Vervolg.
MBAm file
\SystemRoot\System32\smss.exe
c:\PROGRA~2\AVG\AVG2014\avgrsa.exe /boot
C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe /pipeName=5e44ff76-7bcb-4d6f-8752-b21cc724ca3d /coreSdkOptions=4382 /logConfFile=“C:\Windows\system32\config\systemprofile\AppData\Local\Avg2014\temp\92780571-bf53-4008-9016-112368c4b03d-1c4-oopp.tmp” /loggerName=AVG.RS.Core /binaryPath=“C:\Program Files (x86)\AVG\AVG2014\” /tempPath=“C:\Windows\system32\config\systemprofile\AppData\Local\Avg2014\temp\” /logPath=“C:\Windows\system32\config\systemprofile\AppData\Local\Avg2014\log\”
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
“C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe”
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
atieclxx
C:\Windows\system32\WLANExt.exe 24431392
\??\C:\Windows\system32\conhost.exe "-5573892111645965021-831605534-9374211545841874072042178313-1393005651841329432
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
“C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe”
“C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe”
“taskhost.exe”
“C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe”
“C:\Windows\system32\Dwm.exe”
C:\Windows\Explorer.EXE
“C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE”
taskeng.exe {B96A5C8F-77E6-493D-9ECA-FAC3BDD1B071}
“C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE”
“C:\Program Files\Software Informer\softinfo.exe” -service
“C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe” -servicelaunch=true
C:\Windows\SysWOW64\svchost.exe -k netsvcs
“C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe”
“C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe”
“C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler64.exe”
“C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe”
“C:\Program Files (x86)\AVG\AVG2014\avgemca.exe”
“c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe”
“C:\Program Files (x86)\Sitecom\Common\RegistryWriter.exe”
“C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe”
C:\Windows\system32\svchost.exe -k imgsvc
C:\Users\Erika\AppData\Local\Torch\Update\TorchCrashHandler.exe
“C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe”
C:\Windows\servicing\TrustedInstaller.exe
“C:\Windows\System32\WUDFHost.exe” -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-06d5b808-2c43-43d0-9df7-b00d1ee917ce -SystemEventPortName:HostProcess-e44ee93a-b14c-4ca5-b8f7-88dfa6f72314 -IoCancelEventPortName:HostProcess-9434a70d-1d56-4264-9edc-6436cebba728 -NonStateChangingEventPortName:HostProcess-804be77b-99fd-486b-b263-2e5f1efd1e48 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:6156a174-6fe2-41da-a67c-a96fb0b7afbd -DeviceGroupId:WpdFsGroup
taskeng.exe {4E6FB0E8-150C-4095-B1B3-181058F091B1}
C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding
“c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe”
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchIndexer.exe /Embedding
“C:\Program Files\Logitech\SetPointP\SetPoint.exe” /launchGaming
“C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe”
“C:\Program Files\HP\HP Photosmart 6510 series\Bin\ScanToPCActivationApp.exe” -deviceID “CN19F411SS05QB:NW” -scfn “HP Photosmart 6510 series (NET)” -AutoStart 1
“C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe”
“C:\Users\Erika\AppData\Local\TNS NIPO Clicks\TNS NIPO Clicks.exe”
“C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe”
“C:\Program Files (x86)\Sitecom\Common\RaUI.exe” -s
“C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe”
“C:\Program Files (x86)\Datacolor\Spyder3Elite\Utility\Spyder3Utility.exe”
“C:\Users\Erika\AppData\Roaming\Dropbox\bin\Dropbox.exe” /systemstartup
KHALMNPR.EXE /API
“C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe” –showwindow=false –onOSstartup=true
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
“C:\Program Files\Windows Media Player\wmpnetwk.exe”
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
“C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe” “-launchedbyvulcan”
“C:\Program Files (x86)\AVG\AVG2014\avgui.exe” /TRAYONLY
“C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe”
ctfmon.exe
“C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe” –type=renderer –no-sandbox –lang=en-US –lang=en-US –log-severity=disable –channel=“3260.0.1997986149\146130368” /prefetch:3
“C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe”
“C:\Program Files (x86)\Mozilla Firefox\firefox.exe”
“F:\RSITx64.exe”
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
=========Mozilla firefox=========
ProfilePath - C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default
prefs.js - “browser.search.useDBForOrder” - “false”
prefs.js - “extensions.enabledItems” - “{a55c4ab0-ac89-4352-a750-98552a6a9337}:1.0, avg@igeared:6.103.018.001, DeviceDetection@logitech.com:1.21.0.11, {195A3098-0BD5-4e90-AE22-BA1C540AFD1E}:2.9.3, {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22, {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23, {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24, {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:10.0.0.1209, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17”
