Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 06-05-2013
Ran by User (administrator) on 07-05-2013 17:09:58
Running from C:\Users\User\Desktop
Windows Vista (TM) Home Premium Service Pack 2 (X86) OS Language: English(US)
Internet Explorer Version 9
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Microsoft Corporation) C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Hewlett-Packard Company) c:\Program Files\Common Files\LightScribe\LSSrvc.exe
(Motive Communications, Inc.) C:\Program Files\Common Files\Motive\McciCMService.exe
(Microsoft Corporation) c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
(Microsoft Corporation) c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\CisTray.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Conexant Systems, Inc.) C:\Windows\system32\DRIVERS\xaudio.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Yahoo! Inc.) C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
(Microsoft Corporation) c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cis.exe
(Hewlett-Packard) c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
(Microsoft Corporation) C:\Windows\system32\wuauclt.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems Incorporated) C:\Windows\system32\Macromed\Flash\FlashUtil32_11_7_700_169_ActiveX.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Farbar) C:\Users\User\Desktop\FRST.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [3012816 2013-04-15] (COMODO)
HKLM\...\Winlogon: [System]
HKU\Default\...\Run: [HPADVISOR] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN [x]
HKU\Default User\...\Run: [HPADVISOR] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN [x]
HKU\Mandy Hall\...\Run: [Sidebar] "C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun [ 2009-04-11] (Microsoft Corporation)
HKU\Mandy Hall\...\Run: [WMPNSCFG] "C:\Program Files\Windows Media Player\WMPNSCFG.exe" [x]
HKU\Mandy Hall\...\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1 [x]
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
https://www.google.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
URLSearchHook: (No Name) - {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - No File
HKLM SearchScopes: DefaultScope {9A1FA604-C476-4D82-9926-38F90E1FF58E} URL =
http://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=hp-psdt
SearchScopes: HKLM - {8F1B4193-563B-4397-BAB3-803AD2FF6452} URL =
http://www.ask.com/web?q={searchTerms}&l=dis&o=uscqd
SearchScopes: HKLM - {9A1FA604-C476-4D82-9926-38F90E1FF58E} URL =
http://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=hp-psdt
HKCU SearchScopes: DefaultScope {9A1FA604-C476-4D82-9926-38F90E1FF58E} URL =
http://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=hp-psdt
SearchScopes: HKCU - {8F1B4193-563B-4397-BAB3-803AD2FF6452} URL =
http://www.ask.com/web?q={searchTerms}&l=dis&o=uscqd
SearchScopes: HKCU - {9A1FA604-C476-4D82-9926-38F90E1FF58E} URL =
http://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=hp-psdt
SearchScopes: HKCU - {C04B7D22-5AEC-4561-8F49-27F6269208F6} URL =
http://toolbar.inbox.com/search/dispatcher.aspx?tp=bs&qkw={searchTerms}&tbid=80085&lng=en
BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: No Name - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No File
BHO: No Name - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - No File
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
BHO: Social Extras Plugin - {FF4E1D1D-705B-4379-AB33-22D98C1ABF55} - C:\Program Files\SocialExtras\socialx.dll (FBSkins.com)
Toolbar: HKLM - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Toolbar: HKLM - Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
Toolbar: HKCU -No Name - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No File
PDF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
PDF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
PDF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
Handler: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
Handler: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL (Microsoft Corporation)
ShellExecuteHooks: - {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No File [ ]
Winsock: Catalog5 01 %SystemRoot%\System32\mswsock.dll [223232] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [19968] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{6726CE5A-455D-4E08-8F7E-F8E1DE90AFF7}: [NameServer]8.26.56.26,156.154.70.22
Chrome:
=======
CHR HomePage: hxxp://
www.google.com/
CHR RestoreOnStartup: "hxxp://
www.google.com/"
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google

riginalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\21.0.1180.89\PepperFlash\pepflashplayer.dll No File
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\26.0.1410.64\gcswf32.dll No File
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\26.0.1410.64\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\26.0.1410.64\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Java Deployment Toolkit 6.0.260.3) - C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll (Sun Microsystems, Inc.)
