Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

PC potentially infected [Closed]


  • This topic is locked This topic is locked

#1
Jommers

Jommers

    New Member

  • Member
  • Pip
  • 5 posts

I've recently been having random crashes in Chrome with the crash signature of "apphang b1". It generally happens when opening or closing tabs/entering URLs into new tabs. It still happens when all extensions are disabled, so I don't think it's that.

 

Here's the full log of the crash:

Spoiler

 

Here are my Farbar logs:

 

Spoiler
 
Spoiler
 
Any help would be greatly appreciated.

Edited by Jommers, 11 October 2015 - 08:47 AM.

  • 0

Advertisements


#2
Naathim

Naathim

    GeekU Minion

  • Expert
  • 4,568 posts

Minion%20Welcome.jpg


My name's Naathim and I'm a GeekU Minion! Now that we are mates and will be working together to clean your machine out of any junkware, feel free to call me Naat :)

I apologize for the delay, this section is kinda busy and sometimes we just miss a topic.

Before we start please note the following:

icon_arrow.gif Analysis and research take some time, also sometimes real life gets in the way, please be patient.
icon_arrow.gif Limit your internet access to posting here, some infections just wait to steal typed-in passwords.
icon_arrow.gif Don't run any scripts or tools on your own, unsupervised usage may cause more harm than good.
icon_arrow.gif Paste the logs in your posts (no spoilers please!), attachments make my work harder and more complicated.
icon_arrow.gif Stay with me to the end, the absence of symtoms doesn't mean that your machine is fully operational.
icon_arrow.gif Note that we may live in totally different time zones, what may cause some delays between answers.

icon_idea.gif I can't foresee everything, so if anything unexpected happens, please stop and inform me!
icon_idea.gif There are no silly questions. Never be afraid to ask if in doubt!

Let's start and enjoy the fight! :)



51a612a8b27e2-Zoek.png Scan with ZOEK

Please download ZOEK by Smeenk and save it to your desktop (preferred version is the *.exe one)
Temporary disable your AntiVirus and AntiSpyware protection - instructions here.
  • Right-click on 51a612a8b27e2-Zoek.png icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
  • Wait patiently until the main console will appear, it may take a minute or two.
  • In the main box please paste in the following script:
    createsrpoint;
    process;
    drivers-services-list;
    systemspecs;
    startupall;
    skipfix-iedefaults;
    firefoxlook;
    chromelook;
    filesrcm;
    installedprogs;
  • Make sure that Scan All Users option is checked.
  • Push Run Script and wait patiently. The scan may take a couple of minutes.
  • When the scan completes, a zoek-results logfile should open in notepad.
  • If a reboot is needed, it will be opened after it. You may also find it at your main drive (usually C:\ drive)
Please include its content in your next reply.
Don't forget to re-enable your switched-off protection software!
  • 0

#3
Jommers

Jommers

    New Member

  • Topic Starter
  • Member
  • Pip
  • 5 posts

Hi Naat, thanks very much for replying.

 

Here's the ZOEK log:

 

 

Zoek.exe v5.0.0.1 Updated 17-October-2015
Tool run by Alasdair on 17/10/2015 at 15:31:03.75.
Microsoft Windows 7 Ultimate  6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Alasdair\Downloads\zoek.exe    [Scan all users] [Script inserted] 
 
==== System Restore Info ======================
 
17/10/2015 15:32:42 Zoek.exe System Restore Point Created Successfully.
 
==== Installed Programs ======================
 
64 Bit HP CIO Components Installer  
Adobe Flash Player 19 ActiveX  
Adobe Flash Player 19 NPAPI  
Adobe Reader XI (11.0.13)  
Adobe Refresh Manager  
Adobe Shockwave Player 12.1  
AIO_CDB_ProductContext  
AIO_CDB_Software  
AIO_Scan  
Apple Application Support (32-bit)  
Apple Application Support (64-bit)  
Apple Mobile Device Support  
Apple Software Update  
Assassin's Creed IV Black Flag  
Assassin's Creed® III v1.06  
ASUS GPU Tweak  
Banished  
Bastion  
Batman: Arkham Asylum GOTY Edition  
Batman: Arkham City GOTY  
Battle.net  
BBC iPlayer Downloads  
BitRaider Web Client  
Blitzkrieg Mod  
Blitzkrieg Mod version 4.8.2.0  
Bonjour  
Borderlands 2  
BufferChm  
Cities in Motion  
ClipSync Server  
Company of Heroes 2  
Copy  
Core Temp 1.0 RC5  
Counter-Strike: Source  
Crusader Kings II  
CutePDF Writer 3.0  
DAEMON Tools Lite  
Day of Defeat  
Day of Defeat: Source  
Definition Update for Microsoft Office 2013 (KB3085580) 64-Bit Edition  
Deus Ex: Human Revolution - Director's Cut  
DeviceDiscovery  
Diablo III  
Dishonored  
DocProc  
Dokan Library 0.6.0  
Don't Starve  
Dual-Core Optimizer  
Dungeon Keeper Gold  
Europa Universalis IV  
F300  
F300_Help  
F300Trb  
Far Cry© 3  
Fax  
FTL: Faster Than Light  
GIGABYTE FORCE Driver  
GIMP 2.8.6  
Google Chrome  
Google Update Helper  
GPBaseService2  
Hammerwatch  
Hearthstone  
Heroes of the Storm  
Hotline Miami  
HP Customer Participation Program 13.0  
HP Imaging Device Functions 13.0  
HP Photosmart Essential 3.5  
HP Photosmart Officejet and Deskjet All-In-One Driver Software 13.0 Rel. B  
HP Smart Web Printing 4.51  
HP Solution Center 13.0  
HP Update  
HPDiagnosticAlert  
HPPhotoGadget  
HPPhotoSmartDiscLabelContent1  
HPPhotosmartEssential  
HPProductAssistant  
HPSSupply  
Java 8 Update 31  
Java Auto Updater  
Katawa Shoujo  
KMSpico v9.0.5.20131112  
LUFTRAUSERS  
Mafia II  
Malwarebytes Anti-Malware version 2.1.8.1057  
MarketResearch  
McAfee Security Scan Plus  
Men of War (Remove Only)  
Metro 2033  
Microsoft .NET Framework 4.5.2  
Microsoft Access MUI (English) 2013  
Microsoft Access Setup Metadata MUI (English) 2013  
Microsoft ASP.NET MVC 4 Runtime  
Microsoft DCF MUI (English) 2013  
Microsoft Excel MUI (English) 2013  
Microsoft Groove MUI (English) 2013  
Microsoft InfoPath MUI (English) 2013  
Microsoft Lync MUI (English) 2013  
Microsoft Office 32-bit Components 2013  
Microsoft Office OSM MUI (English) 2013  
Microsoft Office OSM UX MUI (English) 2013  
Microsoft Office Professional Plus 2013  
Microsoft Office Proofing (English) 2013  
Microsoft Office Proofing Tools 2013 - English  
Microsoft Office Proofing Tools 2013 - Espa¤ol  
Microsoft Office Shared 32-bit MUI (English) 2013  
Microsoft Office Shared MUI (English) 2013  
Microsoft Office Shared Setup Metadata MUI (English) 2013  
Microsoft OneNote MUI (English) 2013  
Microsoft Outlook MUI (English) 2013  
Microsoft PowerPoint MUI (English) 2013  
Microsoft Publisher MUI (English) 2013  
Microsoft Security Client  
Microsoft Security Essentials  
Microsoft Silverlight  
Microsoft Visual C++ 2005 Redistributable  
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022  
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17  
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161  
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022  
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17  
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161  
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219  
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219  
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030  
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030  
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030  
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030  
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030  
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030  
Microsoft Visual Studio 2010 Tools for Office Runtime (x64)  
Microsoft Word MUI (English) 2013  
Microsoft XNA Framework Redistributable 3.1  
Microsoft XNA Framework Redistributable 4.0 Refresh  
Middle-earth: Shadow of Mordor  
Monaco  
Mount & Blade: Warband  
Mount & Blade: With Fire and Sword  
MSXML 4.0 SP2 (KB954430)  
MSXML 4.0 SP2 (KB973688)  
Napoleon: Total War  
Network64  
NVIDIA 3D Vision Controller Driver 352.65  
NVIDIA 3D Vision Driver 353.06  
NVIDIA Control Panel 353.06  
NVIDIA GeForce Experience 2.4.5.44  
NVIDIA GeForce Experience Service  
NVIDIA Graphics Driver 353.06  
NVIDIA HD Audio Driver 1.3.34.3  
NVIDIA Install Application  
NVIDIA LED Visualizer 1.0  
NVIDIA Network Service  
NVIDIA PhysX System Software 9.15.0428  
NVIDIA ShadowPlay 2.4.5.44  
NVIDIA Stereoscopic 3D Driver  
NVIDIA Update 2.4.5.44  
NVIDIA Update Core  
NVIDIA Virtual Audio 1.2.28  
OCR Software by I.R.I.S. 13.0  
OpenAL  
Outils de v‚rification linguistique 2013 de Microsoft Officeÿ- Fran‡ais  
Papers, Please  
Parche Europe At War v6.1.8  
Path of Exile  
Pillars of Eternity  
Prison Architect  
Rapport  
Realtek Ethernet Controller Driver  
Rock of Ages  
Rogue Legacy  
Security Update for Microsoft Excel 2013 (KB3085583) 64-Bit Edition  
Security Update for Microsoft Office 2013 (KB2910941) 64-Bit Edition  
Security Update for Microsoft Office 2013 (KB3039734) 64-Bit Edition  
Security Update for Microsoft Office 2013 (KB3039798) 64-Bit Edition  
Security Update for Microsoft Office 2013 (KB3054816) 64-Bit Edition  
Security Update for Microsoft Office 2013 (KB3054932) 64-Bit Edition  
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition  
SHIELD Streaming  
SHIELD Wireless Controller Driver  
Shop for HP Supplies  
Sid Meier's Civilization V  
Sid Meier's Pirates  
SimCity 4 Deluxe  
Skype Click to Call  
SkypeT 7.11  
SmartWebPrinting  
SolutionCenter  
Spec Ops: The Line  
Spotify  
Star Wars The Old Republic  
Star Wars: The Old Republic  
StarCraft II  
Status  
Steam  
SteamWorld Dig  
Super Hexagon  
Super Meat Boy  
swMSM  
System Requirements Lab CYRI  
System Requirements Lab Detection  
Tarsia 3.9  
Teachers Report Assistant  
TeamSpeak 3 Client  
The Binding of Isaac  
The Binding of Isaac: Rebirth  
The Bureau: XCOM Declassified  
The Elder Scrolls V: Skyrim  
The Lord of the Rings: War in the North  
The Witcher 2: Assassins of Kings Enhanced Edition  
The Witcher 3: Wild Hunt  
Theme Hospital  
TL-WN721N/TL-WN722N Driver  
Tom Clancy's Splinter Cell© BlacklistT  
Toolbox  
Total War: SHOGUN 2  
TP-LINK Wireless Configuration Utility  
TrayApp  
Tropico 4  
Trusteer Endpoint Protection  
Unicode Phonetic Keyboard (UCL) - 1.10  
Unicode Phonetic Keyboard 1.10 and SIL Fonts  
Unity Web Player  
UnloadSupport  
Update for Microsoft Access 2013 (KB3085503) 64-Bit Edition  
Update for Microsoft Office 2013 (KB2760344) 64-Bit Edition  
Update for Microsoft Office 2013 (KB2760371) 64-Bit Edition  
Update for Microsoft Office 2013 (KB2760544) 64-Bit Edition  
Update for Microsoft Office 2013 (KB2880487) 64-Bit Edition  
Update for Microsoft Office 2013 (KB2881076) 64-Bit Edition  
Update for Microsoft Office 2013 (KB2883095) 64-Bit Edition  
Update for Microsoft Office 2013 (KB2889863) 64-Bit Edition  
Update for Microsoft Office 2013 (KB2899522) 64-Bit Edition  
Update for Microsoft Office 2013 (KB2975869) 64-Bit Edition  
Update for Microsoft Office 2013 (KB3023052) 64-Bit Edition  
Update for Microsoft Office 2013 (KB3039701) 64-Bit Edition  
Update for Microsoft Office 2013 (KB3039718) 64-Bit Edition  
Update for Microsoft Office 2013 (KB3039720) 64-Bit Edition  
Update for Microsoft Office 2013 (KB3039739) 64-Bit Edition  
Update for Microsoft Office 2013 (KB3039762) 64-Bit Edition  
Update for Microsoft Office 2013 (KB3039766) 64-Bit Edition  
Update for Microsoft Office 2013 (KB3039778) 64-Bit Edition  
Update for Microsoft Office 2013 (KB3039787) 64-Bit Edition  
Update for Microsoft Office 2013 (KB3039800) 64-Bit Edition  
Update for Microsoft Office 2013 (KB3054783) 64-Bit Edition  
Update for Microsoft Office 2013 (KB3054785) 64-Bit Edition  
Update for Microsoft Office 2013 (KB3054805) 64-Bit Edition  
Update for Microsoft Office 2013 (KB3054856) 64-Bit Edition  
Update for Microsoft Office 2013 (KB3054935) 64-Bit Edition  
Update for Microsoft Office 2013 (KB3054941) 64-Bit Edition  
Update for Microsoft Office 2013 (KB3055011) 64-Bit Edition  
Update for Microsoft Office 2013 (KB3085479) 64-Bit Edition  
Update for Microsoft Office 2013 (KB3085493) 64-Bit Edition  
Update for Microsoft Office 2013 (KB3085506) 64-Bit Edition  
Update for Microsoft Office 2013 (KB3085563) 64-Bit Edition  
Update for Microsoft Office 2013 (KB3085566) 64-Bit Edition  
Update for Microsoft Office 2013 (KB3085576) 64-Bit Edition  
Update for Microsoft Office 2013 (KB3085585) 64-Bit Edition  
Update for Microsoft OneDrive for Business (KB3085509) 64-Bit Edition  
Update for Microsoft OneNote 2013 (KB3085574) 64-Bit Edition  
Update for Microsoft Outlook 2013 (KB3085579) 64-Bit Edition  
Update for Microsoft Outlook Social Connector 2013 (KB3054854) 64-Bit Edition  
Update for Microsoft PowerPoint 2013 (KB3085564) 64-Bit Edition  
Update for Microsoft Project 2013 (KB3085590) 64-Bit Edition  
Update for Microsoft Publisher 2013 (KB3023050) 64-Bit Edition  
Update for Microsoft Visio Viewer 2013 (KB2817301) 64-Bit Edition  
Update for Microsoft Word 2013 (KB2878319) 64-Bit Edition  
Update for Microsoft Word 2013 (KB3085573) 64-Bit Edition  
Update for Skype for Business 2015 (KB2889853) 64-Bit Edition  
Update for Skype for Business 2015 (KB3085581) 64-Bit Edition  
Uplay  
Valiant Hearts: The Great WarT / Soldats Inconnus : M‚moires de la Grande GuerreT  
Volgarr the Viking  
War Thunder  
WebReg  
WinRAR 5.00 (64-bit)  
World of Goo  
World of Tanks  
World of Warships  
XCOM: Enemy Unknown  
 