“Description”=Adobe® Flash® Player 14.0.0.145 Plugin
“Path”=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll
“Description”=Adobe Shockwave Player
“Path”=C:\Windows\SysWOW64\Adobe\Director\np32dsw_1211151.dll
“Description”=Garmin GPS Control for Firefox
“Path”=C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll
“Description”=Google Earth in your browser
“Path”=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
“Description”=Java™ Deployment Toolkit
“Path”=C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll
“Description”=Oracle® Next Generation Java™ Plug-In
“Path”=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
“Description”=
“Path”=disabled
“Description”=Ag Player Plugin
“Path”=c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll
“Description”=Google Update
“Path”=C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll
“Description”=Google Update
“Path”=C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll
“Description”=Zylom Games Player 1.00
“Path”=C:\ProgramData\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
“Description”=Handles PDFs in-place in Firefox
“Path”=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
“Description”=
“Path”=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll
“Description”=
“Path”=C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll
“Description”=VLC Multimedia Plugin
“Path”=C:\Users\Erika\AppData\Local\Torch\Plugins\Video\VLC\npvlc.dll
“Description”=Adobe® Flash® Player 14.0.0.145 Plugin
“Path”=C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll
“Description”=Garmin GPS Control for Firefox
“Path”=C:\Program Files\Garmin GPS Plugin\npGarmin.dll
“Description”=
“Path”=disabled
“Description”=Ag Player Plugin
“Path”=c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll
“Description”=
“Path”=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll
“Description”=
“Path”=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll
“Description”=
“Path”=C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\Win64Plugin\npAdobeExManDetectX64.dll
C:\Program Files (x86)\Mozilla Firefox\plugins\
ILnsp110.log
ILnsp120.log
NPCltInst11.dll
NPCltInst121.dll
nppdf32.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
QuickTimePlugin.class
C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\extensions\
DeviceDetection@logitech.com
kaiyu.25q@yewnlduyeygpb.org
{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}-trash
{ab91efd4-6975-4081-8552-1b3922ed79e2}
======Registry dump======
Logitech SetPoint - C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll
Java™ Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
Logitech SetPoint - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll
Bing Bar Helper - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll
Java™ Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
TNS NIPO Clicks - C:\Users\Erika\AppData\Local\Wakoopa Shared\WakoopaBHO.dll
{ae07101b-46d4-4a98-af68-0333ea26e113}
{ae07101b-46d4-4a98-af68-0333ea26e113}
{8dcb7100-df86-4384-8842-8fa844297b3f} - Bing Bar - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll
“AdobeAAMUpdater-1.0”=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe
“Logitech Download Assistant”=C:\Windows\System32\LogiLDA.dll
“EvtMgr6”=C:\Program Files\Logitech\SetPointP\SetPoint.exe
“NCPluginUpdater”=C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe
“HP Photosmart 6510 series (NET)”=C:\Program Files\HP\HP Photosmart 6510 series\Bin\ScanToPCActivationApp.exe
“GarminExpressTrayApp”=C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe
“TNS NIPO Clicks”=C:\Users\Erika\AppData\Local\TNS NIPO Clicks\TNS NIPO Clicks.exe
“AVG-Secure-Search-Update_1213b”=C:\Users\Erika\AppData\Roaming\AVG 1213b Campaign\AVG-Secure-Search-Update-1213b.exe /PROMPT /mid=8da9f4b0987847d392c69128c064797a-b1ab53bf69ee3d56e0b68fecf6a63d5566bf3245 /CMPID=1213b
C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe
C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\ReaderAppHelper.exe
C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatchTray10.exe
C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
“hpsysdrv”=c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe
“IAStorIcon”=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
“StartCCC”=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
“SwitchBoard”=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
“AdobeCS6ServiceManager”=C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe
“Adobe ARM”=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
“APSDaemon”=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
“QuickTime Task”=C:\Program Files (x86)\QuickTime\QTTask.exe
“Adobe Creative Cloud”=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
“AVG_UI”=C:\Program Files (x86)\AVG\AVG2014\avgui.exe
“SunJavaUpdateSched”=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Sitecom Wireless Utility.lnk - C:\Program Files (x86)\Sitecom\Common\RaUI.exe
