FYI: Get Savin removed by Junkware Removal Tool (by Thisisu) Win7 64bit

Solved
By Row1
Jun 11, 2013
  1. FYI: Get Savin removed by Junkware Removal Tool (by Thisisu) Win7 64bit
    I never get these trashy annoying adware programs because I browse safely. But for work, I wanted to access a government report - the only version anyone knew of was on Docstoc - in an unsuccessful attempt to download this document (maybe things would have gone well if I had paid the $120 annual use fee), it asked to install a downloader application.

    I agreed (- dumb -) and tried hard to deselect all the options to make this or that my home page etc. etc.

    After installation, I looked at "uninstall prorgams," and uninstalled several that magically appeared. One, GetSavin, said it could not uninstall because it was already removed.

    Right.

    This was all over my IExplorere - suggesting search terms including 'phallus' and a couple other sketchy terms, opening new windows so quickly it looked like it was th epage I had clicked to go to, etc.

    Could not "uninstall." Their webpage says to uninstall, use the uninstall feature - wrong.

    I browsed techspot until I found one of the great but lengthy malware removal sessions. I figured out that the person had 'getsavin' removed after running a couple specific adware/malware programs.

    -This may not be the official, acceptable way to use techspot, but I did it anyway.-

    I downloaded one program mentioned there - Junkware Removal Tool (by Thisisu). I ran it. Getsavin seems totally gone. No other problems thus far.

    I hope this bit of info helps someone else.
  2. Broni

    Broni Malware Annihilator Posts: 45,275   +243

    Thank you for reporting happy computer :)
  3. Row1

    Row1 TechSpot Maniac Topic Starter Posts: 349   +8

    OK, I am having occasional 'explorer has quit working' notices, so the removal may not have gone perfectly. Possibly because this was added along with a utility I asked to download, then also with a handful of other annoyances I did not want - and removed one by one.

    Can I reload Internet Explorer? I am not due for an upgrade.
  4. Broni

    Broni Malware Annihilator Posts: 45,275   +243

    We can run some checks...

    Please, complete all steps listed here: http://www.techspot.com/vb/topic58138.html
    Make sure, you PASTE all logs. If some log exceeds 50,000 characters post limit, split it between couple of replies.
    Attached logs won't be reviewed.

    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running any tools, fixes or applying any changes to your computer other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.
  5. Row1

    Row1 TechSpot Maniac Topic Starter Posts: 349   +8

    Ok let's do it. getsav-in has re-installed itself.
    I will start posting logs in a minute.
  6. Row1

    Row1 TechSpot Maniac Topic Starter Posts: 349   +8

    I am downloading avast. I am in 'inpriv ate bro wsing' mode - this seems to be keeping the malarcky at bay.
  7. Row1

    Row1 TechSpot Maniac Topic Starter Posts: 349   +8

    Avast says no threat found,
  8. Broni

    Broni Malware Annihilator Posts: 45,275   +243

    Go on...
  9. Row1

    Row1 TechSpot Maniac Topic Starter Posts: 349   +8

    Malwarebytes sez no problems detected...
    log:


    Malwarebytes Anti-Malware (Trial) 1.75.0.1300
    www.malwarebytes.org
    Database version: v2013.06.11.08
    Windows 7 Service Pack 1 x64 NTFS
    Internet Explorer 9.0.8112.16421
    Paul Rowan :: SPH4860 [administrator]
    Protection: Enabled
    6/11/2013 9:39:14 PM
    mbam-log-2013-06-11 (21-39-14).txt
    Scan type: Full scan (C:\|)
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 336181
    Time elapsed: 36 minute(s), 48 second(s)
    Memory Processes Detected: 0
    (No malicious items detected)
    Memory Modules Detected: 0
    (No malicious items detected)
    Registry Keys Detected: 0
    (No malicious items detected)
    Registry Values Detected: 0
    (No malicious items detected)
    Registry Data Items Detected: 0
    (No malicious items detected)
    Folders Detected: 0
    (No malicious items detected)
    Files Detected: 0
    (No malicious items detected)
    (end)
  10. Row1

    Row1 TechSpot Maniac Topic Starter Posts: 349   +8

    DDS log:

