-4E137B5BE1A4} - hxxps://mpsnare.iesnare.com/StmOCX.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
    DPF: {C4B977A3-E8A2-37E9-ADCD-2597FAAC61F5} - hxxp://shop.lenovo.com/SEUILibrary/lenovo-portal/cab/autodetect/MachineInfo.cab
    DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
    DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPID.cab
    TCP: NameServer = 192.168.1.1
    TCP: Interfaces\{6328FF71-503A-4DFF-9A52-A0ED915F6959} : DHCPNameServer = 192.168.1.1
    Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
    SSODL: WebCheck - <orphaned>
    x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    x64-Run: [WrtMon.exe] C:\Windows\System32\spool\drivers\x64\3\WrtMon.exe
    x64-Run: [Logitech Download Assistant] C:\Windows\System32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
    x64-Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe "
    x64-Run: [hpsysdrv] c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe
    x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
    x64-SSODL: WebCheck - <orphaned>
    .
    ============= SERVICES / DRIVERS ===============
    .
    R0 SymDS;Symantec Data Store;C:\Windows\System32\drivers\NISx64\1404000.028\symds64.sys [2013-6-7 493656]
    R0 SymEFA;Symantec Extended File Attributes;C:\Windows\System32\drivers\NISx64\1404000.028\symefa64.sys [2013-6-7 1139800]
    R1 BHDrvx64;BHDrvx64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.1.22\Definitions\BASHDefs\20130531.001\BHDrvx64.sys [2013-5-31 1393240]
    R1 ccSet_NIS;Norton Internet Security Settings Manager;C:\Windows\System32\drivers\NISx64\1404000.028\ccsetx64.sys [2013-6-7 169048]
    R1 IDSVia64;IDSVia64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.1.22\Definitions\IPSDefs\20130611.001\IDSviA64.sys [2013-6-11 513184]
    R1 SymIRON;Symantec Iron Driver;C:\Windows\System32\drivers\NISx64\1404000.028\ironx64.sys [2013-6-7 224416]
    R1 SymNetS;Symantec Network Security WFP Driver;C:\Windows\System32\drivers\NISx64\1404000.028\symnets.sys [2013-6-7 433752]
    R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2010-11-6 237056]
    R2 CinemaNow Service;CinemaNow Service;C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemaNowSvc.exe [2010-6-12 400368]
    R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2010-2-28 821664]
    R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-11-6 13336]
    R2 NIS;Norton Internet Security;C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccsvchst.exe [2013-6-7 144368]
    R2 NOBU;Norton Online Backup;C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2010-6-1 2804568]
    R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2010-4-24 483688]
    R2 UNS;Intel(R) Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-11-6 2320920]
    R3 CT20XUT.SYS;CT20XUT.SYS;C:\Windows\System32\drivers\CT20XUT.sys [2010-7-7 230488]
    R3 CTEXFIFX.SYS;CTEXFIFX.SYS;C:\Windows\System32\drivers\CTEXFIFX.sys [2010-7-7 1445976]
    R3 CTHWIUT.SYS;CTHWIUT.SYS;C:\Windows\System32\drivers\CTHWIUT.sys [2010-7-7 95320]
    R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2013-4-22 138912]
    R3 ha20x22k;Creative 20X2 HAL Driver;C:\Windows\System32\drivers\ha20x22k.sys [2010-7-7 1612888]
    R3 HECIx64;Intel(R) Management Engine Interface;C:\Windows\System32\drivers\HECIx64.sys [2010-11-6 56344]
    R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2010-11-6 346144]
    R3 Sftfs;Sftfs;C:\Windows\System32\drivers\Sftfslh.sys [2010-4-24 721768]
    R3 Sftplay;Sftplay;C:\Windows\System32\drivers\Sftplaylh.sys [2010-4-24 269672]
    R3 Sftredir;Sftredir;C:\Windows\System32\drivers\Sftredirlh.sys [2010-4-24 25960]
    R3 Sftvol;Sftvol;C:\Windows\System32\drivers\Sftvollh.sys [2010-4-24 22376]
    R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2010-4-24 209768]
    S3 BTCFilterService;USB Networking Driver Filter Service;C:\Windows\System32\drivers\motfilt.sys [2009-1-29 6144]
    S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2010-11-6 79360]
    S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2010-11-6 79360]
    S3 CT20XUT;CT20XUT;C:\Windows\System32\drivers\CT20XUT.sys [2010-7-7 230488]
    S3 CTEXFIFX;CTEXFIFX;C:\Windows\System32\drivers\CTEXFIFX.sys [2010-7-7 1445976]
    S3 CTHWIUT;CTHWIUT;C:\Windows\System32\drivers\CTHWIUT.sys [2010-7-7 95320]
    S3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;C:\Windows\System32\drivers\LEqdUsb.sys [2010-8-24 74320]
    S3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;C:\Windows\System32\drivers\LHidEqd.sys [2010-8-24 13392]
    S3 motccgp;Motorola USB Composite Device Driver;C:\Windows\System32\drivers\motccgp.sys [2010-12-3 21504]
    S3 motccgpfl;MotCcgpFlService;C:\Windows\System32\drivers\motccgpfl.sys [2009-1-29 9216]
    S3 Motousbnet;Motorola USB Networking Driver Service;C:\Windows\System32\drivers\Motousbnet.sys [2010-4-1 26624]
    S3 motusbdevice;Motorola USB Dev Driver;C:\Windows\System32\drivers\motusbdevice.sys [2010-1-25 10240]
    S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2012-12-21 19456]
    S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136]
    S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2012-12-21 57856]
    S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2010-9-28 51712]
    S3 vpcuxd;USB Virtualization Stub Service;C:\Windows\System32\drivers\vpcuxd.sys [2011-3-16 16384]
    S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-11-15 1255736]
    .
    =============== Created Last 30 ================
    .
    2013-06-12 19:06:33 -------- d-----w- C:\ProgramData\Malwarebytes' Anti-Malware (portable)
    2013-06-12 11:28:18 751104 ----a-w- C:\Windows\System32\win32spl.dll
    2013-06-11 16:14:23 -------- d-----w- C:\Users\David Lee Volz\AppData\Local\VueSoft
    2013-06-11 13:41:28 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys
    2013-06-11 13:41:28 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
    2013-06-09 01:03:05 -------- d-----w- C:\Users\David Lee Volz\AppData\Roaming\Sunward Games
    2013-06-09 01:00:50 -------- d-----w- C:\Users\David Lee Volz\The Secret Order - Masked Intent Collectors Edition
    2013-06-08 00:11:58 796760 ----a-w- C:\Windows\System32\drivers\NISx64\1404000.028\srtsp64.sys
    2013-06-08 00:11:58 493656 ----a-w- C:\Windows\System32\drivers\NISx64\1404000.028\symds64.sys
    2013-06-08 00:11:58 433752 ----a-w- C:\Windows\System32\drivers\NISx64\1404000.028\symnets.sys
    2013-06-08 00:11:58 36952 ----a-w- C:\Windows\System32\drivers\NISx64\1404000.028\srtspx64.sys
    2013-06-08 00:11:58 23448 ----a-r- C:\Windows\System32\drivers\NISx64\1404000.028\symelam.sys
    2013-06-08 00:11:58 224416 ----a-w- C:\Windows\System32\drivers\NISx64\1404000.028\ironx64.sys
    2013-06-08 00:11:58 169048 ----a-w- C:\Windows\System32\drivers\NISx64\1404000.028\ccsetx64.sys
    2013-06-08 00:11:58 1139800 ----a-w- C:\Windows\System32\drivers\NISx64\1404000.028\symefa64.sys
    2013-06-08 00:11:51 -------- d-----w- C:\Windows\System32\drivers\NISx64\1404000.028
    2013-05-30 02:20:47 -------- d-----w- C:\ProgramData\Meridian93
    2013-05-30 01:46:58 -------- d-----w- C:\Users\David Lee Volz\AppData\Roaming\Meridian93
    2013-05-27 21:47:55 -------- d-----w- C:\Users\David Lee Volz\AppData\Roaming\Artifex Mundi
    2013-05-15 10:19:52 3153920 ----a-w- C:\Windows\System32\win32k.sys
    .
    ==================== Find3M ====================
    .
    2013-06-11 17:55:17 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
    2013-06-11 17:55:17 692104 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
    2013-06-10 20:56:46 177312 ----a-w- C:\Windows\System32\drivers\SYMEVENT64x86.SYS
    2013-05-17 03:09:56 2312704 ----a-w- C:\Windows\System32\jscript9.dll
    2013-05-17 03:02:29 1392128 ----a-w- C:\Windows\System32\wininet.dll
    2013-05-17 03:01:13 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl
    2013-05-17 02:56:09 173056 ----a-w- C:\Windows\System32\ieUnatt.exe
    2013-05-17 02:56:00 599040 ----a-w- C:\Windows\System32\vbscript.dll
    2013-05-17 02:51:27 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
    2013-05-16 22:39:39 1800704 ----a-w- C:\Windows\SysWow64\jscript9.dll
    2013-05-16 22:28:26 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll
    2013-05-16 22:27:30 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
    2013-05-16 22:21:37 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
    2013-05-16 22:20:30 420864 ----a-w- C:\Windows\SysWow64\vbscript.dll
    2013-05-16 22:16:57 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
    2013-05-13 05:51:01 184320 ----a-w- C:\Windows\System32\cryptsvc.dll
    2013-05-13 05:51:00 1464320 ----a-w- C:\Windows\System32\crypt32.dll
    2013-05-13 05:51:00 139776 ----a-w- C:\Windows\System32\cryptnet.dll
    2013-05-13 05:50:40 52224 ----a-w- C:\Windows\System32\certenc.dll
    2013-05-13 04:45:55 140288 ----a-w- C:\Windows\SysWow64\cryptsvc.dll
    2013-05-13 04:45:55 1160192 ----a-w- C:\Windows\SysWow64\crypt32.dll
    2013-05-13 04:45:55 103936 ----a-w- C:\Windows\SysWow64\cryptnet.dll
    2013-05-13 03:43:55 1192448 ----a-w- C:\Windows\System32\certutil.exe
    2013-05-13 03:08:10 903168 ----a-w- C:\Windows\SysWow64\certutil.exe
    2013-05-13 03:08:06 43008 ----a-w- C:\Windows\SysWow64\certenc.dll
    2013-05-10 05:49:27 30720 ----a-w- C:\Windows\System32\cryptdlg.dll
    2013-05-10 03:20:54 24576 ----a-w- C:\Windows\SysWow64\cryptdlg.dll
    2013-05-08 06:39:01 1910632 ----a-w- C:\Windows\System32\drivers\tcpip.sys
    2013-04-26 04:55:21 492544 ----a-w- C:\Windows\SysWow64\win32spl.dll
    2013-04-25 23:30:32 1505280 ----a-w- C:\Windows\SysWow64\d3d11.dll
    2013-04-17 07:02:06 1230336 ----a-w- C:\Windows\SysWow64\WindowsCodecs.dll
    2013-04-17 06:24:46 1424384 ----a-w- C:\Windows\System32\WindowsCodecs.dll
    2013-04-13 05:49:23 135168 ----a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
    2013-04-13 05:49:19 350208 ----a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
    2013-04-13 05:49:19 308736 ----a-w- C:\Windows\apppatch\AppPatch64\AcGenral.dll
    2013-04-13 05:49:19 111104 ----a-w- C:\Windows\apppatch\AppPatch64\acspecfc.dll
    2013-04-13 04:45:16 474624 ----a-w- C:\Windows\apppatch\AcSpecfc.dll
    2013-04-13 04:45:15 2176512 ----a-w- C:\Windows\apppatch\AcGenral.dll
    2013-04-12 14:45:08 1656680 ----a-w- C:\Windows\System32\drivers\ntfs.sys
    2013-04-10 06:01:54 265064 ----a-w- C:\Windows\System32\drivers\dxgmms1.sys
    2013-04-10 06:01:53 983400 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys
    2013-03-31 22:52:16 1887232 ----a-w- C:\Windows\System32\d3d11.dll
    2013-03-19 06:04:06 5550424 ----a-w- C:\Windows\System32\ntoskrnl.exe
    2013-03-19 05:53:58 48640 ----a-w- C:\Windows\System32\wwanprotdim.dll
    2013-03-19 05:53:58 230400 ----a-w- C:\Windows\System32\wwansvc.dll
    2013-03-19 05:46:56 43520 ----a-w- C:\Windows\System32\csrsrv.dll
    2013-03-19 05:04:13 3968856 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
    2013-03-19 05:04:10 3913560 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
    2013-03-19 04:47:50 6656 ----a-w- C:\Windows\SysWow64\apisetschema.dll
    2013-03-19 03:06:33 112640 ----a-w- C:\Windows\System32\smss.exe
    2010-09-02 20:17:36 15872 ----a-w- C:\Program Files (x86)\Common Files\JH_Killer.exe
    .
    ============= FINISH: 16:30:08.06 ===============
     
  2. 2013/06/12
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Welcome aboard [​IMG]

    Please, complete all steps listed HERE

    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running any tools, fixes or applying any changes to your computer other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.
     

  3. to hide this advert.

  4. 2013/06/12
    Woodstock1780

    Woodstock1780 Inactive Thread Starter

    Joined:
    2013/06/12
    Messages:
    57
    Likes Received:
    0
    Steps 1,2 & 3

    Step #1:
    Malwarebytes Anti-Malware 1.75.0.1300
    www.malwarebytes.org

    Database version: v2013.06.11.04

    Windows 7 Service Pack 1 x64 NTFS
    Internet Explorer 9.0.8112.16421
    David Lee Volz :: DAVIDLEEVOLZ-HP [administrator]

    6/12/2013 7:56:43 PM
    mbam-log-2013-06-12 (19-56-43).txt

    Scan type: Quick scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 267567
    Time elapsed: 3 minute(s), 18 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 0
    (No malicious items detected)

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 0
    (No malicious items detected)

    (end)

    Step #2 DDS run and is in initial post
    Step #3 Topic started with original post
     
  5. 2013/06/13
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Please pay attention.

    I still need Attach.txt part of DDS.
     
  6. 2013/06/13
    Woodstock1780

    Woodstock1780 Inactive Thread Starter

    Joined:
    2013/06/12
    Messages:
    57
    Likes Received:
    0
    sorry....thought I copied it all.

