1. Welcome Guest! In order to create a new topic or reply to an existing one, you must register first. It is easy and free. Click here to sign up now!.
    Dismiss Notice

[Solved] Malware check plz

Discussion in 'Malware Removal Help' started by Just-Me, Feb 26, 2015.

  1. Just-Me

    Just-Me Registered Members

    Joined:
    Mar 2, 2014
    Messages:
    117
    Operating System:
    Windows 7
    If I need 64 bit...why does it say 32 bit on the comman window? that is why I had said I tried the 64 bit and thought maybe I should have 32 instead, but none of them worked for me anyhow..LOL
     
  2. Just-Me

    Just-Me Registered Members

    Joined:
    Mar 2, 2014
    Messages:
    117
    Operating System:
    Windows 7
    I finally got it to work for me...phewww


    Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 29-02-2015
    Ran by SYSTEM on MININT-LFK396V on 01-03-2015 11:50:01
    Running from G:\
    Platform: Windows 7 Home Premium (X64) OS Language: English (United States)
    Internet Explorer Version 11
    Boot Mode: Recovery

    The current controlset is ControlSet001
    ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log.

    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

    ==================== Registry (Whitelisted) ==================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [7938080 2009-07-23] (Realtek Semiconductor)
    HKLM\...\Run: [Skytel] => C:\Program Files\Realtek\Audio\HDA\Skytel.exe [1833504 2009-07-23] (Realtek Semiconductor Corp.)
    HKLM\...\Run: [Apoint] => C:\Program Files\Apoint\Apoint.exe [208384 2009-08-03] (Alps Electric Co., Ltd.)
    HKLM\...\Run: [IAAnotif] => C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-06-04] (Intel Corporation)
    HKLM\...\Run: [LXCFCATS] => rundll32 C:\Windows\system32\spool\DRIVERS\x64\3\LXCFtime.dll,RunDLLEntry
    HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
    HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-02-13] (Apple Inc.)
    HKLM-x32\...\Run: [LaunchUserRequestedPrograms] => C:\Program Files\Sony\First Experience\Miniprogram.exe [68608 2009-08-26] ()
    HKLM-x32\...\Run: [RegistrationReminder] => C:\Program Files\Sony\First Experience\OOBEFcdRegistration.exe [268288 2009-07-13] (Sony Electronics, Inc.)
    HKLM-x32\...\Run: [ISBMgr.exe] => C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe [317288 2009-05-26] (Sony Corporation)
    HKLM-x32\...\Run: [StartCCC] => c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2009-07-10] (Advanced Micro Devices, Inc.)
    HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5227112 2015-01-26] (AVAST Software)
    HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
    Winlogon\Notify\VESWinlogon-x32: VESWinlogon.dll [X]
    HKU\Lila\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2014-11-21] (Apple Inc.)
    HKU\Lila\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [7780120 2015-01-27] (SUPERAntiSpyware)
    HKU\Lila\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [43816 2014-11-21] (Apple Inc.)

    ==================== Services (Whitelisted) =================

    (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

    S2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-07-22] (SUPERAntiSpyware.com)
    S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
    S2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-20] (Apple Inc.)
    S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-11-09] (AVAST Software)
    S2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [104416 2014-11-09] (AVAST Software)
    S2 lxcf_device; C:\Windows\system32\lxcfcoms.exe [566192 2007-02-23] ( )
    S2 lxcf_device; C:\Windows\SysWOW64\lxcfcoms.exe [537520 2007-02-23] ( )
    S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
    S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
    S3 Roxio UPnP Renderer 10; C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe [313840 2009-06-26] (Sonic Solutions)
    S2 Roxio Upnp Server 10; C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe [362992 2009-06-26] (Sonic Solutions)
    S2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [189984 2009-07-23] (Realtek Semiconductor)
    S3 SampleCollector; C:\Program Files\Sony\VAIO Care\collsvc.exe [167424 2008-09-29] (Intel Corporation)
    S3 SOHDBSvr; C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe [70952 2009-07-27] (Sony Corporation)
    S3 SOHPlMgr; C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe [91432 2009-07-27] (Sony Corporation)
    S2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.)
    S3 VAIO Entertainment TV Device Arbitration Service; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe [69632 2009-07-23] (Sony Corporation)
    S2 VCFw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [642920 2009-07-22] (Sony Corporation)
    S3 Vcsw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe [313264 2009-07-23] (Sony Corporation)
    S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

    ==================== Drivers (Whitelisted) ====================

    (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

    S3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.)
    S2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-11-09] ()
    S1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [28184 2014-11-09] (AVAST Software)
    S2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [83280 2014-11-09] (AVAST Software)
    S0 aswNdisFlt; C:\Windows\System32\DRIVERS\aswNdisFlt.sys [449936 2014-11-09] (AVAST Software)
    S1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-11-09] (AVAST Software)
    S0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-11-09] ()
    S1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1050432 2014-11-21] (AVAST Software)
    S1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436624 2014-11-09] (AVAST Software)
    S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [116728 2014-11-09] (AVAST Software)
    S0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [267632 2014-11-09] ()
    S1 ElRawDisk; C:\Windows\system32\drivers\rsdrvx64.sys [26024 2009-02-12] (EldoS Corporation)
    S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
    S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-03-01] (Malwarebytes Corporation)
    S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-11-21] (Malwarebytes Corporation)
    S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [27520 2007-05-14] (Research In Motion Limited)
    S2 risdptsk; C:\Windows\system32\DRIVERS\risdsn64.sys [76288 2009-07-31] (REDC)
    S1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
    S1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)

    ==================== NetSvcs (Whitelisted) ===================

    (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


    ==================== One Month Created Files and Folders ========

    (If an entry is included in the fixlist, the file\folder will be moved.)