    DDS (Ver_2012-11-20.01) - NTFS_AMD64
    Internet Explorer: 9.0.8112.16483
    Run by Paul Rowan at 22:45:26 on 2013-06-11
    Microsoft Windows 7 Enterprise 6.1.7601.1.1252.1.1033.18.3969.1962 [GMT -5:00]
    .
    AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
    AV: Microsoft Security Essentials *Enabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5}
    SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    SP: Microsoft Security Essentials *Enabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508}
    .
    ============== Running Processes ===============
    .
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\svchost.exe -k RPCSS
    c:\Program Files\Microsoft Security Client\MsMpEng.exe
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Program Files\IDT\WDM\STacSV64.exe
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\ngvpnmgr.exe
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\system32\WLANExt.exe
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
    C:\Program Files\Broadcom\MgmtAgent\BrcmMgmtAgent.exe
    C:\Program Files\Intel\WiFi\bin\EvtEng.exe
    C:\Windows\system32\HPSIsvc.exe
    C:\Program Files\Intel\iCLS Client\HeciServer.exe
    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
    C:\Windows\system32\o2flash.exe
    C:\Windows\SysWOW64\srvany.exe
    C:\Windows\sysWOW64\SDIOAssist.exe
    C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    c:\Program Files\Microsoft Security Client\NisSrv.exe
    C:\Windows\system32\taskhost.exe
    C:\Windows\system32\Dwm.exe
    C:\Program Files\Microsoft Security Client\msseces.exe
    C:\Windows\System32\igfxtray.exe
    C:\Windows\System32\hkcmd.exe
    C:\Windows\System32\igfxpers.exe
    C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
    C:\Program Files\IDT\WDM\sttray64.exe
    C:\Program Files\DellTPad\Apoint.exe
    C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
    C:\Program Files (x86)\Winamp\winampa.exe
    C:\Program Files\DellTPad\ApMsgFwd.exe
    C:\Program Files\DellTPad\HidFind.exe
    C:\Program Files\DellTPad\Apntex.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Windows\system32\SearchIndexer.exe
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe
    C:\Windows\explorer.exe
    C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
    C:\Program Files (x86)\Internet Explorer\iexplore.exe
    C:\Windows\system32\prevhost.exe
    C:\Program Files (x86)\Internet Explorer\iexplore.exe
    C:\Program Files\AVAST Software\Avast\AvastSvc.exe
    C:\Program Files\AVAST Software\Avast\AvastUI.exe
    C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
    C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
    C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
    C:\Windows\SysWOW64\prevhost.exe
    C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe
    C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe
    C:\Windows\SysWOW64\ctfmon.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Windows\System32\cscript.exe
    .
    ============== Pseudo HJT Report ===============
    .
    uStart Page = hxxp://www.altavista.com/
    uURLSearchHooks: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - <orphaned>
    mWinlogon: Userinit = userinit.exe
    BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
    BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
    BHO: getsav-in 5.0: {B191C6E6-0B41-46B8-A2D3-85365587B2B7} - C:\Users\Paul Rowan\AppData\Local\getsav-in\ie\getsav-in_1370913901.dll
    BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL
    TB: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
    uRun: [ISUSPM] "C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe" -scheduler
    mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    mRun: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
    mRun: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
    mRun: [IMSS] "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe"
    mRun: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
    mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
    mRunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
    mPolicies-Explorer: NoActiveDesktop = dword:1
    mPolicies-Explorer: NoActiveDesktopChanges = dword:1
    mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
    mPolicies-System: ConsentPromptBehaviorUser = dword:3
    mPolicies-System: EnableUIADesktopToggle = dword:0
    IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
    IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
    DPF: {32E7B36C-7960-4A42-B83B-D8AFD0AAEF2B} - hxxp://dizun95pzobbc.cloudfront.net/INDBrowser.CAB
    DPF: {99E63F21-514B-4C2B-9170-D25D54F65D5B} - hxxp://dizun95pzobbc.cloudfront.net/VBIXDPlayer.CAB
    TCP: NameServer = 192.168.1.254
    TCP: Interfaces\{4D9A57CD-4536-4CFD-AC0E-34BEC8EFDFA4} : DHCPNameServer = 192.168.1.254
    TCP: Interfaces\{4D9A57CD-4536-4CFD-AC0E-34BEC8EFDFA4}\2375942554637303 : DHCPNameServer = 192.168.1.254
    TCP: Interfaces\{4D9A57CD-4536-4CFD-AC0E-34BEC8EFDFA4}\5545843534 : DHCPNameServer = 129.106.9.82 129.106.175.225 129.106.9.83
    TCP: Interfaces\{4D9A57CD-4536-4CFD-AC0E-34BEC8EFDFA4}\D416272796F64747D234F6E666562756E63656 : DHCPNameServer = 8.8.8.8 8.8.4.4
    TCP: Interfaces\{4D9A57CD-4536-4CFD-AC0E-34BEC8EFDFA4}\D416272796F64747D27457563747 : DHCPNameServer = 8.8.8.8 8.8.4.4
    TCP: Interfaces\{AA8D1025-E8AA-4917-A23D-5FE6E5A1EA48} : DHCPNameServer = 129.106.9.82 129.106.175.225 129.106.9.83
    Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
    SSODL: WebCheck - <orphaned>
    SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
    x64-BHO: avast! Online Security: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
    x64-BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL
    x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL
    x64-TB: avast! Online Security: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
    x64-Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
    x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
    x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
    x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
    x64-Run: [IntelPROSet] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel PROSet/Wireless
    x64-Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe
    x64-Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
    x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
    x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
    x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
    x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
    x64-Notify: igfxcui - igfxdev.dll
    x64-SSODL: WebCheck - <orphaned>
    x64-SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL
    .
    ============= SERVICES / DRIVERS ===============
    .
    R0 aswVmm;aswVmm;C:\Windows\System32\drivers\aswVmm.sys [2013-6-11 189936]
    R0 iusb3hcs;Intel(R) USB 3.0 Host Controller Switch Driver;C:\Windows\System32\drivers\iusb3hcs.sys [2013-1-8 16152]
    R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2013-1-20 230320]
    R1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2013-6-11 378432]
    R2 aswFsBlk;aswFsBlk;C:\Windows\System32\drivers\aswFsBlk.sys [2013-6-11 33400]
    R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2013-6-11 80816]
    R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-6-11 46808]
    R2 BrcmMgmtAgent;Broadcom Management Agent;C:\Program Files\Broadcom\MgmtAgent\BrcmMgmtAgent.exe [2011-11-30 163840]
    R2 HPSIService;HP SI Service;C:\Windows\System32\HPSIsvc.exe [2013-1-15 127800]
    R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-6-19 634632]
    R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe [2013-1-8 166720]
    R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-6-11 418376]
    R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-6-11 701512]
    R2 NgVpnMgr;Aventail VPN Client;C:\Windows\System32\ngvpnmgr.exe [2011-9-22 510536]
    R2 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2012-8-30 130008]
    R2 O2SDIOAssist;O2SDIOAssist;C:\Windows\SysWOW64\srvany.exe [2013-1-8 8192]
    R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2013-1-8 365376]
    R2 ZeroConfigService;Intel(R) PROSet/Wireless Zero Configuration Service;C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2012-8-23 3342640]
    R3 IntcDAud;Intel(R) Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2013-1-7 331264]
    R3 iusb3hub;Intel(R) USB 3.0 Hub Driver;C:\Windows\System32\drivers\iusb3hub.sys [2013-1-8 356120]
    R3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver;C:\Windows\System32\drivers\iusb3xhc.sys [2013-1-8 787736]
    R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2013-6-11 25928]
    R3 NgLog;Aventail VPN Logging;C:\Windows\System32\drivers\nglog.sys [2011-9-22 31304]
    R3 NgVpn;Aventail VPN Adapter;C:\Windows\System32\drivers\ngvpn.sys [2011-9-22 103496]
    R3 NgWfp;Aventail VPN Callout;C:\Windows\System32\drivers\ngwfp.sys [2011-9-22 28744]
    R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2013-1-27 379360]
    R3 O2SDJRDR;O2SDJRDR;C:\Windows\System32\drivers\o2sdjw7x64.sys [2011-11-14 84712]
    S0 aswRvrt;aswRvrt;C:\Windows\System32\drivers\aswRvrt.sys [2013-6-11 65336]
    S1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2013-6-11 1025808]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
    S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-1-8 161536]
    S3 dmvsc;dmvsc;C:\Windows\System32\drivers\dmvsc.sys [2011-4-12 71168]
    S3 mvusbews;USB EWS Device;C:\Windows\System32\drivers\mvusbews.sys [2012-11-7 19968]
    S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2012-8-23 272688]
    S3 NgFilter;Aventail VPN Filter;C:\Windows\System32\drivers\ngfilter.sys [2011-9-22 26184]
    S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2010-11-20 20992]
    S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136]
    S3 Synth3dVsc;Synth3dVsc;C:\Windows\System32\drivers\Synth3dVsc.sys [2011-4-12 88960]
    S3 terminpt;Microsoft Remote Desktop Input Driver;C:\Windows\System32\drivers\terminpt.sys [2011-4-12 34816]
    S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-20 59392]
    S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-20 31232]
    S3 tsusbhub;tsusbhub;C:\Windows\System32\drivers\tsusbhub.sys [2011-4-12 117248]
    S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2013-1-7 1255736]
    .
    =============== Created Last 30 ================
    .
    2013-06-12 02:37:12 -------- d-----w- C:\Users\Paul Rowan\AppData\Roaming\Malwarebytes
    2013-06-12 02:37:01 -------- d-----w- C:\ProgramData\Malwarebytes
    2013-06-12 02:36:59 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys
    2013-06-12 02:36:58 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
    2013-06-12 02:36:41 -------- d-----w- C:\Users\Paul Rowan\AppData\Local\Programs
    2013-06-12 02:28:18 72016 ----a-w- C:\Windows\System32\drivers\aswRdr2.sys
    2013-06-12 02:28:17 1025808 ----a-w- C:\Windows\System32\drivers\aswSnx.sys
    2013-06-12 02:28:16 189936 ----a-w- C:\Windows\System32\drivers\aswVmm.sys
    2013-06-12 02:28:15 65336 ----a-w- C:\Windows\System32\drivers\aswRvrt.sys
    2013-06-12 02:28:08 80816 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys
    2013-06-12 02:27:01 41664 ----a-w- C:\Windows\avastSS.scr
    2013-06-12 02:26:45 -------- d-----w- C:\Program Files\AVAST Software
    2013-06-12 02:25:37 -------- d-----w- C:\ProgramData\AVAST Software
    2013-06-12 01:33:14 9460464 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{03D7C711-AE76-4B88-8BB7-B1440A5CA6F1}\mpengine.dll
    2013-06-11 14:53:59 -------- d-----w- C:\Windows\ERUNT
    2013-06-11 14:53:52 -------- d-----w- C:\JRT
    2013-06-11 13:57:03 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
    2013-06-11 13:57:03 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy
    2013-06-11 01:31:49 -------- d-----w- C:\Windows\System32\appmgmt
    2013-06-11 01:30:34 -------- d-----w- C:\Users\Paul Rowan\AppData\Roaming\Zeon
    2013-06-11 01:26:01 -------- d-----w- C:\Users\Paul Rowan\AppData\Local\getsav-in
    2013-06-11 01:19:13 -------- d-----w- C:\ProgramData\APN
    2013-06-11 00:35:52 9460464 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
    2013-06-04 02:46:18 1892184 ----a-w- C:\Windows\SysWow64\D3DX9_42.dll
    2013-06-04 02:46:17 2414360 ----a-w- C:\Windows\SysWow64\d3dx9_31.dll
    2013-06-04 02:45:32 -------- d-----w- C:\Program Files (x86)\Common Files\PX Storage Engine
    2013-05-22 20:50:43 964552 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{6A237217-0CCC-47BA-9266-6C3F2C79C86D}\gapaengine.dll
    2013-05-15 23:08:05 -------- d-----w- C:\Program Files (x86)\Citrix
    2013-05-15 23:07:42 61304 ----a-w- C:\Users\Paul Rowan\g2mdlhlpx.exe
    2013-05-15 23:07:25 -------- d-----w- C:\Users\Paul Rowan\AppData\Local\Deployment
    2013-05-15 23:07:25 -------- d-----w- C:\Users\Paul Rowan\AppData\Local\Apps
    2013-05-15 08:02:14 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
    2013-05-15 08:02:14 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
    2013-05-15 00:32:44 983400 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys
    .
    ==================== Find3M ====================
    .
    2013-05-15 00:18:50 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
    2013-05-15 00:18:50 692104 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
    2013-05-02 15:29:56 278800 ------w- C:\Windows\System32\MpSigStub.exe
    2013-04-14 17:58:52 286720 ------w- C:\Windows\Setup1.exe
    2013-04-14 17:58:50 73216 ----a-w- C:\Windows\ST6UNST.EXE
    2013-04-13 05:49:23 135168 ----a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
    2013-04-13 05:49:19 350208 ----a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
    2013-04-13 05:49:19 308736 ----a-w- C:\Windows\apppatch\AppPatch64\AcGenral.dll
    2013-04-13 05:49:19 111104 ----a-w- C:\Windows\apppatch\AppPatch64\acspecfc.dll
    2013-04-13 04:45:16 474624 ----a-w- C:\Windows\apppatch\AcSpecfc.dll
    2013-04-13 04:45:15 2176512 ----a-w- C:\Windows\apppatch\AcGenral.dll
    2013-04-12 14:45:08 1656680 ----a-w- C:\Windows\System32\drivers\ntfs.sys
    2013-04-10 06:01:54 265064 ----a-w- C:\Windows\System32\drivers\dxgmms1.sys
    2013-04-10 03:30:50 3153920 ----a-w- C:\Windows\System32\win32k.sys
    2013-04-05 01:08:44 2312704 ----a-w- C:\Windows\System32\jscript9.dll
    2013-04-05 01:00:30 1392128 ----a-w- C:\Windows\System32\wininet.dll
    2013-04-05 00:59:24 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl
    2013-04-05 00:56:16 173056 ----a-w- C:\Windows\System32\ieUnatt.exe
    2013-04-05 00:55:47 599040 ----a-w- C:\Windows\System32\vbscript.dll
    2013-04-04 22:11:34 1800704 ----a-w- C:\Windows\SysWow64\jscript9.dll
    2013-04-04 22:02:59 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
    2013-04-04 22:02:17 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll
    2013-04-04 21:58:51 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
    2013-04-04 21:57:45 420864 ----a-w- C:\Windows\SysWow64\vbscript.dll
    2013-03-19 06:04:06 5550424 ----a-w- C:\Windows\System32\ntoskrnl.exe
    2013-03-19 05:53:58 48640 ----a-w- C:\Windows\System32\wwanprotdim.dll
    2013-03-19 05:53:58 230400 ----a-w- C:\Windows\System32\wwansvc.dll
    2013-03-19 05:46:56 43520 ----a-w- C:\Windows\System32\csrsrv.dll
    2013-03-19 05:04:13 3968856 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
    2013-03-19 05:04:10 3913560 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
    2013-03-19 04:47:50 6656 ----a-w- C:\Windows\SysWow64\apisetschema.dll
    2013-03-19 03:06:33 112640 ----a-w- C:\Windows\System32\smss.exe
    .
    ============= FINISH: 22:45:58.03 ===============
  11. Row1

    Row1 TechSpot Maniac Topic Starter Posts: 349   +8

    DDS Attach log:

