2014-10-28, 18:03
Ok Ken here we go. Before I started to run Farbar and AswMBR I booted up the laptop with Kaspersky Pure 3.0 Internet disk as a rescue disk and it scanned and found nothing. I also ran Microsoft Security Scanner, also nothing. Back when we were working on the desktop we removed a bunch of .backup bad host files and I had found those same files on the laptop so I removed those from the laptop as well and I've not had any pop ups since. But I am concerned that something may still be lurking so here we are.

So here are the first set of logs:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 27-10-2014 01
Ran by Gateway (administrator) on GATEWAY-PC on 28-10-2014 10:20:53
Running from C:\Users\Gateway\Desktop
Loaded Profile: Gateway (Available profiles: Gateway)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 10
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Check Point Software Technologies LTD) C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Gateway\Gateway Power Management\ePowerSvc.exe
(Acer Incorporated) C:\Program Files (x86)\Gateway\Registration\GREGsvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Check Point Software Technologies, Ltd.) C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Safer Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Alcor Micro Corp.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
(Acer Incorporated) C:\Program Files\Gateway\Gateway Power Management\ePowerTray.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Acer Incorporated) C:\Program Files\Gateway\Gateway Power Management\ePowerEvent.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Check Point Software Technologies LTD) C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(AOL LLC) C:\Program Files (x86)\Common Files\AOL\acs\AOLacsd.exe
(AOL Inc.) C:\Program Files (x86)\Common Files\AOL\1319763878\ee\aolsoftware.exe
(AOL Inc.) C:\Program Files (x86)\Common Files\AOL\1319763878\ee\aolupdates.exe
(AOL Inc.) C:\Program Files (x86)\AOL Desktop 9.6\waol.exe
(AOL Inc.) C:\Program Files (x86)\AOL Desktop 9.6\shellmon.exe

==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11101800 2010-07-28] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1842472 2009-09-17] (Synaptics Incorporated)
HKLM\...\Run: [AmIcoSinglun64] => C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [324608 2010-06-10] (Alcor Micro Corp.)
HKLM\...\Run: [Acer ePower Management] => C:\Program Files\Gateway\Gateway Power Management\ePowerTray.exe [861216 2010-06-11] (Acer Incorporated)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1331288 2014-08-22] (Microsoft Corporation)
HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [975952 2010-08-10] (Dritek System Inc.)
HKLM-x32\...\Run: [ZoneAlarm] => C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe [73832 2013-06-19] (Check Point Software Technologies LTD)
HKLM-x32\...\Run: [WRSVC] => C:\Program Files\Webroot\WRSA.exe [647120 2012-01-16] (Webroot)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1184006042-274145770-2943838389-1000\...\Run: [AOL Fast Start] => C:\Program Files (x86)\AOL Desktop 9.6\AOL.EXE [42320 2011-04-25] (AOL Inc.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x4166C5EAE2DBCF01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.aol.com/
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM-x32 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Spybot-S&D IE Protection -> {53707962-6F74-2D53-2644-206D7942484F} -> C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer]

FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)


==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [368624 2014-08-22] (Microsoft Corporation)
R2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
R2 vsmon; C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe [2445304 2013-06-19] (Check Point Software Technologies LTD)
S2 WRSVC; C:\Program Files\Webroot\WRSA.exe [647120 2012-01-16] (Webroot)
R2 ZAPrivacyService; C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe [54160 2013-06-18] (Check Point Software Technologies, Ltd.)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-13] (Microsoft Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [269008 2014-07-17] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [125584 2014-07-17] (Microsoft Corporation)
R2 TurboB; C:\Windows\System32\DRIVERS\TurboB.sys [13784 2009-11-02] ()
R1 Vsdatant; C:\Windows\System32\DRIVERS\vsdatant.sys [451096 2013-06-13] (Check Point Software Technologies LTD)
R0 WRkrn; C:\Windows\System32\drivers\WRkrn.sys [111080 2012-01-25] (Webroot)
S3 AmUStor; \SystemRoot\system32\drivers\AmUStor.SYS [X]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 PcdrNdisuio; syswow64\drivers\pcdrndisuio.sys [X]
S3 PCDSRVC{FCB8192B-6C0E95E9-06020101}_0; \??\c:\users\gateway\appdata\local\temp\i1amxcawrfo3\pcdrdiag\bin\pcdsrvc_x64.pkms [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)