    2015-03-01 13:17 - 2015-03-01 12:45 - 00059392 _____ () C:\Users\Lila\Documents\BillyLila.14f.backup
    2015-03-01 12:45 - 2015-03-01 13:21 - 00059392 _____ () C:\Users\Lila\Documents\BillyLila.14f
    2015-02-28 12:18 - 2015-02-28 12:18 - 00000000 ____D () C:\Users\Lila\AppData\Roaming\BHOK IT Consulting
    2015-02-28 12:17 - 2015-02-28 12:17 - 00000000 ____D () C:\Users\Lila\AppData\Roaming\BHOK
    2015-02-28 12:17 - 2015-02-28 12:17 - 00000000 ____D () C:\Users\Lila\AppData\Local\IsolatedStorage
    2015-02-28 12:15 - 2015-02-28 12:15 - 00002202 _____ () C:\Users\Public\Desktop\StudioTax Enterprise 2014.lnk
    2015-02-28 12:14 - 2015-02-28 12:14 - 00000000 ____D () C:\Program Files (x86)\BHOK IT Consulting
    2015-02-28 11:59 - 2015-02-28 11:59 - 29775408 _____ (BHOK IT Consulting) C:\Users\Lila\Desktop\StudioTaxEnt14Install.exe
    2015-02-26 19:22 - 2015-02-26 19:24 - 00000000 ____D () C:\AdwCleaner
    2015-02-26 19:11 - 2015-03-01 11:50 - 00000000 ____D () C:\FRST
    2015-02-26 08:54 - 2015-02-26 08:54 - 00000088 _____ () C:\Users\Lila\Desktop\hhd feb 25.txt
    2015-02-26 00:31 - 2015-01-08 18:44 - 00419936 _____ () C:\Windows\SysWOW64\locale.nls
    2015-02-26 00:31 - 2015-01-08 18:43 - 00419936 _____ () C:\Windows\System32\locale.nls
    2015-02-25 21:25 - 2015-02-26 19:21 - 00000781 _____ () C:\Users\Lila\Desktop\extra page.txt
    2015-02-24 18:57 - 2015-02-24 18:57 - 00000877 _____ () C:\Users\Lila\Desktop\SWITSUITS.txt
    2015-02-21 17:09 - 2015-02-21 17:09 - 00001713 _____ () C:\Users\Public\Desktop\iTunes.lnk
    2015-02-21 17:08 - 2015-02-21 17:09 - 00000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
    2015-02-21 17:08 - 2015-02-21 17:09 - 00000000 ____D () C:\Program Files\iTunes
    2015-02-21 17:08 - 2015-02-21 17:08 - 00000000 ____D () C:\Program Files (x86)\iTunes
    2015-02-18 14:08 - 2015-02-18 14:08 - 00000402 _____ () C:\Users\Lila\Desktop\Dr. Information for surgery.txt
    2015-02-18 02:03 - 2015-02-26 16:55 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2015-02-18 02:03 - 2015-02-26 16:55 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
    2015-02-15 14:15 - 2015-01-08 22:14 - 00950272 _____ (Microsoft Corporation) C:\Windows\System32\perftrack.dll
    2015-02-15 14:15 - 2015-01-08 22:14 - 00091136 _____ (Microsoft Corporation) C:\Windows\System32\wdi.dll
    2015-02-15 14:15 - 2015-01-08 22:14 - 00029696 _____ (Microsoft Corporation) C:\Windows\System32\powertracker.dll
    2015-02-15 14:15 - 2015-01-08 21:48 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdi.dll
    2015-02-12 09:12 - 2015-01-22 23:42 - 00814080 _____ (Microsoft Corporation) C:\Windows\System32\jscript9diag.dll
    2015-02-12 09:12 - 2015-01-22 23:41 - 06041600 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll
    2015-02-12 09:12 - 2015-01-22 22:43 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
    2015-02-12 09:12 - 2015-01-22 22:17 - 04300800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2015-02-11 08:22 - 2015-02-03 22:16 - 00894976 _____ (Microsoft Corporation) C:\Windows\System32\appraiser.dll
    2015-02-11 08:22 - 2015-02-03 22:16 - 00762368 _____ (Microsoft Corporation) C:\Windows\System32\invagent.dll
    2015-02-11 08:22 - 2015-02-03 22:16 - 00609280 _____ (Microsoft Corporation) C:\Windows\System32\generaltel.dll
    2015-02-11 08:22 - 2015-02-03 22:16 - 00414720 _____ (Microsoft Corporation) C:\Windows\System32\devinv.dll
    2015-02-11 08:22 - 2015-02-03 22:16 - 00227328 _____ (Microsoft Corporation) C:\Windows\System32\aepdu.dll
    2015-02-11 08:22 - 2015-02-03 22:16 - 00192000 _____ (Microsoft Corporation) C:\Windows\System32\aepic.dll
    2015-02-11 08:22 - 2015-02-03 22:13 - 01098752 _____ (Microsoft Corporation) C:\Windows\System32\aeinv.dll
    2015-02-11 08:22 - 2015-01-27 18:36 - 01239720 _____ (Microsoft Corporation) C:\Windows\System32\aitstatic.exe
    2015-02-11 08:22 - 2015-01-10 01:48 - 00728064 _____ (Microsoft Corporation) C:\Windows\System32\kerberos.dll
    2015-02-11 08:22 - 2015-01-10 01:48 - 00341504 _____ (Microsoft Corporation) C:\Windows\System32\schannel.dll
    2015-02-11 08:22 - 2015-01-10 01:48 - 00314880 _____ (Microsoft Corporation) C:\Windows\System32\msv1_0.dll
    2015-02-11 08:22 - 2015-01-10 01:48 - 00309760 _____ (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
    2015-02-11 08:22 - 2015-01-10 01:48 - 00210944 _____ (Microsoft Corporation) C:\Windows\System32\wdigest.dll
    2015-02-11 08:22 - 2015-01-10 01:48 - 00086528 _____ (Microsoft Corporation) C:\Windows\System32\TSpkg.dll
    2015-02-11 08:22 - 2015-01-10 01:48 - 00022016 _____ (Microsoft Corporation) C:\Windows\System32\credssp.dll
    2015-02-11 08:22 - 2015-01-10 01:27 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