CHR Plugin: (Java(TM) Platform SE 6 U26) - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File
CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
========================== Services (Whitelisted) =================
R2 cmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [4443912 2013-04-25] (COMODO)
S3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [127184 2013-04-15] (COMODO)
R2 HP Health Check Service; c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [65536 2007-09-19] (Hewlett-Packard)
R3 MSSQL$MSSMLBIZ; c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [29293408 2010-12-10] (Microsoft Corporation)
S3 Symantec Core LC; C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe [1245064 2008-02-22] ()
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-20] ()
S2 FastUserSwitchingCompatibility; C:\Windows\system32\FastUv32.dll [x]
S2 MsMpSvc; "c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe" [x]
S2 NecUsb; C:\Windows\system32\NUSB3w32.dll [x]
S2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [x]
S3 NisSrv; "c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe" [x]
S2 PavPrSrv; "C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe" [x]
S2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [x]
S3 rpcapd; "%ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini" [x]
==================== Drivers (Whitelisted) ====================
R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [20072 2013-04-15] (COMODO)
R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [582960 2013-04-15] (COMODO)
R1 cmdHlp; C:\Windows\System32\DRIVERS\cmdhlp.sys [43216 2013-04-15] (COMODO)
R1 inspect; C:\Windows\System32\DRIVERS\inspect.sys [84928 2013-04-25] (COMODO)
R1 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [165648 2011-04-18] (Microsoft Corporation)
S3 MpNWMon; C:\Windows\System32\DRIVERS\MpNWMon.sys [43392 2011-04-18] (Microsoft Corporation)
S3 MREMP50; C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS [19712 2008-01-28] (Printing Communications Assoc., Inc. (PCAUSA))
S3 MRESP50; C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS [18304 2008-01-28] (Printing Communications Assoc., Inc. (PCAUSA))
R2 NPF; C:\Windows\System32\drivers\npf.sys [35088 2010-06-25] (CACE Technologies, Inc.)
R0 pavboot; C:\Windows\System32\Drivers\pavboot.sys [28552 2009-06-30] (Panda Security, S.L.)
S3 RT2500USB; C:\Windows\System32\DRIVERS\rt2500usb.sys [245376 2005-10-17] (Ralink Technology Inc.)
S3 rt70x86; C:\Windows\System32\DRIVERS\netr70.sys [300544 2009-06-19] (Ralink Technology Corp.)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S1 MpKsl0cc1f509; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{C19FFAA9-16B4-4D56-A42D-737E39FE409E}\MpKsl0cc1f509.sys [x]
S1 MpKsl1d3f49dd; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{C713D0CF-B4DC-4852-A1C9-D7C6D4B4A323}\MpKsl1d3f49dd.sys [x]
S1 MpKslb6293a5d; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{E5629555-761A-47D6-B84F-9D1811FD4ECB}\MpKslb6293a5d.sys [x]
S3 MREMP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS [x]
S3 MRESP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
S2 PavProc; \??\C:\Windows\system32\DRIVERS\PavProc.sys [x]
S3 PCD5SRVC{BD6912E3-AC9D80E8-05040000}; \??\C:\PROGRA~1\PC-DOC~1\PCD5SRVC.pkms [x]
S1 ShldDrv; System32\DRIVERS\ShlDrv51.sys [x]
