SpinelesS
Posts: 55 +0
Every now and then I would start getting Ads by Cloudscout showing up. I would Run windows defender, Malwarebytes and ADWcleaner and they would find nothing, but the adverts would go away
Now I'm getting Ads by DNSUnlocker and Malwarebytes and ADWcleaner still aren't finding anything,
I reset my browsers in the hopes that would help but that just ended with me constantly getting DNSUnlocker ads (went through chromes privacy settings and re-denied a bunch of stuff - cookies etc and they seem to have gone away for now, though I have to assume the virus is still there...)
Downloaded and ran FRST
FRST.TXT:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:04-09-2015
Ran by wills (administrator) on HOME (05-09-2015 19:39:45)
Running from C:\Users\wills\Downloads
Loaded Profiles: wills (Available Profiles: wills)
Platform: Windows 8.1 Pro (X64) Language: English (United Kingdom)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
() C:\ProgramData\MobileBrServ\mbbService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe\livecomm.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642216 2012-08-06] (Advanced Micro Devices, Inc.)
Startup: C:\Users\wills\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk [2013-06-16]
ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\..\Interfaces\{069099DC-4CBE-4446-9B56-194B1E558DDF}: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{1206E400-6297-4C54-831C-BA919F239804}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{AE87B87A-3F62-46C1-ACBA-6444E72AC939}: [DhcpNameServer] 192.168.1.1 192.168.1.1
Internet Explorer:
==================
HKU\S-1-5-21-2328787975-3927773778-2076377496-1004\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/en-au/?ocid=iehp
HKU\S-1-5-21-2328787975-3927773778-2076377496-1004\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://search.msn.com/spbasic.htm
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
FireFox:
========
FF ProfilePath: C:\Users\wills\AppData\Roaming\Mozilla\Firefox\Profiles\yhys6o5n.default-1441424448047
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_18_0_0_232.dll [2015-08-12] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll [2015-08-12] ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-08-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-08-28] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-02-05] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-06-29] (Adobe Systems Inc.)
Chrome:
=======
CHR StartupUrls: Default -> "https://www.google.com/"
CHR Plugin: (Google Slides) - C:\Users\wills\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.8.823\_platform_specific\win_x86\widevinecdmadapter.dll No File
CHR Plugin: (Chrome PDF Viewer) - chrome-extension://mhjfbmdgcfjbbpaeojofohoefgiehjai/ No File
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.85\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.85\internal-nacl-plugin No File
CHR Plugin: (Chrome PDF Viewer) - internal-pdf-viewer No File
CHR Profile: C:\Users\wills\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Chrome Web Store Payments) - C:\Users\wills\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-29]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-08-06] (Advanced Micro Devices, Inc.) [File not signed]
S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] ()
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 Mobile Broadband HL Service; C:\ProgramData\MobileBrServ\mbbservice.exe [242256 2014-08-20] ()
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1900400 2014-11-20] (Electronic Arts)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AODDriver4.1; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [53888 2012-03-05] (Advanced Micro Devices)
R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [22128 2012-03-08] ()
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdW86.sys [98472 2012-07-17] (Advanced Micro Devices)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-06-18] (Malwarebytes Corporation)
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [35064 2015-09-05] ()
S3 usbrndis6; C:\Windows\system32\DRIVERS\usb80236.sys [20992 2015-04-25] (Microsoft Corporation)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation)
R2 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation)
S3 ewusbnet; \SystemRoot\system32\DRIVERS\ewusbnet.sys [X]
S3 huawei_enumerator; \SystemRoot\System32\drivers\ew_jubusenum.sys [X]
S3 hwdatacard; \SystemRoot\system32\DRIVERS\ewusbmdm.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-09-05 19:39 - 2015-09-05 19:41 - 00008286 _____ C:\Users\wills\Downloads\FRST.txt
2015-09-05 19:39 - 2015-09-05 19:40 - 00000000 ____D C:\FRST
2015-09-05 19:38 - 2015-09-05 19:38 - 02188800 _____ (Farbar) C:\Users\wills\Downloads\FRST64.exe
2015-09-05 19:29 - 2015-09-05 19:29 - 00182344 _____ (Adlice Software) C:\Users\wills\Downloads\WhyIGotInfected.exe
2015-09-05 19:13 - 2015-09-05 19:29 - 00000000 ____D C:\ProgramData\RogueKiller
2015-09-05 19:13 - 2015-09-05 19:13 - 00035064 _____ C:\WINDOWS\system32\Drivers\TrueSight.sys