    .
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT
    .
    DDS (Ver_2012-11-20.01)
    .
    Microsoft Windows 7 Enterprise
    Boot Device: \Device\HarddiskVolume1
    Install Date: 1/7/2013 1:43:35 PM
    System Uptime: 6/11/2013 2:05:47 PM (8 hours ago)
    .
    Motherboard: Dell Inc. | | 0MYF02
    Processor: Intel(R) Core(TM) i5-3320M CPU @ 2.60GHz | SOCKET 0 | 1196/100mhz
    .
    ==== Disk Partitions =========================
    .
    C: is FIXED (NTFS) - 298 GiB total, 249.678 GiB free.
    D: is CDROM ()
    .
    ==== Disabled Device Manager Items =============
    .
    Class GUID:
    Description:
    Device ID: ACPI\SMO8810\1
    Manufacturer:
    Name:
    PNP Device ID: ACPI\SMO8810\1
    Service:
    .
    ==== System Restore Points ===================
    .
    RP57: 5/13/2013 1:37:19 AM - Windows Update
    RP58: 5/15/2013 3:00:13 AM - Windows Update
    RP59: 5/19/2013 4:16:56 PM - Windows Update
    RP60: 5/23/2013 7:12:46 PM - Windows Update
    RP61: 5/27/2013 12:04:05 AM - Windows Update
    RP62: 5/30/2013 9:28:29 PM - Windows Update
    RP63: 6/3/2013 8:32:55 PM - Windows Update
    RP64: 6/3/2013 9:46:01 PM - Installed DirectX
    RP65: 6/7/2013 7:04:40 PM - Windows Update
    RP66: 6/10/2013 7:35:26 PM - Windows Update
    RP67: 6/10/2013 8:31:26 PM - Removed Nuance PDF Reader.
    RP68: 6/11/2013 9:26:32 PM - avast! Free Antivirus Setup
    .
    ==== Installed Programs ======================
    .
    Adobe Flash Player 11 ActiveX
    Adobe Reader X (10.1.0)
    Amazon MP3 Downloader 1.0.17
    avast! Free Antivirus
    Aventail Access Manager
    Aventail Connect
    Broadcom NetXtreme-I Netlink Driver and Management Installer
    CAM UnZip 4.5
    Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition
    Dell Touchpad
    getsav-in
    HP LaserJet Professional P1100-P1560-P1600 Series
    IBM SPSS Statistics 20
    IDT Audio
    Intel PROSet Wireless
    Intel(R) Management Engine Components
    Intel(R) OpenCL CPU Runtime
    Intel(R) Processor Graphics
    Intel(R) USB 3.0 eXtensible Host Controller Driver
    Intel® PROSet/Wireless WiFi Software
    Intel® Trusted Connect Service Client
    IrfanView (remove only)
    Malwarebytes Anti-Malware version 1.75.0.1300
    Microsoft .NET Framework 4 Client Profile
    Microsoft Office 2010 Service Pack 1 (SP1)
    Microsoft Office Access MUI (English) 2010
    Microsoft Office Access Setup Metadata MUI (English) 2010
    Microsoft Office Excel MUI (English) 2010
    Microsoft Office Groove MUI (English) 2010
    Microsoft Office InfoPath MUI (English) 2010
    Microsoft Office Office 64-bit Components 2010
    Microsoft Office OneNote MUI (English) 2010
    Microsoft Office Outlook MUI (English) 2010
    Microsoft Office PowerPoint MUI (English) 2010
    Microsoft Office Professional Plus 2010
    Microsoft Office Proof (English) 2010
    Microsoft Office Proof (French) 2010
    Microsoft Office Proof (Spanish) 2010
    Microsoft Office Proofing (English) 2010
    Microsoft Office Publisher MUI (English) 2010
    Microsoft Office Shared 64-bit MUI (English) 2010
    Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
    Microsoft Office Shared MUI (English) 2010
    Microsoft Office Shared Setup Metadata MUI (English) 2010
    Microsoft Office Word MUI (English) 2010
    Microsoft Security Client
    Microsoft Security Essentials
    Microsoft Silverlight
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
    O2Micro Flash Memory Card Windows Driver
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576)
    Security Update for Microsoft Excel 2010 (KB2597126) 32-Bit Edition
    Security Update for Microsoft Filter Pack 2.0 (KB2553501) 32-Bit Edition
    Security Update for Microsoft InfoPath 2010 (KB2687422) 32-Bit Edition
    Security Update for Microsoft InfoPath 2010 (KB2760406) 32-Bit Edition
    Security Update for Microsoft Office 2010 (KB2553091)
    Security Update for Microsoft Office 2010 (KB2553096)
    Security Update for Microsoft Office 2010 (KB2553371) 32-Bit Edition
    Security Update for Microsoft Office 2010 (KB2553447) 32-Bit Edition
    Security Update for Microsoft Office 2010 (KB2589320) 32-Bit Edition
    Security Update for Microsoft Office 2010 (KB2598243) 32-Bit Edition
    Security Update for Microsoft Office 2010 (KB2687501) 32-Bit Edition
    Security Update for Microsoft Office 2010 (KB2687510) 32-Bit Edition
    Security Update for Microsoft OneNote 2010 (KB2760600) 32-Bit Edition
    Security Update for Microsoft Publisher 2010 (KB2553147) 32-Bit Edition
    Security Update for Microsoft Visio 2010 (KB2810068) 32-Bit Edition
    Security Update for Microsoft Visio Viewer 2010 (KB2687505) 32-Bit Edition
    Security Update for Microsoft Word 2010 (KB2760410) 32-Bit Edition
    Skype™ 6.1
    Spybot - Search & Destroy
    Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
    Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
    Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
    Update for Microsoft Office 2010 (KB2553065)
    Update for Microsoft Office 2010 (KB2553092)
    Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2553378) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2566458)
    Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2687503) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2687509) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2767886) 32-Bit Edition
    Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition
    Update for Microsoft Outlook 2010 (KB2597090) 32-Bit Edition
    Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition
    Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition
    Update for Microsoft PowerPoint 2010 (KB2598240) 32-Bit Edition
    Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition
    Winamp
    .
    ==== End Of File ===========================
  12. Broni

    Broni Malware Annihilator Posts: 45,275   +243

    [​IMG] You're running two AV programs, MSE and Avast.
    You must uninstall one of them.

    [​IMG] Download RogueKiller for 32bit or Roguekiller for 64bit to your Desktop.
    • Close all the running programs
    • Windows Vista/7 users: right click on RogueKiller.exe, click Run as Administrator
    • Otherwise just double-click on RogueKiller.exe
    • Pre-scan will start. Let it finish.
    • Click on SCAN button.
    • Wait until the Status box shows Scan Finished
    • Click on Delete.
    • Wait until the Status box shows Deleting Finished.
    • Click on Report and copy/paste the content of the Notepad into your next reply.
    • RKreport.txt could also be found on your desktop.
    • If more than one log is produced post all logs.
    • If RogueKiller has been blocked, do not hesitate to try a few times more. If really won't run, rename it to winlogon.exe (or winlogon.com) and try again

    [​IMG] Create new restore point before proceeding with the next step....
    How to:
    - Windows 8: http://www.vikitech.com/11302/system-restore-windows-8
    - Windows 7: http://www.howtogeek.com/howto/3195/create-a-system-restore-point-in-windows-7/
    - Vista: http://www.howtogeek.com/howto/wind...tore-point-for-windows-vistas-system-restore/
    - XP: http://support.microsoft.com/kb/948247

    Download Malwarebytes Anti-Rootkit (MBAR) from HERE
    • Unzip downloaded file.
    • Open the folder where the contents were unzipped and run mbar.exe
    • Follow the instructions in the wizard to update and allow the program to scan your computer for threats.
    • Click on the Cleanup button to remove any threats and reboot if prompted to do so.
    • Wait while the system shuts down and the cleanup process is performed.
    • Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
    • When done, please post the two logs produced they will be in the MBAR folder..... mbar-log-xxxxx.txt and system-log.txt

    ===========================================================
    Note: <<<< - very important - please do this step:
    If no additional threats were found, verify that your system is now running normally, making sure that the following items are functional:
    Internet access
    Windows Update
    Windows Firewall
    (if used)
    If there are additional problems with your system, such as any of those listed above or other system issues, then run the fixdamage tool included with Malwarebytes Anti-Rootkit located in the mbar\plugins folder and reboot.
    Verify that your system is now functioning normally.
  13. Row1

    Row1 TechSpot Maniac Topic Starter Posts: 349   +8

    RogueKiller log....

    RogueKiller V8.5.4 _x64_ [Mar 18 2013] by Tigzy
    mail : tigzyRK<at>gmail<dot>com
    Feedback : http://www.geekstogo.com/forum/files/file/413-roguekiller/
    Website : http://tigzy.geekstogo.com/roguekiller.php
    Blog : http://tigzyrk.blogspot.com/
    Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
    Started in : Normal mode
    User : Paul Rowan [Admin rights]
    Mode : Remove -- Date : 06/11/2013 23:46:04
    | ARK || FAK || MBR |
    ¤¤¤ Bad processes : 0 ¤¤¤
    ¤¤¤ Registry Entries : 5 ¤¤¤
    [HJPOL] HKCU\[...]\System : DisableTaskMgr (0) -> DELETED
    [HJPOL] HKCU\[...]\System : DisableRegistryTools (0) -> DELETED
    [HJ SMENU] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> REPLACED (1)
    [HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
    [HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
    ¤¤¤ Particular Files / Folders: ¤¤¤
    ¤¤¤ Driver : [NOT LOADED] ¤¤¤
    ¤¤¤ HOSTS File: ¤¤¤
    --> C:\Windows\system32\drivers\etc\hosts

    ¤¤¤ MBR Check: ¤¤¤
    +++++ PhysicalDrive0: ST320LT009-9WC142 ATA Device +++++
    --- User ---
    [MBR] 3a760d4919a4bf892df928ff745fc134
    [BSP] 3777aa65898ad2d322d5995d29e3298d : Windows 7/8 MBR Code
    Partition table:
    0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
    1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 305143 Mo
    User = LL1 ... OK!
    User = LL2 ... OK!
    Finished : << RKreport[2]_D_06112013_02d2346.txt >>
    RKreport[1]_S_06112013_02d2340.txt ; RKreport[2]_D_06112013_02d2346.txt
     
  14. Row1

    Row1 TechSpot Maniac Topic Starter Posts: 349   +8

    Malwarebytes won't run; my hard drive is encrypted, and it won't scan an encrypted drive.
    The problem is still on my computer / in my browser - I can tell each time I open IExplorer - but I neutralize this by going to 'inprivate browsing.'
  15. Row1

    Row1 TechSpot Maniac Topic Starter Posts: 349   +8

    The first malwarebytes still works, and says again it finds nothing.
  16. Row1

    Row1 TechSpot Maniac Topic Starter Posts: 349   +8

    Malwarebytes Anti-Malware (Trial) 1.75.0.1300
    www.malwarebytes.org
    Database version: v2013.06.11.08
    Windows 7 Service Pack 1 x64 NTFS
    Internet Explorer 9.0.8112.16421
    Paul Rowan :: SPH4860 [administrator]
    Protection: Enabled
    6/12/2013 12:10:15 AM
    mbam-log-2013-06-12 (00-10-15).txt
    Scan type: Quick scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 234771
    Time elapsed: 2 minute(s), 37 second(s)
    Memory Processes Detected: 0
    (No malicious items detected)
    Memory Modules Detected: 0
    (No malicious items detected)
    Registry Keys Detected: 0
    (No malicious items detected)
    Registry Values Detected: 0
    (No malicious items detected)
    Registry Data Items Detected: 0
    (No malicious items detected)
    Folders Detected: 0
    (No malicious items detected)
    Files Detected: 0
    (No malicious items detected)
    (end)
  17. Broni

    Broni Malware Annihilator Posts: 45,275   +243

    Please download Farbar Recovery Scan Tool and save it to your desktop.

