TechSpot

Slow comp/crashes, and Sendori

Inactive
By AnxietyProne
Jan 2, 2013
  1. My sister's computer has been acting up lately and she was unable to make an account so I'm making this post for her from my account. Her computer has been slow lately and crashing. She's also noticed a program in her processes called Sendori that she didn't download herself and she can't get rid of. She has two instances of it: SendoriUP.exe and SendorityTray.exe. I can't tell if this is a malicious program or not. I will post the necessary scan logs. Thank you.
     
  2. AnxietyProne

    AnxietyProne TS Rookie Topic Starter Posts: 85

    Malwarebytes found no issues, so on to DDS:

    DDS (Ver_2012-11-20.01) - NTFS_x86
    Internet Explorer: 9.0.8112.16457 BrowserJavaVersion: 10.9.2
    Run by Erica at 21:52:11 on 2013-01-02
    Microsoft Windows 7 Starter 6.1.7600.0.1252.1.1033.18.1012.397 [GMT -5:00]
    .
    AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
    SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
    SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    SP: Spybot - Search and Destroy *Enabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
    .
    ============== Running Processes ================
    .
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_0cefa6767c6211ec\STacSV.exe
    C:\Program Files\Tablet\Pen\Pen_TouchService.exe
    C:\Windows\SYSTEM32\WISPTIS.EXE
    C:\Program Files\AVAST Software\Avast\AvastSvc.exe
    C:\Windows\system32\WLANExt.exe
    C:\Windows\system32\conhost.exe
    C:\Windows\System32\spoolsv.exe
    C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_0cefa6767c6211ec\aestsrv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\SwSetup\QuickWeb\QW.SYS\config\DVMExportService.exe
    C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
    C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
    C:\Program Files\Sendori\sndappv2.exe
    C:\Program Files\Tablet\Pen\Pen_Tablet.exe
    C:\Windows\system32\taskhost.exe
    C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    C:\Windows\system32\Dwm.exe
    C:\Program Files\Tablet\Pen\Pen_TabletUser.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Sendori\SendoriSvc.exe
    C:\Program Files\Tablet\Pen\Pen_TouchUser.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
    C:\Program Files\Tablet\Pen\Pen_Tablet.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
    C:\Windows\SYSTEM32\WISPTIS.EXE
    C:\Windows\System32\hkcmd.exe
    C:\Windows\System32\igfxpers.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
    C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
    C:\Windows\system32\igfxsrvc.exe
    C:\Program Files\IDT\WDM\sttray.exe
    C:\Program Files\MSN Toolbar\Platform\4.0.0369.0\mswinext.exe
    C:\Program Files\Sendori\Sendori.Service.exe
    C:\Program Files\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
    C:\Program Files\AVAST Software\Avast\AvastUI.exe
    C:\Program Files\Bamboo Dock\BambooCore.exe
    C:\Program Files\Hewlett-Packard\HP CloudDrive\zumodrive.exe
    C:\Program Files\Sendori\SendoriUp.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
    C:\Windows\system32\conhost.exe
    C:\Program Files\Hp\HP Software Update\hpwuschd2.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Program Files\Sendori\SendoriTray.exe
    C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
    C:\Windows\system32\SearchIndexer.exe
    C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
    C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe
    C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
    C:\Program Files\Hewlett-Packard\Shared\hpCaslNotification.exe
    C:\Windows\system32\wuauclt.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe
    C:\Windows\system32\ctfmon.exe
    C:\Windows\system32\conhost.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\svchost.exe -k RPCSS
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\Windows\System32\svchost.exe -k secsvcs
    .
    ============== Pseudo HJT Report ===============
    .
    BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy 2\SDHelper.dll
    BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - <orphaned>
    BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
    BHO: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll
    BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
    BHO: MSN Toolbar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn toolbar\platform\4.0.0369.0\npwinext.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
    TB: MSN Toolbar: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files\msn toolbar\platform\4.0.0369.0\npwinext.dll
    TB: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll
    uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
    uRun: [Spybot-S&D Cleaning] "c:\program files\spybot - search & destroy 2\SDCleaner.exe" /autoclean
    mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
    mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
    mRun: [Persistence] c:\windows\system32\igfxpers.exe
    mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
    mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
    mRun: [SysTrayApp] c:\program files\idt\wdm\sttray.exe
    mRun: [MSN Toolbar] "c:\program files\msn toolbar\platform\4.0.0369.0\mswinext.exe"
    mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume
    mRun: [HP Quick Launch] c:\program files\hewlett-packard\hp quick launch\HPMSGSVC.exe
    mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
    mRun: [ZumoDrive] "c:\program files\hewlett-packard\hp clouddrive\ZumoLauncher.lnk"
    mRun: [HPWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\delayedappstarter.exe 120 c:\program files\hewlett-packard\hp wireless assistant\HPWA_Main.exe /hidden
    mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
    mRun: [BambooCore] c:\program files\bamboo dock\BambooCore.exe
    mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
    mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
    mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
    mRun: [Sendori Tray] "c:\program files\sendori\SendoriTray.exe"
    mRun: [SDTray] "c:\program files\spybot - search & destroy 2\SDTray.exe"
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
    mRunOnce: [Malwarebytes Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpmedi~1.lnk - c:\program files\hewlett-packard\hp media suite\home\ArcStart.exe
    mPolicies-System: ConsentPromptBehaviorUser = dword:3
    mPolicies-System: EnableUIADesktopToggle = dword:0
    IE: E&xport to Microsoft Excel - c:\progra~1\mif5ba~1\office12\EXCEL.EXE/3000
    IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office12\ONBttnIE.dll
    IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy 2\SDHelper.dll
    LSP: c:\windows\system32\Sendori.dll
    TCP: NameServer = 192.168.1.254
    TCP: Interfaces\{914F22E1-DC67-43AD-B7B6-DD87B933E5C2} : NameServer = 216.146.35.240,216.146.36.240,192.168.1.254
    TCP: Interfaces\{914F22E1-DC67-43AD-B7B6-DD87B933E5C2} : DHCPNameServer = 192.168.1.254
    Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll
    Notify: igfxcui - igfxdev.dll
    Notify: SDWinLogon - SDWinLogon.dll
    mASetup: {4FB2407C-C8E4-BBC8-BB1C-FCCB2EF5914B} - c:\program files\hewlett-packard\hp media suite\home\HPMediaSuite.exe "/installer"