Spyder3Utility.lnk - C:\Program Files (x86)\Datacolor\Spyder3Elite\Utility\Spyder3Utility.exe
C:\Users\Erika\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Dropbox.lnk - C:\Users\Erika\AppData\Roaming\Dropbox\bin\Dropbox.exe
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
“{E54729E8-BB3D-4270-9D49-7389EA579090}”=C:\Windows\SysWow64\EZUPBH~1.DLL
“SecurityProviders”=credssp.dll
“ConsentPromptBehaviorAdmin”=5
“ConsentPromptBehaviorUser”=3
“EnableUIADesktopToggle”=0
“PromptOnSecureDesktop”=0
“dontdisplaylastusername”=0
“legalnoticecaption”=
“legalnoticetext”=
“shutdownwithoutlogon”=1
“undockwithoutlogon”=1
“NoActiveDesktop”=1
“NoActiveDesktopChanges”=1
“ForceActiveDesktopOn”=0
“vidc.mrle”=msrle32.dll
“vidc.msvc”=msvidc32.dll
“msacm.imaadpcm”=imaadp32.acm
“msacm.msg711”=msg711.acm
“msacm.msgsm610”=msgsm32.acm
“msacm.msadpcm”=msadp32.acm
“midimapper”=midimap.dll
“wavemapper”=msacm32.drv
“vidc.uyvy”=msyuv.dll
“vidc.yuy2”=msyuv.dll
“vidc.yvyu”=msyuv.dll
“vidc.iyuv”=iyuv_32.dll
“vidc.i420”=iyuv_32.dll
“vidc.yvu9”=tsbyuv.dll
“msacm.l3acm”=C:\Windows\System32\l3codeca.acm
“wave1”=wdmaud.drv
“midi1”=wdmaud.drv
“mixer1”=wdmaud.drv
“aux1”=wdmaud.drv
“wave”=wdmaud.drv
“midi”=wdmaud.drv
“mixer”=wdmaud.drv
“aux”=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe “%1” %*
======List of files/folders created in the last 1 month======
2014-07-22 16:00:34 —-D—- C:\rsit
2014-07-22 16:00:34 —-D—- C:\Program Files\trend micro
2014-07-22 15:38:54 —-A—- C:\Windows\system32\drivers\MBAMSwissArmy.sys
2014-07-22 15:38:37 —-D—- C:\ProgramData\Malwarebytes
2014-07-22 15:38:37 —-D—- C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-07-22 15:38:37 —-A—- C:\Windows\system32\drivers\mwac.sys
2014-07-22 15:38:37 —-A—- C:\Windows\system32\drivers\mbamchameleon.sys
2014-07-22 15:38:37 —-A—- C:\Windows\system32\drivers\mbam.sys
2014-07-22 15:33:21 —-D—- C:\Program Files\CCleaner
2014-07-22 08:58:36 —-A—- C:\Windows\SYSWOW64\javaws.exe
2014-07-22 08:58:21 —-A—- C:\Windows\SYSWOW64\WindowsAccessBridge-32.dll
2014-07-22 08:58:21 —-A—- C:\Windows\SYSWOW64\javaw.exe
2014-07-22 08:58:21 —-A—- C:\Windows\SYSWOW64\java.exe
2014-07-15 17:48:19 —-D—- C:\ProgramData\TorchCrashHandler
2014-07-12 09:49:15 —-A—- C:\Windows\SYSWOW64\kerberos.dll
2014-07-12 09:49:15 —-A—- C:\Windows\system32\schannel.dll
2014-07-12 09:49:15 —-A—- C:\Windows\system32\kerberos.dll
2014-07-12 09:49:14 —-A—- C:\Windows\SYSWOW64\schannel.dll
2014-07-12 09:49:13 —-A—- C:\Windows\SYSWOW64\msv1_0.dll
2014-07-12 09:49:13 —-A—- C:\Windows\system32\wdigest.dll
2014-07-12 09:49:13 —-A—- C:\Windows\system32\msv1_0.dll
2014-07-12 09:49:12 —-A—- C:\Windows\SYSWOW64\ncrypt.dll
2014-07-12 09:49:12 —-A—- C:\Windows\system32\TSpkg.dll
2014-07-12 09:49:12 —-A—- C:\Windows\system32\ncrypt.dll
2014-07-12 09:49:11 —-A—- C:\Windows\SYSWOW64\wdigest.dll
2014-07-12 09:49:11 —-A—- C:\Windows\SYSWOW64\TSpkg.dll
2014-07-12 09:49:09 —-A—- C:\Windows\SYSWOW64\credssp.dll
2014-07-12 09:49:09 —-A—- C:\Windows\system32\credssp.dll
2014-07-12 09:48:23 —-A—- C:\Windows\SYSWOW64\mstscax.dll
2014-07-12 09:48:22 —-A—- C:\Windows\system32\mstscax.dll
2014-07-09 21:14:11 —-A—- C:\Windows\system32\win32k.sys
2014-07-09 21:14:09 —-A—- C:\Windows\SYSWOW64\osk.exe
2014-07-09 21:14:09 —-A—- C:\Windows\system32\osk.exe
2014-07-09 21:14:05 —-A—- C:\Windows\SYSWOW64\qedit.dll
2014-07-09 21:14:05 —-A—- C:\Windows\system32\qedit.dll
2014-07-09 21:14:04 —-A—- C:\Windows\system32\drivers\afd.sys
2014-07-09 21:13:47 —-A—- C:\Windows\SYSWOW64\mshtmled.dll
2014-07-09 21:13:47 —-A—- C:\Windows\SYSWOW64\ieetwproxystub.dll
2014-07-09 21:13:47 —-A—- C:\Windows\system32\iernonce.dll
2014-07-09 21:13:46 —-A—- C:\Windows\SYSWOW64\urlmon.dll
2014-07-09 21:13:46 —-A—- C:\Windows\SYSWOW64\jscript9diag.dll
2014-07-09 21:13:45 —-A—- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2014-07-09 21:13:45 —-A—- C:\Windows\SYSWOW64\iernonce.dll
2014-07-09 21:13:44 —-A—- C:\Windows\system32\ieetwproxystub.dll
2014-07-09 21:13:44 —-A—- C:\Windows\system32\iedkcs32.dll
2014-07-09 21:13:43 —-A—- C:\Windows\SYSWOW64\mshtml.dll
2014-07-09 21:13:43 —-A—- C:\Windows\SYSWOW64\msfeeds.dll
2014-07-09 21:13:43 —-A—- C:\Windows\SYSWOW64\dxtmsft.dll
2014-07-09 21:13:43 —-A—- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-07-09 21:13:41 —-A—- C:\Windows\SYSWOW64\iesetup.dll
2014-07-09 21:13:41 —-A—- C:\Windows\system32\urlmon.dll
2014-07-09 21:13:40 —-A—- C:\Windows\SYSWOW64\iertutil.dll
2014-07-09 21:13:40 —-A—- C:\Windows\system32\ieetwcollectorres.dll
2014-07-09 21:13:39 —-A—- C:\Windows\SYSWOW64\jsproxy.dll
2014-07-09 21:13:39 —-A—- C:\Windows\SYSWOW64\iedkcs32.dll
2014-07-09 21:13:38 —-A—- C:\Windows\system32\ieetwcollector.exe
2014-07-09 21:13:37 —-A—- C:\Windows\SYSWOW64\ieui.dll
2014-07-09 21:13:37 —-A—- C:\Windows\SYSWOW64\dxtrans.dll
2014-07-09 21:13:37 —-A—- C:\Windows\system32\msfeeds.dll
2014-07-09 21:13:37 —-A—- C:\Windows\system32\dxtmsft.dll
2014-07-09 21:13:36 —-A—- C:\Windows\SYSWOW64\ieframe.dll