2015-09-05 19:09 - 2015-09-05 19:11 - 18779208 _____ C:\Users\wills\Downloads\RogueKiller.exe
2015-09-05 15:02 - 2015-09-05 15:08 - 00003600 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2328787975-3927773778-2076377496-1004
2015-09-05 14:57 - 2015-09-05 18:46 - 00000154 _____ C:\WINDOWS\setupact.log
2015-09-05 14:57 - 2015-09-05 14:57 - 00000000 _____ C:\WINDOWS\setuperr.log
2015-09-05 14:53 - 2015-08-27 12:48 - 00136904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2015-09-05 14:53 - 2015-08-27 04:00 - 00721920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2015-09-05 14:53 - 2015-08-27 04:00 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuwebv.dll
2015-09-05 14:53 - 2015-08-27 04:00 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
2015-09-05 14:53 - 2015-08-27 04:00 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapp.exe
2015-09-05 14:53 - 2015-08-27 00:46 - 03705344 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2015-09-05 14:53 - 2015-08-27 00:29 - 02240512 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll
2015-09-05 14:53 - 2015-08-27 00:27 - 00891904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2015-09-05 14:53 - 2015-08-27 00:27 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll
2015-09-05 14:53 - 2015-08-27 00:26 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll
2015-09-05 14:53 - 2015-08-27 00:26 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2015-09-05 14:53 - 2015-08-27 00:26 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe
2015-09-05 14:51 - 2015-09-05 19:01 - 00109057 _____ C:\WINDOWS\WindowsUpdate.log
2015-09-05 14:32 - 2015-09-05 14:32 - 00034324 _____ C:\Users\wills\Documents\2015 09 05 Registry Backup cc_20150905_143216.reg
2015-09-05 13:58 - 2015-09-05 13:59 - 06667640 _____ (Piriform Ltd) C:\Users\wills\Downloads\ccsetup509.exe
2015-09-05 11:51 - 2015-09-05 11:51 - 02019656 _____ (Bleeping Computer, LLC) C:\Users\wills\Downloads\iExplore.exe
2015-09-03 13:11 - 2015-09-05 13:55 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-08-31 20:13 - 2015-08-31 20:13 - 00081904 _____ C:\Users\wills\AppData\Local\GDIPFONTCACHEV1.DAT
2015-08-26 16:24 - 2015-08-26 16:25 - 00000025 _____ C:\Users\wills\Documents\ebgames carrots.txt
2015-08-20 10:51 - 2015-08-11 11:20 - 25191936 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-08-20 10:51 - 2015-08-11 10:20 - 19871232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-08-20 10:48 - 2015-07-23 00:19 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\UtcResources.dll
2015-08-20 10:48 - 2015-07-22 23:52 - 01633792 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2015-08-20 10:48 - 2015-07-18 00:15 - 00951296 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdh.dll
2015-08-20 10:48 - 2015-07-18 00:10 - 00749568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdh.dll
2015-08-20 10:48 - 2015-07-04 07:51 - 01380056 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2015-08-20 10:48 - 2015-07-04 00:00 - 01097216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2015-08-20 10:48 - 2015-06-27 21:47 - 00118616 _____ (Microsoft Corporation) C:\WINDOWS\system32\consent.exe
2015-08-20 10:47 - 2015-07-14 13:27 - 00063488 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzsync.exe
2015-08-20 10:47 - 2015-07-14 05:10 - 00411455 _____ C:\WINDOWS\system32\ApnDatabase.xml
2015-08-20 10:47 - 2015-07-10 02:14 - 00228864 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2015-08-20 10:47 - 2015-06-20 03:07 - 02819072 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll
2015-08-19 16:51 - 2015-08-20 15:42 - 00000000 _____ C:\Users\wills\Documents\80 music videos.txt
2015-08-12 19:06 - 2015-07-31 00:04 - 00124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-12 19:06 - 2015-07-30 23:48 - 00103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-08-12 18:56 - 2015-07-17 06:36 - 00417792 _____ (Microsoft Corporation) C:\WINDOWS\system32\html.iec
2015-08-12 18:56 - 2015-07-17 06:35 - 02885632 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-08-12 18:56 - 2015-07-17 06:26 - 05923328 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-08-12 18:56 - 2015-07-17 06:23 - 00615936 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieui.dll
2015-08-12 18:56 - 2015-07-17 05:50 - 00341504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\html.iec
2015-08-12 18:56 - 2015-07-17 05:45 - 02279424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-08-12 18:56 - 2015-07-17 05:41 - 00479232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieui.dll