    .
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT
    .
    DDS (Ver_2012-11-20.01)
    .
    Microsoft Windows 7 Professional
    Boot Device: \Device\HarddiskVolume1
    Install Date: 11/13/2010 3:55:50 PM
    System Uptime: 6/12/2013 3:34:33 PM (1 hours ago)
    .
    Motherboard: MSI | | 2A9C
    Processor: Intel(R) Core(TM) i5 CPU 760 @ 2.80GHz | CPU 1 | 2801/133mhz
    .
    ==== Disk Partitions =========================
    .
    C: is FIXED (NTFS) - 686 GiB total, 595.252 GiB free.
    D: is FIXED (NTFS) - 12 GiB total, 1.519 GiB free.
    E: is CDROM ()
    F: is Removable
    G: is Removable
    H: is Removable
    I: is Removable
    J: is Removable
    .
    ==== Disabled Device Manager Items =============
    .
    Class GUID: {eec5ad98-8080-425f-922a-dabf3de3f69a}
    Description: MS/MS-Pro
    Device ID: WPDBUSENUMROOT\UMB\2&37C186B&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_GENERIC-&PROD_MS#MS-PRO&REV_1.03#058F63626476&3#
    Manufacturer: Generic-
    Name: I:\
    PNP Device ID: WPDBUSENUMROOT\UMB\2&37C186B&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_GENERIC-&PROD_MS#MS-PRO&REV_1.03#058F63626476&3#
    Service: WUDFRd
    .
    Class GUID: {eec5ad98-8080-425f-922a-dabf3de3f69a}
    Description: SD/MMC
    Device ID: WPDBUSENUMROOT\UMB\2&37C186B&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_GENERIC-&PROD_SD#MMC&REV_1.00#058F63626476&0#
    Manufacturer: Generic-
    Name: F:\
    PNP Device ID: WPDBUSENUMROOT\UMB\2&37C186B&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_GENERIC-&PROD_SD#MMC&REV_1.00#058F63626476&0#
    Service: WUDFRd
    .
    Class GUID: {eec5ad98-8080-425f-922a-dabf3de3f69a}
    Description: SM/xD-Picture
    Device ID: WPDBUSENUMROOT\UMB\2&37C186B&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_GENERIC-&PROD_SM#XD-PICTURE&REV_1.02#058F63626476&2#
    Manufacturer: Generic-
    Name: H:\
    PNP Device ID: WPDBUSENUMROOT\UMB\2&37C186B&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_GENERIC-&PROD_SM#XD-PICTURE&REV_1.02#058F63626476&2#
    Service: WUDFRd
    .
    Class GUID: {eec5ad98-8080-425f-922a-dabf3de3f69a}
    Description: Storage
    Device ID: WPDBUSENUMROOT\UMB\2&37C186B&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_EPSON&PROD_STORAGE&REV_1.00#8&10A00265&0&4C4A44593138393926&0#
    Manufacturer: EPSON
    Name: J:\
    PNP Device ID: WPDBUSENUMROOT\UMB\2&37C186B&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_EPSON&PROD_STORAGE&REV_1.00#8&10A00265&0&4C4A44593138393926&0#
    Service: WUDFRd
    .
    Class GUID: {eec5ad98-8080-425f-922a-dabf3de3f69a}
    Description: Compact Flash
    Device ID: WPDBUSENUMROOT\UMB\2&37C186B&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_GENERIC-&PROD_COMPACT_FLASH&REV_1.01#058F63626476&1#
    Manufacturer: Generic-
    Name: G:\
    PNP Device ID: WPDBUSENUMROOT\UMB\2&37C186B&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_GENERIC-&PROD_COMPACT_FLASH&REV_1.01#058F63626476&1#
    Service: WUDFRd
    .
    ==== System Restore Points ===================
    .
    RP552: 6/12/2013 7:28:23 AM - Windows Update
    RP553: 6/12/2013 7:43:13 AM - Windows Update
    .
    ==== Installed Programs ======================
    .
    ActiveCheck component for HP Active Support Library
    Adobe AIR
    Adobe Flash Player 11 ActiveX
    Adobe Reader X
    AnswerWorks 5.0 English Runtime
    Anti-phishing Domain Advisor
    Apple Application Support
    Apple Mobile Device Support
    Apple Software Update
    ATI Catalyst Install Manager
    Audible Download Manager
    Big Fish Games: Game Manager
    Bing Bar
    Bing Bar Platform
    Bonjour
    Catalyst Control Center - Branding
    Catalyst Control Center Graphics Previews Common
    Catalyst Control Center Graphics Previews Vista
    Catalyst Control Center InstallProxy
    Catalyst Control Center Localization All
    ccc-core-static
    ccc-utility64
    CCC Help Chinese Standard
    CCC Help Chinese Traditional
    CCC Help Czech
    CCC Help Danish
    CCC Help Dutch
    CCC Help English
    CCC Help Finnish
    CCC Help French
    CCC Help German
    CCC Help Greek
    CCC Help Hungarian
    CCC Help Italian
    CCC Help Japanese
    CCC Help Korean
    CCC Help Norwegian
    CCC Help Polish
    CCC Help Portuguese
    CCC Help Russian
    CCC Help Spanish
    CCC Help Swedish
    CCC Help Thai
    CCC Help Turkish
    CCleaner
    CinemaNow Media Manager
    Cisco Connect
    Creative Audio Control Panel
    Creative Software AutoUpdate
    Creative Sound Blaster Properties x64 Edition
    CyberLink DVD Suite Deluxe
    D3DX10
    Dolby Digital Live Pack
    DVD Menu Pack for HP MediaSmart Video
    Efficient Calendar Free 3.10
    EPSON Artisan 810 Series Printer Uninstall
    Epson Event Manager
    Epson FAX Utility
    Epson Print CD
    EPSON Scan
    eReg
    erLT
    FBReader for Windows
    Feedback Tool
    ffdshow (remove only)
    Garmin WebUpdater
    GIMP 2.6.11
    Google Earth
    Google Update Helper
    Haali Media Splitter
    HP Advisor
    HP Customer Experience Enhancements
    HP MediaSmart CinemaNow 2.0
    HP MediaSmart DVD
    HP MediaSmart Music
    HP MediaSmart Photo
    HP MediaSmart SmartMenu
    HP MediaSmart Video
    HP MediaSmart/TouchSmart Netflix
    HP Odometer
    HP Product Detection
    HP Setup
    HP Support Assistant
    HP Support Information
    HP Update
    HP Vision Hardware Diagnostics
    HPAsset component for HP Active Support Library
    HydraVision
    Intel(R) Management Engine Components
    Intel(R) Rapid Storage Technology
    iTunes
    Jackson Illustrator
    Java Auto Updater
    Java(TM) 6 Update 29
    Java(TM) 6 Update 31
    JH Illustrator Crystal Report net
    Junk Mail filter update
    Kobo
    LabelPrint
    Legacy 7.5
    LightScribe System Software
    LTCM Client
    Malwarebytes Anti-Malware version 1.75.0.1300
    Microsoft Application Error Reporting
    Microsoft Default Manager
    Microsoft IntelliPoint 8.0
    Microsoft Location Finder
    Microsoft Office 2010
    Microsoft Office Click-to-Run 2010
    Microsoft Office PowerPoint Viewer 2007 (English)
    Microsoft Office Starter 2010 - English
    Microsoft PowerPoint Viewer
    Microsoft Search Enhancement Pack
    Microsoft Silverlight
    Microsoft SQL Server 2005 Compact Edition [ENU]
    Microsoft Streets & Trips 2006
    Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2005 Redistributable - KB2467175
    Microsoft Visual C++ 2005 Redistributable (x64)
    Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175
    Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
    Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    Microsoft WSE 3.0 Runtime
    Microsoft XML Parser
    MotoHelper MergeModules
    Motorola Mobile Drivers Installation 5.0.0
    Movie Theme Pack for HP MediaSmart Video
    Mozilla Maintenance Service
    Mozilla Thunderbird 17.0.6 (x86 en-US)
    MSVCRT
    MSVCRT_amd64
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    MSXML 4.0 SP2 Parser and SDK
    Mutual of Omaha
    Mutual of Omaha - Health
    Mutual of Omaha Health Company install
    Norton Internet Security
    Norton Online Backup
    OpenAL
    PhotoNow!
    PhotoScape
    PictureMover
    PlayReady PC Runtime amd64
    Power2Go
    PowerDirector
    PressReader
    Presto! PageManager 8.15.01 SE
    Prudential LTC3 Illustration System
    Quicken 2010
    QuickTime
    Quote It!
    Recovery Manager
    Rhapsody
    Roxio CinemaNow 2.0
    Sound Blaster X-Fi
    The Lost Crown version 2
    The Secret Order: Masked Intent Collector's Edition
    Transamerica Life Products Illustration System - TransWare
    Transamerica Life Products Illustration System TransWare Prerequisite V 2.0
    Transamerica Life Products Illustration System TransWare Prerequisite V3.0
    VideoBrowser
    VueMinder Lite
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live ID Sign-in Assistant
    Windows Live Installer
    Windows Live Language Selector
    Windows Live Mail
    Windows Live Messenger
    Windows Live MIME IFilter
    Windows Live Movie Maker
    Windows Live Photo Common
    Windows Live Photo Gallery
    Windows Live PIMT Platform
    Windows Live SOXE
    Windows Live SOXE Definitions
    Windows Live Sync
    Windows Live UX Platform
    Windows Live UX Platform Language Pack
    Windows Live Writer
    Windows Live Writer Resources
    Windows XP Mode
    WinFlex 6
    Yontoo 1.10.02
    Zinio Reader 4
    .
    ==== Event Viewer Messages From Past Week ========
    .
    6/12/2013 3:35:05 PM, Error: Service Control Manager [7000] - The MCSTRM service failed to start due to the following error: The system cannot find the file specified.
    6/12/2013 2:18:26 PM, Error: Microsoft-Windows-Bits-Client [16398] - A new BITS job could not be created. The current job count for the user DavidLeeVolz-HP\David Lee Volz (60) is equal to or greater than the job limit (60) specified through group policy. To correct the problem, complete or cancel the BITS jobs that haven't made progress by looking at the error, and restart the BITS service. If this error recurs, contact your system administrator and increate the per-user and per-computer Group Policy job limits.
    6/11/2013 5:01:47 PM, Error: volsnap [14] - The shadow copies of volume C: were aborted because of an IO failure on volume C:.
    6/11/2013 12:35:01 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Management Instrumentation service, but this action failed with the following error: An instance of the service is already running.
    6/11/2013 12:35:01 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Multimedia Class Scheduler service, but this action failed with the following error: An instance of the service is already running.
    6/11/2013 12:35:01 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the IKE and AuthIP IPsec Keying Modules service, but this action failed with the following error: An instance of the service is already running.
    6/11/2013 12:34:01 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Server service, but this action failed with the following error: An instance of the service is already running.
    6/11/2013 12:33:01 PM, Error: Service Control Manager [7031] - The Windows Management Instrumentation service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
    6/11/2013 12:33:01 PM, Error: Service Control Manager [7031] - The User Profile Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
    6/11/2013 12:33:01 PM, Error: Service Control Manager [7031] - The Themes service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    6/11/2013 12:33:01 PM, Error: Service Control Manager [7031] - The Task Scheduler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    6/11/2013 12:33:01 PM, Error: Service Control Manager [7031] - The System Event Notification Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
    6/11/2013 12:33:01 PM, Error: Service Control Manager [7031] - The Shell Hardware Detection service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    6/11/2013 12:33:01 PM, Error: Service Control Manager [7031] - The Server service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    6/11/2013 12:33:01 PM, Error: Service Control Manager [7031] - The Multimedia Class Scheduler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
    6/11/2013 12:33:01 PM, Error: Service Control Manager [7031] - The IP Helper service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
    6/11/2013 12:33:01 PM, Error: Service Control Manager [7031] - The IKE and AuthIP IPsec Keying Modules service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
    6/11/2013 12:11:41 PM, Error: Service Control Manager [7001] - The Task Scheduler service depends on the Windows Event Log service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
    6/11/2013 11:57:07 AM, Error: Microsoft-Windows-DistributedCOM [10016] - The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {000C101C-0000-0000-C000-000000000046} and APPID {000C101C-0000-0000-C000-000000000046} to the user DavidLeeVolz-HP\David Lee Volz SID (S-1-5-21-1975598971-2761070460-1008015774-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
    .
    ==== End Of File ===========================
     
  7. 2013/06/13
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    [​IMG] Download RogueKiller for 32bit or Roguekiller for 64bit to your Desktop.
    • Close all the running programs
    • Windows Vista/7 users: right click on RogueKiller.exe, click Run as Administrator
    • Otherwise just double-click on RogueKiller.exe
    • Pre-scan will start. Let it finish.
    • Click on SCAN button.
    • Wait until the Status box shows Scan Finished
    • Click on Delete.
    • Wait until the Status box shows Deleting Finished.
    • Click on Report and copy/paste the content of the Notepad into your next reply.
    • RKreport.txt could also be found on your desktop.
    • If more than one log is produced post all logs.
    • If RogueKiller has been blocked, do not hesitate to try a few times more. If really won't run, rename it to winlogon.exe (or winlogon.com) and try again

    [​IMG] Create new restore point before proceeding with the next step....
    How to:
    - Windows 8: http://www.vikitech.com/11302/system-restore-windows-8
    - Windows 7: http://www.howtogeek.com/howto/3195/create-a-system-restore-point-in-windows-7/
    - Vista: http://www.howtogeek.com/howto/wind...tore-point-for-windows-vistas-system-restore/
    - XP: http://support.microsoft.com/kb/948247

    Download Malwarebytes Anti-Rootkit (MBAR) from HERE
    • Unzip downloaded file.
    • Open the folder where the contents were unzipped and run mbar.exe
    • Follow the instructions in the wizard to update and allow the program to scan your computer for threats.
    • Click on the Cleanup button to remove any threats and reboot if prompted to do so.
    • Wait while the system shuts down and the cleanup process is performed.
    • Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
    • When done, please post the two logs produced they will be in the MBAR folder..... mbar-log-xxxxx.txt and system-log.txt

    ===========================================================
    Note: <<<< - very important - please do this step:
    If no additional threats were found, verify that your system is now running normally, making sure that the following items are functional:
    Internet access
    Windows Update
    Windows Firewall
    (if used)
    If there are additional problems with your system, such as any of those listed above or other system issues, then run the fixdamage tool included with Malwarebytes Anti-Rootkit located in the mbar\plugins folder and reboot.
    Verify that your system is now functioning normally.
     