2014-07-09 21:13:36 —-A—- C:\Windows\system32\iesetup.dll
2014-07-09 21:13:36 —-A—- C:\Windows\system32\ie4uinit.exe
2014-07-09 21:13:35 —-A—- C:\Windows\system32\iertutil.dll
2014-07-09 21:13:34 —-A—- C:\Windows\SYSWOW64\mshtmlmedia.dll
2014-07-09 21:13:34 —-A—- C:\Windows\SYSWOW64\jscript9.dll
2014-07-09 21:13:34 —-A—- C:\Windows\SYSWOW64\ieUnatt.exe
2014-07-09 21:13:33 —-A—- C:\Windows\SYSWOW64\wininet.dll
2014-07-09 21:13:33 —-A—- C:\Windows\SYSWOW64\vbscript.dll
2014-07-09 21:13:33 —-A—- C:\Windows\SYSWOW64\ieapfltr.dll
2014-07-09 21:13:33 —-A—- C:\Windows\system32\jsproxy.dll
2014-07-09 21:13:32 —-A—- C:\Windows\SYSWOW64\msrating.dll
2014-07-09 21:13:32 —-A—- C:\Windows\SYSWOW64\MshtmlDac.dll
2014-07-09 21:13:30 —-A—- C:\Windows\system32\ieui.dll
2014-07-09 21:13:30 —-A—- C:\Windows\system32\ieframe.dll
2014-07-09 21:13:30 —-A—- C:\Windows\system32\dxtrans.dll
2014-07-09 21:13:29 —-A—- C:\Windows\system32\mshtmlmedia.dll
2014-07-09 21:13:29 —-A—- C:\Windows\system32\mshtmled.dll
2014-07-09 21:13:28 —-A—- C:\Windows\system32\jscript9diag.dll
2014-07-09 21:13:28 —-A—- C:\Windows\system32\jscript9.dll
2014-07-09 21:13:28 —-A—- C:\Windows\system32\ieUnatt.exe
2014-07-09 21:13:27 —-A—- C:\Windows\system32\wininet.dll
2014-07-09 21:13:27 —-A—- C:\Windows\system32\vbscript.dll
2014-07-09 21:13:27 —-A—- C:\Windows\system32\ieapfltr.dll
2014-07-09 21:13:26 —-A—- C:\Windows\system32\MshtmlDac.dll
2014-07-09 21:13:25 —-A—- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-07-09 21:13:25 —-A—- C:\Windows\system32\msrating.dll
2014-07-09 21:13:24 —-A—- C:\Windows\system32\mshtml.dll
2014-07-09 21:13:10 —-A—- C:\Windows\system32\lsasrv.dll
2014-07-09 21:13:08 —-A—- C:\Windows\SYSWOW64\sspicli.dll
2014-07-09 21:13:08 —-A—- C:\Windows\SYSWOW64\secur32.dll
======List of files/folders modified in the last 1 month======
2014-07-22 16:00:44 —-D—- C:\Windows\Prefetch
2014-07-22 16:00:38 —-D—- C:\Windows\Temp
2014-07-22 16:00:34 —-RD—- C:\Program Files
2014-07-22 15:54:02 —-D—- C:\Users\Erika\AppData\Roaming\Dropbox
2014-07-22 15:53:38 —-D—- C:\Users\Erika\AppData\Roaming\DropboxMaster
2014-07-22 15:52:24 —-D—- C:\Windows\inf
2014-07-22 15:52:22 —-D—- C:\Windows\system32\config
2014-07-22 15:51:49 —-D—- C:\Windows
2014-07-22 15:51:45 —-HD—- C:\ProgramData
2014-07-22 15:50:33 —-D—- C:\Users\Erika\AppData\Roaming\SupTab
2014-07-22 15:38:54 —-D—- C:\Windows\system32\drivers
2014-07-22 15:38:37 —-RD—- C:\Program Files (x86)
2014-07-22 15:35:47 —-D—- C:\Windows\debug
2014-07-22 15:33:24 —-D—- C:\Windows\system32\Tasks
2014-07-22 15:11:59 —-SHD—- C:\System Volume Information
2014-07-22 13:11:35 —-D—- C:\Windows\system32\wbem
2014-07-22 13:10:21 —-SHD—- C:\Windows\Installer
2014-07-22 13:10:21 —-D—- C:\Windows\Tasks
2014-07-22 13:10:21 —-D—- C:\Windows\SysWOW64
2014-07-22 13:10:21 —-D—- C:\Windows\system32\DriverStore
2014-07-22 13:10:21 —-D—- C:\Windows\system32\catroot2
2014-07-22 13:10:21 —-D—- C:\Windows\System32
2014-07-22 13:10:21 —-D—- C:\Windows\registration
2014-07-22 13:10:21 —-D—- C:\ProgramData\MFAData
2014-07-22 13:06:40 —-SHD—- C:\Config.Msi
2014-07-22 12:59:49 —-A—- C:\Windows\system32\PerfStringBackup.INI
2014-07-22 08:58:48 —-D—- C:\ProgramData\Oracle
2014-07-22 08:58:39 —-D—- C:\Program Files (x86)\Common Files
2014-07-22 08:58:20 —-D—- C:\Program Files (x86)\Java
2014-07-21 16:29:44 —-A—- C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2014-07-15 13:14:17 —-D—- C:\ProgramData\Soulseek
2014-07-13 19:15:02 —-D—- C:\Windows\rescache
2014-07-13 10:47:15 —-D—- C:\Windows\winsxs
2014-07-12 22:57:07 —-D—- C:\Windows\SYSWOW64\Dism
2014-07-12 22:57:06 —-D—- C:\Windows\system32\Dism
2014-07-12 22:57:05 —-D—- C:\Windows\SYSWOW64\nl-NL
2014-07-12 22:57:05 —-D—- C:\Windows\system32\nl-NL
2014-07-12 10:15:48 —-D—- C:\Users\Erika\AppData\Roaming\sweet-page
2014-07-12 09:47:49 —-D—- C:\Windows\system32\catroot
2014-07-10 03:21:31 —-D—- C:\Program Files\Windows Journal
2014-07-10 03:21:29 —-D—- C:\Windows\ehome
2014-07-10 03:21:28 —-D—- C:\Program Files\Internet Explorer
2014-07-10 03:21:27 —-D—- C:\Windows\SYSWOW64\en-US
2014-07-10 03:21:24 —-D—- C:\Windows\system32\en-US
2014-07-10 03:21:23 —-D—- C:\Program Files (x86)\Internet Explorer
2014-07-10 03:05:32 —-D—- C:\Windows\system32\MRT
2014-07-10 03:03:13 —-A—- C:\Windows\system32\MRT.exe
2014-07-10 03:02:45 —-D—- C:\ProgramData\Microsoft Help
2014-07-09 16:43:10 —-A—- C:\Windows\SYSWOW64\FlashPlayerApp.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AVGIDSHA;AVGIDSHA; C:\Windows\system32\DRIVERS\avgidsha.sys
R0 Avgloga;AVG Logging Driver; C:\Windows\system32\DRIVERS\avgloga.sys
R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield; C:\Windows\system32\DRIVERS\avgmfx64.sys
R0 Avgrkx64;AVG Anti-Rootkit Driver; C:\Windows\system32\DRIVERS\avgrkx64.sys
R0 iaStor;Intel RAID Controller; C:\Windows\system32\DRIVERS\iaStor.sys
R0 PxHlpa64;PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys
R1 Avgdiska;AVG Disk Driver; C:\Windows\system32\DRIVERS\avgdiska.sys