2015-08-12 18:56 - 2015-07-17 05:38 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2015-08-12 18:56 - 2015-07-17 05:36 - 00801280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2015-08-12 18:56 - 2015-07-17 05:34 - 14451200 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-08-12 18:56 - 2015-07-17 05:32 - 02125824 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2015-08-12 18:56 - 2015-07-17 05:14 - 02880000 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2015-08-12 18:56 - 2015-07-17 05:13 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2015-08-12 18:56 - 2015-07-17 05:12 - 04520448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-08-12 18:56 - 2015-07-17 05:12 - 02427904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-08-12 18:56 - 2015-07-17 05:10 - 12856832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-08-12 18:56 - 2015-07-17 05:01 - 01545728 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-08-12 18:56 - 2015-07-17 04:52 - 01048576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2015-08-12 18:56 - 2015-07-17 04:49 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2015-08-12 18:56 - 2015-07-17 04:42 - 01951232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-08-12 18:56 - 2015-07-17 04:38 - 01310720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-08-12 18:56 - 2015-07-17 04:37 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2015-08-12 18:55 - 2015-07-17 06:36 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-08-12 18:55 - 2015-07-17 06:21 - 00816640 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-08-12 18:55 - 2015-07-17 05:53 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2015-08-12 18:55 - 2015-07-17 05:51 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-08-12 18:55 - 2015-07-17 05:45 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2015-08-12 18:55 - 2015-07-17 05:39 - 00664064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-08-12 18:55 - 2015-07-17 05:06 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2015-08-12 18:55 - 2015-07-16 10:29 - 07458648 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-08-12 18:55 - 2015-07-16 10:29 - 01735000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2015-08-12 18:55 - 2015-07-16 10:29 - 00101720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mountmgr.sys
2015-08-12 18:55 - 2015-07-16 10:28 - 01499920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2015-08-12 18:55 - 2015-07-11 03:54 - 01217024 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmain.dll
2015-08-12 18:54 - 2015-07-14 05:46 - 00059392 _____ (Microsoft Corporation) C:\WINDOWS\system32\csrsrv.dll
2015-08-12 18:54 - 2015-07-07 19:40 - 00270168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdFilter.sys
2015-08-12 18:54 - 2015-07-07 19:40 - 00114520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdNisDrv.sys
2015-08-12 18:54 - 2015-07-07 19:40 - 00044560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdBoot.sys
2015-08-12 18:54 - 2015-07-02 08:19 - 00228864 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebClnt.dll
2015-08-12 18:54 - 2015-07-02 08:16 - 00104448 _____ (Microsoft Corporation) C:\WINDOWS\system32\davclnt.dll
2015-08-12 18:54 - 2015-07-02 07:37 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WebClnt.dll
2015-08-12 18:54 - 2015-07-02 07:35 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\davclnt.dll
2015-08-12 18:53 - 2015-07-30 00:37 - 01994752 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2015-08-12 18:53 - 2015-07-30 00:30 - 01381888 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2015-08-12 18:53 - 2015-07-30 00:23 - 01559552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2015-08-12 18:53 - 2015-07-25 04:57 - 04177408 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2015-08-12 18:53 - 2015-07-25 04:57 - 00358912 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2015-08-12 18:53 - 2015-07-25 04:52 - 00044032 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2015-08-12 18:53 - 2015-07-25 03:27 - 00301568 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2015-08-12 18:53 - 2015-07-25 03:23 - 00035840 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2015-08-12 18:53 - 2015-07-14 13:22 - 02529880 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2015-08-12 18:53 - 2015-07-14 13:21 - 01901776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2015-08-12 18:53 - 2015-07-14 05:45 - 00059392 _____ (Microsoft Corporation) C:\WINDOWS\system32\basesrv.dll
2015-08-12 18:53 - 2015-07-11 04:19 - 01101824 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdvidcrl.dll
2015-08-12 18:53 - 2015-07-11 03:42 - 02345472 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2015-08-12 18:53 - 2015-07-11 03:14 - 00856064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdvidcrl.dll
2015-08-12 18:53 - 2015-07-11 03:13 - 07032320 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2015-08-12 18:53 - 2015-07-11 02:47 - 01556992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2015-08-12 18:53 - 2015-07-11 02:31 - 06213120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2015-08-12 18:53 - 2015-07-10 03:13 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\notepad.exe
2015-08-12 18:53 - 2015-07-10 03:13 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\notepad.exe
2015-08-12 18:53 - 2015-07-10 02:30 - 00212992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\notepad.exe
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-09-05 19:16 - 2015-05-18 09:59 - 00000916 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-09-05 19:08 - 2013-03-02 15:11 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-09-05 19:02 - 2013-08-23 01:36 - 00000000 ____D C:\WINDOWS\system32\sru