  8. 2013/06/13
    Woodstock1780

    Woodstock1780 Inactive Thread Starter

    Joined:
    2013/06/12
    Messages:
    57
    Likes Received:
    0
    broni, I downloaded RogueKiller, it started the prescan then locked up at rundll32.exe..been at this point for 10 minutes.
     
  9. 2013/06/13
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    You can try safe mode as well.
     
  10. 2013/06/13
    Woodstock1780

    Woodstock1780 Inactive Thread Starter

    Joined:
    2013/06/12
    Messages:
    57
    Likes Received:
    0
    I renamed ... no go. Rebooted in safe mode but cannot do anything in safe mode...just get the rotating load circle. Have attemted this 3 times.
     
  11. 2013/06/13
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Go ahead with MBAR.
     
  12. 2013/06/13
    Woodstock1780

    Woodstock1780 Inactive Thread Starter

    Joined:
    2013/06/12
    Messages:
    57
    Likes Received:
    0
    nothing found:

    --------------------------------------
    Malwarebytes Anti-Rootkit BETA 1.06.0.1003

    (c) Malwarebytes Corporation 2011-2012

    OS version: 6.1.7601 Windows 7 Service Pack 1 x64

    Account is Administrative

    Internet Explorer version: 9.0.8112.16421

    Java version: 1.6.0_31

    File system is: NTFS
    Disk drives: C:\ DRIVE_FIXED, D:\ DRIVE_FIXED, Q:\ DRIVE_FIXED
    CPU speed: 2.793000 GHz
    Memory total: 8547024896, free: 6685614080

    Downloaded database version: v2013.06.13.09
    Downloaded database version: v2013.05.22.01
    Initializing...
    ------------ Kernel report ------------
    06/13/2013 20:12:59
    ------------ Loaded modules -----------
    \SystemRoot\system32\ntoskrnl.exe
    \SystemRoot\system32\hal.dll
    \SystemRoot\system32\kdcom.dll
    \SystemRoot\system32\mcupdate_GenuineIntel.dll
    \SystemRoot\system32\PSHED.dll
    \SystemRoot\system32\CLFS.SYS
    \SystemRoot\system32\CI.dll
    \SystemRoot\system32\drivers\Wdf01000.sys
    \SystemRoot\system32\drivers\WDFLDR.SYS
    \SystemRoot\system32\drivers\ACPI.sys
    \SystemRoot\system32\drivers\WMILIB.SYS
    \SystemRoot\system32\drivers\msisadrv.sys
    \SystemRoot\system32\drivers\pci.sys
    \SystemRoot\system32\drivers\vdrvroot.sys
    \SystemRoot\System32\drivers\partmgr.sys
    \SystemRoot\system32\drivers\volmgr.sys
    \SystemRoot\System32\drivers\volmgrx.sys
    \SystemRoot\System32\drivers\mountmgr.sys
    \SystemRoot\system32\drivers\vmbus.sys
    \SystemRoot\system32\drivers\winhv.sys
    \SystemRoot\system32\DRIVERS\iaStor.sys
    \SystemRoot\system32\drivers\amdxata.sys
    \SystemRoot\system32\drivers\fltmgr.sys
    \SystemRoot\system32\drivers\NISx64\1404000.028\SYMDS64.SYS
    \SystemRoot\system32\drivers\fileinfo.sys
    \SystemRoot\system32\drivers\NISx64\1404000.028\SYMEFA64.SYS
    \SystemRoot\System32\Drivers\Ntfs.sys
    \SystemRoot\System32\Drivers\msrpc.sys
    \SystemRoot\System32\Drivers\ksecdd.sys
    \SystemRoot\System32\Drivers\cng.sys
    \SystemRoot\System32\drivers\pcw.sys
    \SystemRoot\System32\Drivers\Fs_Rec.sys
    \SystemRoot\system32\drivers\ndis.sys
    \SystemRoot\system32\drivers\NETIO.SYS
    \SystemRoot\System32\Drivers\ksecpkg.sys
    \SystemRoot\System32\drivers\tcpip.sys
    \SystemRoot\System32\drivers\fwpkclnt.sys
    \SystemRoot\system32\drivers\vmstorfl.sys
    \SystemRoot\system32\drivers\volsnap.sys
    \SystemRoot\System32\Drivers\spldr.sys
    \SystemRoot\System32\drivers\rdyboost.sys
    \SystemRoot\System32\Drivers\mup.sys
    \SystemRoot\System32\drivers\hwpolicy.sys
    \SystemRoot\System32\DRIVERS\fvevol.sys
    \SystemRoot\system32\DRIVERS\disk.sys
    \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
    \SystemRoot\system32\DRIVERS\cdrom.sys
    \SystemRoot\system32\drivers\NISx64\1404000.028\ccSetx64.sys
    \SystemRoot\System32\Drivers\NISx64\1404000.028\SRTSP64.SYS
    \SystemRoot\system32\drivers\NISx64\1404000.028\SRTSPX64.SYS
    \SystemRoot\system32\drivers\NISx64\1404000.028\Ironx64.SYS
    \??\C:\Windows\system32\Drivers\SYMEVENT64x86.SYS
    \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.1.22\Definitions\VirusDefs\20130613.001\EX64.SYS
    \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.1.22\Definitions\VirusDefs\20130613.001\ENG64.SYS
    \SystemRoot\System32\Drivers\Null.SYS
    \SystemRoot\System32\Drivers\Beep.SYS
    \SystemRoot\System32\drivers\vga.sys
    \SystemRoot\System32\drivers\VIDEOPRT.SYS
    \SystemRoot\System32\drivers\watchdog.sys
    \SystemRoot\System32\DRIVERS\RDPCDD.sys
    \SystemRoot\system32\drivers\rdpencdd.sys
    \SystemRoot\system32\drivers\rdprefmp.sys
    \SystemRoot\System32\Drivers\Msfs.SYS
    \SystemRoot\System32\Drivers\Npfs.SYS
    \SystemRoot\system32\DRIVERS\tdx.sys
    \SystemRoot\system32\DRIVERS\TDI.SYS
    \SystemRoot\system32\drivers\afd.sys
    \SystemRoot\System32\DRIVERS\netbt.sys
    \SystemRoot\system32\DRIVERS\wfplwf.sys
    \SystemRoot\system32\DRIVERS\pacer.sys
    \SystemRoot\system32\DRIVERS\vpcnfltr.sys
    \SystemRoot\system32\DRIVERS\netbios.sys
    \SystemRoot\system32\DRIVERS\wanarp.sys
    \SystemRoot\system32\drivers\vpcvmm.sys
    \SystemRoot\system32\drivers\termdd.sys
    \SystemRoot\System32\Drivers\NISx64\1404000.028\SYMNETS.SYS
    \SystemRoot\system32\DRIVERS\rdbss.sys
    \SystemRoot\system32\drivers\nsiproxy.sys
    \SystemRoot\system32\drivers\mssmbios.sys
    \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.1.22\Definitions\IPSDefs\20130613.001\IDSvia64.sys
    \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys
    \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
    \SystemRoot\System32\drivers\discache.sys
    \SystemRoot\system32\drivers\csc.sys
    \SystemRoot\System32\Drivers\dfsc.sys
    \SystemRoot\system32\DRIVERS\blbdrive.sys
    \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.1.22\Definitions\BASHDefs\20130531.001\BHDrvx64.sys
    \SystemRoot\system32\DRIVERS\tunnel.sys
    \SystemRoot\system32\DRIVERS\intelppm.sys
    \SystemRoot\system32\DRIVERS\atikmpag.sys
    \SystemRoot\system32\DRIVERS\atikmdag.sys
    \SystemRoot\System32\drivers\dxgkrnl.sys
    \SystemRoot\System32\drivers\dxgmms1.sys
    \SystemRoot\system32\drivers\HDAudBus.sys
    \SystemRoot\system32\DRIVERS\HECIx64.sys
    \SystemRoot\system32\drivers\usbehci.sys
    \SystemRoot\system32\drivers\USBPORT.SYS
    \SystemRoot\system32\DRIVERS\Rt64win7.sys
    \SystemRoot\system32\drivers\1394ohci.sys
    \SystemRoot\system32\drivers\ctaud2k.sys
    \SystemRoot\system32\drivers\portcls.sys
    \SystemRoot\system32\drivers\drmk.sys
    \SystemRoot\system32\drivers\ks.sys
    \SystemRoot\system32\drivers\ctoss2k.sys
    \SystemRoot\system32\drivers\ctprxy2k.sys
    \SystemRoot\system32\drivers\ksthunk.sys
    \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
    \SystemRoot\system32\drivers\wmiacpi.sys
    \SystemRoot\system32\drivers\CompositeBus.sys
    \SystemRoot\system32\DRIVERS\AgileVpn.sys
    \SystemRoot\system32\DRIVERS\rasl2tp.sys
    \SystemRoot\system32\DRIVERS\ndistapi.sys
    \SystemRoot\system32\DRIVERS\ndiswan.sys
    \SystemRoot\system32\DRIVERS\raspppoe.sys
    \SystemRoot\system32\DRIVERS\raspptp.sys
    \SystemRoot\system32\DRIVERS\rassstp.sys
    \SystemRoot\system32\DRIVERS\rdpbus.sys
    \SystemRoot\system32\DRIVERS\kbdclass.sys
    \SystemRoot\system32\DRIVERS\mouclass.sys
    \SystemRoot\system32\drivers\swenum.sys
    \SystemRoot\system32\drivers\umbus.sys
    \SystemRoot\system32\DRIVERS\vpcusb.sys
    \SystemRoot\system32\DRIVERS\usbrpm.sys
    \SystemRoot\system32\DRIVERS\USBD.SYS
    \SystemRoot\system32\DRIVERS\vpchbus.sys
    \SystemRoot\system32\DRIVERS\usbhub.sys
    \SystemRoot\System32\Drivers\NDProxy.SYS
    \SystemRoot\system32\drivers\ha20x22k.sys
    \SystemRoot\system32\drivers\emupia2k.sys
    \SystemRoot\system32\drivers\ctsfm2k.sys
    \SystemRoot\System32\drivers\CTHWIUT.SYS
    \SystemRoot\System32\drivers\CT20XUT.SYS
    \SystemRoot\System32\drivers\CTEXFIFX.SYS
    \SystemRoot\system32\drivers\AtiHdmi.sys
    \SystemRoot\System32\win32k.sys
    \SystemRoot\System32\drivers\Dxapi.sys
    \SystemRoot\system32\DRIVERS\usbccgp.sys
    \SystemRoot\system32\DRIVERS\usbscan.sys
    \SystemRoot\system32\DRIVERS\usbprint.sys
    \SystemRoot\system32\DRIVERS\USBSTOR.SYS
    \SystemRoot\system32\DRIVERS\dc3d.sys
    \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
    \SystemRoot\system32\DRIVERS\dot4usb.sys
    \SystemRoot\system32\DRIVERS\Dot4.sys
    \SystemRoot\system32\DRIVERS\hidusb.sys
    \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
    \SystemRoot\system32\drivers\Dot4Prt.sys
    \SystemRoot\system32\DRIVERS\kbdhid.sys
    \SystemRoot\system32\DRIVERS\mouhid.sys
    \SystemRoot\system32\DRIVERS\point64.sys
    \SystemRoot\system32\DRIVERS\Dot4Scan.sys
    \SystemRoot\System32\Drivers\crashdmp.sys
    \SystemRoot\System32\Drivers\dump_iaStor.sys
    \SystemRoot\System32\Drivers\dump_dumpfve.sys
    \SystemRoot\system32\DRIVERS\monitor.sys
    \SystemRoot\System32\TSDDD.dll
    \SystemRoot\System32\cdd.dll
    \SystemRoot\System32\ATMFD.DLL
    \SystemRoot\system32\drivers\luafv.sys
    \SystemRoot\system32\DRIVERS\Sftvollh.sys
    \SystemRoot\system32\DRIVERS\lltdio.sys
    \SystemRoot\system32\DRIVERS\rspndr.sys
    \SystemRoot\system32\drivers\HTTP.sys
    \SystemRoot\system32\DRIVERS\bowser.sys
    \SystemRoot\System32\drivers\mpsdrv.sys
    \SystemRoot\system32\DRIVERS\mrxsmb.sys
    \SystemRoot\system32\DRIVERS\mrxsmb10.sys
    \SystemRoot\system32\DRIVERS\mrxsmb20.sys
    \SystemRoot\system32\drivers\peauth.sys
    \SystemRoot\System32\Drivers\secdrv.SYS
    \SystemRoot\system32\DRIVERS\Sftfslh.sys
    \SystemRoot\system32\DRIVERS\Sftplaylh.sys
    \SystemRoot\System32\DRIVERS\srvnet.sys
    \SystemRoot\System32\drivers\tcpipreg.sys
    \SystemRoot\System32\DRIVERS\srv2.sys
    \SystemRoot\System32\DRIVERS\srv.sys
    \SystemRoot\system32\DRIVERS\Sftredirlh.sys
    \SystemRoot\system32\drivers\spsys.sys
    \??\C:\Windows\system32\drivers\mbamchameleon.sys
    \??\C:\Windows\system32\drivers\mbamswissarmy.sys
    \Windows\System32\ntdll.dll
    \Windows\System32\smss.exe
    \Windows\System32\apisetschema.dll
    \Windows\System32\autochk.exe
    \Windows\System32\comdlg32.dll
    \Windows\System32\gdi32.dll
    \Windows\System32\imagehlp.dll
    \Windows\System32\shlwapi.dll
    \Windows\System32\wininet.dll
    \Windows\System32\kernel32.dll
    \Windows\System32\difxapi.dll
    \Windows\System32\ole32.dll
    \Windows\System32\shell32.dll
    \Windows\System32\nsi.dll
    \Windows\System32\setupapi.dll
    \Windows\System32\clbcatq.dll
    \Windows\System32\Wldap32.dll
    \Windows\System32\user32.dll
    \Windows\System32\msctf.dll
    \Windows\System32\msvcrt.dll
    \Windows\System32\psapi.dll
    \Windows\System32\urlmon.dll
    \Windows\System32\oleaut32.dll
    \Windows\System32\usp10.dll
    \Windows\System32\ws2_32.dll
    \Windows\System32\lpk.dll
    \Windows\System32\imm32.dll
    \Windows\System32\rpcrt4.dll
    \Windows\System32\iertutil.dll
    \Windows\System32\advapi32.dll
    \Windows\System32\normaliz.dll
    \Windows\System32\sechost.dll
    \Windows\System32\cfgmgr32.dll
    \Windows\System32\wintrust.dll
    \Windows\System32\comctl32.dll
    \Windows\System32\KernelBase.dll
    \Windows\System32\crypt32.dll
    \Windows\System32\devobj.dll
    \Windows\System32\msasn1.dll
    \Windows\SysWOW64\normaliz.dll
    ----------- End -----------
    Done!
    <<<1>>>
    Upper Device Name: \Device\Harddisk5\DR5
    Upper Device Object: 0xfffffa800ca6b060
    Upper Device Driver Name: \Driver\Disk\
    Lower Device Name: \Device\0000009f\
    Lower Device Object: 0xfffffa800c7c6b60
    Lower Device Driver Name: \Driver\USBSTOR\
    <<<1>>>
    Upper Device Name: \Device\Harddisk4\DR4
    Upper Device Object: 0xfffffa800ca6a060
    Upper Device Driver Name: \Driver\Disk\
    Lower Device Name: \Device\0000009e\
    Lower Device Object: 0xfffffa800c7c8b60
    Lower Device Driver Name: \Driver\USBSTOR\
    <<<1>>>
    Upper Device Name: \Device\Harddisk3\DR3
    Upper Device Object: 0xfffffa800c91c060
    Upper Device Driver Name: \Driver\Disk\
    Lower Device Name: \Device\0000009d\
    Lower Device Object: 0xfffffa800c7c7b60
    Lower Device Driver Name: \Driver\USBSTOR\
    <<<1>>>
    Upper Device Name: \Device\Harddisk2\DR2
    Upper Device Object: 0xfffffa800ca61060
    Upper Device Driver Name: \Driver\Disk\
    Lower Device Name: \Device\0000009c\
    Lower Device Object: 0xfffffa800c7c0b60
    Lower Device Driver Name: \Driver\USBSTOR\
    <<<1>>>
    Upper Device Name: \Device\Harddisk1\DR1
    Upper Device Object: 0xfffffa800c8f6060
    Upper Device Driver Name: \Driver\Disk\
    Lower Device Name: \Device\00000082\
    Lower Device Object: 0xfffffa800c70eb60
    Lower Device Driver Name: \Driver\USBSTOR\
    <<<1>>>
    Upper Device Name: \Device\Harddisk0\DR0
    Upper Device Object: 0xfffffa8007ad2060
    Upper Device Driver Name: \Driver\Disk\
    Lower Device Name: \Device\Ide\IAAStorageDevice-1\
    Lower Device Object: 0xfffffa80077e0050
    Lower Device Driver Name: \Driver\iaStor\
    <<<2>>>
    Device number: 0, partition: 2
    Physical Sector Size: 512
    Drive: 0, DevicePointer: 0xfffffa8007ad2060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
    --------- Disk Stack ------
    DevicePointer: 0xfffffa8007ad2b90, DeviceName: Unknown, DriverName: \Driver\partmgr\
    DevicePointer: 0xfffffa8007ad2060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
    DevicePointer: 0xfffffa80077e0050, DeviceName: \Device\Ide\IAAStorageDevice-1\, DriverName: \Driver\iaStor\
    ------------ End ----------
    Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
    Upper DeviceData: 0x0, 0x0, 0x0
    Lower DeviceData: 0x0, 0x0, 0x0
    <<<3>>>
    Volume: C:
    File system type: NTFS
    SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
    <<<2>>>
    Device number: 0, partition: 2
    <<<3>>>
    Volume: C:
    File system type: NTFS
    SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
    Scanning drivers directory: C:\Windows\system32\drivers...
    <<<2>>>
    Device number: 0, partition: 2
    <<<3>>>
    Volume: C:
    File system type: NTFS
    SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
    Done!
    Drive 0
    Scanning MBR on drive 0...
    Inspecting partition table:
    MBR Signature: 55AA
    Disk Signature: 87ADC0D8