R1 AVGIDSDriver;AVGIDSDriver; C:\Windows\system32\DRIVERS\avgidsdrivera.sys
R1 Avgldx64;AVG AVI Loader Driver; C:\Windows\system32\DRIVERS\avgldx64.sys
R1 Avgtdia;AVG TDI Driver; C:\Windows\system32\DRIVERS\avgtdia.sys
R1 RapportCerberus_69875;RapportCerberus_69875; \??\C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_69875.sys
R1 RapportEI64;RapportEI64; \??\C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys
R1 RapportPG64;RapportPG64; \??\C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys
R2 acedrv11;acedrv11; \??\C:\Windows\system32\drivers\acedrv11.sys
R2 Sentinel64;Sentinel64; C:\Windows\System32\Drivers\Sentinel64.sys
R3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\AtiHdmi.sys
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys
R3 HECIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys
R3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter; C:\Windows\system32\DRIVERS\LEqdUsb.Sys
R3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter; C:\Windows\system32\DRIVERS\LHidEqd.Sys
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LHidFilt.Sys
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouFilt.Sys
R3 netr28x;Ralink 802.11n Extensible Wireless Driver; C:\Windows\system32\DRIVERS\netr28x.sys
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys
R3 StillCam;Stuurprogramma voor seriële digitale fotocamera; C:\Windows\system32\drivers\serscan.sys
S1 RxFilter;RxFilter; C:\Windows\system32\DRIVERS\RxFilter.sys
S3 grmnusb;Garmin USB Driver; C:\Windows\system32\drivers\grmnusb.sys
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys
S3 RapportKE64;RapportKE64; C:\Windows\System32\Drivers\RapportKE64.sys
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys
S3 SNTUSB64;SafeNet USB SuperPro/UltraPro/HardwareKey; C:\Windows\system32\DRIVERS\SNTUSB64.SYS
S3 Spyder3;Datacolor Spyder3; C:\Windows\system32\DRIVERS\Spyder3.sys
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe
R2 AVGIDSAgent;AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
R2 avgwd;AVG WatchDog; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
R2 BBSvc;Bing Bar Update Service; C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE
R2 BBUpdate;BBUpdate; C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
R2 ezSharedSvc;Easybits Shared Services for Windows; C:\Windows\system32\svchost.exe
R2 Garmin Core Update Service;Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
R2 HP Support Assistant Service;HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
R2 RalinkRegistryWriter;Ralink Registry Writer; C:\Program Files (x86)\Sitecom\Common\RegistryWriter.exe
R2 RapportMgmtService;Rapport Management Service; C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe
R2 RoxWatch10;Roxio Hard Drive Watcher 10; C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe
R2 TorchCrashHandler;Torch Crash Handler; C:\Users\Erika\AppData\Local\Torch\Update\TorchCrashHandler.exe
R3 RoxMediaDB10;RoxMediaDB10; C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
S2 gupdate;Google Update-service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
S2 Roxio Upnp Server 10;Roxio Upnp Server 10; C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe
S2 RoxLiveShare10;LiveShare P2P Server 10; C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
S3 GameConsoleService;GameConsoleService; C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe
S3 gupdatem;Google Update-service (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
S3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
S3 Roxio UPnP Renderer 10;Roxio UPnP Renderer 10; C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe
S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
—————–EOF—————–
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 22-7-2014
Scan Time: 15:39:12
Logfile: Mbam scanlog01.txt
Administrator: Yes
Version: 2.00.2.1012
Malware Database: v2014.07.22.03
Rootkit Database: v2014.07.17.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Erika
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 299369
Time Elapsed: 10 min, 1 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 1
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService\PluginService.exe, 1716, Delete-on-Reboot,
Modules: 0
(No malicious items detected)
Registry Keys: 15
PUP.Optional.IePluginService.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IePluginService, Quarantined, ,
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, Quarantined, ,
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, Quarantined, ,
PUP.Optional.Snapdo.T, HKU\S-1-5-21-1153977891-1869991665-2431096691-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006ee092-9658-4fd6-bd8e-a21a348e59f5}, Quarantined, ,
PUP.Optional.Snapdo.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006EE092-9658-4FD6-BD8E-A21A348E59F5}, Quarantined, ,
PUP.Optional.Babylon.A, HKU\S-1-5-21-1153977891-1869991665-2431096691-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}, Quarantined, ,
PUP.Optional.DataMangr.A, HKLM\SOFTWARE\WOW6432NODE\DataMngr, Quarantined, ,