    Note: You need to run the version compatibale with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
  18. Row1

    Row1 TechSpot Maniac Topic Starter Posts: 349   +8

    Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-06-2013 04
    Ran by Paul Rowan (administrator) on 12-06-2013 17:24:06
    Running from C:\Users\Paul Rowan\Desktop
    Windows 7 Enterprise Service Pack 1 (X64) OS Language: English(US)
    Internet Explorer Version 9
    Boot Mode: Normal
    ==================== Processes (Whitelisted) =================
    (IDT, Inc.) C:\Program Files\IDT\WDM\STacSV64.exe
    (Aventail Corporation) C:\Windows\system32\ngvpnmgr.exe
    (Microsoft Corporation) C:\Windows\system32\WLANExt.exe
    (Broadcom Corporation) C:\Program Files\Broadcom\MgmtAgent\BrcmMgmtAgent.exe
    (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
    (HP) C:\Windows\system32\HPSIsvc.exe
    (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
    (O2Micro International) C:\Windows\system32\o2flash.exe
    () C:\Windows\SysWOW64\srvany.exe
    (O2Micro.) C:\Windows\sysWOW64\SDIOAssist.exe
    (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
    (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
    (Microsoft Corporation) c:\Program Files\Microsoft Security Client\NisSrv.exe
    (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
    (Intel Corporation) C:\Windows\System32\igfxtray.exe
    (Intel Corporation) C:\Windows\System32\hkcmd.exe
    (Intel Corporation) C:\Windows\System32\igfxpers.exe
    (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
    (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
    (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
    (Nullsoft, Inc.) C:\Program Files (x86)\Winamp\winampa.exe
    (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe
    (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\HidFind.exe
    (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apntex.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe
    (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
    (Microsoft Corporation) C:\Windows\system32\prevhost.exe
    (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
    (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
    (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
    (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
    (Microsoft Corporation) C:\Windows\SysWOW64\prevhost.exe
    (Microsoft Corporation) C:\PROGRA~2\MICROS~2\Office14\WINWORD.EXE
    (Microsoft Corporation) C:\Windows\splwow64.exe
    (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe
    (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe
    (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe
    (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe
    ==================== Registry (Whitelisted) ==================
    HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1281512 2013-01-27] (Microsoft Corporation)
    HKLM\...\Run: [IntelPROSet] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel PROSet/Wireless [4805936 2012-08-23] (Intel(R) Corporation)
    HKLM\...\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe [1425408 2012-02-13] (IDT, Inc.)
    HKLM\...\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe [682904 2012-09-20] (Alps Electric Co., Ltd.)
    HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent [532040 2013-04-04] (Malwarebytes Corporation)
    HKCU\...\Run: [ISUSPM] "C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe" -scheduler [x]
    HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent [532040 2013-04-04] (Malwarebytes Corporation)
    MountPoints2: {269efed7-5a7a-11e2-97d2-415645000030} - E:\IVDApp.exe
    MountPoints2: {7f5b148f-5f1a-11e2-8b80-415645000030} - E:\SISetup.exe
    HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [937920 2011-06-06] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-03-13] (Microsoft Corporation)
    HKLM-x32\...\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [291608 2012-02-17] (Intel Corporation)
    HKLM-x32\...\Run: [IMSS] "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe" [133440 2012-07-19] (Intel Corporation)
    HKLM-x32\...\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe" [74752 2012-06-28] (Nullsoft, Inc.)
    HKU\Administrator\...\Run: [Akamai NetSession Interface] "C:\Users\Administrator\AppData\Local\Akamai\netsession_win.exe" [4441920 2012-10-09] (Akamai Technologies, Inc.)
    ==================== Internet (Whitelisted) ====================
    HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.altavista.com/
    HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
    URLSearchHook: (No Name) - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - No File
    BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation)
    BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation)
    BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
    BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation)
    BHO-x32: getsav-in 5.0 - {B191C6E6-0B41-46B8-A2D3-85365587B2B7} - C:\Users\Paul Rowan\AppData\Local\getsav-in\ie\getsav-in_1370913901.dll ()
    BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation)
    DPF: HKLM-x32 {32E7B36C-7960-4A42-B83B-D8AFD0AAEF2B} http://dizun95pzobbc.cloudfront.net/INDBrowser.CAB
    DPF: HKLM-x32 {99E63F21-514B-4C2B-9170-D25D54F65D5B} http://dizun95pzobbc.cloudfront.net/VBIXDPlayer.CAB
    Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
    Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
    ==================== Services (Whitelisted) =================
    R2 BrcmMgmtAgent; C:\Program Files\Broadcom\MgmtAgent\BrcmMgmtAgent.exe [163840 2011-11-30] (Broadcom Corporation)
    R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-07-19] (Intel Corporation)
    R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
    R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
    R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22056 2013-01-27] (Microsoft Corporation)
    S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [272688 2012-08-23] ()
    R2 NgVpnMgr; C:\Windows\system32\ngvpnmgr.exe [510536 2011-09-22] (Aventail Corporation)
    R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [379360 2013-01-27] (Microsoft Corporation)
    R2 O2FLASH; C:\Windows\system32\o2flash.exe [244328 2011-11-16] (O2Micro International)
    R2 O2SDIOAssist; C:\Windows\SysWOW64\srvany.exe [8192 2003-04-18] ()
    R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3342640 2012-08-23] (Intel® Corporation)
    ==================== Drivers (Whitelisted) ====================
    R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
    R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
    R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [230320 2013-01-20] (Microsoft Corporation)
    S3 mvusbews; C:\Windows\System32\Drivers\mvusbews.sys [19968 2012-11-07] (Marvell Semiconductor, Inc.)
    R3 NETwNs64; C:\Windows\System32\DRIVERS\Netwsw00.sys [11523072 2012-09-30] (Intel Corporation)
    S3 NgFilter; C:\Windows\System32\DRIVERS\ngfilter.sys [26184 2011-09-22] (Aventail Corporation)
    R3 NgLog; C:\Windows\System32\DRIVERS\nglog.sys [31304 2011-09-22] (Aventail Corporation)
    R3 NgVpn; C:\Windows\System32\DRIVERS\ngvpn.sys [103496 2011-09-22] (Aventail Corporation)
    R3 NgWfp; C:\Windows\System32\DRIVERS\ngwfp.sys [28744 2011-09-22] (Aventail Corporation)
    R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [130008 2013-01-20] (Microsoft Corporation)
    S3 VGPU; System32\drivers\rdvgkmd.sys [x]
    ==================== NetSvcs (Whitelisted) ===================