    2015-02-11 08:22 - 2015-01-10 01:27 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
    2015-02-11 08:22 - 2015-01-10 01:27 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
    2015-02-11 08:22 - 2015-01-10 01:27 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
    2015-02-11 08:22 - 2015-01-10 01:27 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
    2015-02-11 08:22 - 2015-01-10 01:27 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
    2015-02-11 08:22 - 2015-01-10 01:27 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
    2015-02-11 08:21 - 2015-01-14 00:47 - 00389808 _____ (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
    2015-02-11 08:21 - 2015-01-14 00:09 - 00342712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
    2015-02-11 08:21 - 2015-01-11 22:09 - 25056256 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll
    2015-02-11 08:21 - 2015-01-11 22:05 - 02724864 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
    2015-02-11 08:21 - 2015-01-11 22:05 - 00004096 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollectorres.dll
    2015-02-11 08:21 - 2015-01-11 21:49 - 00066560 _____ (Microsoft Corporation) C:\Windows\System32\iesetup.dll
    2015-02-11 08:21 - 2015-01-11 21:48 - 02885632 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll
    2015-02-11 08:21 - 2015-01-11 21:48 - 00584192 _____ (Microsoft Corporation) C:\Windows\System32\vbscript.dll
    2015-02-11 08:21 - 2015-01-11 21:48 - 00048640 _____ (Microsoft Corporation) C:\Windows\System32\ieetwproxystub.dll
    2015-02-11 08:21 - 2015-01-11 21:47 - 00088064 _____ (Microsoft Corporation) C:\Windows\System32\MshtmlDac.dll
    2015-02-11 08:21 - 2015-01-11 21:40 - 00054784 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
    2015-02-11 08:21 - 2015-01-11 21:39 - 00034304 _____ (Microsoft Corporation) C:\Windows\System32\iernonce.dll
    2015-02-11 08:21 - 2015-01-11 21:36 - 00633856 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll
    2015-02-11 08:21 - 2015-01-11 21:34 - 00144384 _____ (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
    2015-02-11 08:21 - 2015-01-11 21:34 - 00114688 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollector.exe
    2015-02-11 08:21 - 2015-01-11 21:25 - 19740160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2015-02-11 08:21 - 2015-01-11 21:25 - 00968704 _____ (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
    2015-02-11 08:21 - 2015-01-11 21:21 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2015-02-11 08:21 - 2015-01-11 21:21 - 00490496 _____ (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll
    2015-02-11 08:21 - 2015-01-11 21:13 - 00077824 _____ (Microsoft Corporation) C:\Windows\System32\JavaScriptCollectionAgent.dll
    2015-02-11 08:21 - 2015-01-11 21:08 - 00503296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
    2015-02-11 08:21 - 2015-01-11 21:08 - 00199680 _____ (Microsoft Corporation) C:\Windows\System32\msrating.dll
    2015-02-11 08:21 - 2015-01-11 21:07 - 00092160 _____ (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
    2015-02-11 08:21 - 2015-01-11 21:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
    2015-02-11 08:21 - 2015-01-11 21:07 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
    2015-02-11 08:21 - 2015-01-11 21:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
    2015-02-11 08:21 - 2015-01-11 21:04 - 00316928 _____ (Microsoft Corporation) C:\Windows\System32\dxtrans.dll
    2015-02-11 08:21 - 2015-01-11 21:02 - 02277888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2015-02-11 08:21 - 2015-01-11 21:00 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2015-02-11 08:21 - 2015-01-11 20:59 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
    2015-02-11 08:21 - 2015-01-11 20:57 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2015-02-11 08:21 - 2015-01-11 20:55 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
    2015-02-11 08:21 - 2015-01-11 20:48 - 00801280 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
    2015-02-11 08:21 - 2015-01-11 20:48 - 00718848 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
    2015-02-11 08:21 - 2015-01-11 20:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
    2015-02-11 08:21 - 2015-01-11 20:46 - 01359360 _____ (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll
    2015-02-11 08:21 - 2015-01-11 20:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
    2015-02-11 08:21 - 2015-01-11 20:43 - 14401024 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll
    2015-02-11 08:21 - 2015-01-11 20:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
    2015-02-11 08:21 - 2015-01-11 20:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