    mASetup: {4FB2AA7C-C8E4-BBC8-BB1C-FAAB2EF5914B} - c:\windows\system32\wscript.exe "c:\program files\hewlett-packard\hp media suite\home\PinItem.vbs"
    .
    ================= FIREFOX ===================
    .
    FF - ProfilePath - c:\users\erica\appdata\roaming\mozilla\firefox\profiles\tc43n002.default\
    FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll
    FF - plugin: c:\program files\google\update\1.3.21.123\npGoogleUpdate3.dll
    FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
    FF - plugin: c:\program files\microsoft silverlight\5.1.10411.0\npctrlui.dll
    FF - plugin: c:\program files\msn toolbar\platform\4.0.0369.0\npwinext.dll
    FF - plugin: c:\program files\tabletplugins\npwacom.dll
    FF - plugin: c:\program files\tabletplugins\npWacomTabletPlugin.dll
    FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
    FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_5_502_135.dll
    FF - plugin: c:\windows\system32\npdeployJava1.dll
    FF - plugin: c:\windows\system32\npmproxy.dll
    .
    ============= SERVICES / DRIVERS ===============
    .
    R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2012-1-11 738504]
    R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2012-1-11 361032]
    R1 DVMIO;DeviceVM IO Service;c:\windows\system32\drivers\dvmio.sys [2009-11-11 18136]
    R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\driverstore\filerepository\stwrt.inf_x86_neutral_0cefa6767c6211ec\AEstSrv.exe [2010-7-7 81920]
    R2 Application Sendori;Application Sendori;c:\program files\sendori\SendoriSvc.exe [2012-12-10 118632]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2012-1-11 21256]
    R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-1-11 58680]
    R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2012-11-20 44808]
    R2 DvmMDES;DeviceVM Meta Data Export Service;c:\swsetup\quickweb\qw.sys\config\DVMExportService.exe [2010-3-31 338168]
    R2 HP Wireless Assistant Service;HP Wireless Assistant Service;c:\program files\hewlett-packard\hp wireless assistant\HPWA_Service.exe [2010-4-5 103992]
    R2 HPWMISVC;HPWMISVC;c:\program files\hewlett-packard\hp quick launch\HPWMISVC.exe [2010-4-9 26168]
    R2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files\spybot - search & destroy 2\SDFSSvc.exe [2012-12-23 1103392]
    R2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files\spybot - search & destroy 2\SDUpdSvc.exe [2012-12-23 1369624]
    R2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files\spybot - search & destroy 2\SDWSCSvc.exe [2012-12-23 168384]
    R2 Service Sendori;Service Sendori;c:\program files\sendori\Sendori.Service.exe [2012-12-10 14696]
    R2 sndappv2;sndappv2;c:\program files\sendori\sndappv2.exe [2012-12-10 3569512]
    R2 TabletServicePen;TabletServicePen;c:\program files\tablet\pen\Pen_Tablet.exe [2012-2-19 5554552]
    R2 TeamViewer7;TeamViewer 7;c:\program files\teamviewer\version7\TeamViewer_Service.exe [2012-9-19 2754984]
    R2 TouchServicePen;Wacom Consumer Touch Service;c:\program files\tablet\pen\Pen_TouchService.exe [2012-2-19 451960]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 HP Support Assistant Service;HP Support Assistant Service;"c:\program files\hewlett-packard\hp support framework\hpsa_service.exe" --> c:\program files\hewlett-packard\hp support framework\hpsa_service.exe [?]
    S2 MBAMScheduler;MBAMScheduler;c:\program files\malwarebytes' anti-malware\mbamscheduler.exe [2012-9-30 398184]
    S2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2012-9-30 682344]
    S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-7-3 160944]
    S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
    S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-1-11 21104]
    S3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\drivers\netw5v32.sys [2009-6-10 4231168]
    S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RtsUStor.sys [2010-7-7 186912]
    S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2010-7-7 204288]
    S3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\drivers\VSTAZL3.SYS [2009-7-13 207360]
    S3 SrvHsfV92;SrvHsfV92;c:\windows\system32\drivers\VSTDPV3.SYS [2009-7-13 980992]
    S3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\drivers\VSTCNXT3.SYS [2009-7-13 661504]
    S3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\drivers\wacmoumonitor.sys [2012-2-19 10752]
    S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\drivers\yk62x86.sys [2009-7-13 311296]
    .
    =============== Created Last 30 ================
    .
    2013-01-03 01:37:11 -------- d-----w- c:\program files\iPod
    2013-01-03 01:36:54 -------- d-----w- c:\programdata\188F1432-103A-4ffb-80F1-36B633C5C9E1
    2013-01-03 01:36:54 -------- d-----w- c:\program files\iTunes
    2013-01-02 06:58:27 6812136 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{9862e471-8451-465e-8212-f3bee5bdd10b}\mpengine.dll
    2012-12-24 04:08:28 -------- d-----w- c:\programdata\Spybot - Search & Destroy
    2012-12-24 04:07:50 15224 ----a-w- c:\windows\system32\sdnclean.exe
    2012-12-24 04:07:20 -------- d-----w- c:\program files\Spybot - Search & Destroy 2
    2012-12-24 04:06:11 -------- d-----w- c:\users\erica\appdata\local\Programs
    2012-12-22 08:01:26 295424 ----a-w- c:\windows\system32\atmfd.dll
    2012-12-22 08:01:24 34304 ----a-w- c:\windows\system32\atmlib.dll
    2012-12-15 02:43:04 2382848 ----a-w- c:\windows\system32\mshtml.tlb
    2012-12-15 02:43:03 420864 ----a-w- c:\windows\system32\vbscript.dll
    2012-12-15 02:43:03 149536 ----a-w- c:\program files\internet explorer\sqmapi.dll
    2012-12-15 02:43:02 194048 ----a-w- c:\program files\internet explorer\IEShims.dll
    2012-12-12 10:44:25 2344960 ----a-w- c:\windows\system32\win32k.sys
    2012-12-12 10:42:31 376832 ----a-w- c:\windows\system32\dpnet.dll
    2012-12-12 10:42:27 245616 ----a-w- c:\windows\system32\drivers\volsnap.sys
    2012-12-12 10:42:05 2048 ----a-w- c:\windows\system32\tzres.dll
    .
    ==================== Find3M ====================
    .
    2012-12-14 21:49:28 21104 ----a-w- c:\windows\system32\drivers\mbam.sys
    2012-12-12 03:38:33 697272 ----a-w- c:\windows\system32\FlashPlayerApp.exe
    2012-12-12 03:38:32 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    2012-12-10 23:01:54 321384 ----a-w- c:\windows\system32\Sendori.dll
    2012-11-14 02:09:22 1800704 ----a-w- c:\windows\system32\jscript9.dll
    2012-11-14 01:58:15 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
    2012-11-14 01:57:37 1129472 ----a-w- c:\windows\system32\wininet.dll
    2012-11-14 01:49:25 142848 ----a-w- c:\windows\system32\ieUnatt.exe
    2012-10-30 23:51:58 738504 ----a-w- c:\windows\system32\drivers\aswSnx.sys
    2012-10-30 23:51:57 58680 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
    2012-10-30 23:51:07 41224 ----a-w- c:\windows\avastSS.scr
    2012-10-16 20:34:37 559104 ----a-w- c:\windows\apppatch\AcLayers.dll
    2012-10-15 16:59:28 44784 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
    2012-10-08 12:30:53 821736 ----a-w- c:\windows\system32\npdeployJava1.dll
    2012-10-08 12:30:53 746984 ----a-w- c:\windows\system32\deployJava1.dll
    .
    ============= FINISH: 21:53:41.90 ===============
     
  3. AnxietyProne

    AnxietyProne TS Rookie Topic Starter Posts: 85

    DDS Attach:

    .
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT
    .
    DDS (Ver_2012-11-20.01)
    .
    Microsoft Windows 7 Starter
    Boot Device: \Device\HarddiskVolume1
    Install Date: 11/5/2011 3:36:26 AM
    System Uptime: 1/2/2013 8:46:17 PM (1 hours ago)
    .
    Motherboard: Hewlett-Packard | | 3660
    Processor: Intel(R) Atom(TM) CPU N455 @ 1.66GHz | CPU | 1332/667mhz
    .
    ==== Disk Partitions =========================
    .
    C: is FIXED (NTFS) - 218 GiB total, 177.109 GiB free.
    D: is FIXED (NTFS) - 15 GiB total, 2.134 GiB free.
    E: is FIXED (FAT32) - 0 GiB total, 0.093 GiB free.
    .
    ==== Disabled Device Manager Items =============
    .
    Class GUID: {6bdd1fc6-810f-11d0-bec7-08002be2092f}
    Description: USB Video Device
    Device ID: USB\VID_5986&PID_0182&MI_00\6&387D489B&0&0000
    Manufacturer: Microsoft
    Name: HP Webcam-50
    PNP Device ID: USB\VID_5986&PID_0182&MI_00\6&387D489B&0&0000
    Service: usbvideo
    .
    ==== System Restore Points ===================
    .
    RP142: 12/7/2012 11:24:27 AM - Windows Update
    RP143: 12/12/2012 5:28:07 AM - Windows Update
    RP144: 12/14/2012 9:29:33 PM - Windows Update
    RP145: 12/18/2012 1:30:45 PM - Windows Update
    RP146: 12/21/2012 8:58:35 PM - Windows Update
    RP147: 12/22/2012 3:00:21 AM - Windows Update
    RP149: 12/24/2012 5:39:15 AM - C
    RP150: 12/28/2012 8:57:00 PM - Windows Update
    RP151: 1/2/2013 1:56:01 AM - Windows Update
    .
    ==== Installed Programs ======================
    .
    Update for Microsoft Office 2007 (KB2508958)
    Acrobat.com
    Adobe AIR
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 11 Plugin
    Adobe Reader 9.5.2 MUI
    Adobe Shockwave Player
    AIM for Windows
    Apple Application Support
    Apple Mobile Device Support
    Apple Software Update
    ArcSoft WebCam Companion 3
    avast! Free Antivirus
    Bamboo
    Bamboo Dock
    Bejeweled 2 Deluxe
    Blasterball 3
    Bonjour
    Broadcom 802.11 Wireless LAN Adapter
    CCleaner
    Chuzzle Deluxe
    Compatibility Pack for the 2007 Office system
    CyberLink DVD Suite
    Diner Dash 2 Restaurant Rescue
    Dream Chronicles
    ESU for Microsoft Windows 7
    Faerie Solitaire
    FATE
    Gem Shop
    GIMP 2.8.0
    Google Chrome
    Google Update Helper
    HP CloudDrive
    HP Customer Experience Enhancements
    HP Game Console
    HP Games
    HP HomeBase
    HP Quick Launch
    HP QuickSync
    HP QuickWeb Installer
    HP Setup
    HP Software Framework
    HP Update
    HP User Guides 0214
    HP Wireless Assistant
    IDT Audio
    Insaniquarium Deluxe
    Intel(R) Graphics Media Accelerator Driver
    Intel® Matrix Storage Manager
    iTunes
    Java 7 Update 9
    Java Auto Updater
    Jewel Match 2
    Jewel Quest II
    Jewel Quest Solitaire
    JoJo's Fashion Show
    Junk Mail filter update
    Mahjongg Artifacts
    Malwarebytes Anti-Malware version 1.70.0.1100
    Microsoft .NET Framework 4 Client Profile
    Microsoft Application Error Reporting
    Microsoft Choice Guard
    Microsoft Default Manager
    Microsoft Office 2007 Service Pack 3 (SP3)
    Microsoft Office Excel MUI (English) 2007
    Microsoft Office Home and Student 2007
    Microsoft Office OneNote MUI (English) 2007
    Microsoft Office PowerPoint MUI (English) 2007
    Microsoft Office PowerPoint Viewer 2007 (English)
    Microsoft Office Proof (English) 2007
    Microsoft Office Proof (French) 2007
    Microsoft Office Proof (Spanish) 2007
    Microsoft Office Proofing (English) 2007
    Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
    Microsoft Office Shared MUI (English) 2007
    Microsoft Office Shared Setup Metadata MUI (English) 2007
    Microsoft Office Suite Activation Assistant
    Microsoft Office Word MUI (English) 2007
    Microsoft Silverlight
    Microsoft SQL Server 2005 Compact Edition [ENU]
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    Microsoft Works
    Mozilla Firefox 17.0.1 (x86 en-US)
    Mozilla Maintenance Service
    MSN Toolbar
    MSN Toolbar Platform
    MSVCRT
    Penguins!
    Plants vs. Zombies
    Polar Bowler
    Power2Go
    Realtek Ethernet Controller Driver For Windows Vista and Later
    Realtek USB 2.0 Card Reader
    Recovery Manager
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
    Security Update for Microsoft Office 2007 suites (KB2596615) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2596672) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2596856) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2687311) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2687441) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2760416) 32-Bit Edition
    Security Update for Microsoft Office Excel 2007 (KB2687307) 32-Bit Edition
    Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Edition
    Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition
    Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition
    Security Update for Microsoft Office Word 2007 (KB2760421) 32-Bit Edition
    Sendori
    Skype Click to Call
    Skype™ 5.10
    Slingo Deluxe
    Spybot - Search & Destroy
    Synaptics Pointing Device Driver
    TeamViewer 7
    Times Reader
    Update for 2007 Microsoft Office System (KB967642)
    Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
    Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
    Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
    Update for Microsoft Office 2007 Help for Common Features (KB963673)
    Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition
    Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition
    Update for Microsoft Office Excel 2007 Help (KB963678)
    Update for Microsoft Office OneNote 2007 Help (KB963670)
    Update for Microsoft Office Powerpoint 2007 Help (KB963669)
    Update for Microsoft Office Script Editor Help (KB963671)
    Update for Microsoft Office Word 2007 Help (KB963665)
    Virtual Villagers - The Secret City
    WebTablet FB Plugin
    WebTablet IE Plugin
    WebTablet Netscape Plugin
    Wedding Dash
    Windows Live Call
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live ID Sign-in Assistant
    Windows Live Mail
    Windows Live Messenger
    Windows Live Photo Gallery
    Windows Live Sync
    Windows Live Upload Tool
    Windows Live Writer
    Zuma Deluxe
    .
    ==== Event Viewer Messages From Past Week ========
    .
    12/31/2012 4:30:34 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Service Sendori service to connect.
    12/31/2012 4:30:34 AM, Error: Service Control Manager [7000] - The Service Sendori service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    12/29/2012 7:38:46 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Wlansvc service.
    12/29/2012 10:41:18 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the TouchServicePen service.
    12/29/2012 10:27:51 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service.
    12/28/2012 12:12:11 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Netman service.
    12/27/2012 7:51:16 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the HP Wireless Assistant Service service.
    12/26/2012 1:04:38 PM, Error: Service Control Manager [7000] - The Google Update Service (gupdate) service failed to start due to the following error: The pipe has been ended.
    12/26/2012 1:04:38 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "109" attempting to start the service gupdate with arguments "/comsvc" in order to run the server: {4EB61BAC-A3B6-4760-9581-655041EF4D69}
    1/2/2013 8:51:30 PM, Error: Service Control Manager [7000] - The HP Support Assistant Service service failed to start due to the following error: The system cannot find the file specified.
    1/2/2013 8:49:25 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: cdrom
    1/2/2013 8:49:25 PM, Error: Service Control Manager [7022] - The Service Sendori service hung on starting.
    1/2/2013 8:30:19 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Apple Mobile Device service, but this action failed with the following error: An instance of the service is already running.
    1/2/2013 8:29:19 PM, Error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    1/2/2013 8:28:28 PM, Error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    1/2/2013 3:51:25 PM, Error: Service Control Manager [7034] - The sndappv2 service terminated unexpectedly. It has done this 1 time(s).
    1/2/2013 2:02:51 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the HPWMISVC service.
    1/2/2013 2:02:48 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Spybot-S&D 2 Updating Service service to connect.
    1/2/2013 2:02:48 AM, Error: Service Control Manager [7000] - The Spybot-S&D 2 Updating Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    1/2/2013 1:43:25 AM, Error: Service Control Manager [7034] - The Google Update Service (gupdate) service terminated unexpectedly. It has done this 1 time(s).
    1/2/2013 1:42:38 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the WinHttpAutoProxySvc service.
    .
    ==== End Of File ===========================
     