==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-10-28 10:20 - 2014-10-28 10:22 - 00009446 _____ () C:\Users\Gateway\Desktop\FRST.txt
2014-10-28 10:20 - 2014-10-28 10:20 - 00000000 ____D () C:\FRST
2014-10-28 10:18 - 2014-10-28 10:18 - 05192704 _____ (AVAST Software) C:\Users\Gateway\Desktop\aswMBR.exe
2014-10-28 10:14 - 2014-10-28 10:14 - 02113024 _____ (Farbar) C:\Users\Gateway\Desktop\FRST64.exe
2014-10-28 03:20 - 2014-10-28 03:20 - 00111080 _____ (Webroot) C:\Windows\system32\Drivers\jnsAdKtw.sys
2014-10-27 11:58 - 2014-10-27 11:58 - 00000000 ____D () C:\Users\Gateway\AppData\Local\Apps\2.0
2014-10-27 09:56 - 2014-10-27 09:56 - 00000994 _____ () C:\Users\Gateway\Desktop\AdwCleaner1027.txt
2014-10-27 09:54 - 2014-10-27 09:54 - 00111080 _____ (Webroot) C:\Windows\system32\Drivers\pDKYbgdo.sys
2014-10-27 09:47 - 2014-10-27 09:48 - 01998336 _____ () C:\Users\Gateway\Desktop\adwcleaner_4.002.exe
2014-10-27 09:39 - 2014-10-27 09:39 - 00111080 _____ (Webroot) C:\Windows\system32\Drivers\JmOVyYpY.sys
2014-10-27 07:40 - 2014-10-27 07:40 - 00000000 ____D () C:\ProgramData\boost_interprocess
2014-10-27 07:29 - 2014-10-27 07:29 - 00111080 _____ (Webroot) C:\Windows\system32\Drivers\atYthjoV.sys
2014-10-27 07:25 - 2014-10-27 07:25 - 00111080 _____ (Webroot) C:\Windows\system32\Drivers\IXtkPayO.sys
2014-10-27 07:19 - 2014-10-27 07:19 - 00111080 _____ (Webroot) C:\Windows\system32\Drivers\YVTTuumS.sys
2014-10-27 07:10 - 2014-10-27 07:10 - 00111080 _____ (Webroot) C:\Windows\system32\Drivers\gSuQpyHA.sys
2014-10-27 07:06 - 2014-10-27 07:06 - 00111080 _____ (Webroot) C:\Windows\system32\Drivers\PGBxTkEF.sys
2014-10-27 00:52 - 2014-10-27 00:53 - 120300280 _____ (Microsoft Corporation) C:\Users\Gateway\Desktop\msert.exe
2014-10-26 19:43 - 2014-10-26 19:43 - 00111080 _____ (Webroot) C:\Windows\system32\Drivers\ufimfweO.sys
2014-10-26 18:25 - 2014-10-26 18:25 - 00012872 _____ (SurfRight B.V.) C:\Windows\system32\bootdelete.exe
2014-10-26 18:25 - 2014-10-26 18:25 - 00004290 _____ () C:\Users\Gateway\Desktop\HitmanPro_20141026_1825.log
2014-10-26 18:00 - 2014-10-26 18:00 - 03469871 _____ (LIGHTNING UK!) C:\Users\Gateway\Downloads\SetupImgBurn_2.5.8.0.exe
2014-10-26 17:54 - 2014-10-26 17:58 - 308455424 _____ () C:\Users\Gateway\Downloads\kav_rescue_10.iso
2014-10-26 07:46 - 2014-10-26 07:46 - 00111080 _____ (Webroot) C:\Windows\system32\Drivers\SaBACdhX.sys
2014-10-26 07:29 - 2014-10-27 09:55 - 00000000 ____D () C:\AdwCleaner
2014-10-26 04:27 - 2014-10-26 04:27 - 00000710 _____ () C:\DelFix.txt
2014-10-25 13:42 - 2014-10-25 13:42 - 00111080 _____ (Webroot) C:\Windows\system32\Drivers\qkkcNgcg.sys
2014-10-24 17:36 - 2014-10-24 17:36 - 00111080 _____ (Webroot) C:\Windows\system32\Drivers\sBDzxsjA.sys
2014-10-22 10:01 - 2014-10-22 10:01 - 00111080 _____ (Webroot) C:\Windows\system32\Drivers\iOwjfFdq.sys
2014-10-22 06:23 - 2014-10-22 06:23 - 00111080 _____ (Webroot) C:\Windows\system32\Drivers\sNmtkkiz.sys
2014-10-22 06:05 - 2014-10-22 06:05 - 00111080 _____ (Webroot) C:\Windows\system32\Drivers\PHrqeLVS.sys
2014-10-22 05:54 - 2014-10-22 05:54 - 00111080 _____ (Webroot) C:\Windows\system32\Drivers\KnLHwfQW.sys
2014-10-21 14:34 - 2014-10-21 14:34 - 00111080 _____ (Webroot) C:\Windows\system32\Drivers\BlFSMOwS.sys
2014-10-21 08:15 - 2014-10-22 09:59 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-10-21 08:00 - 2014-10-21 08:00 - 00111080 _____ (Webroot) C:\Windows\system32\Drivers\ipEyTLGa.sys
2014-10-21 07:49 - 2014-06-18 17:23 - 01943696 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
2014-10-21 07:49 - 2014-06-18 17:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dfshim.dll
2014-10-21 07:49 - 2014-06-18 17:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscorier.dll
2014-10-21 07:49 - 2014-06-18 17:23 - 00156312 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll
2014-10-21 07:49 - 2014-06-18 17:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscories.dll
2014-10-21 07:49 - 2014-06-18 17:23 - 00073880 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll
2014-10-21 07:40 - 2014-10-21 07:40 - 00111080 _____ (Webroot) C:\Windows\system32\Drivers\tICbFABY.sys
2014-10-21 07:37 - 2014-10-21 07:37 - 00111080 _____ (Webroot) C:\Windows\system32\Drivers\uOqCtCGV.sys
2014-10-21 07:33 - 2014-10-09 21:05 - 00507392 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-10-21 07:33 - 2014-10-09 21:05 - 00276480 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2014-10-21 07:33 - 2014-10-09 21:00 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-10-21 07:33 - 2014-09-24 21:08 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2014-10-21 07:33 - 2014-09-24 20:40 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2014-10-21 07:33 - 2014-09-17 21:00 - 03241472 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-10-21 07:33 - 2014-09-17 20:32 - 02363904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-10-21 07:33 - 2014-07-16 21:07 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2014-10-21 07:33 - 2014-07-16 21:07 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-10-21 07:33 - 2014-07-16 21:07 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll
2014-10-21 07:33 - 2014-07-16 21:07 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
2014-10-21 07:33 - 2014-07-16 21:07 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-10-21 07:33 - 2014-07-16 21:07 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-10-21 07:33 - 2014-07-16 20:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winsta.dll
2014-10-21 07:33 - 2014-07-16 20:39 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-10-21 07:33 - 2014-07-16 20:39 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-10-21 07:33 - 2014-07-16 20:21 - 00212480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2014-10-21 07:33 - 2014-07-16 20:21 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2014-10-21 07:32 - 2014-09-28 19:58 - 03198976 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-10-21 07:32 - 2014-09-04 21:11 - 06584320 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-10-21 07:32 - 2014-09-04 20:52 - 05703168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-10-21 07:32 - 2014-09-04 00:23 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
2014-10-21 07:32 - 2014-09-04 00:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastls.dll
2014-10-21 07:32 - 2014-08-28 21:07 - 03179520 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-10-21 07:31 - 2014-09-12 20:58 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-10-21 07:31 - 2014-09-12 20:40 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
2014-10-21 07:17 - 2014-10-21 07:17 - 00111080 _____ (Webroot) C:\Windows\system32\Drivers\TejdXozT.sys
2014-10-21 07:14 - 2014-09-20 00:18 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-10-21 07:14 - 2014-09-20 00:17 - 02236928 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-10-21 07:14 - 2014-09-20 00:17 - 01407488 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-10-21 07:14 - 2014-09-20 00:16 - 19280896 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-10-21 07:14 - 2014-09-20 00:16 - 15399424 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-10-21 07:14 - 2014-09-20 00:16 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-10-21 07:14 - 2014-09-20 00:16 - 02655232 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-10-21 07:14 - 2014-09-20 00:16 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-10-21 07:14 - 2014-09-20 00:16 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-10-21 07:14 - 2014-09-20 00:16 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-10-21 07:14 - 2014-09-20 00:16 - 00255488 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-10-21 07:14 - 2014-09-20 00:16 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-10-21 07:14 - 2014-09-20 00:16 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-10-21 07:14 - 2014-09-20 00:16 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-10-21 07:14 - 2014-09-20 00:16 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-10-21 07:14 - 2014-09-20 00:16 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-10-21 07:14 - 2014-09-20 00:16 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-10-21 07:14 - 2014-09-20 00:15 - 01508864 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-10-21 07:14 - 2014-09-20 00:15 - 00451584 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-10-21 07:14 - 2014-09-20 00:15 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-10-21 07:14 - 2014-09-19 22:57 - 14368768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-10-21 07:14 - 2014-09-19 22:57 - 13757952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-10-21 07:14 - 2014-09-19 22:57 - 02861568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-10-21 07:14 - 2014-09-19 22:57 - 02055168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-10-21 07:14 - 2014-09-19 22:57 - 01762816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-10-21 07:14 - 2014-09-19 22:57 - 01180672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-10-21 07:14 - 2014-09-19 22:57 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-10-21 07:14 - 2014-09-19 22:57 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-10-21 07:14 - 2014-09-19 22:57 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-10-21 07:14 - 2014-09-19 22:57 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-10-21 07:14 - 2014-09-19 22:57 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-10-21 07:14 - 2014-09-19 22:57 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2014-10-21 07:14 - 2014-09-19 22:57 - 00080384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-10-21 07:14 - 2014-09-19 22:57 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-10-21 07:14 - 2014-09-19 22:57 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-10-21 07:14 - 2014-09-19 22:57 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-10-21 07:14 - 2014-09-19 22:56 - 01440768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-10-21 07:14 - 2014-09-19 22:56 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-10-21 07:14 - 2014-09-19 22:56 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-10-21 07:14 - 2014-09-19 22:38 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-10-21 07:14 - 2014-09-19 22:33 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-10-21 07:14 - 2014-09-19 21:43 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2014-10-21 07:14 - 2014-09-19 21:35 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2014-10-20 02:29 - 2014-10-20 02:29 - 00111080 _____ (Webroot) C:\Windows\system32\Drivers\VaIZBLul.sys
2014-10-09 11:42 - 2014-10-09 11:42 - 00111080 _____ (Webroot) C:\Windows\system32\Drivers\pkUPoewm.sys
2014-10-09 11:41 - 2014-10-28 03:20 - 00002026 _____ () C:\Windows\setupact.log
2014-10-08 04:40 - 2014-10-08 04:40 - 00111080 _____ (Webroot) C:\Windows\system32\Drivers\PvmDPGpu.sys
2014-10-08 04:14 - 2014-10-08 04:14 - 00111080 _____ (Webroot) C:\Windows\system32\Drivers\qCEOYKVu.sys
2014-10-06 06:42 - 2014-10-06 06:42 - 00111080 _____ (Webroot) C:\Windows\system32\Drivers\FKACWuEl.sys
2014-10-03 18:34 - 2014-10-03 18:34 - 00111080 _____ (Webroot) C:\Windows\system32\Drivers\kCpsrgpo.sys
2014-10-02 08:31 - 2014-10-22 10:15 - 00037624 _____ () C:\Windows\system32\Drivers\TrueSight.sys
2014-10-02 08:31 - 2014-10-02 08:31 - 00000000 ____D () C:\ProgramData\RogueKiller
2014-09-29 12:31 - 2014-09-29 12:31 - 00111080 _____ (Webroot) C:\Windows\system32\Drivers\exTZeEAA.sys
2014-09-29 12:23 - 2014-09-09 17:11 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-09-29 12:23 - 2014-09-09 16:47 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-09-29 12:23 - 2014-07-08 21:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL
2014-09-29 12:23 - 2014-07-08 21:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL
2014-09-29 12:23 - 2014-07-08 21:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL
2014-09-29 12:23 - 2014-07-08 21:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL
2014-09-29 12:23 - 2014-07-08 21:03 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL
2014-09-29 12:23 - 2014-07-08 20:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDYAK.DLL
2014-09-29 12:23 - 2014-07-08 20:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTAT.DLL
2014-09-29 12:23 - 2014-07-08 20:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU1.DLL
2014-09-29 12:23 - 2014-07-08 20:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU.DLL
2014-09-29 12:23 - 2014-07-08 20:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDBASH.DLL
2014-09-29 12:23 - 2014-07-08 17:38 - 00419992 _____ () C:\Windows\system32\locale.nls
2014-09-29 12:23 - 2014-07-08 17:30 - 00419992 _____ () C:\Windows\SysWOW64\locale.nls
2014-09-29 07:58 - 2014-09-29 07:58 - 00111080 _____ (Webroot) C:\Windows\system32\Drivers\Cllvxtmc.sys
2014-09-29 07:40 - 2014-09-29 07:40 - 00111080 _____ (Webroot) C:\Windows\system32\Drivers\dubezlMy.sys
2014-09-28 19:24 - 2014-09-28 19:35 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-09-28 19:09 - 2014-09-28 19:09 - 00000000 ____D () C:\Program Files\HitmanPro
2014-09-28 19:08 - 2014-10-26 18:25 - 00000000 ____D () C:\ProgramData\HitmanPro
2014-09-28 18:59 - 2014-09-28 18:59 - 00111080 _____ (Webroot) C:\Windows\system32\Drivers\OyPexOOc.sys
2014-09-28 14:58 - 2014-09-28 14:58 - 00111080 _____ (Webroot) C:\Windows\system32\Drivers\yMxFRDLr.sys
2014-09-28 14:36 - 2014-09-28 14:36 - 00111080 _____ (Webroot) C:\Windows\system32\Drivers\UzVfwxBv.sys
2014-09-28 09:17 - 2014-09-28 09:17 - 00111080 _____ (Webroot) C:\Windows\system32\Drivers\VbdJPgnZ.sys
2014-09-28 08:59 - 2014-09-28 08:59 - 00111080 _____ (Webroot) C:\Windows\system32\Drivers\bUvERcaW.sys
2014-09-28 08:58 - 2014-09-28 09:11 - 00000000 ____D () C:\Windows\erdnt
2014-09-28 06:53 - 2014-09-28 06:53 - 00111080 _____ (Webroot) C:\Windows\system32\Drivers\ICPieGzC.sys