==== Running Processes ======================
 
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\SysWOW64\ASGT.exe
C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe
C:\Windows\SysWOW64\svchost.exe
C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Program Files (x86)\ASUS\GPU Tweak\GPUTweak.exe
C:\Program Files (x86)\Google\Update\1.3.28.15\GoogleCrashHandler.exe
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe
C:\Program Files (x86)\ASUS\GPU Tweak\Monitor.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Users\Alasdair\AppData\Roaming\Spotify\SpotifyWebHelper.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\GIGABYTE FORCE\GIGABYTE FORCE.exe
C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
C:\Program Files (x86)\Common Files\Steam\SteamService.exe
C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
C:\Users\Alasdair\Downloads\zoek.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\SysWOW64\cmd.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\cmd.exe
 
==== Services(whitelist) ======================
Powered by E Dev
 
R2 - [AdobeARMservice] - Adobe Acrobat Update Service - c:\program files (x86)\common files\adobe\arm\1.0\armsvc.exe
R2 - [Apple Mobile Device Service] - Apple Mobile Device Service - c:\program files\common files\apple\mobile device support\applemobiledeviceservice.exe
R2 - [Bonjour Service] - Bonjour Service - c:\program files\bonjour\mdnsresponder.exe
R2 - [c2cautoupdatesvc] - Skype Click to Call Updater - c:\program files (x86)\skype\toolbars\autoupdate\skypec2cautoupdatesvc.exe
R2 - [c2cpnrsvc] - Skype Click to Call PNR Service - c:\program files (x86)\skype\toolbars\pnrsvc\skypec2cpnrsvc.exe
R2 - [DokanMounter] - DokanMounter - c:\program files (x86)\dokan\dokanlibrary\mounter.exe
R2 - [GfExperienceService] - NVIDIA GeForce Experience Service - c:\program files\nvidia corporation\geforce experience service\gfexperienceservice.exe
R2 - [MsMpSvc] - Microsoft Antimalware Service - c:\program files\microsoft security client\msmpeng.exe
R2 - [NvNetworkService] - NVIDIA Network Service - c:\program files (x86)\nvidia corporation\netservice\nvnetworkservice.exe
R2 - [NvStreamSvc] - NVIDIA Streamer Service - c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe
R2 - [nvsvc] - NVIDIA Display Driver Service - c:\windows\system32\nvvsvc.exe
R2 - [PnkBstrA] - PnkBstrA - c:\windows\system32\pnkbstra.exe [x]
R2 - [RapportMgmtService] - Rapport Management Service - c:\program files (x86)\trusteer\rapport\bin\rapportmgmtservice.exe
R2 - [Stereo Service] - NVIDIA Stereoscopic 3D Driver Service - c:\program files (x86)\nvidia corporation\3d vision\nvscpapisvr.exe
R2 - [WMPNetworkSvc] - Windows Media Player Network Sharing Service - c:\program files\windows media player\wmpnetwk.exe
R2 - [WSearch] - Windows Search - c:\windows\system32\searchindexer.exe
R3 - [Steam Client Service] - Steam Client Service - c:\program files (x86)\common files\steam\steamservice.exe
R3 - [TrustedInstaller] - Windows Modules Installer - c:\windows\servicing\trustedinstaller.exe
R3 - [VSS] - Volume Shadow Copy - c:\windows\system32\vssvc.exe
S2 - [clr_optimization_v4.0.30319_32] - Microsoft .NET Framework NGEN v4.0.30319_X86 - c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe
S2 - [clr_optimization_v4.0.30319_64] - Microsoft .NET Framework NGEN v4.0.30319_X64 - c:\windows\microsoft.net\framework64\v4.0.30319\mscorsvw.exe
S2 - [gupdate] - Google Update Service (gupdate) - c:\program files (x86)\google\update\googleupdate.exe
S2 - [MBAMService] - MBAMService - c:\program files (x86)\malwarebytes anti-malware\mbamservice.exe
S2 - [SkypeUpdate] - Skype Updater - c:\program files (x86)\skype\updater\updater.exe
S2 - [sppsvc] - Software Protection - c:\windows\system32\sppsvc.exe
S3 - [AdobeFlashPlayerUpdateSvc] - Adobe Flash Player Update Service - c:\windows\syswow64\macromed\flash\flashplayerupdateservice.exe
S3 - [ALG] - Application Layer Gateway Service - c:\windows\system32\alg.exe
S3 - [aspnet_state] - ASP.NET State Service - c:\windows\microsoft.net\framework64\v4.0.30319\aspnet_state.exe
S3 - [clr_optimization_v2.0.50727_32] - Microsoft .NET Framework NGEN v2.0.50727_X86 - c:\windows\microsoft.net\framework\v2.0.50727\mscorsvw.exe
S3 - [clr_optimization_v2.0.50727_64] - Microsoft .NET Framework NGEN v2.0.50727_X64 - c:\windows\microsoft.net\framework64\v2.0.50727\mscorsvw.exe
S3 - [COMSysApp] - COM+ System Application - c:\windows\system32\dllhost.exe
S3 - [ehRecvr] - Windows Media Center Receiver Service - c:\windows\ehome\ehrecvr.exe
S3 - [ehSched] - Windows Media Center Scheduler Service - c:\windows\ehome\ehsched.exe
S3 - [Fax] - Fax - c:\windows\system32\fxssvc.exe
S3 - [FontCache3.0.0.0] - Windows Presentation Foundation Font Cache 3.0.0.0 - c:\windows\microsoft.net\framework64\v3.0\wpf\presentationfontcache.exe
S3 - [gupdatem] - Google Update Service (gupdatem) - c:\program files (x86)\google\update\googleupdate.exe
S3 - [ICCS] - Intel® Integrated Clock Controller Service - Intel® ICCS - c:\program files (x86)\intel\intel® integrated clock controller service\iccproxy.exe
S3 - [MSDTC] - Distributed Transaction Coordinator - c:\windows\system32\msdtc.exe
S3 - [msiserver] - Windows Installer - c:\windows\system32\msiexec.exe
S3 - [NisSrv] - Microsoft Network Inspection - c:\program files\microsoft security client\nissrv.exe
S3 - [ose64] - Office 64 Source Engine - c:\program files\common files\microsoft shared\source engine\ose.exe
S3 - [osppsvc] - Office Software Protection Platform - c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\osppsvc.exe
S3 - [PerfHost] - Performance Counter DLL Host - c:\windows\syswow64\perfhost.exe
S3 - [RpcLocator] - Remote Procedure Call (RPC) Locator - c:\windows\system32\locator.exe
S3 - [SNMPTRAP] - SNMP Trap - c:\windows\system32\snmptrap.exe
S3 - [vds] - Virtual Disk - c:\windows\system32\vds.exe
S3 - [wbengine] - Block Level Backup Engine Service - c:\windows\system32\wbengine.exe
S3 - [wmiApSrv] - WMI Performance Adapter - c:\windows\system32\wbem\wmiapsrv.exe
S4 - [IEEtwCollectorService] - Internet Explorer ETW Collector Service - c:\windows\system32\ieetwcollector.exe
S4 - [McComponentHostService] - McAfee Security Scan Component Host Service - c:\program files\mcafee security scan\3.8.150\mcchsvc.exe
 