  4. Broni

    Broni Malware Annihilator Posts: 48,013   +271

    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running any tools, fixes or applying any changes to your computer other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

    ===================================

    I always want see all logs even if nothing was found.

    • Download RogueKiller on the desktop
    • Close all the running programs
    • Windows Vista/7 users: right click on RogueKiller.exe, click Run as Administrator
    • Otherwise just double-click on RogueKiller.exe
    • Pre-scan will start. Let it finish.
    • Click on SCAN button.
    • Wait until the Status box shows Scan Finished
    • Click on Delete.
    • Wait until the Status box shows Deleting Finished.
    • Click on Report and copy/paste the content of the Notepad into your next reply.
    • RKreport.txt could also be found on your desktop.
    • If more than one log is produced post all logs.
    • If RogueKiller has been blocked, do not hesitate to try a few times more. If really won't run, rename it to winlogon.exe (or winlogon.com) and try again

    ============================

    Download aswMBR to your desktop.
    Double click the aswMBR.exe to run it.
    If you see this question: Would you like to download latest Avast! virus definitions?" say "Yes".
    Click the "Scan" button to start scan.
    On completion of the scan click "Save log", save it to your desktop and post in your next reply.

    NOTE. aswMBR will create MBR.dat file on your desktop. This is a copy of your MBR. Do NOT delete it.
     
  5. AnxietyProne

    AnxietyProne TS Rookie Topic Starter Posts: 85

    My apologies, Broni. Here is the Malwarebytes log for your records:

    Malwarebytes Anti-Malware 1.70.0.1100
    www.malwarebytes.org

    Database version: v2013.01.02.10

    Windows 7 x86 NTFS
    Internet Explorer 9.0.8112.16421
    Erica :: ERICA-PC [administrator]

    1/2/2013 9:31:55 PM
    mbam-log-2013-01-02 (21-31-55).txt

    Scan type: Quick scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | PUP | PUM
    Scan options disabled: Heuristics/Shuriken | P2P
    Objects scanned: 207335
    Time elapsed: 14 minute(s), 40 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 0
    (No malicious items detected)

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 0
    (No malicious items detected)

    (end)
     
  6. AnxietyProne

    AnxietyProne TS Rookie Topic Starter Posts: 85

    RogueKiller Log:

    RogueKiller V8.4.2 [Dec 31 2012] by Tigzy
    mail : tigzyRK<at>gmail<dot>com
    Feedback : http://www.geekstogo.com/forum/files/file/413-roguekiller/
    Website : http://tigzy.geekstogo.com/roguekiller.php
    Blog : http://tigzyrk.blogspot.com/

    Operating System : Windows 7 (6.1.7600 ) 32 bits version
    Started in : Normal mode
    User : Erica [Admin rights]
    Mode : Remove -- Date : 01/03/2013 01:58:14

    ¤¤¤ Bad processes : 0 ¤¤¤

    ¤¤¤ Registry Entries : 5 ¤¤¤
    [DNS] HKLM\[...]\ControlSet001\Services\Tcpip\Interfaces\{914F22E1-DC67-43AD-B7B6-DD87B933E5C2} : NameServer (216.146.35.240,216.146.36.240,192.168.1.254) -> NOT REMOVED, USE DNSFIX
    [DNS] HKLM\[...]\ControlSet002\Services\Tcpip\Interfaces\{914F22E1-DC67-43AD-B7B6-DD87B933E5C2} : NameServer (216.146.35.240,216.146.36.240,192.168.1.254) -> NOT REMOVED, USE DNSFIX
    [HJPOL] HKCU\[...]\System : disableregistrytools (0) -> DELETED
    [HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
    [HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)

    ¤¤¤ Particular Files / Folders: ¤¤¤

    ¤¤¤ Driver : [LOADED] ¤¤¤

    ¤¤¤ HOSTS File: ¤¤¤
    --> C:\Windows\system32\drivers\etc\hosts

    127.0.0.1 localhost


    ¤¤¤ MBR Check: ¤¤¤

    +++++ PhysicalDrive0: ST9250410AS +++++
    --- User ---
    [MBR] e333384ada68f5f79c145728a62db8a5
    [BSP] c9e2a9c3cb6a242d888f9111c359368c : Windows Vista/7/8 MBR Code
    Partition table:
    0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 199 Mo
    1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 409600 | Size: 222972 Mo
    2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 457056256 | Size: 15199 Mo
    3 - [XXXXXX] FAT32-LBA (0x0c) [VISIBLE] Offset (sectors): 488183808 | Size: 103 Mo
    User = LL1 ... OK!
    User = LL2 ... OK!

    Finished : << RKreport[2]_D_01032013_02d0158.txt >>
    RKreport[1]_S_01032013_02d0157.txt ; RKreport[2]_D_01032013_02d0158.txt
     
  7. AnxietyProne

    AnxietyProne TS Rookie Topic Starter Posts: 85

    aswMBR Log:

    aswMBR version 0.9.9.1707 Copyright(c) 2011 AVAST Software
    Run date: 2013-01-03 02:02:24
    -----------------------------
    02:02:24.027 OS Version: Windows 6.1.7600
    02:02:24.027 Number of processors: 2 586 0x1C0A
    02:02:24.027 ComputerName: ERICA-PC UserName: Erica
    02:02:26.757 Initialize success
    02:02:28.239 AVAST engine defs: 13010201
    02:04:22.532 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0
    02:04:22.532 Disk 0 Vendor: ST925041 0006 Size: 238475MB BusType: 3
    02:04:22.563 Disk 0 MBR read successfully
    02:04:22.579 Disk 0 MBR scan
    02:04:22.594 Disk 0 unknown MBR code
    02:04:22.625 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 199 MB offset 2048
    02:04:22.657 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 222972 MB offset 409600
    02:04:22.703 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 15199 MB offset 457056256
    02:04:22.719 Disk 0 Partition 4 00 0C FAT32 LBA MSDOS5.0 103 MB offset 488183808
    02:04:22.750 Disk 0 scanning sectors +488395120
    02:04:22.844 Disk 0 scanning C:\Windows\system32\drivers
    02:04:40.487 Service scanning
    02:05:07.850 Modules scanning
    02:05:15.513 Disk 0 trace - called modules:
    02:05:15.576 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll iaStor.sys
    02:05:15.591 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x84e461c0]
    02:05:15.623 3 CLASSPNP.SYS[867af59e] -> nt!IofCallDriver -> [0x8445e878]
    02:05:15.654 5 ACPI.sys[860bb3b2] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0x84041028]
    02:05:17.605 AVAST engine scan C:\Windows
    02:05:21.458 AVAST engine scan C:\Windows\system32
    02:09:03.770 AVAST engine scan C:\Windows\system32\drivers
    02:09:22.586 AVAST engine scan C:\Users\Erica
    02:14:19.190 AVAST engine scan C:\ProgramData
    02:17:02.476 Scan finished successfully
    02:20:18.330 Disk 0 MBR has been saved successfully to "C:\Users\Erica\Desktop\MBR.dat"
    02:20:18.361 The log file has been saved successfully to "C:\Users\Erica\Desktop\aswMBR.txt"
     