S1 Smb; s [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-05-07 17:09 - 2013-05-07 17:09 - 00000000 ____D C:\FRST
2013-05-07 17:09 - 2013-05-07 17:08 - 01313531 ____A (Farbar) C:\Users\User\Desktop\FRST.exe
2013-05-07 16:24 - 2013-05-07 16:24 - 00000000 ___SD C:\ComboFix
2013-05-07 16:02 - 2013-05-07 16:02 - 00012981 ____A C:\ComboFix.txt
2013-05-07 15:08 - 2013-05-07 15:03 - 01752992 ____A (Bleeping Computer, LLC) C:\Users\User\Desktop\rkill (1).exe
2013-05-07 15:07 - 2013-05-07 15:13 - 05067045 ____R (Swearware) C:\Users\User\Desktop\ComboFix.exe
2013-05-07 13:20 - 2013-05-07 13:20 - 00000000 ____D C:\Users\User\Desktop\mbar-1.05.0.1001
2013-05-07 12:25 - 2013-05-07 12:25 - 00003221 ____A C:\Users\User\Desktop\RKreport[2]_D_05072013_02d1225.txt
2013-05-07 12:22 - 2013-05-07 12:22 - 00003032 ____A C:\Users\User\Desktop\RKreport[1]_S_05072013_02d1222.txt
2013-05-07 12:19 - 2013-05-07 12:23 - 00000000 ____D C:\Users\User\Desktop\RK_Quarantine
2013-05-07 12:18 - 2013-05-07 12:17 - 00816128 ____A C:\Users\User\Desktop\RogueKiller.exe
2013-05-07 12:12 - 2013-05-07 12:10 - 12917756 ____A C:\Users\User\Desktop\mbar-1.05.0.1001.zip
2013-05-07 12:12 - 2013-05-07 12:10 - 00791040 ____A C:\Users\User\Desktop\RogueKillerX64.exe
2013-05-07 12:07 - 2013-05-07 17:10 - 00680001 ____A C:\Windows\System32\Drivers\sfi.dat
2013-05-07 11:24 - 2013-05-07 11:24 - 00008876 ____A C:\Users\User\Desktop\attach.txt
2013-05-07 11:24 - 2013-05-07 11:23 - 00008270 ____A C:\Users\User\Desktop\dds.txt
2013-05-07 11:20 - 2013-05-07 11:20 - 00001745 ____A C:\Users\Public\Desktop\COMODO Internet Security.lnk
2013-05-07 11:20 - 2013-05-07 11:20 - 00000551 ____A C:\Users\Public\Desktop\Shared Space.lnk
2013-05-07 11:19 - 2013-05-07 11:20 - 00000000 ___SD C:\ProgramData\Shared Space
2013-05-07 11:18 - 2013-05-07 12:08 - 00000000 ____D C:\ProgramData\Comodo
2013-05-07 11:18 - 2013-05-07 11:18 - 00000000 ____D C:\ProgramData\Comodo Downloader
2013-05-07 11:18 - 2013-05-07 11:18 - 00000000 ____D C:\Program Files\COMODO
2013-05-07 11:17 - 2013-05-07 11:18 - 00000000 ____D C:\ProgramData\MFAData
2013-05-07 11:17 - 2013-05-07 11:17 - 00000000 ____D C:\Users\User\AppData\Local\MFAData
2013-05-07 11:17 - 2013-05-07 11:17 - 00000000 ____D C:\Users\User\AppData\Local\Avg2013
2013-05-07 11:16 - 2013-05-07 16:21 - 00003214 ____A C:\Users\User\Desktop\Rkill.txt
2013-05-07 11:16 - 2013-05-07 11:16 - 00000293 ____A C:\Users\User\Desktop\iExplore.exe - Shortcut (2).lnk
2013-05-07 11:16 - 2013-05-07 11:14 - 04446832 ____A (AVG Technologies) C:\Users\User\Desktop\avg_isct_stb_all_2013_3272.exe
2013-05-07 11:16 - 2013-05-07 10:14 - 01752992 ____A (Bleeping Computer, LLC) C:\Users\User\Desktop\iExplore.exe
2013-05-07 11:11 - 2013-05-07 11:11 - 00000293 ____A C:\Users\User\Desktop\iExplore.exe - Shortcut.lnk
2013-05-07 11:11 - 2013-05-07 11:00 - 52278048 ____A (COMODO) C:\Users\User\Desktop\cispremium_installer_x86.exe
2013-05-07 11:11 - 2013-05-07 10:57 - 00688992 ____R (Swearware) C:\Users\User\Desktop\dds.com
2013-05-07 10:21 - 2013-05-07 10:23 - 00002816 ____A C:\Users\Mandy Hall\Desktop\Rkill.txt
2013-05-07 10:21 - 2013-05-07 10:14 - 01752992 ____A (Bleeping Computer, LLC) C:\Users\Mandy Hall\Desktop\iExplore.exe
2013-05-07 10:20 - 2013-05-07 10:20 - 00000400 ____A C:\Users\Mandy Hall\Desktop\iExplore.exe - Shortcut.lnk
2013-05-03 10:50 - 2013-05-03 10:57 - 00000000 ____D C:\ProgramData\18E6919474BD2AD4000018E678B43109