2015-09-05 19:02 - 2013-03-03 11:49 - 00000562 _____ C:\WINDOWS\system32\Drivers\etc\hosts.ics
2015-09-05 18:51 - 2014-03-19 01:25 - 00863592 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-09-05 18:48 - 2014-05-16 18:58 - 00000000 __RDO C:\Users\wills\OneDrive
2015-09-05 18:46 - 2015-05-18 09:58 - 00000912 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-09-05 18:46 - 2013-08-23 00:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-09-05 17:10 - 2013-08-22 23:25 - 00786432 ___SH C:\WINDOWS\system32\config\BBI
2015-09-05 17:05 - 2014-05-16 20:15 - 00003910 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{2A0A3BCF-EF48-4FA9-8CCA-9ACF99987F59}
2015-09-05 15:20 - 2013-08-23 01:36 - 00000000 ____D C:\WINDOWS\rescache
2015-09-05 14:55 - 2013-08-23 01:36 - 00000000 ____D C:\WINDOWS\system32\en-GB
2015-09-05 14:52 - 2012-07-26 17:59 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-09-05 14:33 - 2014-07-25 20:31 - 00000000 ____D C:\Program Files (x86)\Steam
2015-09-05 14:33 - 2014-07-11 22:55 - 00000000 ____D C:\WINDOWS\Minidump
2015-09-05 14:33 - 2013-03-03 15:08 - 00000000 ____D C:\Users\wills\AppData\Roaming\uTorrent
2015-09-05 14:18 - 2013-08-23 01:36 - 00000000 ____D C:\WINDOWS\system32\NDF
2015-09-05 14:00 - 2013-03-02 17:54 - 00000834 _____ C:\Users\Public\Desktop\CCleaner.lnk
2015-09-05 14:00 - 2013-03-02 17:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-09-05 14:00 - 2013-03-02 17:54 - 00000000 ____D C:\Program Files\CCleaner
2015-09-05 13:55 - 2013-03-02 14:42 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-09-05 11:58 - 2015-03-10 12:10 - 00113880 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-09-05 11:47 - 2014-07-14 19:17 - 00000000 ____D C:\NeverwinterNights
2015-09-05 11:47 - 2013-03-02 08:56 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-09-05 10:41 - 2013-08-23 01:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-09-03 20:42 - 2015-04-07 16:17 - 00002239 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-09-03 19:47 - 2014-08-14 12:38 - 00705024 ___SH C:\Users\wills\Downloads\Thumbs.db
2015-09-03 11:12 - 2014-04-03 11:01 - 00000000 ____D C:\Users\wills\AppData\Roaming\vlc
2015-09-02 23:18 - 2015-03-10 12:58 - 00000000 ____D C:\AdwCleaner
2015-08-28 21:11 - 2015-05-18 09:59 - 00003888 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-08-28 21:11 - 2015-05-18 09:59 - 00003652 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2015-08-22 12:41 - 2013-03-02 11:36 - 00000000 ____D C:\Users\wills\Documents\Games
2015-08-20 10:49 - 2013-08-23 01:36 - 00000000 ____D C:\WINDOWS\SysWOW64\en-GB
2015-08-15 11:59 - 2013-03-03 10:42 - 00000000 ____D C:\Users\wills\AppData\Local\Packages
2015-08-12 19:19 - 2013-08-23 00:44 - 00377600 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-08-12 19:18 - 2013-03-16 15:08 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-08-12 19:18 - 2013-03-16 15:08 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2015-08-12 19:16 - 2013-08-23 01:36 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-08-12 19:16 - 2013-08-23 01:36 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-08-12 19:16 - 2013-08-23 01:36 - 00000000 ____D C:\Program Files\Windows Defender
2015-08-12 19:16 - 2013-08-23 01:36 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2015-08-12 19:07 - 2013-03-02 16:04 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-08-12 19:06 - 2013-03-16 15:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-08-12 19:05 - 2013-07-15 12:00 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-08-12 19:02 - 2013-03-02 11:14 - 132483416 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-08-12 18:59 - 2013-08-23 01:36 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-12 18:59 - 2013-08-23 01:36 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-12 13:08 - 2013-03-02 15:11 - 00003718 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2015-08-08 23:55 - 2013-08-23 01:38 - 00794088 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-08-08 23:55 - 2013-08-23 01:38 - 00179688 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-08-08 04:46 - 2014-05-15 10:07 - 00000000 ____D C:\Users\wills
==================== Files in the root of some directories =======
2013-04-04 15:49 - 2013-04-04 15:49 - 0005120 _____ () C:\Users\wills\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-04-23 12:30 - 2015-04-23 12:30 - 0000017 _____ () C:\Users\wills\AppData\Local\resmon.resmoncfg
Some files in TEMP:
====================
C:\Users\wills\AppData\Local\Temp\dllnt_dump.dll
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-09-05 18:58
==================== End of FRST.txt ============================
Now I'm getting Ads by DNSUnlocker and Malwarebytes and ADWcleaner still aren't finding anything,
I reset my browsers in the hopes that would help but that just ended with me constantly getting DNSUnlocker ads (went through chromes privacy settings and re-denied a bunch of stuff - cookies etc and they seem to have gone away for now, though I have to assume the virus is still there...)