    Partition information:

    Partition 0 type is Primary (0x7)
    Partition is ACTIVE.
    Partition starts at LBA: 2048 Numsec = 204800
    Partition file system is NTFS
    Partition is bootable

    Partition 1 type is Primary (0x7)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 206848 Numsec = 1438918656

    Partition 2 type is Primary (0x7)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 1439125504 Numsec = 26019840

    Partition 3 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0 Numsec = 0

    Disk Size: 750156374016 bytes
    Sector size: 512 bytes

    Scanning physical sectors of unpartitioned space on drive 0 (1-2047-1465129168-1465149168)...
    Done!
    Physical Sector Size: 0
    Drive: 1, DevicePointer: 0xfffffa800c8f6060, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\
    --------- Disk Stack ------
    DevicePointer: 0xfffffa800c8f6b90, DeviceName: Unknown, DriverName: \Driver\partmgr\
    DevicePointer: 0xfffffa800c8f6060, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\
    DevicePointer: 0xfffffa800c70eb60, DeviceName: \Device\00000082\, DriverName: \Driver\USBSTOR\
    ------------ End ----------
    Physical Sector Size: 0
    Drive: 2, DevicePointer: 0xfffffa800ca61060, DeviceName: \Device\Harddisk2\DR2\, DriverName: \Driver\Disk\
    --------- Disk Stack ------
    DevicePointer: 0xfffffa800ca61b90, DeviceName: Unknown, DriverName: \Driver\partmgr\
    DevicePointer: 0xfffffa800ca61060, DeviceName: \Device\Harddisk2\DR2\, DriverName: \Driver\Disk\
    DevicePointer: 0xfffffa800c7c0b60, DeviceName: \Device\0000009c\, DriverName: \Driver\USBSTOR\
    ------------ End ----------
    Physical Sector Size: 0
    Drive: 3, DevicePointer: 0xfffffa800c91c060, DeviceName: \Device\Harddisk3\DR3\, DriverName: \Driver\Disk\
    --------- Disk Stack ------
    DevicePointer: 0xfffffa800c91cb90, DeviceName: Unknown, DriverName: \Driver\partmgr\
    DevicePointer: 0xfffffa800c91c060, DeviceName: \Device\Harddisk3\DR3\, DriverName: \Driver\Disk\
    DevicePointer: 0xfffffa800c7c7b60, DeviceName: \Device\0000009d\, DriverName: \Driver\USBSTOR\
    ------------ End ----------
    Physical Sector Size: 0
    Drive: 4, DevicePointer: 0xfffffa800ca6a060, DeviceName: \Device\Harddisk4\DR4\, DriverName: \Driver\Disk\
    --------- Disk Stack ------
    DevicePointer: 0xfffffa800ca6ab90, DeviceName: Unknown, DriverName: \Driver\partmgr\
    DevicePointer: 0xfffffa800ca6a060, DeviceName: \Device\Harddisk4\DR4\, DriverName: \Driver\Disk\
    DevicePointer: 0xfffffa800c7c8b60, DeviceName: \Device\0000009e\, DriverName: \Driver\USBSTOR\
    ------------ End ----------
    Physical Sector Size: 0
    Drive: 5, DevicePointer: 0xfffffa800ca6b060, DeviceName: \Device\Harddisk5\DR5\, DriverName: \Driver\Disk\
    --------- Disk Stack ------
    DevicePointer: 0xfffffa800ca6bb90, DeviceName: Unknown, DriverName: \Driver\partmgr\
    DevicePointer: 0xfffffa800ca6b060, DeviceName: \Device\Harddisk5\DR5\, DriverName: \Driver\Disk\
    DevicePointer: 0xfffffa800c7c6b60, DeviceName: \Device\0000009f\, DriverName: \Driver\USBSTOR\
    ------------ End ----------
    Scan finished
    =======================================


    Removal queue found; removal started
    Removing c:\programdata\malwarebytes' anti-malware (portable)\mbr_0_i.mbam...
    Removing c:\programdata\malwarebytes' anti-malware (portable)\bootstrap_0_0_2048_i.mbam...
    Removing c:\programdata\malwarebytes' anti-malware (portable)\mbr_0_r.mbam...
    Removal finished
     
  13. 2013/06/13
    Woodstock1780

    Woodstock1780 Inactive Thread Starter

    Joined:
    2013/06/12
    Messages:
    57
    Likes Received:
    0
    mbar log

    Malwarebytes Anti-Rootkit BETA 1.06.0.1003
    www.malwarebytes.org

    Database version: v2013.06.13.09

    Windows 7 Service Pack 1 x64 NTFS
    Internet Explorer 9.0.8112.16421
    David Lee Volz :: DAVIDLEEVOLZ-HP [administrator]

    6/13/2013 8:13:02 PM
    mbar-log-2013-06-13 (20-13-02).txt

    Scan type: Quick scan
    Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUM | P2P
    Scan options disabled: Deep Anti-Rootkit Scan | PUP
    Objects scanned: 300339
    Time elapsed: 13 minute(s), 53 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 0
    (No malicious items detected)

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 0
    (No malicious items detected)

    Physical Sectors Detected: 0
    (No malicious items detected)

    (end)
     
  14. 2013/06/13
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Please download Farbar Recovery Scan Tool and save it to your desktop.

    Note: You need to run the version compatibale with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please copy and paste it to your reply.
     
  15. 2013/06/13
    Woodstock1780

    Woodstock1780 Inactive Thread Starter

    Joined:
    2013/06/12
    Messages:
    57
    Likes Received:
    0
    Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-06-2013
    Ran by David Lee Volz (administrator) on 13-06-2013 20:46:59
    Running from C:\Users\David Lee Volz\Downloads
    Windows 7 Professional Service Pack 1 (X64) OS Language: English(US)
    Internet Explorer Version 9
    Boot Mode: Normal

    ==================== Processes (Whitelisted) =================

    (AMD) C:\Windows\system32\atiesrxx.exe
    (Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
    (AMD) C:\Windows\system32\atieclxx.exe
    (Apple Inc.) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    (CinemaNow, Inc.) C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe
    (SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE
    (SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE
    (Hewlett-Packard Company) c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
    (NewSoft Technology Corporation) C:\Windows\System32\spool\drivers\x64\3\WrtMon.exe
    (Microsoft Corporation) C:\Program Files\Microsoft IntelliPoint\ipoint.exe
    (NewSoft Technology Corporation) C:\Windows\System32\spool\drivers\x64\3\WrtProc.exe
    (Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
    () C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
    (Microsoft Corporation) C:\Program Files (x86)\Microsoft Location Finder\LocationFinder.exe
    (NewSoft Technology Corporation) C:\Program Files (x86)\NewSoft\Presto! PageManager 8 for EP\PMSpeed.exe
    (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
    (Audible, Inc.) C:\Program Files (x86)\Audible\Bin\AudibleDownloadHelper.exe
    (Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
    (Creative Technology Ltd) C:\Windows\SysWOW64\CTXFISPI.EXE
    (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleCrashHandler.exe
    (PIXELA CORPORATION) C:\Program Files (x86)\PIXELA\VideoBrowser\CameraMonitor.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
    (Hewlett-Packard) C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe
    (SEIKO EPSON CORPORATION) C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
    (Creative Technology Ltd) C:\Windows\SysWOW64\Ctxfihlp.exe
    (Visicom Media Inc. (Powered by Panda Security)) C:\ProgramData\Anti-phishing Domain Advisor\visicom_antiphishing.exe
    (SEIKO EPSON CORPORATION) C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe
    (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleCrashHandler64.exe
    (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe
    (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
    (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe
    (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
    (Microsoft Corporation) C:\Windows\splwow64.exe
    (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
    (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
    (Microsoft Corporation) C:\Windows\syswow64\svchost.exe
    (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
    (Adobe Systems Incorporated) C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_7_700_224_ActiveX.exe
    (Microsoft Corporation) C:\Windows\splwow64.exe