==== Drivers(whitelist) ======================
Powered by E Dev
 
R0 - [FileInfo] - File Information FS MiniFilter - C:\Windows\system32\Drivers\FileInfo.sys
R0 - [FltMgr] - FltMgr - C:\Windows\system32\Drivers\FltMgr.sys
R0 - [MpFilter] - Microsoft Malware Protection Driver - C:\Windows\system32\Drivers\MpFilter.sys
R0 - [Mup] - Mup - C:\Windows\system32\Drivers\Mup.sys
R1 - [NetBIOS] - NetBIOS Interface - C:\Windows\system32\Drivers\NetBIOS.sys
R3 - [srv] - Server SMB 1.xxx Driver - C:\Windows\system32\Drivers\srv.sys
R3 - [srv2] - Server SMB 2.xxx Driver - C:\Windows\system32\Drivers\srv2.sys
R0 - [ACPI] - Microsoft ACPI Driver - C:\Windows\system32\Drivers\ACPI.sys
R0 - [amdxata] - amdxata - C:\Windows\system32\Drivers\amdxata.sys
R0 - [atapi] - IDE Channel - C:\Windows\system32\Drivers\atapi.sys
R0 - [CLFS] - Common Log (CLFS) - C:\Windows\system32\Drivers\CLFS.sys [x]
R0 - [CNG] - CNG - C:\Windows\system32\Drivers\CNG.sys
R0 - [Disk] - Disk Driver - C:\Windows\system32\Drivers\Disk.sys
R0 - [fvevol] - Bitlocker Drive Encryption Filter Driver - C:\Windows\system32\Drivers\fvevol.sys
R0 - [hwpolicy] - Hardware Policy Driver - C:\Windows\system32\Drivers\hwpolicy.sys
R0 - [KSecDD] - KSecDD - C:\Windows\system32\Drivers\KSecDD.sys
R0 - [KSecPkg] - KSecPkg - C:\Windows\system32\Drivers\KSecPkg.sys
R0 - [mountmgr] - Mount Point Manager - C:\Windows\system32\Drivers\mountmgr.sys
R0 - [msahci] - msahci - C:\Windows\system32\Drivers\msahci.sys
R0 - [msisadrv] - msisadrv - C:\Windows\system32\Drivers\msisadrv.sys
R0 - [NDIS] - NDIS System Driver - C:\Windows\system32\Drivers\NDIS.sys
R0 - [partmgr] - Partition Manager - C:\Windows\system32\Drivers\partmgr.sys
R0 - [pci] - PCI Bus Driver - C:\Windows\system32\Drivers\pci.sys
R0 - [pcw] - Performance Counters for Windows Driver - C:\Windows\system32\Drivers\pcw.sys
R0 - [RapportHades64] - RapportHades64 - C:\Windows\system32\Drivers\RapportHades64.sys
R0 - [RapportKE64] - RapportKE64 - C:\Windows\system32\Drivers\RapportKE64.sys
R0 - [rdyboost] - ReadyBoost - C:\Windows\system32\Drivers\rdyboost.sys
R0 - [spldr] - Security Processor Loader Driver - C:\Windows\system32\Drivers\spldr.sys
R0 - [storflt] - Disk Virtual Machine Bus Acceleration Filter Driver - C:\Windows\system32\Drivers\storflt.sys [x]
R0 - [Tcpip] - TCP/IP Protocol Driver - C:\Windows\system32\Drivers\Tcpip.sys
R0 - [vdrvroot] - Microsoft Virtual Drive Enumerator Driver - C:\Windows\system32\Drivers\vdrvroot.sys
R0 - [vmbus] - Virtual Machine Bus - C:\Windows\system32\Drivers\vmbus.sys
R0 - [volmgr] - Volume Manager Driver - C:\Windows\system32\Drivers\volmgr.sys
R0 - [volmgrx] - Dynamic Volume Manager - C:\Windows\system32\Drivers\volmgrx.sys
R0 - [volsnap] - Storage volumes - C:\Windows\system32\Drivers\volsnap.sys
R0 - [Wdf01000] - Kernel Mode Driver Frameworks service - C:\Windows\system32\Drivers\Wdf01000.sys
R1 - [AFD] - Ancillary Function Driver for Winsock - C:\Windows\system32\Drivers\AFD.sys
R1 - [Beep] - Beep - C:\Windows\system32\Drivers\Beep.sys
R1 - [tdx] - NetIO Legacy TDI Support Driver - C:\Windows\system32\Drivers\tdx.sys
R2 - [tcpipreg] - TCP/IP Registry Compatibility - C:\Windows\system32\Drivers\tcpipreg.sys
 
==== System Specs ======================
 
Windows: Windows 7 Ultimate Edition (64-bit) Service Pack 1 (Build 7601)
Memory (RAM): 8121 MB
CPU Info: Intel® Core™ i5-4430 CPU @ 3.00GHz
CPU Speed: 3002.8 MHz
Sound Card: Speakers (High Definition Audio | 
Display Adapters: NVIDIA GeForce GTX 660 Ti | NVIDIA GeForce GTX 660 Ti | NVIDIA GeForce GTX 660 Ti | NVIDIA GeForce GTX 660 Ti | RDPDD Chained DD | RDP Encoder Mirror Driver | RDP Reflector Display Driver
Monitors: 1x; BenQ G2250 (Analog) | 
Screen Resolution: 1920 X 1080 - 32 bit
Network: Network Present
Network Adapters: Microsoft Virtual WiFi Miniport Adapter | Atheros AR9271 Wireless Network Adapter | Realtek PCIe GBE Family Controller
CD / DVD Drives: 2x (D: | E: | ) D: ATAPI   iHAS124   W      | E: DTSOFT  BDROM
Ports: COM1 LPT Port NOT Present. 
Mouse: 8 Button Wheel Mouse Present
Hard Disks: C:  931.4GB
Hard Disks - Free: C:  196.0GB
Manufacturer *: American Megatrends Inc.
BIOS Info: AT/AT COMPATIBLE | 06/07/13 | DELL   - 1072009
Time Zone: GMT Standard Time
Motherboard *: MSI H87M-E33 (MS-7817)
Country: United Kingdom 
Language: ENG 
 
==== System Specs (Software) ======================
 
AV: Microsoft Security Essentials *Disabled/Updated* {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
SP: Microsoft Security Essentials *Disabled/Updated* {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
Internet Explorer Version: 11.0.9600.18059 
Google Chrome version: 46.0.2490.71
Adobe Reader version: 11.0.13.17
Sun Java version: 1.8.0_31 (32-bit) 
Sun Java version: 1.8.0_31 (64-bit) 
Flash Player version: 19.0.0.207
Shockwave Player version: 12.1.1r151
 