  8. Broni

    Broni Malware Annihilator Posts: 48,013   +271

    Create new restore point before proceeding with the next step....
    How to:
    - Windows 8: http://www.vikitech.com/11302/system-restore-windows-8
    - Windows 7: http://www.howtogeek.com/howto/3195/create-a-system-restore-point-in-windows-7/
    - Vista: http://www.howtogeek.com/howto/wind...tore-point-for-windows-vistas-system-restore/
    - XP: http://support.microsoft.com/kb/948247

    ============================

    Please download ComboFix from Here, Here or Here to your Desktop.

    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    • Never rename Combofix unless instructed.
    • Close any open browsers.
    • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
      If the connection is not there use restore point you created prior to running Combofix.
    • Double click on combofix.exe & follow the prompts.

    • NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
    • When finished, it will produce a report for you.
    • Please post the "C:\ComboFix.txt"
    **Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
    **Note 2 for AVG and CA Internet Security (Total Defense Internet Security) users: ComboFix will not run until AVG/CA Internet Security is uninstalled as a protective measure against the anti-virus. This is because AVG/CA Internet Security "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results". Since AVG/CA Internet Security cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG/CA Internet Security first.
    Use AppRemover to uninstall it: http://www.appremover.com/
    We can reinstall it when we're done with CF.
    **Note 3: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion", restart computer to fix the issue.
    **Note 4: Some infections may take some significant time to be cured. As long as your computer clock is running Combofix is still working. Be patient.


    Make sure, you re-enable your security programs, when you're done with Combofix.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    NOTE.
    If, for some reason, Combofix refuses to run, try the following...

    Delete Combofix file, download fresh one, but rename combofix.exe to your_name.exe BEFORE saving it to your desktop.
    Do NOT run it yet.
    Download Rkill (courtesy of BleepingComputer.com) to your desktop.
    There are 2 different versions. If one of them won't run then download and try to run the other one.
    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    rKill.exe: http://www.bleepingcomputer.com/download/rkill/dl/10/
    iExplore.exe (renamed rKill.exe): http://www.bleepingcomputer.com/download/rkill/dl/11/

    Restart computer in safe mode

    • Double-click on the Rkill desktop icon to run the tool.
    • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    • If not, delete the file, then download and use the one provided in Link 2.
    • Do not reboot until instructed.
    • If the tool does not run from any of the links provided, please let me know.

    When the scan is done Notepad will open with rKill.txt log.
    NOTE. rKill.txt log will also be present on your desktop.

    Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

    IF you had to run rKill post BOTH logs, rKill.txt and Combofix.txt.
     
  9. AnxietyProne

    AnxietyProne TS Rookie Topic Starter Posts: 85

    When trying to run Combofix, the computer crashed. Upon restarting there were multiple errors so I attempted to set it back to the newly made restore point. When it turned the computer back on, a box appeared that said the computer failed to restart and it is searching for a new point to send the computer back to to get it working again. It's been going for five minutes. I will update when it turns back on.. if it turns back on.
     
  10. AnxietyProne

    AnxietyProne TS Rookie Topic Starter Posts: 85

    It restarted, and the screen stayed white for three minutes. Finally it loaded the desktop background and icons. It has never done this before, so I'm worried something is now corrupted. I believe it did manage to set it back to the newly made restore point as ComboFix is gone but not the other programs that have been recently added. Should I proceed with ComboFix scan?

    edit: Since the restore, it's not doing the white screen thing anymore. I'm still going to wait until I get the go ahead from you to run the Combofix scan though. Sorry for the wait.
     
  11. Broni

    Broni Malware Annihilator Posts: 48,013   +271

    For x32 (x86) bit systems download Farbar Recovery Scan Tool 32-Bit and save it to a flash drive.
    For x64 bit systems download Farbar Recovery Scan Tool 64-Bit and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    If you are using Windows 8 consult How to use the Windows 8 System Recovery Environment Command Prompt to enter System Recovery Command prompt.

    If you are using Vista or Windows 7 enter System Recovery Options.

    To enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.

    To enter System Recovery Options by using Windows installation disc:
    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.

    On the System Recovery Options menu you will get the following options:

      • Startup Repair
        System Restore
        Windows Complete PC Restore
        Windows Memory Diagnostic Tool
        Command Prompt
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.
     
     
  12. AnxietyProne

    AnxietyProne TS Rookie Topic Starter Posts: 85

    FRST Log:

    Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 31-12-2012
    Ran by SYSTEM at 04-01-2013 21:23:16
    Running from G:\
    Windows 7 Starter (X86) OS Language: English(US)
    The current controlset is ControlSet001

    ==================== Registry (Whitelisted) ===================

    HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [1721640 2012-02-21] (Synaptics Incorporated)
    HKLM\...\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-10-13] (Intel Corporation)
    HKLM\...\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe [495708 2010-02-26] (IDT, Inc.)
    HKLM\...\Run: [MSN Toolbar] "C:\Program Files\MSN Toolbar\Platform\4.0.0369.0\mswinext.exe" [240472 2009-11-30] (Microsoft Corp.)
    HKLM\...\Run: [Microsoft Default Manager] "C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume [288080 2009-07-17] (Microsoft Corporation)
    HKLM\...\Run: [HP Quick Launch] C:\Program Files\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [601144 2010-04-09] (Hewlett-Packard Company)
    HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [919008 2012-07-11] (Adobe Systems Incorporated)
    HKLM\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [38872 2012-07-31] (Adobe Systems Incorporated)
    HKLM\...\Run: [ZumoDrive] "C:\Program Files\Hewlett-Packard\HP CloudDrive\ZumoLauncher.lnk" [2038 2010-05-12] ()
    HKLM\...\Run: [HPWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe 120 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe /hidden [363064 2010-04-05] (Hewlett-Packard)
    HKLM\...\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui [4297136 2012-10-30] (AVAST Software)
    HKLM\...\Run: [BambooCore] C:\Program Files\Bamboo Dock\BambooCore.exe [646744 2012-12-12] ()
    HKLM\...\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-05-09] (Hewlett-Packard)
    HKLM\...\Run: [] [x]
    HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-11-28] (Apple Inc.)
    HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [252848 2012-07-03] (Sun Microsystems, Inc.)
    HKLM\...\Run: [Sendori Tray] "C:\Program Files\Sendori\SendoriTray.exe" [82792 2012-12-10] (Sendori, Inc.)
    HKLM\...\Run: [SDTray] "C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe" [3825176 2012-11-13] (Safer-Networking Ltd.)
    HKLM\...\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [152544 2012-12-12] (Apple Inc.)
    HKU\Erica\...\Run: [Spybot-S&D Cleaning] "C:\Program Files\Spybot - Search & Destroy 2\SDCleaner.exe" /autoclean [3713032 2012-11-13] (Safer-Networking Ltd.)
    Winlogon\Notify\SDWinLogon: SDWinLogon.dll [X]
    Tcpip\Parameters: [DhcpNameServer] 192.168.1.254

