Recent Posts

Pages: 1 [2] 3 4 ... 10
11
General Computer Issues / Re: scanning and defrag issue
« Last post by kitkat51 on December 14, 2014, 07:59:55 pm »
 :ty will try it
12
After doing these scans, when I reboot my computer Trojan Killer is showing the Adobe Launcher as a threat. It's done this twice. I didn't bother moving it to quarantine because I'd like to know what you think first.

EDIT: Also, AVG Secure Search still shows up when I open a new tab in Firefox no matter what I do.
13
Hoov,
Problem seems to be fixed.
Thanks again for the help.
My father had me make a donation for him so you guys can continue the great work.
--Ed
14
Zoek.exe v5.0.0.0 Updated 14-December-2014
Tool run by Zack on Sun 12/14/2014 at 20:28:01.01.
Microsoft Windows 7 Professional  6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Zack\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

12/14/2014 8:30:44 PM Zoek.exe System Restore Point Created Succesfully.

==== Empty Folders Check ======================

C:\PROGRA~2\Malwarebytes' Anti-Malware deleted successfully
C:\PROGRA~2\MeteorEntertainment deleted successfully
C:\PROGRA~2\Yahoo! deleted successfully
C:\PROGRA~3\Avg_Update_1214av deleted successfully
C:\PROGRA~3\Corel PDF Fusion deleted successfully
C:\PROGRA~3\Malwarebytes' Anti-Malware (portable) deleted successfully
C:\PROGRA~3\{D1D4879F-2279-49C9-AEBF-3B95C84EAA8F} deleted successfully
C:\Users\Zack\AppData\Roaming\Malwarebytes deleted successfully
C:\Users\Zack\AppData\Local\Adobe deleted successfully
C:\Users\Zack\AppData\Local\DriverTuner deleted successfully
C:\Users\Zack\AppData\Local\Solid State Networks deleted successfully
C:\Users\Zack\AppData\Local\WMTools Downloaded Files deleted successfully

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-913676279-1143746095-4277644156-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{78234974-0C4B-4111-BDEB-D9A104418772} deleted successfully
HKEY_USERS\S-1-5-21-913676279-1143746095-4277644156-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{78234974-0C4B-4111-BDEB-D9A104418772} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{78234974-0C4B-4111-BDEB-D9A104418772} deleted successfully

==== Deleting CLSID Registry Values ======================

HKEY_USERS\S-1-5-21-913676279-1143746095-4277644156-1001\Software\Mozilla\Firefox\Extensions\pp@perk.com deleted successfully

==== Running Processes ======================

C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe
C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnWMI.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
C:\Program Files (x86)\Panda USB Vaccine\USBVaccine.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
C:\Program Files (x86)\AVG\AVG2015\avgui.exe
C:\Windows\SysWOW64\ctfmon.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Users\Zack\Desktop\zoek.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\SysWOW64\cmd.exe

==== Deleting Services ======================


==== FireFox Fix ======================

Deleted from C:\Users\Zack\AppData\Roaming\Mozilla\Firefox\Profiles\r7v4bs9j.default\prefs.js:
user_pref("browser.startup.homepage", "google.com");
user_pref("browser.newtab.url", "google.com");
user_pref("keyword.URL", "");

Added to C:\Users\Zack\AppData\Roaming\Mozilla\Firefox\Profiles\r7v4bs9j.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);

==== Deleting Files \ Folders ======================

C:\PROGRA~3\Malwarebytes' Anti-Malware (portable) not found
C:\PROGRA~3\{D1D4879F-2279-49C9-AEBF-3B95C84EAA8F} not found
C:\PROGRA~2\Mozilla Firefox\browser\searchplugins\safeguard-secure-search.xml deleted
C:\PROGRA~2\Media Player Classic - Home Cinema deleted
C:\PROGRA~2\COMMON~1\DVDVideoSoft\bin deleted
C:\PROGRA~2\Wondershare deleted
C:\PROGRA~2\COMMON~1\Wondershare deleted
C:\Users\Zack\AppData\Roaming\Yahoo! deleted
C:\PROGRA~3\Avg_Update_0814tb deleted
C:\PROGRA~3\Avg_Update_1114tb deleted
C:\Users\Zack\AppData\Local\Wondershare deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare deleted
C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow\AVG SafeGuard toolbar deleted
C:\Users\Zack\AppData\Roaming\Mozilla\Firefox\Profiles\r7v4bs9j.default\jetpack deleted