    ==================== One Month Created Files and Folders ========
    2013-06-12 17:22 - 2013-06-12 17:22 - 00000000 ____D C:\FRST
    2013-06-12 17:20 - 2013-06-12 17:20 - 01920280 ____A (Farbar) C:\Users\Paul Rowan\Desktop\FRST64.exe
    2013-06-12 00:03 - 2013-06-12 00:03 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
    2013-06-11 23:46 - 2013-06-11 23:46 - 00001622 ____A C:\Users\Paul Rowan\Desktop\RKreport[2]_D_06112013_02d2346.txt
    2013-06-11 23:40 - 2013-06-11 23:40 - 00001558 ____A C:\Users\Paul Rowan\Desktop\RKreport[1]_S_06112013_02d2340.txt
    2013-06-11 23:39 - 2013-06-11 23:45 - 00000000 ____D C:\Users\Paul Rowan\Desktop\RK_Quarantine
    2013-06-11 23:37 - 2013-06-11 23:38 - 00791040 ____A C:\Users\Paul Rowan\Desktop\RogueKillerX64.exe
    2013-06-11 22:46 - 2013-06-11 22:46 - 00006860 ____A C:\Users\Paul Rowan\Desktop\attach.txt
    2013-06-11 22:46 - 2013-06-11 22:45 - 00019325 ____A C:\Users\Paul Rowan\Desktop\dds.txt
    2013-06-11 21:37 - 2013-06-11 21:37 - 00001109 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2013-06-11 21:37 - 2013-06-11 21:37 - 00000000 ____D C:\Users\Paul Rowan\AppData\Roaming\Malwarebytes
    2013-06-11 21:37 - 2013-06-11 21:37 - 00000000 ____D C:\ProgramData\Malwarebytes
    2013-06-11 21:36 - 2013-06-11 21:37 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
    2013-06-11 21:36 - 2013-04-04 14:50 - 00025928 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
    2013-06-11 21:28 - 2013-06-11 21:28 - 00000000 ____A C:\Windows\SysWOW64\config.nt
    2013-06-11 21:28 - 2013-05-09 03:58 - 00287840 ____A (AVAST Software) C:\Windows\System32\aswBoot.exe
    2013-06-11 21:26 - 2013-06-11 21:26 - 00000000 ____D C:\Program Files\AVAST Software
    2013-06-11 21:25 - 2013-06-11 21:26 - 00000000 ____D C:\ProgramData\AVAST Software
    2013-06-11 21:08 - 2013-06-11 21:25 - 117478104 ____A C:\Users\Paul Rowan\Downloads\avast_free_antivirus_setup.exe
    2013-06-11 09:56 - 2013-06-11 09:56 - 00000808 ____A C:\Users\Paul Rowan\Desktop\JRT.txt
    2013-06-11 09:53 - 2013-06-11 09:53 - 00000000 ____D C:\Windows\ERUNT
    2013-06-11 09:53 - 2013-06-11 09:53 - 00000000 ____D C:\JRT
    2013-06-11 09:52 - 2013-06-11 09:52 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\Paul Rowan\Desktop\JRT.exe
    2013-06-11 08:57 - 2013-06-11 09:12 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
    2013-06-11 08:57 - 2013-06-11 08:59 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy
    2013-06-11 08:57 - 2013-06-11 08:57 - 00001258 ____A C:\Users\Paul Rowan\Desktop\Spybot - Search & Destroy.lnk
    2013-06-10 20:31 - 2013-06-10 20:31 - 00000000 ____D C:\Windows\System32\appmgmt
    2013-06-10 20:30 - 2013-06-10 20:30 - 00000000 ____D C:\Users\Paul Rowan\AppData\Roaming\Zeon
    2013-06-10 20:30 - 2013-06-10 20:30 - 00000000 ____D C:\ProgramData\FLEXnet
    2013-06-10 20:26 - 2013-06-10 20:26 - 00000000 ____D C:\Users\Paul Rowan\AppData\Local\getsav-in
    2013-06-10 20:25 - 2013-06-10 20:32 - 00000000 ____D C:\ProgramData\Yahoo!
    2013-06-10 20:19 - 2013-06-10 20:19 - 00000000 ____D C:\ProgramData\APN
    2013-06-03 21:46 - 2013-06-03 21:46 - 00000979 ____A C:\Users\Public\Desktop\Winamp.lnk
    2013-06-03 21:46 - 2009-09-04 17:29 - 01892184 ____A (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_42.dll
    2013-06-03 21:46 - 2006-09-28 16:05 - 02414360 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_31.dll
    2013-06-03 21:45 - 2013-06-03 22:59 - 00000000 ____D C:\Users\Paul Rowan\AppData\Roaming\Winamp
    2013-06-03 21:45 - 2013-06-03 21:46 - 00000000 ____D C:\Program Files (x86)\Winamp
    2013-05-15 18:08 - 2013-06-11 20:33 - 00000000 ____D C:\Program Files (x86)\Citrix
    2013-05-15 18:07 - 2013-05-15 18:07 - 00061304 ____A C:\Users\Paul Rowan\g2mdlhlpx.exe
    2013-05-15 18:07 - 2013-05-15 18:07 - 00000000 ____D C:\Users\Paul Rowan\AppData\Local\Deployment
    2013-05-15 18:07 - 2013-05-15 18:07 - 00000000 ____D C:\Users\Paul Rowan\AppData\Local\Apps\2.0
    2013-05-15 03:02 - 2013-05-05 16:36 - 17818624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
    2013-05-15 03:02 - 2013-05-05 16:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
    2013-05-15 03:02 - 2013-05-05 14:25 - 12324864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2013-05-15 03:02 - 2013-05-05 14:12 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2013-05-15 03:01 - 2013-04-04 20:19 - 10926080 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
    2013-05-15 03:01 - 2013-04-04 20:08 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
    2013-05-15 03:01 - 2013-04-04 20:01 - 01346560 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
    2013-05-15 03:01 - 2013-04-04 20:00 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
    2013-05-15 03:01 - 2013-04-04 19:59 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
    2013-05-15 03:01 - 2013-04-04 19:58 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
    2013-05-15 03:01 - 2013-04-04 19:57 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
    2013-05-15 03:01 - 2013-04-04 19:56 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
    2013-05-15 03:01 - 2013-04-04 19:55 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
    2013-05-15 03:01 - 2013-04-04 19:55 - 00599040 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
    2013-05-15 03:01 - 2013-04-04 19:54 - 02147840 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
    2013-05-15 03:01 - 2013-04-04 19:54 - 00729088 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
    2013-05-15 03:01 - 2013-04-04 19:51 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
    2013-05-15 03:01 - 2013-04-04 19:46 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
    2013-05-15 03:01 - 2013-04-04 17:11 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2013-05-15 03:01 - 2013-04-04 17:09 - 09738752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2013-05-15 03:01 - 2013-04-04 17:02 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2013-05-15 03:01 - 2013-04-04 17:02 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2013-05-15 03:01 - 2013-04-04 17:02 - 01104384 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2013-05-15 03:01 - 2013-04-04 17:01 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
    2013-05-15 03:01 - 2013-04-04 16:59 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2013-05-15 03:01 - 2013-04-04 16:58 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
    2013-05-15 03:01 - 2013-04-04 16:58 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
    2013-05-15 03:01 - 2013-04-04 16:57 - 00420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
    2013-05-15 03:01 - 2013-04-04 16:56 - 00607744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
    2013-05-15 03:01 - 2013-04-04 16:55 - 01796096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2013-05-15 03:01 - 2013-04-04 16:54 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
    2013-05-15 03:01 - 2013-04-04 16:50 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2013-05-14 19:32 - 2013-04-10 01:01 - 00983400 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys
    2013-05-14 19:32 - 2013-04-10 01:01 - 00265064 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgmms1.sys
    2013-05-14 19:32 - 2013-04-09 22:30 - 03153920 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
    2013-05-14 19:32 - 2013-03-19 00:53 - 00230400 ____A (Microsoft Corporation) C:\Windows\System32\wwansvc.dll
    2013-05-14 19:32 - 2013-03-19 00:53 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\wwanprotdim.dll
    2013-05-14 19:32 - 2013-02-27 01:02 - 00111448 ____A (Microsoft Corporation) C:\Windows\System32\consent.exe
    2013-05-14 19:32 - 2013-02-27 00:52 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
    2013-05-14 19:32 - 2013-02-27 00:52 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\shdocvw.dll
    2013-05-14 19:32 - 2013-02-27 00:48 - 01930752 ____A (Microsoft Corporation) C:\Windows\System32\authui.dll
    2013-05-14 19:32 - 2013-02-27 00:47 - 00070144 ____A (Microsoft Corporation) C:\Windows\System32\appinfo.dll
    2013-05-14 19:32 - 2013-02-26 23:55 - 12872704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
    2013-05-14 19:32 - 2013-02-26 23:55 - 00180224 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
    2013-05-14 19:32 - 2013-02-26 23:49 - 01796096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
    2013-05-14 19:32 - 2011-02-03 06:25 - 00144384 ____A (Microsoft Corporation) C:\Windows\System32\cdd.dll
    ==================== One Month Modified Files and Folders =======
    2013-06-12 17:22 - 2013-06-12 17:22 - 00000000 ____D C:\FRST
    2013-06-12 17:20 - 2013-06-12 17:20 - 01920280 ____A (Farbar) C:\Users\Paul Rowan\Desktop\FRST64.exe
    2013-06-12 17:14 - 2013-01-08 12:16 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
    2013-06-12 15:05 - 2013-01-07 16:31 - 01357964 ____A C:\Windows\WindowsUpdate.log
    2013-06-12 10:14 - 2013-01-08 12:16 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2013-06-12 10:14 - 2013-01-08 12:16 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
    2013-06-12 09:52 - 2009-07-14 00:13 - 00726316 ____A C:\Windows\System32\PerfStringBackup.INI
    2013-06-12 00:03 - 2013-06-12 00:03 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
    2013-06-11 23:55 - 2009-07-13 23:45 - 00022208 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2013-06-11 23:55 - 2009-07-13 23:45 - 00022208 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2013-06-11 23:46 - 2013-06-11 23:46 - 00001622 ____A C:\Users\Paul Rowan\Desktop\RKreport[2]_D_06112013_02d2346.txt
    2013-06-11 23:45 - 2013-06-11 23:39 - 00000000 ____D C:\Users\Paul Rowan\Desktop\RK_Quarantine
    2013-06-11 23:40 - 2013-06-11 23:40 - 00001558 ____A C:\Users\Paul Rowan\Desktop\RKreport[1]_S_06112013_02d2340.txt
    2013-06-11 23:38 - 2013-06-11 23:37 - 00791040 ____A C:\Users\Paul Rowan\Desktop\RogueKillerX64.exe
    2013-06-11 22:46 - 2013-06-11 22:46 - 00006860 ____A C:\Users\Paul Rowan\Desktop\attach.txt
    2013-06-11 22:45 - 2013-06-11 22:46 - 00019325 ____A C:\Users\Paul Rowan\Desktop\dds.txt
    2013-06-11 21:37 - 2013-06-11 21:37 - 00001109 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2013-06-11 21:37 - 2013-06-11 21:37 - 00000000 ____D C:\Users\Paul Rowan\AppData\Roaming\Malwarebytes
    2013-06-11 21:37 - 2013-06-11 21:37 - 00000000 ____D C:\ProgramData\Malwarebytes
    2013-06-11 21:37 - 2013-06-11 21:36 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
    2013-06-11 21:28 - 2013-06-11 21:28 - 00000000 ____A C:\Windows\SysWOW64\config.nt
    2013-06-11 21:26 - 2013-06-11 21:26 - 00000000 ____D C:\Program Files\AVAST Software
    2013-06-11 21:26 - 2013-06-11 21:25 - 00000000 ____D C:\ProgramData\AVAST Software
    2013-06-11 21:25 - 2013-06-11 21:08 - 117478104 ____A C:\Users\Paul Rowan\Downloads\avast_free_antivirus_setup.exe
    2013-06-11 20:33 - 2013-05-15 18:08 - 00000000 ____D C:\Program Files (x86)\Citrix
    2013-06-11 20:27 - 2013-01-09 11:46 - 00000000 ____D C:\backup
    2013-06-11 09:56 - 2013-06-11 09:56 - 00000808 ____A C:\Users\Paul Rowan\Desktop\JRT.txt
    2013-06-11 09:53 - 2013-06-11 09:53 - 00000000 ____D C:\Windows\ERUNT
    2013-06-11 09:53 - 2013-06-11 09:53 - 00000000 ____D C:\JRT
    2013-06-11 09:52 - 2013-06-11 09:52 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\Paul Rowan\Desktop\JRT.exe
    2013-06-11 09:31 - 2009-07-14 00:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
    2013-06-11 09:31 - 2009-07-13 23:51 - 00032523 ____A C:\Windows\setupact.log
    2013-06-11 09:12 - 2013-06-11 08:57 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
    2013-06-11 08:59 - 2013-06-11 08:57 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy
    2013-06-11 08:57 - 2013-06-11 08:57 - 00001258 ____A C:\Users\Paul Rowan\Desktop\Spybot - Search & Destroy.lnk
    2013-06-10 20:33 - 2010-11-20 22:47 - 00042774 ____A C:\Windows\PFRO.log
    2013-06-10 20:32 - 2013-06-10 20:25 - 00000000 ____D C:\ProgramData\Yahoo!
    2013-06-10 20:31 - 2013-06-10 20:31 - 00000000 ____D C:\Windows\System32\appmgmt
    2013-06-10 20:30 - 2013-06-10 20:30 - 00000000 ____D C:\Users\Paul Rowan\AppData\Roaming\Zeon
    2013-06-10 20:30 - 2013-06-10 20:30 - 00000000 ____D C:\ProgramData\FLEXnet
    2013-06-10 20:30 - 2013-01-07 15:00 - 00000000 ____D C:\Users\Paul Rowan\AppData\Local\Downloaded Installations
    2013-06-10 20:26 - 2013-06-10 20:26 - 00000000 ____D C:\Users\Paul Rowan\AppData\Local\getsav-in
    2013-06-10 20:19 - 2013-06-10 20:19 - 00000000 ____D C:\ProgramData\APN
    2013-06-05 21:48 - 2013-01-12 13:10 - 00002038 ___AH C:\Users\Paul Rowan\Documents\Default.rdp
    2013-06-05 20:28 - 2013-01-20 21:12 - 00000072 ____A C:\Users\Public\LMDebug.log
    2013-06-05 14:28 - 2009-07-14 00:32 - 00000000 ____D C:\Windows\System32\FxsTmp
    2013-06-03 22:59 - 2013-06-03 21:45 - 00000000 ____D C:\Users\Paul Rowan\AppData\Roaming\Winamp
    2013-06-03 21:46 - 2013-06-03 21:46 - 00000979 ____A C:\Users\Public\Desktop\Winamp.lnk
    2013-06-03 21:46 - 2013-06-03 21:45 - 00000000 ____D C:\Program Files (x86)\Winamp
    2013-05-15 18:07 - 2013-05-15 18:07 - 00061304 ____A C:\Users\Paul Rowan\g2mdlhlpx.exe
    2013-05-15 18:07 - 2013-05-15 18:07 - 00000000 ____D C:\Users\Paul Rowan\AppData\Local\Deployment
    2013-05-15 18:07 - 2013-05-15 18:07 - 00000000 ____D C:\Users\Paul Rowan\AppData\Local\Apps\2.0
    2013-05-15 18:07 - 2013-01-07 14:43 - 00000000 ____D C:\users\Paul Rowan
    2013-05-15 08:01 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\rescache
    2013-05-15 03:27 - 2009-07-13 23:45 - 00418136 ____A C:\Windows\System32\FNTCACHE.DAT
    2013-05-15 03:08 - 2013-01-08 12:20 - 00000000 ____D C:\ProgramData\Microsoft Help
    2013-05-15 03:06 - 2013-01-07 16:00 - 75016696 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
    ==================== Bamital & volsnap Check =================
    C:\Windows\System32\winlogon.exe => MD5 is legit
    C:\Windows\System32\wininit.exe => MD5 is legit
    C:\Windows\SysWOW64\wininit.exe => MD5 is legit
    C:\Windows\explorer.exe => MD5 is legit
    C:\Windows\SysWOW64\explorer.exe => MD5 is legit
    C:\Windows\System32\svchost.exe => MD5 is legit
    C:\Windows\SysWOW64\svchost.exe => MD5 is legit
    C:\Windows\System32\services.exe => MD5 is legit
    C:\Windows\System32\User32.dll => MD5 is legit
    C:\Windows\SysWOW64\User32.dll => MD5 is legit
    C:\Windows\System32\userinit.exe => MD5 is legit
    C:\Windows\SysWOW64\userinit.exe => MD5 is legit
    C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

    LastRegBack: 2013-06-03 16:11
    ==================== End Of Log ============================

    Attached Files:

  19. Broni

    Broni Malware Annihilator Posts: 45,275   +243

    Please observe forum rules.
    All logs have to be pasted not attached.
  20. Row1

    Row1 TechSpot Maniac Topic Starter Posts: 349   +8

    "All logs have to be pasted not attached."
    That was my understanding.
    And then I saw this intruction from you:
    "The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply."