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\sweet-pageSoftware, Quarantined, ,
PUP.Optional.DataMngr.A, HKU\S-1-5-21-1153977891-1869991665-2431096691-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DataMngr, Quarantined, ,
PUP.Optional.DataMngr.A, HKU\S-1-5-21-1153977891-1869991665-2431096691-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DataMngr_Toolbar, Quarantined, ,
PUP.Optional.Babylon.A, HKU\S-1-5-21-1153977891-1869991665-2431096691-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\BABSOLUTION\Redir, Quarantined, ,
PUP.Optional.Babylon.A, HKU\S-1-5-21-1153977891-1869991665-2431096691-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\BABSOLUTION\Updater, Quarantined, ,
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1153977891-1869991665-2431096691-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, Quarantined, ,
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1153977891-1869991665-2431096691-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, Quarantined, ,
PUP.Optional.Softonic.A, HKU\S-1-5-21-1153977891-1869991665-2431096691-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, Quarantined, ,
Registry Values: 1
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1153977891-1869991665-2431096691-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0L1N1H2O1S, Quarantined,
Registry Data: 12
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe http://www.sweet-page.com/?type=sc&ts=1400231706&from=sof&uid=WDCXWD10EADS-65M2B0_WD-WCAV5634178841788, Good: (iexplore.exe), Bad: (C:\Program Files\Internet Explorer\iexplore.exe http://www.sweet-page.com/?type=sc&ts=1400231706&from=sof&uid=WDCXWD10EADS-65M2B0_WD-WCAV5634178841788),Replaced,
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, http://www.sweet-page.com/web/?type=ds&ts=1400231706&from=sof&uid=WDCXWD10EADS-65M2B0_WD-WCAV5634178841788&q={searchTerms}, Good: (www.google.com), Bad: (http://www.sweet-page.com/web/?type=ds&ts=1400231706&from=sof&uid=WDCXWD10EADS-65M2B0_WD-WCAV5634178841788&q={searchTerms}),Replaced,
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, http://www.sweet-page.com/web/?type=ds&ts=1400231706&from=sof&uid=WDCXWD10EADS-65M2B0_WD-WCAV5634178841788&q={searchTerms}, Good: (www.google.com), Bad: (http://www.sweet-page.com/web/?type=ds&ts=1400231706&from=sof&uid=WDCXWD10EADS-65M2B0_WD-WCAV5634178841788&q={searchTerms}),Replaced,
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe http://www.sweet-page.com/?type=sc&ts=1400231706&from=sof&uid=WDCXWD10EADS-65M2B0_WD-WCAV5634178841788, Good: (iexplore.exe), Bad: (C:\Program Files\Internet Explorer\iexplore.exe http://www.sweet-page.com/?type=sc&ts=1400231706&from=sof&uid=WDCXWD10EADS-65M2B0_WD-WCAV5634178841788),Replaced,
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, http://www.sweet-page.com/web/?type=ds&ts=1400231706&from=sof&uid=WDCXWD10EADS-65M2B0_WD-WCAV5634178841788&q={searchTerms}, Good: (www.google.com), Bad: (http://www.sweet-page.com/web/?type=ds&ts=1400231706&from=sof&uid=WDCXWD10EADS-65M2B0_WD-WCAV5634178841788&q={searchTerms}),Replaced,
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, http://www.sweet-page.com/web/?type=ds&ts=1400231706&from=sof&uid=WDCXWD10EADS-65M2B0_WD-WCAV5634178841788&q={searchTerms}, Good: (www.google.com), Bad: (http://www.sweet-page.com/web/?type=ds&ts=1400231706&from=sof&uid=WDCXWD10EADS-65M2B0_WD-WCAV5634178841788&q={searchTerms}),Replaced,
PUP.Optional.SnapDo.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, http://feed.snapdo.com/?publisher=QuickObrw&dpid=QuickObrw&co=NL&userid=a55c4ab0-ac89-4352-a750-98552a6a9337&searchtype=ds&q={searchTerms}&installDate=23/06/2013, Good: (www.google.com), Bad: (http://feed.snapdo.com/?publisher=QuickObrw&dpid=QuickObrw&co=NL&userid=a55c4ab0-ac89-4352-a750-98552a6a9337&searchtype=ds&q={searchTerms}&installDate=23/06/2013),Replaced,
PUP.Optional.Snapdo, HKU\S-1-5-21-1153977891-1869991665-2431096691-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, http://feed.snapdo.com/?publisher=QuickObrw&dpid=QuickObrw&co=NL&userid=a55c4ab0-ac89-4352-a750-98552a6a9337&searchtype=ds&q={searchTerms}&installDate=23/06/2013, Good: (www.google.com), Bad: (http://feed.snapdo.com/?publisher=QuickObrw&dpid=QuickObrw&co=NL&userid=a55c4ab0-ac89-4352-a750-98552a6a9337&searchtype=ds&q={searchTerms}&installDate=23/06/2013),Replaced,
PUP.Optional.Snapdo, HKU\S-1-5-21-1153977891-1869991665-2431096691-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, http://feed.snapdo.com/?publisher=QuickObrw&dpid=QuickObrw&co=NL&userid=a55c4ab0-ac89-4352-a750-98552a6a9337&searchtype=ds&q={searchTerms}&installDate=23/06/2013, Good: (www.google.com), Bad: (http://feed.snapdo.com/?publisher=QuickObrw&dpid=QuickObrw&co=NL&userid=a55c4ab0-ac89-4352-a750-98552a6a9337&searchtype=ds&q={searchTerms}&installDate=23/06/2013),Replaced,