==== System Specs ======================

Windows: Windows 7 Professional Edition (64-bit) Service Pack 1 (Build 7601)
Memory (RAM): 3982 MB
CPU Info: Intel(R) Core(TM) i7-3630QM CPU @ 2.40GHz
CPU Speed: 2435.3 MHz
Sound Card: Speakers (Realtek High Definiti |
Display Adapters: Intel(R) HD Graphics 4000 | Intel(R) HD Graphics 4000 | Intel(R) HD Graphics 4000 | RDPDD Chained DD | RDP Encoder Mirror Driver | RDP Reflector Display Driver
Monitors: 1x; Generic PnP Monitor |
Screen Resolution: 1366 X 768 - 32 bit
Network: Network Present
Network Adapters: Atheros AR9485 Wireless Network Adapter | Realtek PCIe GBE Family Controller
CD / DVD Drives: 1x (E: | ) E: TSSTcorpCDDVDW SN-208BB
Ports: COM Ports NOT Present. LPT Port NOT Present.
Mouse: 16 Button Wheel Mouse Present
Hard Disks: C:  186.3GB | D:  254.1GB
Hard Disks - Free: C:  21.2GB | D:  30.2GB
Manufacturer *: American Megatrends Inc.
BIOS Info: AT/AT COMPATIBLE | 08/20/12 | _ASUS_ - 1072009
Time Zone: Eastern Standard Time
Motherboard *: ASUSTeK COMPUTER INC. K55A
Country: United States
Language: ENU

==== System Specs (Software) ======================

Anti-Virus: AVG AntiVirus Free Edition 2015 On-access scanning disabled (Outdated)
Anti-Spyware: Windows Defender disabled (Outdated)
Anti-Spyware: AVG AntiVirus Free Edition 2015 disabled (Outdated)
Default Browser: Google Chrome   39.0.2171.95
Internet Explorer Version: 11.0.9600.17501
Mozilla Firefox version: 34.0.5 (x86 en-US)
Google Chrome version: 39.0.2171.95
Adobe Reader version: 11.0.10.32
Sun Java version: 1.8.0_25 (32-bit)
Sun Java version: 1.8.0_25 (64-bit)
Flash Player version: 15.0.0.246