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-10-28 10:08 - 2011-07-06 16:01 - 02065412 _____ () C:\Windows\WindowsUpdate.log
2014-10-28 07:07 - 2009-07-13 23:45 - 00025840 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-10-28 07:07 - 2009-07-13 23:45 - 00025840 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-10-28 07:05 - 2009-07-14 00:13 - 00781790 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-10-28 03:20 - 2011-11-16 13:12 - 00000754 _____ () C:\Users\Public\Desktop\Webroot SecureAnywhere.lnk
2014-10-28 03:20 - 2009-07-14 00:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-10-27 09:55 - 2011-11-16 13:06 - 00000000 ____D () C:\ProgramData\WRData
2014-10-27 09:53 - 2011-10-27 12:59 - 02489784 _____ () C:\Windows\PFRO.log
2014-10-27 09:45 - 2010-11-20 00:06 - 00000000 ____D () C:\ProgramData\Adobe
2014-10-27 09:45 - 2010-11-20 00:06 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-10-21 07:37 - 2009-07-13 23:45 - 00267672 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-10-21 07:35 - 2014-05-22 13:45 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-10-09 11:40 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-09-29 16:15 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\rescache
2014-09-28 19:24 - 2013-11-28 08:33 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-09-28 18:53 - 2009-07-13 21:34 - 00000215 _____ () C:\Windows\system.ini

Some content of TEMP:

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2014-10-27 10:43

==================== End Of Log ============================

<<<Addition log>>>>>:

AswMBR log:

2014-10-28, 19:25
Looking at your log now, be back soon

2014-10-28, 19:54
You never posted the aswMBR log, you posted FRST twice :)

Your log looks fine, lets do this, open Malwarebytes and up on the top tell me what version it is, the latest version is 2.0.3, if its an older version go ahead and uninstall it with this removal tool


Then reboot your computer and download and install the latest version

Download Malwarebytes' Anti-Malware (http://www.malwarebytes.org/mbam-download.php) to your desktop.

Windows XP : Double click on the icon to run it.
Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"

http://i24.photobucket.com/albums/c30/ken545/MBAM203_zps0a230260.jpg (http://s24.photobucket.com/user/ken545/media/MBAM203_zps0a230260.jpg.html)

On the Dashboard click on Update Now
Go to the Setting Tab
Under Setting go to Detection and Protection
Under PUP and PUM make sure both are set to show Threat Detections as Malware
Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
Then on the Dashboard click on Scan
Make sure to select THREAT SCAN
Then click on Scan
When the scan is finished and the log pops up...select Copy to Clipboard
Please paste the log back into this thread for review
Exit Malwarebytes

2014-10-28, 21:08
Well I thought I copied the AswMbr log, might have forgot to hit copy. I'll post it in a minute. I had uninstalled Malwarebytes the last time I used it so I don't know why it was still showing, but I ran the cleaner just in case and downloaded the new one. Log also to follow. There was one file found and hit quarantine although I have not rebooted yet to completely remove it. I think that one was from trying to do a recovery disk for the desktop. You'll see it in the log.