    2015-02-11 08:21 - 2015-01-11 20:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
    2015-02-11 08:21 - 2015-01-11 20:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
    2015-02-11 08:21 - 2015-01-11 20:27 - 02358272 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll
    2015-02-11 08:21 - 2015-01-11 20:23 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2015-02-11 08:21 - 2015-01-11 20:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
    2015-02-11 08:21 - 2015-01-11 20:22 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
    2015-02-11 08:21 - 2015-01-11 20:14 - 12829184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2015-02-11 08:21 - 2015-01-11 20:14 - 01548288 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll
    2015-02-11 08:21 - 2015-01-11 20:02 - 00800768 _____ (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll
    2015-02-11 08:21 - 2015-01-11 20:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2015-02-11 08:21 - 2015-01-11 19:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2015-02-11 08:21 - 2015-01-11 19:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
    2015-02-11 08:20 - 2015-01-15 03:14 - 00155072 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
    2015-02-11 08:20 - 2015-01-15 03:14 - 00095680 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
    2015-02-11 08:20 - 2015-01-15 03:09 - 01461760 _____ (Microsoft Corporation) C:\Windows\System32\lsasrv.dll
    2015-02-11 08:20 - 2015-01-15 03:09 - 00136192 _____ (Microsoft Corporation) C:\Windows\System32\sspicli.dll
    2015-02-11 08:20 - 2015-01-15 03:09 - 00031232 _____ (Microsoft Corporation) C:\Windows\System32\lsass.exe
    2015-02-11 08:20 - 2015-01-15 03:09 - 00029184 _____ (Microsoft Corporation) C:\Windows\System32\sspisrv.dll
    2015-02-11 08:20 - 2015-01-15 03:09 - 00028160 _____ (Microsoft Corporation) C:\Windows\System32\secur32.dll
    2015-02-11 08:20 - 2015-01-15 03:08 - 00064000 _____ (Microsoft Corporation) C:\Windows\System32\auditpol.exe
    2015-02-11 08:20 - 2015-01-15 03:06 - 00146432 _____ (Microsoft Corporation) C:\Windows\System32\msaudite.dll
    2015-02-11 08:20 - 2015-01-15 03:06 - 00060416 _____ (Microsoft Corporation) C:\Windows\System32\msobjs.dll
    2015-02-11 08:20 - 2015-01-15 03:04 - 00686080 _____ (Microsoft Corporation) C:\Windows\System32\adtschema.dll
    2015-02-11 08:20 - 2015-01-15 02:42 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
    2015-02-11 08:20 - 2015-01-15 02:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
    2015-02-11 08:20 - 2015-01-15 02:41 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
    2015-02-11 08:20 - 2015-01-15 02:39 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
    2015-02-11 08:20 - 2015-01-15 02:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
    2015-02-11 08:20 - 2015-01-15 02:37 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
    2015-02-11 08:20 - 2015-01-14 23:22 - 00458824 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
    2015-02-11 08:20 - 2015-01-12 22:10 - 01424384 _____ (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll
    2015-02-11 08:20 - 2015-01-12 21:49 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
    2015-02-11 08:19 - 2014-12-12 00:31 - 01480192 _____ (Microsoft Corporation) C:\Windows\System32\crypt32.dll
    2015-02-11 08:19 - 2014-12-12 00:07 - 01174528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
    2015-02-11 08:19 - 2014-11-25 22:53 - 00861696 _____ (Microsoft Corporation) C:\Windows\System32\oleaut32.dll
    2015-02-11 08:19 - 2014-11-25 22:32 - 00571904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
    2015-02-11 08:17 - 2015-01-14 01:09 - 05554112 _____ (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
    2015-02-11 08:17 - 2015-01-14 01:05 - 00503808 _____ (Microsoft Corporation) C:\Windows\System32\srcore.dll
    2015-02-11 08:17 - 2015-01-14 01:05 - 00050176 _____ (Microsoft Corporation) C:\Windows\System32\srclient.dll
    2015-02-11 08:17 - 2015-01-14 01:04 - 00296960 _____ (Microsoft Corporation) C:\Windows\System32\rstrui.exe
    2015-02-11 08:17 - 2015-01-14 00:44 - 03972544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
    2015-02-11 08:17 - 2015-01-14 00:44 - 03917760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
    2015-02-11 08:17 - 2015-01-14 00:41 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
    2015-02-11 08:17 - 2014-12-07 22:09 - 00406528 _____ (Microsoft Corporation) C:\Windows\System32\scesrv.dll
    2015-02-11 08:17 - 2014-12-07 21:46 - 00308224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scesrv.dll
    2015-02-11 08:16 - 2015-01-08 21:03 - 03201536 _____ (Microsoft Corporation) C:\Windows\System32\win32k.sys