2013-04-25 11:05 - 2013-04-25 11:05 - 00084928 ____A (COMODO) C:\Windows\System32\Drivers\inspect.sys
2013-04-23 15:04 - 2013-04-23 15:04 - 00348048 ____A (COMODO) C:\Windows\System32\guard32.dll
2013-04-15 18:38 - 2013-04-15 18:38 - 00582960 ____A (COMODO) C:\Windows\System32\Drivers\cmdguard.sys
2013-04-15 18:38 - 2013-04-15 18:38 - 00276688 ____A (COMODO) C:\Windows\System32\cmdvrt32.dll
2013-04-15 18:38 - 2013-04-15 18:38 - 00043216 ____A (COMODO) C:\Windows\System32\Drivers\cmdhlp.sys
2013-04-15 18:38 - 2013-04-15 18:38 - 00040656 ____A (COMODO) C:\Windows\System32\cmdkbd32.dll
2013-04-15 18:38 - 2013-04-15 18:38 - 00035488 ____A (COMODO) C:\Windows\System32\cmdcsr.dll
2013-04-15 18:38 - 2013-04-15 18:38 - 00020072 ____A (COMODO) C:\Windows\System32\Drivers\cmderd.sys
2013-04-12 10:07 - 2013-04-12 10:07 - 00000510 ____A C:\Users\User\Downloads\stewart_CRIM.txt.dt7sh8w.partial
2013-04-11 03:07 - 2013-02-22 00:05 - 12324352 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-04-11 03:07 - 2013-02-21 23:47 - 09738752 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-04-11 03:07 - 2013-02-21 23:46 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-04-11 03:07 - 2013-02-21 23:38 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-04-11 03:07 - 2013-02-21 23:38 - 01104384 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-04-11 03:07 - 2013-02-21 23:37 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2013-04-11 03:07 - 2013-02-21 23:36 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2013-04-11 03:07 - 2013-02-21 23:35 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-04-11 03:07 - 2013-02-21 23:34 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-04-11 03:07 - 2013-02-21 23:34 - 00420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2013-04-11 03:07 - 2013-02-21 23:34 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2013-04-11 03:07 - 2013-02-21 23:33 - 00607744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-04-11 03:07 - 2013-02-21 23:32 - 01796096 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-04-11 03:07 - 2013-02-21 23:31 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-04-11 03:07 - 2013-02-21 23:31 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2013-04-11 03:07 - 2013-02-21 23:28 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-04-10 17:17 - 2013-03-11 09:25 - 03603816 ____A (Microsoft Corporation) C:\Windows\System32\ntkrnlpa.exe
2013-04-10 17:17 - 2013-03-11 09:25 - 03551080 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2013-04-10 17:17 - 2013-03-08 23:45 - 00049152 ____A (Microsoft Corporation) C:\Windows\System32\csrsrv.dll
2013-04-10 17:17 - 2013-03-08 21:28 - 00064000 ____A (Microsoft Corporation) C:\Windows\System32\smss.exe
2013-04-10 17:17 - 2013-03-07 23:53 - 00376320 ____A (Microsoft Corporation) C:\Windows\System32\winsrv.dll
2013-04-10 17:17 - 2013-03-07 23:52 - 02067968 ____A (Microsoft Corporation) C:\Windows\System32\mstscax.dll
2013-04-10 17:17 - 2013-03-04 21:40 - 02049024 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2013-04-10 17:17 - 2013-03-03 15:07 - 01082232 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ntfs.sys
==================== One Month Modified Files and Folders ========
2013-05-07 17:10 - 2013-05-07 12:07 - 00680001 ____A C:\Windows\System32\Drivers\sfi.dat