==== Files Recently Created / Modified ======================
 
====== C:\Windows ====
====== C:\Users\Alasdair\AppData\Local\Temp ====
====== Java Cache =====
====== C:\Windows\SysWOW64 =====
2015-10-15 17:55:20 C19537A50B723E0F7B53D413163B35EE 3936192 ----a-w- C:\Windows\SysWOW64\ntoskrnl.exe
2015-10-15 17:55:19 63FD03CED9739062E9B94F0D1E54A406 3990976 ----a-w- C:\Windows\SysWOW64\ntkrnlpa.exe
2015-10-15 17:55:18 9E83A4F6E776F7A3E5F7FB90180FBC0B 1114112 ----a-w- C:\Windows\SysWOW64\kernel32.dll
2015-10-15 17:55:16 CA504606753BD62FA3128D3056320264 552960 ----a-w- C:\Windows\SysWOW64\kerberos.dll
2015-10-15 17:55:16 22BF275468F714A4F7E6F36449D1DCE2 259584 ----a-w- C:\Windows\SysWOW64\msv1_0.dll
2015-10-15 17:55:16 0834E70A068360D85CDC47697A4B7898 248832 ----a-w- C:\Windows\SysWOW64\schannel.dll
2015-10-15 17:55:15 C7293C9340BDC8291F6718913F3F7B14 221184 ----a-w- C:\Windows\SysWOW64\ncrypt.dll
2015-10-15 17:55:15 4EB6A0445891D56D56BB4580B3906BEA 1311768 ----a-w- C:\Windows\SysWOW64\ntdll.dll
2015-10-15 17:55:14 6D16D1B9DB2526B985BBB9B27A56B70B 172032 ----a-w- C:\Windows\SysWOW64\wdigest.dll
2015-10-15 17:55:14 3FA49981A847AE62259E6AEB585C84B8 65536 ----a-w- C:\Windows\SysWOW64\TSpkg.dll
2015-10-15 17:55:13 5FC0F48FD38D0AC7FC54EBEFBC3F69C5 25600 ----a-w- C:\Windows\SysWOW64\setup16.exe
2015-10-15 17:55:12 C00E4CD3AC3A0D8E339635E06546B77D 50176 ----a-w- C:\Windows\SysWOW64\auditpol.exe
2015-10-15 17:55:11 8A4ED460B6557EDCA637236073794DFF 43008 ----a-w- C:\Windows\SysWOW64\srclient.dll
2015-10-15 17:55:11 15192FC6BFCB37AE43A645A9C84AEF2F 36864 ----a-w- C:\Windows\SysWOW64\cryptbase.dll
2015-10-15 17:55:10 D8269205300BB593C3698BB77178E8D3 17408 ----a-w- C:\Windows\SysWOW64\credssp.dll
2015-10-15 17:55:10 1ADCC4F94981430FE968EE992353C535 14336 ----a-w- C:\Windows\SysWOW64\ntvdm64.dll
2015-10-15 17:55:07 2464CEAC16185B73774662AC625F695D 22016 ----a-w- C:\Windows\SysWOW64\secur32.dll
2015-10-15 17:55:07 2421C989BF8485B6A9EBBAC35ACADF1D 665088 ----a-w- C:\Windows\SysWOW64\rpcrt4.dll
2015-10-15 17:55:06 D9F5F78F8EA5749CA651B71335A96421 5120 ----a-w- C:\Windows\SysWOW64\wow32.dll
2015-10-15 17:55:06 C142CBB756205146B88DDB66D00BFE66 274944 ----a-w- C:\Windows\SysWOW64\KernelBase.dll
2015-10-15 17:55:06 6848FA8B421A0CEC8990AFE7A615574F 96768 ----a-w- C:\Windows\SysWOW64\sspicli.dll
2015-10-15 17:55:04 B421B311420FD650BE3B25EAC217E685 7680 ----a-w- C:\Windows\SysWOW64\instnm.exe
2015-10-15 17:55:04 1BE5DF925C30D9D1FAD1212FB215E469 6656 ----a-w- C:\Windows\SysWOW64\apisetschema.dll
2015-10-15 17:55:01 09BA6677E9CCBB1884CD0FB24F6EF584 2048 ----a-w- C:\Windows\SysWOW64\user.exe
2015-10-15 17:55:00 FE7B23203C757148CBCCA0A39EAD3C59 60416 ----a-w- C:\Windows\SysWOW64\msobjs.dll
2015-10-15 17:55:00 D414A645F6853BB2C8A24B85C1C86581 686080 ----a-w- C:\Windows\SysWOW64\adtschema.dll
2015-10-15 17:55:00 64B92847AA0945992BB49B62D9B0440E 146432 ----a-w- C:\Windows\SysWOW64\msaudite.dll
2015-10-15 17:45:44 F811B932E3DBA308014F8C870F752F16 12875776 ----a-w- C:\Windows\SysWOW64\shell32.dll
2015-10-15 17:45:42 5CB2886338C82E388F68557E2745200F 1498624 ----a-w- C:\Windows\SysWOW64\ExplorerFrame.dll
2015-10-15 17:45:22 908BBA41A5B57DDB126B85EC14DD58EF 76288 ----a-w- C:\Windows\SysWOW64\mshtmled.dll
2015-10-15 17:45:22 0E036A353DB9D8F4F642AC0F9412F09E 47616 ----a-w- C:\Windows\SysWOW64\ieetwproxystub.dll
2015-10-15 17:45:22 04BB7AF8E0DAE83982155F0752308666 64000 ----a-w- C:\Windows\SysWOW64\MshtmlDac.dll
2015-10-15 17:45:21 D586CB95B4EADC0525E8929A241898F5 20357632 ----a-w- C:\Windows\SysWOW64\mshtml.dll
2015-10-15 17:45:21 C89372B642726F1CF3EB479397976DA3 279040 ----a-w- C:\Windows\SysWOW64\dxtrans.dll
2015-10-15 17:45:21 C848E013BB85C48C787001E1EA36905F 60416 ----a-w- C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-10-15 17:45:21 A7028D5D5E3DCF820B3C0AFE0137A87E 130048 ----a-w- C:\Windows\SysWOW64\occache.dll
2015-10-15 17:45:21 9F36964CDB9A920779314395E3911503 504832 ----a-w- C:\Windows\SysWOW64\vbscript.dll
2015-10-15 17:45:21 098F6097F919EE77EA490E16D11E427A 1311232 ----a-w- C:\Windows\SysWOW64\urlmon.dll
2015-10-15 17:45:21 060409834CC8FAC3F1231DA3F0648CC5 689152 ----a-w- C:\Windows\SysWOW64\msfeeds.dll
2015-10-15 17:45:21 00FBEDF0E74AD8815469A95271C0E562 345688 ----a-w- C:\Windows\SysWOW64\iedkcs32.dll
2015-10-15 17:45:20 B87A11C95703AB19ACB43993DDA0F1A3 62464 ----a-w- C:\Windows\SysWOW64\iesetup.dll
2015-10-15 17:45:20 7E8EABA6A2B10FE11E2381378A57322B 2724864 ----a-w- C:\Windows\SysWOW64\mshtml.tlb
2015-10-15 17:45:20 12DCE9300FF5B74DC2F7DBAC96B0614E 710144 ----a-w- C:\Windows\SysWOW64\ieapfltr.dll
2015-10-15 17:45:19 F274AF14C7DB6C52C023BCBDA4197D17 47104 ----a-w- C:\Windows\SysWOW64\jsproxy.dll
2015-10-15 17:45:19 9F4234838400CC3A964AF53DE4410A50 2279936 ----a-w- C:\Windows\SysWOW64\iertutil.dll
2015-10-15 17:45:19 8C9BCE16E894D4FBCE151F4A5FE05F55 30720 ----a-w- C:\Windows\SysWOW64\iernonce.dll
2015-10-15 17:45:19 816B489E2BBFE2479C844AAD486ABB42 2052608 ----a-w- C:\Windows\SysWOW64\inetcpl.cpl
2015-10-15 17:45:19 73189A2739491ABB556872737C501F8E 663552 ----a-w- C:\Windows\SysWOW64\jscript.dll
2015-10-15 17:45:19 584E6632F1F4027AB64DEB0F4139E7D7 620032 ----a-w- C:\Windows\SysWOW64\jscript9diag.dll
2015-10-15 17:45:18 BE1263EE0CB8CF942FC35CC86E0C3941 12853760 ----a-w- C:\Windows\SysWOW64\ieframe.dll
2015-10-15 17:45:18 AFC4F34507B555D1C9C4F049CCA1475F 416256 ----a-w- C:\Windows\SysWOW64\dxtmsft.dll
2015-10-15 17:45:18 4A3CA2C73C4D66A90C63E9E532746020 480256 ----a-w- C:\Windows\SysWOW64\ieui.dll
2015-10-15 17:45:17 CEDBC9DBD9800E0EE81B0840EBC2BAC5 1155072 ----a-w- C:\Windows\SysWOW64\mshtmlmedia.dll
2015-10-15 17:45:16 E401E66CCB2AE219CF41F7F901C410C1 2011136 ----a-w- C:\Windows\SysWOW64\wininet.dll
2015-10-15 17:45:16 DE53F76D63CA64E172B336BC7CFF6EDA 4527616 ----a-w- C:\Windows\SysWOW64\jscript9.dll
2015-10-15 17:45:16 A7012A7032207D1C16B7236EDF91F4BB 168960 ----a-w- C:\Windows\SysWOW64\msrating.dll
2015-10-15 17:45:16 A25C9DD040CA9799C2A7E41732D0752A 230400 ----a-w- C:\Windows\SysWOW64\webcheck.dll
2015-10-15 17:45:16 5EE17D52CAF79663211C01C614594620 341504 ----a-w- C:\Windows\SysWOW64\html.iec
2015-10-15 17:45:16 17B66052348D3A3681A9411EDD839E18 115712 ----a-w- C:\Windows\SysWOW64\ieUnatt.exe
2015-10-15 17:41:40 C4240CA64E6B3523110DE3CAF4066F07 566784 ----a-w- C:\Windows\SysWOW64\wuapi.dll
2015-10-15 17:41:40 693F6EC2312B8B3F57B7277B069B91A3 174080 ----a-w- C:\Windows\SysWOW64\wuwebv.dll
2015-10-15 17:41:39 DDCABBADA6116E8E3472D93FDF56FE66 93696 ----a-w- C:\Windows\SysWOW64\wudriver.dll
2015-10-15 17:41:37 7902FB8C129A6DCAA9E0002BD3600F00 35328 ----a-w- C:\Windows\SysWOW64\wuapp.exe
2015-10-15 17:41:35 6CE7ACA0022C27A3FAECB600E097F81B 30208 ----a-w- C:\Windows\SysWOW64\wups.dll
2015-10-15 06:40:21 0D0FF2A38473552DDFF4F21756700F9B 50688 ----a-w- C:\Windows\SysWOW64\appidapi.dll
2015-10-15 06:39:23 C1096DA4634AD3356A10C00B24F53393 22368 ----a-w- C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll
2015-10-15 06:39:23 B23936CF83DAC4B64660A88711B5234A 12128 ----a-w- C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll
2015-10-15 06:39:23 9D66FCC681389EC619D4E801F1DDBB2F 17760 ----a-w- C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2015-10-15 06:39:23 8E534F49C77D787DB69BABFF931A497A 12640 ----a-w- C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll
2015-10-15 06:39:23 85CEBA9A21CE5D51B35EF2DE9EBFBAC4 12128 ----a-w- C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll
2015-10-15 06:39:23 80BEB858D2EEE9CA657647B599E5D844 11616 ----a-w- C:\Windows\SysWOW64\api-ms-win-eventing-provider-l1-1-0.dll
2015-10-15 06:39:23 6C7F782FDBF9AEFFE7663FA1579A610E 17760 ----a-w- C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll
2015-10-15 06:39:23 4669249FB01EA369C7FD40A530966FA1 12640 ----a-w- C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll
2015-10-15 06:39:23 00A0A24BB2E9AADE11494B627EB164C4 12640 ----a-w- C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll
2015-10-15 06:39:22 CBF3CFC9EE1FD29707D95C63A5E7A78B 19808 ----a-w- C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2015-10-15 06:39:22 9F9FE5F52E9B2AD655C896B849883B1A 12128 ----a-w- C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll
2015-10-15 06:39:22 94FEB4417CF3E39C8C58A1B73620687E 66400 ----a-w- C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll
2015-10-15 06:39:22 73CED8B30963E54D262DAE2559116E46 13664 ----a-w- C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2015-10-15 06:39:22 5B55E9A1360A6C52CC988DA6804D6CA2 901264 ----a-w- C:\Windows\SysWOW64\ucrtbase.dll
2015-10-15 06:39:22 408019E57D3D2DA62A9F28389EED0AC1 16224 ----a-w- C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2015-10-15 06:39:22 39F9D0F1B698D53D78C79576C7C60526 14176 ----a-w- C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll
2015-10-15 06:39:22 33E8CCBE05123C8146CD16293B688417 15712 ----a-w- C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll
====== C:\Windows\SysWOW64\drivers =====
====== C:\Windows\Sysnative =====
2015-10-15 17:55:20 3FE5671328B8A655F766D872D12DC373 5569472 ----a-w- C:\Windows\Sysnative\ntoskrnl.exe
2015-10-15 17:55:18 91DDAFAFCEC3E360881FE35AF06B9EE4 1730496 ----a-w- C:\Windows\Sysnative\ntdll.dll
2015-10-15 17:55:18 6C190505923A971F0474F8BA8DA50789 1461760 ----a-w- C:\Windows\Sysnative\lsasrv.dll
2015-10-15 17:55:18 11C18D613F66CB5CE829B821599ED339 1164800 ----a-w- C:\Windows\Sysnative\kernel32.dll
2015-10-15 17:55:17 CD349AD99C801523B55030AC234CC1EF 243712 ----a-w- C:\Windows\Sysnative\wow64.dll
2015-10-15 17:55:17 A06A96A26FE0BE22B08B641362296B68 424960 ----a-w- C:\Windows\Sysnative\KernelBase.dll
2015-10-15 17:55:16 F337ACC4CF6B9DFBE46D9A7E54E10756 503808 ----a-w- C:\Windows\Sysnative\srcore.dll
2015-10-15 17:55:16 EE035334B7A58C7F748C3D0394574A35 342016 ----a-w- C:\Windows\Sysnative\schannel.dll
2015-10-15 17:55:16 5B9427E47B86AFDA813A8D252713FC35 296960 ----a-w- C:\Windows\Sysnative\rstrui.exe
2015-10-15 17:55:16 5401C9D2F4B0A98B60259C621DDF1EB6 338432 ----a-w- C:\Windows\Sysnative\conhost.exe
2015-10-15 17:55:16 4AD1C61152A0199E3D7F9A82C07AC629 215040 ----a-w- C:\Windows\Sysnative\winsrv.dll
2015-10-15 17:55:16 365480590A46ECB0E4BF1DBD7BC69713 729088 ----a-w- C:\Windows\Sysnative\kerberos.dll
2015-10-15 17:55:16 338FD40323ADD43B5C94B4A6CB91874B 1216512 ----a-w- C:\Windows\Sysnative\rpcrt4.dll
2015-10-15 17:55:15 E43F36D0B4C674FEA2C992564A3E0F28 210944 ----a-w- C:\Windows\Sysnative\wdigest.dll
2015-10-15 17:55:15 D2BF3CD0F66139B5F1BA1D35C6613E78 315392 ----a-w- C:\Windows\Sysnative\msv1_0.dll
2015-10-15 17:55:15 96DE914D834FD7809A1720AF5D913C96 309760 ----a-w- C:\Windows\Sysnative\ncrypt.dll
2015-10-15 17:55:14 E9CCB68290F27837A3D7058FEB51F7A8 136192 ----a-w- C:\Windows\Sysnative\sspicli.dll
2015-10-15 17:55:14 D2E2A613EBD0C959E72556C3A63A6B4A 112640 ----a-w- C:\Windows\Sysnative\smss.exe
2015-10-15 17:55:14 06AA22DBBD294BB40F01E23BF826AA9C 86528 ----a-w- C:\Windows\Sysnative\TSpkg.dll
2015-10-15 17:55:13 95E4E6C645175731B1DC8084329121AA 64000 ----a-w- C:\Windows\Sysnative\auditpol.exe
2015-10-15 17:55:13 5424EC756808C1002457033D969115C7 31232 ----a-w- C:\Windows\Sysnative\lsass.exe
2015-10-15 17:55:12 8F15F0D6F42A2B8A58EDD1AA55D7FB98 50176 ----a-w- C:\Windows\Sysnative\srclient.dll
2015-10-15 17:55:11 78461527B753B9A6043038AEF25745D3 16384 ----a-w- C:\Windows\Sysnative\ntvdm64.dll
2015-10-15 17:55:11 3CF93F8BA5016A86073F7ACE4A225D69 44032 ----a-w- C:\Windows\Sysnative\cryptbase.dll
2015-10-15 17:55:11 23682AD752DE308760672C84A7E74554 43520 ----a-w- C:\Windows\Sysnative\csrsrv.dll
2015-10-15 17:55:10 C0EC18A77CBE5505019AF1BEB6CE824D 22016 ----a-w- C:\Windows\Sysnative\credssp.dll