Downloaded and ran FRST
FRST.TXT:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:04-09-2015
Ran by wills (administrator) on HOME (05-09-2015 19:39:45)
Running from C:\Users\wills\Downloads
Loaded Profiles: wills (Available Profiles: wills)
Platform: Windows 8.1 Pro (X64) Language: English (United Kingdom)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
() C:\ProgramData\MobileBrServ\mbbService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe\livecomm.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642216 2012-08-06] (Advanced Micro Devices, Inc.)
Startup: C:\Users\wills\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk [2013-06-16]
ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\..\Interfaces\{069099DC-4CBE-4446-9B56-194B1E558DDF}: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{1206E400-6297-4C54-831C-BA919F239804}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{AE87B87A-3F62-46C1-ACBA-6444E72AC939}: [DhcpNameServer] 192.168.1.1 192.168.1.1
Internet Explorer:
==================
HKU\S-1-5-21-2328787975-3927773778-2076377496-1004\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/en-au/?ocid=iehp
HKU\S-1-5-21-2328787975-3927773778-2076377496-1004\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://search.msn.com/spbasic.htm
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
FireFox:
========
FF ProfilePath: C:\Users\wills\AppData\Roaming\Mozilla\Firefox\Profiles\yhys6o5n.default-1441424448047
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_18_0_0_232.dll [2015-08-12] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll [2015-08-12] ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-08-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-08-28] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-02-05] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-06-29] (Adobe Systems Inc.)
Chrome:
=======
CHR StartupUrls: Default -> "https://www.google.com/"
CHR Plugin: (Google Slides) - C:\Users\wills\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.8.823\_platform_specific\win_x86\widevinecdmadapter.dll No File
CHR Plugin: (Chrome PDF Viewer) - chrome-extension://mhjfbmdgcfjbbpaeojofohoefgiehjai/ No File
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.85\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.85\internal-nacl-plugin No File
CHR Plugin: (Chrome PDF Viewer) - internal-pdf-viewer No File
CHR Profile: C:\Users\wills\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Chrome Web Store Payments) - C:\Users\wills\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-29]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-08-06] (Advanced Micro Devices, Inc.) [File not signed]
S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] ()
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 Mobile Broadband HL Service; C:\ProgramData\MobileBrServ\mbbservice.exe [242256 2014-08-20] ()
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1900400 2014-11-20] (Electronic Arts)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AODDriver4.1; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [53888 2012-03-05] (Advanced Micro Devices)
R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [22128 2012-03-08] ()
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdW86.sys [98472 2012-07-17] (Advanced Micro Devices)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-06-18] (Malwarebytes Corporation)
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [35064 2015-09-05] ()
S3 usbrndis6; C:\Windows\system32\DRIVERS\usb80236.sys [20992 2015-04-25] (Microsoft Corporation)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation)
R2 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation)
S3 ewusbnet; \SystemRoot\system32\DRIVERS\ewusbnet.sys [X]
S3 huawei_enumerator; \SystemRoot\System32\drivers\ew_jubusenum.sys [X]
S3 hwdatacard; \SystemRoot\system32\DRIVERS\ewusbmdm.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-09-05 19:39 - 2015-09-05 19:41 - 00008286 _____ C:\Users\wills\Downloads\FRST.txt
2015-09-05 19:39 - 2015-09-05 19:40 - 00000000 ____D C:\FRST
2015-09-05 19:38 - 2015-09-05 19:38 - 02188800 _____ (Farbar) C:\Users\wills\Downloads\FRST64.exe
2015-09-05 19:29 - 2015-09-05 19:29 - 00182344 _____ (Adlice Software) C:\Users\wills\Downloads\WhyIGotInfected.exe
2015-09-05 19:13 - 2015-09-05 19:29 - 00000000 ____D C:\ProgramData\RogueKiller
2015-09-05 19:13 - 2015-09-05 19:13 - 00035064 _____ C:\WINDOWS\system32\Drivers\TrueSight.sys
2015-09-05 19:09 - 2015-09-05 19:11 - 18779208 _____ C:\Users\wills\Downloads\RogueKiller.exe
2015-09-05 15:02 - 2015-09-05 15:08 - 00003600 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2328787975-3927773778-2076377496-1004
2015-09-05 14:57 - 2015-09-05 18:46 - 00000154 _____ C:\WINDOWS\setupact.log
2015-09-05 14:57 - 2015-09-05 14:57 - 00000000 _____ C:\WINDOWS\setuperr.log