==== Files Recently Created / Modified ======================

====== C:\Windows ====
====== C:\Users\Zack\AppData\Local\Temp ====
====== Java Cache =====
====== C:\Windows\SysWOW64 =====
2014-12-10 06:42:05   E8CC0C545A001AA0CAC9789EDE2E4DC9   3981488   ----a-w-   C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2014-12-10 05:28:40   E1456E7396022EBE4E5434188D1AC8B0   1230336   ----a-w-   C:\Windows\SysWOW64\WindowsCodecs.dll
2014-12-10 05:28:33   F98B3860BB47089EA8C1504F043E90E9   342200   ----a-w-   C:\Windows\SysWOW64\iedkcs32.dll
2014-12-10 05:28:33   F34F6DC38A21FCDBB50CDD1EE97B1EA3   1307136   ----a-w-   C:\Windows\SysWOW64\urlmon.dll
2014-12-10 05:28:33   F25284C763E728E4DAC248C211D1FC5B   76288   ----a-w-   C:\Windows\SysWOW64\mshtmled.dll
2014-12-10 05:28:33   D7A98A4CEA2E89F544065A00BF37FC10   688640   ----a-w-   C:\Windows\SysWOW64\msfeeds.dll
2014-12-10 05:28:33   BB25F69463AD8E7E51B5D9D158B5F8DF   30720   ----a-w-   C:\Windows\SysWOW64\iernonce.dll
2014-12-10 05:28:33   69AC6FD5B0B4DC963723E1EBDEE10A2C   285696   ----a-w-   C:\Windows\SysWOW64\dxtrans.dll
2014-12-10 05:28:33   2EADED07BDA52C1FC5A6D4E1CC5858F0   47616   ----a-w-   C:\Windows\SysWOW64\ieetwproxystub.dll
2014-12-10 05:28:33   2ABC5587D582ACCEA30B4CF968C2A4A5   60416   ----a-w-   C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-12-10 05:28:33   220505B0B3E96C857DD01729AF0CD369   19749376   ----a-w-   C:\Windows\SysWOW64\mshtml.dll
2014-12-10 05:28:31   F0BCBD8FCDA145EED53ED66C45CC378B   62464   ----a-w-   C:\Windows\SysWOW64\iesetup.dll
2014-12-10 05:28:31   DEB9476A3CD1A5819DD4504BB7C6BA66   2724864   ----a-w-   C:\Windows\SysWOW64\mshtml.tlb
2014-12-10 05:28:31   41AFA61E061E98E97272AC02184C8C2C   710144   ----a-w-   C:\Windows\SysWOW64\ieapfltr.dll
2014-12-10 05:28:30   EC5A3E4E21079B9D423AA0760828D678   620032   ----a-w-   C:\Windows\SysWOW64\jscript9diag.dll
2014-12-10 05:28:30   543ADCEA31CF9C2B4EEB900D4AAFD0F9   2052096   ----a-w-   C:\Windows\SysWOW64\inetcpl.cpl
2014-12-10 05:28:30   01777AB557997E98691E322225314E57   2277888   ----a-w-   C:\Windows\SysWOW64\iertutil.dll
2014-12-10 05:28:29   759E2FAD5371512C6679FA346719493E   47104   ----a-w-   C:\Windows\SysWOW64\jsproxy.dll
2014-12-10 05:28:28   D90585C3BE942DAAFBDC868FDC061844   115712   ----a-w-   C:\Windows\SysWOW64\ieUnatt.exe
2014-12-10 05:28:27   CF9D05678B02B44FBC8D8AD8C9F30D58   478208   ----a-w-   C:\Windows\SysWOW64\ieui.dll
2014-12-10 05:28:27   35BD045804B67E78F4CAB72CB820AF7F   418304   ----a-w-   C:\Windows\SysWOW64\dxtmsft.dll
2014-12-10 05:28:26   B59E370277EDB6643083B62297175628   12836864   ----a-w-   C:\Windows\SysWOW64\ieframe.dll
2014-12-10 05:28:25   F728E7E9937117E0F32F39840EB6D737   4299264   ----a-w-   C:\Windows\SysWOW64\jscript9.dll
2014-12-10 05:28:25   930F63D6BC43D4BCD937DFCECDA95F82   168960   ----a-w-   C:\Windows\SysWOW64\msrating.dll
2014-12-10 05:28:25   5E4E0E43E0A5BF9F089696DFA7A3D677   1888256   ----a-w-   C:\Windows\SysWOW64\wininet.dll
2014-12-10 05:28:25   37F078B5B435AFC6BF316F2AD14B469A   501248   ----a-w-   C:\Windows\SysWOW64\vbscript.dll
2014-12-10 05:28:25   2E9E105037AC1274656C3D1125323352   1155072   ----a-w-   C:\Windows\SysWOW64\mshtmlmedia.dll
2014-12-10 05:28:25   29CED1A4777A43526A4ED8A7B6936883   64000   ----a-w-   C:\Windows\SysWOW64\MshtmlDac.dll
====== C:\Windows\SysWOW64\drivers =====
====== C:\Windows\Sysnative =====
2014-12-10 05:28:43   A9A0BFD706B3A24C403EEFEB0790D011   1424384   ----a-w-   C:\Windows\Sysnative\WindowsCodecs.dll
2014-12-10 05:28:33   F987718A5CA053DC23E94A531F1754A4   34304   ----a-w-   C:\Windows\Sysnative\iernonce.dll
2014-12-10 05:28:33   D471F7A428C21DB04D810445D12D68E0   48640   ----a-w-   C:\Windows\Sysnative\ieetwproxystub.dll
2014-12-10 05:28:33   9F07E8FC75C5F98A783ABFD3005EFC22   77824   ----a-w-   C:\Windows\Sysnative\JavaScriptCollectionAgent.dll
2014-12-10 05:28:33   39B512C643812FC2D4843C0D4206C759   718848   ----a-w-   C:\Windows\Sysnative\ie4uinit.exe
2014-12-10 05:28:33   0FABE2AB8CA2D5CC7C95798533B4D057   114688   ----a-w-   C:\Windows\Sysnative\ieetwcollector.exe
2014-12-10 05:28:33   077AEB068A51B396F25BBCAB0944FC3A   2724864   ----a-w-   C:\Windows\Sysnative\mshtml.tlb