2015-10-15 17:55:10 4E10C0CD94FD2E9F04B0AA11C4DB1592 29184 ----a-w- C:\Windows\Sysnative\sspisrv.dll
2015-10-15 17:55:09 E91002F7EC3A9BF7F62BF1E215A32451 362496 ----a-w- C:\Windows\Sysnative\wow64win.dll
2015-10-15 17:55:09 8260FD420E49C1E3DD6539BCEA2B376E 28160 ----a-w- C:\Windows\Sysnative\secur32.dll
2015-10-15 17:55:07 FCFE939A325054DFC69E1D8C58751A62 13312 ----a-w- C:\Windows\Sysnative\wow64cpu.dll
2015-10-15 17:55:04 023394934150F7EC547EBCC2107EEA5F 6656 ----a-w- C:\Windows\Sysnative\apisetschema.dll
2015-10-15 17:55:01 DD01EBF9D35E614CAEA1BF4876B07134 686080 ----a-w- C:\Windows\Sysnative\adtschema.dll
2015-10-15 17:55:00 B5D2DF46AB955A070F67FF192C52E7BD 60416 ----a-w- C:\Windows\Sysnative\msobjs.dll
2015-10-15 17:55:00 7CDA2FE5F02370B5879DF8D35133B0E1 146432 ----a-w- C:\Windows\Sysnative\msaudite.dll
2015-10-15 17:45:46 885B08E5EC912D2680F533094B87770D 14176768 ----a-w- C:\Windows\Sysnative\shell32.dll
2015-10-15 17:45:45 0F08BB62CD162883E9A3004BBE7914BD 1866752 ----a-w- C:\Windows\Sysnative\ExplorerFrame.dll
2015-10-15 17:45:22 9AEE2A881FD10E6A463588303D8027AD 114688 ----a-w- C:\Windows\Sysnative\ieetwcollector.exe
2015-10-15 17:45:22 3A0773E21355B41176ACAD8BB099D9B3 48640 ----a-w- C:\Windows\Sysnative\ieetwproxystub.dll
2015-10-15 17:45:21 BF8A5B4E696F4E8F3B2B5E9902467418 720896 ----a-w- C:\Windows\Sysnative\ie4uinit.exe
2015-10-15 17:45:21 9E0D0522908C1106E0D77708CB9926FE 34304 ----a-w- C:\Windows\Sysnative\iernonce.dll
2015-10-15 17:45:21 80E9DF296F127B3BC965EBC5A2C8F044 2724864 ----a-w- C:\Windows\Sysnative\mshtml.tlb
2015-10-15 17:45:21 521E1A87D4F750FD9694DBF3AB37B38F 77824 ----a-w- C:\Windows\Sysnative\JavaScriptCollectionAgent.dll
2015-10-15 17:45:20 4AEB3F2FB0CC23A18ED997F6C0476819 391784 ----a-w- C:\Windows\Sysnative\iedkcs32.dll
2015-10-15 17:45:20 3295B811A0260C0A5B346ECB73C5FCF0 152064 ----a-w- C:\Windows\Sysnative\occache.dll
2015-10-15 17:45:19 8A2A46DD0C51E5D2D0A2EF2AA289DA4D 1546752 ----a-w- C:\Windows\Sysnative\urlmon.dll
2015-10-15 17:45:19 2A898891EB7FBCF0774F0B96AAD05561 968704 ----a-w- C:\Windows\Sysnative\MsSpellCheckingFacility.exe
2015-10-15 17:45:19 12C1DECE9502828C0A5ADB50AB1673A0 4096 ----a-w- C:\Windows\Sysnative\ieetwcollectorres.dll
2015-10-15 17:45:18 F6F91F217D760981017E4AA4F1C7E633 66560 ----a-w- C:\Windows\Sysnative\iesetup.dll
2015-10-15 17:45:18 D661A17B4634171C58373699CBD6455B 315392 ----a-w- C:\Windows\Sysnative\dxtrans.dll
2015-10-15 17:45:18 6E1EEB1CE2F9F3AB14A9E8A6B1E82455 801280 ----a-w- C:\Windows\Sysnative\msfeeds.dll
2015-10-15 17:45:18 0FA614470B3A78FC5B8F3F3F742B9837 800768 ----a-w- C:\Windows\Sysnative\ieapfltr.dll
2015-10-15 17:45:17 E91FD3ACC10C971CBA991FCD058ABB58 2886656 ----a-w- C:\Windows\Sysnative\iertutil.dll
2015-10-15 17:45:17 7C3050383491011FEDD40961A37A2D99 2126336 ----a-w- C:\Windows\Sysnative\inetcpl.cpl
2015-10-15 17:45:16 A865136AC6436533E0A4A3C67F259401 585728 ----a-w- C:\Windows\Sysnative\vbscript.dll
2015-10-15 17:45:16 84C63F3D2D488A918A947E06BD1105EF 54784 ----a-w- C:\Windows\Sysnative\jsproxy.dll
2015-10-15 17:45:15 BC92D9D88959542FBAF1F8CF21F86B38 14458368 ----a-w- C:\Windows\Sysnative\ieframe.dll
2015-10-15 17:45:15 88D3F690043A1AA43F33DEC6DDA82178 616960 ----a-w- C:\Windows\Sysnative\ieui.dll
2015-10-15 17:45:15 5175A9C2C71D49394424C07CA856B803 1359360 ----a-w- C:\Windows\Sysnative\mshtmlmedia.dll
2015-10-15 17:45:15 4A9FFAC9325EFFDEFD7E8C0830B0ABEC 92160 ----a-w- C:\Windows\Sysnative\mshtmled.dll
2015-10-15 17:45:15 45A56A2CC2D6A4B649B7DC3B5DF259FF 489984 ----a-w- C:\Windows\Sysnative\dxtmsft.dll
2015-10-15 17:45:14 B0917E6238C1675E48CFE64947DD9FD9 144384 ----a-w- C:\Windows\Sysnative\ieUnatt.exe
2015-10-15 17:45:14 373B3EFBBF1A2706F8660C4DE4202694 262144 ----a-w- C:\Windows\Sysnative\webcheck.dll
2015-10-15 17:45:13 E36C7069B9C56DF9A53DD4FA5DCDDE72 5990912 ----a-w- C:\Windows\Sysnative\jscript9.dll
2015-10-15 17:45:13 BD06D875FB79E92DAF724C91DE743AFA 2487808 ----a-w- C:\Windows\Sysnative\wininet.dll
2015-10-15 17:45:13 58DD42AC31D1F86D303BAAF5955A59BA 417792 ----a-w- C:\Windows\Sysnative\html.iec
2015-10-15 17:45:13 454669BB12162610D93954BCC942A41C 817664 ----a-w- C:\Windows\Sysnative\jscript.dll
2015-10-15 17:45:13 1DE918244ED8AB9D3F2C4B9A1F91A24D 814080 ----a-w- C:\Windows\Sysnative\jscript9diag.dll
2015-10-15 17:45:12 BEA081F4F2D507D6461B142AB11995B3 199680 ----a-w- C:\Windows\Sysnative\msrating.dll
2015-10-15 17:45:12 99BA96F5AC545D857E662A9FC576D919 25851904 ----a-w- C:\Windows\Sysnative\mshtml.dll
2015-10-15 17:45:12 0783994A921469A6E97F3117AA0934DD 88064 ----a-w- C:\Windows\Sysnative\MshtmlDac.dll
2015-10-15 17:41:43 291778E1A36716182AFBC1731B2DFEAB 2607104 ----a-w- C:\Windows\Sysnative\wuaueng.dll
2015-10-15 17:41:42 2FFBB9A44A8BA9CBC9589C31E0A36605 3168768 ----a-w- C:\Windows\Sysnative\wucltux.dll
2015-10-15 17:41:41 ECB1C858D9989C4F19FDCE3B7F8BA1F7 696320 ----a-w- C:\Windows\Sysnative\wuapi.dll
2015-10-15 17:41:41 C64C6AA9F061E89AE6CA1B484AC3F94E 192512 ----a-w- C:\Windows\Sysnative\wuwebv.dll
2015-10-15 17:41:39 DA4450EE180CBDFB800FB230978BBC58 98816 ----a-w- C:\Windows\Sysnative\wudriver.dll
2015-10-15 17:41:39 64B432FB351118B222A5342A7A461696 140288 ----a-w- C:\Windows\Sysnative\wuauclt.exe
2015-10-15 17:41:38 96983751026F0940CAEEB15901B49FF2 37888 ----a-w- C:\Windows\Sysnative\wuapp.exe
2015-10-15 17:41:38 5F1A7C984117F478F7411BDD98411B58 91136 ----a-w- C:\Windows\Sysnative\WinSetupUI.dll
2015-10-15 17:41:36 7A2E35CA7131819A8CCE1FA1368D7813 37888 ----a-w- C:\Windows\Sysnative\wups2.dll
2015-10-15 17:41:35 B322CE702FA01DA60876BC5D417B15FE 36864 ----a-w- C:\Windows\Sysnative\wups.dll
2015-10-15 17:41:34 74F288D562E78E1062D4AA2A6C3AB74C 12288 ----a-w- C:\Windows\Sysnative\wu.upgrade.ps.dll
2015-10-15 06:41:07 F03EA93F045D009830C890010750B34A 25432 ----a-w- C:\Windows\Sysnative\CompatTelRunner.exe
2015-10-15 06:41:07 AFE7905DD772DEA54B9C443C6634740A 700416 ----a-w- C:\Windows\Sysnative\invagent.dll
2015-10-15 06:41:07 9F780E22C79AACBF3A93F6ACDE2A4E0A 766464 ----a-w- C:\Windows\Sysnative\generaltel.dll
2015-10-15 06:41:07 952D66DCA6CB744381B7298F8AAE994F 73216 ----a-w- C:\Windows\Sysnative\acmigration.dll
2015-10-15 06:41:07 21C89857E5671990BBF2B430BD75B9C9 1291264 ----a-w- C:\Windows\Sysnative\appraiser.dll
2015-10-15 06:41:07 1AC3E0E57844764B0CA6D2BF0F76C773 503808 ----a-w- C:\Windows\Sysnative\devinv.dll
2015-10-15 06:41:07 14A5CC0EE60278D483A88124B88F3524 1163776 ----a-w- C:\Windows\Sysnative\aeinv.dll
2015-10-15 06:40:35 87FEDB1FF42C3A10FFE2CE95AB2AF306 616360 ----a-w- C:\Windows\Sysnative\winresume.efi
2015-10-15 06:40:28 541B7C53EDA8F84790A593B13FB32E56 692672 ----a-w- C:\Windows\Sysnative\winload.efi
2015-10-15 06:40:21 B6C85437FDC8EC6464BE359D41BBC3F7 59392 ----a-w- C:\Windows\Sysnative\appidapi.dll
2015-10-15 06:40:21 ABC373B9C6275D45F17DB559408FFD1B 32768 ----a-w- C:\Windows\Sysnative\appidsvc.dll
2015-10-15 06:40:21 7503BAD9B2A08B8A95319F7C0CA9F869 63488 ----a-w- C:\Windows\Sysnative\setbcdlocale.dll
2015-10-15 06:40:21 7030F95F994B2F2CCC1C521E342369DB 147456 ----a-w- C:\Windows\Sysnative\appidpolicyconverter.exe
2015-10-15 06:40:20 B17B1E5FB5CE63DA4DB4D49E3683487F 17920 ----a-w- C:\Windows\Sysnative\appidcertstorecheck.exe
2015-10-15 06:39:23 ED14B64C94F543974B7FDC592FA0594B 12640 ----a-w- C:\Windows\Sysnative\api-ms-win-crt-conio-l1-1-0.dll
2015-10-15 06:39:23 CC337898E64D9078CB697AC19F995C7F 12128 ----a-w- C:\Windows\Sysnative\api-ms-win-crt-utility-l1-1-0.dll
2015-10-15 06:39:23 BBAE7B5436D6D1B0FC967FF67E35415F 16224 ----a-w- C:\Windows\Sysnative\api-ms-win-crt-runtime-l1-1-0.dll
2015-10-15 06:39:23 6631C212F79350458589A5281374B38B 12640 ----a-w- C:\Windows\Sysnative\api-ms-win-crt-process-l1-1-0.dll
2015-10-15 06:39:23 56556659C691DD043DBE24B0A195D64C 20832 ----a-w- C:\Windows\Sysnative\api-ms-win-crt-math-l1-1-0.dll
2015-10-15 06:39:23 53E9526AF1FDCE39F799BFE9217397A8 17760 ----a-w- C:\Windows\Sysnative\api-ms-win-crt-stdio-l1-1-0.dll
2015-10-15 06:39:23 32B2264317EA6200DA5DEEEC7DCB0EEB 11616 ----a-w- C:\Windows\Sysnative\api-ms-win-eventing-provider-l1-1-0.dll
2015-10-15 06:39:23 2381E189321EAD521FF71E72D08A6B17 984448 ----a-w- C:\Windows\Sysnative\ucrtbase.dll
2015-10-15 06:39:23 1908861649E67CDC20C563C234A89914 15712 ----a-w- C:\Windows\Sysnative\api-ms-win-crt-convert-l1-1-0.dll
2015-10-15 06:39:23 090DD0BB2BDDEE3EAAE5B6FF15FAE209 14176 ----a-w- C:\Windows\Sysnative\api-ms-win-crt-time-l1-1-0.dll
2015-10-15 06:39:22 F97E7878A2B372291B1269D80327BBF6 12640 ----a-w- C:\Windows\Sysnative\api-ms-win-crt-heap-l1-1-0.dll
2015-10-15 06:39:22 ECCF5973B80D771A79643732017CEA9A 17760 ----a-w- C:\Windows\Sysnative\api-ms-win-crt-string-l1-1-0.dll
2015-10-15 06:39:22 E9F6D776545843A9817D8ACF38D06D09 19808 ----a-w- C:\Windows\Sysnative\api-ms-win-crt-multibyte-l1-1-0.dll
2015-10-15 06:39:22 AF851DFD0D9FECB76FF2B403F3C30F5B 12128 ----a-w- C:\Windows\Sysnative\api-ms-win-crt-environment-l1-1-0.dll
2015-10-15 06:39:22 761DDD8669A661D57D9CF9C335949C06 12128 ----a-w- C:\Windows\Sysnative\api-ms-win-crt-locale-l1-1-0.dll
2015-10-15 06:39:22 653CB5DF3CEC6A4A0E402B33D8AA5C08 63840 ----a-w- C:\Windows\Sysnative\api-ms-win-crt-private-l1-1-0.dll
2015-10-15 06:39:22 0F143310FADE4DE116070A3917A79C18 13664 ----a-w- C:\Windows\Sysnative\api-ms-win-crt-filesystem-l1-1-0.dll
====== C:\Windows\Sysnative\drivers =====
2015-10-15 17:55:18 C6330F7C2E92A00E6773E82F79078AFC 157016 ----a-w- C:\Windows\Sysnative\drivers\ksecpkg.sys
2015-10-15 17:55:18 ACB6782973BD93760D597FC7BB37E692 159232 ----a-w- C:\Windows\Sysnative\drivers\mrxsmb.sys
2015-10-15 17:55:18 3A8C03156C3E31E70EF84E48CA179B46 97112 ----a-w- C:\Windows\Sysnative\drivers\ksecdd.sys
2015-10-15 17:55:07 262BF7BB7D0E44CFAA9B12A1E0A6EDF1 290816 ----a-w- C:\Windows\Sysnative\drivers\mrxsmb10.sys
2015-10-15 17:55:06 8C0376974AA28398FF501E78C04ACB30 129024 ----a-w- C:\Windows\Sysnative\drivers\mrxsmb20.sys
2015-10-15 06:40:20 27DABFB4A6B0140C34DBEC713469592B 61440 ----a-w- C:\Windows\Sysnative\drivers\appid.sys
2015-09-27 08:17:04 8F22037D3F5A6BB676525D825A1388B9 113880 ----a-w- C:\Windows\Sysnative\drivers\MBAMSwissArmy.sys
2015-09-27 08:16:44 E681CE4AE5C09651D53CB4387CA3560E 109272 ----a-w- C:\Windows\Sysnative\drivers\mbamchameleon.sys
2015-09-27 08:16:44 AE757332EA130E94E646621CC695B52A 63704 ----a-w- C:\Windows\Sysnative\drivers\mwac.sys
====== C:\Windows\Tasks ======
2015-10-01 19:35:17 DE21937662500F9C0B713C72ACDEC362 3898 ----a-w- C:\Windows\Sysnative\Tasks\GoogleUpdateTaskMachineUA
2015-10-01 19:35:16 8C796AD525471C8811A086B665D44823 898 ----a-w- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-10-01 19:35:16 7E854735AEA9709D5DA424BE49FDF4BE 902 ----a-w- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-10-01 19:35:16 0E9E5BCD9AA873A96C93BA8D6580C36E 3646 ----a-w- C:\Windows\Sysnative\Tasks\GoogleUpdateTaskMachineCore
====== C:\Windows\Temp ======
======= C:\Program Files =====
======= C:\PROGRA~2 =====
2015-09-29 06:18:40 -------- d-----w- C:\PROGRA~2\COMMON~1\Skype
======= C: =====
====== C:\Users\Alasdair\AppData\Roaming ======
====== C:\Users\Alasdair ======
2015-10-11 20:23:32 8BA618F15C8D721B12668D602DBAE5DB 1682432 ----a-w- C:\Users\Alasdair\Downloads\adwcleaner_5.013 (1).exe
2015-10-11 18:30:38 8BA618F15C8D721B12668D602DBAE5DB 1682432 ----a-w- C:\Users\Alasdair\Downloads\adwcleaner_5.013.exe
2015-10-11 14:00:26 F7620D24115E249DC0F336A579B291E4 2195456 ----a-w- C:\Users\Alasdair\Desktop\FRST64.exe
2015-10-01 19:36:29 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-09-29 06:18:43 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
 