    ==================== One Month Modified Files and Folders =======

    (If an entry is included in the fixlist, the file\folder will be moved.)

    2015-03-01 13:44 - 2014-02-13 14:59 - 01980904 _____ () C:\Windows\WindowsUpdate.log
    2015-03-01 13:36 - 2014-02-18 20:45 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
    2015-03-01 13:23 - 2014-04-12 17:27 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\System32\Drivers\MBAMSwissArmy.sys
    2015-03-01 13:14 - 2014-04-11 19:49 - 00000000 ____D () C:\Users\Lila\Desktop\Zips not extracted
    2015-03-01 10:46 - 2014-02-17 15:49 - 00000000 ____D () C:\Users\Lila\Documents\My PSP Files
    2015-03-01 09:52 - 2014-04-11 19:35 - 00000000 ___RD () C:\Users\Lila\Desktop\TagsForGroup
    2015-03-01 08:09 - 2014-02-13 16:27 - 00121928 _____ () C:\Users\Lila\AppData\Local\GDIPFONTCACHEV1.DAT
    2015-03-01 08:01 - 2014-02-16 21:07 - 00000000 ____D () C:\Program Files (x86)\SpywareBlaster
    2015-03-01 08:01 - 2014-02-16 19:03 - 00000000 ____D () C:\ProgramData\TEMP
    2015-03-01 07:55 - 2009-07-13 23:45 - 00018928 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2015-03-01 07:55 - 2009-07-13 23:45 - 00018928 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2015-03-01 07:53 - 2014-10-22 04:53 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware
    2015-03-01 07:53 - 2014-02-18 20:45 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
    2015-03-01 07:44 - 2015-01-14 00:57 - 00066098 _____ () C:\Windows\PFRO.log
    2015-03-01 07:44 - 2015-01-14 00:57 - 00008130 _____ () C:\Windows\setupact.log
    2015-03-01 07:44 - 2009-07-14 00:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
    2015-03-01 00:18 - 2014-10-27 21:18 - 00000508 _____ () C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 96c5fce4-a01b-485f-b6d9-56d70aaf19a1.job
    2015-03-01 00:14 - 2014-10-27 21:18 - 00000508 _____ () C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 5dc701af-7193-4fc8-8cc2-be40302ad012.job
    2015-02-28 22:28 - 2014-12-06 01:35 - 00000508 _____ () C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 00ef3d56-5f6a-43cb-8e10-6e30adb3dc2d.job
    2015-02-28 20:13 - 2014-02-13 16:52 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
    2015-02-28 19:00 - 2014-10-27 21:18 - 00000508 _____ () C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 14b8d3fb-378f-4cf5-8f82-282b0e4bad21.job
    2015-02-28 18:47 - 2014-03-06 10:20 - 00000000 ____D () C:\users\Bill
    2015-02-28 17:19 - 2015-01-17 16:21 - 00000000 ____D () C:\Users\Lila\Desktop\Downloaded Scrapkits
    2015-02-28 13:11 - 2014-04-16 07:32 - 00000000 ____D () C:\Program Files\Lx_cats
    2015-02-28 00:59 - 2009-07-13 23:45 - 00377336 _____ () C:\Windows\System32\FNTCACHE.DAT
    2015-02-27 15:20 - 2009-07-14 00:13 - 00781790 _____ () C:\Windows\System32\PerfStringBackup.INI
    2015-02-24 13:34 - 2015-01-05 23:59 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
    2015-02-24 07:24 - 2014-02-13 16:27 - 00000000 ____D () C:\Users\Lila\AppData\Local\VirtualStore
    2015-02-21 17:08 - 2014-03-06 09:18 - 00000000 ____D () C:\Program Files\iPod
    2015-02-21 17:08 - 2014-02-17 14:32 - 00000000 ____D () C:\Program Files\Common Files\Apple
    2015-02-15 15:54 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\tracing
    2015-02-15 14:24 - 2014-02-19 16:05 - 00766100 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
    2015-02-15 14:00 - 2014-09-14 20:23 - 00732996 _____ () C:\test.xml
    2015-02-13 13:01 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\rescache
    2015-02-12 08:55 - 2014-12-10 03:15 - 00000000 ____D () C:\Windows\System32\appraiser
    2015-02-12 08:55 - 2014-04-23 06:15 - 00000000 ___SD () C:\Windows\System32\CompatTel
    2015-02-12 01:07 - 2014-02-13 19:54 - 00000000 ____D () C:\Windows\System32\MRT
    2015-02-12 01:02 - 2014-02-13 19:53 - 116773704 _____ (Microsoft Corporation) C:\Windows\System32\MRT.exe
    2015-02-06 17:30 - 2014-02-18 20:45 - 00003894 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
    2015-02-06 17:30 - 2014-02-18 20:45 - 00003642 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
    2015-02-03 10:00 - 2014-02-16 21:44 - 00000000 ____D () C:\Users\Lila\Desktop\Utilities
    2015-01-31 22:51 - 2014-04-11 19:50 - 00000000 ____D () C:\Users\Lila\Desktop\Forum Info & Passwords
    2015-01-31 22:29 - 2014-12-06 01:35 - 00003584 _____ () C:\Windows\System32\Tasks\SUPERAntiSpyware Scheduled Task 00ef3d56-5f6a-43cb-8e10-6e30adb3dc2d
    2015-01-30 02:21 - 2014-02-16 17:19 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service

    ==================== Known DLLs (Whitelisted) ================


    ==================== Bamital & volsnap Check =================

    (There is no automatic fix for files that do not pass verification.)