AswMbr log:

aswMBR version Copyright(c) 2014 AVAST Software
Run date: 2014-10-28 10:27:58
10:27:58.861 OS Version: Windows x64 6.1.7601 Service Pack 1
10:27:58.861 Number of processors: 4 586 0x2505
10:27:58.861 ComputerName: GATEWAY-PC UserName: Gateway
10:28:01.014 Initialize success
10:28:01.076 VM: initialized successfully
10:28:01.092 VM: Intel CPU supported
10:28:04.790 VM: supported disk I/O iaStor.sys
10:30:28.365 AVAST engine defs: 14102800
10:32:04.086 The log file has been saved successfully to "C:\Users\Gateway\Desktop\aswMBR.txt"
10:32:27.802 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
10:32:27.802 Disk 0 Vendor: TOSHIBA_ GS00 Size: 610480MB BusType: 3
10:32:27.911 VM: Disk 0 MBR read successfully
10:32:27.911 Disk 0 MBR scan
10:32:27.927 Disk 0 Windows VISTA default MBR code
10:32:27.942 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 18553 MB offset 2048
10:32:27.989 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 356 MB offset 37998592
10:32:27.989 Disk 0 default boot code
10:32:28.036 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 591569 MB offset 38727680
10:32:28.254 Disk 0 scanning C:\Windows\system32\drivers
10:33:12.761 Service scanning
10:33:57.315 Modules scanning
10:33:57.315 Disk 0 trace - called modules:
10:33:58.204 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
10:33:58.204 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004c02060]
10:33:58.220 3 CLASSPNP.SYS[fffff8800120143f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8004950050]
10:34:00.248 AVAST engine scan C:\Windows
10:34:12.057 AVAST engine scan C:\Windows\system32
10:40:17.004 AVAST engine scan C:\Windows\system32\drivers
10:42:08.170 AVAST engine scan C:\Users\Gateway
10:44:29.319 AVAST engine scan C:\ProgramData
10:49:35.737 Disk 0 statistics 4166393/0/22 @ 3.54 MB/s
10:49:35.737 Scan finished successfully
10:51:51.316 Disk 0 MBR has been saved successfully to "C:\Users\Gateway\Desktop\MBR.dat"
10:51:51.316 The log file has been saved successfully to "C:\Users\Gateway\Desktop\aswMBR.txt"

Malwarebytes log:

Malwarebytes Anti-Malware

Scan Date: 10/28/2014
Scan Time: 1:40:32 PM
Logfile: mbamlog1.txt
Administrator: Yes

Malware Database: v2014.10.28.05
Rootkit Database: v2014.10.22.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Gateway

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 317142
Time Elapsed: 17 min, 28 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 1
PUP.Optional.OpenCandy, C:\Users\Gateway\Downloads\SetupImgBurn_2.5.8.0.exe, Quarantined, [bc0569ae5923cf678d3724320bfa7a86],

Physical Sectors: 0
(No malicious items detected)


2014-10-28, 21:56
Don't use OpenCandy to download anything, it includes adds and is considered ADWARE

Logs look good, everything running ok ?

2014-10-29, 00:28
Seems to be running ok. No pop ups or weird things for now. And I usually don't download that kind of thing, I was trying to create a bootable disk to get the desktop unfrozen but of course that didn't work. So what's next?

2014-10-29, 01:25
Looks like your good to go, I will leave this thread open for a few days in case you have problems and need to post back, keep all your tools in case we need them again, we can remove them in a few days if need be

Ken :)

2014-10-29, 13:04
Well thought I was good to go but I guess not. This morning as soon as I tried to access my e-mail I started getting pop ups from edbr2 and edbr3 as 3rd party cookies. So something still lurking on this laptop. I ran adware right away but it was clean. Any ideas?

2014-10-29, 14:29
Those are from a game I am assuming ???

Open notepad (Start --> All Programs --> Accessories --> Notepad).
Please copy the entire contents of the code box below.
(To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste).
Save it to the same directory as FRST or FRST64 as fixlist.txt. (it has to be right next to FRST or FRST64) either in a directory you saved FRST or FRST64 or on your desktop if thats where you saved it.
You can use your mouse to drag Fixlist right next to FRST or FRST64, either above or below it but not on top of it.

CMD: ipconfig /flushdns

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

Then open FRST or FRST64 and click on fix
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

2014-10-29, 14:56
Those are from a game I am assuming ???


I don't believe so. It happens every time I try to open an e-mail. After I did what you asked I tried to get into e-mail again and the same pop up and also got adnxs pop up as well. Haven't had these for a while so I don't know why I'm getting them again.

Here's the log:
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 29-10-2014
Ran by Gateway at 2014-10-29 07:47:36 Run:1
Running from C:\Users\Gateway\Desktop
Loaded Profile: Gateway (Available profiles: Gateway)
Boot Mode: Normal

Content of fixlist:
CMD: ipconfig /flushdns

Processes closed successfully.

========= ipconfig /flushdns =========

Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========= End of CMD: =========

C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 19.8 MB temporary data.

The system needed a reboot.

==== End of Fixlog ====

2014-10-29, 15:16
Something else that might be a problem. I was in my AOL software and went into internet options. In the manage add ons section there are a bunch of add ons under Microsoft Corporation:

XML Dom Doc, HTML DLG Safe Helper Class, Windows Media Player, XML HTTP 6.0 and a few others. In a box where you want to add websites to run it was a *. I removed it. I've never seen these files in add ons before. I went into my IE 10 directly and they are not there. Still getting pop ups when I enter e-mail. Not sure what the heck is going on. I've disabled everything that was listed in add ons under Microsoft heading. Not sure where to go from here.

2014-10-29, 16:22
Not a fan of anything AOL, if you can live without it go ahead in Programs and Features in the control panel and uninstall it all, in this day and age there is no need for anything AOL

Running AdwCleaner and Junkware Removal and then Malwarebytes should remove those pop ups

Here they are again in case you need them, run them all even if you have already, when your done with them all go ahead and run a new scan with FRST, checkmark Additions and post both logs

-AdwCleaner-by Xplode

Click on this link to download : ADWCleaner (http://www.bleepingcomputer.com/download/adwcleaner/)
Click on ONE of the Two Blue Download Now buttons That have a blue arrow beside them and save it to your desktop.

Do not click on any links in the top Advertisment.

Close all open programs and internet browsers.
Double click on AdwCleaner.exe to run the tool.
Click on Scan.
After the scan is complete click on "Clean"
Confirm each time with Ok.
Your computer will be rebooted automatically. A text file will open after the restart.
Please post the content of that logfile with your next reply.
You can find the logfile at C:\AdwCleaner[S1].txt as well.


http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool (http://thisisudax.org/downloads/JRT.exe) to your desktop.