    ==================== Registry (Whitelisted) ==================

    HKLM\...\Run: [WrtMon.exe] C:\Windows\system32\spool\drivers\x64\3\WrtMon.exe [26448 2008-05-24] (NewSoft Technology Corporation)
    HKLM\...\Run: [Logitech Download Assistant] C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch [1580368 2010-11-03] (Logitech, Inc.)
    HKLM\...\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2327952 2010-07-21] (Microsoft Corporation)
    HKLM\...\Run: [hpsysdrv] c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe [62768 2008-11-20] (Hewlett-Packard)
    HKLM\...\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe /background [568888 2010-01-18] ()
    HKLM Group Policy restriction on software: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot% <====== ATTENTION
    HKLM Group Policy restriction on software: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir% <====== ATTENTION
    HKCU\...\Run: [Microsoft Location Finder] "C:\Program Files (x86)\Microsoft Location Finder\LocationFinder.exe" [101080 2005-08-24] (Microsoft Corporation)
    HKCU\...\Run: [EPSON Artisan 810 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIFRA.EXE /FU "C:\Windows\TEMP\E_SFC1.tmp" /EF "HKCU" [x]
    HKCU\...\Run: [PMSpeed] C:\Program Files (x86)\NewSoft\Presto! PageManager 8 for EP\PMSpeed.EXE [55120 2008-12-09] (NewSoft Technology Corporation)
    HKCU\...\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun [1475584 2010-11-20] (Microsoft Corporation)
    HKCR\...409d6c4515e9\InprocServer32: [Default-shell32] C:\Users\DAVIDL~1\AppData\Local\Temp\spqvjee\sfrxyqq\wow64.dll ATTENTION! ====> ZeroAccess
    MountPoints2: {40427de2-b478-11e1-b804-6c626d7dcb01} - J:\setup.exe -a
    MountPoints2: {4e31dc87-c274-11e0-8d96-6c626d7dcb01} - K:\setup.exe -a
    HKLM-x32\...\Run: [] [x]
    HKLM-x32\...\Run: [EfficientCalendarFree] [x]
    HKLM-x32\...\Run: [VolPanel] "C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r [241789 2009-07-07] (Creative Technology Ltd)
    HKLM-x32\...\Run: [UpdReg] C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.)
    HKLM-x32\...\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [98304 2010-05-17] (Advanced Micro Devices, Inc.)
    HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2010-11-29] (Apple Inc.)
    HKLM-x32\...\Run: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume [288088 2009-11-11] (Microsoft Corporation)
    HKLM-x32\...\Run: [LTCM Client] C:\Program Files (x86)\LTCM Client\ltcmClient.exe /startup [1596096 2009-08-05] (Leader Technologies Inc.)
    HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-03-03] (Intel Corporation)
    HKLM-x32\...\Run: [HP Software Update] c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [54576 2008-12-08] (Hewlett-Packard)
    HKLM-x32\...\Run: [EEventManager] C:\PROGRA~2\EPSONS~1\EVENTM~1\EEventManager.exe [673616 2009-04-07] (SEIKO EPSON CORPORATION)
    HKLM-x32\...\Run: [CTxfiHlp] CTXFIHLP.EXE [24576 2010-07-07] (Creative Technology Ltd)
    HKLM-x32\...\Run: [Anti-phishing Domain Advisor] "C:\ProgramData\Anti-phishing Domain Advisor\visicom_antiphishing.exe" [217256 2011-07-29] (Visicom Media Inc. (Powered by Panda Security))
    HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [35736 2010-11-10] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [932288 2010-11-10] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [FUFAXSTM] "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe" [843776 2009-06-05] (SEIKO EPSON CORPORATION)
    HKU\Administrator\...\Run: [HPAdvisorDock] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Dock\HPAdvisorDock.exe [1715768 2010-09-28] (Hewlett-Packard)
    HKU\Default\...\Run: [HPAdvisorDock] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe [1715768 2010-09-28] (Hewlett-Packard)
    HKU\Default User\...\Run: [HPAdvisorDock] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe [1715768 2010-09-28] (Hewlett-Packard)
    HKU\DefaultAppPool\...\Run: [HPAdvisorDock] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe [1715768 2010-09-28] (Hewlett-Packard)
    Startup: C:\ProgramData\Start Menu\Programs\Startup\Audible Download Manager.lnk
    ShortcutTarget: Audible Download Manager.lnk -> C:\Program Files (x86)\Audible\Bin\AudibleDownloadHelper.exe (Audible, Inc.)
    Startup: C:\ProgramData\Start Menu\Programs\Startup\VideoBrowser Camera Monitor.lnk
    ShortcutTarget: VideoBrowser Camera Monitor.lnk -> C:\Program Files (x86)\PIXELA\VideoBrowser\CameraMonitor.exe (PIXELA CORPORATION)

    ==================== Internet (Whitelisted) ====================

    HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.foxnews.com/index.html
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPDSK/1
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK/1
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPDSK/1
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK/1
    SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKLM - {8651C49A-4A5B-405A-B50D-0A5C79B2014D} URL = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpd
    SearchScopes: HKLM - {A70D9132-58C9-4497-8215-C31D89A2CB71} URL = http://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF
    SearchScopes: HKLM - {C7205BA0-9EF3-425C-A3CF-2E893440D40D} URL = http://en.wikipedia.org/wiki/Special:Search?search={searchTerms}
    SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKLM-x32 - {8651C49A-4A5B-405A-B50D-0A5C79B2014D} URL = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpd
    SearchScopes: HKLM-x32 - {A70D9132-58C9-4497-8215-C31D89A2CB71} URL = http://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF
    SearchScopes: HKLM-x32 - {C7205BA0-9EF3-425C-A3CF-2E893440D40D} URL = http://en.wikipedia.org/wiki/Special:Search?search={searchTerms}
    SearchScopes: HKCU - {8651C49A-4A5B-405A-B50D-0A5C79B2014D} URL = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpd
    SearchScopes: HKCU - {945E6A55-773F-4FC2-A00A-B7A83FDFF1F1} URL =
    SearchScopes: HKCU - {A70D9132-58C9-4497-8215-C31D89A2CB71} URL = http://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF
    SearchScopes: HKCU - {C7205BA0-9EF3-425C-A3CF-2E893440D40D} URL = http://en.wikipedia.org/wiki/Special:Search?search={searchTerms}
    SearchScopes: HKCU - {F68D5FEE-1B84-46CC-B44B-ED5B54DE0F6F} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2559647
    BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
    BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
    BHO-x32: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation)
    BHO-x32: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\IPS\IPSBHO.DLL (Symantec Corporation)
    BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
    BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
    BHO-x32: No Name - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - No File
    BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
    Toolbar: HKLM-x32 - No Name - {8dcb7100-df86-4384-8842-8fa844297b3f} - No File
    Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation)
    Toolbar: HKCU - No Name - {37153479-1976-43C3-A1EE-557513977B64} - No File
    DPF: HKLM-x32 {7A0D1738-10EA-47FF-92BE-4E137B5BE1A4} https://mpsnare.iesnare.com/StmOCX.cab
    DPF: HKLM-x32 {C4B977A3-E8A2-37E9-ADCD-2597FAAC61F5} http://shop.lenovo.com/SEUILibrary/lenovo-portal/cab/autodetect/MachineInfo.cab
    DPF: HKLM-x32 {D4B68B83-8710-488B-A692-D74B50BA558E} http://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
    DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPID.cab
    Handler-x32: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files (x86)\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
    Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

    Chrome:
    =======
    CHR HomePage: hxxp://www.google.com
    CHR RestoreOnStartup: "hxxp://www.google.com "
    CHR Extension: (Docs) - C:\Users\David Lee Volz\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0
    CHR Extension: (Google Drive) - C:\Users\David Lee Volz\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0
    CHR Extension: (YouTube) - C:\Users\David Lee Volz\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0
    CHR Extension: (Google Search) - C:\Users\David Lee Volz\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0
    CHR Extension: (Gmail) - C:\Users\David Lee Volz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0

    ==================== Services (Whitelisted) =================

    R2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe [144368 2013-05-21] (Symantec Corporation)
    S4 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-01] (Symantec Corporation)
    R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [453120 2010-11-20] (Microsoft Corporation)

    ==================== Drivers (Whitelisted) ====================

    R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.1.22\Definitions\BASHDefs\20130531.001\BHDrvx64.sys [1393240 2013-05-31] (Symantec Corporation)
    R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.1.22\Definitions\BASHDefs\20130531.001\BHDrvx64.sys [1393240 2013-05-31] (Symantec Corporation)
    R1 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1404000.028\ccSetx64.sys [169048 2013-04-15] (Symantec Corporation)
    R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484512 2013-02-13] (Symantec Corporation)
    R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484512 2013-02-13] (Symantec Corporation)
    R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [138912 2013-02-13] (Symantec Corporation)
    R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.1.22\Definitions\IPSDefs\20130613.001\IDSvia64.sys [513184 2013-02-26] (Symantec Corporation)
    R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.1.22\Definitions\IPSDefs\20130613.001\IDSvia64.sys [513184 2013-02-26] (Symantec Corporation)
    R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.1.22\Definitions\VirusDefs\20130613.001\ENG64.SYS [126040 2013-05-22] (Symantec Corporation)
    R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.1.22\Definitions\VirusDefs\20130613.001\ENG64.SYS [126040 2013-05-22] (Symantec Corporation)
    R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.1.22\Definitions\VirusDefs\20130613.001\EX64.SYS [2098776 2013-05-22] (Symantec Corporation)
    R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.1.22\Definitions\VirusDefs\20130613.001\EX64.SYS [2098776 2013-05-22] (Symantec Corporation)
    R1 SRTSP; C:\Windows\System32\Drivers\NISx64\1404000.028\SRTSP64.SYS [796760 2013-05-16] (Symantec Corporation)
    R1 SRTSPX; C:\Windows\system32\drivers\NISx64\1404000.028\SRTSPX64.SYS [36952 2013-03-04] (Symantec Corporation)
    R0 SymDS; C:\Windows\System32\drivers\NISx64\1404000.028\SYMDS64.SYS [493656 2013-05-21] (Symantec Corporation)
    R0 SymEFA; C:\Windows\System32\drivers\NISx64\1404000.028\SYMEFA64.SYS [1139800 2013-05-23] (Symantec Corporation)
    R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177312 2013-06-10] (Symantec Corporation)
    R1 SymIRON; C:\Windows\system32\drivers\NISx64\1404000.028\Ironx64.SYS [224416 2013-03-04] (Symantec Corporation)
    R1 SymNetS; C:\Windows\System32\Drivers\NISx64\1404000.028\SYMNETS.SYS [433752 2013-04-24] (Symantec Corporation)
    U4 mbamswissarmy;
    U2 MSSQL$TRANSAMERICA;

    ==================== NetSvcs (Whitelisted) ===================


    ==================== One Month Created Files and Folders ========

    2013-06-13 20:46 - 2013-06-13 20:46 - 01920398 ____A (Farbar) C:\Users\David Lee Volz\Downloads\FRST64.exe
    2013-06-13 20:46 - 2013-06-13 20:46 - 00000000 ____D C:\FRST
    2013-06-13 20:11 - 2013-06-13 20:11 - 00000000 ____D C:\Users\David Lee Volz\Downloads\mbar-1.06.0.1003
    2013-06-13 20:07 - 2013-06-13 20:08 - 13169742 ____A C:\Users\David Lee Volz\Downloads\mbar-1.06.0.1003.zip
    2013-06-13 19:18 - 2013-06-13 19:46 - 00000000 ____D C:\Users\David Lee Volz\Desktop\RK_Quarantine
    2013-06-13 19:16 - 2013-06-13 19:16 - 00791040 ____A C:\Users\David Lee Volz\Desktop\winlogon.exe.exe
    2013-06-13 19:15 - 2013-06-13 19:15 - 00791040 ____A C:\Users\David Lee Volz\Downloads\RogueKillerX64.exe
    2013-06-12 17:52 - 2013-06-12 17:52 - 04938520 ____A (Piriform Ltd) C:\Users\David Lee Volz\Downloads\spsetup121.exe
    2013-06-12 17:52 - 2013-06-12 17:52 - 00000798 ____A C:\Users\Public\Desktop\Speccy.lnk
    2013-06-12 17:52 - 2013-06-12 17:52 - 00000000 ____D C:\Program Files\Speccy
    2013-06-12 16:30 - 2013-06-12 16:30 - 00019943 ____A C:\Users\David Lee Volz\Desktop\dds.txt
    2013-06-12 16:30 - 2013-06-12 16:30 - 00013743 ____A C:\Users\David Lee Volz\Desktop\attach.txt
    2013-06-12 16:23 - 2013-06-12 16:23 - 00688992 ____R (Swearware) C:\Users\David Lee Volz\Downloads\dds.com
    2013-06-12 15:06 - 2013-06-13 20:27 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
    2013-06-12 15:05 - 2013-06-12 15:05 - 00000000 ____D C:\Users\David Lee Volz\Documents\mbar-1.06.0.1003
    2013-06-12 07:30 - 2013-05-17 00:05 - 17824768 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
    2013-06-12 07:30 - 2013-05-16 23:27 - 10926080 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
    2013-06-12 07:30 - 2013-05-16 23:09 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
    2013-06-12 07:30 - 2013-05-16 23:02 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
    2013-06-12 07:30 - 2013-05-16 23:02 - 01346560 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
    2013-06-12 07:30 - 2013-05-16 23:01 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
    2013-06-12 07:30 - 2013-05-16 23:00 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
    2013-06-12 07:30 - 2013-05-16 22:58 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
    2013-06-12 07:30 - 2013-05-16 22:56 - 00599040 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
    2013-06-12 07:30 - 2013-05-16 22:56 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
    2013-06-12 07:30 - 2013-05-16 22:55 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
    2013-06-12 07:30 - 2013-05-16 22:54 - 00729088 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
    2013-06-12 07:30 - 2013-05-16 22:53 - 02147840 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
    2013-06-12 07:30 - 2013-05-16 22:51 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
    2013-06-12 07:30 - 2013-05-16 22:51 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
    2013-06-12 07:30 - 2013-05-16 22:46 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
    2013-06-12 07:30 - 2013-05-16 19:08 - 12329984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2013-06-12 07:30 - 2013-05-16 18:49 - 09738752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2013-06-12 07:30 - 2013-05-16 18:39 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2013-06-12 07:30 - 2013-05-16 18:28 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2013-06-12 07:30 - 2013-05-16 18:28 - 01104384 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2013-06-12 07:30 - 2013-05-16 18:27 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2013-06-12 07:30 - 2013-05-16 18:26 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
    2013-06-12 07:30 - 2013-05-16 18:23 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2013-06-12 07:30 - 2013-05-16 18:21 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
    2013-06-12 07:30 - 2013-05-16 18:21 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
    2013-06-12 07:30 - 2013-05-16 18:20 - 00420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
    2013-06-12 07:30 - 2013-05-16 18:19 - 00607744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
    2013-06-12 07:30 - 2013-05-16 18:17 - 01796096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2013-06-12 07:30 - 2013-05-16 18:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
    2013-06-12 07:30 - 2013-05-16 18:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2013-06-12 07:30 - 2013-05-16 18:12 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2013-06-12 07:28 - 2013-05-13 01:51 - 01464320 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
    2013-06-12 07:28 - 2013-05-13 01:51 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
    2013-06-12 07:28 - 2013-05-13 01:51 - 00139776 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
    2013-06-12 07:28 - 2013-05-13 01:50 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll
    2013-06-12 07:28 - 2013-05-13 00:45 - 01160192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
    2013-06-12 07:28 - 2013-05-13 00:45 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
    2013-06-12 07:28 - 2013-05-13 00:45 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
    2013-06-12 07:28 - 2013-05-12 23:43 - 01192448 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe
    2013-06-12 07:28 - 2013-05-12 23:08 - 00903168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
    2013-06-12 07:28 - 2013-05-12 23:08 - 00043008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
    2013-06-12 07:28 - 2013-05-10 01:49 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll
    2013-06-12 07:28 - 2013-05-09 23:20 - 00024576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
    2013-06-12 07:28 - 2013-05-08 02:39 - 01910632 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
    2013-06-12 07:28 - 2013-04-26 01:51 - 00751104 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
    2013-06-12 07:28 - 2013-04-26 00:55 - 00492544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
    2013-06-12 07:28 - 2013-04-25 19:30 - 01505280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
    2013-06-12 07:28 - 2013-04-17 03:02 - 01230336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
    2013-06-12 07:28 - 2013-04-17 02:24 - 01424384 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll
    2013-06-12 07:28 - 2013-03-31 18:52 - 01887232 ____A (Microsoft Corporation) C:\Windows\System32\d3d11.dll
    2013-06-11 12:14 - 2013-06-11 12:14 - 00000000 ____D C:\Users\David Lee Volz\AppData\Local\VueSoft
    2013-06-11 09:41 - 2013-06-11 09:41 - 00001075 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2013-06-11 09:41 - 2013-06-11 09:41 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
    2013-06-11 09:41 - 2013-04-04 14:50 - 00025928 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
    2013-06-08 21:03 - 2013-06-08 21:03 - 00000000 ____D C:\Users\David Lee Volz\AppData\Roaming\Sunward Games
    2013-06-08 21:02 - 2013-06-08 21:02 - 00002223 ____A C:\Users\Public\Desktop\Play The Secret Order - Masked Intent Collectors Edition.lnk
    2013-06-08 21:00 - 2013-06-08 21:02 - 00000000 ____D C:\Users\David Lee Volz\The Secret Order - Masked Intent Collectors Edition
    2013-05-29 22:20 - 2013-05-29 22:20 - 00000000 ____D C:\ProgramData\Meridian93
    2013-05-29 21:46 - 2013-05-29 21:46 - 00000000 ____D C:\Users\David Lee Volz\AppData\Roaming\Meridian93
    2013-05-27 17:47 - 2013-05-27 17:47 - 00000000 ____D C:\Users\David Lee Volz\AppData\Roaming\Artifex Mundi
    2013-05-19 02:03 - 2013-05-19 02:03 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
    2013-05-15 06:20 - 2013-04-10 02:01 - 00983400 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys
    2013-05-15 06:20 - 2013-04-10 02:01 - 00265064 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgmms1.sys
    2013-05-15 06:20 - 2013-03-19 01:53 - 00230400 ____A (Microsoft Corporation) C:\Windows\System32\wwansvc.dll
    2013-05-15 06:20 - 2013-03-19 01:53 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\wwanprotdim.dll
    2013-05-15 06:20 - 2013-02-27 02:02 - 00111448 ____A (Microsoft Corporation) C:\Windows\System32\consent.exe
    2013-05-15 06:20 - 2013-02-27 01:52 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
    2013-05-15 06:20 - 2013-02-27 01:52 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\shdocvw.dll
    2013-05-15 06:20 - 2013-02-27 01:48 - 01930752 ____A (Microsoft Corporation) C:\Windows\System32\authui.dll
    2013-05-15 06:20 - 2013-02-27 01:47 - 00070144 ____A (Microsoft Corporation) C:\Windows\System32\appinfo.dll
    2013-05-15 06:20 - 2013-02-27 00:55 - 12872704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
    2013-05-15 06:20 - 2013-02-27 00:55 - 00180224 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
    2013-05-15 06:20 - 2013-02-27 00:49 - 01796096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
    2013-05-15 06:20 - 2011-02-03 07:25 - 00144384 ____A (Microsoft Corporation) C:\Windows\System32\cdd.dll
    2013-05-15 06:19 - 2013-04-09 23:30 - 03153920 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys

    ==================== One Month Modified Files and Folders =======

    2013-06-13 20:46 - 2013-06-13 20:46 - 01920398 ____A (Farbar) C:\Users\David Lee Volz\Downloads\FRST64.exe
    2013-06-13 20:46 - 2013-06-13 20:46 - 00000000 ____D C:\FRST
    2013-06-13 20:27 - 2013-06-12 15:06 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
    2013-06-13 20:16 - 2009-07-14 00:45 - 00016976 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2013-06-13 20:16 - 2009-07-14 00:45 - 00016976 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2013-06-13 20:11 - 2013-06-13 20:11 - 00000000 ____D C:\Users\David Lee Volz\Downloads\mbar-1.06.0.1003
    2013-06-13 20:08 - 2013-06-13 20:07 - 13169742 ____A C:\Users\David Lee Volz\Downloads\mbar-1.06.0.1003.zip
    2013-06-13 19:58 - 2009-07-14 01:13 - 00855108 ____A C:\Windows\System32\PerfStringBackup.INI
    2013-06-13 19:57 - 2010-11-06 00:37 - 01735907 ____A C:\Windows\WindowsUpdate.log
    2013-06-13 19:55 - 2012-12-26 07:56 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
    2013-06-13 19:54 - 2013-02-06 15:35 - 00000910 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
    2013-06-13 19:54 - 2012-08-09 19:53 - 00000000 ____D C:\ProgramData\Anti-phishing Domain Advisor
    2013-06-13 19:54 - 2010-12-01 15:38 - 00000000 ____D C:\Users\David Lee Volz\AppData\Roaming\.oit
    2013-06-13 19:54 - 2009-07-14 01:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
    2013-06-13 19:53 - 2010-12-10 08:05 - 00083928 ____A C:\Windows\setupact.log
    2013-06-13 19:48 - 2011-07-03 18:29 - 02731520 __ASH C:\Users\David Lee Volz\Desktop\Thumbs.db
    2013-06-13 19:47 - 2010-11-15 20:23 - 00000000 ____D C:\Users\David Lee Volz\AppData\Local\CrashDumps
    2013-06-13 19:46 - 2013-06-13 19:18 - 00000000 ____D C:\Users\David Lee Volz\Desktop\RK_Quarantine
    2013-06-13 19:16 - 2013-06-13 19:16 - 00791040 ____A C:\Users\David Lee Volz\Desktop\winlogon.exe.exe
    2013-06-13 19:15 - 2013-06-13 19:15 - 00791040 ____A C:\Users\David Lee Volz\Downloads\RogueKillerX64.exe
    2013-06-13 18:50 - 2013-02-06 15:35 - 00000914 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
    2013-06-13 08:40 - 2011-04-25 10:56 - 00000000 ____D C:\Windows\pss
    2013-06-12 22:28 - 2010-11-14 20:54 - 00000000 ____D C:\Users\David Lee Volz\AppData\Roaming\SoftGrid Client
    2013-06-12 17:52 - 2013-06-12 17:52 - 04938520 ____A (Piriform Ltd) C:\Users\David Lee Volz\Downloads\spsetup121.exe
    2013-06-12 17:52 - 2013-06-12 17:52 - 00000798 ____A C:\Users\Public\Desktop\Speccy.lnk
    2013-06-12 17:52 - 2013-06-12 17:52 - 00000000 ____D C:\Program Files\Speccy
    2013-06-12 16:30 - 2013-06-12 16:30 - 00019943 ____A C:\Users\David Lee Volz\Desktop\dds.txt
    2013-06-12 16:30 - 2013-06-12 16:30 - 00013743 ____A C:\Users\David Lee Volz\Desktop\attach.txt
    2013-06-12 16:23 - 2013-06-12 16:23 - 00688992 ____R (Swearware) C:\Users\David Lee Volz\Downloads\dds.com
    2013-06-12 15:34 - 2009-07-14 01:08 - 00032594 ____A C:\Windows\Tasks\SCHEDLGU.TXT
    2013-06-12 15:05 - 2013-06-12 15:05 - 00000000 ____D C:\Users\David Lee Volz\Documents\mbar-1.06.0.1003
    2013-06-12 11:45 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\rescache
    2013-06-12 07:29 - 2010-11-17 08:56 - 75825640 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
    2013-06-12 07:15 - 2010-12-16 08:21 - 00179622 ____A C:\Windows\PFRO.log
    2013-06-11 13:55 - 2012-08-18 18:25 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2013-06-11 13:55 - 2011-06-28 07:14 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
    2013-06-11 12:14 - 2013-06-11 12:14 - 00000000 ____D C:\Users\David Lee Volz\AppData\Local\VueSoft
    2013-06-11 12:04 - 2010-12-01 15:39 - 00000000 ____D C:\Program Files (x86)\ArcSoft
    2013-06-11 12:04 - 2010-11-06 00:35 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
    2013-06-11 09:41 - 2013-06-11 09:41 - 00001075 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2013-06-11 09:41 - 2013-06-11 09:41 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
    2013-06-11 09:35 - 2010-11-13 16:55 - 00000000 ____D C:\users\David Lee Volz
    2013-06-11 09:27 - 2013-03-19 10:00 - 00000000 ____D C:\Program Files (x86)\Cold Case Summer demo
    2013-06-10 20:57 - 2013-02-27 12:58 - 00002463 ____A C:\Users\Public\Desktop\Norton Internet Security.lnk
    2013-06-10 20:57 - 2010-11-06 01:02 - 00000000 ____D C:\Windows\System32\Drivers\NISx64
    2013-06-10 16:56 - 2013-02-27 12:58 - 00177312 ____A (Symantec Corporation) C:\Windows\System32\Drivers\SYMEVENT64x86.SYS
    2013-06-10 16:56 - 2013-02-27 12:58 - 00007631 ____A C:\Windows\System32\Drivers\SYMEVENT64x86.CAT
    2013-06-08 21:47 - 2011-01-15 23:13 - 00000000 ____D C:\BigFishGamesCache
    2013-06-08 21:03 - 2013-06-08 21:03 - 00000000 ____D C:\Users\David Lee Volz\AppData\Roaming\Sunward Games
    2013-06-08 21:02 - 2013-06-08 21:02 - 00002223 ____A C:\Users\Public\Desktop\Play The Secret Order - Masked Intent Collectors Edition.lnk
    2013-06-08 21:02 - 2013-06-08 21:00 - 00000000 ____D C:\Users\David Lee Volz\The Secret Order - Masked Intent Collectors Edition
    2013-06-08 19:40 - 2012-01-01 13:04 - 00000000 ____D C:\Users\David Lee Volz\AppData\Roaming\AlawarEntertainment
    2013-06-08 19:36 - 2012-05-31 21:09 - 00000000 ____D C:\Users\David Lee Volz\AppData\Roaming\Eipix
    2013-06-08 16:32 - 2011-05-25 21:35 - 00000000 ____D C:\Users\David Lee Volz\AppData\Roaming\GameMill Entertainment
    2013-06-07 13:33 - 2012-02-16 10:28 - 00000000 ____D C:\Users\David Lee Volz\Documents\EfficientPIM AutoBackup
    2013-06-07 13:33 - 2012-02-16 10:24 - 01851392 ____A C:\Users\David Lee Volz\Documents\MyCalendar.ecfx
    2013-06-07 09:36 - 2011-01-17 01:14 - 00000000 ____D C:\Users\David Lee Volz\AppData\Roaming\Big Fish Games
    2013-06-03 06:31 - 2013-02-17 21:11 - 00000368 ____A C:\Windows\Tasks\HPCeeScheduleForDavid Lee Volz.job
    2013-06-02 20:14 - 2010-11-21 16:46 - 00000052 ____A C:\Windows\SysWOW64\DOErrors.log
    2013-06-02 20:14 - 2010-11-21 16:45 - 00000000 ____D C:\Users\David Lee Volz\AppData\Roaming\HP Support Assistant
    2013-06-02 20:14 - 2010-11-14 17:09 - 00000000 ____D C:\Users\David Lee Volz\AppData\Roaming\HpUpdate
    2013-05-30 11:19 - 2012-10-22 21:38 - 00000000 ____D C:\ProgramData\Playrix Entertainment
    2013-05-29 22:20 - 2013-05-29 22:20 - 00000000 ____D C:\ProgramData\Meridian93
    2013-05-29 21:46 - 2013-05-29 21:46 - 00000000 ____D C:\Users\David Lee Volz\AppData\Roaming\Meridian93
    2013-05-29 21:44 - 2011-01-30 16:15 - 00000000 ____D C:\Users\David Lee Volz\AppData\Roaming\ERS Game Studios
    2013-05-27 17:47 - 2013-05-27 17:47 - 00000000 ____D C:\Users\David Lee Volz\AppData\Roaming\Artifex Mundi
    2013-05-20 16:55 - 2011-08-25 14:17 - 00076288 __ASH C:\Users\David Lee Volz\Documents\Thumbs.db
    2013-05-20 06:52 - 2012-10-13 20:29 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
    2013-05-19 20:25 - 2013-03-03 21:07 - 00001854 ____A C:\Users\David Lee Volz\AppData\Roaming\GhostObjGAFix.xml
    2013-05-19 02:03 - 2013-05-19 02:03 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
    2013-05-17 00:05 - 2013-06-12 07:30 - 17824768 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
    2013-05-16 23:27 - 2013-06-12 07:30 - 10926080 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
    2013-05-16 23:09 - 2013-06-12 07:30 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
    2013-05-16 23:02 - 2013-06-12 07:30 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
    2013-05-16 23:02 - 2013-06-12 07:30 - 01346560 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
    2013-05-16 23:01 - 2013-06-12 07:30 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
    2013-05-16 23:00 - 2013-06-12 07:30 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
    2013-05-16 22:58 - 2013-06-12 07:30 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
    2013-05-16 22:56 - 2013-06-12 07:30 - 00599040 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
    2013-05-16 22:56 - 2013-06-12 07:30 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
    2013-05-16 22:55 - 2013-06-12 07:30 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
    2013-05-16 22:54 - 2013-06-12 07:30 - 00729088 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
    2013-05-16 22:53 - 2013-06-12 07:30 - 02147840 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
    2013-05-16 22:51 - 2013-06-12 07:30 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
    2013-05-16 22:51 - 2013-06-12 07:30 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
    2013-05-16 22:46 - 2013-06-12 07:30 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
    2013-05-16 19:08 - 2013-06-12 07:30 - 12329984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2013-05-16 18:49 - 2013-06-12 07:30 - 09738752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2013-05-16 18:39 - 2013-06-12 07:30 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2013-05-16 18:28 - 2013-06-12 07:30 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2013-05-16 18:28 - 2013-06-12 07:30 - 01104384 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2013-05-16 18:27 - 2013-06-12 07:30 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2013-05-16 18:26 - 2013-06-12 07:30 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
    2013-05-16 18:23 - 2013-06-12 07:30 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2013-05-16 18:21 - 2013-06-12 07:30 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
    2013-05-16 18:21 - 2013-06-12 07:30 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
    2013-05-16 18:20 - 2013-06-12 07:30 - 00420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
    2013-05-16 18:19 - 2013-06-12 07:30 - 00607744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
    2013-05-16 18:17 - 2013-06-12 07:30 - 01796096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2013-05-16 18:17 - 2013-06-12 07:30 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
    2013-05-16 18:16 - 2013-06-12 07:30 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2013-05-16 18:12 - 2013-06-12 07:30 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2013-05-15 06:49 - 2010-11-25 13:44 - 00000000 ___RD C:\Users\David Lee Volz\Virtual Machines
    2013-05-15 06:49 - 2009-07-14 00:45 - 00287000 ____A C:\Windows\System32\FNTCACHE.DAT