2015-09-05 14:53 - 2015-08-27 12:48 - 00136904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2015-09-05 14:53 - 2015-08-27 04:00 - 00721920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2015-09-05 14:53 - 2015-08-27 04:00 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuwebv.dll
2015-09-05 14:53 - 2015-08-27 04:00 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
2015-09-05 14:53 - 2015-08-27 04:00 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapp.exe
2015-09-05 14:53 - 2015-08-27 00:46 - 03705344 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2015-09-05 14:53 - 2015-08-27 00:29 - 02240512 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll
2015-09-05 14:53 - 2015-08-27 00:27 - 00891904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2015-09-05 14:53 - 2015-08-27 00:27 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll
2015-09-05 14:53 - 2015-08-27 00:26 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll
2015-09-05 14:53 - 2015-08-27 00:26 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2015-09-05 14:53 - 2015-08-27 00:26 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe
2015-09-05 14:51 - 2015-09-05 19:01 - 00109057 _____ C:\WINDOWS\WindowsUpdate.log
2015-09-05 14:32 - 2015-09-05 14:32 - 00034324 _____ C:\Users\wills\Documents\2015 09 05 Registry Backup cc_20150905_143216.reg
2015-09-05 13:58 - 2015-09-05 13:59 - 06667640 _____ (Piriform Ltd) C:\Users\wills\Downloads\ccsetup509.exe
2015-09-05 11:51 - 2015-09-05 11:51 - 02019656 _____ (Bleeping Computer, LLC) C:\Users\wills\Downloads\iExplore.exe
2015-09-03 13:11 - 2015-09-05 13:55 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-08-31 20:13 - 2015-08-31 20:13 - 00081904 _____ C:\Users\wills\AppData\Local\GDIPFONTCACHEV1.DAT
2015-08-26 16:24 - 2015-08-26 16:25 - 00000025 _____ C:\Users\wills\Documents\ebgames carrots.txt
2015-08-20 10:51 - 2015-08-11 11:20 - 25191936 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-08-20 10:51 - 2015-08-11 10:20 - 19871232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-08-20 10:48 - 2015-07-23 00:19 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\UtcResources.dll
2015-08-20 10:48 - 2015-07-22 23:52 - 01633792 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2015-08-20 10:48 - 2015-07-18 00:15 - 00951296 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdh.dll
2015-08-20 10:48 - 2015-07-18 00:10 - 00749568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdh.dll
2015-08-20 10:48 - 2015-07-04 07:51 - 01380056 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2015-08-20 10:48 - 2015-07-04 00:00 - 01097216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2015-08-20 10:48 - 2015-06-27 21:47 - 00118616 _____ (Microsoft Corporation) C:\WINDOWS\system32\consent.exe
2015-08-20 10:47 - 2015-07-14 13:27 - 00063488 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzsync.exe
2015-08-20 10:47 - 2015-07-14 05:10 - 00411455 _____ C:\WINDOWS\system32\ApnDatabase.xml
2015-08-20 10:47 - 2015-07-10 02:14 - 00228864 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2015-08-20 10:47 - 2015-06-20 03:07 - 02819072 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll
2015-08-19 16:51 - 2015-08-20 15:42 - 00000000 _____ C:\Users\wills\Documents\80 music videos.txt
2015-08-12 19:06 - 2015-07-31 00:04 - 00124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-12 19:06 - 2015-07-30 23:48 - 00103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-08-12 18:56 - 2015-07-17 06:36 - 00417792 _____ (Microsoft Corporation) C:\WINDOWS\system32\html.iec
2015-08-12 18:56 - 2015-07-17 06:35 - 02885632 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-08-12 18:56 - 2015-07-17 06:26 - 05923328 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-08-12 18:56 - 2015-07-17 06:23 - 00615936 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieui.dll
2015-08-12 18:56 - 2015-07-17 05:50 - 00341504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\html.iec
2015-08-12 18:56 - 2015-07-17 05:45 - 02279424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-08-12 18:56 - 2015-07-17 05:41 - 00479232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieui.dll