Shut down your protection software now to avoid potential conflicts.
Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
The tool will open and start scanning your system.
Please be patient as this can take a while to complete depending on your system's specifications.
On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
Post the contents of JRT.txt into your next message.


Download Malwarebytes' Anti-Malware (http://www.malwarebytes.org/mbam-download.php) to your desktop.

Windows XP : Double click on the icon to run it.
Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"

http://i24.photobucket.com/albums/c30/ken545/MBAM203_zps0a230260.jpg (http://s24.photobucket.com/user/ken545/media/MBAM203_zps0a230260.jpg.html)

On the Dashboard click on Update Now
Go to the Setting Tab
Under Setting go to Detection and Protection
Under PUP and PUM make sure both are set to show Treat Detections as Malware
Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
Then on the Dashboard click on Scan
Make sure to select THREAT SCAN
Then click on Scan
When the scan is finished and the log pops up...select Copy to Clipboard
Please paste the log back into this thread for review
Exit Malwarebytes

2014-10-29, 17:29
Cannot do without AOL but I did do a quick restore on it. I will rerun all that stuff you suggested and will get back to you with logs in a little while.

2014-10-29, 18:38
Following are the logs: They found nothing but I'm still getting adnxs pop ups.

# AdwCleaner v4.002 - Report created 29/10/2014 at 10:42:47
# DB v2014-10-26.6
# Updated 27/10/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Gateway - GATEWAY-PC
# Running from : C:\Users\Gateway\Desktop\adwcleaner_4.002.exe
# Option : Clean

***** [ Services ] *****

***** [ Files / Folders ] *****

***** [ Scheduled Tasks ] *****

***** [ Shortcuts ] *****

***** [ Registry ] *****

***** [ Browsers ] *****

-\\ Internet Explorer v10.0.9200.17116


AdwCleaner[R0].txt - [712 octets] - [29/10/2014 10:39:08]
AdwCleaner[S0].txt - [627 octets] - [29/10/2014 10:42:47]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [686 octets] ##########

JRT log:

Junkware Removal Tool (JRT) by Thisisu
Version: 6.3.3 (10.21.2014:1)
OS: Windows 7 Home Premium x64
Ran by Gateway on Wed 10/29/2014 at 10:57:02.04

~~~ Services

~~~ Registry Values

~~~ Registry Keys

~~~ Files

~~~ Folders

~~~ Event Viewer Logs were cleared

Scan was completed on Wed 10/29/2014 at 10:59:31.81
End of JRT log

MBAM log:

Malwarebytes Anti-Malware

Scan Date: 10/29/2014
Scan Time: 11:01:11 AM
Logfile: mbam log.txt
Administrator: Yes

Malware Database: v2014.10.29.05
Rootkit Database: v2014.10.22.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Gateway

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 316784
Time Elapsed: 16 min, 6 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)


I will be back on later. Have some stuff to do.

2014-10-29, 18:42
What I would do is go into your AOL mail and delete anything with an attachment or even mail that you deem safe but no longer need, even in your send folder then empty the trash, just guessing you may have an infected email

Download ComboFix from one of these locations:

Link 1 (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)
Link 2 (http://www.forospyware.com/sUBs/ComboFix.exe)

* IMPORTANT !!! Save ComboFix.exe to your Desktop

Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
See this Link (http://www.bleepingcomputer.com/forums/topic114351.html) for programs that need to be disabled and instruction on how to disable them.
Remember to re-enable them when we're done.

Double click on ComboFix.exe & follow the prompts.

As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

2014-10-29, 21:03
<<What I would do is go into your AOL mail and delete anything with an attachment or even mail that you deem safe but no longer need, even in your send folder then empty the trash, just guessing you may have an infected email>>

E-mail in AOL is not stored on the computer so that you can access it anywhere. But I did go ahead and permanetly delete the deleted e-mails and anything else I didn't think I would need.

Here's the combofix log:

ComboFix 14-10-29.01 - Gateway 10/29/2014 13:30:50.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3764.2645 [GMT -5:00]
Running from: c:\users\Gateway\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}
AV: Webroot SecureAnywhere *Enabled/Updated* {9C0666FC-6C7D-3E97-3C40-0C6B33FC7401}
FW: ZoneAlarm Free Firewall Firewall *Disabled* {E6380B7E-D4B2-19F1-083E-56486607704B}
SP: Microsoft Security Essentials *Disabled/Updated* {F4542E20-6399-F3B9-D5A7-4EE87964D00C}
SP: Webroot SecureAnywhere *Enabled/Updated* {27678718-4A47-3119-06F0-3719487B3EBC}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
((((((((((((((((((((((((( Files Created from 2014-09-28 to 2014-10-29 )))))))))))))))))))))))))))))))
2014-10-29 18:38 . 2014-10-29 18:38 -------- d-----w- c:\users\Public\AppData\Local\temp
2014-10-29 18:38 . 2014-10-29 18:38 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-10-29 18:33 . 2014-10-29 18:33 -------- d-----w- c:\users\Gateway\AppData\Local\CrashDumps
2014-10-29 16:29 . 2014-10-29 16:29 111080 ----a-w- c:\windows\system32\drivers\eKdgjNlY.sys
2014-10-29 16:28 . 2014-10-14 19:59 11627712 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{5D769973-A26B-4408-B1CB-B88CB8F20A13}\mpengine.dll
2014-10-29 16:00 . 2014-10-29 16:31 129752 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-10-29 16:00 . 2014-10-01 16:11 63704 ----a-w- c:\windows\system32\drivers\mwac.sys
2014-10-29 16:00 . 2014-10-01 16:11 93400 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-10-29 16:00 . 2014-10-01 16:11 25816 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-10-29 16:00 . 2014-10-29 16:00 -------- d-----w- c:\program files (x86)\Malwarebytes Anti-Malware
2014-10-29 15:53 . 2014-10-29 15:53 111080 ----a-w- c:\windows\system32\drivers\AVoXsrYx.sys
2014-10-29 15:43 . 2014-10-29 15:43 111080 ----a-w- c:\windows\system32\drivers\HxQQQsyo.sys
2014-10-29 15:39 . 2014-10-29 15:42 -------- d-----w- C:\AdwCleaner
2014-10-29 15:17 . 2014-10-29 15:17 111080 ----a-w- c:\windows\system32\drivers\MxlQYWlT.sys
2014-10-29 12:48 . 2014-10-29 12:48 111080 ----a-w- c:\windows\system32\drivers\PwOKWLIh.sys
2014-10-29 11:09 . 2014-10-29 11:09 111080 ----a-w- c:\windows\system32\drivers\UBrLFeHr.sys
2014-10-29 10:48 . 2014-10-29 10:48 111080 ----a-w- c:\windows\system32\drivers\opRcMSkk.sys
2014-10-28 18:39 . 2014-10-28 18:39 -------- d-----w- c:\programdata\Malwarebytes
2014-10-28 18:35 . 2014-10-28 18:35 111080 ----a-w- c:\windows\system32\drivers\iAncQEAl.sys
2014-10-28 15:20 . 2014-10-29 12:47 -------- d-----w- C:\FRST
2014-10-28 08:20 . 2014-10-28 08:20 111080 ----a-w- c:\windows\system32\drivers\jnsAdKtw.sys
2014-10-28 07:35 . 2014-10-14 19:59 11627712 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-10-27 16:58 . 2014-10-27 16:58 -------- d-----w- c:\users\Gateway\AppData\Local\Apps
2014-10-27 14:54 . 2014-10-27 14:54 111080 ----a-w- c:\windows\system32\drivers\pDKYbgdo.sys
2014-10-27 14:39 . 2014-10-27 14:39 111080 ----a-w- c:\windows\system32\drivers\JmOVyYpY.sys
2014-10-27 12:40 . 2014-10-27 12:40 -------- d-----w- c:\programdata\boost_interprocess
2014-10-27 12:29 . 2014-10-27 12:29 111080 ----a-w- c:\windows\system32\drivers\atYthjoV.sys
2014-10-27 12:25 . 2014-10-27 12:25 111080 ----a-w- c:\windows\system32\drivers\IXtkPayO.sys
2014-10-27 12:19 . 2014-10-27 12:19 111080 ----a-w- c:\windows\system32\drivers\YVTTuumS.sys
2014-10-27 12:10 . 2014-10-27 12:10 111080 ----a-w- c:\windows\system32\drivers\gSuQpyHA.sys
2014-10-27 12:06 . 2014-10-27 12:06 111080 ----a-w- c:\windows\system32\drivers\PGBxTkEF.sys
2014-10-27 00:43 . 2014-10-27 00:43 111080 ----a-w- c:\windows\system32\drivers\ufimfweO.sys
2014-10-26 23:25 . 2014-10-26 23:25 12872 ----a-w- c:\windows\system32\bootdelete.exe
2014-10-26 12:46 . 2014-10-26 12:46 111080 ----a-w- c:\windows\system32\drivers\SaBACdhX.sys
2014-10-25 18:42 . 2014-10-25 18:42 111080 ----a-w- c:\windows\system32\drivers\qkkcNgcg.sys
2014-10-24 22:36 . 2014-10-24 22:36 111080 ----a-w- c:\windows\system32\drivers\sBDzxsjA.sys
2014-10-22 15:01 . 2014-10-22 15:01 111080 ----a-w- c:\windows\system32\drivers\iOwjfFdq.sys
2014-10-22 11:23 . 2014-10-22 11:23 111080 ----a-w- c:\windows\system32\drivers\sNmtkkiz.sys
2014-10-22 11:05 . 2014-10-22 11:05 111080 ----a-w- c:\windows\system32\drivers\PHrqeLVS.sys
2014-10-22 10:54 . 2014-10-22 10:54 111080 ----a-w- c:\windows\system32\drivers\KnLHwfQW.sys
2014-10-21 19:34 . 2014-10-21 19:34 111080 ----a-w- c:\windows\system32\drivers\BlFSMOwS.sys
2014-10-21 13:00 . 2014-10-21 13:00 111080 ----a-w- c:\windows\system32\drivers\ipEyTLGa.sys
2014-10-21 12:49 . 2014-06-18 22:23 1943696 ----a-w- c:\windows\system32\dfshim.dll
2014-10-21 12:49 . 2014-06-18 22:23 156312 ----a-w- c:\windows\system32\mscorier.dll
2014-10-21 12:49 . 2014-06-18 22:23 156824 ----a-w- c:\windows\SysWow64\mscorier.dll
2014-10-21 12:49 . 2014-06-18 22:23 1131664 ----a-w- c:\windows\SysWow64\dfshim.dll
2014-10-21 12:49 . 2014-06-18 22:23 73880 ----a-w- c:\windows\system32\mscories.dll
2014-10-21 12:49 . 2014-06-18 22:23 81560 ----a-w- c:\windows\SysWow64\mscories.dll
2014-10-21 12:40 . 2014-10-21 12:40 111080 ----a-w- c:\windows\system32\drivers\tICbFABY.sys
2014-10-21 12:37 . 2014-10-21 12:37 111080 ----a-w- c:\windows\system32\drivers\uOqCtCGV.sys
2014-10-21 12:32 . 2014-08-29 02:07 3179520 ----a-w- c:\windows\system32\rdpcorets.dll
2014-10-21 12:32 . 2014-09-04 05:23 424448 ----a-w- c:\windows\system32\rastls.dll
2014-10-21 12:32 . 2014-09-04 05:04 372736 ----a-w- c:\windows\SysWow64\rastls.dll
2014-10-21 12:32 . 2014-09-29 00:58 3198976 ----a-w- c:\windows\system32\win32k.sys
2014-10-21 12:32 . 2014-09-05 02:11 6584320 ----a-w- c:\windows\system32\mstscax.dll
2014-10-21 12:32 . 2014-09-05 01:52 5703168 ----a-w- c:\windows\SysWow64\mstscax.dll
2014-10-21 12:31 . 2014-09-13 01:58 77312 ----a-w- c:\windows\system32\packager.dll
2014-10-21 12:31 . 2014-09-13 01:40 67072 ----a-w- c:\windows\SysWow64\packager.dll
2014-10-21 12:17 . 2014-10-21 12:17 111080 ----a-w- c:\windows\system32\drivers\TejdXozT.sys
2014-10-20 07:29 . 2014-10-20 07:29 111080 ----a-w- c:\windows\system32\drivers\VaIZBLul.sys
2014-10-09 16:42 . 2014-10-09 16:42 111080 ----a-w- c:\windows\system32\drivers\pkUPoewm.sys
2014-10-08 09:40 . 2014-10-08 09:40 111080 ----a-w- c:\windows\system32\drivers\PvmDPGpu.sys
2014-10-08 09:14 . 2014-10-08 09:14 111080 ----a-w- c:\windows\system32\drivers\qCEOYKVu.sys
2014-10-06 11:42 . 2014-10-06 11:42 111080 ----a-w- c:\windows\system32\drivers\FKACWuEl.sys
2014-10-03 23:34 . 2014-10-03 23:34 111080 ----a-w- c:\windows\system32\drivers\kCpsrgpo.sys
2014-10-02 13:31 . 2014-10-22 15:15 37624 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2014-10-02 13:31 . 2014-10-02 13:31 -------- d-----w- c:\programdata\RogueKiller
2014-10-01 10:17 . 2014-09-17 11:05 1188440 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{78B986AF-7794-4504-8620-03B8D602F3A3}\gapaengine.dll
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2014-09-29 17:31 . 2014-09-29 17:31 111080 ----a-w- c:\windows\system32\drivers\exTZeEAA.sys
2014-09-29 12:58 . 2014-09-29 12:58 111080 ----a-w- c:\windows\system32\drivers\Cllvxtmc.sys
2014-09-29 12:40 . 2014-09-29 12:40 111080 ----a-w- c:\windows\system32\drivers\dubezlMy.sys
2014-09-28 23:59 . 2014-09-28 23:59 111080 ----a-w- c:\windows\system32\drivers\OyPexOOc.sys
2014-09-28 19:58 . 2014-09-28 19:58 111080 ----a-w- c:\windows\system32\drivers\yMxFRDLr.sys
2014-09-28 19:36 . 2014-09-28 19:36 111080 ----a-w- c:\windows\system32\drivers\UzVfwxBv.sys
2014-09-28 14:17 . 2014-09-28 14:17 111080 ----a-w- c:\windows\system32\drivers\VbdJPgnZ.sys