2014-12-10 05:28:30   E7A2061ADF0F4D430FECDA1E8D6B7BA6   1548288   ----a-w-   C:\Windows\Sysnative\urlmon.dll
2014-12-10 05:28:30   B4E481E9498CE22113628C4E9EA24427   4096   ----a-w-   C:\Windows\Sysnative\ieetwcollectorres.dll
2014-12-10 05:28:30   5BF0BAA1E5EF724287565E97C9219254   389296   ----a-w-   C:\Windows\Sysnative\iedkcs32.dll
2014-12-10 05:28:27   EBC8C9F61F4C148B8C6A28EDE80C51E4   968704   ----a-w-   C:\Windows\Sysnative\MsSpellCheckingFacility.exe
2014-12-10 05:28:27   14BA910E7731FC84EB85328BD0F1EE81   800768   ----a-w-   C:\Windows\Sysnative\msfeeds.dll
2014-12-10 05:28:27   0AF0AEF0BA9EF6169E61C78504DCAE55   316928   ----a-w-   C:\Windows\Sysnative\dxtrans.dll
2014-12-10 05:28:26   EFBA893429814EA3244C87C2D1256618   800768   ----a-w-   C:\Windows\Sysnative\ieapfltr.dll
2014-12-10 05:28:26   3FE71E2A5BD3EC652E64FC8BCEFEDD2C   2125312   ----a-w-   C:\Windows\Sysnative\inetcpl.cpl
2014-12-10 05:28:26   23AE7A3B44D5C550B81347288CE3230E   66560   ----a-w-   C:\Windows\Sysnative\iesetup.dll
2014-12-10 05:28:25   DFECAE6D925FBC9078870E16F98C471F   54784   ----a-w-   C:\Windows\Sysnative\jsproxy.dll
2014-12-10 05:28:25   982B871A25B5078093FAD82D0AB0E3FC   2885120   ----a-w-   C:\Windows\Sysnative\iertutil.dll
2014-12-10 05:28:25   5F24313333AB409251152CAFADA40015   144384   ----a-w-   C:\Windows\Sysnative\ieUnatt.exe
2014-12-10 05:28:24   F7CCA58B973FB5EAED8D1F12DD3E51F6   490496   ----a-w-   C:\Windows\Sysnative\dxtmsft.dll
2014-12-10 05:28:24   8EF01E2EF21D41A23FF70B28179F9ABE   633856   ----a-w-   C:\Windows\Sysnative\ieui.dll
2014-12-10 05:28:24   556D271F4243B273EDA353512BF3608A   14412800   ----a-w-   C:\Windows\Sysnative\ieframe.dll
2014-12-10 05:28:23   DB10D681314714E0D4623E4C0CF6654A   92160   ----a-w-   C:\Windows\Sysnative\mshtmled.dll
2014-12-10 05:28:23   7AC115968B8856004920057B2271224C   1359360   ----a-w-   C:\Windows\Sysnative\mshtmlmedia.dll
2014-12-10 05:28:23   021DFF3CB0ADCD19B3AAA00A650FDEE2   814080   ----a-w-   C:\Windows\Sysnative\jscript9diag.dll
2014-12-10 05:28:22   8D64466AD12CA5677CD0099C43C58569   6039552   ----a-w-   C:\Windows\Sysnative\jscript9.dll
2014-12-10 05:28:22   89296EF4A3729A049DA25B7D67A04078   199680   ----a-w-   C:\Windows\Sysnative\msrating.dll
2014-12-10 05:28:22   4AF089160FE082E5EA5C4AA72782DCA2   2358272   ----a-w-   C:\Windows\Sysnative\wininet.dll
2014-12-10 05:28:22   1D294810D3A8A8F722E86AA001F54DCC   580096   ----a-w-   C:\Windows\Sysnative\vbscript.dll
2014-12-10 05:28:22   17A157A4225CF562202AC71DB8103177   88064   ----a-w-   C:\Windows\Sysnative\MshtmlDac.dll
2014-12-10 05:28:21   D478A4CF07FB8ADF72FB16B88E8030B8   25059840   ----a-w-   C:\Windows\Sysnative\mshtml.dll
====== C:\Windows\Sysnative\drivers =====
2014-12-05 15:25:04   F8C46A0B35C94C2FDACB50463D883A35   17568   ----a-w-   C:\Windows\Sysnative\drivers\gtkdrv.sys
====== C:\Windows\Tasks ======
====== C:\Windows\Temp ======
======= C:\Program Files =====
======= C:\PROGRA~2 =====
2014-12-15 01:09:14   --------   d-----w-   C:\PROGRA~2\COMMON~1\Java
2014-12-15 01:04:33   --------   d-----w-   C:\PROGRA~2\COMMON~1\Adobe
2014-12-15 01:04:33   --------   d-----w-   C:\PROGRA~2\Adobe
======= C: =====
2014-12-08 03:01:19   8D987BE841B404B83E6CE18C33C44C88   55   ----a-w-   C:\AdwCleanerDebug.txt
====== C:\Users\Zack\AppData\Roaming ======
2014-12-09 04:19:59   --------   d-sh--w-   C:\Users\Zack\AppData\Locallow\EmieBrowserModeList
2014-12-09 04:17:00   --------   d-sh--w-   C:\Users\Zack\AppData\Local\EmieBrowserModeList
====== C:\Users\Zack ======
2014-12-15 01:25:03   F783EC309D42813F74319EB776153B2B   165376   ----a-w-   C:\Users\Zack\Desktop\SystemLook_x64.exe
2014-12-08 18:02:36   788FCDDD88240A85039F7F561093B118   448512   ----a-w-   C:\Users\Zack\Desktop\TFC.exe
2014-12-08 03:31:23   4EF3D33B04CFC213F194A9C5A15E749E   2119168   ----a-w-   C:\Users\Zack\Desktop\FRST64.exe
2014-12-08 03:19:34   4DEDE96BD568BD11DC92C6D893666E1E   32507072   ----a-w-   C:\Users\Zack\Desktop\Windows-KB890830-x64-V5.18.exe
2014-12-08 03:13:06   C254F3ECEB9B1AC795BA6B25DE008EBA   1707646   ----a-w-   C:\Users\Zack\Desktop\JRT.exe
2014-12-08 03:00:24   AF506E0B71016682293AC3814A7D62BA   2153472   ----a-w-   C:\Users\Zack\Desktop\AdwCleaner.exe