    ==================== Services (Whitelisted) ===================

    3 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [109056 2009-02-06] (ArcSoft Inc.)
    2 Application Sendori; C:\Program Files\Sendori\SendoriSvc.exe [118632 2012-12-10] (Sendori, Inc.)
    2 avast! Antivirus; "C:\Program Files\AVAST Software\Avast\AvastSvc.exe" [44808 2012-10-30] (AVAST Software)
    2 DvmMDES; "C:\SwSetup\QuickWeb\QW.SYS\config\DVMExportService.exe" [338168 2010-03-31] (DeviceVM, Inc.)
    3 GameConsoleService; "C:\Program Files\HP Games\HP Game Console\GameConsoleService.exe" [238328 2010-01-04] (WildTangent, Inc.)
    2 HP Wireless Assistant Service; "C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe" [103992 2010-04-05] (Hewlett-Packard)
    2 HPWMISVC; C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [26168 2010-04-09] ()
    2 MBAMScheduler; "C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe" [398184 2012-12-14] (Malwarebytes Corporation)
    2 MBAMService; "C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe" [682344 2012-12-14] (Malwarebytes Corporation)
    2 SDScannerService; C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe [1103392 2012-11-13] (Safer-Networking Ltd.)
    2 SDUpdateService; C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe [1369624 2012-11-13] (Safer-Networking Ltd.)
    2 SDWSCService; C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe [168384 2012-11-13] (Safer-Networking Ltd.)
    2 Service Sendori; C:\Program Files\Sendori\Sendori.Service.exe [14696 2012-12-10] (sendori)
    2 sndappv2; C:\Program Files\Sendori\sndappv2.exe [3569512 2012-12-10] (Sendori)
    2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_0cefa6767c6211ec\STacSV.exe [229458 2010-02-26] (IDT, Inc.)
    4 avast! Firewall; "C:\Program Files\AVAST Software\Avast\afwServ.exe" [x]
    2 HP Support Assistant Service; "C:\Program Files\Hewlett-Packard\HP Support Framework\hpsa_service.exe" [x]

    ==================== Drivers (Whitelisted) ====================

    2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [21256 2012-10-30] (AVAST Software)
    2 aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [58680 2012-10-30] (AVAST Software)
    1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [44784 2012-10-15] (AVAST Software)
    1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [738504 2012-10-30] (AVAST Software)
    1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [361032 2012-10-30] (AVAST Software)
    1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [54232 2012-10-30] (AVAST Software)
    1 DVMIO; C:\Windows\System32\DRIVERS\dvmio.sys [18136 2009-11-11] (DeviceVM, Inc.)
    3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [21104 2012-12-14] (Malwarebytes Corporation)
    3 catchme; \??\C:\Users\Erica\AppData\Local\Temp\catchme.sys [x]

    ==================== NetSvcs (Whitelisted) ===================


    ==================== One Month Created Files and Folders ========

    2013-01-04 21:23 - 2013-01-04 21:23 - 00000000 ____D C:\FRST
    2013-01-04 18:06 - 2013-01-04 18:07 - 00909508 ____A (Farbar) C:\Users\Erica\Downloads\FRST.exe
    2013-01-02 23:20 - 2013-01-02 23:20 - 00002088 ____A C:\Users\Erica\Desktop\aswMBR.txt
    2013-01-02 23:20 - 2013-01-02 23:20 - 00000512 ____A C:\Users\Erica\Desktop\MBR.dat
    2013-01-02 23:00 - 2013-01-02 23:01 - 04732416 ____A (AVAST Software) C:\Users\Erica\Desktop\aswMBR.exe
    2013-01-02 22:58 - 2013-01-02 22:58 - 00001986 ____A C:\Users\Erica\Desktop\RKreport[2]_D_01032013_02d0158.txt
    2013-01-02 22:57 - 2013-01-02 22:57 - 00001895 ____A C:\Users\Erica\Desktop\RKreport[1]_S_01032013_02d0157.txt
    2013-01-02 22:55 - 2013-01-02 22:58 - 00000000 ____D C:\Users\Erica\Desktop\RK_Quarantine
    2013-01-02 22:53 - 2013-01-02 22:53 - 00761856 ____A C:\Users\Erica\Desktop\RogueKiller.exe
    2013-01-02 18:54 - 2013-01-02 18:54 - 00011788 ____A C:\Users\Erica\Desktop\attach.txt
    2013-01-02 18:54 - 2013-01-02 18:53 - 00017020 ____A C:\Users\Erica\Desktop\dds.txt
    2013-01-02 18:48 - 2013-01-02 18:48 - 00688992 ____R (Swearware) C:\Users\Erica\Desktop\dds.com
    2013-01-02 17:38 - 2013-01-02 17:38 - 00001753 ____A C:\Users\Public\Desktop\iTunes.lnk
    2013-01-02 17:37 - 2013-01-02 17:37 - 00000000 ____D C:\Program Files\iPod
    2013-01-02 17:36 - 2013-01-02 17:38 - 00000000 ____D C:\Program Files\iTunes
    2012-12-31 01:29 - 2013-01-04 18:17 - 00000504 ____A C:\Windows\setupact.log
    2012-12-31 01:29 - 2012-12-31 01:29 - 00000000 ____A C:\Windows\setuperr.log
    2012-12-23 20:08 - 2012-12-23 20:08 - 00002119 ____A C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
    2012-12-23 20:07 - 2012-12-23 20:08 - 00000000 ____D C:\Program Files\Spybot - Search & Destroy 2
    2012-12-23 20:07 - 2009-01-25 09:14 - 00015224 ____A (Safer Networking Limited) C:\Windows\System32\sdnclean.exe
    2012-12-23 20:02 - 2012-12-23 20:05 - 55454464 ____A (Safer-Networking Ltd. ) C:\Users\Erica\Downloads\SpybotSD2.exe
    2012-12-22 00:01 - 2012-12-16 06:25 - 00295424 ____A (Adobe Systems Incorporated) C:\Windows\System32\atmfd.dll
    2012-12-22 00:01 - 2012-12-16 06:25 - 00034304 ____A (Adobe Systems) C:\Windows\System32\atmlib.dll
    2012-12-14 18:43 - 2012-11-13 17:51 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
    2012-12-14 18:43 - 2012-11-13 17:48 - 00420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
    2012-12-14 18:43 - 2012-11-13 17:45 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
    2012-12-14 18:43 - 2012-11-13 17:44 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
    2012-12-14 18:43 - 2012-11-13 17:41 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
    2012-12-14 18:42 - 2012-11-13 18:48 - 12320256 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
    2012-12-14 18:42 - 2012-11-13 18:14 - 09738240 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
    2012-12-14 18:42 - 2012-11-13 18:09 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
    2012-12-14 18:42 - 2012-11-13 17:58 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
    2012-12-14 18:42 - 2012-11-13 17:57 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
    2012-12-14 18:42 - 2012-11-13 17:57 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
    2012-12-14 18:42 - 2012-11-13 17:55 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
    2012-12-14 18:42 - 2012-11-13 17:49 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
    2012-12-14 18:42 - 2012-11-13 17:49 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
    2012-12-14 18:42 - 2012-11-13 17:47 - 00607744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
    2012-12-14 18:42 - 2012-11-13 17:46 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
    2012-12-12 02:44 - 2012-11-21 23:43 - 02344960 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
    2012-12-12 02:43 - 2012-10-04 08:53 - 00169984 ____A (Microsoft Corporation) C:\Windows\System32\winsrv.dll
    2012-12-12 02:43 - 2012-10-04 08:49 - 00868352 ____A (Microsoft Corporation) C:\Windows\System32\kernel32.dll
    2012-12-12 02:43 - 2012-10-04 08:49 - 00293376 ____A (Microsoft Corporation) C:\Windows\System32\KernelBase.dll
    2012-12-12 02:43 - 2012-10-04 08:45 - 00005120 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
    2012-12-12 02:43 - 2012-10-04 08:45 - 00004608 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
    2012-12-12 02:43 - 2012-10-04 08:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
    2012-12-12 02:43 - 2012-10-04 08:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
    2012-12-12 02:43 - 2012-10-04 08:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
    2012-12-12 02:43 - 2012-10-04 08:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
    2012-12-12 02:43 - 2012-10-04 08:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
    2012-12-12 02:43 - 2012-10-04 08:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
    2012-12-12 02:43 - 2012-10-04 08:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
    2012-12-12 02:43 - 2012-10-04 08:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
    2012-12-12 02:43 - 2012-10-04 08:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
    2012-12-12 02:43 - 2012-10-04 08:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
    2012-12-12 02:43 - 2012-10-04 08:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
    2012-12-12 02:43 - 2012-10-04 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
    2012-12-12 02:43 - 2012-10-04 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
    2012-12-12 02:43 - 2012-10-04 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
    2012-12-12 02:43 - 2012-10-04 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
    2012-12-12 02:43 - 2012-10-04 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
    2012-12-12 02:43 - 2012-10-04 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
    2012-12-12 02:43 - 2012-10-04 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
    2012-12-12 02:43 - 2012-10-04 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
    2012-12-12 02:43 - 2012-10-04 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
    2012-12-12 02:43 - 2012-10-04 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
    2012-12-12 02:43 - 2012-10-04 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
    2012-12-12 02:43 - 2012-10-04 07:00 - 00271360 ____A (Microsoft Corporation) C:\Windows\System32\conhost.exe
    2012-12-12 02:43 - 2012-10-04 06:44 - 00006144 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
    2012-12-12 02:43 - 2012-10-04 06:44 - 00004608 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
    2012-12-12 02:43 - 2012-10-04 06:44 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
    2012-12-12 02:43 - 2012-10-04 06:44 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
    2012-12-12 02:42 - 2012-11-08 20:49 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\tzres.dll
    2012-12-12 02:42 - 2012-11-01 20:48 - 00376832 ____A (Microsoft Corporation) C:\Windows\System32\dpnet.dll
    2012-12-12 02:42 - 2012-09-06 08:48 - 00245616 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\volsnap.sys
    2012-12-05 20:44 - 2012-12-05 20:45 - 00000000 ____D C:\Program Files\Mozilla Firefox