    ==================== Bamital & volsnap Check =================

    C:\Windows\System32\winlogon.exe => MD5 is legit
    C:\Windows\System32\wininit.exe => MD5 is legit
    C:\Windows\SysWOW64\wininit.exe => MD5 is legit
    C:\Windows\explorer.exe => MD5 is legit
    C:\Windows\SysWOW64\explorer.exe => MD5 is legit
    C:\Windows\System32\svchost.exe => MD5 is legit
    C:\Windows\SysWOW64\svchost.exe => MD5 is legit
    C:\Windows\System32\services.exe => MD5 is legit
    C:\Windows\System32\User32.dll => MD5 is legit
    C:\Windows\SysWOW64\User32.dll => MD5 is legit
    C:\Windows\System32\userinit.exe => MD5 is legit
    C:\Windows\SysWOW64\userinit.exe => MD5 is legit
    C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


    LastRegBack: 2013-06-13 13:57

    ==================== End Of Log ============================
     
  16. 2013/06/13
    Woodstock1780

    Woodstock1780 Inactive Thread Starter

    Joined:
    2013/06/12
    Messages:
    57
    Likes Received:
    0
    addition

    Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-06-2013
    Ran by David Lee Volz at 2013-06-13 20:47:13 Run:
    Running from C:\Users\David Lee Volz\Downloads
    Boot Mode: Normal
    ==========================================================


    ==================== Installed Programs =======================

    ActiveCheck component for HP Active Support Library (Version: 3.0.0.3)
    Adobe AIR (Version: 1.5.3.9130)
    Adobe Flash Player 11 ActiveX (Version: 11.7.700.224)
    Adobe Reader X (Version: 10.0.0)
    AnswerWorks 5.0 English Runtime (Version: 5.0.7)
    Anti-phishing Domain Advisor (Version: 1.1.0.1)
    Apple Application Support (Version: 1.4.1)
    Apple Mobile Device Support (Version: 3.3.0.69)
    Apple Software Update (Version: 2.1.2.120)
    Apple Software Update (Version: 2.1.3.127)
    ATI Catalyst Install Manager (Version: 3.0.778.0)
    Audible Download Manager (Version: 6.6.0.13)
    Big Fish Games: Game Manager (Version: 3.0.1.60)
    Bing Bar (Version: 7.0.609.0)
    Bing Bar Platform (Version: 5.0.1438.0)
    Bonjour (Version: 2.0.4.0)
    Catalyst Control Center - Branding (Version: 1.00.0000)
    Catalyst Control Center Graphics Previews Common (Version: 2010.0517.1742.29870)
    Catalyst Control Center Graphics Previews Vista (Version: 2010.0517.1742.29870)
    Catalyst Control Center InstallProxy (Version: 2010.0517.1742.29870)
    Catalyst Control Center Localization All (Version: 2010.0517.1742.29870)
    CCC Help Chinese Standard (Version: 2010.0517.1741.29870)
    CCC Help Chinese Traditional (Version: 2010.0517.1741.29870)
    CCC Help Czech (Version: 2010.0517.1741.29870)
    CCC Help Danish (Version: 2010.0517.1741.29870)
    CCC Help Dutch (Version: 2010.0517.1741.29870)
    CCC Help English (Version: 2010.0517.1741.29870)
    CCC Help Finnish (Version: 2010.0517.1741.29870)
    CCC Help French (Version: 2010.0517.1741.29870)
    CCC Help German (Version: 2010.0517.1741.29870)
    CCC Help Greek (Version: 2010.0517.1741.29870)
    CCC Help Hungarian (Version: 2010.0517.1741.29870)
    CCC Help Italian (Version: 2010.0517.1741.29870)
    CCC Help Japanese (Version: 2010.0517.1741.29870)
    CCC Help Korean (Version: 2010.0517.1741.29870)
    CCC Help Norwegian (Version: 2010.0517.1741.29870)
    CCC Help Polish (Version: 2010.0517.1741.29870)
    CCC Help Portuguese (Version: 2010.0517.1741.29870)
    CCC Help Russian (Version: 2010.0517.1741.29870)
    CCC Help Spanish (Version: 2010.0517.1741.29870)
    CCC Help Swedish (Version: 2010.0517.1741.29870)
    CCC Help Thai (Version: 2010.0517.1741.29870)
    CCC Help Turkish (Version: 2010.0517.1741.29870)
    ccc-core-static (Version: 2010.0517.1742.29870)
    ccc-utility64 (Version: 2010.0517.1742.29870)
    CCleaner (Version: 3.28)
    CinemaNow Media Manager (Version: 1.9.1.105)
    Cisco Connect (Version: 1.4.12284.0)
    Creative Audio Control Panel (Version: 3.00)
    Creative Software AutoUpdate (Version: 1.40)
    Creative Sound Blaster Properties x64 Edition (Version: 1.02)
    CyberLink DVD Suite Deluxe (Version: 7.0.2823)
    D3DX10 (Version: 15.4.2368.0902)
    Dolby Digital Live Pack (Version: 3.00)
    DVD Menu Pack for HP MediaSmart Video (Version: 4.1.4030)
    Efficient Calendar Free 3.10
    EPSON Artisan 810 Series Printer Uninstall
    Epson Event Manager (Version: 2.30.01)
    Epson FAX Utility (Version: 1.00.01)
    Epson Print CD (Version: 2.00.00)
    EPSON Scan
    eReg (Version: 1.20.138.34)
    erLT (Version: 1.20.0137)
    FBReader for Windows
    Feedback Tool (Version: 1.1.0)
    Feedback Tool (Version: 1.2.0)
    ffdshow (remove only)
    Garmin WebUpdater (Version: 2.5.4)
    GIMP 2.6.11 (Version: 2.6.11)
    Google Earth (Version: 7.0.2.8415)
    Google Earth (Version: 7.0.3.8542)
    Google Update Helper (Version: 1.3.21.145)
    Haali Media Splitter
    HP Advisor (Version: 3.4.12850.3526)
    HP Customer Experience Enhancements (Version: 6.0.1.4)
    HP MediaSmart CinemaNow 2.0 (Version: 2.0)
    HP MediaSmart DVD (Version: 4.1.4229)
    HP MediaSmart Music (Version: 4.1.4301)
    HP MediaSmart Photo (Version: 4.1.4211)
    HP MediaSmart SmartMenu (Version: 3.1.1.12)
    HP MediaSmart Video (Version: 4.1.4214)
    HP MediaSmart/TouchSmart Netflix (Version: 1.0.3.0)
    HP Odometer (Version: 2.10.0000)
    HP Product Detection (Version: 10.7.9.0)
    HP Setup (Version: 8.1.4186.3400)
    HP Support Assistant (Version: 5.0.11.16)
    HP Support Assistant (Version: 5.1.10.7)
    HP Support Information (Version: 10.1.0002)
    HP Update (Version: 5.002.003.003)
    HP Vision Hardware Diagnostics (Version: 2.1.2.27173)
    HPAsset component for HP Active Support Library (Version: 3.0.2.2)
    HydraVision (Version: 4.2.166.0)
    Intel(R) Management Engine Components (Version: 6.0.0.1179)
    Intel(R) Rapid Storage Technology (Version: 9.6.0.1014)
    iTunes (Version: 10.1.1.4)
    Jackson Illustrator
    Java Auto Updater (Version: 2.0.3.1)
    Java(TM) 6 Update 29 (Version: 6.0.290)
    Java(TM) 6 Update 31 (Version: 6.0.310)
    JH Illustrator Crystal Report net (Version: 10.00.0000)
    Junk Mail filter update (Version: 15.4.3502.0922)
    Kobo
    LabelPrint (Version: 2.5.2823)
    Legacy 7.5 (Version: 7.5 )
    LightScribe System Software (Version: 1.18.15.1)
    LTCM Client
    Malwarebytes Anti-Malware version 1.75.0.1300 (Version: 1.75.0.1300)
    Microsoft Application Error Reporting (Version: 12.0.6015.5000)
    Microsoft Default Manager (Version: 2.1.55.0)
    Microsoft IntelliPoint 8.0 (Version: 8.0.225.0)
    Microsoft Location Finder (Version: 1.2.0)
    Microsoft Office 2010 (Version: 14.0.4763.1000)
    Microsoft Office Click-to-Run 2010 (Version: 14.0.4763.1000)
    Microsoft Office PowerPoint Viewer 2007 (English) (Version: 12.0.6425.1000)
    Microsoft Office Starter 2010 - English (Version: 14.0.4763.1000)
    Microsoft PowerPoint Viewer (Version: 14.0.4763.1000)
    Microsoft Search Enhancement Pack
    Microsoft Silverlight (Version: 4.1.10329.0)
    Microsoft Silverlight (Version: 5.1.20125.0)
    Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000)
    Microsoft Streets & Trips 2006 (Version: 13.00.09.0200)
    Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (Version: 8.0.50727.4053)
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053)
    Microsoft Visual C++ 2005 Redistributable - KB2467175 (Version: 8.0.51011)
    Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336)
    Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (Version: 8.0.51011)
    Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336)
    Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
    Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (Version: 9.0.30729.5570)
    Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (Version: 9.0.30729.5570)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
    Microsoft WSE 3.0 Runtime (Version: 3.0.5305.0)
    Microsoft XML Parser (Version: 8.0.8308.1)
    MotoHelper MergeModules (Version: 1.2.0)
    Motorola Mobile Drivers Installation 5.0.0 (Version: 5.0.0)
    Movie Theme Pack for HP MediaSmart Video (Version: 4.1.4030)
    Mozilla Maintenance Service (Version: 17.0.6)
    Mozilla Thunderbird 17.0.6 (x86 en-US) (Version: 17.0.6)
    MSVCRT (Version: 15.4.2862.0708)
    MSVCRT_amd64 (Version: 15.4.2862.0708)
    MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
    MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
    MSXML 4.0 SP2 Parser and SDK (Version: 4.20.9818.0)
    Mutual of Omaha - Health
    Mutual of Omaha Health Company install
    Norton Internet Security (Version: 20.4.0.40)
    Norton Online Backup (Version: 2.1.17869)
    OpenAL
    PhotoNow! (Version: 1.1.6904)
    PhotoScape
    PictureMover (Version: 3.5.0.28)
    PlayReady PC Runtime amd64 (Version: 1.3.0)
    Power2Go (Version: 6.1.4022)
    PowerDirector (Version: 8.0.2906)
    PressReader (Version: 5.10.621.0)
    Presto! PageManager 8.15.01 SE (Version: 8.15.01)
    Prudential LTC3 Illustration System
    Quicken 2010 (Version: 19.1.1.27)
    QuickTime (Version: 7.69.80.9)
    Quote It!
    Recovery Manager (Version: 5.5.2926)
    Rhapsody
    Roxio CinemaNow 2.0 (Version: 1.0.284)
    Sound Blaster X-Fi (Version: 1.0)
    Speccy (Version: 1.21)
    The Lost Crown version 2 (Version: 2.0)
    The Secret Order: Masked Intent Collector's Edition
    Transamerica Life Products Illustration System - TransWare (Version: 15.50.1100)
    Transamerica Life Products Illustration System - TransWare (Version: 15.60.1336)
    Transamerica Life Products Illustration System - TransWare (Version: 15.70.1280)
    Transamerica Life Products Illustration System - TransWare (Version: 15.90.1127)
    Transamerica Life Products Illustration System - TransWare (Version: 16.60.1076)
    Transamerica Life Products Illustration System TransWare Prerequisite V 2.0 (Version: 5.00.00)
    Transamerica Life Products Illustration System TransWare Prerequisite V3.0 (Version: 10.00.0000)
    VideoBrowser (Version: 2.00.204)
    VueMinder Lite (Version: 9.0.1010)
    Windows Live Communications Platform (Version: 15.4.3502.0922)
    Windows Live Essentials (Version: 15.4.3502.0922)
    Windows Live ID Sign-in Assistant (Version: 7.250.4225.0)
    Windows Live Installer (Version: 15.4.3502.0922)
    Windows Live Language Selector (Version: 15.4.3502.0922)
    Windows Live Mail (Version: 15.4.3502.0922)
    Windows Live Messenger (Version: 15.4.3502.0922)
    Windows Live MIME IFilter (Version: 15.4.3502.0922)
    Windows Live Movie Maker (Version: 15.4.3502.0922)
    Windows Live Photo Common (Version: 15.4.3502.0922)
    Windows Live Photo Gallery (Version: 15.4.3502.0922)
    Windows Live PIMT Platform (Version: 15.4.3502.0922)
    Windows Live SOXE (Version: 15.4.3502.0922)
    Windows Live SOXE Definitions (Version: 15.4.3502.0922)
    Windows Live Sync (Version: 14.0.8089.726)
    Windows Live UX Platform (Version: 15.4.3502.0922)
    Windows Live UX Platform Language Pack (Version: 15.4.3502.0922)
    Windows Live Writer (Version: 15.4.3502.0922)
    Windows Live Writer Resources (Version: 15.4.3502.0922)
    Windows XP Mode (Version: 1.3.7600.16423)
    WinFlex 6 (Version: 6.103.0.21)
    Yontoo 1.10.02 (Version: 1.10.02)
    Zinio Reader 4 (Version: 4.0.2811)

    ==================== Restore Points =========================

    12-06-2013 11:28:23 Windows Update
    12-06-2013 11:43:13 Windows Update
    14-06-2013 00:10:52 before mbar

    ==================== Faulty Device Manager Devices =============

    Name: I:\
    Description: MS/MS-Pro
    Class Guid: {eec5ad98-8080-425f-922a-dabf3de3f69a}
    Manufacturer: Generic-
    Service: WUDFRd
    Problem: : Windows cannot start this hardware device because its configuration information (in the registry) is incomplete or damaged. (Code 19)
    Resolution: A registry problem was detected.
    This can occur when more than one service is defined for a device, if there is a failure opening the service subkey, or if the driver name cannot be obtained from the service subkey. Try these options:
    On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
    Click "Uninstall ", and then click "Scan for hardware changes" to load a usable driver.