PUP.Optional.Snapdo, HKU\S-1-5-21-1153977891-1869991665-2431096691-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, http://feed.snapdo.com/?publisher=QuickObrw&dpid=QuickObrw&co=NL&userid=a55c4ab0-ac89-4352-a750-98552a6a9337&searchtype=ds&q={searchTerms}&installDate=23/06/2013, Good: (www.google.com), Bad: (http://feed.snapdo.com/?publisher=QuickObrw&dpid=QuickObrw&co=NL&userid=a55c4ab0-ac89-4352-a750-98552a6a9337&searchtype=ds&q={searchTerms}&installDate=23/06/2013),Replaced,
PUP.Optional.Snapdo, HKU\S-1-5-21-1153977891-1869991665-2431096691-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, http://feed.snapdo.com/?publisher=QuickObrw&dpid=QuickObrw&co=NL&userid=a55c4ab0-ac89-4352-a750-98552a6a9337&searchtype=ds&q={searchTerms}&installDate=23/06/2013, Good: (www.google.com), Bad: (http://feed.snapdo.com/?publisher=QuickObrw&dpid=QuickObrw&co=NL&userid=a55c4ab0-ac89-4352-a750-98552a6a9337&searchtype=ds&q={searchTerms}&installDate=23/06/2013),Replaced,
PUP.Optional.SnapDo.A, HKU\S-1-5-21-1153977891-1869991665-2431096691-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, http://feed.snapdo.com/?publisher=QuickObrw&dpid=QuickObrw&co=NL&userid=a55c4ab0-ac89-4352-a750-98552a6a9337&searchtype=ds&q={searchTerms}&installDate=23/06/2013, Good: (www.google.com), Bad: (http://feed.snapdo.com/?publisher=QuickObrw&dpid=QuickObrw&co=NL&userid=a55c4ab0-ac89-4352-a750-98552a6a9337&searchtype=ds&q={searchTerms}&installDate=23/06/2013),Replaced,
Folders: 11
PUP.Optional.SearchNewTab, C:\ProgramData\SearchNewTab, Quarantined, ,
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService, Delete-on-Reboot, ,
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService\update, Quarantined, ,
PUP.Optional.Yontoo.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\extensions\plugin@yontoo.com, Quarantined, ,
PUP.Optional.Yontoo.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\extensions\plugin@yontoo.com\content, Quarantined, ,
PUP.Optional.Yontoo.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\extensions\plugin@yontoo.com\defaults, Quarantined, ,
PUP.Optional.Yontoo.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\extensions\plugin@yontoo.com\defaults\preferences, Quarantined, ,
PUP.Optional.Yontoo.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\extensions\plugin@yontoo.com\locale, Quarantined, ,
PUP.Optional.Yontoo.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\extensions\plugin@yontoo.com\locale\en-US, Quarantined, ,
PUP.Optional.Yontoo.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\extensions\plugin@yontoo.com\META-INF, Quarantined, ,
PUP.Optional.Yontoo.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\extensions\plugin@yontoo.com\skin, Quarantined, ,
Files: 51
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService\PluginService.exe, Delete-on-Reboot, ,
PUP.Optional.Delta.A, C:\Users\Erika\AppData\Roaming\BabSolution\Shared\enhancedNT.dll, Quarantined, ,
PUP.Optional.SupTab.A, C:\Users\Erika\AppData\Roaming\SupTab\SupTab.dll, Quarantined, ,
PUP.Optional.WebSearch.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\searchplugins\Web Search.xml, Quarantined, ,
PUP.Optional.SearchNewTab, C:\ProgramData\SearchNewTab\51c6b1fc3a193.tlb, Quarantined, ,
PUP.Optional.SearchNewTab, C:\ProgramData\SearchNewTab\settings.ini, Quarantined, ,
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService\update\conf, Quarantined, ,
PUP.Optional.Yontoo.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\extensions\plugin@yontoo.com\build.sh, Quarantined, ,
PUP.Optional.Yontoo.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\extensions\plugin@yontoo.com\chrome.manifest, Quarantined, ,
PUP.Optional.Yontoo.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\extensions\plugin@yontoo.com\config_build.sh, Quarantined, ,
PUP.Optional.Yontoo.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\extensions\plugin@yontoo.com\install.rdf, Quarantined, ,
PUP.Optional.Yontoo.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\extensions\plugin@yontoo.com\readme.txt, Quarantined, ,
PUP.Optional.Yontoo.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\extensions\plugin@yontoo.com\content\about.xul, Quarantined, ,
PUP.Optional.Yontoo.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\extensions\plugin@yontoo.com\content\firefoxOverlay.xul, Quarantined, ,
PUP.Optional.Yontoo.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\extensions\plugin@yontoo.com\content\options.xul, Quarantined, ,
PUP.Optional.Yontoo.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\extensions\plugin@yontoo.com\content\overlay.js, Quarantined, ,
PUP.Optional.Yontoo.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\extensions\plugin@yontoo.com\content\y2layers.jpg, Quarantined, ,
PUP.Optional.Yontoo.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\extensions\plugin@yontoo.com\defaults\preferences\y2layers.js, Quarantined, ,
PUP.Optional.Yontoo.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\extensions\plugin@yontoo.com\locale\en-US\about.dtd, Quarantined, ,
PUP.Optional.Yontoo.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\extensions\plugin@yontoo.com\locale\en-US\prefwindow.dtd, Quarantined, ,