    ==================== One Month Modified Files and Folders ========

    2013-01-04 18:19 - 2012-11-18 02:08 - 00000884 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
    2013-01-04 18:17 - 2012-12-31 01:29 - 00000504 ____A C:\Windows\setupact.log
    2013-01-04 18:17 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
    2013-01-04 18:08 - 2010-07-07 17:39 - 01908207 ____A C:\Windows\WindowsUpdate.log
    2013-01-04 18:07 - 2013-01-04 18:06 - 00909508 ____A (Farbar) C:\Users\Erica\Downloads\FRST.exe
    2013-01-04 18:03 - 2009-09-06 15:02 - 00730720 ____A C:\Windows\System32\PerfStringBackup.INI
    2013-01-04 17:51 - 2012-04-02 21:54 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
    2013-01-04 02:19 - 2012-11-18 02:08 - 00000880 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
    2013-01-03 23:18 - 2012-11-14 19:13 - 00000000 ___SD C:\ComboFix
    2013-01-03 23:18 - 2012-01-16 05:18 - 00000000 ____D C:\Windows\ERDNT
    2013-01-03 23:18 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\wfp
    2013-01-03 23:18 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\DriverStore
    2013-01-03 23:18 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\registration
    2013-01-03 23:10 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\LogFiles
    2013-01-03 21:01 - 2009-07-13 20:34 - 00014128 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2013-01-03 21:01 - 2009-07-13 20:34 - 00014128 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2013-01-03 20:52 - 2011-11-04 23:44 - 00000000 ____D C:\Users\Erica\AppData\Roaming\ZumoDrive
    2013-01-03 20:19 - 2011-11-04 23:36 - 00000000 ____D C:\users\Erica
    2013-01-03 10:42 - 2012-03-08 16:34 - 00000000 ____D C:\Users\Erica\AppData\Local\CrashDumps
    2013-01-02 23:20 - 2013-01-02 23:20 - 00002088 ____A C:\Users\Erica\Desktop\aswMBR.txt
    2013-01-02 23:20 - 2013-01-02 23:20 - 00000512 ____A C:\Users\Erica\Desktop\MBR.dat
    2013-01-02 23:01 - 2013-01-02 23:00 - 04732416 ____A (AVAST Software) C:\Users\Erica\Desktop\aswMBR.exe
    2013-01-02 22:58 - 2013-01-02 22:58 - 00001986 ____A C:\Users\Erica\Desktop\RKreport[2]_D_01032013_02d0158.txt
    2013-01-02 22:58 - 2013-01-02 22:55 - 00000000 ____D C:\Users\Erica\Desktop\RK_Quarantine
    2013-01-02 22:57 - 2013-01-02 22:57 - 00001895 ____A C:\Users\Erica\Desktop\RKreport[1]_S_01032013_02d0157.txt
    2013-01-02 22:53 - 2013-01-02 22:53 - 00761856 ____A C:\Users\Erica\Desktop\RogueKiller.exe
    2013-01-02 18:54 - 2013-01-02 18:54 - 00011788 ____A C:\Users\Erica\Desktop\attach.txt
    2013-01-02 18:53 - 2013-01-02 18:54 - 00017020 ____A C:\Users\Erica\Desktop\dds.txt
    2013-01-02 18:48 - 2013-01-02 18:48 - 00688992 ____R (Swearware) C:\Users\Erica\Desktop\dds.com
    2013-01-02 18:30 - 2012-01-11 12:57 - 00001067 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2013-01-02 18:30 - 2012-01-11 12:57 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
    2013-01-02 17:38 - 2013-01-02 17:38 - 00001753 ____A C:\Users\Public\Desktop\iTunes.lnk
    2013-01-02 17:38 - 2013-01-02 17:36 - 00000000 ____D C:\Program Files\iTunes
    2013-01-02 17:37 - 2013-01-02 17:37 - 00000000 ____D C:\Program Files\iPod
    2013-01-02 17:37 - 2012-05-08 19:00 - 00000000 ____D C:\Program Files\Common Files\Apple
    2012-12-31 01:29 - 2012-12-31 01:29 - 00000000 ____A C:\Windows\setuperr.log
    2012-12-23 20:08 - 2012-12-23 20:08 - 00002119 ____A C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
    2012-12-23 20:08 - 2012-12-23 20:07 - 00000000 ____D C:\Program Files\Spybot - Search & Destroy 2
    2012-12-23 20:05 - 2012-12-23 20:02 - 55454464 ____A (Safer-Networking Ltd. ) C:\Users\Erica\Downloads\SpybotSD2.exe
    2012-12-22 01:21 - 2009-07-13 20:33 - 00342496 ____A C:\Windows\System32\FNTCACHE.DAT
    2012-12-21 21:11 - 2012-04-04 16:40 - 00000000 ____D C:\Users\Erica\AppData\Roaming\Skype
    2012-12-18 15:36 - 2012-05-06 04:52 - 00025881 ____A C:\Users\Erica\Documents\qx.txt
    2012-12-16 06:25 - 2012-12-22 00:01 - 00295424 ____A (Adobe Systems Incorporated) C:\Windows\System32\atmfd.dll
    2012-12-16 06:25 - 2012-12-22 00:01 - 00034304 ____A (Adobe Systems) C:\Windows\System32\atmlib.dll
    2012-12-15 21:09 - 2012-11-14 18:48 - 00000320 ____A C:\Windows\Tasks\HPCeeScheduleForErica.job
    2012-12-15 00:58 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\rescache
    2012-12-14 18:36 - 2012-11-18 02:12 - 00002320 ____A C:\Users\Public\Desktop\Google Chrome.lnk
    2012-12-14 18:20 - 2012-10-29 19:21 - 00000000 ____D C:\Program Files\Sendori
    2012-12-14 13:49 - 2012-01-11 12:57 - 00021104 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
    2012-12-12 14:11 - 2012-02-19 12:56 - 00000000 ____D C:\Users\Erica\AppData\Roaming\Wacom
    2012-12-12 14:11 - 2012-02-19 12:55 - 00000000 ____D C:\Program Files\Bamboo Dock
    2012-12-11 19:38 - 2012-04-02 21:53 - 00697272 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
    2012-12-11 19:38 - 2011-11-05 07:25 - 00073656 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
    2012-12-10 15:01 - 2012-10-29 19:22 - 00321384 ____A (Sendori) C:\Windows\System32\Sendori.dll
    2012-12-07 08:14 - 2012-04-27 01:33 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
    2012-12-05 20:45 - 2012-12-05 20:44 - 00000000 ____D C:\Program Files\Mozilla Firefox