====== C: exe-files ==
=== C: other files ==
2015-10-15 17:55:18 C6330F7C2E92A00E6773E82F79078AFC 157016 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2015-10-15 17:55:18 ACB6782973BD93760D597FC7BB37E692 159232 ----a-w- C:\Windows\System32\drivers\mrxsmb.sys
2015-10-15 17:55:18 3A8C03156C3E31E70EF84E48CA179B46 97112 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2015-10-15 17:55:07 262BF7BB7D0E44CFAA9B12A1E0A6EDF1 290816 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys
2015-10-15 17:55:06 8C0376974AA28398FF501E78C04ACB30 129024 ----a-w- C:\Windows\System32\drivers\mrxsmb20.sys
2015-10-15 06:40:20 27DABFB4A6B0140C34DBEC713469592B 61440 ----a-w- C:\Windows\System32\drivers\appid.sys
2015-10-13 17:27:01 9C438DBBA163933DB2F57E9A58E03CED 6004992 ----a-w- C:\Users\Alasdair\Documents\Backup\STM\French\Year 10\all-6168636.zip
2015-10-13 17:24:32 3B893FCD1AD5FFAF049B93E2B0AC6C45 773307 ----a-w- C:\Users\Alasdair\Documents\Backup\CBS\Extra resources\Jane Andrews resources 2014-15\Year 8 term 3\mes vacances - worksheet.zip
2015-10-13 17:24:30 DA54814C3CBFBD872996B5524B5CEEE7 110194 ----a-w- C:\Users\Alasdair\Documents\Backup\CBS\Extra resources\Jane Andrews resources 2014-15\year 8 term 2(2)\foods.zip
2015-10-12 08:31:50 A27D866DB8AFDFEE5D7E853F6582B523 97581 ----a-w- C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx
 
==== Startup Registry Enabled ======================
 
[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"
 
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"
 
[HKEY_USERS\S-1-5-21-2663238727-1038402730-3101154227-1000\Software\Microsoft\Windows\CurrentVersion\Run]
"Steam"="C:\Program Files (x86)\Steam\steam.exe -silent"
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe /autoRun"
"DAEMON Tools Lite"="C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe -autorun"
"Spotify Web Helper"="C:\Users\Alasdair\AppData\Roaming\Spotify\SpotifyWebHelper.exe"
"Spotify"="C:\Users\Alasdair\AppData\Roaming\Spotify\Spotify.exe -autostart -minimized"
"Skype"="C:\Program Files (x86)\Skype\Phone\Skype.exe /minimized /regrun"
 
[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"
 
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"amd_dc_opt"="C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe"
"GMouse"="C:\GIGABYTE FORCE\GIGABYTE FORCE.EXE /hide"
 
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Steam"="C:\Program Files (x86)\Steam\steam.exe -silent"
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe /autoRun"
"DAEMON Tools Lite"="C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe -autorun"
"Spotify Web Helper"="C:\Users\Alasdair\AppData\Roaming\Spotify\SpotifyWebHelper.exe"
"Spotify"="C:\Users\Alasdair\AppData\Roaming\Spotify\Spotify.exe -autostart -minimized"
"Skype"="C:\Program Files (x86)\Skype\Phone\Skype.exe /minimized /regrun"
 
==== Startup Registry Enabled x64 ======================
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Nvtmru"="C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
"MSC"="c:\Program Files\Microsoft Security Client\msseces.exe -hide -runkey"
"ShadowPlay"="C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart"
"NvBackend"="C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
 
==== Startup Registry Disabled x64 ======================
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\HP Software Update]
"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="HP Software Update"
"hkey"="HKLM"
"command"="C:\\Program Files (x86)\\HP\\HP Software Update\\HPWuSchd2.exe"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\hpqSRMon]
"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="hpqSRMon"
"hkey"="HKLM"
"command"="C:\\Program Files (x86)\\HP\\Digital Imaging\\bin\\hpqSRMon.exe"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SunJavaUpdateSched]
"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SunJavaUpdateSched"
"hkey"="HKLM"
"command"="\"C:\\Program Files (x86)\\Common Files\\Java\\Java Update\\jusched.exe\""
 
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
"path"="C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\HP Digital Imaging Monitor.lnk"
"backup"="C:\\Windows\\pss\\HP Digital Imaging Monitor.lnk.CommonStartup"
"backupExtension"=".CommonStartup"
"command"="C:\\PROGRA~2\\HP\\DIGITA~1\\bin\\hpqtra08.exe "
"item"="HP Digital Imaging Monitor"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk]
"path"="C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\McAfee Security Scan Plus.lnk"
"backup"="C:\\Windows\\pss\\McAfee Security Scan Plus.lnk.CommonStartup"
"backupExtension"=".CommonStartup"
"command"="C:\\PROGRA~1\\MCAFEE~1\\385C9A~1.150\\SSSCHE~1.EXE "
"item"="McAfee Security Scan Plus"
 