    C:\Windows\System32\winlogon.exe => MD5 is legit
    C:\Windows\System32\wininit.exe => MD5 is legit
    C:\Windows\SysWOW64\wininit.exe => MD5 is legit
    C:\Windows\explorer.exe => MD5 is legit
    C:\Windows\SysWOW64\explorer.exe => MD5 is legit
    C:\Windows\System32\svchost.exe => MD5 is legit
    C:\Windows\SysWOW64\svchost.exe => MD5 is legit
    C:\Windows\System32\services.exe => MD5 is legit
    C:\Windows\System32\User32.dll => MD5 is legit
    C:\Windows\SysWOW64\User32.dll => MD5 is legit
    C:\Windows\System32\userinit.exe => MD5 is legit
    C:\Windows\SysWOW64\userinit.exe => MD5 is legit
    C:\Windows\System32\rpcss.dll => MD5 is legit
    C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

    ==================== Restore Points =========================

    Restore point made on: 2015-02-24 06:31:21
    Restore point made on: 2015-02-26 00:31:20
    Restore point made on: 2015-02-28 12:14:29

    ==================== Memory info ===========================

    Percentage of memory in use: 15%
    Total physical RAM: 4063.02 MB
    Available physical RAM: 3428.54 MB
    Total Pagefile: 4061.17 MB
    Available Pagefile: 3416.61 MB
    Total Virtual: 8192 MB
    Available Virtual: 8191.9 MB

    ==================== Drives ================================

    Drive c: () (Fixed) (Total:457.98 GB) (Free:401.81 GB) NTFS
    Drive e: (Recovery) (Fixed) (Total:7.68 GB) (Free:0.83 GB) NTFS ==>[System with boot components (obtained from reading drive)]
    Drive g: () (Removable) (Total:7.45 GB) (Free:1.28 GB) FAT32
    Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
    Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: D1667CB9)
    Partition 1: (Not Active) - (Size=7.7 GB) - (Type=27)
    Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
    Partition 3: (Not Active) - (Size=458 GB) - (Type=07 NTFS)

    ========================================================
    Disk: 1 (Size: 7.5 GB) (Disk ID: 00000000)

    Partition: GPT Partition Type.


    LastRegBack: 2015-02-23 09:49

    ==================== End Of Log ============================
     
  3. Just-Me

    Just-Me Registered Members

    Joined:
    Mar 2, 2014
    Messages:
    117
    Operating System:
    Windows 7
    ummmm what happened to my post with FRST. I worked and I posted the results and now my post is gone from here. I came back last night to see if you had answered me and it was still here, but its gone now.. :eek:((
    guess I will have to do it over again. I'm not imagining it. I know it was posted here. would it be possible someone deleted it?
     
  4. Just-Me

    Just-Me Registered Members

    Joined:
    Mar 2, 2014
    Messages:
    117
    Operating System:
    Windows 7

    ahhhh it popped up after I posted this message LOL I thought I was going insane.
     
  5. etavares

    etavares Malware Removal Specialist - Moderator

    Joined:
    Aug 6, 2011
    Messages:
    259
    Location:
    USA (GMT -5)
    You got it, Nice work! Unfortunately, I'm not seeing anything in the extra information that log provided that will easily explain the redirects across multiple browers. If it was only Chrome, we could diagnose extensions/add-ins, but if it's FF too, then it's something at a deeper level. Where do the popups send you to? (please don't post a link, just something like google.com is enough for me to dig in a bit more.

    -etavares
     
  6. Just-Me

    Just-Me Registered Members

    Joined:
    Mar 2, 2014
    Messages:
    117
    Operating System:
    Windows 7
    the pages that pop up are health pages. one of the was Dr. Oz lol about losing weight. maybe my computer is trying to tell me something ahahaha
    well if you can't see anything I don't know what to do. maybe I will just back everything up to my external and go back to factory settings. I forget how to do that its been a couple of years since I did it last. I can google I guess. or can you tell me which key to use or is it best to use my rescue disks?
     
  7. Just-Me

    Just-Me Registered Members

    Joined:
    Mar 2, 2014
    Messages:
    117
    Operating System:
    Windows 7
    hi I got this messsage from a donetao, but don't see it here. not sure why I am not seeing the messages until I post. is this the way this forum works?
    what is this ExTS all about:


    From donetao
    Hi! I don't want to start any trouble here on ExTS. Would you consider running this software?? Sense you have been cleared by our malware team, before you format and restore back to factory, give it a try.
     