    ==================== Known DLLs (Whitelisted) =================


    ==================== Bamital & volsnap Check =================

    C:\Windows\explorer.exe => MD5 is legit
    C:\Windows\System32\winlogon.exe => MD5 is legit
    C:\Windows\System32\wininit.exe => MD5 is legit
    C:\Windows\System32\svchost.exe => MD5 is legit
    C:\Windows\System32\services.exe => MD5 is legit
    C:\Windows\System32\User32.dll => MD5 is legit
    C:\Windows\System32\userinit.exe => MD5 is legit
    C:\Windows\System32\Drivers\volsnap.sys
    [2012-12-12 02:42] - [2012-09-06 08:48] - 0245616 ____A (Microsoft Corporation) 59F06B4968E58BC83DFC56CA4517960E


    ==================== EXE ASSOCIATION =====================

    HKLM\...\.exe: exefile => OK
    HKLM\...\exefile\DefaultIcon: %1 => OK
    HKLM\...\exefile\open\command: "%1" %* => OK

    ==================== Restore Points =========================

    Restore point made on: 2012-12-12 02:28:36
    Restore point made on: 2012-12-14 18:30:25
    Restore point made on: 2012-12-18 10:31:26
    Restore point made on: 2012-12-21 17:59:19
    Restore point made on: 2012-12-22 00:00:58
    Restore point made on: 2012-12-24 02:39:42
    Restore point made on: 2012-12-28 17:57:34
    Restore point made on: 2013-01-01 22:56:45
    Restore point made on: 2013-01-03 19:47:14
    Restore point made on: 2013-01-03 20:05:34

    ==================== Memory info ===========================

    Percentage of memory in use: 47%
    Total physical RAM: 1012.2 MB
    Available physical RAM: 533.7 MB
    Total Pagefile: 1012.2 MB
    Available Pagefile: 531.53 MB
    Total Virtual: 2047.88 MB
    Available Virtual: 1962.3 MB

    ==================== Partitions =============================

    1 Drive c: () (Fixed) (Total:217.75 GB) (Free:177.02 GB) NTFS ==>[System with boot components (obtained from reading drive)]
    2 Drive e: (RECOVERY) (Fixed) (Total:14.84 GB) (Free:2.13 GB) NTFS ==>[System with boot components (obtained from reading drive)]
    3 Drive f: (HP_TOOLS) (Fixed) (Total:0.1 GB) (Free:0.09 GB) FAT32
    4 Drive g: (USB20FD) (Removable) (Total:3.73 GB) (Free:3.73 GB) FAT32
    5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
    6 Drive y: (SYSTEM) (Fixed) (Total:0.19 GB) (Free:0.16 GB) NTFS ==>[System with boot components (obtained from reading drive)]

    Disk ### Status Size Free Dyn Gpt
    -------- ------------- ------- ------- --- ---
    Disk 0 Online 232 GB 0 B
    Disk 1 Online 3824 MB 0 B

    Partitions of Disk 0:
    ===============

    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    Partition 1 Primary 199 MB 1024 KB
    Partition 2 Primary 217 GB 200 MB
    Partition 3 Primary 14 GB 217 GB
    Partition 4 Primary 103 MB 232 GB

    =========================================================

    Disk: 0
    Partition 1
    Type : 07
    Hidden: No
    Active: Yes

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 0 Y SYSTEM NTFS Partition 199 MB Healthy

    =========================================================

    Disk: 0
    Partition 2
    Type : 07
    Hidden: No
    Active: No

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 1 C NTFS Partition 217 GB Healthy

    =========================================================

    Disk: 0
    Partition 3
    Type : 07
    Hidden: No
    Active: No

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 2 E RECOVERY NTFS Partition 14 GB Healthy

    =========================================================

    Disk: 0
    Partition 4
    Type : 0C
    Hidden: No
    Active: No

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 3 F HP_TOOLS FAT32 Partition 103 MB Healthy

    =========================================================

    Partitions of Disk 1:
    ===============

    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    Partition 1 Primary 3823 MB 572 KB

    =========================================================

    Disk: 1
    Partition 1
    Type : 0C
    Hidden: No
    Active: Yes

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 4 G USB20FD FAT32 Removable 3823 MB Healthy

    =========================================================

    Last Boot: 2013-01-04 01:09

    ==================== End Of Log ============================
     
  13. Broni

    Broni Malware Annihilator Posts: 48,013   +271

    I don't see anything malicious on your computer.
    I suggest you start new topic in Windows forum.
     
  14. AnxietyProne

    AnxietyProne TS Rookie Topic Starter Posts: 85

    Oh, well thank you for taking a look, Broni. Sorry to take up your time. Before you close this topic, I was wondering if you happen to know anything about this Sendori program? It came out of nowhere.
     


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.