2015-08-12 18:56 - 2015-07-17 05:38 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2015-08-12 18:56 - 2015-07-17 05:36 - 00801280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2015-08-12 18:56 - 2015-07-17 05:34 - 14451200 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-08-12 18:56 - 2015-07-17 05:32 - 02125824 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2015-08-12 18:56 - 2015-07-17 05:14 - 02880000 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2015-08-12 18:56 - 2015-07-17 05:13 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2015-08-12 18:56 - 2015-07-17 05:12 - 04520448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-08-12 18:56 - 2015-07-17 05:12 - 02427904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-08-12 18:56 - 2015-07-17 05:10 - 12856832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-08-12 18:56 - 2015-07-17 05:01 - 01545728 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-08-12 18:56 - 2015-07-17 04:52 - 01048576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2015-08-12 18:56 - 2015-07-17 04:49 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2015-08-12 18:56 - 2015-07-17 04:42 - 01951232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-08-12 18:56 - 2015-07-17 04:38 - 01310720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-08-12 18:56 - 2015-07-17 04:37 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2015-08-12 18:55 - 2015-07-17 06:36 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-08-12 18:55 - 2015-07-17 06:21 - 00816640 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-08-12 18:55 - 2015-07-17 05:53 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2015-08-12 18:55 - 2015-07-17 05:51 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-08-12 18:55 - 2015-07-17 05:45 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2015-08-12 18:55 - 2015-07-17 05:39 - 00664064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-08-12 18:55 - 2015-07-17 05:06 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2015-08-12 18:55 - 2015-07-16 10:29 - 07458648 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-08-12 18:55 - 2015-07-16 10:29 - 01735000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2015-08-12 18:55 - 2015-07-16 10:29 - 00101720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mountmgr.sys
2015-08-12 18:55 - 2015-07-16 10:28 - 01499920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2015-08-12 18:55 - 2015-07-11 03:54 - 01217024 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmain.dll
2015-08-12 18:54 - 2015-07-14 05:46 - 00059392 _____ (Microsoft Corporation) C:\WINDOWS\system32\csrsrv.dll
2015-08-12 18:54 - 2015-07-07 19:40 - 00270168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdFilter.sys
2015-08-12 18:54 - 2015-07-07 19:40 - 00114520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdNisDrv.sys
2015-08-12 18:54 - 2015-07-07 19:40 - 00044560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdBoot.sys
2015-08-12 18:54 - 2015-07-02 08:19 - 00228864 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebClnt.dll
2015-08-12 18:54 - 2015-07-02 08:16 - 00104448 _____ (Microsoft Corporation) C:\WINDOWS\system32\davclnt.dll
2015-08-12 18:54 - 2015-07-02 07:37 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WebClnt.dll
2015-08-12 18:54 - 2015-07-02 07:35 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\davclnt.dll
2015-08-12 18:53 - 2015-07-30 00:37 - 01994752 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2015-08-12 18:53 - 2015-07-30 00:30 - 01381888 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2015-08-12 18:53 - 2015-07-30 00:23 - 01559552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2015-08-12 18:53 - 2015-07-25 04:57 - 04177408 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2015-08-12 18:53 - 2015-07-25 04:57 - 00358912 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2015-08-12 18:53 - 2015-07-25 04:52 - 00044032 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2015-08-12 18:53 - 2015-07-25 03:27 - 00301568 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2015-08-12 18:53 - 2015-07-25 03:23 - 00035840 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2015-08-12 18:53 - 2015-07-14 13:22 - 02529880 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2015-08-12 18:53 - 2015-07-14 13:21 - 01901776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2015-08-12 18:53 - 2015-07-14 05:45 - 00059392 _____ (Microsoft Corporation) C:\WINDOWS\system32\basesrv.dll
2015-08-12 18:53 - 2015-07-11 04:19 - 01101824 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdvidcrl.dll
2015-08-12 18:53 - 2015-07-11 03:42 - 02345472 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2015-08-12 18:53 - 2015-07-11 03:14 - 00856064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdvidcrl.dll
2015-08-12 18:53 - 2015-07-11 03:13 - 07032320 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2015-08-12 18:53 - 2015-07-11 02:47 - 01556992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2015-08-12 18:53 - 2015-07-11 02:31 - 06213120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2015-08-12 18:53 - 2015-07-10 03:13 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\notepad.exe
2015-08-12 18:53 - 2015-07-10 03:13 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\notepad.exe
2015-08-12 18:53 - 2015-07-10 02:30 - 00212992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\notepad.exe