  8. allheart55 (Cindy E)

    allheart55 (Cindy E) Administrator Administrator

    Joined:
    Jun 11, 2009
    Messages:
    10,495
    Location:
    Pennsylvania
    Operating System:
    Windows 10
    Computer Brand or Motherboard:
    ASUS M4A77TD AM3 AMD 770 ATX AMD
    CPU:
    AMD Phenom II X6 1090T-Thuban 3.2GHz
    Memory:
    Crucial-DDR3 SDRAM 1333-8GB
    Hard Drive:
    WD Caviar Black SE HDD 640 GB - WD Caviar Black SE HDD 500 GB
    Graphics Card:
    Sapphire Radeon HD-7870 2GB
    Power Supply:
    CORSAIR CMPSU-750W
    First, I apologize for interrupting the cleaning process. Please disregard that post, it has been removed from the board.

    The member, donetao, posted that in your other thread, http://computerhelpforums.net/threads/pages-popping-up.43386/

    I removed it from the forum because it interferes with your cleaning process being done by our malware expert, Etavares.

    Again, my apologies.
     
  9. Just-Me

    Just-Me Registered Members

    Joined:
    Mar 2, 2014
    Messages:
    117
    Operating System:
    Windows 7
    thank you for replying. will wait to see what is next.
    have a great day
     
  10. etavares

    etavares Malware Removal Specialist - Moderator

    Joined:
    Aug 6, 2011
    Messages:
    259
    Location:
    USA (GMT -5)
    OK, I clearly missed some posts here while I was at work!

    Let's move onto a couple quick automated scans. Let's start with adwCleaner. We're just going to scan here, not remove until we see what/if it detects anything.

    Please download AdwCleaner by Xplode and save to your Desktop.
    • Double click on AdwCleaner.exe to run the tool.Vista/Windows7/8 users right-click andselectRun As Administrator[/*]
    • The tool will start to update the database, please wait a bit.[/*]
    • Click on I agree button.[/*]
    • Click on the Scan button.[/*]
    • AdwCleaner will begin...be patient as the scan may take some time to complete.[/*]
    • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).[/*]
    • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.[/*]
    • Copy and paste the contents of that logfile in your next reply.[/*]
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.[/*]

    -etavares
     
    Cats-4_Owners-2 likes this.
  11. Just-Me

    Just-Me Registered Members

    Joined:
    Mar 2, 2014
    Messages:
    117
    Operating System:
    Windows 7
    Here is the scan for AdwCleaner. I didn't have it fix anything cause I am not sure what this program is all about and I see C:\Windows\System32\drivers\rsdrvx64.sys and don't know what it is.



    # AdwCleaner v4.111 - Logfile created 04/03/2015 at 09:18:24
    # Updated 18/02/2015 by Xplode
    # Database : 2015-03-02.3 [Server]
    # Operating system : Windows 7 Home Premium Service Pack 1 (x64)
    # Username : Lila - LILA-VAIO
    # Running from : C:\Users\Lila\Desktop\adwcleaner_4.111.exe
    # Option : Scan

    ***** [ Services ] *****


    ***** [ Files / Folders ] *****

    File Found : C:\Windows\System32\drivers\rsdrvx64.sys

    ***** [ Scheduled tasks ] *****

    Task Found : UpdaterEX

    ***** [ Shortcuts ] *****


    ***** [ Registry ] *****

    Data Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.local

    ***** [ Web browsers ] *****

    -\\ Internet Explorer v11.0.9600.17631


    -\\ Mozilla Firefox v36.0 (x86 en-US)


    -\\ Google Chrome v40.0.2214.115

    *************************

    AdwCleaner[R6].txt - [1250 bytes] - [26/02/2015 17:22:30]
    AdwCleaner[R7].txt - [1176 bytes] - [04/03/2015 09:11:55]
    AdwCleaner[R8].txt - [958 bytes] - [04/03/2015 09:18:24]

    ########## EOF - C:\AdwCleaner\AdwCleaner[R8].txt - [1016 bytes] ##########
     
  12. etavares

    etavares Malware Removal Specialist - Moderator

    Joined:
    Aug 6, 2011
    Messages:
    259
    Location:
    USA (GMT -5)
    Hi,

    I'm glad you just scanned as I asked and didn't fix it, the log is clean and that is a legitimate file. :)

    Let's try the second scan:

    Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Post the contents of JRT.txt into your next message.
     
  13. Just-Me

    Just-Me Registered Members

    Joined:
    Mar 2, 2014
    Messages:
    117
    Operating System:
    Windows 7
    here is the scan results

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Junkware Removal Tool (JRT) by Thisisu
    Version: 6.4.3 (03.01.2015:1)
    OS: Windows 7 Home Premium x64
    Ran by Lila on 03/04/2015 at 21:58:00.32
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




    ~~~ Services



    ~~~ Registry Values



    ~~~ Registry Keys

    Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\util findright



    ~~~ Files



    ~~~ Folders

    Successfully deleted: [Folder] "C:\Users\Lila\AppData\Roaming\software informer"



    ~~~ Event Viewer Logs were cleared





    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Scan was completed on 03/04/2015 at 22:07:21.95
    End of JRT log
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
     
  14. etavares

    etavares Malware Removal Specialist - Moderator

    Joined:
    Aug 6, 2011
    Messages:
    259
    Location:
    USA (GMT -5)
    Hi,

    OK, nothing there\ that was active. Just leftovers it looks like were removed before.