2014-09-28 13:59 . 2014-09-28 13:59 111080 ----a-w- c:\windows\system32\drivers\bUvERcaW.sys
2014-09-28 11:53 . 2014-09-28 11:53 111080 ----a-w- c:\windows\system32\drivers\ICPieGzC.sys
2014-09-27 21:41 . 2014-09-27 21:41 111080 ----a-w- c:\windows\system32\drivers\UgqyfSyY.sys
2014-09-27 21:22 . 2014-09-27 21:22 111080 ----a-w- c:\windows\system32\drivers\dFcHOCdB.sys
2014-09-27 21:13 . 2014-09-27 21:13 111080 ----a-w- c:\windows\system32\drivers\KxCEIaxm.sys
2014-09-27 21:07 . 2014-09-27 21:07 111080 ----a-w- c:\windows\system32\drivers\yspnfyZk.sys
2014-09-25 13:11 . 2014-09-25 13:11 111080 ----a-w- c:\windows\system32\drivers\OVeQxxot.sys
2014-09-25 13:01 . 2014-09-25 13:01 111080 ----a-w- c:\windows\system32\drivers\NsnVqhYY.sys
2014-09-24 16:07 . 2014-09-24 16:07 111080 ----a-w- c:\windows\system32\drivers\gRQyHaVv.sys
2014-09-24 12:14 . 2014-09-24 12:14 111080 ----a-w- c:\windows\system32\drivers\cqVRFPRT.sys
2014-09-22 06:42 . 2011-10-27 20:21 278152 ------w- c:\windows\system32\MpSigStub.exe
2014-09-20 22:52 . 2014-09-20 22:52 111080 ----a-w- c:\windows\system32\drivers\orzShdkG.sys
2014-09-20 22:40 . 2014-09-20 22:40 111080 ----a-w- c:\windows\system32\drivers\lNmKKXXK.sys
2014-09-20 22:13 . 2014-09-20 22:13 111080 ----a-w- c:\windows\system32\drivers\ILtPGRZV.sys
2014-09-20 22:11 . 2014-09-20 22:11 111080 ----a-w- c:\windows\system32\drivers\NBCkzyDb.sys
2014-09-20 21:46 . 2014-09-20 21:46 111080 ----a-w- c:\windows\system32\drivers\SsgbkfyY.sys
2014-09-20 13:10 . 2013-06-26 14:27 71344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-09-20 13:10 . 2013-06-26 14:27 701104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-09-17 11:05 . 2012-02-10 12:24 1188440 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2014-09-16 10:51 . 2014-09-16 10:51 111080 ----a-w- c:\windows\system32\drivers\aWWCvThI.sys
2014-09-09 22:11 . 2014-09-29 17:23 2048 ----a-w- c:\windows\system32\tzres.dll
2014-09-09 21:47 . 2014-09-29 17:23 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2014-09-03 19:47 . 2010-06-24 18:33 23256 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2014-09-03 19:46 . 2014-09-03 19:46 111080 ----a-w- c:\windows\system32\drivers\iVIgRJke.sys
2014-09-03 19:44 . 2014-09-03 19:44 111080 ----a-w- c:\windows\system32\drivers\LixWLhJB.sys
2014-08-31 17:20 . 2014-08-31 17:20 111080 ----a-w- c:\windows\system32\drivers\HwhACASq.sys
2014-08-28 21:09 . 2014-08-28 21:09 111080 ----a-w- c:\windows\system32\drivers\ajOQjQhU.sys
2014-08-27 14:47 . 2014-08-27 14:47 111080 ----a-w- c:\windows\system32\drivers\txAthFaK.sys
2014-08-27 14:46 . 2014-08-27 14:46 111080 ----a-w- c:\windows\system32\drivers\JKzFHMwg.sys
2014-08-23 02:07 . 2014-09-20 21:59 404480 ----a-w- c:\windows\system32\gdi32.dll
2014-08-23 01:45 . 2014-09-20 21:59 311808 ----a-w- c:\windows\SysWow64\gdi32.dll
2014-08-23 00:34 . 2014-08-23 00:34 111080 ----a-w- c:\windows\system32\drivers\vCKYeTXc.sys
2014-08-21 13:56 . 2014-08-21 13:56 111080 ----a-w- c:\windows\system32\drivers\SXkkfHGk.sys
2014-08-19 15:44 . 2014-08-19 15:44 111080 ----a-w- c:\windows\system32\drivers\lFDmxCus.sys
2014-08-10 22:23 . 2014-08-10 22:22 111080 ----a-w- c:\windows\system32\drivers\ObnXGiKQ.sys
2014-08-02 18:38 . 2014-08-02 18:38 111080 ----a-w- c:\windows\system32\drivers\OBYIpiCc.sys
2014-08-01 11:53 . 2014-09-20 22:01 1031168 ----a-w- c:\windows\system32\TSWorkspace.dll
2014-08-01 11:35 . 2014-09-20 22:01 793600 ----a-w- c:\windows\SysWow64\TSWorkspace.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
"AOL Fast Start"="c:\program files (x86)\AOL Desktop 9.6\AOL.EXE" [2011-04-25 42320]
"LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2010-08-11 975952]
"ZoneAlarm"="c:\program files (x86)\CheckPoint\ZoneAlarm\zatray.exe" [2013-06-20 73832]
"WRSVC"="c:\program files\Webroot\WRSA.exe" [2012-01-16 647120]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [x]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x]
R2 Updater Service;Updater Service;c:\program files\Gateway\Gateway Updater\UpdaterService.exe;c:\program files\Gateway\Gateway Updater\UpdaterService.exe [x]
R2 WRSVC;WRSVC;c:\program files\Webroot\WRSA.exe;c:\program files\Webroot\WRSA.exe [x]
R3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS;c:\windows\SYSNATIVE\drivers\AmUStor.SYS [x]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
R3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 PCDSRVC{FCB8192B-6C0E95E9-06020101}_0;PCDSRVC{FCB8192B-6C0E95E9-06020101}_0 - PCDR Kernel Mode Service Helper Driver;c:\users\gateway\appdata\local\temp\i1amxcawrfo3\pcdrdiag\bin\pcdsrvc_x64.pkms;c:\users\gateway\appdata\local\temp\i1amxcawrfo3\pcdrdiag\bin\pcdsrvc_x64.pkms [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TurboBoost;TurboBoost;c:\program files\Intel\TurboBoost\TurboBoost.exe;c:\program files\Intel\TurboBoost\TurboBoost.exe [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 WRkrn;WRkrn;c:\windows\System32\drivers\WRkrn.sys;c:\windows\SYSNATIVE\drivers\WRkrn.sys [x]
S2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe;c:\program files (x86)\Launch Manager\dsiwmis.exe [x]
S2 ePowerSvc;Acer ePower Service;c:\program files\Gateway\Gateway Power Management\ePowerSvc.exe;c:\program files\Gateway\Gateway Power Management\ePowerSvc.exe [x]
S2 GREGService;GREGService;c:\program files (x86)\Gateway\Registration\GREGsvc.exe;c:\program files (x86)\Gateway\Registration\GREGsvc.exe [x]
S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe;c:\program files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe [x]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [x]
S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys;c:\windows\SYSNATIVE\DRIVERS\TurboB.sys [x]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S2 ZAPrivacyService;ZoneAlarm Privacy Service;c:\program files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe;c:\program files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe [x]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys;c:\windows\SYSNATIVE\DRIVERS\HECIx64.sys [x]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys;c:\windows\SYSNATIVE\DRIVERS\Impcd.sys [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys;c:\windows\SYSNATIVE\DRIVERS\k57nd60a.sys [x]
--------- X64 Entries -----------
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-05-07 161304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-05-07 386584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-05-07 413208]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-07-29 11101800]
"AmIcoSinglun64"="c:\program files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" [2010-06-10 324608]
"Acer ePower Management"="c:\program files\Gateway\Gateway Power Management\ePowerTray.exe" [2010-06-11 861216]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2014-08-22 1331288]
------- Supplementary Scan -------
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.aol.com/
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer =
- - - - ORPHANS REMOVED - - - -
Toolbar-Locked - (no file)
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
--------------------- LOCKED REGISTRY KEYS ---------------------
@Denied: (A 2) (Everyone)
@Denied: (A 2) (Everyone)
@Denied: (A 2) (Everyone)
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_152.ocx, 1"
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_152.ocx, 1"
@Denied: (A 2) (Everyone)
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
@DACL=(02 0000)
@Denied: (Full) (Everyone)
Completion time: 2014-10-29 13:46:48
ComboFix-quarantined-files.txt 2014-10-29 18:46
Pre-Run: 567,220,666,368 bytes free
Post-Run: 566,681,833,472 bytes free
- - End Of File - - E7318077D953FCAB3C349E51402095F3