    Name: F:\
    Description: SD/MMC
    Class Guid: {eec5ad98-8080-425f-922a-dabf3de3f69a}
    Manufacturer: Generic-
    Service: WUDFRd
    Problem: : Windows cannot start this hardware device because its configuration information (in the registry) is incomplete or damaged. (Code 19)
    Resolution: A registry problem was detected.
    This can occur when more than one service is defined for a device, if there is a failure opening the service subkey, or if the driver name cannot be obtained from the service subkey. Try these options:
    On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
    Click "Uninstall ", and then click "Scan for hardware changes" to load a usable driver.

    Name: H:\
    Description: SM/xD-Picture
    Class Guid: {eec5ad98-8080-425f-922a-dabf3de3f69a}
    Manufacturer: Generic-
    Service: WUDFRd
    Problem: : Windows cannot start this hardware device because its configuration information (in the registry) is incomplete or damaged. (Code 19)
    Resolution: A registry problem was detected.
    This can occur when more than one service is defined for a device, if there is a failure opening the service subkey, or if the driver name cannot be obtained from the service subkey. Try these options:
    On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
    Click "Uninstall ", and then click "Scan for hardware changes" to load a usable driver.

    Name: J:\
    Description: Storage
    Class Guid: {eec5ad98-8080-425f-922a-dabf3de3f69a}
    Manufacturer: EPSON
    Service: WUDFRd
    Problem: : Windows cannot start this hardware device because its configuration information (in the registry) is incomplete or damaged. (Code 19)
    Resolution: A registry problem was detected.
    This can occur when more than one service is defined for a device, if there is a failure opening the service subkey, or if the driver name cannot be obtained from the service subkey. Try these options:
    On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
    Click "Uninstall ", and then click "Scan for hardware changes" to load a usable driver.

    Name: G:\
    Description: Compact Flash
    Class Guid: {eec5ad98-8080-425f-922a-dabf3de3f69a}
    Manufacturer: Generic-
    Service: WUDFRd
    Problem: : Windows cannot start this hardware device because its configuration information (in the registry) is incomplete or damaged. (Code 19)
    Resolution: A registry problem was detected.
    This can occur when more than one service is defined for a device, if there is a failure opening the service subkey, or if the driver name cannot be obtained from the service subkey. Try these options:
    On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
    Click "Uninstall ", and then click "Scan for hardware changes" to load a usable driver.


    ==================== Event log errors: =========================

    Application errors:
    ==================
    Error: (06/13/2013 07:55:01 PM) (Source: Application Hang) (User: )
    Description: The program Explorer.EXE version 6.1.7601.17567 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

    Process ID: 5d0

    Start Time: 01ce689147bfb7e9

    Termination Time: 0

    Application Path: C:\Windows\Explorer.EXE

    Report Id: a3afa65d-d484-11e2-ad4a-6c626d7dcb01

    Error: (06/13/2013 07:47:10 PM) (Source: Application Error) (User: )
    Description: Faulting application name: iexplore.exe, version: 9.0.8112.16490, time stamp: 0x51955cca
    Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
    Exception code: 0xc0000005
    Fault offset: 0x30303220
    Faulting process id: 0x1374
    Faulting application start time: 0xiexplore.exe0
    Faulting application path: iexplore.exe1
    Faulting module path: iexplore.exe2
    Report Id: iexplore.exe3

    Error: (06/13/2013 07:45:46 PM) (Source: Application Hang) (User: )
    Description: The program Explorer.EXE version 6.1.7601.17567 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

    Process ID: 5e4

    Start Time: 01ce68900047907f

    Termination Time: 0

    Application Path: C:\Windows\Explorer.EXE

    Report Id: 594f5a9a-d483-11e2-9393-6c626d7dcb01

    Error: (06/13/2013 07:40:44 PM) (Source: Application Hang) (User: )
    Description: The program Explorer.EXE version 6.1.7601.17567 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

    Process ID: 734

    Start Time: 01ce688f4ec5e9bc

    Termination Time: 0

    Application Path: C:\Windows\Explorer.EXE

    Report Id: a53ca86f-d482-11e2-b1e1-6c626d7dcb01

    Error: (06/13/2013 07:27:26 PM) (Source: Application Hang) (User: )
    Description: The program Explorer.EXE version 6.1.7601.17567 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

    Process ID: 774

    Start Time: 01ce688d6c10fab2

    Termination Time: 0

    Application Path: C:\Windows\Explorer.EXE

    Report Id: c8ce89da-d480-11e2-9da9-6c626d7dcb01

    Error: (06/13/2013 01:57:35 PM) (Source: SideBySide) (User: )
    Description: Activation context generation failed for "assemblyIdentity1 ".Error in manifest or policy file "assemblyIdentity2" on line assemblyIdentity3.
    The value "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute "version" in element "assemblyIdentity" is invalid.

    Error: (06/13/2013 00:28:44 PM) (Source: Application Hang) (User: )
    Description: The program Explorer.EXE version 6.1.7601.17567 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

    Process ID: 76c

    Start Time: 01ce6852ec6c351a

    Termination Time: 0

    Application Path: C:\Windows\Explorer.EXE

    Report Id: 4a66996f-d446-11e2-9346-6c626d7dcb01

    Error: (06/13/2013 00:22:19 PM) (Source: Application Hang) (User: )
    Description: The program Explorer.EXE version 6.1.7601.17567 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

    Process ID: 7ac

    Start Time: 01ce6851d94a0105

    Termination Time: 0

    Application Path: C:\Windows\Explorer.EXE

    Report Id: 65bdd5bd-d445-11e2-9451-6c626d7dcb01

    Error: (06/13/2013 10:06:48 AM) (Source: .NET Runtime) (User: )
    Description: Shim database version C:\Windows\Microsoft.NET\Framework\v4.0.30319 doesn't have a matching runtime directory

    Error: (06/13/2013 10:06:43 AM) (Source: .NET Runtime) (User: )
    Description: Shim database version C:\Windows\Microsoft.NET\Framework\v4.0.30319 doesn't have a matching runtime directory


    System errors:
    =============
    Error: (06/13/2013 07:54:03 PM) (Source: Service Control Manager) (User: )
    Description: The MCSTRM service failed to start due to the following error:
    %%2

    Error: (06/13/2013 07:52:17 PM) (Source: Service Control Manager) (User: )
    Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error:
    %%1068

    Error: (06/13/2013 07:52:15 PM) (Source: Service Control Manager) (User: )
    Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error:
    %%1068

    Error: (06/13/2013 07:52:15 PM) (Source: DCOM) (User: )
    Description: 1068netprofm{A47979D2-C419-11D9-A5B4-001185AD2B89}

    Error: (06/13/2013 07:52:15 PM) (Source: DCOM) (User: )
    Description: 1068netman{BA126AD1-2166-11D1-B1D0-00805FC1270E}

    Error: (06/13/2013 07:52:15 PM) (Source: DCOM) (User: )
    Description: 1084WSearch{7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}

    Error: (06/13/2013 07:52:15 PM) (Source: DCOM) (User: )
    Description: 1084WSearch{9E175B6D-F52A-11D8-B9A5-505054503030}

    Error: (06/13/2013 07:52:14 PM) (Source: DCOM) (User: )
    Description: 1084EventSystem{1BE1F766-5536-11D1-B726-00C04FB926AF}

    Error: (06/13/2013 07:52:05 PM) (Source: DCOM) (User: )
    Description: 1084ShellHWDetection{DD522ACC-F821-461A-A407-50B198B896DC}

    Error: (06/13/2013 07:52:00 PM) (Source: Service Control Manager) (User: )
    Description: The following boot-start or system-start driver(s) failed to load:
    AFD
    BHDrvx64
    ccSet_NIS
    CSC
    DfsC
    discache
    eeCtrl
    IDSVia64
    NetBIOS
    NetBT
    nsiproxy
    Psched
    rdbss
    spldr
    SRTSP
    SRTSPX
    SymIRON
    SymNetS
    tdx
    vpcnfltr
    vpcvmm
    Wanarpv6
    WfpLwf


    Microsoft Office Sessions:
    =========================
    Error: (06/13/2013 07:55:01 PM) (Source: Application Hang)(User: )
    Description: Explorer.EXE6.1.7601.175675d001ce689147bfb7e90C:\Windows\Explorer.EXEa3afa65d-d484-11e2-ad4a-6c626d7dcb01

    Error: (06/13/2013 07:47:10 PM) (Source: Application Error)(User: )
    Description: iexplore.exe9.0.8112.1649051955ccaunknown0.0.0.000000000c000000530303220137401ce689032d2ac90C:\Program Files (x86)\Internet Explorer\iexplore.exeunknown8fa0e054-d483-11e2-9393-6c626d7dcb01

    Error: (06/13/2013 07:45:46 PM) (Source: Application Hang)(User: )
    Description: Explorer.EXE6.1.7601.175675e401ce68900047907f0C:\Windows\Explorer.EXE594f5a9a-d483-11e2-9393-6c626d7dcb01

    Error: (06/13/2013 07:40:44 PM) (Source: Application Hang)(User: )
    Description: Explorer.EXE6.1.7601.1756773401ce688f4ec5e9bc0C:\Windows\Explorer.EXEa53ca86f-d482-11e2-b1e1-6c626d7dcb01

    Error: (06/13/2013 07:27:26 PM) (Source: Application Hang)(User: )
    Description: Explorer.EXE6.1.7601.1756777401ce688d6c10fab20C:\Windows\Explorer.EXEc8ce89da-d480-11e2-9da9-6c626d7dcb01

    Error: (06/13/2013 01:57:35 PM) (Source: SideBySide)(User: )
    Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3

    Error: (06/13/2013 00:28:44 PM) (Source: Application Hang)(User: )
    Description: Explorer.EXE6.1.7601.1756776c01ce6852ec6c351a0C:\Windows\Explorer.EXE4a66996f-d446-11e2-9346-6c626d7dcb01

    Error: (06/13/2013 00:22:19 PM) (Source: Application Hang)(User: )
    Description: Explorer.EXE6.1.7601.175677ac01ce6851d94a01050C:\Windows\Explorer.EXE65bdd5bd-d445-11e2-9451-6c626d7dcb01

    Error: (06/13/2013 10:06:48 AM) (Source: .NET Runtime)(User: )
    Description: Shim database version C:\Windows\Microsoft.NET\Framework\v4.0.30319 doesn't have a matching runtime directory

    Error: (06/13/2013 10:06:43 AM) (Source: .NET Runtime)(User: )
    Description: Shim database version C:\Windows\Microsoft.NET\Framework\v4.0.30319 doesn't have a matching runtime directory


    ==================== Memory info ===========================

    Percentage of memory in use: 23%
    Total physical RAM: 8151.08 MB
    Available physical RAM: 6229.43 MB
    Total Pagefile: 16300.34 MB
    Available Pagefile: 14234.6 MB
    Total Virtual: 8192 MB
    Available Virtual: 8191.8 MB

    ==================== Drives ================================

    Drive c: (OS) (Fixed) (Total:686.13 GB) (Free:594.13 GB) NTFS (Disk=0 Partition=2)
    Drive d: (HP_RECOVERY) (Fixed) (Total:12.41 GB) (Free:1.52 GB) NTFS (Disk=0 Partition=3) ==>[System with boot components (obtained from reading drive)]

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (Size: 699 GB) (Disk ID: 87ADC0D8)
    Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
    Partition 2: (Not Active) - (Size=686 GB) - (Type=07 NTFS)
    Partition 3: (Not Active) - (Size=12 GB) - (Type=07 NTFS)

    ==================== End Of Log ============================
     
  17. 2013/06/13
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Good job :)

    Hold on there while I review your logs.
     
  18. 2013/06/13
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Download attached fixlist.txt file and save it to the Desktop.
    NOTE. It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Run FRST/FRST64 and press the Fix button just once and wait.
    The tool will make a log on the Desktop (Fixlog.txt). Please post it to your reply.

    When done see if RogueKiller will run.
     

    Attached Files:

  19. 2013/06/13
    Woodstock1780

    Woodstock1780 Inactive Thread Starter

    Joined:
    2013/06/12
    Messages:
    57
    Likes Received:
    0
    fixlog.txt

    Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 13-06-2013
    Ran by David Lee Volz at 2013-06-13 21:21:14 Run:1
    Running from C:\Users\David Lee Volz\Desktop
    Boot Mode: Normal
    ==============================================

    HKLM => Group Policy Restriction on software restored successfully.
    HKLM => Group Policy Restriction on software restored successfully.
    HKCR\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InprocServer32\\Default => Value was restored successfully.
    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{40427de2-b478-11e1-b804-6c626d7dcb01} => Key deleted successfully.
    HKCR\CLSID\{40427de2-b478-11e1-b804-6c626d7dcb01} => Key not found.
    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4e31dc87-c274-11e0-8d96-6c626d7dcb01} => Key deleted successfully.
    HKCR\CLSID\{4e31dc87-c274-11e0-8d96-6c626d7dcb01} => Key not found.
    HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully.
    HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\EfficientCalendarFree => Value deleted successfully.
    C:\Users\DAVIDL~1\AppData\Local\Temp\spqvjee\sfrxyqq\wow64.dll => Moved successfully.
    HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\UpdReg => Value deleted successfully.
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f} => Key deleted successfully.
    HKCR\Wow6432Node\CLSID\{d2ce3e00-f94a-4740-988e-03dc2f38c34f} => Key not found.
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{8dcb7100-df86-4384-8842-8fa844297b3f} => Value deleted successfully.
    HKCR\Wow6432Node\CLSID\{8dcb7100-df86-4384-8842-8fa844297b3f} => Key not found.
    HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{37153479-1976-43C3-A1EE-557513977B64} => Value deleted successfully.
    HKCR\CLSID\{37153479-1976-43C3-A1EE-557513977B64} => Key not found.

    ==== End of Fixlog ====
     
  20. 2013/06/13
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Good :)

     
  21. 2013/06/13
    Woodstock1780

    Woodstock1780 Inactive Thread Starter

    Joined:
    2013/06/12
    Messages:
    57
    Likes Received:
    0
    Rk

    Broni, RK stalls at the same place. Also, there is a one line message in RK .... KILL SUSP....then something about antiphishing...tried to right click & copy but it didn't work.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.