    Please follow forum rules; please do not intruct someone to attach something whe nthey have been instructed to not attach things.
  21. Row1

    Row1 TechSpot Maniac Topic Starter Posts: 349   +8

    Additional scan result of Farbar Recovery Scan Tool (x64) Version: 12-06-2013 04
    Ran by Paul Rowan at 2013-06-12 17:24:32 Run:
    Running from C:\Users\Paul Rowan\Desktop
    Boot Mode: Normal
    ==========================================================

    ==================== Installed Programs =======================
    Adobe Flash Player 11 ActiveX (Version: 11.7.700.224)
    Adobe Reader X (10.1.0) (Version: 10.1.0)
    Amazon MP3 Downloader 1.0.17 (Version: 1.0.17)
    Aventail Access Manager (Version: 10.54.41)
    Aventail Connect (Version: 10.54.41)
    Broadcom NetXtreme-I Netlink Driver and Management Installer (Version: 15.0.8.5)
    CAM UnZip 4.5
    Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition
    Dell Touchpad (Version: 8.1200.101.116)
    getsav-in (Version: 1.1370913920)
    HP LaserJet Professional P1100-P1560-P1600 Series
    IBM SPSS Statistics 20 (Version: 20.0.0.0)
    IDT Audio (Version: 1.0.6388.0)
    Intel PROSet Wireless
    Intel(R) Management Engine Components (Version: 8.1.0.1281)
    Intel(R) OpenCL CPU Runtime
    Intel(R) Processor Graphics (Version: 8.15.10.2712)
    Intel(R) USB 3.0 eXtensible Host Controller Driver (Version: 1.0.3.214)
    Intel® PROSet/Wireless WiFi Software (Version: 15.03.1000.1637)
    Intel® Trusted Connect Service Client (Version: 1.24.738.1)
    IrfanView (remove only) (Version: 4.35)
    Malwarebytes Anti-Malware version 1.75.0.1300 (Version: 1.75.0.1300)
    Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
    Microsoft Office 2010 Service Pack 1 (SP1)
    Microsoft Office Access MUI (English) 2010 (Version: 14.0.6029.1000)
    Microsoft Office Access Setup Metadata MUI (English) 2010 (Version: 14.0.6029.1000)
    Microsoft Office Excel MUI (English) 2010 (Version: 14.0.6029.1000)
    Microsoft Office Groove MUI (English) 2010 (Version: 14.0.6029.1000)
    Microsoft Office InfoPath MUI (English) 2010 (Version: 14.0.6029.1000)
    Microsoft Office Office 64-bit Components 2010 (Version: 14.0.6029.1000)
    Microsoft Office OneNote MUI (English) 2010 (Version: 14.0.6029.1000)
    Microsoft Office Outlook MUI (English) 2010 (Version: 14.0.6029.1000)
    Microsoft Office PowerPoint MUI (English) 2010 (Version: 14.0.6029.1000)
    Microsoft Office Professional Plus 2010 (Version: 14.0.6029.1000)
    Microsoft Office Proof (English) 2010 (Version: 14.0.6029.1000)
    Microsoft Office Proof (French) 2010 (Version: 14.0.6029.1000)
    Microsoft Office Proof (Spanish) 2010 (Version: 14.0.6029.1000)
    Microsoft Office Proofing (English) 2010 (Version: 14.0.6029.1000)
    Microsoft Office Publisher MUI (English) 2010 (Version: 14.0.6029.1000)
    Microsoft Office Shared 64-bit MUI (English) 2010 (Version: 14.0.6029.1000)
    Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010 (Version: 14.0.6029.1000)
    Microsoft Office Shared MUI (English) 2010 (Version: 14.0.6029.1000)
    Microsoft Office Shared Setup Metadata MUI (English) 2010 (Version: 14.0.6029.1000)
    Microsoft Office Word MUI (English) 2010 (Version: 14.0.6029.1000)
    Microsoft Security Client (Version: 4.2.0223.1)
    Microsoft Security Essentials (Version: 4.2.223.1)
    Microsoft Silverlight (Version: 5.1.20125.0)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
    Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
    O2Micro Flash Memory Card Windows Driver (Version: 3.0.07.37)
    Skype™ 6.1 (Version: 6.1.129)
    Spybot - Search & Destroy (Version: 1.6.2)
    Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
    Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
    Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
    Update for Microsoft Office 2010 (KB2553065)
    Update for Microsoft Office 2010 (KB2553092)
    Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2553378) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2566458)
    Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2687503) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2687509) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2767886) 32-Bit Edition
    Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition
    Update for Microsoft Outlook 2010 (KB2597090) 32-Bit Edition
    Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition
    Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition
    Update for Microsoft PowerPoint 2010 (KB2598240) 32-Bit Edition
    Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition
    Winamp (Version: 5.63 )
    ==================== Restore Points =========================
    19-05-2013 21:16:56 Windows Update
    24-05-2013 00:12:46 Windows Update
    27-05-2013 05:04:05 Windows Update
    31-05-2013 02:28:29 Windows Update
    04-06-2013 01:32:55 Windows Update
    04-06-2013 02:46:01 Installed DirectX
    08-06-2013 00:04:40 Windows Update
    11-06-2013 00:35:26 Windows Update
    11-06-2013 01:31:26 Removed Nuance PDF Reader.
    12-06-2013 02:26:32 avast! Free Antivirus Setup
    12-06-2013 04:23:45 avast! Free Antivirus Setup
    12-06-2013 04:50:26 PostRogueKillerJun1113
    ==================== Faulty Device Manager Devices =============
    Name:
    Description:
    Class Guid:
    Manufacturer:
    Service:
    Problem: : The drivers for this device are not installed. (Code 28)
    Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

    ==================== Event log errors: =========================
    Application errors:
    ==================
    Error: (06/12/2013 09:36:54 AM) (Source: SideBySide) (User: )
    Description: Activation context generation failed for "assemblyIdentity1".Error in manifest or policy file "assemblyIdentity2" on line assemblyIdentity3.
    The value "*" of attribute "language" in element "assemblyIdentity" is invalid.
    Error: (06/11/2013 11:50:26 PM) (Source: Microsoft-Windows-CAPI2) (User: )
    Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

    Details:
    AddLegacyDriverFiles: Unable to back up image of binary aswFsBlk.
    System Error:
    The system cannot find the file specified.
    .
    Error: (06/11/2013 11:50:26 PM) (Source: Microsoft-Windows-CAPI2) (User: )
    Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

    Details:
    AddLegacyDriverFiles: Unable to back up image of binary aswSP.
    System Error:
    The system cannot find the file specified.
    .
    Error: (06/11/2013 11:50:26 PM) (Source: Microsoft-Windows-CAPI2) (User: )
    Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

    Details:
    AddLegacyDriverFiles: Unable to back up image of binary AswRdr.
    System Error:
    The system cannot find the file specified.
    .
    Error: (06/11/2013 11:50:26 PM) (Source: Microsoft-Windows-CAPI2) (User: )
    Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

    Details:
    AddLegacyDriverFiles: Unable to back up image of binary avast! Network Shield Support.
    System Error:
    The system cannot find the file specified.
    .
    Error: (06/11/2013 11:50:26 PM) (Source: Microsoft-Windows-CAPI2) (User: )
    Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

    Details:
    AddLegacyDriverFiles: Unable to back up image of binary aswVmm.
    System Error:
    The system cannot find the file specified.
    .
    Error: (06/11/2013 11:50:26 PM) (Source: Microsoft-Windows-CAPI2) (User: )
    Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

    Details:
    AddLegacyDriverFiles: Unable to back up image of binary aswMonFlt.
    System Error:
    The system cannot find the file specified.
    .
    Error: (06/11/2013 01:05:23 PM) (Source: Application Error) (User: )
    Description: Faulting application name: iexplore.exe, version: 9.0.8112.16483, time stamp: 0x515df825
    Faulting module name: getsav-in_1370913901.dll, version: 0.0.0.0, time stamp: 0x51b67c80
    Exception code: 0xc0000005
    Fault offset: 0x00001e94
    Faulting process id: 0x1a20
    Faulting application start time: 0xiexplore.exe0
    Faulting application path: iexplore.exe1
    Faulting module path: iexplore.exe2
    Report Id: iexplore.exe3
    Error: (06/11/2013 01:05:18 PM) (Source: Application Error) (User: )
    Description: Faulting application name: iexplore.exe, version: 9.0.8112.16483, time stamp: 0x515df825
    Faulting module name: getsav-in_1370913901.dll, version: 0.0.0.0, time stamp: 0x51b67c80
    Exception code: 0xc0000005
    Fault offset: 0x00001e94
    Faulting process id: 0xebc
    Faulting application start time: 0xiexplore.exe0
    Faulting application path: iexplore.exe1
    Faulting module path: iexplore.exe2
    Report Id: iexplore.exe3
    Error: (06/11/2013 00:53:51 PM) (Source: Application Error) (User: )
    Description: Faulting application name: iexplore.exe, version: 9.0.8112.16483, time stamp: 0x515df825
    Faulting module name: getsav-in_1370913901.dll, version: 0.0.0.0, time stamp: 0x51b67c80
    Exception code: 0xc0000005
    Fault offset: 0x00001e94
    Faulting process id: 0x1994
    Faulting application start time: 0xiexplore.exe0
    Faulting application path: iexplore.exe1
    Faulting module path: iexplore.exe2
    Report Id: iexplore.exe3

    System errors:
    =============
    Error: (06/12/2013 05:19:27 PM) (Source: Schannel) (User: NT AUTHORITY)
    Description: The following fatal alert was generated: 40. The internal error state is 107.
    Error: (06/12/2013 05:19:27 PM) (Source: Schannel) (User: NT AUTHORITY)
    Description: An SSL 3.0 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed.
    Error: (06/12/2013 05:19:27 PM) (Source: Schannel) (User: NT AUTHORITY)
    Description: The following fatal alert was generated: 40. The internal error state is 107.
    Error: (06/12/2013 05:19:27 PM) (Source: Schannel) (User: NT AUTHORITY)
    Description: An SSL 3.0 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed.
    Error: (06/12/2013 05:19:27 PM) (Source: Schannel) (User: NT AUTHORITY)
    Description: The following fatal alert was generated: 40. The internal error state is 107.
    Error: (06/12/2013 05:19:27 PM) (Source: Schannel) (User: NT AUTHORITY)
    Description: An SSL 3.0 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed.
    Error: (06/12/2013 05:19:27 PM) (Source: Schannel) (User: NT AUTHORITY)
    Description: The following fatal alert was generated: 40. The internal error state is 107.
    Error: (06/12/2013 05:19:27 PM) (Source: Schannel) (User: NT AUTHORITY)
    Description: An SSL 3.0 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed.
    Error: (06/12/2013 01:59:55 PM) (Source: DCOM) (User: )
    Description: {995C996E-D918-4A8C-A302-45719A6F4EA7}
    Error: (06/12/2013 11:56:50 AM) (Source: Schannel) (User: NT AUTHORITY)
    Description: The following fatal alert was generated: 40. The internal error state is 107.