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-09-05 19:16 - 2015-05-18 09:59 - 00000916 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-09-05 19:08 - 2013-03-02 15:11 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-09-05 19:02 - 2013-08-23 01:36 - 00000000 ____D C:\WINDOWS\system32\sru
2015-09-05 19:02 - 2013-03-03 11:49 - 00000562 _____ C:\WINDOWS\system32\Drivers\etc\hosts.ics
2015-09-05 18:51 - 2014-03-19 01:25 - 00863592 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-09-05 18:48 - 2014-05-16 18:58 - 00000000 __RDO C:\Users\wills\OneDrive
2015-09-05 18:46 - 2015-05-18 09:58 - 00000912 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-09-05 18:46 - 2013-08-23 00:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-09-05 17:10 - 2013-08-22 23:25 - 00786432 ___SH C:\WINDOWS\system32\config\BBI
2015-09-05 17:05 - 2014-05-16 20:15 - 00003910 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{2A0A3BCF-EF48-4FA9-8CCA-9ACF99987F59}
2015-09-05 15:20 - 2013-08-23 01:36 - 00000000 ____D C:\WINDOWS\rescache
2015-09-05 14:55 - 2013-08-23 01:36 - 00000000 ____D C:\WINDOWS\system32\en-GB
2015-09-05 14:52 - 2012-07-26 17:59 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-09-05 14:33 - 2014-07-25 20:31 - 00000000 ____D C:\Program Files (x86)\Steam
2015-09-05 14:33 - 2014-07-11 22:55 - 00000000 ____D C:\WINDOWS\Minidump
2015-09-05 14:33 - 2013-03-03 15:08 - 00000000 ____D C:\Users\wills\AppData\Roaming\uTorrent
2015-09-05 14:18 - 2013-08-23 01:36 - 00000000 ____D C:\WINDOWS\system32\NDF
2015-09-05 14:00 - 2013-03-02 17:54 - 00000834 _____ C:\Users\Public\Desktop\CCleaner.lnk
2015-09-05 14:00 - 2013-03-02 17:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-09-05 14:00 - 2013-03-02 17:54 - 00000000 ____D C:\Program Files\CCleaner
2015-09-05 13:55 - 2013-03-02 14:42 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-09-05 11:58 - 2015-03-10 12:10 - 00113880 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-09-05 11:47 - 2014-07-14 19:17 - 00000000 ____D C:\NeverwinterNights
2015-09-05 11:47 - 2013-03-02 08:56 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-09-05 10:41 - 2013-08-23 01:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-09-03 20:42 - 2015-04-07 16:17 - 00002239 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-09-03 19:47 - 2014-08-14 12:38 - 00705024 ___SH C:\Users\wills\Downloads\Thumbs.db
2015-09-03 11:12 - 2014-04-03 11:01 - 00000000 ____D C:\Users\wills\AppData\Roaming\vlc
2015-09-02 23:18 - 2015-03-10 12:58 - 00000000 ____D C:\AdwCleaner
2015-08-28 21:11 - 2015-05-18 09:59 - 00003888 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-08-28 21:11 - 2015-05-18 09:59 - 00003652 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2015-08-22 12:41 - 2013-03-02 11:36 - 00000000 ____D C:\Users\wills\Documents\Games
2015-08-20 10:49 - 2013-08-23 01:36 - 00000000 ____D C:\WINDOWS\SysWOW64\en-GB
2015-08-15 11:59 - 2013-03-03 10:42 - 00000000 ____D C:\Users\wills\AppData\Local\Packages
2015-08-12 19:19 - 2013-08-23 00:44 - 00377600 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-08-12 19:18 - 2013-03-16 15:08 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-08-12 19:18 - 2013-03-16 15:08 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2015-08-12 19:16 - 2013-08-23 01:36 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-08-12 19:16 - 2013-08-23 01:36 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-08-12 19:16 - 2013-08-23 01:36 - 00000000 ____D C:\Program Files\Windows Defender
2015-08-12 19:16 - 2013-08-23 01:36 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2015-08-12 19:07 - 2013-03-02 16:04 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-08-12 19:06 - 2013-03-16 15:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-08-12 19:05 - 2013-07-15 12:00 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-08-12 19:02 - 2013-03-02 11:14 - 132483416 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-08-12 18:59 - 2013-08-23 01:36 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-12 18:59 - 2013-08-23 01:36 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-12 13:08 - 2013-03-02 15:11 - 00003718 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2015-08-08 23:55 - 2013-08-23 01:38 - 00794088 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-08-08 23:55 - 2013-08-23 01:38 - 00179688 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-08-08 04:46 - 2014-05-15 10:07 - 00000000 ____D C:\Users\wills
==================== Files in the root of some directories =======
2013-04-04 15:49 - 2013-04-04 15:49 - 0005120 _____ () C:\Users\wills\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-04-23 12:30 - 2015-04-23 12:30 - 0000017 _____ () C:\Users\wills\AppData\Local\resmon.resmoncfg
Some files in TEMP:
====================
C:\Users\wills\AppData\Local\Temp\dllnt_dump.dll
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-09-05 18:58
==================== End of FRST.txt ============================