2013-05-07 17:09 - 2013-05-07 17:09 - 00000000 ____D C:\FRST
2013-05-07 17:08 - 2013-05-07 17:09 - 01313531 ____A (Farbar) C:\Users\User\Desktop\FRST.exe
2013-05-07 16:48 - 2008-04-28 12:34 - 01597361 ____A C:\Windows\WindowsUpdate.log
2013-05-07 16:46 - 2006-11-02 06:33 - 00773468 ____A C:\Windows\System32\PerfStringBackup.INI
2013-05-07 16:40 - 2012-08-29 13:13 - 00000890 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-05-07 16:40 - 2006-11-02 09:01 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-05-07 16:40 - 2006-11-02 08:47 - 00003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-05-07 16:40 - 2006-11-02 08:47 - 00003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-05-07 16:24 - 2013-05-07 16:24 - 00000000 ___SD C:\ComboFix
2013-05-07 16:24 - 2011-12-28 13:20 - 00000000 ____D C:\Qoobox
2013-05-07 16:21 - 2013-05-07 11:16 - 00003214 ____A C:\Users\User\Desktop\Rkill.txt
2013-05-07 16:04 - 2006-11-02 09:01 - 00032520 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2013-05-07 16:02 - 2013-05-07 16:02 - 00012981 ____A C:\ComboFix.txt
2013-05-07 15:58 - 2006-11-02 06:23 - 00000215 ____A C:\Windows\system.ini
2013-05-07 15:49 - 2010-03-09 12:23 - 00558372 ____A C:\Windows\PFRO.log
2013-05-07 15:48 - 2010-03-09 12:32 - 00000000 ____D C:\Windows\ERDNT
2013-05-07 15:33 - 2012-08-29 13:13 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-05-07 15:13 - 2013-05-07 15:07 - 05067045 ____R (Swearware) C:\Users\User\Desktop\ComboFix.exe
2013-05-07 15:12 - 2012-08-07 13:24 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-05-07 15:03 - 2013-05-07 15:08 - 01752992 ____A (Bleeping Computer, LLC) C:\Users\User\Desktop\rkill (1).exe
2013-05-07 13:20 - 2013-05-07 13:20 - 00000000 ____D C:\Users\User\Desktop\mbar-1.05.0.1001
2013-05-07 12:25 - 2013-05-07 12:25 - 00003221 ____A C:\Users\User\Desktop\RKreport[2]_D_05072013_02d1225.txt
2013-05-07 12:23 - 2013-05-07 12:19 - 00000000 ____D C:\Users\User\Desktop\RK_Quarantine
2013-05-07 12:22 - 2013-05-07 12:22 - 00003032 ____A C:\Users\User\Desktop\RKreport[1]_S_05072013_02d1222.txt
2013-05-07 12:17 - 2013-05-07 12:18 - 00816128 ____A C:\Users\User\Desktop\RogueKiller.exe
2013-05-07 12:11 - 2010-11-30 11:00 - 00057312 ____A C:\Windows\setupact.log
2013-05-07 12:10 - 2013-05-07 12:12 - 12917756 ____A C:\Users\User\Desktop\mbar-1.05.0.1001.zip
2013-05-07 12:10 - 2013-05-07 12:12 - 00791040 ____A C:\Users\User\Desktop\RogueKillerX64.exe
2013-05-07 12:08 - 2013-05-07 11:18 - 00000000 ____D C:\ProgramData\Comodo
2013-05-07 11:24 - 2013-05-07 11:24 - 00008876 ____A C:\Users\User\Desktop\attach.txt
2013-05-07 11:23 - 2013-05-07 11:24 - 00008270 ____A C:\Users\User\Desktop\dds.txt
2013-05-07 11:20 - 2013-05-07 11:20 - 00001745 ____A C:\Users\Public\Desktop\COMODO Internet Security.lnk
2013-05-07 11:20 - 2013-05-07 11:20 - 00000551 ____A C:\Users\Public\Desktop\Shared Space.lnk
2013-05-07 11:20 - 2013-05-07 11:19 - 00000000 ___SD C:\ProgramData\Shared Space
2013-05-07 11:18 - 2013-05-07 11:18 - 00000000 ____D C:\ProgramData\Comodo Downloader
2013-05-07 11:18 - 2013-05-07 11:18 - 00000000 ____D C:\Program Files\COMODO
2013-05-07 11:18 - 2013-05-07 11:17 - 00000000 ____D C:\ProgramData\MFAData
2013-05-07 11:17 - 2013-05-07 11:17 - 00000000 ____D C:\Users\User\AppData\Local\MFAData