    Microsoft Office Sessions:
    =========================
    Error: (06/12/2013 09:36:54 AM) (Source: SideBySide)(User: )
    Description: assemblyIdentitylanguage*c:\program files (x86)\spybot - search & destroy\DelZip179.dllc:\program files (x86)\spybot - search & destroy\DelZip179.dll8
    Error: (06/11/2013 11:50:26 PM) (Source: Microsoft-Windows-CAPI2)(User: )
    Description:
    Details:
    AddLegacyDriverFiles: Unable to back up image of binary aswFsBlk.
    System Error:
    The system cannot find the file specified.
    Error: (06/11/2013 11:50:26 PM) (Source: Microsoft-Windows-CAPI2)(User: )
    Description:
    Details:
    AddLegacyDriverFiles: Unable to back up image of binary aswSP.
    System Error:
    The system cannot find the file specified.
    Error: (06/11/2013 11:50:26 PM) (Source: Microsoft-Windows-CAPI2)(User: )
    Description:
    Details:
    AddLegacyDriverFiles: Unable to back up image of binary AswRdr.
    System Error:
    The system cannot find the file specified.
    Error: (06/11/2013 11:50:26 PM) (Source: Microsoft-Windows-CAPI2)(User: )
    Description:
    Details:
    AddLegacyDriverFiles: Unable to back up image of binary avast! Network Shield Support.
    System Error:
    The system cannot find the file specified.
    Error: (06/11/2013 11:50:26 PM) (Source: Microsoft-Windows-CAPI2)(User: )
    Description:
    Details:
    AddLegacyDriverFiles: Unable to back up image of binary aswVmm.
    System Error:
    The system cannot find the file specified.
    Error: (06/11/2013 11:50:26 PM) (Source: Microsoft-Windows-CAPI2)(User: )
    Description:
    Details:
    AddLegacyDriverFiles: Unable to back up image of binary aswMonFlt.
    System Error:
    The system cannot find the file specified.
    Error: (06/11/2013 01:05:23 PM) (Source: Application Error)(User: )
    Description: iexplore.exe9.0.8112.16483515df825getsav-in_1370913901.dll0.0.0.051b67c80c000000500001e941a2001ce66ce3c9d3a6fC:\Program Files (x86)\Internet Explorer\iexplore.exeC:\Users\Paul Rowan\AppData\Local\getsav-in\ie\getsav-in_1370913901.dll7c44ca6a-d2c1-11e2-bff6-415645000030
    Error: (06/11/2013 01:05:18 PM) (Source: Application Error)(User: )
    Description: iexplore.exe9.0.8112.16483515df825getsav-in_1370913901.dll0.0.0.051b67c80c000000500001e94ebc01ce66cca2928619C:\Program Files (x86)\Internet Explorer\iexplore.exeC:\Users\Paul Rowan\AppData\Local\getsav-in\ie\getsav-in_1370913901.dll7919152c-d2c1-11e2-bff6-415645000030
    Error: (06/11/2013 00:53:51 PM) (Source: Application Error)(User: )
    Description: iexplore.exe9.0.8112.16483515df825getsav-in_1370913901.dll0.0.0.051b67c80c000000500001e94199401ce66cca1bc4a40C:\Program Files (x86)\Internet Explorer\iexplore.exeC:\Users\Paul Rowan\AppData\Local\getsav-in\ie\getsav-in_1370913901.dlldf8c89c5-d2bf-11e2-bff6-415645000030

    ==================== Memory info ===========================
    Percentage of memory in use: 68%
    Total physical RAM: 3969.29 MB
    Available physical RAM: 1251.06 MB
    Total Pagefile: 7936.75 MB
    Available Pagefile: 4787.89 MB
    Total Virtual: 8192 MB
    Available Virtual: 8191.82 MB
    ==================== Drives ================================
    Drive c: () (Fixed) (Total:297.99 GB) (Free:250.79 GB) NTFS (Disk=0 Partition=2)
    Drive e: (ExternalDrive) (Fixed) (Total:1397.26 GB) (Free:1180.16 GB) NTFS (Disk=1 Partition=1)
    ==================== MBR & Partition Table ==================
    ========================================================
    Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: 4117B00F)
    Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
    Partition 2: (Not Active) - (Size=298 GB) - (Type=07 NTFS)
    ========================================================
    Disk: 1 (Size: 1397 GB) (Disk ID: 8037BD9C)
    Partition 1: (Not Active) - (Size=-698724909056) - (Type=07 NTFS)
    ==================== End Of Log ============================
  22. Broni

    Broni Malware Annihilator Posts: 45,275   +243

    I apologize for the confusion :)

    Download attached fixlist.txt file and save it to the Desktop.
    NOTE. It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Run FRST/FRST64 and press the Fix button just once and wait.
    The tool will make a log on the Desktop (Fixlog.txt). Please post it to your reply.

    Attached Files:

  23. Row1

    Row1 TechSpot Maniac Topic Starter Posts: 349   +8

    Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 12-06-2013 04
    Ran by Paul Rowan at 2013-06-12 18:48:02 Run:1
    Running from C:\Users\Paul Rowan\Desktop
    Boot Mode: Normal
    ==============================================
    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{269efed7-5a7a-11e2-97d2-415645000030} => Key deleted successfully.
    HKCR\CLSID\{269efed7-5a7a-11e2-97d2-415645000030} => Key not found.
    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7f5b148f-5f1a-11e2-8b80-415645000030} => Key deleted successfully.
    HKCR\CLSID\{7f5b148f-5f1a-11e2-8b80-415645000030} => Key not found.
    HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\\{81017EA9-9AA8-4A6A-9734-7AF40E7D593F} => Value deleted successfully.
    HKCR\CLSID\{81017EA9-9AA8-4A6A-9734-7AF40E7D593F} => Key not found.
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B191C6E6-0B41-46B8-A2D3-85365587B2B7} => Key deleted successfully.
    HKCR\Wow6432Node\CLSID\{B191C6E6-0B41-46B8-A2D3-85365587B2B7} => Key deleted successfully.
    C:\Users\Paul Rowan\AppData\Local\getsav-in => Moved successfully.
    ==== End of Fixlog ====
  24. Broni

    Broni Malware Annihilator Posts: 45,275   +243

    Good.

    [​IMG] Create new restore point before proceeding with the next step....
    How to:
    - Windows 8: http://www.vikitech.com/11302/system-restore-windows-8
    - Windows 7: http://www.howtogeek.com/howto/3195/create-a-system-restore-point-in-windows-7/
    - Vista: http://www.howtogeek.com/howto/wind...tore-point-for-windows-vistas-system-restore/
    - XP: http://support.microsoft.com/kb/948247

    [​IMG] Please download ComboFix from Here, Here or Here to your Desktop.

    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    • Never rename Combofix unless instructed.
    • Close any open browsers.
    • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
      If the connection is not there use restore point you created prior to running Combofix.
    • Double click on combofix.exe & follow the prompts.

    • NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
    • When finished, it will produce a report for you.
    • Please post the "C:\ComboFix.txt"
    **Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
    **Note 2 for AVG and CA Internet Security (Total Defense Internet Security) users: ComboFix will not run until AVG/CA Internet Security is uninstalled as a protective measure against the anti-virus. This is because AVG/CA Internet Security "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results". Since AVG/CA Internet Security cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG/CA Internet Security first.
    Use AppRemover to uninstall it: http://www.appremover.com/
    We can reinstall it when we're done with CF.
    **Note 3: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion", restart computer to fix the issue.
    **Note 4: Some infections may take some significant time to be cured. As long as your computer clock is running Combofix is still working. Be patient.


    Make sure, you re-enable your security programs, when you're done with Combofix.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    NOTE.
    If, for some reason, Combofix refuses to run, try the following...

    Delete Combofix file, download fresh one, but rename combofix.exe to your_name.exe BEFORE saving it to your desktop.
    Do NOT run it yet.
    Download Rkill (courtesy of BleepingComputer.com) to your desktop.
    There are 2 different versions. If one of them won't run then download and try to run the other one.
    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    rKill.exe: http://www.bleepingcomputer.com/download/rkill/dl/10/
    iExplore.exe (renamed rKill.exe): http://www.bleepingcomputer.com/download/rkill/dl/11/

    Restart computer in safe mode

    • Double-click on the Rkill desktop icon to run the tool.
    • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    • If not, delete the file, then download and use the one provided in Link 2.
    • Do not reboot until instructed.
    • If the tool does not run from any of the links provided, please let me know.

    When the scan is done Notepad will open with rKill.txt log.
    NOTE. rKill.txt log will also be present on your desktop.

    Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

    IF you had to run rKill post BOTH logs, rKill.txt and Combofix.txt.
  25. Row1

    Row1 TechSpot Maniac Topic Starter Posts: 349   +8

    ComboFix 13-06-12.02 - Paul Rowan 06/12/2013 19:24:49.1.4 - x64
    Microsoft Windows 7 Enterprise 6.1.7601.1.1252.1.1033.18.3969.1781 [GMT -5:00]
    Running from: c:\users\Paul Rowan\Desktop\ComboFix.exe
    AV: Microsoft Security Essentials *Disabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5}
    SP: Microsoft Security Essentials *Disabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\programdata\Roaming
    c:\users\Paul Rowan\g2mdlhlpx.exe
    c:\windows\SysWow64\instsrv.exe
    .
    .
    ((((((((((((((((((((((((( Files Created from 2013-05-13 to 2013-06-13 )))))))))))))))))))))))))))))))
    .
    .
    2013-06-13 00:27 . 2013-06-13 00:27 -------- d-----w- c:\users\Default\AppData\Local\temp
    2013-06-13 00:27 . 2013-06-13 00:27 -------- d-----w- c:\users\Administrator\AppData\Local\temp
    2013-06-13 00:17 . 2013-06-13 00:17 -------- d-----w- c:\program files (x86)\Samsung
    2013-06-12 22:22 . 2013-06-12 22:22 -------- d-----w- C:\FRST
    2013-06-12 05:03 . 2013-06-12 05:03 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable)
    2013-06-12 04:24 . 2013-06-12 04:24 -------- d-s---w- c:\windows\SysWow64\Microsoft
    2013-06-12 02:37 . 2013-06-12 02:37 -------- d-----w- c:\users\Paul Rowan\AppData\Roaming\Malwarebytes
    2013-06-12 02:37 . 2013-06-12 02:37 -------- d-----w- c:\programdata\Malwarebytes
    2013-06-12 02:36 . 2013-04-04 19:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
    2013-06-12 02:36 . 2013-06-12 02:37 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
    2013-06-12 02:36 . 2013-06-12 02:36 -------- d-----w- c:\users\Paul Rowan\AppData\Local\Programs
    2013-06-12 02:28 . 2013-05-09 08:58 287840 ----a-w- c:\windows\system32\aswBoot.exe
    2013-06-12 02:26 . 2013-06-12 02:26 -------- d-----w- c:\program files\AVAST Software
    2013-06-12 02:25 . 2013-06-12 02:26 -------- d-----w- c:\programdata\AVAST Software
    2013-06-12 01:33 . 2013-05-13 06:37 9460464 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{03D7C711-AE76-4B88-8BB7-B1440A5CA6F1}\mpengine.dll
    2013-06-11 14:53 . 2013-06-11 14:53 -------- d-----w- c:\windows\ERUNT
    2013-06-11 14:53 . 2013-06-11 14:53 -------- d-----w- C:\JRT
    2013-06-11 13:57 . 2013-06-11 14:12 -------- d-----w- c:\programdata\Spybot - Search & Destroy
    2013-06-11 13:57 . 2013-06-11 13:59 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy
    2013-06-11 01:31 . 2013-06-11 01:31 -------- d-----w- c:\windows\system32\appmgmt
    2013-06-11 01:30 . 2013-06-11 01:30 -------- d-----w- c:\users\Paul Rowan\AppData\Roaming\Zeon
    2013-06-11 01:30 . 2013-06-11 01:30 -------- d-----w- c:\programdata\FLEXnet
    2013-06-11 01:25 . 2013-06-11 01:32 -------- d-----w- c:\programdata\Yahoo!
    2013-06-11 01:19 . 2013-06-11 01:19 -------- d-----w- c:\programdata\APN
    2013-06-11 00:35 . 2013-05-13 06:37 9460464 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
    2013-06-04 02:46 . 2009-09-04 22:29 1892184 ----a-w- c:\windows\SysWow64\D3DX9_42.dll
    2013-06-04 02:46 . 2006-09-28 21:05 2414360 ----a-w- c:\windows\SysWow64\d3dx9_31.dll
    2013-06-04 02:45 . 2013-06-04 02:45 -------- d-----w- c:\program files (x86)\Common Files\PX Storage Engine
    2013-06-04 02:45 . 2013-06-04 03:59 -------- d-----w- c:\users\Paul Rowan\AppData\Roaming\Winamp
    2013-06-04 02:45 . 2013-06-04 02:46 -------- d-----w- c:\program files (x86)\Winamp
    2013-05-22 20:50 . 2013-05-22 20:50 964552 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6A237217-0CCC-47BA-9266-6C3F2C79C86D}\gapaengine.dll
    2013-05-15 23:08 . 2013-06-12 01:33 -------- d-----w- c:\program files (x86)\Citrix
    2013-05-15 23:07 . 2013-05-15 23:07 -------- d-----w- c:\users\Paul Rowan\AppData\Local\Deployment
    2013-05-15 23:07 . 2013-05-15 23:07 -------- d-----w- c:\users\Paul Rowan\AppData\Local\Apps
    2013-05-15 08:02 . 2013-05-05 21:36 17818624 ----a-w- c:\windows\system32\mshtml.dll
    2013-05-15 08:02 . 2013-05-05 21:16 2382848 ----a-w- c:\windows\system32\mshtml.tlb
    2013-05-15 08:02 . 2013-05-05 19:12 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb
    2013-05-15 00:32 . 2013-04-10 06:01 265064 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2013-06-12 15:14 . 2013-01-08 17:16 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
    2013-06-12 15:14 . 2013-01-08 17:16 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
    2013-05-15 08:06 . 2013-01-07 21:00 75016696 ----a-w- c:\windows\system32\MRT.exe
    2013-05-02 15:29 . 2010-11-21 03:27 278800 ------w- c:\windows\system32\MpSigStub.exe
    2013-04-23 15:17 . 2013-03-13 12:17 905296 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
    2013-04-14 17:58 . 2013-04-14 17:58 286720 ------w- c:\windows\Setup1.exe
    2013-04-14 17:58 . 2013-04-14 17:58 73216 ----a-w- c:\windows\ST6UNST.EXE
    2013-04-13 05:49 . 2013-05-15 00:32 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
    2013-04-13 05:49 . 2013-05-15 00:32 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
    2013-04-13 05:49 . 2013-05-15 00:32 308736 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll
    2013-04-13 05:49 . 2013-05-15 00:32 111104 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll
    2013-04-13 04:45 . 2013-05-15 00:32 474624 ----a-w- c:\windows\apppatch\AcSpecfc.dll
    2013-04-13 04:45 . 2013-05-15 00:32 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll
    2013-04-12 14:45 . 2013-04-24 12:34 1656680 ----a-w- c:\windows\system32\drivers\ntfs.sys
    2013-03-19 06:04 . 2013-04-10 09:51 5550424 ----a-w- c:\windows\system32\ntoskrnl.exe
    2013-03-19 05:46 . 2013-04-10 09:51 43520 ----a-w- c:\windows\system32\csrsrv.dll
    2013-03-19 05:04 . 2013-04-10 09:51 3968856 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
    2013-03-19 05:04 . 2013-04-10 09:51 3913560 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
    2013-03-19 04:47 . 2013-04-10 09:51 6656 ----a-w- c:\windows\SysWow64\apisetschema.dll
    2013-03-19 03:06 . 2013-04-10 09:51 112640 ----a-w- c:\windows\system32\smss.exe
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
    "BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
    "USB3MON"="c:\program files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2012-02-17 291608]
    "IMSS"="c:\program files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe" [2012-07-19 133440]
    "WinampAgent"="c:\program files (x86)\Winamp\winampa.exe" [2012-06-28 74752]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
    "Malwarebytes Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2013-04-04 532040]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 5 (0x5)
    "ConsentPromptBehaviorUser"= 3 (0x3)
    "EnableUIADesktopToggle"= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
    @="Service"
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
    @="Driver"
    .
    R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
    R2 O2SDIOAssist;O2SDIOAssist;c:\windows\SysWOW64\srvany.exe;c:\windows\SysWOW64\srvany.exe [x]
    R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
    R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
    R3 mvusbews;USB EWS Device;c:\windows\system32\Drivers\mvusbews.sys;c:\windows\SYSNATIVE\Drivers\mvusbews.sys [x]
    R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [x]
    R3 NgFilter;Aventail VPN Filter;c:\windows\system32\DRIVERS\ngfilter.sys;c:\windows\SYSNATIVE\DRIVERS\ngfilter.sys [x]
    R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]
    R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]
    R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
    R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x]
    R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys;c:\windows\SYSNATIVE\drivers\terminpt.sys [x]
    R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
    R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
    R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]
    R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]
    R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
    S0 iusb3hcs;Intel(R) USB 3.0 Host Controller Switch Driver;c:\windows\system32\DRIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hcs.sys [x]
    S2 BrcmMgmtAgent;Broadcom Management Agent;c:\program files\Broadcom\MgmtAgent\BrcmMgmtAgent.exe;c:\program files\Broadcom\MgmtAgent\BrcmMgmtAgent.exe [x]
    S2 HPSIService;HP SI Service;c:\windows\system32\HPSIsvc.exe;c:\windows\SYSNATIVE\HPSIsvc.exe [x]
    S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
    S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x]
    S2 NgVpnMgr;Aventail VPN Client;c:\windows\system32\ngvpnmgr.exe;c:\windows\SYSNATIVE\ngvpnmgr.exe [x]
    S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
    S2 ZeroConfigService;Intel(R) PROSet/Wireless Zero Configuration Service;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe [x]
    S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
    S3 iusb3hub;Intel(R) USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x]
    S3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x]
    S3 NgLog;Aventail VPN Logging;c:\windows\system32\DRIVERS\nglog.sys;c:\windows\SYSNATIVE\DRIVERS\nglog.sys [x]
    S3 NgVpn;Aventail VPN Adapter;c:\windows\system32\DRIVERS\ngvpn.sys;c:\windows\SYSNATIVE\DRIVERS\ngvpn.sys [x]
    S3 NgWfp;Aventail VPN Callout;c:\windows\system32\DRIVERS\ngwfp.sys;c:\windows\SYSNATIVE\DRIVERS\ngwfp.sys [x]
    S3 O2SDJRDR;O2SDJRDR;c:\windows\system32\DRIVERS\o2sdjw7x64.sys;c:\windows\SYSNATIVE\DRIVERS\o2sdjw7x64.sys [x]
    .
    .
    --- Other Services/Drivers In Memory ---
    .
    *NewlyCreated* - ASWFSBLK
    *NewlyCreated* - ASWMONFLT
    *NewlyCreated* - ASWRDR
    *NewlyCreated* - ASWSP
    *NewlyCreated* - ASWTDI
    *NewlyCreated* - ASWVMM
    *NewlyCreated* - MBAMPROTECTOR
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2013-06-13 c:\windows\Tasks\Adobe Flash Player Updater.job
    - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-01-08 15:14]
    .
    .
    --------- X64 Entries -----------
    .
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-01-27 1281512]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-04-25 170264]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-04-25 398616]
    "Persistence"="c:\windows\system32\igfxpers.exe" [2012-04-25 439064]
    "IntelPROSet"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2012-08-23 4805936]
    "SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2012-02-14 1425408]
    "Apoint"="c:\program files\DellTPad\Apoint.exe" [2012-09-20 682904]
    .
    ------- Supplementary Scan -------
    .
    uLocal Page = c:\windows\system32\blank.htm
    uStart Page = hxxp://www.altavista.com/
    mLocal Page = c:\windows\system32\blank.htm
    IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\Office14\EXCEL.EXE/3000
    Trusted Zone: samsungsetup.com\www
    TCP: DhcpNameServer = 192.168.1.254
    DPF: {32E7B36C-7960-4A42-B83B-D8AFD0AAEF2B} - hxxp://dizun95pzobbc.cloudfront.net/INDBrowser.CAB
    DPF: {99E63F21-514B-4C2B-9170-D25D54F65D5B} - hxxp://dizun95pzobbc.cloudfront.net/VBIXDPlayer.CAB
    .
    - - - - ORPHANS REMOVED - - - -
    .
    Toolbar-Locked - (no file)
    Wow6432Node-HKCU-Run-ISUSPM - c:\programdata\FLEXnet\Connect\11\ISUSPM.exe
    AddRemove-getsav-in - c:\users\Paul Rowan\AppData\Local\getsav-in\uninst.exe
    .
    .
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
    @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker5"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Shockwave Flash Object"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
    @="0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
    @="ShockwaveFlash.ShockwaveFlash.11"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="ShockwaveFlash.ShockwaveFlash"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Macromedia Flash Factory Object"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
    @="FlashFactory.FlashFactory.1"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="FlashFactory.FlashFactory"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker5"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\User Preferences]
    @Denied: (2) (Administrator)
    "88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
    d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,19,75,84,ed,f7,40,31,4c,ba,14,96,\
    "6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15,
    d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,19,75,84,ed,f7,40,31,4c,ba,14,96,\
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
    @Denied: (A) (Everyone)
    "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
    @Denied: (A) (Everyone)
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
    "Key"="ActionsPane3"
    "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    .
    Completion time: 2013-06-12 19:29:25
    ComboFix-quarantined-files.txt 2013-06-13 00:29
    .
    Pre-Run: 269,313,400,832 bytes free
    Post-Run: 272,720,465,920 bytes free
    .
    - - End Of File - - 3178D27D98F996F227E8B20081A654E5
    A36C5E4F47E84449FF07ED3517B43A31


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.