====== C: exe-files ==
2014-12-15 01:25:16   ABA5454313C35929E0C72AA81D21FCB2   544   ----a-w-   C:\$RECYCLE.BIN\S-1-5-21-913676279-1143746095-4277644156-1001\$IAX9ZVL.exe
2014-12-15 01:08:16   E3E6B18458FFB07CB24D7A0BA77C9FDF   15784   ----a-w-   C:\Program Files (x86)\Java\jre1.8.0_25\bin\pack200.exe
2014-12-15 01:08:16   DC197DCE6325CBAC905DE0D0E3BA3E8E   15784   ----a-w-   C:\Program Files (x86)\Java\jre1.8.0_25\bin\rmid.exe
2014-12-15 01:08:16   BB8C890E3E6372F2720709262BD42BF4   30632   ----a-w-   C:\Program Files (x86)\Java\jre1.8.0_25\bin\jabswitch.exe
2014-12-15 01:08:16   B719E0F43166037DF46B5CFBE60A5118   15784   ----a-w-   C:\Program Files (x86)\Java\jre1.8.0_25\bin\jjs.exe
2014-12-15 01:08:16   AA3520FB0133A56BEE1DB34D74DBEF64   176552   ----a-w-   C:\Program Files (x86)\Java\jre1.8.0_25\bin\java.exe
2014-12-15 01:08:16   A458E2535E46151690E53E2A03FAA711   15784   ----a-w-   C:\Program Files (x86)\Java\jre1.8.0_25\bin\keytool.exe
2014-12-15 01:08:16   9BFAEF308D50779F6B255CB7BA7DCA5A   15784   ----a-w-   C:\Program Files (x86)\Java\jre1.8.0_25\bin\kinit.exe
2014-12-15 01:08:16   7AB1F1B3FB6C3DACA34EA2F988CDF5AC   16296   ----a-w-   C:\Program Files (x86)\Java\jre1.8.0_25\bin\orbd.exe
2014-12-15 01:08:16   75EE99C7F0038C746D82C76221ECA4EF   16296   ----a-w-   C:\Program Files (x86)\Java\jre1.8.0_25\bin\policytool.exe
2014-12-15 01:08:16   75D477E868CA51EC1B09D730570F322B   176552   ----a-w-   C:\Program Files (x86)\Java\jre1.8.0_25\bin\javaw.exe
2014-12-15 01:08:16   74713E9C1B01B152DDD3A1A3519A3647   15784   ----a-w-   C:\Program Files (x86)\Java\jre1.8.0_25\bin\java-rmi.exe
2014-12-15 01:08:16   70E67429D2C011FD0419AF899A8D0D70   68520   ----a-w-   C:\Program Files (x86)\Java\jre1.8.0_25\bin\javacpl.exe
2014-12-15 01:08:16   691D49FB44EDE9788288CABE4F7E0DAF   272296   ----a-w-   C:\Program Files (x86)\Java\jre1.8.0_25\bin\javaws.exe
2014-12-15 01:08:16   67F763B09F4BC8689E6FA9761E068D74   159656   ----a-w-   C:\Program Files (x86)\Java\jre1.8.0_25\bin\unpack200.exe
2014-12-15 01:08:16   57E1F756FAA787623DFCD2C1B2AACC68   51112   ----a-w-   C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssvagent.exe
2014-12-15 01:08:16   4367C05B0CF5553E71B34F51003D0615   76200   ----a-w-   C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2launcher.exe
2014-12-15 01:08:16   4109C4DB4BD48F5BF8115C7523A6B6F8   15784   ----a-w-   C:\Program Files (x86)\Java\jre1.8.0_25\bin\klist.exe
2014-12-15 01:08:16   33D2AF53E209DA3E2BA939EB89801DC0   16296   ----a-w-   C:\Program Files (x86)\Java\jre1.8.0_25\bin\rmiregistry.exe
2014-12-15 01:08:16   29E65AC6AFD8A0A9CAA361FF6F7B4886   16296   ----a-w-   C:\Program Files (x86)\Java\jre1.8.0_25\bin\servertool.exe
2014-12-15 01:08:16   28FC00F89631B0F6E1E9CA386FADD566   16296   ----a-w-   C:\Program Files (x86)\Java\jre1.8.0_25\bin\tnameserv.exe
2014-12-15 01:08:16   26C7F32186B1F0364CD06EA69227A79D   15784   ----a-w-   C:\Program Files (x86)\Java\jre1.8.0_25\bin\ktab.exe
2014-12-15 01:07:08   3A582BF6FD39DC6A52AAF316126B40BA   638888   ----a-w-   C:\$RECYCLE.BIN\S-1-5-21-913676279-1143746095-4277644156-1001\$RAX9ZVL.exe
2014-12-11 17:16:08   7543EB509DCAAD14441E6D6E1A9D815C   80008   ----a-w-   C:\Program Files\Microsoft Silverlight\5.1.31211.0\coregen.exe
2014-12-11 17:16:08   6368E5F574AAA4F005D44A0E0F10BA66   523920   ----a-w-   C:\Program Files\Microsoft Silverlight\sllauncher.exe
2014-12-11 17:16:08   48344819D332CD91444DB4684BF30CF9   304816   ----a-w-   C:\Program Files\Microsoft Silverlight\5.1.31211.0\Silverlight.Configuration.exe
2014-12-11 17:16:08   0249C742BD0AE0F70C9A1E82D00E0D96   17544   ----a-w-   C:\Program Files\Microsoft Silverlight\5.1.31211.0\agcp.exe
2014-12-11 16:53:12   B76732459011D66823BC19318409E162   237232   ----a-w-   C:\Program Files (x86)\Microsoft Silverlight\5.1.31211.0\Silverlight.Configuration.exe
2014-12-11 16:53:12   9DDBAFE6EA118A0AFBA2AE79A673778E   16520   ----a-w-   C:\Program Files (x86)\Microsoft Silverlight\5.1.31211.0\agcp.exe
2014-12-11 16:53:12   937A5E0B86C60CDFA83BD0CCB66CE4FD   68744   ----a-w-   C:\Program Files (x86)\Microsoft Silverlight\5.1.31211.0\coregen.exe
2014-12-11 16:53:12   40B5F7A9ABE0BF6AD9CDC53418B33642   387216   ----a-w-   C:\Program Files (x86)\Microsoft Silverlight\sllauncher.exe
2014-12-10 05:28:33   A8A8FD02E3A9264A603892DE1F522166   221184   ----a-w-   C:\Program Files (x86)\Internet Explorer\ielowutil.exe
2014-12-10 05:28:30   B7BCC767AC0E76384BCDC292184DD8C8   222720   ----a-w-   C:\Program Files\Internet Explorer\ielowutil.exe
2014-12-10 05:28:30   A24BFBAE8B50A6780B68FF3673FAB52F   815280   ----a-w-   C:\Program Files (x86)\Internet Explorer\iexplore.exe
2014-12-10 05:28:30   43CE0C99DBC0F96DB2B7259B0BE0930E   468992   ----a-w-   C:\Program Files (x86)\Internet Explorer\ieinstal.exe
2014-12-10 05:28:26   C3D17F3199D39A2AB85956A63731F188   484352   ----a-w-   C:\Program Files\Internet Explorer\ieinstal.exe
2014-12-10 05:28:25   2A9DA9E7462EBA3F6D2036E8D18FF773   813744   ----a-w-   C:\Program Files\Internet Explorer\iexplore.exe
2014-12-10 03:29:07   450BDEE760894CE151404E41819E964F   1097808   ----a-w-   C:\Program Files (x86)\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\39.0.2171.95\39.0.2171.95_39.0.2171.71_chrome_updater.exe
2014-12-10 02:33:48   D3AC8B90796EE8EF3B91465664F634A6   7141064   ----a-w-   C:\Program Files (x86)\AVG\AVG2015\Notification\Launcher.exe
=== C: other files ==
2014-12-15 01:08:16   CE44A9D4918DCDC7CCCF5503BF4D7A3D   14130   ----a-w-   C:\Program Files (x86)\Java\jre1.8.0_25\lib\deploy\ffjcext.zip
2014-12-08 20:30:03   AC8E0E28D993898E7759279543A450AD   14160   ----a-w-   C:\Users\Zack\AppData\Roaming\Mozilla\Firefox\Profiles\r7v4bs9j.default\extensions\CNT@ednovak.net.xpi
2014-12-08 19:44:28   BCF28E2D5A6163FD355DA377980C194A   4292   ----a-w-   C:\ProgramData\GridinSoft\Trojan Killer\storage\419816142149421.zip
2014-12-08 19:44:28   446761A76D64E91EA24049D0F202EF82   14444   ----a-w-   C:\ProgramData\GridinSoft\Trojan Killer\storage\419816142158449.zip
2014-12-08 02:21:57   134357BED7B211D56A80D67C1C7236B9   28667   ----a-w-   C:\ProgramData\GridinSoft\Trojan Killer\storage\419808902492014.zip
2014-12-08 02:21:56   F0013076EDB9ABEDEDDFB50FFB226D1D   17170   ----a-w-   C:\ProgramData\GridinSoft\Trojan Killer\storage\419808902370718.zip
2014-12-08 02:21:55   43AE5516C6AC683C06515E30FC7599BC   12236   ----a-w-   C:\ProgramData\GridinSoft\Trojan Killer\storage\419808902248958.zip