    So, let's try this. Launch Chrome. Open a new incognito window by Pressing Ctrl-Shift-N while in Chrome. This will open a new incognito window which doesn't load plug ins. Browse for a while...did you get any popups?

    -etavares
     
  15. Just-Me

    Just-Me Registered Members

    Joined:
    Mar 2, 2014
    Messages:
    117
    Operating System:
    Windows 7
    ok did as you said and yes I got pop up pages.
     
  16. etavares

    etavares Malware Removal Specialist - Moderator

    Joined:
    Aug 6, 2011
    Messages:
    259
    Location:
    USA (GMT -5)
    OK, sorry for the delay, I went through all the logs again and nothing is standing out as illegitimate and actively running. There are a few leftovers from a previous infection, so let's take care of those and see how it runs after that.

    Download attached fixlist.txt file and save it to the same place on your computer where you originally saved FRST. (Not the one on the flash drive, the original scan you ran when you posted here). E.g., if FRST is on your desktop, then save fixlist.txt to your desktop.

    NOTE. It's important that both files, FRST64 and fixlist.txt are in the same location or the fix will not work.

    NOTICE:This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Run FRST64 and press the Fix button just once and wait.If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run. When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

    -etavares
     

    Attached Files:

  17. Just-Me

    Just-Me Registered Members

    Joined:
    Mar 2, 2014
    Messages:
    117
    Operating System:
    Windows 7
    Ok here is the log. I am not rushing you here, but I have to have this completed by the end of next week. I have surgery and won't be around for quite awhile. is there much more to do? I will come back later on and let you know if I am still getting the pop up windows. thanks for your help once again. I really so appreciate you helping me and saving me tons of money. if I have to reformat I will do that after I am all healed up.
    have a great day


    Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 08-03-2015 03
    Ran by Lila at 2015-03-09 05:57:30 Run:1
    Running from C:\Users\Lila\Desktop
    Loaded Profiles: Lila (Available profiles: Lila)
    Boot Mode: Normal
    ==============================================

    Content of fixlist:
    *****************
    Winlogon\Notify\VESWinlogon-x32: VESWinlogon.dll [X]
    CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
    SearchScopes: HKLM-x32 -> DefaultScope value is missing.
    BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> No File
    Task: {BDC6DBD5-D786-473A-A5F8-5105C75E5EE3} - \{DEA80C2E-DC22-4722-AD6E-00BDC96E508C} No Task File <==== ATTENTION
    Task: {DF033E57-2DA6-40FC-A921-22382CAF85F4} - \UpdaterEX No Task File <==== ATTENTION
    AlternateDataStreams: C:\ProgramData\TEMP:5C321E34
    AlternateDataStreams: C:\ProgramData\TEMP:DDCCB2FA
    CMD: ipconfig /flushdns
    EmptyTemp:
    *****************

    "HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\VESWinlogon" => Key deleted successfully.
    "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully.
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
    "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}" => Key deleted successfully.
    "HKCR\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9}" => Key deleted successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BDC6DBD5-D786-473A-A5F8-5105C75E5EE3}" => Key deleted successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BDC6DBD5-D786-473A-A5F8-5105C75E5EE3}" => Key deleted successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{DEA80C2E-DC22-4722-AD6E-00BDC96E508C}" => Key deleted successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DF033E57-2DA6-40FC-A921-22382CAF85F4}" => Key deleted successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DF033E57-2DA6-40FC-A921-22382CAF85F4}" => Key deleted successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\UpdaterEX" => Key deleted successfully.
    C:\ProgramData\TEMP => ":5C321E34" ADS removed successfully.
    C:\ProgramData\TEMP => ":DDCCB2FA" ADS removed successfully.

    ========= ipconfig /flushdns =========


    Windows IP Configuration

    Successfully flushed the DNS Resolver Cache.

    ========= End of CMD: =========

    EmptyTemp: => Removed 130.3 MB temporary data.


    The system needed a reboot.

    ==== End of Fixlog 05:57:53 ====
     
  18. etavares

    etavares Malware Removal Specialist - Moderator

    Joined:
    Aug 6, 2011
    Messages:
    259
    Location:
    USA (GMT -5)
    That ran well and did what it was supposed to, I'm assuming you still have pop ups? I hope surgery goes well. Given the logs and scans aren't showing anything, the second opinion I've asked for agrees that nothing is evident, if this was my computer I would restore to factory settings after a backup of your irreplaceable documents.

    -etavares
     
  19. Just-Me

    Just-Me Registered Members

    Joined:
    Mar 2, 2014
    Messages:
    117
    Operating System:
    Windows 7
    hi I am home from surgery and am only on machine now. pretty sore still so won't be online alot for next couple of weeks. I noticed error message a couple of times when I started machine up to update my programs. the error message would pop up. what is this? ty
     

    Attached Files:

  20. Just-Me

    Just-Me Registered Members

    Joined:
    Mar 2, 2014
    Messages:
    117
    Operating System:
    Windows 7
    well that strange. I was in here last week and someone told me to uninstall my SuperAntiSpyware and then reinstall it. am I going insane?
    anyhow I have done it and am wondering what was wrong with it to begin with?
    thank you
     

Share This Page