2013-05-07 11:17 - 2013-05-07 11:17 - 00000000 ____D C:\Users\User\AppData\Local\Avg2013
2013-05-07 11:16 - 2013-05-07 11:16 - 00000293 ____A C:\Users\User\Desktop\iExplore.exe - Shortcut (2).lnk
2013-05-07 11:14 - 2013-05-07 11:16 - 04446832 ____A (AVG Technologies) C:\Users\User\Desktop\avg_isct_stb_all_2013_3272.exe
2013-05-07 11:11 - 2013-05-07 11:11 - 00000293 ____A C:\Users\User\Desktop\iExplore.exe - Shortcut.lnk
2013-05-07 11:00 - 2013-05-07 11:11 - 52278048 ____A (COMODO) C:\Users\User\Desktop\cispremium_installer_x86.exe
2013-05-07 10:57 - 2013-05-07 11:11 - 00688992 ____R (Swearware) C:\Users\User\Desktop\dds.com
2013-05-07 10:36 - 2006-11-02 07:18 - 00000000 ____D C:\Windows\registration
2013-05-07 10:23 - 2013-05-07 10:21 - 00002816 ____A C:\Users\Mandy Hall\Desktop\Rkill.txt
2013-05-07 10:20 - 2013-05-07 10:20 - 00000400 ____A C:\Users\Mandy Hall\Desktop\iExplore.exe - Shortcut.lnk
2013-05-07 10:14 - 2013-05-07 11:16 - 01752992 ____A (Bleeping Computer, LLC) C:\Users\User\Desktop\iExplore.exe
2013-05-07 10:14 - 2013-05-07 10:21 - 01752992 ____A (Bleeping Computer, LLC) C:\Users\Mandy Hall\Desktop\iExplore.exe
2013-05-03 13:13 - 2011-12-28 13:35 - 00000912 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-05-03 13:13 - 2010-03-09 12:06 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-05-03 13:05 - 2012-04-25 03:02 - 00000000 ____D C:\Windows\Temp101B0233-3EA1-BEB2-E16C-485559CC2463-Signatures
2013-05-03 10:57 - 2013-05-03 10:50 - 00000000 ____D C:\ProgramData\18E6919474BD2AD4000018E678B43109
2013-05-02 02:06 - 2009-10-05 09:14 - 00238872 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe
2013-05-01 12:22 - 2008-02-22 05:22 - 00000000 ____D C:\ProgramData\Adobe
2013-05-01 12:19 - 2012-08-07 13:24 - 00691592 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2013-05-01 12:19 - 2011-07-25 14:18 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2013-04-25 11:05 - 2013-04-25 11:05 - 00084928 ____A (COMODO) C:\Windows\System32\Drivers\inspect.sys
2013-04-23 15:04 - 2013-04-23 15:04 - 00348048 ____A (COMODO) C:\Windows\System32\guard32.dll
2013-04-22 17:49 - 2011-05-27 09:30 - 00000000 ____D C:\Users\User\AppData\Roaming\Yahoo!
2013-04-15 18:38 - 2013-04-15 18:38 - 00582960 ____A (COMODO) C:\Windows\System32\Drivers\cmdguard.sys
2013-04-15 18:38 - 2013-04-15 18:38 - 00276688 ____A (COMODO) C:\Windows\System32\cmdvrt32.dll
2013-04-15 18:38 - 2013-04-15 18:38 - 00043216 ____A (COMODO) C:\Windows\System32\Drivers\cmdhlp.sys
2013-04-15 18:38 - 2013-04-15 18:38 - 00040656 ____A (COMODO) C:\Windows\System32\cmdkbd32.dll
2013-04-15 18:38 - 2013-04-15 18:38 - 00035488 ____A (COMODO) C:\Windows\System32\cmdcsr.dll
2013-04-15 18:38 - 2013-04-15 18:38 - 00020072 ____A (COMODO) C:\Windows\System32\Drivers\cmderd.sys
2013-04-12 10:07 - 2013-04-12 10:07 - 00000510 ____A C:\Users\User\Downloads\stewart_CRIM.txt.dt7sh8w.partial
2013-04-11 03:29 - 2006-11-02 08:47 - 00399672 ____A C:\Windows\System32\FNTCACHE.DAT
2013-04-11 03:08 - 2008-04-28 13:20 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-04-11 03:02 - 2006-11-02 06:24 - 70490256 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe
2013-04-10 00:33 - 2012-08-29 13:13 - 00001933 ____A C:\Users\Public\Desktop\Google Chrome.lnk
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
Last Boot: 2013-05-07 16:49
==================== End Of Log ============================