==== Startup Registry Enabled ======================

[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"

[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"

[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"

[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"

[HKEY_USERS\S-1-5-21-913676279-1143746095-4277644156-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG_UI"="C:\Program Files (x86)\AVG\AVG2015\avgui.exe /TRAYONLY"
"Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]

==== Startup Registry Enabled x64 ======================

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe"
"RTHDVCPL"="C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s"
"IgfxTray"="C:\Windows\system32\igfxtray.exe"

==== Startup Registry Disabled ======================

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run-]
"Sidebar"="C:\\Program Files\\Windows Sidebar\\sidebar.exe /autoRun"


[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run-]
"iTunesHelper"="\"C:\\Program Files (x86)\\iTunes\\iTunesHelper.exe\""
"Adobe Reader Speed Launcher"="\"C:\\Program Files (x86)\\Adobe\\Reader 10.0\\Reader\\Reader_sl.exe\""
"APSDaemon"="\"C:\\Program Files (x86)\\Common Files\\Apple\\Apple Application Support\\APSDaemon.exe\""
"Adobe ARM"="\"C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe\""
"ACMON"="C:\\Program Files (x86)\\ASUS\\Splendid\\ACMON.exe"
"ASUS Screen Saver Protector"="C:\\Windows\\AsScrPro.exe"
"ATKMEDIA"="C:\\Program Files (x86)\\ASUS\\ATK Package\\ATK Media\\DMedia.exe"
"DivXUpdate"="\"C:\\Program Files (x86)\\DivX\\DivX Update\\DivXUpdate.exe\" /CHECKNOW"
"QuickTime Task"="\"C:\\Program Files (x86)\\QuickTime\\QTTask.exe\" -atboottime"
"SunJavaUpdateSched"="\"C:\\Program Files (x86)\\Common Files\\Java\\Java Update\\jusched.exe\""
"Wondershare Helper Compact.exe"="C:\\Program Files (x86)\\Common Files\\Wondershare\\Wondershare Helper Compact\\WSHelper.exe"