2014-10-29, 21:07
Oh forgot to mention as I was running combo fix. It's said Webroot Secure anywhere was still active even though I had it disabled. It comes up when I reboot and I disable it because I don't like it except for clearing temp files. So for the most part it's disabled. Also about like 8 or 9 in the combofix process a notification came up that PEV.exe stopped working and required me to close the program to continue. Not sure if that's part of combo fix or something else.

2014-10-29, 22:07
Combofix is showing a ton of drivers that wont Google, when I cant find any info on them there most times bad, I want you to check two of them before we remove them all

You need to enable windows to show all files and folders, instructions Here (http://www.bleepingcomputer.com/tutorials/tutorial62.html)

Go to VirusTotal (http://www.virustotal.com/) and submit these files for analysis, just use CHOOSE FILE and then Scan It, if it says this file has been checked before, have them recheck it. When the scan is done just copy and paste the link back to this forum for me to see.


If the site is busy you can try this one

2014-10-29, 22:29
When I go to Virus Total I cannot find either of these drivers. When I search for then in the C: drive the properties says it's part of Webroot Secure Anywhere. I've had this come up before. I don't know why those won't show except for maybe they are part of security software?

2014-10-30, 01:42
Did some asking around and they may be part of webroot, never been a big fan of webroot, its up to you but try uninstalling it and see if things get better

2014-10-30, 02:11
Since I ran combo fix I've not gotten a pop up. But then again these things come and go. I've been in my e-mail several times and nothing yet. So I'll check it out again tomorrow morning and see what happens. It's just strange that it comes and goes. Nothing consistent, which is why it's so darned frustrating and probably hard to find. I'll check in again tomorrow and let you know how it goes.

2014-10-30, 02:54
If you look at your Combofix log nothing was removed

Lets reset all your browsers back to company defaults

Open IE
Go to Tools> Internet Options > Advanced Tab
Reset Internet Explorer Setting
This will take a few seconds
Close IE and then reopen it and see if it helped

Open Firefox
Click on Help > Troubleshooting Information > Reset Firefox to its default state

Click the Chrome menu http://i24.photobucket.com/albums/c30/ken545/Clipboard01_zps2e55f676.jpgon the browser toolbar.
Select Settings.
Scroll down to Show advanced settings...
Down on the bottom you will see an option for RESET BROWSER SETTINGS
Click on it and it will set Chome back to defaults

2014-10-30, 10:50
I've reset IE and at first I thought maybe that worked. But now I'm getting edbr2.com pop ups constantly everytime I go into my AOL e-mail where as before it was sporadic. I'm going to see if I can find a way to reload AOL 9.6 but it might take me a while. I'm thinking maybe the software got dinged by something. So give me a day or so. At this point I'm so frustrated I'm about ready to take it back to factory specs if it didn't mean losing a whole lot of favorite places in IE. Thanks for being patient with me. If you have any other ideas I'd be happy to hear them.

2014-10-30, 13:51
I think your problems have to do with AOL and I think as long as you use it your going to have these issues

2014-10-30, 15:35
Well at least that version of AOL. I upgrade to IE11 and removed the aol software v. 9.6 and anything related to it. Then downloaded new v. 9.7 and so far so good. It's just odd that it was only the e-mail portion that affected. I'm going to go run Adware and Malwarebytes just to make sure I don't have anything lingering but I'm hoping we are done with this. Thanks for all your help and advice. Should we clean up?

2014-10-30, 15:55
No, go ahead and run AdwCleaner, Junkware Removal and Malwarebytes and lets see if your clean

2014-10-30, 16:30
Ok AdwCleaner found the viewpoint software so I cleaned that. Malwarebytes was clean.

Here's the JRT log:

Junkware Removal Tool (JRT) by Thisisu
Version: 6.3.3 (10.21.2014:1)
OS: Windows 7 Home Premium x64
Ran by Gateway on Thu 10/30/2014 at 9:24:06.40

~~~ Services

~~~ Registry Values

~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{32C7D14C-388E-4B2C-A5C3-C6B72F0D932D}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{7B48AC99-4C2E-4794-824C-D1468583D385}

~~~ Files

~~~ Folders

~~~ Event Viewer Logs were cleared

Scan was completed on Thu 10/30/2014 at 9:26:38.99
End of JRT log

2014-10-30, 16:47
Looks like your finally good to go

Double click on AdwCleaner.exe to run the tool again.

Click on the Uninstall button.
Click Yes when asked are you sure you want to uninstall.
Both AdwCleaner.exe, its folder and all logs will be removed.


Please download DelFix (http://general-changelog-team.fr/en/downloads/finish/20-outils-de-xplode/9-delfix) and save the file to your Desktop.

Windows XP Double Click DelFix.exe to run the program.
Windows Vista > Win 7 > Win 8 Right Click on DelFix.exe and select RUN AS ADMINISTRATOR
Place a checkmark next to the following items

Activate UAC
Remove Disinfection Tools
Create registry backup
Reset System Settings

Click the Run button

This will remove the specialised tools we used to clean your system. Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually


How did I get infected in the first place ?
Read these links and find out how to prevent getting infected again.
Tutorial for System Restore (http://www.bleepingcomputer.com/tutorials/tutorial56.html) <-- Do this first to prevent yourself from being reinfected.
WhattheTech (http://forums.whatthetech.com/index.php?showtopic=57817)
Grinler BleepingComputer (http://www.bleepingcomputer.com/forums/topic2520.html)
GeeksTo Go (http://www.geekstogo.com/forum/index.php?autocom=custom&page=How_did_I)
Dslreports (http://www.dslreports.com/faq/10002)

Safe Surfn