PUP.Optional.Yontoo.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\extensions\plugin@yontoo.com\locale\en-US\y2layers.dtd, Quarantined, ,
PUP.Optional.Yontoo.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\extensions\plugin@yontoo.com\locale\en-US\y2layers.properties, Quarantined, ,
PUP.Optional.Yontoo.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\extensions\plugin@yontoo.com\META-INF\manifest.mf, Quarantined, ,
PUP.Optional.Yontoo.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\extensions\plugin@yontoo.com\META-INF\zigbert.rsa, Quarantined, ,
PUP.Optional.Yontoo.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\extensions\plugin@yontoo.com\META-INF\zigbert.sf, Quarantined, ,
PUP.Optional.Yontoo.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\extensions\plugin@yontoo.com\skin\overlay.css, Quarantined, ,
PUP.Optional.Yontoo.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\extensions\plugin@yontoo.com\skin\toolbar-button.png, Quarantined, ,
PUP.Optional.Delta.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\prefs.js, Good: (), Bad: (user_pref(“extensions.delta.admin”, false), Replaced,
PUP.Optional.Delta.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\prefs.js, Good: (), Bad: (user_pref(“extensions.delta.aflt”, “babsst”), Replaced,
PUP.Optional.Delta.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\prefs.js, Good: (), Bad: (user_pref(“extensions.delta.appId”, “{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}”), Replaced,
PUP.Optional.Delta.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\prefs.js, Good: (), Bad: (user_pref(“extensions.delta.autoRvrt”, “false”), Replaced,
PUP.Optional.Delta.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\prefs.js, Good: (), Bad: (user_pref(“extensions.delta.dfltLng”, “nl”), Replaced,
PUP.Optional.Delta.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\prefs.js, Good: (), Bad: (user_pref(“extensions.delta.excTlbr”, false), Replaced,
PUP.Optional.Delta.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\prefs.js, Good: (), Bad: (user_pref(“extensions.delta.ffxUnstlRst”, true), Replaced,
PUP.Optional.Delta.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\prefs.js, Good: (), Bad: (user_pref(“extensions.delta.id”, “9a6c7b0d000000000000701a044a5c9b”), Replaced,
PUP.Optional.Delta.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\prefs.js, Good: (), Bad: (user_pref(“extensions.delta.instlDay”, “15947”), Replaced,
PUP.Optional.Delta.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\prefs.js, Good: (), Bad: (user_pref(“extensions.delta.instlRef”, “sst”), Replaced,
PUP.Optional.Delta.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\prefs.js, Good: (), Bad: (user_pref(“extensions.delta.newTab”, false), Replaced,
PUP.Optional.Delta.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\prefs.js, Good: (), Bad: (user_pref(“extensions.delta.prdct”, “delta”), Replaced,
PUP.Optional.Delta.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\prefs.js, Good: (), Bad: (user_pref(“extensions.delta.prtnrId”, “delta”), Replaced,
PUP.Optional.Delta.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\prefs.js, Good: (), Bad: (user_pref(“extensions.delta.rvrt”, “false”), Replaced,
PUP.Optional.Delta.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\prefs.js, Good: (), Bad: (user_pref(“extensions.delta.smplGrp”, “none”), Replaced,
PUP.Optional.Delta.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\prefs.js, Good: (), Bad: (user_pref(“extensions.delta.tlbrId”, “base”), Replaced,
PUP.Optional.Delta.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\prefs.js, Good: (), Bad: (user_pref(“extensions.delta.tlbrSrchUrl”, “”), Replaced,
PUP.Optional.Delta.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\prefs.js, Good: (), Bad: (user_pref(“extensions.delta.vrsn”, “1.8.24.6”), Replaced,
PUP.Optional.Delta.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\prefs.js, Good: (), Bad: (user_pref(“extensions.delta.vrsnTs”, “1.8.24.610:10:16”), Replaced,
PUP.Optional.Delta.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\prefs.js, Good: (), Bad: (user_pref(“extensions.delta.vrsni”, “1.8.24.6”), Replaced,
PUP.Optional.Delta.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\prefs.js, Good: (), Bad: (user_pref(“extensions.delta_i.babExt”, “”), Replaced,
PUP.Optional.Delta.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\prefs.js, Good: (), Bad: (user_pref(“extensions.delta_i.babTrack”, “affID=119357&tt=280813_ts&tsp=4990”), Replaced,
PUP.Optional.Delta.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\prefs.js, Good: (), Bad: (user_pref(“extensions.delta_i.srcExt”, “ss”), Replaced,
PUP.Optional.Conduit.A, C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\prefs.js, Good: (), Bad: (user_pref(“browser.search.defaulturl”, “http://search.conduit.com/ResultsExt.aspx?ctid=CT2866439&SearchSource=3&q={searchTerms}”), Replaced,
Physical Sectors: 0
(No malicious items detected)
(end)