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\BRSptSvc]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\c2cautoupdatesvc]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\c2cpnrsvc]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\IEEtwCollectorService]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\McComponentHostService]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\SkypeUpdate]
 
 
==== Startup Folders ======================
 
2013-07-30 21:46:55 2297 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TP-LINK Wireless Configuration Utility.lnk
 
==== Task Scheduler Jobs ======================
 
C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [15/10/2015 18:50]
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [01/10/2015 20:35]
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [01/10/2015 20:35]
 
==== Other Scheduled Tasks ======================
 
"C:\Windows\SysNative\tasks\Adobe Acrobat Update Task" [C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe]
"C:\Windows\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe]
"C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe]
"C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe]
"C:\Windows\SysNative\tasks\SidebarExecute" [C:\Program Files\Windows Sidebar\sidebar.exe]
"C:\Windows\SysNative\tasks\{A93B1CEF-DE75-4F90-BA2F-C1D062A145CA}" ["c:\program files (x86)\google\chrome\application\chrome.exe"]
"C:\Windows\SysNative\tasks\{CD5435E2-433D-40CA-B2CC-037A9B3B1434}" ["c:\program files (x86)\google\chrome\application\chrome.exe"]
"C:\Windows\SysNative\tasks\Apple\AppleSoftwareUpdate" [C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe]
"C:\Windows\SysNative\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc]
 
==== Firefox Extensions Registry ======================
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"[email protected]"="C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3" [16/06/2014 19:07]
[HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions]
"[email protected]"="C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3" [16/06/2014 19:07]
 
==== Chromium Look ======================
 
Google Chrome Version: 46.0.2490.71
 
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
bopakagnckmlgajfccecajhnimjiiedh - No path found[]
lifbcibllhkdhoafpjfnlhfpfgnpldfl - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx[12/10/2015 09:31]
 
HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions
bbjllphbppobebmjpjcijfbakobcheof - No path found[]
 
Duolingo on the Web - Alasdair\AppData\Local\Google\Chrome\User Data\Default\Extensions\aiahmijlpehemcpleichkcokhegllfjl
Rapport - Alasdair\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjllphbppobebmjpjcijfbakobcheof
Google Voice Search Hotword (Beta) - Alasdair\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn
whatsapp-for-chrome - Alasdair\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgkodfmeijboinjdegggmkbkjfiagaan
YouTube - Alasdair\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo
Google Search - Alasdair\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf
AdBlock - Alasdair\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom
Reddit Enhancement Suite - Alasdair\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb
Auto HD For YouTube - Alasdair\AppData\Local\Google\Chrome\User Data\Default\Extensions\koiaokdomkpjdgniimnkhgbilbjgpeak
Chrome Web Store Payments - Alasdair\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
Gmail - Alasdair\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia
 
==== IE Start and Search Settings ======================
 
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
 
==== All HKCU SearchScopes ======================
 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing  Url="http://www.bing.com/...ox&FORM=IESR02"
 
==== C:\zoek_backup content ======================
 
C:\zoek_backup (files=0 folders=0 0 bytes)
 
==== EOF on 17/10/2015 at 15:39:49.11 ======================

Edited by Jommers, 17 October 2015 - 08:45 AM.

  • 0

#4
Naathim

Naathim

    GeekU Minion

  • Expert
  • 4,568 posts
Hi,

I see AdwCleaner in your logfiles, did you run it already?



51a612a8b27e2-Zoek.png Scan with ZOEK

Temporary disable your AntiVirus and AntiSpyware protection - instructions here.
  • Right-click on 51a612a8b27e2-Zoek.png icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
  • Wait patiently until the main console will appear, it may take a minute or two.
  • In the main box please paste in the following script:
    createsrpoint;
    autoclean;
    emptyclsid;
    bopakagnckmlgajfccecajhnimjiiedh;chr
    bbjllphbppobebmjpjcijfbakobcheof;chr
    
  • Make sure that Scan All Users option is checked.
  • Push Run Script and wait patiently. The scan may take a couple of minutes.
  • When the scan completes, a zoek-results logfile should open in notepad.
  • If a reboot is needed, it will be opened after it. You may also find it at your main drive (usually C:\ drive)
Please include its content in your next reply.
Don't forget to re-enable your switched-off protection software!
  • 0

#5
Jommers

Jommers

    New Member

  • Topic Starter
  • Member
  • Pip
  • 5 posts

Yes I have run it and the problem persisted.

 

Here's the ZOEK log:

 

 

 
Zoek.exe v5.0.0.1 Updated 18-October-2015
Tool run by Alasdair on 18/10/2015 at 22:08:59.41.
Microsoft Windows 7 Ultimate  6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Alasdair\Downloads\zoek.exe [Scan all users] [Script inserted] 
 
==== Older Logs ======================
 
C:\zoek-results2015-10-17-143949.log 58145 bytes
 
==== System Restore Info ======================
 
18/10/2015 22:11:48 Zoek.exe System Restore Point Created Successfully.
 
==== Empty Folders Check ======================
 
C:\PROGRA~2\MSXML 4.0 deleted successfully
C:\PROGRA~2\COMMON~1\Blizzard Entertainment deleted successfully
C:\Users\Alasdair\AppData\Roaming\BitTorrent deleted successfully
C:\Users\Alasdair\AppData\Roaming\Malwarebytes deleted successfully
C:\Users\Alasdair\AppData\Roaming\Yahoo! deleted successfully
C:\Users\Alasdair\AppData\Local\CutePDF Writer deleted successfully
C:\Users\Alasdair\AppData\Local\WarThunder deleted successfully
 
==== Deleting CLSID Registry Keys ======================
 
 
==== Deleting CLSID Registry Values ======================
 
 
==== Deleting Services ======================
 
 
==== Deleting Files \ Folders ======================
 
C:\Users\Alasdair\AppData\Roaming\QuickScan deleted
C:\PROGRA~2\Yahoo! deleted
C:\install.exe deleted
C:\NDP40-KB2640103-x64.exe deleted
C:\PROGRA~3\Package Cache deleted
C:\Users\Alasdair\AppData\Local\Unity deleted
C:\Users\Alasdair\AppData\LocalLow\Unity deleted
 
==== Firefox Extensions Registry ======================
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"[email protected]"="C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3" [16/06/2014 19:07]
[HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions]
"[email protected]"="C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3" [16/06/2014 19:07]
 
==== Chromium Look ======================
 
Google Chrome Version: 46.0.2490.71
 
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
bopakagnckmlgajfccecajhnimjiiedh - No path found[]
lifbcibllhkdhoafpjfnlhfpfgnpldfl - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx[12/10/2015 09:31]
 
HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions
bbjllphbppobebmjpjcijfbakobcheof - No path found[]
 
Duolingo on the Web - Alasdair\AppData\Local\Google\Chrome\User Data\Default\Extensions\aiahmijlpehemcpleichkcokhegllfjl
Rapport - Alasdair\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjllphbppobebmjpjcijfbakobcheof
Google Voice Search Hotword (Beta) - Alasdair\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn
whatsapp-for-chrome - Alasdair\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgkodfmeijboinjdegggmkbkjfiagaan
YouTube - Alasdair\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo
Google Search - Alasdair\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf
AdBlock - Alasdair\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom
Reddit Enhancement Suite - Alasdair\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb
Auto HD For YouTube - Alasdair\AppData\Local\Google\Chrome\User Data\Default\Extensions\koiaokdomkpjdgniimnkhgbilbjgpeak
Chrome Web Store Payments - Alasdair\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
Gmail - Alasdair\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia
 
==== Chromium Fix ======================
 
C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_toolbar.utorrent.com_0.localstorage deleted successfully
C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_toolbar.utorrent.com_0.localstorage-journal deleted successfully
C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_metrovideogame.wikia.com_0.localstorage deleted successfully
C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_planefinder.net_0.localstorage deleted successfully
C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_planefinder.net_0.localstorage-journal deleted successfully
C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.olark.com_0.localstorage deleted successfully
C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.olark.com_0.localstorage-journal deleted successfully
C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_c.betrad.com_0.localstorage deleted successfully
C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_c.betrad.com_0.localstorage-journal deleted successfully
C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_c.betrad.com_0.localstorage deleted successfully
C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_c.betrad.com_0.localstorage-journal deleted successfully
C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_d16fk4ms6rqz1v.cloudfront.net_0.localstorage deleted successfully
C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_d16fk4ms6rqz1v.cloudfront.net_0.localstorage-journal deleted successfully
C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_d22j4fzzszoii2.cloudfront.net_0.localstorage deleted successfully
C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_d22j4fzzszoii2.cloudfront.net_0.localstorage-journal deleted successfully
C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_d30ke5tqu2tkyx.cloudfront.net_0.localstorage deleted successfully
C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_d30ke5tqu2tkyx.cloudfront.net_0.localstorage-journal deleted successfully
C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_teacherservices.education.gov.uk_0.localstorage deleted successfully
C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_teacherservices.education.gov.uk_0.localstorage-journal deleted successfully
C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_services.hearstmags.com_0.localstorage deleted successfully
C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_services.hearstmags.com_0.localstorage-journal deleted successfully
C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.xpoitservices.co.uk_0.localstorage deleted successfully
C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.xpoitservices.co.uk_0.localstorage-journal deleted successfully
C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjllphbppobebmjpjcijfbakobcheof deleted successfully
 
==== Set IE to Default ======================
 
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
 
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
 
==== All HKCU SearchScopes ======================
 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{012E1000-F331-11DB-8314-0800200C9A66} Google  Url="http://www.google.co...={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing  Url="http://www.bing.com/...ox&FORM=IESR02"
 
==== Deleting Registry Keys ======================
 
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\bopakagnckmlgajfccecajhnimjiiedh deleted successfully
HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions\bbjllphbppobebmjpjcijfbakobcheof deleted successfully
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\UnityWebPlayer deleted successfully
 
==== Empty IE Cache ======================
 
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Alasdair\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\Alasdair\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Alasdair\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Alasdair\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2GL03P4T will be deleted at reboot
C:\Users\Alasdair\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9233IY3R will be deleted at reboot
C:\Users\Alasdair\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\99ZI8SL5 will be deleted at reboot
C:\Users\Alasdair\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CFPJGNW3 will be deleted at reboot
C:\Users\Alasdair\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DDGHBTYP will be deleted at reboot
C:\Users\Alasdair\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JT0UOM0P will be deleted at reboot
C:\Users\Alasdair\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\M4FO0RM2 will be deleted at reboot
C:\Users\Alasdair\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XKQ7266W will be deleted at reboot
 
==== Empty FireFox Cache ======================
 
No FireFox Profiles found
 
==== Empty Chrome Cache ======================
 
C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
 
==== Empty All Flash Cache ======================
 
Flash Cache Emptied Successfully
 
==== Empty All Java Cache ======================
 
Java Cache cleared successfully
 
==== C:\zoek_backup content ======================
 
C:\zoek_backup (files=76 folders=32 57762952 bytes)
 
==== Empty Temp Folders ======================
 
C:\Users\Alasdair\AppData\Local\Temp will be emptied at reboot
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\hedev\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
 
==== After Reboot ======================
 
==== Empty Temp Folders ======================
 
C:\Windows\Temp successfully emptied
C:\Users\Alasdair\AppData\Local\Temp successfully emptied
 
==== Empty Recycle Bin ======================
 
C:\$RECYCLE.BIN successfully emptied
 
==== Deleting Files / Folders ======================
 
"C:\Users\Alasdair\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2GL03P4T" not found
"C:\Users\Alasdair\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9233IY3R" not found
"C:\Users\Alasdair\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\99ZI8SL5" not found
"C:\Users\Alasdair\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CFPJGNW3" not found
"C:\Users\Alasdair\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DDGHBTYP" not found
"C:\Users\Alasdair\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JT0UOM0P" not found
"C:\Users\Alasdair\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\M4FO0RM2" not found
"C:\Users\Alasdair\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XKQ7266W" not found
"C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\Low" not deleted
 
==== EOF on 18/10/2015 at 22:38:39.53 ======================

  • 0

#6
Naathim

Naathim

    GeekU Minion

  • Expert
  • 4,568 posts

Yes I have run it and the problem persisted.