==== Startup Registry Disabled x64 ======================

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\LogMeIn Hamachi Ui]
"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="LogMeIn Hamachi Ui"
"hkey"="HKLM"
"command"="\"C:\\Program Files (x86)\\LogMeIn Hamachi\\hamachi-2-ui.exe\" --auto-start"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Skype]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Skype"
"hkey"="HKCU"
"command"="\"C:\\Program Files (x86)\\Skype\\Phone\\Skype.exe\" /minimized /regrun"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\uTorrent]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="uTorrent"
"hkey"="HKCU"
"command"="\"C:\\Users\\Zack\\AppData\\Roaming\\uTorrent\\uTorrent.exe\"  /MINIMIZED"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Yontoo Desktop]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Yontoo Desktop"
"hkey"="HKCU"
"command"="\"C:\\Users\\Zack\\AppData\\Roaming\\Yontoo\\YontooDesktop.exe\""


[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run-]
"ASUS Quick Gesture (x86)"="C:\\Program Files (x86)\\ASUS\\ASUS Smart Gesture\\QuickGesture\\x86\\QuickGesture.exe"
"ASUS Quick Gesture (x64)"="C:\\Program Files (x86)\\ASUS\\ASUS Smart Gesture\\QuickGesture\\x64\\QuickGesture64.exe"
"ASUS TP Center (x64)"="C:\\Program Files (x86)\\ASUS\\ASUS Smart Gesture\\AsTPCenter\\x64\\AsusTPCenter.exe"
"XboxStat"="\"C:\\Program Files\\Microsoft Xbox 360 Accessories\\XboxStat.exe\" silentrun"


==== Task Scheduler Jobs ======================

C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [12/10/2014 01:42 AM]
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ [Undetermined Task]
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [04/27/2013 05:51 PM]

==== Other Scheduled Tasks ======================

"C:\Windows\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe]
"C:\Windows\SysNative\tasks\ASUS Live Update" [C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe]
"C:\Windows\SysNative\tasks\ASUS P4G" [C:\Program Files\ASUS\P4G\BatteryLife.exe]
"C:\Windows\SysNative\tasks\ASUS SmartLogon Console Sensor" [C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe]
"C:\Windows\SysNative\tasks\ASUS USB Charger Plus" ["C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe"]
"C:\Windows\SysNative\tasks\ASUS Wireless Console 3" [C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe]
"C:\Windows\SysNative\tasks\ATKOSD2" [C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe]
"C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe]
"C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe]
"C:\Windows\SysNative\tasks\Java(TM) Platform SE Auto Updater" [C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe]
"C:\Windows\SysNative\tasks\PandaUSBVaccine" ["C:\Program Files (x86)\Panda USB Vaccine\RunInteractiveWin.exe"]
"C:\Windows\SysNative\tasks\SidebarExecute" [C:\Program Files\Windows Sidebar\sidebar.exe]
"C:\Windows\SysNative\tasks\Trojan Killer" ["C:\Program Files\GridinSoft Trojan Killer\trojankiller.exe"]
"C:\Windows\SysNative\tasks\TuneUpUtilities_Task_BkGndMaintenance2013" [C:\Program Files (x86)\AVG\AVG PC TuneUp\OneClick.exe]
"C:\Windows\SysNative\tasks\{20377ED7-3D29-420D-948D-4141EEACA34F}" ["c:\program files (x86)\google\chrome\application\chrome.exe"]
"C:\Windows\SysNative\tasks\{BA49A9B8-AA33-4436-AAD1-A6104277D668}" ["c:\program files (x86)\google\chrome\application\chrome.exe"]
"C:\Windows\SysNative\tasks\Apple\AppleSoftwareUpdate" [C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe]

==== Firefox Extensions ======================

ProfilePath: C:\Users\Zack\AppData\Roaming\Mozilla\Firefox\Profiles\r7v4bs9j.default
- Undetermined - artur.dubovoy@gmail.com
- Flash Video Downloader - YouTube HD Download [4K] - %ProfilePath%\extensions\artur.dubovoy@gmail.com
- Custom New Tab - %ProfilePath%\extensions\CNT@ednovak.net.xpi
- ExHentai Easy 2 - %ProfilePath%\extensions\jid1-7NbXi2AqS1oUFw@jetpack.xpi
- Adblock Edge - %ProfilePath%\extensions\{fe272bd1-5f76-4ea4-8501-a05d35d823fc}.xpi

AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

==== Firefox Plugins ======================

Profilepath: C:\Users\Zack\AppData\Roaming\Mozilla\Firefox\Profiles\r7v4bs9j.default
9860727E477F17B88E39AF8B69B0407A   - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_246.dll -   Shockwave Flash


==== Chromium Look ======================

Google Chrome Version: 39.0.2171.95 (Up to date, latest Stable version: 39.0.2171.95)


AdBlock - Zack\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom
NTR - Zack\AppData\Local\Google\Chrome\User Data\Default\Extensions\icpgjfneehieebagbmdbhnlpiopdcmna

==== Chromium Fix ======================

C:\Users\Zack\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_media.mtvnservices.com_0.localstorage deleted successfully

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{84826FE9-117F-453A-B87D-6E19895168C3}"
{012E1000-F331-11DB-8314-0800200C9A66} Google  Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Unknown  Url="Not_Found"
{84826FE9-117F-453A-B87D-6E19895168C3} Google  Url="https://www.google.com/search?q={searchTerms}"

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-913676279-1143746095-4277644156-1001\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} deleted successfully

==== Deleting CLSID Registry Values ======================


==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yontoo Desktop deleted successfully

==== HijackThis Entries ======================

F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2015\avgui.exe" /TRAYONLY
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\RunOnce: [Adobe Speed Launcher] 1418606546
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{B8594177-8815-4E1B-9D1F-E4F340E512BE}: NameServer = 184.172.114.130,208.43.110.90
O17 - HKLM\System\CCS\Services\Tcpip\..\{F9205CE0-11F9-4E16-8724-AB577FD654D0}: NameServer = 184.172.114.130,208.43.110.90
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 184.172.114.130,208.43.110.90
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 184.172.114.130,208.43.110.90
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 184.172.114.130,208.43.110.90
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Protocol: WSIEChrome - (no CLSID) - (no file)
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: ASLDR Service (ASLDRService) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ASUS InstantOn Service (ASUS InstantOn) - ASUS - C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files (x86)\Canon\CAL\CALMAIN.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: AVG PC TuneUp Service (TuneUp.UtilitiesSvc) - AVG Technologies - C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Zack\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\32H5UWFV will be deleted at reboot
C:\Users\Zack\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F5XTM81W will be deleted at reboot
C:\Users\Zack\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LNFWWJMH will be deleted at reboot

==== Empty FireFox Cache ======================

No FireFox Cache found

==== Empty Chrome Cache ======================

C:\Users\Zack\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=1305 folders=103 417882910 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\TEMP\AppData\Local\Temp emptied successfully
C:\Users\TEMP.Zack-PC\AppData\Local\Temp emptied successfully
C:\Users\Zack\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\Zack\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\Users\Zack\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\32H5UWFV" not found
"C:\Users\Zack\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F5XTM81W" not found
"C:\Users\Zack\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LNFWWJMH" not found

==== EOF on Sun 12/14/2014 at 20:51:20.40 ======================
15
SystemLook 30.07.11 by jpshortstuff
Log created at 20:25 on 14/12/2014 by Zack
Administrator - Elevation successful

========== regfind ==========

Searching for "*AVG-Secure-Search*"
No data found.

-= EOF =-
16
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 14-12-2014 01
Ran by Zack at 2014-12-14 20:18:27 Run:1
Running from C:\Users\Zack\Desktop
Loaded Profile: Zack (Available profiles: Zack)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
start
U4 Yontoo Desktop Updater; No ImagePath
Task: {9260343F-7DC1-4920-A46A-3876F4F94A49} - System32\Tasks\1214avUpdateInfo => C:\ProgramData\Avg_Update_1214av\1214av_AVG-Secure-Search-Update.exe [2014-10-26] ()
C:\ProgramData\Avg_Update_1214av\1214av_AVG-Secure-Search-Update.exe
Task: C:\Windows\Tasks\1214avUpdateInfo.job => C:\ProgramData\Avg_Update_1214av\1214av_AVG-Secure-Search-Update.exe
AlternateDataStreams: C:\ProgramData\Temp:8CE646EE
EmptyTemp:
end



*****************

Yontoo Desktop Updater => Service deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9260343F-7DC1-4920-A46A-3876F4F94A49}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9260343F-7DC1-4920-A46A-3876F4F94A49}" => Key deleted successfully.
C:\Windows\System32\Tasks\1214avUpdateInfo => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\1214avUpdateInfo" => Key deleted successfully.
C:\ProgramData\Avg_Update_1214av\1214av_AVG-Secure-Search-Update.exe => Moved successfully.
C:\Windows\Tasks\1214avUpdateInfo.job => Moved successfully.
C:\ProgramData\Temp => ":8CE646EE" ADS removed successfully.
EmptyTemp: => Removed 693.4 MB temporary data.


The system needed a reboot.

==== End of Fixlog ====
17
Post Here for Malware Removal ... / Re: [In Progress] MS Defender will not start or reload
« Last post by Hoov on December 14, 2014, 03:11:43 pm »
You are welcome.
18
Okay, thanks very much Hoov. I really appreciate your help.
19
Post Here for Malware Removal ... / Re: [In Progress] MS Defender will not start or reload
« Last post by Hoov on December 14, 2014, 01:14:52 pm »
Microsoft Security Essentials has defender as part of it. So when you install and run Microsoft Security Essentials the standalone version of Defender gets turned off.

Go ahead and run the computer normally for a day, making sure to reboot a couple times during that day. If all is well, then we will do some cleanup and call this done.
20
That seems to have worked. I haven't seen the popup about genuine windows. When I downloaded and activated the MSE program during the middle of this process did it disable Defender? Defender shows it is turned off and when I try to turn it on I get the same timeout message. MSE is showing on and all green.
Pages: 1 [2] 3 4 ... 10