OK, but can you please show me the reports generated by AdwCleaner? You can find them in the C:\AdwCleaner folder, named AdwCleaner[S*] and AdwCleaner[C*]. They might contain some useful info.
  • 0

#7
Jommers

Jommers

    New Member

  • Topic Starter
  • Member
  • Pip
  • 5 posts

Of course - sorry I overlooked that. There's also a Quarantine log. Would that be helpful, too?

 

# AdwCleaner v5.013 - Logfile created 11/10/2015 at 19:52:00
# Updated 09/10/2015 by Xplode
# Database : 2015-10-09.3 [Server]
# Operating system : Windows 7 Ultimate Service Pack 1 (x64)
# Username : Alasdair - ALASDAIR-PC
# Running from : C:\Users\Alasdair\Downloads\adwcleaner_5.013.exe
# Option : Cleaning
 
***** [ Services ] *****
 
 
***** [ Folders ] *****
 
[-] Folder Deleted : C:\Program Files (x86)\Conduit
[-] Folder Deleted : C:\ProgramData\apn
[-] Folder Deleted : C:\Users\Alasdair\AppData\Local\Conduit
[-] Folder Deleted : C:\Users\Alasdair\AppData\Local\NativeMessaging
[-] Folder Deleted : C:\Users\Alasdair\AppData\LocalLow\Conduit
[-] Folder Deleted : C:\Users\Alasdair\AppData\Roaming\Yahoo!\Companion
 
***** [ Files ] *****
 
[-] File Deleted : C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\local storage\hxxp_www.azlyrics.com_0.localstorage
[-] File Deleted : C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\local storage\hxxp_www.azlyrics.com_0.localstorage-journal
[-] File Deleted : C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\local storage\hxxp_www.superfish.com_0.localstorage-journal
[-] File Deleted : C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
[-] File Deleted : C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage
[-] File Deleted : C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage-journal
[-] File Deleted : C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.veoh.com_0.localstorage
[-] File Deleted : C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.veoh.com_0.localstorage-journal
 
***** [ DLLs ] *****
 
 
***** [ Shortcuts ] *****
 
 
***** [ Scheduled tasks ] *****
 
 
***** [ Registry ] *****
 
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\YMERemote.DLL
[-] Key Deleted : HKLM\SOFTWARE\Classes\YBrowserToolbar.YBrowserToolbar.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\YBrowserToolbar.YBrowserToolbar
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8233093C-178B-484B-979E-3C6B5B147DBC}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{B722ED8B-0B38-408E-BB89-260C73BCF3D4}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{8233093C-178B-484B-979E-3C6B5B147DBC}
[-] Key Deleted : HKCU\Software\Conduit
[-] Key Deleted : HKCU\Software\Yahoo\Companion
[-] Key Deleted : HKCU\Software\Yahoo\YFriendsBar
[-] Key Deleted : HKCU\Software\AppDataLow\Software\Yahoo\Companion
[-] Key Deleted : HKLM\SOFTWARE\Conduit
[-] Key Deleted : HKLM\SOFTWARE\Yahoo\Companion
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Steam App 228200
[!] Key Not Deleted : [x64] HKCU\Software\Conduit
[!] Key Not Deleted : [x64] HKCU\Software\Yahoo\Companion
[!] Key Not Deleted : [x64] HKCU\Software\Yahoo\YFriendsBar
[!] Key Not Deleted : HKU\S-1-5-21-2663238727-1038402730-3101154227-1000\Software\AppDataLow\Software\Yahoo\Companion
 
***** [ Web browsers ] *****
 
[-] [C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : bopakagnckmlgajfccecajhnimjiiedh
[-] [C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : dknkjnkhedbanphkkpbpcgoblmkbfhlf
 
*************************
 
:: Winsock settings cleared
 
########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [4646 bytes] ##########
 
 
# AdwCleaner v5.013 - Logfile created 11/10/2015 at 19:30:53
# Updated 09/10/2015 by Xplode
# Database : 2015-10-09.3 [Server]
# Operating system : Windows 7 Ultimate Service Pack 1 (x64)
# Username : Alasdair - ALASDAIR-PC
# Running from : C:\Users\Alasdair\Downloads\adwcleaner_5.013.exe
# Option : Scan
 
***** [ Services ] *****
 
 
***** [ Folders ] *****
 
Folder Found : C:\Program Files (x86)\Conduit
Folder Found : C:\ProgramData\apn
Folder Found : C:\Users\Alasdair\AppData\Local\Conduit
Folder Found : C:\Users\Alasdair\AppData\Local\NativeMessaging
Folder Found : C:\Users\Alasdair\AppData\LocalLow\Conduit
Folder Found : C:\Users\Alasdair\AppData\Roaming\Yahoo!\Companion
 
***** [ Files ] *****
 
File Found : C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\local storage\hxxp_www.azlyrics.com_0.localstorage
File Found : C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\local storage\hxxp_www.azlyrics.com_0.localstorage-journal
File Found : C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\local storage\hxxp_www.superfish.com_0.localstorage-journal
File Found : C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
File Found : C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage
File Found : C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage-journal
File Found : C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.veoh.com_0.localstorage
File Found : C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.veoh.com_0.localstorage-journal
 
***** [ DLLs ] *****
 
 
***** [ Shortcuts ] *****
 
 
***** [ Scheduled tasks ] *****
 
 
***** [ Registry ] *****
 
Key Found : HKLM\SOFTWARE\Classes\AppID\YMERemote.DLL
Key Found : HKLM\SOFTWARE\Classes\YBrowserToolbar.YBrowserToolbar.1
Key Found : HKLM\SOFTWARE\Classes\YBrowserToolbar.YBrowserToolbar
Key Found : HKLM\SOFTWARE\Classes\Interface\{8233093C-178B-484B-979E-3C6B5B147DBC}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{B722ED8B-0B38-408E-BB89-260C73BCF3D4}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{8233093C-178B-484B-979E-3C6B5B147DBC}
Key Found : HKCU\Software\Conduit
Key Found : HKCU\Software\Yahoo\Companion
Key Found : HKCU\Software\Yahoo\YFriendsBar
Key Found : HKCU\Software\AppDataLow\Software\Yahoo\Companion
Key Found : HKLM\SOFTWARE\Conduit
Key Found : HKLM\SOFTWARE\Yahoo\Companion
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Steam App 228200
Key Found : [x64] HKCU\Software\Conduit
Key Found : [x64] HKCU\Software\Yahoo\Companion
Key Found : [x64] HKCU\Software\Yahoo\YFriendsBar
Key Found : HKU\S-1-5-21-2663238727-1038402730-3101154227-1000\Software\AppDataLow\Software\Yahoo\Companion
 
***** [ Web browsers ] *****
 
[C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : bopakagnckmlgajfccecajhnimjiiedh
[C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : dknkjnkhedbanphkkpbpcgoblmkbfhlf
 
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [4314 bytes] ##########
 
 
# AdwCleaner v5.013 - Logfile created 11/10/2015 at 19:48:30
# Updated 09/10/2015 by Xplode
# Database : 2015-10-09.3 [Server]
# Operating system : Windows 7 Ultimate Service Pack 1 (x64)
# Username : Alasdair - ALASDAIR-PC
# Running from : C:\Users\Alasdair\Downloads\adwcleaner_5.013.exe
# Option : Scan
 
***** [ Services ] *****
 
 
***** [ Folders ] *****
 
Folder Found : C:\Program Files (x86)\Conduit
Folder Found : C:\ProgramData\apn
Folder Found : C:\Users\Alasdair\AppData\Local\Conduit
Folder Found : C:\Users\Alasdair\AppData\Local\NativeMessaging
Folder Found : C:\Users\Alasdair\AppData\LocalLow\Conduit
Folder Found : C:\Users\Alasdair\AppData\Roaming\Yahoo!\Companion
 
***** [ Files ] *****
 
File Found : C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\local storage\hxxp_www.azlyrics.com_0.localstorage
File Found : C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\local storage\hxxp_www.azlyrics.com_0.localstorage-journal
File Found : C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\local storage\hxxp_www.superfish.com_0.localstorage-journal
File Found : C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
File Found : C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage
File Found : C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage-journal
File Found : C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.veoh.com_0.localstorage
File Found : C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.veoh.com_0.localstorage-journal
 
***** [ DLLs ] *****
 
 
***** [ Shortcuts ] *****
 
 
***** [ Scheduled tasks ] *****
 
 
***** [ Registry ] *****
 
Key Found : HKLM\SOFTWARE\Classes\AppID\YMERemote.DLL
Key Found : HKLM\SOFTWARE\Classes\YBrowserToolbar.YBrowserToolbar.1
Key Found : HKLM\SOFTWARE\Classes\YBrowserToolbar.YBrowserToolbar
Key Found : HKLM\SOFTWARE\Classes\Interface\{8233093C-178B-484B-979E-3C6B5B147DBC}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{B722ED8B-0B38-408E-BB89-260C73BCF3D4}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{8233093C-178B-484B-979E-3C6B5B147DBC}
Key Found : HKCU\Software\Conduit
Key Found : HKCU\Software\Yahoo\Companion
Key Found : HKCU\Software\Yahoo\YFriendsBar
Key Found : HKCU\Software\AppDataLow\Software\Yahoo\Companion
Key Found : HKLM\SOFTWARE\Conduit
Key Found : HKLM\SOFTWARE\Yahoo\Companion
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Steam App 228200
Key Found : [x64] HKCU\Software\Conduit
Key Found : [x64] HKCU\Software\Yahoo\Companion
Key Found : [x64] HKCU\Software\Yahoo\YFriendsBar
Key Found : HKU\S-1-5-21-2663238727-1038402730-3101154227-1000\Software\AppDataLow\Software\Yahoo\Companion
 
***** [ Web browsers ] *****
 
[C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : bopakagnckmlgajfccecajhnimjiiedh
[C:\Users\Alasdair\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : dknkjnkhedbanphkkpbpcgoblmkbfhlf
 
########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [4314 bytes] ##########

  • 0

#8
Naathim

Naathim

    GeekU Minion

  • Expert
  • 4,568 posts
Hi,

I apologize - I have been left without the internet access for a couple of days.


We did some cleaning with ZOEK, time to take a fresh look with FRST.



FRST.gif Scan with Farbar Recovery Scan Tool

Please re-run Farbar Recovery Scan Tool.
  • Right-click on FRST.gif icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
    > XP users click run after receipt of Windows Security Warning - Open File.
    > 8 users will be prompted about Windows SmartScreen protection - click More information and Run.
  • Make sure that Addition option is checked.
  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.
Please include their content in your next reply.
  • 0

#9
Naathim

Naathim

    GeekU Minion

  • Expert
  • 4,568 posts

Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.


  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP